Scene device security binding system and method based on trusted terminal monitoring

By acquiring and comparing the real-time characteristics of trusted terminals and devices, a scene binding association graph is constructed for bidirectional dynamic verification, which solves the security risks in existing binding methods and achieves highly secure device binding.

CN120785665BActive Publication Date: 2025-11-21NAT CERTIFICATION TECH (HANGZHOU) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511294026.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-09-11
Publication Date
2025-11-21
Estimated Expiration
2045-09-11

AI Technical Summary

Technical Problem

Existing methods for secure device binding in various scenarios have security vulnerabilities, including a lack of monitoring and evaluation of the real-time operating status of terminals and devices, and one-way verification is easily attacked, leaving the system exposed to security threats.

Method used

By acquiring the real-time operating characteristics and dynamic status characteristics of trusted terminals and devices to be bound, trusted baseline comparison and security baseline comparison are performed to generate terminal trust deviation and device security deviation, construct a scenario binding association graph, perform two-way dynamic verification, generate binding relationship files and store them in an encrypted storage area.

Benefits of technology

It enables accurate security risk assessment of terminals and devices, prevents one-way verification vulnerabilities, improves binding security and reliability, meets security needs in different scenarios, and ensures the security of binding relationships through encrypted storage.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120785665B_ABST
    Figure CN120785665B_ABST
Patent Text Reader

Abstract

The application provides a scene device security binding system and method based on trusted terminal monitoring, and belongs to the technical field of device security binding. Firstly, real-time running feature sets of trusted terminals and dynamic state feature sets of scene devices to be bound are acquired, then trusted baseline comparison processing and security baseline comparison processing are respectively performed on the real-time running feature sets and the dynamic state feature sets, terminal trusted deviation and device security deviation are generated, then the two are combined to construct a scene binding correlation graph, a bidirectional dynamic verification sequence is generated according to the scene binding correlation graph and is sent to the trusted terminal and the scene device to be bound to perform cross verification operation, a cross verification result set is obtained, a hierarchical binding process is started according to the cross verification result set, a binding relationship archive is generated, and is respectively stored in an encrypted storage area of the trusted terminal and a security partition of the scene device to be bound, hierarchical management of binding is realized, and the security requirements in different scenes are met.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of device security binding technology, and more specifically, to a scenario-based device security binding system and method based on trusted terminal monitoring. Background Technology

[0002] In today's era of rapid digital and intelligent development, the binding of devices and terminals in various scenarios is becoming increasingly widespread. Examples include the binding of various smart devices with user terminals in smart home scenarios, and the binding of production equipment with control terminals in industrial IoT scenarios. These binding relationships enable data interaction, command transmission, and collaborative work between devices and terminals, providing users with a more convenient and efficient service experience.

[0003] However, existing methods for secure device binding in various scenarios have numerous security vulnerabilities. On one hand, traditional binding methods often focus only on basic connections and simple authentication between the device and the terminal, lacking effective monitoring and evaluation of the real-time operational status of both. Terminals may experience abnormal operation due to hardware failures, system vulnerabilities, or malicious attacks, while devices may pose security risks due to interface failures, sensor damage, or being in unsafe environments. Binding without understanding these real-time conditions easily exposes the entire system to security threats. On the other hand, existing binding verification mechanisms are mostly one-way verification, meaning only the terminal verifies the device, or vice versa. This one-way verification method is easily exploited by attackers who can bypass verification by forging device or terminal information, thereby achieving illegal binding, stealing data, controlling devices, or launching other malicious attacks. Summary of the Invention

[0004] In view of the aforementioned problems, and in conjunction with the first aspect of the present invention, embodiments of the present invention provide a method for secure binding of scene devices based on trusted terminal monitoring, the method comprising:

[0005] The real-time operation feature set of the trusted terminal and the dynamic status feature set of the device to be bound to the scene are obtained. The real-time operation feature set includes real-time parameters of terminal hardware, system process features and network interaction identifiers. The dynamic status feature set includes real-time status of device interface, sensor perception data and environmental correlation features.

[0006] A trusted baseline comparison process is performed on the real-time running feature set to generate a terminal trusted deviation; a security baseline comparison process is performed on the dynamic state feature set to generate a device security deviation.

[0007] A scene binding association graph is constructed by combining the terminal trust deviation and the device security deviation. The scene binding association graph includes feature mapping relationships, deviation coupling parameters, and scene adaptation coefficients.

[0008] A bidirectional dynamic verification sequence is generated based on the scene binding association graph. The bidirectional dynamic verification sequence is sent to a trusted terminal and a scene device to be bound to perform cross-verification operations to obtain a cross-verification result set.

[0009] The hierarchical binding process is initiated based on the cross-validation result set, generating a binding relationship file containing dynamic binding identifiers, scene association parameters, and security level labels, and storing the binding relationship file in the encrypted storage area of ​​the trusted terminal and the security partition of the scene device to be bound, respectively.

[0010] In another aspect, embodiments of the present invention also provide a scene device security binding system based on trusted terminal monitoring, including a processor and a machine-readable storage medium. The machine-readable storage medium is connected to the processor. The machine-readable storage medium is used to store programs, instructions or code. The processor is used to execute the programs, instructions or code in the machine-readable storage medium to implement the above-described method.

[0011] Based on the above, this embodiment of the invention obtains the real-time operating feature set of a trusted terminal and the dynamic state feature set of the device to be bound. It then performs trusted baseline comparison processing and security baseline comparison processing on the real-time operating feature set and the dynamic state feature set, respectively, generating terminal trust deviation and device security deviation. This accurately quantifies the degree of deviation between the terminal and device and their normal state, enabling timely detection of potential security risks. A scene binding association graph is constructed by combining the terminal trust deviation and the device security deviation, including feature mapping relationships, deviation coupling parameters, and scene adaptation coefficients. This provides an in-depth analysis and modeling of the association between the terminal and the device from multiple dimensions. A bidirectional dynamic verification sequence is generated based on the scene binding association graph and sent to the trusted terminal and the device to be bound for cross-verification operations. This achieves bidirectional, dynamic verification between the terminal and the device, effectively preventing security vulnerabilities that may exist in one-way verification and greatly improving the security and reliability of the binding process. The hierarchical binding process is initiated based on the cross-validation result set, generating a binding relationship file containing dynamic binding identifiers, scenario association parameters, and security level labels. The file is then stored in the encrypted storage area of ​​the trusted terminal and the secure partition of the device to be bound. This not only achieves hierarchical management of binding and meets the security requirements of different scenarios, but also ensures the security of the binding relationship file through encrypted storage and secure partitioning. Attached Figure Description

[0012] Figure 1 This is a schematic diagram of the execution flow of the scene device security binding method based on trusted terminal monitoring provided in an embodiment of the present invention.

[0013] Figure 2This is a schematic diagram of exemplary hardware and software components of the scene device security binding system based on trusted terminal monitoring provided in an embodiment of the present invention. Detailed Implementation

[0014] The present invention will now be described in detail with reference to the accompanying drawings. Figure 1 This is a flowchart illustrating a scene device security binding method based on trusted terminal monitoring, provided in one embodiment of the present invention. The following is a detailed description of this scene device security binding method based on trusted terminal monitoring.

[0015] Step S110: Obtain the real-time running feature set of the trusted terminal and the dynamic status feature set of the scene device to be bound. The real-time running feature set includes real-time parameters of the terminal hardware, system process characteristics and network interaction identifiers. The dynamic status feature set includes real-time status of the device interface, sensor perception data and environmental correlation characteristics.

[0016] In this embodiment, the trusted terminal can be any terminal device with trusted computing capabilities, and the device to be bound to the scenario is the device that needs to establish a secure binding relationship with the trusted terminal.

[0017] Step S111: Collect real-time parameters of the terminal hardware through the hardware monitoring unit of the trusted terminal at a preset cycle. The real-time parameters of the terminal hardware include CPU load, memory usage ratio and storage read / write frequency.

[0018] The hardware monitoring unit is a dedicated module built into the trusted terminal for monitoring hardware status. Its preset cycle can be set according to actual needs, such as a shorter cycle to ensure data real-time performance. When collecting CPU load data, the hardware monitoring unit continuously monitors the CPU's computational usage per unit time, forming multi-dimensional feature data that includes changes in CPU load over different time periods. Memory usage ratio data is collected by monitoring the ratio of used memory space to total memory space, recording the ratio at multiple time points to form a feature set of memory usage ratios. Storage read / write frequency data records the number of read and write operations performed by the storage device per unit time, reflecting the real-time operating status of the storage device.

[0019] Step S112: Call the terminal process management module to extract system process characteristics, which include process startup time, inter-process communication frequency and process permission level.

[0020] The terminal process management module is responsible for managing and monitoring all processes running on the trusted terminal. When extracting process startup time, it records the time information from each process's startup to the current moment, as well as the startup order of different processes, forming a multi-dimensional time feature vector. Inter-process communication frequency is extracted by statistically analyzing the number of data interactions between different processes per unit time; the communication frequency of each process with multiple other processes together constitutes the feature set of inter-process communication frequency. Process permission levels are determined based on the operational permissions assigned to each process by the system. Different permission levels are represented by different identifiers, and the permission level information of all processes is combined to form the feature data of the process permission level.

[0021] Step S113: Record the network interaction identifier through the terminal network monitoring component. The network interaction identifier includes the connection protocol type, the address of the communication peer, and the direction of data transmission.

[0022] The terminal network monitoring component constantly monitors the network connectivity of trusted terminals. The connection protocol type record identifies the various protocols used by the trusted terminal when interacting with other devices, such as TCP and UDP; these protocol types constitute a feature set. The communication peer address record obtains the network addresses of other devices communicating with the trusted terminal; these may be multiple different addresses, forming a multi-dimensional address feature. The data transmission direction record distinguishes whether data is sent from the trusted terminal or received from an external source; the direction information of each network interaction is combined into a feature vector of the data transmission direction.

[0023] Step S114: Combine the real-time parameters of the terminal hardware, system process characteristics, and network interaction identifiers according to timestamps to form a real-time running feature set.

[0024] A timestamp is a time stamp corresponding to the time of collection of each feature data. When combining real-time runtime feature sets, feature data with the same or similar timestamps in real-time terminal hardware parameters, system process characteristics, and network interaction identifiers can be identified and combined. For example, the CPU load at a certain point in time, the start time of a certain process at that point in time, and the network connection protocol type at that point in time will be grouped together, and multiple groups of the above data together constitute the real-time runtime feature set.

[0025] Step S115: Collect the real-time status of the device interface through the interface status monitor of the device to be bound. The real-time status of the device interface includes interface connection stability, data transmission error rate and interface power supply parameters.

[0026] The interface status monitor for devices to be bound is specifically designed to monitor various states of the device interface. Interface connection stability is monitored by tracking the duration of the connection between the interface and other devices, and whether interruptions occur. Data transmission error rate (BER) is calculated by determining the ratio of erroneous data to the total data volume during data transmission; the BER at different time points constitutes a feature set of the BER. Interface power supply parameters are collected by recording changes in parameters such as voltage and current, forming a multi-dimensional power supply feature vector.

[0027] Step S116: Collect sensor perception data through the multi-dimensional sensor array of the scene device to be bound. The sensor perception data includes vibration frequency characteristics, sound wave intensity characteristics, and light perception change characteristics.

[0028] The multi-dimensional sensor array consists of multiple sensors of different types, each used to sense different environmental parameters. Vibration frequency characteristics are acquired by recording changes in the vibration frequency of the environment surrounding the equipment using vibration sensors; vibration data from different frequency bands constitute a multi-dimensional set of vibration frequency characteristics. Sound wave intensity characteristics are acquired by sound wave sensors, recording sound wave intensity values ​​at different times to form a feature vector of sound wave intensity. Light sensitivity change characteristics are acquired by monitoring changes in ambient light using light sensors; light sensitivity data from different time points are combined to form a data set of light sensitivity change characteristics.

[0029] Step S117: Call the device environment association module to generate environmental association features, which include the electromagnetic features, temperature and humidity coordination features, and air pressure fluctuation features of the space where the device is located.

[0030] The equipment environment association module processes data collected by the multi-dimensional sensor array and other relevant environmental information to generate environmental association features. Electromagnetic features are generated by analyzing parameters such as the intensity and frequency of electromagnetic radiation around the equipment, forming a multi-dimensional set of electromagnetic features. Temperature and humidity co-variance features are generated by combining data from temperature and humidity sensors to analyze the co-variance between temperature and humidity, constructing a feature vector for temperature and humidity co-variance features. Barometric pressure fluctuation features are generated by recording barometric pressure fluctuations based on data collected by barometric pressure sensors, forming multi-dimensional barometric pressure fluctuation feature data.

[0031] Step S118: Combine the real-time status of the device interface, sensor sensing data, and environmental correlation features into a dynamic status feature set according to the acquisition time sequence.

[0032] The acquisition sequence refers to the order in which various feature data are collected. When combining dynamic state feature sets, they are arranged and combined sequentially according to the order in which the real-time status of the device interface, sensor-sensed data, and environmental correlation features are collected. For example, the interface connection stability data, the corresponding vibration frequency feature data, and the electromagnetic feature data collected first will be grouped together, and the subsequent data collected will be combined in the same way to form a dynamic state feature set.

[0033] Step S120: Perform trusted baseline comparison processing on the real-time running feature set to generate terminal trusted deviation, and perform security baseline comparison processing on the dynamic state feature set to generate device security deviation.

[0034] In this embodiment, the trusted baseline and security baseline are standard feature data sets that have been validated and optimized over a long period of time. They are used to measure the degree of deviation between the real-time running feature set and the dynamic state feature set. Through comparison processing, it can be determined whether the current state of the trusted terminal and the device to be bound to the scene is within the normal range.

[0035] Step S121: Retrieve the terminal trusted baseline parameters from the built-in trusted database of the trusted terminal. The terminal trusted baseline parameters include the normal operating threshold range of hardware, the process security behavior model, and the network interaction benchmark mode.

[0036] The built-in trusted database is a dedicated database within the trusted terminal for storing various baseline parameters and trusted information, offering high security and stability. The normal operating threshold range for hardware is determined based on the trusted terminal's hardware design parameters and long-term operational experience, encompassing the normal fluctuation range of parameters such as CPU load, memory usage ratio, and storage read / write frequency. The process security behavior model is a model trained on a large amount of secure process behavior data, including security patterns such as process startup time, inter-process communication frequency, and process privilege levels. This process security behavior model can be represented as a feature vector. The network interaction baseline pattern is a standard pattern that records characteristics such as connection protocol type, peer address, and data transmission direction under normal network interaction conditions.

[0037] Step S122: Compare the real-time parameters of the terminal hardware in the real-time running feature set with the normal operating threshold range of the hardware, calculate the parameter deviation percentage, match the system process features with the process security behavior model, calculate the behavior deviation coefficient, and compare the network interaction identifier with the network interaction benchmark mode to calculate the mode deviation index.

[0038] When performing various comparisons and calculations, it is necessary to ensure that the dimensions and formats of the data match each other to guarantee the accuracy and validity of the calculation results.

[0039] Step S1221: Extract the CPU load, memory usage ratio and storage read / write frequency from the real-time running feature set, and calculate the difference between them and the corresponding thresholds in the normal hardware operation threshold range to obtain the absolute deviation value of each parameter.

[0040] The extraction process involves filtering three real-time terminal hardware parameters—CPU load, memory usage ratio, and storage read / write frequency—from a set of real-time operational features. When calculating the difference, for CPU load, the feature value at each time point is subtracted from the threshold value for the corresponding time interval within the normal hardware operating threshold range to obtain the absolute deviation value for each time point. These absolute deviation values ​​constitute the set of absolute deviation values ​​for CPU load. Similarly, memory usage ratio and storage read / write frequency are calculated in a similar manner, yielding their respective sets of absolute deviation values.

[0041] Step S1222: Divide the absolute deviation value of each parameter by the corresponding upper limit value of the threshold to obtain the parameter deviation percentage. The numerical range of the parameter deviation percentage is mapped to a preset interval.

[0042] For each absolute deviation of the CPU load, it can be divided by the upper limit of the CPU load threshold within the normal hardware operating threshold range to obtain the percentage deviation of the CPU load parameter at each time point. The percentage deviation of memory usage ratio and storage read / write frequency is calculated in the same way. The calculated percentage deviation is then transformed to a preset range using a mapping function, for example, mapping it to the range of 0 to 1, making the percentage deviations of different parameters comparable.

[0043] Step S1223: Analyze the process startup time, inter-process communication frequency and process permission level in the system process characteristics, and convert them into feature vector form, denoted as process feature vector.

[0044] The parsing process involves structuring the data in the system process characteristics, clarifying the specific values ​​and meanings of process start time, inter-process communication frequency, and process permission level. When converting to feature vectors, the start time, communication frequency with other processes, permission level, and other data for each process can be arranged in a predetermined order. The feature vectors of multiple processes together constitute a process feature vector set, which comprehensively reflects the characteristics of the system processes.

[0045] Step S1224: Invoke the process safety behavior model to generate a standard process feature vector, calculate the Euclidean distance between the process feature vector and the standard process feature vector, and convert the Euclidean distance into a behavior deviation coefficient.

[0046] When generating standard process feature vectors, the process safety behavior model can output a standard vector with the same dimensions as the process feature vectors, based on the model's internal algorithms and parameters. This standard vector represents the process's safe behavior pattern. When calculating Euclidean distance, each vector in the process feature vector set is compared with the standard process feature vector, resulting in multiple Euclidean distance values. These distance values ​​reflect the differences between the actual process characteristics and the standard characteristics. When converting the Euclidean distance to behavior deviation coefficients, a defined transformation function can be used to map the distance values ​​to a specific interval, forming a set of behavior deviation coefficients.

[0047] Step S1225: Compare the connection protocol type, communication peer address and data transmission direction in the network interaction identifier with the corresponding elements in the network interaction baseline mode one by one, and count the number of mismatched elements.

[0048] One-by-one comparison refers to comparing each connection protocol type in the network interaction identifier with the connection protocol type in the network interaction baseline mode to determine if they are consistent. Similarly, a similar comparison is performed on the peer address and data transmission direction. During the comparison process, for each network interaction event, the number of mismatched elements in the connection protocol type, peer address, and data transmission direction is recorded.

[0049] Step S1226: Divide the number of mismatched elements by the total number of elements to obtain the pattern deviation index. The larger the value of the pattern deviation index, the more the network interaction deviates from the baseline pattern.

[0050] The total number of elements refers to the total number of elements contained in each network interaction event. In this embodiment, each network interaction event contains three elements: connection protocol type, communication peer address, and data transmission direction. Therefore, the total number of elements is 3. The pattern deviation index for each network interaction event is obtained by dividing the number of mismatched elements by 3.

[0051] Step S123: Perform weighted fusion processing on the parameter deviation percentage, behavior deviation coefficient and pattern deviation index to generate terminal credibility deviation. The weights of the weighted fusion processing are dynamically adjusted according to the terminal device type.

[0052] Weighted fusion processing combines three multi-dimensional feature sets—parameter deviation percentage, behavioral deviation coefficient, and pattern deviation index—according to predefined weights. The weights are dynamically adjusted based on the type of terminal device; for example, different types of terminal devices have varying importance in terms of hardware, processes, and network interactions, thus assigning different weights. During the fusion process, the parameter deviation percentage, behavioral deviation coefficient, and pattern deviation index for each dimension are multiplied by their corresponding weights, and the results are then concatenated to form the terminal credibility deviation score.

[0053] Step S124: Retrieve the device security baseline parameters from the security configuration library of the device to be bound to the scene. The device security baseline parameters include interface stable operation standards, normal output range of sensors, and environmental correlation benchmark characteristics.

[0054] The security configuration library is a database used to store security baseline parameters in the device to be bound to the scenario, and it has strict access control and update mechanisms. The interface stable operation standard is formulated according to the design specifications and normal operation requirements of the device interface, including standard values ​​for interface connection stability, data transmission error rate, and interface power supply parameters. The normal output range of the sensor is the range of output data of the sensor under normal operating conditions, with corresponding ranges for vibration frequency characteristics, sound wave intensity characteristics, and light sensitivity change characteristics. The environmental correlation baseline characteristics are a set of standard characteristics of the device under normal environmental conditions, including electromagnetic characteristics, temperature and humidity correlation characteristics, and air pressure fluctuation characteristics.

[0055] Step S125: Compare the real-time status of the device interface in the dynamic state feature set with the interface stable operation standard, calculate the state deviation value, compare the sensor sensing data with the normal output range of the sensor, calculate the sensing deviation degree, match the environmental correlation features with the environmental correlation benchmark features, and calculate the environmental adaptation deviation coefficient.

[0056] Step S1251: Extract the interface connection stability, data transmission error rate and interface power supply parameters from the real-time status of the device interface, and convert them into standardized values.

[0057] The extraction process involves obtaining specific data on interface connection stability, data transmission error rate, and interface power supply parameters from the real-time status of the device interface. When converting these data to standardized values, a pre-defined standardization method can be used, such as mapping the data to a range of 0 to 1, to eliminate dimensional differences between different parameters.

[0058] Step S1252: Extract the corresponding standard values ​​from the interface stable operation standard, and calculate the absolute difference between the standardized value and the standard value of each parameter.

[0059] Standard values ​​corresponding to interface connection stability, data transmission error rate, and interface power supply parameters are extracted from the interface stability operation standard. When calculating the absolute difference, for each dimension of each parameter, the standardized value is subtracted from the corresponding standard value, and the absolute value is taken to obtain the absolute difference for each dimension. The absolute differences of multiple dimensions constitute the absolute difference set of that parameter. The absolute difference sets of the three parameters together form a comprehensive absolute difference set.

[0060] Step S1253: Perform a sum of squares operation on the absolute difference and take the square root to obtain the state deviation value.

[0061] The sum of squares operation involves squaring each value in the set of absolute differences and then summing all the squared values. Taking the square root involves taking the square root of the sum of squares to obtain the state deviation value.

[0062] Step S1254: Compare the vibration frequency characteristics, sound wave intensity characteristics, and light sensitivity change characteristics in the sensor-sensed data with the normal output range of the sensor to determine the proportion of each characteristic that exceeds the range.

[0063] Interval comparison checks whether each value in the vibration frequency feature, sound wave intensity feature, and light sensitivity change feature is within the normal output range of the corresponding sensor. For each value of each feature, if it exceeds the normal output range, it is recorded as exceeding the range; otherwise, it is recorded as normal. The percentage of values ​​exceeding the range is calculated by dividing the number of values ​​exceeding the normal range for each feature by the total number of values ​​for that feature.

[0064] Step S1255: Perform an arithmetic average on the proportion of the out-of-range data to obtain the perceived deviation.

[0065] Arithmetic averaging involves adding the proportions of vibration frequency characteristics, sound wave intensity characteristics, and light perception change characteristics that exceed the range, and then dividing by 3 to obtain the perception deviation.

[0066] Step S1256: Match the electromagnetic features, temperature and humidity co-location features, and air pressure fluctuation features in the environmental correlation features with the environmental correlation benchmark features, and count the number of successfully matched feature points.

[0067] Feature point matching compares each feature point in the environmental associated features with its corresponding feature point in the environmental associated baseline features to determine if they match. For example, for a frequency point in the electromagnetic features, the intensity of the same frequency point in the baseline features is compared; if they are within a set range, a successful match is considered. To count the number of successfully matched feature points, the number of successfully matched feature points in the electromagnetic features, temperature and humidity associated features, and air pressure fluctuation features can be counted separately, and then summed to obtain the total number of successful matches.

[0068] Step S1257: Divide the number of successfully matched feature points by the total number of feature points to obtain the matching success rate, and subtract the matching success rate from 1 to obtain the environment adaptation deviation coefficient.

[0069] The total number of feature points is the sum of all feature points in the environmental association features, including electromagnetic features, humidity-related features, air pressure fluctuation features, etc. For each dimension, the total number of successful matches is divided by the total number of feature points in that dimension to obtain the matching success rate for that dimension. Then, subtracting the matching success rate for each dimension from 1 yields the environmental adaptation deviation coefficient for each dimension. The environmental adaptation deviation coefficients from multiple dimensions constitute the environmental adaptation deviation coefficient set.

[0070] Step S126: Normalize and integrate the state deviation value, perception deviation degree and environmental adaptation deviation coefficient to generate the equipment safety deviation degree.

[0071] Normalization and integration processing transforms state deviation values, perception deviations, and environmental adaptation deviation coefficients into the same numerical range for comprehensive integration. Normalization can be achieved by subtracting the minimum value from each value and then dividing by the difference between the maximum and minimum values, mapping all values ​​to the range of 0 to 1. Integration processing then concatenates the normalized state deviation values, perception deviations, and environmental adaptation deviation coefficients in a predetermined order to form the device safety deviation.

[0072] Step S130: Construct a scene binding association graph by combining the terminal trust deviation and the device security deviation. The scene binding association graph includes feature mapping relationships, deviation coupling parameters and scene adaptation coefficients.

[0073] In this embodiment, the construction of the scene binding association graph is to establish an association model between the trusted terminal and the scene device to be bound. The scene binding association graph can clearly reflect the mapping of features, the correlation of deviation, and the scene adaptation between the two.

[0074] Step S131: Perform feature decomposition processing on the terminal trust deviation to obtain terminal hardware deviation component, process behavior deviation component and network interaction deviation component.

[0075] Feature decomposition processing uses feature extraction algorithms to decompose the terminal trust deviation into its constituent basic components. The terminal hardware deviation component is the deviation related to real-time terminal hardware parameters, decomposed from the terminal trust deviation, corresponding to the deviation reflected by the parameter deviation percentage. The process behavior deviation component is the deviation related to system process characteristics, decomposed from the terminal trust deviation, corresponding to the deviation reflected by the behavior deviation coefficient. The network interaction deviation component is the deviation related to network interaction identifiers, decomposed from the network interaction deviation index, corresponding to the deviation reflected by the pattern deviation index.

[0076] Step S132: Perform feature decomposition processing on the device safety deviation to obtain interface state deviation component, sensor perception deviation component and environment-related deviation component.

[0077] Similar to the feature decomposition of terminal trust deviation, the feature decomposition of device security deviation also employs feature extraction algorithms to break it down into various basic components. The interface state deviation component is the deviation related to the real-time state of the device interface, decomposed from the device security deviation, corresponding to the deviation reflected by the state deviation value. The sensor perception deviation component is the deviation related to sensor perception data, decomposed from the sensor perception deviation, corresponding to the deviation reflected by the perception deviation. The environment-related deviation component is the deviation related to environment-related features, decomposed from the environment adaptation deviation coefficient, corresponding to the deviation reflected by the environment adaptation deviation coefficient.

[0078] Step S133: Establish the mapping relationship between the terminal deviation component and the device deviation component, and generate the feature mapping relationship, which is represented in the form of a directed graph.

[0079] When establishing mapping relationships, it is necessary to analyze the inherent connections between terminal deviation components and device deviation components. For example, terminal hardware deviation components may be related to device interface state deviation components, because the operating state of terminal hardware may affect the interaction with the device interface; process behavior deviation components may be related to sensor perception deviation components, as abnormal process behavior may lead to abnormal processing of sensor data; network interaction deviation components may be related to environment-related deviation components, as abnormal network interactions may be affected by environmental factors. In a directed graph, each terminal deviation component and device deviation component is treated as a node, and the directed edges between nodes represent the mapping relationship between them, with the direction of the edge indicating the direction of influence, thus forming a feature mapping relationship.

[0080] Step S134: Calculate the product of the terminal deviation component and the device deviation component in each pair of mapping relationships to obtain the deviation coupling parameter, which reflects the correlation strength between the two.

[0081] For each directed edge in the directed graph representing a mapping relationship—that is, for each pair of terminal deviation components and device deviation components with a mapping relationship—the values ​​of their corresponding dimensions are multiplied together. For example, multiplying a certain dimension value of the terminal hardware deviation component with the same dimension value of the corresponding interface state deviation component yields the deviation coupling parameter value for that dimension. The product of all dimensions constitutes the deviation coupling parameter for that mapping relationship. The deviation coupling parameters of multiple mapping relationships together form a set of deviation coupling parameters, which reflects the correlation strength between the two components in each mapping relationship.

[0082] Step S135: Call the scene adaptation evaluation model, input the real-time running feature set and the dynamic state feature set, and generate scene adaptation coefficients. The scene adaptation coefficients are positively correlated with the scene matching degree of the terminal and the device.

[0083] The scene adaptation evaluation model is a pre-trained model used to evaluate the degree of matching between a trusted terminal and a device to be bound to in the current scene. By inputting real-time running feature sets and dynamic state feature sets into this model, it outputs a scene adaptation coefficient. The higher the scene adaptation coefficient, the higher the degree of matching between the terminal and the device in the current scene.

[0084] Step S1351: Extract the communication peer address and data transmission direction from the network interaction identifier in the real-time operation feature set, and extract the electromagnetic features and temperature and humidity coordination features from the environmental association features in the dynamic state feature set.

[0085] The extraction process involves filtering out two features from the network interaction identifiers of the real-time running feature set: the communication peer address and the data transmission direction. These features reflect the network interaction objects and data flow direction of the terminal. Simultaneously, electromagnetic features and temperature / humidity co-occurrence features are extracted from the environmental correlation features of the dynamic state feature set. These two features reflect the environmental conditions in which the device operates.

[0086] Step S1352: Convert the communication peer address into network location features, convert the data transmission direction into interaction direction features, convert the electromagnetic features into electromagnetic spectrum features, and convert the temperature and humidity coordination features into environmental coordination features.

[0087] The conversion of the communication peer's address involves using a network address resolution algorithm to transform address information into a feature vector reflecting its network location, i.e., network location features. The conversion of data transmission direction involves encoding directional information into a specific feature vector, forming interactive directional features. The conversion of electromagnetic features involves performing spectral analysis on the electromagnetic features to obtain electromagnetic spectrum features, which more clearly reflect the spectral distribution of electromagnetic signals. The conversion of temperature and humidity synergistic features involves further processing the synergistic relationship between temperature and humidity to form environmental synergistic features, which better reflect the correlation between temperature and humidity.

[0088] Step S1353: Input the network location features, interaction direction features, electromagnetic spectrum features and environmental collaboration features into the feature preprocessing layer of the scene adaptation evaluation model, and perform feature standardization and dimension alignment processing.

[0089] The feature preprocessing layer is the first processing layer in the scene adaptation evaluation model. Its function is to preprocess the input features for subsequent processing. Feature standardization transforms network location features, interaction direction features, electromagnetic spectrum features, and environmental cooperation features to the same numerical range, eliminating the influence of dimensions. Dimension alignment adjusts the dimensions of each feature to have the same number of dimensions for merging processing.

[0090] Step S1354: The processed features are nonlinearly mapped using the multilayer perceptron of the scene adaptation evaluation model to generate intermediate feature vectors.

[0091] A multilayer perceptron consists of multiple fully connected layers, each containing several neurons. Processed features are first input to neurons in the first layer, then weighted and processed by activation functions before being output to neurons in the next layer, and so on, through multiple layers. During this process, features undergo non-linear mapping to extract higher-level, more abstract features, ultimately generating an intermediate feature vector.

[0092] Step S1355: Call the output layer of the scene adaptation evaluation model to normalize the intermediate feature vector and generate scene adaptation coefficients. The numerical range of the scene adaptation coefficients is within a preset range.

[0093] The output layer typically contains one or more neurons, whose function is to convert intermediate feature vectors into final scene adaptation coefficients. Normalization maps the values ​​of the intermediate feature vectors to a preset range, such as 0 to 1, so that the scene adaptation coefficients have a uniform scale.

[0094] Step S136: Construct a scene binding association graph using feature mapping relationships as edges, deviation coupling parameters as edge weights, and scene adaptation coefficients as node attributes.

[0095] When constructing the scene binding association graph, the directed edges represented in the feature mapping relationship are used as edges of the graph. The weight of each edge is set to the corresponding deviation coupling parameter, which reflects the association strength of the mapping relationship represented by the edge. The nodes in the graph include terminal deviation component nodes and device deviation component nodes. The attribute of each node is set to the corresponding scene adaptation coefficient, which reflects the adaptation status of the node in the current scene. Through the above settings, a complete scene binding association graph is constructed, which can comprehensively reflect the association relationship between trusted terminals and devices in the scene to be bound.

[0096] Step S140: Generate a bidirectional dynamic verification sequence based on the scene binding association graph, and send the bidirectional dynamic verification sequence to the trusted terminal and the scene device to be bound to perform cross-verification operation to obtain a cross-verification result set.

[0097] In this embodiment, the generation of the bidirectional dynamic verification sequence is based on the association relationship and parameters in the scene binding association graph. Through this sequence, the trusted terminal and the scene device to be bound can be cross-verified to ensure the authenticity and security of their status and association relationship. The cross-verification result set is a record of the verification process and results.

[0098] Step S141: Extract feature mapping relationships and deviation coupling parameters from the scene binding association graph to determine the verification nodes and the association order between nodes.

[0099] Extracting feature mapping relationships and deviation coupling parameters is crucial for understanding the associations that need to be verified and their strength. Verification nodes are determined based on the nodes in the feature mapping relationships, specifically terminal and device deviation component nodes. The features corresponding to these nodes are the key elements to be verified. The association order between nodes is determined by the direction of the directed edges in the feature mapping relationships and the magnitude of the deviation coupling parameters; typically, nodes with high association strength are verified first.

[0100] Step S142: Generate an initial verification sequence based on the verification nodes and their associated order. The initial verification sequence includes terminal-side verification instructions and device-side verification instructions.

[0101] The initial verification sequence is generated by generating corresponding verification instructions for each verification node according to a defined verification node and its associated order. For terminal-side verification nodes, terminal-side verification instructions are generated to instruct trusted terminals to perform relevant verification operations; for device-side verification nodes, device-side verification instructions are generated to instruct the device to be bound to perform relevant verification operations. The initial verification sequence is a sequence formed by arranging these instructions in the associated order.

[0102] Step S143: Dynamically adjust the initial verification sequence according to the scenario adaptation coefficient, increase the number of verification nodes in high adaptation scenarios, and reduce redundant verification nodes in low adaptation scenarios.

[0103] The scenario adaptation coefficient reflects the matching degree between the terminal and the device in the current scenario. A high adaptation scenario indicates a high degree of matching between the two, requiring more comprehensive verification to ensure security. Therefore, the number of verification nodes is increased to verify more features. A low adaptation scenario indicates a low degree of matching between the two, potentially containing some unnecessary verification nodes. Therefore, redundant verification nodes are reduced to improve verification efficiency. The adjusted verification sequence better reflects the actual situation of the current scenario.

[0104] Step S144: The adjusted verification sequence is split into terminal verification sub-sequence and device verification sub-sequence, and combined to form a bidirectional dynamic verification sequence.

[0105] The splitting process involves extracting the terminal-side verification instructions from the adjusted verification sequence and assembling them into a terminal verification sub-sequence in sequence; and extracting the device-side verification instructions and assembling them into a device verification sub-sequence. Then, these two sub-sequences are combined to form a bidirectional dynamic verification sequence, which contains all verification instructions for both the trusted terminal and the device to be bound to the scenario.

[0106] Step S145: Send the terminal verification sub-sequence to the trusted terminal, triggering the trusted terminal to perform hardware feature verification, process integrity verification, and network interaction consistency verification in sequence.

[0107] The sending terminal can verify the subsequence through a secure communication channel, ensuring that the instructions are not tampered with or leaked during transmission. After receiving the subsequence, the trusted terminal can execute the verification operations sequentially according to the instructions in the sequence to verify whether its hardware, processes, and network interactions are functioning correctly.

[0108] Step S1451: After receiving the terminal verification subsequence, the trusted terminal parses it to obtain the hardware feature verification instruction, the process integrity verification instruction, and the network interaction consistency verification instruction.

[0109] The trusted terminal has a dedicated instruction parsing module that parses the received terminal verification subsequence. The parsing process identifies each instruction in the subsequence, distinguishes between hardware feature verification instructions, process integrity verification instructions, and network interaction consistency verification instructions, and determines their execution order.

[0110] Step S1452: In response to the hardware feature verification command, call the hardware monitoring unit to re-collect the CPU operating load, memory usage ratio and storage read / write frequency, compare them with the corresponding parameters in the real-time running feature set, and generate hardware feature verification results.

[0111] Upon responding to a hardware signature verification command, the trusted terminal activates its hardware monitoring unit to re-collect CPU load, memory usage ratio, and storage read / write frequency using the same collection method and cycle as before. Then, the newly collected parameters are compared one by one with the corresponding parameters stored in the real-time signature database to check their consistency. The comparison results are recorded, forming the hardware signature verification result.

[0112] Step S1453: Respond to the process integrity verification command, start the process verification module to perform signature verification on the process startup time, inter-process communication frequency and process permission level in the system process characteristics, check for unauthorized modifications, and generate process integrity verification results.

[0113] The process verification module obtains current data on process startup time, inter-process communication frequency, and process permission level from system process characteristics, and retrieves the original signature information of this data. Using a signature verification algorithm, it checks whether the current data matches the original signature to determine if unauthorized modifications have occurred. The verification results are then compiled into a process integrity verification result.

[0114] Step S1454: In response to the network interaction consistency verification command, obtain the current network interaction identifier through the network monitoring component, compare it with the network interaction identifier in the real-time running feature set for time sequence consistency, and generate the network interaction consistency verification result.

[0115] The network monitoring component acquires current network interaction identifiers in real time, including connection protocol type, peer address, and data transmission direction. These current identifiers are then compared chronologically with the network interaction identifiers recorded in the real-time feature set to check their temporal consistency. The comparison results constitute the network interaction consistency verification results.

[0116] Step S1455: Combine the hardware feature verification result, process integrity verification result, and network interaction consistency verification result into a terminal verification result according to the order of the terminal verification sub-sequence.

[0117] The combination process arranges the corresponding verification results sequentially according to the execution order of hardware feature verification instructions, process integrity verification instructions, and network interaction consistency verification instructions in the terminal verification subsequence, forming the terminal verification result. This terminal verification result comprehensively reflects the verification status of the trusted terminal.

[0118] Step S146: Send the device verification sub-sequence to the device to be bound in the scene, triggering the device to be bound in the scene to perform interface status verification, sensor data verification and environmental feature verification in sequence.

[0119] The transmission of device verification sub-sequences is also conducted through a secure communication channel to ensure the security of the instructions. After receiving the sub-sequence, the device to be bound to can execute various verification operations in the order of the instructions to verify the status of its own interfaces, sensors, and environmental characteristics.

[0120] Step S1461: After receiving the device verification subsequence, the device to be bound to the scene parses out the interface status verification instruction, sensor data verification instruction and environmental feature verification instruction.

[0121] The instruction parsing module inside the device to be bound will parse the device verification subsequence, identify the interface status verification instruction, sensor data verification instruction, and environmental feature verification instruction, and determine their execution order.

[0122] Step S1462: Respond to the interface status verification command, re-collect the real-time status of the device interface through the interface status monitor, calculate the deviation between the real-time status of the device interface and the dynamic status feature set, and generate the interface status verification result.

[0123] The interface status monitor re-collects the real-time status of the device interface, including interface connection stability, data transmission error rate, and interface power supply parameters. Then, it calculates the deviation between the newly collected status data and the corresponding status data stored in the dynamic status feature set, such as calculating the difference or ratio between the two. The calculation result forms the interface status verification result.

[0124] Step S1463: In response to the sensor data verification command, control the multi-dimensional sensor array to re-acquire vibration frequency characteristics, sound wave intensity characteristics and light sensing change characteristics, perform trend consistency analysis with the sensor sensing data, and generate sensor data verification results.

[0125] The multi-dimensional sensor array will re-acquire vibration frequency characteristics, sound wave intensity characteristics, and light sensitivity change characteristics using the same acquisition method as before. Trend consistency analysis compares the newly acquired data with the sensor-sensed data to see if they are consistent in their trends, such as both showing an upward trend, a downward trend, or remaining stable. The analysis results constitute the sensor data verification results.

[0126] Step S1464: In response to the environmental feature verification command, call the environmental association module to regenerate the environmental association features, perform feature matching with the environmental association features in the dynamic state feature set, and generate the environmental feature verification result.

[0127] The environmental association module generates new environmental association features based on the newly collected environmental data, including electromagnetic features, temperature and humidity co-occurrence features, and air pressure fluctuation features. Then, it matches the newly generated environmental association features with the environmental association features in the dynamic state feature set, and calculates the proportion of successful matches. The matching results form the environmental feature verification results.

[0128] Step S1465: Combine the interface status verification result, sensor data verification result, and environmental feature verification result into a device verification result according to the order of the device verification sub-sequence.

[0129] According to the execution order of interface status verification instructions, sensor data verification instructions, and environmental feature verification instructions in the device verification subsequence, the corresponding verification results are arranged in sequence and combined to form the device verification result. This device verification result comprehensively reflects the verification status of the device in the scene to be bound.

[0130] Step S147: After the trusted terminal completes the verification, a terminal verification result is generated; after the device to be bound to the scene completes the verification, a device verification result is generated.

[0131] The terminal verification result and the device verification result are generated by the trusted terminal and the device to be bound to the scenario after they have completed their respective verification sub-sequences. They contain details and results of each verification operation.

[0132] Step S148: Associate the terminal verification results and device verification results according to the corresponding verification nodes to form a cross-verification result set.

[0133] Correspondence association involves linking the portion of the terminal verification result corresponding to each verification node with the portion of the device verification result corresponding to the same verification node. For example, for the verification node of terminal hardware deviation component and device interface state deviation component, the verification portion of the terminal verification result related to terminal hardware characteristics is associated with the verification portion of the device verification result related to interface state. After all terminal and device verification portions corresponding to all verification nodes are associated, a complete cross-verification result set is formed. This cross-verification result set contains the correspondence between the terminal and device verification status of each verification node, clearly reflecting the consistency and correlation between the trusted terminal and the device to be bound in the scenario at each verification node.

[0134] Step S150: Start the hierarchical binding process according to the cross-validation result set, generate a binding relationship file containing dynamic binding identifier, scene association parameters and security level label, and store the binding relationship file in the encrypted storage area of ​​the trusted terminal and the security partition of the scene device to be bound.

[0135] In this embodiment, the hierarchical binding process adopts different binding strategies based on different cross-validation result sets. By generating and securely storing binding relationship files, it achieves secure binding between trusted terminals and devices in the target scenario, ensuring the security and reliability of both in subsequent interactions.

[0136] Step S151: Parse the cross-validation result set, count the number of matches between terminal validation results and device validation results, and calculate the validation matching rate.

[0137] When parsing the cross-validation result set, the matching status of the terminal verification result and the device verification result corresponding to each verification node can be checked one by one. The number of matches is counted by the number of verification nodes whose terminal verification results and device verification results are consistent in content and trend. The verification match rate is calculated by dividing the counted number of matches by the total number of verification nodes.

[0138] Step S152: Determine the binding level based on the verification matching rate. If the verification matching rate reaches the first preset threshold, start the advanced binding process. If it reaches the second preset threshold, start the intermediate binding process. Otherwise, start the basic binding process.

[0139] The first and second preset thresholds are pre-set critical values ​​used to distinguish different binding levels, with the first preset threshold being higher than the second. When determining the binding level, the calculated verification matching rate can be compared with these two thresholds. When the verification matching rate reaches or exceeds the first preset threshold, it indicates a very high degree of matching between the trusted terminal and the device to be bound, making it suitable to initiate the advanced binding process. When the verification matching rate reaches or exceeds the second preset threshold but does not reach the first preset threshold, it indicates a good degree of matching, and the intermediate binding process is initiated. When the verification matching rate is lower than the second preset threshold, it indicates a moderate degree of matching, and the basic binding process is initiated.

[0140] Step S153: In the advanced binding process, generate a dynamic binding identifier that includes a real-time update mechanism, extract the feature mapping relationship and scene adaptation coefficient from the scene binding association graph as scene association parameters, and mark the advanced security level label.

[0141] A dynamic binding identifier is a unique identifier used to identify the binding relationship between a trusted terminal and a device in the scene to be bound. In the advanced binding process, its real-time update mechanism means that the identifier is updated in real time according to changes in the state of the terminal and device to ensure its timeliness and security. When extracting scene association parameters, all feature mapping relationships and scene adaptation coefficients can be obtained from the scene binding association graph. These parameters comprehensively reflect the association between the two and the degree of scene adaptation. An advanced security level label is used to indicate that the binding relationship has a higher security level, indicating that the interaction between the terminal and device under this binding relationship has stricter security guarantees.

[0142] Step S154: In the intermediate binding process, a dynamic binding identifier containing a timed update mechanism is generated, the deviation coupling parameter and the scene adaptation coefficient in the scene binding association graph are extracted as scene association parameters, and the intermediate security level label is marked.

[0143] The timed update mechanism of the dynamic binding identifier in the intermediate binding process means that the identifier is updated at preset fixed time intervals, ensuring a certain timeliness of the identifier without consuming excessive resources like real-time updates. The extracted deviation coupling parameters and scene adaptation coefficients, used as scene association parameters, reflect the strength of the correlation between the two deviations and the scene adaptation. The intermediate security level label indicates that the security level of this binding relationship is moderate, and its security measures are suitable for general interaction scenarios.

[0144] Step S155: In the basic binding process, generate a dynamic binding identifier that includes a fixed periodic update mechanism, extract the feature mapping relationship in the scene binding association graph as the scene association parameter, and mark the basic security level label.

[0145] Dynamic binding identifiers under a fixed-period update mechanism are updated after a relatively long fixed period, suitable for scenarios where timeliness requirements are not high. The extracted feature mapping relationship, used as a scenario association parameter, can basically reflect the association between the two. The basic security level label indicates that the security level of this binding relationship is low, suitable for some simple interaction scenarios with low security requirements.

[0146] Step S156: Combine the dynamic binding identifier, scene association parameters, and security level label into a binding relationship file.

[0147] The assembly process combines the dynamic binding identifier, scenario association parameters, and security level labels according to a set format and order to form a complete binding relationship file. This binding relationship file contains all the key information about the binding relationship.

[0148] Step S157: Call the encrypted storage module of the trusted terminal to encrypt the binding relationship file and store it in the encrypted storage area, which is protected by hardware encryption.

[0149] The encrypted storage module of the trusted terminal has powerful encryption capabilities. Before storing the binding relationship files, advanced encryption algorithms can be used to encrypt the files, converting plaintext files into ciphertext. The encrypted storage area is a dedicated area in the trusted terminal for storing sensitive information. The hardware encryption method used is implemented through a hardware encryption chip inside the terminal, which can effectively prevent files from being illegally accessed and tampered with, ensuring the secure storage of binding relationship files on the terminal side.

[0150] Step S158: Send the binding relationship file to the scene device to be bound through a secure communication channel, so that the scene device to be bound stores it in a secure partition, which only allows processes with specific permissions to access the secure partition.

[0151] A secure communication channel is an encrypted and authenticated communication link that ensures the binding relationship file is not stolen, tampered with, or forged during transmission. Once the device receiving the file can store it in its own secure partition, this partition has a strict access control mechanism. Only processes with specific permissions can read or modify it; other unauthorized processes cannot access it, thus ensuring the secure storage of the binding relationship file on the device side.

[0152] Figure 2 The illustration shows exemplary hardware and software components of a scene device security binding system 100 based on trusted terminal monitoring, which can implement the ideas of this application, according to some embodiments of this application. For example, a processor 120 can be used in the scene device security binding system 100 based on trusted terminal monitoring and to perform the functions in this application.

[0153] The scene device security binding system 100 based on trusted terminal monitoring can be a general-purpose server or a special-purpose server; both can be used to implement the scene device security binding method based on trusted terminal monitoring of this application. Although only one server is shown in this application, for convenience, the functions described in this application can be implemented in a distributed manner on multiple similar platforms to balance the load.

[0154] For example, the scene device security binding system 100 based on trusted terminal monitoring may include a network port 110 connected to a network, one or more processors 120 for executing program instructions, a communication bus 130, and various forms of storage media 140, such as a disk, ROM, or RAM, or any combination thereof. Exemplarily, the scene device security binding system 100 based on trusted terminal monitoring may also include program instructions stored in ROM, RAM, or other types of non-transitory storage media, or any combination thereof. The methods of this application can be implemented according to these program instructions. The scene device security binding system 100 based on trusted terminal monitoring also includes an I / O interface 150 between the computer and other input / output devices.

[0155] For ease of explanation, only one processor is described in the scene device security binding system 100 based on trusted terminal monitoring. However, it should be noted that the scene device security binding system 100 based on trusted terminal monitoring in this application may also include multiple processors. Therefore, the steps executed by one processor described in this application may also be executed jointly or individually by multiple processors. For example, if the processor of the scene device security binding system 100 based on trusted terminal monitoring executes steps A and B, it should be understood that steps A and B may also be executed jointly by two different processors or individually by one processor. For example, the first processor executes step A, the second processor executes step B, or the first processor and the second processor jointly execute steps A and B.

[0156] Furthermore, this embodiment of the invention also provides a readable storage medium, wherein computer-executable instructions are preset in the readable storage medium, and when the processor executes the computer-executable instructions, the above-mentioned scene device security binding method based on trusted terminal monitoring is implemented.

[0157] It should be noted that, in order to simplify the description of the present invention and thus help to understand one or more embodiments of the invention, multiple features may sometimes be grouped into one embodiment, drawing or description thereof in the foregoing description of the embodiments of the present invention.

Claims

1. A method for secure binding of scene devices based on trusted terminal monitoring, characterized in that, The method comprises: obtaining a real-time running feature set of a trusted terminal and a dynamic state feature set of a scene device to be bound, wherein the real-time running feature set comprises terminal hardware real-time parameters, system process features and network interaction identifiers, and the dynamic state feature set comprises device interface real-time states, sensor sensing data and environment-related features; performing trusted baseline comparison processing on the real-time running feature set to generate a terminal trusted deviation degree, and performing security baseline comparison processing on the dynamic state feature set to generate a device security deviation degree; constructing a scene binding correlation graph by combining the terminal trusted deviation degree and the device security deviation degree, comprising: performing feature decomposition processing on the terminal trusted deviation degree to obtain terminal hardware deviation components, process behavior deviation components and network interaction deviation components; performing feature decomposition processing on the device security deviation degree to obtain interface state deviation components, sensor sensing deviation components and environment-related deviation components; establishing a mapping relationship between the terminal deviation components and the device deviation components to generate a feature mapping relationship, wherein the feature mapping relationship is represented in the form of a directed graph; calculating the product of the terminal deviation components and the device deviation components in each pair of mapping relationships to obtain a deviation degree coupling parameter, wherein the deviation degree coupling parameter reflects the correlation strength of the two; calling a scene adaptation evaluation model, inputting the real-time running feature set and the dynamic state feature set, and generating a scene adaptation coefficient, wherein the scene adaptation coefficient is positively correlated with the scene matching degree of the terminal and the device; constructing a scene binding correlation graph with the feature mapping relationship as the edge and the deviation degree coupling parameter as the edge weight, and with the scene adaptation coefficient as the node attribute; generating a bidirectional dynamic verification sequence according to the scene binding correlation graph, sending the bidirectional dynamic verification sequence to the trusted terminal and the scene device to be bound respectively to perform cross-verification operations, and obtaining a cross-verification result set; starting a hierarchical binding process according to the cross-verification result set, generating a binding relationship archive containing a dynamic binding identifier, a scene correlation parameter and a security level label, and storing the binding relationship archive in an encrypted storage area of the trusted terminal and a security partition of the scene device to be bound respectively.

2. The method of claim 1, wherein the trusted terminal monitoring based scene device security binding method is characterized by, The method comprises: acquiring the real-time running feature set of the trusted terminal and the dynamic state feature set of the scene device to be bound, comprising: acquiring terminal hardware real-time parameters by a hardware monitoring unit of the trusted terminal at a preset period, wherein the terminal hardware real-time parameters comprise CPU running load, memory occupancy ratio and storage read-write frequency; extracting system process features by a terminal process management module, wherein the system process features comprise process startup time, inter-process communication frequency and process permission level; recording network interaction identifiers by a terminal network monitoring component, wherein the network interaction identifiers comprise connection protocol type, communication peer address and data transmission direction; aligning and combining the terminal hardware real-time parameters, system process features and network interaction identifiers by timestamp to form the real-time running feature set; acquiring device interface real-time states by an interface state monitor of the scene device to be bound, wherein the device interface real-time states comprise interface connection stability, data transmission error rate and interface power supply parameters; The sensor perception data collected by the multi-dimensional sensor array of the scene device to be bound includes vibration frequency characteristics, sound wave intensity characteristics and light perception change characteristics; The device environment association module is called to generate environment association characteristics, which include electromagnetic characteristics, temperature and humidity coordination characteristics and air pressure fluctuation characteristics of the space where the device is located; The device interface real-time state, sensor perception data and environment association characteristics are combined into a dynamic state feature set according to the collection time sequence. 3.The method of claim 1, wherein, The real-time running feature set is compared with the trusted baseline to generate a terminal trusted deviation degree, and the dynamic state feature set is compared with the security baseline to generate a device security deviation degree, including: The terminal trusted baseline parameters are called from the built-in trusted database of the trusted terminal, which include hardware normal running threshold range, process security behavior model and network interaction reference mode; The terminal hardware real-time parameters in the real-time running feature set are compared with the hardware normal running threshold range to calculate the parameter deviation percentage, the system process characteristics are matched with the process security behavior model to calculate the behavior deviation coefficient, and the network interaction identifier is compared with the network interaction reference mode to calculate the mode deviation index; The parameter deviation percentage, behavior deviation coefficient and mode deviation index are weighted and fused to generate a terminal trusted deviation degree, and the weights of the weighted fusion processing are dynamically adjusted according to the terminal device type; The device security baseline parameters are called from the security configuration library of the scene device to be bound, which include interface stable running standard, sensor normal output range and environment association reference characteristics; The device interface real-time state in the dynamic state feature set is compared with the interface stable running standard to calculate the state deviation value, the sensor perception data is compared with the sensor normal output range to calculate the perception deviation degree, and the environment association characteristics are matched with the environment association reference characteristics to calculate the environment adaptation deviation coefficient; The state deviation value, perception deviation degree and environment adaptation deviation coefficient are normalized and integrated to generate a device security deviation degree.

4. The method of claim 3, wherein the trusted terminal monitoring based scene device security binding method is characterized by, The terminal hardware real-time parameters in the real-time running feature set are compared with the hardware normal running threshold range to calculate the parameter deviation percentage, the system process characteristics are matched with the process security behavior model to calculate the behavior deviation coefficient, and the network interaction identifier is compared with the network interaction reference mode to calculate the mode deviation index, including: The CPU running load, memory occupation ratio and storage read-write frequency in the real-time running feature set are extracted, and the absolute deviation values of each parameter are obtained by difference calculation with the corresponding threshold values in the hardware normal running threshold range; The absolute deviation values of each parameter are divided by the upper limit value of the corresponding threshold value to obtain the parameter deviation percentage, and the numerical range of the parameter deviation percentage is mapped to a preset interval; The process start time, inter-process communication frequency and process permission level in the system process characteristics are analyzed and converted into a feature vector form, denoted as a process feature vector; The calling process security behavior model generates a standard process feature vector, calculates the Euclidean distance between the process feature vector and the standard process feature vector, and converts the Euclidean distance into a behavior deviation coefficient; The connection protocol type, communication opposite end address and data transmission direction in the network interaction identification are compared with the corresponding elements in the network interaction reference mode one by one, and the number of unmatched elements is counted; The number of unmatched elements is divided by the total number of elements to obtain a mode deviation index, and the larger the value of the mode deviation index, the more the network interaction deviates from the reference mode; The device interface real-time state in the dynamic state feature set is compared with the interface stable operation standard, the state deviation value is calculated, the sensor perception data is compared with the sensor normal output range, the perception deviation degree is calculated, and the environment correlation feature is matched with the environment correlation reference feature to calculate the environment adaptation deviation coefficient, including: The interface connection stability, data transmission error rate and interface power supply parameters in the device interface real-time state are extracted and converted into standardized values; The corresponding standard values are extracted from the interface stable operation standard, and the absolute difference between the standardized value and the standard value of each parameter is calculated; The absolute difference is squared and summed, and the square root is taken to obtain the state deviation value; The vibration frequency feature, sound wave intensity feature and light sense change feature in the sensor perception data are respectively compared with the sensor normal output range to determine the exceeding interval proportion of each feature; The exceeding interval proportions are arithmetically averaged to obtain the perception deviation degree; The electromagnetic feature, temperature and humidity coordination feature and air pressure fluctuation feature in the environment correlation feature are matched with the environment correlation reference feature, and the number of matched feature points is counted; The number of matched feature points is divided by the total number of feature points to obtain a matching success rate, and the environment adaptation deviation coefficient is obtained by subtracting the matching success rate from 1.

5. The method of claim 1, wherein the trusted terminal monitoring based scene device security binding method is characterized by, The calling scene adaptation evaluation model inputs the real-time running feature set and the dynamic state feature set to generate a scene adaptation coefficient, including: The communication opposite end address and data transmission direction in the network interaction identification are extracted from the real-time running feature set, and the electromagnetic feature and temperature and humidity coordination feature in the environment correlation feature are extracted from the dynamic state feature set; The communication opposite end address is converted into a network location feature, the data transmission direction is converted into an interaction direction feature, the electromagnetic feature is converted into an electromagnetic spectrum feature, and the temperature and humidity coordination feature is converted into an environment coordination feature; The network location feature, interaction direction feature, electromagnetic spectrum feature and environment coordination feature are input into the feature preprocessing layer of the scene adaptation evaluation model for feature standardization and dimension alignment processing; The processed features are processed by the multilayer perceptron of the scene adaptation evaluation model for nonlinear mapping to generate an intermediate feature vector; The output layer of the scene adaptation evaluation model is called to normalize the intermediate feature vector to generate a scene adaptation coefficient, and the value range of the scene adaptation coefficient is within a preset interval. 6.The method of claim 1, wherein, The bidirectional dynamic verification sequence is generated according to the scene binding association graph, and the bidirectional dynamic verification sequence is sent to a trusted terminal and a scene device to be bound to perform cross verification, and a cross verification result set is obtained, including: Extracting a feature mapping relationship and a deviation degree coupling parameter from the scene binding association graph, determining a verification node and an association order between nodes; Generating an initial verification sequence based on the verification node and the association order, the initial verification sequence including a terminal-side verification instruction and a device-side verification instruction; According to the scene adaptation coefficient, the initial verification sequence is dynamically adjusted, the number of verification nodes in a high adaptation scene is increased, and redundant verification nodes in a low adaptation scene are reduced; The adjusted verification sequence is split into a terminal verification sub-sequence and a device verification sub-sequence, and combined to form a bidirectional dynamic verification sequence; The terminal verification sub-sequence is sent to the trusted terminal, triggering the trusted terminal to perform hardware feature verification, process integrity verification, and network interaction consistency verification according to the sequence; The device verification sub-sequence is sent to the scene device to be bound, triggering the scene device to be bound to perform interface state verification, sensor data verification, and environment feature verification according to the sequence; The trusted terminal generates a terminal verification result after completing verification, and the scene device to be bound generates a device verification result after completing verification; The terminal verification result and the device verification result are associated according to the corresponding verification nodes to form a cross verification result set.

7. The trusted terminal monitoring based scene device security binding method according to claim 6, characterized in that, The terminal verification sub-sequence is sent to the trusted terminal, triggering the trusted terminal to perform hardware feature verification, process integrity verification, and network interaction consistency verification according to the sequence, including: After the trusted terminal receives the terminal verification sub-sequence, hardware feature verification instructions, process integrity verification instructions, and network interaction consistency verification instructions are obtained by parsing; In response to the hardware feature verification instruction, the hardware monitoring unit is called to reacquire CPU running load, memory occupation ratio, and storage read-write frequency, and consistency comparison is performed with the corresponding parameters in the real-time running feature set to generate a hardware feature verification result; In response to the process integrity verification instruction, the process checking module is started to verify the signature of the process start time, inter-process communication frequency, and process permission level in the system process feature, check whether there is unauthorized modification, and generate a process integrity verification result; In response to the network interaction consistency verification instruction, the current network interaction identifier is obtained through the network monitoring component, and timing consistency comparison is performed with the network interaction identifier in the real-time running feature set to generate a network interaction consistency verification result; The hardware feature verification result, the process integrity verification result, and the network interaction consistency verification result are combined into a terminal verification result in the order of the terminal verification sub-sequence; And, the device verification sub-sequence is sent to the scene device to be bound, triggering the scene device to be bound to perform interface state verification, sensor data verification, and environment feature verification according to the sequence, including: After the scene device to be bound receives the device verification sub-sequence, interface state verification instructions, sensor data verification instructions, and environment feature verification instructions are obtained by parsing; In response to the interface state verification instruction, the interface state monitor is used to reacquire the real-time state of the device interface, deviation calculation is performed on the real-time state of the device interface in the dynamic state feature set, and an interface state verification result is generated; In response to the sensor data verification instruction, the multi-dimensional sensor array is controlled to reacquire the vibration frequency feature, the sound wave intensity feature, and the light sense change feature, trend consistency analysis is performed on the sensor sensing data, and a sensor data verification result is generated; In response to the environment feature verification instruction, the environment correlation module is called to reacquire the environment correlation feature, feature matching is performed on the environment correlation feature in the dynamic state feature set, and an environment feature verification result is generated; The interface state verification result, the sensor data verification result, and the environment feature verification result are combined into a device verification result in the order of the device verification subsequence. 8.The method of claim 1, wherein, The cross-verification result set is analyzed, the matching number of terminal verification results and device verification results is counted, and a verification matching rate is calculated. According to the verification matching rate, the binding level is determined. If the verification matching rate reaches a first preset threshold, a high-level binding process is started. If the verification matching rate reaches a second preset threshold, a medium-level binding process is started. Otherwise, a basic binding process is started. In the high-level binding process, a dynamic binding identifier containing a real-time update mechanism is generated, the feature mapping relationship and the scene adaptation coefficient in the scene binding correlation graph are extracted as the scene correlation parameters, and a high-level security level label is marked. In the medium-level binding process, a dynamic binding identifier containing a timing update mechanism is generated, the deviation coupling parameter and the scene adaptation coefficient in the scene binding correlation graph are extracted as the scene correlation parameters, and a medium-level security level label is marked. In the basic binding process, a dynamic binding identifier containing a fixed period update mechanism is generated, the feature mapping relationship in the scene binding correlation graph is extracted as the scene correlation parameter, and a basic security level label is marked. The dynamic binding identifier, the scene correlation parameter, and the security level label are combined into a binding relationship file. The encryption storage module of the trusted terminal is called, the binding relationship file is encrypted and stored in the encrypted storage area, and the encrypted storage area is protected by a hardware encryption method. The binding relationship file is sent to the scene device to be bound through a secure communication channel, so that the scene device to be bound stores it in a secure partition, and the secure partition only allows processes with specific permissions to access. The device comprises a processor and a memory. The memory and the processor are connected. The memory is used to store programs, instructions or codes. The processor is used to execute the programs, instructions or codes in the memory to implement the scene device security binding method based on the trusted terminal monitoring according to any one of claims 1-8.

9. A scene device security binding system based on trusted terminal monitoring, characterized in that... ​

Citation Information

Patent Citations

  • Method for achieving home credible networking based on safety pendent of smart home device

    CN103873487A

  • Security processing method and device

    CN111431840A