A device access verification system based on an internet of things gateway
By collecting and analyzing information about devices to be connected in real time and performing multi-factor authentication, the problem of insecure access caused by gateway authentication service anomalies is solved, and dual authentication and security verification of devices are realized, thereby improving the security of the network boundary.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- SHENZHEN ZHUTAI TECH CO LTD
- Filing Date
- 2023-01-29
- Publication Date
- 2026-05-05
AI Technical Summary
In traditional centralized network architectures, when the gateway authentication service malfunctions, a large number of insecure users can access the network, making it difficult to effectively protect internal network resources.
By collecting information about devices to be connected in real time, analyzing the devices and obtaining verification results, and performing comprehensive security authentication based on multiple verification modules, the qualification and security of the devices are ensured.
It implements dual authentication for access devices, preventing unknown or insecure users from accessing the network and improving the security and reliability of the network boundary.
Smart Images

Figure CN116170199B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of Internet of Things (IoT) technology, and in particular to a device access verification system based on an IoT gateway. Background Technology
[0002] Currently, with the widespread adoption of the internet and the booming development of industries such as mobile office, IoT, and connected vehicles, network architectures are becoming increasingly complex. Defining a company's network boundaries and protecting internal network resources deployed in various locations has become a challenge for many large enterprises. Identity authentication and edge access are essential capabilities for these companies. The edge network refers to the last segment of the network used to access users. However, in traditional centralized network architectures, user terminal devices need to be authenticated at the network gateway. If the gateway's authentication service malfunctions, a large number of insecure users will access the network.
[0003] Therefore, this invention proposes a device access verification system based on an Internet of Things gateway. Summary of the Invention
[0004] This invention provides a device access verification system based on an IoT gateway. It collects information about devices to be accessed in real time, stores and transmits this information to a device analysis processor to obtain device analysis results. Based on these results, it sends a pass / fail verification request to the gateway device to obtain a first verification result. Then, based on the device analysis results, it performs security verification on each device to be accessed to obtain a second verification result. Finally, it performs comprehensive security authentication on the devices to be accessed based on both the first and second verification results. This solves the problem in the prior art where a large number of insecure users access the system if the gateway's authentication service malfunctions.
[0005] This invention proposes a device access verification system based on an IoT gateway, comprising:
[0006] Information acquisition module: used to collect information of devices to be connected in real time, store the collected information and transmit it to the device analysis processor to obtain the device analysis results;
[0007] First verification module: Used to send a qualified verification request to the gateway device and obtain the first verification result for the same device to be connected;
[0008] The second verification module is used to perform security verification on the corresponding device to be connected based on the device analysis results, and obtain the second verification result.
[0009] Security authentication module: used to perform comprehensive security authentication on the same device to be connected based on the first verification result and the second verification result.
[0010] Preferably, the information collection module includes:
[0011] Detection unit: Used to detect in real time whether a device sends an access gateway request; if so, it generates a device acquisition command.
[0012] The acquisition unit is used to acquire information about the device to be connected according to the device acquisition command.
[0013] The transmission unit is used to transmit the information of the device to be accessed to the device analysis processor via the 5G network and start its device analysis function.
[0014] The receiving unit is used to receive and statistically analyze the device analysis results of the device analysis processor for each device to be accessed. The device analysis results include: device type, device hardware and software information, and device security information.
[0015] Preferably, the first verification module includes:
[0016] First acquisition unit: used to acquire the unique identifier of each device to be connected based on the device analysis results;
[0017] Generation unit: used to generate a question-based verification code for each device to be accessed based on its unique identifier.
[0018] Detection unit: used to receive verification information from each device to be connected in response to the question-and-answer verification code, and to detect whether the verification information is valid;
[0019] The first verification unit is configured to verify that the verification is successful if the verification information matches the standard answer, and unsuccessful if the verification information does not match the standard answer.
[0020] Preferably, the second verification module includes:
[0021] The second acquisition unit is used to acquire the network security attributes and device security attributes of each device to be accessed based on the device analysis results.
[0022] The parsing unit is used to parse the network security attributes and device security attributes of each device to be accessed, and determine the device's own security and device network access security based on the parsing results.
[0023] The second verification unit is used to perform security verification on the device to be accessed based on the device's own security and the device's network access security, and to obtain the second verification result.
[0024] Preferably, the security authentication module includes:
[0025] The first extraction unit is used to extract the first verification parameter from the first verification result and, at the same time, extract the second verification parameter from the second verification result.
[0026] The second extraction unit is used to extract security authentication indicators from the first verification parameters and the second verification parameters.
[0027] The startup unit is used to initiate a preset security authentication program.
[0028] The authentication unit is used to perform comprehensive security authentication on the security authentication indicators using the preset security authentication procedure.
[0029] Preferred options also include:
[0030] The first acquisition module is used to acquire device indication information based on the authentication information of each device to be connected;
[0031] The second acquisition module is used to obtain the deployment encryption level of each device to be accessed based on the device indication information of each device to be accessed.
[0032] The selection module is used to select the appropriate access protocol based on the deployment encryption level of each device to be connected;
[0033] The access module is used to connect each device to the IoT gateway according to its access protocol.
[0034] Preferably, the second verification unit includes:
[0035] The generation subunit is used to generate a set of security verification indicators for each device to be accessed based on the weights of the device's own security-related indicators and the weights of the device's network access security-related indicators.
[0036] The sub-unit is determined to identify the data type of each security indicator in the security verification indicator set for each device to be connected.
[0037] The verification subunit is used to select a verification channel to perform security verification on each security indicator based on the data type of each security indicator in the security verification indicator set of each device to be accessed.
[0038] The calculation unit is used to perform weighted calculations on the verification results of each security indicator in the security verification indicator set of each device to be accessed to determine the security index of the device to be accessed.
[0039] Preferably, the judgment module is used to obtain the deployment encryption level of each device to be accessed based on the device indication information of that device, including:
[0040] The second acquisition unit is used to acquire the authorization and non-authorization information of each device to be accessed based on the device indication information of each device to be accessed.
[0041] The first determining unit is used to determine the gateway permission function information corresponding to the authorized permission information and the unauthorized permission information respectively;
[0042] The second determining unit is used to determine the permission level corresponding to the gateway permission function information;
[0043] The fourth acquisition unit is used to obtain the deployment encryption level of each device to be connected based on the permission level corresponding to the gateway permission function information.
[0044] Preferably, the second acquisition unit acquires the authorization and non-authorization information of each device to be accessed based on the device indication information of that device, including:
[0045] Trigger commands to retrieve each permission information;
[0046] Based on the trigger command, the command response information is retrieved from the device indication information of each device to be connected;
[0047] Determine the current matching degree between the trigger command for each permission information and the command response information of that permission information in the device indication information of each device to be connected;
[0048] First permission information with a current matching degree greater than or equal to a preset matching degree is confirmed as authorized permission information, and second permission information with a current matching degree less than the preset matching degree is initially confirmed as unauthorized permission information;
[0049] Obtain the permission seed corresponding to each second permission information;
[0050] The permission seeds are subjected to multi-dimensional behavioral evaluation to obtain evaluation results. Based on the evaluation results, the permission type of each second permission information is determined. The permission types include: normal permissions and advanced permissions.
[0051] Determine the relevant indicators for permission evaluation for each second permission information based on the permission type of each second permission information;
[0052] Obtain the associated permission evaluation index for each second permission information from the instruction response information of each device to be connected, and determine the missing permission evaluation index based on the similarity interval of the permission evaluation related index and the associated permission evaluation index.
[0053] Retrieve the associated device data for the missing permission assessment indicators from the device indication information of each device to be connected;
[0054] The associated device data is evaluated for permissions according to the evaluation rules of the missing permission evaluation index. If the permission evaluation result is that the associated device data meets the permission usage conditions, the second permission information is confirmed as authorized permission information. If the permission evaluation result is that the associated device data does not meet the permission usage conditions, the second permission information is further confirmed as unauthorized permission information.
[0055] Preferably, after the second acquisition module obtains the deployment encryption level of each device to be accessed based on the device indication information of each device to be accessed, the system is further configured to:
[0056] Deploy a gateway node for each device to be connected based on its encryption level, and obtain the deployment results.
[0057] Generate a gateway device deployment plan based on the deployment results, and obtain the access devices to be allocated for each gateway node based on the gateway device deployment plan;
[0058] Obtain the node-allocated load of each gateway node, and determine the network communication cost index of that gateway node based on the node-allocated load of each gateway node.
[0059] Determine the virtual hop count and communication delay coefficient for each gateway node under the network communication cost index;
[0060] Based on the node load allocation, network communication cost index, and virtual hop count and communication latency coefficient of each gateway node under the network communication cost index, the device deployment difficulty coefficient of each gateway node is calculated:
[0061]
[0062] Among them, F i Let R1 represent the device deployment difficulty coefficient of the i-th gateway node, and let Q represent the random weight value of the first system. i Let Q represent the load allocated to the i-th gateway node, Q represent the reference threshold for the load allocation to maintain optimal performance of the gateway node, R2 represent the random weight value of the second system, and G represent the load allocation value. i Let D be the network communication cost index of the i-th gateway node. i Let α represent the virtual hop count of the i-th gateway node, D represent the reference threshold for the virtual hop count of a node under standard conditions, and α represent the virtual hop count of the node. i Let S be the communication delay coefficient of the i-th gateway node. i β represents the proportion of network overhead incurred when data is transmitted by the i-th gateway node, e is the natural constant with a value of 2.72, and β i This represents the current performance index of the i-th gateway node;
[0063] Based on the device deployment difficulty coefficient of each gateway node, select the best suitable access device from the available access devices to be assigned to that gateway node;
[0064] Among them, the higher the deployment difficulty coefficient, the higher the performance score of the selected access device should be.
[0065] Other features and advantages of the invention will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention may be realized and obtained by means of the structures particularly pointed out in the written description, claims, and drawings.
[0066] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. Attached Figure Description
[0067] The accompanying drawings are provided to further illustrate the invention and form part of the specification. They are used in conjunction with embodiments of the invention to explain the invention and do not constitute a limitation thereof. In the drawings:
[0068] Figure 1 This is a structural diagram of a device access verification system based on an IoT gateway in an embodiment of the present invention;
[0069] Figure 2 This is another structural diagram of a device access verification system based on an IoT gateway in an embodiment of the present invention. Detailed Implementation
[0070] The preferred embodiments of the present invention will be described below with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are for illustration and explanation only and are not intended to limit the present invention.
[0071] Example 1:
[0072] This invention provides a device access verification system based on an IoT gateway, such as... Figure 1 As shown, the system includes:
[0073] Information acquisition module: used to collect information of devices to be connected in real time, store the collected information and transmit it to the device analysis processor to obtain the device analysis results;
[0074] First verification module: Used to send a qualified verification request to the gateway device and obtain the first verification result for the same device to be connected;
[0075] The second verification module is used to perform security verification on the corresponding device to be connected based on the device analysis results, and obtain the second verification result.
[0076] Security authentication module: used to perform comprehensive security authentication on the same device to be connected based on the first verification result and the second verification result.
[0077] In this embodiment, the device information to be accessed is the device information that is about to access the gateway, such as whether the device is a tablet, computer or mobile phone, the device model and the device's hardware and software information.
[0078] In this embodiment, the device analysis processor analyzes the device model and its hardware and software information.
[0079] In this embodiment, the qualification verification is, for example, sending the last four digits of the phone number to the device or asking for the correct pattern to check whether the device is qualified. If the answer is correct, it proves that the device is qualified.
[0080] In this embodiment, security verification verifies whether the device is secure. For example, if the phone contains an unsafe Trojan or virus, then the phone is determined to be unsafe and cannot be connected.
[0081] The beneficial effects of the above technical solution are: by analyzing the real-time collected information of the devices to be accessed and obtaining the analysis results, the devices are qualified and secure based on the analysis results, and finally a comprehensive verification is performed, which can perform dual authentication of the devices and prevent unknown or insecure users from accessing the gateway.
[0082] Example 2:
[0083] This invention provides a device access verification system based on an IoT gateway, such as... Figure 2 As shown, the information collection module includes:
[0084] Detection unit: Used to detect in real time whether a device sends an access gateway request; if so, it generates a device acquisition command.
[0085] The acquisition unit is used to acquire information about the device to be connected according to the device acquisition command.
[0086] The transmission unit is used to transmit the information of the device to be accessed to the device analysis processor via the 5G network and start its device analysis function.
[0087] The receiving unit is used to receive and statistically analyze the device analysis results of the device analysis processor for each device to be accessed. The device analysis results include: device type, device hardware and software information, and device security information.
[0088] In this embodiment, the acquisition command is a command for the device to acquire data.
[0089] In this embodiment, the device analysis processor analyzes the device model and its hardware and software information.
[0090] The beneficial effects of the above technical solution are: by detecting whether a device sends an access gateway request, collecting device information and sending it to the device analysis processor to obtain analysis results, it is possible to obtain the device information of the device to be accessed in a timely manner, laying the foundation for subsequent security verification.
[0091] Example 3:
[0092] This invention provides a device access verification system based on an IoT gateway, comprising a first verification module, including:
[0093] First acquisition unit: used to acquire the unique identifier of each device to be connected based on the device analysis results;
[0094] Generation unit: used to generate a question-based verification code for each device to be accessed based on its unique identifier.
[0095] Detection unit: used to receive verification information from each device to be connected in response to the question-and-answer verification code, and to detect whether the verification information is valid;
[0096] The first verification unit is configured to verify that the verification is successful if the verification information matches the standard answer, and unsuccessful if the verification information does not match the standard answer.
[0097] In this embodiment, the unique identifier is a 128-bit identifier that each device has, which is a unique and universally recognized identifier used in the computer system to identify the number of device information.
[0098] In this embodiment, the question-based verification code is, for example, the last four digits of a mobile phone number or the selection of the correct pattern.
[0099] In this embodiment, the verification information is the answer entered by the user, which is used to verify whether the device is qualified.
[0100] The beneficial effects of the above technical solution are: by generating a question-based verification code for the device, allowing the user to answer and compare it with the standard answer, the system can quickly determine whether the device to be connected is qualified.
[0101] Example 4:
[0102] This invention provides a device access verification system based on an IoT gateway, comprising a second verification module:
[0103] The second acquisition unit is used to acquire the network security attributes and device security attributes of each device to be accessed based on the device analysis results.
[0104] The parsing unit is used to parse the network security attributes and device security attributes of each device to be accessed, and determine the device's own security and device network access security based on the parsing results.
[0105] The second verification unit is used to perform security verification on the device to be accessed based on the device's own security and the device's network access security, and to obtain the second verification result.
[0106] In this embodiment, network security attributes are one of the elements for network security assessment. Internet applications are identified by creating network application names of devices to be accessed, server operating systems, and content management systems.
[0107] In this embodiment, device security attributes are one of the elements for security assessment of a device, and can be device security and media security, used to ensure the hardware and software security of the device.
[0108] The beneficial effects of the above technical solution are: by parsing the security attributes of the device and the network security attributes of the device to be connected, the security of the device and the network can be obtained, and the security of the device can be verified in a timely manner to determine whether the device contains Trojans or viruses.
[0109] Example 5:
[0110] This invention provides a device access verification system based on an IoT gateway, including a security authentication module comprising:
[0111] The first extraction unit is used to extract the first verification parameter from the first verification result and, at the same time, extract the second verification parameter from the second verification result.
[0112] The second extraction unit is used to extract security authentication indicators from the first verification parameters and the second verification parameters.
[0113] The startup unit is used to initiate a preset security authentication program.
[0114] The authentication unit is used to perform comprehensive security authentication on the security authentication indicators using the preset security authentication procedure.
[0115] In this embodiment, the first verification parameter is a pass / fail verification parameter, such as a device driver or device hardware.
[0116] In this embodiment, the second verification parameter is a security verification parameter, such as the internet environment and network security.
[0117] In this embodiment, the security authentication index is an index used for security verification among the conformity verification parameters and security verification parameters. For example, devices containing viruses and Trojans are not allowed to access the network.
[0118] In this embodiment, the security authentication procedure is a pre-defined procedure used directly or indirectly during the security authentication process to determine whether the relevant requirements of the access gateway are met.
[0119] The beneficial effects of the above technical solution are: by extracting security authentication indicators from the first verification parameters and the second verification parameters, and starting a preset security authentication program to perform comprehensive security authentication on the security authentication indicators, the security of the device to be connected can be guaranteed to a large extent.
[0120] Example 6:
[0121] This invention provides a device access verification system based on an IoT gateway, and further includes:
[0122] The first acquisition module is used to acquire device indication information based on the authentication information of each device to be connected;
[0123] The second acquisition module is used to obtain the deployment encryption level of each device to be accessed based on the device indication information of each device to be accessed.
[0124] The selection module is used to select the appropriate access protocol based on the deployment encryption level of each device to be connected;
[0125] The access module is used to connect each device to the IoT gateway according to its access protocol.
[0126] In this embodiment, the authentication information is the indicator deviation and authentication matching information of the device to be connected.
[0127] In this embodiment, the device indication information is the next step indication information for each device to be accessed, such as obtaining mobile phone permissions.
[0128] In this embodiment, the encryption level is the encryption level of the hardware information, software information, or account information of the device to be accessed in the access gateway.
[0129] In this embodiment, the access protocol is a protocol that enables transmission and bearer functions between the IoT gateway interface and the interface of the device to be accessed.
[0130] The beneficial effects of the above technical solution are: by obtaining the device indication information through the information of the device to be connected, the deployment encryption level of the device to be connected can be obtained, thereby selecting the appropriate access protocol and accurately connecting the device to be connected to the IoT gateway.
[0131] Example 7:
[0132] This invention provides a device access verification system based on an IoT gateway, comprising a second verification unit:
[0133] The generation subunit is used to generate a set of security verification indicators for each device to be accessed based on the weights of the device's own security-related indicators and the weights of the device's network access security-related indicators.
[0134] The sub-unit is determined to identify the data type of each security indicator in the security verification indicator set for each device to be connected.
[0135] The verification subunit is used to select a verification channel to perform security verification on each security indicator based on the data type of each security indicator in the security verification indicator set of each device to be accessed.
[0136] The calculation unit is used to perform weighted calculations on the verification results of each security indicator in the security verification indicator set of each device to be accessed to determine the security index of the device to be accessed.
[0137] In this embodiment, the weight of the device's own security-related indicators is the weight of the security-related indicators of the software that comes with the device to be connected, such as Trojans.
[0138] In this embodiment, the weight of the device network access security-related index is the weight of the device network baseband index related to security.
[0139] In this embodiment, the security verification indicator set is a collection of indicators used to verify the security of the device.
[0140] The beneficial effects of the above technical solution are: by obtaining the data type of security indicators generated by the weights of the device's own security-related indicators and the weights of the device's network access security-related indicators, the security index of the device to be accessed is calculated by weighting the verification results of the security indicators. The security of the device to be accessed can be verified through the specific calculation results, and the security level of the device can be seen intuitively.
[0141] Example 8:
[0142] This invention provides a device access verification system based on an IoT gateway. The judgment module is used to obtain the deployment encryption level of each device to be accessed based on its device indication information, including:
[0143] The second acquisition unit is used to acquire the authorization and non-authorization information of each device to be accessed based on the device indication information of each device to be accessed.
[0144] The first determining unit is used to determine the gateway permission function information corresponding to the authorized permission information and the unauthorized permission information respectively;
[0145] The second determining unit is used to determine the permission level corresponding to the gateway permission function information;
[0146] The fourth acquisition unit is used to obtain the deployment encryption level of each device to be connected based on the permission level corresponding to the gateway permission function information.
[0147] In this embodiment, the device indication information is the next step indication information for each device to be accessed, such as obtaining mobile phone permissions.
[0148] In this embodiment, the authorization permissions are the operation permissions that the device to be connected to has already been authorized in the gateway.
[0149] In this embodiment, unauthorized permission information refers to the operation permissions that the device to be connected does not have authorized in the gateway.
[0150] In this embodiment, the gateway permission function information is the function corresponding to each operation permission, such as restricting devices from accessing the gateway.
[0151] In this embodiment, the permission level is a preset level for each operation permission. For example, level one is to control all access devices, and level two is to control some access devices.
[0152] In this embodiment, the encryption level is the encryption level of the hardware information, software information, or account information of the device to be accessed in the access gateway.
[0153] The beneficial effects of the above technical solution are: by determining the gateway permission function information corresponding to the authorized and unauthorized permission information of the device to be accessed, the deployment encryption level of the device to be accessed can be determined, and the authorization information of each device to be accessed for different gateways can be clearly defined.
[0154] Example 9:
[0155] This invention provides a device access verification system based on an IoT gateway. The second acquisition unit obtains the authorization and non-authorization information of each device to be accessed based on device indication information, including:
[0156] Trigger commands to retrieve each permission information;
[0157] Based on the trigger command, the command response information is retrieved from the device indication information of each device to be connected;
[0158] Determine the current matching degree between the trigger command for each permission information and the command response information of that permission information in the device indication information of each device to be connected;
[0159] First permission information with a current matching degree greater than or equal to a preset matching degree is confirmed as authorized permission information, and second permission information with a current matching degree less than the preset matching degree is initially confirmed as unauthorized permission information;
[0160] Obtain the permission seed corresponding to each second permission information;
[0161] The permission seeds are subjected to multi-dimensional behavioral evaluation to obtain evaluation results. Based on the evaluation results, the permission type of each second permission information is determined. The permission types include: normal permissions and advanced permissions.
[0162] Determine the relevant indicators for permission evaluation for each second permission information based on the permission type of each second permission information;
[0163] Obtain the associated permission evaluation index for each second permission information from the instruction response information of each device to be connected, and determine the missing permission evaluation index based on the similarity interval of the permission evaluation related index and the associated permission evaluation index.
[0164] Retrieve the associated device data for the missing permission assessment indicators from the device indication information of each device to be connected;
[0165] The associated device data is evaluated for permissions according to the evaluation rules of the missing permission evaluation index. If the permission evaluation result is that the associated device data meets the permission usage conditions, the second permission information is confirmed as authorized permission information. If the permission evaluation result is that the associated device data does not meet the permission usage conditions, the second permission information is further confirmed as unauthorized permission information.
[0166] In this embodiment, the device indication information is the next step indication information for each device to be accessed, such as obtaining mobile phone permissions.
[0167] In this embodiment, the command response information is the device's response to the command, such as no response or a failed response.
[0168] In this embodiment, the similarity interval is the overlapping data between permission assessment-related indicators and associated permission assessment indicators, in order to determine missing data.
[0169] In this embodiment, the triggering instruction is a request instruction for the device to trigger operation permissions. For example, if the device needs to access the Internet, it needs to generate an Internet access request through the IP address and Internet Protocol.
[0170] In this embodiment, the current matching degree is the matching degree between the parameters required by the trigger command and the actual response parameters of the device. For example, the trigger command requires an IP address and Internet Protocol, but the actual device can only reach the IP address of the trigger command, so the current matching degree is 50%.
[0171] In this embodiment, the preset matching degree can be 90%.
[0172] In this embodiment, the permission seed is based on either implicit device control parameters or explicit device control parameters. Implicit device control parameters directly verify whether a user has operation permissions through parameters, while explicit device control parameters allow the removal of one parameter representing a certain set of permission parameters without modifying all parameters.
[0173] In this embodiment, multi-dimensional behavior evaluation is the evaluation of triggering behaviors in different dimensions. For example, internet access permissions can be evaluated based on login account and network speed.
[0174] In this embodiment, the permission assessment related indicators are the relevant indicators for assessing each second permission information. For example, the permission to access the Internet is an active access, and its relevant indicators are the Internet environment and network security.
[0175] In this embodiment, the missing permission evaluation metric is the metric that was missed.
[0176] In this embodiment, the evaluation rules specify the circumstances under which this indicator is used and the range of values for this indicator.
[0177] The beneficial effects of the above technical solution are: by obtaining the permission seed of unauthorized permission information and conducting multi-dimensional evaluation to obtain permission evaluation-related indicators, and then evaluating the device data based on the missing permission evaluation indicators, it is possible to accurately obtain the authorized permission information and unauthorized permission information of the device, thus ensuring network security.
[0178] Example 10:
[0179] This invention provides a device access verification system based on an IoT gateway. After the second acquisition module obtains the deployment encryption level of each device to be accessed based on the device indication information, the system is further configured to:
[0180] Deploy a gateway node for each device to be connected based on its encryption level, and obtain the deployment results.
[0181] Generate a gateway device deployment plan based on the deployment results, and obtain the access devices to be allocated for each gateway node based on the gateway device deployment plan;
[0182] Obtain the node-allocated load of each gateway node, and determine the network communication cost index of that gateway node based on the node-allocated load of each gateway node.
[0183] Determine the virtual hop count and communication delay coefficient for each gateway node under the network communication cost index;
[0184] Based on the node load allocation, network communication cost index, and virtual hop count and communication latency coefficient of each gateway node under the network communication cost index, the device deployment difficulty coefficient of each gateway node is calculated:
[0185]
[0186] Among them, F i Let R1 represent the device deployment difficulty coefficient of the i-th gateway node, and let Q represent the random weight value of the first system. i Let Q represent the load allocated to the i-th gateway node, Q represent the reference threshold for the load allocation to maintain optimal performance of the gateway node, R2 represent the random weight value of the second system, and G represent the load allocation value. i Let D be the network communication cost index of the i-th gateway node. i Let α represent the virtual hop count of the i-th gateway node, D represent the reference threshold for the virtual hop count of a node under standard conditions, and α represent the virtual hop count of the node. i Let S be the communication delay coefficient of the i-th gateway node. i β represents the proportion of network overhead incurred when data is transmitted by the i-th gateway node, e is the natural constant with a value of 2.72, and β i This represents the current performance index of the i-th gateway node;
[0187] Based on the device deployment difficulty coefficient of each gateway node, select the best suitable access device from the available access devices to be assigned to that gateway node;
[0188] Among them, the higher the deployment difficulty coefficient, the higher the performance score of the selected access device should be.
[0189] In this embodiment, the load allocated to each node is the pre-allocated system load for each node, such as 100 or 200.
[0190] In this embodiment, the load allocation reference threshold can be 200.
[0191] In this embodiment, the network communication cost index is the communication cost of each Internet node.
[0192] In this embodiment, the virtual data hop count is an indicator of data hops when transmitting data within each gateway.
[0193] In this embodiment, the communication delay coefficient is the ratio of the actual time each node takes to connect to the Internet to the preset time.
[0194] In this embodiment, the overhead ratio is the ratio of network resource usage.
[0195] The beneficial effects of the above technical solution are: by calculating the device deployment difficulty coefficient of the gateway node, the best matching access device can be selected from the access devices to be allocated according to the coefficient, so as to select the best access device for access and make the access process more accurate.
[0196] Obviously, those skilled in the art can make various modifications and variations to this invention without departing from its spirit and scope. Therefore, if these modifications and variations fall within the scope of the claims of this invention and their equivalents, this invention also intends to include these modifications and variations.
Claims
1. A device access verification system based on an Internet of Things (IoT) gateway, characterized in that, The system includes: Information acquisition module: used to collect information of devices to be connected in real time, store the collected information and transmit it to the device analysis processor to obtain the device analysis results; First verification module: Used to send a qualified verification request to the gateway device and obtain the first verification result for the same device to be connected; The second verification module is used to perform security verification on the corresponding device to be connected based on the device analysis results, and obtain the second verification result. Security authentication module: used to perform comprehensive security authentication on the same device to be connected based on the first verification result and the second verification result; The information collection module includes: Detection unit: Used to detect in real time whether any device sends an access gateway request; if so, it generates a device acquisition command. The acquisition unit is used to acquire information about the device to be connected according to the device acquisition command. The transmission unit is used to transmit the information of the device to be accessed to the device analysis processor via the 5G network and start its device analysis function. The receiving unit is used to receive and statistically analyze the device analysis results of the device analysis processor for each device to be accessed. The device analysis results include: device type, device hardware and software information, and device security information. The first verification module includes: First acquisition unit: used to acquire the unique identifier of each device to be connected based on the device analysis results; Generation unit: used to generate a question-based verification code for each device to be accessed based on its unique identifier. Detection unit: used to receive verification information from each device to be connected in response to the question-and-answer verification code, and to detect whether the verification information is valid; The first verification unit is configured to verify that the verification is successful if the verification information matches the standard answer, and unsuccessful if the verification information does not match the standard answer. The second verification module includes: The second acquisition unit is used to acquire the network security attributes and device security attributes of each device to be accessed based on the device analysis results. The parsing unit is used to parse the network security attributes and device security attributes of each device to be accessed, and determine the device's own security and device network access security based on the parsing results. The second verification unit is used to perform security verification on the device to be accessed based on the device's own security and the device's network access security, and to obtain the second verification result. The security authentication module includes: The first extraction unit is used to extract the first verification parameter from the first verification result and, at the same time, extract the second verification parameter from the second verification result. The second extraction unit is used to extract security authentication indicators from the first verification parameters and the second verification parameters. The startup unit is used to initiate a preset security authentication program. The authentication unit is used to perform comprehensive security authentication on the security authentication indicators using the preset security authentication procedure. The system also includes: The first acquisition module is used to acquire device indication information based on the authentication information of each device to be accessed, wherein the device indication information is the next step indication information for each device to be accessed. The second acquisition module is used to obtain the deployment encryption level of each device to be accessed based on the device indication information of each device to be accessed. The selection module is used to select the appropriate access protocol based on the deployment encryption level of each device to be connected; The access module is used to connect each device to the IoT gateway according to its access protocol. After the second acquisition module obtains the deployment encryption level of each device to be accessed based on the device indication information of each device, the system is further configured to: Deploy a gateway node for each device to be connected based on its encryption level, and obtain the deployment results. Generate a gateway device deployment plan based on the deployment results, and obtain the access devices to be allocated for each gateway node based on the gateway device deployment plan; Obtain the node-allocated load of each gateway node, and determine the network communication cost index of that gateway node based on the node-allocated load of each gateway node. Determine the virtual data hop count and communication delay coefficient under the network communication cost index at each gateway node, wherein the virtual data hop count is an indicator of data hops when transmitting data within each gateway; Based on the node load allocation, network communication cost index, and virtual hop count and communication latency coefficient of each gateway node under the network communication cost index, the device deployment difficulty coefficient of each gateway node is calculated: in, Let represent the device deployment difficulty coefficient of the i-th gateway node. Represented as the random weight value of the first system, This represents the load allocated to the i-th gateway node. This represents the reference threshold for the allocated load to maintain optimal performance of the gateway node. Represented as the random weight value of the second system, Let be the network communication cost index of the i-th gateway node. This represents the virtual hop count for the data at the i-th gateway node. This represents the reference threshold for the virtual hop count of a node under standard conditions. Let represent the communication delay coefficient of the i-th gateway node. This represents the proportion of network overhead incurred when data is transmitted by the i-th gateway node, and e represents the natural constant with a value of 2.
72. This represents the current performance index of the i-th gateway node; Based on the device deployment difficulty coefficient of each gateway node, select the best suitable access device from the available access devices to be assigned to that gateway node; Among them, the higher the deployment difficulty coefficient, the higher the performance score of the selected access device should be.
2. The device access verification system based on an IoT gateway according to claim 1, characterized in that, The second verification unit includes: The generation subunit is used to generate a set of security verification indicators for each device to be accessed, based on the weights of the device's own security-related indicators and the weights of the device's network access security-related indicators. The sub-unit is determined to identify the data type of each security indicator in the security verification indicator set for each device to be connected. The verification subunit is used to select a verification channel to perform security verification on each security indicator based on the data type of each security indicator in the security verification indicator set of each device to be accessed. The calculation unit is used to perform weighted calculations on the verification results of each security indicator in the security verification indicator set of each device to be accessed to determine the security index of the device to be accessed.
3. The device access verification system based on an IoT gateway according to claim 1, characterized in that, The judgment module is used to obtain the deployment encryption level of each device to be accessed based on the device indication information of that device, including: The second acquisition unit is used to acquire the authorization and non-authorization information of each device to be accessed based on the device indication information of each device to be accessed. The first determining unit is used to determine the gateway permission function information corresponding to the authorized permission information and the unauthorized permission information respectively; The second determining unit is used to determine the permission level corresponding to the gateway permission function information; The fourth acquisition unit is used to obtain the deployment encryption level of each device to be connected based on the permission level corresponding to the gateway permission function information.
4. The device access verification system based on an IoT gateway according to claim 3, characterized in that, The second acquisition unit obtains the authorization and non-authorization information of each device to be accessed based on the device indication information of that device, including: Trigger commands to retrieve each permission information; Based on the trigger command, the command response information is retrieved from the device indication information of each device to be connected; Determine the current matching degree between the trigger command for each permission information and the command response information of that permission information in the device indication information of each device to be connected; First permission information with a current matching degree greater than or equal to a preset matching degree is confirmed as authorized permission information, and second permission information with a current matching degree less than the preset matching degree is initially confirmed as unauthorized permission information; Obtain the permission seed corresponding to each second permission information. The permission seed is based on the implicit control parameters or explicit control parameters of the device. The implicit control parameters of the device directly verify whether the user has operation permissions through parameters. The explicit control parameters of the device can remove one parameter representing a certain permission parameter set without modifying all parameters. The permission seeds are subjected to multi-dimensional behavioral evaluation to obtain evaluation results. Based on the evaluation results, the permission type of each second permission information is determined. The permission types include: normal permissions and advanced permissions. Determine the relevant indicators for permission evaluation for each second permission information based on the permission type of each second permission information; Obtain the associated permission evaluation index for each second permission information from the instruction response information of each device to be connected, and determine the missing permission evaluation index based on the similarity interval of the permission evaluation related index and the associated permission evaluation index. Retrieve the associated device data for the missing permission assessment indicators from the device indication information of each device to be connected; The associated device data is evaluated for permissions according to the evaluation rules of the missing permission evaluation index. If the permission evaluation result is that the associated device data meets the permission usage conditions, the second permission information is confirmed as authorized permission information. If the permission evaluation result is that the associated device data does not meet the permission usage conditions, the second permission information is further confirmed as unauthorized permission information.
Citation Information
Patent Citations
Access request authentication method and device, API gateway equipment and storage medium
CN114157503A
Equipment access method, system and device, Internet of Things equipment and gateway equipment
CN114666155A