Device authentication method, electronic device, storage medium and program product

By authenticating PLC devices through the generation of unique device fingerprints, and utilizing timestamps and multi-factor authentication mechanisms, the security and accuracy issues of PLC devices are resolved, thereby improving the accuracy of authentication and defense capabilities.

CN120934752APending Publication Date: 2025-11-11HUBEI TIANRONGXIN NETWORK SECURITY TECH CO LTD +3
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511209605.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-27
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

In the existing technology, the hardware identification data encryption scheme of programmable logic controllers (PLCs) is not very secure and accurate, making it difficult to defend against threats such as unauthorized access, program tampering and device cloning.

Method used

By receiving the physical address information, timestamp, and device information of the device to be verified, a unique device fingerprint is generated using a preset key generation and parsing algorithm. An authorization key is then generated through hash operation. After comparison, it is determined whether the device can be added to the production system. The combination of dynamic timestamps and multi-factor authentication mechanisms improves the accuracy of authentication.

Benefits of technology

It improves the accuracy of device authentication, increases the cost for attackers to crack it, effectively defends against unauthorized access and device cloning, and ensures the security of the production system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120934752A_ABST
    Figure CN120934752A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides a device authentication method, an electronic device, a storage medium and a program product, and the method comprises the steps: receiving a first authorization key sent by a to-be-verified device, carrying out the analysis processing of the first authorization key through employing a preset key analysis algorithm, and obtaining a second authorization key corresponding to the to-be-verified device; and comparing the second authorization key with a preset equipment key, and judging whether to add the to-be-verified equipment into the production system according to a comparison result. According to the embodiment of the invention, the timestamp, the equipment physical address information and the equipment information, such as a network number and a CPU number, are combined with a HASH function to be applied to the generation of the unique equipment fingerprint of the equipment; according to the method and the device, the key calculation is carried out through the Hash operation, the authorization key is generated, and the authorization key is compared with the preset device key, so that whether the device can be added into the production system is judged, the cracking cost of an attacker is high, and the accuracy of device authentication and recognition is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of security technology, and more specifically, to a device authentication method, electronic device, storage medium, and program product. Background Technology

[0002] Industrial control systems (ICS), as the core of critical infrastructure, are directly related to production stability and social operational safety. Programmable Logic Controllers (PLCs), serving as the "brain" of industrial automation, have long faced threats such as unauthorized access, program tampering, and device cloning. Current technologies encrypt the hardware identification data of PLCs for authentication; however, relying on a single characteristic is not accurate enough for reliable authentication security. Therefore, improving the accuracy of PLC security authentication is a pressing issue that needs to be addressed. Summary of the Invention

[0003] The purpose of some embodiments of this application is to provide a device authentication method, electronic device, storage medium, and program product. Through the technical solutions of the embodiments of this application, a first authorization key sent by a device to be verified is received. This first authorization key is obtained by the device to be verified using a preset key generation algorithm, which processes the physical address information, timestamp, and device information of the device to be verified. A preset key parsing algorithm is used to parse the first authorization key to obtain a second authorization key corresponding to the device to be verified. The preset key parsing algorithm corresponds to the preset key generation algorithm. The second authorization key is compared with a preset device key, and based on the comparison result, it is determined whether the device to be verified should be added to the production system. In this application embodiment, the timestamp, device physical address information, and device information, such as network ID and CPU ID, are combined with a HASH function to generate a unique device fingerprint. A key calculation is performed using hash operations to generate an authorization key. The authorization key is compared with the preset device key to determine whether the device can be added to the production system. This makes it costly for attackers to crack the system and improves the accuracy of device authentication and identification.

[0004] Firstly, some embodiments of this application provide a device authentication method, including: Receive a first authorization key sent by the device to be verified, wherein the first authorization key is obtained by the device to be verified by processing the physical address information, timestamp and device information of the device to be verified using a preset key generation algorithm; The first authorization key is parsed using a preset key parsing algorithm to obtain a second authorization key corresponding to the device to be verified; wherein the preset key parsing algorithm corresponds to the preset key generation algorithm; The second authorization key and the preset device key are compared, and based on the comparison result, it is determined whether to add the device to be verified to the production system.

[0005] Some embodiments of this application combine timestamps, device physical address information, and device information, such as network ID and CPU ID, with a hash function to generate a unique device fingerprint. A key is then calculated using hash operations to generate an authorization key. The authorization key is compared with a preset device key to determine whether the device can be added to the production system. This makes it costly for attackers to crack the system and improves the accuracy of device authentication and identification.

[0006] Optionally, before receiving the first authorization key sent by the device to be verified, the method further includes: Receive registration requests from multiple devices, wherein the registration request includes at least device physical address information, device information and timestamp, and the device information includes at least network number, processing unit number, input / output port number of the target module and station number of the target module; Generate a preset device key using the device's physical address information and the timestamp; Based on the correspondence between the preset device key and the device information, a preset device registry corresponding to the device is determined.

[0007] In some embodiments of this application, in the initial environment, multiple PLC devices send registration requests to the target server, generate a private key based on the physical address and timestamp of the PLC device using a preset private key generation algorithm, and send the private key, along with network number, CPU number, target module I / O number, and target module station number information, to the target server for storage in the device registry.

[0008] Optionally, generating a preset device key from the device physical address information and the timestamp includes: Convert the device physical address information into decimal physical address information; Perform a hash operation on the decimal physical address information to obtain a hash value corresponding to the device physical address information; The preset device key is generated based on the hash value and the timestamp.

[0009] Some embodiments of this application obtain the physical address information of the PLC device, i.e. the device to be verified, convert the physical address information into a decimal integer, perform a hash function operation to obtain a hash value, and then add a timestamp to the hash value to generate a private key, i.e., a preset device key.

[0010] Optionally, the step of parsing the first authorization key using a preset key parsing algorithm to obtain a second authorization key corresponding to the device to be verified includes: The first authorization key is converted to binary to obtain binary data; Based on the pre-set identifier position, determine the device information and first key data corresponding to the binary data; The second authorization key is obtained by identifying the timestamp and authorization key in the intermediate key data.

[0011] In some embodiments of this application, a preset key parsing algorithm is used to parse the first authorization key, wherein the preset key parsing algorithm corresponds to the preset key generation algorithm to obtain a second authorization key, which is used to compare with a preset device key. Optionally, the method further includes: Obtain the target device information of the device to be verified; Based on the target device information, a matching process is performed in the preset device registry. If multiple sets of target device information exist in the preset device registry, the device to be verified is determined to be an abnormal device.

[0012] In some embodiments of this application, after determining that the second authorization key and the preset device key match successfully, it is indicated that the device to be verified is a quasi-access device. It is also necessary to determine whether the device to be verified is secure in the production environment. The parsed network number and other information are then matched with the preset device registry. It is also determined whether the number of connections of the device in the production environment is greater than a preset value. If it is greater than the preset value, it indicates that there is a cloned device, that is, the device to be verified is an abnormal device. If the attacker only clones the physical address and lacks the PLC-specific parameters, the authentication will fail, which can effectively defend against the identification forgery attack.

[0013] Optionally, the first authorization key is obtained in the following manner: The physical address information of the device to be verified is converted to decimal to obtain the decimal physical address information; Perform a hash operation on the decimal physical address information to obtain a hexadecimal hash value; The second key data is determined based on the hexadecimal hash value and timestamp; The second key data and the device information are subjected to binary conversion and shifting to obtain the first authorization key.

[0014] Some embodiments of this application combine PLC device parameters such as timestamp, network number, and CPU number with a HASH function to generate a unique device fingerprint. Key calculation using HASH makes it very costly for attackers to crack the fingerprint.

[0015] Optionally, the method further includes: In the event of a change in the preset device registry, identity re-authentication information is broadcast so that each device receives the identity re-authentication information update timestamp. Receive the fourth key data returned by each device and re-authenticate.

[0016] In some embodiments of this application, when the device registry changes in the production environment, a new PLC device applies to join the production environment, or a PLC device needs to be updated, the target server broadcasts an identity re-authentication message in the production environment network after the device registry of the target server changes. All PLC devices will simultaneously receive the message to update the timestamp and time synchronization request.

[0017] Optionally, the method further includes: If the number of device authentication failures exceeds a preset value, the device is determined to be an abnormal device.

[0018] In some embodiments of this application, if a PLC device is identified as an abnormal device after three failed security authentications, the connection to other host computers or PLCs will be forcibly disconnected.

[0019] Optionally, the method further includes: The timestamp is updated at preset time intervals.

[0020] In some embodiments of this application, the timestamp is updated every preset time period. In this way, the target server will broadcast a message to all PLC devices in the production environment, forcing the PLC devices to report the authorization key using the new timestamp. This operation can prevent replay attacks: the key expires every preset time period, and the intercepted data cannot be reused.

[0021] Secondly, some embodiments of this application provide a device authentication apparatus, including: The receiving module is used to receive a first authorization key sent by the device to be verified, wherein the first authorization key is obtained by the device to be verified by processing the physical address information, timestamp and device information of the device to be verified using a preset key generation algorithm; The parsing module is used to parse the first authorization key using a preset key parsing algorithm to obtain a second authorization key corresponding to the device to be verified; wherein the preset key parsing algorithm corresponds to the preset key generation algorithm; The comparison module is used to compare the second authorization key and the preset device key, and determine whether to add the device to be verified to the production system based on the comparison result.

[0022] Some embodiments of this application combine timestamps, device physical address information, and device information, such as network ID and CPU ID, with a hash function to generate a unique device fingerprint. A key is then calculated using hash operations to generate an authorization key. The authorization key is compared with a preset device key to determine whether the device can be added to the production system. This makes it costly for attackers to crack the system and improves the accuracy of device authentication and identification.

[0023] Optionally, the receiving module is further configured to: Receive registration requests from multiple devices, wherein the registration request includes at least device physical address information, device information and timestamp, and the device information includes at least network number, processing unit number, input / output port number of the target module and station number of the target module; Generate a preset device key using the device's physical address information and the timestamp; Based on the correspondence between the preset device key and the device information, a preset device registry corresponding to the device is determined.

[0024] In some embodiments of this application, in the initial environment, multiple PLC devices send registration requests to the target server, generate a private key based on the physical address and timestamp of the PLC device using a preset private key generation algorithm, and send the private key, along with network number, CPU number, target module I / O number, and target module station number information, to the target server for storage in the device registry.

[0025] Optionally, the receiving module is further configured to: Convert the device physical address information into decimal physical address information; Perform a hash operation on the decimal physical address information to obtain a hash value corresponding to the device physical address information; The preset device key is generated based on the hash value and the timestamp.

[0026] Some embodiments of this application obtain the physical address information of the PLC device, i.e. the device to be verified, convert the physical address information into a decimal integer, perform a hash function operation to obtain a hash value, and then add a timestamp to the hash value to generate a private key, i.e., a preset device key.

[0027] Optionally, the parsing module is used for: The first authorization key is converted to binary to obtain binary data; Based on the pre-set identifier position, determine the device information and first key data corresponding to the binary data; The second authorization key is obtained by identifying the timestamp and authorization key in the intermediate key data.

[0028] In some embodiments of this application, a preset key parsing algorithm is used to parse the first authorization key, wherein the preset key parsing algorithm corresponds to the preset key generation algorithm to obtain a second authorization key, which is used to compare with a preset device key. Optionally, the receiving module is further configured to: Obtain the target device information of the device to be verified; Based on the target device information, a matching process is performed in the preset device registry. If multiple sets of target device information exist in the preset device registry, the device to be verified is determined to be an abnormal device.

[0029] In some embodiments of this application, after determining that the second authorization key and the preset device key match successfully, it is indicated that the device to be verified is a quasi-access device. It is also necessary to determine whether the device to be verified is secure in the production environment. The parsed network number and other information are then matched with the preset device registry. It is also determined whether the number of connections of the device in the production environment is greater than a preset value. If it is greater than the preset value, it indicates that there is a cloned device, that is, the device to be verified is an abnormal device. If the attacker only clones the physical address and lacks the PLC-specific parameters, the authentication will fail, which can effectively defend against the identification forgery attack.

[0030] Optionally, the first authorization key is obtained in the following manner: The physical address information of the device to be verified is converted to decimal to obtain the decimal physical address information; Perform a hash operation on the decimal physical address information to obtain a hexadecimal hash value; The second key data is determined based on the hexadecimal hash value and timestamp; The second key data and the device information are subjected to binary conversion and shifting to obtain the first authorization key.

[0031] Some embodiments of this application combine PLC device parameters such as timestamp, network number, and CPU number with a HASH function to generate a unique device fingerprint. Key calculation using HASH makes it very costly for attackers to crack the fingerprint.

[0032] Optionally, the receiving module is further configured to: In the event of a change in the preset device registry, identity re-authentication information is broadcast so that each device receives the identity re-authentication information update timestamp. Receive the fourth key data returned by each device and re-authenticate.

[0033] In some embodiments of this application, when the device registry changes in the production environment, a new PLC device applies to join the production environment, or a PLC device needs to be updated, the target server broadcasts an identity re-authentication message in the production environment network after the device registry of the target server changes. All PLC devices will simultaneously receive the message to update the timestamp and time synchronization request.

[0034] Optionally, the receiving module is further configured to: If the number of device authentication failures exceeds a preset value, the device is determined to be an abnormal device.

[0035] In some embodiments of this application, if a PLC device is identified as an abnormal device after three failed security authentications, the connection to other host computers or PLCs will be forcibly disconnected.

[0036] Optionally, the receiving module is further configured to: The timestamp is updated at preset time intervals.

[0037] In some embodiments of this application, the timestamp is updated every preset time period. In this way, the target server will broadcast a message to all PLC devices in the production environment, forcing the PLC devices to report the authorization key using the new timestamp. This operation can prevent replay attacks: the key expires every preset time period, and the intercepted data cannot be reused.

[0038] Thirdly, some embodiments of this application provide an electronic device including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, can implement the device authentication method as described in any embodiment of the first aspect.

[0039] Fourthly, some embodiments of this application provide a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, can implement the device authentication method as described in any embodiment of the first aspect.

[0040] Fifthly, some embodiments of this application provide a computer program product, the computer program product including a computer program, wherein the computer program, when executed by a processor, can implement the device authentication method as described in any embodiment of the first aspect. Attached Figure Description

[0041] To more clearly illustrate the technical solutions of some embodiments of this application, the accompanying drawings used in some embodiments of this application will be briefly described below. It should be understood that the following drawings only show some embodiments of this application and should not be regarded as a limitation of the scope. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.

[0042] Figure 1 A schematic flowchart illustrating a device authentication method provided in an embodiment of this application; Figure 2 This is a schematic diagram of the device authentication system provided in the embodiments of this application; Figure 3 A flowchart illustrating yet another device authentication method provided in this application embodiment; Figure 4 This is a schematic diagram of the structure of a device authentication apparatus provided in an embodiment of this application; Figure 5 This is a schematic diagram of an electronic device provided in an embodiment of this application. Detailed Implementation

[0043] The technical solutions of some embodiments of this application will now be described with reference to the accompanying drawings.

[0044] It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures. Furthermore, in the description of this application, terms such as "first," "second," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0045] Stability and social operational safety. As the "brain" of industrial automation, the Programmable Logic Controller (PLC) has long faced threats such as unauthorized access, program tampering, and equipment cloning. In existing technologies, hardware identification data of programmable logic controllers (PLCs) is encrypted to authenticate them. However, a single feature is not accurate enough for secure authentication. Therefore, improving the accuracy of PLC security authentication is an urgent problem to be solved. In view of this, some embodiments of this application provide a device authentication method. This method includes receiving a first authorization key sent by a device to be verified. The first authorization key is obtained by the device to be verified by processing its physical address information, timestamp, and device information using a preset key generation algorithm. A preset key parsing algorithm is used to parse the first authorization key to obtain a second authorization key corresponding to the device to be verified. The preset key parsing algorithm corresponds to the preset key generation algorithm. The second authorization key is compared with a preset device key, and based on the comparison result, it is determined whether to add the device to the production system. In this application embodiment, the timestamp, device physical address information, and device information, such as network ID and CPU ID, are combined with a hash function to generate a unique device fingerprint. A key is calculated using hash operations to generate an authorization key. The authorization key is compared with the preset device key to determine whether the device can be added to the production system. This makes it costly for attackers to crack the system and improves the accuracy of device authentication and identification.

[0046] like Figure 1 As shown, an embodiment of this application provides a device authentication method, the method comprising: S101. Receive the first authorization key sent by the device to be verified, wherein the first authorization key is obtained by the device to be verified by processing the physical address information, timestamp and device information of the device to be verified using a preset key generation algorithm; like Figure 2 As shown, the embodiments of this application are applied to a device authentication system, which includes at least a target server and multiple devices to be verified, and the devices to be verified may be PLC devices.

[0047] When device authentication is required, the device to be authenticated uses a preset key generation algorithm to encrypt its physical address information, device information, and timestamp to obtain a first authorization key. The device information includes at least the network number, CPU number, target module I / O number, and target module station number. The timestamp can be a timestamp at preset time intervals, such as every 24 hours, every 12 hours, or every 6 hours, etc., and is not specifically limited in this application.

[0048] The target server receives the first authorization key sent by the device to be verified.

[0049] S102. The first authorization key is parsed using a preset key parsing algorithm to obtain a second authorization key corresponding to the device to be verified; wherein the preset key parsing algorithm corresponds to the preset key generation algorithm; Specifically, the target server stores a preset key parsing algorithm, which corresponds to the preset key generation algorithm. The preset key parsing algorithm is the reverse algorithm of the preset key generation algorithm. The target server uses the preset key parsing algorithm to parse the first authorization key to obtain the second authorization key corresponding to the device to be verified.

[0050] S103. Compare the second authorization key and the preset device key, and determine whether to add the device to be verified to the production system based on the comparison result.

[0051] Specifically, the target server stores the preset device keys for each device in advance. After obtaining the second authorization key, the second authorization key and the preset device key are compared to determine whether they are the same. If they are the same, the device to be verified is determined to be a qualified device to be added, that is, it can be added to the production system. If they are different, the device to be verified is determined to be an abnormal device.

[0052] For example, the physical address, timestamp, and device information of the PLC device (the device to be verified) that needs to be authorized are obtained. Then, the PLC device information is used to generate a first authorization key through a preset authorization key generation algorithm. The timestamp can be the early morning of the day before the current day (to ensure that the time difference with the private key is ≥24 hours) to prevent attackers from intercepting the key on the same day and reusing it indefinitely. The first authorization key is then sent to the target server.

[0053] The target server parses the first authorization key using a preset authorization key parsing algorithm to obtain the comparison key, which is the second authorization key (the parsing key is the reverse algorithm of the encryption key). The comparison key is then matched with the preset device key in the preset device registry on the target server. If the match fails, it means that the requested PLC device is an abnormal device and is not allowed to participate in the data communication of the current production environment; if the match succeeds, it means that the requested PLC device is a quasi-access device.

[0054] Some embodiments of this application combine timestamps, device physical address information, and device information, such as network ID and CPU ID, with a hash function to generate a unique device fingerprint. A key is then calculated using hash operations to generate an authorization key. The authorization key is compared with a preset device key to determine whether the device can be added to the production system. This makes it costly for attackers to crack the system and improves the accuracy of device authentication and identification.

[0055] Another embodiment of this application further supplements the device authentication method provided in the above embodiments.

[0056] Optionally, before receiving the first authorization key sent by the device to be verified, the method further includes: Receive registration requests from multiple devices. The registration request includes at least the device physical address information, device information and timestamp. The device information includes at least the network number, processing unit number, input / output port number of the target module and station number of the target module. Generate a preset device key using the device's physical address information and timestamp; Based on the correspondence between the preset device key and device information, determine the preset device registry corresponding to the device.

[0057] Specifically, in this embodiment of the application, the target server uploads the device's parameter information to the target server when the initial environment is secure and isolated from the external network, i.e., in the case of an intranet.

[0058] In the initial environment, multiple PLC devices send registration requests to the target server. Based on the physical address and timestamp of the PLC device, a private key is generated using a preset private key generation algorithm. The private key, along with the network number, CPU number, target module I / O number, and target module station number, are sent to the target server and stored in a preset device registry. The target server then uses a preset private key parsing algorithm to parse out the physical address and timestamp information.

[0059] The following table shows an example of the contents of the default device registry: Table 1

[0060] In some embodiments of this application, in the initial environment, multiple PLC devices send registration requests to the target server, generate a private key based on the physical address and timestamp of the PLC device using a preset private key generation algorithm, and send the private key, along with network number, CPU number, target module I / O number, and target module station number information, to the target server for storage in the device registry.

[0061] Optionally, a preset device key is generated from the device's physical address information and timestamp, including: Convert the device's physical address information into decimal physical address information; Perform a hash operation on the decimal physical address information to obtain a hash value corresponding to the device's physical address information; Generate a preset device key based on the hash value and timestamp.

[0062] The private key generation algorithm is as follows: First, the device obtains its own physical address information, such as the physical address information of a PLC device; after converting the physical address information into a decimal integer, a hash function is performed to obtain the hash value, and a timestamp is added to generate a preset device key. For example, the timestamp of the current date 00:00:00 AM is added to the right side of the hash value to generate a private key, i.e., the preset device key.

[0063] Some embodiments of this application obtain the physical address information of the PLC device, i.e. the device to be verified, convert the physical address information into a decimal integer, perform a hash function operation to obtain a hash value, and then add a timestamp to the hash value to generate a private key, i.e., a preset device key.

[0064] Optionally, a preset key parsing algorithm is used to parse the first authorization key to obtain a second authorization key corresponding to the device to be verified, including: The first authorization key is converted to binary to obtain binary data; Based on the pre-set identifier position, determine the device information and first key data corresponding to the binary data; The second authorization key is obtained by identifying the timestamp and authorization key in the intermediate key data.

[0065] In some embodiments of this application, a preset key parsing algorithm is used to parse the first authorization key, wherein the preset key parsing algorithm corresponds to the preset key generation algorithm to obtain a second authorization key, which is used to compare with a preset device key. Optionally, the method further includes: Obtain the target device information of the device to be verified; Based on the target device information, a match is made in the preset device registry. If multiple target device information exists in the preset device registry, the device to be verified is determined to be an abnormal device.

[0066] Specifically, the target server matches the target device information with the preset device registry. If the match is successful, it indicates that the requested PLC device is a quasi-access device. Then, it determines whether the PLC device is secure in the production environment. The network ID and other information from the parsed target device information are matched with the preset device registry. If the number of connections to the device in the production environment is ≥2, it indicates the existence of a cloned device, which may pose a potential risk. All PLC devices matching this device information will have their existing data connections forcibly disconnected, and operators will be warned to remove this PLC device from the production environment. If the device is functioning correctly, network connections and data operations are allowed in the production environment.

[0067] In some embodiments of this application, after determining that the second authorization key and the preset device key match successfully, it is indicated that the device to be verified is a quasi-access device. It is also necessary to determine whether the device to be verified is secure in the production environment. The parsed network number and other information are then matched with the preset device registry. It is also determined whether the number of connections of the device in the production environment is greater than a preset value. If it is greater than the preset value, it indicates that there is a cloned device, that is, the device to be verified is an abnormal device. If the attacker only clones the physical address and lacks the PLC-specific parameters, the authentication will fail, which can effectively defend against the identification forgery attack.

[0068] Optionally, the first authorization key is obtained in the following way: The physical address information of the device to be verified is converted to decimal to obtain the decimal physical address information; Perform a hash operation on the decimal physical address information to obtain a hexadecimal hash value; The second key data is determined based on the hexadecimal hash value and timestamp; The second key data and device information are converted into binary and shifted to obtain the first authorization key.

[0069] Specifically, the device to be verified obtains the PLC's network number, CPU number, target module I / O number, target module station number, and physical address; processes the physical address data, removes the colon separator, converts the data into decimal data, and performs SHA-256 HASH operation to obtain the hexadecimal hash value.

[0070] Shift the hash value 32 bits to the left and append the timestamp data to the right side of the hash value to generate key A, which is the second key data. Then, convert key A and the device information (PLC station number, network number, CPU number, target module I / O number, etc.) into binary. Then, shift the binary data of the requested target module station number (8 bits), network number (8 bits), CPU number (8 bits), and requested target module I / O number (16 bits) to the right side of key A in sequence. Finally, convert the shifted data into hexadecimal to generate the first authorization key.

[0071] Some embodiments of this application combine PLC device parameters such as timestamp, network number, and CPU number with a HASH function to generate a unique device fingerprint. Key calculation using HASH makes it very costly for attackers to crack the fingerprint.

[0072] Optionally, the method further includes: If the default device registry changes, broadcast the identity re-authentication information so that each device receives the identity re-authentication information update timestamp; Receive the fourth key data returned by each device and re-authenticate.

[0073] In some embodiments of this application, when the device registry changes in the production environment, a new PLC device applies to join the production environment, or a PLC device needs to be updated, the target server broadcasts an identity re-authentication message in the production environment network after the device registry of the target server changes. All PLC devices will simultaneously receive the message to update the timestamp and time synchronization request.

[0074] Optionally, the method further includes: If the number of device authentication failures exceeds the preset value, the device is identified as an abnormal device.

[0075] Specifically, if the default device registry in the production environment changes, a new PLC device requests to join the production environment, or a PLC device needs to be updated, the target server broadcasts a re-authentication message in the production network after the device registry changes. All PLC devices simultaneously receive this message, along with an update timestamp and time synchronization request. Subsequently, all PLC devices synchronize their time with the target server. If the times do not match, the PLC time is updated to the target server time. All PLC devices resend the newly generated private key to the server and re-authenticate. If any PLC device is identified as an abnormal device after three failed authentication attempts, its connection to other host computers or PLCs will be forcibly disconnected.

[0076] In some embodiments of this application, if a PLC device is identified as an abnormal device after three failed security authentications, the connection to other host computers or PLCs will be forcibly disconnected.

[0077] Optionally, the method further includes: The timestamp is updated at preset time intervals.

[0078] In some embodiments of this application, the timestamp is updated every preset time period. In this way, the target server will broadcast a message to all PLC devices in the production environment, forcing the PLC devices to report the authorization key using the new timestamp. This operation can prevent replay attacks: the key expires every preset time period, and the intercepted data cannot be reused.

[0079] This application provides a secure Mitsubishi PLC device authentication method. Through multiple authentication methods, it performs secure identity authentication on PLC devices in the production environment and issues alarms for abnormal connections that pose potential hazards, aiming to eliminate abnormal factors in the production environment.

[0080] like Figure 3 As shown, the present invention provides a security authentication method for Mitsubishi PLC equipment, comprising the following steps: In the initial environment (before production and isolation from the external network), multiple PLC devices send registration requests to the target server, generate a private key for the current PLC device based on the physical address identifier and timestamp of the PLC device, and send the private key and device information to the target server for storage; In a formal production environment, the PLC device generates an authorization key according to a preset key generation algorithm. After the authorization key is sent to the target server, the target server parses the authorization key according to a preset key parsing algorithm to obtain the PLC device key. The PLC device key is then matched with the private key pre-stored in the target server, and corresponding measures are taken based on the matching result.

[0081] In this embodiment, PLC device parameters such as timestamps, network IDs, and CPU IDs are combined with a HASH function to generate a unique device fingerprint. Key calculation using HASH makes it extremely costly for attackers to crack. Compared to a single key binding scheme, where an attacker only clones the physical address but lacks the PLC-specific parameters, authentication will fail, effectively preventing identifier spoofing attacks. Dynamic factor injection is implemented: by using non-continuous timestamps to create keys, the "one-time use" nature of the key is achieved, preventing unauthorized personnel from reusing the device for extended periods after hijacking it, thus avoiding significant damage to the production environment. A custom key algorithm is used, where PLC device control parameters are concatenated to the low-order bits of the key in a fixed order. Even if an attacker obtains partial parameters, they cannot reconstruct a valid authorization key because they cannot crack the shift structure.

[0082] This application embodiment constructs device fingerprints by combining multiple factors, rendering hijacking / cloning attacks ineffective due to missing information or timeliness differences. Through a two-stage model (initial registration + production authentication) and a daily automatic timeliness mechanism, it eliminates replay attack windows, reduces operational load, and avoids unnecessary resource consumption in the network environment caused by frequent security authentication.

[0083] It should be noted that each of the implementable methods in this embodiment can be implemented individually or in any combination without conflict. This application does not limit this.

[0084] Another embodiment of this application provides a device authentication apparatus for performing the device authentication method provided in the above embodiments.

[0085] like Figure 4 The diagram shown is a structural schematic of a device authentication apparatus provided in an embodiment of this application. The device authentication apparatus includes a receiving module 401, a parsing module 402, and a comparison module 403, wherein: The receiving module 401 is used to receive the first authorization key sent by the device to be verified, wherein the first authorization key is obtained by the device to be verified by processing the physical address information, timestamp and device information of the device to be verified using a preset key generation algorithm; The parsing module 402 is used to parse the first authorization key using a preset key parsing algorithm to obtain a second authorization key corresponding to the device to be verified; wherein, the preset key parsing algorithm corresponds to the preset key generation algorithm; The comparison module 403 is used to compare the second authorization key and the preset device key, and based on the comparison result, to determine whether to add the device to be verified to the production system.

[0086] Regarding the apparatus in this embodiment, the specific manner in which each module performs its operation has been described in detail in the embodiments related to the method, and will not be elaborated upon here.

[0087] Some embodiments of this application combine timestamps, device physical address information, and device information, such as network ID and CPU ID, with a hash function to generate a unique device fingerprint. A key is then calculated using hash operations to generate an authorization key. The authorization key is compared with a preset device key to determine whether the device can be added to the production system. This makes it costly for attackers to crack the system and improves the accuracy of device authentication and identification.

[0088] Another embodiment of this application further supplements the description of the device authentication apparatus provided in the above embodiments.

[0089] Optionally, the receiving module is also used for: Receive registration requests from multiple devices. The registration request includes at least the device physical address information, device information and timestamp. The device information includes at least the network number, processing unit number, input / output port number of the target module and station number of the target module. Generate a preset device key using the device's physical address information and timestamp; Based on the correspondence between the preset device key and device information, determine the preset device registry corresponding to the device.

[0090] In some embodiments of this application, in the initial environment, multiple PLC devices send registration requests to the target server, generate a private key based on the physical address and timestamp of the PLC device using a preset private key generation algorithm, and send the private key, along with network number, CPU number, target module I / O number, and target module station number information, to the target server for storage in the device registry.

[0091] Optionally, the receiving module is also used for: Convert the device's physical address information into decimal physical address information; Perform a hash operation on the decimal physical address information to obtain a hash value corresponding to the device's physical address information; Generate a preset device key based on the hash value and timestamp.

[0092] Some embodiments of this application obtain the physical address information of the PLC device, i.e. the device to be verified, convert the physical address information into a decimal integer, perform a hash function operation to obtain a hash value, and then add a timestamp to the hash value to generate a private key, i.e., a preset device key.

[0093] Optionally, the parsing module is used for: The first authorization key is converted to binary to obtain binary data; Based on the pre-set identifier position, determine the device information and first key data corresponding to the binary data; The second authorization key is obtained by identifying the timestamp and authorization key in the intermediate key data.

[0094] In some embodiments of this application, a preset key parsing algorithm is used to parse the first authorization key, wherein the preset key parsing algorithm corresponds to the preset key generation algorithm to obtain a second authorization key, which is used to compare with a preset device key. Optionally, the receiving module is also used for: Obtain the target device information of the device to be verified; Based on the target device information, a match is made in the preset device registry. If multiple target device information exists in the preset device registry, the device to be verified is determined to be an abnormal device.

[0095] In some embodiments of this application, after determining that the second authorization key and the preset device key match successfully, it is indicated that the device to be verified is a quasi-access device. It is also necessary to determine whether the device to be verified is secure in the production environment. The parsed network number and other information are then matched with the preset device registry. It is also determined whether the number of connections of the device in the production environment is greater than a preset value. If it is greater than the preset value, it indicates that there is a cloned device, that is, the device to be verified is an abnormal device. If the attacker only clones the physical address and lacks the PLC-specific parameters, the authentication will fail, which can effectively defend against the identification forgery attack.

[0096] Optionally, the first authorization key is obtained in the following way: The physical address information of the device to be verified is converted to decimal to obtain the decimal physical address information; Perform a hash operation on the decimal physical address information to obtain a hexadecimal hash value; The second key data is determined based on the hexadecimal hash value and timestamp; The second key data and device information are converted into binary and shifted to obtain the first authorization key.

[0097] Some embodiments of this application combine PLC device parameters such as timestamp, network number, and CPU number with a HASH function to generate a unique device fingerprint. Key calculation using HASH makes it very costly for attackers to crack the fingerprint.

[0098] Optionally, the receiving module is also used for: If the default device registry changes, broadcast the identity re-authentication information so that each device receives the identity re-authentication information update timestamp; Receive the fourth key data returned by each device and re-authenticate.

[0099] In some embodiments of this application, when the device registry changes in the production environment, a new PLC device applies to join the production environment, or a PLC device needs to be updated, the target server broadcasts an identity re-authentication message in the production environment network after the device registry of the target server changes. All PLC devices will simultaneously receive the message to update the timestamp and time synchronization request.

[0100] Optionally, the receiving module is also used for: If the number of device authentication failures exceeds the preset value, the device is identified as an abnormal device.

[0101] In some embodiments of this application, if a PLC device is identified as an abnormal device after three failed security authentications, the connection to other host computers or PLCs will be forcibly disconnected.

[0102] Optionally, the receiving module is also used for: The timestamp is updated at preset time intervals.

[0103] In some embodiments of this application, the timestamp is updated every preset time period. In this way, the target server will broadcast a message to all PLC devices in the production environment, forcing the PLC devices to report the authorization key using the new timestamp. This operation can prevent replay attacks: the key expires every preset time period, and the intercepted data cannot be reused.

[0104] Regarding the apparatus in this embodiment, the specific manner in which each module performs its operations has been described in detail in the embodiments related to the method, and will not be elaborated upon here.

[0105] It should be noted that each of the implementable methods in this embodiment can be implemented individually or in any combination without conflict. This application does not limit this.

[0106] This application also provides a computer-readable storage medium storing a computer program thereon, which, when executed by a processor, can perform the operation of any of the methods corresponding to the device authentication methods provided in the above embodiments.

[0107] This application also provides a computer program product, which includes a computer program, wherein when the computer program is executed by a processor, it can implement the operation of any of the methods corresponding to the device authentication methods provided in the above embodiments.

[0108] like Figure 5 As shown, some embodiments of this application provide an electronic device 500, which includes: a memory 510, a processor 520, and a computer program stored in the memory 510 and executable on the processor 520. When the processor 520 reads the program from the memory 510 via a bus 530 and executes the program, it can implement the method of any embodiment of the device authentication method described above.

[0109] Processor 520 can process digital signals and can include various computing architectures. For example, it can be a complex instruction set computer architecture, a reduced instruction set computer architecture, or an architecture that implements multiple instruction set combinations. In some examples, processor 520 can be a microprocessor.

[0110] The memory 510 can be used to store instructions executed by the processor 520 or data related to the execution of instructions. These instructions and / or data may include code for implementing some or all of the functions of one or more modules described in the embodiments of this application. The processor 520 of this disclosure embodiment can be used to execute the instructions in the memory 510 to implement the methods shown above. The memory 510 includes dynamic random access memory, static random access memory, flash memory, optical memory, or other memories well known to those skilled in the art.

[0111] The above are merely embodiments of this application and are not intended to limit the scope of protection of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of protection of this application. It should be noted that similar reference numerals and letters in the following figures indicate similar items; therefore, once an item is defined in one figure, it does not need to be further defined and explained in subsequent figures.

[0112] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

[0113] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.

Claims

1. A device authentication method, characterized in that, The method includes: Receive a first authorization key sent by the device to be verified, wherein the first authorization key is obtained by the device to be verified by processing the physical address information, timestamp and device information of the device to be verified using a preset key generation algorithm; The first authorization key is parsed using a preset key parsing algorithm to obtain a second authorization key corresponding to the device to be verified; wherein the preset key parsing algorithm corresponds to the preset key generation algorithm; The second authorization key and the preset device key are compared, and based on the comparison result, it is determined whether to add the device to be verified to the production system.

2. The device authentication method according to claim 1, characterized in that, Before receiving the first authorization key sent by the device to be verified, the method further includes: Receive registration requests from multiple devices, wherein the registration request includes at least device physical address information, device information and timestamp, and the device information includes at least network number, processing unit number, input / output port number of the target module and station number of the target module; Generate a preset device key using the device's physical address information and the timestamp; Based on the correspondence between the preset device key and the device information, a preset device registry corresponding to the device is determined.

3. The device authentication method according to claim 2, characterized in that, The step of generating a preset device key from the device physical address information and the timestamp includes: Convert the device physical address information into decimal physical address information; Perform a hash operation on the decimal physical address information to obtain a hash value corresponding to the device physical address information; The preset device key is generated based on the hash value and the timestamp.

4. The device authentication method according to claim 2, characterized in that, The step of parsing the first authorization key using a preset key parsing algorithm to obtain the second authorization key corresponding to the device to be verified includes: The first authorization key is converted to binary to obtain binary data; Based on the pre-set identifier position, determine the device information and first key data corresponding to the binary data; The second authorization key is obtained by identifying the timestamp and authorization key in the intermediate key data.

5. The device authentication method according to claim 2, characterized in that, The method further includes: Obtain the target device information of the device to be verified; Based on the target device information, a matching process is performed in the preset device registry. If multiple sets of target device information exist in the preset device registry, the device to be verified is determined to be an abnormal device.

6. The device authentication method according to claim 1, characterized in that, The first authorization key is obtained in the following way: The physical address information of the device to be verified is converted to decimal to obtain the decimal physical address information; Perform a hash operation on the decimal physical address information to obtain a hexadecimal hash value; The second key data is determined based on the hexadecimal hash value and timestamp; The second key data and the device information are subjected to binary conversion and shifting to obtain the first authorization key.

7. The device authentication method according to claim 2, characterized in that, The method further includes: In the event of a change in the preset device registry, identity re-authentication information is broadcast so that each device receives the identity re-authentication information update timestamp. Receive the fourth key data returned by each device and re-authenticate.

8. The device authentication method according to claim 7, characterized in that, The method further includes: If the number of device authentication failures exceeds a preset value, the device is determined to be an abnormal device.

9. The device authentication method according to claim 1, characterized in that, The method further includes: The timestamp is updated at preset time intervals.

10. An electronic device, characterized in that, The device includes a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, implements the device authentication method according to any one of claims 1-9.

11. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, characterized in that, when the program is executed by a processor, it can implement the device authentication method according to any one of claims 1-9.

12. A computer program product, said computer program product comprising a computer program, wherein, When the computer program is executed by a processor, it can implement the device authentication method according to any one of claims 1-9.