An internet device access authentication method for network security

By establishing a baseline of device behavior and calculating deviation values ​​to assess risk, low-risk devices can be quickly screened, solving the problem of excessively long authentication time for temporary devices. This achieves a balance between security and efficiency and is suitable for scenarios with massive numbers of devices, such as the Internet of Things.

CN120200840BActive Publication Date: 2026-03-20JIANGSU YUEDA NETWORK TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-06
Publication Date
2026-03-20

AI Technical Summary

Technical Problem

In existing technologies, the high-security authentication methods used when temporary devices access enterprise networks result in excessively long verification times, impacting business efficiency and customer experience, especially during peak business periods.

Method used

By acquiring device type, historical access data, and traffic data, a baseline for device behavior is established. The deviation values ​​of access location, time, and traffic are calculated to generate a comprehensive risk value, which is used to quickly screen low-risk devices and determine the best access authentication method.

Benefits of technology

While ensuring network security, it significantly shortens device access authentication time and improves business processing efficiency, making it suitable for scenarios with a large number of devices, such as the Internet of Things.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200840B_ABST
    Figure CN120200840B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of device access authentication, and particularly discloses an internet device access authentication method for network security, which comprises the following steps: step S1: obtaining the type of a device to be accessed, associating historical access data of the device and historical traffic data of devices of the same type, and establishing a device behavior baseline; step S2: comparing the difference between the current access location and time of the device and a historical distribution map in combination with the geographical location of an enterprise, calculating an access location deviation value and an access time deviation value; based on the historical traffic fluctuation law of similar devices, the current traffic is evaluated for deviation from the expected value, and a traffic deviation value is generated; and step S3: comprehensively calculating a comprehensive risk value from the three deviation values, and matching an authentication strategy according to the risk level; the application balances safety and efficiency by quantifying behavior anomalies, and is suitable for massive device scenarios such as the Internet of Things.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of device access authentication, and particularly relates to an Internet device access authentication method for network security. BACKGROUND

[0002] In today's rapidly developing digital era, the business operations of enterprises are highly dependent on various information technologies and network systems. In the complex process of daily business execution, it is inevitable to involve the login of temporary devices. Temporary devices here cover a variety of types, such as mobile office devices used by employees due to temporary work needs, devices of partners temporarily accessing enterprise internal systems for specific projects, and other external devices used in some special business scenarios.

[0003] However, the access of these temporary devices often has great security risks. Since temporary devices come from a wide range of sources and are uncertain, their network environment may also be complex and may lack the basic security protection measures required by enterprise internal systems. For example, some temporary devices may not have the latest security patches installed, or their operating systems have known security vulnerabilities, which provides an opportunity for criminals to exploit these security weaknesses to invade enterprise networks, steal sensitive information, tamper with data, or launch malicious attacks, thereby posing a serious threat to the business operations and information security of enterprises.

[0004] In view of this, in order to protect the security of enterprise networks and data, a higher security access authentication method is usually required for temporary devices. These higher security access authentication methods often use multiple verification mechanisms, such as identity authentication combined with cryptography, multi-factor authentication (such as SMS verification code, hardware token, etc.), and trust evaluation of the device itself. Through these strict authentication means, the identity and legitimacy of temporary devices can be effectively identified and verified, preventing unauthorized devices from accessing enterprise networks, thereby reducing security risks to some extent.

[0005] However, this higher security access authentication method also brings some new problems in actual application, the most prominent of which is the longer verification time. This is because these complex authentication processes need to process and verify a large amount of information to ensure the security of the device. For example, in multi-factor authentication, the user may need to enter the username, password, then receive and enter the SMS verification code, and may also need to insert a hardware token for secondary verification, etc. This series of operations undoubtedly increases the time required for authentication.

[0006] The impact of this situation is particularly significant during peak business hours. As businesses grow and market demand increases, enterprises may face a large number of business requests during a certain period of time, and a large number of devices need to access the enterprise system to support the development of business. In this case, if each temporary device needs to undergo a long security access authentication, the accumulated time cost will be considerable. This not only leads to low efficiency of device access, causing delays in business processes, but also affects customer experience, and may even lead to the loss of some highly time-sensitive business opportunities. Therefore, how to improve the efficiency of access authentication while ensuring the security of temporary device access has become an important problem to be solved in the process of digital transformation of enterprises. SUMMARY

[0007] The purpose of the present application is to provide an Internet device access authentication method for network security, which solves the above technical problems.

[0008] The purpose of the present application can be achieved by the following technical solutions:

[0009] An Internet device access authentication method for network security, comprising the following steps:

[0010] Step S1: Obtain the current device type of the current device, and obtain the historical device access data and historical access traffic data of the current device type;

[0011] Step S2: Obtain the enterprise location, and obtain the access location and access time of the current device; according to the historical device access data and enterprise location, obtain the access location distribution map and access time distribution curve of all historical devices, and according to the access location and access time, obtain the access location deviation value and access time deviation value of the current device; and according to the historical access traffic data, obtain the traffic deviation value of the current device type;

[0012] Step S3: According to the access location deviation value, access time deviation value and traffic deviation value of the current device, obtain the risk value of the current device; according to the risk value, determine the best access authentication method of the current device, and perform access authentication on the current device through the best access authentication method.

[0013] As a further scheme of the present application: obtaining a device type of a current device, denoted as a current device type, the device type including a desktop computer, a notebook computer, a mobile phone, and a router; the historical device access data including historical access locations and historical access times of all historical devices, the access location being a location coordinate when a device applies for access, the historical access time being an access time of the historical device, the access time being a time when the device applies for access; the historical access traffic data being traffic data of all device types of the historical devices within a preset monitoring time period.

[0014] As a further scheme of the present application: the setting process of the monitoring time period includes:

[0015] obtaining an access time t of a device and obtaining a disconnection time t' of the device, the disconnection time being a time when the device disconnects access; setting a time length threshold T, selecting a monitoring starting time t-T according to the access time and the time length threshold, and then obtaining a monitoring time period [t-T, t'].

[0016] As a further scheme of the present application: the obtaining process of the traffic data includes:

[0017] selecting a plurality of time nodes at equal intervals within the monitoring time period, obtaining a traffic transmission rate of the server at each time node, and denoting the traffic transmission rate at each time node as traffic data.

[0018] As a further scheme of the present application: the obtaining process of the access location distribution map includes:

[0019] obtaining distances between each historical access location and the enterprise location, selecting a maximum value of the distances, and obtaining a circular distribution range with the maximum value of the distances as a radius and the enterprise location as a center; denoting each historical access location as a point in the distribution range to obtain an access location distribution map.

[0020] As a further scheme of the present application: the obtaining process of the access location deviation value of the current device includes:

[0021] performing rectangular grid division on the access location distribution map to obtain a plurality of rectangular grids, obtaining a total number of points in each rectangular grid, obtaining eight rectangular grids adjacent to the rectangular grid, denoted as adjacent grids, and obtaining a total number of points in each adjacent grid; obtaining a density value of the rectangular grid , wherein N0 represents the total number of points in the rectangular grid, Ni represents the total number of points in the i-th adjacent grid, and T represents the time length threshold. i

[0022] ​Obtain the dense values of each rectangular grid, select the rectangular grid with the highest dense value as the center rectangular grid, obtain the center point of the center rectangular grid as the distribution center of the access site distribution map; obtain the distance between the access site of the current device and the distribution center as the access site deviation value.

[0023] As a further scheme of the present application, the obtaining process of the access time distribution curve comprises:

[0024] Divide 24 hours of a day into several time periods, number each time period, obtain the total number of access times in each time period; establish a coordinate system with the number of the time period as the horizontal coordinate and the number of the access times as the vertical coordinate; convert each numbered time period and the total number of access times in the time period into the coordinate point of the corresponding position in the coordinate system, connect each coordinate point with a smooth curve to obtain the access time distribution curve.

[0025] As a further scheme of the present application, the obtaining process of the access time deviation value of the current device comprises:

[0026] Obtain all the maximum value points on the access time distribution curve, and obtain the vertical coordinate value corresponding to each maximum value point as the maximum value; sort each maximum value from small to large, and set the peak value coefficient in turn, the peak value coefficient of the first maximum value after sorting is 1, the peak value coefficient of the first maximum value after sorting is 2, and so on.

[0027] Convert the access time into a point on the coordinate system as the current point; obtain the maximum value point closest to the current point as the nearest point, and obtain the access time deviation value Dt=Pf|P-P´| according to the peak value coefficient of the nearest point, wherein Pf represents the peak value coefficient of the nearest point, and |P-P´| represents the distance between the nearest point P' and the current point P.

[0028] The present application has the following advantages:

[0029] 1. The present application establishes a device behavior baseline by combining device type, historical access data and traffic data, and calculates access site deviation value, access time deviation value and traffic deviation value to comprehensively evaluate the risk level of the device. This method can quickly screen out low-risk devices and reduce strict verification of high-risk devices, significantly shortening the overall access authentication time. During the peak period of enterprise business, a large number of temporary devices need to access the network quickly to support business operation. Through the method of the present application, business delay caused by long verification time can be effectively reduced, and the overall business processing efficiency can be improved.

[0030] 2、The application generates multiple deviation values by comparing the differences between the current access location and time of the device and the historical distribution map, and evaluating the deviation of the current traffic based on the historical traffic fluctuation rules of similar devices, which collectively constitute the comprehensive risk value of the device, providing a basis for subsequent access authentication strategies. Through multiple verification mechanisms (such as identity authentication, multi-factor authentication, device trust evaluation, etc.), the identity and legitimacy of temporary devices can be effectively identified and verified, preventing unauthorized devices from accessing enterprise networks, thereby reducing security risks to a certain extent.

[0031] 3、The application is not only suitable for temporary device access authentication, but also can be applied to various types of Internet devices, including desktop computers, laptops, mobile phones and routers, etc. By flexibly adjusting the monitoring time period and the acquisition method of traffic data, it can adapt to the needs of different devices and different application scenarios. Due to the use of quantitative behavior anomaly method, it is particularly suitable for massive device scenarios such as Internet of Things, and can efficiently manage and authenticate the access of a large number of devices.

[0032] In summary, the application has the advantages of balancing security and efficiency through quantitative behavior anomaly, and is suitable for massive device scenarios such as Internet of Things. Specifically, this Internet device access authentication method not only ensures network security, but also improves the efficiency of device access, solving the problem of long verification time caused by traditional high-security access authentication methods. BRIEF DESCRIPTION OF DRAWINGS

[0033] The application will be further described below with reference to the accompanying drawings.

[0034] Figure 1 is a flowchart of an Internet device access authentication method for network security according to the application. DETAILED DESCRIPTION

[0035] The technical solutions in the embodiments of the application will be described clearly and completely below with reference to the accompanying drawings in the embodiments of the application. Obviously, the described embodiments are only part of the embodiments of the application, not all. Based on the embodiments in the application, all other embodiments obtained by those skilled in the art without creative labor are within the scope of protection of the application.

[0036] Please refer to Figure 1 The application is an Internet device access authentication method for network security, which includes the following steps:

[0037] Step S1: obtaining a device type of a current device, denoted as a current device type, and obtaining historical device access data of the current device type, the historical device access data including historical access locations and historical access times of all historical devices; and obtaining historical access traffic data, the historical access traffic data being traffic data of all devices of the device type in a preset monitoring time period;

[0038] As a preferred embodiment of the present application, the device type includes desktop computers, notebook computers, mobile phones and routers, the historical access location is an access location of the historical device, the access location is a location coordinate when the device applies for access, the historical access time is an access time of the historical device, and the access time is a time when the device applies for access.

[0039] As a preferred embodiment of the present application, the setting process of the monitoring time period includes:

[0040] obtaining an access time t of the device and a disconnection time t' of the device, the disconnection time being a time when the device disconnects access; setting a time length threshold T, selecting a monitoring starting time t-T according to the access time and the time length threshold, and then obtaining a monitoring time period [t-T, t'];

[0041] As a preferred embodiment of the present application, the obtaining process of the traffic data includes:

[0042] selecting a plurality of time nodes at equal intervals in the monitoring time period, obtaining a traffic transmission rate of the server at each time node, and denoting the traffic transmission rate at each time node as traffic data;

[0043] It should be noted that the access time does not include a date, but only a time of day within 24 hours;

[0044] It should be noted that, based on historical behavior modeling, a baseline mode of device access is established by collecting two types of key data; a normal behavior model of the device type (such as a certain type of sensor usually accesses from a fixed position at 8:00-18:00) is constructed through the historical access location and time of the same type of device; and the traffic change generated after the device access of different device types (such as the number of requests per second and bandwidth occupancy) is used to detect abnormal behavior through the historical traffic data of all devices;

[0045] Step S2: obtaining a location coordinate of an enterprise, denoted as an enterprise location, and obtaining an access location and an access time of the current device; obtaining an access location distribution diagram of all historical devices according to the historical device access data and the enterprise location; and obtaining an access location deviation value of the current device according to the access location distribution diagram and the access location.

[0046] According to the historical device access data, an access time distribution curve of all historical devices is obtained, and an access time deviation value of the current device is obtained according to the access time distribution curve and an access time; according to the historical access traffic data, a traffic deviation value of the current device type is obtained;

[0047] As a preferred embodiment of the present application, the access site distribution map obtaining process comprises:

[0048] The distance between each historical access site and the enterprise site is obtained, the maximum distance is selected, and a circular distribution range is obtained with the maximum distance as a radius and the enterprise site as a center; each historical access site is recorded as a point in the distribution range to obtain an access site distribution map;

[0049] As a preferred embodiment of the present application, the access site deviation value of the current device comprises:

[0050] The access site distribution map is divided into a plurality of rectangular grids, the total number of points in each rectangular grid is obtained, and eight rectangular grids adjacent to the rectangular grid are obtained, which are recorded as adjacent grids, and the total number of points in each adjacent grid is obtained; the density value of the rectangular grid is obtained , wherein N0 represents the total number of points in the rectangular grid, N i represents the total number of points in the i-th adjacent grid.

[0051] The density value of each rectangular grid is obtained, the rectangular grid with the highest density value is selected and recorded as a center rectangular grid, the center point of the center rectangular grid is obtained and recorded as the distribution center of the access site distribution map, and the distance between the access site of the current device and the distribution center is obtained and recorded as an access site deviation value.

[0052] It can be understood that the access positions (such as GPS coordinates, IP geographical library) of all historical devices are counted to form a heat map or a clustering model (such as DBSCAN), and the difference (such as Euclidean distance, whether outside the historical aggregation area) between the access position of the current device and the historical distribution is calculated.

[0053] As a preferred embodiment of the present application, the access time distribution curve comprises:

[0054] The 24 hours of a day are divided into a plurality of time periods, each time period is numbered, and the total number of access times in each time period is obtained; a coordinate system is established with the number of the time period as the abscissa and the number of the access times as the ordinate; each numbered time period and the total number of access times in the time period are converted into coordinate points at corresponding positions in the coordinate system, a smooth curve is connected between the coordinate points, and an access time distribution curve is obtained.

[0055] As a preferred embodiment of the present application, the access time deviation value of the current device is obtained by:

[0056] All maximum points on the access time distribution curve are obtained, and the corresponding ordinate values of each maximum point are obtained, denoted as maximum values. Each maximum value is sorted from small to large, and a peak value coefficient is set in turn. The peak value coefficient of the first maximum value after sorting is 1, the peak value coefficient of the first maximum value after sorting is 2, and so on.

[0057] The access time is converted into a point in the coordinate system, denoted as the current point. The maximum point closest to the current point is obtained, denoted as the nearest point, and the access time deviation value Dt=Pf|P-P´| is obtained according to the peak value coefficient of the nearest point, wherein Pf represents the peak value coefficient of the nearest point, and |P-P´| represents the distance between the nearest point P´ and the current point P.

[0058] It can be understood that the access time regularity of historical devices (such as concentrated login from 9:00 to 18:00) is counted, a time probability model (such as Gaussian distribution) is established, and it is judged whether the current access time is outside the common interval (such as login at 3:00 in the morning);

[0059] As a preferred embodiment of the present application, the traffic deviation value of the current device type is obtained by:

[0060] The standard deviation s of all traffic transmission rates in the traffic data of the historical devices of each device type is obtained, and the average value Ave of all traffic transmission rates is obtained, to obtain the coefficient of variation Cv=s / Ave of the traffic data of the historical devices of each device type. The average value of all coefficients of variation is obtained, denoted as the average coefficient of variation, and the coefficient of variation of the current device type is obtained, denoted as the current coefficient of variation. The difference between the current coefficient of variation and the average coefficient of variation is obtained, denoted as the traffic deviation value.

[0061] It can be understood that the real-time traffic (such as request frequency) of the current device type is compared with the historical baseline (mean value ± standard deviation of the same type of device traffic).

[0062] It should be noted that by multi-dimensional deviation detection, it is evaluated whether the behavior of the current device deviates from the historical normal mode, the device behavior is abstracted into a numerical index (such as location deviation value=3.2, time deviation value=1.5), and input is provided for subsequent comprehensive risk assessment. For example: low deviation value (such as normal location / time / traffic) represents rapid authentication (saving resources), and high deviation value (such as remote location+late night+traffic surge) represents enhanced verification or blocking (preventing attacks).

[0063] Step S3: obtaining a risk value of the current device according to the access location deviation value, the access time deviation value and the traffic deviation value of the current device; setting a plurality of risk threshold values, setting a plurality of access authentication methods according to the risk threshold values, and determining the optimal access authentication method of the current device according to the risk value of the current device, and performing access authentication on the current device through the optimal access authentication method;

[0064] As a preferred embodiment of the present application, the risk value Rv of the current device is w1Dp+w2Dt+w3DI, wherein w1, w2 and w3 are weight coefficients;

[0065] It should be noted that the weight coefficients are adjusted according to business needs (e.g., w1 is higher when enterprises pay more attention to geographic security), and the model is trained using historical attack data (e.g., SIEM logs) to optimize the weight coefficients;

[0066] As a preferred embodiment of the present application, a risk range is obtained from two adjacent risk threshold values, and access authentication methods with different security strengths are obtained, and each risk range corresponds to an access authentication method;

[0067] It can be understood that the preset risk threshold values (e.g., low risk: 0-30, medium risk: 30-70, and high risk: 70-100) are discretized to match different authentication strengths;

[0068] As a preferred embodiment of the present application, the determination process of the optimal access authentication method includes:

[0069] Obtaining the risk range in which the risk value of the current device is located, obtaining the access authentication method corresponding to the risk range, and recording it as the optimal access authentication method.

[0070] The above describes one embodiment of the present application in detail, but the content is only a preferred embodiment of the present application and cannot be considered as limiting the scope of the present application. Any equivalent changes and improvements made within the scope of the present application should still belong to the scope of the present application.

Claims

1. A method for authenticating internet device access for network security, characterized in that, Includes the following steps: Step S1: Obtain the current device type of the current device, and obtain the historical device access data and historical access traffic data of the current device type; Step S2: Obtain the enterprise location, and obtain the access location and access time of the current device; based on the historical device access data and enterprise location, obtain the access location distribution map and access time distribution curve of all historical devices, and based on the access location and access time, obtain the access location deviation value and access time deviation value of the current device; And based on the historical access traffic data, obtain the traffic deviation value for the current device type; Step S3: Obtain the risk value of the current device based on the current device's access location deviation value, access time deviation value, and traffic deviation value; Based on the risk value, determine the optimal access authentication method for the current device, and perform access authentication for the current device using the optimal access authentication method; The process of obtaining the current device's access location deviation value includes: The access point distribution map is divided into rectangular grids to obtain several rectangular cells. The total number of points in each rectangular cell is obtained, and the eight adjacent rectangular cells are also obtained and recorded as adjacent cells. The total number of points in each adjacent cell is obtained. The density value of the rectangular cells is then obtained. Where N0 represents the total number of points within the rectangular grid, N i This represents the total number of points within the i-th adjacent cell; Obtain the density value of each rectangular grid, select the rectangular grid with the highest density value and record it as the central rectangular grid, obtain the center point of the central rectangular grid and record it as the distribution center of the access location distribution map; obtain the distance between the current device's access location and the distribution center and record it as the access location deviation value.

2. The Internet device access authentication method for network security according to claim 1, characterized in that, In step S1, the device type of the current device is obtained and denoted as the current device type. The device type includes desktop computers, laptops, mobile phones, and routers. The historical device access data includes the historical access locations and historical access times of all historical devices. The access location is the location coordinates when the device applied for access, and the historical access time is the access time of the historical device. The historical access traffic data is the traffic data of historical devices of all device types within a preset monitoring time period.

3. The Internet device access authentication method for network security according to claim 2, characterized in that, In step S1, the process of setting the monitoring time period includes: Obtain the device's access time t and the device's disconnection time t´, where the disconnection time is the time the device disconnects from the access point; set a duration threshold T, and select a monitoring start time tT based on the access time and duration threshold to obtain the monitoring time period [tT, t´].

4. The Internet device access authentication method for network security according to claim 2, characterized in that, In step S1, the process of acquiring the traffic data includes: Within the monitoring period, select several time nodes at equal intervals, obtain the server's traffic transmission rate at each time node, and record the traffic transmission rate at each time node as traffic data.

5. The Internet device access authentication method for network security according to claim 2, characterized in that, In step S2, the process of obtaining the access location distribution map includes: Obtain the distance between each historical access location and the enterprise location, select the maximum distance, and use the maximum distance as the radius and the enterprise location as the center to obtain a circular distribution range; record each historical access location as a point within the distribution range to obtain an access location distribution map.

6. The Internet device access authentication method for network security according to claim 2, characterized in that, In step S2, the process of obtaining the access time distribution curve includes: Divide a day's 24 hours into several time periods, number each time period, and obtain the total number of access times within each time period. Establish a coordinate system with the time period number as the horizontal axis and the number of access times as the vertical axis. Convert each numbered time period and the total number of access times within each time period into coordinate points corresponding to the positions in the coordinate system. Connect each coordinate point with a smooth curve to obtain the access time distribution curve.

7. The Internet device access authentication method for network security according to claim 6, characterized in that, In step S2, the process of obtaining the access time deviation value of the current device includes: Obtain all the maximum points on the access time distribution curve and obtain the vertical coordinate value corresponding to each maximum point, which is recorded as the maximum value; sort the maximum values ​​from smallest to largest and set the peak coefficients in turn, setting the peak coefficient of the first maximum value after sorting to 1, the peak coefficient of the first maximum value after sorting to 2, and so on. The access time is converted into a point on the coordinate system and denoted as the current point; the nearest maximum point to the current point is obtained and denoted as the nearest point, and the access time deviation value Dt=Pf|PP´| is obtained according to the peak coefficient of the nearest point, where Pf represents the peak coefficient of the nearest point and |PP´| represents the distance between the nearest point P´ and the current point P.

Citation Information

Patent Citations

  • Internet of Things anomaly positioning method and device and electronic equipment

    CN112350836A

  • Power network security protection method based on zero trust

    CN115189927A

  • Account-free user unification method and system of construction and management system based on multimode authentication

    CN119357939A