Method and apparatus for device authentication

Through the integration of blockchain and federated learning, combined with multi-factor authentication protocol, the problem of single-factor authentication is solved, and high accuracy recognition of device identity and safe and reliable distributed authentication are achieved.

CN114329418BActive Publication Date: 2025-07-04BEIJING UNIV OF POSTS & TELECOMM +2
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202111400096.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-11-19
Publication Date
2025-07-04
Estimated Expiration
2041-11-19

AI Technical Summary

Technical Problem

Most existing device authentication solutions rely on single-factor authentication, which are prone to attacks and cannot meet security requirements.

Method used

Using the combination of blockchain and federated learning, the global model parameters are determined by training the local model parameters, dual-weight parameters and asynchronous parameter aggregation of the blockchain nodes, and combining the multi-factor authentication protocol, including RF information identity factors, access network authentication factors and random factors, the two-way authentication of the device is realized.

Benefits of technology

It realizes high-correction equipment identification and authentication, and the system is distributed, safe and reliable, reducing the amount of encrypted and decrypted information, and avoiding the process of additional key negotiation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN114329418B_ABST
    Figure CN114329418B_ABST
Patent Text Reader

Abstract

The present invention provides a method and device for device authentication. The method includes: determining the global model parameters of the blockchain based on the local model parameters, dual weight parameters, and asynchronous parameter aggregation of the trained blockchain nodes; identifying the radio frequency information identity factor of the device based on the global model parameters of the blockchain and the device information; and completing the two-way authentication of the device based on the multi-factor authentication protocol, where the multi-factor at least includes a combination of one or more of the following: the radio frequency information identity factor of the device, the authentication factor corresponding to the access network, and the random factor. The device authentication method provided by the present invention realizes high-accuracy identification of factors and a distributed authentication system by integrating blockchain and federated learning. At the same time, based on the multi-factor authentication protocol, it is secure and reliable, requires less information for encryption and decryption, and the authentication process includes key negotiation without an additional key negotiation process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and particularly to a method and device for device authentication. Background Art

[0002] In recent years, the rapid development of network technology has led to an explosive growth in the number of Internet of Things devices, and more and more devices are used in various industries for services. However, due to the high openness of the network itself, some illegal devices can disguise their identities through certain malicious means, obtain access rights to the service system, and then perform other malicious operations on the system. Therefore, correctly authenticating the identity of devices is the most important factor in ensuring system security.

[0003] However, most of the existing identity authentication schemes only use a single factor to authenticate devices, such as using account passwords, fingerprints, etc. Single-factor identity authentication schemes cannot meet the security requirements in many scenarios and are easily attacked. Summary of the Invention

[0004] In view of the problems existing in the prior art, the present invention provides a method and device for device authentication.

[0005] In a first aspect, the present invention provides a method for device authentication, including:

[0006] Based on the local model parameters of the trained blockchain nodes, double weight parameters, and asynchronous parameter aggregation, determining the global model parameters of the blockchain;

[0007] Based on the global model parameters of the blockchain and device information, identifying the radio frequency information identity factor of the device;

[0008] Based on a multi-factor authentication protocol, completing the two-way authentication of the device;

[0009] Wherein, the multi-factor at least includes a combination of one or more of the following: the radio frequency information identity factor of the device, the authentication factor corresponding to the access network, and a random number.

[0010] Optionally, the local model parameters of the blockchain nodes are trained with the radio frequency information of the device as the local data set, and the device is located near the blockchain nodes.

[0011] Optionally, the determining the global model parameters of the blockchain based on the local model parameters of the trained blockchain nodes, double weight parameters, and asynchronous parameter aggregation includes:

[0012] After the local model training of a specific blockchain node is completed, synchronizing the local model parameters to the new block generated by the specific blockchain node and other nodes of the blockchain;

[0013] Determine the global model parameters of the blockchain based on dual-weight parameters and asynchronous parameter aggregation.

[0014] Optionally, after the specific blockchain node generates a new block, the method further includes:

[0015] Based on the Pow consensus mechanism, determine a new block that meets the preset difficulty coefficient value, and broadcast the new block to the entire blockchain.

[0016] Optionally, the determining the global model parameters of the blockchain based on dual-weight parameters and asynchronous parameter aggregation includes:

[0017] Based on the ratio of the local sample quantity to the total sample quantity and the ratio of the time used for the current local model training to the time used for the current global model training, determine the dual-weight parameters for the current global model aggregation;

[0018] Based on the previously trained global model parameters, the locally trained model parameters of the specific blockchain node, and the dual-weight parameters, determine the global model parameters of the blockchain in the manner of asynchronous parameter aggregation;

[0019] If the specific blockchain node generates a corresponding new block, synchronize the local model parameters of the specific blockchain node to the corresponding new block;

[0020] Wherein, the time used for the current global model training is the shortest time for the specific local model training.

[0021] Optionally, the formula for asynchronous parameter aggregation is:

[0022]

[0023]

[0024] Wherein, represents the global model obtained from the p-th global iteration, represents the models of other nodes received by the node, ψ (p) is a dual-weight function, representing the proportion of the local model in this model update, used to calculate the ratio of the local sample quantity to the total sample quantity, used to calculate the ratio of the time used for the current local model training to the time used for the global model.

[0025] Optionally, the completing the two-way authentication of the device based on the multi-factor authentication protocol includes:

[0026] Based on the authentication result returned by the network access request of the device, determine the authentication factor corresponding to the network to which the device is connected;

[0027] Based on DDH, determine the identity factor of the radio frequency fingerprint information of the device and the identity information Data of the device i and save them to the blockchain to complete the registration phase of the multi-factor authentication protocol;

[0028] Based on the response challenge mechanism between the device and a specific blockchain node, obtain the authentication challenge m0 and the first secret key K on the side of the specific blockchain node, and the authentication response m1 and the second secret key K' on the side of the device respectively;

[0029] Based on the message authentication function, determine whether the authentication results are both 1 respectively;

[0030] If the authentication results on both sides are both 1, the two-way authentication of the device is successful.

[0031] In a second aspect, the present invention provides a device authentication apparatus, including:

[0032] A model determination module, configured to determine the global model parameters of the blockchain based on the local model parameters, double weight parameters and asynchronous parameter aggregation of the trained blockchain node;

[0033] An identification module, configured to identify the radio frequency information identity factor of the device based on the global model parameters of the blockchain and the device information;

[0034] An authentication module, configured to complete the two-way authentication of the device based on the multi-factor authentication protocol;

[0035] Wherein, the multi-factor at least includes a combination of one or more of the following: the radio frequency information identity factor of the device, the authentication factor corresponding to the access network, and a random number.

[0036] In a third aspect, the present invention provides an electronic device, including a memory and a memory storing a computer program, and the processor implements the steps of the first aspect or the device authentication method when executing the program.

[0037] In a fourth aspect, the present invention provides a processor-readable storage medium, and the processor-readable storage medium stores a computer program, and the computer program is used to make the processor execute the steps of the device authentication method in the first aspect.

[0038] The device authentication method and apparatus provided by the present invention fuse blockchain and federated learning to achieve high-accuracy identification of factors and a distributed authentication system. At the same time, based on the multi-factor authentication protocol, it is safe and reliable, requires less information for encryption and decryption, and the authentication process includes key negotiation without an additional key negotiation process. Description of the Drawings

[0039] To more clearly illustrate the technical solutions in the present invention or the prior art, the following briefly introduces the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.

[0040] Figure 1 It is one of the schematic flowcharts of the device authentication method provided by the present invention;

[0041] Figure 2 It is a schematic diagram of the multi-factor authentication protocol interaction provided by the present invention;

[0042] Figure 3 It is the second schematic overall flowchart of the device authentication method provided by the present invention;

[0043] Figure 4 It is the structural schematic diagram of the device authentication apparatus provided by the present invention;

[0044] Figure 5 It is the physical structural schematic diagram of the electronic device provided by the present invention. Detailed implementation manners

[0045] To make the objectives, technical solutions, and advantages of the present invention clearer, the following will clearly and completely describe the technical solutions in the present invention in conjunction with the accompanying drawings in the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art without creative efforts based on the embodiments in the present invention belong to the scope of protection of the present invention.

[0046] The following combines Figures 1 - 5 to describe the device authentication method and apparatus provided by the present invention.

[0047] Figure 1 It is one of the schematic flowcharts of the device authentication method provided by the present invention. As Figure 1 shown, the device authentication method includes:

[0048] Step 101: Based on the local model parameters, dual-weight parameters, and asynchronous parameter aggregation of the trained blockchain nodes, determine the global model parameters of the blockchain;

[0049] Step 102: Based on the global model parameters of the blockchain and device information, identify the radio frequency information identity factor of the device;

[0050] Step 103: Based on the multi-factor authentication protocol, complete the mutual authentication of the device;

[0051] Among them, the multi-factor at least includes one or several combinations of the following: the radio frequency information identity factor of the device, the authentication factor corresponding to the access network, and the random factor.

[0052] Specifically, the present invention mainly includes blockchain and federated learning, and the multi-factor protocol. The former realizes a decentralized authentication method, the identification of identity factors, and the security of the system. The latter theoretically guarantees the correctness of the identity authentication of the device after the combination of multiple factors.

[0053] For blockchain and federated learning, the number of IoT devices is large and they are widely distributed. Each device needs to verify its identity before accessing the network to prevent malicious devices from accessing the system. If a centralized authentication method is adopted, it will bring a great computational pressure to the nodes. Therefore, in the present invention, a distributed authentication method is used to authenticate IoT devices. Blockchain is the key technology to realize a decentralized distributed system. At the same time, combined with federated learning technology, distributed authentication can be realized while ensuring the privacy of device data.

[0054] Blockchain has the characteristics of transparency, openness, information immutability, decentralization, etc. Blockchain nodes have certain storage controls, can be connected to the network, and have visual operations, etc. Blockchain nodes constitute the backbone of the blockchain network. Information is not stored in a centralized server, but is stored in a distributed and decentralized manner. Users can fully control this information, which is basically realized through this node network.

[0055] All nodes in the blockchain train the node according to the device information near the node. Once the training is completed, the corresponding blockchain node will generate local model parameters and broadcast the trained local model parameters to other nodes in the blockchain. After receiving the trained local model parameters, each node verifies the signature, integrity, etc. of the message.

[0056] When a certain node in the blockchain receives the trained local model parameter information transmitted from other nodes, it immediately performs the aggregation of the model parameters, rather than waiting for all nodes to complete the training and aggregate at the same time. Therefore, it is asynchronous parameter aggregation. And the weight of the trained local model parameters of each blockchain node in the global model update process is adopted with a double weight function. On the one hand, it represents the ratio of the local sample quantity to the total sample quantity, and on the other hand, it also represents the ratio of the time used for this local model training to the time used for the global model. Thus, the influence of the local model parameters on the global model parameters is considered more dimensionally. Furthermore, the global model parameters of the blockchain are determined to be more typical and representative.

[0057] After the global model parameters of the blockchain are determined, by securely uploading and saving the device entity identity information on the blockchain, broadcasting and sharing data, any service node in the blockchain network can obtain the corresponding identity information of the entity and verify it, thereby enabling rapid identification and authentication of the user entity identity. The advantage of using blockchain technology is that it can ensure the security of authentication information data, while enabling the decentralization of authentication nodes, echoing with decentralized IoT devices, and reducing the computing pressure of the authentication center.

[0058] Among them, the physical identity information of the device can include various forms, such as the production number of the device, the RF fingerprint information of the device, etc. The RF fingerprint comes from the hardware differences inside different devices. Even if the devices are produced by the same manufacturer and the same production line, there will be certain hardware reciprocity, which means that the physical layer characteristics of the device itself are unique and difficult to be tampered with. Therefore, more and more are used as identity factors for identifying devices.

[0059] In the present invention, the radio frequency fingerprint information of the device is used as the radio frequency information identity factor for identifying the device. Then, combined with multiple factor identity authentication protocols, the authentication node can authenticate the device end, increase the selection dimension of the corresponding parameters of the identity authentication, and avoid tampering as much as possible. Moreover, through the introduction of random factors, it is more random and it is not easy to find patterns to prevent imitation.

[0060] A device authentication method provided by the present invention integrates blockchain and federated learning to achieve high-accuracy factor recognition and distributed authentication system. At the same time, it is based on a multi-factor authentication protocol, is safe and reliable, requires a small amount of information for encryption and decryption, and the authentication process includes key negotiation, without the need for an additional key negotiation process.

[0061] Optionally, the local model parameters of the blockchain node are obtained by training using the radio frequency information of the device as a local data set, and the device is located near the blockchain node.

[0062] Specifically, the local model parameters of the blockchain node must first upload the radio frequency information of each device near the blockchain node in units of blockchain nodes, and all devices upload local encrypted radio frequency fingerprint information and local device identification to the adjacent blockchain nodes. Then the blockchain node trains the local model parameters based on federated learning. When the local model parameters reach convergence, the training of the local model parameters is completed and the corresponding trained local model parameters are determined.

[0063] In the actual deployment stage, blockchain nodes may be composed of servers with strong computing and storage capabilities. These servers are distributed in different locations to form a blockchain network with a wide distribution range and a large number. When uploading radio frequency information, the device actively sends a signal to the blockchain node and selects the nearest server based on the IP address or geographical location. Usually, the nearby range is within 2km.

[0064] Optionally, the determining of the global model parameters of the blockchain based on the trained local model parameters of the blockchain node, the dual weight parameters and the asynchronous parameter aggregation includes:

[0065] After the local model training of a specific blockchain node is completed, the local model parameters are synchronized to the new block generated by the specific blockchain node and other nodes of the blockchain;

[0066] Based on the dual-weight parameters and asynchronous parameter aggregation, global model parameters of the blockchain are determined.

[0067] Specifically, all nodes in the blockchain use local encrypted RF fingerprint information as training samples to train local models. When a node completes the local model training, the node will generate a new block and write the trained model parameters into it. At the same time, the information will be broadcast to other nodes. After receiving the model parameters, each node in the blockchain will verify the signature and completeness of the message.

[0068] In addition, when a node receives model parameter information from other nodes, it immediately aggregates the global model parameters without waiting for all nodes to complete training. Therefore, it is asynchronous aggregation. Specifically, dual weight parameters are used to aggregate the model. The dual weight parameters take into account the proportion of local samples to total samples on the one hand, and the time used for local model training and the time used for global model training on the other hand. The time used for the global model is the time required for the node in the blockchain that completes local model training the fastest to complete its local model training.

[0069] A device authentication method provided by the present invention integrates blockchain and federated learning to achieve high-accuracy factor recognition and distributed authentication system. At the same time, it is based on a multi-factor authentication protocol, is safe and reliable, requires a small amount of information for encryption and decryption, and the authentication process includes key negotiation, without the need for an additional key negotiation process.

[0070] Optionally, after the specific blockchain node generates a new block, the method further includes:

[0071] Based on the Pow consensus mechanism, a new block that meets the preset difficulty coefficient value is determined and broadcasted to the entire blockchain.

[0072] Specifically, according to the Pow consensus mechanism, a preset difficulty coefficient value is set. The difficulty coefficient value can be set according to actual needs. The larger the difficulty coefficient, the greater the corresponding computational amount. For example, if the difficulty coefficient is defined as the first 4 zeros, that is, a 16-bit length (0000 0000 00000001 = 4 characters = 2 bytes), for the new blocks generated when each node in the blockchain trains its local model, calculate their corresponding random numbers, and broadcast the new blocks that meet the difficulty coefficient in the Pow consensus mechanism to the entire blockchain.

[0073] A device authentication method provided by the present invention realizes high-accuracy identification of factors and a distributed authentication system by integrating blockchain and federated learning. At the same time, based on a multi-factor authentication protocol, it is secure and reliable, requires less information for encryption and decryption, and the authentication process includes key negotiation without an additional key negotiation process.

[0074] Optionally, determining the global model parameters of the blockchain based on the dual-weight parameters and asynchronous parameter aggregation includes:

[0075] Determine the dual-weight parameters for the aggregation of the current global model based on the ratio of the local sample quantity to the total sample quantity and the ratio of the time used for the current local model training to the time used for the current global model training;

[0076] Determine the global model parameters of the blockchain in the manner of asynchronous parameter aggregation based on the previously trained global model parameters, the locally trained model parameters of a specific blockchain node, and the dual-weight parameters;

[0077] If the specific blockchain node generates a corresponding new block, synchronize the locally trained model parameters of the specific blockchain node to the corresponding new block;

[0078] Wherein, the time used for the current global model training is the shortest time for the training of the specific local model.

[0079] Specifically, when a certain node in the blockchain receives the locally trained model parameters transmitted from other nodes, it updates the global model and immediately aggregates the global model parameters in the form of asynchronous parameter aggregation, without waiting for all nodes to complete training and aggregate simultaneously.

[0080] And if the node that has trained the local model parameters generates a corresponding new block, synchronize the trained local model parameters to the new block, and then update the global model parameters of the blockchain by asynchronous parameter aggregation according to this. The formula for the asynchronous parameter aggregation is:

[0081]

[0082]

[0083] Among them, represents the global model obtained in the p-th global iteration, represents the models of other nodes received by the node, and ψ (p) is a double-weight function, representing the proportion of the local model in this model update, which is used to calculate the proportion of the local sample quantity in the total samples, and is used to calculate the ratio of the time used for this local model training to the time used for the global model.

[0084] While performing the learning and update of the federated learning model, the node runs the Pow consensus mechanism to determine whether the newly generated block meets the preset difficulty coefficient, and broadcasts the new block that meets the difficulty coefficient to the entire blockchain, so as to determine that the global model achieves a good correct rate for the identity recognition factor.

[0085] A device authentication method provided by the present invention realizes high-correct-rate recognition of factors and a distributed authentication system by integrating the blockchain and federated learning. At the same time, based on the multi-factor authentication protocol, it is safe and reliable, requires less information for encryption and decryption, and the authentication process includes key negotiation without an additional key negotiation process.

[0086] Optionally, the two-way authentication of the device based on the multi-factor authentication protocol includes:

[0087] Based on the authentication result returned by the network access request of the device, determine the authentication factor corresponding to the access network of the device;

[0088] Based on the DDH (Decisional Diffie–Hellman assumption), determine the identity factor of the radio frequency fingerprint information of the device and the identity information Data i of the device, and save them to the blockchain to complete the registration stage of the multi-factor authentication protocol;

[0089] Based on the response challenge mechanism between the device and a specific blockchain node, respectively obtain the authentication challenge m0 and the first secret key K on the side of the specific blockchain node, and the authentication response m1 and the second secret key K' on the side of the device;

[0090] Based on the message verification function, respectively determine whether the verification result is 1;

[0091] If the verification results on both sides are 1, the two-way authentication of the device is successful.

[0092] Specifically, after using blockchain and federated learning to identify factors, a joint authentication protocol for multiple factors based on the DDH assumption is used to ensure the security when multiple factors are combined. This protocol is implemented using a response-challenge mechanism.

[0093] Suppose G is a cyclic group of order q, P ∈ G, and P is a generator of G. CA selects a security parameter θ. For the authentication node CA: According to θ, run the key generation function to generate its own public key PubKey and private key PriKey, publicly announce P, the public key, G, and q parameters, and secretly store and the private key. Denote the set of large prime numbers. In the following formula is the exclusive OR operation, and || is the concatenation operation.

[0094] Registration phase: Device D i Sends an access request to the 5G base station, and the returned authentication result is used as the authentication factor α. The device runs a radio frequency extractor to extract its own radio frequency information and encrypts it using the CA public key and sends it to the CA node. After receiving it, CA decrypts it and uses the global model to identify the radio frequency fingerprint information, generating a second device identity factor, denoted as β. The device randomly generates a random number as the third identity factor δ and stores it in its own secure hardware. CA calculates D = P (α+δ)·β and encrypts it using the public key to obtain Data that can represent the device information i , and saves (Data i , ID i ) to the blockchain through a smart contract.

[0095] Authentication phase:

[0096] Step1: When device D i sends a request for authentication, it first needs to encrypt the radio frequency fingerprint information of the local machine, that is, generate a message (ID i , ) and send an authentication request to the CA node.

[0097] Step2: After receiving the authentication request, CA uses the smart contract to find device Data i through ID. If not found, it returns authentication failure. If found, it decrypts it using its own private key to obtain D. Then, CA randomly selects three random numbers a, b, c from i and generates nonceN1, decrypts the device authentication request to obtain and uses the model to identify β. CA calculates U = P , V = P a , V = P b , Send the authentication challenge m0 = <U||V||Q||N1||sid> to the device, where Sid represents the session identifier for the communication between the two parties.

[0098] Step3: Device D i After receiving the authentication challenge, first verify the correctness of the nonce. If the nonce has been used, it proves that there may be a replay attack in this authentication, and the authentication returns failure. After that, D i Sends an access request to the 5G base station to obtain the authentication result α, and at the same time reads the factor δ stored in the device's security hardware.

[0099] Device D i Selects three random numbers a′, b′, c′, and generates a nonce N2, calculates U′ = P a′ , V′ = P b′ , Q′ = U (α+δ) / P c′ , After that, runs the message encryption function MAC.Sig(K, m0) = σ0, sets m1 = <U′||V′||Q′||N2||sid, σ0>, and sends m1 as the authentication response to the CA.

[0100] Step4: When the CA receives the authentication response message, first perform the correctness verification of the nonce in the same way, and then calculate Runs the message encryption function MAC.Sig(K, m1) = σ1, and sends σ1 to the device.

[0101] At this point, the device and the CA node both have (m0, σ0) and (m1, σ1). They respectively execute the message verification functions MAC.Ver(K, σ0) and MAC.Ver(K′, σ1). If the results are both 1, the authentication is successful; otherwise, the authentication fails. The specific interaction process is as Figure 2 shown.

[0102] A device authentication method provided by the present invention realizes high-accuracy identification of factors and a distributed authentication system by integrating blockchain and federated learning. At the same time, based on a multi-factor authentication protocol, it is secure and reliable, requires less information for encryption and decryption, and the authentication process includes key negotiation without an additional key negotiation process.

[0103] Figure 3 is the second overall process schematic diagram of the device authentication method provided by the present invention, as Figure 3 shown, and the method includes:

[0104] Step 301: Initialization;

[0105] The number of Internet of Things devices is large and they are widely distributed. Before each device accesses the network, its identity needs to be verified to prevent malicious devices from accessing the system. If a centralized authentication method is adopted, it will bring a great computational pressure to the nodes. Therefore, a distributed authentication method should be used to authenticate Internet of Things devices. Blockchain is a decentralized distributed system. Combining with federated learning technology, it can achieve distributed authentication while ensuring the privacy of device data.

[0106] Suppose D i represents the i-th Internet of Things device, and N i represents the i-th authentication node (blockchain node), and the initialization is completed.

[0107] Step 302: Upload the radio frequency information of each electronic device to the blockchain node;

[0108] All devices upload the locally encrypted radio frequency fingerprint information and the device identifier of this machine to the adjacent blockchain node.

[0109] Step 303: Update the local model of the blockchain;

[0110] Node N i collects the radio frequency information of multiple devices as the local data set of the node, and uses the federated learning algorithm to train the model. The model update formula is:

[0111]

[0112] where represents the local model obtained from the l-th round of training of N i under the p-th global model. η represents the learning rate, and S i is the collected radio frequency information data set.

[0113] Step 304: Cross-validate the node model;

[0114] When the node completes the local model training this time, the node will generate a new block and write the model parameter information into it. At the same time, it broadcasts this information to other nodes. After each node receives the model parameters, it verifies the signature, integrity, etc. of the message.

[0115] Step 305: Aggregate the model using double weight parameters to obtain the global model;

[0116] When a certain node receives the parameter information transmitted from other nodes, it immediately aggregates the model parameters, rather than waiting for all nodes to complete training and aggregate at the same time. Therefore, it is asynchronous parameter aggregation.

[0117] In addition, double weight parameters are used to aggregate the model.

[0118]

[0119]

[0120] Among them, represents the global model obtained from the p-th training, represents the models of other nodes received by the node, and ψ (p) is a parameter function, representing the proportion of the local model in this global model, used to calculate the proportion of the local sample quantity in the total sample quantity, used to calculate the ratio of the time used for training the local model this time to the time used for the global model.

[0121] Step 306: The node runs the Pow mechanism to generate a new block;

[0122] While performing the learning and updating of the federated learning model, the node runs the Pow consensus mechanism. Once a node calculates a random number that meets the requirements, it means successful mining and a new block is generated.

[0123] Step 307: The new block is propagated in the blockchain network;

[0124] After generating a new block, the node that successfully calculates the random number required by the Pow consensus mechanism propagates the block to the entire blockchain network through broadcasting.

[0125] Step 308: The node verifies the block and updates the global model.

[0126] The above steps are repeatedly iterated until the global model achieves a good recognition accuracy for the factor.

[0127] Next, the device authentication apparatus provided by the present invention will be described. The device authentication apparatus described below can be correspondingly referred to the device authentication method described above.

[0128] Figure 4 is a schematic structural diagram of the device authentication apparatus provided by the present invention. As Figure 4 shown, the apparatus includes:

[0129] A model determination module 401, configured to determine the global model parameters of the blockchain based on the local model parameters, dual-weight parameters, and asynchronous parameter aggregation of the trained blockchain node;

[0130] An identification module 402, configured to identify the radio frequency information identity factor of the device based on the global model parameters of the blockchain and the device information;

[0131] An authentication module 403, configured to complete the two-way authentication of the device based on the multi-factor authentication protocol;

[0132] Among them, the multi-factor at least includes one or several combinations of the following: the radio frequency information identity factor of the device, the authentication factor corresponding to the access network, and a random number.

[0133] Optionally, the local model parameters of the blockchain node are trained with the radio frequency information of the device as the local data set, and the device is located near the blockchain node.

[0134] Optionally, the model determination module 401 is further configured to:

[0135] After the local model training of a specific blockchain node is completed, synchronize the local model parameters to the new block generated by the specific blockchain node and other nodes of the blockchain;

[0136] Based on the double weight parameter and asynchronous parameter aggregation, determine the global model parameters of the blockchain.

[0137] Optionally, the authentication module 403 is further configured to:

[0138] Based on the Pow consensus mechanism, determine a new block that meets the preset difficulty coefficient value, and broadcast the new block to the entire blockchain.

[0139] Optionally, the model determination module 401 is further configured to:

[0140] Based on the ratio of the local sample quantity to the total sample quantity and the ratio of the time used for the current local model training to the time used for the current global model training, determine the double weight parameter for the current global model aggregation;

[0141] Based on the previously trained global model parameters, the locally trained local model parameters of a specific blockchain node, and the double weight parameter, determine the global model parameters of the blockchain in the manner of asynchronous parameter aggregation;

[0142] If the specific blockchain node generates a corresponding new block, synchronize the local model parameters of the specific blockchain node to the corresponding new block;

[0143] Among them, the time used for the current global model training is the shortest time for the specific local model training.

[0144] Optionally, the formula for the asynchronous parameter aggregation is:

[0145]

[0146]

[0147] Among them, represents the global model obtained from the p-th global iteration, Denote the models of other nodes received by the node, ψ (p) is a double weight function, representing the proportion of the local model in this model update, used to calculate the proportion of the local sample quantity in the total samples, used to calculate the ratio of the time used for this local model training to the time used for the global model.

[0148] Optionally, the authentication module 403 is further configured to:

[0149] Determine the authentication factor corresponding to the access network of the device based on the authentication result returned by the network access request of the device;

[0150] Based on DDH, determine the radio frequency fingerprint information identity factor of the device and the identity information Data of the device i and save them to the blockchain to complete the registration phase of the multi-factor authentication protocol;

[0151] Based on the response challenge mechanism between the device and a specific blockchain node, respectively obtain the authentication challenge m0 and the first secret key K on the side of the specific blockchain node, and the authentication response m1 and the second secret key K' on the side of the device;

[0152] Based on the message verification function, respectively determine whether the verification result is 1;

[0153] If the verification results on both sides are 1, the mutual authentication of the device is successful.

[0154] It should be noted that the division of units in the embodiments of the present application is illustrative, only a logical function division, and there may be other division methods in actual implementation. In addition, in each embodiment of the present application, the functional units may be integrated in one processing unit, or each unit may exist physically alone, or two or more units may be integrated in one unit. The above integrated units may be implemented in the form of hardware or in the form of software functional units.

[0155] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a processor-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) or a processor to execute all or part of the steps of the methods described in various embodiments of this application. The aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical discs that can store program codes.

[0156] It should be noted here that the device authentication device provided by the present invention can implement all the method steps implemented by the above method embodiments and can achieve the same technical effects. Therefore, the parts and beneficial effects that are the same as those in the method embodiments in the device authentication device provided by the present invention will not be specifically described herein.

[0157] Figure 5 An example of the physical structure diagram of an electronic device is shown as Figure 5 As shown, the electronic device may include: a processor 510, a communication interface 520, a memory 530, and a communication bus 540. Among them, the processor 510, the communication interface 520, and the memory 530 communicate with each other through the communication bus 540. The processor 510 can call the computer program in the memory 530 to execute the steps of the device authentication method, for example, including:

[0158] Based on the local model parameters, double weight parameters, and asynchronous parameter aggregation of the trained blockchain nodes, determine the global model parameters of the blockchain;

[0159] Based on the global model parameters of the blockchain and the device information, identify the radio frequency information identity factor of the device;

[0160] Based on the multi-factor authentication protocol, complete the two-way authentication of the device;

[0161] Among them, the multi-factor at least includes one or several combinations of the following: the radio frequency information identity factor of the device, the authentication factor corresponding to the access network, and the random factor.

[0162] Optionally, the local model parameters of the blockchain node are trained with the radio frequency information of the device as the local data set, and the device is located near the blockchain node.

[0163] Optionally, based on the local model parameters of the trained blockchain node, double weight parameters, and asynchronous parameter aggregation, determining the global model parameters of the blockchain includes:

[0164] After the local model training of a specific blockchain node is completed, synchronize the local model parameters to the new block generated by the specific blockchain node and other nodes of the blockchain;

[0165] Based on double weight parameter and asynchronous parameter aggregation, determine the global model parameters of the blockchain.

[0166] Optionally, after the specific blockchain node generates a new block, the steps further include:

[0167] Based on the Pow consensus mechanism, determine a new block that meets the preset difficulty coefficient value, and broadcast the new block to the entire blockchain.

[0168] Optionally, the determining the global model parameters of the blockchain based on double weight parameter and asynchronous parameter aggregation includes:

[0169] Based on the ratio of the local sample quantity to the total sample quantity and the ratio of the time used for the current local model training to the time used for the current global model training, determine the double weight parameters for the current global model aggregation;

[0170] Based on the previously trained global model parameters, the locally trained model parameters of a specific blockchain node, and the double weight parameters, determine the global model parameters of the blockchain in the manner of asynchronous parameter aggregation;

[0171] If the specific blockchain node generates a corresponding new block, synchronize the local model parameters of the specific blockchain node to the corresponding new block;

[0172] Among them, the time used for the current global model training is the shortest time for the specific local model training.

[0173] Optionally, the formula for asynchronous parameter aggregation is:

[0174]

[0175]

[0176] Among them, represents the global model obtained from the p-th global iteration, represents the model of other nodes received by the node, ψ(p) is a double weight function, representing the proportion of the local model in this model update. It is used to calculate the proportion of the local sample quantity in the total samples. It is used to calculate the ratio of the time used for this local model training to the time used for the global model.

[0177] Optionally, the two-way authentication of the device based on the multi-factor authentication protocol includes:

[0178] Based on the authentication result returned by the network access request of the device, determine the authentication factor corresponding to the access network of the device;

[0179] Based on DDH, determine the radio frequency fingerprint information identity factor of the device and the identity information Data of the device i , and save them to the blockchain to complete the registration stage of the multi-factor authentication protocol;

[0180] Based on the response challenge mechanism between the device and a specific blockchain node, respectively obtain the authentication challenge m0 and the first secret key K on the side of the specific blockchain node, and the authentication response m1 and the second secret key K' on the side of the device;

[0181] Based on the message verification function, respectively determine whether the verification result is 1;

[0182] If the verification results on both sides are 1, the two-way authentication of the device is successful.

[0183] In addition, when the logical instructions in the above-mentioned memory 530 can be implemented in the form of software functional units and sold or used as an independent product, they can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art or a part of this technical solution can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. And the aforementioned storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks, or optical discs that can store program codes.

[0184] It should be noted here that the above-mentioned electronic device provided by the present invention can implement all the method steps implemented by the above-mentioned method embodiments and can achieve the same technical effects. Here, the same parts and beneficial effects of the electronic device provided by the present invention as those of the device authentication method embodiment provided by the present invention will not be specifically described in detail.

[0185] On the other hand, the present invention also provides a computer program product, which includes a computer program stored on a non-transitory computer-readable storage medium. The computer program includes program instructions. When the program instructions are executed by a computer, the computer can execute the steps of the device authentication method provided by the above-mentioned various methods, for example, including:

[0186] Based on the local model parameters of the trained blockchain nodes, the dual-weight parameters and the asynchronous parameter aggregation, determine the global model parameters of the blockchain;

[0187] Based on the global model parameters of the blockchain and the device information, identify the radio frequency information identity factor of the device;

[0188] Based on the multi-factor authentication protocol, complete the mutual authentication of the device;

[0189] Wherein, the multi-factor at least includes one or a combination of several of the following: the radio frequency information identity factor of the device, the authentication factor corresponding to the access network, and the random factor.

[0190] On the other hand, an embodiment of the present application also provides a processor-readable storage medium, which stores a computer program for causing the processor to execute the steps of the device authentication method provided by the above-mentioned various embodiments, for example, including:

[0191] Based on the local model parameters of the trained blockchain nodes, the dual-weight parameters and the asynchronous parameter aggregation, determine the global model parameters of the blockchain;

[0192] Based on the global model parameters of the blockchain and the device information, identify the radio frequency information identity factor of the device;

[0193] Based on the multi-factor authentication protocol, complete the mutual authentication of the device;

[0194] Wherein, the multi-factor at least includes one or a combination of several of the following: the radio frequency information identity factor of the device, the authentication factor corresponding to the access network, and the random factor.

[0195] The processor-readable storage medium may be any available medium or data storage device that can be accessed by the processor, including but not limited to magnetic memories (such as floppy disks, hard disks, magnetic tapes, magneto-optical discs (MO), etc.), optical memories (such as CDs, DVDs, BDs, HVDs, etc.), and semiconductor memories (such as ROMs, EPROMs, EEPROMs, non-volatile memories (NANDFLASH), solid state drives (SSD)).

[0196] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without creative effort.

[0197] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on this understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0198] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements on some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A method for device authentication, characterized in that, Including: Based on the local model parameters, double weight parameters, and asynchronous parameter aggregation of the trained blockchain nodes, determine the global model parameters of the blockchain; Based on the global model parameters of the blockchain and device information, identify the radio frequency information identity factor of the device; Based on the multi-factor authentication protocol, complete the two-way authentication of the device; Wherein, the multi-factors include: the radio frequency information identity factor of the device, the authentication factor corresponding to the access network, and a random factor; The double weight parameters include: Based on the proportion of the local sample quantity in the total sample quantity and the ratio of the time used for the current local model training to the time used for the current global model training, determine the double weight parameters for the aggregation of the current global model; Based on the global model parameters trained in the previous time, the local model parameters trained by a specific blockchain node, and the double weight parameters, determine the global model parameters of the blockchain in the manner of asynchronous parameter aggregation; Wherein, the time used for the current global model training is the shortest time for the training of the specific local model; The formula for the asynchronous parameter aggregation is: ; Among them, represents the global model obtained in the p-th global iteration, represents the models of other nodes received by the node, is a double weight function, representing the proportion of the local model in this model update, used to calculate the proportion of the local sample quantity in the total sample quantity, used to calculate the ratio of the time used for this local model training to the time used for the global model.

2. The method for device authentication according to claim 1, characterized in that The local model parameters of the blockchain node are trained with the radio frequency information of the device as the local data set, and the device is located near the blockchain node.

3. The method for device authentication according to claim 2, wherein The determining of the global model parameters of the blockchain based on the local model parameters, double weight parameters, and asynchronous parameter aggregation of the trained blockchain nodes includes: After the local model training of a specific blockchain node is completed, synchronize the local model parameters to the new block generated by the specific blockchain node and other nodes of the blockchain; Based on the double weight parameters and asynchronous parameter aggregation, determine the global model parameters of the blockchain.

4. The method for device authentication according to claim 3, wherein, After the specific blockchain node generates a new block, the method further includes: Based on the Pow consensus mechanism, determine a new block that meets the preset difficulty coefficient value, and broadcast the new block to the entire blockchain.

5. The method for device authentication according to claim 3, characterized in that, The determining of the global model parameters of the blockchain based on the double weight parameters and asynchronous parameter aggregation includes: If the specific blockchain node generates a corresponding new block, synchronize the local model parameters of the specific blockchain node to the corresponding new block.

6. The method for device authentication according to any one of claims 1 to 5, characterized in that The completing of the two-way authentication of the device based on the multi-factor authentication protocol includes: Based on the authentication result returned by the network access request of the device, determine the authentication factor corresponding to the access network of the device; Based on DDH, determine the identity factor of the radio frequency fingerprint information of the device and the identity information of the device , and save them to the blockchain to complete the registration phase of the multi-factor authentication protocol; Based on the response challenge mechanism between the device and a specific blockchain node, obtain the authentication challenge on the side of the specific blockchain node respectively and the first secret key , and the authentication response on the side of the device and the second secret key ; Based on the message verification function, respectively determine whether the verification results are 1; If the verification results on both sides are 1, the two-way authentication of the device is successful.

7. A device authentication apparatus, characterized in that, Including: A model determination module, configured to determine the global model parameters of the blockchain based on the local model parameters, double weight parameters, and asynchronous parameter aggregation of the trained blockchain nodes; An identification module, configured to identify the radio frequency information identity factor of the device based on the global model parameters of the blockchain and device information; An authentication module, configured to complete the two-way authentication of the device based on the multi-factor authentication protocol; Wherein, the multi-factors include: the radio frequency information identity factor of the device, the authentication factor corresponding to the access network, and a random number; The model determination module is specifically configured to: Determine the dual-weight parameters for aggregating the current global model based on the ratio of the number of local samples to the total number of samples and the ratio of the time taken for training the current local model to the time taken for training the current global model; Based on the parameters of the previously trained global model, the parameters of the local model trained by a specific blockchain node, and the dual-weight parameters, determine the global model parameters of the blockchain in an asynchronous parameter aggregation manner; Among them, the time used for training the current global model is the shortest time for training the specific local model; The formula for the asynchronous parameter aggregation is: ; Among them, represents the global model obtained in the p-th global iteration, represents the models of other nodes received by the node, is a double weight function, representing the proportion of the local model in this model update, is used to calculate the proportion of the local sample quantity in the total sample quantity, is used to calculate the ratio of the time used for this local model training to the time used for the global model.

8. An electronic device for device authentication, comprising a processor and a memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method for device authentication described in any one of claims 1 to 6.

9. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the method for device authentication described in any one of claims 1 to 6.

Citation Information

Patent Citations

  • College graduate intelligent recruitment information pushing method and system based on blockchain, and terminal equipment

    CN112307331A

  • Internet of Things personalized federal learning method based on blockchain

    CN113052331A