Identity authentication method and system based on equipment

Through hash calculation and behavioral pattern comparison of device unique identification information, the problem of insufficient static comparison in existing device identity authentication is solved, dynamic analysis and multiple rounds of authentication are realized, and the security and accuracy of device identity authentication are improved.

CN120238356AActive Publication Date: 2025-07-01SHAANXI ZHENMI TECHNOLOGY CO LTD

Patent Information

Application Number
CN202510452034.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-11
Publication Date
2025-07-01
Estimated Expiration
2045-04-11

AI Technical Summary

Technical Problem

The existing equipment identity authentication mechanisms are mostly one-time static comparisons, and lack dynamic analysis capabilities at the behavioral level, resulting in insufficient security and limited recognition accuracy.

Method used

By obtaining the unique identification information of the device, hash calculations are performed to generate identity characteristic values, match server data, calculate hash value comparison, analyze abnormal situations in combination with the access request mode, and send temporary identity authentication factors for multiple rounds of interactive authentication.

Benefits of technology

It improves the security and recognition accuracy of device identity authentication, can promptly identify disguises, cloning and abnormal behaviors, and enhances the system's tamper-proof ability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238356A_ABST
    Figure CN120238356A_ABST
Patent Text Reader

Abstract

The invention is suitable for the technical field of device identification methods, and provides a device-based identity authentication method and system, and the method comprises the steps: obtaining unique identification information of a target device; carrying out Hash calculation on the unique identification information of the equipment, generating an identity characteristic value, sending an identity authentication request to a server, obtaining registration equipment data, and matching the registration equipment data with the identity authentication request; acquiring an equipment public key stored in the server according to a matching result, calculating a feature hash value of the registration equipment data and a feature hash value in the identity authentication request, and determining whether the identity of the target equipment is legal or not according to a comparison result; the access request mode is compared with the basic mode, an abnormal condition is determined according to a comparison result, an abnormal score is determined according to the abnormal condition, and if the abnormal score is higher than a threshold value, a temporary identity authentication factor is sent to the target equipment. And the dynamic analysis capability of the behavior level is lacked.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the technical field of device identification methods, and particularly relates to an identity authentication method and system based on devices. Background Art

[0002] With the wide deployment of Internet of Things devices, large-scale edge devices, and industrial intelligent terminals, device access authentication has become a core link to ensure system security, network trust, and data trust. In practical applications, the unique identification information of devices is widely used for device identity registration and identification. However, with the complexity of the device usage environment and the development of attack technologies, the method of relying solely on static unique identification for identity authentication gradually exposes problems such as insufficient security, poor anti-tampering ability, and limited recognition accuracy.

[0003] In the prior art, device identity authentication mainly relies on identity feature values generated locally by the device. After calculating the device identification information through an encryption hash algorithm, an identity authentication request is generated, and the identity authentication server conducts comparison and verification.

[0004] However, the existing methods have the problems that the current device identity authentication mechanism is mostly a one-time static comparison, lacking the ability of dynamic analysis at the behavioral level, and generally adopting a "direct rejection" strategy after authentication failure, without deeply analyzing the access behavior patterns of devices. Summary of the Invention

[0005] The purpose of the embodiments of the present invention is to provide an identity authentication method based on devices, aiming to solve the problems proposed in the third part of the background art.

[0006] The embodiments of the present invention are implemented as follows. An identity authentication method based on devices, the method includes:

[0007] Obtain the unique identification information of the target device, where the unique identification information includes the hardware serial number, MAC address, and firmware version information of the device;

[0008] Perform a hash calculation on the device unique identification information to generate an identity feature value, send an identity authentication request to the server, obtain the registered device data, and match the registered device data with the identity authentication request;

[0009] Obtain the device public key stored in the server according to the matching result, calculate the feature hash value of the registered device data and the feature hash value in the identity authentication request, and determine whether the identity of the target device is legal according to the comparison result;

[0010] Compare the access request pattern with the basic pattern, determine the abnormal situation according to the comparison result, determine the abnormal score according to the abnormal situation, and if the abnormal score is higher than the threshold, send a temporary identity authentication factor to the target device.

[0011] Preferably, the steps of performing a hash calculation on the unique device identification information to generate an identity feature value, sending an identity authentication request to the server, obtaining the registered device data, and matching the registered device data with the identity authentication request specifically include:

[0012] Generate an identity authentication request according to the unique identification information. The identity authentication generation method uses the SHA-256 encryption hash algorithm to perform a hash calculation on the unique device identification information;

[0013] Generate an identity feature value. The identity authentication request includes the unique identification information and the current timestamp. Send the identity authentication request to the server, and the server is used to parse the identity authentication request and extract the unique identification information of the target device;

[0014] Obtain the registered device data. The registered device data is used to provide a credible basis for device identity authentication and serve as a reference benchmark for subsequent behavior monitoring, anomaly identification, and security auditing, and match the registered device data with the identity authentication request.

[0015] Preferably, the steps of obtaining the device public key stored in the server according to the matching result, calculating the feature hash value of the registered device data and the feature hash value in the identity authentication request, and determining whether the identity of the target device is legal according to the comparison result specifically include:

[0016] Obtain the matching result. The matching result includes retrieving the matching registered device data, and obtain the device public key stored in the server according to the matching result;

[0017] Calculate the feature hash value of the registered device data and the feature hash value in the identity authentication request to obtain the first hash value and the second hash value respectively, and compare the first hash value and the second hash value;

[0018] Obtain the comparison result, and determine whether the identity of the target device is legal according to the comparison result. If it is determined to be legal, send an identity authentication success message to the target device.

[0019] Preferably, the steps of comparing the access request pattern with the basic pattern, determining the abnormal situation according to the comparison result, determining the abnormal score according to the abnormal situation, and sending a temporary identity authentication factor to the target device if the abnormal score is higher than the threshold specifically include:

[0020] If it is determined to be illegal, obtain the access request pattern of the target device. The access request pattern includes the historical access IP, the device running environment, the access time interval, and the access request type;

[0021] Compare the access request mode with the basic mode, where the basic mode is the legitimate target device under normal circumstances, obtain the comparison result, determine the abnormal situation based on the comparison result, and determine the abnormal score based on the abnormal situation;

[0022] Compare the abnormal score with the threshold. If the abnormal score is higher than the threshold, send a temporary identity authentication factor to the target device and receive the target device confirmation information.

[0023] Preferably, the temporary identity authentication factor includes a security verification code.

[0024] Another object of the embodiments of the present invention is to provide an identity authentication system based on a device, and the system includes:

[0025] A unique identification information module that obtains the unique identification information of the target device, and the unique identification information includes the hardware serial number, MAC address, and firmware version information of the device;

[0026] An identity authentication module that performs a hash calculation on the device unique identification information to generate an identity feature value, sends an identity authentication request to the server, obtains the registered device data, and matches the registered device data with the identity authentication request;

[0027] A target device identity confirmation module that obtains the device public key stored in the server according to the matching result, calculates the characteristic hash value of the registered device data and the characteristic hash value in the identity authentication request, and determines whether the target device identity is legal according to the comparison result;

[0028] A temporary identity authentication factor module that compares the access request mode with the basic mode, determines the abnormal situation according to the comparison result, determines the abnormal score according to the abnormal situation, and if the abnormal score is higher than the threshold, sends a temporary identity authentication factor to the target device.

[0029] Preferably, the identity authentication module includes:

[0030] A hash calculation unit that generates an identity authentication request according to the unique identification information, and the identity authentication generation method uses the SHA-256 encryption hash algorithm to perform a hash calculation on the device unique identification information;

[0031] An identity feature value unit that generates an identity feature value, and the identity authentication request includes the unique identification information and the current timestamp, and sends the identity authentication request to the server, and the server is used to parse the identity authentication request and extract the unique identification information of the target device;

[0032] An identity authentication unit that obtains the registered device data, and the registered device data is used to provide a credible basis for device identity authentication and serve as a reference benchmark for subsequent behavior monitoring, abnormal identification, and security auditing, and matches the registered device data with the identity authentication request.

[0033] Preferably, the target device identity confirmation module includes:

[0034] A matching unit that obtains a matching result. The matching result includes retrieving matching registered device data, and obtains the device public key stored in the server according to the matching result;

[0035] A hash value comparison unit that calculates the characteristic hash value of the registered device data and the characteristic hash value in the identity authentication request, respectively obtains a first hash value and a second hash value, and compares the first hash value and the second hash value;

[0036] A target device identity confirmation unit that obtains the comparison result, determines whether the identity of the target device is legal according to the comparison result. If it is determined to be legal, it sends an identity authentication success message to the target device.

[0037] Preferably, the temporary identity authentication factor module includes:

[0038] An access request unit that, if it is determined to be illegal, obtains the access request mode of the target device. The access request mode includes historical access IP, device operating environment, access time interval, and access request type;

[0039] An abnormal score unit that compares the access request mode with the basic mode. The basic mode is a legal target device under normal circumstances, obtains the comparison result, determines the abnormal situation according to the comparison result, and determines the abnormal score according to the abnormal situation;

[0040] A temporary identity authentication factor unit that compares the abnormal score with a threshold. If the abnormal score is higher than the threshold, it sends a temporary identity authentication factor to the target device and receives the target device confirmation information.

[0041] Preferably, the temporary identity authentication factor includes a security verification code.

[0042] An identity authentication method based on a device provided by an embodiment of the present invention obtains the unique identification information of a target device. The unique identification information includes the hardware serial number, MAC address, and firmware version information of the device. An identity authentication request is generated based on the unique identification information. The unique identification information of the device is subjected to a hash calculation to generate an identity feature value. The identity authentication request is sent to a server, and the registered device data is obtained. The registered device data is matched with the identity authentication request to obtain a matching result. Based on the matching result, the device public key stored in the server is obtained. The characteristic hash value of the registered device data and the characteristic hash value in the identity authentication request are calculated to obtain a first hash value and a second hash value respectively. The first hash value and the second hash value are compared to obtain a comparison result. Based on the comparison result, it is determined whether the identity of the target device is legal. If it is determined to be illegal, the access request mode of the target device is obtained, and the access request mode is compared with the basic mode. Based on the comparison result, an abnormal situation is determined. Based on the abnormal situation, an abnormal score is determined. The abnormal score is compared with a threshold. If the abnormal score is higher than the threshold, a temporary identity authentication factor is sent to the target device, and the target device confirmation information is received, solving the problem that in the existing device authentication process, the identity of the device cannot be compared multiple times, and at the same time, an early warning cannot be given in a timely manner when an abnormal situation occurs. BRIEF DESCRIPTION OF THE DRAWINGS

[0043] Figure 1 It is a flowchart of an identity authentication method based on a device provided by an embodiment of the present invention;

[0044] Figure 2 It is a flowchart of the steps of performing a hash calculation on the unique identification information of the device, sending an identity authentication request to the server, and matching the registered device data with the identity authentication request provided by an embodiment of the present invention;

[0045] Figure 3 It is a flowchart of the steps of calculating the characteristic hash value of the registered device data and the characteristic hash value in the identity authentication request, and determining whether the identity of the target device is legal based on the comparison result provided by an embodiment of the present invention;

[0046] Figure 4 It is a flowchart of the steps of comparing the access request mode with the basic mode and determining the abnormal score based on the abnormal situation provided by an embodiment of the present invention;

[0047] Figure 5 It is an architecture diagram of an identity authentication system based on a device provided by an embodiment of the present invention;

[0048] Figure 6 It is an architecture diagram of the identity authentication module provided by an embodiment of the present invention;

[0049] Figure 7 It is an architecture diagram of the target device identity confirmation module provided by an embodiment of the present invention;

[0050] Figure 8 This is the architecture diagram of the temporary identity authentication factor module provided by the embodiments of the present invention. Specific embodiments

[0051] In order to make the objectives, technical solutions and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.

[0052] It can be understood that the terms "first", "second", etc. used in the present application may be used herein to describe various elements, but unless otherwise specified, these elements are not limited by these terms. These terms are only used to distinguish a first element from another element. For example, without departing from the scope of the present application, the first xx script may be referred to as the second xx script, and similarly, the second xx script may be referred to as the first xx script.

[0053] As Figure 1 shown, a device-based identity authentication method provided by the embodiments of the present invention includes:

[0054] S100. Obtain the unique identification information of the target device, where the unique identification information includes the hardware serial number, MAC address and firmware version information of the device.

[0055] In this step, obtaining the unique identification information of the target device is a basic step for realizing device identity authentication. The unique identification information includes, but is not limited to, the hardware serial number, MAC address and firmware version information of the device. Different types of unique identification information reflect different attributes of the device at the physical layer, network layer and system layer, which helps to accurately identify the device identity from multiple dimensions;

[0056] The hardware serial number is the unique identification burned into the device hardware by the device manufacturer during the production process, generally stored in the read-only area of the device motherboard or storage chip, and cannot be modified casually, with strong uniqueness and non-forgeability;

[0057] The MAC address is the unique address burned when the network card leaves the factory, used to identify the device identity during network communication, with global uniqueness;

[0058] The firmware version information refers to the version number of the system firmware currently running on the device, usually used to identify the integrity and consistency of the device operating environment.

[0059] S200. Perform a hash calculation on the device unique identification information to generate an identity feature value, send an identity authentication request to the server, obtain the registered device data, and match the registered device data with the identity authentication request.

[0060] In this step, the unique identifier information of the device is hashed. To achieve secure authentication of the device identity, the unique identifier information of the target device needs to be hashed to generate an identity feature value, construct an identity authentication request, and send it to the identity authentication server. The server retrieves the registered device data and makes a comparison to complete the confirmation of the device identity's legitimacy. This process involves multiple technical details;

[0061] To avoid plaintext transmission and improve data consistency and security, it is necessary to calculate through an encrypted hash algorithm to generate an identity feature value. After generating the identity feature value, the device constructs an identity authentication request packet and sends it to the identity authentication server through a secure channel;

[0062] After receiving the authentication request, the identity authentication server retrieves from its registered device database whether there is corresponding registered device data. The key field of the registered device data is the pre-stored device identity hash value.

[0063] S300, obtain the device public key stored in the server according to the matching result, calculate the feature hash value of the registered device data and the feature hash value in the identity authentication request, and determine whether the target device identity is legal according to the comparison result.

[0064] In this step, obtain the device public key stored in the server according to the matching result. After the identity authentication server receives the identity authentication request sent by the target device and successfully matches the registered device data, it needs to further obtain the device public key stored in the server to verify the identity feature value in the authentication request to judge whether the target device identity is;

[0065] It is completed by calculating the feature hash value of the registered device data and comparing it with the feature hash value carried in the request to ensure that the authentication result has authenticity, anti-tampering ability, and anti-forgery ability.

[0066] S400, compare the access request pattern with the basic pattern, determine the abnormal situation according to the comparison result, determine the abnormal score according to the abnormal situation. If the abnormal score is higher than the threshold, send a temporary identity authentication factor to the target device.

[0067] In this step, compare the access request pattern with the basic pattern. During the device identity authentication process, it not only relies on static identification information (such as hash values, signatures), but also introduces an access request behavior pattern comparison mechanism to enhance the system's ability to identify device disguise, cloning, and abnormal behaviors;

[0068] By comparing the current access request pattern of the target device with the "basic behavior pattern" extracted during the registration phase or historical behavior, analyzing it, calculating an anomaly score based on the deviation degree, and if the score is higher than the set threshold, triggering a security response measure, that is, sending a temporary identity authentication factor to initiate a multi-round interactive authentication process to further confirm the device identity.

[0069] As Figure 2 shown, as a preferred embodiment of the present invention, the steps of performing a hash calculation on the device unique identification information to generate an identity feature value, sending an identity authentication request to the server, and obtaining the registered device data and matching the registered device data with the identity authentication request specifically include:

[0070] S201, generating an identity authentication request according to the unique identification information, and the identity authentication generation method uses the SHA-256 encryption hash algorithm to perform a hash calculation on the device unique identification information.

[0071] In this step, an identity authentication request is generated according to the unique identification information. The generation of the identity authentication request depends on performing a hash calculation on the unique identification information of the target device to construct an identity feature value of the device. This process is completed using the SHA-256 encryption hash algorithm. SHA-256 is a secure and irreversible encryption hash algorithm, with collision resistance and anti-tampering properties, capable of ensuring the integrity and confidentiality of device identity data during transmission and verification;

[0072] The unique identification information of the device includes multiple dimensions. To ensure structured processing, each field needs to be concatenated into a raw identity data string in a unified format. When concatenating, the field order and delimiter should be kept consistent to avoid inconsistent hash results due to inconsistent formats, and then it is encrypted using SHA-256. SHA-256 will perform multiple rounds of bit operations and data expansion on the input string, and output an irreversible 256-bit (64-bit hexadecimal) hash value;

[0073] Based on the calculated device identity feature value, combined with the current timestamp and digital signature, an identity authentication request structure is constructed. Assuming the current timestamp is 2025-03-26T15:30:20Z, the device uses the private key to sign device_hash ||timestamp, and the generated signature result is ab3f...91c8.

[0074] S202, generating an identity feature value, the identity authentication request includes the unique identification information and the current timestamp, and sending the identity authentication request to the server, and the server is used to parse the identity authentication request and extract the unique identification information of the target device.

[0075] In this step, an identity feature value is generated. To achieve a trusted authentication of the device identity, first, an identity feature value is generated based on the unique identification information of the target device, and an identity authentication request is constructed, which includes the unique identification information of the device and the current timestamp. After receiving the identity authentication request, the server will parse it, extract the device identification information, and execute a matching verification process to confirm the legitimacy of the device identity;

[0076] Send an identity authentication request to the server. The identity authentication request is initiated actively by the device, used to indicate its identity to the server and request authentication permission. The authentication request contains the identity feature value and the current timestamp. The device sends the above request to the interface address specified by the identity authentication server through a preset secure communication protocol (such as HTTPS, TLS).

[0077] S203, Obtain the registered device data. The registered device data is used to provide a trusted basis for device identity authentication and serve as a reference benchmark for subsequent behavior monitoring, anomaly recognition, and security auditing, and match the registered device data with the identity authentication request.

[0078] In this step, obtain the registered device data. Obtaining the registered device data is an important link in implementing device identity authentication. The registered device data is a set of trusted data submitted by the device and stored by the identity authentication server when the target device first accesses the platform or system, and is used for identity comparison and behavior verification in subsequent authentication processes. The registered device data is not only used to verify the legitimacy of the device identity but also serves as a reference benchmark for subsequent behavior monitoring, anomaly recognition, and security auditing;

[0079] After receiving the identity authentication request, the server first extracts the identity feature value in the request as a query condition and enters the registered device database for retrieval. If the hash value exists, it is considered that the device has been successfully registered. If no matching item is found, it is regarded as an illegal device or an unregistered device. After the identity authentication request arrives, the server executes the identity hash comparison and device status verification process.

[0080] As Figure 3 shown, as a preferred embodiment of the present invention, the step of obtaining the device public key stored in the server according to the matching result, calculating the feature hash value of the registered device data and the feature hash value in the identity authentication request, and determining whether the identity of the target device is legal according to the comparison result specifically includes:

[0081] S301, Obtain the matching result. The matching result includes retrieving the matching registered device data, and obtain the device public key stored in the server according to the matching result.

[0082] In this step, obtain the matching result. After the identity authentication server receives the identity authentication request initiated by the target device, it first parses the device identity feature value carried in the request and retrieves it in the registered device database. The core objective of the retrieval process is to determine whether there is registered device data that exactly matches this identity feature value;

[0083] If it exists, it is regarded as "matching successfully"; this matching result not only includes the complete registered device data retrieved, but also provides the basic conditions for subsequent operations such as obtaining the device public key and verifying the identity legality.

[0084] S302, calculate the feature hash values of the registered device data and the feature hash value in the identity authentication request to obtain the first hash value and the second hash value respectively, and compare the first hash value and the second hash value.

[0085] In this step, calculate the feature hash value of the registered device data and the feature hash value in the identity authentication request to further verify the authenticity of the target device identity. After the identity authentication request and the registered device data match successfully, the server needs to recalculate a set of identity feature hash values (i.e., the first hash value) based on the registered device data and compare it with the device feature hash value (i.e., the second hash value) carried in the identity authentication request one by one. This process ensures that the unique identification information provided by the device during the request authentication has not been forged or tampered with, and has extremely strong anti-counterfeiting and anti-tampering capabilities;

[0086] By performing a hash calculation on the unique identification information in the registered device data (generating the first hash value) and comparing it with the device feature hash value (the second hash value) carried in the identity authentication request one by one, it is the core technical link to ensure the authenticity, integrity, and consistency of the device identity. This process constitutes an important defense line of the identity authentication system in the present invention, with both technical rigor and security defense capabilities.

[0087] S303, obtain the comparison result, determine whether the identity of the target device is legal according to the comparison result. If it is determined to be legal, send an identity authentication success message to the target device.

[0088] In this step, obtain the comparison result. After the server completes the comparison of the first hash value and the second hash value, it can judge whether the identity of the target device is legal based on the comparison result. If the comparison result shows that the identity feature value provided by the device is consistent with the identity feature value calculated from the registered device data, and there are no abnormalities in the cooperation of timestamp verification and signature verification, it can be determined that the identity of the target device is legal;

[0089] The server will return an identity authentication success message to the target device and record this authentication event for auditing and behavior tracking. By comparing the first hash value and the second hash value, and combining signature verification and timestamp verification, it is possible to accurately determine whether the identity of the target device is legal, and send the identity authentication result to the device in a timely and standardized manner after successful authentication.

[0090] As Figure 4 shown, as a preferred embodiment of the present invention, the steps of comparing the access request mode with the basic mode, determining the abnormal situation according to the comparison result, determining the abnormal score according to the abnormal situation, and if the abnormal score is higher than the threshold, sending a temporary identity authentication factor to the target device specifically include:

[0091] S401, if it is determined to be illegal, obtain the access request mode of the target device, and the access request mode includes historical access IP, device operating environment, access time interval, and access request type.

[0092] In this step, if it is determined to be illegal, when there are abnormalities in the target device identity authentication process, such as hash value mismatch, signature verification failure, timestamp invalidity, or serious deviation of behavior patterns, etc., resulting in the server determining that the identity of the target device is illegal, the system will further obtain the access request mode of the target device;

[0093] so as to analyze whether its access behavior has risks of forgery, simulation, cloning, or attack. The access request mode includes, but is not limited to, multi-dimensional behavior information such as historical access IP, device operating environment, access time interval, and access request type;

[0094] After the device identity authentication fails, obtaining the access request mode including parameters such as historical access IP, operating environment, time interval, and request type helps the system to judge whether there are spoofing attacks, script simulations, or illegal cloning behaviors from the behavioral level, and provides technical support for dynamic security response and risk control mechanisms.

[0095] S402, compare the access request mode with the basic mode, where the basic mode is a legal target device under normal circumstances, obtain the comparison result, determine the abnormal situation according to the comparison result, and determine the abnormal score according to the abnormal situation.

[0096] In this step, comparing the access request mode with the basic mode, in order to further improve the intelligence and security of device identity authentication, an access behavior pattern comparison mechanism is introduced. When there are doubts about the device identity (such as identity authentication failure or signature abnormality), it not only relies on static identifiers (such as device ID or hash value) for authentication;

[0097] By comparing the current access request mode of the device with the basic behavior mode, the basic mode refers to the "standard behavior portrait" presented by the device during the registration or long-term stable use in the normal operation state. This portrait is automatically extracted and learned by the system or manually set by the administrator, and has the uniqueness and stability of the device individual, and can identify potential disguised, cloned or abnormal operation behaviors. The system extracts abnormal situations based on the comparison results, and further calculates the abnormal score, providing a basis for whether to trigger the dynamic authentication mechanism or security response.

[0098] S403. Compare the abnormal score with the threshold. If the abnormal score is higher than the threshold, send a temporary identity authentication factor to the target device. The temporary identity authentication factor includes a security verification code, and receive the confirmation information of the target device.

[0099] In this step, compare the abnormal score with the threshold. When the abnormal score obtained by comparing the access request mode with the basic behavior mode exceeds the preset threshold, the system does not immediately reject the access request of the target device, but further initiates a dynamic identity confirmation operation by sending a temporary identity authentication factor. This process belongs to a multi-round interactive authentication mechanism, and the core is to verify whether the device is the registered device body with a higher security level, avoiding misjudging the device as an abnormal source due to environmental or network factors;

[0100] The temporary identity authentication factor includes a security verification code. The target device needs to return the correct confirmation information within the specified time, and the system then determines whether to allow the device to continue communicating according to the confirmation response result.

[0101] As Figure 5 shown, a device-based identity authentication system provided by an embodiment of the present invention includes:

[0102] The unique identification information module 100 is used to obtain the unique identification information of the target device. The unique identification information includes the hardware serial number, MAC address and firmware version information of the device.

[0103] In this system, the unique identification information module 100 obtains the unique identification information of the target device. Obtaining the unique identification information of the target device is a basic step for realizing device identity authentication. The unique identification information includes but is not limited to the hardware serial number, MAC address and firmware version information of the device. Different types of unique identification information reflect different attributes of the device at the physical layer, network layer and system layer, which helps to accurately identify the device identity from multiple dimensions;

[0104] The hardware serial number is the unique identification burned into the device hardware by the device manufacturer during the production process, generally stored in the read-only area of the device motherboard or storage chip, and cannot be modified casually, with strong uniqueness and non-forgeability;

[0105] The MAC address is the unique address burned into the network card at the factory, used to identify the device's identity during network communication, and has global uniqueness;

[0106] The firmware version information refers to the version number of the system firmware currently running on the device, and is usually used to identify the integrity and consistency of the device's operating environment.

[0107] The identity authentication module 200 is used to perform a hash calculation on the device's unique identification information, generate an identity feature value, send an identity authentication request to the server, obtain the registered device data, and match the registered device data with the identity authentication request.

[0108] In this system, the identity authentication module 200 performs a hash calculation on the device's unique identification information. To achieve secure identification of the device's identity, it is necessary to perform a hash calculation on the unique identification information of the target device, generate an identity feature value, construct an identity authentication request and send it to the identity authentication server. The server obtains the registered device data and performs a comparison to complete the confirmation of the legitimacy of the device's identity. This process involves multiple technical details;

[0109] To avoid plaintext transmission and improve data consistency and security, it is necessary to perform a calculation through an encryption hash algorithm to generate an identity feature value. After generating the identity feature value, the device constructs an identity authentication request packet and sends it to the identity authentication server through a secure channel;

[0110] After receiving the authentication request, the identity authentication server retrieves from its registered device database whether there is corresponding registered device data. The key field of the registered device data is the device identity hash value stored in advance.

[0111] The target device identity confirmation module 300 is used to obtain the device public key stored in the server according to the matching result, calculate the feature hash value of the registered device data and the feature hash value in the identity authentication request, and determine whether the target device identity is legal according to the comparison result.

[0112] In this system, the target device identity confirmation module 300 obtains the device public key stored in the server according to the matching result. After the identity authentication server receives the identity authentication request sent by the target device and successfully matches the registered device data, it needs to further obtain the device public key stored in the server to verify the identity feature value in the authentication request to determine whether the target device identity is;

[0113] It is completed by calculating the feature hash value of the registered device data and comparing it with the feature hash value carried in the request to ensure that the authentication result has authenticity, anti-tampering ability and anti-forgery ability.

[0114] The temporary identity authentication factor module 400 is used to compare the access request pattern with the basic pattern, determine the abnormal situation according to the comparison result, determine the abnormal score according to the abnormal situation, and send the temporary identity authentication factor to the target device if the abnormal score is higher than the threshold.

[0115] In this system, the temporary identity authentication factor module 400 compares the access request pattern with the basic pattern. During the device identity authentication process, it not only relies on static identification information (such as hash values, signatures), but also introduces an access request behavior pattern comparison mechanism to improve the system's ability to identify device disguise, cloning, and abnormal behaviors.

[0116] By analyzing the comparison between the current access request pattern of the target device and the "basic behavior pattern" extracted during the registration phase or historical behaviors, calculate the abnormal score according to the deviation degree. If the score is higher than the set threshold, trigger the security response measure, that is, send the temporary identity authentication factor to start a multi-round interactive authentication process to further confirm the device identity.

[0117] Such as Figure 6 As shown, as a preferred embodiment of the present invention, the identity authentication module 200 includes:

[0118] The hash calculation unit 201 is used to generate an identity authentication request according to the unique identification information. The identity authentication generation method uses the SHA-256 encryption hash algorithm to perform a hash calculation on the device unique identification information.

[0119] In this module, the hash calculation unit 201 generates an identity authentication request according to the unique identification information. The generation of the identity authentication request depends on performing a hash calculation on the unique identification information of the target device to construct the identity characteristic value of the device. This process is completed using the SHA-256 encryption hash algorithm. SHA-256 is a secure and irreversible encryption hash algorithm, with collision resistance and anti-tampering properties, which can ensure the integrity and confidentiality of device identity data during transmission and verification.

[0120] The unique identification information of the device includes multiple dimensions. To ensure structured processing, each field needs to be concatenated into a raw identity data string in a unified format. When concatenating, the field order and delimiter should be kept consistent to avoid inconsistent hash results due to inconsistent formats, and then perform encryption processing using SHA-256. SHA-256 will perform multiple rounds of bit operations and data expansion on the input string, and output a 256-bit (64-bit hexadecimal) irreversible hash value.

[0121] Based on the calculated device identity feature value, combined with the current timestamp and digital signature, construct an identity authentication request structure. Assume the current timestamp is 2025-03-26T15:30:20Z, and the device uses the private key to sign device_hash || timestamp, generating a signature result of ab3f...91c8.

[0122] The identity feature value unit 202 is used to generate an identity feature value. The identity authentication request includes unique identification information and the current timestamp, and sends the identity authentication request to the server, which is used to parse the identity authentication request and extract the unique identification information of the target device.

[0123] In this module, the identity feature value unit 202 generates an identity feature value. To achieve trusted authentication of the device identity, first generate an identity feature value based on the unique identification information of the target device, and construct an identity authentication request, which includes the unique identification information of the device and the current timestamp. After receiving the identity authentication request, the server will parse it, extract the device identification information, and execute a matching verification process to confirm the legality of the device identity;

[0124] Send the identity authentication request to the server. The identity authentication request is initiated by the device actively and is used to indicate its identity to the server and request authentication permission. The authentication request contains the identity feature value and the current timestamp, and the device sends the above request to the interface address specified by the identity authentication server through a preset secure communication protocol (such as HTTPS, TLS).

[0125] The identity authentication unit 203 is used to obtain the registered device data. The registered device data is used to provide a trusted basis for device identity authentication and serve as a reference benchmark for subsequent behavior monitoring, anomaly identification, and security auditing, and match the registered device data with the identity authentication request.

[0126] In this module, the identity authentication unit 203 obtains the registered device data. Obtaining the registered device data is an important link in implementing device identity authentication. The registered device data is a set of trusted data submitted by the device and stored by the identity authentication server when the target device first accesses the platform or system, and is used for identity comparison and behavior verification in subsequent authentication processes. The registered device data is not only used to verify the legality of the device identity but also serves as a reference benchmark for subsequent behavior monitoring, anomaly identification, and security auditing;

[0127] After receiving the identity authentication request, the server first extracts the identity feature value in the request as a query condition, enters the registered device database for retrieval. If the hash value exists, it is considered that the device has been successfully registered. If there is no matching item, it is regarded as an illegal device or an unregistered device. After the identity authentication request arrives, the server executes the identity hash comparison and device status verification process.

[0128] As shown Figure 7 in the following, as a preferred embodiment of the present invention, the target device identity confirmation module 300 includes:

[0129] A matching unit 301, configured to obtain a matching result, where the matching result includes retrieved registered device data that matches, and obtain the device public key stored in the server according to the matching result.

[0130] In this module, the matching unit 301 obtains a matching result. After the identity authentication server receives an identity authentication request initiated by the target device, it first parses the device identity feature value carried in the request and retrieves it in the registered device database. The core objective of the retrieval process is to determine whether there is registered device data that exactly matches the identity feature value;

[0131] If it exists, it is regarded as "matching successfully"; this matching result not only includes the retrieved complete registered device data, but also provides a basic condition for subsequent operations such as obtaining the device public key and verifying the legitimacy of the identity.

[0132] A hash value comparison unit 302, configured to calculate the characteristic hash value of the registered device data and the characteristic hash value in the identity authentication request to obtain a first hash value and a second hash value respectively, and compare the first hash value and the second hash value.

[0133] In this module, the hash value comparison unit 302 calculates the characteristic hash value of the registered device data and the characteristic hash value in the identity authentication request to further verify the authenticity of the target device identity. After the identity authentication request and the registered device data match successfully, the server needs to recalculate a set of identity characteristic hash values (i.e., the first hash value) based on the registered device data and compare it with the device characteristic hash value (i.e., the second hash value) carried in the identity authentication request one by one. This process ensures that the unique identification information provided by the device during the request for authentication has not been forged or tampered with, and has a strong anti-counterfeiting and anti-tampering ability;

[0134] By performing a hash calculation on the unique identification information in the registered device data (generating the first hash value) and comparing it with the device characteristic hash value (the second hash value) carried in the identity authentication request one by one, it is the core technical link to ensure the authenticity, integrity and consistency of the device identity. This process constitutes an important defense line of the identity authentication system in the present invention, combining technical rigor and security defense capabilities.

[0135] A target device identity confirmation unit 303, configured to obtain a comparison result, determine whether the identity of the target device is legal according to the comparison result, and if it is determined to be legal, send an identity authentication success message to the target device.

[0136] In this module, the target device identity confirmation unit 303 obtains the comparison result. After the server completes the comparison of the first hash value and the second hash value, it can determine whether the identity of the target device is legal based on the comparison result. If the comparison result shows that the identity feature value provided by the device is consistent with the identity feature value calculated from the registered device data, and there are no abnormalities in the cooperation of timestamp verification and signature verification, it can be determined that the identity of the target device is legal;

[0137] The server will return an identity authentication success message to the target device and record this authentication event for auditing and behavior tracking. By comparing the first hash value and the second hash value, and combining signature verification and timestamp verification, it can accurately determine whether the identity of the target device is legal, and send the identity authentication result to the device in a timely and standardized manner after successful authentication.

[0138] As Figure 8 shown, as a preferred embodiment of the present invention, the temporary identity authentication factor module 400 includes:

[0139] An access request unit 401, which is used to obtain the access request mode of the target device if it is determined to be illegal. The access request mode includes historical access IP, device operating environment, access time interval, and access request type.

[0140] In this module, if the access request unit 401 determines that it is illegal, when there are abnormalities in the target device identity authentication process, such as hash value mismatch, signature verification failure, timestamp invalidity, or serious deviation in behavior patterns, etc., resulting in the server determining that the identity of the target device is illegal, the system will further obtain the access request mode of the target device;

[0141] So as to analyze whether its access behavior has risks of forgery, simulation, cloning, or attack. The access request mode includes, but is not limited to, multi-dimensional behavior information such as historical access IP, device operating environment, access time interval, and access request type;

[0142] After the device identity authentication fails, obtaining the access request mode including parameters such as historical access IP, operating environment, time interval, and request type helps the system to judge whether there are spoofing attacks, script simulations, or illegal cloning behaviors from the behavioral level, providing technical support for dynamic security response and risk control mechanisms.

[0143] An anomaly scoring unit 402, which is used to compare the access request mode with the basic mode. The basic mode is a legal target device under normal circumstances, obtain the comparison result, determine the anomaly situation according to the comparison result, and determine the anomaly score according to the anomaly situation.

[0144] In this module, the anomaly scoring unit 402 compares the access request pattern with the basic pattern. To further enhance the intelligence and security of device identity authentication, an access behavior pattern comparison mechanism is introduced. When there are doubts about the device identity (such as identity authentication failure or signature anomaly), it does not rely solely on static identifiers (such as device ID or hash value) for authentication;

[0145] By comparing the current access request pattern of the device with the basic behavior pattern, the basic behavior pattern refers to the "standard behavior profile" presented by the device during the registration or long-term stable use process under normal operating conditions. This profile is automatically extracted, learned by the system, or manually set by the administrator, and has the uniqueness and stability of the device individual, and can identify potential disguise, cloning, or abnormal operation behaviors. The system extracts abnormal situations based on the comparison results and further calculates the anomaly score, providing a basis for whether to trigger the dynamic authentication mechanism or security response.

[0146] The temporary identity authentication factor unit 403 is used to compare the anomaly score with the threshold. If the anomaly score is higher than the threshold, it sends a temporary identity authentication factor to the target device. The temporary identity authentication factor includes a security verification code and receives the target device confirmation information.

[0147] In this module, the temporary identity authentication factor unit 403 compares the anomaly score with the threshold. When the anomaly score obtained by comparing the access request pattern with the basic behavior pattern exceeds the preset threshold, the system does not immediately reject the access request of the target device, but further initiates a dynamic identity confirmation operation by sending a temporary identity authentication factor. This process belongs to a multi-round interactive authentication mechanism, and the core is to verify whether the device is the registered device body with a higher security level, avoiding misjudging the device as an abnormal source due to environmental or network factors;

[0148] The temporary identity authentication factor includes a security verification code, and the target device needs to return the correct confirmation information within the specified time, and the system then judges whether to allow the device to continue communicating according to the confirmation response result.

[0149] In one embodiment, a computer device is proposed. The computer device includes a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented:

[0150] Obtain the unique identification information of the target device, where the unique identification information includes the hardware serial number, MAC address, and firmware version information of the device;

[0151] Perform a hash calculation on the device unique identification information to generate an identity feature value, send an identity authentication request to the server, obtain the registered device data, and match the registered device data with the identity authentication request;

[0152] Obtain the device public key stored in the server according to the matching result, calculate the characteristic hash value of the registered device data and the characteristic hash value in the identity authentication request, and determine whether the identity of the target device is legal according to the comparison result;

[0153] Compare the access request pattern with the basic pattern, determine the abnormal situation according to the comparison result, determine the abnormal score according to the abnormal situation, and if the abnormal score is higher than the threshold, send a temporary identity authentication factor to the target device.

[0154] In one embodiment, a computer-readable storage medium is provided. A computer program is stored on the computer-readable storage medium. When the computer program is executed by a processor, the processor is caused to perform the following steps:

[0155] Obtain the unique identification information of the target device, where the unique identification information includes the hardware serial number, MAC address, and firmware version information of the device;

[0156] Perform a hash calculation on the device unique identification information to generate an identity characteristic value, send an identity authentication request to the server, obtain the registered device data, and match the registered device data with the identity authentication request;

[0157] Obtain the device public key stored in the server according to the matching result, calculate the characteristic hash value of the registered device data and the characteristic hash value in the identity authentication request, and determine whether the identity of the target device is legal according to the comparison result;

[0158] Compare the access request pattern with the basic pattern, determine the abnormal situation according to the comparison result, determine the abnormal score according to the abnormal situation, and if the abnormal score is higher than the threshold, send a temporary identity authentication factor to the target device.

[0159] It should be understood that although the steps in the flowcharts of the embodiments of the present invention are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear description in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover, at least a part of the steps in each embodiment may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily executed at the same time, but can be executed at different times. The execution order of these sub-steps or stages is not necessarily sequential, but can be executed alternately or alternately with at least a part of other steps or sub-steps or stages of other steps.

[0160] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The program can be stored in a non-volatile computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the embodiments provided in this application can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.

[0161] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0162] The above embodiments merely represent several implementation manners of the present invention. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the patent of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention should be subject to the appended claims.

[0163] The above is only the preferred embodiment of the present invention and is not used to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention should be included in the protection scope of the present invention.

Claims

1. A device-based identity authentication method, characterized in that: The method comprises: Obtain unique identification information of the target device, the unique identification information including the hardware serial number, MAC address and firmware version information of the device; Perform hash calculation on the unique identification information of the device to generate an identity feature value, send an identity authentication request to the server, obtain the registered device data, and match the registered device data with the identity authentication request; Obtain the device public key stored in the server based on the matching result, calculate the characteristic hash value of the registered device data and the characteristic hash value in the identity authentication request, and determine whether the target device identity is legal based on the comparison result; The access request pattern is compared with the basic pattern, an abnormal situation is determined according to the comparison result, an abnormality score is determined according to the abnormal situation, and if the abnormality score is higher than the threshold, a temporary identity authentication factor is sent to the target device.

2. A device-based identity authentication method according to claim 1, characterized in that: The steps of performing hash calculation on the unique identification information of the device, generating an identity feature value, sending an identity authentication request to the server, obtaining the registered device data, and matching the registered device data with the identity authentication request specifically include: Generate an identity authentication request based on the unique identification information, wherein the identity authentication generation method uses the SHA-256 encrypted hash algorithm to perform hash calculation on the unique identification information of the device; Generate an identity feature value, the identity authentication request includes unique identification information and a current timestamp, and send the identity authentication request to a server, the server is used to parse the identity authentication request and extract the unique identification information of the target device; Obtain registered device data, which is used to provide a credible basis for device identity authentication and serves as a benchmark reference for subsequent behavior monitoring, anomaly identification and security audits to match registered device data with identity authentication requests.

3. The device-based identity authentication method according to claim 1, characterized in that: The steps of obtaining the device public key stored in the server according to the matching result, calculating the characteristic hash value of the registered device data and the characteristic hash value in the identity authentication request, and determining whether the target device identity is legal according to the comparison result specifically include: Obtaining a matching result, wherein the matching result includes retrieving matching registered device data, and obtaining a device public key stored in the server according to the matching result; Calculate the characteristic hash value of the registered device data and the characteristic hash value in the identity authentication request to obtain a first hash value and a second hash value respectively, and compare the first hash value and the second hash value; Obtain the comparison result, and determine whether the target device identity is legal based on the comparison result. If it is determined to be legal, send an identity authentication success message to the target device.

4. The device-based identity authentication method according to claim 1, characterized in that: The step of comparing the access request mode with the basic mode, determining an abnormal situation according to the comparison result, determining an abnormality score according to the abnormal situation, and sending a temporary identity authentication factor to the target device if the abnormality score is higher than a threshold, specifically includes: If it is determined to be illegal, the access request mode of the target device is obtained, and the access request mode includes the historical access IP, device operating environment, access time interval and access request type; Comparing the access request pattern with a basic pattern, where the basic pattern is a legitimate target device under normal circumstances, obtaining a comparison result, determining an abnormal situation according to the comparison result, and determining an abnormality score according to the abnormal situation; The anomaly score is compared with the threshold. If the anomaly score is higher than the threshold, a temporary identity authentication factor is sent to the target device, and confirmation information is received from the target device.

5. A device-based identity authentication method according to claim 4, characterized in that: The temporary identity authentication factor includes a security verification code.

6. A device-based identity authentication system, characterized in that: The system comprises: A unique identification information module is used to obtain the unique identification information of the target device, wherein the unique identification information includes the hardware serial number, MAC address and firmware version information of the device; The identity authentication module performs hash calculation on the unique identification information of the device, generates an identity feature value, sends an identity authentication request to the server, obtains the registered device data, and matches the registered device data with the identity authentication request; The target device identity confirmation module obtains the device public key stored in the server according to the matching result, calculates the characteristic hash value of the registered device data and the characteristic hash value in the identity authentication request, and determines whether the target device identity is legal according to the comparison result; The temporary identity authentication factor module compares the access request mode with the basic mode, determines the abnormal situation according to the comparison result, determines the abnormal score according to the abnormal situation, and sends the temporary identity authentication factor to the target device if the abnormal score is higher than the threshold.

7. The device-based identity authentication system according to claim 6, characterized in that: The identity authentication module comprises: A hash calculation unit generates an identity authentication request according to the unique identification information, wherein the identity authentication generation method adopts the SHA-256 encrypted hash algorithm to perform hash calculation on the unique identification information of the device; An identity feature value unit generates an identity feature value, wherein the identity authentication request includes unique identification information and a current timestamp, and sends the identity authentication request to a server, wherein the server is used to parse the identity authentication request and extract the unique identification information of the target device; The identity authentication unit obtains the registered device data, which is used to provide a credible basis for device identity authentication and serves as a benchmark reference for subsequent behavior monitoring, anomaly identification and security auditing to match the registered device data with the identity authentication request.

8. The device-based identity authentication system according to claim 7, characterized in that: The target device identity confirmation module includes: A matching unit, which obtains a matching result, wherein the matching result includes retrieving matching registered device data, and obtains a device public key stored in the server according to the matching result; A hash value comparison unit, which calculates a characteristic hash value of the registered device data and a characteristic hash value in the identity authentication request, obtains a first hash value and a second hash value respectively, and compares the first hash value and the second hash value; The target device identity confirmation unit obtains the comparison result, and determines whether the target device identity is legal according to the comparison result. If it is determined to be legal, an identity authentication success message is sent to the target device.

9. The device-based identity authentication system according to claim 8, characterized in that: The temporary identity authentication factor module includes: The access request unit obtains the access request mode of the target device if it is determined to be illegal, wherein the access request mode includes the historical access IP, the device operating environment, the access time interval and the access request type; an anomaly scoring unit, comparing the access request mode with a basic mode, where the basic mode is a legitimate target device under normal circumstances, obtaining a comparison result, determining an abnormal situation according to the comparison result, and determining an anomaly score according to the abnormal situation; The temporary identity authentication factor unit compares the anomaly score with the threshold, and if the anomaly score is higher than the threshold, sends the temporary identity authentication factor to the target device and receives confirmation information from the target device.

10. The device-based identity authentication system according to claim 9, characterized in that: The temporary identity authentication factor includes a security verification code.

Citation Information

Patent Citations

  • Authentication method and device of terminal identification equipment, storage medium and equipment

    CN116170228A

  • Equipment identity verification system based on MAC (Media Access Control) address

    CN119696791A

  • Device risk level based on device metadata comparison

    US20220141220A1

Cited By

  • Intelligent cloud box device management and remote operation and maintenance method and system

    CN122554096A

  • Intelligent cloud box device management and remote operation and maintenance method and system

    CN122554096B