IoT terminal authentication methods, devices, equipment, media and products
By using the trained authentication model to generate signal samples from simulated communication signals and channel impulse responses, the security and compatibility issues of IoT terminal identity authentication are resolved, and the accuracy and reliability of authentication are improved.
Patent Information
- Application Number
- CN202411934027.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-25
- Publication Date
- 2025-11-14
- Estimated Expiration
- 2044-12-25
AI Technical Summary
Existing IoT terminal authentication methods struggle to guarantee terminal security when faced with attackers who have improved computing power. Furthermore, resource-constrained terminal users have limited computing capabilities, resulting in poor authentication reliability and decreased compatibility.
The trained authentication model is used to authenticate the communication signals of IoT terminals. The model is trained by generating signal samples through simulated communication signals, channel impulse responses, and twin communication environments. A twin communication environment is constructed to improve the accuracy and fault tolerance of the authentication model.
It reduces the possibility of neural network overfitting, improves the accuracy and fault tolerance of the authentication model, and enhances the identity security and communication reliability of IoT terminals.
Smart Images

Figure CN119853981B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of Internet of Things (IoT) technology, and more specifically, to an identity authentication method, apparatus, device, medium, and product for IoT terminals. Background Technology
[0002] Currently, due to the openness of wireless channels, users in any location can receive signals.
[0003] In related technologies, eavesdroppers can tamper with MAC (Media Access Control) addresses to impersonate trusted users and launch cloning attacks, disrupting legitimate communication between trusted users and posing a huge security threat and causing property losses to the Industrial Internet of Things.
[0004] However, traditional identity authentication has at least several drawbacks:
[0005] (1) As attackers improve their computing power, cryptographic authentication methods are less able to guarantee the security of terminal identity.
[0006] (2) As the number of terminals increases, the compatibility of identity authentication will decrease because each terminal node has an independent public key certificate.
[0007] (3) For resource-constrained end users, their computing performance is limited and they are not suitable for two-way authentication schemes.
[0008] It should be noted that the information disclosed in the background section above is only used to enhance the understanding of the background of this disclosure, and therefore may include information that does not constitute prior art known to those skilled in the art. Summary of the Invention
[0009] The purpose of this disclosure is to provide an identity authentication method, apparatus, device, medium, and product for Internet of Things (IoT) terminals, which at least to some extent overcomes the problems of poor reliability of identity authentication for IoT terminals caused by limitations and defects in related technologies.
[0010] According to a first aspect of the present disclosure, an identity authentication method for an Internet of Things (IoT) terminal is provided, comprising: authenticating the communication signals of the IoT terminal using a trained authentication model, wherein the authentication model is configured to be trained based on simulated communication signals, channel impulse response, and signal samples generated by a twin communication environment, wherein the twin communication environment is configured to be constructed based on construction information of the communication environment and the user location information.
[0011] In one exemplary embodiment of this disclosure, before authenticating the communication signals of the IoT terminal using the trained authentication model, the method further includes:
[0012] Obtain the construction information of the communication environment and user location information corresponding to the IoT terminal;
[0013] The twin communication environment of the IoT terminal is constructed based on the construction information of the communication environment and the user location information;
[0014] The channel impulse response is determined based on preset configuration parameters between the IoT terminal and the receiver.
[0015] Signal samples are generated based on the simulated communication signal, the channel impulse response, and the twin communication environment;
[0016] The signal samples are input into the authentication model for training until the loss function of the authentication model satisfies the convergence condition.
[0017] In one exemplary embodiment of this disclosure, obtaining the construction information of the communication environment and the user location information corresponding to the IoT terminal includes:
[0018] Obtain the user location information corresponding to the IoT terminal;
[0019] Channel estimation is performed based on the user location information and the address of the receiving end to determine the communication channel parameters in the communication environment. The communication channel parameters include at least one of channel state information, power spectral density, and power amplifier characteristics.
[0020] The communication environment information is obtained through the sensing devices associated with the IoT terminal;
[0021] The construction information is determined based on the communication environment information and the communication channel parameters.
[0022] In one exemplary embodiment of this disclosure, determining the channel impulse response based on preset configuration parameters between the IoT terminal and the receiver includes:
[0023] Obtain the antenna configuration information and specified channel model corresponding to the IoT terminal;
[0024] The channel impulse response between the IoT terminal and the receiver is generated based on the user location information, the antenna configuration information, and the specified channel model.
[0025] In one exemplary embodiment of this disclosure, generating signal samples based on the simulated communication signal, the channel impulse response, and the twin communication environment includes:
[0026] The transmitted signal of the signal sample to be generated is modulated;
[0027] The orthogonal frequency division multiplexing algorithm is used to divide the modulated transmission signal to obtain multiple subcarrier signals;
[0028] Extract multiple subcarrier signals according to a preset number;
[0029] The specified subcarrier signal is spoofed according to the preset attack code strategy to generate negative samples, and the subcarrier that has not undergone the spoofing process is determined as a positive sample.
[0030] The signal sample is generated based on the positive sample, the negative sample, the channel impulse response, and the twin communication environment.
[0031] In one exemplary embodiment of this disclosure, generating the signal sample based on the positive sample, the negative sample, the channel impulse response, and the twin communication environment includes:
[0032] The positive and negative samples are convolved using the channel impulse response.
[0033] According to the twin communication environment, noise signals are added to the positive and / or negative samples after convolution processing, and the positive and / or negative samples with added noise signals are determined as the simulated communication signals.
[0034] In one exemplary embodiment of this disclosure, obtaining the antenna configuration information and the specified channel model corresponding to the IoT terminal includes:
[0035] Obtain the antenna configuration information corresponding to the IoT terminal;
[0036] Determine the communication path information between the IoT terminal and the receiving end. The communication path information includes path loss and / or multipath fading. The path loss includes free space path loss or two-path loss. The multipath fading includes Rayleigh fading model and / or Rice fading.
[0037] And / or determine the shadowing fading information of a log-normally distributed analog signal;
[0038] The specified channel model is determined based on the communication path information and / or the shadow fading information.
[0039] According to a second aspect of the present disclosure, an identity authentication device for an Internet of Things (IoT) terminal is provided, comprising:
[0040] The authentication module is configured to use a trained authentication model to authenticate the communication signals of IoT terminals. The authentication model is configured to be trained based on simulated communication signals, channel impulse responses, and signal samples generated by a twin communication environment. The twin communication environment is configured to be constructed based on the construction information of the communication environment and the user location information.
[0041] According to a third aspect of this disclosure, an electronic device is provided, comprising: a memory; and a processor coupled to the memory, the processor being configured to perform the method as described in any of the preceding methods based on instructions stored in the memory.
[0042] According to a fourth aspect of this disclosure, a computer-readable storage medium is provided having a program stored thereon that, when executed by a processor, implements the authentication method for an Internet of Things (IoT) terminal as described in any of the preceding claims.
[0043] According to a fifth aspect of this disclosure, a computer program product is provided, comprising a computer program, characterized in that, when executed by a processor, the computer program implements the authentication method for an Internet of Things terminal as described in any of the preceding claims.
[0044] In this embodiment, an authentication model is used to authenticate the communication signals of an IoT terminal. The authentication model is configured to be trained based on simulated communication signals, channel impulse responses, and signal samples generated by a twin communication environment. The twin communication environment is configured to be constructed based on the construction information of the communication environment and the user location information. This reduces the possibility of overfitting in the neural network, improves the accuracy and fault tolerance of the authentication model, enhances the accuracy of authentication, and improves the identity security and communication reliability of the industrial IoT terminal.
[0045] It should be understood that the above general description and the following detailed description are exemplary and explanatory only, and are not intended to limit this disclosure. Attached Figure Description
[0046] The accompanying drawings, which are incorporated in and form part of this specification, illustrate embodiments consistent with this disclosure and, together with the description, serve to explain the principles of this disclosure. It is obvious that the drawings described below are merely some embodiments of this disclosure, and those skilled in the art can obtain other drawings based on these drawings without any inventive effort.
[0047] Figure 1 A schematic diagram of an exemplary system architecture for an identity authentication scheme for IoT terminals that can be applied according to embodiments of the present invention is shown;
[0048] Figure 2This is a flowchart of an identity authentication method for an Internet of Things (IoT) terminal according to an exemplary embodiment of this disclosure;
[0049] Figure 3 This is a flowchart of another IoT terminal authentication method in an exemplary embodiment of this disclosure;
[0050] Figure 4 This is a flowchart of another IoT terminal authentication method in an exemplary embodiment of this disclosure;
[0051] Figure 5 This is a flowchart of another IoT terminal authentication method in an exemplary embodiment of this disclosure;
[0052] Figure 6 This is a flowchart of another IoT terminal authentication method in an exemplary embodiment of this disclosure;
[0053] Figure 7 This is a flowchart of another IoT terminal authentication method in an exemplary embodiment of this disclosure;
[0054] Figure 8 This is a flowchart of another IoT terminal authentication method in an exemplary embodiment of this disclosure;
[0055] Figure 9 This is a flowchart illustrating the workflow of each module in an identity authentication architecture for an IoT terminal according to an exemplary embodiment of this disclosure.
[0056] Figure 10 This is a block diagram of an identity authentication device for an Internet of Things (IoT) terminal according to an exemplary embodiment of this disclosure;
[0057] Figure 11 This is a block diagram of an electronic device according to an exemplary embodiment of the present disclosure. Detailed Implementation
[0058] Example embodiments will now be described more fully with reference to the accompanying drawings. However, example embodiments can be implemented in many forms and should not be construed as limited to the examples set forth herein; rather, these embodiments are provided to make this disclosure more comprehensive and complete, and to fully convey the concept of the example embodiments to those skilled in the art. The described features, structures, or characteristics can be combined in any suitable manner in one or more embodiments. In the following description, numerous specific details are provided to give a full understanding of embodiments of this disclosure. However, those skilled in the art will recognize that the technical solutions of this disclosure can be practiced with one or more of the specific details omitted, or other methods, components, apparatus, steps, etc., can be employed. In other instances, well-known technical solutions are not shown or described in detail to avoid obscuring various aspects of this disclosure.
[0059] Furthermore, the accompanying drawings are merely illustrative of this disclosure, and the same reference numerals in the drawings denote the same or similar parts, thus repeated descriptions of them will be omitted. Some block diagrams shown in the drawings are functional entities and do not necessarily correspond to physically or logically independent entities. These functional entities may be implemented in software, in one or more hardware modules or integrated circuits, or in different network and / or processor devices and / or microcontroller devices.
[0060] Figure 1 A schematic diagram of an exemplary system architecture for an IoT terminal authentication scheme that can be applied to embodiments of the present invention is shown.
[0061] like Figure 1 As shown, system architecture 100 may include one or more of terminal devices 101, 102, and 103, a network 104, and a server 105. Network 104 serves as the medium for providing communication links between terminal devices 101, 102, and 103 and server 105. Network 104 may include various connection types, such as wired or wireless communication links or fiber optic cables, etc.
[0062] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, there can be any number of terminal devices, networks, and servers. For example, server 105 could be a server cluster composed of multiple servers.
[0063] Users can use terminal devices 101, 102, and 103 to interact with server 105 via network 104 to receive or send messages, etc. Terminal devices 101, 102, and 103 can be various electronic devices with displays, including but not limited to smartphones, tablets, laptops, and desktop computers, etc.
[0064] In some embodiments, the IoT terminal authentication method provided in this invention is generally executed by server 105, and correspondingly, the IoT terminal authentication device is generally located in terminal device 103 (or terminal device 101 or 102). In other embodiments, some terminals may have functions similar to those of the server device to execute this method.
[0065] The exemplary embodiments of this disclosure will now be described in detail with reference to the accompanying drawings.
[0066] Figure 2 This is a flowchart of an identity authentication method for an IoT terminal in an exemplary embodiment of this disclosure.
[0067] refer to Figure 2The authentication methods for IoT terminals may include:
[0068] Step S202: The trained authentication model is used to authenticate the communication signals of the IoT terminal. The authentication model is configured to be trained based on simulated communication signals, channel impulse response and signal samples generated by twin communication environment. The twin communication environment is configured to be constructed based on the construction information of the communication environment and the user location information.
[0069] In this embodiment, an authentication model is used to authenticate the communication signals of an IoT terminal. The authentication model is configured to be trained based on simulated communication signals, channel impulse responses, and signal samples generated by a twin communication environment. The twin communication environment is configured to be constructed based on the construction information of the communication environment and the user location information. This reduces the possibility of overfitting in the neural network, improves the accuracy and fault tolerance of the authentication model, enhances the accuracy of authentication, and improves the identity security and communication reliability of the industrial IoT terminal.
[0070] Below, combined with Figures 3 to 8 This document provides a detailed explanation of each step in the authentication method for IoT terminals.
[0071] In one exemplary embodiment of this disclosure, such as Figure 3 As shown, before using the trained authentication model to authenticate the communication signals of IoT terminals, the following steps are also included:
[0072] Step S302: Obtain the construction information of the communication environment and the user location information corresponding to the IoT terminal;
[0073] Step S304: Construct the twin communication environment of the IoT terminal based on the construction information of the communication environment and the user location information;
[0074] Step S306: Determine the channel impulse response based on the preset configuration parameters between the IoT terminal and the receiver;
[0075] Step S308: Generate signal samples based on the simulated communication signal, the channel impulse response, and the twin communication environment;
[0076] Step S310: Input the signal sample into the authentication model for training until the loss function of the authentication model satisfies the convergence condition.
[0077] In one exemplary embodiment of this disclosure, such as Figure 4 As shown, obtaining the construction information of the communication environment and user location information corresponding to the IoT terminal includes:
[0078] Step S402: Obtain the user location information corresponding to the IoT terminal;
[0079] Step S404: Perform channel estimation based on the user location information and the address of the receiving end to determine the communication channel parameters in the communication environment. The communication channel parameters include at least one of channel state information, power spectral density, and power amplifier characteristics.
[0080] Step S406: Obtain communication environment information through the sensing device associated with the IoT terminal;
[0081] Step S408: Determine the construction information based on the communication environment information and the communication channel parameters.
[0082] In one exemplary embodiment of this disclosure, such as Figure 5 As shown, determining the channel impulse response based on preset configuration parameters between the IoT terminal and the receiver includes:
[0083] Step S502: Obtain the antenna configuration information and specified channel model corresponding to the IoT terminal;
[0084] Step S504: Generate the channel impulse response between the IoT terminal and the receiver based on the user location information, the antenna configuration information, and the specified channel model.
[0085] In one exemplary embodiment of this disclosure, such as Figure 6 As shown, the signal samples generated based on the simulated communication signal, the channel impulse response, and the twin communication environment include:
[0086] Step S602: Modulate the transmission signal of the signal sample to be generated;
[0087] Step S604: The modulated transmission signal is divided using an orthogonal frequency division multiplexing algorithm to obtain multiple subcarrier signals;
[0088] Step S606: Extract multiple subcarrier signals according to a preset number;
[0089] Step S608: The specified subcarrier signal is spoofed according to the preset attack code strategy to generate negative samples, and the subcarriers that have not undergone the spoofing process are determined as positive samples.
[0090] Step S610: Generate the signal sample based on the positive sample, the negative sample, the channel impulse response, and the twin communication environment.
[0091] In one exemplary embodiment of this disclosure, such as Figure 7As shown, generating the signal samples based on the positive samples, the negative samples, the channel impulse response, and the twin communication environment includes:
[0092] Step S702: Perform convolution processing on the positive samples and the negative samples using the channel impulse response;
[0093] Step S704: Add noise signals to the positive and / or negative samples after convolution processing according to the twin communication environment, and determine the positive and / or negative samples with added noise signals as the simulated communication signals.
[0094] In one exemplary embodiment of this disclosure, such as Figure 8 As shown, obtaining the antenna configuration information and specified channel model corresponding to the IoT terminal includes:
[0095] Step S802: Obtain the antenna configuration information corresponding to the IoT terminal;
[0096] Step S804: Determine the communication path information between the IoT terminal and the receiving end. The communication path information includes path loss and / or multipath fading. The path loss includes free space path loss or two-path loss. The multipath fading includes Rayleigh fading model and / or Rice fading.
[0097] And / or, in step S806, determine the shadowing fading information of the log-normally distributed analog signal;
[0098] Step S808: Determine the specified channel model based on the communication path information and / or the shadow fading information.
[0099] Figure 9 This is a flowchart illustrating the workflow of each module in the identity authentication architecture of an IoT terminal according to an exemplary embodiment of this disclosure.
[0100] refer to Figure 9 The identity authentication architecture of the IoT terminal includes a data acquisition module 902, a digital twin module 904, an authentication model training module 906, and an identity authentication module 908. The workflow of each module includes, but is not limited to, the following.
[0101] In one exemplary embodiment of this disclosure, the data acquisition module 902 acquires the physical structure of the industrial environment and the location of each user node through sensors and monitoring equipment. The receiving node obtains physical quantities such as channel state information and received signal strength through channel estimation. Specifically, the process includes the following steps:
[0102] (1) Obtain physical structure information of the industrial environment through sensors and monitoring equipment.
[0103] (2) Establish a coordinate system and obtain the position coordinates (x, y, z) of each user node.
[0104] (3) The receiving node receives wireless signals from various industrial terminals.
[0105] (4) The receiving node obtains physical quantities such as channel state information, power spectral density, and power amplifier characteristics of the received signal through channel estimation. The receiving node obtains channel state information (CSI) of the received signal through channel estimation technology. Channel state information describes the fading, delay, noise and other characteristics of the channel. It is the basis for modulation and demodulation, equalization and other physical layer signal processing. Channel estimation is usually achieved through pilot signals, training sequences or blind estimation methods. It can help the receiving end to better compensate for various attenuations and distortions that the signal suffers during transmission and improve the receiving performance.
[0106] In one exemplary embodiment of this disclosure, the data acquisition module 902 transmits the industrial environment entity structure information and the coordinate information of the user node to the digital twin module 904. The data acquisition module 902 then transmits the received physical quantities to the authentication model training module 906.
[0107] In one exemplary embodiment of this disclosure, in the digital twin module 904, a digital twin world of the industrial Internet of Things is constructed using parameters acquired by the data acquisition module 902. The wireless signal transmission and reception process is simulated by using parameter information such as the location, antenna, and carrier of each user, thereby obtaining signal samples transmitted by users at each location received by the receiving node.
[0108] In one exemplary embodiment of this disclosure, the digital twin module 904 constructs a digital twin world for the industrial Internet of Things using parameters transmitted by the data acquisition module 902. It simulates the transmission and reception of wireless signals using parameters such as the location, antenna, and carrier wave of each user. Specifically, this includes the following steps:
[0109] (1) User channel model establishment, that is, establishing a channel model between the user and the receiver based on the user's location and antenna configuration. Commonly used channel models include:
[0110] (1.1) Path loss model: Calculates the path loss of a signal as it propagates in space. Path loss is usually a function of distance, such as using a free-space path loss model or a two-path loss model.
[0111] (1.2) Multipath fading model: Considering the multipath effect caused by buildings, ground, obstacles, etc., Rayleigh fading model or Rice fading model is used to simulate the multipath fading of wireless signals.
[0112] (1.3) Shadow fading: The shadow effect of the signal in different environments is simulated by using the log-normal distribution, such as signal attenuation when passing through walls or trees.
[0113] (2) Channel response generation, which uses user location, antenna information and multipath parameters to generate the channel impulse response between the user and the receiver.
[0114] In one exemplary embodiment of this disclosure, the channel impulse response is key to the received signal and is used to characterize the signal’s attenuation, delay, and phase changes in the time and space domains.
[0115] (3) Signal modulation and transmission, that is, using appropriate modulation methods to modulate the user's original information (e.g., QPSK, 16-QAM, etc.). When the modulated signal is transmitted through the channel, it is affected by factors such as path loss, multipath fading, phase rotation, and noise. In addition, OFDM (Orthogonal Frequency Division Multiplexing) technology can be used to divide the signal into multiple subcarriers for transmission, thereby resisting frequency-selective fading.
[0116] (4) Received signal generation: This involves convolving the modulated signal with the generated channel impulse response to simulate the signal propagation process from the user to the receiver. Signals from multiple users are superimposed, and noise (such as additive white Gaussian noise, AWGN) is added to generate signal samples received by the receiver. Signal samples transmitted by users at various locations are generated at the receiver node. If the number of samples is less than the threshold ρ, sample signal generation continues; if the number of samples is greater than the threshold ρ, the next step is performed, transmitting the generated signal samples to the authentication model training module 906.
[0117] In one exemplary embodiment of this disclosure, in the authentication model training module 906, the real signal samples collected by the data acquisition module 902 and the signal samples generated by the digital twin module 904 are used as samples for training the authentication model. The neural network is selected and the parameters of the authentication model are obtained through backpropagation and gradient descent, and then transmitted to the identity authentication module.
[0118] In one exemplary embodiment of this disclosure, the authentication model training module 906 selects one of the following neural networks as the authentication model: DNN, CNN, or RNN.
[0119] In one exemplary embodiment of this disclosure, real signal samples transmitted by the data acquisition module 902 and signal samples generated by the digital twin module 904 are used as training samples for the authentication model. The parameters of the authentication model are optimized through backpropagation and gradient descent. When the value of the loss function exceeds a threshold... If the value of the loss function is less than the threshold, return to step 14. If the condition is met, proceed to the next step. Transmit the parameters of the authentication model to the identity authentication module 908.
[0120] In one exemplary embodiment of this disclosure, in the identity authentication module 908, an optimized authentication model is used to authenticate the signal to be authenticated, and an authentication result is obtained. The receiving node receives a signal unknown to the sending end. The receiving node uses the optimized authentication model to authenticate the signal to be authenticated and obtains the identity authentication result.
[0121] Corresponding to the above method embodiments, this disclosure also provides an identity authentication device for an Internet of Things (IoT) terminal, which can be used to execute the above method embodiments.
[0122] Figure 10 This is a block diagram of an identity authentication device for an Internet of Things (IoT) terminal according to an exemplary embodiment of this disclosure.
[0123] refer to Figure 10 The IoT terminal authentication device 1000 may include:
[0124] The authentication module 1002 is configured to use a trained authentication model to authenticate the communication signals of the Internet of Things terminal. The authentication model is configured to be trained based on simulated communication signals, channel impulse responses, and signal samples generated by a twin communication environment. The twin communication environment is configured to be constructed based on the construction information of the communication environment and the user location information.
[0125] In one exemplary embodiment of this disclosure, before authenticating the communication signals of the IoT terminal using the trained authentication model, the IoT terminal authentication device 1000 is further configured to:
[0126] Obtain the construction information of the communication environment and user location information corresponding to the IoT terminal;
[0127] The twin communication environment of the IoT terminal is constructed based on the construction information of the communication environment and the user location information;
[0128] The channel impulse response is determined based on preset configuration parameters between the IoT terminal and the receiver.
[0129] Signal samples are generated based on the simulated communication signal, the channel impulse response, and the twin communication environment;
[0130] The signal samples are input into the authentication model for training until the loss function of the authentication model satisfies the convergence condition.
[0131] In one exemplary embodiment of this disclosure, the authentication device 1000 of the Internet of Things terminal is further configured to:
[0132] Obtain the user location information corresponding to the IoT terminal;
[0133] Channel estimation is performed based on the user location information and the address of the receiving end to determine the communication channel parameters in the communication environment. The communication channel parameters include at least one of channel state information, power spectral density, and power amplifier characteristics.
[0134] The communication environment information is obtained through the sensing devices associated with the IoT terminal;
[0135] The construction information is determined based on the communication environment information and the communication channel parameters.
[0136] In one exemplary embodiment of this disclosure, the authentication device 1000 of the Internet of Things terminal is further configured to:
[0137] Obtain the antenna configuration information and specified channel model corresponding to the IoT terminal;
[0138] The channel impulse response between the IoT terminal and the receiver is generated based on the user location information, the antenna configuration information, and the specified channel model.
[0139] In one exemplary embodiment of this disclosure, the authentication device 1000 of the Internet of Things terminal is further configured to:
[0140] The transmitted signal of the signal sample to be generated is modulated;
[0141] The orthogonal frequency division multiplexing algorithm is used to divide the modulated transmission signal to obtain multiple subcarrier signals;
[0142] Extract multiple subcarrier signals according to a preset number;
[0143] The specified subcarrier signal is spoofed according to the preset attack code strategy to generate negative samples, and the subcarrier that has not undergone the spoofing process is determined as a positive sample.
[0144] The signal sample is generated based on the positive sample, the negative sample, the channel impulse response, and the twin communication environment.
[0145] In one exemplary embodiment of this disclosure, the authentication device 1000 of the Internet of Things terminal is further configured to:
[0146] The positive and negative samples are convolved using the channel impulse response.
[0147] According to the twin communication environment, noise signals are added to the positive and / or negative samples after convolution processing, and the positive and / or negative samples with added noise signals are determined as the simulated communication signals.
[0148] In one exemplary embodiment of this disclosure, the authentication device 1000 of the Internet of Things terminal is further configured to:
[0149] Obtain the antenna configuration information corresponding to the IoT terminal;
[0150] Determine the communication path information between the IoT terminal and the receiving end. The communication path information includes path loss and / or multipath fading. The path loss includes free space path loss or two-path loss. The multipath fading includes Rayleigh fading model and / or Rice fading.
[0151] And / or determine the shadowing fading information of a log-normally distributed analog signal;
[0152] The specified channel model is determined based on the communication path information and / or the shadow fading information.
[0153] Since the functions of the device 1000 have been described in detail in their corresponding method embodiments, they will not be repeated here.
[0154] Compared with the prior art, the technical solution defined in the embodiments of this application has the following main advantages:
[0155] 1. In order to fully leverage the advantages of digital twins, the physical structure and terminal nodes of the Industrial Internet of Things can be digitally represented through digital twins, and the wireless signal transmission and reception process can be simulated, thereby generating a large number of wireless signal samples.
[0156] 2. Samples generated in the digital twin world can assist in the training of certification models, avoid overfitting of neural networks, and improve the accuracy and fault tolerance of models.
[0157] The main inventiveness of the technical solution defined in the embodiments of this application compared with the prior art lies in:
[0158] 1. Compared with identity authentication methods based on digital twins and blockchain, the sample parameter information used for authentication in this application can be self-configured, and the authentication performance will not decrease as the data volume increases. It has lower latency and is therefore more practical. The authentication method of this application is one-way authentication, which does not require any computing resources from the sending node, and is therefore a lightweight authentication method. In addition, this application is based on the physical quantity of the wireless channel and can realize "one-time password" encrypted authentication, thus providing higher security.
[0159] 2. Compared with neural network-based identity authentication methods, this application introduces digital twins to generate additional training samples, avoiding the overfitting problem of neural networks during training, improving the accuracy of authentication, and ensuring the identity security of industrial IoT terminals.
[0160] It should be noted that although several modules or units for the device used to perform actions have been mentioned in the detailed description above, this division is not mandatory. In fact, according to embodiments of this disclosure, the features and functions of two or more modules or units described above can be embodied in one module or unit. Conversely, the features and functions of one module or unit described above can be further divided and embodied by multiple modules or units.
[0161] In an exemplary embodiment of this disclosure, an electronic device capable of implementing the above-described method is also provided.
[0162] Those skilled in the art will understand that various aspects of the present invention can be implemented as systems, methods, or program products. Therefore, various aspects of the present invention can be specifically implemented in the following forms: entirely hardware implementations, entirely software implementations (including firmware, microcode, etc.), or implementations combining hardware and software aspects, collectively referred to herein as “circuits,” “modules,” or “systems.”
[0163] The following reference Figure 11 To describe an electronic device 1100 according to this embodiment of the present invention. Figure 11 The electronic device 1100 shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of the present invention.
[0164] like Figure 11 As shown, the electronic device 1100 is manifested in the form of a general-purpose computing device. The components of the electronic device 1100 may include, but are not limited to: at least one processing unit 1110, at least one storage unit 1120, and a bus 1130 connecting different system components (including storage unit 1120 and processing unit 1110).
[0165] The storage unit stores program code that can be executed by the processing unit 1110, causing the processing unit 1110 to perform the steps described in the "Exemplary Methods" section of this specification according to various exemplary embodiments of the present invention. For example, the processing unit 1110 can perform the method shown in the embodiments of this disclosure.
[0166] Storage unit 1120 may include a readable medium in the form of a volatile storage unit, such as random access memory (RAM) 11201 and / or cache memory 11202, and may further include a read-only memory (ROM) 11203.
[0167] Storage unit 1120 may also include a program / utility 11204 having a set (at least one) of program modules 11205, such program modules 11205 including but not limited to: operating system, one or more application programs, other program modules and program data, each or some combination of these examples may include an implementation of a network environment.
[0168] Bus 1130 can represent one or more of several types of bus structures, including a memory cell bus or memory cell controller, a peripheral bus, a graphics acceleration port, a processing unit, or a local bus using any of the various bus structures.
[0169] Electronic device 1100 can also communicate with one or more external devices 1140 (e.g., keyboard, pointing device, Bluetooth device, etc.), and with one or more devices that enable a user to interact with electronic device 1100, and / or with any device that enables electronic device 1100 to communicate with one or more other computing devices (e.g., router, modem, etc.). This communication can be performed via input / output (I / O) interface 1150. Furthermore, electronic device 1100 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 1160. As shown, network adapter 1160 communicates with other modules of electronic device 1100 via bus 1130. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with electronic device 1100, including but not limited to: microcode, device drivers, redundant processing units, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.
[0170] From the above description of the embodiments, those skilled in the art will readily understand that the exemplary embodiments described herein can be implemented by software or by combining software with necessary hardware. Therefore, the technical solutions according to the embodiments of this disclosure can be embodied in the form of a software product, which can be stored in a non-volatile storage medium (such as a CD-ROM, USB flash drive, external hard drive, etc.) or on a network, including several instructions to cause a computing device (such as a personal computer, server, terminal device, or network device, etc.) to execute the methods according to the embodiments of this disclosure.
[0171] In exemplary embodiments of this disclosure, a computer-readable storage medium is also provided, on which a program product capable of implementing the methods described above is stored. In some possible embodiments, various aspects of the invention may also be implemented as a program product comprising program code that, when the program product is run on a terminal device, causes the terminal device to perform the steps of the various exemplary embodiments of the invention described in the "Exemplary Methods" section of this specification.
[0172] The program product for implementing the above-described method according to embodiments of the present invention may employ a portable compact disc read-only memory (CD-ROM) and include program code, and may run on a terminal device, such as a personal computer. However, the program product of the present invention is not limited thereto. In this document, the readable storage medium may be any tangible medium containing or storing a program that may be used by or in conjunction with an instruction execution system, apparatus, or device.
[0173] The readable medium can be a readable signal medium or a readable storage medium. A readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of readable storage media (a non-exhaustive list) include: an electrical connection having one or more wires, a portable disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.
[0174] Computer-readable signal media may include data signals propagated in baseband or as part of a carrier wave, carrying readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium, capable of sending, propagating, or transmitting programs for use by or in conjunction with an instruction execution system, apparatus, or device.
[0175] The program code contained on the readable medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.
[0176] In exemplary embodiments of this disclosure, a computer program product is also provided. This computer program product can be loaded or stored on any combination of one or more readable media. The program code for performing operations of the present invention can be written in any combination of one or more programming languages, including object-oriented programming languages such as Java and C++, and conventional procedural programming languages such as C or similar languages. The program code can be executed entirely on a user's computing device, partially on a user's computing device, as a standalone software package, partially on a user's computing device and partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0177] Furthermore, the above figures are merely illustrative of the processes included in the method according to exemplary embodiments of the present invention, and are not intended to be limiting. It is readily understood that the processes shown in the above figures do not indicate or limit the temporal order of these processes. Additionally, it is readily understood that these processes may be executed synchronously or asynchronously, for example, in multiple modules.
[0178] Other embodiments of this disclosure will readily occur to those skilled in the art upon consideration of the specification and practice of the invention disclosed herein. This application is intended to cover any variations, uses, or adaptations of this disclosure that follow the general principles of this disclosure and include common knowledge or customary techniques in the art not disclosed herein. The specification and examples are to be considered exemplary only, and the true scope and concept of this disclosure are indicated by the claims.
Claims
1. An authentication method for an Internet of Things (IoT) terminal, characterized in that, include: The transmitted signal of the signal sample to be generated is modulated; The orthogonal frequency division multiplexing algorithm is used to divide the modulated transmission signal to obtain multiple subcarrier signals; Extract multiple subcarrier signals according to a preset number; The specified subcarrier signal is spoofed according to the preset attack code strategy to generate negative samples, and the subcarrier that has not undergone the spoofing process is determined as a positive sample. The signal samples are generated based on the positive samples, the negative samples, the channel impulse response, and the twin communication environment; An authenticated model is used to authenticate the communication signals of IoT terminals. This model is configured to be trained based on simulated communication signals, channel impulse responses, and signal samples generated from a twin communication environment. The twin communication environment is configured to be constructed based on its construction information and the user's location information. Before using the trained authentication model to authenticate the communication signals of IoT terminals, the following steps are also included: Obtain the construction information of the communication environment and user location information corresponding to the IoT terminal; The twin communication environment of the IoT terminal is constructed based on the construction information of the communication environment and the user location information; Obtaining the construction information of the communication environment and user location information corresponding to the IoT terminal also includes: Obtain the user location information corresponding to the IoT terminal; Channel estimation is performed based on the user location information and the address of the receiving end to determine the communication channel parameters in the communication environment. The communication channel parameters include at least one of channel state information, power spectral density, and power amplifier characteristics. The communication environment information is obtained through the sensing devices associated with the IoT terminal.
2. The IoT terminal authentication method as described in claim 1, characterized in that, Before using the trained authentication model to authenticate the communication signals of IoT terminals, the following steps are also included: Obtain the construction information of the communication environment and user location information corresponding to the IoT terminal; The twin communication environment of the IoT terminal is constructed based on the construction information of the communication environment and the user location information; The channel impulse response is determined based on the preset configuration parameters between the IoT terminal and the receiver. Signal samples are generated based on the simulated communication signal, the channel impulse response, and the twin communication environment; The signal samples are input into the authentication model for training until the loss function of the authentication model satisfies the convergence condition.
3. The IoT terminal authentication method as described in claim 2, characterized in that, Obtaining the construction information of the communication environment and user location information corresponding to the IoT terminal includes: Obtain the user location information corresponding to the IoT terminal; Channel estimation is performed based on the user location information and the address of the receiving end to determine the communication channel parameters in the communication environment. The communication channel parameters include at least one of channel state information, power spectral density, and power amplifier characteristics. The communication environment information is obtained through the sensing devices associated with the IoT terminal; The construction information is determined based on the communication environment information and the communication channel parameters.
4. The IoT terminal authentication method as described in claim 2, characterized in that, Determining the channel impulse response based on preset configuration parameters between the IoT terminal and the receiver includes: Obtain the antenna configuration information and specified channel model corresponding to the IoT terminal; The channel impulse response between the IoT terminal and the receiver is generated based on the user location information, the antenna configuration information, and the specified channel model.
5. The IoT terminal authentication method as described in claim 1, characterized in that, Generating the signal samples based on the positive samples, the negative samples, the channel impulse response, and the twin communication environment includes: The positive and negative samples are convolved using the channel impulse response. According to the twin communication environment, noise signals are added to the positive and / or negative samples after convolution processing, and the positive and / or negative samples with added noise signals are determined as the simulated communication signals.
6. The IoT terminal authentication method as described in claim 4, characterized in that, Obtaining the antenna configuration information and specified channel model corresponding to the IoT terminal includes: Obtain the antenna configuration information corresponding to the IoT terminal; Determine the communication path information between the IoT terminal and the receiving end. The communication path information includes path loss and / or multipath fading. The path loss includes free space path loss or two-path loss. The multipath fading includes Rayleigh fading model and / or Rice fading. And / or determine the shadowing fading information of a log-normally distributed analog signal; The specified channel model is determined based on the communication path information and / or the shadow fading information.
7. An identity authentication device for an Internet of Things (IoT) terminal, characterized in that, include: The authentication module is configured to modulate the transmitted signal of the signal sample to be generated; The orthogonal frequency division multiplexing algorithm is used to divide the modulated transmission signal to obtain multiple subcarrier signals; Extract multiple subcarrier signals according to a preset number; The specified subcarrier signal is spoofed according to the preset attack code strategy to generate negative samples, and the subcarrier that has not undergone the spoofing process is determined as a positive sample. The signal samples are generated based on the positive samples, the negative samples, the channel impulse response, and the twin communication environment; An authenticated model is used to authenticate the communication signals of IoT terminals. This model is configured to be trained based on simulated communication signals, channel impulse responses, and signal samples generated from a twin communication environment. The twin communication environment is configured to be constructed based on its construction information and the user's location information. Before using the trained authentication model to authenticate the communication signals of IoT terminals, the following steps are also included: Obtain the construction information of the communication environment and user location information corresponding to the IoT terminal; The twin communication environment of the IoT terminal is constructed based on the construction information of the communication environment and the user location information; Obtaining the construction information of the communication environment and user location information corresponding to the IoT terminal also includes: Obtain the user location information corresponding to the IoT terminal; Channel estimation is performed based on the user location information and the address of the receiving end to determine the communication channel parameters in the communication environment. The communication channel parameters include at least one of channel state information, power spectral density, and power amplifier characteristics. The communication environment information is obtained through the sensing devices associated with the IoT terminal.
8. An electronic device, characterized in that, include: Memory; as well as A processor coupled to the memory, the processor being configured to execute the authentication method for an IoT terminal as described in any one of claims 1-6 based on instructions stored in the memory.
9. A computer-readable storage medium having a program stored thereon that, when executed by a processor, implements the authentication method for an Internet of Things (IoT) terminal as described in any one of claims 1-6.
10. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the authentication method for the Internet of Things terminal as described in any one of claims 1-6.
Citation Information
Patent Citations
Identity authentication method and device, storage medium and electronic equipment
CN114186211A
Access authentication method adaptive to network twinning scene
CN117915328A