A method for accessing information system

By building an identity device identification blockchain and dynamic device access identifiers, the problems of overload and single security of centralized systems are solved, decentralized management and cross-device access control are achieved, and the security and adaptability of the system are enhanced, making it suitable for the Internet of Things and mobile device environments.

CN119783083BActive Publication Date: 2025-09-26SHANDONG WANQIAN YOUXIN ENTERPRISE SERVICE CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202411638226.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-23
Publication Date
2025-09-26
Estimated Expiration
2045-02-23

AI Technical Summary

Technical Problem

The existing centralized identity management system is overloaded when faced with a large number of devices accessing it simultaneously, has a single security model, lacks dynamic identity conversion capabilities, and cannot effectively deal with situations where device authentication fails or is hacked.

Method used

By building an identity device identification blockchain, leveraging the blockchain's immutability for decentralized storage and management, dynamically updating device identities, combining dynamic device access identifiers for dual authentication, and generating cross-device access solutions, refined access control can be achieved.

Benefits of technology

It improves system security and flexibility, solves the problem of overload in centralized systems, enhances adaptability to rapidly changing environments, ensures system security and reliability, and is particularly suitable for environments where the Internet of Things and mobile devices are prevalent.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119783083B_ABST
    Figure CN119783083B_ABST
Patent Text Reader

Abstract

The present invention relates to the field of data interaction technology, and in particular to a method for accessing an information system. The method comprises the following steps: obtaining system access user data, extracting access device data, and constructing an identity device identification blockchain. Identifying a new access device through access device data is converted into an identifier, and performing dynamic identification conversion on the identity device identification blockchain to obtain a dynamic device access identifier. Dynamic user access identification is performed on user data, and new device analysis is performed with the dynamic device access identifier to obtain device information system access data and a new device authentication sequence. The dynamic device access identifier is converted into an identification authentication sequence, and based on this, cross-device access processing is performed on the new device authentication sequence, and finally, the same-device and cross-device access data are combined to generate an information system access plan. The present invention enhances the security of information system access and improves the security of cross-device access through dynamic identification conversion technology.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data interaction, and in particular to an access method for an information system. Background Art

[0002] Current technologies typically employ centralized identity management systems, using traditional databases to store user and device information. This traditional approach typically employs a centralized architecture and uses a database to store user and device information, making system design and implementation relatively simple, especially for small or closed systems. Centralized systems provide centralized control and management, making it easier for administrators to manage and monitor user access. Administrators can easily add, remove, or modify user permissions and centrally manage security policies for the entire system. However, these systems suffer from security and flexibility limitations. For example, simultaneous access by a large number of devices can overload the centralized system, impacting responsiveness. Furthermore, if the central database is compromised or compromised, the security of the entire system is severely impacted. Existing technologies often lack dynamic identity conversion capabilities and are unable to update device identities in real time, limiting their ability to adapt to rapidly changing environments. While some systems implement cross-device access control, they lack effective responses to device authentication failures or compromises. Summary of the Invention

[0003] Based on this, it is necessary to provide an information system access method to solve at least one of the above technical problems.

[0004] To achieve the above object, a method for accessing an information system is provided, the method comprising the following steps:

[0005] Step S1: Obtain system access user data; extract access device data from the system access user data to obtain access device data; construct an identification blockchain based on the system access user data and access device data to obtain an identity device identification blockchain;

[0006] Step S2: Identify the new access device based on the access device data to obtain new access device data; perform identifier conversion on the new access device data to obtain a new device identifier; perform new device block conversion on the new access device data to obtain new device block data; perform dynamic identifier conversion on the identity device identification blockchain based on the new device block data to obtain a dynamic device access identifier;

[0007] Step S3: Perform dynamic user access identification on the system access user data to obtain user access identification data; perform new device analysis on the dynamic device access identifier based on the user access identification data to obtain device information system access data and a new device authentication sequence;

[0008] Step S4: Perform authentication data conversion on the dynamic device access identifier to obtain an identification authentication sequence; perform information system cross-device access processing on the new device authentication sequence based on the identification authentication sequence to obtain cross-device information system access data; perform information system access based on the same-device information system access data and the cross-device information system access data to obtain an information system access plan.

[0009] This invention achieves decentralized storage and management of identity and device information by acquiring user and device data and constructing an identity device identification blockchain. Leveraging the immutability of blockchain, it effectively prevents identity forgery and data tampering, improving system security and mitigating the risk of central database intrusion or compromise. New access devices are identified, their identifiers converted, and their blocks converted. Dynamic identity conversion is then performed using the identity device identification blockchain to generate a dynamic device access identifier. This enables dynamic updates of device identities, enhancing the system's adaptability to rapidly changing environments and addressing the lack of dynamic identity conversion capabilities in existing technologies. Users are dynamically identified for access and, combined with the dynamic device access identifier, new device analysis is performed to generate device information system access data and a new device authentication sequence. This achieves dual authentication of users and devices, further improving access security and providing foundational data for subsequent cross-device access control. The dynamic device access identifier is converted into an identity authentication sequence, which is then combined with the new device authentication sequence for cross-device access processing, ultimately generating an information system access plan. This enables refined cross-device access control, effectively addressing device authentication failures or intrusions, and addressing the issue of excessive load on centralized systems when a large number of devices access simultaneously. This approach provides a secure, flexible, and efficient access control mechanism, particularly suitable for environments with widespread IoT and mobile devices. It addresses issues such as overloaded centralized systems, single-source security, and a lack of dynamic updates and cross-device access control. It also introduces a zero-trust mechanism to ensure system security and reliability. BRIEF DESCRIPTION OF THE DRAWINGS

[0010] Figure 1 A flowchart of steps of a method for accessing an information system;

[0011] Figure 2 for Figure 1 Detailed implementation steps of step S2 in FIG.

[0012] Figure 3 for Figure 2 Detailed implementation steps of step S25 are shown in the flowchart.

[0013] The purpose, features and advantages of the present invention will be further described with reference to the accompanying drawings and in conjunction with the embodiments. DETAILED DESCRIPTION

[0014] The following is a clear and complete description of the technical method of the present invention in conjunction with the accompanying drawings. It is obvious that the embodiments described are part of the embodiments of the present invention, but not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making any creative efforts are within the scope of protection of the present invention.

[0015] In addition, the accompanying drawings are merely schematic illustrations of the present invention and are not necessarily drawn to scale. Identical reference numerals in the figures denote identical or similar parts, and thus repetitive descriptions thereof will be omitted. Some of the block diagrams shown in the accompanying drawings are functional entities that do not necessarily correspond to physically or logically separate entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor and / or microcontroller approaches.

[0016] It should be understood that although the terms "first," "second," and the like may be used herein to describe various elements, these elements should not be limited by these terms. These terms are used solely to distinguish one element from another. For example, a first element may be referred to as a second element, and similarly, a second element may be referred to as a first element, without departing from the scope of the exemplary embodiments. The term "and / or" as used herein includes any and all combinations of one or more of the listed associated items.

[0017] To achieve this, please refer to Figures 1 to 3 , a method for accessing an information system, the method comprising the following steps:

[0018] Step S1: Obtain system access user data; extract access device data from the system access user data to obtain access device data; construct an identification blockchain based on the system access user data and access device data to obtain an identity device identification blockchain;

[0019] Step S2: Identify the new access device based on the access device data to obtain new access device data; perform identifier conversion on the new access device data to obtain a new device identifier; perform new device block conversion on the new access device data to obtain new device block data; perform dynamic identifier conversion on the identity device identification blockchain based on the new device block data to obtain a dynamic device access identifier;

[0020] Step S3: Perform dynamic user access identification on the system access user data to obtain user access identification data; perform new device analysis on the dynamic device access identifier based on the user access identification data to obtain device information system access data and a new device authentication sequence;

[0021] Step S4: Perform authentication data conversion on the dynamic device access identifier to obtain an identification authentication sequence; perform information system cross-device access processing on the new device authentication sequence based on the identification authentication sequence to obtain cross-device information system access data; perform information system access based on the same-device information system access data and the cross-device information system access data to obtain an information system access plan.

[0022] In the embodiment of the present invention, please refer to Figure 1 FIG. 1 is a flow chart showing the steps of a method for accessing an information system according to the present invention. In this example, the method for accessing an information system includes the following steps:

[0023] Step S1: Obtain system access user data; extract access device data from the system access user data to obtain access device data; construct an identification blockchain based on the system access user data and access device data to obtain an identity device identification blockchain;

[0024] In an embodiment of the present invention, user access data is obtained through the system, including user information such as user name, password, IP address, access time, and database information such as user ID, user group, and access rights, and access device data such as device type, operating system, browser version, MAC address, IP address, etc. are extracted, and an access device identifier is generated using a hash algorithm. The user data is associated with the identifier to generate access device associated data, and finally the associated data and identifier are packaged into a new block containing user information, access time, device information, identifier and the hash value of the previous block to form an identity device identification blockchain.

[0025] Step S2: Identify the new access device based on the access device data to obtain new access device data; perform identifier conversion on the new access device data to obtain a new device identifier; perform new device block conversion on the new access device data to obtain new device block data; perform dynamic identifier conversion on the identity device identification blockchain based on the new device block data to obtain a dynamic device access identifier;

[0026] In an embodiment of the present invention, the system identifies a new access device based on access device data and generates a new device identifier using a hash algorithm; then, based on the new access device data, the associated user identity information is searched in the identity device identification blockchain to obtain an access identity unit, and based on the access identity unit, the new device access block is located, and the new device identifier is compared and verified with the device identifier in the block, and the block data is extracted to obtain the new device block data; then, based on the new access device data, the new device block data is subjected to a time-series attenuation weight generation to obtain the new device time-series attenuation weight data; finally, a dynamic device access identifier is generated based on the new device block data, the new device time-series attenuation weight data, the access identity unit and other information.

[0027] Step S3: Perform dynamic user access identification on the system access user data to obtain user access identification data; perform new device analysis on the dynamic device access identifier based on the user access identification data to obtain device information system access data and a new device authentication sequence;

[0028] In an embodiment of the present invention, the system performs dynamic user access identification on user access data to obtain user access identification data, and based on this data, extracts user identity information from the dynamic device access identifier to obtain a dynamic user access identifier; then the dynamic user access identifier is compared with the dynamic device access identifier to obtain new device identification comparison data containing identification comparison identical data and identification comparison difference data; finally, based on the comparison result, if the identification comparison is identical data, information system access processing is performed to obtain the same device information system access data; if the identification comparison is different data, new device authentication processing is performed to obtain a new device authentication sequence.

[0029] Step S4: Perform authentication data conversion on the dynamic device access identifier to obtain an identification authentication sequence; perform information system cross-device access processing on the new device authentication sequence based on the identification authentication sequence to obtain cross-device information system access data; perform information system access based on the same-device information system access data and the cross-device information system access data to obtain an information system access plan.

[0030] In an embodiment of the present invention, the system converts the dynamic device access identifier into authentication data to obtain an identification authentication sequence, and compares it with the new device authentication sequence to obtain new device sequence authentication data containing authentication sequence comparison identical data and authentication sequence comparison difference data; if the comparison result is authentication sequence comparison identical data, information system access processing is performed to obtain cross-device information system access data; if the comparison result is authentication sequence comparison difference data, device zero-trust identification processing is performed on the new device authentication sequence to obtain a device zero-trust identification; finally, an information system access plan is formulated based on the same-device information system access data and the cross-device information system access data.

[0031] This invention achieves decentralized storage and management of identity and device information by acquiring user and device data and constructing an identity device identification blockchain. Leveraging the immutability of blockchain, it effectively prevents identity forgery and data tampering, improving system security and mitigating the risk of central database intrusion or compromise. New access devices are identified, their identifiers converted, and their blocks converted. Dynamic identity conversion is then performed using the identity device identification blockchain to generate a dynamic device access identifier. This enables dynamic updates of device identities, enhancing the system's adaptability to rapidly changing environments and addressing the lack of dynamic identity conversion capabilities in existing technologies. Users are dynamically identified for access and, combined with the dynamic device access identifier, new device analysis is performed to generate device information system access data and a new device authentication sequence. This achieves dual authentication of users and devices, further improving access security and providing foundational data for subsequent cross-device access control. The dynamic device access identifier is converted into an identity authentication sequence, which is then combined with the new device authentication sequence for cross-device access processing, ultimately generating an information system access plan. This enables refined cross-device access control, effectively addressing device authentication failures or intrusions, and addressing the issue of excessive load on centralized systems when a large number of devices access simultaneously. This approach provides a secure, flexible, and efficient access control mechanism, particularly suitable for environments with widespread IoT and mobile devices. It addresses issues such as overloaded centralized systems, single-source security, and a lack of dynamic updates and cross-device access control. It also introduces a zero-trust mechanism to ensure system security and reliability.

[0032] Preferably, step S1 includes the following steps:

[0033] Step S11: Obtain system access user data;

[0034] In this embodiment of the present invention, when a user attempts to access the system, the system collects the user's identity information, such as username and password, through the user login interface. The system also records information such as the user's IP address and access time. Furthermore, the system can retrieve other user-related information, such as user ID, user group, and access permissions, from an existing user database. The system verifies the username and password submitted by the user to ensure the legitimacy of the user's identity. Once verification is successful, the system stores the collected user information in temporary variables for use in subsequent steps.

[0035] Step S12: extracting access device data from the system access user data to obtain access device data;

[0036] In this embodiment of the present invention, access device data is extracted from system access user data. The system analyzes the User-Agent field in the user's access request to extract information such as the device type, operating system version, and browser version. The system also analyzes network data packets to extract network information such as the device's MAC address and IP address. If the user uses a mobile device, the system may also attempt to obtain unique identifiers such as the device's IMEI and IMSI numbers.

[0037] Step S13: Generate an identifier based on the access device data to obtain an access device identifier;

[0038] In this embodiment of the present invention, the access device identifier is generated by generating an identifier based on the access device data. The system uses a hash algorithm, such as SHA-256, to hash the extracted device feature data, generating a fixed-length hash value as the access device identifier. To ensure the uniqueness of the identifier, the system compares the generated identifier with an existing identifier database. If a duplicate is found, a new identifier is generated until a unique identifier is generated.

[0039] Step S14: performing data association on the system access user data based on the access device identifier to obtain access device association data;

[0040] In this embodiment of the present invention, the system associates the acquired system access user data with the generated access device identifier to generate access device association data. This association data can be stored in a temporary data structure, such as a dictionary or a table, where the key-value pairs are user identity information and access device identifier. This association data includes user identity, access time, device information, etc.

[0041] Step S15: Block mapping is performed based on the access device association data and the access device identifier to obtain the identity device identification blockchain.

[0042] In this embodiment of the present invention, the identity device identification blockchain is generated by performing block mapping based on the access device association data and the access device identifier. The system packages the generated access device association data and the access device identifier into a new block. This block contains user identity information, access time, device information, the access device identifier, and the hash value of the previous block.

[0043] By acquiring system access user data and extracting access device data, the system can establish an association between users and devices. This crucial data collection process ensures accurate authentication and access control in subsequent steps. By analyzing user access behavior and device characteristics, user identity and device status can be more accurately identified. Based on the access device data, an access device identifier is generated, assigning a unique identifier to each access device. This allows the system to distinguish between different access devices, even when the same user accesses different devices. The generation of access device identifiers can utilize techniques such as hashing algorithms to ensure uniqueness and security. The access device identifier is then used to associate system access user data with access device data to generate access device association data. This establishes a clear correspondence between users and devices, providing a data foundation for subsequent block mapping operations. By associating user and device data, a more comprehensive understanding of user access behavior and device usage can be achieved. Ultimately, an identity and device identification blockchain is formed. This leverages the decentralized and tamper-proof nature of blockchain to ensure the security of identity and device information, prevent data tampering or forgery, and achieve trusted identity and device identification management. It constitutes a powerful authentication and access control framework. By combining device data and user data, the system can make more accurate and secure access control decisions while ensuring decentralized and secure user identity management.

[0044] Preferably, step S13 includes the following steps:

[0045] Step S131: extracting feature data based on access device data to obtain device feature data;

[0046] In an embodiment of the present invention, the system extracts various device feature information from the access device data, such as operating system type, operating system version number, browser type, browser version number, device model, CPU architecture, screen resolution, language setting, plug-in information, time zone, etc.

[0047] Step S132: performing a hash algorithm conversion on the device feature data to obtain an initial device feature identifier; performing identifier deduplication on the initial device feature identifier to obtain a device feature identifier;

[0048] In this embodiment of the present invention, the system uses a hash algorithm to hash the device feature data. The structured device feature data is serialized into a string and used as input to the hash algorithm, resulting in a fixed-length hash value, the initial device feature identifier. The system then queries the database to see if the initial identifier exists. If so, it indicates that the device has previously accessed the system, and the system uses the existing device feature identifier. If not, the initial identifier is stored in the database as the device feature identifier and associated with the current access.

[0049] Step S133: performing access data analysis based on the access device data to obtain access data, wherein the access data includes access timestamp data and access geographic location data;

[0050] In this embodiment of the present invention, the system extracts access timestamp data from the access device data, accurate to the millisecond level. Simultaneously, the system attempts to obtain the user's geolocation information. If the user authorizes location access permissions, the system can obtain the user's latitude and longitude coordinates through the browser API or IP address location.

[0051] Step S134: converting the access timestamp data and the access geographic location data into an access system identifier to obtain an access user identifier;

[0052] In this embodiment of the present invention, the access user identifier is obtained by converting the access timestamp data and the access geolocation data into an access system identifier. The system combines the access timestamp and geolocation data into a string, such as "timestamp-longitude-latitude". This string is then hashed using a hash algorithm to obtain a fixed-length hash value as the access user identifier.

[0053] Step S135: Correspondingly associate the device feature identifier and the access user identifier to obtain the access device identifier.

[0054] In this embodiment of the present invention, the system associates the obtained device feature identifier with the obtained access user identifier to generate a final access device identifier. This association can be done by simply concatenating the strings, such as "device feature identifier - access user identifier," or by hashing the two together to generate a new hash value as the final access device identifier.

[0055] The present invention extracts device feature data, such as device model, operating system version, browser type, and IP address, from access device data. This feature data is extracted to more accurately identify devices and distinguish between different devices. Even devices of the same model can be distinguished through other features. This provides the basis for the subsequent generation of a unique device identifier. A hash algorithm is applied to the device feature data to generate an initial device feature identifier, which is then deduplicated to obtain a unique device feature identifier. This method ensures the privacy and security of device features while providing a simple device identification method. This data can provide additional user information, such as user access habits and activity ranges. This helps to more comprehensively understand user behavior patterns and improve the accuracy of user identification. This data is converted into an access user identifier, providing a representation of user identity. Combined with the device feature identifier, a more accurate user-device mapping can be achieved. The device feature identifier and the access user identifier are then associated to generate a final access device identifier. This step combines device information with user behavior information to generate a more recognizable access device identifier, enabling more accurate identification of users and devices and enhancing access control security.

[0056] Preferably, step S15 includes the following steps:

[0057] Step S151: Slice the access device identifier to obtain identifier slicing data, wherein the identifier slicing data includes access identity identifier slicing data and device identifier slicing data;

[0058] In embodiments of the present invention, data sharding of an access device identifier can be performed to divide the identifier into multiple parts, each representing different information. For example, an identifier includes information such as a user ID, device type, and access rights, and this information can be sharded into different parts. The sharded data can include access identity identifier fragments and device identifier fragments.

[0059] Step S152: Blocking the access identity identifier fragment data and the device identifier fragment data to obtain access identity block data and access device block data;

[0060] In this embodiment of the present invention, the system processes the access identifier fragment and the device identifier fragment separately. Taking the access identifier fragment as an example, the system combines this fragment with the current timestamp, a random number, and the hash value of the previous block. The system then uses a hash algorithm to hash this combined data, generating a new hash value that serves as the hash value of the current block. The data structure containing the access identifier fragment, timestamp, random number, previous block hash value, and current block hash value now constitutes the access identifier block data.

[0061] Step S153: performing chain creation processing on the access identity block data and the access device block data to obtain the access identity blockchain and the access device blockchain;

[0062] In this embodiment of the present invention, the system links the generated access identity block data and access device block data to their respective blockchains. For the access identity blockchain, the system appends the new access identity block data to the end of the chain, linking it to the previous block. The hash value of the new block is recorded in the next block, forming a chain structure and creating two independent blockchains, one for storing access identity information and the other for device information.

[0063] Step S154: Based on the access device association data and the access device blockchain, a cross-chain mapping interaction is performed on the access identity blockchain to obtain the identity device identification blockchain.

[0064] In this embodiment of the present invention, the system leverages access device-associated data to establish a mapping between the access identity blockchain and the access device blockchain. For example, the system can add a pointer or hash value to a block on the access identity blockchain that points to a corresponding block on the access device blockchain. This allows information on the access identity blockchain to be used to find corresponding information on the access device blockchain, thereby linking user identity and device information. Ultimately, through this cross-chain mapping interaction, the system constructs a unified identity device identification blockchain.

[0065] The present invention shards data using access device identifiers, splitting it into access identity identifier shard data and device identifier shard data. Data sharding improves data security; even if some shard data is leaked, the security of the entire identifier remains intact. Furthermore, data sharding improves data processing efficiency. By constructing the access identity identifier shard data and the device identifier shard data into blocks, respectively, the resulting access identity block data and access device block data ensure data integrity and immutability. Blockchain creation is then performed on the block data to form an access identity and device blockchain. Blockchain technology provides a secure, decentralized data storage and management method, ensuring data integrity and tamper-resistance. It allows interaction and data exchange between different blockchains, thereby establishing a unified identity and device identification system. This approach addresses interoperability issues between different data sources and blockchains, ensuring accurate management of user and device identities in a distributed environment. This results in a distributed, secure, and scalable identity and device identification system, enabling information systems to effectively manage user and device access in complex environments while ensuring data security and system performance.

[0066] Preferably, step S2 includes the following steps:

[0067] Step S21: Identify the new access device according to the access device data to obtain the new access device data;

[0068] Step S22: performing identifier conversion on the new access device data to obtain a new device identifier;

[0069] Step S23: performing access identity unit identification on the identity device identification blockchain based on the new access device data to obtain an access identity unit;

[0070] Step S24: Locate the block of the identity device identification blockchain based on the access identity unit to obtain the new device access block; verify and map the new device access block according to the new device identifier to obtain the new device block data;

[0071] Step S25: generating a time-series weakening weight for the new device block data according to the new access device data to obtain the new device time-series weakening weight data;

[0072] Step S26: Perform dynamic identification conversion on the identity device identification blockchain according to the new device block data and the new device time sequence attenuation weight data to obtain a dynamic device access identifier.

[0073] As an embodiment of the present invention, refer to Figure 2 As shown, Figure 1 Detailed step flow diagram of step S2 in the embodiment, step S2 includes the following steps:

[0074] Step S21: Identify the new access device according to the access device data to obtain the new access device data;

[0075] In this embodiment of the present invention, the system receives a user's access request, which includes access device data such as device type, operating system, browser version, IP address, MAC address, etc. The system compares this data with an existing device database. If a matching record is found, the device is considered a known device; if no matching record is found, the device is considered a new access device.

[0076] Step S22: performing identifier conversion on the new access device data to obtain a new device identifier;

[0077] In this embodiment of the present invention, the system uses a hash algorithm, such as SHA-256 or MD5, to hash the newly accessed device data and generate a fixed-length hash value as the new device identifier. To ensure the uniqueness of the identifier, the system checks whether the generated identifier already exists in the system. If so, a new identifier is generated until a unique identifier is generated.

[0078] Step S23: performing access identity unit identification on the identity device identification blockchain based on the new access device data to obtain an access identity unit;

[0079] In this embodiment of the present invention, the system searches for the user identity information associated with the newly accessed device data, such as the IP address and user agent string, in the identity device identification blockchain. This search involves traversing multiple blocks on the blockchain until a matching record is found. Once a matching record is found, the system extracts the corresponding user identity information, such as the username and user ID, as the access identity unit.

[0080] Step S24: Locate the block of the identity device identification blockchain based on the access identity unit to obtain the new device access block; verify and map the new device access block according to the new device identifier to obtain the new device block data;

[0081] In this embodiment of the present invention, the system searches for a corresponding block in the device identification blockchain based on the access identity unit. After locating the block, the system compares the new device identifier with the device identifier in the block. If a match is found, the block is marked as a new device access block and other relevant data in the block, such as access time and access permissions, is extracted as the new device block data.

[0082] Step S25: generating a time-series weakening weight for the new device block data according to the new access device data to obtain the new device time-series weakening weight data;

[0083] In this embodiment of the present invention, the system calculates a time-sequentially decreasing weight based on the access time of a new access device. For example, an exponential decay function can be used to calculate the weight based on the difference between the access time and the current time. The greater the time difference, the smaller the weight. This weight reflects the trustworthiness of the new device; the more recent the access time, the higher the trustworthiness.

[0084] Step S26: Perform dynamic identification conversion on the identity device identification blockchain according to the new device block data and the new device time sequence attenuation weight data to obtain a dynamic device access identifier.

[0085] In an embodiment of the present invention, the system combines new device block data, new device timing attenuation weight data and other related information, such as access identity units, and uses a hash algorithm to generate a new dynamic device access identifier. This identifier is dynamically generated and contains device information, user identity information and time information.

[0086] This invention identifies new devices by analyzing access device data and collects new device information, providing a foundation for subsequent identification and verification. This helps distinguish new devices from registered devices, enabling differentiated management. New device data is converted into a unique identifier, facilitating system tracking and management of new device access behavior and facilitating subsequent blockchain operations. This simplifies device management. New device data is used to identify the corresponding user identity unit on the blockchain, linking the device to the user and ensuring the legitimacy of device access. This strengthens device access security and prevents unauthorized access. The access identity unit is used to locate the relevant block on the blockchain, and the new device identifier is used for verification and mapping to generate new device block data. This securely records the new device's access information on the blockchain, ensuring data immutability. A time-dependent weight is generated based on the new device data and block data, reducing the new device's access rights over time. This effectively manages new device access rights and reduces security risks. Based on the block data and the time-dependent weight, the blockchain is dynamically identified and a dynamic device access identifier is generated. Dynamic identifiers enhance security and effectively prevent security threats such as replay attacks. Through dynamic identity management and time-series weight generation, the system can quickly adapt to the addition of new devices and effectively manage device access identities, providing flexible and secure access control strategies for information systems.

[0087] Preferably, step S25 includes the following steps:

[0088] Step S251: extracting the data timestamp of the newly accessed device data to obtain the device access timestamp data;

[0089] Step S252: performing time sequence arrangement according to the device access timestamp data to obtain device access time sequence data;

[0090] Step S253: performing weight distribution on the new device block data based on the device access timing data to obtain timing device weight distribution data;

[0091] Step S254: performing a time sequence fading weight analysis on the new device block data according to the time sequence device weighting data to obtain new device time sequence fading weight data.

[0092] As an embodiment of the present invention, refer to Figure 3 As shown, Figure 2 Detailed step flow diagram of step S25 in the embodiment, step S25 includes the following steps:

[0093] Step S251: extracting the data timestamp of the newly accessed device data to obtain the device access timestamp data;

[0094] In an embodiment of the present invention, the system extracts device access timestamp information from newly accessed device data. Newly accessed device data contains timestamps in various formats, such as Unix timestamps and date and time strings. The system converts these timestamps into a standard format, such as a Unix timestamp, and stores them as device access timestamp data. If the newly accessed device data contains multiple timestamps, such as the start and end time of an access, the system can select one or more timestamps for extraction based on specific needs.

[0095] Step S252: performing time sequence arrangement according to the device access timestamp data to obtain device access time sequence data;

[0096] In this embodiment of the present invention, the system sorts the access timestamp data of all devices and arranges them in chronological order to generate device access time series data. The sorting algorithm can be selected based on the data volume, such as quick sort or merge sort. The device access time series data can be an ordered list or array, where each element contains a device identifier and a corresponding timestamp.

[0097] Step S253: performing weight distribution on the new device block data based on the device access timing data to obtain timing device weight distribution data;

[0098] In an embodiment of the present invention, the system assigns weights to new device block data based on device access timing data. For example, different weights can be assigned based on the order in which devices are accessed, with devices with earlier access times receiving lower weights and devices with later access times receiving higher weights. Weights can also be assigned based on access frequency, with devices with higher access frequencies receiving higher weights and devices with lower access frequencies receiving lower weights. The weight assignment algorithm can be adjusted based on specific needs. The assigned weight values ​​are then added to the new device block data, forming time-series device weighted data.

[0099] Step S254: performing a time sequence fading weight analysis on the new device block data according to the time sequence device weighting data to obtain new device time sequence fading weight data.

[0100] In an embodiment of the present invention, the system analyzes the decentralized data of sequential devices and calculates the sequential fading weight of each device. The sequential fading weight refers to the gradual decrease in the weight of a device over time. For example, an exponential decay function or other decay function can be used to calculate the sequential fading weight based on the difference between the device's last access time and the current time. The greater the time difference, the greater the weight decay. The calculated sequential fading weight is then updated to the new device block data, ultimately resulting in the new device sequential fading weight data.

[0101] The present invention provides a method for recording device access history by extracting device access timestamps from newly accessed device data. This timestamp data provides a basis for subsequent time series arrangement and analysis, ensuring the accuracy of device access data. The device access timestamp data is then time-sequenced to generate device access time series data. This step helps the system understand device access patterns and frequencies, providing important information for subsequent weight allocation and analysis. Based on the device access time series data, the system weights new device block data to generate time series device weighting data. This weighting mechanism assigns weights based on device access time series, ensuring fair resource allocation and taking device access history into account. By analyzing the time series device weighting data, the system generates new device time series attenuation weighting data. This weighting analysis method considers historical device access trends, allowing the system to prioritize updated device access data, improving response speed and resource utilization efficiency. By recording and analyzing device access timestamps, these steps impart a temporal dimension to device access data, enabling the system to make more intelligent decisions and resource allocation based on device access history. This approach improves the information system's responsiveness to device access, especially when a large number of devices are accessing it simultaneously, ensuring the system's real-time and high efficiency.

[0102] Preferably, step S3 includes the following steps:

[0103] Step S31: Perform dynamic user access identification on the system access user data to obtain user access identification data;

[0104] In this embodiment of the present invention, the system collects user access behavior data, such as login time, login location, access frequency, pages visited, and operational habits. The system uses machine learning algorithms, such as rule-based models, anomaly detection models, or behavioral biometric models, to analyze this data and identify the user. The analysis process includes statistical analysis, pattern recognition, and anomaly detection. The analysis results generate user access identification data, such as user behavior patterns and risk scores.

[0105] Step S32: extracting the user identity from the dynamic device access identifier based on the user access identification data to obtain a dynamic user access identifier;

[0106] In this embodiment of the present invention, the system analyzes a dynamic device access identifier, which contains device information, user identity information, and time information. Based on user access identification data, such as user behavior patterns, the system extracts user identity information from the dynamic device access identifier. This extraction method can be rule-based matching or prediction using a machine learning model. The extracted user identity information, such as user ID and username, constitutes the dynamic user access identifier.

[0107] Step S33: performing a new device identification comparison on the dynamic device access identifier according to the dynamic user access identifier to obtain new device identification comparison data, wherein the new device identification comparison data includes identification comparison identical data and identification comparison difference data;

[0108] In this embodiment of the present invention, the system compares the extracted dynamic user access identifier with the generated dynamic device access identifier. This comparison can be a simple string comparison or a more complex pattern matching or similarity calculation. If the two identifiers are identical or highly similar, they are considered to be identical data; otherwise, they are considered to be different data. The comparison results are stored as new device identifier comparison data.

[0109] Step S34: If the new device identification comparison data is identification comparison identical data, then the information system is processed for information system access to obtain the same device information system access data; if the new device identification comparison data is identification comparison difference data, then the information system is processed for new device authentication to obtain the new device authentication sequence.

[0110] In an embodiment of the present invention, the data compared by the new device identification is "identification comparison same data", indicating that the current access device is a commonly used device. At this time, the system will directly allow access to the information system, and record the access information, such as access time, access resources, etc., to generate "same device information system access data". Since the system has identified the current device as a commonly used device of the user, no additional identity authentication is required, and access can be directly authorized. The system will record access logs, including user identifiers, device identifiers, access time, access resources and other information for subsequent auditing and analysis. The new device identification comparison data is "identification comparison difference data", indicating that the current access device is not a commonly used device. In order to ensure the security of the information system, the system will perform authentication processing on the new device.

[0111] By performing dynamic user access identification on system access user data, the system can obtain the user's current access behavior, providing basic data for subsequent user identity extraction and device identification comparison. This dynamic identification mechanism ensures that the system can respond to changes in user access in real time. Based on the user access identification data, the system extracts user identity information from the dynamic device access identifier to obtain a dynamic user access identifier. This method links user access behavior with device identity, providing key information for subsequent access control decisions. By comparing the dynamic user access identifier with the dynamic device access identifier, the system obtains new device identification comparison data. This comparison process distinguishes between identical and new devices, providing important judgment basis for the next access processing step. Based on the new device identification comparison data, the system determines whether to proceed with information system access processing or new device authentication. This dynamic processing mechanism ensures that the system can make appropriate access control decisions based on the current status of the user and device, improving the system's flexibility and security. By analyzing user access behavior and device identity in real time, the system can make more accurate access decisions while ensuring the dynamic association of user and device identities, enhancing the security and responsiveness of the information system.

[0112] Preferably, step S4 includes the following steps:

[0113] Step S41: performing authentication data conversion on the dynamic device access identifier to obtain an identification authentication sequence;

[0114] In an embodiment of the present invention, by obtaining a dynamic device access identifier, when a user attempts to access an information system using a new device, the system generates a dynamic device access identifier, such as a randomly generated string or a timestamp-based token. Select a preset authentication algorithm. The system pre-sets multiple authentication algorithms, such as SHA-256, HMAC-SHA256, etc., for converting dynamic identifiers into authentication sequences. Apply the algorithm for conversion. The system selects a suitable authentication algorithm according to preset rules and uses the dynamic device access identifier as input to perform hash operations or encryption processing. Generate an identification authentication sequence. After algorithm processing, the system obtains a string of characters or numbers of a fixed length, which is the identification authentication sequence.

[0115] Step S42: performing an authentication sequence comparison with the new device authentication sequence based on the identification authentication sequence to obtain new device authentication data, wherein the new device authentication data includes authentication sequence comparison identical data and authentication sequence comparison difference data;

[0116] In an embodiment of the present invention, by obtaining a new device authentication sequence, the system obtains preset information from the new device, such as a device fingerprint, a hardware serial number, etc., and processes it using the same authentication algorithm as step S41 to obtain a new device authentication sequence. Performing an authentication sequence comparison, the system compares the identification authentication sequence obtained in step S41 with the new device authentication sequence bit by bit. Recording the comparison results, during the comparison process, the system records completely identical characters or digital fragments as "authentication sequence comparison identical data"; at the same time, it records the different parts as "authentication sequence comparison difference data." Generate new device sequence authentication data, the system integrates the "authentication sequence comparison identical data" and the "authentication sequence comparison difference data" to form the new device sequence authentication data.

[0117] Step S43: If the new device authentication sequence is inconsistent with the identification authentication sequence, the new device authentication sequence is subjected to device zero trust identification to obtain a device zero trust identification;

[0118] In this embodiment of the present invention, by judging the authentication results, the system analyzes the authentication data of the new device sequence obtained in step S42 to determine whether they are identical or different. In the case of identical authentication, if the authentication sequence is exactly the same, it indicates that the new device is trustworthy, and the system allows it to access the information system and records the access records, data transmission, and other information as "cross-device information system access data." In the case of differences, if the authentication sequence is different, it indicates that the security of the new device requires further confirmation. The system will mark the authentication sequence of the new device, for example, by adding a specific tag or adding it to the "device list for review" to form a "device zero trust identification."

[0119] Step S44: Access the information system according to the same-device information system access data and the cross-device information system access data to obtain an information system access plan.

[0120] In an embodiment of the present invention, the system collects user access behavior data on different devices, including same-device information system access data, such as user operation records on frequently used devices, and cross-device information system access data, such as user access requests on new devices. The system uses machine learning and other technologies to analyze user access behavior patterns, such as commonly used access times, locations, and data types. Based on the analysis results, the system dynamically adjusts security policies and formulates personalized information system access plans. For example, for access requests from trusted devices, the system can simplify the authentication process; for access requests from higher-risk devices, the system can require multi-factor authentication or restrict access rights.

[0121] Through authentication data conversion, the system converts dynamic device access identifiers into identification authentication sequences, providing a standardized data format for subsequent authentication sequence comparisons and access control decisions. This conversion ensures data compatibility and consistency. The system compares the identification authentication sequence with the new device authentication sequence to obtain new device sequence authentication data. This comparison process distinguishes between identical and different authentication scenarios, providing key judgment basis for subsequent access processing and ensuring system security. Based on the new device sequence authentication data, the system determines whether to proceed with information system access processing or device zero-trust identification. When the authentication sequences are identical, the system allows access; when there are differences, the system performs zero-trust identification of the device, ensuring a secure response to abnormal situations. Combining same-device and cross-device access data, the system develops an information system access plan. This comprehensive approach ensures that the system can make accurate access control decisions in a multi-device environment while maintaining security and user experience. By converting and comparing dynamic device access identifiers, the system can assess the security of access requests in real time and make appropriate access decisions based on the authentication results. This approach introduces zero-trust device identity, further enhancing the security of the system and enabling it to effectively manage access control in complex multi-device environments.

[0122] Preferably, step S41 includes the following steps:

[0123] Step S411: performing two-dimensional data conversion on the dynamic device access identifier to obtain two-dimensional dynamic identification data;

[0124] In an embodiment of the present invention, by obtaining a dynamic device access identifier, when a user attempts to access an information system using a new device, the system generates a dynamic device access identifier, such as a randomly generated string or a timestamp-based token. The system selects an appropriate encoding method, such as ASCII code or Unicode code, based on preset rules to convert the dynamic device access identifier into a digital sequence. A two-dimensional data structure is constructed. The system arranges the digital sequence into a two-dimensional matrix according to preset rules, such as row-by-row filling or spiral filling, to form two-dimensional dynamic identification data. The dimensions of the matrix can be adjusted based on the length of the identifier and preset rules.

[0125] Step S412: performing data plane mapping on the two-dimensional dynamic identification data to obtain a dynamic identification two-dimensional plane;

[0126] In this embodiment of the present invention, the system predefines a two-dimensional plane, such as a rectangular area, as the target area for mapping. The system maps each element of the two-dimensional dynamic identification data to a unique coordinate point on the two-dimensional plane using a predefined algorithm, such as linear mapping or hash mapping. After mapping all elements, the system obtains a set of coordinate points distributed on the two-dimensional plane, which is the dynamic identification two-dimensional plane. Each coordinate point represents an element in the two-dimensional dynamic identification data.

[0127] Step S413: partitioning is performed according to the dynamic device access identifier to obtain dynamic identification partition data;

[0128] In an embodiment of the present invention, an analysis system analyzes the characteristics of a dynamic device access identifier, such as length and character composition, and divides it into several substrings according to preset rules. Based on the number of substrings and a preset algorithm, such as equal division or hashing, the system divides the two-dimensional plane of the dynamic identifier into an equal number of regions. Each region contains several coordinate points, forming a dynamic identifier partition data. The system stores all partition data for subsequent coordinate mapping.

[0129] Step S414: performing coordinate mapping on the dynamic identification two-dimensional plane based on the dynamic identification partition data to obtain the dynamic identification partition coordinates;

[0130] In this embodiment of the present invention, the system traverses the dynamically identified partition data, sequentially reading each dynamically identified partition data point and obtaining all coordinate points contained therein. Based on a pre-defined mapping algorithm, such as center point mapping or average value mapping, the system calculates a representative coordinate point on a two-dimensional plane for each partition data point, which serves as the dynamically identified partition coordinate for that partition. After completing the coordinate mapping for all partition data points, the system obtains a dynamically identified partition coordinate sequence, which is used for subsequent authentication sequence conversion.

[0131] Step S415: performing sequential authentication sequence conversion on the dynamic identification partition coordinates based on the dynamic device access identifier to obtain an identification authentication sequence.

[0132] In an embodiment of the present invention, by extracting key information: the system extracts key information from the dynamic device access identifier based on preset rules, such as characters in specific positions and the frequency of character occurrence. Based on the extracted key information and a preset algorithm, such as sequential reading or skip reading, the system determines an order for reading the dynamic identification partition coordinate sequence. The system reads the dynamic identification partition coordinate sequence in the determined order and converts the read coordinate values ​​into characters or numbers in a specific format. The resulting strings are then concatenated into a string, which becomes the identification authentication sequence.

[0133] The present invention provides a visual representation of the identifier by converting the dynamic device access identifier into two-dimensional data. This two-dimensional representation method facilitates subsequent plane mapping and partition cutting operations, improving the intuitiveness of data processing. The two-dimensional dynamic identification data is mapped onto a plane, creating a dynamic identification two-dimensional plane. This plane representation method provides an infrastructure for subsequent coordinate mapping and sequential authentication number series conversion, ensuring the orderliness and visualization of the data. Based on the dynamic device access identifier, the system partitions and cuts the two-dimensional plane to obtain dynamic identification partition data. This partition grouping method can help the system organize and manage a large number of identifiers, improving the efficiency of data processing. By performing coordinate mapping on the dynamic identification partition data, the system obtains the dynamic identification partition coordinates. This coordinate representation method provides a spatial organizational structure, facilitates the subsequent sequential authentication number series conversion, and ensures the accuracy and controllability of data processing. Based on the dynamic device access identifier, the system converts the dynamic identification partition coordinates into a sequential authentication number series. This conversion process ensures the sequential consistency of the identifier and provides a standardized data format for subsequent authentication and access control decisions. Through two-dimensional data conversion, plane mapping and partition cutting, the system can visually manage dynamic device access identifiers, improve the controllability and visualization of data processing, and lay the foundation for subsequent authentication and access control processes.

[0134] Preferably, step S43 includes the following steps:

[0135] Step S431: convert the authentication failure identifier of the new device authentication sequence to obtain a failed authentication identifier;

[0136] In this embodiment of the present invention, all events with an "authentication failed" result are filtered from the authentication sequence. Then, for each failed event, key information is extracted, such as the timestamp, device ID, and authentication method, and this information is combined into a structured string or data object. This conversion is performed on all failed events, ultimately resulting in a new sequence in which each element is an identifier representing a failed authentication. This new sequence serves as the failed authentication identifier.

[0137] Step S432: fitting the dynamic device access identifier based on the failed authentication identifier to obtain a failed authentication dynamic identifier;

[0138] In this embodiment of the present invention, for each dynamic device access identifier, a search is performed for a failed authentication identifier with a timestamp closest to that of the dynamic device access identifier and within a specified time window, for example, within 5 minutes before or after the access time. If a matching failed authentication identifier is found, the two are merged into a new data structure. For example, the fields of the failed authentication identifier are added to the dynamic device access identifier to form a new identifier containing both access information and authentication failure information. If no matching failed authentication identifier is found within the specified time window, the failed authentication identifier can be set to a null value or a default value, resulting in a new sequence, namely the failed authentication dynamic identifier.

[0139] Step S433: Segment the identifier into blocks according to the failed authentication dynamic identifier to obtain identifier block data, wherein the identifier block data includes failed access blocks and failed device blocks;

[0140] In an embodiment of the present invention, the identifier is divided into different failed access blocks based on the access resource information in the failed authentication dynamic identifier. For example, the identifier can be grouped according to the accessed URL or API interface, and each group represents an access attempt to a specific resource. Then, the identifier is divided into different failed device blocks based on the device ID information in the failed authentication dynamic identifier. Each group represents all access attempts for a specific device. The identifier block data can be organized into a nested structure, such as a dictionary or JSON object. For example, with the device ID as the key, the value corresponding to each key is a list containing all failed access block information for the device.

[0141] Step S434: assigning zero device weight to the failed access block based on the failed device block to obtain zero device weight data;

[0142] In an embodiment of the present invention, for each failed device block, all corresponding failed access blocks are traversed. Based on predefined rules, each failed access block is assigned a device weight of zero. For example, the weight can be determined based on the number of failed authentications, the failure reason code, or other factors. The lower the weight, the less trustworthy the device is in accessing the resource. For example, if a device has repeatedly failed to access a resource, its weight for accessing the resource can be set to 0, indicating that the device is completely untrustworthy in accessing the resource.

[0143] Step S435: Generate a zero-trust identifier for the failed authentication dynamic identifier based on the zero device weight data to obtain a device zero-trust identifier.

[0144] In this embodiment of the present invention, the weighted average of all resources accessed by a device is used as the device's zero trust identity. Alternatively, different weight coefficients can be set based on the importance of different resources, and the weighted average is then calculated as the device's zero trust identity. More complex policies can consider factors such as access time and failure reason codes.

[0145] The present invention converts authentication failure identifiers into failed authentication identifiers. This identifier represents the device or access request that failed authentication, providing key information for subsequent processing and analysis. Based on the failed authentication identifier, the system fits the dynamic device access identifier to obtain a failed authentication dynamic identifier. This step ensures that failed authentication information is incorporated into the dynamic system, enabling the system to respond to and process authentication failures in real time. The system then segments the failed authentication dynamic identifier into identifier blocks, resulting in failed access blocks and failed device blocks. This segmentation method organizes the failure information and provides a basic data structure for the subsequent zero device weight assignment. Based on the failed device blocks, the system assigns zero device weights to the failed access blocks, generating zero device weight data. This process ensures that failed devices or access requests are assigned lower weights, reflecting their reduced credibility, and provides basic data for generating device zero trust identifiers. Using the zero device weight data, the system generates a device zero trust identifier. This identifier represents zero trust processing of failed authentication devices or requests, ensuring the security and robustness of the system in the face of potential risks. By identifying, fitting, blocking and weighting failure situations, the system can effectively manage and respond to authentication failure events and generate zero-trust identification for devices, thereby improving the security and risk resistance of information systems.

[0146] The present invention is therefore intended to be illustrative and non-restrictive in all respects, with the scope of the invention being defined by the appended claims rather than the foregoing description, and all changes that come within the meaning and range of equivalents of the application documents are intended to be embraced therein.

[0147] The foregoing description is intended only to provide specific embodiments of the present invention, which will enable those skilled in the art to understand and implement the present invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not intended to be limited to the embodiments shown herein, but is to be construed in the widest possible manner consistent with the principles and novel features disclosed herein.

Claims

1. A method for accessing an information system, characterized in that: The following steps are involved: Step S1: Obtain system access user data; Extracting access device data from system access user data to obtain access device data; Construct an identification blockchain based on the system access user data and access device data to obtain the identity device identification blockchain; Wherein step S1 comprises the following steps: Step S11: Obtain system access user data; Step S12: extracting access device data from the system access user data to obtain access device data; Step S13: Generate an identifier based on the access device data to obtain an access device identifier; wherein step S13 includes the following steps: Step S131: extracting feature data based on access device data to obtain device feature data; Step S132: performing a hash algorithm conversion on the device feature data to obtain an initial device feature identifier; performing identifier deduplication on the initial device feature identifier to obtain a device feature identifier; Step S133: performing access data analysis based on the access device data to obtain access data, wherein the access data includes access timestamp data and access geographic location data; Step S134: converting the access timestamp data and the access geographic location data into an access system identifier to obtain an access user identifier; Step S135: Correspondingly associating the device feature identifier and the access user identifier to obtain an access device identifier; Step S14: performing data association on the system access user data based on the access device identifier to obtain access device association data; Step S15: Block mapping is performed based on the access device association data and the access device identifier to obtain the identity device identification blockchain, wherein step S15 includes the following steps: Step S151: Slice the access device identifier to obtain identifier slicing data, wherein the identifier slicing data includes access identity identifier slicing data and device identifier slicing data; Step S152: Blocking the access identity identifier fragment data and the device identifier fragment data to obtain access identity block data and access device block data; Step S153: performing chain creation processing on the access identity block data and the access device block data to obtain the access identity blockchain and the access device blockchain; Step S154: Perform cross-chain mapping interaction on the access identity blockchain based on the access device association data and the access device blockchain to obtain the identity device identification blockchain; Step S2: Identify the new access device based on the access device data to obtain new access device data; perform identifier conversion on the new access device data to obtain a new device identifier; perform new device block conversion on the new access device data to obtain new device block data; perform dynamic identifier conversion on the identity device identification blockchain based on the new device block data to obtain a dynamic device access identifier; Step S3: Perform dynamic user access identification on the system access user data to obtain user access identification data; perform new device analysis on the dynamic device access identifier based on the user access identification data to obtain device information system access data and a new device authentication sequence; Step S4: Perform authentication data conversion on the dynamic device access identifier to obtain an identification authentication sequence; perform information system cross-device access processing on the new device authentication sequence based on the identification authentication sequence to obtain cross-device information system access data; perform information system access based on the same-device information system access data and the cross-device information system access data to obtain an information system access plan.

2. The information system access method according to claim 1, characterized in that: Step S2 includes the following steps: Step S21: Identify the new access device according to the access device data to obtain the new access device data; Step S22: performing identifier conversion on the new access device data to obtain a new device identifier; Step S23: performing access identity unit identification on the identity device identification blockchain based on the new access device data to obtain an access identity unit; Step S24: Locate the block of the identity device identification blockchain based on the access identity unit to obtain the new device access block; verify and map the new device access block according to the new device identifier to obtain the new device block data; Step S25: generating a time-series weakening weight for the new device block data according to the new access device data to obtain the new device time-series weakening weight data; Step S26: Perform dynamic identification conversion on the identity device identification blockchain according to the new device block data and the new device time sequence attenuation weight data to obtain a dynamic device access identifier.

3. The information system access method according to claim 2, characterized in that: Step S25 includes the following steps: Step S251: extracting the data timestamp of the newly accessed device data to obtain the device access timestamp data; Step S252: performing time sequence arrangement according to the device access timestamp data to obtain device access time sequence data; Step S253: performing weight distribution on the new device block data based on the device access timing data to obtain timing device weight distribution data; Step S254: performing a time sequence fading weight analysis on the new device block data according to the time sequence device weighting data to obtain new device time sequence fading weight data.

4. The information system access method according to claim 1, characterized in that: Step S3 includes the following steps: Step S31: Perform dynamic user access identification on the system access user data to obtain user access identification data; Step S32: extracting the user identity from the dynamic device access identifier based on the user access identification data to obtain a dynamic user access identifier; Step S33: performing a new device identification comparison on the dynamic device access identifier according to the dynamic user access identifier to obtain new device identification comparison data, wherein the new device identification comparison data includes identification comparison identical data and identification comparison difference data; Step S34: If the new device identification comparison data is identification comparison identical data, then the information system is processed for information system access to obtain the same device information system access data; if the new device identification comparison data is identification comparison difference data, then the information system is processed for new device authentication to obtain the new device authentication sequence.

5. The information system access method according to claim 1, characterized in that: Step S4 includes the following steps: Step S41: performing authentication data conversion on the dynamic device access identifier to obtain an identification authentication sequence; Step S42: performing an authentication sequence comparison with the new device authentication sequence based on the identification authentication sequence to obtain new device authentication data, wherein the new device authentication data includes authentication sequence comparison identical data and authentication sequence comparison difference data; Step S43: If the new device authentication sequence is inconsistent with the identification authentication sequence, the new device authentication sequence is subjected to device zero trust identification to obtain a device zero trust identification; Step S44: Access the information system according to the same-device information system access data and the cross-device information system access data to obtain an information system access plan.

6. The information system access method according to claim 5, characterized in that: Step S41 includes the following steps: Step S411: performing two-dimensional data conversion on the dynamic device access identifier to obtain two-dimensional dynamic identification data; Step S412: performing data plane mapping on the two-dimensional dynamic identification data to obtain a dynamic identification two-dimensional plane; Step S413: partitioning is performed according to the dynamic device access identifier to obtain dynamic identification partition data; Step S414: performing coordinate mapping on the dynamic identification two-dimensional plane based on the dynamic identification partition data to obtain the dynamic identification partition coordinates; Step S415: performing sequential authentication sequence conversion on the dynamic identification partition coordinates based on the dynamic device access identifier to obtain an identification authentication sequence.

7. The method for accessing an information system according to claim 5, wherein: Step S52 includes the following steps: Step S431: convert the authentication failure identifier of the new device authentication sequence to obtain a failed authentication identifier; Step S432: fitting the dynamic device access identifier based on the failed authentication identifier to obtain a failed authentication dynamic identifier; Step S433: Segment the identifier into blocks according to the failed authentication dynamic identifier to obtain identifier block data, wherein the identifier block data includes failed access blocks and failed device blocks; Step S434: assigning zero device weight to the failed access block based on the failed device block to obtain zero device weight data; Step S435: Generate a zero-trust identifier for the failed authentication dynamic identifier based on the zero device weight data to obtain a device zero-trust identifier.

Citation Information

Patent Citations

  • Method and apparatus for managing user authentication in a blockchain network

    CN111567013A