Information terminal authentication method based on cloud platform
By generating multi-level signal diversion verification of hash value codes and checksum codes, combined with the characteristic values of MAC addresses and serial numbers, the problem of information terminal authentication methods being easily forged and tampered with is solved, and accurate identification and dynamic adjustment of terminal identities are achieved, thereby improving the security and access efficiency of the cloud platform.
Patent Information
- Application Number
- CN202510626121.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-15
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2045-05-15
AI Technical Summary
In the existing technology, information terminal authentication methods are easy to forge and tamper with, and when faced with massive heterogeneous terminals, key management is complex and certificate updates are delayed, resulting in low cloud platform security and access efficiency, and a lack of multi-dimensional verification and dynamic maintenance mechanisms.
By generating hash value codes and checksum codes, combined with the characteristic values of MAC addresses and serial numbers, multi-level signal diversion verification is performed to identify tampering behavior. By isolating interactions through virtual space, misjudged terminals are dynamically identified to achieve automatic error correction.
Effectively identify terminal tampering behavior, improve authentication accuracy, reduce manual intervention costs, and balance the security and access efficiency of the cloud platform.
Smart Images

Figure CN120474781B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of information authentication, in particular to an information terminal authentication method based on a cloud platform. BACKGROUND
[0002] With the wide application of cloud computing technology, a large number of information terminals (such as mobile devices, Internet of Things terminals, enterprise office equipment, etc.) need to access the cloud platform to realize data interaction and resource sharing. In this process, terminal identity authentication as the first barrier of security protection, its accuracy and reliability directly affect the security and stability of cloud services.
[0003] Traditional authentication methods mostly rely on single MAC address or device serial number verification, which has the risk of being easily forged and tampered with. While the authentication means based on password or certificate are prone to key management complexity and certificate update lag when facing a large number of heterogeneous terminals. In the prior art, although some schemes introduce multi-factor authentication or hash algorithm to improve security, there is still a lack of deep verification and dynamic maintenance mechanism for terminal identity identification.
[0004] For example, when any information in the MAC address and the serial number is illegally modified, the system is difficult to quickly locate the tampering source and restore the data accuracy; for newly accessed or misjudged terminals, a "one-size-fits-all" interception strategy is often adopted, resulting in low access efficiency of legal devices and increased operation and maintenance costs; in addition, the diversity of terminal types (such as industrial control devices, BYOD devices, etc.) and the complexity of network attack means (such as man-in-the-middle attack, replay attack) in the cloud environment further exacerbate the vulnerability of the authentication system.
[0005] Therefore, there is an urgent need for an authentication method with multi-dimensional verification, dynamic correction and misjudgment identification capability to balance the security and access flexibility of the cloud platform. SUMMARY
[0006] In view of the deficiencies of the prior art, the present application provides an information terminal authentication method based on a cloud platform, which solves the problem of weak multi-dimensional representation of the original authentication method.
[0007] To achieve the above purpose, the present application is implemented by the following technical scheme: an information terminal authentication method based on a cloud platform, comprising the following steps:
[0008] Step one, processing the identity identifiers stored in the cloud platform and belonging to different information terminals, confirming the verification source code and verification code associated with the corresponding identity identifier, and storing them again in the storage location of the corresponding identity identifier;
[0009] Step two, determining the MAC address and serial number of the information terminal participating in the authentication, and generating an authentication-related signal based on the specific results of the identification determination;
[0010] Step three, based on the generated authentication-related signal, the cloud platform verifies the association of the information terminal, assesses whether the identity associated with the information terminal has been tampered with, and makes corrections and adjustments;
[0011] Step four, for information terminals that fail authentication, a set of virtual spaces is established for information interaction, and based on the actual information interaction process, such information terminals are designated as authenticable terminals or abnormal terminals.
[0012] Preferably, the identity includes the MAC address associated with the corresponding information terminal and the corresponding serial number.
[0013] Preferably, in step one, the specific way to confirm the verification code is:
[0014] Confirm the identity associated with different information terminals, confirm the MAC address and serial number from the identity;
[0015] Based on the pre-set hash value association table, convert the MAC address and serial number to hash values, confirm the hash values associated with the corresponding characters in the MAC address and serial number, and sort the associated hash values according to the original character sorting method, to generate the hash value code belonging to the corresponding MAC address and the hash value code belonging to the serial number;
[0016] Record the hash value code belonging to the MAC address associated with the corresponding identity as the primary code, and the hash value code belonging to the serial number as the secondary code, determine the verification code associated with the primary code and the secondary code: take the first hash value of the primary code and the secondary code as the characteristic value, and according to this characteristic value, confirm the difference between the subsequent other hash values and the characteristic value, the difference > 0, and according to the specific way of step-by-step confirmation, keep the position of the characteristic value unchanged, arrange the subsequent differences in turn, to generate the verification code associated with the primary code and the secondary code.
[0017] Preferably, in step one, the specific way to confirm the verification code is:
[0018] Further determine the verification code associated with the primary code and the secondary code: confirm the difference between the hash values belonging to the same sorting position, the difference > 0, sort the differences confirmed in turn according to the sorting position, to generate the verification code, if there is a hash value in a certain code at the sorting position, and there is no corresponding sorting position in another group of codes, do not confirm the difference.
[0019] Preferably, in step two, the specific way to generate the authentication-related signal is:
[0020] Confirming the MAC address and the serial number of the corresponding information terminal, and identifying whether the MAC address and the serial number are both recorded in the cloud platform:
[0021] If both are recorded, a permission signal is generated;
[0022] If only the MAC address or the serial number is recorded, a code check signal is generated;
[0023] If neither the MAC address nor the serial number is recorded, a source code check signal is generated.
[0024] Preferably, in step three, the specific way of identifying whether the identity associated with the information terminal is tampered with is:
[0025] If the authentication-related signal is the permission signal, it means that the authentication of the information terminal is passed;
[0026] If the authentication-related signal is the code check signal, the record item in which the MAC address and the serial number of the information terminal exist is recorded as a designated item, the check code associated with the storage area of the designated item is recorded as a verification code, the MAC address and the serial number of the information terminal are encoded based on the preset hash value association table, two sets of codes associated with the MAC address and the serial number are locked, the difference between the two sets of codes and the hash value at the sorting position is confirmed, the determined difference is greater than 0, the sequentially confirmed differences are sorted, the difference code is locked, the difference code and the verification code are compared and checked, it is identified whether the two sets of codes are exactly the same, if they are exactly the same, it means that the authentication of the information terminal is passed, if they are not exactly the same, it means that the authentication of the information terminal is not passed, and based on the existing record item, another set of other items without record is locked, the numerical characteristics associated with the other items are re-recorded, and the numerical characteristics of the other items stored in the original storage position are deleted;
[0027] If the authentication-related signal is a source code verification signal, the MAC address and the serial number of the information terminal are compared with a preset hash value association table, the encoding associated with the MAC address and the encoding associated with the serial number are locked, the first hash value of the corresponding encoding is taken as a pending value, the difference between the subsequent other hash values in the corresponding encoding and the pending value is determined, the difference > 0, and the corresponding difference is sorted according to the sorting mode between the adjacent hash values of the encoding, the to-be-verified code is confirmed, a group of to-be-verified codes are randomly selected, and it is determined whether the same verification source code exists in different storage locations of the cloud platform, if yes, the corresponding storage location is recorded as a pending location, and if not, it means that the information terminal authentication fails, based on the determined pending location, the remaining another group of to-be-verified codes are compared with the remaining verification source codes of the corresponding storage location for consistency, if there is a completely consistent pending location, it means that the information terminal authentication passes, otherwise, it means that the information terminal authentication fails.
[0028] Preferably, in the fourth step, the specific way of calibrating the information terminal is:
[0029] The interaction information generated in the information interaction process is read, the number of registries is confirmed from the data protocol, the number of registries actually generated in the reading process is determined, and it is determined whether the numbers of registries associated with the two times are consistent, if yes, the information terminal is calibrated as an authenticable terminal, and relevant display is performed, and if not, the information terminal is calibrated as an abnormal terminal, and the abnormal terminal is not allowed to perform subsequent authentication processing.
[0030] The application provides an information terminal authentication method based on a cloud platform.
[0031] The application converts the character features of the MAC address and the serial number into comparable numerical sequences through multi-level verification of the hash value encoding, the verification source code and the verification encoding, and effectively identifies tampering behavior.
[0032] Through three-level signal distribution of "permission-coding verification-source code verification", registered terminals are quickly released, partial matching or new terminals are triggered for targeted verification, performance loss caused by full data comparison is avoided, and safety and access efficiency are considered.
[0033] For the terminal that fails authentication (step four), the registration table consistency is analyzed through virtual space isolation interaction, which can prevent malicious terminal penetration and dynamically identify misjudgment scenarios (such as legal new devices), and realizes automatic error correction through calibration of "authenticable terminal", thereby reducing manual intervention cost. BRIEF DESCRIPTION OF DRAWINGS
[0034] Figure 1 The figure is a flowchart of the method of the application.
[0035] Figure 2 A schematic diagram for generating an authentication-related signal of the present application. DETAILED DESCRIPTION
[0036] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the protection scope of the present application.
[0037] First embodiment
[0038] Please refer to Figure 1 The present application provides an information terminal authentication method based on a cloud platform, comprising the following steps:
[0039] Step one, processing the identity identifiers stored in the cloud platform and belonging to different information terminals, confirming the verification source code and verification code associated with the corresponding identity identifiers, and storing them again in the storage location of the corresponding identity identifiers. The identity identifier includes the MAC address associated with the corresponding information terminal and the corresponding serial number. The specific processing method for confirming the related code is as follows:
[0040] Confirming the identity identifiers associated with different information terminals, confirming the MAC address and serial number from the identity identifier;
[0041] Based on the preset hash value association table, converting the MAC address and serial number into hash values, confirming the hash values associated with the corresponding characters in the MAC address and serial number, and sorting the associated hash values according to the original character sorting method, to generate the hash value code of the corresponding MAC address and the hash value code of the serial number. For example, the corresponding MAD address is "00:1A:2B:3C:4D:5E", the hash value corresponding to the corresponding character "0" is 11, the hash value corresponding to ":" is 18, and the hash value is confirmed in this way, and the corresponding hash value code is generated, which is represented as "111118……";
[0042] The hash value corresponding to the identity associated with the MAC address is encoded as the primary code, and the hash value corresponding to the serial number is encoded as the secondary code. The check source code associated with the primary code and the secondary code is determined: the first hash value of the primary code and the secondary code is taken as the characteristic value, and the difference between the subsequent other hash values and the characteristic value is confirmed according to the characteristic value, the difference > 0, and the position of the characteristic value is kept unchanged according to the specific way of step-by-step confirmation, and the subsequent differences are arranged in turn to generate the check source code associated with the primary code and the secondary code. For example: assuming that the determined primary code is 1123456214, the subsequent other values and the value 1 are all corresponding to the difference, that is, 1012345103, so the determined 1012345103 is the check source code associated with the primary code.
[0043] The check code associated with the primary code and the secondary code is determined again: the hash values at the same sorting position are confirmed by difference, the difference > 0, and the confirmed differences are sorted according to the sorting position to generate the check code. If there is a hash value in the sorting position of a certain code, and there is no corresponding sorting position in another group of codes, then the difference cannot be confirmed (that is, one string of codes is 8 groups of hash values, and another string of codes is 10 groups of hash values, so the difference associated with the ninth and tenth positions cannot be confirmed). For example, the primary code is 1234566542, and the secondary code is 975312894. After the difference is confirmed, the corresponding check code can be confirmed. The confirmed check code is 852144247.
[0044] Step 2, determine the MAC address and serial number of the information terminal participating in the authentication, and generate an authentication-related signal based on the specific result of the identification, wherein the specific way of generating is:
[0045] In combination with Figure 2 , confirm the MAC address and serial number of the corresponding information terminal, and identify whether the MAC address and serial number are recorded in the cloud platform:
[0046] If they are all recorded, generate a permission signal (representing that the information terminal is authenticated);
[0047] If only the MAC address or the serial number is recorded, generate a code check signal, and perform subsequent check processing based on the code check signal;
[0048] If neither the MAC address nor the serial number is recorded, generate a source code check signal, and perform related check on the related features based on the source code check signal to determine whether there is related record or whether the corresponding feature is tampered.
[0049] Step three, based on the generated authentication-related signal, the cloud platform performs association verification on the information terminal, assesses whether the identity associated with the information terminal has been tampered with, and makes corrections and adjustments. The specific processing method for assessment is as follows:
[0050] If the authentication-related signal is a permission signal, it means that the information terminal has passed authentication and can directly interact with information without any further processing.
[0051] If the authentication-related signal is a code verification signal, the record item containing the MAC address and serial number of the information terminal (i.e., the corresponding item recorded in the cloud platform) is marked as the calibration item. The verification code associated with the storage area of the calibration item is marked as the check code. Based on the pre-set hash value association table, the MAC address and serial number of the information terminal are encoded for confirmation. The two sets of codes associated with the MAC address and serial number are locked. The difference between the hash values at the sorting position is confirmed. If the determined difference is greater than 0, the sequentially confirmed differences are sorted, the difference code is locked, and the difference code is compared with the check code to identify whether the two sets of codes are identical. If they are identical, it means that the information terminal has passed authentication. If they are not identical, it means that the information terminal has not passed authentication. Based on the existing record item, another set of non-existing record items is locked. The numerical characteristics associated with the other items are re-recorded, and the numerical characteristics of the other items stored in the original storage location are deleted. If the MAC address is a record item, the serial number is another item. Therefore, the serial number stored in the corresponding information terminal needs to be modified and replaced. The serial number associated with the information terminal is re-stored to ensure the integrity and accuracy of the corresponding storage location number.
[0052] If the authentication-related signal is a source code verification signal, the MAC address and serial number of the information terminal are compared with the pre-set hash value association table. The code associated with the corresponding MAC address and the code associated with the serial number are locked. The first hash value of the corresponding code is used as the pending value. The difference between the subsequent other hash values in the corresponding code and the pending value is determined, and the difference is > 0. According to the sorting method of adjacent hash values in the code, the corresponding difference is sorted to confirm the verification code. A set of verification codes is randomly selected to confirm whether the same verification source code exists in different storage locations of the cloud platform. If it exists, the corresponding storage location is marked as the pending location. If it does not exist, it means that the information terminal has not passed authentication. Based on the determined pending location, the remaining set of verification codes is compared with the remaining verification source code in the corresponding storage location for consistency. If there is a completely consistent pending location, it means that the information terminal has passed authentication. Otherwise, it means that the information terminal has not passed authentication.
[0053] Specifically, in this case, the MAC address and the serial number corresponding to the terminal do not exist any record, so for this kind of situation, it is possible that the MAC address and the serial number corresponding to the storage location are tampered, resulting in the absence of the situation, it is also possible that the relevant information of the corresponding terminal is not recorded in the first place, so for this kind of situation, the verification source code actually exists, so according to the specific circumstances of the corresponding information, the encoding features associated with the MAC address and the serial number are locked, and the same position difference is confirmed, the corresponding code is locked, and the authentication verification is carried out to comprehensively evaluate whether the corresponding information terminal can pass the authentication;
[0054] Step four, for the information terminal that fails to pass the authentication, a set of virtual space is established to interact with the information terminal, and based on the actual information interaction process, the information terminal is marked as an authenticable terminal or an abnormal terminal, wherein the specific way of marking is:
[0055] The interaction information generated in the information interaction process is read, and the number of registration tables is confirmed from the data protocol, and the number of registration tables actually generated in the reading process is determined, and whether the number of registration tables associated with the two times is consistent is determined, if consistent, the information terminal is marked as an authenticable terminal, and relevant display is carried out, if inconsistent, the information terminal is marked as an abnormal terminal, and the abnormal terminal is not allowed to carry out subsequent authentication processing.
[0056] Part of the data in the above formula is dimensionless numerical calculation, and the contents not described in detail in the specification belong to the prior art known to those skilled in the art.
[0057] The above examples are only used to illustrate the technical method of the present application and not to limit it, although the present application has been described in detail with reference to the preferred embodiments, those skilled in the art should understand that the technical method of the present application can be modified or replaced equivalently without departing from the spirit and scope of the technical method of the present application.
Claims
1. The information terminal authentication method based on the cloud platform is characterized in that: The following steps are involved: Step 1: Process the identity tags belonging to different information terminals stored in the cloud platform, confirm the verification source code and verification code associated with the corresponding identity tags, and re-store them to the storage location of the corresponding identity tags; The specific method for confirming the verification source code is: Confirm the identity tags associated with different information terminals, and confirm the MAC address and serial number from the identity tags; Based on a preset hash value association table, the MAC address and serial number are hashed, the hash values associated with the corresponding characters in the MAC address and serial number are confirmed, and the associated hash values are sorted according to the original character sorting method to generate a hash value code belonging to the corresponding MAC address and a hash value code belonging to the serial number; The hash value code of the MAC address associated with the corresponding identity identifier is recorded as the primary code, and the hash value code of the serial number is recorded as the secondary code. The verification source code associated with the primary code and the secondary code is determined: the first hash value of the primary code and the secondary code is used as the characteristic value, and based on this characteristic value, the difference between the subsequent hash values and this characteristic value is confirmed. The difference is greater than 0. According to the specific method of step-by-step confirmation, the position of the characteristic value remains unchanged, and the subsequent differences are arranged in sequence to generate the verification source code associated with the corresponding primary code and the secondary code; The specific method for confirming the check code is as follows: Then determine the check code associated with the primary code and the secondary code: confirm the difference of the hash values at the same sorting position. If the difference is greater than 0, sort the confirmed differences in sequence according to the sorting position to generate the check code. If a hash value exists at a sorting position in a code, but does not exist at the corresponding sorting position in another set of codes, no difference confirmation is performed. Step 2: Determine the MAC address and serial number of the information terminal participating in the authentication, and generate an authentication-related signal based on the specific identification results. The specific method is as follows: Confirm the MAC address and serial number of the corresponding information terminal, and check whether the MAC address and serial number are recorded in the cloud platform: If both records exist, a permission signal is generated; If only a single record of the MAC address or serial number exists, a coding verification signal is generated; If there is no record of MAC address and serial number, a source code verification signal is generated; Step 3: Based on the generated authentication-related signal, the cloud platform performs association verification on the information terminal to assess whether the identity associated with the information terminal has been tampered with, and makes corrections and adjustments; Step 4: For information terminals that fail authentication, a set of virtual spaces is established to interact with such information terminals, and based on the actual information interaction process, such information terminals are marked as authenticated terminals or abnormal terminals.
2. The cloud platform-based information terminal authentication method according to claim 1, characterized in that: The identity identifier includes a MAC address associated with the corresponding information terminal and a corresponding serial number.
3. The cloud platform-based information terminal authentication method according to claim 1, characterized in that: In step 3, the specific method for determining whether the identity associated with the information terminal has been tampered with is as follows: If the authentication-related signal is a permission signal, it means that the information terminal has passed the authentication; If the authentication-related signal is a coding verification signal, the record item containing the MAC address and serial number of this information terminal is recorded as a calibration item, and the verification code associated with the calibration item storage area is recorded as a verification code. Based on the preset hash value association table, the MAC address and serial number of this information terminal are coded and confirmed, the two sets of codes associated with the MAC address and serial number are locked, and the difference between the hash values at the same sorting position of the two sets of codes is confirmed. The determined difference is greater than 0, and the confirmed differences are sorted in sequence, the difference code is locked, and the difference code is compared and verified with the verification code to identify whether the two sets of codes are exactly the same. If they are exactly the same, it means that the authentication of this information terminal has passed. If they are completely different, it means that the authentication of this information terminal has failed. Based on the existing record items, another set of other items that do not exist in the record is locked, the numerical features associated with the other items are re-recorded, and the numerical features of the other items stored in the original storage position are deleted.
4. The cloud platform-based information terminal authentication method according to claim 3, characterized in that: If the authentication-related signal is a source code verification signal, the MAC address and serial number of the information terminal are compared with the preset hash value association table, the code associated with the corresponding MAC address and the code associated with the serial number are locked, and the first hash value of the corresponding code is used as the pending value, and the difference between the subsequent hash values in the corresponding code and the pending value is determined. The difference is greater than 0, and the corresponding differences are sorted according to the sorting method between adjacent hash values of the code. The pending code is confirmed, and a group of pending codes are randomly selected to confirm whether the same verification source code exists in different storage locations of the cloud platform. If so, the corresponding storage location is recorded as the pending location. If not, it means that the authentication of this information terminal has failed. Based on the determined pending location, the remaining group of pending codes is compared with the remaining verification source code of the corresponding storage location for consistency. If there is a completely consistent pending location, it means that the authentication of this information terminal has passed. Otherwise, it means that the authentication of this information terminal has failed.
5. The cloud platform-based information terminal authentication method according to claim 1, characterized in that: In step 4, the specific method of calibrating the information terminal is: The interactive information generated during the information interaction process is read, and the number of registration tables is confirmed from the data protocol. The number of registration tables actually generated during the reading process is then determined, and whether the two numbers of associated registration tables are consistent. If they are consistent, such information terminals are marked as authenticated terminals and relevant displays are performed. If they are inconsistent, such information terminals are marked as abnormal terminals, and subsequent authentication processing of such abnormal terminals is not allowed.
Citation Information
Patent Citations
Method and device for operating communication equipment in intelligent substation
CN109361783A
Data source identification method based on block chain
CN112765687A