A two-factor authentication method for mobile terminal based on spatial magnetic field signal

By utilizing the spatial magnetic field signal generated by the CPU utilization change of mobile devices, the physical fingerprint and password sequence of the device are extracted for two-factor authentication. This solves the problems of insufficient user participation and security in existing technologies, and realizes efficient and secure mobile device authentication without user intervention.

CN115438331BActive Publication Date: 2026-05-22HUNAN UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
HUNAN UNIV
Filing Date
2022-07-20
Publication Date
2026-05-22

AI Technical Summary

Technical Problem

Existing mobile device authentication technologies require active user participation and are vulnerable to man-in-the-middle and coordinated location attacks, resulting in poor security. They fail to meet the security and convenience requirements arising from the increasing number of mobile devices and longer user usage time.

Method used

By utilizing the spatial magnetic field signal generated when the CPU utilization of a mobile device changes, the signal is collected and processed by a magnetic sensor to extract the device's physical fingerprint and password sequence for two-factor authentication. The device's own hardware features are used for legitimacy verification, avoiding user intervention and the introduction of additional sensor hardware.

Benefits of technology

It achieves secure and convenient identity authentication without requiring active user participation, can resist various attack methods, improves the security and authentication efficiency of mobile device systems, and is suitable for mobile devices that lack interactive hardware or have inconsistent sensors.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115438331B_ABST
    Figure CN115438331B_ABST
Patent Text Reader

Abstract

The application discloses a two-factor identity authentication method of a mobile terminal device based on a space magnetic field signal. First, a user closely attaches a verification device used for checking a legal identity to a body surface of a login device provided with a magnetic sensor, and changes a space magnetic field signal of an environment around the device by running a regular CPU occupancy rate change program arranged in the verification device, so that the change can be collected by the magnetic sensor in the login device. Second, the collected signal is filtered, the filtered signal is subjected to feature extraction, and two features of a physical feature only related to a hardware characteristic between the verification device and the login device and a password sequence composed of a regular change of the CPU occupancy rate are extracted. The extracted features are compared with information left by the verification device during registration, so that the identity legality of the verification device is checked.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention mainly relates to the field of mobile device identity authentication. It mainly studies the characteristics of mobile devices radiating magnetic field signals into space under different CPU utilization load conditions, the principle that devices are bound only to the characteristics of the hardware itself, the spatial magnetic field response characteristics induced by the regular changes in the CPU of the device, the reconstruction method of program password sequence under high noise, and the method of device physical fingerprint extraction and verification, etc., to realize two-factor authentication technology. Background Technology

[0002] Mobile devices have experienced rapid development in recent years and are now widely used in various aspects of life. Common mobile devices include handheld game consoles, smartphones, fitness trackers, and tablets. Data from digital analysts at the GSMA (Global System for Mobile Communications Association) shows that in 2014, the number of mobile devices in the world exceeded the human population. App Annie's "2022 State of Mobility Report" shows that global mobile device usage reached a record high of 3.8 trillion hours in 2021. The rapid rise of the mobile device industry has not only drastically changed lifestyles but also significantly improved social efficiency and convenience. At the same time, it has brought new and severe challenges to the protection of information security for nations, businesses, and individuals. Mobile device authentication technology is the first line of defense for information security, playing an irreplaceable role in preventing information leaks and combating system intrusions. Traditional mobile device authentication technologies all require varying degrees of active user participation in the authentication process and are vulnerable to man-in-the-middle attacks and coordinated location attacks. The increasing number of mobile devices and the increasing time users spend on them pose new requirements for mobile device authentication technology. Therefore, developing new mobile device identity authentication technologies to verify the legitimacy of mobile device identities, thereby ensuring the security of mobile systems and the privacy of data, and meeting the national requirements for security, reliability, and convenience in mobile device infrastructure, is urgent and of great significance in the current era.

[0003] Currently, the widely used and researched mobile device identity authentication technologies mainly include the following three types: (1) The system sends a notification to the verification device to approve the login, and the user manually confirms the authentication information; (2) The user answers a call from the system to the registered device and presses the button to approve the login authentication information; (3) The user enters the password sequence sent by the system to the verification device or automatically generated by the verification device on the login interface and compares the authentication information.

[0004] All of the above authentication methods require varying degrees of active user participation in the authentication process, and their security is relatively poor, making them vulnerable to various security threats such as brute-force attacks, replay attacks, identity theft, password theft, man-in-the-middle attacks, and coordinated location attacks. To improve the user experience on mobile devices while ensuring the security of identity authentication information, it is necessary to research and develop a new identity authentication technology that is universally applicable, secure, efficient, and convenient, enabling multi-scenario application of user identity verification on mobile devices. This is also an urgent need and a challenge of our time in the context of the rapid development of mobile devices.

[0005] In recent years, research and application of space magnetic field signals have developed rapidly. Space magnetic field signals are no longer simply used as geomagnetic compasses, but are widely applied in various technical fields such as energy utilization, information carriers, detection tools, measurement and control positioning, and equipment authentication, providing a new approach and option for mobile device authentication. When a mobile device runs a program with regularly changing CPU usage, its hardware circuits generate alternating electrical signals. As shown by Maxwell's equations, alternating currents can induce changing space magnetic field signals in the surrounding environment. These alternating space magnetic field signals are often considered as device operating noise, but this noise can be received by magnetic sensors. This noise provides random signals or information entropy for mobile device authentication because magnetic sensors are universally applicable to most mobile devices, eliminating the need for additional sensors to collect and process them. This points to a new direction for authentication research, but how to utilize these signals to make authentication more secure, convenient, and efficient remains a challenge. Summary of the Invention

[0006] To achieve the above objectives, we propose a two-factor authentication method for mobile devices based on spatial magnetic field signals. The implementation scheme is as follows: First, the user places a verification device (used to verify legitimacy) against the surface of a login device equipped with a magnetic sensor. Then, a program that tracks regular CPU usage changes on the verification device is run. Second, this CPU usage change program causes changes in the spatial magnetic field signal of the surrounding environment. These changes are detected by the magnetic sensor inside the login device. Through processing and analysis of these signals, a physical fingerprint, which is only related to hardware characteristics between devices, and a password sequence constructed by the CPU usage change program running on the verification device are extracted. Finally, the extracted physical fingerprint and password sequence are compared with the features from previous device registration to verify whether the device is legitimate.

[0007] Our authentication method is based on the following:

[0008] (1) The unique physical characteristics caused by manufacturing defects in the equipment, as well as the spatial magnetic field signal radiated by the change in CPU utilization within the equipment itself, are used to complete the identity authentication of mobile devices. This method does not require the introduction of additional sensor hardware and can be universally applied to situations where mobile devices lack interactive hardware or where sensors are not standardized.

[0009] (2) By using the password sequence of the custom CPU utilization regular change program running on the verification device and the physical fingerprint between devices that is only related to the hardware characteristics, the device has dual authentication of the legitimate identity of the mobile device, which can resist various attack methods such as password theft and identity theft, and improve the security of the mobile device system.

[0010] (3) By using a program that tracks regular CPU usage changes to complete identity authentication, the program essentially replaces the traditional method of user interaction during mobile device authentication. This not only provides users with a secure and convenient mobile experience but also effectively improves authentication efficiency.

[0011] Therefore, this method, as a brand-new identity authentication technology, is a supplement and extension to existing identity authentication methods. It not only has the advantage of not requiring users to actively cooperate with the authentication process, but also enables universal, secure and rapid verification of the legitimacy of mobile device users' identities, greatly improving the user's secure and convenient experience on mobile devices.

[0012] Technical solution

[0013] Registration phase:

[0014] Step 1. The user places the verification device close to the outer surface of the login device. After placement, a program that regularly changes the CPU usage rate will run to affect the surrounding magnetic field signal, causing it to change.

[0015] Step 2. Log in to the device to collect the changing spatial magnetic field signal and store it in the device's storage unit;

[0016] Step 3. After collecting signals over a certain period of time, the device extracts features from the signals and divides the extracted signal data into training datasets and test datasets.

[0017] Step 4. Train the classifier using the training dataset obtained in Step 3 to obtain the trained classifier.

[0018] Step 5. Use the test dataset obtained in Step 3 to test the trained classifier obtained in Step 4, and repeat Steps 4 and 5 until the classifier finally passes the test and the certified classifier is obtained.

[0019] Certification phase:

[0020] Step 6. The user places the verification device on the same outer surface of the device as the login device during the registration phase. After placement, a program that regularly changes the CPU usage rate will run to affect the surrounding magnetic field signal, causing it to change.

[0021] Step 7. Log in to the device to collect the space magnetic field signal and store it in the device's storage unit;

[0022] Step 8. Log in to the device, extract features from the signals obtained in Step 7, and use the authentication classifier obtained in Step 5 to classify the extracted data and obtain the classification results.

[0023] The two-factor authentication method for mobile devices based on space magnetic field signals further includes the following steps:

[0024] The program behavior described in Step 1 and Step 6 specifically refers to the CPU utilization rate regular change program running when using the verification device to verify the identity of the mobile device.

[0025] The login device described in Steps 2 and 7 collects space magnetic field signals. Specifically, the magnetic sensor (MagneticSensorEnabled) inside the login device can sense and collect space magnetic field signals.

[0026] The feature extraction described in Steps 3 and 8 specifically involves extracting features from the acquired signals using the following steps:

[0027] A. Noise reduction of the acquired space magnetic field signals;

[0028] B. Extract the physical fingerprint of the device in multiple dimensions such as time domain, frequency domain, and statistics;

[0029] C. Extract the password sequence generated by the verification device during the program that shows regular changes in CPU utilization.

[0030] The classifier mentioned in Step 4 is an authentication classifier.

[0031] The authentication classifier is specifically selected by using the following method to determine the optimal classifier:

[0032] Regarding the physical fingerprint of the device, machine learning classification algorithms will be used to train it based on multiple dimensions of features, including time domain features, frequency domain features, and statistical features.

[0033] In verifying the password sequence generated by the device's running program, rhythm extraction is required to extract the corresponding password sequence. Furthermore, to reduce the error caused by the same device running at different times, fuzzy matching and other methods are used to solve the error problem. Attached Figure Description

[0034] Figure 1 This is the research plan for the design;

[0035] Figure 2 Equivalent magnetic field coordinates for spatial alignment of the equipment after eliminating geomagnetic and ambient magnetic fields;

[0036] Figure 3 The password sequence for the extracted device's CPU usage change program;

[0037] Figure 4 Here is a flowchart of the two-factor authentication process;

[0038] Figure 5 The magnetic field cosine similarity curves collected by the noise-reduced device under different conditions;

[0039] Figure 6 The curve showing the effect of changes in CPU utilization during device operation on the magnetic field.

[0040] Figure 7 The attached figure is for the abstract. Detailed Implementation

[0041] The present invention will be further described below with reference to the accompanying drawings.

[0042] like Figure 1 As shown

[0043] Registration phase:

[0044] Step 1. Verify that the device influences the surrounding magnetic field radiation signal by running a CPU program that changes regularly, causing it to change.

[0045] Step 2. Log in to the device to collect (via the magnetic sensor inside the mobile device) the spatial magnetic field signal and store it in the device's storage unit;

[0046] Step 3. After collecting signals over a certain period of time, log in to the device to extract features, and divide the extracted signal data into training and testing datasets; the specific steps for feature extraction are as follows:

[0047] A. Noise reduction of the acquired space magnetic field signals;

[0048] B. Extract the physical fingerprint of the device in multiple dimensions such as time domain, frequency domain, and statistics;

[0049] C. Extract and verify the password sequence generated by the program that verifies the regular changes in CPU utilization during the operation of the device;

[0050] Because the data collected by the magnetic sensor in the login device also includes ambient white noise, power supply magnetic field noise, and magnetic field noise from other electronic devices, it needs to be denoised. The denoising result is as follows: Figure 5 Although the noise-reduced signal can already serve as a feature to distinguish different devices, in order to improve the accuracy of authentication, the method of this invention adopts the following scheme:

[0051] To extract more accurate physical fingerprints, we employ various signal features, which we will explain in detail in the time domain, frequency domain, and statistical aspects:

[0052] a) Time-domain dimension features: The amplitude of the acquired signal is fitted in the time domain to obtain a high-dimensional approximate curve, and the polynomial coefficients of the curve are used as the feature T of the signal in the time dimension.

[0053] b) Frequency domain dimension features: Fourier transform of the signal to obtain Fourier coefficients as the frequency features F of the signal.

[0054] c) Statistical dimensional features: The statistical features of the signal include the maximum value, minimum value, mean, median, root mean square (RMS), standard deviation (StD), Kurtosis, Skewness, IQR, sharpness, slope sign change, Willisson Amplitude, etc., as features S.

[0055] To extract the password sequence generated by the program that shows regular changes in CPU utilization while the verification device is running, we adopt the methods of envelope extraction and window segmentation, as follows:

[0056] Envelope extraction:

[0057] After signal denoising, in order to obtain a clearer image of the signal amplitude changes when the verification device is running the program, we use an envelope extraction algorithm to further process the denoised signal, extract clearer amplitude changes, and locate and segment the high / low CPU utilization rhythm based on the drastic amplitude value changes caused by changes in CPU utilization and the response characteristics of program operation.

[0058] Window splitting:

[0059] We use the high CPU utilization runtime, low CPU utilization runtime, and relative high / low CPU utilization runtime as references for constructing the program password sequence: within a relative program runtime (a time period from the start to the end of program execution), the signal segment is divided into N windows. The window segment within the high CPU utilization time is identified as 1, and the window segment within the low CPU utilization time is identified as 0, thereby generating a program password sequence.

[0060] Step 1. Use the training dataset obtained in Step 3 to train the classifier, thereby obtaining the trained classifier;

[0061] Step 2. Test the trained classifier obtained in Step 4 using the test dataset acquired in Step 3, and repeat Steps 4-5 until the classifier passes the test, obtaining the final authentication classifier. To achieve the best authentication accuracy, the specific steps are as follows:

[0062] Based on the feature extraction in Step 3, features from multiple dimensions such as time domain features, frequency domain features, and statistical features can be obtained. However, the optimal classifiers for various features of physical fingerprints may not be consistent. The present invention proposes a method:

[0063] First, multiple machine learning classification algorithms are used to calculate the impact of each feature parameter on the classifier's decision result using Fisher Score. The set of signal features with the highest accuracy in distinguishing devices is selected as the best classifier for each feature. Then, a classifier voting strategy is used to determine the final verification result.

[0064] For the password sequence generated by the device's running program, slight deviations may occur during verification when the CPU utilization change program is running. For example, the CPU utilization change sequence may be similar but the speed may be slower / faster, causing the generated password sequence to not completely match the password sequence recorded by the login device. The present invention specifically adopts the following solution:

[0065] The dynamic time warping algorithm is used to reduce the time-domain extension or compression of the CPU utilization signal, and the Hamming distance between the generated password sequence and the registered sequence is compared. Sequences that do not exceed a certain error distance are allowed to be identified as program running passwords of the same device.

[0066] Certification phase:

[0067] Step 1. Verify that the device influences the surrounding magnetic field radiation signal by running a CPU program that changes regularly, causing it to change.

[0068] Step 2. Log in to the device to collect (via the magnetic sensor inside the mobile device) the spatial magnetic field signal and store it in the device's storage unit;

[0069] Step 3. After collecting signals over a certain period of time, log in to the device to extract features from them, and then use the authentication classifier obtained in Step 5 to classify the extracted data and obtain the classification results. The specific steps for feature extraction are as follows:

[0070] A. Noise reduction of the acquired space magnetic field signals;

[0071] B. Extract the physical fingerprint of the device in multiple dimensions such as time domain, frequency domain, and statistics;

[0072] C. Extract and verify the password sequence generated by the program that verifies the regular changes in CPU utilization during the operation of the device;

[0073] The two-factor authentication method for mobile devices based on spatial magnetic field signals proposed in this invention differs significantly from traditional authentication methods. First, traditional authentication methods all require users to actively participate in the authentication process to varying degrees. However, this solution utilizes the spatial magnetic field signal radiated by the change in the CPU utilization of the mobile device itself to complete the authentication of the mobile device, without requiring the user to actively participate in the authentication process. Moreover, this method does not require the introduction of additional sensor hardware and can be universally applicable to situations where mobile devices lack interactive hardware or have inconsistent sensors. Second, traditional solutions typically only employ the following methods: (1) the system sends a notification to the verification device to approve login, and the user manually confirms; (2) the user answers a phone call from the system to the registration device and presses the button to approve login; (3) the user enters the password sent by the system to the verification device or automatically generated by the verification device on the login interface. These methods are susceptible to various attack methods such as imitation attacks, shoulder spying attacks, man-in-the-middle attacks, and collaborative positioning attacks. In contrast, this solution uses a password sequence generated by the regular change in the CPU utilization of the device running to perform two-factor authentication and a physical fingerprint, which can resist various attack methods such as password theft and identity theft, thereby improving the security of the mobile device system. Third, this invention uses a program that tracks regular CPU usage changes to complete identity authentication, essentially replacing the traditional interactive method required for user authentication on mobile devices. This not only provides a secure and convenient user experience on mobile devices but also effectively improves authentication efficiency.

[0074] Therefore, this invention, as a novel mobile device authentication scheme, not only improves the efficiency of users verifying their legitimacy by verifying the device, but also solves a current problem in the authentication field: mobile device authentication processes all require users to actively cooperate to varying degrees, which is very cumbersome for users. This invention, however, has the advantage of eliminating the need for active user cooperation in the authentication process, using device software to replace this process, greatly improving the user's secure and convenient experience on mobile devices. Therefore, it is a universal, secure, convenient, and efficient two-factor authentication invention for mobile devices.

Claims

1. A two-factor authentication method for mobile devices based on spatial magnetic field signals, comprising the following steps: Step 1: Verify that the device is firmly attached to the surface of the login device to perform mobile device identity authentication; Step 2: Log in to the device's internal magnetic sensor to collect spatial magnetic field signals; Step 3: Perform noise reduction processing on the collected signals to remove interference from surrounding environmental noise and strong magnetic fields; Step 4: Segment the noise-reduced signals; Step 5: Construct a password sequence based on physical fingerprints and CPU usage changes; Step 6: Verify the legitimacy of the mobile device's identity. Specifically, step 5 includes: a) Physical fingerprint extraction: During the high CPU utilization phase, physical fingerprints related only to the hardware features between the verification device and the login device are extracted from multiple dimensions of features, including time domain features, frequency domain features, and statistical features; b) Password sequence extraction: Based on the different operating phases of high or low CPU utilization, the relative running time of high or low CPU utilization is extracted. Based on the length of the relative running time of high or low CPU utilization and the segmentation of high CPU utilization operation and low CPU utilization operation, the password sequence of CPU utilization change is extracted.

2. The method according to claim 1, step 1 specifically includes the user first attaching the verification device used to verify legitimate identity to the surface of the login device equipped with a magnetic sensor, and then running a program set on the verification device to track regular CPU usage changes.

3. The method according to claim 1, step 2 specifically includes the change in the spatial magnetic field signal of the surrounding environment caused by the change in CPU occupancy inside the device, which can be collected by the magnetic sensor inside the device.

4. The method according to claim 1, step 3 specifically includes denoising the signal acquired by the magnetic sensor: using wavelet transform, Gaussian filter, low-pass and band-stop filter to filter and denoise the received signal, thereby reducing environmental noise and signal pollution from other electronic devices.

5. The method according to claim 1, step 4 specifically includes dividing the noise-reduced signal into three stages: a high CPU utilization operation stage, a low CPU utilization operation stage, and a high or low CPU utilization switching stage.

6. The method according to claim 1, step 6 specifically includes the following operations when finally verifying the legitimacy of the mobile device's identity: First step: The user places the verification device on the surface of the login device in the same position as during registration; Step 2: Run the program set to verify changes in CPU usage on the device; Step 3: After the magnetic sensor of the login device collects the corresponding signal, it is processed in steps 3 to 5 to extract the physical fingerprint of the device and the password sequence of CPU usage changes. Step 4: Compare the extracted information with the information registered during device registration. Use DTW and Hamming distance algorithms as the measurement standard. If the error distance d is within the tolerable range, the device is considered legitimate.