A method for secure communication between an edge server and a terminal device

By generating multi-dimensional feature vectors through hardware driver loading and physical layer channel probing between edge servers and terminal devices, and combining them with coded network models and hash algorithms for identity authentication, and employing hybrid encryption technology and dynamic session key management, the problem of easy cracking and attack of existing secure communication schemes is solved, thereby improving the security, reliability and anti-attack capabilities of communication.

CN120434624BActive Publication Date: 2025-11-25BEIJING HUAKUN ZHENYU INTELLIGENT TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510743129.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-05
Publication Date
2025-11-25
Estimated Expiration
2045-06-05

AI Technical Summary

Technical Problem

Existing secure communication solutions between edge servers and terminal devices suffer from problems such as easy cracking of key management, easy expiration of static keys, and vulnerability to attacks on identity authentication. They are difficult to adapt to complex and ever-changing network environments and cannot fundamentally ensure the true identities of the communicating parties and the security of data transmission.

Method used

By loading hardware drivers and probing physical layer channels through terminal devices, multi-dimensional feature vectors are generated. Dynamic device identifiers are generated using an coded network model and identity authentication is performed using a hash algorithm. Edge servers perform multi-dimensional legitimacy verification and employ hybrid encryption technology and dynamic session key management to ensure the security and reliability of communication.

Benefits of technology

It effectively resists man-in-the-middle attacks and replay attacks, ensures the authenticity of the identities of both parties in communication, enhances the confidentiality and integrity of data transmission, adapts to complex network environments, reduces computing resource consumption, and improves communication efficiency and anti-attack capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120434624B_ABST
    Figure CN120434624B_ABST
Patent Text Reader

Abstract

The application relates to a secure communication method between an edge server and a terminal device, a physical layer channel state information database is established, a multi-dimensional feature vector is generated and encoded into a terminal device identifier, the terminal device generates an identity authentication request, performs a hash operation to obtain a first hash value, and sends the identity authentication request and the first hash value to the edge server; the edge server verifies the identity authentication request, queries a corresponding device key, performs a hash operation to obtain a second hash value, compares the second hash value with the first hash value, generates an authentication response message after success, encrypts the authentication response message by using the device key, and sends the encrypted authentication response message to the terminal device; the terminal device decrypts by using the device key, obtains a session key, and communicates with the edge server based on the session key. By utilizing physical layer channel information and device hardware features, a secure communication method combining dynamic identity authentication and efficient key management is provided, and the security, reliability and attack resistance of communication between the edge server and the terminal device are improved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The application belongs to the technical field of server communication, and particularly relates to a secure communication method between an edge server and a terminal device. BACKGROUND

[0002] With the rapid development of technologies such as the Internet of Things and artificial intelligence, edge computing has become an important support for terminal device data processing and interaction due to its low delay and high bandwidth advantages. Secure communication between an edge server and a terminal device is a core link for ensuring data privacy and stable system operation, and is widely used in fields such as industrial automation, intelligent transportation, and smart home.

[0003] At present, traditional edge server and terminal device secure communication schemes mainly rely on symmetric encryption or asymmetric encryption algorithms for data protection, and verify device identity through a static identity authentication mechanism. However, such schemes have many limitations. In terms of key management, static keys are easily cracked during long-term use, and once leaked, will lead to security failure of the entire communication link. The dynamic key update mechanism often lacks sufficient security and flexibility, and is difficult to adapt to complex and variable network environments. In terms of identity authentication, authentication methods based on simple passwords and digital certificates are vulnerable to man-in-the-middle attacks and replay attacks, and attackers can pretend to be legitimate devices by intercepting authentication information to access the system. In addition, existing schemes usually ignore physical layer channel characteristics and device hardware features, and are difficult to resist attacks on communication protocol vulnerabilities, and cannot ensure the authenticity of the communication parties and the security of data transmission from the root.

[0004] With the explosive growth of the number of terminal devices and the increasing diversification of network attack methods, traditional secure communication methods have been difficult to meet the actual application requirements, and the present application provides a secure communication method that fully utilizes physical layer channel information and device hardware features, and combines dynamic identity authentication and efficient key management, to improve the security, reliability, and attack resistance of communication between an edge server and a terminal device. SUMMARY

[0005] The purpose of the present application is to provide a secure communication method between an edge server and a terminal device, which fully utilizes physical layer channel information and device hardware features, and combines dynamic identity authentication and efficient key management, to improve the security, reliability, and attack resistance of communication between an edge server and a terminal device.

[0006] To solve the above technical problems, the technical solution adopted by the present application is as follows:

[0007] A secure communication method between an edge server and a terminal device, comprising the following steps:

[0008] S1: the terminal device starts the wireless transceiver module and performs hardware driver loading and physical layer channel probing and modeling, establishes a physical layer channel state information database, and generates a multi-dimensional feature vector;

[0009] S2: the multi-dimensional feature vector is encoded into a terminal device identifier of a specified bit;

[0010] S3: the terminal device generates an identity authentication request, the identity authentication request containing a terminal device identifier and a random number, performs a hash operation on the identity authentication request using a preset hash algorithm to obtain a first hash value, and sends the identity authentication request and the first hash value to an edge server;

[0011] S4: the edge server verifies the legality of the identity authentication request, and if the request is judged to be legal, queries a device key of the corresponding terminal device stored locally according to the terminal device identifier;

[0012] S5: the same hash algorithm is used to perform a hash operation on the identity authentication request and the device key to obtain a second hash value, and the first hash value and the second hash value are compared, if they are the same, an authentication response message containing a session key, an edge server identifier, and a timestamp is generated, the authentication response message is encrypted using the device key, and the encrypted authentication response message is sent to the terminal device;

[0013] S6: the terminal device uses the device key to decrypt and obtain the session key, and uses the session key to communicate with the edge server, and the session key is dynamically updated during the communication process.

[0014] Preferably, the specific process of step S1 is as follows:

[0015] S11: the terminal device starts the wireless transceiver module to automatically load a preset physical layer protocol stack firmware, the physical layer protocol stack firmware including a radio frequency parameter calibration module and a spectrum sensing engine;

[0016] S12: the edge server broadcasts a pilot signal containing a time synchronization marker through a directional antenna array, and the terminal device dynamically adjusts the transmission power according to the received signal strength;

[0017] S13: the terminal device sends an orthogonal frequency division multiplexing training sequence, and the edge server extracts a multipath time delay spread parameter and a channel impulse response matrix;

[0018] S14: extract the hardware inherent characteristics of the terminal device, the hardware inherent characteristics including a carrier frequency offset statistic and an I / Q imbalance parameter phase noise distribution, collect random disturbance characteristics of the physical layer channel state information and GPS positioning trajectory, the physical layer channel state information including a Doppler shift and a path loss index;

[0019] S15: generating a multi-dimensional feature vector based on the terminal device hardware inherent characteristics, physical layer channel state information and random perturbation characteristics of the GPS positioning trajectory.

[0020] Preferably, the multi-dimensional feature vector in step S2 is encoded into a specific process of terminal device identifier with a specified bit as follows:

[0021] S21: constructing an encoding network model, and inputting the multi-dimensional feature vector into the input layer of the encoding network model;

[0022] S22: the feature extraction layer of the encoding network model extracts the spatial correlation characteristics between each feature in the input multi-dimensional feature vector;

[0023] S23: the feature compression layer of the encoding network model compresses the spatial correlation characteristics, and the output of the feature compression layer is constrained to the interval [-1, 1] through the tanh activation function;

[0024] S24: the features constrained to the interval [-1, 1] are encoded into 128-bit binary dynamic hash code, i.e. device identifier, through a preset sign function.

[0025] Preferably, the specific process of the feature extraction layer of the encoding network model extracting the spatial correlation characteristics between each feature in the input multi-dimensional feature vector in step S22 is as follows:

[0026] S221: the original multi-dimensional feature vector is reshaped into a two-dimensional feature matrix, and the channel number is dynamically adjusted according to the feature dimension;

[0027] S222: the feature extraction layer includes at least three layers, low-level feature extraction is performed through the first layer of the feature extraction layer, local feature correlation is calculated through a sliding window, and a nonlinear value is introduced through a ReLU activation function;

[0028] S223: middle-level feature aggregation is performed through the second layer of the feature extraction layer, the receptive field is expanded through a hollow convolution, and convergence is accelerated through batch normalization;

[0029] S224: high-level semantic fusion is performed through the third layer of the feature extraction layer, feature weights are dynamically adjusted through a channel attention mechanism, and multi-scale information is captured through spatial pyramid pooling;

[0030] S225: the features output by the first layer are connected with the features output by the third layer through a skip connection, spatial coordinate information is embedded into the feature channel through a position encoding vector, and the spatial correlation characteristics are obtained.

[0031] Preferably, the specific process of step S3 is as follows:

[0032] S31: The terminal device generates a random number through a built-in random number generator, combines the device identifier and the random data according to a preset data format to generate an identity authentication request;

[0033] S32: A preset hash algorithm library is called, and a preset hash algorithm is used to perform hash operation on the identity authentication request to convert the identity authentication request into a first hash value of a specified length;

[0034] S33: The identity authentication request and the first hash value are encapsulated in a specified network data packet by using a transport layer protocol in a TCP / IP protocol stack;

[0035] S34: The network data packet is ensured not to be tampered after encapsulation by calculating a hash value of the network data packet and comparing the hash value with a pre-stored hash value;

[0036] S35: The terminal device sends the data packet processed in a secure manner to an edge server through a specified network interface.

[0037] Preferably, the specific process of verifying the legality of the identity authentication request by the edge server in step S4 is as follows:

[0038] S41: A network monitoring module of the edge server monitors a specified port in real time, and when receiving the identity authentication request data packet sent by the terminal device, the network monitoring module performs unpacking on the data packet through a network protocol stack to extract original data containing the identity authentication request and the first hash value from the TCP / IP protocol data;

[0039] S42: The identity authentication request is parsed according to a preset data format to separate the terminal device identifier and the random number, which prepares for subsequent verification steps;

[0040] S43: Whether the identity authentication request contains a timestamp field is checked, and the timestamp in the request is compared with a system time of the edge server, while a preset time tolerance range is considered; if the timestamp exceeds the tolerance range, it is indicated that the request is expired or an attacker attempts to perform illegal authentication by replaying an old request, and the edge server immediately rejects the request and records an abnormal request log for subsequent security audit;

[0041] S44: According to the terminal device identifier obtained by parsing, a device registration information library stored locally in the edge server is queried to verify whether the device identifier is legal and the registration state of the device is normal; if the device identifier is illegal or the state is abnormal, it is indicated that the request source is suspicious, and the edge server directly rejects the identity authentication request and returns error information of authentication failure to the terminal device;

[0042] S45: After confirming the legality of the device identifier, the device key corresponding to the terminal device is extracted from the device key management module according to the device identifier. The device key is assigned by the system and securely stored in the device registration stage, and is used for encryption and verification operations in the identity authentication process, which is a key element for ensuring the authenticity of the communication parties;

[0043] S46: The received identity authentication request and the extracted device key are hashed using the same preset hash algorithm as the terminal device, a second hash value is generated, and the generated second hash value is accurately compared with the first hash value carried in the identity authentication request. If the two hash values are completely consistent, it means that the terminal device has the correct device key, and the request has not been tampered with during transmission, and the identity authentication is initially passed. Otherwise, it is determined that there is a problem with the request, and the identity authentication request is rejected, and further security measures are taken, such as limiting the number of retries of the device to prevent brute force attack;

[0044] S47: The edge server performs further security verification, checks whether the source IP address of the request is within the authorized IP address segment to prevent illegal devices from performing authentication by pseudo IP; the frequency of the request is analyzed, and if a large number of authentication requests from the same device are received within a short period of time, it may be subject to malicious attacks, and the edge server will limit or block the requests of the device.

[0045] Preferably, the specific process of step S5 is as follows:

[0046] S51: Extract the terminal device identifier and the original data field of the random number in the analysis result of the identity verification request;

[0047] S52: Call the built-in cryptography library of the system, concatenate the extracted request data and the device key in a predetermined order, and perform hash calculation using the predetermined hash algorithm to generate a second hash value;

[0048] S53: Use the time constant comparison algorithm to compare the first hash value and the second hash value bit by bit, if the comparison is successful, execute step S54, otherwise record the exception and punish the security audit process;

[0049] S54: Call the security random number generator of the cryptography library to generate a session key of a specified bit, which will be used for symmetric encryption in subsequent communication;

[0050] S55: Get the high-precision system time of the edge server, convert it into an ISO 8601 format string timestamp, which is used to identify the response generation time;

[0051] S56: extracting the unique identifier of the edge server from the server configuration file, assembling the authentication response message according to a specified rule by using the session key, the timestamp and the unique identifier of the edge server, encrypting the authentication response message and transmitting the encrypted authentication response message to the device terminal.

[0052] Preferably, the specific process of transmitting the encrypted authentication response message to the device terminal in step S56 is as follows:

[0053] S561: converting the authentication response message into a byte stream to generate a specified byte random initialization vector value;

[0054] S562: encoding the byte stream according to a specified rule based on the device key, and then encrypting the byte stream using a preset symmetric encryption algorithm to generate ciphertext and an authentication tag, wherein a message authentication code is automatically generated during the encryption process to ensure data integrity;

[0055] S563: splicing the initialization vector value, the ciphertext and the authentication tag according to a specified format, and converting the splicing result into a Base64 encoded authentication response message;

[0056] S564: wrapping the encrypted authentication response into a secure communication protocol frame, adding a protocol version number and message type metadata, sending the response message to the terminal device through a preconfigured TLS1.3 session, establishing an encrypted channel using a server certificate and a private key, setting a response timeout, triggering a retransmission mechanism and recording a timeout log if the device terminal does not confirm receipt within the specified time, using a specified transmission protocol to ensure message delivery, and closing the communication connection after receiving the ACK confirmation of the terminal.

[0057] The beneficial effects of the present application include:

[0058] The secure communication method between the edge server and the terminal device provided by the present application starts the wireless transceiver module of the terminal device, loads the hardware driver and performs physical layer channel detection and modeling to establish a physical layer channel state information database and generate a multi-dimensional feature vector. The identity is authenticated through a preset hash algorithm, the authentication response message is encrypted, and the encrypted authentication response message is sent to the terminal device. The terminal device uses the device key to decrypt and obtain the session key, and communicates with the edge server based on the session key. By using the physical layer channel information and the device hardware features, the secure communication method of dynamic identity authentication and efficient key management is fused, and the security, reliability and attack resistance of the communication between the edge server and the terminal device are improved.

[0059] Firstly, by constructing a multi-dimensional feature vector based on physical layer channel state information and device hardware inherent characteristics, and using an encoding network model to encode it into a dynamic device identifier, each terminal device has a unique and difficult to copy identity. The physical layer channel characteristics will change dynamically with the environment, and the hardware inherent characteristics have device uniqueness. The device identifier generated by combining the two effectively resists the man-in-the-middle attack, replay attack and other attacks that the traditional static identity authentication is vulnerable to, and ensures the authenticity of the identity of the communication parties from the root. At the same time, the multi-dimensional legitimacy verification process of the edge server, including timestamp verification, IP address check, request frequency analysis, further improves the security and reliability of the identity authentication.

[0060] Secondly, during data transmission, hybrid encryption technology is used. The device key and symmetric encryption algorithm are combined when encrypting the authentication response message, and the TLS 1.3 protocol is used to establish an encrypted channel during network transmission. Double encryption ensures the confidentiality and integrity of data during transmission. At the same time, the data is digitally signed and message authentication code processed to ensure that the data has not been tampered with and is reliable, effectively preventing data from being stolen, forged and tampered with, and improving the security of data transmission.

[0061] Thirdly, the terminal device dynamically adjusts the transmission power according to the physical layer channel detection results, and the edge server optimizes the communication parameters by analyzing the channel state information, so that the communication system can better adapt to the complex and changeable network environment and ensure the stability of the communication. And through machine learning algorithm to analyze the communication data in real time, timely discovery of abnormal communication behavior and take corresponding protection measures, enhance the system's resistance to network attack ability, improve the survival ability of the communication system in complex network environment.

[0062] Finally, in the process of identity authentication and data transmission, efficient hash algorithm, symmetric encryption algorithm and optimized data processing process are used to reduce the consumption of computing resources and data transmission delay. The use of orthogonal frequency division multiplexing training sequence improves the spectrum utilization, and the fast processing and compression of the feature by the encoding network model speeds up the identity authentication, thereby improving the communication efficiency between the edge server and the terminal device as a whole, meeting the demand of real-time application scenarios. The session key is updated dynamically during communication to avoid the risk of static key being cracked for long-term use, significantly enhancing the security of the key. BRIEF DESCRIPTION OF DRAWINGS

[0063] Fig. 1 It is a flowchart of the secure communication method between the edge server and the terminal device of the present application.

[0064] Fig. 2 It is a flowchart of encoding a multi-dimensional feature vector into a terminal device identifier with a specified bit.

[0065] Fig. 3 A dynamic updating flowchart of the session key of the present application. DETAILED DESCRIPTION

[0066] The accompanying drawings are referred to in order to better understand the present application. Figs. 1-3 The present application is further described in detail:

[0067] Embodiment 1

[0068] The accompanying drawings are referred to in order to better understand the present application. Fig. 1 As shown in the accompanying drawings, a secure communication method between an edge server and a terminal device includes the following steps:

[0069] S1: The terminal device starts the wireless transceiver module and performs hardware driver loading and physical layer channel probing and modeling, establishes a physical layer channel state information database, and generates a multi-dimensional feature vector. After the terminal is powered on, the operating system thereof calls the driver program of the wireless transceiver module through the hardware abstraction layer and drives the physical layer protocol stack firmware. At the same time, the driver program initializes the module register and configures the radio frequency parameter, and completes the hardware self-checking. The terminal device actively sends a probing signal, or passively receives surrounding wireless signals. Based on the physical layer parameters such as signal strength, phase offset, and multipath time delay, a channel impulse response model is constructed through a signal processing algorithm. The physical layer channel state information is extracted from the physical layer channel, including time domain features: time delay spread, number of multipaths; frequency domain features: channel frequency response, fading depth; spatial features (if there are multiple antennas): angle spread, angle of arrival (AoA); statistical features: mean, variance, correlation time.

[0070] S2: The multi-dimensional feature vector is encoded into a terminal device identifier with a specified number of bits. A coding network model is constructed to extract features from the input multi-dimensional feature vector. First, the feature extraction layer of the coding network model extracts the spatial correlation features between each feature in the input multi-dimensional feature vector. The feature compression layer of the coding network model compresses the spatial correlation features, and the output of the feature compression layer is constrained through a tanh activation function. The constrained features are encoded into a specified number of binary dynamic hash codes, i.e., a device identifier, through a preset sign function.

[0071] S3: The terminal device generates an identity authentication request, the identity authentication request containing a terminal device identifier and a random number, hashes the identity authentication request using a preset hash algorithm to obtain a first hash value, and sends the identity authentication request and the first hash value to the edge server. The terminal device generates a random number through a built-in random number generator, combines the device identifier and the random data according to a preset data format to generate an identity authentication request, hashes the identity authentication request using a preset hash algorithm to obtain a first hash value, and encapsulates the identity authentication request and the first hash value. The terminal device sends the data packet after security processing to the edge server through a specified network interface.

[0072] S4: After verifying the legality of the identity authentication request, the edge server queries the locally stored device key of the corresponding terminal device according to the terminal device identifier. The network monitoring module of the edge server monitors the specified port in real time, and when receiving the identity authentication request data packet sent by the terminal device, extracts the original data of the identity authentication request and the first hash value by unpackaging the data packet through the network protocol stack. The identity authentication request is parsed, and whether the terminal device identifier is legal and the registration state is normal is queried according to the parsed terminal device identifier. The pre-stored device key is extracted from the device key management module, and the identity authentication request and the device key are hashed to generate a second hash value, which is compared with the first hash value. The edge server performs further security verification to check whether the source IP address of the request is within the authorized IP address segment.

[0073] S5: The identity authentication request and the device key are hashed using the same hash algorithm to obtain a second hash value, and the first hash value and the second hash value are compared. If they are the same, an authentication response message containing a session key, an edge server identifier, and a timestamp is generated, the authentication response message is encrypted using the device key, and the encrypted authentication response message is sent to the terminal device.

[0074] S6: The terminal device uses the device key to decrypt and obtain the session key, and uses the session key to communicate with the edge server. The session key is dynamically updated during the communication process. The terminal device receives the encrypted response message (ciphertext) sent by the edge server. The terminal uses the locally stored device key to decrypt the response. The HMAC value of the received message is calculated and compared with the MAC in the response. The difference between the Timestamp and the local time is checked to avoid replay attacks. Both parties use the Session_Key as a symmetric key and use the AES-GCM mode for communication, which can provide encryption and authentication.

[0075] A session key update mechanism is set, and the dynamic update trigger condition of the session key is time-driven or data volume-driven or event-driven. The dynamic update process of the session key is that when any session key dynamic update trigger condition occurs, the edge server generates a new session key SK-new and sends it to the terminal device, the terminal device receives and updates the session key, verifies the time stamp and sequence number, and activates and saves the new session key SK-new after passing. In the above dynamic update process of the session key, a security protection mechanism for key update is set.

[0076] Embodiment 2

[0077] On the basis of embodiment 1, the specific process of step S1 is as follows:

[0078] S11: The terminal device starts the wireless transceiver module to automatically load the preset physical layer protocol stack firmware, and the physical layer protocol stack firmware includes a radio frequency parameter calibration module and a spectrum sensing engine. After the terminal device is powered on, the operating system locates the firmware path of the wireless module through the device tree or the driver registry. The preset physical layer protocol stack firmware is loaded, which is usually stored in the SPI Flash or eMMC. The physical layer protocol stack firmware includes a radio frequency parameter calibration module and a spectrum sensing engine. The radio frequency parameter calibration module is used to compensate for the frequency offset and power fluctuation caused by temperature and voltage changes; the spectrum sensing engine scans the available spectrum resources based on the energy detection or feature detection algorithm.

[0079] The firmware performs a hardware self-test to verify the status of the radio frequency front-end components. The initial radio frequency parameters, such as center frequency, transmit power, modulation mode, and channel bandwidth, are configured. The spectrum sensing engine performs wide-band scanning (such as 2.4GHz~6GHz) to detect primary user signals, co-frequency interference sources, noise floor distribution, and generate a spectrum occupancy map to select the optimal frequency band for subsequent communication.

[0080] S12: The edge server broadcasts pilot signals containing time synchronization markers through a directional antenna array, and the terminal device dynamically adjusts the transmit power according to the received signal strength. The edge server generates narrow beams through a large-scale MIMO antenna array to broadcast pilot signals containing time synchronization markers. The terminal device calculates the received signal strength indication (RSSI) by receiving the pilot signals, and dynamically adjusts the transmit power based on the RSSI, with the formula:

[0081] P tx = P ref - RSSI + Δ.

[0082] Where P tx is the adjusted power, P ref is the reference power, and Δ is the margin.

[0083] The power adjustment step is usually 1dB, and the adjustment period is 10ms.

[0084] S13: The terminal device sends an orthogonal frequency division multiplexing training sequence, and the edge server extracts a multipath delay spread parameter and a channel impulse response matrix. The terminal sends an orthogonal frequency division multiplexing training sequence as an OFDM training signal, which includes a time domain synchronization sequence, a frequency domain pilot symbol, and a cyclic prefix, which is used to resist multipath effects. After the server receives the signal, the following actions are performed: time domain synchronization: determine the symbol boundary through correlation detection; frequency offset estimation: compensate for the carrier frequency offset; channel estimation: calculate the channel frequency response based on the least squares (LS) or minimum mean square error algorithm.

[0085] S14: Extract the terminal device hardware inherent characteristics, including the carrier frequency offset statistics and the I / Q imbalance parameter phase noise distribution, collect the random disturbance features of the physical layer channel state information and the GPS positioning trajectory, and the physical layer channel state information includes the Doppler shift and the path loss index. Estimate the carrier frequency offset statistics through the phase difference of multiple OFDM symbols; calculate the mean, variance, and autocorrelation function of the carrier frequency offset statistics as features. Estimate the gain imbalance and phase error of the in-phase and quadrature branches; typical features include gain mismatch and phase error. Collect the original GPS coordinates (longitude, latitude, and altitude); calculate the speed fluctuation variance, acceleration sudden change point number, and trajectory deviation from the map road to obtain the random disturbance features of the GPS positioning trajectory.

[0086] S15: Based on the terminal device hardware inherent characteristics, the physical layer channel state information, and the random disturbance features of the GPS positioning trajectory, a multi-dimensional feature vector is generated.

[0087] In this embodiment, referring to FIG. 2, the multi-dimensional feature vector is encoded in step S2, and the specific process of encoding the terminal device identifier with a specified bit is as follows: Fig. 2

[0088] S21: Construct an encoding network model, and input the multi-dimensional feature vector into the input layer of the encoding network model;

[0089] S22: The feature extraction layer of the encoding network model extracts the spatial correlation features between each feature in the input multi-dimensional feature vector;

[0090] S23: The feature compression layer of the encoding network model performs feature compression on the spatial correlation features, and the output of the feature compression layer is constrained to the [-1, 1] interval through a tanh activation function;

[0091] ​S24: encode the features constrained to the interval [-1, 1] into a 128-bit binary dynamic hash code, i.e., a device identifier, by a preset sign function.

[0092] The specific process of extracting the spatial correlation features between each feature in the input multi-dimensional feature vector by the feature extraction layer of the encoding network model in step S22 is as follows:

[0093] S221: reshape the original multi-dimensional feature vector into a two-dimensional feature matrix, and dynamically adjust the number of channels according to the feature dimension;

[0094] S222: the feature extraction layer includes at least three layers, low-level feature extraction is performed by the first layer of the feature extraction layer, local feature correlation is calculated by a sliding window, and a nonlinear value is introduced by a ReLU activation function;

[0095] S223: middle-level feature aggregation is performed by the second layer of the feature extraction layer, the receptive field is expanded by a dilated convolution, and convergence is accelerated by batch normalization;

[0096] S224: high-level semantic fusion is performed by the third layer of the feature extraction layer, feature weights are dynamically adjusted by a channel attention mechanism, and multi-scale information is captured by spatial pyramid pooling;

[0097] S225: the features output by the first layer are connected to the features output by the third layer by a skip connection, spatial coordinate information is embedded into the feature channel by a position encoding vector, and spatial correlation features are obtained.

[0098] Embodiment 3

[0099] On the basis of embodiment 1 or embodiment 2, the specific process of step S3 is as follows:

[0100] S31: the terminal device generates a random number by a built-in random number generator, combines the device identifier and the random data according to a preset data format to generate an identity authentication request;

[0101] S32: call a preset hash algorithm library, perform hash operation on the identity authentication request using a preset hash algorithm, and convert the identity authentication request into a first hash value of a specified length;

[0102] S33: encapsulate the identity authentication request and the first hash value in a specified network data packet using a transport layer protocol in a TCP / IP protocol stack;

[0103] S34: ensure that the network data packet is not tampered after encapsulation by calculating the hash value of the network data packet and comparing it with a pre-stored hash value;

[0104] S35: The terminal device sends the security-processed data packet to the edge server through a designated network interface.

[0105] The specific process of verifying the legality of the identity authentication request by the edge server in step S4 is as follows:

[0106] S41: The network monitoring module of the edge server monitors a designated port in real time, and when receiving the identity authentication request data packet sent by the terminal device, the module unpacks the data packet through a network protocol stack and extracts the original data containing the identity authentication request and the first hash value from the TCP / IP protocol data;

[0107] S42: The identity authentication request is parsed according to a preset data format, and the terminal device identifier and the random number are separated out, preparing for the subsequent verification steps;

[0108] S43: It is checked whether the identity authentication request contains a timestamp field, and the timestamp in the request is compared with the system time of the edge server, while considering a preset time tolerance range. If the timestamp exceeds the tolerance range, it indicates that the request is expired or an attacker attempts to perform illegal authentication by replaying an old request, and the edge server immediately rejects the request and records the abnormal request log for subsequent security audit;

[0109] S44: According to the terminal device identifier obtained by parsing, the device registration information library stored locally in the edge server is queried to verify whether the device identifier is legal and the registration state of the device is normal. If the device identifier is illegal or the state is abnormal, it indicates that the request source is suspicious, and the edge server directly rejects the identity authentication request and returns error information of authentication failure to the terminal device;

[0110] S45: After confirming the legality of the device identifier, the device key corresponding to the terminal device is extracted from the device key management module according to the device identifier. The device key is allocated by the system and securely stored during the device registration stage, and is used for encryption and verification operations in the identity authentication process, which is a key element for ensuring the authenticity of the communication parties;

[0111] S46: The received identity authentication request and the extracted device key are hashed using the same preset hash algorithm as the terminal device, a second hash value is generated, and the generated second hash value is accurately compared with the first hash value carried in the identity authentication request. If the two hash values are exactly the same, it indicates that the terminal device has the correct device key and the request has not been tampered with during transmission, and the identity authentication is initially passed. Otherwise, it is determined that there is a problem with the request, and the identity authentication request is rejected, and further security measures are taken, such as limiting the number of retries of the device to prevent brute force attack;

[0112] S47: The edge server performs further security verification, checks whether the source IP address of the request is in the authorized IP address segment, prevents illegal devices from performing authentication through pseudo IP, and analyzes the frequency of the request. If a large number of authentication requests from the same device are received in a short time, it may be subjected to malicious attacks, and the edge server will limit or block the requests of the device.

[0113] Embodiment 4

[0114] On the basis of Embodiment 1 or Embodiment 2 or Embodiment 3, the specific process of step S5 is as follows:

[0115] S51: Extract the terminal device identifier and the random number original data field in the analysis result of the identity verification request. The terminal device identifier is 128-bit 16-byte symbols, and the random number is 64-bit 8-byte symbols. The analysis result also includes a 32-bit 4-byte timestamp.

[0116] S52: Call the built-in cryptography library of the system, and splice the extracted request data and the device key according to the preset order. The specific spliced data = device ID || random number || timestamp || device key, and || represents byte string splicing. Use the preset hash algorithm to perform hash calculation to generate a second hash value.

[0117] S53: Use the time-invariant comparison algorithm to compare the first hash value and the second hash value bit by bit. The time-invariant comparison algorithm is used to avoid timing attacks. If the comparison is successful, step S54 is executed, otherwise the abnormality is recorded and the security audit process is punished.

[0118] S54: Use the security random number generator of the cryptography library provided by the operating system to generate a session key of a specified bit, and check the generated key entropy value. The key will be used for subsequent communication of symmetric encryption.

[0119] S55: Obtain the high-precision system time of the edge server, and convert it into an ISO 8601 format timestamp string, which is used to identify the response generation time;

[0120] S56: Extract the unique identifier of the edge server from the server configuration file, assemble the session key, timestamp and unique identifier of the edge server according to the specified rule to generate an authentication response message, and transmit the encrypted authentication response message to the device terminal.

[0121] The specific process of transmitting the encrypted authentication response message to the device terminal in step S56 is as follows:

[0122] S561: Convert the authentication response message into a byte stream, and generate a random initialization vector value of a specified byte;

[0123] S562: Perform encryption processing on the byte stream based on the device key, using a preset symmetric encryption algorithm after specified rule encoding, to generate ciphertext and an authentication tag. A message authentication code is automatically generated during the encryption process to ensure data integrity.

[0124] S563: Concatenate the initialization vector value, ciphertext, and authentication tag in a specified format, and convert the concatenation result into a Base64 encoded authentication response message.

[0125] S564: Wrap the encrypted authentication response into a secure communication protocol frame, add protocol version number and message type metadata, send the response message to the terminal device through a preconfigured TLS1.3 session, establish an encrypted channel using the server certificate and private key, set a response timeout, trigger a retransmission mechanism and record a timeout log if the device terminal does not confirm receipt within the specified time, use a specified transmission protocol to ensure message delivery, and close the communication connection after receiving the ACK confirmation of the terminal.

[0126] The terminal device in step S6 uses the device key for decryption, obtains the session key, and uses the session key for communication between the edge server. The specific process of dynamically updating the session key during communication is as follows:

[0127] The terminal device receives the encrypted response message (ciphertext) sent by the edge server, which has the format: Encrypted_Response = AES-CBC (device key, Session_Key||Server_ID||Timestamp||MAC). Where: device key is a 256-bit device key pre-shared by the terminal and the server; Session_Key is a newly generated 256-bit session key; and MAC is a message authentication code used to verify data integrity.

[0128] The terminal uses the locally stored device key to decrypt the response. The HMAC value of the received message is calculated and compared with the MAC in the response. The difference between the Timestamp and the local time is checked to avoid replay attacks. Both parties use the Session_Key as a symmetric key and use the AES-GCM mode for communication, which can provide encryption and authentication.

[0129] The dynamic updating mechanism of the session key is as follows:

[0130] The dynamic updating trigger conditions of the session key are: time-driven: set a fixed update period and use a counter to record the session duration. Data volume-driven: cumulative encrypted data volume exceeds a preset threshold; event-driven: abnormal traffic is detected, and the number of key usage reaches a preset upper limit.

[0131] Referring to Fig. 3 As shown, the dynamic updating process of the session key is as follows: when any session key dynamic updating trigger condition occurs, the edge server generates a new session key SK-new, sends the character Enc(SK-old, SK-new||timestamp||sequence number) obtained by splicing the new session key SK-new, the original session key SK-old, a timestamp, and a sequence number to the terminal device, the terminal device receives and decrypts the new session key SK-new with the original session key SK-old, verifies the timestamp and the sequence number, generates the character Enc(SK-new, confirmation message||timestamp||) and returns it to the edge server, and the edge server verifies the confirmation message and activates and saves the new session key SK-new after the confirmation message is passed.

[0132] In the above dynamic updating process of the session key, a security protection mechanism for key updating is set, specifically, the sequence number is incremented each time the key is updated to prevent the old key update message from covering the new key: the terminal and the server each maintain a local sequence number, which is compared when received, and if the received sequence number is less than the local record, the message is discarded. A double key validity period is set, and the new and old keys coexist for a specified period of time, during which the sender uses the new key for encryption, and the receiver simultaneously attempts to decrypt with the new and old keys, and if successful, the local key is updated.

[0133] A key derivation function is used to generate the session key: the session key is derived based on the master key and contains session ID, timestamp, etc. If the master key is leaked, the past session keys are still secure because the derivation process introduces time entropy. The terminal device locally encrypts the last N session keys, and uses the device unique identifier as the encryption key.

[0134] If the terminal fails to decrypt the new key, it sends a failure message to the server, and the server retries to send the new key after receiving the failure message, up to 3 times. If it still fails, the current session is terminated and the terminal is required to re-initiate the authentication process. The keys of both parties are periodically checked for consistency: the server sends a random number R encrypted with the current session key; the terminal returns Hash(R||timestamp) after decryption, and the server verifies the result. If a key leakage risk is detected, the server sends a key revocation instruction, and the terminal deletes the current key immediately after receiving it and enters the re-authentication process.

[0135] In summary, the security communication method between the edge server and the terminal device provided by the application, through the terminal device starts the wireless transceiver module and carries out hardware driver loading and physical layer channel detection and modeling, establishes a physical layer channel state information database, and generates a multi-dimensional feature vector. The identity authentication is carried out through a preset hash algorithm, the authentication response message is encrypted, and the encrypted authentication response message is sent to the terminal device. The terminal device uses the device key for decryption, obtains the session key, and communicates with the edge server based on the session key. By utilizing the physical layer channel information and the device hardware features, the dynamic identity authentication and the efficient key management are combined, and the security, reliability and attack resistance of the communication between the edge server and the terminal device are improved.

[0136] By constructing a multi-dimensional feature vector based on the physical layer channel state information and the inherent hardware features of the device, the multi-dimensional feature vector is encoded into a dynamic device identifier by using an encoding network model, so that each terminal device has a secure identity identifier. The physical layer channel feature dynamically changes with the environment, and the hardware inherent feature has device uniqueness, and the device identifier generated by combining the two effectively resists security risks. At the same time, the multi-dimensional legitimacy verification process of the edge server, and the multiple encryption of the hybrid encryption technology in the data transmission process guarantee the confidentiality and integrity of the data in the transmission process.

[0137] The terminal device dynamically adjusts the transmission power according to the physical layer channel detection result, and the edge server optimizes the communication parameters by analyzing the channel state information, so that the communication system can better adapt to the complex and changeable network environment and guarantee the stability of the communication. In the identity authentication and data transmission process, efficient hash algorithm, symmetric encryption algorithm and optimized data processing process are adopted, which reduces the consumption of computing resources and data transmission delay. The use of orthogonal frequency division multiplexing training sequence improves the spectrum utilization, and the fast processing and compression of the feature by the encoding network model speeds up the identity authentication, thereby improving the communication efficiency between the edge server and the terminal device as a whole, and meeting the demand of the application scene with high real-time requirement. The session key is dynamically updated during the communication process, which avoids the risk that the static key is easily cracked due to long-term use, and significantly enhances the security of the key.

Claims

1. A secure communication method between an edge server and a terminal device, characterized in that, Includes the following steps: S1: The terminal device starts the wireless transceiver module and loads the hardware driver and performs physical layer channel detection and modeling, establishes a physical layer channel state information database, and generates multi-dimensional feature vectors. S2: Encode the multidimensional feature vector into a terminal device identifier of a specified number of bits; S3: The terminal device generates an identity authentication request, which includes a terminal device identifier, a random number, and a timestamp. A preset hash algorithm is used to perform a hash operation on the identity authentication request and the device key to obtain a first hash value. The identity authentication request and the first hash value are then sent to the edge server. S4: The edge server verifies the legitimacy of the authentication request. If the request is deemed legitimate, it queries the device key of the corresponding terminal device stored locally based on the terminal device identifier. S5: Use the same hash algorithm to perform a hash operation on the authentication request and the device key to obtain a second hash value. Compare the first hash value and the second hash value. If they are the same, generate an authentication response message containing the session key, edge server identifier, and timestamp. Encrypt the authentication response message using the device key and send the encrypted authentication response message to the terminal device. S6: The terminal device uses the device key to decrypt and obtain the session key, and communicates with the edge server using the session key. During the communication process, the session key is dynamically updated. The specific process of step S1 is as follows: S11: The terminal device starts the wireless transceiver module to automatically load the preset physical layer protocol stack firmware, which includes a radio frequency parameter calibration module and a spectrum sensing engine. S12: The edge server broadcasts a pilot signal containing time synchronization markers through a directional antenna array, and the terminal device dynamically adjusts the transmission power according to the received signal strength; S13: The terminal device sends the orthogonal frequency division multiplexing training sequence, and the edge server extracts the multipath delay spread parameters and the channel impulse response matrix; S14: Extract the inherent hardware features of the terminal device, including carrier frequency offset statistics and I / Q imbalance parameter phase noise distribution; collect physical layer channel state information and random disturbance features of GPS positioning trajectory, including Doppler frequency shift and path loss index. S15: Generate a multi-dimensional feature vector based on the inherent hardware characteristics of the terminal device, physical layer channel state information, and random disturbance characteristics of the GPS positioning trajectory; In step S6, a dynamic session key update mechanism is set up so that the session key is dynamically updated when the dynamic session key update trigger condition is met: The edge server generates a new session key SK-new, and sends the concatenated string Enc(SK-old, SK-new||timestamp||serial number) to the terminal device. The terminal device receives and decrypts the new session key SK-old to obtain the new session key SK-new, verifies the timestamp and serial number to generate the string Enc(SK-new, acknowledgment message||timestamp) and returns it to the edge server. After the edge server verifies the acknowledgment message, it activates and saves the new session key SK-new. And set up a security protection mechanism for key updates: Each time the key is updated, the sequence number is incremented to prevent the old key update message from overwriting the new key: the terminal and the server each maintain a local sequence number, which is compared upon receiving the message. If the received sequence number is less than the local record, the message is discarded. Set the validity period of the dual keys, with the old and new keys coexisting for a specified time period. During this specified time period, the sender uses the new key to encrypt, and the receiver simultaneously attempts to decrypt using both the old and new keys. If successful, the local key is updated.

2. The secure communication method between an edge server and a terminal device according to claim 1, characterized in that, The specific process of encoding the multidimensional feature vector into a terminal device identifier of a specified number of bits in step S2 is as follows: S21: Construct an encoding network model and input the multidimensional feature vector into the input layer of the encoding network model; S22: The feature extraction layer of the encoding network model extracts the spatial correlation features between features in the input multidimensional feature vector; S23: The feature compression layer of the encoding network model compresses the spatial correlation features and constrains the output of the feature compression layer to the interval [-1, 1] by using the tanh activation function; S24: Encode the features constrained to the [-1, 1] interval into a 128-bit binary dynamic hash code, i.e., the device identifier, through a preset symbol function.

3. The secure communication method between an edge server and a terminal device according to claim 2, characterized in that, The specific process of the feature extraction layer of the encoding network model in step S22 extracting the spatial correlation features between features in the input multidimensional feature vector is as follows: S221: Reshape the original multidimensional feature vector into a two-dimensional feature matrix, with the number of channels dynamically adjusted according to the feature dimension; S222: The feature extraction layer includes at least three layers. Low-level feature extraction is performed through the first layer of the feature extraction layer, local feature correlation is calculated through a sliding window, and non-linear values ​​are introduced through the ReLU activation function. S223: Intermediate feature aggregation is performed through the second layer of the feature extraction layer, the receptive field is expanded through dilated convolution, and convergence is accelerated through batch normalization; S224: Advanced semantic fusion is performed through the third layer of the feature extraction layer, the feature weights are dynamically adjusted through the channel attention mechanism, and multi-scale information is captured through spatial pyramid pooling. S225: The features output from the first layer are connected to the features output from the third layer in a skip connection. Spatial coordinate information is embedded into the feature channel through the position encoding vector to obtain spatial correlation features.

4. The secure communication method between an edge server and a terminal device according to claim 1, characterized in that, The specific process of the edge server verifying the legitimacy of the authentication request in step S4 is as follows: S41: The network listening module of the edge server monitors the specified port in real time. When it receives the authentication request data packet sent by the terminal device, it decapsulates the data packet through the network protocol stack and extracts the original data containing the authentication request and the first hash value from the TCP / IP protocol data. S42: Parse the identity authentication request according to the preset data format, and separate the terminal device identifier and random number to prepare for subsequent verification steps; S43: Check if the authentication request contains a timestamp field, compare the timestamp in the request with the edge server's own system time, and consider the preset time tolerance range. If the timestamp exceeds the tolerance range, it indicates that the request has expired or that an attacker is trying to perform illegal authentication by replaying an old request. The edge server immediately rejects the request and records the abnormal request log for subsequent security auditing. S44: Based on the parsed terminal device identifier, query the device registration information database stored locally on the edge server to verify whether the device identifier is valid and whether the device registration status is normal. If the device identifier is invalid or the status is abnormal, it indicates that the request source is suspicious. The edge server directly rejects the identity authentication request and returns an authentication failure error message to the terminal device. S45: After confirming the validity of the device identifier, extract the pre-stored device key of the corresponding terminal device from the device key management module according to the device identifier. The device key is allocated and securely stored by the system during the device registration stage and is used for encryption and verification operations during the identity authentication process. S46: Using the same preset hash algorithm as the terminal device, perform a hash operation on the received authentication request and the extracted device key to generate a second hash value. Compare the generated second hash value with the first hash value carried in the authentication request. If the two hash values ​​are completely identical, it means that the terminal device has the correct device key and the request has not been tampered with during transmission, and the authentication is initially successful; otherwise, it is determined that there is a problem with the request, the authentication request is rejected, and further security measures are taken, including limiting the number of retries for the device or preventing brute-force attacks. S47: The edge server performs further security verification, checking whether the source IP address of the request is within the authorized IP address range to prevent unauthorized devices from authenticating by spoofing IPs; it analyzes the frequency of requests, and if a large number of authentication requests are received from the same device in a short period of time, it may be under malicious attack, and the edge server will rate-limit or block the requests from that device.

5. The secure communication method between an edge server and a terminal device according to claim 4, characterized in that, The specific process of step S5 is as follows: S51: Extract the original data fields of the terminal device identifier and the random number from the parsing result of the identity authentication request; S52: Call the system's built-in cryptography library, concatenate the extracted request data and device key in a preset order, and perform hash calculation using the preset hash algorithm to generate a second hash value; S53: Use the constant time comparison algorithm to compare the first hash value and the second hash value bit by bit. If the comparison is successful, proceed to step S54; otherwise, record the exception and trigger the security audit process. S54: Call the secure random number generator in the cryptography library to generate a session key of a specified number of bits, which will be used for symmetric encryption in subsequent communications; S55: Obtain the high-precision system time of the edge server, convert it into a timestamp in ISO 8601 format string, and use it to identify the response generation time; S56: Extract the unique identifier of the edge server from the server configuration file, assemble the session key, timestamp, and unique identifier of the edge server according to the specified rules to generate an authentication response message, encrypt the authentication response message, and transmit it to the terminal device.

6. The secure communication method between an edge server and a terminal device according to claim 5, characterized in that, The specific process of encrypting the authentication response message and transmitting it to the terminal device in step S56 is as follows: S561: Convert the authentication response message into a byte stream and generate a random initialization vector value for a specified byte; S562: After encoding the byte stream according to the specified rules based on the device key, the byte stream is encrypted using a preset symmetric encryption algorithm to generate ciphertext and authentication tags. During the encryption process, a message authentication code is automatically generated to ensure data integrity. S563: Concatenate the initialization vector value, ciphertext, and authentication tag according to the specified format, and convert the concatenation result into a Base64 encoded authentication response message; S564: The encrypted authentication response is packaged into a secure communication protocol frame, with the protocol version number and message type metadata added. The response message is then sent to the terminal device through a pre-configured TLS 1.3 session.

Citation Information

Patent Citations

  • Authentication verification method, system and device

    CN114338158A

  • Identity verification method based on identity information of Internet of Things equipment

    CN119814334A