A road terminal access method for a road traffic network and related devices
Through the dual identity authentication and operating environment evaluation methods, the problem of insufficient security of traditional access methods is solved, and safe and trusted access to road traffic terminals is achieved.
Patent Information
- Application Number
- CN202510322618.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-19
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-03-19
AI Technical Summary
Traditional road traffic terminal access methods have insufficient security problems and cannot effectively prevent the risks of malicious attacks and illegal access.
The double-time identity authentication mechanism is adopted, first performing static identity authentication, and then performing dynamic ciphertext and signature data verification based on random challenge values, combined with the evaluation of the terminal operating environment, ensuring the legality and security of the terminal equipment.
Through dual identity authentication and operating environment assessment, the security and credibility of road traffic terminal access is significantly improved, and malicious attacks and illegal access are prevented.
Smart Images

Figure CN119854039B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of road communication, and particularly to a method for a road terminal to access a road traffic network and related devices. Background Art
[0002] When a terminal device needs to access a road traffic network system, the terminal device and an access server need to perform identity authentication. When the access server verifies that the identity authentication information of the terminal device passes, the terminal device is allowed to access the system, thereby ensuring the legality of the identity of the terminal device accessing the road traffic network. Since a large number of road traffic terminals are distributed outdoors and are easily stolen and invaded, the traditional authentication method only needs to pass the authentication once to permanently access, which reduces the security of the terminal accessing the road traffic network and cannot effectively prevent the risks of malicious attacks and illegal access. Summary of the Invention
[0003] The present disclosure provides a method for a road terminal to access a road traffic network and related devices to solve the above technical problems to a certain extent.
[0004] In a first aspect of the present disclosure, a method for a road terminal to access a road traffic network is provided, including:
[0005] Obtaining an access request from a road terminal, where the access request includes attribute information of the road terminal;
[0006] Performing a first identity authentication on the road terminal based on the access request;
[0007] In response to the first identity authentication passing, sending a random challenge value and a second identity authentication request to the road terminal;
[0008] Receiving ciphertext and signature data returned by the road terminal in response to the second identity authentication request; wherein, the ciphertext is obtained based on the random challenge value, and the signature data is obtained based on the ciphertext;
[0009] Performing a second identity authentication based on the ciphertext and the signature data;
[0010] In response to the second identity authentication passing, evaluating the operating environment of the road terminal to obtain an evaluation result;
[0011] In response to the evaluation result meeting a preset requirement, allowing the road terminal to access the road traffic network.
[0012] In a second aspect of the present disclosure, a device for a road terminal to access a road traffic network is provided, including:
[0013] An identity authentication module, configured to: obtain an access request from a road terminal, where the access request includes attribute information of the road terminal; perform a first identity authentication on the road terminal based on the access request; in response to the first identity authentication being passed, send a random challenge value and a second identity authentication request to the road terminal; receive a ciphertext and a signature returned by the road terminal for the second identity authentication request; where the ciphertext is obtained based on the random challenge value, and the signature is obtained based on the ciphertext; and perform a second identity authentication based on the ciphertext and the signature;
[0014] An operating environment security assessment module, configured to: in response to the second identity authentication being passed, evaluate the operating environment of the road terminal to obtain an evaluation result; and in response to the evaluation result meeting a preset requirement, allow the road terminal to access the road traffic network.
[0015] In a third aspect of the present disclosure, an electronic device is provided, including one or more processors, a memory; and one or more programs, where the one or more programs are stored in the memory and are executed by the one or more processors, and the programs include instructions for executing the method according to the first aspect.
[0016] In a fourth aspect of the present disclosure, a non-volatile computer-readable storage medium containing a computer program is provided, and when the computer program is executed by one or more processors, the processors are caused to execute the method according to the first aspect.
[0017] In a fifth aspect of the present disclosure, a computer program product is provided, including computer program instructions, and when the computer program instructions are executed on a computer, the computer is caused to execute the method according to the first aspect.
[0018] As can be seen from the above, a method for a road terminal to access a road traffic network and related devices provided by the present disclosure combine a static authentication mechanism of identity authentication and basic operating environment security assessment, and a method of adopting a running behavior dynamic measurement mechanism during the operation of the terminal, and at the same time provide a related system structure. Taking the identity authentication mechanism and the evaluation strategy of the terminal's basic operating environment as the authentication basis, combining the running behavior dynamic measurement mechanism to provide continuous trust evaluation for the terminal, combining cryptographic technology with anomaly detection, and adopting a method of authenticating first and then connecting and dynamically evaluating, can achieve secure and reliable access of road traffic terminals. Description of the Drawings
[0019] To more clearly illustrate the technical solutions in the present disclosure or related technologies, the following will briefly introduce the drawings required for use in the embodiments or related technology descriptions. Obviously, the drawings in the following descriptions are only the embodiments of the present disclosure. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0020] Figure 1 It is a schematic diagram of the road terminal access architecture of the road traffic network according to an embodiment of the present disclosure.
[0021] Figure 2 It is a schematic diagram of the hardware structure of an exemplary electronic device according to an embodiment of the present disclosure.
[0022] Figure 3 It is a schematic flowchart of the road terminal access method for the road traffic network according to an embodiment of the present disclosure.
[0023] Figure 4 It is a schematic diagram of the road terminal access device for the road traffic network according to an embodiment of the present disclosure. Detailed implementation manners
[0024] To make the purpose, technical solutions, and advantages of the present disclosure clearer and more understandable, the following further elaborates on the present disclosure in detail in combination with specific embodiments and with reference to the drawings.
[0025] It should be noted that unless otherwise defined, the technical terms or scientific terms used in the embodiments of the present disclosure should have the ordinary meaning understood by those of ordinary skill in the art to which the present disclosure belongs. The "first", "second", and similar terms used in the embodiments of the present disclosure do not indicate any order, quantity, or importance, but are only used to distinguish different components. The terms such as "including" or "comprising" mean that the elements or objects appearing before this word cover the elements or objects listed after this word and their equivalents, without excluding other elements or objects. The terms such as "connected" or "coupled" are not limited to physical or mechanical connections, but may include electrical connections, whether direct or indirect. The terms such as "upper", "lower", "left", "right", etc. are only used to represent relative positional relationships, and when the absolute position of the object being described changes, the relative positional relationship may also change accordingly.
[0026] It can be understood that before using the technical solutions disclosed in the embodiments of the present disclosure, the types, usage scopes, usage scenarios, etc. of the personal information involved in the present disclosure should be informed to users and user authorization should be obtained in an appropriate manner in accordance with relevant laws and regulations.
[0027] For example, when a user's active request is received, a prompt message is sent to the user to clearly prompt the user that the operation requested by the user will require obtaining and using the user's personal information. Thus, the user can autonomously choose whether to provide personal information to software or hardware such as an electronic device, an application, a server, or a storage medium that performs the operations of the present disclosure's technical solution based on the prompt message.
[0028] It can be understood that the above notification and user authorization process is only illustrative and does not limit the implementation manner of the present disclosure. Other manners that comply with relevant laws and regulations can also be applied to the implementation manner of the present disclosure.
[0029] Figure 1 The figure shows a schematic diagram of the road terminal access architecture of the road traffic network according to an embodiment of the present disclosure. Refer to Figure 1 , the road terminal access architecture 100 of the road traffic network may include a server 110, a terminal 120, and a network 130 providing a communication link. The server 110 and the terminal 120 can be connected through the wired or wireless network 130. Among them, the server 110 can be an independent physical server, or a server cluster or a distributed system composed of multiple physical servers, or a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, security services, and CDN.
[0030] The terminal 120 can be implemented by hardware or software. For example, when the terminal 120 is implemented by hardware, it can be various electronic devices with a display screen and supporting page display, including but not limited to smart phones, tablet computers, e-book readers, laptop computers, and desktop computers, etc. When the terminal 120 device is implemented by software, it can be installed in the above-listed electronic devices; it can be implemented as multiple software or software modules (such as software or software modules for providing distributed services), or it can be implemented as a single software or software module, which is not specifically limited herein.
[0031] It should be noted that the road terminal access method for the road traffic network provided by the embodiments of the present application can be executed by the terminal 120 or by the server 110. It should be understood that Figure 1 the numbers of the terminals, the network, and the server in
[0032] Figure 2 The figure shows a schematic diagram of the hardware structure of an exemplary electronic device 200 provided by an embodiment of the present disclosure. As Figure 2As shown, the electronic device 200 may include: a processor 202, a memory 204, a network module 206, a peripheral interface 208, and a bus 210. Among them, the processor 202, the memory 204, the network module 206, and the peripheral interface 208 are communicatively connected to each other inside the electronic device 200 through the bus 210.
[0033] The processor 202 may be a central processing unit (CPU), a neural network processor (NPU), a microcontroller (MCU), a programmable logic device, a digital signal processor (DSP), an application specific integrated circuit (ASIC), or one or more integrated circuits. The processor 202 may be used to execute functions related to the technologies described in this disclosure. In some embodiments, the processor 202 may further include multiple processors integrated as a single logic component. For example, as Figure 2 shown, the processor 202 may include multiple processors 202a, 202b, and 202c.
[0034] The memory 204 may be configured to store data (e.g., instructions, computer code, etc.). As Figure 2 shown, the data stored in the memory 204 may include program instructions (e.g., program instructions for implementing the road terminal access method of the road traffic network in the embodiments of this disclosure) and data to be processed (e.g., the memory may store configuration files of other modules, etc.). The processor 202 may also access the program instructions and data stored in the memory 204, and execute the program instructions to operate on the data to be processed. The memory 204 may include a volatile storage device or a non-volatile storage device. In some embodiments, the memory 204 may include a random access memory (RAM), a read only memory (ROM), an optical disc, a magnetic disk, a hard disk, a solid state drive (SSD), a flash memory, a memory stick, etc.
[0035] The network module 206 may be configured to provide communication with other external devices to the electronic device 200 via a network. The network may be any wired or wireless network capable of transmitting and receiving data. For example, the network may be a wired network, a local wireless network (e.g., Bluetooth, WiFi, near field communication (NFC), etc.), a cellular network, the Internet, or a combination of the above. It can be understood that the type of the network is not limited to the above specific examples. In some embodiments, the network module 206 may include any combination of any number of network interface controllers (NICs), radio frequency modules, transceivers, modems, routers, gateways, adapters, cellular network chips, etc.
[0036] The peripheral interface 208 can be configured to connect the electronic device 200 to one or more peripheral devices to enable information input and output. For example, the peripheral devices can include input devices such as keyboards, mice, touchpads, touchscreens, microphones, various sensors, etc., and output devices such as displays, speakers, vibrators, indicator lights, etc.
[0037] The bus 210 can be configured to transfer information between various components of the electronic device 200 (such as the processor 202, the memory 204, the network module 206, and the peripheral interface 208), such as internal buses (e.g., the processor-memory bus), external buses (USB ports, PCI-E buses), etc.
[0038] It should be noted that although the architecture of the above-mentioned electronic device 200 only shows the processor 202, the memory 204, the network module 206, the peripheral interface 208, and the bus 210, in the specific implementation process, the architecture of the electronic device 200 may also include other components necessary for normal execution. In addition, those skilled in the art can understand that the architecture of the above-mentioned electronic device 200 may also only include the components necessary to implement the solution of the embodiments of the present disclosure, and do not necessarily include all the components shown in the figure.
[0039] With the rapid development of intelligent transportation systems, more and more terminal devices (such as roadside units, traffic police checkpoints, etc.) need to be connected to the road traffic network. Moreover, the terminal nodes are widely dispersed, the business scenarios are complex, and each terminal node may be scheduled for use. Large-scale ubiquitous heterogeneous terminals have become a security shortcoming. The access security and reliability of these terminal devices have become urgent problems to be solved. When a terminal device needs to access the road traffic network system, the terminal device and the access server need to perform identity authentication. When the access server verifies that the identity authentication information of the terminal device is passed, the terminal device is allowed to access the system, thereby ensuring the legality of the identity of the terminal device accessing the road traffic network. Since a large number of road traffic terminals are distributed outdoors and are easily stolen and invaded, the traditional method of one-time authentication and permanent access can no longer meet the requirements of the new Internet. In addition, there is a lack of static security assessment of the terminal's basic operating environment and dynamic monitoring of the behavior during operation, which cannot effectively prevent the risks of malicious attacks and illegal access. Therefore, how to improve the security and credibility of road traffic terminal access has become an urgent technical problem to be solved.
[0040] In view of this, embodiments of the present disclosure provide a method for a road terminal to access a road traffic network and related devices, a static authentication mechanism that combines identity authentication and security assessment of the basic operating environment, and a method that uses a dynamic measurement mechanism for operating behavior during the operation of the terminal. At the same time, a related system structure is provided. Based on the identity authentication mechanism and the evaluation strategy of the terminal's basic operating environment, combined with the dynamic measurement mechanism of operating behavior, continuous trust evaluation is provided for the terminal. By combining cryptographic technology with anomaly detection and adopting the method of authenticating first and then connecting and dynamically evaluating, secure and reliable access of road traffic terminals can be achieved.
[0041] See Figure 3 , Figure 3 shows a schematic flowchart of a method for a road terminal to access a road traffic network according to an embodiment of the present disclosure. The method for a road terminal to access a road traffic network according to an embodiment of the present disclosure can be deployed on a terminal or a server side. Figure 3 In [the figure], the method 300 for a road terminal to access a road traffic network may further include the following steps.
[0042] In step S310, an access request from the road terminal is obtained, and the access request includes attribute information of the road terminal.
[0043] Among them, the terminal device sends an access request to the trusted access gateway. The attribute information of the road terminal may include information such as a device identifier and an IP address. The access request of the road terminal and its attribute information can be transmitted via a network through a specific communication protocol or data interface.
[0044] In some embodiments, the method 300 may further include:
[0045] Generate a session key, public parameters, a signature master public key, and a signature master private key.
[0046] In some embodiments, the method 300 may further include:
[0047] Generate a corresponding terminal signature private key based on the signature master private key and the device identifier of the road terminal.
[0048] Specifically, the key generation center can generate a session key SessionKey using the national cryptographic algorithm SM4 and securely send it to the terminal device and the trusted access gateway. The KGC uses the SM9 algorithm to generate system public parameters and a signature master key pair (ks, Ppub-s), secretly stores the signature master private key ks, and publishes the system public parameters and the signature master public key Ppub-s. The KGC combines the master private key ks and the terminal identifier ID to generate a terminal signature private key ds and secretly sends it to the terminal device.
[0049] In step S320, a first identity authentication of the road terminal is performed based on the access request.
[0050] Among them, the first identity authentication may be to confirm whether the road terminal is registered and whether the network address is trustworthy.
[0051] In some embodiments, performing a first identity authentication on the road terminal based on the access request includes:
[0052] Verifying whether the device identifier is registered based on a comparison database, and whether the network address is in a trusted network segment;
[0053] In response to the device identifier being registered and the network address being in a trusted network segment, determining that the first identity authentication is passed.
[0054] Specifically, after receiving the access request from the terminal device, the trusted access gateway verifies whether the terminal device is legal, verifies whether the identification ID of the terminal device is registered in the system, and verifies whether the IP address of the terminal device is in the network segment allocated by the trusted access gateway through a comparison database. If the device identifier of the terminal device exists in the database and the terminal device IP address is also a legal network segment, an identity authentication request and a random challenge value are sent to the road terminal for further identity verification; otherwise, the terminal device is illegal and access is refused.
[0055] In step S330, in response to the first identity authentication being passed, a random challenge value and a second identity authentication request are sent to the road terminal.
[0056] Among them, the road terminal first attempts to access the road traffic network and sends a first identity authentication request containing its basic identity information (such as device ID, serial number, etc.). After receiving the request, it can be compared with the pre-stored information to verify the validity of these identity information. Once the first identity authentication is passed, a random challenge value, for example, a random number or a string of encrypted data, can be used to increase the uncertainty in subsequent identity authentication steps to prevent replay attacks or other forms of fraud. Sending this random challenge value to the road terminal can be part of the second identity authentication request. In addition to the random challenge value, the second identity authentication request may also contain other instructions or requirements, such as instructing the road terminal to use a specific encryption algorithm or hash function to process the challenge value.
[0057] In step S340, the ciphertext and signature data returned by the road terminal in response to the second identity authentication request are received; wherein, the ciphertext is obtained based on the random challenge value, and the signature data is obtained based on the ciphertext.
[0058] Among them, after the road terminal receives the challenge value and the second identity authentication request, it processes according to the requirements and returns the processed response. After receiving this response, the same algorithm or key (if it is symmetric encryption) can be used to verify the correctness of the response. If it is asymmetric encryption, the system may use the public key of the road terminal to verify the validity of the signature. If the second identity authentication response is verified successfully, the identity of the road terminal can be considered legal, and it is allowed to access the system or perform subsequent operations. If the verification fails, the access request can be rejected, and relevant events can be recorded for subsequent analysis. The random challenge value can ensure that the challenge value is truly random to prevent attackers from predicting or reusing previous challenge values. Use strong encryption algorithms and a sufficiently long key length to increase the difficulty of cracking. Include a timestamp in the challenge value or response to prevent replay attacks. Through the two identity authentication processes, the identity of the road terminal can be verified more effectively, and the overall security can be enhanced.
[0059] In some embodiments, the ciphertext is obtained based on the random challenge value, including:
[0060] The road terminal generates a data packet based on the random challenge value, the device identifier, the basic operating environment, the timestamp, and the data packet size;
[0061] The ciphertext is obtained by encrypting the data packet based on the session key.
[0062] Specifically, the terminal device generates a data packet M according to information such as the random challenge value, the device identifier, the basic operating environment (including IP address, protocol version, operating system, etc.), the timestamp, and the data packet size. The terminal device uses the key SessionKey sent by KCG to encrypt the data packet M to generate the ciphertext C, C = E(M, SessionKey), where E can be the encryption algorithm of SM4.
[0063] In some embodiments, the signature data is obtained based on the ciphertext, including:
[0064] The road terminal signs the ciphertext based on the public parameters, the signature master public key, the ciphertext, and the terminal signature private key to obtain the signature data.
[0065] Specifically, the terminal device uses the system parameters params, the signature master public key Ppub-s, the data C, and the signature key ds to sign the data packet to generate the signature (h, S), (h, S) = Sign(C, params, Ppub-s, ds), where Sign is the SM9 signature algorithm. After the calculation is completed, the road terminal sends the ciphertext C and the signature (h, S) to the trusted access gateway together.
[0066] In step S350, a second authentication is performed based on the ciphertext and the signature data.
[0067] In some embodiments, performing a second authentication based on the ciphertext and the signature data includes:
[0068] Verifying the signature data based on public parameters, the public key of the signature master, an identifier, a device identifier, and the ciphertext to obtain a verification result;
[0069] In response to the verification result indicating successful verification, decrypting the ciphertext based on the session key to obtain a restored data packet;
[0070] Extracting a random challenge restoration value and a device restoration identifier from the restored data packet;
[0071] Comparing the random challenge restoration value with the random challenge value and whether the device restoration identifier is legal;
[0072] In response to the random challenge restoration value being consistent with the random challenge value and the device restoration identifier being legal, the second authentication passes.
[0073] Specifically, after the trusted access gateway receives the ciphertext C' and the signature (h', S') of the terminal device, the trusted access gateway uses the system parameters params, the public key of the signature master Ppub-s, the identifier hid (the identifier can be selected and publicly disclosed by the key generation center), the device identifier ID, the message C' and its digital signature (h', S') to verify the correctness of the signature: , where Verify is the signature verification algorithm of SM9. If the verification is successful (the output is 1), it is confirmed that the signature information of the terminal device is legal. The trusted access gateway uses SessionKey to decrypt the ciphertext C to restore the original data packet M', extracts the random challenge value and the device identifier therein, and verifies whether the random challenge value is consistent with the previously sent one to ensure that the terminal device responds to the current authentication request and prevent replay attacks. It is again confirmed that the device identifier is legal and valid in the system to ensure that even if other steps pass, the finally accessed device is still a legally registered device. If the authentication is successful, a static security assessment is performed, otherwise the terminal device is refused access.
[0074] In step S360, in response to the second authentication passing, evaluating the operating environment of the road terminal to obtain an evaluation result.
[0075] In some embodiments, evaluating the operating environment of the road terminal to obtain an evaluation result includes:
[0076] Determine the evaluation membership degree matrix based on the network address, protocol version, and operating system information of the road terminal; wherein, the protocol version includes protocol supportiveness and protocol security, and the operating system information includes version compliance and system security;
[0077] Obtain the evaluation result based on the membership degree matrix and the weight matrix.
[0078] Specifically, the trusted access gateway parses the data packet M' and extracts data such as the IP address, protocol version, and operating system information therein. The fuzzy comprehensive evaluation method (FCE) is used to evaluate the score of the basic environment. First, construct the factor set of the comprehensive evaluation. The factor set is an ordinary set composed of various factors that affect the evaluation object. In this solution, the factor set is the factors with a certain degree of fuzziness for evaluating the operating environment of the road terminal, denoted as U = {IP address u1, protocol version u2 (protocol supportiveness u21, protocol security u22), operating system information u3 (version compliance u31, system security u32)}. Given the weight parameters of each level of indicators, the first-level weight is denoted as W = [w1, w2, w3], and the second-level weights are W2 = [w21, w22], W3 = [w31, w32]. Set the evaluation grade set V = {poor, relatively poor, medium, good, excellent} to describe the evaluation results of each indicator. Obtain the evaluation membership degrees R1, R2, R3 of each indicator according to the extracted IP address, protocol version, and operating system information, where R1 is the single-factor judgment vector corresponding to the IP address, and R2, R3 are the second-level single-factor judgment matrices corresponding to the protocol version and operating system information. Calculate the membership degree matrix R = [R1, (W2 * R2)T, (W3 * R3)T]. Calculate the first-level indicator judgment set B = W * R, and take the evaluation grade with the largest value in B as the comprehensive evaluation result. If the evaluation result is "good" or above, the security evaluation passes, and the road terminal device is allowed to access.
[0079] In step S370, in response to the evaluation result meeting the preset requirements, allow the road terminal to access the road traffic network.
[0080] In some embodiments, method 300 may further include:
[0081] Receive a registration request from the road terminal, where the registration request includes the device identifier of the road terminal;
[0082] In response to the registration request, return a registration result to the road terminal.
[0083] Among them, the registration request is usually sent to the central system through a network (such as the Internet, private network, etc.). The registration request may include the device identifier of the road terminal, which may include the unique identifier of the device (such as MAC address, serial number, etc.), device type, manufacturer information, installation location, etc. After receiving the registration request, the Key Generation Center (KGC) will first verify the identity information in the request. The verification process may include checking whether the device identifier is unique, whether the device type is within the allowed range, whether the manufacturer is trustworthy, etc. If the identity information does not meet the requirements, the Key Generation Center (KGC) can reject the registration request. If the identity information is verified successfully, the system will continue to process the registration request. For example, create a new device record in the database, assign a unique device ID, configure the basic parameters of the device (such as communication protocol, data format, etc.). After processing the registration request, the Key Generation Center (KGC) can return the registration result to the road terminal. The registration result can be a simple status code or message indicating whether the registration is successful. If the registration is successful, the result may also include necessary information such as device ID, key, configuration parameters, etc. If the registration fails, the result should contain the reason for failure or error code for the road terminal to troubleshoot or retry registration.
[0084] Specifically, the method for a road terminal device to access the road traffic network may include steps such as registration, key generation, access request, basic verification, challenge authentication, packet information generation, identity authentication, and security assessment. For example, the road terminal device can perform registration. The road terminal device sends the identity information as the registration information to the Key Generation Center (KGC). The KGC receives and processes the registration information, generates the session key SessionKey, and securely sends it to the terminal device and the trusted access gateway. At the same time, the KGC generates the system public parameters and the signature master key pair, secretly saves the signature master private key, and publishes the system public parameters and the signature public master key.
[0085] The KGC can generate and distribute keys without explicit message passing. Processing logic: The KGC combines the master private key and the terminal identifier to generate the terminal signature private key and secretly sends it to the terminal device.
[0086] The terminal device sends an access request to the trusted access gateway, including information such as device identifier, IP address, etc. The trusted access gateway receives and processes the access request.
[0087] The trusted access gateway performs basic verification (i.e., the first identity authentication) and initiates challenge authentication (i.e., the second identity authentication). The trusted access gateway verifies the legitimacy of the terminal device, the registration status of the identification ID, and the allocation status of the IP address. If the verification passes, it sends an identity authentication request and a random challenge value to the terminal device. It can use implicit message passing (based on database verification).
[0088] The terminal device generates data packet M information, including a random challenge value, device identifier, basic operating environment (including information such as IP address, protocol version, operating system, etc.), timestamp, data packet size, etc., and uses the SessionKey to encrypt data M to generate ciphertext C, and simultaneously generates a signature (h, S). The terminal device sends the ciphertext C and the signature (h, S) to the trusted access gateway.
[0089] The trusted access gateway receives the ciphertext C’ and the signature (h’, S’), verifies the correctness of the signature, and uses the SessionKey to decrypt the ciphertext C to obtain the data packet M’, and verifies the random challenge value and the device identifier.
[0090] Use a security assessment algorithm to perform a security assessment on the basic operating environment. If the terminal device successfully passes the authentication and security assessment, it accesses the road traffic network system; otherwise, access is refused.
[0091] Among them, the national cryptographic algorithms SM4 and SM9 can be used for encryption and signature to ensure the security of communication and the integrity of data. It can be seen that the above-mentioned trusted access gateway ensures that the accessed terminal devices meet the security requirements through a strict verification and evaluation process.
[0092] In some embodiments, method 300 may further include:
[0093] Obtain the first type of network traffic data and the second type of network traffic data of the road terminal within the target time period;
[0094] Based on the trained first type of prediction model, predict the first type of traffic data in the target time period to obtain a first prediction sequence set; and based on the trained second type of prediction model, predict the second type of traffic data in the target time period to obtain a second prediction sequence set; wherein, the first type of prediction model and the second type of prediction model are respectively trained based on historical first type of network traffic data and historical second type of network traffic data;
[0095] Based on the first prediction sequence set and the first type of network traffic data, obtain a first error, and based on the second prediction sequence set and the second type of network traffic data, obtain a second error;
[0096] In response to the first error being greater than or equal to the first confidence threshold and / or the second error being greater than or equal to the second confidence threshold, determine that there is a traffic anomaly in the road terminal; wherein, the first confidence threshold and the second confidence threshold are respectively obtained based on the training of the first type of prediction model and the second type of prediction model;
[0097] In response to the road terminal having a traffic anomaly, refuse the road terminal to access the road traffic network; and / or, perform secondary authentication on the road terminal.
[0098] Specifically, the normal network traffic data of the terminal history can be obtained, which is a feature vector of a specific dimension statistically based on the terminal traffic activities within time slots. Before training with a neural network, it is necessary to normalize the data obtained above. By normalizing the data, numerical problems can be avoided, and at the same time, the network can converge quickly. The statistical limit value method is a commonly used normalization method. Specifically, it is implemented by finding the maximum value Max and the minimum value Min in the sample dataset for standardization, and scaling the values of each feature in the feature vector into the closed interval of [0,1]. The formula is: . The time dimension of the terminal is divided into two time dimensions: terminal request activities and daily activities. Extract the first traffic data sequence under the time dimension of terminal request activities, and use the VAE-LSTM model for time series modeling to obtain a prediction model during requests and calculate the reconstruction error to obtain the first confidence threshold. Extract the second traffic data sequence under the time dimension of terminal daily activities, and use the VAE-LSTM model for time series modeling to obtain a prediction model during daily activities and calculate the reconstruction error to obtain the second confidence threshold. The VAE-LSTM model encodes the data sequence within the input time window using the VAE encoder to obtain a low-dimensional embedding sequence, then inputs the embedding sequence into the LSTM model to obtain a predicted embedding sequence, and finally decodes it through the VAE decoder to obtain a reconstructed window sequence.
[0099] Obtain the terminal network traffic data during the time period to be detected, and divide the time dimension of the terminal into two time dimensions: terminal request activities and terminal daily activities. Tq={tq1,…,tqn} represents the set of time slots for terminal request activities, and Tr={tr1,…,trm} represents the set of time slots for terminal daily activities. Use the prediction model during requests to predict the traffic data within the time dimension of terminal request activities to obtain the first set of prediction sequences, and use the prediction model during daily activities to predict the traffic data within the time dimension of terminal daily activities to obtain the second set of prediction sequences. Use the Euclidean distance to calculate the prediction error using the prediction sequences and the actual traffic data. The formula is . Compare the mean of the prediction error set of the first set of prediction sequences with the first confidence threshold, and compare the mean of the prediction error set of the second set of prediction sequences with the second confidence threshold. If it is greater than the confidence threshold, it indicates that there is traffic anomaly.
[0100] According to the anomaly detection result, if there is traffic anomaly, prohibit the terminal from accessing the road traffic network service system, and at the same time require the terminal to initiate secondary authentication.
[0101] It can be seen that the method according to the embodiments of the present disclosure, combining the static authentication mechanism of identity authentication and the security assessment of the basic operating environment, and the method of adopting the running behavior dynamic measurement mechanism during the operation of the terminal, can meet the security requirements of the road traffic network for road terminals. When the terminal accesses, a static security authentication module including identity authentication and the security assessment of the basic operating environment is adopted to realize the secure access of the road traffic network terminal. The identity authentication based on the identifier can effectively guarantee the legality of a large number of ubiquitous heterogeneous terminal devices in the road traffic network and prevent the illegal access of devices. Combining the identifier authentication enhanced by the challenge authentication based on the national cryptographic algorithm and the basic operating environment assessment ensures that only legal and stable environment terminal devices can access the system. At the same time, the assessment strategy for the terminal basic operating environment can identify potential risks and confirm whether the software and hardware configurations of the terminal devices are stable enough to support the expected applications and services.
[0102] After the terminal accesses, a running behavior dynamic measurement module is adopted to track the communication behavior and other operation behaviors of the terminal, collect the terminal network traffic data, combine the deep learning model to detect whether there is an abnormal activity pattern, and implement dynamic access control according to the abnormal detection result to prevent security problems caused by abnormal terminal operation. The abnormal detection method based on time series prediction is adopted to divide the terminal activities into two time dimensions of request activities and daily activities, establish prediction models respectively to adapt to the traffic changes in different scenarios, and adopt dynamic access control. Based on the identity authentication mechanism and the assessment strategy of the terminal basic operating environment as the authentication basis, combining the running behavior dynamic measurement mechanism to provide continuous trust assessment for the terminal, combining the cryptographic technology with the abnormal detection, and adopting the method of authenticating first and then connecting and dynamically evaluating, the secure and trustworthy access of the road traffic terminal can be realized.
[0103] It should be noted that the method of the embodiments of the present disclosure can be executed by a single device, such as a computer or a server, etc. The method of this embodiment can also be applied to a distributed scenario and completed by the cooperation of multiple devices. In this case of the distributed scenario, one of the multiple devices can only execute one or more steps of the method of the embodiments of the present disclosure, and these multiple devices will interact with each other to complete the described method.
[0104] It should be noted that some embodiments of the present disclosure have been described above. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims can be executed in a different order from that in the above embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In certain embodiments, multitasking and parallel processing are also possible or may be advantageous.
[0105] Based on the same inventive concept, corresponding to the method of any of the above embodiments, the present disclosure also provides a road terminal access device for a road traffic network. Refer to Figure 4 , the road terminal access device for the road traffic network, the device includes:
[0106] An identity authentication module, configured to: obtain an access request from a road terminal, where the access request includes attribute information of the road terminal; perform a first identity authentication on the road terminal based on the access request; in response to the first identity authentication passing, send a random challenge value and a second identity authentication request to the road terminal; receive a ciphertext and a signature returned by the road terminal in response to the second identity authentication request; where the ciphertext is obtained based on the random challenge value, the signature is obtained based on the ciphertext; and perform a second identity authentication based on the ciphertext and the signature;
[0107] An operating environment security assessment module, configured to: in response to the second identity authentication passing, evaluate the operating environment of the road terminal to obtain an evaluation result; and in response to the evaluation result meeting a preset requirement, allow the road terminal to access the road traffic network.
[0108] In some embodiments, the device further includes:
[0109] A key generation center, configured to generate a session key, public parameters, a signature public key, and a signature private key; and generate a corresponding terminal signature private key based on the signature private key and the device identifier of the road terminal.
[0110] In some embodiments, the device further includes:
[0111] An abnormal behavior detection module, configured to: obtain first-type network traffic data and second-type network traffic data of the road terminal within a target time period;
[0112] Predict the first-type traffic data of the target time period based on a trained first-type prediction model to obtain a first prediction sequence set; and predict the second-type traffic data of the target time period based on a trained second-type prediction model to obtain a second prediction sequence set; where the first-type prediction model and the second-type prediction model are respectively trained based on historical first-type network traffic data and historical second-type network traffic data;
[0113] Obtain a first error based on the first prediction sequence set and the first-type network traffic data, and obtain a second error based on the second prediction sequence set and the second-type network traffic data;
[0114] In response to the first error being greater than or equal to the first confidence threshold and / or the second error being greater than or equal to the second confidence threshold, it is determined that there is a traffic anomaly at the road terminal; wherein, the first confidence threshold and the second confidence threshold are respectively obtained based on the training of the first type of prediction model and the second type of prediction model.
[0115] In some embodiments, the device further includes:
[0116] A dynamic access control module, configured to, in response to there being a traffic anomaly at the road terminal, deny the road terminal access to the road traffic network; and / or, perform secondary authentication on the road terminal.
[0117] For the convenience of description, when describing the above device, various modules are described separately according to their functions. Of course, when implementing the present disclosure, the functions of each module can be implemented in one or more software and / or hardware.
[0118] The device in the above embodiment is used to implement the method for accessing a road terminal of a road traffic network in any of the foregoing embodiments, and has the beneficial effects of the corresponding method embodiments, which will not be elaborated herein.
[0119] Based on the same technical concept, corresponding to the method in any of the above embodiments, the present disclosure further provides a non-transitory computer-readable storage medium storing computer instructions for causing the computer to execute the method for accessing a road terminal of a road traffic network in any of the foregoing embodiments.
[0120] The computer-readable medium in this embodiment includes permanent and non-permanent, removable and non-removable media, and information storage can be implemented by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device.
[0121] The computer instructions stored in the storage medium in the above embodiment are used to cause the computer to execute the method for accessing a road terminal of a road traffic network in any of the foregoing embodiments, and have the beneficial effects of the corresponding method embodiments, which will not be elaborated herein.
[0122] Those of ordinary skill in the art should understand that the discussion of any of the above embodiments is merely exemplary and is not intended to imply that the scope of the present disclosure (including the claims) is limited to these examples; under the concept of the present disclosure, the technical features in the above embodiments or different embodiments can also be combined, the steps can be implemented in any order, and there are many other variations in different aspects of the embodiments of the present disclosure as described above. For the sake of brevity, they are not provided in detail.
[0123] In addition, for simplicity of explanation and discussion, and in order not to make the embodiments of the present disclosure difficult to understand, the well-known power / ground connections to integrated circuit (IC) chips and other components may or may not be shown in the provided drawings. Further, the devices may be shown in block diagram form in order to avoid making the embodiments of the present disclosure difficult to understand, and this also takes into account the fact that the details of the implementation of these block diagram devices are highly dependent on the platform on which the embodiments of the present disclosure are to be implemented (i.e., these details should be fully within the understanding of those skilled in the art). In cases where specific details (such as circuits) are set forth to describe exemplary embodiments of the present disclosure, it will be apparent to those skilled in the art that the embodiments of the present disclosure may be implemented without these specific details or with variations of these specific details. Therefore, these descriptions should be considered illustrative rather than restrictive.
[0124] Although the present disclosure has been described in connection with specific embodiments of the present disclosure, many alternatives, modifications, and variations of these embodiments will be apparent to those of ordinary skill in the art based on the foregoing description. For example, other memory architectures (such as dynamic RAM (DRAM)) may be used with the embodiments discussed.
[0125] The embodiments of the present disclosure are intended to cover all such alternatives, modifications, and variations that fall within the broad scope of the appended claims. Therefore, any omissions, modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the embodiments of the present disclosure shall be included within the protection scope of the present disclosure.
Claims
1. A road terminal access method for a road traffic network, characterized in that: include: Acquire an access request from a road terminal, wherein the access request includes attribute information of the road terminal; Performing a first identity authentication on the road terminal based on the access request; In response to the first identity authentication being passed, sending a random challenge value and a second identity authentication request to the road terminal; Receiving the ciphertext and signature data returned from the road terminal in response to the second identity authentication request; wherein the ciphertext is obtained based on the random challenge value, and the signature data is obtained based on the ciphertext; Performing a second identity authentication based on the ciphertext and the signature data; In response to the second identity authentication being passed, evaluating the operating environment of the road terminal to obtain an evaluation result; In response to the evaluation result meeting a preset requirement, allowing the road terminal to access the road traffic network; The method further comprises: Acquire the first type of network traffic data and the second type of network traffic data of the road terminal within a target time period; Predicting the first type of traffic data of the target time period based on the trained first type prediction model to obtain a first prediction sequence set; and predicting the second type of traffic data of the target time period based on the trained second type prediction model to obtain a second prediction sequence set; Obtain a first error based on the first prediction sequence set and the first type of network traffic data, and obtain a second error based on the second prediction sequence set and the second type of network traffic data; In response to the first error being greater than or equal to a first confidence threshold and / or the second error being greater than or equal to a second confidence threshold, determining that a traffic abnormality exists at the road terminal; In response to traffic anomalies at the road terminal, denying the road terminal access to the road traffic network; and / or performing secondary authentication on the road terminal.
2. The method according to claim 1, characterized in that The attribute information includes a device identifier and a network address; Then, based on the access request, the first identity authentication is performed on the road terminal, including: Verifying whether the device identification is registered and whether the network address is in a trusted network segment based on a comparison database; In response to the device identification having been registered and the network address being in a trusted network segment, it is determined that the first identity authentication has passed.
3. The method according to claim 2, characterized in that The ciphertext is obtained based on the random challenge value, including: The road terminal generates a data packet based on the random challenge value, the device identification, the basic operating environment, the timestamp and the data packet size; Encrypting the data packet based on the session key to obtain the ciphertext; The signature data is obtained based on the ciphertext, including: The road terminal signs the ciphertext based on the public parameters, the signature master public key, the ciphertext and the terminal signature private key to obtain the signature data.
4. The method according to claim 2, characterized in that: Performing a second identity authentication based on the ciphertext and the signature data includes: Verify the signature data based on the public parameters, the signature master public key, the identifier, the device identification, and the ciphertext to obtain a verification result; In response to the verification result indicating successful verification, decrypting the ciphertext based on the session key to obtain a restored data packet; Extracting the random challenge recovery value and the device recovery identifier in the recovery data packet; comparing the random challenge recovery value with the random challenge value and whether the device recovery identifier is legal; In response to the random challenge recovery value being consistent with the random challenge value and the device recovery identifier being legal, it is determined that the second identity authentication is passed.
5. The method according to claim 1, characterized in that The operating environment of the road terminal is evaluated to obtain an evaluation result, including: Determining an evaluation membership matrix based on the network address, protocol version and operating system information of the road terminal; wherein the protocol version includes protocol supportability and protocol security, and the operating system information includes version compliance and system security; The evaluation result is obtained based on the membership matrix and the weight matrix.
6. The method according to claim 1, characterized in that The first type of prediction model and the second type of prediction model are trained based on the historical first type of network traffic data and the historical second type of network traffic data respectively; The first confidence threshold and the second confidence threshold are obtained based on the training of the first type of prediction model and the second type of prediction model, respectively.
7. The method according to claim 1, characterized in that The method further comprises: Generate session keys, public parameters, signature master public key and signature master private key; A corresponding terminal signature private key is generated based on the signature master private key and the device identification of the road terminal.
8. A road terminal access device for a road traffic network, characterized in that: include: The identification authentication module is used to: obtain an access request from a road terminal, wherein the access request includes attribute information of the road terminal; Performing a first identity authentication on the road terminal based on the access request; in response to the first identity authentication being successful, sending a random challenge value and a second identity authentication request to the road terminal; receiving a ciphertext and a signature returned from the road terminal in response to the second identity authentication request; wherein the ciphertext is obtained based on the random challenge value, and the signature is obtained based on the ciphertext; and performing a second identity authentication based on the ciphertext and the signature; An operating environment security assessment module, configured to: in response to the second identity authentication being passed, assess the operating environment of the road terminal to obtain an assessment result; and in response to the assessment result meeting a preset requirement, allow the road terminal to access the road traffic network; An abnormal behavior detection module is used to: obtain the first type of network traffic data and the second type of network traffic data of the road terminal within a target time period; Predicting the first type of traffic data of the target time period based on the trained first type prediction model to obtain a first prediction sequence set; and predicting the second type of traffic data of the target time period based on the trained second type prediction model to obtain a second prediction sequence set; Obtain a first error based on the first prediction sequence set and the first type of network traffic data, and obtain a second error based on the second prediction sequence set and the second type of network traffic data; In response to the first error being greater than or equal to a first confidence threshold and / or the second error being greater than or equal to a second confidence threshold, determining that a traffic abnormality exists at the road terminal; The dynamic access control module is used to deny the road terminal access to the road traffic network in response to traffic anomalies at the road terminal; and / or to perform secondary authentication on the road terminal.
9. An electronic device, characterized in that: The method comprises a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the method according to any one of claims 1 to 7 is implemented.
10. A non-transitory computer-readable storage medium, characterized in that: The non-transitory computer-readable storage medium stores computer instructions, and the computer instructions are used to cause a computer to execute the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Access authentication method of wireless local area network, server and authentication system
CN106713222A
Provisioning and verifying device credentials
CN114788219A