An Internet of Things security verification control protection system

By introducing multi-dimensional acquisition modules and intelligent protection modules into the IoT security verification control protection system, the problem of single security verification mechanisms and lack of dynamic risk assessment in traditional systems is solved, and the accurate identification of user accounts and trust level management is achieved, and the security and protection capabilities of the IoT system are improved.

CN119652673BActive Publication Date: 2025-05-09ZHEJIANG QIANGUA INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510166165.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-14
Publication Date
2025-05-09
Estimated Expiration
2045-02-14

AI Technical Summary

Technical Problem

The security verification mechanism of the traditional IoT security verification control protection system is single, making it difficult to effectively judge and manage accounts with different trust levels. It lacks a dynamic risk assessment mechanism, resulting in slow response speed and poor security protection capabilities during malicious attacks.

Method used

A security verification control protection system for IoT is designed, including a multi-dimensional acquisition module and an intelligent protection module. The multi-dimensional acquisition module collects user account data and IoT device management data through user data units and device data units. The intelligent protection module analyzes the frequency of user account data changes through security assessment units and prevention and control management units, divides user behavior types, builds a timeline, judges user account abnormalities, generates risk scores, and prioritizes upgrading IoT devices based on vulnerability scores.

Benefits of technology

It realizes accurate identification and trust level management of user accounts, improves the accuracy and response speed of protection, establishes a dynamic risk assessment mechanism, and enhances the security and protection capabilities of the Internet of Things system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119652673B_ABST
    Figure CN119652673B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of Internet of Things security protection technology, and discloses an Internet of Things security verification control protection system, including a multi-dimensional acquisition module and an intelligent protection module. The Internet of Things security verification control protection system collects account data of all users and management data of all Internet of Things devices through the multi-dimensional acquisition module, and classifies and forms a data set. The intelligent protection module analyzes the change frequency of each user's account data, and the account with higher change frequency is divided into the behavior type of each user, and a unified time axis is constructed. Then, the average time domain of each user is analyzed to determine whether the user account is abnormal, and a corresponding abnormal behavior data group and risk score are generated. The comprehensive analysis and recognition accuracy is high. The intelligent protection module identifies the attack target according to the abnormal behavior data group, and then analyzes the vulnerability score of each attack target, determines the trust level of the user account, and performs corresponding management measures, and has strong dynamic management and security protection capabilities.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of Internet of Things security protection, and in particular to an Internet of Things security verification control protection system. Background Art

[0002] With the continuous development of IoT technology, the application scenarios are also increasing, and the security issues of IoT will become more complex and diverse. The security issues of IoT are not only about the confidentiality, integrity and availability of information, but also involve identity authentication, device authorization, data privacy protection and other aspects. IoT devices and systems are often faced with vulnerability threats. In order to prevent attackers from exploiting vulnerabilities, the IoT security verification control and protection system needs to conduct vulnerability scanning and assessment regularly to timely discover and repair security vulnerabilities. In addition, equipment manufacturers also need to release security patches and ensure that devices can be updated automatically or manually to prevent vulnerabilities from existing for a long time. The security verification control and protection system is a set of comprehensive protection measures designed to ensure the security of IoT devices and networks and prevent illegal access and data leakage. The core functions include identity authentication, access control, data encryption, intrusion detection and prevention, vulnerability management, etc. The IoT security verification control and protection system is an important part of ensuring the security of IoT, protecting user privacy and promoting technological innovation. Through a multi-level and comprehensive protection mechanism, we can effectively respond to the security challenges faced by IoT and promote the healthy development of IoT technology.

[0003] At present, the traditional Internet of Things security verification control and protection system has a single security verification mechanism, which makes it difficult to effectively judge and manage accounts of different trust levels. It lacks a dynamic risk assessment mechanism, and when subjected to malicious attacks, it has a slow response speed and poor security protection capabilities. Summary of the invention

[0004] 1. Technical issues to be resolved

[0005] In view of the shortcomings of the prior art, the present invention provides an Internet of Things security verification control and protection system, which has the advantages of high comprehensive analysis and identification accuracy, strong dynamic management and security protection capabilities, etc., and solves the problems of the traditional Internet of Things security verification control and protection system having a single security verification mechanism and a lack of dynamic risk assessment mechanism.

[0006] (II) Technical solution

[0007] To achieve the above-mentioned purpose, the present invention provides the following technical solutions: an Internet of Things security verification control and protection system, comprising a multi-dimensional acquisition module and an intelligent protection module;

[0008] The multi-dimensional acquisition module is composed of a user data unit and a device data unit. The user data unit collects a user data set through a network connection to a database, and the user data set includes account data of all users. The device data unit collects a device data set through a network connection to an Internet of Things system, and the device data set includes management data of all Internet of Things devices.

[0009] The intelligent protection module consists of a security assessment unit and a prevention and control management unit. The security assessment unit analyzes the change frequency of each user account data based on the user data set. , and divide each user's behavior type according to the API interface usage record to build a unified timeline The safety assessment unit is based on the time axis , analyze the average time domain of each user , combined with the user data set, determine whether the user account is abnormal, and generate the corresponding abnormal behavior data set and risk score The prevention and control management unit is based on the abnormal behavior data group , identify the attack targets, and then analyze the vulnerability scores of each attack target based on the device data set The control management unit is set with a fixed range of frequency thresholds and scoring threshold , combined with the change frequency , Risk Score and abnormal behavior data set , determine the trust level of the user account and take corresponding management measures.

[0010] Preferably, the expression of the user data set is , to The first to the The account data of each user includes historical account name, historical account password, account-associated email address, IP address, and API interface usage records. Indicates the specific time when each user registered an account.

[0011] Preferably, the expression of the device data set is , to The first to the Management data of IoT devices, including API transmission speed and storage capacity. Indicates the access key length of each IoT device.

[0012] Preferably, the change frequency The calculation process is as follows:

[0013] Extract the user data set The account data of each user, and the statistics of Number of historical account name changes for each user , Statistics Number of times a user's historical account password has been changed , Statistics Number of changes to email addresses associated with user accounts , Statistics Number of times a user's IP address has changed ;

[0014]

[0015] In the formula, Indicates the current time point. Indicates The specific time when a user registered an account, Indicates The registration duration of each user account, Indicates The total number of changes to the user's historical account name, historical account password, account-associated email address, and IP address, It represents the ratio of the total number of changes to the registration duration, which is The frequency of changes to user accounts.

[0016] Preferably, the time axis The build process is as follows:

[0017] According to the user data set API usage records of each user, dividing the behavior into categories;

[0018] Jordi When a user accesses an IoT device only through an API interface, it is classified as an access behavior;

[0019] Jordi When a user downloads data through the API interface, it is classified as output behavior;

[0020] Jordi When a user uploads data through the API interface, it is classified as input behavior;

[0021] According to API usage records for each user, building a unified timeline , and each behavior corresponds to a time node.

[0022] Preferably, the abnormal behavior data set The calculation process is as follows:

[0023] S11. According to the timeline , Statistics The time of each user's login is marked as , to From the first to the The time of the first login, statistics The offline time of each user is marked as , to From the first to the The offline time point, During the registration period of user accounts, the total number of logins is ;

[0024] S12, calculate the Average login time of users and average offline time , and its calculation formula is as follows:

[0025]

[0026]

[0027] S13. According to Average login time of users and average offline time , which constitutes the average time domain ;

[0028] If the time axis In The login time of users exceeds the average time range If the number of times continues for three or more times, the The user account is marked as an abnormal account and the All behaviors of a user account constitute an abnormal behavior data group, including abnormal access behavior, abnormal output behavior, and abnormal input behavior.

[0029] Preferably, the risk score The calculation process is as follows:

[0030]

[0031] In the formula, Indicates the standard registration duration for a single user account. Indicates The registration duration of each user account, Indicates the standard registration duration and The ratio of the registration duration of each user account, Represents the evaluation weight for the registration duration ratio. represents the evaluation weight for the change frequency, Indicates abnormal behavior data group In The total number of abnormal behaviors of users, Represents the evaluation weight for the total number of abnormal behaviors, , Indicates according to , and Weight, calculate the The risk score of each user account.

[0032] Preferably, the vulnerability score The calculation process is as follows:

[0033] S21. Based on abnormal behavior data group , Statistics Abnormal access behavior of users , Statistics Abnormal output behavior of users , Statistics Abnormal input behavior of users ;

[0034] S22. According to Abnormal access behavior of users , Abnormal output behavior and abnormal input behavior , filter out the corresponding IoT devices in the device data set, and the selected IoT devices are all The target of the attack of users and marked as , to The first to the IoT devices compromised;

[0035] S23. Extract the first Management data of compromised IoT devices, , and the The API transfer speed of IoT devices is marked as , will The storage capacity of IoT devices is marked as ;

[0036]

[0037]

[0038] In the formula, Indicates The time it takes for an IoT device to transmit data. Indicates the standard time required for IoT devices to transmit data. represents the evaluation weight for the transmission time ratio, Indicates the standard length of IoT device access keys. Indicates the length of the access key of the IoT device. represents the evaluation weight for the key length ratio, , Indicates according to and Weight, calculate the Vulnerability scores for IoT devices.

[0039] Preferably, the change frequency Included in frequency threshold , the trust level of the user account is the first level, and the change frequency Frequency threshold exceeded When the user account is at the second level of trust, the account is forced to log off and re-authenticate. If a single user account has a record of abnormal account tags, the user account's trust level is the third level, and the user account's access scope is limited to one IoT device. If the risk score of a single user account is Below the rating threshold When the trust level of the user account is the third level, the account is forcibly blocked and the access keys of all IoT devices are updated. Among them, the access scope of the first level is better than the second level, and the access scope of the second level is better than the third level.

[0040] Preferably, the abnormal behavior data set When there is data in the vulnerability score, the prevention and control management unit Arrange IoT devices from high to low, and upgrade IoT devices with high rankings first.

[0041] Compared with the prior art, the present invention provides an Internet of Things security verification control protection system, which has the following beneficial effects:

[0042] 1. The present invention collects the account data of all users and the management data of all IoT devices through a multi-dimensional collection module, and classifies them into user data sets and device data sets. The intelligent protection module analyzes the change frequency of each user's account data based on the user data sets. The more frequently the account is changed, the lower the trust is and the higher the risk of abnormal behavior is. According to the API interface usage records, the behavior types of each user are divided and a unified timeline is constructed. , comprehensively analyze the behavioral characteristics of multiple user accounts, accurately identify attack targets, and the intelligent protection module , analyze the average time domain of each user , combined with the user data set, determine whether the user account is abnormal, and generate the corresponding abnormal behavior data set and risk score , comprehensive analysis and recognition with high accuracy.

[0043] 2. The present invention uses an intelligent protection module to , identify the attack targets, and then analyze the vulnerability scores of each attack target based on the device data set , change frequency Included in frequency threshold When the trust level of the user account is the first level, the change frequency Frequency threshold exceeded When the user account is at the second level of trust, the account is forced to log off and re-authenticate. If a single user account has a record of abnormal account tags, the user account's trust level is the third level, and the user account's access scope is limited to one IoT device. If the risk score of a single user account is Below the rating threshold When the trust level of the user account is the third level, the account is forcibly blocked and the access keys of all IoT devices are updated. This effectively determines and manages accounts of different trust levels, improves the accuracy and response speed of protection, and improves the abnormal behavior data group When there is data in the vulnerability score, the prevention and control management unit IoT devices are arranged from high to low, and high-ranking IoT devices are upgraded first. A dynamic risk assessment mechanism is established to enhance the security and protection capabilities of the IoT system. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] Figure 1 It is a schematic diagram of the system flow of the present invention. DETAILED DESCRIPTION

[0045] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0046] Due to the single security verification mechanism of the traditional IoT security verification control and protection system, it is difficult to effectively judge and manage accounts of different trust levels, lacks a dynamic risk assessment mechanism, and has a slow response speed and poor security protection capabilities when attacked by malicious attacks. Therefore, an IoT security verification control and protection system is provided. Please refer to Figure 1 , an Internet of Things security verification control and protection system, including a multi-dimensional acquisition module and an intelligent protection module;

[0047] The multi-dimensional acquisition module consists of a user data unit and a device data unit. The user data unit collects user data sets through a network connection to the database. The user data set includes the account data of all users. The expression of the user data set is: , to The first to the The account data of each user includes historical account name, historical account password, account-associated email address, IP address, and API interface usage records. Indicates the specific time when each user registered an account;

[0048] The device data unit collects the device data set through the network connection to the IoT system. The device data set includes the management data of all IoT devices. The expression of the device data set is , to The first to the Management data of IoT devices, including API transmission speed and storage capacity. Indicates the access key length of each IoT device;

[0049] The intelligent protection module consists of a security assessment unit and a prevention and control management unit. The security assessment unit analyzes the change frequency of each user account data based on the user data set. , and divide each user's behavior type according to the API interface usage record to build a unified timeline ;

[0050] Change frequency The calculation process is as follows:

[0051] Extract the user data set The account data of each user, and the statistics of Number of times a user's historical account name has been changed , Statistics Number of times a user's historical account password has been changed , Statistics Number of changes to email addresses associated with user accounts , Statistics Number of times a user's IP address has changed ;

[0052]

[0053] In the formula, Indicates the current time point. Indicates The specific time when a user registered an account, Indicates The registration duration of each user account, Indicates The total number of changes to the user's historical account name, historical account password, account-associated email address, and IP address, It represents the ratio of the total number of changes to the registration duration, which is The frequency of changes to user accounts. Accounts with higher frequency of changes have lower trust and higher risk of abnormal behavior.

[0054] Timeline The build process is as follows:

[0055] According to the user data set API usage records of each user, dividing the behavior into categories;

[0056] Jordi When a user accesses an IoT device only through an API interface, it is classified as an access behavior;

[0057] Jordi When a user downloads data through the API interface, it is classified as output behavior;

[0058] Jordi When a user uploads data through the API interface, it is classified as input behavior;

[0059] According to API usage records for each user, building a unified timeline , and each behavior corresponds to a time node. Specifically, in actual application, the behavior characteristics of multiple user accounts can be comprehensively analyzed to accurately identify attack targets;

[0060] Safety Assessment Unit according to timeline , analyze the average time domain of each user , combined with the user data set, determine whether the user account is abnormal, and generate the corresponding abnormal behavior data set and risk score ;

[0061] Abnormal Behavior Data Group The calculation process is as follows:

[0062] S11. According to the timeline , Statistics The time of each user's login is marked as , to From the first to the The time of the first login, statistics The offline time of each user is marked as , to From the first to the The offline time point, During the registration period of user accounts, the total number of logins is ;

[0063] S12, calculate the Average login time of users and average offline time , and its calculation formula is as follows:

[0064]

[0065]

[0066] S13. According to Average login time of users and average offline time , which constitutes the average time domain ;

[0067] If the time axis In The login time of users exceeds the average time range If the number of times continues for three or more times, the The user account is marked as an abnormal account and the All behaviors of a user account constitute an abnormal behavior data group, including abnormal access behavior, abnormal output behavior, and abnormal input behavior. Under normal circumstances, users usually log in during the day. If they suddenly log in frequently late at night, there may be a risk of being attacked;

[0068] Risk Scoring The calculation process is as follows:

[0069]

[0070] In the formula, Indicates the standard registration duration for a single user account. Indicates The registration duration of each user account, Indicates the standard registration duration and The ratio of the registration duration of each user account, Represents the evaluation weight for the registration duration ratio. represents the evaluation weight for the change frequency, Indicates abnormal behavior data group In The total number of abnormal behaviors of users, Represents the evaluation weight for the total number of abnormal behaviors, , Indicates according to , and Weight, calculate the Risk scoring for each user account, comprehensive analysis and high identification accuracy;

[0071] The prevention and control management unit is based on abnormal behavior data , identify the attack targets, and then analyze the vulnerability scores of each attack target based on the device data set ;

[0072] Vulnerability Scoring The calculation process is as follows:

[0073] S21. Based on abnormal behavior data group , Statistics Abnormal access behavior of users , Statistics Abnormal output behavior of users , Statistics Abnormal input behavior of users ;

[0074] S22. According to Abnormal access behavior of users , Abnormal output behavior and abnormal input behavior , filter out the corresponding IoT devices in the device data set, and the selected IoT devices are all The target of the attack of users and marked as , to The first to the IoT devices compromised;

[0075] S23. Extract the first Management data of compromised IoT devices, , and the The API transfer speed of IoT devices is marked as , will The storage capacity of IoT devices is marked as ;

[0076]

[0077]

[0078] In the formula, Indicates The time it takes for an IoT device to transmit data. Indicates the standard time required for IoT devices to transmit data. represents the evaluation weight for the transmission time ratio, Indicates the standard length of IoT device access keys. Indicates the length of the access key of the IoT device. represents the evaluation weight for the key length ratio, , Indicates according to and Weight, calculate the Vulnerability scores for IoT devices;

[0079] The control management unit sets a fixed range of frequency thresholds and scoring threshold , combined with the change frequency , Risk Score and abnormal behavior data set , determine the trust level of the user account and the frequency of change Included in frequency threshold When the trust level of the user account is the first level, the change frequency Frequency threshold exceeded When the user account is at the second level of trust, the account is forced to log off and re-authenticate. If a single user account has a record of abnormal account tags, the user account's trust level is the third level, and the user account's access scope is limited to one IoT device. If the risk score of a single user account is Below the rating threshold When the trust level of the user account is the third level, the account is forcibly blocked and the access keys of all IoT devices are updated. Among them, the access scope of the first level is better than the second level, and the access scope of the second level is better than the third level. Accounts of different trust levels are effectively judged and managed, and the accuracy and response speed of protection are improved. The abnormal behavior data group When there is data in the vulnerability score, the prevention and control management unit IoT devices are arranged from high to low, and high-ranking IoT devices are upgraded first. A dynamic risk assessment mechanism is established to enhance the security and protection capabilities of the IoT system.

[0080] Example 1: In this experiment, a user account that has been registered for one month is selected as the experimental object. According to statistics, the number of changes in the user's historical account name is 3 times, the number of changes in the user's historical account password is 3 times, the number of changes in the user's account-associated email address is 2 times, and the number of changes in the user's IP address is 3 times. The change frequency of the user The calculation formula is as follows:

[0081]

[0082] In the formula, Indicates the registration duration of the user account, in days. Indicates the total number of changes to the user's historical account name, historical account password, account-associated email address, and IP address. Indicates the ratio of the total number of changes to the registration duration. The change frequency of this user account is sky.

[0083] Example 2: In this experiment, a user account that has been registered for five years is selected as the experimental object. According to statistics, the standard registration period of a single user account is one year. Within five years, the change frequency of the user account is In 2017, the user account was not marked as an abnormal account, and the user risk score The calculation formula is as follows:

[0084]

[0085]

[0086] In the formula, Indicates the standard registration duration and The ratio of the registration duration of each user account, Represents the evaluation weight for the registration duration ratio. represents the evaluation weight for the change frequency, Represents the evaluation weight for the total number of abnormal behaviors, according to , and Weight, the risk score of the user account is calculated as .

[0087] Although embodiments of the present invention have been shown and described, it will be appreciated by those skilled in the art that various changes, modifications, substitutions and variations may be made to the embodiments without departing from the principles and spirit of the present invention, and that the scope of the present invention is defined by the appended claims and their equivalents.

Claims

1. An Internet of Things security verification control and protection system, characterized in that: Including multi-dimensional acquisition module and intelligent protection module; The multi-dimensional acquisition module is composed of a user data unit and a device data unit. The user data unit collects a user data set through a network connection to a database, and the user data set includes account data of all users. The device data unit collects a device data set through a network connection to an Internet of Things system, and the device data set includes management data of all Internet of Things devices. The intelligent protection module consists of a security assessment unit and a prevention and control management unit. The security assessment unit analyzes the change frequency of each user account data based on the user data set. , and divide each user's behavior type according to the API interface usage record to build a unified timeline The safety assessment unit is based on the time axis , analyze the average time domain of each user , combined with the user data set, determine whether the user account is abnormal, and generate the corresponding abnormal behavior data set and risk score The prevention and control management unit is based on the abnormal behavior data group , identify the attack targets, and then analyze the vulnerability scores of each attack target based on the device data set The control management unit is set with a fixed range of frequency thresholds and scoring threshold , combined with the change frequency , Risk Score and abnormal behavior data set , determine the trust level of the user account and take corresponding management measures.

2. The Internet of Things security verification control and protection system according to claim 1 is characterized in that: The expression of the user data set is: , to The first to the The account data of each user includes historical account name, historical account password, account-associated email address, IP address, and API interface usage records. Indicates the specific time when each user registered an account.

3. The Internet of Things security verification control and protection system according to claim 2 is characterized in that: The expression of the device data set is , to The first to the Management data of IoT devices, including API transmission speed and storage capacity. Indicates the access key length of each IoT device.

4. The Internet of Things security verification control and protection system according to claim 3 is characterized in that: The frequency of change The calculation process is as follows: Extract the user data set The account data of each user, and the statistics of Number of times a user's historical account name has been changed , Statistics Number of times a user's historical account password has been changed , Statistics Number of changes to email addresses associated with user accounts , Statistics Number of times a user's IP address has changed ; ; In the formula, Indicates the current time point. Indicates The specific time when a user registered an account, Indicates The registration duration of each user account, Indicates The total number of changes to the user's historical account name, historical account password, account-associated email address, and IP address, It represents the ratio of the total number of changes to the registration duration, which is The frequency of changes to user accounts.

5. The Internet of Things security verification control and protection system according to claim 4 is characterized in that: The timeline The build process is as follows: According to the user data set API usage records of each user, dividing the behavior into categories; Jordi When a user accesses an IoT device only through an API interface, it is classified as an access behavior; Jordi When a user downloads data through the API interface, it is classified as output behavior; Jordi When a user uploads data through the API interface, it is classified as input behavior; According to API usage records for each user, building a unified timeline , and each behavior corresponds to a time node.

6. The Internet of Things security verification control and protection system according to claim 5 is characterized in that: The abnormal behavior data set The calculation process is as follows: S11. According to the timeline , Statistics The time of each user's login is marked as , to From the first to the The time of the first login, statistics The offline time of each user is marked as , to From the first to the The offline time point, During the registration period of user accounts, the total number of logins is ; S12, calculate the Average login time of users and average offline time , and its calculation formula is as follows: ; ; S13. According to Average login time of users and average offline time , which constitutes the average time domain ; If the time axis In The login time of users exceeds the average time range If the number of times continues for three or more times, the The user account is marked as an abnormal account and the All behaviors of a user account constitute an abnormal behavior data group, including abnormal access behavior, abnormal output behavior, and abnormal input behavior.

7. The Internet of Things security verification control and protection system according to claim 6 is characterized in that: The risk score The calculation process is as follows: ; In the formula, Indicates the standard registration duration for a single user account. Indicates The registration duration of each user account, Indicates the standard registration duration and The ratio of the registration duration of each user account, Represents the evaluation weight for the registration duration ratio. represents the evaluation weight for the change frequency, Indicates abnormal behavior data group In The total number of abnormal behaviors of users, Represents the evaluation weight for the total number of abnormal behaviors, , Indicates according to , and Weight, calculate the The risk score of each user account.

8. The Internet of Things security verification control and protection system according to claim 7 is characterized in that: Score of the vulnerability The calculation process is as follows: S21. Based on abnormal behavior data group , Statistics Abnormal access behavior of users , Statistics Abnormal output behavior of users , Statistics Abnormal input behavior of users ; S22. According to Abnormal access behavior of users , Abnormal output behavior and abnormal input behavior , filter out the corresponding IoT devices in the device data set, and the filtered IoT devices are all The target of the attack of users and marked as , to The first to the IoT devices compromised; S23. Extract the first Management data of compromised IoT devices, , and the The API transfer speed of IoT devices is marked as , will The storage capacity of IoT devices is marked as ; ; ; In the formula, Indicates The time it takes for an IoT device to transmit data. Indicates the standard time required for IoT devices to transmit data. represents the evaluation weight for the transmission time ratio, Indicates the standard length of IoT device access keys. Indicates the length of the access key of the IoT device. represents the evaluation weight for the key length ratio, , Indicates according to and Weight, calculate the Vulnerability scores for IoT devices.

9. The Internet of Things security verification control and protection system according to claim 8, characterized in that: The frequency of change Included in frequency threshold , the trust level of the user account is the first level, and the change frequency Frequency threshold exceeded When the user account is at the second level of trust, the account is forced to log off and re-authenticate. If a single user account has a record of abnormal account tags, the user account's trust level is the third level, and the user account's access scope is limited to one IoT device. If the risk score of a single user account is Below the rating threshold When the trust level of the user account is the third level, the account is forcibly blocked and the access keys of all IoT devices are updated. Among them, the access scope of the first level is better than the second level, and the access scope of the second level is better than the third level.

10. The Internet of Things security verification control and protection system according to claim 9, characterized in that: The abnormal behavior data set When there is data in the vulnerability score, the prevention and control management unit Arrange IoT devices from high to low, and upgrade IoT devices with high rankings first.

Citation Information

Patent Citations

  • Account risk evaluation method based on relational network

    CN114066470A

  • Information security risk assessment system based on Internet of Things

    CN118445796A