Method for enhancing identity authentication of industrial control system
By combining the multi-factor authentication method of username, password, usbkey and PIN code in the industrial control system, the problem of insufficient security in the modern industrial environment is solved, and higher security and data protection effects are achieved.
Patent Information
- Application Number
- CN202510366147.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-26
- Publication Date
- 2025-06-27
AI Technical Summary
Traditional username and password authentication methods have security vulnerabilities in modern industrial environments, which are easily guessed or cracked, and a single authentication mechanism is difficult to resist attacks when facing complex network environments, resulting in insufficient security of industrial control systems.
By combining username, password, usbkey and its PIN code, multi-factor authentication is realized, ensuring that each usbkey is consistent with a specific container name, and a unique hash value is generated through random number and hash operations, and a digital signature algorithm is used for signature verification to enhance the security of identity authentication.
Improves the security of industrial control systems, prevents unauthorized access, prevents device theft and identity impersonation, enhances data integrity and confidentiality, and reduces the risk of a single password being cracked or leaked.
Smart Images

Figure CN120223392A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of identity authentication, and particularly relates to a method for enhancing identity authentication in industrial control systems. Background Art
[0002] With the continuous advancement of the global industrialization process, industrial control systems (ICS) play a crucial role in key infrastructures such as modern manufacturing, energy, power, transportation, and water treatment. These systems achieve the monitoring, control, and optimization of the production process through automated control devices and network connections. However, with the continuous development of information technology, especially the widespread application of Internet and cloud computing technologies, industrial control systems are facing unprecedented security challenges.
[0003] Traditional identity authentication methods, such as usernames and passwords, although widely used in various computer systems in the past few decades, their inherent security vulnerabilities and defects are becoming more apparent in the modern industrial environment. The password system is one of the most common authentication methods in industrial control systems, but as the number of users increases and the complexity of password management rises, the security of passwords is greatly reduced. Many users choose simple passwords for easy memorization, and these passwords are often easy to guess or crack, becoming a weak link for attackers to obtain system permissions. The dilemma of password management, especially in terms of regular password updates and strength requirements, further exacerbates these security risks.
[0004] At the same time, attack methods such as social engineering attacks and brute-force cracking are constantly evolving, making the traditional username and password authentication method no longer sufficient to resist complex attack threats. For industrial control systems, these problems are particularly serious because once the system is breached by attackers, it may lead to production line shutdowns, equipment damage, production data leakage, and even affect public safety and social order. Therefore, how to ensure the secure authentication of user identities has become the core issue for ensuring the stable and secure operation of industrial control systems.
[0005] Currently, many industrial control systems still rely on a single identity authentication mechanism, that is, user identity authentication is carried out through the combination of a username and a password. However, the single authentication mechanism has obvious security risks, especially when industrial control systems face more complex network environments such as external networking and remote access. Attackers can break through the traditional authentication mechanism through network vulnerabilities, phishing attacks, etc., and obtain unauthorized access rights. Especially when some industrial control systems do not implement multi-factor authentication (MFA), the single authentication method makes the system extremely vulnerable to unauthorized access and may even be manipulated by malicious attackers, resulting in serious security incidents. Therefore, there is an urgent need to introduce a more secure, flexible, and easy-to-manage identity authentication solution to ensure the stable operation of industrial control systems. Summary of the Invention
[0006] The object of the present invention is to provide a method for enhancing the identity authentication of industrial control systems, so as to solve the technical problems in the prior art, reduce the risk of a single password being cracked or leaked, and improve the security of industrial control systems.
[0007] To achieve the above object, the present invention adopts the following technical solutions: The present invention provides a method for enhancing the identity authentication of industrial control systems, including: Configuring the PIN code and container name of the usbkey; Establishing a one-to-one correspondence between the user name and the usbkey container name; Establishing a correspondence between the user name and the password; Inserting the usbkey into the host computer; the host computer obtains the user name, password, and PIN code of the usbkey; Performing preliminary verification. After the preliminary verification is successful, it is judged whether the inserted usbkey container name a is the same as the usbkey container name b corresponding to the user name; if the container name a and the container name b are not the same, the identity authentication fails; otherwise, the container name b and a random number are subjected to a hashing operation to obtain a hashing result; the hashing result is signed through a private key to obtain a signature value; the digital certificate, root certificate, hashing result, and signature value are verified through a public key; if the verification passes, the identity authentication is successful, otherwise the identity authentication fails; Wherein, the host computer is configured with a digital certificate; the server is configured with a root certificate.
[0008] Preferably, the method for the preliminary verification is: verifying whether the user name and the password are in a corresponding relationship, and at the same time verifying whether the obtained PIN code is the same as the configured PIN code. If the user name and the password are in a corresponding relationship and the obtained PIN code is the same as the configured PIN code, the verification is successful; otherwise, the verification fails.
[0009] Preferably, the usbkey is configured and applied before insertion to activate the usbkey.
[0010] Preferably, before the preliminary verification, the host computer judges whether the server is successfully initialized. If the initialization fails, the process is terminated; if the initialization is successful, the preliminary verification is performed.
[0011] Preferably, after the initialization is successful, the host computer judges whether the usbkey is detected by enumerating the device interface. If the usbkey is detected, the preliminary verification is performed; if the usbkey is not detected, the process is terminated.
[0012] Preferably, the inserted usbkey container name a is obtained through a container interface.
[0013] Preferably, the random number is generated through a random number interface.
[0014] Preferably, the hashing operation adopts the SHA-256 algorithm.
[0015] Preferably, the IP address of the host computer and the IP address of the server are connected and configured in a network with the same network segment.
[0016] Preferably, a usbkey control is set in the host computer.
[0017] Compared with the prior art, the present invention has the following beneficial effects: By combining the user name, password, usbkey and its PIN code, the present invention realizes multi-factor authentication, thereby improving security and preventing unauthorized access; by judging whether the inserted usbkey container name is consistent with the user name corresponding container name, it is ensured that each usbkey is consistent with a specific container name, thereby effectively preventing device theft or identity impersonation; through random numbers and hashing operations, the system generates a unique hash value for each user request, and then uses a digital signature algorithm for signature, ensuring that only users with the same private key can successfully verify the signature, thereby verifying the legitimacy of their identities and enhancing the overall data integrity and confidentiality. BRIEF DESCRIPTION OF THE DRAWINGS
[0018] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required to be used in the embodiments. It should be understood that the following drawings only show some embodiments of the present invention, and therefore should not be regarded as limiting the scope. For those of ordinary skill in the art, without creative efforts, other related drawings can also be obtained based on these drawings.
[0019] Figure 1 It is a flowchart of the method of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0020] To make the objectives, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Usually, the components of the embodiments of the present invention described and illustrated in the drawings here can be arranged and designed in various different configurations.
[0021] Therefore, the following detailed description of the embodiments of the present invention provided in the drawings is not intended to limit the scope of the present invention claimed, but merely represents the selected embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present invention.
[0022] It should be noted that like reference numerals and letters refer to like items in the following figures, and thus, once an item is defined in one figure, it need not be further defined or explained in subsequent figures.
[0023] In the description of the embodiments of the present invention, it should be noted that if terms such as "upper", "lower", "horizontal", "inner", etc. are used to indicate the orientation or positional relationship, it is based on the orientation or positional relationship shown in the figures, or the orientation or positional relationship in which the product of the present invention is habitually placed during use. This is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation, and thus should not be construed as a limitation of the present invention. In addition, terms such as "first", "second", etc. are only used for distinguishing descriptions and cannot be construed as indicating or implying relative importance.
[0024] In addition, if the term "horizontal" appears, it does not mean that the component is required to be absolutely horizontal, but it can be slightly inclined. For example, "horizontal" only means that its direction is more horizontal relative to "vertical", and does not mean that the structure must be completely horizontal, but it can be slightly inclined.
[0025] In the description of the embodiments of the present invention, it should also be noted that unless otherwise clearly specified and limited, if terms such as "set", "installed", "connected", "connected" are used, they should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection, or an integral connection; it can be a mechanical connection or an electrical connection; it can be directly connected or indirectly connected through an intermediate medium, and it can be the communication inside two elements. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.
[0026] The present invention will be further described in detail below with reference to the figures: As Figure 1 shown, the present invention provides a method for enhancing the identity authentication of an industrial control system, including: Configuring the PIN code and container name of the intelligent password key (usbkey); Establishing a one-to-one correspondence between the user name and the usbkey container name (for example, if the user name is "admin1", then the container name of the usbkey can be called "admin1key", and there is only one container name called "admin1key"); Establishing a correspondence between the user name and the password; Inserting the usbkey into the host computer; the host computer obtains the user name, password, and PIN code of the usbkey; Perform preliminary verification. After the preliminary verification is successful, determine whether the USB key container name a inserted is the same as the USB key container name b corresponding to the username. If the container name a and the container name b are not the same, the identity authentication fails. Otherwise, perform a hashing operation on the container name b and a random number to obtain a hashing result. Sign the hashing result with the private key to obtain a signature value. Verify the signature of the digital certificate, root certificate, hashing result, and signature value with the public key. If the signature verification passes, the identity authentication is successful; otherwise, the identity authentication fails. Among them, the host computer is configured with a digital certificate, and the server is configured with a root certificate.
[0027] The present invention combines the username, password, USB key, and its PIN code to implement multi-factor authentication, that is, combines the knowledge factor (username and password) with the possession factor (USB key), improving the security of identity authentication and reducing the risk of a single password being cracked or leaked. In addition, the hardware characteristics of the USB key key also make physical access an additional security barrier, ensuring that only the physical holder can access it, effectively preventing users from logging in remotely or on unauthorized devices with a password, enhancing the physical security of the identity authentication process, and preventing illegal access after the password is stolen by malicious software such as viruses and Trojans. Secondly, the present invention establishes a one-to-one correspondence between the username and the container name of the USB key, ensuring that the container name of the USB key must match the username in the system during identity authentication, effectively preventing the risk of identity impersonation by forging or replacing the USB key. During the implementation process, the container name in the USB key key is used as the identifier of the user identity, ensuring that each USB key is bound to the identity information of a specific user, ensuring that only authorized users can use their corresponding USB key key to log in. Even if the user's password is stolen, they cannot log in without the corresponding USB key.
[0028] After passing the preliminary verification, the present invention performs a hashing operation on the USB key container name and a random number and signs it with the private key, further increasing the complexity of the authentication. Digital signatures not only prevent information tampering but also ensure the integrity of the authentication process. Verifying the signature of the hashing result with the public key increases the ability to prevent forgery and man-in-the-middle attacks and enhances the anti-attack ability of the system. The present invention's security verification mechanism based on signature and signature verification ensures the legitimacy of the user identity. The host computer and the server are respectively configured with a digital certificate and a root certificate, further strengthening the trust chain of identity verification. The digital certificate is issued by a certification authority, and the root certificate ensures the legitimacy and validity of the digital certificate. Using these certificates can ensure that the information transmission during the identity authentication process is secure and reliable, preventing malicious attackers from forging certificates or tampering with data.
[0029] The method of the preliminary verification is as follows: verify whether the username and password are in a corresponding relationship, and at the same time verify whether the obtained PIN code is consistent with the configured PIN code. If the username and password are in a corresponding relationship and the obtained PIN code is consistent with the configured PIN code, the verification is successful; otherwise, the verification fails. By simultaneously verifying the corresponding relationship between the username and password and the correctness of the PIN code, the present invention ensures multiple guarantees in the identity verification process. The username and password are traditional identity verification means, while the PIN code is additional identity authentication information, which increases the protection level of the system and reduces the risk of the account being illegally accessed. Even if an attacker knows the username and password, as long as the correct PIN code is not available, the verification process still cannot pass, effectively preventing the security of the account from being obtained through the leakage of a single password.
[0030] The usbkey is configured and applied before insertion to activate the usbkey. For the usbkey used for data encryption or storage, through pre-configuration activation, the data protection mechanism can be enhanced to prevent the usbkey from being misused or lost. For example, additional encryption functions can be enabled during activation, or password protection can be set to ensure that the data stored on the usbkey can only be accessed by authorized users.
[0031] Before the preliminary verification, the host computer determines whether the server has been successfully initialized. If the initialization fails, the process is terminated; if the initialization is successful, the preliminary verification is carried out. By checking whether the server has been successfully initialized before the preliminary verification, it is ensured that the system runs in a normal working environment. If the server is not successfully initialized, the process will be terminated, thus avoiding the system from continuing to execute subsequent operations in an unstable or incorrect environment, which helps to prevent system crashes, data loss, or other potential failures caused by initialization failures.
[0032] After the successful initialization, the host computer determines whether the usbkey is detected by enumerating the device interface. If the usbkey is detected, the preliminary verification is carried out; if the usbkey is not detected, the process is terminated. The mechanism of judging the device legality by enumerating the interface and terminating the process when the USB Key is not detected not only enhances the simplicity of the operation but also improves the security of the system, effectively reducing security vulnerabilities caused by incorrect operations, unauthorized devices, or malicious device insertions. For the overall data protection of the host computer, it ensures that the host computer runs only in a correct and secure device environment.
[0033] The name a of the inserted USB key container is obtained through the container interface. The host computer can quickly identify the newly inserted USB key without manual intervention, improving the convenience of device use and enabling users to quickly and easily use the USB key without having to manually configure or install drivers. At the same time, the system can monitor the insertion and removal of the USB key in real time to achieve dynamic management. When the USB key is inserted, the system can automatically detect and start relevant operations, and when the USB key is removed, the system will release resources in a timely manner to avoid unnecessary conflicts or errors. Through the container interface, the USB key can be compatible with various hardware platforms and operating systems, thus improving the scalability and compatibility of the system.
[0034] The random number is generated through the random number interface, which can ensure the security and unpredictability of the system, thereby enhancing the confidentiality of data and preventing attackers from conducting prediction and replay attacks. Among them, unpredictability means that the generated random number cannot be speculated by any external observer or attacker without internal system information. This means that even if the attacker obtains some output data, they cannot reverse-infer future random values or the system's key based on this data, which greatly reduces the possibility of cracking the system.
[0035] The hashing operation uses the SHA-256 algorithm. SHA-256 (Secure Hash Algorithm 256-bit) is a widely used secure hash algorithm that converts data of any length into a fixed-length 256-bit hash value, ensuring the integrity and immutability of the data. Using the SHA-256 algorithm can effectively prevent data tampering, enhance the security of the system, and ensure data consistency. SHA-256 is crucial for applications such as cryptography, authentication, and digital signatures, providing high collision resistance and attack resistance.
[0036] The host computer IP address and the server IP address are connected and configured in a network with the same network segment, which can ensure more efficient and stable communication between them. Since devices within the same network segment communicate through the local area network, the data transmission delay is low and the bandwidth utilization rate is high. At the same time, it simplifies network management and device access control, eliminating cross-network segment routing and access restrictions, making network connection and data exchange more direct and fast.
[0037] A USB key control is set in the host computer. The USB key control is used to implement the interaction with the USB key hardware device on the host computer to ensure that the system can recognize and use the encryption service or identity authentication function provided by the USB key. Through the USB key control, it is convenient to manage and operate the host computer, enhancing the functional scalability and flexibility of the USB key.
[0038] In summary, by combining multiple authentication factors such as username, password, USB key, and PIN code, the present invention can greatly enhance the security of authentication. Each authentication factor is independent and difficult to replicate. Therefore, even if an attacker obtains one of the information (such as username and password), they cannot successfully pass the authentication system. The present invention introduces the combination of USB key and PIN code, making the authentication process more complex and difficult to break. The present invention ensures that each USB key matches a specific container name by determining whether the inserted USB key container name is the same as the container name corresponding to the username. Specifically, each USB key device is bound to a unique container name, and this name is compared with the user's username during the authentication process. Only when the inserted USB key container name is exactly the same as the container name corresponding to the user can the authentication pass, effectively preventing the risk of device theft or identity impersonation. For example, assume that an attacker obtains a USB key device, but this device is not bound to the container name of a specific user. During authentication, due to the name mismatch, the system will reject the authentication request of this device, thus ensuring the uniqueness and security of the user identity. To further improve the security of the authentication process, the present invention also introduces random number generation and hashing operations. At each authentication request, the system generates a unique hash value, which is calculated based on the user input information and random numbers. This hash value is not only a verification of the authentication request but also encrypted through a digital signature algorithm. The digital signature algorithm can ensure that only the user with the private key corresponding to the hash value can perform effective signature verification. Specifically, the user signs the hash value with their private key, and the system verifies the signature using the corresponding public key. If the signature verification is successful, the system will confirm that the user's identity is legal and thus grant them access rights. In addition to identity authentication, the combination of the hash value and digital signature further enhances the integrity and confidentiality of the system data. The hashing algorithm can map input data of any length to a hash value of a fixed length, and any minor tampering of the data will result in a huge change in the hash value, which effectively guarantees the data integrity. In addition, the digital signature algorithm can ensure that the data transmitted during the authentication process will not be tampered with, and only the user with the correct private key can generate a valid signature, thus ensuring the data confidentiality.
[0039] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: still can modify the specific implementation manners of the present invention or make equivalent replacements, and any modification or equivalent replacement that does not depart from the spirit and scope of the present invention should be covered within the protection scope of the claims of the present invention.
Claims
1. A method for enhancing identity authentication of an industrial control system, characterized in that: include: Configure the PIN code and container name of the USBKey; Establish a one-to-one correspondence between the user name and the usbkey container name; Establish a corresponding relationship between the user name and the password; Insert the USB key into the host computer; the host computer obtains the user name, password and PIN code of the USB key; Perform a preliminary verification, and after the preliminary verification succeeds, determine whether the inserted USBKey container name a is consistent with the USBKey container name b corresponding to the user name; if the container name a and the container name b are inconsistent, the identity authentication fails; otherwise, the container name b and the random number are hashed to obtain a hash result; the hash result is signed by the private key to obtain a signature value; The digital certificate, root certificate, hash result and signature value are verified through the public key; if the verification passes, the identity authentication is successful, otherwise the identity authentication fails; Wherein, the host computer is configured with a digital certificate; and the server is configured with a root certificate.
2. A method for enhancing identity authentication of an industrial control system according to claim 1, characterized in that: The method of the preliminary verification is: verify whether the user name corresponds to the password, and verify whether the obtained PIN code is consistent with the configured PIN code. If the user name corresponds to the password and the obtained PIN code is consistent with the configured PIN code, the verification is successful, otherwise the verification fails.
3. The method for enhancing identity authentication of an industrial control system according to claim 1, characterized in that: The USBKey is configured and applied before being inserted to activate the USBKey.
4. The method for enhancing identity authentication of an industrial control system according to claim 1, characterized in that: The host computer determines whether the server is successfully initialized before the preliminary verification. If the initialization fails, the process is terminated; if the initialization is successful, the preliminary verification is performed.
5. A method for enhancing identity authentication of an industrial control system according to claim 4, characterized in that: After the initialization is successful, the host computer determines whether the USB key is detected by enumerating the device interface. If the USB key is detected, a preliminary verification is performed. If the USB key is not detected, the process is terminated.
6. The method for enhancing identity authentication of an industrial control system according to claim 1, characterized in that: The inserted usbkey container name a is obtained through the container interface.
7. The method for enhancing identity authentication of an industrial control system according to claim 1, characterized in that: The random number is generated through a random number interface.
8. The method for enhancing identity authentication of an industrial control system according to claim 1, characterized in that: The hash operation adopts the SHA-256 algorithm.
9. The method for enhancing identity authentication of an industrial control system according to claim 1, characterized in that: The host computer IP address and the server IP address are connected and configured in the same network segment.
10. The method for enhancing identity authentication of an industrial control system according to claim 1, characterized in that: The host computer is provided with a USBKey control.