Remote management method and system for communication gateway equipment

By adopting asymmetric encryption and dynamic authentication in remote management of communication gateway devices, combined with device behavior trust evaluation and dynamic permission adjustment, the security and reliability problems in remote management of devices are solved, achieving high security and flexible management effects.

CN119995902AInactive Publication Date: 2025-05-13SHANGHAI CHARMHOPE INFORMATION TECH CO LTD

Patent Information

Application Number
CN202510480107.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-17
Publication Date
2025-05-13
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Communication gateway devices have security problems in remote management, including simple username and password authentication that are vulnerable to attacks, a single point of failure risk in centralized management architecture, a lack of dynamic device behavior assessment and trusted historical recording mechanisms.

Method used

Asymmetric encryption and dynamic authentication mechanisms are adopted to generate device unique identifiers and authentication challenge values ​​through a secure hash function to realize device identity authentication. At the same time, trust scores are calculated through device behavior, permission control is dynamically adjusted, and traceability of the management process is recorded.

Benefits of technology

It improves the security and reliability of remote management of communication gateway equipment, realizes multi-dimensional security guarantee and flexible management mechanism, and can dynamically respond to security risks during equipment operation.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995902A_ABST
    Figure CN119995902A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of intelligent gateways, and particularly discloses a remote management method and system for communication gateway equipment, which is specifically characterized in that remote management network access equipment is registered, and a secure hash function is utilized to generate an equipment unique identifier and an authentication challenge value; the network access equipment signs the authentication challenge value by using an equipment private key, and the management end authenticates the identity of the network access equipment; acquiring a registration state and historical behavior data of the network access equipment, and calculating a trust score to obtain an authority level; the same shared point is calculated to generate a session key so as to realize encrypted communication and data storage recording work between the network access equipment and the management end; inputting the response time deviation data, the CPU utilization rate deviation data and the memory utilization rate deviation data into a behavior deviation score expression to obtain a total deviation score; the total deviation score is compared with a deviation threshold value, if the total deviation score is larger than the deviation threshold value, recalculation of the trust score and the permission level is triggered again, the access permission is updated, and the management end records the change.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of intelligent gateways, and in particular to a remote management method and system for communication gateway equipment. Background Art

[0002] With the rapid development of Internet of Things technology and industrial Internet, communication gateway devices have been widely used in industrial control, intelligent manufacturing, smart cities and other fields. These gateway devices undertake important functions such as data forwarding, protocol conversion, and edge computing. Their security and stable operation directly affect the reliability of the entire system. At present, the traditional remote management method of communication gateway devices mainly adopts the authentication mechanism based on username and password and the centralized management architecture, which has the following problems: First, simple username and password authentication is vulnerable to security threats such as man-in-the-middle attacks and replay attacks, and key management is complex and prone to leakage; second, the centralized management architecture has a single point of failure risk. Once the management center is attacked or fails, it will affect the operation of the entire system; third, the existing solution lacks a dynamic evaluation mechanism for device behavior and cannot dynamically adjust the management strategy according to the real-time status of the device; finally, the system lacks a reliable history recording mechanism, making it difficult to trace and audit the operation history of the device. These problems seriously restrict the security, reliability and flexibility of the remote management system of communication gateway devices, and a new solution is urgently needed. Summary of the invention

[0003] (1) Technical issues to be resolved The purpose of the present invention is to provide a communication gateway device remote management method and system to solve the security problem existing in the remote management of the communication gateway device.

[0004] (2) Technical solution To achieve the above object, the present invention provides a communication gateway device remote management method, the method comprising the following steps: S1, register the networked device for remote management, input the device public key, device serial number, and timestamp parameters into the secure hash function to generate the device unique identifier; input the random number and current timestamp into the secure hash function to generate the authentication challenge value, and the networked device signs the authentication challenge value with the device private key; the management end queries the corresponding device public key through the device unique identifier, uses the device public key to verify the signature to confirm the device identity, and authenticates the networked device; S2, obtain the registration status and historical behavior data of the networked device and input the expression for calculating the trust score of the device behavior to obtain the trust score; obtain the permission level according to the permission management method and the trust score; the device side and the management side respectively calculate the same shared point, input the coordinate value of the shared point into the secure hash function to generate a session key, so as to realize the encrypted communication between the networked device and the management side and the data storage and recording work; S3, obtain the response time deviation, CPU usage deviation, and memory usage deviation of the networked device, input the response time deviation, CPU usage deviation, and memory usage deviation data into the behavior deviation score expression to obtain the total deviation score; compare the total deviation score with the deviation threshold. If the total deviation score is greater than the deviation threshold, recalculation of the trust score and permission level is retriggered, and the access rights are updated. The management end records this change.

[0005] Furthermore, the method of registering a remotely managed networked device and inputting a device-side public key, a device serial number, and a timestamp parameter into a secure hash function to generate a unique device identifier includes: Set the device unique identifier The expression is: in, is a secure hash function, is the public key of the device. is the device serial number, Is the timestamp.

[0006] Furthermore, the method of inputting the random number and the current timestamp into a secure hash function to generate an authentication challenge value, and the network access device signing the authentication challenge value with a device private key includes: Set the authentication challenge value The expression is: ; in, is a secure hash function, is a random number, is the current timestamp; The networked device signs the authentication challenge value with the device private key: Calculate the elliptic curve point R: Among them, k is a random number generated and used once, G is the base point, which is a specific point pre-selected on the elliptic curve secp256k1. The base point G is a fixed coordinate and is a public parameter known to all participants; Calculate the first signature value : ; in, To find the remainder function, is the x-coordinate of the elliptic curve point R, is the order, defining the order of the elliptic curve base point G, that is, satisfying The smallest positive integer of ; Calculating the hash value : ; in, is a secure hash function, is the authentication challenge value; Calculate the second signature value : ; in, To find the remainder function, k is a generated random number, It is the device private key, which is stored locally and confidentially on the connected device and can only be held and used by the connected device; The final signature is: (r, s).

[0007] Furthermore, the management end queries the corresponding device public key through the device unique identifier, and uses the device public key to verify the signature to confirm the device identity. The method for authenticating the networked device includes: Calculate the hash auxiliary value and signature auxiliary value : ; ; in, To find the remainder function, is the hash value, is the second signature value, is the first signature value; Calculate reconstruction points : ; Among them, G is the base point, It is the public key of the device. Device public key The calculation expression is: ; in, It is the device-side private key. is the base point, representing the public identity of the device; Verify the signature of the networked device: Check Is it equal to ,in for The x-coordinate of the two nodes; if they are equal, the signature verification succeeds; if they are not equal, the signature verification fails and the user is not authorized to access the network for the session.

[0008] Further, the method of obtaining the registration status and historical behavior data of the networked device and inputting the expression of the device behavior to calculate the trust score to obtain the trust score; obtaining the permission level according to the permission management method and the trust score; the device end and the management end respectively calculate the same shared point, and input the coordinate value of the shared point into the secure hash function to generate a session key to realize the encrypted communication and data storage and recording work between the networked device and the management end includes: After the signature verification is passed, the management end obtains the registration status of the networked device; after the status is normal, the historical behavior data of the networked device is obtained, including the authentication success rate, response time, and data quality data; The expression for calculating the trust score of device behavior is set as: ; Among them, TS is the trust score, is the weight of the i-th type of behavior, is the score of the i-th type of behavior, is the online time, is the total observation time, α is the behavior weight coefficient, β is the online time weight coefficient, and α + β = 1; Get permission levels based on permission management methods and trust scores , the calculation expression is: Among them, PL is the permission level, TS is the trust score, T1 and T2 are the trust thresholds, and L1, L2, and L3 are the corresponding permission levels; Device-side computing sharing point : ; in, It is the device-side private key. It is the public key of the management end; Management end public key Sent publicly from the management end to the device end, the calculation expression is: ; in, It is the management side private key. It is the base point; Management end calculation sharing point : ; Device public key Sent publicly from the device to the management end, the calculation expression is: ; verify , and finally share the point or , the coordinates are or ; Session Key The expression is: .

[0009] Further, the response time deviation, CPU usage deviation, and memory usage deviation of the networked device are obtained, and the response time deviation, CPU usage deviation, and memory usage deviation data are input into the behavior deviation score expression to obtain a total deviation score; the total deviation score is compared with the deviation threshold. If the total deviation score is greater than the deviation threshold, the trust score and the authority level are recalculated again, and the access rights are updated. The method for the management end to record this change includes: Based on the statistical analysis of the historical operation data of the equipment, the current observed value of the response time is obtained from the database 、Current observed value of CPU usage 、Current observed value of memory usage , historical average response time , CPU usage historical average , Historical average memory usage , response time standard deviation , CPU usage standard deviation , memory usage standard deviation ; The total deviation score is calculated by the expression of behavioral deviation score: ; in, is the current observation value, is the historical average. is the standard deviation, is the feature dimension; The total deviation score Deviation threshold If the total deviation score is less than the deviation threshold, the condition is met and the existing permission level is maintained. Otherwise, the trust score is recalculated. , the expression is: ; in, is the original trust score, is the attenuation factor, is the total deviation score, is the maximum permissible deviation; The change in the new trust score triggers a recalculation of the permission level PL to determine whether to maintain the original permission level or downgrade it, and updates the access rights. The management end records the change.

[0010] Based on the same inventive concept, on the other hand, the present invention also provides a communication gateway device remote management system, the system comprising: The identity authentication module is used to register the networked devices for remote management, input the device public key, device serial number, and timestamp parameters into the secure hash function to generate the device unique identifier; input the random number and current timestamp into the secure hash function to generate the authentication challenge value, and the networked device signs the authentication challenge value with the device private key; the management end queries the corresponding device public key through the device unique identifier, uses the device public key to verify the signature to confirm the device identity, and authenticates the networked device; The secure communication module is used to obtain the registration status and historical behavior data of the networked device and input the expression for calculating the trust score of the device behavior to obtain the trust score; the permission level is obtained according to the permission management method and the trust score; the device side and the management side respectively calculate the same shared point, and input the coordinate value of the shared point into the secure hash function to generate a session key, so as to realize the encrypted communication and data storage and recording between the networked device and the management side; The permission control module obtains the response time deviation, CPU usage deviation, and memory usage deviation of the networked device, inputs the response time deviation, CPU usage deviation, and memory usage deviation data into the behavior deviation score expression to obtain the total deviation score; compares the total deviation score with the deviation threshold. If the total deviation score is greater than the deviation threshold, the trust score and permission level are recalculated, and the access rights are updated. The management end records this change.

[0011] (3) Beneficial effects Compared with the prior art, the present invention has the following beneficial effects: 1. Asymmetric encryption and dynamic authentication are used to make data traceable; it supports a secure key negotiation process, so both parties do not need to share keys in advance, and can be updated regularly to achieve multi-dimensional security protection; 2. Intelligent management of networked devices can be achieved through dynamic trust assessment. The management end can adaptively adjust permission control based on historical data and current data. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] Figure 1 A flowchart of a method for remote management of a communication gateway device according to Embodiment 1 of the present invention;

[0013] Figure 2 This is a module block diagram of a communication gateway device remote management system according to Embodiment 2 of the present invention. DETAILED DESCRIPTION

[0014] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0015] Before giving examples, it is necessary to explain the application scenarios of the present invention. The present invention is applied to the real-time collection and processing of instantaneous current value signals of factory equipment.

[0016] Example 1: Figure 1 As shown, this embodiment provides a communication gateway device remote management method, the method comprising the following steps: S1, register the networked device for remote management, input the device public key, device serial number, and timestamp parameters into the secure hash function to generate the device unique identifier; input the random number and current timestamp into the secure hash function to generate the authentication challenge value, and the networked device signs the authentication challenge value with the device private key; the management end queries the corresponding device public key through the device unique identifier, uses the device public key to verify the signature to confirm the device identity, and authenticates the networked device; S2, obtain the registration status and historical behavior data of the networked device and input the expression for calculating the trust score of the device behavior to obtain the trust score; obtain the permission level according to the permission management method and the trust score; the device side and the management side respectively calculate the same shared point, input the coordinate value of the shared point into the secure hash function to generate a session key, so as to realize the encrypted communication between the networked device and the management side and the data storage and recording work; S3, obtain the response time deviation, CPU usage deviation, and memory usage deviation of the networked device, input the response time deviation, CPU usage deviation, and memory usage deviation data into the behavior deviation score expression to obtain the total deviation score; compare the total deviation score with the deviation threshold. If the total deviation score is greater than the deviation threshold, recalculation of the trust score and permission level is retriggered, and the access rights are updated. The management end records this change.

[0017] For example, the network access device requests a network access session through the management terminal, and the device public key 04A5B3...F921 (compressed to display the first 4 digits), device serial number The timestamp is GW20240321001. 1708483200 (2024-02-21 00:00:00 UTC); the registration status and historical behavior data of the networked devices are stored in the management database, and the authentication success rate, response time, data quality pass rate, and deviation threshold are obtained based on the historical behavior data; the management first ensures that the identity of the networked device is authentic through device registration and identity authentication, and confirms the device identity through the device public key verification signature; after the device is connected to the system, the device's authority level is determined; at the same time, the device and the management generate session keys through a secure key exchange mechanism, establish an encrypted communication channel, and ensure the security of subsequent management operations; the management continuously monitors the operating status of the device. When abnormal device behavior is detected, the management will re-evaluate the trust score of the device and adjust its authority level accordingly, thereby realizing dynamic management and control of the device; all authority change records will be securely stored to ensure the traceability of the management process; This remote management method based on dynamic trust assessment not only ensures the security of the system, but also provides a flexible management mechanism that can effectively deal with various security risks during equipment operation.

[0018] Furthermore, the method of registering a remotely managed networked device and inputting a device-side public key, a device serial number, and a timestamp parameter into a secure hash function to generate a unique device identifier includes: Set the device unique identifier The expression is: ; in, is a secure hash function, is the public key of the device. is the device serial number, Is the timestamp.

[0019] For example, the device public key, device serial number, and timestamp parameters are input into the device unique identifier. The expression of is: ; Is a 64-bit hexadecimal unique identifier.

[0020] Furthermore, the method of inputting the random number and the current timestamp into a secure hash function to generate an authentication challenge value, and the network access device signing the authentication challenge value with a device private key includes: Set the authentication challenge value The expression is: ; in, is a secure hash function, is a random number, is the current timestamp; The networked device signs the authentication challenge value with the device private key: Calculate the elliptic curve point R: ; Among them, k is a random number generated and used once, G is the base point, which is a specific point pre-selected on the elliptic curve secp256k1. The base point G is a fixed coordinate and is a public parameter known to all participants; Calculate the first signature value : ; in, To find the remainder function, is the x-coordinate of the elliptic curve point R, is the order, defining the order of the elliptic curve base point G, that is, satisfying The smallest positive integer of ; Calculating the hash value : ; in, is a secure hash function, is the authentication challenge value; Calculate the second signature value : ; in, To find the remainder function, k is a generated random number, It is the device private key, which is stored locally and confidentially on the connected device and can only be held and used by the connected device; The final signature is: (r, s).

[0021] Exemplarily, the parameters are set as: System generates random numbers is 9d8e7f6g5h, Current timestamp is 1708483800 (2024-02-21 00:10:00 UTC); Based on the authentication challenge value The expression of , we get: ; The networked device signs the authentication challenge value with the device private key: Set the system to generate a one-time random number k = 28d7f53bc52831ed... (256-bit random number), G is the base point, which is a specific point pre-selected on the elliptic curve secp256k1. The base point G is a fixed coordinate, which is a public parameter known to all participants. The abbreviated coordinate value is (0x79BE..., 0x483A...); By calculating the formula for elliptic curve points , the x and y coordinates of R are: Rx = 0x9a8b7c6d5e4f3a2b1c9d8e7f6a5b4c3d2e1f0a9b8c7d6e5f4a3b2c1d0e9f8a, Ry = 0x1a2b3c4d5e6f7g8h9i0j1k2l3m4n5o6p7q8r9s0t1u2v3w4x5y6z7a8b9c0d1; By calculating the first signature value Formula ,get =7c6d5e4f3a2b1c9a...; Calculating the hash value , = 4b3c2d1e0f9a8b7c...; Calculate the second signature value , = 2d1e0f9a8b7c6543..; The final signature result (r, s) is (7c6d5e4f3a2b1c9a... , 2d1e0f9a8b7c6543...).

[0022] Furthermore, the management end queries the corresponding device public key through the device unique identifier, and uses the device public key to verify the signature to confirm the device identity. The method for authenticating the networked device includes: Calculate the hash auxiliary value and signature auxiliary value : ; ; in, To find the remainder function, is the hash value, is the second signature value, is the first signature value; Calculate reconstruction points : ; Among them, G is the base point, It is the public key of the device. Device public key The calculation expression is: ; in, It is the device-side private key. is the base point, representing the public identity of the device; Verify the signature of the networked device: Check Is it equal to ,in for The x-coordinate of the two nodes; if they are equal, the signature verification succeeds; if they are not equal, the signature verification fails and the user is not authorized to access the network for the session.

[0023] Exemplarily, the hash auxiliary value is calculated and signature auxiliary value : =3c2d1e0f9a8b7654... ; =5e4f3a2b1c9d8e7f... ; Set the device private key 1234...5678 (confidential), calculate the public key of the device , and Substitute the result into the formula , get the reconstruction point The x-coordinate is: =9a8b7c6d5e4f3a2b...; Verify the signature of the networked device: = 7c6d5e4f3a2b1c9a... is equal to the r value (7c6d5e4f3a2b1c9a...), the signature verification is successful, the permission level can be calculated and the network can be accessed for conversation.

[0024] Further, the method of obtaining the registration status and historical behavior data of the networked device and inputting the expression of the device behavior to calculate the trust score to obtain the trust score; obtaining the permission level according to the permission management method and the trust score; the device end and the management end respectively calculate the same shared point, and input the coordinate value of the shared point into the secure hash function to generate a session key to realize the encrypted communication and data storage and recording work between the networked device and the management end includes: After the signature verification is passed, the management end obtains the registration status of the networked device; after the status is normal, the historical behavior data of the networked device is obtained, including the authentication success rate, response time, and data quality data; The expression for calculating the trust score of device behavior is set as: ; Among them, TS is the trust score, is the weight of the i-th type of behavior, is the score of the i-th type of behavior, is the online time, is the total observation time, α is the behavior weight coefficient, β is the online time weight coefficient, and α + β = 1; Get permission levels based on permission management methods and trust scores , the calculation expression is: Among them, PL is the permission level, TS is the trust score, T1 and T2 are the trust thresholds, and L1, L2, and L3 are the corresponding permission levels; Device-side computing sharing point : ; in, It is the device-side private key. It is the public key of the management end; Management end public key Sent publicly from the management end to the device end, the calculation expression is: ; in, It is the private key of the management end. It is the base point; Management end calculation sharing point : ; Device public key Sent publicly from the device to the management end, the calculation expression is: ; verify , and finally share the point or , the coordinates are or ; Session Key The expression is: .

[0025] Exemplarily, after the signature verification is passed, the management end obtains the registration status of the networked device; after the status is normal, the historical behavior data of the networked device is obtained, including the authentication success rate, response time, and data quality pass rate; Setting behavior weight parameters : Authentication success rate =0.4, response time =0.3, data quality =0.3; Setting behavior score parameters : Recent certification success rate = 0.95, response time compliance rate = 0.88, data quality pass rate =0.92; Setting time parameters :Online time =580, total observation time =600, in minutes; Set weight coefficient: Behavior weight coefficient =0.7, online time weight coefficient =0.3; Set the trust thresholds T1=0.9, T2=0.7; Expression to calculate trust score based on device behavior ,get =0.934; Based on permission level Calculate the expression: Get permission level ; Set the device private key d 1 =0x1234567890ABCDEF1234567890ABCDEF1234567890ABCDEF1234567890ABCDEF; Set the management private key d 2 =0x9876543210FEDCBA9876543210FEDCBA9876543210FEDCBA9876543210FEDCBA; Device public key Q 1 = d 1×G = (0x8A7B6C5D4E3F2A1B0C9D8E7F6A5B4C3D2E1F0A9B8C7D6E5F4A3B2C1D0E9F8A7, 0x3F2E1D0C9B8A7F6E5D4C3B2A1F0E9D8C7B6A5F4E3D2C1B0A9F8E7D6C5B4A3D2); Management end public key Q 2 = d 2 ×G = (0x2F1E0D3C4B5A6978291A0B1C2D3E4F5A6B7C8D9E0F1A2B3C4D5E6F7A8B9C0D1, 0x5E4D3C2B1A0F9E8D7C6B5A4938271615241322120F1E2D3C4B5A6978899AABBCC); Device-side computing sharing point = 0x1234...CDEF × (0x2F1E...0D1,0x5E4D...BCC) = (0x5C6D4E3F2A1B0C9D8E7F6A5B4C3D2E1F0A9B8C7D6E5F4A3B2C1D0E9F8A7B6C, 0x9A8B7C6D5E4F3A2B1C9D8E7F0A9B8C7D6E5F4A3B2C1D0E9F8A7B6C5D4E3F2A1); Management end calculation sharing point = 0x9876...DCBA × (0x8A7B...8A7,0x3F2E...3D2) = (0x5C6D4E3F2A1B0C9D8E7F6A5B4C3D2E1F0A9B8C7D6E5F4A3B2C1D0E9F8A7B6C, 0x9A8B7C6D5E4F3A2B1C9D8E7F0A9B8C7D6E5F4A3B2C1D0E9F8A7B6C5D4E3F2A1); The calculation results show that , so the final share point or , the coordinates are or ; =0x5C6D4E3F2A1B0C9D8E7F6A5B4C3D2E1F0A9B8C7D6E5F4A3B2C1D0E9F8A7B6C, =0x9A8B7C6D5E4F3A2B1C9D8E7F0A9B8C7D6E5F4A3B2C1D0E9F8A7B6C5D4E3F2A1; Calculate the session key =0x2D1E0F9A8B7C6543210FEDCBA9876543210FEDCBA9876543210FEDCBA98765432.

[0026] Further, the response time deviation, CPU usage deviation, and memory usage deviation of the networked device are obtained, and the response time deviation, CPU usage deviation, and memory usage deviation data are input into the behavior deviation score expression to obtain a total deviation score; the total deviation score is compared with the deviation threshold. If the total deviation score is greater than the deviation threshold, the trust score and the authority level are recalculated again, and the access rights are updated. The method for the management end to record this change includes: Based on the statistical analysis of the historical operation data of the equipment, the current observed value of the response time is obtained from the database 、Current observed value of CPU usage 、Current observed value of memory usage , historical average response time , CPU usage historical average , Historical average memory usage , response time standard deviation , CPU usage standard deviation , memory usage standard deviation ; The total deviation score is calculated by the expression of behavioral deviation score: ; in, is the current observation value, is the historical average, is the standard deviation, is the feature dimension; The total deviation score Deviation threshold If the total deviation score is less than the deviation threshold, the condition is met and the existing permission level is maintained. Otherwise, the trust score is recalculated. , the expression is: ; in, is the original trust score, is the attenuation factor, is the total deviation score, is the maximum permissible deviation; The change in the new trust score triggers a recalculation of the permission level PL to determine whether to maintain the original permission level or downgrade it, and updates the access rights. The management end records the change.

[0027] For example, based on the statistical analysis of the historical operation data of the equipment, the current observed value of the response time is obtained from the database. =120(ms), Current observed value of CPU usage =98(%), current observed value of memory usage =85(%), historical average response time =100(ms), historical average value of CPU usage =95(%), historical average memory usage =80(%), response time standard deviation =10, CPU usage standard deviation =5, memory usage standard deviation =8; feature dimension =3, =2.0; Calculated as the total deviation score = = 2.18; The calculation results show that > , set to be the attenuation factor =0.1, maximum allowable deviation 3, recalculate the trust score : ; The calculation results show that , so PL = L2, downgraded to intermediate level, the management end updates the access rights and records the change.

[0028] Embodiment 2: Based on the same inventive concept, Figure 2 As shown, this embodiment also provides a communication gateway device remote management system, the system comprising: The identity authentication module is used to register the networked devices for remote management, input the device public key, device serial number, and timestamp parameters into the secure hash function to generate the device unique identifier; input the random number and current timestamp into the secure hash function to generate the authentication challenge value, and the networked device signs the authentication challenge value with the device private key; the management end queries the corresponding device public key through the device unique identifier, uses the device public key to verify the signature to confirm the device identity, and authenticates the networked device; The secure communication module is used to obtain the registration status and historical behavior data of the networked device and input the expression for calculating the trust score of the device behavior to obtain the trust score; the permission level is obtained according to the permission management method and the trust score; the device side and the management side respectively calculate the same shared point, and input the coordinate value of the shared point into the secure hash function to generate a session key, so as to realize the encrypted communication and data storage and recording between the networked device and the management side; The permission control module obtains the response time deviation, CPU usage deviation, and memory usage deviation of the networked device, inputs the response time deviation, CPU usage deviation, and memory usage deviation data into the behavior deviation score expression to obtain the total deviation score; compares the total deviation score with the deviation threshold. If the total deviation score is greater than the deviation threshold, the trust score and permission level are recalculated, and the access rights are updated. The management end records this change.

[0029] It should be noted that, regarding the system in the above embodiment, the specific manner in which each module performs operations has been described in detail in the embodiment of the method, and will not be elaborated here.

[0030] Finally, it should be noted that: Although the present invention has been described in detail with reference to the aforementioned embodiments, it is still possible for those skilled in the art to modify the technical solutions described in the aforementioned embodiments, or to make equivalent substitutions for some of the technical features therein. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the protection scope of the present invention.

Claims

1. A remote management method for a communication gateway device, characterized in that: The method comprises: S1, register the networked device for remote management, input the device public key, device serial number, and timestamp parameters into the secure hash function to generate the device unique identifier; input the random number and current timestamp into the secure hash function to generate the authentication challenge value, and the networked device signs the authentication challenge value with the device private key; the management end queries the corresponding device public key through the device unique identifier, uses the device public key to verify the signature to confirm the device identity, and authenticates the networked device; S2, obtain the registration status and historical behavior data of the networked device and input the expression for calculating the trust score of the device behavior to obtain the trust score; obtain the permission level according to the permission management method and the trust score; the device side and the management side respectively calculate the same shared point, input the coordinate value of the shared point into the secure hash function to generate a session key, so as to realize the encrypted communication between the networked device and the management side and the data storage and recording work; S3, obtain the response time deviation, CPU usage deviation, and memory usage deviation of the networked device, input the response time deviation, CPU usage deviation, and memory usage deviation data into the behavior deviation score expression to obtain the total deviation score; compare the total deviation score with the deviation threshold. If the total deviation score is greater than the deviation threshold, recalculation of the trust score and permission level is retriggered, and the access rights are updated. The management end records this change.

2. A communication gateway device remote management method according to claim 1, characterized in that: The method of registering a remotely managed networked device and inputting a device-side public key, a device serial number, and a timestamp parameter into a secure hash function to generate a unique device identifier includes: Set the device unique identifier The expression is: in, is a secure hash function, is the public key of the device. is the device serial number, Is the timestamp.

3. A communication gateway device remote management method according to claim 2, characterized in that: The method of inputting a random number and a current timestamp into a secure hash function to generate an authentication challenge value, and the network access device signing the authentication challenge value with a device private key comprises: Set the authentication challenge value The expression is: ; in, is a secure hash function, is a random number, is the current timestamp; The networked device signs the authentication challenge value with the device private key: Calculate the elliptic curve point R: Among them, k is a random number generated and used once, G is the base point, which is a specific point pre-selected on the elliptic curve secp256k1. The base point G is a fixed coordinate and is a public parameter known to all participants; Calculate the first signature value : ; in, To find the remainder function, is the x-coordinate of the elliptic curve point R, is the order, defining the order of the elliptic curve base point G, that is, satisfying The smallest positive integer of ; Calculating the hash value : ; in, is a secure hash function, is the authentication challenge value; Calculate the second signature value : ; in, To find the remainder function, k is a generated random number, It is the device private key, which is stored locally and confidentially on the connected device and can only be held and used by the connected device; The final signature is: (r, s).

4. A communication gateway device remote management method according to claim 3, characterized in that: The management end queries the corresponding device end public key through the device unique identifier, and uses the device end public key to verify the signature to confirm the device identity. The method for authenticating the networked device includes: Calculate the hash auxiliary value and signature auxiliary value : ; ; in, To find the remainder function, is the hash value, is the second signature value, is the first signature value; Calculate reconstruction points : ; Among them, G is the base point, It is the public key of the device. Device public key The calculation expression is: ; in, It is the device-side private key. is the base point, representing the public identity of the device; Verify the signature of the networked device: Check Is it equal to ,in for The x-coordinate of the two nodes; if they are equal, the signature verification succeeds; if they are not equal, the signature verification fails and the user is not authorized to access the network for the session.

5. A communication gateway device remote management method according to claim 4, characterized in that: The registration status and historical behavior data of the networked device are obtained and the expression for calculating the trust score of the device behavior is input to obtain the trust score; Obtain permission levels based on permission management methods and trust scores; The device end and the management end respectively calculate the same shared point, input the coordinate value of the shared point into the secure hash function to generate a session key, so as to realize the encrypted communication and data storage and recording work between the networked device and the management end, including: After the signature verification is passed, the management end obtains the registration status of the networked device; after the status is normal, the historical behavior data of the networked device is obtained, including the authentication success rate, response time, and data quality data; The expression for calculating the trust score of device behavior is set as: ; Among them, TS is the trust score, is the weight of the i-th type of behavior, is the score of the i-th type of behavior, is the online time, is the total observation time, α is the behavior weight coefficient, β is the online time weight coefficient, and α + β = 1; Get permission levels based on permission management methods and trust scores , the calculation expression is: Among them, PL is the permission level, TS is the trust score, T1 and T2 are the trust thresholds, and L1, L2, and L3 are the corresponding permission levels; Device-side computing sharing point : ; in, It is the device-side private key. It is the public key of the management end; Management end public key Sent publicly from the management end to the device end, the calculation expression is: ; in, It is the management side private key. It is the base point; Management end calculation sharing point : ; Device public key Sent publicly from the device to the management end, the calculation expression is: ; verify , and finally share the point or , the coordinates are or ; Session Key The expression is: 。 6. A communication gateway device remote management method according to claim 5, characterized in that: The method of obtaining the response time deviation, CPU usage deviation, and memory usage deviation of the networked device, inputting the response time deviation, CPU usage deviation, and memory usage deviation data into the behavior deviation score expression to obtain a total deviation score; comparing the total deviation score with the deviation threshold, and if the total deviation score is greater than the deviation threshold, re-triggering the recalculation of the trust score and the permission level, and updating the access rights, and the management end recording this change includes: Based on the statistical analysis of the historical operation data of the equipment, the current observed value of the response time is obtained from the database , Current observed value of CPU usage 、Current observed value of memory usage , historical average response time , CPU usage historical average , Historical average memory usage , response time standard deviation , CPU usage standard deviation , memory usage standard deviation ; The total deviation score is calculated by the expression of behavioral deviation score: ; in, is the current observation value, is the historical average. is the standard deviation, is the feature dimension; The total deviation score Deviation threshold If the total deviation score is less than the deviation threshold, the condition is met and the existing permission level is maintained. Otherwise, the trust score is recalculated. , the expression is: ; in, is the original trust score, is the attenuation factor, is the total deviation score, is the maximum permissible deviation; The change in the new trust score triggers a recalculation of the permission level PL to determine whether to maintain the original permission level or downgrade it, and updates the access rights. The management end records the change.

7. A communication gateway device remote management system, characterized in that: The system comprises: The identity authentication module is used to register the networked devices for remote management, input the device public key, device serial number, and timestamp parameters into the secure hash function to generate the device unique identifier; input the random number and current timestamp into the secure hash function to generate the authentication challenge value, and the networked device signs the authentication challenge value with the device private key; the management end queries the corresponding device public key through the device unique identifier, uses the device public key to verify the signature to confirm the device identity, and authenticates the networked device; The secure communication module is used to obtain the registration status and historical behavior data of the networked device and input the expression for calculating the trust score of the device behavior to obtain the trust score; the permission level is obtained according to the permission management method and the trust score; the device side and the management side respectively calculate the same shared point, and input the coordinate value of the shared point into the secure hash function to generate a session key, so as to realize the encrypted communication and data storage and recording between the networked device and the management side; The permission control module obtains the response time deviation, CPU usage deviation, and memory usage deviation of the networked device, inputs the response time deviation, CPU usage deviation, and memory usage deviation data into the behavior deviation score expression to obtain the total deviation score; compares the total deviation score with the deviation threshold. If the total deviation score is greater than the deviation threshold, the trust score and permission level are recalculated, and the access rights are updated. The management end records this change.

Citation Information

Patent Citations

  • A base station connection method, a device, a network and a storage medium based on a block chain

    CN109041175A

  • Access management method and device for charging pile cloud platform

    CN115134158A

  • Method and system for verifying identity security of terminal equipment, terminal and storage medium

    CN116938595A

  • Novel electric power system trust evaluation method based on behavior deviation

    CN117155598A

  • 5G network information security authority authentication method and system based on asymmetric algorithm

    CN118714568A

Cited By

  • LoT equipment authentication method and Internet of Things agricultural system

    CN121966885A