A multi-level security authentication method and system
By adopting a multi-level security authentication method in the Internet of Things network, using physical layer characteristics and dynamic authentication maps for authentication and trust scores, the shortcomings of traditional authentication methods in the face of increasing number of devices and malicious attacks are solved, and efficient and reliable security authentication and global trust assessment are achieved.
Patent Information
- Application Number
- CN202411864212.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-18
- Publication Date
- 2025-06-10
- Estimated Expiration
- 2044-12-18
AI Technical Summary
In the existing Internet of Things networks, the traditional single-level authentication method shows shortcomings in the face of increasing number of devices, malicious node disguise and network attacks, cannot dynamically adapt to network topology changes, and is difficult to fully reflect the global trust of nodes, and cannot effectively resist quantum computing attacks.
A multi-level security authentication method is proposed, which extracts the physical layer characteristics of the new node through neighboring nodes to generate physical layer fingerprints for preliminary authentication, updates the authentication map dynamically to generate authentication paths, verifys the anti-quantum signature legitimacy and behavioral characteristics trust scores of the new nodes, monitors the node's behavior in real time and performs abnormal detection.
It effectively avoids the security risks caused by forging identity information in traditional authentication, improves the reliability and efficiency of authentication, significantly reduces authentication costs, enhances resistance to quantum computing attacks and malicious node disguises, and improves the robustness of the authentication system and the overall security of the network.
Smart Images

Figure CN119325086B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of the Internet of Things, and particularly to a multi-level security authentication method and system. Background Art
[0002] With the rapid development of the Internet of Things technology, more and more devices are connected to the network, and the scale and complexity of the network are constantly increasing. However, the security risks brought by the access of new nodes are also highlighted. The traditional single-level authentication method shows many deficiencies in the face of the increase in the number of devices, the disguise of malicious nodes, and network attacks. In current research, physical layer characteristics (such as channel state information and received signal strength) are widely used in device authentication because they are difficult to forge. In addition, as a graph-structured representation method, the dynamic authentication graph can reflect the trust relationship between nodes in real time and has gradually become an important tool for solving dynamic network security problems.
[0003] The existing authentication systems mainly face the following deficiencies: First, for the identity authentication of new nodes, most methods rely on static authentication mechanisms and cannot dynamically adapt to the changes in network topology and node behavior, resulting in a decline in authentication efficiency and accuracy. Second, the existing technologies usually calculate the trust score based on only a single level of node relationship, which is difficult to comprehensively reflect the global trust degree of nodes and is easily affected by malicious nodes. Finally, in the face of the threat of quantum computing, the security of traditional signature algorithms is gradually decreasing, but the application of the existing systems against quantum signatures is still imperfect. Summary of the Invention
[0004] In view of the above existing problems, the present invention is proposed.
[0005] Therefore, the present invention provides a multi-level security authentication method to solve the problems of dynamically generating an authentication path when a new node accesses the network, verifying the legality of anti-quantum signatures, and calculating the global network trust score.
[0006] To solve the above technical problems, the present invention provides the following technical solutions:
[0007] In a first aspect, the present invention provides a multi-level security authentication method, which includes:
[0008] When a new node accesses the network, neighbor nodes extract the physical layer characteristics of the new node by receiving wireless signals, generate a physical layer fingerprint, and perform a preliminary authentication;
[0009] Based on the preliminary authentication result of the physical layer fingerprint, dynamically update the authentication graph and generate a dynamic authentication path;
[0010] According to the dynamic authentication path, the new node verifies the anti-quantum signature legality of the identity credential and the behavior characteristic trust score through the neighbor nodes, and outputs the device layer authentication result;
[0011] According to the device-level authentication result, select the verification node in the authentication path to conduct identity review and weighted update of the trust score of the new node, and obtain the neighbor-level authentication result and the trust score of the entire network;
[0012] Based on the neighbor layer authentication results, the core node verifies the new node's network-wide trust score and the legitimacy of the quantum-resistant signature through a dynamic authentication graph, and updates and detects anomalies in the dynamic graph.
[0013] As a preferred solution of the multi-level security authentication method of the present invention, when a new node accesses the network, the neighboring node extracts the physical layer characteristics of the new node by receiving wireless signals, generates a physical layer fingerprint and performs preliminary authentication, including the following steps:
[0014] The new node broadcasts access request information to neighboring nodes through wireless communication;
[0015] The neighboring node extracts the channel state information and measures the received signal strength of the new node’s wireless signal by sampling the wireless signal sent by the new node;
[0016] The extracted channel state information and received signal strength are combined to generate the physical layer fingerprint of the new node;
[0017] The neighboring node matches the generated physical layer fingerprint of the new node with the physical layer fingerprint library of the legal node stored locally. The expression is:
[0018] ;
[0019] in, Indicates the new node fingerprint and the The similarity score of fingerprints, represents the new node fingerprint, Indicates the first fingerprints, Represents the fingerprint index in the fingerprint library, represents the eigenvalue index, represents the number of eigenvalues, The first eigenvalues, Indicates the fingerprint database The fingerprint eigenvalues;
[0020] Set a similarity threshold, compare the similarity score with the similarity threshold, and determine whether the fingerprint match is successful.
[0021] As a preferred solution of the multi-level security authentication method described in the present invention, based on the preliminary authentication result of the physical layer fingerprint, dynamically update the authentication map, and generating a dynamic authentication path includes the following steps:
[0022] After the network control center receives a new node sent by a neighbor node, add the new node to the node set in the dynamic map;
[0023] According to the neighbor node set of the new node, add an edge between the new node and the neighbor nodes, and calculate the weight of each edge;
[0024] ;
[0025] Among them, represents the weight between the starting node and the ending node , represents the starting node, represents the ending node, represents the starting node and the ending node between the authentication costs, represents the weight factor of the authentication cost, represents the weight factor of the trust score, represents the starting node and the ending node between the trust scores;
[0026] According to the dynamic map and the calculated edge weights, use the shortest path algorithm to generate an authentication path from the new node to the core node of the entire network. The expression is:
[0027] ;
[0028] Among them, represents the initial authentication path of the new node, represents a path in the dynamic authentication map.
[0029] As a preferred solution of the multi-level security authentication method described in the present invention, based on the dynamic authentication path, the new node verifies the legitimacy of the quantum-resistant signature of the identity credential and the trust score of the behavior characteristics through the neighbor node, and the output device layer authentication result includes the following steps:
[0030] The new node sends an authentication request message to its neighbor nodes according to the authentication path information provided in the dynamic authentication map;
[0031] After the neighbor node receives the authentication request message from the new node, use the public key of the network control center to verify the identity credential and the quantum-resistant signature of the new node;
[0032] Based on the anti-quantum signature verification result, the behavior of the new node is monitored in real time;
[0033] The neighbor nodes compare these behaviors with the historical normal behavior model and calculate the behavior deviation score;
[0034] Based on the authentication result and the behavior deviation score, the neighbor nodes update the trust score of the new node;
[0035] Set a trust threshold, compare the updated trust score of the new node with the trust threshold, and output the device layer authentication result.
[0036] As a preferred solution of the multi-level security authentication method described in the present invention, wherein: according to the device layer authentication result, select the verification nodes in the authentication path to re-check the identity of the new node and update the trust score with weighting, and obtain the neighbor layer authentication result and the whole network trust score, including the following steps,
[0037] The network control center obtains the connection relationship and edge weights between the new node and the neighbor nodes according to the dynamic authentication graph;
[0038] Based on the shortest path algorithm of the dynamic graph, select the set of neighbor nodes with the lowest authentication cost as the verification node set;
[0039] The new node sends an authentication request message to each verification node according to the information of the verification node set;
[0040] Each verification node re-checks the legality of the identity certificate and anti-quantum signature of the new node;
[0041] Based on the re-check result and the trust score of the device layer, combined with its own trust score, the trust score of the new node is updated with weighting to obtain the whole network trust score;
[0042] Set the trust threshold of the network layer, compare the whole network trust score with the trust threshold of the network layer, and obtain the neighbor layer authentication result.
[0043] As a preferred solution of the multi-level security authentication method described in the present invention, wherein: based on the neighbor layer authentication result, the core node verifies the whole network trust score and the anti-quantum signature legality of the new node through the dynamic authentication graph, including the following steps,
[0044] The network control center broadcasts the neighbor layer verification result to the network layer core node set;
[0045] The core node obtains the whole network connection relationship and the whole network trust score of the new node from the dynamic authentication graph;
[0046] According to the security policy of the network layer, the core node judges whether the whole network trust score of the new node meets the security threshold of the network layer;
[0047] When the global trust score of the new node is less than the security threshold, the core node triggers a high-intensity quantum-resistant authentication and requires the new node to submit a multi-factor signature;
[0048] The core node verifies the first-factor signature and the second-factor signature submitted by the new node respectively;
[0049] The core node queries the physical layer fingerprints in the dynamic authentication graph and compares them with the fingerprint data submitted by the new node in the device layer and neighbor layer authentications to obtain the physical layer fingerprint review result;
[0050] The core node verifies the integrity and consistency of the neighbor layer dynamic authentication path;
[0051] The core node combines the results of the global trust score, multi-factor signature verification, physical layer fingerprint review, and dynamic authentication path verification to determine whether the network layer authentication passes.
[0052] As a preferred solution of the multi-level security authentication method described in the present invention, wherein: based on the global trust score of the new node and the verification result of the quantum-resistant signature legitimacy, updating and anomaly detection of the dynamic graph include the following steps,
[0053] After the network layer authentication passes, the network control center broadcasts the authentication result and trust score of the new node to the whole network, notifies all nodes of the authentication result, and officially adds the new node to the dynamic authentication graph for updating;
[0054] Extract the trust score change rate, communication frequency, edge weight change rate, and authentication path change rate related to the node from the updated dynamic authentication graph;
[0055] According to the extracted data, define the anomaly detection threshold of the trust score change rate, the anomaly detection threshold of the communication frequency, the anomaly detection threshold of the edge weight change rate, and the anomaly detection threshold of the authentication path change rate;
[0056] Compare the extracted data with the corresponding anomaly detection thresholds. When a node meets any one of the anomaly conditions, it is determined as an abnormal node;
[0057] For the detected abnormal nodes, temporarily isolate the nodes and their related edges from the authentication graph and trigger the re-authentication process;
[0058] When no abnormal nodes are detected, the authentication process ends, and the dynamic authentication graph enters a stable operation state.
[0059] In a second aspect, the present invention provides a multi-level security authentication system, including,
[0060] Initial authentication module: When a new node accesses the network, the neighboring node extracts the physical layer characteristics of the new node by receiving wireless signals, generates a physical layer fingerprint and performs initial authentication;
[0061] The map update module dynamically updates the authentication map based on the preliminary authentication results of the physical layer and generates a dynamic authentication path;
[0062] Device authentication module: Based on the dynamic authentication path, the new node verifies the legitimacy of the quantum-resistant signature and the trust score of the behavioral characteristics of the identity credential through the neighboring nodes, and outputs the device-level authentication result;
[0063] The neighbor authentication module selects the verification node in the authentication path to perform identity review and weighted update of the trust score of the new node based on the device layer authentication result, and obtains the neighbor layer authentication result and the trust score of the whole network;
[0064] Anomaly detection module, based on the neighbor layer authentication results, the core node verifies the new node's full network trust score and the legitimacy of the quantum-resistant signature through a dynamic authentication graph, and updates and detects anomalies in the dynamic graph.
[0065] In a third aspect, the present invention provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: when the computer program is executed by the processor, any step of the multi-level security authentication method as described in the first aspect of the present invention is implemented.
[0066] In a fourth aspect, the present invention provides a computer-readable storage medium having a computer program stored thereon, wherein: when the computer program is executed by a processor, it implements any step of the multi-level security authentication method as described in the first aspect of the present invention.
[0067] The beneficial effects of the present invention are as follows: by extracting the physical layer fingerprint of the new node through the neighbor node and performing preliminary authentication, the security risks caused by forged identity information in traditional identity authentication are effectively avoided, and the reliability of authentication is improved by utilizing the physical layer characteristics; the authentication path is generated based on the dynamic authentication graph, so that the authentication process can adapt in real time with the changes in network topology, significantly improving the authentication efficiency and reducing the authentication cost; the dynamic authentication graph also ensures the optimality of the authentication path by dynamically adjusting the edge weights and comprehensively considering the authentication cost and trust score; through anti-quantum signature verification and behavioral feature trust score, the resistance of new node authentication to quantum computing attacks and malicious node disguise is enhanced; the anomaly detection mechanism of the dynamic authentication graph can monitor node behavior in real time, quickly isolate abnormal nodes and trigger the re-authentication process, thereby improving the robustness of the authentication system and the overall security of the network. BRIEF DESCRIPTION OF THE DRAWINGS
[0068] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.
[0069] Figure 1 It is a flowchart of the multi-level security authentication method in Embodiment 1.
[0070] Figure 2 It is a schematic diagram of multi-level authentication in Embodiment 1. Detailed implementation manners
[0071] To make the above objects, features, and advantages of the present invention more obvious and understandable, the following will make a detailed description of the specific implementation manners of the present invention with reference to the accompanying drawings of the specification.
[0072] In the following description, many specific details are set forth to fully understand the present invention. However, the present invention can also be implemented in other ways different from those described herein. Those skilled in the art can make similar extensions without departing from the connotation of the present invention. Therefore, the present invention is not limited by the specific embodiments disclosed below.
[0073] Secondly, the so-called "one embodiment" or "embodiment" herein refers to a specific feature, structure, or characteristic that can be included in at least one implementation manner of the present invention. The "in one embodiment" that appears in different places in this specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment that mutually excludes other embodiments.
[0074] Embodiment 1, referring to Figure 1 and Figure 2 , is the first embodiment of the present invention. This embodiment provides a multi-level security authentication method, including the following steps:
[0075] S1. When a new node accesses the network, the neighbor node extracts the physical layer characteristics of the new node by receiving the wireless signal, generates a physical layer fingerprint, and performs a preliminary authentication.
[0076] S1.1. The new node broadcasts an access request message to the neighbor node through wireless communication.
[0077] The request message includes the identification information of the node, the current timestamp, the public key, and the encrypted signature; the current timestamp is used to prevent replay attacks; the public key is used for subsequent quantum-resistant signature verification; the encrypted signature is generated by the quantum-resistant signature of the private key pair of the new node.
[0078] S1.2. The neighbor nodes sample the wireless signals sent by the new node, extract the channel state information, and measure the received signal strength of the new node's wireless signals;
[0079] Specifically, the expression for the received signal strength is:
[0080] ;
[0081] Where, represents the received signal strength, which is used to infer the authenticity of the physical location of the new node, represents the transmission power of the new node at time , represents the physical distance between the new node and the neighbor node. The farther the distance, the greater the signal attenuation, represents the channel path loss, which is the power attenuation caused by distance and environmental factors during the propagation of the signal from the new node to the neighbor node. It is calculated according to the distance and the path loss exponent, and the expression is:
[0082] ;
[0083] Where, represents the path loss exponent, which describes the attenuation rate of the signal in a specific environment. The typical values are 2 (free space), 3 - 5 (indoor environment), represents the random fading component, which is the random signal strength fluctuation caused by multipath effects (signal reflection, scattering) and environmental noise.
[0084] S1.3. Combine the extracted channel state information and the received signal strength to generate the physical layer fingerprint of the new node; The neighbor nodes match the generated physical layer fingerprint of the new node with the legitimate node physical layer fingerprint library stored locally, and the expression is:
[0085] ;
[0086] Where, represents the similarity score between the fingerprint of the new node and the th fingerprint in the fingerprint library, represents the fingerprint of the new node, represents the th fingerprint in the fingerprint library, represents the fingerprint index in the fingerprint library, represents the eigenvalue index, represents the number of eigenvalues, represents the th eigenvalue of the fingerprint of the new node, represents the th fingerprint in the fingerprint library, th eigenvalue;
[0087] Set a similarity threshold. When the similarity score exceeds the similarity threshold, the fingerprint match is successful. The neighbor node binds the physical layer fingerprint of the new node to its access request information and sends the matching result to the network control center. When the similarity score is lower than the similarity threshold, the access request is rejected and the process ends.
[0088] S2. Dynamically update the authentication graph based on the preliminary authentication result of the physical layer fingerprint to generate a dynamic authentication path.
[0089] S2.1. After the network control center receives the new node sent by the neighbor node, add the new node to the node set in the dynamic graph; according to the neighbor node set of the new node, add an edge between the new node and the neighbor node and calculate the weight of each edge;
[0090] ;
[0091] Among them, represents the weight between the starting node and the ending node , represents the starting node, represents the ending node, represents the starting node and the ending node between the authentication cost, represents the weight factor of the authentication cost, represents the weight factor of the trust score, represents the starting node and the ending node between the trust scores;
[0092] Specifically, the expression of the authentication cost is:
[0093] ;
[0094] Among them, represents the communication delay between the starting node and the ending node , represents the calculation consumption between the starting node and the ending node ;
[0095] The expression of the trust score is:
[0096] ;
[0097] Among them, represents the starting node and the ending node The trust score between represents the weight factor of the trust score feedback, represents the trust score of the neighbor nodes for the new node, providing a subjective evaluation of the trust level of the neighbor nodes for the new node. represents the default initial trust score of the new node, ensuring that the new node can still obtain a basic trust value when there is no neighbor score feedback.
[0098] S2.2. Generate an authentication path from the new node to the core nodes of the entire network using the shortest path algorithm according to the dynamic graph and the calculated edge weights. The expression is:
[0099] ;
[0100] where represents the initial authentication path of the new node, represents a path in the dynamic authentication graph.
[0101] S3. Based on the dynamic authentication path, the new node verifies the legitimacy of the quantum-resistant signature of the identity credential and the trust score of the behavior characteristics through the neighbor nodes, and outputs the authentication result at the device layer.
[0102] S3.1. The new node sends an authentication request message to its neighbor nodes according to the authentication path information provided in the dynamic authentication graph. After receiving the authentication request message from the new node, the neighbor nodes use the public key of the network control center to verify the identity credential of the new node. When the verification fails, it means that the identity credential is invalid, and the neighbor nodes reject the authentication request. When the verification is successful, the neighbor nodes use the public key of the new node to verify the quantum-resistant signature in the authentication message. Based on the verification result of the quantum-resistant signature, the behavior of the new node is monitored in real time. The neighbor nodes compare these behaviors with the historical normal behavior model and calculate the behavior deviation score.
[0103] Specifically, the expression of the behavior deviation score is:
[0104] ;
[0105] where represents the behavior deviation score, represents the th behavior characteristic value monitored currently, represents the th characteristic value of the normal behavior model.
[0106] S3.2. The neighboring node updates the trust score of the new node based on the identity authentication result and the behavior deviation score; sets a trust threshold, compares the updated trust score of the new node with the trust threshold, and determines the device layer authentication result; when the trust score of the updated new node is greater than the trust threshold, the device layer authentication passes, and the neighboring node submits the result to the network control center; when the trust score of the updated new node is less than the trust threshold, the device layer authentication fails, the authentication request is rejected, and the abnormal behavior is recorded.
[0107] Specifically, based on the identity verification result and the behavior deviation score, the expression for updating the trust score of the new node is:
[0108] ;
[0109] in, Indicates the updated trust score of the new node, Indicates the starting node and the terminal node The weight parameter of the trust score between represents the identity verification score, represents the weight parameter of the identity verification score, Represents the weight parameter of the behavioral deviation score.
[0110] S4. According to the device-layer authentication result, select the verification node in the authentication path to conduct identity review and weighted update of the trust score of the new node to obtain the neighbor-layer authentication result and the trust score of the entire network.
[0111] S4.1. The network control center obtains the connection relationship and edge weight between the new node and the neighboring nodes according to the dynamic authentication graph; based on the shortest path algorithm of the dynamic graph, the neighboring node set with the lowest authentication cost is selected as the verification node set; the new node sends an authentication request message to each verification node according to the information of the verification node set; each verification node re-verifies the legitimacy of the identity credentials and quantum-resistant signature of the new node; based on the review result and the trust score of the device layer, combined with its own trust score, the trust score of the new node is weighted updated to obtain the trust score of the entire network; the trust threshold of the network layer is set, and the trust score of the entire network is compared with the trust threshold of the network layer to obtain the authentication result of the neighbor layer.
[0112] Specifically, when the network-wide trust score is greater than the network layer trust threshold, the neighbor layer authentication is successful; when the network-wide trust score is less than the network layer trust threshold, the neighbor layer authentication fails, the authentication request is rejected, and the abnormal behavior is recorded.
[0113] S5. Based on the neighbor layer authentication results, the core node verifies the network-wide trust score and quantum-resistant signature legitimacy of the new node through the dynamic authentication graph, and updates and detects anomalies in the dynamic graph.
[0114] S5.1. After the neighbor layer verification is completed, the network control center broadcasts the neighbor layer verification results to the set of core nodes in the network layer; the core nodes obtain the full-network connection relationships and full-network trust scores of the new nodes from the dynamic authentication graph; according to the security policies of the network layer, the core nodes determine whether the full-network trust scores of the new nodes meet the security thresholds of the network layer.
[0115] Specifically, when the full-network trust score of the new node is greater than the security threshold, the full-network trust score verification passes; when the full-network trust score of the new node is less than the security threshold, the core nodes trigger high-strength quantum-resistant authentication and require the new nodes to submit multi-factor signatures.
[0116] S5.2. The core nodes separately verify the first-factor signature and the second-factor signature submitted by the new node.
[0117] The core nodes query the physical layer fingerprints in the dynamic authentication graph and compare them with the fingerprint data submitted by the new node during the device layer and neighbor layer authentication to obtain the physical layer fingerprint verification results; the core nodes verify the integrity and consistency of the neighbor layer dynamic authentication path; the core nodes combine the results of the full-network trust score, multi-factor signature verification, physical layer fingerprint verification, and dynamic authentication path verification to determine whether the network layer authentication passes; when all verifications pass, the network layer authentication is successful; when any verification fails, the network layer authentication fails and the new node is rejected from access.
[0118] S5.3. Based on the full-network trust score of the new node and the verification results of the quantum-resistant signature legality, update the dynamic graph and perform anomaly detection.
[0119] S5.3.1. After the network layer authentication passes, the network control center broadcasts the authentication results and trust scores of the new nodes to the entire network, notifies all nodes of the authentication results, and officially adds the new nodes to the dynamic authentication graph for update; extract the trust score change rate, communication frequency, edge weight change rate, and authentication path change rate related to the nodes from the updated dynamic authentication graph.
[0120] Specifically, the expression for the trust score change rate is:
[0121] ;
[0122] Among them, represents the trust score change rate, represents the current node 's trust score, represents the node 's previous moment trust score, represents the nodes in the dynamic authentication graph, and represents a device or entity in the network;
[0123] The expression for the communication frequency is:
[0124] ;
[0125] where, represents the communication frequency of node , represents the time interval, represents node the total number of messages sent;
[0126] The expression for the edge weight change rate is:
[0127] ;
[0128] where, represents the weight change rate between the starting node and the ending node , represents the weight at the current moment between the starting node and the ending node , represents the weight at the previous moment between the starting node and the ending node ;
[0129] The expression for the authentication path change rate is:
[0130] ;
[0131] represents the authentication path change rate of node , represents the current authentication path set of node , represents the authentication path set of node at the previous moment.
[0132] S5.3.2. Define the anomaly detection thresholds for the trust score change rate, communication frequency, edge weight change rate, and authentication path change rate based on the extracted data; compare the extracted data with the corresponding anomaly detection thresholds. When a node meets any one of the anomaly conditions, it is determined as an abnormal node; temporarily isolate the node and its related edges from the authentication graph for the detected abnormal nodes and trigger the re - authentication process; when no abnormal nodes are detected, the authentication process ends, and the dynamic authentication graph enters the stable operation state.
[0133] Specifically, the set anomaly detection threshold for the trust score change rate is and the anomaly detection threshold for the communication frequency is , the abnormal detection threshold of the edge weight change rate is , the abnormal detection threshold of the authentication path change rate is ;
[0134] Trust score sharp drop detection: When ≤ , it is considered that the trust score of node 𝑣 is abnormal;
[0135] Communication frequency abnormal detection: When ≥ , it is considered that the communication frequency of node 𝑣 is abnormal;
[0136] Edge weight fluctuation detection: When ≥ , it is considered that the edge is abnormal;
[0137] Authentication path change abnormal detection: When ≤ , it is considered that the authentication path of node 𝑣 has an abnormality.
[0138] The abnormal node resubmits an authentication request and is re-verified according to the authentication processes of the device layer, neighbor layer, and network layer;
[0139] If the re-authentication fails, the node is permanently isolated;
[0140] If the re-authentication is successful, the node is restored to the authentication graph, and the relevant edge weights are updated.
[0141] This embodiment also provides a multi-level security authentication system, including: a preliminary authentication module. When a new node accesses the network, the neighbor node extracts the physical layer characteristics of the new node by receiving a wireless signal, generates a physical layer fingerprint, and performs preliminary authentication; a graph update module. Based on the physical layer preliminary authentication result, the authentication graph is dynamically updated to generate a dynamic authentication path; a device authentication module. According to the dynamic authentication path, the new node verifies the anti-quantum signature legality and the behavior characteristic trust score of the identity credential through the neighbor node, and outputs the device layer authentication result; a neighbor authentication module. According to the device layer authentication result, the verification nodes in the authentication path are selected to conduct identity review and trust score weighted update for the new node, and the neighbor layer authentication result and the whole network trust score are obtained; an abnormal detection module. Based on the neighbor layer authentication result, the core node verifies the whole network trust score and anti-quantum signature legality of the new node through the dynamic authentication graph, and updates and performs abnormal detection on the dynamic graph.
[0142] This embodiment also provides a computer device, which is applicable to the case of the multi-level security authentication method, including: a memory and a processor; the memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions to implement the multi-level security authentication method proposed in the above embodiment.
[0143] The computer device may be a terminal. The computer device includes a processor, a memory, a communication interface, a display screen, and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The communication interface of the computer device is used to communicate with an external terminal in a wired or wireless manner. The wireless manner can be implemented through WIFI, a carrier network, NFC (Near Field Communication), or other technologies. The display screen of the computer device may be a liquid crystal display screen or an electronic ink display screen. The input device of the computer device may be a touch layer covering the display screen, or a button, a trackball, or a touchpad provided on the outer shell of the computer device, or an external keyboard, touchpad, or mouse, etc.
[0144] This embodiment also provides a storage medium, on which a computer program is stored. When the program is executed by a processor, it implements the multi-level security authentication method proposed in the above embodiment; the storage medium can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (Static Random Access Memory, abbreviated as SRAM), electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, abbreviated as EEPROM), erasable programmable read-only memory (Erasable Programmable Read Only Memory, abbreviated as EPROM), programmable read-only memory (Programmable Red-Only Memory, abbreviated as PROM), read-only memory (Read-Only Memory, abbreviated as ROM), magnetic memory, flash memory, a magnetic disk, or an optical disc.
[0145] In summary, the present invention: extracts the physical layer fingerprints of new nodes by neighbor nodes and conducts preliminary authentication, effectively avoiding the security risks caused by forged identity information in traditional identity authentication, and at the same time improving the reliability of authentication by utilizing the physical layer characteristics; generates an authentication path based on a dynamic authentication graph, enabling the authentication process to adapt in real time to changes in the network topology, significantly improving the authentication efficiency and reducing the authentication cost; the dynamic authentication graph also ensures the optimality of the authentication path by dynamically adjusting the edge weights and comprehensively considering the authentication cost and trust score; enhances the resistance of new node authentication to quantum computing attacks and malicious node disguise through anti-quantum signature verification and behavior feature trust score; the anomaly detection mechanism of the dynamic authentication graph can monitor node behavior in real time, quickly isolate abnormal nodes and trigger the re-authentication process, improving the robustness of the authentication system and the overall security of the network.
[0146] Embodiment 2, referring to Table 1, is the second embodiment of the present invention. To further verify the technical solution of the present invention, experimental simulation data of a multi-level security authentication method is given.
[0147] A small-scale Internet of Things network experimental environment was constructed. The experimental network includes 1 core node, 10 neighbor nodes, and 10 newly accessed nodes. The core node is responsible for the management and update of the dynamic authentication graph, the neighbor nodes are responsible for physical layer fingerprint collection and device layer authentication, and the newly accessed nodes simulate terminal devices in the actual environment. The experiment uses a real wireless signal transmission environment, where the channel state information (CSI) and received signal strength (RSSI) are used as the characteristic data of the physical layer fingerprint. The anti-quantum signature adopts a lattice-based cryptography scheme, and the behavior feature trust score is calculated through the historical communication behavior data of the device.
[0148] The experimental process includes the following steps:
[0149] Physical layer fingerprint extraction and preliminary authentication:
[0150] Each newly accessed node broadcasts a wireless signal to the surrounding neighbor nodes. The neighbor nodes sample the received signal, extract the CSI and RSSI data, and combine them to generate the physical layer fingerprint. Subsequently, the neighbor nodes perform similarity matching between the physical layer fingerprint and the stored legal fingerprint library, set the similarity threshold to 0.9, and the nodes with successful matching pass the preliminary authentication.
[0151] Dynamic authentication graph update and path generation:
[0152] After the preliminary authentication is successful, the core node adds the new node to the dynamic graph node set, generates edge weights according to the authentication results of the neighbor nodes, and calculates respectively according to the feedback of the neighbor nodes. The core node uses the shortest path algorithm to generate the optimal authentication path from each new node to the core node.
[0153] Device layer authentication:
[0154] The new node sends an authentication request through the neighboring nodes in the authentication path. The neighboring nodes verify its quantum-resistant signature and monitor its behavioral characteristics. The behavioral deviation score is calculated by comparing the current behavior of the new node with the historical normal behavior model. If the trust score is higher than the set threshold (0.75), the device layer authentication is passed.
[0155] Neighborhood-level authentication and trust score updates:
[0156] The core node selects a set of verification nodes based on the device layer authentication results. The verification node reviews the identity credentials of the new node and updates the results with its own weighted trust score to calculate the trust score of the entire network.
[0157] Network layer authentication and anomaly detection:
[0158] The core node evaluates the network-wide trust score of the new node. If the score is lower than 0.7, a high-intensity authentication is triggered, including multi-factor signature verification and physical layer fingerprint review. After the authentication is completed, the core node updates the dynamic map and monitors abnormal nodes in real time.
[0159] Assumptions:
[0160] New access node :5;
[0161] Legal fingerprint database : =1, 2, 3;
[0162] Similarity threshold: 0.9;
[0163] Each fingerprint feature value: 4 (i.e. m=4).
[0164] The details are shown in Table 1 below:
[0165] Table 1 New access nodes and legal fingerprint database data table
[0166]
[0167] Calculate the similarity between each new access node and the fingerprint in the legal fingerprint library, as shown in Table 2 below:
[0168] Table 2 Similarity calculation results
[0169]
[0170] The similarity calculation formula is:
[0171] ;
[0172] The following are the similarity calculation results between each newly connected node and the fingerprints in the legal fingerprint database:
[0173] Example calculation (taking _1 and P_1 as an example):
[0174] Numerator:
[0175] ;
[0176] Denominator:
[0177] ;
[0178] ;
[0179] Similarity:
[0180] ;
[0181] Other data is calculated according to the above calculation method.
[0182] The newly connected nodes with successful similarity matching perform device layer authentication, neighbor layer authentication, and network layer authentication. After the authentication is completed, the core node updates the dynamic graph and real-time detects abnormal nodes. The initial state and current state data are shown in Table 3 below:
[0183] Table 3 Initial State and Current State Data Table
[0184]
[0185] The initial weight and current weight data are shown in Table 4 below:
[0186] Table 4 Initial Weight and Current Weight Data Table
[0187]
[0188] Based on the above data, the anomaly detection results are obtained, as shown in Table 5 below:
[0189] Table 5 Anomaly Detection Results Table
[0190]
[0191] The specific process is as follows:
[0192] Taking _1 as an example, set the time interval seconds,
[0193] The expression for the change rate of the trust score is:
[0194] ;
[0195] ;
[0196] The expression for the communication frequency is:
[0197] ;
[0198] ;
[0199] The expression for the edge weight change rate is:
[0200] ;
[0201] ;
[0202] The expression for the authentication path change rate is:
[0203] ;
[0204] ;
[0205] The anomaly detection threshold for the trust score change rate: = 0.1, the anomaly detection threshold for the communication frequency change rate: = 0.2, the anomaly detection threshold for the edge weight change rate: = 0.15, the anomaly detection threshold for the authentication path change rate: = 0.1.
[0206] Compare the calculated data with the anomaly detection threshold to obtain the anomaly result;
[0207] _1 and _5 are determined as abnormal nodes because their authentication path change rates do not reach the threshold. Remove the abnormal nodes _1 and _5, and update the edge weight and authentication path sets to ensure the security and stability of the network.
[0208] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that the technical solutions of the present invention can be modified or equivalently replaced without departing from the spirit and scope of the technical solutions of the present invention, and they should all be covered within the scope of the claims of the present invention.
Claims
1. A multi-level security authentication method, characterized in that: include, When a new node accesses the network, the neighboring node extracts the physical layer characteristics of the new node by receiving wireless signals, generates a physical layer fingerprint and performs preliminary authentication; Based on the preliminary authentication results of the physical layer fingerprint, the authentication map is dynamically updated to generate a dynamic authentication path, including: After receiving the new node sent by the neighbor node, the network control center adds the new node to the node set in the dynamic graph; According to the neighbor node set of the new node, add edges between the new node and the neighbor nodes, and calculate the weight of each edge; w a,b =α·C a,b +β·(1-T a,b ); Among them, w a,b represents the weight between the starting node a and the ending node b, C a,b =D a,b +O a,b represents the authentication cost between the starting node a and the ending node b, D a,b represents the communication delay between the starting node a and the ending node b, O a,b represents the computational consumption between the starting node a and the ending node b, α represents the weight factor of the authentication cost, β represents the weight factor of the trust score, and T a,b =γ·T n +(1-γ)·T init represents the trust score between the starting node a and the ending node b, γ represents the weight factor of the trust score feedback, T n represents the trust score of the neighbor node to the new node, T init Represents the default initial trust score of a new node; The shortest path algorithm is used to generate the initial authentication path of the new node. The expression is: M new =argmin∑ (a,b)∈M w a,b ; Among them, M new represents the initial authentication path of a new node, and M represents a path in the dynamic authentication graph; According to the dynamic authentication path, the neighbor node verifies the identity credentials and the legitimacy of the quantum-resistant signature of the new node, calculates the behavioral deviation score, updates the trust score of the new node, and outputs the device-level authentication result based on the updated trust score of the new node; According to the device-level authentication result, select the verification node in the authentication path to verify the identity of the new node, and perform a weighted update on the trust score of the updated new node to obtain the neighbor-level authentication result and the trust score of the entire network; Based on the neighbor layer authentication results, the core node verifies the new node's network-wide trust score and the legitimacy of the quantum-resistant signature through a dynamic authentication graph, and updates and detects anomalies in the dynamic graph.
2. The multi-level security authentication method according to claim 1, wherein: When a new node accesses the network, the neighboring node extracts the physical layer characteristics of the new node by receiving wireless signals, generates a physical layer fingerprint and performs preliminary authentication, including the following steps: The new node broadcasts access request information to neighboring nodes through wireless communication; The neighboring node extracts the channel state information and measures the received signal strength of the new node’s wireless signal by sampling the wireless signal sent by the new node; The extracted channel state information and received signal strength are combined to generate the physical layer fingerprint of the new node; The neighboring node matches the generated physical layer fingerprint of the new node with the physical layer fingerprint library of the legal node stored locally. The expression is: Among them, S(P new ,P i ) represents the similarity score between the new node fingerprint and the i-th fingerprint in the fingerprint library, P new represents the new node fingerprint, P i represents the i-th fingerprint in the fingerprint library, i represents the fingerprint index in the fingerprint library, k represents the feature value index, m represents the number of feature values, P new [k] represents the kth eigenvalue of the new node fingerprint, P i [k] represents the kth eigenvalue of the ith fingerprint in the fingerprint database; Set a similarity threshold, compare the similarity score with the similarity threshold, and determine whether the fingerprint match is successful.
3. The multi-level security authentication method as claimed in claim 2, characterized in that: According to the dynamic authentication path, the neighbor node verifies the identity credentials and quantum-resistant signature legitimacy of the new node, calculates the behavioral deviation score, updates the trust score of the new node, and outputs the device layer authentication result based on the updated trust score of the new node, including the following steps: The new node sends an authentication request message to its neighbor nodes based on the authentication path information provided in the dynamic authentication graph; After receiving the authentication request message from the new node, the neighboring node uses the public key of the network control center to verify the identity certificate and quantum-resistant signature of the new node; Based on the verification results of quantum-resistant signatures, the behavior of new nodes is monitored in real time; Neighboring nodes compare these behaviors with historical normal behavior models and calculate behavior deviation scores; The neighboring node updates the trust score of the new node based on the authentication result and the behavior deviation score; Set a trust threshold, compare the trust score of the updated new node with the trust threshold, and output the device-level authentication result.
4. The multi-level security authentication method as claimed in claim 3, characterized in that: Based on the neighbor layer authentication results, the core node verifies the network-wide trust score and quantum-resistant signature legitimacy of the new node through a dynamic authentication graph, including the following steps: The network control center broadcasts the neighbor layer verification results to the network layer core node set; The core node obtains the network-wide connection relationship and network-wide trust score of the new node from the dynamic authentication graph; According to the security policy of the network layer, the core node determines whether the network-wide trust score of the new node meets the security threshold of the network layer; When the network-wide trust score of a new node is less than the security threshold, the core node triggers a high-intensity quantum-resistant authentication and requires the new node to submit a multi-factor signature. The core node verifies the first factor signature and the second factor signature submitted by the new node respectively; The core node queries the physical layer fingerprint in the dynamic authentication map and compares it with the fingerprint data submitted by the new node in the device layer and neighbor layer authentication to obtain the physical layer fingerprint verification result; The core node verifies the integrity and consistency of the dynamic authentication path of the neighbor layer; The core node combines the results of the whole network trust score, multi-factor signature verification, physical layer fingerprint review and dynamic authentication path verification to determine whether the network layer authentication has passed.
5. The multi-level security authentication method as claimed in claim 4, characterized in that: Based on the network-wide trust score of the new node and the legitimacy verification results of the quantum-resistant signature, the dynamic graph is updated and anomaly detected, including the following steps: After the network layer authentication is passed, the network control center broadcasts the authentication result and trust score of the new node to the entire network, informs all nodes of the authentication result, and formally adds the new node to the dynamic authentication map for update; Extract the trust score change rate, communication frequency, edge weight change rate and authentication path change rate associated with the node from the updated dynamic authentication graph; Based on the extracted data, define the anomaly detection threshold of the trust score change rate, the anomaly detection threshold of the communication frequency, the anomaly detection threshold of the edge weight change rate, and the anomaly detection threshold of the authentication path change rate; Compare the extracted data with the corresponding anomaly detection threshold. When a node meets any abnormal condition, it is determined to be an abnormal node. For detected abnormal nodes, the nodes and their related edges are temporarily isolated from the authentication graph, and the re-authentication process is triggered; When no abnormal nodes are detected, the authentication process ends and the dynamic authentication graph enters a stable operating state.
6. A multi-level security authentication system, based on the multi-level security authentication method according to any one of claims 1 to 5, characterized in that: include, Initial authentication module: When a new node accesses the network, the neighboring node extracts the physical layer characteristics of the new node by receiving wireless signals, generates a physical layer fingerprint and performs initial authentication; The map update module dynamically updates the authentication map based on the preliminary authentication results of the physical layer and generates a dynamic authentication path; The device authentication module verifies the identity credentials and quantum-resistant signature legitimacy of the new node based on the dynamic authentication path, calculates the behavior deviation score, updates the trust score of the new node, and outputs the device-layer authentication result based on the updated trust score of the new node. The neighbor authentication module selects the verification node in the authentication path to verify the identity of the new node according to the device layer authentication result, and performs weighted update on the trust score of the updated new node to obtain the neighbor layer authentication result and the whole network trust score; Anomaly detection module, based on the neighbor layer authentication results, the core node verifies the new node's full network trust score and the legitimacy of the quantum-resistant signature through a dynamic authentication graph, and updates and detects anomalies in the dynamic graph.
7. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the multi-level security authentication method according to any one of claims 1 to 5 are implemented.
8. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the multi-level security authentication method according to any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Safe and efficient wireless ad hoc network distributed security authentication method
CN114599035A
Wi-Fi equipment identification system and method based on multi-domain physical layer fingerprint features
CN115664905A