Internet of Things terminal equipment distributed authentication method for smart city

By adopting distributed authentication methods in the IoT terminal devices in smart cities, using technologies such as chaotic mapping algorithms, machine learning, blockchain and quantum heuristic encryption, the traditional centralized authentication method is solved in the performance bottlenecks and insufficient security when handling massive requests, and an efficient, secure and flexible authentication system is achieved.

CN120200841AActive Publication Date: 2025-06-24牟璐

Patent Information

Application Number
CN202510571689.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-06
Publication Date
2025-06-24
Estimated Expiration
2045-05-06

AI Technical Summary

Technical Problem

The traditional centralized authentication method has serious performance bottlenecks when handling massive authentication requests, which is difficult to meet the real-time requirements of smart cities. At the same time, there are problems such as redundant authentication information, difficulty in retrieval, weak attack resistance, and waste of computing resources.

Method used

The distributed authentication method for IoT terminal devices for smart cities is adopted, and the key is generated through chaotic mapping algorithms, combined with machine learning and blockchain technology to verify and store authentication information, and used distributed federated learning and zero-knowledge proof technology to perform authentication and calculations, and improved authentication efficiency and security through fuzzy logic, reinforcement learning and quantum heuristic encryption algorithms.

Benefits of technology

It significantly improves the processing speed of authentication requests, reduces authentication delays, improves authentication security, enhances the flexibility and adaptability of the system, and can quickly respond to the certification needs of massive terminal devices, and meets the requirements of smart cities for real-time.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120200841A_ABST
    Figure CN120200841A_ABST
Patent Text Reader

Abstract

The invention discloses an Internet of Things terminal equipment distributed authentication method for a smart city, and relates to the technical field of equipment authentication. The method comprises the following steps of: initializing to build a distributed authentication network containing different function clusters, determining an information distribution rule according to multi-dimensional attributes of equipment, and generating parameters and keys by using a chaotic mapping algorithm; the equipment provides multi-feature information during registration, and machine learning and block chain verification storage are used; the authentication request is transmitted in a self-adaptive multi-path and multi-mode encryption mode, and an authentication node is selected through fuzzy logic; distributed federated learning and zero knowledge proof are used for calculation, and node weighted voting judgment is coordinated; and the result is encrypted and fed back and the equipment trust value is dynamically adjusted. According to the invention, multiple technologies are adopted to guarantee safety and defend attacks; the method has high flexibility and adaptability, can intelligently adjust along with changes of the equipment and the network, realizes distributed learning and intelligent contract optimization model, automatically executes rules, and provides powerful support for authentication of the Internet of Things equipment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of device authentication, and particularly to a distributed authentication method for Internet of Things (IoT) terminal devices for smart cities. Background Art

[0002] With the continuous advancement of smart city construction, the number of IoT terminal devices has increased explosively, covering multiple fields such as transportation, energy, security, and environmental protection. These devices are interconnected through networks to achieve data collection, transmission, and sharing, providing support for the intelligent management of the city. However, the access of a large number of terminal devices poses a huge challenge to device authentication. The traditional centralized authentication method relies on a single authentication center, which is prone to performance bottlenecks, low authentication efficiency, and difficulty in meeting the real-time requirements of smart cities when processing a large number of authentication requests. At the same time, once the authentication center is attacked or fails, the entire authentication system will be paralyzed, seriously affecting the normal operation of the smart city.

[0003] In the existing research and application of distributed authentication, there are many deficiencies. Some methods lack flexibility and efficiency in the storage and management of authentication information, and cannot be reasonably allocated according to the diverse attributes of terminal devices, resulting in redundant authentication information or difficult retrieval. During the authentication process, the means of verifying device identities are relatively single, mainly relying on traditional methods such as device identifiers and passwords, and it is difficult to resist increasingly complex attack means, such as forging device identities and stealing authentication keys, and cannot effectively guarantee the authenticity and legality of device identities. In addition, the cooperation and consensus mechanism between authentication nodes is not perfect, and there are problems such as waste of computing resources and large communication overhead when processing authentication requests, resulting in low authentication efficiency and difficulty in adapting to the dynamically changing network environment of smart cities.

[0004] In terms of authentication security, the existing distributed authentication methods face severe challenges. With the continuous upgrading of network attack technologies, attackers may obtain authentication information through means such as network eavesdropping and man-in-the-middle attacks, tamper with authentication results, and threaten the security of IoT terminal devices. At the same time, for abnormal situations that occur during the authentication process, such as abnormal operation behaviors of devices and mutations of authentication parameters, the existing methods lack effective detection and response mechanisms, cannot detect and handle potential security risks in a timely manner, and are difficult to ensure the safe and reliable operation of IoT terminal devices in smart cities. There is an urgent need for a more efficient, secure, and flexible distributed authentication method. Summary of the Invention

[0005] The present invention proposes a distributed authentication method for IoT terminal devices for smart cities to solve the problems mentioned in the above prior art.

[0006] In order to achieve the above object, the present invention adopts the following technical solution: a distributed authentication method for IoT terminal devices for smart cities, comprising:

[0007] Initialization phase: Build a distributed authentication network, use the chaotic mapping algorithm to generate the system's public parameters and key pairs, and use the formula Generate subkey SK i , where K master Master key, ID i is the identifier of the i-th authentication node, It is a random sequence generated based on chaotic mapping, and H is a hash function;

[0008] Terminal device registration phase: When a terminal device sends a registration request, it includes the device's identification information and public key, and also needs to provide the device's behavior pattern characteristics. The authentication network uses a machine learning algorithm to verify the registration information and build a verification model based on feature fusion. At the same time, it uses distributed ledger technology to store the registration information in a distributed manner. If the verification is successful, the authentication node passes the formula Calculate the initial trust value Trust of the device device , where info j is the different characteristic information of the device, w j is the weight of the corresponding feature, f j is the feature evaluation function;

[0009] Authentication request stage: The terminal device uses adaptive transmission and encryption methods to send authentication requests, dynamically selects the optimal transmission path according to the real-time network status, and encrypts the request by combining symmetric encryption and asymmetric encryption algorithms;

[0010] C trans =E pub (E sym (M req )) Authentication request message M req Encryption, where E sym is a symmetric encryption algorithm, E pub It is an asymmetric encryption algorithm that uses the public key of the authentication network. After receiving the request, the authentication network determines the set of authentication nodes participating in the authentication based on the fuzzy logic algorithm, taking into account the node load, credibility, and relevance to the terminal device.

[0011] Authentication calculation phase: The authentication nodes participating in the authentication adopt a distributed federated learning algorithm for authentication calculation, jointly improving the accuracy of the authentication model without sharing the original data; at the same time, zero-knowledge proof technology is introduced to enable the authentication nodes to complete the authentication calculation without disclosing sensitive information; each authentication node sends the calculation result to the coordination node, and the coordination node makes a comprehensive judgment through a weighted voting algorithm, and the voting weight is dynamically adjusted according to the historical authentication accuracy and computing power factors of the node, through the formula

[0012] Vote weight =α·Accuracy history +β·Computation ability calculate the voting weight, where α and β are weight coefficients, and α + β = 1.

[0013] Furthermore, it also includes:

[0014] Authentication result feedback phase: The coordination node uses a combination of encrypted broadcast and directional feedback to feedback the authentication result to the terminal device and related application systems. Through the formula C result =E priv (M result ||σ result ) encrypt the authentication result message M result

[0015] , where σ result is the digital signature of the result, and E priv is the encryption algorithm using the private key of the coordination node; at the same time, the authentication network dynamically adjusts the trust value of the terminal device according to the authentication result, through the formula

[0016] ΔTrust device =k·(1 - Trust device )·Result flag update the trust value, where k is the adjustment coefficient and Result flag is the authentication result identifier;

[0017] Authentication information update mechanism: When some information of the terminal device changes, the terminal device sends an update request, and the request contains the feature vector of the changed information; the authentication network uses the autoencoder model in deep learning to extract features and detect anomalies of the changed information. During the update process, through the improved formula

[0018] regenerate the updated sub-key where is the updated authentication node identifier, is the new chaotic random sequence, and Δinfo is the feature vector of the information change.

[0019] Anomaly detection mechanism: During the authentication process, the authentication node monitors the time series parameters and spatial distribution parameters in real time, and adopts an anomaly detection model based on the Generative Adversarial Network (GAN). Through the adversarial training of the generator and discriminator, the ability to identify abnormal patterns is improved; through the formula Calculate the change amount ΔP of multi-dimensional parameters multi-dim , where P current,j is the parameter value of the current j-th dimension, P average,j is the historical average value of the parameter of this dimension, and σ j is the standard deviation of the parameter of this dimension; when ΔP multi-dim is greater than the threshold T multi-dim , the anomaly handling process is triggered.

[0020] Furthermore, in the initialization stage, the selection of authentication nodes adopts a distributed election algorithm based on reinforcement learning. The algorithm takes the computing power, storage capacity, network bandwidth, and energy consumption factors of the nodes as the state space, and the selection actions of the nodes as the action space. The reward function guides the algorithm to select the optimal set of authentication nodes; the reward function is calculated through the formula

[0021] R node = γ1·C i + γ2·S i + γ3·B i - γ4·E i Calculate,

[0022] where C i is the computing power of the node, S i is the storage capacity of the node, B i is the network bandwidth of the node, E i is the energy consumption of the node, γ1, γ2, γ3, γ4 are the corresponding weight coefficients, and γ1 + γ2 + γ3 + γ4 = 1.

[0023] Furthermore, in the authentication request stage, the terminal device sends the authentication request using an adaptive transmission and encryption method; the terminal device monitors the network topology structure and traffic status in real time, and uses the ant colony algorithm to dynamically plan the optimal transmission path; at the same time, it combines a quantum-inspired encryption algorithm to encrypt the authentication request, simulating some characteristics of quantum encryption in the classical computing environment. The authentication request message M trans = E pub-quantum (E sym-quantum (M req )) is used to encrypt the authentication request message M req , where E sym-quantum is a quantum-inspired symmetric encryption algorithm, and E pub-quantum is a quantum-inspired asymmetric encryption algorithm.

[0024] Further, in the authentication calculation stage, a blockchain-based distributed consensus algorithm is adopted among authentication nodes to verify the consistency of calculation results; each authentication node packages the calculation results into blocks and reaches a consensus through a hybrid consensus mechanism that combines the proof of work (PoW) and the proof of stake (PoS); meanwhile, contract technology is used to automatically supervise and manage the authentication calculation process.

[0025] Further, in the authentication result feedback stage, the coordination node feeds back the authentication results to the terminal device and relevant application systems by combining encrypted broadcast and directed feedback; the coordination node dynamically adjusts the encryption method and transmission strategy according to the security levels and communication requirements of the terminal device and the application system; the encryption level E of the feedback is calculated through the formula where s level is a relevant factor of the security level and communication requirements, and ω k is the weight of the corresponding factor. k

[0026] Further, it also includes:

[0027] The dynamic management mechanism of authentication nodes: when a node in the authentication network fails or its performance degrades, a node replacement strategy based on fuzzy clustering and genetic algorithms is adopted; first, the nodes are classified into different categories through the fuzzy clustering algorithm, and then the genetic algorithm is used to select the optimal replacement node in each category; the fitness Fitness of the node is calculated through the formula Fitness node = δ1·Health i + δ2·Compatibility i where Health node is the health status of the node, Compatibility i is the compatibility of the node with the current authentication network, δ1 and δ2 are weight coefficients, and δ1 + δ2 = 1. i

[0028] Further, in the terminal device registration stage, the identity of the terminal device is authenticated. In addition to the device identifier, public key, geographical location, and usage time, the hardware fingerprint and software version factors of the device are also considered; the authentication score Auth of the terminal device is calculated through the formula where info score is the different characteristic information of the device, η l is the weight of the corresponding characteristic, f l is the characteristic evaluation function, and l

[0029] ​​​Furthermore, during the authentication process, a technology combining blockchain and edge computing is adopted to store and manage authentication information; some authentication computing tasks are offloaded to edge nodes for processing; meanwhile, the smart contract of blockchain is utilized to achieve the automated execution and dynamic adjustment of authentication rules, and the authentication strategy is optimized in real time according to the usage conditions of terminal devices and the network environment.

[0030] Compared with the existing technologies, the beneficial effects of the present invention are as follows:

[0031] In terms of authentication efficiency, by constructing an authentication node cluster with diverse functions, combining adaptive multi-path transmission and edge computing technologies, the processing speed of authentication requests is greatly improved, the authentication delay is reduced, and the authentication needs of a large number of terminal devices can be quickly responded to, meeting the strict requirements of smart cities for real-time performance.

[0032] In terms of authentication security, a variety of innovative technologies are adopted to ensure the security and reliability of the authentication process. The chaotic mapping algorithm generates keys, the quantum-inspired encryption algorithm, the zero-knowledge proof technology, and the application of blockchain effectively prevent the leakage and tampering of authentication information, resist various network attacks, and ensure the authenticity of device identities and the credibility of authentication results. The multi-factor authentication and anomaly detection mechanism can detect abnormal behaviors in a timely manner, further enhancing the security of the system.

[0033] In terms of authentication flexibility and adaptability, based on the authentication information distribution rule of device multi-dimensional attributes, the dynamic authentication node management mechanism, and the application of algorithms such as fuzzy logic and reinforcement learning, the authentication system can be intelligently adjusted according to device characteristics, network environment, and security requirements. Whether facing device information changes or complex and changeable network conditions, it can maintain good authentication performance. In addition, the use of distributed federated learning and smart contracts realizes the continuous optimization of the authentication model and the automated execution of authentication rules, improving the intelligent level and overall efficiency of the authentication system, and providing a strong guarantee for the secure authentication of Internet of Things terminal devices in smart cities. BRIEF DESCRIPTION OF THE DRAWINGS

[0034] Figure 1 It is a schematic block diagram of the distributed authentication method for Internet of Things terminal devices for smart cities proposed by the present invention;

[0035] Figure 2 It is a schematic diagram of the comparison of the authentication efficiency of Internet of Things terminal devices for smart cities proposed by the present invention under different authentication methods in multiple scenarios;

[0036] Figure 3 It is a schematic diagram of the authentication efficiency trend of the distributed authentication method for Internet of Things terminal devices for smart cities proposed by the present invention under different network loads. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0037] Next, in combination with the accompanying drawings in the embodiments of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present invention.

[0038] In the description of the present invention, it should be understood that the terms "center", "longitudinal", "transverse", "length", "width", "thickness", "upper", "lower", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", "clockwise", "counterclockwise", etc. indicate the orientation or positional relationship based on the orientation or positional relationship shown in the accompanying drawings. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as a limitation to the present invention.

[0039] In addition, the terms "first" and "second" are only used for descriptive purposes and should not be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of the described features. In the description of the present invention, "a plurality of" means two or more unless otherwise specifically defined. In addition, the terms "installation", "connection", and "connection" should be understood in a broad sense. For example, it may be a fixed connection, a detachable connection, or an integral connection; it may be a mechanical connection or an electrical connection; it may be directly connected or indirectly connected through an intermediate medium, and it may be the communication inside two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations. The present invention will be further described in detail below with reference to the accompanying drawings.

[0040] Refer to Figure 1 and Figure 3 : A specific implementation method of a distributed authentication method for Internet of Things terminal devices for smart cities

[0041] I. Initialization stage

[0042] First, a distributed authentication network needs to be built. This network consists of multiple authentication node clusters with different functional focuses, namely a storage cluster, a computing cluster, and a communication cluster. The storage cluster is responsible for storing authentication information securely and efficiently; the computing cluster focuses on complex computing tasks during the authentication process; the communication cluster ensures the fast and stable transmission of authentication information in the network.

[0043] Determine the distribution rule of authentication information based on the multi-dimensional attributes of the terminal device. These multi-dimensional attributes cover device function types (such as sensors, actuators, etc.), usage frequency (high, medium, low), and security level requirements (ordinary, important, core), etc. By comprehensively considering these attributes, the authentication information can be more reasonably allocated, improving the authentication efficiency and security.

[0044] Use the chaotic mapping algorithm to generate the public parameters and key pairs of the system. The chaotic mapping has high randomness and unpredictability, which can effectively enhance the security of the key. Specifically, through the formula Generate the sub-key SK i . Where, K master is the master key, ID i is the unique identifier of the i-th authentication node, is a random sequence generated based on the chaotic mapping, and H is a hash function. In actual operation, the parameters of the chaotic mapping need to be finely adjusted to ensure that the generated random sequence has sufficient randomness and unpredictability. At the same time, strict security protection is carried out on the master key to prevent leakage.

[0045] II. Terminal device registration stage

[0046] When the terminal device initiates a registration request, it needs to provide rich information. In addition to the device's identification information (such as device number, MAC address) and public key, it also needs to provide the device's behavior pattern characteristics, such as operation frequency (number of operations per day), operation time pattern (operation during a specific time period), etc.

[0047] After receiving the registration request, the authentication network uses machine learning algorithms to deeply verify the registration information. Build a verification model based on multi-feature fusion, which will comprehensively consider various feature information of the device to judge the legitimacy and reliability of the device. At the same time, use blockchain technology to store the registration information in a distributed manner. The immutable and traceable characteristics of the blockchain can ensure the security and integrity of the registration information.

[0048] If the verification passes, the authentication node will calculate the initial trust value Trust of the device through the formula . Where, info device is the different feature information of the device, w j is the weight corresponding to the feature, and f j is the feature evaluation function. Different feature information has different importance when evaluating the device's trust value, so the weight w j needs to be reasonably set according to the actual situation. For example, when the security level requirement of the device is high, the verification weight of the public key can be appropriately increased. j

[0049] III. Authentication request stage end

[0050] When the terminal device sends an authentication request, it adopts an adaptive multi-path transmission and multi-modal encryption method. It real-time monitors information such as the network topology, traffic status, and signal strength, and uses the ant colony algorithm to dynamically plan the optimal transmission path. The ant colony algorithm has self-adaptability and global search ability, and can find the best path according to the real-time network conditions, improving the transmission efficiency and reliability.

[0051] At the same time, it combines symmetric encryption and asymmetric encryption algorithms to encrypt the authentication request. Through the formula

[0052] Vote weight =α·Accuracy history +β·Computation ability

[0053] encrypts the authentication request message M req , where E sym is the symmetric encryption algorithm, and E pub is the asymmetric encryption algorithm using the public key of the authentication network. This multi-modal encryption method can effectively protect the security of the authentication request information during transmission.

[0054] After receiving the request, the authentication network determines the set of authentication nodes participating in the authentication based on the fuzzy logic algorithm. The fuzzy logic algorithm comprehensively considers factors such as the load of the nodes (CPU usage rate, memory usage rate), credibility (historical authentication accuracy rate), and relevance with the terminal device (geographical location, network connection stability). In practical applications, it is necessary to continuously collect and analyze network status information to ensure the accuracy of path selection and node selection.

[0055] IV. Authentication Calculation Stage

[0056] The authentication nodes participating in the authentication use the distributed federated learning algorithm for authentication calculation. Distributed federated learning allows nodes to jointly train and optimize the authentication model without sharing the original data. Each node conducts model training locally and then uploads the training parameters to the coordination node for aggregation. This method can not only protect data privacy but also improve the accuracy and generalization ability of the model.

[0057] At the same time, the zero-knowledge proof technology is introduced to enable the authentication nodes to complete the authentication calculation without disclosing sensitive information. Each authentication node sends the calculation result to the coordination node, and the coordination node uses the formula

[0058] Vote weight =α·Accuracy history +β·Computatiol abilityCalculate the voting weight, where α and β are weight coefficients and α + β = 1. Then, based on this weight, use the improved weighted voting algorithm for comprehensive judgment. In practical applications, it is necessary to dynamically adjust the weight coefficients α and β according to different authentication scenarios and the actual performance of the nodes.

[0059] V. Authentication Result Feedback

[0060] The stage coordination node feeds back the authentication result to the terminal device and the relevant application systems in a combination of encrypted broadcast and directional feedback. Through the formula C result = E priv (M result || σ result ) encrypts the authentication result message M result , where σ result is the digital signature of the result, and E priv is the encryption algorithm using the private key of the coordination node. This encryption method can ensure the confidentiality and integrity of the authentication result during transmission.

[0061] At the same time, the authentication network dynamically adjusts the trust value of the terminal device according to the authentication result. Through the formula ΔTrust device = k · (1 - Trust device ) · Result flag update the trust value, where k is the adjustment coefficient and Result flag is the authentication result identifier (1 for passing and 0 for failing). In actual operations, it is necessary to reasonably adjust the adjustment coefficient k according to factors such as the historical performance of the device, security requirements, and authentication environment.

[0062] VI. Authentication Information Update Mechanism

[0063] When certain information of the terminal device (such as public key, device identifier, behavioral pattern characteristics, etc.) changes, the terminal device sends an update request, and the request contains the feature vector of the changed information. The authentication network uses the autoencoder model in deep learning to extract features and detect anomalies of the changed information. The autoencoder model can automatically learn the feature representation of the data and detect whether the information has changed abnormally by comparing the differences between the input and output.

[0064] During the update process, through the formula

[0065] regenerate the updated sub - key where is the updated authentication node identifier, is the new chaotic random sequence, and Δinfo is the feature vector of the information change. In practical applications, it is necessary to regularly train and optimize the autoencoder model to improve the accuracy of anomaly detection.

[0066] VII. Anomaly Detection Mechanism

[0067] During the authentication process, the authentication nodes monitor the authentication parameters in real time in multiple dimensions, including time series parameters (time interval of authentication requests, time consumption of authentication calculations), spatial distribution parameters (geographical location of devices, network topology structure), etc. An anomaly detection model based on the Generative Adversarial Network (GAN) is adopted, and through the adversarial training of the generator and the discriminator, the ability to identify abnormal patterns is improved.

[0068] Through the formula Calculate the change amount ΔP of multi-dimensional parameters multi-dim , where P current,j is the parameter value of the current j-th dimension, P average,j is the historical average value of the parameter of this dimension, and σ j is the standard deviation of the parameter of this dimension. When ΔP multi-dim is greater than the threshold T multi-dim , the anomaly handling process is triggered. In actual operation, the GAN model needs to be continuously trained and adjusted to adapt to different abnormal patterns.

[0069] VIII. Authentication Node Selection Mechanism

[0070] In the initialization stage, the selection of authentication nodes adopts a distributed election algorithm based on reinforcement learning. The algorithm takes factors such as the computing power of the nodes (CPU performance, computing speed), storage capacity (hard disk size, available memory), network bandwidth (upload speed, download speed), energy consumption (power consumption, battery life) as the state space, and the selection actions of the nodes as the action space, and guides the algorithm to select the optimal set of authentication nodes through the reward function.

[0071] The reward function is calculated through the formula

[0072] R node =γ1·C i +γ2·S i +γ3·B i -γ4·E i ,

[0073] where C i is the computing power of the node, S i is the storage capacity of the node, B i is the network bandwidth of the node, E i is the energy consumption of the node, γ1, γ2, γ3, γ4 are the corresponding weight coefficients, and γ1 + γ2 + γ3 + γ4 = 1. In practical applications, the weight coefficients need to be dynamically adjusted according to the actual situation of the network and task requirements.

[0074] IX. Authentication Result Feedback Encryption Mechanism

[0075] The coordination node dynamically adjusts the feedback encryption method and transmission strategy according to the security levels and communication requirements of the terminal device and the application system. Through the formula Calculate the feedback encryption level E level , where s k is a relevant factor of the security level and communication requirements, and ω k is the weight of the corresponding factor.

[0076] For terminal devices and application systems with high security level requirements, more advanced encryption algorithms and more secure transmission strategies are adopted; for those with lower security level requirements, the encryption level and transmission cost can be appropriately reduced. In actual operation, it is necessary to accurately evaluate the security level and communication requirements to determine the appropriate encryption level.

[0077] X. Authentication Node Dynamic Management Mechanism

[0078] When some nodes in the authentication network fail (such as hardware damage, software crash) or the performance degrades (CPU overload, high network latency), a node replacement strategy based on fuzzy clustering and genetic algorithm is adopted. First, the nodes are classified into different categories through the fuzzy clustering algorithm, considering factors such as the function, performance, and geographical location of the nodes. Then, the genetic algorithm is used to select the optimal replacement node in each category.

[0079] Through the formula

[0080] Fitness node =δ1·Health i +δ2·Compatibility i Calculate the fitness Fitness of the node node , where Health i is the health status of the node, Compatibility i is the compatibility of the node with the current authentication network, δ1 and δ2 are weight coefficients, and δ1 + δ2 = 1. In actual applications, it is necessary to accurately evaluate the health status and compatibility to select the most suitable replacement node.

[0081] XI. Multi-Factor Authentication Mechanism for Terminal Devices

[0082] During the registration phase of the terminal device, multi-factor authentication is performed on the identity of the terminal device. In addition to the device identifier, public key, geographical location, and usage time, factors such as the hardware fingerprint (chip serial number, motherboard number) and software version (operating system version, application version) of the device are also considered.

[0083] Through the formula Calculate the authentication score Auth of the computing terminal device score , where info l is the different characteristic information of the device, and η l is the weight corresponding to the characteristic, and f l is the characteristic evaluation function, and In actual operation, it is necessary to adjust the characteristic weights and evaluation functions according to different types of devices and application scenarios.

[0084] XII. Data Representation and Explanation

[0085]

[0086] It can be clearly seen from the tabular data the significant advantages of the authentication method of this application compared with the traditional method. In terms of authentication efficiency, the average authentication time is greatly shortened from 15 seconds to 3 seconds, an increase of 80%, which benefits from the adaptive multi-path transmission, distributed computing, and intelligent node selection strategy, which can quickly process authentication requests. In terms of authentication security, the authentication failure rate after being attacked drops sharply from 40% to 3%, a decrease of 92.5%. A variety of encryption technologies, zero-knowledge proofs, and anomaly detection mechanisms effectively resist various attacks. The ability score of authentication flexibility is increased from 2 points to 9 points, an increase of 350%. The dynamic node management and adaptive strategy enable it to easily adapt to different network environments. The resource utilization rate is increased from 30% to 70%, an increase of 133.3%. The distributed architecture and optimized algorithms reasonably allocate and utilize computing resources. In terms of the accuracy of trust evaluation, the trust value error rate is reduced from 20% to 5%, a decrease of 75%. The multi-factor authentication and dynamic trust adjustment mechanism ensure the accuracy of the device trust evaluation. These improvements make the method of this application have extremely high practicality and competitiveness in the authentication of Internet of Things terminal devices in smart cities, and can provide a strong guarantee for the safe and stable operation of smart cities.

[0087] The above is only the preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any person skilled in the art within the technical scope disclosed by the present invention, according to the technical solution and inventive concept of the present invention, makes equivalent substitutions or changes, and should be covered by the protection scope of the present invention.

Claims

1. A distributed authentication method for IoT terminal devices for smart cities, characterized in that: include: Initialization phase: Build a distributed authentication network, use the chaotic mapping algorithm to generate the system's public parameters and key pairs, and use the formula Generate subkey SK i , where K master Master key, ID i is the identifier of the i-th authentication node, It is a random sequence generated based on chaotic mapping, and H is a hash function; Terminal device registration phase: When a terminal device sends a registration request, it includes the device's identification information and public key, and also needs to provide the device's behavior pattern characteristics. The authentication network uses a machine learning algorithm to verify the registration information and build a verification model based on feature fusion. At the same time, it uses distributed ledger technology to store the registration information in a distributed manner. If the verification is successful, the authentication node passes the formula Calculate the initial trust value Trust of the device device , where info j is the different characteristic information of the device, w j is the weight of the corresponding feature, f j is the feature evaluation function; Authentication request stage: The terminal device uses adaptive transmission and encryption methods to send authentication requests, dynamically selects the optimal transmission path according to the real-time network status, and encrypts the request by combining symmetric encryption and asymmetric encryption algorithms; C trans =E pub (E sym (M req )) Authentication request message M req Encryption, where E sym is a symmetric encryption algorithm, E pub It is an asymmetric encryption algorithm that uses the public key of the authentication network. After receiving the request, the authentication network determines the set of authentication nodes participating in the authentication based on the fuzzy logic algorithm, taking into account the node load, credibility, and relevance to the terminal device. Authentication calculation stage: The authentication nodes participating in the authentication use a distributed federated learning algorithm to perform authentication calculations. Without sharing the original data, they jointly improve the accuracy of the authentication model and introduce zero-knowledge proof technology to enable the authentication nodes to complete the authentication calculations without leaking information. Each authentication node sends the calculation results to the coordination node, which makes judgments through a weighted voting algorithm. The voting weight is dynamically adjusted according to the node's historical authentication accuracy and computing power factors. Vote weight =α·Accuracy history +β·Computation ability Calculate the voting weight, where α and β are weight coefficients, and α+β=1.

2. The distributed authentication method for IoT terminal devices for smart cities according to claim 1 is characterized in that: Also includes: Authentication result feedback phase: The coordination node uses a combination of encrypted broadcast and directional feedback to feed back the authentication result to the terminal device and related application systems. result =E priu (M result ||σ result ) for the authentication result message M result Encryption is performed, where σ result is the digital signature of the result, E priv To use the encryption algorithm of the coordination node private key and the authentication network to dynamically adjust the trust value of the terminal device according to the authentication result, the formula ΔTrust device =k·(1-Trust device )·Result flag Update the trust value, where k is the adjustment coefficient, Result flag Identifies the authentication result; Authentication information update mechanism: When some information of the terminal device changes, the terminal device sends an update request, which contains the feature vector of the change information; the authentication network uses the autoencoder model in deep learning to extract features and detect anomalies of the change information. During the update process, the formula Regenerate updated subkeys in is the updated authentication node identifier, is a new chaotic random sequence, Δ info is the feature vector of information change.

3. The distributed authentication method for IoT terminal devices for smart cities according to claim 1 is characterized in that: Also includes: Anomaly detection mechanism: During the authentication process, the authentication node monitors the time series parameters and spatial distribution parameters in real time, and adopts an anomaly detection model based on the generative adversarial network (GAN). Through adversarial training of the generator and the discriminator, the ability to recognize abnormal patterns is improved. Calculate the change ΔP of multi-dimensional parameters multi-dim , where P current,j is the parameter value of the current j-th dimension, P average,j is the historical average value of the dimension parameter, σ j is the standard deviation of the dimension parameter; when ΔP multi-dim Greater than the threshold T multi-dim The exception handling process is triggered.

4. The distributed authentication method for IoT terminal devices for smart cities according to claim 1 is characterized in that: In the initialization phase, the selection of authentication nodes adopts a distributed election algorithm based on reinforcement learning. The algorithm uses the node's computing power, storage capacity, network bandwidth, and energy consumption factors as the state space, and the node's selection action as the action space. The algorithm is guided by the reward function to select the optimal set of authentication nodes. The reward function is given by the formula R node =γ1·C i +γ2·S i +γ3·B i -γ4·E i Calculate, where C i is the computing power of the node, S i is the storage capacity of the node, B i is the network bandwidth of the node, E i is the energy consumption of the node, γ1, γ2, γ3, γ4 are the corresponding weight coefficients, and γ1+γ2+γ3+γ4=1.

5. The distributed authentication method for IoT terminal devices for smart cities according to claim 1 is characterized in that: In the authentication request stage, the terminal device uses adaptive transmission and encryption to send the authentication request. The terminal device monitors the network topology and traffic status in real time, and uses the ant colony algorithm to dynamically plan the optimal transmission path. At the same time, the authentication request is encrypted in combination with the quantum-inspired encryption algorithm, and some characteristics of quantum encryption are simulated in the classical computing environment. The formula C trans =E pub-quantum (E sym-quantum (M req )) Authentication request message M req Encryption, where E sym-quantum is a quantum-inspired symmetric encryption algorithm, E pub-quantum It is a quantum-inspired asymmetric encryption algorithm.

6. The distributed authentication method for IoT terminal devices for smart cities according to claim 1 is characterized in that: During the authentication calculation stage, a distributed consensus algorithm based on blockchain is used between authentication nodes to verify the consistency of the calculation results; each authentication node packages the calculation results into blocks and reaches a consensus through a hybrid consensus mechanism that combines proof of work (PoW) and proof of stake (PoS); at the same time, contract technology is used to automatically supervise and manage the authentication calculation process.

7. The distributed authentication method for IoT terminal devices for smart cities according to claim 2 is characterized in that: In the authentication result feedback phase, the coordination node uses a combination of encrypted broadcast and directional feedback to feed back the authentication results to the terminal device and related application system. The coordination node dynamically adjusts the feedback encryption method and transmission strategy according to the security level and communication requirements of the terminal device and application system. Calculate the encryption level E of the feedback level , where s k is the relevant factor of security level and communication requirements, ω k is the weight of the corresponding factor.

8. The distributed authentication method for IoT terminal devices for smart cities according to claim 1 is characterized in that: Also includes: Dynamic management mechanism of authentication nodes: When a node in the authentication network fails or its performance degrades, a node replacement strategy based on fuzzy clustering and genetic algorithm is adopted. First, the nodes are divided into different categories by fuzzy clustering algorithm, and then the genetic algorithm is used to select the best replacement node in each category. Fitness node =δ1·Health i +δ2·Compatibility i Calculate the node's fitness node , of which Health i The health status of the node, Compatibility i is the compatibility of the node with the current authentication network, δ1 and δ2 are weight coefficients, and δ1+δ2=1.

9. The distributed authentication method for IoT terminal devices for smart cities according to claim 1 is characterized in that: During the terminal device registration phase, the identity of the terminal device is authenticated. In addition to the device identification, public key, geographic location, and usage time, the device's hardware fingerprint and software version factors are also considered; through the formula Calculate the authentication score Auth of the terminal device score , where info l is the different characteristic information of the device, η l is the weight of the corresponding feature, f l is the feature evaluation function, and 10. The distributed authentication method for IoT terminal devices for smart cities according to claim 1 is characterized in that: During the authentication process, a combination of blockchain and edge computing technology is used to store and manage authentication information; some authentication computing tasks are offloaded to edge nodes for processing; at the same time, blockchain contracts are used to realize automatic execution and dynamic adjustment of authentication rules, and optimize authentication strategies in real time according to the usage of terminal devices and the network environment.

Citation Information

Patent Citations

  • Distributed node intrusion situation awareness method based on block chain

    CN116405187A

  • Internet of Things equipment access authentication system and method based on lightweight block chain

    CN117062076A

  • Smart agriculture smart contract authentication method and system based on block chain

    CN118300806A

  • Blockchain-based authentication system

    DE202025100776U1

Cited By

  • Decentralized Stakeholder Voting Layer for Trust-Weighted Blockchain Governance

    US20250391219A1