Information terminal authentication method based on cloud platform
Through the multi-level verification method of hash encoding and verification encoding, combined with virtual spatial interaction, the problem of weak multi-dimensional representation of information terminal authentication is solved, and the balance between terminal security and access efficiency is achieved, reducing the cost of manual intervention.
Patent Information
- Application Number
- CN202510626121.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-15
- Publication Date
- 2025-08-12
- Estimated Expiration
- 2045-05-15
AI Technical Summary
In the prior art, the authentication method of the information terminal is not strong in multiple dimensions, is prone to forgery and tampering, and the processing efficiency of new access or misjudgment terminals is low, resulting in insufficient security and access flexibility.
The multi-level verification method of hash encoding, verification source code and verification encoding is adopted. The character characteristics of the MAC address and sequence number are converted into comparable numerical sequences, combined with the "license-encoding verification-source code verification" three-level signal diversion, identify tampering behavior and quickly release the registered terminals, perform targeted verification on partial matching or brand new terminals, and use virtual space isolation interaction to analyze the consistency of the registry, and dynamically identify misjudgment scenarios.
Effectively identify terminal tampering behavior, improve security and access efficiency, reduce manual intervention costs, and take into account security and access flexibility.
Smart Images

Figure CN120474781A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information authentication technology, and in particular to an information terminal authentication method based on a cloud platform. Background Art
[0002] With the widespread adoption of cloud computing, a large number of information terminals (such as mobile devices, IoT devices, and enterprise office equipment) need to connect to cloud platforms to exchange data and share resources. In this process, terminal identity authentication serves as the first line of defense for security, and its accuracy and reliability directly impact the security and stability of cloud services.
[0003] Traditional authentication methods mostly rely on single MAC address or device serial number verification, which is prone to the risk of forgery and tampering; and authentication methods based on passwords or certificates are prone to problems such as complex key management and delayed certificate updates when facing massive heterogeneous terminals; in existing technologies, although some solutions introduce multi-factor authentication or hash algorithms to improve security, they still lack in-depth verification and dynamic maintenance mechanisms for terminal identity identification.
[0004] For example, when any information in the MAC address and serial number is illegally modified, it is difficult for the system to quickly locate the source of tampering and restore data accuracy; for newly connected or misjudged terminals, a "one-size-fits-all" interception strategy is often adopted, resulting in inefficient access of legitimate devices and increased operation and maintenance costs; in addition, the diversity of terminal types in cloud environments (such as industrial control equipment, BYOD devices, etc.) and the complexity of network attack methods (such as man-in-the-middle attacks and replay attacks) further exacerbate the vulnerability of the authentication system.
[0005] Therefore, there is an urgent need for an authentication method with multi-dimensional verification, dynamic correction and misjudgment identification capabilities to balance the security and access flexibility of the cloud platform. Summary of the Invention
[0006] In view of the shortcomings of the existing technology, the present invention provides an information terminal authentication method based on a cloud platform, which solves the problem that the original authentication method has weak representation in multiple dimensions.
[0007] To achieve the above objectives, the present invention is implemented through the following technical solutions: an information terminal authentication method based on a cloud platform, comprising the following steps:
[0008] Step 1: Process the identity tags belonging to different information terminals stored in the cloud platform, confirm the verification source code and verification code associated with the corresponding identity tags, and re-store them to the storage location of the corresponding identity tags;
[0009] Step 2: Determine the MAC address and serial number of the information terminal participating in the authentication, and generate an authentication-related signal based on the specific identification results;
[0010] Step 3: Based on the generated authentication-related signal, the cloud platform performs association verification on the information terminal to assess whether the identity associated with the information terminal has been tampered with, and makes corrections and adjustments;
[0011] Step 4: For information terminals that fail authentication, a set of virtual spaces is established to interact with such information terminals, and based on the actual information interaction process, such information terminals are marked as authenticated terminals or abnormal terminals.
[0012] Preferably, the identity identifier includes a MAC address associated with the corresponding information terminal and a corresponding serial number.
[0013] Preferably, in step 1, the specific method for confirming the verification source code is:
[0014] Confirm the identity tags associated with different information terminals, and confirm the MAC address and serial number from the identity tags;
[0015] Based on a preset hash value association table, the MAC address and serial number are hashed, the hash values associated with the corresponding characters in the MAC address and serial number are confirmed, and the associated hash values are sorted according to the original character sorting method to generate a hash value code belonging to the corresponding MAC address and a hash value code belonging to the serial number;
[0016] The hash value code of the MAC address associated with the corresponding identity identifier is recorded as the primary code, and the hash value code of the serial number is recorded as the secondary code. The verification source code associated with the primary code and the secondary code is determined: the first hash value of the primary code and the secondary code is used as the characteristic value, and based on this characteristic value, the difference between the subsequent other hash values and this characteristic value is confirmed, and the difference is greater than 0. According to the specific method of step-by-step confirmation, the position of the characteristic value remains unchanged, and the subsequent differences are arranged in sequence to generate the verification source code associated with the corresponding primary code and the secondary code.
[0017] Preferably, in step 1, the specific method for confirming the verification code is:
[0018] Then determine the check code associated with the primary code and the secondary code: confirm the difference of the hash values belonging to the same sorting position, and the difference is greater than 0. Sort the confirmed differences in sequence according to the sorting position to generate a check code. If a hash value exists at a sorting position in a certain code and there is no corresponding sorting position in another set of codes, no difference confirmation is performed.
[0019] Preferably, in step 2, the specific method of generating the authentication-related signal is:
[0020] Confirm the MAC address and serial number of the corresponding information terminal, and check whether the MAC address and serial number are recorded in the cloud platform:
[0021] If both records exist, a permission signal is generated;
[0022] If only a single record of the MAC address or serial number exists, a coding verification signal is generated;
[0023] If there is no record of the MAC address and serial number, a source code verification signal is generated.
[0024] Preferably, in step 3, the specific method of determining whether the identity associated with the information terminal has been tampered with is:
[0025] If the authentication-related signal is a permission signal, it means that the information terminal has passed the authentication;
[0026] If the authentication-related signal is a coding verification signal, the record item of the MAC address and serial number of this information terminal is recorded as a calibration item, and the verification code associated with the calibration item storage area is recorded as a verification code. Based on the preset hash value association table, the MAC address and serial number of this information terminal are coded and confirmed, the two sets of codes associated with the MAC address and serial number are locked, and the hash values of the two sets of codes at the same sorting position are difference confirmed. The determined difference is greater than 0, and the confirmed differences are sorted in sequence, the difference code is locked, and the difference code is compared and verified with the verification code to identify whether the two sets of codes are exactly the same. If they are exactly the same, it means that the authentication of this information terminal has been passed. If they are completely different, it means that the authentication of this information terminal has not been passed. Based on the existing record items, another set of other items that do not exist in the record is locked, the numerical features associated with the other items are re-recorded, and the numerical features of the other items stored in the original storage position are deleted;
[0027] If the authentication-related signal is a source code verification signal, the MAC address and serial number of the information terminal are compared with the preset hash value association table, the code associated with the corresponding MAC address and the code associated with the serial number are locked, and the first hash value of the corresponding code is used as the pending value, and the difference between the subsequent hash values in the corresponding code and the pending value is determined. The difference is greater than 0, and the corresponding differences are sorted according to the sorting method between adjacent hash values of the code. The pending code is confirmed, and a group of pending codes are randomly selected to confirm whether the same verification source code exists in different storage locations of the cloud platform. If so, the corresponding storage location is recorded as the pending location. If not, it means that the authentication of this information terminal has failed. Based on the determined pending location, the remaining group of pending codes is compared with the remaining verification source code of the corresponding storage location for consistency. If there is a completely consistent pending location, it means that the authentication of this information terminal has passed. Otherwise, it means that the authentication of this information terminal has failed.
[0028] Preferably, in step 4, the specific method of calibrating the information terminal is:
[0029] The interactive information generated during the information interaction process is read, and the number of registration tables is confirmed from the data protocol. The number of registration tables actually generated during the reading process is then determined, and whether the two numbers of associated registration tables are consistent. If they are consistent, such information terminals are marked as authenticated terminals and relevant displays are performed. If they are inconsistent, such information terminals are marked as abnormal terminals, and subsequent authentication processing of such abnormal terminals is not allowed.
[0030] The present invention provides a cloud platform-based information terminal authentication method. Compared with the existing technology, it has the following advantages:
[0031] The present invention uses multi-level verification of hash value coding, source code verification, and verification code verification to convert the character features of MAC addresses and serial numbers into comparable numerical sequences, effectively identifying tampering behavior.
[0032] Through the three-level signal diversion of "permission-coding verification-source code verification", registered terminals are quickly released, and targeted verification is triggered for partially matched or new terminals, avoiding the performance loss caused by full data comparison, and balancing security and access efficiency;
[0033] For terminals that fail authentication (step four), virtual space isolating interactions and analyzing registry consistency can prevent malicious terminal infiltration and dynamically identify misjudgment scenarios (such as legitimate new devices). Automatic error correction is achieved by calibrating "authenticated terminals" to reduce manual intervention costs. BRIEF DESCRIPTION OF THE DRAWINGS
[0034] Figure 1 Schematic diagram of the process of the present invention;
[0035] Figure 2 Schematic diagram of generation of authentication-related signals of the present invention. DETAILED DESCRIPTION
[0036] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0037] First embodiment
[0038] See also Figure 1 , this application provides an information terminal authentication method based on a cloud platform, comprising the following steps:
[0039] Step 1: Process the identity tags belonging to different information terminals stored in the cloud platform, confirm the verification source code and verification code associated with the corresponding identity tag, and re-store them to the storage location of the corresponding identity tag. The identity tag includes the MAC address and serial number associated with the corresponding information terminal. The specific processing method for confirming the relevant code is as follows:
[0040] Confirm the identity tags associated with different information terminals, and confirm the MAC address and serial number from the identity tags;
[0041] Based on the preset hash value association table, the MAC address and serial number are hashed, the hash values associated with the corresponding characters in the MAC address and serial number are confirmed, and the associated hash values are sorted according to the original character sorting method to generate the hash value code belonging to the corresponding MAC address and the hash value code belonging to the serial number. For example, the corresponding MAD address is "00:1A:2B:3C:4D:5E", the hash value corresponding to the corresponding character "0" is 11, and the hash value corresponding to the character ":" is 18. The hash values are confirmed in this order and the corresponding hash value code is generated, which is expressed as "111118...";
[0042] The hash value code of the MAC address associated with the corresponding identity identifier is recorded as the primary code, and the hash value code of the serial number is recorded as the secondary code, and the verification source code associated with the primary code and the secondary code is determined: the first hash value of the primary code and the secondary code is used as the characteristic value, and based on this characteristic value, the difference between the subsequent other hash values and this characteristic value is confirmed, and the difference is greater than 0, and according to the specific method of step-by-step confirmation, the position of the characteristic value is kept unchanged, and the subsequent differences are arranged in sequence to generate the verification source code associated with the corresponding primary code and the secondary code. For example: assuming that the determined primary code is: 1123456214, and the determined value 1 is used as the characteristic value, there is a corresponding difference between its subsequent values and this value 1, then it is 1012345103, so the determined 1012345103 is the verification source code associated with the corresponding primary code;
[0043] Then determine the check code associated with the primary code and the secondary code: confirm the difference of the hash values belonging to the same sorting position, and the difference is greater than 0. Sort the confirmed differences in sequence according to the sorting position to generate a check code. If a hash value exists at a sorting position in a certain code and the corresponding sorting position does not exist in the other set of codes, the difference confirmation will not be performed (that is, if one string of codes is 8 groups of hash values and the other string of codes is 10 groups of hash values, then the difference associated with the ninth and tenth digits cannot be confirmed). For example: the primary code is 1234566542 and the secondary code is 975312894. Then, after the difference confirmation, the corresponding check code can be confirmed, and the confirmed check code is: 852144247.
[0044] Step 2: Determine the MAC address and serial number of the information terminal participating in the authentication, and generate an authentication-related signal based on the specific results of the identification and determination. The specific method for generating the signal is as follows:
[0045] Combine Figure 2 , confirm the MAC address and serial number of the corresponding information terminal, and identify whether this MAC address and serial number are recorded in the cloud platform:
[0046] If there are records for both, a permission signal is generated (indicating that the information terminal has passed the authentication);
[0047] If only a single record of the MAC address or serial number exists, a coding verification signal is generated, and subsequent verification processing is performed based on the coding verification signal;
[0048] If there is no record of the MAC address and serial number, a source code verification signal is generated, and the relevant features are verified based on this source code verification signal to assess whether there is a relevant record or whether the corresponding feature has been tampered with.
[0049] Step 3: Based on the generated authentication-related signals, the cloud platform performs association verification on the information terminal to assess whether the identity associated with the information terminal has been tampered with and makes corrections and adjustments. The specific processing method for the assessment is as follows:
[0050] If the authentication-related signal is a permission signal, it means that the information terminal has passed the authentication and can directly exchange information without any processing;
[0051] If the authentication-related signal is a coding verification signal, the record item of the MAC address and serial number of this information terminal (that is, the corresponding item with record stored in the cloud platform) is recorded as the calibration item, and the verification code associated with the calibration item storage area is recorded as the verification code. Based on the preset hash value association table, the MAC address and serial number of this information terminal are coded and confirmed, the two sets of codes associated with the MAC address and serial number are locked, and the difference between the hash values of the two sets of codes at the same sorting position is confirmed. The determined difference is greater than 0, and the confirmed differences are sorted in sequence, the difference code is locked, and the difference code is compared and verified with the verification code. Identify whether the two sets of codes are exactly the same. If they are exactly the same, it means that the information terminal has passed the authentication. If they are completely different, it means that the information terminal has failed the authentication. Based on the existing record items, lock the other items in the other set that do not have records, re-record the numerical features associated with the other items, and delete the numerical features of the other items stored in the original storage location. If the MAC address is a record item, then the serial number is another item. In this case, the serial number stored in the corresponding information terminal has been modified. It is necessary to replace and adjust it, and re-store the serial number associated with this information terminal to ensure the numbering integrity and accuracy of the corresponding storage location;
[0052] If the authentication-related signal is a source code verification signal, the MAC address and serial number of the information terminal are compared with the preset hash value association table, the code associated with the corresponding MAC address and the code associated with the serial number are locked, and the first hash value of the corresponding code is used as the pending value, and the difference between the subsequent hash values in the corresponding code and the pending value is determined. The difference is greater than 0, and the corresponding differences are sorted according to the sorting method between adjacent hash values of the code. The pending code is confirmed, and a group of pending codes are randomly selected to confirm whether the same verification source code exists in different storage locations of the cloud platform. If so, the corresponding storage location is recorded as the pending location. If not, it means that the authentication of this information terminal has failed. Based on the determined pending location, the remaining group of pending codes is compared with the remaining verification source code of the corresponding storage location for consistency. If there is a completely consistent pending location, it means that the authentication of this information terminal has passed. Otherwise, it means that the authentication of this information terminal has failed.
[0053] Specifically, here is the case where there is no record of the MAC address and serial number of the corresponding terminal. In this case, it is possible that the MAC address and serial number in the corresponding storage location have been tampered with, resulting in the absence of the MAC address and serial number. It is also possible that the relevant information of the corresponding terminal was not recorded in the first place. In this case, the verification source code actually exists. Therefore, based on the specific situation related to the corresponding information, the coding features associated with the corresponding MAC address and serial number are locked, and then the difference confirmation at the same position is performed. The corresponding code is locked and authentication verification is performed to conduct a comprehensive assessment to determine whether the corresponding information terminal can pass the authentication.
[0054] Step 4: For information terminals that fail authentication, a set of virtual spaces is established to interact with such information terminals. Based on the actual information interaction process, such information terminals are marked as authenticated terminals or abnormal terminals. The specific method of marking is as follows:
[0055] The interactive information generated during the information interaction process is read, and the number of registration tables is confirmed from the data protocol. The number of registration tables actually generated during the reading process is then determined, and whether the two numbers of associated registration tables are consistent. If they are consistent, such information terminals are marked as authenticated terminals and relevant displays are performed. If they are inconsistent, such information terminals are marked as abnormal terminals, and subsequent authentication processing of such abnormal terminals is not allowed.
[0056] Some of the data in the above formulas are dimensionless and numerically calculated. Meanwhile, the contents not described in detail in this specification belong to the prior art known to those skilled in the art.
[0057] The above embodiments are only used to illustrate the technical method of the present invention and are not intended to limit the present invention. Although the present invention has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical method of the present invention may be modified or replaced by equivalents without departing from the spirit and scope of the technical method of the present invention.
Claims
1. The information terminal authentication method based on the cloud platform is characterized in that: The following steps are involved: Step 1: Process the identity tags belonging to different information terminals stored in the cloud platform, confirm the verification source code and verification code associated with the corresponding identity tags, and re-store them to the storage location of the corresponding identity tags; Step 2: Determine the MAC address and serial number of the information terminal participating in the authentication, and generate an authentication-related signal based on the specific identification results; Step 3: Based on the generated authentication-related signal, the cloud platform performs association verification on the information terminal to assess whether the identity associated with the information terminal has been tampered with, and makes corrections and adjustments; Step 4: For information terminals that fail authentication, a set of virtual spaces is established to interact with such information terminals, and based on the actual information interaction process, such information terminals are marked as authenticated terminals or abnormal terminals.
2. The cloud platform-based information terminal authentication method according to claim 1, characterized in that: The identity identifier includes a MAC address associated with the corresponding information terminal and a corresponding serial number.
3. The cloud platform-based information terminal authentication method according to claim 1, characterized in that: In step 1, the specific method for confirming the verification source code is: Confirm the identity tags associated with different information terminals, and confirm the MAC address and serial number from the identity tags; Based on a preset hash value association table, the MAC address and serial number are hashed, the hash values associated with the corresponding characters in the MAC address and serial number are confirmed, and the associated hash values are sorted according to the original character sorting method to generate a hash value code belonging to the corresponding MAC address and a hash value code belonging to the serial number; The hash value code of the MAC address associated with the corresponding identity identifier is recorded as the primary code, and the hash value code of the serial number is recorded as the secondary code. The verification source code associated with the primary code and the secondary code is determined: the first hash value of the primary code and the secondary code is used as the characteristic value, and based on this characteristic value, the difference between the subsequent other hash values and this characteristic value is confirmed, and the difference is greater than 0. According to the specific method of step-by-step confirmation, the position of the characteristic value remains unchanged, and the subsequent differences are arranged in sequence to generate the verification source code associated with the corresponding primary code and the secondary code.
4. The cloud platform-based information terminal authentication method according to claim 3, characterized in that: In step 1, the specific method for confirming the verification code is: Then determine the check code associated with the primary code and the secondary code: confirm the difference of the hash values belonging to the same sorting position, and the difference is greater than 0. Sort the confirmed differences in sequence according to the sorting position to generate a check code. If a hash value exists at a sorting position in a certain code and there is no corresponding sorting position in another set of codes, no difference confirmation is performed.
5. The cloud platform-based information terminal authentication method according to claim 1, characterized in that: In step 2, the specific method of generating the authentication-related signal is: Confirm the MAC address and serial number of the corresponding information terminal, and check whether the MAC address and serial number are recorded in the cloud platform: If both records exist, a permission signal is generated; If only a single record of the MAC address or serial number exists, a coding verification signal is generated; If there is no record of the MAC address and serial number, a source code verification signal is generated.
6. The cloud platform-based information terminal authentication method according to claim 5, characterized in that: In step 3, the specific method for determining whether the identity associated with the information terminal has been tampered with is as follows: If the authentication-related signal is a permission signal, it means that the information terminal has passed the authentication; If the authentication-related signal is a coding verification signal, the record item containing the MAC address and serial number of this information terminal is recorded as a calibration item, and the verification code associated with the calibration item storage area is recorded as a verification code. Based on the preset hash value association table, the MAC address and serial number of this information terminal are coded and confirmed, the two sets of codes associated with the MAC address and serial number are locked, and the difference between the hash values at the same sorting position of the two sets of codes is confirmed. The determined difference is greater than 0, and the confirmed differences are sorted in sequence, the difference code is locked, and the difference code is compared and verified with the verification code to identify whether the two sets of codes are exactly the same. If they are exactly the same, it means that the authentication of this information terminal has passed. If they are completely different, it means that the authentication of this information terminal has failed. Based on the existing record items, another set of other items that do not exist in the record is locked, the numerical features associated with the other items are re-recorded, and the numerical features of the other items stored in the original storage position are deleted.
7. The cloud platform-based information terminal authentication method according to claim 6, characterized in that: If the authentication-related signal is a source code verification signal, the MAC address and serial number of the information terminal are compared with the preset hash value association table, the code associated with the corresponding MAC address and the code associated with the serial number are locked, and the first hash value of the corresponding code is used as the pending value, and the difference between the subsequent hash values in the corresponding code and the pending value is determined. The difference is greater than 0, and the corresponding differences are sorted according to the sorting method between adjacent hash values of the code. The pending code is confirmed, and a group of pending codes are randomly selected to confirm whether the same verification source code exists in different storage locations of the cloud platform. If so, the corresponding storage location is recorded as the pending location. If not, it means that the authentication of this information terminal has failed. Based on the determined pending location, the remaining group of pending codes is compared with the remaining verification source code of the corresponding storage location for consistency. If there is a completely consistent pending location, it means that the authentication of this information terminal has passed. Otherwise, it means that the authentication of this information terminal has failed.
8. The cloud platform-based information terminal authentication method according to claim 1, characterized in that: In step 4, the specific method of calibrating the information terminal is: The interactive information generated during the information interaction process is read, and the number of registration tables is confirmed from the data protocol. The number of registration tables actually generated during the reading process is then determined, and whether the two numbers of associated registration tables are consistent. If they are consistent, such information terminals are marked as authenticated terminals and relevant displays are performed. If they are inconsistent, such information terminals are marked as abnormal terminals, and subsequent authentication processing of such abnormal terminals is not allowed.
Citation Information
Patent Citations
Method and device for operating communication equipment in intelligent substation
CN109361783A
Data source identification method based on block chain
CN112765687A
Equipment identity authentication method and device, terminal, authentication node and storage medium
CN115086958A
Identity verification method based on identity information of Internet of Things equipment
CN119814334A
Systems and methods for multi-level authentication
US20210314318A1