An access identity verification method for computer software

By building a software access control platform in IoT devices, using multi-layer identity verification and dynamic verification monitoring technology, combined with blockchain and deep learning, the lack of identity authentication and access control functions in IoT devices is solved, and security and data processing efficiency are improved.

CN119106410BActive Publication Date: 2025-06-20YANSHAN UNIV +1
View PDF 4 Cites 0 Cited by

Patent Information

Application Number
CN202411067308.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-06
Publication Date
2025-06-20
Estimated Expiration
2044-08-06

AI Technical Summary

Technical Problem

The prior art has difficulty integrating identity authentication and access control functions in IoT devices, resulting in inefficient data collection and processing and increasing security risks.

Method used

By building a software access control platform, collecting data information from IoT nodes, using multi-layer identity verification and dynamic verification monitoring technology, combining blockchain technology and deep learning algorithms, identity verification and access rights management of the access subject are realized.

Benefits of technology

Improves the security and data processing efficiency of IoT devices, reduces the risk of malicious access and resource exhaustion, and enhances the flexibility and user experience of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119106410B_ABST
    Figure CN119106410B_ABST
Patent Text Reader

Abstract

A method for verifying access identity of computer software, which relates to the technical field of access identity verification. A software access control platform is constructed to collect data information of each Internet of Things node, and identity verification operations are performed on the access requests of access subjects; an access trend heat map of the subject ID is constructed, the number of identity verification layers of the subject ID is obtained, and multi-layer identity verification is performed on the subject ID according to the number of identity verification layers of the subject ID. When the multi-layer identity verification of the access subject passes, the access request permission verification of the access subject is performed; when the access request permission verification of the access subject passes, access monitoring items are set, and the access process of the access subject is dynamically verified and monitored according to the access monitoring items, and the access process of the access subject is controlled according to the results of the dynamic verification and monitoring. Compared with the traditional static access control method, it has significant improvements in terms of security, flexibility, user experience, etc., and can better adapt to complex Internet of Things environments.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of access identity verification, and specifically to an access identity verification method for computer software. Background Art

[0002] The prior art CN113285808A "An Identity Information Verification Method, Device, Equipment and Storage Medium" includes: an identity verification server obtains identity information forwarded by a service-side server, generates an access token according to the identity information and sends it to the service-side server for forwarding to a client; the identity verification server receives an identity verification request carried with the access token initiated by the client, and determines the operating system type to which the client belongs; through the identity verification server, a verification service unit corresponding to the operating system type is called to process the verification request and determine the verification result, and then the belonging identity verification result is fed back to the client.

[0003] The prior art CN112231667A "Identity Verification Method, Device, Storage Medium, System and Equipment" includes obtaining a first login state of a first application program; if the first login state of the first application program is valid, obtaining an access request of a user for a second application program, where the second application program uses the first application program as a host application; if the second login state of the user account in the second application program is valid, determining a target sensitive category corresponding to the second application program according to the access request; obtaining an identity trust level of the user account in the second application program; judging whether an identity verification service needs to be provided according to the identity trust level and the target sensitive category; if so, calling an identity verification interface corresponding to the identity trust level to perform identity verification, and if the identity verification passes, updating the identity trust level of the user account.

[0004] Since most Internet of Things devices do not have strong computing power, sufficient storage space and durable batteries, it is impossible to directly integrate security functions such as identity authentication and access control in the Internet of Things device chips, which will seriously affect the data collection and processing efficiency. It is precisely due to this defect of the Internet of Things devices that many malicious users have the opportunity to steal the data information collected by the Internet of Things devices through various means, or cause the Internet of Things devices to run out of resources and unable to continue collecting data, thus triggering a large number of security problems. Summary of the Invention

[0005] In order to solve the above technical problems, the purpose of the present invention is to provide an access identity verification method for computer software, including the following steps:

[0006] Step s1: Construct a software access control platform, collect data information of each Internet of Things node, and perform identity verification operations on the access requests of access subjects;

[0007] Step s2: Construct an access trend heat map of the subject ID based on the historical access logs of the subject ID. Obtain the number of authentication layers of the subject ID according to the access trend heat map, and perform multi-layer identity verification on the subject ID based on the number of authentication layers of the subject ID. When the multi-layer identity verification of the accessed subject passes, perform the access request permission verification of the accessed subject;

[0008] Step s3: When the access request permission verification of the accessed subject passes, set access monitoring items according to the access request of the accessed subject and the data information of the object IoT node, dynamically verify and monitor the access process of the accessed subject according to the access monitoring items, and control the access process of the accessed subject according to the dynamic verification and monitoring results.

[0009] Furthermore, construct a software access control platform, collect the data information of each IoT node. The process of performing identity verification operations on the access request of the accessed subject includes:

[0010] Construct a software access control platform based on blockchain technology. The software access control platform is communicatively connected to a number of blockchain nodes. The blockchain nodes are interconnected to form a blockchain network. The blockchain nodes are communicatively linked to IoT terminals. The blockchain nodes are used to collect the data information of IoT terminals, mark the collection time, and set the collection period;

[0011] The accessed subject logs in to the IoT terminal by inputting the subject ID and password, marks the IoT terminal as the subject IoT terminal, and at the same time inputs an access request to the subject IoT terminal. The access request includes the object IoT terminal, object data information, and operation type. The IoT terminal packages the subject ID and the access request into a data packet and uploads it to the blockchain node. The software access control platform performs identity verification operations on the data packet received by the blockchain node.

[0012] Furthermore, the process of constructing an access trend heat map of the subject ID based on the historical access logs of the subject ID and obtaining the number of authentication layers of the subject ID according to the access trend heat map includes:

[0013] Obtain the historical access logs of the subject ID in the data packet, perform statistical analysis on the historical access logs, and construct an access trend heat map of the accessed subject. The access trend heat map includes the access probability, operation type probability, object data information probability, and access result probability of the accessed subject for all IoT terminals at different timestamps;

[0014] Obtain the access probability of the object IoT terminal, the probability of object data information, the probability of operation type, and the access probability of the subject IoT terminal in the current timestamp data packet according to the access trend heat map. Use the access probability of the object IoT terminal, the probability of object data information, the probability of operation type, and the access probability of the subject IoT terminal as evaluation indicators, set the index weight matrix and trend fit level of the evaluation indicators, and judge the membership matrix of the evaluation indicators for the trend fit level through fuzzy comprehensive evaluation;

[0015] Obtain the trend fit level of the subject ID according to the membership matrix and the index weight matrix. Determine the number of identity verification layers of the subject ID according to the trend fit level, and perform multi-layer identity verification on the subject ID according to the number of identity verification layers.

[0016] Further, the process of the software access control platform performing multi-layer identity verification on the subject ID according to the number of identity verification layers of the subject ID includes:

[0017] The software access control platform pre-constructs an ID identity recognition database, and the ID identity recognition database includes identity verification data corresponding to several identity verification types of each ID;

[0018] Determine the number k of identity verification types of the subject ID according to the number of identity verification layers of the subject ID. Obtain several identity verification types of the ID that is the same as the subject ID from the ID identity recognition database. Randomly select k identity verification types from several identity verification types, use the identity verification data corresponding to the k identity verification types as the data to be compared, and construct a multi-factor identity verification instruction according to the k identity verification types. Send the multi-factor identity verification instruction to the IoT terminal logged in by the subject ID. The subject ID sends the identity verification data to be verified corresponding to the k identity verification types to the IoT terminal according to the multi-factor identity verification instruction. The IoT terminal packs the identity verification data to be verified into a data packet to be verified and sends it to the blockchain node. Match the identity verification data to be verified corresponding to the k identity verification types in the data packet to be verified received by the blockchain node with the data to be compared. If the identity verification data to be verified corresponding to the k identity verification types is consistent with the data to be compared, perform multi-layer identity verification on the access subject and verify the access request permission of the access subject. If the identity verification data to be verified corresponding to the k identity verification types is inconsistent with the data to be compared, the multi-layer identity verification of the access subject fails, and the access request of the access subject is rejected.

[0019] Further, when the multi-layer identity verification of the access subject passes, the process of verifying the access request permission of the access subject includes:

[0020] Preset the permission levels for each ID and the permission requirement levels for different operation types corresponding to the respective object data information of each Internet of Things terminal. Obtain the permission level of the subject ID in the data packet and the permission requirement level for the operation type corresponding to the object data information of the object Internet of Things terminal. Compare the permission level with the permission requirement level. If the permission requirement level is greater than or equal to the permission level, allow the access request of the subject and perform a dynamic process verification operation on the accessing subject. If the permission requirement level is less than the permission level, the accessing subject submits an artificial review application file to the software access control platform, and the administrator of the software access control platform determines whether to grant access permission based on the artificial review application file.

[0021] Further, when the access request permission of the accessing subject is verified, set access monitoring items according to the access request of the accessing subject and the data information of the object Internet of Things node. Dynamically verify and monitor the access process of the accessing subject according to the access monitoring items. The process of controlling the access process of the accessing subject according to the dynamic verification and monitoring results includes:

[0022] Obtain the level difference between the permission level of the subject ID and the permission requirement level. Obtain the initial access reputation value of the accessing subject according to the level difference of the subject ID, the trend matching level, and the access result probability. At the same time, obtain the predicted data information trend within the current collection cycle of the object Internet of Things node, use the predicted information trend as the judgment data, use the access request of the accessing subject and the data information of the object Internet of Things node as the access monitoring items, perform real-time monitoring on the access process of the accessing subject according to the access monitoring items, and reduce the initial access reputation value of the accessing subject in real time according to the real-time monitoring results. When the initial access reputation value of the accessing subject is zero, stop the access process of the accessing subject.

[0023] Further, the process of performing real-time monitoring on the access process of the accessing subject according to the access monitoring items and reducing the initial access reputation value of the accessing subject in real time according to the real-time monitoring results includes:

[0024] When the object Internet of Things terminal, object data information, and operation type accessed by the accessing subject during the access process are inconsistent with the object Internet of Things terminal, object data information, and operation type in the access monitoring items, clear the initial access reputation value of the accessing subject;

[0025] When the IoT terminal of the object, the object data information, and the operation type accessed by the access subject during the access process are consistent with the IoT terminal of the object, the object data information, and the operation type in the access monitoring item, the deviation rate information between the data information of the object IoT node and the interpretation data is obtained at the same time. A preset deviation rate threshold is set to determine whether the deviation rate information is greater than the deviation rate threshold. If it is greater, the cumulative time when the deviation rate information is greater than the deviation rate threshold and the deviation rate amplitude between the deviation rate information and the deviation rate threshold are extracted. A negative credit value is obtained according to the cumulative time and the deviation rate amplitude, and the initial access credit value of the access subject is updated in real time according to the negative credit value.

[0026] Further, the process of obtaining the predicted data information trend within the current collection period of the object IoT node includes:

[0027] Construct a data information trend prediction model based on deep learning, obtain the data information of each IoT node within a number of historical collection periods, use the data information as the training set and the test set, input the training set into the data information trend prediction model for training until the loss function is trained stably, save the model parameters, and test the data information trend prediction model through the test set until it meets the preset requirements, and output the data information trend prediction model;

[0028] Output the predicted data information trend of the object IoT node in the current collection period according to the data information trend prediction model.

[0029] Compared with the prior art, the beneficial effects of the present invention are:

[0030] 1. Multi-layer authentication increases the difficulty for attackers to illegally access the system because multiple verification points are required. Dynamic verification and monitoring can timely detect abnormal behaviors and take corresponding measures, reducing the possibility of security vulnerabilities being exploited and significantly improving security.

[0031] 2. The access trend heat map can adjust the authentication strategy according to historical access patterns, enabling the software access control platform to better adapt to the changing security environment. Dynamic verification and monitoring can flexibly adjust the monitoring strategy according to the behavior of the access subject and the state of the IoT node, significantly improving flexibility.

[0032] 3. Multi-layer authentication can be automatically adjusted according to the historical behavior of the access subject, reducing the disturbance to low-risk users. The access request permission verification ensures that legitimate users can quickly obtain the required permissions while maintaining a high level of security, significantly enhancing the user experience.

[0033] 4. The combination of the access trend heat map and dynamic verification monitoring can more accurately identify the difference between normal access behavior and abnormal behavior, reduce the false alarm rate, and at the same time, through refined access control, the false alarm situation caused by excessive restriction can be reduced.

[0034] 5. Automated access control decisions reduce the need for manual intervention, improve the system's response speed and overall efficiency, enhance the system's intelligence and automation level, and have significant improvements in terms of security, flexibility, user experience, etc. compared with traditional static access control methods, and can better adapt to complex Internet of Things environments. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] Figure 1 It is a schematic diagram of an access identity verification method for a computer software according to an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0036] Next, with reference to the accompanying drawings in the embodiments of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative efforts shall fall within the protection scope of the present application.

[0037] As Figure 1 shown, an access identity verification method for a computer software includes the following steps:

[0038] Step S1: Construct a software access control platform, collect data information of each Internet of Things node, and perform identity verification operations on the access requests of the access subject.

[0039] Step S2: Construct an access trend heat map of the subject ID according to the historical access logs of the subject ID, obtain the identity verification levels of the subject ID according to the access trend heat map, perform multi-level identity verification on the subject ID according to the identity verification levels of the subject ID, and when the multi-level identity verification of the access subject passes, perform access request permission verification on the access subject.

[0040] Step S3: When the access request permission verification of the access subject passes, set access monitoring items according to the access request of the access subject and the data information of the object Internet of Things node, perform dynamic verification monitoring on the access process of the access subject according to the access monitoring items, and control the access process of the access subject according to the dynamic verification monitoring results.

[0041] It should be further noted that in the specific implementation process, the process of constructing a software access control platform, collecting data information of each Internet of Things node, and performing identity verification operations on the access requests of the access subject includes:

[0042] Build a software access control platform based on blockchain technology. The software access control platform is communicatively connected to a number of blockchain nodes, which are interconnected to form a blockchain network. The blockchain nodes are communicatively linked to Internet of Things (IoT) terminals. The blockchain nodes are used to collect data information of the IoT terminals, mark the collection time, and set the collection period.

[0043] The access subject logs in to the IoT terminal by inputting the subject ID and password, marks the IoT terminal as the subject IoT terminal, and simultaneously inputs an access request to the subject IoT terminal. The access request includes the object IoT terminal, object data information, and operation type. The IoT terminal packages the subject ID and the access request into a data packet and uploads it to the blockchain node. The software access control platform performs an identity verification operation on the data packet received by the blockchain node.

[0044] It should be further noted that in the specific implementation process, constructing an access trend heat map of the subject ID based on the historical access logs of the subject ID, and the process of obtaining the identity verification levels of the subject ID according to the access trend heat map includes:

[0045] Obtain the historical access logs of the subject ID in the data packet. The historical access logs include access timestamps, access frequencies and durations of each IoT terminal, operation types (including read: obtaining the status or data of the IoT terminal, write: changing the status or configuration of the IoT terminal, control: sending commands to the IoT terminal, such as turning on or off a certain function, query: requesting specific information of the subject IoT terminal or object IoT terminal, configure: modifying the basic settings or advanced settings of the IoT terminal, diagnose: performing troubleshooting or maintenance tasks, etc.), object data information (including the name, path, or identifier of the accessed data, etc.), and access results (including identity verification results, access request permission verification results, and dynamic verification monitoring results). Statistically analyze the historical access logs to construct an access trend heat map of the access subject. The access trend heat map includes the access probabilities, operation type probabilities, object data information probabilities, and access result probabilities of the access subject for all IoT terminals at different timestamps.

[0046] It should be further noted that in the specific implementation process, the calculation formulas for statistically analyzing the historical access logs to obtain the access probabilities, operation type probabilities, object data information probabilities, and access result probabilities of the access subject for all IoT terminals at different timestamps are as follows:

[0047]

[0048] Among them, C (a,b) represents the access probability of IoT terminal a to IoT terminal b at timestamp t, nt(a,b) Denotes the cumulative access times of IoT terminal a to IoT terminal b at timestamp t, NT (a,b) Denotes the total cumulative access times of IoT terminal a to IoT terminal b, SE (a,b,i) Denotes the probability that IoT terminal a performs operation type i on IoT terminal b at timestamp t, nti (a,b) Denotes the cumulative times that IoT terminal a performs operation type i on IoT terminal b at timestamp t, NTI (a,b) Denotes the total cumulative times that IoT terminal a performs all operation types on IoT terminal b at timestamp t, FV (a,b,j) Denotes the probability that IoT terminal a accesses object data information j on IoT terminal b at timestamp t, ntj (a,b) Denotes the cumulative times that IoT terminal a accesses object data information j on IoT terminal b at timestamp t, NTJ (a,b) Denotes the total cumulative times that IoT terminal a accesses all object data information on IoT terminal b at timestamp t, UD (a,b,k) Denotes the probability that the access result of IoT terminal a to IoT terminal b at timestamp t is k, ntk (a,b) Denotes the cumulative times that the access result of IoT terminal a to IoT terminal b at timestamp t is k, NTK (a,b) Denotes the total cumulative times of all access results of IoT terminal a to IoT terminal b at timestamp t. α, β, δ, θ denote conversion coefficients.

[0049] Obtain the access probability of the object IoT terminal, the probability of object data information, the probability of operation type, and the access probability of the subject IoT terminal in the data packet of the current timestamp according to the access trend heat map. Take the access probability of the object IoT terminal, the probability of object data information, the probability of operation type, and the access probability of the subject IoT terminal as evaluation indicators, set the index weight matrix and trend fit level of the evaluation indicators, and judge the membership matrix of the evaluation indicators for the trend fit level through fuzzy comprehensive evaluation;

[0050] Obtain the trend fit level of the subject ID according to the membership matrix and the index weight matrix, determine the identity verification layer number of the subject ID according to the trend fit level, and perform multi-layer identity verification on the subject ID according to the identity verification layer number.

[0051] It should be further noted that in the specific implementation process, it should be further noted that in the specific implementation process, the process of obtaining the trend fit level of the subject ID according to the membership matrix and the index weight matrix includes:

[0052] Fuse the index weight matrix and the membership degree matrix of the evaluation index through a formula to obtain the fuzzy comprehensive evaluation matrix of the evaluation index. According to the fuzzy comprehensive evaluation matrix, obtain the membership degree of the subject ID for different trend fit levels, screen out the trend fit level with the highest membership degree corresponding to the subject ID, and use the trend fit level with the highest membership degree corresponding to the subject ID as the trend fit level of the subject ID;

[0053] Among them, the formula is:

[0054] M = a1M1 × a2M2;

[0055] Among them, M is the fuzzy comprehensive evaluation matrix of the evaluation index, M1 is the index weight matrix of the evaluation index, M2 is the membership degree matrix, "×" represents the multiplication of the elements at the corresponding positions of the weight matrix and the membership degree matrix of the evaluation index, and a1 and a2 are weighting parameters used to control the balance between the weight matrix and the membership degree matrix in the fuzzy comprehensive evaluation matrix of the evaluation index.

[0056] It should be further noted that in the specific implementation process, the process of the software access control platform performing multi-layer identity verification on the subject ID according to the number of subject ID identity verification layers includes:

[0057] The software access control platform pre-constructs an ID identity recognition database, and the ID identity recognition database includes identity verification data corresponding to several identity verification types of each ID. The identity verification types include email addresses, biometric data, hardware tokens, software tokens, etc.;

[0058] Determine the number k of identity verification types of the subject ID according to the number of subject ID identity verification layers. Obtain several identity verification types of the ID that is the same as the subject ID from the ID identity recognition database. Randomly select k identity verification types from several identity verification types, use the identity verification data corresponding to the k identity verification types as the data to be compared, and construct a multi-factor identity verification instruction according to the k identity verification types. Send the multi-factor identity verification instruction to the Internet of Things terminal logged in by the subject ID. The subject ID sends the identity verification data to be verified corresponding to the k identity verification types to the Internet of Things terminal according to the multi-factor identity verification instruction. The Internet of Things terminal packs the identity verification data to be verified into a data packet to be verified and sends it to the blockchain node. Match the identity verification data to be verified corresponding to the k identity verification types in the data packet to be verified received by the blockchain node with the data to be compared. If the identity verification data to be verified corresponding to the k identity verification types is consistent with the data to be compared, perform multi-layer identity verification on the access subject and verify the access request permission of the access subject. If the identity verification data to be verified corresponding to the k identity verification types is inconsistent with the data to be compared, the multi-layer identity verification of the access subject fails, and the access request of the access subject is rejected.

[0059] It should be further noted that in the specific implementation process, when the multi-level identity verification of the access subject passes, the process of verifying the access request permission of the access subject includes:

[0060] Preset the permission levels of each ID and the permission requirement levels corresponding to different operation types of the object data information of each Internet of Things terminal, obtain the permission level of the subject ID in the data packet and the permission requirement level corresponding to the operation type of the object data information of the object Internet of Things terminal, compare the permission level with the permission requirement level. If the permission requirement level is greater than or equal to the permission level, the access request of the access subject is allowed, and the dynamic process verification operation of the access subject is performed. If the permission requirement level is less than the permission level, the access subject submits an artificial review application file to the software access control platform, and the administrator of the software access control platform determines whether to grant access permission according to the artificial review application file.

[0061] It should be further noted that in the specific implementation process, when the access request permission verification of the access subject passes, access monitoring items are set according to the access request of the access subject and the data information of the object Internet of Things node, the access process of the access subject is dynamically verified and monitored according to the access monitoring items, and the process of controlling the access process of the access subject according to the dynamic verification and monitoring results includes:

[0062] Obtain the level difference between the permission level and the permission requirement level of the subject ID, obtain the initial access credit value of the access subject according to the level difference, trend fit level and access result probability of the subject ID. At the same time, obtain the predicted data information trend within the current collection period of the object Internet of Things node. The predicted data information trend includes the predicted data type and the predicted data traffic of each type. Use the predicted information trend as the judgment data, use the access request of the access subject and the data information of the object Internet of Things node as the access monitoring items, perform real-time monitoring on the access process of the access subject according to the access monitoring items, and reduce the initial access credit value of the access subject in real time according to the real-time monitoring results. When the initial access credit value of the access subject is zero, stop the access process of the access subject.

[0063] It should be further noted that in the specific implementation process, the calculation formula for obtaining the initial access credit value of the access subject according to the level difference, trend fit level and access result probability of the subject ID is:

[0064] DVE = γ * exp(a3 × WXP + a4 × QXP + a5 × RSC);

[0065] Where DVE represents the initial access credit value, γ represents the conversion coefficient, WXP represents the level difference, QXP represents the trend fit level, and RSC represents the access result probability.

[0066] It should be further noted that in the specific implementation process, the process of real-time monitoring of the access process of the access subject according to the access monitoring items and real-time reducing the initial access credibility value of the access subject includes:

[0067] When the object Internet of Things terminal, object data information, and operation type accessed by the access subject during the access process are inconsistent with the object Internet of Things terminal, object data information, and operation type in the access monitoring items, the initial access credibility value of the access subject is cleared;

[0068] When the object Internet of Things terminal, object data information, and operation type accessed by the access subject during the access process are consistent with the object Internet of Things terminal, object data information, and operation type in the access monitoring items, at the same time, obtain the deviation rate information between the data information of the object Internet of Things node and the interpretation data, preset a deviation rate threshold, and determine whether the deviation rate information is greater than the deviation rate threshold. If it is greater, extract the cumulative time when the deviation rate information is greater than the deviation rate threshold and the deviation rate amplitude between the deviation rate information and the deviation rate threshold, obtain a negative credibility value according to the cumulative time and the deviation rate amplitude, and update the initial access credibility value of the access subject in real time according to the negative credibility value.

[0069] It should be further noted that in the specific implementation process, the calculation process of obtaining the deviation rate information between the data information of the object Internet of Things node and the interpretation data is as follows:

[0070]

[0071] Among them, DFA represents the deviation rate information, ns represents the number of the same data types between the data information of the object Internet of Things node and the interpretation data, NSD represents the total number of data types of the data information of the object Internet of Things node and the interpretation data, IF pt the data traffic corresponding to the data type p at the t-th moment of the object Internet of Things node, IFS pt represents the data traffic corresponding to the data type p at the t-th moment of the interpretation data, n1 represents the length of the acquisition cycle moment, and a6, a7 represent weight factors.

[0072] It should be further noted that in the specific implementation process, the calculation formula for obtaining the negative credibility value according to the cumulative time and the deviation rate amplitude is as follows:

[0073] DECS = σ * (a8 × DT + a9 × (DFA - DFAS));

[0074] Among them, σ represents the conversion coefficient, DT represents the cumulative time, DFAS represents the deviation rate threshold, and a8, a9 represent weight factors.

[0075] It should be further noted that in the specific implementation process, the process of obtaining the predicted data information trend within the current collection period of the target Internet of Things node includes:

[0076] Construct a data information trend prediction model based on deep learning, obtain the data information of each Internet of Things node within a number of historical collection periods, use the data information as the training set and the test set, input the training set into the data information trend prediction model for training until the loss function is stably trained, save the model parameters, test the data information trend prediction model through the test set until it meets the preset requirements, and output the data information trend prediction model;

[0077] According to the data information trend prediction model, output the predicted data information trend of the target Internet of Things node in the current collection period.

[0078] The above embodiments are only used to illustrate the technical method of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical method of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical method of the present invention.

Claims

1. A method for verifying the access identity of computer software, characterized in that: The following steps are involved: Step s1: Build a software access control platform, collect data information of each IoT node, and perform identity verification operations on access requests from access subjects; Step s2: construct an access trend heat map of the subject ID based on the historical access log of the subject ID, obtain the identity authentication layer number of the subject ID based on the access trend heat map, perform multi-layer identity verification on the subject ID based on the identity authentication layer number of the subject ID, and when the multi-layer identity verification of the access subject passes, perform access request authority verification on the access subject; Step s3: When the access request authority of the access subject is verified, an access monitoring item is set according to the access request of the access subject and the data information of the object IoT node, and the access process of the access subject is dynamically verified and monitored according to the access monitoring item, and the access process of the access subject is controlled according to the dynamic verification and monitoring result; The process of constructing an access trend heat map of the subject ID based on the historical access logs of the subject ID and obtaining the number of authentication layers of the subject ID based on the access trend heat map includes: Obtain historical access logs of the subject ID in the data packet, perform statistical analysis on the historical access logs, and construct an access trend heat map of the access subject, wherein the access trend heat map includes the access probability, operation type probability, object data information probability, and access result probability of the access subject to all IoT terminals at different timestamps; According to the access trend heat map, the access probability of the object IoT terminal, the object data information probability, the operation type probability and the access probability of the subject IoT terminal in the current timestamp data packet are obtained, and the access probability of the object IoT terminal, the object data information probability, the operation type probability and the access probability of the subject IoT terminal are used as evaluation indicators, and the indicator weight matrix and the trend fit level of the evaluation indicator are set, and the membership matrix of the evaluation indicator to the trend fit level is judged by fuzzy comprehensive evaluation; The trend matching level of the subject ID is obtained according to the membership matrix and the indicator weight matrix, the number of identity authentication levels of the subject ID is determined according to the trend matching level, and multi-layer identity verification is performed on the subject ID according to the number of identity authentication levels.

2. A method for verifying the access identity of computer software according to claim 1, characterized in that: The process of building a software access control platform, collecting data information from each IoT node, and performing identity verification operations on access requests from access subjects includes: Building a software access control platform based on blockchain technology, wherein the software access control platform is communicatively connected to a number of blockchain nodes, the blockchain nodes are interconnected to form a blockchain network, the blockchain nodes are communicatively linked to the IoT terminals, and the blockchain nodes are used to collect data information of the IoT terminals and mark the collection time, and set the collection cycle; The access subject logs in to the IoT terminal by entering the subject ID and password, marks the IoT terminal as the subject IoT terminal, and inputs an access request to the subject IoT terminal. The access request includes the object IoT terminal, object data information, and operation type. The IoT terminal packages the subject ID and the access request into a data packet and uploads it to the blockchain node. The software access control platform performs identity verification operations on the data packets received by the blockchain node.

3. A method for verifying the access identity of computer software according to claim 2, characterized in that: The process of the software access control platform performing multi-layer identity verification on the subject ID according to the number of subject ID authentication layers includes: The software access control platform pre-builds an ID identity recognition database, which includes identity recognition data corresponding to several identity recognition types of each ID; The number k of identity authentication types of the subject ID is determined according to the number of identity authentication layers of the subject ID, several identity authentication types of the ID consistent with the subject ID are obtained from the ID identity recognition database, k identity authentication types are randomly selected from the several identity authentication types, the identity authentication data corresponding to the k identity authentication types are used as the data to be compared, and a multi-factor identity authentication instruction is constructed according to the k identity authentication types, and the multi-factor identity authentication instruction is sent to the Internet of Things terminal logged in by the subject ID. The subject ID sends the identity authentication data to be verified corresponding to the k identity authentication types to the Internet of Things terminal according to the multi-factor identity authentication instruction, and the Internet of Things terminal packages the identity authentication data to be verified into a data packet to be verified and sends it to the blockchain node, and the identity authentication data to be verified corresponding to the k identity authentication types in the data packet to be verified received by the blockchain node are matched with the data to be compared for consistency. If the identity authentication data to be verified corresponding to the k identity authentication types are consistent with the data to be compared, the multi-layer identity of the access subject is verified, and the access request authority of the access subject is verified. If the identity authentication data to be verified corresponding to the k identity authentication types are inconsistent with the data to be compared, the multi-layer identity verification of the access subject fails, and the access request of the access subject is rejected.

4. A method for verifying the access identity of computer software according to claim 3, characterized in that: When the multi-layer identity verification of the access subject is passed, the process of verifying the access request permission of the access subject includes: The permission level of each ID and the permission requirement level of each object data information of each IoT terminal corresponding to different operation types are preset, the permission level of the subject ID in the data packet and the permission requirement level of the operation type corresponding to the object data information of the object IoT terminal are obtained, the permission level is compared with the permission requirement level, if the permission requirement level is greater than or equal to the permission requirement level, the access request of the access subject is allowed, and the dynamic process verification operation of the access subject is performed, if the permission requirement level is less than the permission requirement level, the access subject submits a manual review application document to the software access control platform, and the administrator of the software access control platform determines whether to grant access rights based on the manual review application document.

5. A method for verifying access identity of computer software according to claim 4, characterized in that: When the access request authority of the access subject is verified, an access monitoring item is set according to the access request of the access subject and the data information of the object IoT node, and the access process of the access subject is dynamically verified and monitored according to the access monitoring item. The process of controlling the access process of the access subject according to the dynamic verification and monitoring result includes: Obtain the level difference between the authority level and the authority requirement level of the subject ID, obtain the initial access credibility of the access subject according to the level difference of the subject ID, the trend matching level and the access result probability, and simultaneously obtain the predicted data information trend within the current acquisition cycle of the object Internet of Things node, use the predicted data information trend as the judgment data, use the access request of the access subject and the data information of the object Internet of Things node as the access monitoring items, monitor the access process of the access subject in real time according to the access monitoring items, reduce the initial access credibility of the access subject in real time according to the real-time monitoring results, and stop the access process of the access subject when the initial access credibility of the access subject is zero.

6. A method for verifying the access identity of computer software according to claim 5, characterized in that: The process of monitoring the access process of the access subject in real time according to the access monitoring items and reducing the initial access reputation value of the access subject in real time according to the real-time monitoring results includes: When the object IoT terminal, object data information and operation type accessed by the access subject during the access process are inconsistent with the object IoT terminal, object data information and operation type in the access monitoring item, the initial access reputation value of the access subject is cleared; When the object Internet of Things terminal, object data information and operation type accessed by the access subject during the access process are consistent with the object Internet of Things terminal, object data information and operation type in the access monitoring item, the deviation rate information between the data information of the object Internet of Things node and the judgment data is obtained at the same time, a deviation rate threshold is preset, and it is determined whether the deviation rate information is greater than the deviation rate threshold. If greater than, the cumulative time when the deviation rate information is greater than the deviation rate threshold and the deviation rate amplitude between the deviation rate information and the deviation rate threshold are extracted, and a negative reputation value is obtained according to the cumulative time and the deviation rate amplitude, and the initial access reputation value of the access subject is updated in real time according to the negative reputation value.

7. A method for verifying the access identity of computer software according to claim 6, characterized in that: The process of obtaining the forecast data information trend within the current collection cycle of the object IoT node includes: Construct a data information trend prediction model based on deep learning, obtain data information within several historical collection cycles of each IoT node, use the data information as a training set and a test set, input the training set into the data information trend prediction model for training until the loss function training is stable, save the model parameters, test the data information trend prediction model with the test set until it meets the preset requirements, and output the data information trend prediction model; According to the data information trend prediction model, the predicted data information trend of the current collection cycle of the object Internet of Things node is output.

Citation Information

Patent Citations

  • Identity verification method, device and system, storage medium and equipment

    CN112231667A

  • Identity information verification method and device, equipment and storage medium

    CN113285808A

  • Threat level-based multi-factor identity authentication method

    CN109450959A

  • Internet of Things zero-trust system based on block chain and access method

    CN114338701A