Star flash chip isolation and end-to-end encryption Internet of Things management system
Through star flash chip isolation technology and dynamic identity authentication, a secure communication link for IoT devices is built, which solves the problem of IoT devices being easily attacked, and achieves efficient and secure communication protection, ensuring the reliability of device identity authentication and reasonable allocation of resources.
Patent Information
- Application Number
- CN202510738209.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-04
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2045-06-04
AI Technical Summary
IoT devices face challenges in terms of security isolation and communication efficiency. Traditional wireless communications are easily monitored or counterfeited by malicious devices, resulting in data leakage, and identity authentication mechanisms are easily replayed and forged attacks, making it difficult to resist relay attacks and device hijacking.
Using star flash chip isolation technology, a secure communication link is established through physical frequency hopping channels and hardware fingerprint authentication, combining dynamic identity tags and multiple rounds of session recursive authentication, forming an authentication closed loop, dynamically adjusting encryption algorithms and resource allocation, realizing device hardware fingerprint verification and threat level feedback.
Effectively defend against relay attacks and forgery attacks, ensure zero vulnerabilities in device identity authentication, realize intelligent perception and dynamic response of security threats, optimize resource utilization, and ensure timely transmission of critical tasks.
Smart Images

Figure CN120263552A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data security, and specifically to an Internet of Things management system with SparkLink chip isolation and end-to-end encryption. Background Art
[0002] Under the background of the booming development of Internet of Things technology, SparkLink chips, as the core carriers of the new generation of short-range communication technology, are promoting the high-speed interconnection of Internet of Things devices in fields such as industrial control, smart home, and vehicle networking. The SparkLink chip isolation technology constructs a secure communication link independent of the traditional network through physical frequency hopping channels and hardware fingerprint authentication, providing physical-level security isolation at the bottom layer for Internet of Things devices.
[0003] Current Internet of Things management systems face multiple challenges in terms of security isolation and communication efficiency. Traditional wireless communication technologies use fixed frequency bands or simple frequency hopping, which are easily monitored or impersonated by malicious devices, resulting in data leakage or device hijacking. For example, smart home devices may suffer from relay attacks due to non-isolated channels, causing sensitive information such as door lock status and camera images to be stolen. In the identity authentication link, static identity tags and single-round authentication mechanisms are difficult to resist replay attacks and forgery attacks, and attackers can intercept fixed identity information to impersonate legitimate devices to access the system.
[0004] The above problems arise from the heterogeneity of Internet of Things devices, the complexity of the network environment, and the static nature of security mechanisms. For example, in traditional smart home systems, different devices such as smart bulbs, door locks, and cameras share the same communication channel and are not physically isolated. Once a device is invaded, attackers can spread through the channel penetration to the entire network; under the single-round authentication mechanism, attackers can use the captured one-time challenge response data to repeatedly attempt to log in within the valid time, causing the authentication system to collapse. Summary of the Invention
[0005] In view of the above problems existing in the prior art, the present application provides an Internet of Things management system with SparkLink chip isolation and end-to-end encryption.
[0006] The embodiments of the present disclosure provide an Internet of Things management system with SparkLink chip isolation and end-to-end encryption, including
[0007] A SparkLink physical isolation access subsystem, which establishes an isolation communication link through a SparkLink chip based on a physical frequency hopping channel and performs underlying identity confirmation based on the device hardware fingerprint;
[0008] A dynamic identity feature generation subsystem, which generates a session dynamic identity tag based on the current timestamp, the device hardware fingerprint, and the SparkLink channel signal feature;
[0009] The multi-round session recursive authentication subsystem, based on dynamic identity tags, performs multi-round challenge and response recursive interactions to form an authentication closed-loop;
[0010] The authentication risk feedback subsystem detects abnormal responses during the authentication process and calculates the risk intensity to feedback threat level signals;
[0011] The computing power and power consumption adaptive adjustment subsystem dynamically adjusts authentication and encryption algorithms based on the real-time status of smart home devices;
[0012] The session cache management subsystem predicts user behavior and generates session caches in advance;
[0013] The XingShan isolated channel priority scheduling subsystem allocates resources of the channel switched by the current channel establishment unit based on the weight of the task and the pressure of the bandwidth.
[0014] Optionally, the XingShan physical isolation access subsystem includes a channel establishment unit, an identity confirmation unit, and a channel switching control unit;
[0015] The channel establishment unit is used to pre-select the 6GHz frequency band as the communication frequency band, generate a frequency hopping sequence using the chaotic mapping algorithm, switch channels within the 6GHz frequency band according to the generated frequency hopping sequence with a period of 50ms to establish an isolated communication link, and on each channel, expand the signal bandwidth to more than 100MHz through direct sequence spread spectrum technology;
[0016] The identity confirmation unit is used to send the device hardware fingerprint stored in the XingShan chip to the cloud server using the channel switched by the current channel establishment unit when the smart home device is connected to the smart home system network. The cloud server uses the Hamming distance to verify the difference degree between the device hardware fingerprint and the fingerprint stored in the cloud database. If the Hamming distance does not exceed the preset difference threshold, the device hardware fingerprint is considered legal, otherwise it is determined to be illegal;
[0017] The channel switching control unit is used to receive the threat level signal of the authentication risk feedback subsystem. When the threat level signal is at a high threat level, it automatically switches to an advanced frequency hopping sequence. Among them, the advanced frequency hopping sequence adopts a 7-layer pseudo-random code nesting technology and the frequency hopping period is shortened to 20ms.
[0018] Optionally, the dynamic identity feature generation subsystem includes a feature collection unit, a tag generation unit, and a tag verification unit;
[0019] The feature collection unit is used to obtain the XingShan channel signal features according to the channel switched by the current channel establishment unit and generate a unique random number per session according to the hardware random number generator;
[0020] The label generation unit is used to generate a 64-byte dynamic identity label Is by using the SHA-384 hashing algorithm based on the StarFlash channel signal features obtained from the feature acquisition unit and the unique random number per session.
[0021] The label verification unit is used to compare the hash values of the newly generated dynamic identity label and the previous label to obtain the similarity. If the similarity exceeds the pre-set similarity threshold, it triggers the feature acquisition unit to re-acquire features and generate a new label.
[0022] Optionally, the multi-round session recursive authentication subsystem includes a challenge generation unit, a response processing unit, and an authentication closed-loop control unit;
[0023] The challenge generation unit is responsible for generating challenge information for verifying the identity of the smart home device during the multi-round session recursive authentication process. The challenge information includes, in the first round of authentication start, generating a 128-bit random number as the initial challenge, and after the initial challenge is generated, outputting a response value. Using a pseudo-random number generator, with the dynamic identity label of the smart home device as the seed, generating a random number sequence with the same length as the response value output by the initial challenge, performing an exclusive OR operation on each bit of the response value output by the initial challenge and the generated random number to obtain a new binary sequence, and encrypting the exclusive OR result using the master key. The encryption mode adopts the block encryption mode, and the encrypted result is the challenge for the current round;
[0024] The response processing unit is used to receive the challenge for the current round, perform an exclusive OR operation on each bit of the challenge for the current round and the dynamic identity label of the smart home device itself to obtain a new binary sequence, and use the session key as the key to perform HMAC calculation on the exclusive OR result in the response processing unit. The hashing algorithm adopts the SHA-512 hashing algorithm, and the calculation result is the response value of the smart home device to the current challenge, and it is sent to the cloud server for verification to obtain the response result;
[0025] The authentication closed-loop control unit is used to record the time length from sending the challenge to the smart home device to receiving the response from the smart home device during each round of authentication, that is, the time spent for each round of authentication. If the time spent for authentication does not fall within the safe time range or the response result is a verification error, the authentication is immediately terminated and an abnormal signal is sent to the authentication risk feedback subsystem.
[0026] Optionally, the authentication risk feedback subsystem includes an anomaly detection unit, a risk assessment unit, and a signal feedback unit;
[0027] The anomaly detection unit is used to receive anomaly signals, calculate and obtain the response error rate and time offset according to the time spent and response results of each round of authentication collected in the historical time period and in real time, and determine the anomaly response type parameters according to the type of anomaly response. The types of anomaly responses include response timeout, timing anomaly, frequency anomaly, and pattern anomaly;
[0028] The risk assessment unit is used to perform a weighted sum of the response error rate, time offset, and anomaly response type parameters to calculate and obtain the risk intensity;
[0029] The signal feedback unit is used to compare the calculated risk intensity with a preset risk threshold to classify the calculated risk intensity into low-threat level signals, medium-threat level signals, and high-threat level signals. If it is a high-threat level signal, it will be sent to the StarFlash physical isolation access subsystem, the computing power and power consumption adaptive adjustment subsystem, and the session cache management subsystem.
[0030] Optionally, the computing power and power consumption adaptive adjustment subsystem includes a status monitoring unit, a computing power allocation unit, and an algorithm adjustment unit;
[0031] The status monitoring unit is used to obtain the power, computing power load data of the smart home device, and the threat level signal of the authentication risk feedback subsystem in real time;
[0032] The computing power allocation unit is used to dynamically allocate computing power resources when performing authentication tasks when the threat level signal of the authentication risk feedback subsystem changes to obtain the final computing power. The specific way to obtain the final computing power is: collect the real-time status of the smart home device in real time to obtain the remaining power, CPU temperature, available memory, and risk intensity, and calculate and obtain the dynamic adjustment factor according to the real-time status of the smart home device, and combine the basic computing power requirements to calculate and obtain the final computing power; and when the remaining power of the smart home device is lower than 10%, turn off the non-critical authentication rounds in the multi-round session recursive authentication subsystem;
[0033] The algorithm adjustment unit is used to dynamically switch the encryption algorithm according to the threat level signal of the smart home device. If the remaining power is lower than 10% and the threat level signal is a low-threat level signal, switch the AES-256 encryption algorithm to the AES-128 encryption algorithm.
[0034] Optionally, the session cache management subsystem includes a behavior prediction unit, a key pre-generation unit, and a cache optimization unit;
[0035] The prediction unit is used to predict user behavior based on historical data using a long short-term memory network, output the probability distribution of the user's next operation, use a histogram to count the operation frequencies in each time period, and then cluster the high-density points into time period intervals through the K-means algorithm to obtain the high-frequency operation time periods;
[0036] The key pre-generation unit is used to set the preparation duration. Before the preparation duration in the predicted high-frequency period, session keys are pre-generated through the channel switched by the current channel establishment unit, and all the generated keys are cached in a dual-encryption method that encrypts the session keys with the private key of the SparkLink chip and the encryption algorithm. When the algorithm adjustment unit determines that the remaining power is lower than 10% and the threat level signal is a low threat level signal, the encryption algorithm is switched to the AES-128 encryption algorithm;
[0037] The cache optimization unit is used to analyze the effectiveness of the cache policy to calculate and obtain the cache hit rate. If the cache hit rate is lower than the preset hit threshold, the reinforcement learning algorithm is started to retrain the long short-term memory network with historical authentication data, and the cache policy is adjusted according to the threat level signal of the authentication risk feedback subsystem. Only the core instruction keys are cached when the threat level signal is a high threat level signal.
[0038] Optionally, the SparkLink isolation channel priority scheduling subsystem includes a task classification unit, a bandwidth allocation unit, and a scheduling policy unit;
[0039] The task classification unit is used to receive the task type and weight data of the service logic module, and divide the tasks into emergency level, real-time level, and non-real-time level according to the task type and weight data. When the task requests bandwidth, the requirements are guaranteed in turn according to the divided levels of the tasks;
[0040] The bandwidth allocation unit is used to configure independent token buckets for tasks with different weights, and determine the minimum bandwidth guarantee ratio for tasks with different weights. According to the token bucket algorithm, the current number of tokens in each token bucket is calculated periodically. If the tokens in the token bucket corresponding to the emergency level task are insufficient, tokens are temporarily preempted from the token buckets of other weight tasks to meet the corresponding minimum bandwidth guarantee ratio for data transmission;
[0041] The scheduling policy unit is used to monitor the channel bandwidth utilization rate in real time. When the channel bandwidth utilization rate exceeds the threshold bandwidth, a delay scheduling policy is adopted for non-real-time level tasks, and the delay time is calculated by the formula where is the base delay time, is the used bandwidth, is the threshold bandwidth, is the total bandwidth, is the delay time.
[0042] Advantages of the present invention:
[0043] (1) This system builds a three-dimensional security protection system through the Xingshan physical isolation access subsystem, dynamic identity feature generation subsystem and multi-round session recursive authentication subsystem. The Xingshan physical isolation access subsystem adopts 6GHz frequency hopping and direct sequence spread spectrum technology, combined with hardware fingerprint Hamming distance verification, to block illegal device access from the bottom layer. For example, when a smart home device encounters a counterfeit attack, the hardware fingerprint verification mechanism can quickly identify and intercept it. The dynamic identity feature generation subsystem combines the timestamp and channel signal characteristics to generate a 64-byte dynamic tag, and the tag verification unit compares the hash value in real time to prevent the tag from being predicted and forged. The multi-round session recursive authentication subsystem responds through a 128-bit random number challenge and HMAC calculation. If a smart door lock responds to a timeout or error during authentication, the authentication closed-loop control unit immediately terminates the authentication and issues an alarm to ensure zero loopholes in identity authentication.
[0044] (2) The authentication risk feedback subsystem works in conjunction with the computing power and power consumption adjustment subsystem to achieve intelligent perception and dynamic response to security threats. The authentication risk feedback subsystem analyzes the response error rate, time offset, and anomaly type through the anomaly detection unit, and the risk assessment unit weights and calculates the risk intensity. When it is determined to be a high threat, the signal feedback unit links the Star Flash physical isolation access subsystem to switch the 7-layer pseudo-random code frequency hopping sequence. At the same time, the computing power and power consumption adaptive adjustment subsystem adjusts the authentication computing power and maintains the AES-256 encryption strength to effectively resist attacks. In low-power scenarios, such as when the power of the smart door lock is less than 10%, the algorithm adjustment unit automatically switches to AES-128 encryption to balance security and battery life.
[0045] (3) The session cache management subsystem is combined with the Xingshan isolation channel priority scheduling subsystem to achieve efficient resource utilization. The session cache management subsystem predicts user behavior through the LSTM network and pre-generates keys in advance, so that the authentication response time is further shortened; the cache optimization unit dynamically optimizes the strategy based on the hit rate, and only retains the core instruction keys when the threat is high, reducing the risk of leakage. The Xingshan isolation channel priority scheduling subsystem uses the token bucket algorithm and task classification to ensure the bandwidth of emergency tasks. For example, the door lock abnormal alarm task can give priority to preempting the non-real-time task token to ensure timely transmission of the alarm; when the channel utilization exceeds the threshold, the non-real-time tasks such as firmware upgrades are delayed to improve the utilization of channel resources. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] In order to more clearly illustrate the technical solutions in the present application or the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings in the following description are some embodiments of the present application.
[0047] Figure 1 This is a system module diagram of the present invention. DETAILED DESCRIPTION
[0048] To make the objectives, technical solutions, and advantages of this application clearer, the following will clearly and completely describe the technical solutions in this application in conjunction with the accompanying drawings in this application. Obviously, the described embodiments are part of the embodiments of this application, rather than all of them. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of this application.
[0049] With the popularization of smart homes, most device-to-device communications rely on WiFi links, but there are many security risks in the existing technology. On the one hand, the fixed-key or long-term-key mechanism is easily obtained by hackers, resulting in data leakage; on the other hand, the link authentication is vulnerable. Devices are only authenticated at the initial access, and subsequent communications are vulnerable to man-in-the-middle attacks. For example, hackers can hijack the WiFi link to steal the images of home cameras or the passwords of smart door locks, seriously threatening users' privacy and property security. Existing solutions have deficiencies in terms of security, dynamic adaptability, and resource utilization efficiency, and are difficult to meet the complex security requirements of smart homes. The present invention aims to provide a smart home communication protection system and method based on physical isolation of SparkLink chips and multi-round session recursive authentication. By constructing a heterogeneous dual-link architecture and a dynamic authentication mechanism, it solves the problem of WiFi link hijacking and realizes secure, efficient, and adaptive smart home communication protection.
[0050] As Figure 1 shown, the implementation of the present invention proposes an Internet of Things management system with SparkLink chip isolation and end-to-end encryption, including
[0051] a SparkLink physical isolation access subsystem that establishes an isolated communication link based on physical frequency-hopping channels through SparkLink chips and performs underlying identity confirmation based on device hardware fingerprints;
[0052] The SparkLink physical isolation access subsystem includes a channel establishment unit, an identity confirmation unit, and a channel switching control unit;
[0053] The channel establishment unit is used to pre-select the 6 GHz (gigahertz) band as the communication band, generate a frequency-hopping sequence using the chaotic mapping algorithm, switch channels within the 6 GHz band according to the generated frequency-hopping sequence at a period of 50 ms (milliseconds) to establish an isolated communication link, and on each channel, expand the signal bandwidth to more than 100 MHz (megahertz) through direct-sequence spread spectrum technology;
[0054] Selecting the 6 GHz band as the communication band is because this band has less interference compared to other commonly used bands and rich bandwidth resources, which is suitable for building a secure and high-speed communication link.
[0055] Using the chaotic mapping algorithm , a frequency hopping sequence is generated. This algorithm generates a seemingly random but actually regular numerical sequence through continuous iterative calculations. These numerical values are mapped to specific frequency bands to form a frequency hopping sequence. Among them, is the result of the a-th iteration, and the next value is calculated by continuously substituting the formula , thus generating a series of numerical values. These numerical values can be mapped to different frequency bands after processing, so as to determine the channel that the communication link should switch to in each cycle. is a numerical value between 0 and 1; is the result of the (a + 1)-th iteration;
[0056] Taking 50 ms as a cycle, the channel is switched within the 6 GHz frequency band according to the generated frequency hopping sequence. Every 50 ms, the communication link switches to the next channel specified by the frequency hopping sequence for data transmission. This way of quickly switching channels makes it difficult for illegal eavesdroppers to track and intercept the communication content, thus achieving physical isolation.
[0057] On each channel, the signal bandwidth is expanded to more than 100 MHz through direct sequence spread spectrum technology. The specific method is to perform modulo-2 addition (or multiplication) operation on the original narrowband signal and a high-speed pseudo-random code, so that the signal bandwidth increases significantly. The spread spectrum signal has strong anti-interference ability. Even if it is interfered by some frequency bands, the original signal can still be restored through despreading operation.
[0058] The identity confirmation unit is used to, when the smart home device is connected to the smart home system network, use the channel switched by the current channel establishment unit to send the device hardware fingerprint stored in the SparkLink chip to the cloud server. The cloud server uses the Hamming distance to verify the difference degree between the device hardware fingerprint and the fingerprint stored in the cloud database. If the Hamming distance does not exceed the preset difference threshold, the device hardware fingerprint is considered legal, otherwise it is determined to be illegal;
[0059] The Hamming distance is used to verify the legality of the device hardware fingerprint and determine whether the device is a legally connected device. It reflects the difference degree between the fingerprint requested by the device for verification and the fingerprint stored in the cloud database. The smaller the Hamming distance, the more similar the two fingerprints are and the higher the device legality; on the contrary, the larger the Hamming distance, the greater the difference and the higher the risk of illegal access to the device.
[0060] The channel switching control unit is used to receive the threat level signal of the authentication risk feedback subsystem. When the threat level signal is at a high threat level, it automatically switches to an advanced frequency hopping sequence, in which the advanced frequency hopping sequence adopts 7 layers of pseudo-random code nesting technology and the frequency hopping period is shortened to 20ms to improve channel security. The advanced frequency hopping sequence adopts 7 layers of pseudo-random code nesting technology, that is, multiple layers of different pseudo-random codes are nested and combined to generate a frequency hopping sequence. The frequency hopping period is shortened to 20ms, which is faster than the conventional frequency hopping sequence switching speed, making it more difficult for illegal eavesdroppers to capture and crack the communication content.
[0061] The frequency hopping sequence is generated by the chaotic mapping algorithm, and the channel is quickly switched in the 6GHz frequency band with a period of 50ms. Combined with the direct sequence spread spectrum technology, the communication link is difficult to be tracked and monitored by illegal devices. For example, when smart home devices establish communication through this mechanism, the attacker needs to complete channel scanning and signal analysis within 50ms, and the spread spectrum technology further increases the difficulty of deciphering the signal after interception, which can effectively defend against threats such as relay attacks and spectrum sniffing.
[0062] When the authentication risk feedback subsystem detects a high threat level, the channel switching control unit automatically enables an advanced frequency hopping sequence with 7 layers of pseudo-random codes nested in it. The frequency hopping period is shortened to 20ms, the channel change speed is increased, and combined with more complex code sequences, the interference cost for attackers increases exponentially.
[0063] The identity confirmation unit compares the device hardware fingerprint through the Hamming distance, such as the chip ID, sensor serial number and other unique identifiers. If the difference exceeds the threshold, it is judged to be illegal. For example, when an attacker tries to access the system using a forged device ID, the cloud server can quickly identify it through the fingerprint difference, preventing "fake devices" from mixing into the smart home network, and preventing security incidents such as illegal control of door locks and theft of camera images.
[0064] When the threat is low, the basic frequency hopping strategy (50ms period) is used to balance security and power consumption. When the threat is high, it switches to the advanced strategy (20ms period + 7 layers of pseudo code nesting). For example, when an abnormal login attempt or network attack is detected, the system automatically shortens the frequency hopping period and increases the complexity of the code sequence to ensure the transmission security of key data such as emergency alarm signals.
[0065] In this embodiment, the channel establishment unit serves as the core of physical isolation, and the generated frequency hopping sequence and spreading parameters provide a communication carrier for identity verification and channel switching. For example, the identity verification unit needs to transmit the hardware fingerprint through the currently switched channel of this unit. If the channel is unstable or easily monitored, the fingerprint data may be tampered with or stolen during transmission. The identity verification unit relies on the channel resources of the channel establishment unit to complete the fingerprint verification and feedback the verification result to the system core module. If the verification fails (the Hamming distance exceeds the threshold), subsequent authentication processes and service requests will be blocked to prevent illegal devices from entering the network. The channel switching control unit receives the threat level signal (such as high threat) from the authentication risk feedback subsystem and triggers the channel establishment unit to adjust the frequency hopping parameters. For example, when the identity verification unit detects multiple illegal fingerprint verifications, the authentication risk feedback subsystem determines it as a high threat, and the channel switching control unit immediately instructs the channel establishment unit to enable an advanced frequency hopping sequence to form a security closed-loop of detection - response - enhancement.
[0066] For example, in the scenario of preventing intrusion in smart homes:
[0067] 1. The smart door lock establishes a frequency hopping link in the 6GHz band through the channel establishment unit and sends the hardware fingerprint (such as the unique ID of the MCU) to the cloud.
[0068] 2. The identity verification unit verifies the legality of the fingerprint through the Hamming distance. If it is legal, access is allowed; if it is illegal (such as an attacker forging a fingerprint), the system rejects access and triggers an alarm.
[0069] 3. If the attacker continuously attempts to intrude, the authentication risk feedback subsystem determines it as a high threat. The channel switching control unit instructs to switch to an advanced frequency hopping sequence with a 20ms period and simultaneously shortens the transmission interval of the door lock status data to ensure the priority transmission of the alarm signal.
[0070] In summary, through the cooperation of the three units, the system realizes a three-dimensional protection of "dynamic channel isolation + hardware identity anchoring + threat adaptive adjustment", which not only ensures the secure access of Internet of Things devices but also further improves the communication anti-interference ability in complex attack environments.
[0071] Furthermore, the dynamic identity feature generation subsystem generates a session dynamic identity tag based on the current timestamp, device hardware fingerprint, and SparkLink channel signal characteristics;
[0072] The dynamic identity feature generation subsystem includes a feature acquisition unit, a tag generation unit, and a tag verification unit;
[0073] The feature acquisition unit is used to obtain the StarFlash channel signal features according to the channel switched by the current channel establishment unit, and generate a unique random number per session based on the hardware random number generator (HRNG); the unique random number per session is a unique random value generated in each communication session, which is used to increase the communication security and randomness, and prevent session prediction, replay attacks, etc.
[0074] The StarFlash channel signal features refer to various characteristic information of the signals transmitted on the StarFlash channel, which are used to characterize the channel state and signal characteristics. It includes the hopping sequence index (indicating the number of the hopping sequence currently in use), the standard deviation of the signal strength (reflecting the fluctuation degree of the signal strength), the channel phase offset, and the multipath fading parameters, etc. These features can reflect the channel quality, interference situation, etc. The StarFlash channel signal features are generally measured and calculated by the signal processing unit inside the StarFlash chip. After receiving the StarFlash channel signal, the chip analyzes the changes of parameters such as signal strength, frequency, and phase through the built-in algorithm, and then calculates the characteristic values such as the standard deviation of the signal strength; the hopping sequence index can be obtained from the hopping control module of the chip, and this module is responsible for switching the hopping sequence according to the predetermined algorithm and recording the current index value.
[0075] The tag generation unit is used to generate a 64-byte dynamic identity tag Is according to the StarFlash channel signal features and the unique random number per session obtained from the feature acquisition unit, using the SHA-384 hashing algorithm, according to the formula Is = SHA-384(T⊕(F⊕V)⊕L⊕Nonce), where ⊕ is the exclusive OR operation, T is the nanosecond-level timestamp, F is the in-shed hardware fingerprint, V is the firmware version number, L is the StarFlash channel signal features, and Nonce is the unique random number per session; the dynamic identity tag generated by this unit has uniqueness and timeliness, and will be updated according to the real-time changing parameters in each session, greatly enhancing the security of identity authentication and providing a reliable basis for subsequent multi-round session recursive authentication;
[0076] The firmware version number is the number that identifies the firmware version of the device, and is generally stored in the non-volatile memory of the device (such as flash memory). When the device starts or runs, the version number can also be directly viewed. For example, in the APP management interface of a smart home device, the firmware version number of the device can be viewed. The firmware version number reflects the update and iteration status of the firmware, and different versions may have differences in functions, stability, security, etc.
[0077] The tag verification unit is used to compare the hash values of the newly generated dynamic identity tag and the previous tag to obtain the similarity. If the similarity exceeds the pre-set similarity threshold, it will trigger the feature acquisition unit to re-acquire the features and generate a new tag to prevent the tag from being predicted or forged. The similarity can be calculated and obtained through the Euclidean distance;
[0078] In this embodiment, by combining the current timestamp, the device hardware fingerprint, and the StarFlash channel signal characteristics, a 64-byte dynamic identity tag Is is generated through the SHA-384 hashing algorithm. This makes the identity tag of each session unique and unpredictable, increasing the difficulty for attackers to forge identities. For example, in a smart home system, the dynamic identity tags generated during each device communication are different. Even if an attacker intercepts the tag of one communication, it cannot be used for impersonation in subsequent sessions.
[0079] The tag verification unit compares the similarity of the hash values of the newly generated tag and the previous tag. If it exceeds the threshold, it will re-collect the characteristics to generate a new tag, which effectively prevents the tag from being predicted or forged and further enhances the security of identity authentication. For example, when an attacker attempts to generate a forged tag through a prediction algorithm, the tag verification unit can detect it in a timely manner and trigger the re-generation process to ensure the security of the system.
[0080] Feature collection unit: As the basis, it obtains the StarFlash channel signal characteristics from the current channel and generates a unique random number for each session, providing the raw data for tag generation. Tag generation unit: Based on the data of the feature collection unit, it uses the SHA-384 hashing algorithm to generate a dynamic identity tag. It depends on the accuracy and integrity of the feature collection unit. If the input data is incorrect, the generated tag will not be able to correctly reflect the device identity characteristics. Tag verification unit: It compares the hash values of the newly generated tag and the previous tag and decides whether to trigger the feature collection unit to re-collect according to the result. It forms a closed loop with the feature collection unit and the tag generation unit to ensure the security and effectiveness of the tag. For example, if the tag verification unit fails, it may allow a forged tag to pass the verification, resulting in a security vulnerability in the system.
[0081] Furthermore, the multi-round session recursive authentication subsystem performs multiple rounds of challenge and response recursive interactions based on the dynamic identity tag to form an authentication closed loop;
[0082] The multi-round session recursive authentication subsystem includes a challenge generation unit, a response processing unit, and an authentication closed loop control unit;
[0083] The challenge generation unit is responsible for generating challenge information for verifying the identity of the smart home device during the multi-round session recursive authentication process. The challenge information includes, in the first round of authentication start, generating a random number with a length of 128 bits as the initial challenge, and outputting a response value after the initial challenge is generated. Using a pseudo-random number generator (PRNG), with the dynamic identity tag of the smart home device as the seed, generating a random number sequence with the same length as the response value output by the initial challenge, performing an exclusive OR operation (0 for the same, 1 for different) on each bit of the response value output by the initial challenge and the generated random number to obtain a new binary sequence, encrypting the exclusive OR result using the master key, and adopting a block cipher mode for encryption. The encrypted result is the challenge for the current round; the master key is a long-term and highly confidential encryption key, usually pre-configured in the cloud server and the SparkLink chip by the system administrator, used to encrypt the challenge to ensure the identity of the server.
[0084] The block cipher mode divides the plaintext into blocks of a fixed length and encrypts the current block through the initialization vector and the previous ciphertext block.
[0085] Through the initial challenge and subsequent challenges, the legitimacy of the device identity is further verified. Each round of challenge is associated with the previous round, forming a closed loop of recursive authentication. Even if an attacker intercepts the challenge and response information of a certain round, it is difficult to use it to crack the authentication of subsequent rounds because the subsequent challenges are dynamically changing and dependent on the previous authentication results. It is not used to obtain specific information but as a key verification element in the authentication process to ensure the security and reliability of the authentication.
[0086] The response processing unit is used to receive the challenge of the current round, perform an exclusive OR operation on each bit of the challenge of the current round and the dynamic identity tag of the smart home device itself to obtain a new binary sequence, and use the session key as the key to perform HMAC (Hash-based Message Authentication Code) calculation on the exclusive OR result in the response processing unit, where the hash algorithm adopts the SHA-512 hash algorithm, and the calculation result is the response value of the smart home device to the current challenge.
[0087] HMAC (Hash-based Message Authentication Code) is a message authentication code based on a hash function, used to verify the integrity of data and the identity of the sender. It combines a key and a hash function to generate a hash value of a fixed length (i.e., the HMAC value), ensuring that any modification to the message will cause the HMAC value to change.
[0088] The response value Rn is calculated through the formula Rn = HMAC-SHA-512(Cn ⊕ Is, Ksession), where Ksession is the session key and Cn is the challenge of the nth round.
[0089] In the multi-round session recursive authentication process, each subsystem does not operate independently. Instead, through real-time interaction and collaboration, a tight protection network is constructed. The authentication risk feedback subsystem will, based on the results of the multi-round session recursive authentication, capture abnormal responses in real time, providing a key basis for the dynamic adjustment of the system security policy. Information is exchanged between each subsystem through a secure data bus, and the data transmission uses the AES-256 encryption algorithm to ensure the data security and integrity during the module collaboration process, further enhancing the overall protection ability of the system. The authentication risk feedback subsystem can keenly capture any abnormal fluctuations by monitoring the response data during the multi-round session recursive authentication process in real time. Once an abnormal response is detected, it will immediately activate the risk assessment mechanism, calculate the risk intensity value using an accurate calculation formula, and quickly feedback this key information to each subsystem of the system, providing a scientific basis for the subsequent dynamic adjustment of the security policy.
[0090] And it is sent to the cloud server for verification to obtain the response result. The specific steps are as follows:
[0091] Cloud receiving: The cloud server receives the response value sent by the device;
[0092] Local calculation: The cloud server calculates according to the relevant information stored in itself (such as dynamic identity tags, session keys), and the received challenge, using the same formula Rn = HMAC-SHA-512(Cn⊕Is, Ksession) to obtain a locally calculated response value;
[0093] Comparison and judgment: Compare the response value sent by the device with the locally calculated response value. If the two are the same, it is considered that the device passes the authentication in this round, that is, the verification is successful; if they are different, the authentication fails, that is, the verification is incorrect.
[0094] The authentication closed-loop control unit is used to record the time length from sending a challenge to the smart home device to receiving the response from the smart home device during each round of authentication, that is, the time spent on each round of authentication. This is to ensure that the authentication process is completed within a reasonable time range and prevent overly long waits or abnormal delays.
[0095] If the time spent on authentication does not fall within the safe time range or the response result is a verification error, the authentication will be immediately terminated and an abnormal signal will be sent to the authentication risk feedback subsystem.
[0096] In this embodiment, through multiple rounds of challenge and response recursive interactions, the reliability and security of authentication are enhanced. Each round of challenge is generated based on a dynamic identity tag, and the challenge content changes continuously, making it difficult for attackers to obtain a legitimate identity through means such as replay attacks. For example, during the authentication process of smart home devices, the first-round challenge may be a random number, and the challenges in subsequent rounds are generated based on the response of the previous round and the dynamic identity tag. Even if an attacker intercepts the challenge and response of the first round, they cannot handle the authentication in subsequent rounds. The authentication closed-loop control unit records the authentication time for each round. If the security time range is exceeded or the response is incorrect, the authentication is immediately terminated and an exception signal is sent. This effectively prevents timeout attacks and incorrect responses during the authentication process, ensuring the timeliness and accuracy of authentication. For example, when an attacker attempts to interfere with the authentication by occupying the authentication channel for a long time, the authentication closed-loop control unit can detect and terminate the authentication in a timely manner, avoiding waste of system resources.
[0097] The challenge generation unit is responsible for generating challenge information used to verify the identity of smart home devices. The challenges it generates are based on dynamic identity tags and a pseudo-random number generator. It provides the challenge content for the response processing unit and is the initiator of the authentication process. For example, if the challenges generated by the challenge generation unit are too simple or predictable, the security of authentication will be reduced.
[0098] The response processing unit receives the challenges generated by the challenge generation unit, performs an exclusive OR operation with the dynamic identity tag of the smart home device itself, and generates a response value through HMAC calculation and sends it to the cloud server for verification. It depends on the challenge content of the challenge generation unit and the dynamic identity tag of the device. If an error occurs during the calculation process or the tag is tampered with, the response result will be incorrect.
[0099] The authentication closed-loop control unit monitors the authentication time and response result for each round, and decides whether to terminate the authentication and send an exception signal according to the situation. It works closely with the challenge generation unit and the response processing unit to form an authentication closed-loop. For example, if the authentication closed-loop control unit fails to detect authentication timeout or incorrect response in a timely manner, illegal devices may pass the authentication. Traditional identity authentication mostly uses static identity tags, which are easily obtained and forged by attackers. The dynamic identity tags of this system are generated by combining multiple real-time features and are unique for each session, further improving the security of identity authentication. For example, in a traditional smart home system, if the identity tag is obtained by an attacker, the device may be illegally controlled for a long time; while the dynamic identity tags of this system make it extremely difficult for attackers to obtain and crack each time.
[0100] Compared with traditional single-round authentication, multi-round session recursive authentication increases the complexity and reliability of authentication through multiple rounds of challenges and responses. Once the traditional single-round authentication is breached by an attacker, the device will lose all protection; while in the multi-round authentication mechanism of this system, even if a certain round is breached, subsequent rounds may still detect and prevent illegal access. For example, in the authentication of some traditional Internet of Things devices, an attacker may obtain device control rights through a single attack; while in this system, the attacker needs to continuously breach multiple rounds of authentication, further reducing the probability of successful attack.
[0101] For example, in the application scenario of remote control of smart home devices, when a user remotely controls a smart home device, such as a smart camera, through a mobile phone, the dynamic identity feature generation subsystem first generates a dynamic identity tag, and the multi-round session recursive authentication subsystem starts the multi-round authentication process. The challenge generation unit generates challenge information, the response processing unit calculates the response value and sends it to the cloud server for verification, and the authentication closed-loop control unit monitors the time and response result of each round of authentication. If the authentication is successful, the user can remotely control the camera; if the authentication fails or times out, the system will terminate the authentication and prompt the user. For example, if an attacker attempts to interfere when the user remotely controls the camera, the authentication closed-loop control unit can detect and terminate the authentication in time to protect the user's privacy and device security.
[0102] Furthermore, the authentication risk feedback subsystem detects abnormal responses during the authentication process and calculates the risk intensity to feedback a threat level signal;
[0103] The authentication risk feedback subsystem includes an anomaly detection unit, a risk assessment unit, and a signal feedback unit;
[0104] The anomaly detection unit is used to receive anomaly signals, calculate and obtain the response error rate and time offset according to the time and response results spent on each round of authentication collected historically and in real time, and determine the anomaly response type parameter according to the type of abnormal response;
[0105] Among them, the types of abnormal responses include response timeout, timing anomaly, frequency anomaly, and pattern anomaly; response timeout means that the time spent on each round of authentication exceeds the safe range, which may be caused by network latency or exhaustion of computing resources. Timing anomaly means that the response time fluctuations between adjacent rounds are too large, which may imply a man-in-the-middle attack or abnormal device performance. Frequency anomaly means that authentication requests are frequently initiated within a short period of time (such as more than 10 times within 1 minute), which may be a sign of brute force cracking or DoS attack. Pattern anomaly means that the hash value distribution of the response value does not meet the expectation, which may indicate that the device's calculation logic has been tampered with.
[0106] If the type of abnormal response is a timing anomaly, the anomaly response type parameter is the number of timeouts Total number of authentications, i.e., timeout percentage; if the abnormal response type is response timeout, the abnormal response type parameter is the response time standard deviation; if the abnormal response type is frequency anomaly, the abnormal response type parameter is pattern anomaly; if the abnormal response type is timing anomaly, the abnormal response type parameter is the response value entropy;
[0107] The response error rate is calculated as: Failed rounds Total rounds;
[0108] The time offset is calculated as: ,in, is the time offset, The time spent on the nth round of authentication, Average time spent for certification;
[0109] The risk assessment unit is used to perform weighted summation of the response error rate, time offset and abnormal response type parameters to calculate the risk intensity;
[0110] The signal feedback unit is used to compare the calculated risk intensity with the preset risk threshold to divide the calculated risk intensity into low threat level signals, medium threat level signals and high threat level signals. If it is a high threat level signal, it will be sent to the Star Flash physical isolation access subsystem, the computing power and power consumption adaptive adjustment subsystem and the session cache management subsystem.
[0111] Specifically, if the risk intensity is greater than the risk threshold, it is a high threat level signal; when the risk intensity is equal to the risk threshold, it is a medium threat level signal; and if the risk intensity is less than the risk threshold, it is a low threat level signal.
[0112] In this embodiment, by real-time monitoring of authentication time, such as the time taken for each round of authentication and the response result being a verification error, the response error rate and time offset are calculated, and types such as response timeouts, timing anomalies, frequency anomalies, and pattern anomalies are identified. For example, when a smart home device frequently experiences response timeouts during authentication (such as exceeding a safe time range of 200ms), or the response error rate suddenly rises to more than 30%, the system can quickly locate the anomaly.
[0113] A weighted formula is used to comprehensively assess risks, and different types of anomalies are assigned different weights to ensure that high-risk behaviors are triggered first. The risk intensity is divided into low, medium and high threat levels. When the threat is high, signals are sent to the physical isolation subsystem, computing power adjustment subsystem, etc. to strengthen protection. For example, if a device is detected to initiate 10 abnormal authentication requests in a short period of time, the risk intensity is determined to be a high threat, triggering the Star Flash channel to switch to a 20ms advanced frequency hopping sequence, and shutting down non-critical authentication rounds to concentrate computing power.
[0114] Form a complete link from anomaly detection, risk calculation to hierarchical response to avoid misjudgment in a single dimension. For example, an increase in the time offset alone may be caused by network fluctuations, but if it is accompanied by an increase in the response error rate and pattern anomalies at the same time, it is comprehensively determined as medium to high risk, further improving the detection accuracy.
[0115] Receive the anomaly signals sent by the authentication closed-loop control unit, such as authentication timeout and response error, collect historical and real-time authentication data, calculate the anomaly response type parameters and identify the anomaly type, such as the timing anomaly corresponding to the disorder of the authentication round order.
[0116] Obtain the response error rate, time offset and anomaly response type parameters from the anomaly detection unit, and synthesize the risk intensity E according to the preset weight. Compare the risk intensity with the threshold and then output the hierarchical signal. When the threat is high, notify the Spark physical isolation access subsystem (switch to advanced frequency hopping), the computing power and power consumption adaptive adjustment subsystem (adjust the authentication computing power and switch the encryption algorithm), and the session cache management subsystem (only cache the core key) at the same time, so as to ensure that each subsystem synchronizes the adjustment strategy and forms a three-dimensional defense. For example, when the threat is high, the Spark channel switching and computing power enhancement are carried out simultaneously to avoid the lag of a single measure.
[0117] In a traditional system, when a single authentication timeout occurs in a smart door lock due to network fluctuations, the system misjudges it as an attack and triggers an alarm, which requires manual troubleshooting. In this system, when the anomaly detection unit finds that the single authentication time offset is large but the response error rate is still <5% and there is no other anomaly type, by calculating the risk intensity, its value is small, and it is determined as low risk, only recording the log without triggering the defense measure; if multiple timeouts occur continuously within the next 5 minutes and the response error rate continues to rise, when it is comprehensively determined as a medium threat, trigger the channel hopping period to be shortened to 30ms.
[0118] Furthermore, the computing power and power consumption adaptive adjustment subsystem dynamically adjusts the authentication and encryption algorithms based on the real-time status of smart home devices;
[0119] The computing power and power consumption adaptive adjustment subsystem includes a status monitoring unit, a computing power allocation unit and an algorithm adjustment unit;
[0120] The status monitoring unit is used to obtain the power, computing power load data of smart home devices and the threat level signal of the authentication risk feedback subsystem in real time;
[0121] The computing power allocation unit is used to dynamically allocate the computing power resources during the execution of the authentication task when the threat level signal of the authentication risk feedback subsystem changes, so as to obtain the final computing power. The specific way to obtain the final computing power is: collect the real-time status of smart home devices in real time to obtain the remaining power, CPU temperature, available memory and risk intensity, and calculate the dynamic adjustment factor according to the real-time status of smart home devices, and combine the basic computing power requirements to calculate the final computing power;
[0122] The formula for calculating the dynamic adjustment factor is as follows: , where is the dynamic adjustment factor, is the remaining battery power, is the maximum battery power, is the available memory, is the maximum memory, is the risk intensity, , and are weight values, + + = 1, and their specific values are set by the user according to the situation;
[0123] The formula for calculating the final computing power is as follows: , where is the final computing power, is the basic computing power requirement;
[0124] The core objective of final computing power allocation is to achieve dynamic balance among security requirements, system performance, and resource consumption, ensuring that the authentication system operates efficiently and reliably in different scenarios. The specific functions include: coping with different threat levels. When high risks (such as frequent authentication failures, abnormal traffic) are detected, more computing power is allocated to high-strength encryption algorithms (such as AES-256, ECDSA-P384) to enhance the anti-attack ability.
[0125] And when the remaining battery power of the smart home device is lower than 10%, the non-critical authentication rounds in the multi-round session recursive authentication subsystem are turned off;
[0126] Among them, non-critical authentication rounds refer to the authentication rounds that have a relatively small impact on the overall authentication security compared to the core authentication rounds during the multi-round session recursive authentication process. The main role of these rounds is to further verify the device identity, but in some special cases (such as extremely low device battery power, etc.), they can be temporarily turned off to save computing power and power consumption; usually, they are pre-determined by the system according to the device type, security requirements, and the design of the authentication process. For example, for some smart home devices with relatively low security requirements (such as smart bulbs, etc.), their non-critical authentication rounds may be relatively more; while for devices with higher security requirements (such as smart door locks), the non-critical authentication rounds are fewer. At the same time, the system will consider the consumption of computing power and power consumption of the authentication rounds by the device, as well as the contribution of each round of authentication to the overall security to comprehensively determine the non-critical authentication rounds.
[0127] The algorithm adjustment unit is used to dynamically switch the encryption algorithm according to the threat level signal of the smart home device. When the remaining power is lower than 10% and the threat level signal is a low threat level signal, the AES-256 encryption algorithm is switched to the AES-128 encryption algorithm.
[0128] In this embodiment, the computing power resources are dynamically adjusted according to the threat level of the authentication risk feedback subsystem. For example, when it becomes a high threat (such as detecting an abnormal authentication attack), the computing power allocation unit increases the computing power ratio of the authentication task from the default 40% to 70% to ensure the real-time performance of high-strength encryption algorithms (such as AES-256) and multi-round authentication; when it becomes a low threat (such as daily device status query), the computing power ratio is reduced to 20% to reduce power consumption. When the remaining power of the device is lower than 10% and the threat level is low, the algorithm adjustment unit automatically switches AES-256 to AES-128, reducing the encryption computing power consumption by about 30% while maintaining the basic security level.
[0129] For example, in the low-power mode of the smart door lock, the battery life is extended by reducing the encryption strength to avoid the lock getting out of control due to power exhaustion. The status monitoring unit continuously collects data such as power, CPU temperature, and memory, and calculates the dynamic adjustment factor in combination with the risk intensity. In low-power or high-load scenarios, non-critical authentication steps are identified according to the round weight, and the computing power consumption can be reduced by 40% after being turned off. For example, when the smart camera is transmitting a video stream, the non-critical rounds of fingerprint verification are turned off to give priority to ensuring the computing power requirements for video encryption. The computing power is dynamically adjusted through temperature perception to avoid accelerated aging caused by the chip running at full load for a long time.
[0130] The status monitoring unit continuously collects device status data (power, temperature, memory) and threat level signals to provide a basis for computing power allocation and algorithm adjustment. For example, if the status monitoring unit fails to detect in time that the power is lower than 10%, the algorithm adjustment unit will not be able to trigger the AES-128 switch, which may cause the device to power off in advance.
[0131] The computing power allocation unit calculates the dynamic adjustment factor based on the status monitoring data, and calculates the final computing power in combination with the basic computing power requirements. The non-critical round closing logic is triggered during low power, and the steps that can be closed are identified through a round weight table (such as the fingerprint verification round weight is 0.6, and the timestamp verification round weight is 0.3).
[0132] The algorithm adjustment unit switches the encryption algorithm according to the threat level and power status, and the priority is: high threat → force the use of AES-256; low power + low threat → switch to AES-128; in other cases, the default is AES-256. For example, when the threat level rises from medium to high, regardless of the power status, the algorithm adjustment unit immediately resumes AES-256 to ensure the encryption strength.
[0133] In traditional systems, smart speakers may still run AES-256 encryption when the battery is low, resulting in a possible sudden reduction in battery life from 5 hours to 3 hours, and there is no round-by-round shutdown mechanism, and the authentication delay continues to increase. In this system, when the battery level of the smart speaker is lower than 10% and the threat level is low, it automatically switches to AES-128 and shuts down non-critical authentication rounds to achieve the purpose of extending battery life.
[0134] Furthermore, the session cache management subsystem predicts user behavior and generates session caches in advance;
[0135] The session cache management subsystem includes a behavior prediction unit, a key pre-generation unit, and a cache optimization unit;
[0136] The prediction unit is used to predict user behavior based on historical data, using a long short-term memory network (LSTM) to output the probability distribution of the user's next operation, and use a histogram to count the operation frequencies in each time period, and then cluster the high-density points into time period intervals through the K-means algorithm to obtain high-frequency operation time periods;
[0137] The long short-term memory network (LSTM) is a special type of recurrent neural network (RNN) that can learn long-term dependencies in sequential data. Compared with traditional RNNs, LSTM solves the problem of gradient disappearance through gating mechanisms (input gate, forget gate, output gate), and is particularly suitable for processing time series data (such as user behavior sequences). Steps for predicting user behavior using LSTM:
[0138] Data collection: Record the user's historical authentication time, operation types (such as login, data transfer, file access), operation duration, etc.
[0139] Feature engineering: Extract time features (such as hour, day of the week), operation frequencies, operation intervals, etc. Perform one-hot encoding on the operation types;
[0140] Sequence construction: Convert historical data into sequences of fixed length (such as predicting the next operation based on the previous 5 operations);
[0141] Model training: LSTM network structure: input layer → LSTM layer (including forget gate, input gate, output gate) → fully connected layer → output layer (softmax classification); Loss function: cross-entropy loss (classification problem);
[0142] Prediction and application: Input the current operation sequence, and the model outputs the probability distribution of the next operation.
[0143] The key pre-generation unit is used to set the preparation duration. Before the preparation duration in the predicted high-frequency period, session keys are pre-generated through the channel switched by the current channel establishment unit. All the generated keys are cached in a dual-encryption manner by encrypting the session keys with the private key of the SparkLink chip and using an encryption algorithm. Here, the encryption algorithms include AES-256 and AES-128. When the algorithm adjustment unit determines that the remaining power is less than 10% and the threat level signal is a low-threat level signal, the encryption algorithm is switched to the AES-128 encryption algorithm, indicating that the encryption algorithm here is AES-128; otherwise, it is AES-256.
[0144] Among them, caching all the generated keys means including pre-generated session keys, session keys, instruction keys, and so on.
[0145] The cache optimization unit is used to analyze the effectiveness of the cache policy to calculate and obtain the cache hit rate. If the cache hit rate is lower than the preset hit threshold, the reinforcement learning algorithm is started to retrain the long short-term memory network with historical authentication data, and the cache policy is adjusted according to the threat level signal of the authentication risk feedback subsystem. When the threat level signal is a high-threat level signal, only the core instruction keys are cached.
[0146] The calculation method of the cache hit rate is: the number of hits The total number of requests; the cache hit rate is used to reflect the effectiveness of the cache policy. A high hit rate indicates a reasonable cache policy, reducing the overhead of repeated calculations or key negotiations.
[0147] The historical authentication data includes authentication time, authentication result, used key, operation type, device status (power, temperature), and threat level, etc.
[0148] The core instruction key refers to the key used to ensure the secure transmission and execution of key control instructions in the smart home system. These keys are crucial for the core functions of the system (such as door lock control, real-time camera monitoring, etc.). Once leaked, it may lead to serious security problems, such as illegal door opening, privacy leakage, etc. The acquisition method: the preset core instruction list can be read from the system configuration file or based on the statistical analysis of historical operation frequencies, and the instructions with the highest execution frequency and the highest permission level are selected.
[0149] In this embodiment, the historical operation data is analyzed through the LSTM network, combined with K-means time period clustering, to accurately identify the user's high-frequency operation time period, such as starting the smart door lock from 7:00 to 8:00 in the morning and controlling the light from 19:00 to 21:00 in the evening). For example, it is predicted that the user will use the mobile phone to control the living room air conditioner at 19:30 every night. The system will generate a session key in advance at 19:00, shortening the authentication response time from 200ms to 50ms. The pre-generated session key, instruction key, etc. are double-encrypted and stored using the Star Flash chip private key and the AES algorithm to ensure the security of cached data.
[0150] When a device requests access, it directly obtains the key from the cache to avoid repeated calculation overhead. The cache optimization unit calculates the cache hit rate in real time. When it is lower than the threshold, it starts the reinforcement learning algorithm and retrains the LSTM model with historical authentication data to optimize the prediction accuracy. When the threat is high, only the core instruction keys (such as door lock control instructions) are cached to reduce the risk of sensitive data exposure. For example, when the authentication risk feedback subsystem sends a high threat signal, the system immediately clears the non-critical cache to reduce the risk of key leakage.
[0151] In conjunction with the computing power and power consumption adaptive adjustment subsystem, AES-256 is automatically downgraded to AES-128 encrypted cache when the power is low and the threat is low, thereby further reducing energy consumption. The behavior prediction unit generates a pre-cache time window based on the LSTM output user operation probability distribution (such as the probability of "turning on the living room lights" is 0.75) combined with the high-frequency time period of K-means clustering (such as 18:00-19:00 every day). For example, for the predicted 7:30 kitchen appliance operation, the system generates a session key at 7:00 and encrypts it for storage, while monitoring channel switching events (such as increased threat levels triggering channel upgrades) to ensure that the key matches the current channel. The cache optimization unit calculates the cache hit rate. When it is lower than the threshold, the LSTM model parameters (such as learning rate and number of hidden layer nodes) are adjusted through the reinforcement learning algorithm.
[0152] Furthermore, the Star Flash isolation channel priority scheduling subsystem allocates the resources of the channel to which the current channel establishment unit switches based on the task weight and bandwidth pressure.
[0153] The priority scheduling subsystem of the star flash isolation channel includes a task classification unit, a bandwidth allocation unit and a scheduling strategy unit;
[0154] The task classification unit is used to receive the task type and weight data of the business logic module. According to the task type and weight data, the task is divided into emergency level (such as door lock abnormal alarm, weight = 100), real-time level (such as camera control, weight = 50) and non-real-time level (such as firmware upgrade, weight = 10). When the task requests bandwidth, the demand is guaranteed in order according to the task classification level;
[0155] The task classification unit receives the task type and weight data of the service logic module through the system bus interface, where the task types include voice calls, file transfers, device management, device configuration, status queries, log uploads, data synchronization, etc.;
[0156] The weight data reflects the relative importance of the tasks and is usually set by the system administrator or application developer. For example: the voice call weight is 8, the file transfer weight is 5, and the log upload weight is 2.
[0157] The bandwidth allocation unit is used to configure independent token buckets for tasks with different weights respectively, and determine the minimum bandwidth guarantee ratio for tasks with different weights. According to the token bucket algorithm, the current number of tokens in each token bucket is calculated periodically;
[0158] When a task requests to transfer data, it needs to obtain tokens equal to the data volume from the corresponding token bucket. Only when the number of tokens is sufficient can the task perform data transfer. If the tokens are insufficient, the task needs to wait for the next round of token generation until it has enough tokens. In this way, the instantaneous traffic of the task is restricted, making the data transfer rate more stable and avoiding channel congestion caused by sudden large traffic.
[0159] If the tokens in the token bucket corresponding to the emergency-level task are insufficient, tokens are temporarily preempted from the token buckets of other weight tasks (provided that it does not affect the basic transmission of other tasks) to meet the corresponding minimum bandwidth guarantee ratio for data transfer;
[0160] The token bucket algorithm is used to smooth the bandwidth allocation, ensure that the task obtains a stable transmission rate, and at the same time allow burst traffic.
[0161] The scheduling policy unit is used to monitor the channel bandwidth utilization rate in real time. When the channel bandwidth utilization rate exceeds the threshold bandwidth, a delay scheduling policy is adopted for non-real-time level tasks, and the delay time is calculated through the formula where is the basic delay time, is the used bandwidth, is the threshold bandwidth, is the total bandwidth, is the delay time.
[0162] Some of the data in the above formula are used for numerical calculation by taking their dimensions. For example, the weighted summation algorithm, and the content not described in detail in this specification belongs to the prior art well-known to those skilled in the art.
[0163] In this embodiment, according to the task type and weight, tasks are clearly divided into emergency level, real-time level and non-real-time level. This enables the system to make reasonable resource allocation according to the importance and urgency of tasks, ensuring that critical tasks are processed first. For example, when the task of abnormal door lock alarm appears, due to its high weight, the system will immediately prioritize to ensure its bandwidth requirements to ensure that the alarm information can be transmitted in time and security is guaranteed.
[0164] When a task requests bandwidth, it is guaranteed in turn according to the divided task levels. This method ensures that emergency-level tasks can obtain sufficient bandwidth resources under any circumstances and will not be delayed or failed due to the interference of other tasks. For example, in a smart home system, the emergency alarm task will obtain bandwidth prior to other non-emergency tasks such as device status query, so as to notify the user of potential security threats in time. Separate token buckets are configured for tasks with different weights, and the minimum bandwidth guarantee ratio for tasks with different weights is determined. In this way, bandwidth resources can be flexibly allocated according to the characteristics and requirements of tasks. For example, for real-time level tasks, a relatively high minimum bandwidth guarantee ratio may be allocated to ensure that it can continuously and stably transmit data. For example, the camera control task needs to transmit video streams in real time, and a higher bandwidth guarantee can ensure the smoothness of the video.
[0165] According to the token bucket algorithm, the current number of tokens in each token bucket is calculated periodically. This algorithm can effectively control the traffic of tasks and avoid congestion of the channel caused by burst traffic. For example, when a task needs to transmit a large amount of data, the token bucket algorithm will limit its transmission speed according to the token generation rate and the capacity of the bucket, so that it will not instantaneously occupy too much bandwidth resources and affect the normal progress of other tasks.
[0166] The scheduling strategy unit monitors the channel bandwidth utilization rate in real time to timely understand the usage of the channel. When the channel bandwidth utilization rate exceeds the threshold bandwidth, the system can quickly react and take corresponding measures to adjust the resource allocation to avoid channel congestion. For example, when it is found that the channel bandwidth utilization rate reaches 80% (threshold bandwidth), the system will realize that there may be bandwidth pressure and adjustment is needed. A delay scheduling strategy is adopted for non-real-time level tasks, and the delay time is calculated by a formula. This strategy can reasonably delay the execution of non-critical tasks when the channel bandwidth is tight, so as to free up more bandwidth resources for emergency and real-time tasks.
[0167] Traditional systems may simply classify tasks into real-time and non-real-time categories, or the priority division of tasks is not clear and detailed enough. For example, in some traditional Internet of Things systems, tasks may only be classified into real-time tasks and non-real-time tasks according to the real-time requirements of the tasks, but the priority differences between different real-time tasks are not further distinguished, resulting in the inability to accurately meet the needs of each task during resource allocation. Through clear task level division and weight setting, this system can manage the priorities of tasks more precisely. It not only distinguishes between real-time and non-real-time tasks, but also further divides real-time tasks into emergency level and ordinary real-time level, and assigns different weights to tasks at each level, enabling the system to allocate resources more reasonably according to the actual importance and urgency of the tasks. For example, in a smart home system, the task of abnormal door lock alarm, as an emergency level task, has a significantly higher weight than the ordinary camera control task (real-time level), and the system will give priority to ensuring the bandwidth requirements of the abnormal door lock alarm task to ensure that security events can be processed in a timely manner. And the bandwidth allocation method of traditional systems may be relatively fixed and lack the ability of dynamic adjustment. For example, some traditional systems may adopt a fixed bandwidth allocation ratio, assigning a fixed bandwidth share to each task, and regardless of the actual needs of the tasks, allocate according to this fixed ratio. This method may not be able to effectively utilize channel resources in the face of sudden traffic or changes in task requirements, resulting in a decline in the performance of some tasks. This system uses the token bucket algorithm to configure independent token buckets for tasks with different weights and dynamically adjusts the allocation of tokens according to the requirements of the tasks. This method can flexibly allocate bandwidth resources according to the actual traffic requirements of the tasks and the usage of the channel. For example, when a large amount of data transmission requirements suddenly appear for an emergency task, the system can temporarily seize tokens from the token buckets of other tasks through the token bucket algorithm to meet the bandwidth requirements of the emergency task, and then return the tokens after the emergency task is completed to ensure that other tasks can continue to operate normally. This dynamic adjustment mechanism can better adapt to the uncertainty of task traffic in the Internet of Things environment and improve the utilization rate of channel resources.
[0168] When faced with excessively high channel bandwidth utilization, traditional systems may lack effective countermeasures or the measures taken may not be intelligent enough. For example, some traditional systems may simply limit the bandwidth of all tasks or randomly select some tasks for delay or discard. This approach may affect the normal execution of some important tasks and cannot fundamentally solve the problem of channel congestion. By real-time monitoring the channel bandwidth utilization and adopting a delay scheduling strategy based on formula calculation for non-real-time tasks, this system can more effectively handle channel congestion. When the channel bandwidth utilization exceeds the threshold bandwidth, the system will reasonably delay the execution of non-real-time tasks according to the priority of the tasks and the usage of the channel, making more bandwidth resources available for urgent and real-time tasks. This strategy can effectively alleviate channel congestion and improve the overall performance of the system while ensuring the normal execution of important tasks.
[0169] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application and are not intended to limit them. Although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments or perform equivalent replacements for some of the technical features. However, such modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present application.
Claims
1. An Internet of Things management system with SparkLink chip isolation and end-to-end encryption, characterized in that: including, The SparkLink physical isolation access subsystem establishes an isolation communication link through the SparkLink chip based on the physical frequency hopping channel and performs underlying identity verification based on the device hardware fingerprint; The dynamic identity feature generation subsystem generates a session dynamic identity label based on the current timestamp, device hardware fingerprint, and SparkLink channel signal feature; The multi-round session recursive authentication subsystem performs multi-round challenge and response recursive interactions based on the dynamic identity label to form an authentication closed-loop; The authentication risk feedback subsystem detects abnormal responses and calculates the risk intensity during the authentication process to feedback the threat level signal; The computing power and power consumption adaptive adjustment subsystem dynamically adjusts the authentication and encryption algorithms based on the real-time status of the smart home device; The session cache management subsystem predicts user behavior and generates a session cache in advance; The SparkLink isolation channel priority scheduling subsystem allocates the resources of the channel switched by the current channel establishment unit based on the weight of the task and the pressure of the bandwidth.
2. The Internet of Things management system for SparkLink chip isolation and end-to-end encryption according to claim 1, characterized in that: The SparkLink physical isolation access subsystem includes a channel establishment unit, an identity verification unit, and a channel switching control unit; The channel establishment unit is used to pre-select the 6GHz band as the communication band, generate a frequency hopping sequence using the chaotic mapping algorithm, switch channels within the 6GHz band according to the generated frequency hopping sequence with a period of 50ms to establish an isolation communication link, and on each channel, expand the signal bandwidth to more than 100MHz through direct sequence spread spectrum technology; The identity verification unit is used to send the device hardware fingerprint stored in the SparkLink chip to the cloud server using the channel switched by the current channel establishment unit when the smart home device connects to the smart home system network. The cloud server uses the Hamming distance to verify the difference degree between the device hardware fingerprint and the fingerprint stored in the cloud database. If the Hamming distance does not exceed the preset difference threshold, the device hardware fingerprint is considered legal, otherwise it is determined to be illegal; The channel switching control unit is used to receive the threat level signal from the authentication risk feedback subsystem. When the threat level signal is at a high threat level, it automatically switches to the advanced frequency hopping sequence. Among them, the advanced frequency hopping sequence adopts a 7-layer pseudo-random code nesting technology and the frequency hopping period is shortened to 20ms.
3. The Internet of Things management system for SparkLink chip isolation and end-to-end encryption according to claim 2, wherein: The dynamic identity feature generation subsystem includes a feature collection unit, a label generation unit, and a label verification unit; The feature collection unit is used to obtain the SparkLink channel signal feature according to the channel switched by the current channel establishment unit and generate a unique random number per session according to the hardware random number generator; The label generation unit is used to generate a 64-byte dynamic identity label Is using the SHA-384 hash algorithm according to the SparkLink channel signal feature and the unique random number per session obtained in the feature collection unit; The label verification unit is used to compare the hash values of the newly generated dynamic identity label and the previous label to obtain the similarity. If the similarity exceeds the pre-set similarity threshold, it triggers the feature collection unit to re-collect features and generate a new label.
4. The Internet of Things management system for SparkLink chip isolation and end-to-end encryption according to claim 3, wherein: The multi-round session recursive authentication subsystem includes a challenge generation unit, a response processing unit, and an authentication closed-loop control unit; The challenge generation unit is responsible for generating challenge information for verifying the identity of the smart home device during the multi-round session recursive authentication process. The challenge information includes, in the first round of authentication at the start, generating a 128-bit random number as the initial challenge, and outputting a response value after the initial challenge is generated. Using a pseudo-random number generator, with the dynamic identity tag of the smart home device as the seed, generating a random number sequence of the same length as the response value output by the initial challenge, performing an exclusive OR operation on each bit of the response value output by the initial challenge and the generated random numbers to obtain a new binary sequence, encrypting the exclusive OR result using the master key, and adopting a block cipher mode for encryption. The encrypted result is the challenge for the current round; The response processing unit is used to receive the challenge of the current round, perform an exclusive OR operation on each bit of the challenge of the current round and the dynamic identity tag of the smart home device itself to obtain a new binary sequence, use the session key as the key to perform HMAC calculation on the exclusive OR result in the response processing unit, where the hash algorithm adopts the SHA-512 hash algorithm, and the calculation result is the response value of the smart home device to the current challenge, and send it to the cloud server for verification to obtain the response result; The authentication closed-loop control unit is used to record the time length from sending the challenge to the smart home device to receiving the response from the smart home device during each round of authentication, that is, the time spent on each round of authentication. If the time spent on authentication does not fall within the safe time range or the response result is a verification error, the authentication is immediately terminated and an abnormal signal is sent to the authentication risk feedback subsystem.
5. The Internet of Things management system for SparkLink chip isolation and end-to-end encryption according to claim 4, characterized in that: The authentication risk feedback subsystem includes an anomaly detection unit, a risk assessment unit, and a signal feedback unit; The anomaly detection unit is used to receive the abnormal signal, calculate and obtain the response error rate and time offset according to the time spent on each round of authentication and the response result collected historically and in real time, and determine the abnormal response type parameter according to the type of abnormal response. Among them, the types of abnormal responses include response timeout, timing anomaly, frequency anomaly, and mode anomaly; The risk assessment unit is used to perform a weighted sum of the response error rate, time offset, and abnormal response type parameter to calculate and obtain the risk intensity; The signal feedback unit is used to compare the calculated risk intensity with the preset risk threshold to classify the calculated risk intensity into a low threat level signal, a medium threat level signal, and a high threat level signal. If it is a high threat level signal, it is sent to the XingShan physical isolation access subsystem, the computing power and power consumption adaptive adjustment subsystem, and the session cache management subsystem.
6. An Internet of Things management system for SparkLink chip isolation and end-to-end encryption according to claim 5, characterized in that: The computing power and power consumption adaptive adjustment subsystem includes a status monitoring unit, a computing power allocation unit, and an algorithm adjustment unit; The status monitoring unit is used to obtain the power, computing power load data of the smart home device and the threat level signal of the authentication risk feedback subsystem in real time; The computing power allocation unit is used to dynamically allocate computing power resources during the execution of the authentication task when the threat level signal of the authentication risk feedback subsystem changes, so as to obtain the final computing power. The specific way to obtain the final computing power is as follows: collect the real-time status of the smart home device in real time to obtain the remaining power, CPU temperature, available memory, and risk intensity, calculate the dynamic adjustment factor according to the real-time status of the smart home device, and combine it with the basic computing power requirement to calculate the final computing power; when the remaining power of the smart home device is lower than 10%, close the non-critical authentication rounds in the multi-round session recursive authentication subsystem. The algorithm adjustment unit is used to dynamically switch the encryption algorithm according to the threat level signal of the smart home device. If the remaining power is lower than 10% and the threat level signal is a low threat level signal, switch the AES-256 encryption algorithm to the AES-128 encryption algorithm.
7. An Internet of Things management system for SparkLink chip isolation and end-to-end encryption according to claim 6, characterized in that: The session cache management subsystem includes a behavior prediction unit, a key pre-generation unit, and a cache optimization unit. The prediction unit is used to predict user behavior based on historical data, use a long short-term memory network to output the probability distribution of the user's next operation, use a histogram to count the operation frequencies of each time period, and then cluster the high-density points into time period intervals through the K-means algorithm to obtain the high-frequency operation time periods. The key pre-generation unit is used to set the preparation duration. Before the preparation duration of the predicted high-frequency time period, pre-generate the session key through the channel switched by the current channel establishment unit, and cache all the generated keys in a dual encryption method of encrypting the session key with the private key of the SparkLink chip and the encryption algorithm. When the algorithm adjustment unit determines that the remaining power is lower than 10% and the threat level signal is a low threat level signal, the encryption algorithm is switched to the AES-128 encryption algorithm. The cache optimization unit is used to analyze the effectiveness of the cache policy to calculate the cache hit rate. If the cache hit rate is lower than the pre-set hit threshold, start the reinforcement learning algorithm, retrain the long short-term memory network through historical authentication data, and adjust the cache policy according to the threat level signal of the authentication risk feedback subsystem. When the threat level signal is a high threat level signal, only cache the core instruction keys.
8. An Internet of Things management system for SparkLink chip isolation and end-to-end encryption according to claim 7, characterized in that: The SparkLink isolated channel priority scheduling subsystem includes a task classification unit, a bandwidth allocation unit, and a scheduling policy unit. The task classification unit is used to receive the task type and weight data of the service logic module, divide the tasks into emergency level, real-time level, and non-real-time level according to the task type and weight data, and guarantee the requirements in turn according to the levels of the tasks when the tasks request bandwidth. The bandwidth allocation unit is used to configure independent token buckets for tasks with different weights, determine the minimum bandwidth guarantee ratio for tasks with different weights, calculate the current number of tokens in each token bucket periodically according to the token bucket algorithm. If the number of tokens in the token bucket corresponding to the emergency level task is insufficient, temporarily preempt tokens from the token buckets of other weight tasks to meet the corresponding minimum bandwidth guarantee ratio for data transmission. The scheduling policy unit is used to monitor the channel bandwidth utilization in real time. When the channel bandwidth utilization exceeds the threshold bandwidth, a delay scheduling policy is adopted for non-real-time tasks, and the delay time is calculated by the formula where is the base delay time, is the used bandwidth, is the threshold bandwidth, is the total bandwidth, is the delay time.
Citation Information
Patent Citations
Coherent laser frequency modulation communication based transmitting terminal, receiving terminal, system and method
CN107911171A
Information management method and system for access control card chip
CN119397600A
Lightweight dynamic security authentication method and system implemented based on PUF (Physical Unclonable Function)
CN119402205A
Distributed architecture for a wireless data communications system
US6005884A
Cited By
Server hardware anti-counterfeiting method and electronic equipment
CN120915452A
Security authentication encryption system for lighting equipment
CN121217323A
A security authentication and encryption system for lighting equipment
CN121217323B
Intelligent cloud box device management and remote operation and maintenance method and system
CN122554096A