A multi-system password security management method based on device authentication

Through the combination of dual-participant identity authentication, homomorphic encryption of lattice cryptography, dynamic password update and zero-knowledge proof, the problems of insufficient security of device authentication and low efficiency of multi-system password management are solved, and high security and efficient multi-system password security management of equipment are achieved.

CN119603079BActive Publication Date: 2025-05-23JIANGSU HEGUAN INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510138868.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-08
Publication Date
2025-05-23
Estimated Expiration
2045-02-08

AI Technical Summary

Technical Problem

The security of existing equipment authentication is insufficient, and the password management efficiency of multi-systems is low, so it is impossible to effectively deal with dynamic changes in equipment and security management silos between multiple systems.

Method used

A unique device identity identification is generated through the dual-participant identity authentication mechanism, a homomorphic encryption algorithm based on grid cryptography is used to generate the device initial password, and a password update model is established through the spatiotemporal behavior feature matrix and environmental factors to dynamically update the device password. At the same time, the device identity is verified based on the zero-knowledge proof mechanism, and the hierarchical permission management based on attribute encryption is realized.

Benefits of technology

It improves the security of device authentication, solves the risk leakage problem of static passwords, realizes unified password management among multiple systems, and the dynamic update mechanism improves the system's attack resistance and resource management efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119603079B_ABST
    Figure CN119603079B_ABST
Patent Text Reader

Abstract

The present invention relates to the technical field of cryptography and information security management, and in particular to a multi-system password security management method based on device authentication, comprising: generating a unique identity through a dual-identity participant authentication mechanism, identifying and generating an initial password for a device using a homomorphic encryption algorithm based on lattice cryptography, effectively overcoming the potential security risks and management loopholes in the prior art. The method not only improves the reliability of identity authentication, but also effectively improves the security of the device by binding and storing the device identity with the initial password; at the same time, by improving the dynamic update of the device password based on a spatiotemporal behavior feature matrix and environmental factors, the security and flexibility of the system are further improved; in addition, a zero-knowledge proof mechanism is used for device identity authentication, and combined with hierarchical authority management based on attribute encryption, the collaborative security and management efficiency between multiple systems are enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of cryptography and information security management, and in particular to a multi-system cryptographic security management method based on device authentication. Background Art

[0002] With the continuous development of information technology, the interconnection between devices and modern systems has become the foundation of society. In this context, the importance of device authentication and password security management technology has become increasingly prominent, especially in the fields of Internet of Things (IoT), Vehicle to Everything (V2X) and smart home. The access and authentication mechanism of devices plays a vital role in system security and privacy protection.

[0003] Traditional authentication methods mainly rely on static passwords or simple digital certificates for identity authentication. However, with the continuous upgrading of network attack technology, the security of traditional methods is facing challenges. Therefore, how to ensure reliable identity authentication through advanced encryption technology and effectively manage password security between multiple systems of devices has become an important research direction.

[0004] Existing device authentication technologies mostly rely on static generation of device initial passwords or simple authentication based on device hardware features. Although these methods can ensure the security of device access within a certain mechanism, they have some obvious shortcomings:

[0005] First, static passwords are vulnerable to password guessing attacks or brute force attacks, especially when the device is running for a long time, the risk of password leakage is high;

[0006] Secondly, the identity authentication mechanism in the existing technology is usually unable to effectively handle the dynamic changes of the device, such as fluctuations in the device status and network environment, resulting in failures in the effectiveness and real-time nature of the authentication information;

[0007] In addition, security management among multiple systems often lacks unified standards, and there are problems of password management islands among different systems, which leads to inefficient management and even affects the security of the entire system. Summary of the invention

[0008] The purpose of this section is to summarize some aspects of the embodiments of the present invention and briefly introduce some preferred embodiments. Some simplifications or omissions may be made in this section and the abstract of the specification and the title of the invention of this application to avoid blurring the purpose of this section, the abstract of the specification and the title of the invention, and such simplifications or omissions cannot be used to limit the scope of the present invention.

[0009] In view of the above existing problems, the present invention is proposed.

[0010] Therefore, the technical problems solved by the present invention are: the security of existing device authentication and the efficiency of multi-system password management.

[0011] In order to solve the above technical problems, the present invention provides the following technical solutions: when a device first accesses the system, a unique device identity is generated through a dual-participant identity authentication mechanism, and the device identity includes a device hardware feature value and a dynamic session token;

[0012] Generate an initial password for the device using a homomorphic encryption algorithm based on lattice cryptography, and bind the initial password to the device identity for storage;

[0013] Establish a password update model based on the spatiotemporal behavior feature matrix and environmental factors to dynamically update the device password;

[0014] The device identity is verified based on the zero-knowledge proof mechanism to achieve hierarchical permission management based on attribute encryption.

[0015] As a preferred solution of the multi-system password security management method based on device authentication described in the present invention, a unique device identity is generated through a dual-participant identity authentication mechanism, including:

[0016] Collect device hardware fingerprint information and generate device hardware feature values;

[0017] Generate dynamic session tokens through a two-participant authentication mechanism;

[0018] The device hardware feature value is combined with the dynamic session token to generate the device identity DID: DID = HF|| T, and then stored securely.

[0019] As a preferred solution of the multi-system password security management method based on device authentication of the present invention, generating a hardware characteristic value HF includes:

[0020] HF = SHA3-256(CPU ID || MAC Address || Storage ID || BIOS Version )

[0021] Among them, SHA3-256 is a secure hash algorithm, || represents a string concatenation operation, and CPU ID Indicates the device CPU serial number, MAC Address Indicates the MAC address of the network interface, Storage ID Indicates the serial number of the main storage device, BIOS Version Indicates the version information of the input and output system.

[0022] As a preferred solution of the multi-system password security management method based on device authentication of the present invention, generating a dynamic session token includes:

[0023] The device sends an authentication request to the authentication server, including the hardware feature value HF;

[0024] The authentication server generates a random challenge value R;

[0025] The device calculates the authentication response value Y;

[0026] Among them, HMAC is a key-hashed message authentication code function;

[0027] After the authentication server verifies the response value Y, it generates a dynamic session token T:

[0028] T = AES-256-GCM(K server , HF || Y || Timestamp)

[0029] Among them, K server is the server-side key, AES-256-GCM is the Advanced Encryption Standard algorithm with authenticated encryption, and Timestamp is the timestamp.

[0030] As a preferred solution of the multi-system password security management method based on device authentication described in the present invention, a homomorphic encryption algorithm based on lattice cryptography is used to generate an initial password for the device, and the initial password is bound and stored with the device identity, including:

[0031] Initialize lattice cryptographic parameters and generate public-private key pairs for the Ring-LWE encryption scheme;

[0032] Based on the device identity, a cryptographic seed value is generated through an extensible hash function, and cryptographic base support is built;

[0033] Encrypting the cryptographic base support using a homomorphic encryption algorithm to generate a device initialization password;

[0034] The device initial password is bound to the device identity and is securely stored in a variety of storage methods.

[0035] As a preferred solution of the multi-system password security management method based on device authentication described in the present invention, a password update model is established based on the spatiotemporal behavior feature matrix and environmental factors to dynamically update the device password, including:

[0036] Construct a device spatiotemporal behavior feature matrix based on the device behavior data, and perform standardization on the matrix;

[0037] Build a password update prediction model using a deep neural network structure;

[0038] Assess the security risks of devices based on environmental factors and dynamically adjust password update policies;

[0039] Perform password update operations and ensure the security of the update process.

[0040] As a preferred solution of the multi-system password security management method based on device authentication described in the present invention, the password update operation includes:

[0041] Generate a new password P using the HMAC-based key derivation function new :

[0042] P new = HKDF(P old || S, salt)

[0043] Among them, HKDF is a key derivation function based on HMAC, S is a secure random number, and salt is a random value;

[0044] Verify the strength of the newly generated password and calculate its entropy value:

[0045] entropy = -Σ(p i ·log2(p i ))

[0046] Among them, p i is the probability of occurrence of the i-th character. If the entropy value of the password meets the set strength requirement, the new password is considered to be secure enough;

[0047] Use the homomorphic encryption algorithm to encrypt the newly generated password to protect the security of the password during storage and transmission:

[0048] CT new = HE.Encrypt(P new , pk)

[0049] Among them, HE.Encrypt is the homomorphic encryption function, and pk is the public key;

[0050] Update password records in the storage system and save change logs of password updates to ensure that each password update has a traceable history.

[0051] As a preferred solution of the multi-system password security management method based on device authentication described in the present invention, the device identity is verified based on a zero-knowledge proof mechanism to implement hierarchical authority management based on attribute encryption, including:

[0052] Build a zero-knowledge proof protocol for identity authentication;

[0053] Execute the zero-knowledge proof process;

[0054] Build a hierarchical permission management system based on attribute encryption;

[0055] Implement dynamic permission adjustment and access control.

[0056] As a preferred solution of the multi-system password security management method based on device authentication described in the present invention, the trust score F of the device is calculated according to the device behavior data, and the trust score is used to evaluate the reliability of the device:

[0057] F = Σ(W i ·f i (B)

[0058] Among them, W i is the behavioral factor weight, f i is the evaluation function, B is the operating behavior of the device;

[0059] Dynamically adjust permissions based on the device's trust score:

[0060] When F≥0.8, the authority level is increased;

[0061] When 0.5 ≤ F<0.8, maintain the current authority;

[0062] When F<0.5, reduce the authority level.

[0063] Beneficial effects of the present invention:

[0064] 1. Through hardware feature values, the uniqueness and non-replicability of the device at the physical level are guaranteed, while the dynamic session token avoids the risk of device identity being replayed or forged, effectively improving the security of the device authentication process and solving the identity forgery and attack problems that may be caused by traditional static authentication methods. Through this dual guarantee, the system can efficiently verify the legitimacy of the device and ensure that the access device is an authorized device, thereby avoiding the risk of malicious device intrusion or non-compliant device access to the system;

[0065] 2. Through the dual binding of the device and the password, the problem of identity forgery after the password is leaked is avoided, the overall security of the system is improved, and through encryption protection, the risk of external attackers obtaining or tampering with the password is effectively avoided;

[0066] 3. Through the integration of spatiotemporal characteristics and environmental factors, it is possible to monitor in real time whether there are abnormal behaviors or security threats during the use of the device, so as to update the password in time when such potential risks are discovered. Dynamic update effectively avoids the security risks brought about by the long-term existence of static passwords. The mechanism improves the flexibility and prevention of the system in dealing with security attacks, and ensures the timeliness and security of passwords.

[0067] 4. By verifying the identity of the device based on the zero-knowledge proof mechanism and combining it with the hierarchical permission management of attribute encryption, the device's access rights in the system can be effectively controlled, ensuring that the zero-knowledge proof mechanism implements identity authentication during the verification process without leaking the sensitive information of the device, greatly improving the security of privacy protection. The hierarchical permission management based on attribute encryption can grant different access rights according to the attributes and roles of different devices, further optimizing the system's resource management. This method can effectively prevent permission occupation and unnecessary authorization leakage, while ensuring that each device can only access its authorized resources. By implementing refined permission control, the system can improve resource utilization efficiency and flexible management while ensuring security. BRIEF DESCRIPTION OF THE DRAWINGS

[0068] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative labor. Among them:

[0069] Figure 1 It is a flowchart of the multi-system password security management method based on device authentication shown in the present invention. DETAILED DESCRIPTION

[0070] In order to make the above-mentioned objects, features and advantages of the present invention more obvious and easy to understand, the specific implementation methods of the present invention are described in detail below in conjunction with the drawings. It is obvious that the described embodiments are only part of the embodiments of the present invention, but not all of the embodiments.

[0071] Based on the embodiments of the present invention, all other embodiments obtained by ordinary persons in the art without making any creative work should fall within the scope of protection of the present invention.

[0072] In the following description, many specific details are set forth to facilitate a full understanding of the present invention, but the present invention may also be implemented in other ways different from those described herein, and those skilled in the art may make similar generalizations without violating the connotation of the present invention. Therefore, the present invention is not limited to the specific embodiments disclosed below.

[0073] According to an embodiment of the present invention, Figure 1 The flowchart shown is a multi-system password security management method based on device authentication, which specifically includes the following steps:

[0074] S1. When a device is first connected to the system, a unique device identity is generated through a dual-participant identity authentication mechanism. The device identity includes the device hardware feature value and a dynamic session token. The following are some of the steps that need to be explained:

[0075] S1.1. Collect device hardware fingerprint information and generate device hardware feature values; specifically:

[0076] Get the device CPU serial number;

[0077] Get the MAC addresses of all network interfaces;

[0078] Read the serial number of the primary storage device;

[0079] Get the version information of the input and output system;

[0080] Generate hardware characteristic value HF:

[0081] HF = SHA3-256(CPU ID || MAC Address || Storage ID || BIOS Version )

[0082] Among them, SHA3-256 is a secure hash algorithm, || represents a string concatenation operation, and CPU ID Indicates the device CPU serial number, MAC Address Indicates the MAC address of the network interface, Storage ID Indicates the serial number of the main storage device, BIOS Version Indicates the version information of the input and output system;

[0083] S1.2. Generate a dynamic session token through a dual-participant identity authentication mechanism; specifically:

[0084] The device sends an authentication request to the authentication server, including the hardware feature value HF;

[0085] The authentication server generates a random challenge value R: R = CSPRNG(256);

[0086] Among them, CSPRNG is a cryptographically secure random number generator;

[0087] The device calculates the authentication response value Y: Y = HMAC-SHA3-256(HF, R || Timestamp);

[0088] Among them, HMAC is the key hash message authentication code function, and Timestamp is the timestamp;

[0089] After the authentication server verifies the response value Y, it generates a dynamic session token T:

[0090] T = AES-256-GCM(K server , HF || Y || Timestamp)

[0091] Among them, K server is the server-side key, and AES-256-GCM is the Advanced Encryption Standard algorithm with authenticated encryption;

[0092] S1.3. Combine the device hardware feature value with the dynamic session token to generate a device identity and store it securely. Specifically:

[0093] Combine the hardware characteristic value and the dynamic session token to generate the device identity DID: DID = HF|| T;

[0094] Generate a signature using the elliptical digital signature algorithm: Sig DID = ECDSA(SK server , DID);

[0095] Among them, SK server is the server private key, ECDSA is the elliptical digital signature function;

[0096] Store the device identity DID and its signature in local databases and establish an index structure;

[0097] Furthermore, the storage structure of the database includes:

[0098] Main data area: stores the device identity DID and its associated basic information;

[0099] Data signature area: store digital signature Sig DID and target information required for verification;

[0100] Index data area: stores the fast query index established based on the hardware feature value HF.

[0101] In an optional embodiment, a network interface is used to connect to a multi-system security management platform, which includes an authentication server, a key management server, and a permission management server. The types of devices that can be accessed include but are not limited to industrial control equipment, Internet of Things terminal devices, and mobile devices.

[0102] S2. Generate the initial password of the device using a homomorphic encryption algorithm based on lattice cryptography, and bind the initial password to the device identity for storage. The following points need to be explained in this step:

[0103] S2.1. Initialize the lattice cryptographic parameters and generate the public-private key pair for the Ring-LWE encryption scheme. Specifically:

[0104] Select the demonstration ring dimension n=1024 and determine the modulus q=2 32 ;

[0105] Set discrete Gaussian distribution parameter σ=3.2;

[0106] Sampling from discrete Gaussian distribution X yields a private key s: ,in, Represents sampling from a standard discrete Gaussian distribution;

[0107] Generate Public Key :

[0108]

[0109] Among them, e is the error term generated by the noise term, which ensures the security of the cryptographic system, and b is the constant factor in the encryption process. is a random number, ∈ : , seed is a secure random number;

[0110] S2.2. Generate a cryptographic seed value based on the device identity through an extensible hash function and build a cryptographic base support; specifically:

[0111] Generate a seed value using the device identity DID:

[0112]

[0113] in, is the timestamp;

[0114] Construct k-dimensional cryptographic base seed support V based on value:

[0115]

[0116] Among them, PRF is a pseudo-random function based on AES;

[0117] S2.3. Encrypt the cryptographic base support using a homomorphic encryption algorithm to generate a device initialization password; specifically:

[0118] The generated ciphertext CT contains two components :

[0119]

[0120] The encryption process is:

[0121]

[0122] Among them, r is the random sampling style, , is the noise term, Encode is the encoding function, which is the encoding of the cryptographic base V;

[0123] S2.4. Bind the initial password of the device to the device identity and use multiple storage methods for secure storage; specifically:

[0124] Record device binding information BR:

[0125]

[0126] Among them, TS represents time, SIG represents signature, ;

[0127] Divide the device binding records into the primary shard MS and the verification shard VS to enhance the security and reliability of data storage:

[0128]

[0129] Primary shard MS: stores the device identity and encrypted device initial password ciphertext CT;

[0130] Verification slice VS: stores the digital signature SIG and additional verification information used to verify the binding record;

[0131] Use distributed storage technology to divide the binding information into pieces and store them separately:

[0132] Primary shard MS: stored in an encrypted database to ensure data security;

[0133] Verification piece VS: stored in the blockchain network, providing an unalterable verification function to ensure the transparency and credibility of the binding information;

[0134] Use a threshold scheme for key distribution to ensure that the key can only be decrypted with the cooperation of a certain number of authorized nodes;

[0135] The specific operations of the threshold scheme are: ;

[0136] Among them, t is the threshold value, indicating how many storage nodes are required to participate in decryption, and n is the total number of storage nodes.

[0137] S3. Establish a password update model based on the spatiotemporal behavior feature matrix and environmental factors to dynamically update the device password. Among them, what needs to be explained in this step is:

[0138] S3.1. Construct a device spatiotemporal behavior feature matrix based on device behavior data and standardize the matrix. Specifically:

[0139] As examples, device behavior data includes:

[0140] Time characteristics: device activity time, session duration, operation frequency;

[0141] Spatial characteristics: physical location coordinates, network topology location, routing hop count;

[0142] Characteristic behaviors: resource access patterns, data transfer volume, command sequences;

[0143] Based on the above device behavior data, the device spatiotemporal behavior feature matrix M is constructed. The dimension of the matrix is ​​three-dimensional (time dimension, space dimension and behavior dimension), and each element represents the value of the corresponding feature:

[0144] M[i,j,k] = {t[i], g[j], h[k]}

[0145] Where i, j, k represent the dimension indexes of time, space, and behavior respectively, t[i] represents the i-th time feature, g[j] represents the j-th space feature, and h[k] represents the k-th behavior feature;

[0146] In an optional implementation, the data in the matrix M is standardized to ensure that the ranges of all eigenvalues ​​are in the same interval to avoid excessive influence of certain features on the model, such as Z-Score standardization;

[0147] S3.2. Use a deep neural network structure to build a password update prediction model; the model structure includes:

[0148] Input layer: receives the standardized spatiotemporal behavior feature matrix, and each element in the matrix is ​​used as input data;

[0149] Structural layer: extracting local correlations of spatiotemporal features;

[0150] LSTM layer: captures long-term dependencies of behavior sequences;

[0151] Fully connected layer: summarizes all extracted features, comprehensively considers spatiotemporal features and long-term dependencies, and outputs the predicted value of password update;

[0152] Define the model loss function L:

[0153]

[0154] Among them, CE is the cross entropy loss, is a regularization term to avoid overfitting, are the parameters of the model, and is the weight coefficient in the loss function, is the output prediction value, is the true value;

[0155] Use gradient descent algorithm to optimize model parameters: θ new = θ old - η·∇L(θ)

[0156] Where η is the learning rate, ∇L(θ) is the gradient of the loss function with respect to the parameter;

[0157] S3.3. Evaluate the security risk of the device based on environmental factors and dynamically adjust the password update strategy; specifically:

[0158] Collect environmental data E:

[0159] E = {net status , sys load , Threat level}

[0160] Among them, net status The network status factors (whether the network connection is stable and whether the bandwidth is sufficient), sys load System load factors (current CPU and memory load of the device), Threat leve is the threat level factor (based on known security threat assessment levels);

[0161] The weighted sum method is used to calculate the environmental risk score Z, which indicates the degree of security risk of the environment in which the device is located:

[0162] Z = Σ(w i ·f i (E)

[0163] Among them, w i is the weight of each environmental factor, f i is the evaluation function;

[0164] Determine password update strategy based on risk score:

[0165] When Z>0.8, it is a high risk, and the password should be updated immediately;

[0166] When 0.5 ≤ Z ≤ 0.8, it is a medium risk, and the password should be updated regularly (e.g. every hour);

[0167] When Z<0.5, it is a low risk, so update the password periodically (e.g., once a week);

[0168] S3.4. Perform password update operations and ensure the security of the update process; the password update operation includes:

[0169] Generate a new password P using the HMAC-based key derivation function (HKDF) new :

[0170] P new = HKDF(P old || S, salt)

[0171] Among them, HKDF is a key derivation function based on HMAC, S is a secure random number, and salt is a random value;

[0172] Verify the strength of the newly generated password and calculate its entropy (amount of information):

[0173] entropy = -Σ(p i ·log2(p i ))

[0174] Among them, p i is the probability of occurrence of the i-th character. If the entropy value of the password meets the set strength requirement, the new password is considered to be secure enough;

[0175] Use the homomorphic encryption algorithm to encrypt the newly generated password to protect the security of the password during storage and transmission:

[0176] CT new = HE.Encrypt(P new , pk)

[0177] Among them, HE.Encrypt is the homomorphic encryption function, and pk is the public key;

[0178] Update password records in the storage system and save change logs of password updates to ensure that each password update has a traceable history.

[0179] S4. Verify the device identity based on the zero-knowledge proof mechanism to implement hierarchical permission management based on attribute encryption. The following points need to be explained in this step:

[0180] S4.1. Construct a zero-knowledge proof protocol for identity authentication; specifically:

[0181] The proof target is defined as verifying the identity of the device (device display identifier DID), and proving the device's initial password P, hardware feature value HF, and dynamic session token T. The verification is performed through a zero-knowledge proof protocol to ensure that the device's identity authentication process does not leak any other information;

[0182] The relationship between the device initial password P and the display identifier DID is expressed by a mathematical formula:

[0183] P = {x: ∃w, Q(x,w) = 1}

[0184] Where x is public information, w is device secret information, and Q is the verification relationship function, which means that when public information x and secret information w are given, the verification relationship function returns a value of 1, indicating that the password is valid;

[0185] The Pedersen commitment function is used to construct a zero-knowledge proof protocol for identity authentication. The specific commitment function form is:

[0186] C = Pedersen(DID || HF || T, r)

[0187] Among them, r is a random number, and Pedersen is a commitment function, which ensures that the committed information will not be leaked when it is made public, but can be effectively verified in the subsequent verification process;

[0188] S4.2. Execute the zero-knowledge proof process; specifically:

[0189] The prover (device) generates an initial commitment a, which is based on public information and random numbers:

[0190]

[0191] Among them, u, o are group generators, r, s are random numbers, and p is a large prime number;

[0192] The verifier (server) generates a random challenge e, which is generated based on the device commitment a and the current timestamp:

[0193] e = Hash(a || timestamp)

[0194] Among them, Hash is a secure hash function;

[0195] The prover (device) calculates the response z based on the received challenge e and its secret information l:

[0196] z = (r + e·l) modq

[0197] Among them, l is the secret information of the prover, and q is the order of the group;

[0198] The verifier confirms the legitimacy of the device identity by checking the following equation:

[0199]

[0200] in, To recalculate the commitment value using the response z, verify whether the equation is satisfied. If the equation is satisfied, it proves that the device identity is valid;

[0201] S4.3. Construct a hierarchical authority management system based on attribute encryption; specifically:

[0202] Construct an attribute set A for device permission management, which includes the following attributes:

[0203] Device type: such as mobile phone, sensor, server;

[0204] Security level: the security level of the device, such as low, medium, and high;

[0205] Functional permissions: the permissions that a device can perform, such as read, write, and execute;

[0206] Access increment: the growth or change of device access data;

[0207] Define attribute set A = {device type, security level, function permission, access increment};

[0208] Construct an attribute access policy tree T, which defines the logical conditions for device access control, such as:

[0209] T = (A 1 AND A 2 ) OR (A 3 AND A 4 )

[0210] Among them, A i is the i-th attribute or attribute combination;

[0211] Generate the access control key SK for the device using the Attribute Based Encryption (ABE) algorithm:

[0212] SK = ABE.KeyGen(MSK, A)

[0213] Among them, MSK is the master key and ABE is the attribute-based encryption algorithm;

[0214] S4.4. Implement dynamic permission adjustment and access control; specifically:

[0215] Monitor the operation behavior of the device in real time and collect the following behavior data:

[0216] Operation type: the specific operation performed by the device, such as read, write, and modify;

[0217] Access frequency: the access request frequency of the device;

[0218] Resource consumption: the resources consumed by the device during operation, such as CPU, memory, and bandwidth;

[0219] B = {operation type, access frequency, resource consumption};

[0220] The trust score F of the device is calculated based on the device behavior data. The trust score is used to evaluate the reliability of the device:

[0221] F = Σ(W i ·f i (B)

[0222] Among them, W i is the behavioral factor weight, f i is the evaluation function;

[0223] Dynamically adjust permissions based on trust:

[0224] When F≥0.8, the authority level is increased (e.g., one level);

[0225] When 0.5 ≤ F<0.8, maintain the current authority;

[0226] When F<0.5, reduce the authority level (e.g., reduce it by one level);

[0227] When the device's permissions change, its attribute key needs to be updated. The updated attribute key SKnew is generated by the new attribute set Anew:

[0228] SK new = ABE.KeyUpdate(SK, A new )

[0229] Among them, A new The updated attribute collection.

[0230] It should be noted that through the implementation of the above steps, the security, flexibility and anti-attack capability of the system can be effectively improved. Preferably, through the combination of dual-participant identity authentication, lattice cryptography homomorphic encryption, dynamic password update and zero-knowledge proof, it is ensured that identity authentication, password protection and permission allocation in the device access and management process can be effectively guaranteed. It not only solves the security risks of static authentication and password management in the prior art, but also improves the system's anti-attack capability and operability through dynamic updates and refined control, thereby achieving a strong guarantee for device security management in a multi-system environment.

[0231] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention rather than to limit it. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical solutions of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical solutions of the present invention, which should all be included in the scope of the claims of the present invention.

Claims

1. A multi-system password security management method based on device authentication, characterized in that: include: When a device is first connected to the system, a unique device identity is generated through a dual-participant identity authentication mechanism, and the device identity includes a device hardware feature value and a dynamic session token; Collecting device hardware fingerprint information and generating the device hardware feature value; including: Get the device CPU serial number; Get the MAC addresses of all network interfaces; Read the serial number of the primary storage device; Get the version information of the input and output system; Generate hardware characteristic value HF: HF = SHA3-256(CPU ID || MAC Address || Storage ID || BIOS Version ) Among them, SHA3-256 is a secure hash algorithm, || represents a string concatenation operation, and CPU ID Indicates the device CPU serial number, MAC Address Indicates the MAC address of the network interface, Storage ID Indicates the serial number of the main storage device, BIOS Version Indicates the version information of the input and output system; Generating the dynamic session token through a dual-participant identity authentication mechanism; including: The device sends an authentication request to the authentication server, including the hardware feature value HF; The authentication server generates a random challenge value R: R = CSPRNG(256); Among them, CSPRNG is a cryptographically secure random number generator; The device calculates the authentication response value Y: Y = HMAC-SHA3-256(HF, R || Timestamp); Among them, HMAC is the key hash message authentication code function, and Timestamp is the timestamp; After the authentication server verifies the response value Y, it generates a dynamic session token T: T = AES-256-GCM(K server , HF || Y || Timestamp) Among them, K server is the server-side key, and AES-256-GCM is the Advanced Encryption Standard algorithm with authenticated encryption; Combining the device hardware feature value with the dynamic session token to generate a device identity, and storing it securely; including: Combine the hardware feature value and the dynamic session token to generate a device identity DID: DID = HF|| T; Generate a signature using the elliptical digital signature algorithm: Sig DID = ECDSA(SK server , DID); Among them, SK server is the server private key, ECDSA is the elliptical digital signature function; The device identity DID and its signature are stored in local databases, and an index structure is established; Generate an initial password for the device using a homomorphic encryption algorithm based on lattice cryptography, and bind the initial password to the device identity for storage; Establish a password update model based on the spatiotemporal behavior feature matrix and environmental factors to dynamically update the device password; The device identity is verified based on the zero-knowledge proof mechanism to achieve hierarchical permission management based on attribute encryption.

2. The multi-system password security management method based on device authentication according to claim 1 is characterized in that: Generate an initial password for the device using a homomorphic encryption algorithm based on lattice cryptography, and bind the initial password to the device identity for storage, including: Initialize lattice cryptographic parameters and generate public-private key pairs for the Ring-LWE encryption scheme; Based on the device identity, a cryptographic seed value is generated through an extensible hash function, and cryptographic base support is built; Encrypting the cryptographic base support using a homomorphic encryption algorithm to generate a device initialization password; The device initial password is bound to the device identity and is securely stored in a variety of storage methods.

3. The multi-system password security management method based on device authentication according to claim 1 is characterized in that: A password update model is established based on the spatiotemporal behavior feature matrix and environmental factors to dynamically update the device password, including: Construct a device spatiotemporal behavior feature matrix based on the device behavior data, and perform standardization on the matrix; Build a password update prediction model using a deep neural network structure; Assess the security risks of devices based on environmental factors and dynamically adjust password update policies; Perform password update operations and ensure the security of the update process.

4. The multi-system password security management method based on device authentication according to claim 3 is characterized in that: The password update operation includes: Generate a new password P using the HMAC-based key derivation function new : P new = HKDF(P old || S, salt) Among them, HKDF is a key derivation function based on HMAC, S is a secure random number, and salt is a random value; Verify the strength of the newly generated password and calculate its entropy value: entropy = -Σ(p i ·log2(p i )) Among them, p i is the probability of occurrence of the i-th character. If the entropy value of the password meets the set strength requirement, the new password is considered to be secure enough; Use the homomorphic encryption algorithm to encrypt the newly generated password to protect the security of the password during storage and transmission: CT new = HE.Encrypt(P new , pk) Among them, HE.Encrypt is the homomorphic encryption function, and pk is the public key; Update password records in the storage system and save change logs of password updates to ensure that each password update has a traceable history.

5. The multi-system password security management method based on device authentication according to claim 1 is characterized in that: Verify device identity based on zero-knowledge proof mechanism to implement hierarchical permission management based on attribute encryption, including: Build a zero-knowledge proof protocol for identity authentication; Execute the zero-knowledge proof process; Build a hierarchical permission management system based on attribute encryption; Implement dynamic permission adjustment and access control.

6. The multi-system password security management method based on device authentication according to claim 5 is characterized in that: The trust score F of the device is calculated based on the device behavior data. The trust score is used to evaluate the reliability of the device: F = Σ(W i ·f i (B)) Among them, W i is the behavioral factor weight, f i is the evaluation function, B is the operating behavior of the device; Dynamically adjust permissions based on the device's trust score: When F≥0.8, the authority level is increased; When 0.5 ≤ F < 0.8, maintain the current authority; When F < 0.5, reduce the authority level.

Citation Information

Patent Citations

  • Dual authentication method, system and device for SSH safe login

    CN105162764A

  • Authentication method and device, equipment and medium

    CN116192483A