Internet of Things security authentication communication method and system

By combining dynamic credential generation and hash chain technology with multi-dimensional anomaly detection, the problems of rigid authentication, coarse verification, and delayed response in IoT security authentication communication are solved, realizing dynamic authentication, timely detection, and full-link security defense.

CN120934810AInactive Publication Date: 2025-11-11SHAANXI SCI TECH UNIV
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511089645.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-08-05
Publication Date
2025-11-11
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Existing IoT security authentication communication methods suffer from rigid authentication mechanisms, coarse-grained integrity verification, single-dimensional anomaly detection, and delayed risk response, resulting in insufficient authentication flexibility, untimely data tampering detection, and a high false alarm rate.

Method used

By integrating device hardware identifiers, communication protocol versions, and computing power parameters to generate dynamic credentials, using hash chain technology for segmented verification, constructing communication behavior feature vectors and performing multi-dimensional anomaly detection, and combining a weighted evaluation model and dynamic defense mechanism, device authentication, data integrity verification, and behavior monitoring are achieved.

Benefits of technology

It achieves dynamic authentication based on real-time device characteristics, timely detection of data tampering, reduction of man-in-the-middle attack interference, improvement of anomaly detection accuracy, and forms a full-link security framework to provide proactive defense capabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120934810A_ABST
    Figure CN120934810A_ABST
Patent Text Reader

Abstract

The invention discloses an Internet of Things security authentication communication method and system, and belongs to the field of Internet of Things security, and the method comprises the following steps: integrating a hardware identifier, a communication protocol version and a computing power parameter of a target device to generate a device feature vector; processing the device feature vector by adopting an encryption algorithm to generate a dynamic voucher, and completing device authentication based on a device authentication rule to obtain an authentication device list; generating a segmented check code for the communication data stream of the authentication equipment by using a hash chain technology, and verifying the integrity of the data stream according to the check code; and extracting communication frequency, packet size and time interval parameters according to an integrity verification result, constructing a communication behavior feature vector, calculating a deviation degree between the communication behavior feature vector and a preset baseline, and judging an abnormal behavior if the deviation degree exceeds a threshold value. Efficient anomaly detection is realized, and the active defense capability of the Internet of Things communication system is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of Internet of Things (IoT) security, and specifically relates to an IoT security authentication communication method and system. Background Technology

[0002] With the development of IoT security technology, technologies based on device feature authentication and communication data verification have emerged. These technologies verify device identity through hardware identifier binding and encryption algorithms, and ensure the integrity of transmitted data using hash verification. Traditional technologies often employ static credentials or one-way encryption protocols for device authentication. For example, a fixed identity identifier is generated using a pre-set key, combined with a one-way hash algorithm to verify device legitimacy. For communication integrity protection, end-to-end hash value verification or fixed block verification mechanisms are typically used to detect data tampering. However, current authentication and communication security methods have significant drawbacks: rigid authentication mechanisms: static credentials are easily cracked or forged and cannot adapt to dynamic device characteristics, resulting in insufficient authentication flexibility; coarse-grained integrity verification: traditional hash verification has long cycles and fixed blocks, making it difficult to detect local data tampering in a timely manner, and the verification process is susceptible to man-in-the-middle attacks; single-dimensional anomaly detection: existing methods rely on isolated parameters to determine anomalies, lacking dynamic baseline analysis of multi-dimensional characteristics of communication behavior, leading to a high false alarm rate; and delayed risk response: traditional solutions struggle to promptly correlate authentication failures, data tampering, and abnormal behavior with multi-source time-series data, failing to quantify comprehensive security risks and trigger dynamic defense mechanisms. Summary of the Invention

[0003] Therefore, it is necessary to provide an IoT security authentication communication method and system that can solve the above problems.

[0004] Firstly, this application provides an IoT security authentication communication method, including:

[0005] Obtain the target device's hardware identifier, communication protocol version, and computing power parameters, and integrate them to generate a device feature vector;

[0006] The device feature vector is processed using an encryption algorithm to obtain a dynamic credential. Based on the device authentication rules, the dynamic credential is used to authenticate the device and obtain a list of authenticated devices.

[0007] Based on the list of certified devices, the communication data stream of the certified devices is obtained. Hash chain technology is used to generate segmented check codes for the communication data stream. The integrity of the communication data stream is judged based on the segmented check codes, and an integrity verification result is generated.

[0008] Based on the verification results, the frequency, packet size, and time interval parameters of the communication data stream are extracted to construct a communication behavior feature vector. The deviation of the communication behavior feature vector from a preset baseline is calculated. If the deviation exceeds a preset threshold, abnormal behavior is determined, and a corresponding anomaly detection result is generated. In one embodiment, generating the corresponding anomaly detection result includes:

[0009] Cluster analysis based on device physical topology is performed on the behavioral feature vectors of communication data streams, and the results of the cluster analysis are integrated to form an abnormal pattern library;

[0010] The first time series is formed by extracting the time series data of the number of authentication failures from the device authentication records, the second time series is formed by extracting the time series data of data tampering events from the communication integrity verification records, and the third time series is formed by extracting the time series data of the frequency of abnormal behavior triggering from the abnormal pattern library.

[0011] Based on the same preset time window, the authentication failure rate of the first time series, the data tampering rate of the second time series, and the anomaly occurrence rate of the third time series are calculated respectively.

[0012] The authentication failure rate, data tampering rate, or anomaly occurrence rate are compared with preset thresholds. When any one of them exceeds the corresponding threshold, a preliminary anomaly detection result is generated.

[0013] In one embodiment, after generating the initial anomaly detection result, the method further includes:

[0014] A comprehensive security score is calculated based on the authentication failure rate, data tampering rate, and anomaly occurrence rate using a pre-defined weighted evaluation model.

[0015] Based on a preset risk level mapping table, the comprehensive safety score is mapped and matched, and divided into three levels: when the comprehensive safety score S < 0.4, it is mapped to low risk; when 0.4 ≤ S < 0.7, it is mapped to medium risk; and when S ≥ 0.7, it is mapped to high risk. An anomaly comprehensive detection result containing three levels of labels: high risk, medium risk, and low risk is generated.

[0016] In one embodiment, the calculation expression of the weighted evaluation model in the comprehensive safety score is obtained by using a preset weighted evaluation model:

[0017]

[0018] Where t represents the current time window index, t k This represents the historical time window index, λ represents the time decay factor, and w k Let w represent the baseline weights of each time unit within the sliding window, and satisfy ∑w k =1, Indicates the authentication failure rate. Indicates the data tampering rate. C represents the incidence rate of abnormalities. max T0 represents the maximum allowed authentication failure rate threshold, and A represents the normalized baseline value for the tampering rate. th The threshold for anomaly incidence is represented by α, β, and γ, which are dynamic weighting coefficients and satisfy α+β+γ=1. tanh(·) represents the hyperbolic tangent function.

[0019] In one embodiment, when the overall anomaly detection result is high-risk, the following steps are performed:

[0020] Based on a comprehensive security score, the key length parameter of the encryption algorithm is dynamically updated using a preset dynamic credential optimization strategy;

[0021] Based on the high-frequency abnormal behavior feature vectors in the comprehensive anomaly detection results, the preset baseline of the communication behavior feature vectors is updated using the sliding window mean algorithm.

[0022] In one embodiment, when the anomaly detection result is high-risk, the following defense mechanism is triggered:

[0023] Two-factor authentication is performed on communication data streams based on elliptic curve encryption technology.

[0024] Using network access control technology, communication links are blocked for devices that are detected to exhibit abnormal behavior;

[0025] Based on the characteristics of hash chain technology, the generation period of segmented check codes is adjusted, and the adjusted generation period does not exceed 1 / 2 of the original period.

[0026] In one embodiment, when the overall anomaly detection result is at a high-risk level, the following steps are further performed:

[0027] Based on the communication topology data between abnormal devices and authentication devices, graph structure analysis is performed using the adjacency matrix generated by the communication handshake frequency to obtain a set of risk propagation paths.

[0028] Based on the spatiotemporal correlation characteristics of communication data streams, an abnormal link screening process is performed using a similarity comparison algorithm between a preset baseline and real-time data streams to obtain a set of abnormal interaction links with a matching degree lower than a threshold.

[0029] Based on the risk diffusion path set and the abnormal interaction link set, smart contract technology is used to perform topological fingerprint and dynamic credential association encapsulation processing to obtain a blockchain audit record chain containing timestamps.

[0030] Secondly, this application also provides an Internet of Things (IoT) security authentication communication system, comprising:

[0031] The device feature extraction module is used to obtain the hardware identifier, communication protocol version, and computing capability parameters of the target device, and integrate them to generate a device feature vector;

[0032] The dynamic credential authentication module is used to process the device feature vector using an encryption algorithm to obtain a dynamic credential, and to authenticate the device using the dynamic credential based on the device authentication rules to obtain a list of authenticated devices.

[0033] The data integrity verification module is used to obtain the communication data stream of the certified devices based on the list of certified devices, generate segmented verification codes for the communication data stream using hash chain technology, and determine the integrity of the communication data stream based on the segmented verification codes to generate integrity verification results.

[0034] The behavior anomaly detection module is used to extract the frequency, packet size and time interval parameters of the communication data stream based on the verification results, construct the communication behavior feature vector, and calculate the deviation of the communication behavior feature vector from the preset baseline. If the deviation exceeds the preset threshold, it is determined that there is abnormal behavior and the corresponding anomaly detection result is generated.

[0035] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the above-described Internet of Things security authentication communication method.

[0036] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the above-described Internet of Things security authentication communication method.

[0037] The aforementioned IoT security authentication communication method and system, by integrating device hardware identifiers, communication protocol versions, and computing power parameters to generate dynamic credentials, can achieve dynamic authentication based on real-time device characteristics. This solves the rigidity problems of traditional static credentials, which are easily cracked and lack flexibility. Employing hash chain technology to generate segmented verification codes for the communication data stream enables finer-grained real-time detection of data integrity, timely detection of local tampering, and reduction of man-in-the-middle attack interference, improving the long verification cycle and fixed block structure of traditional methods. Extracting multi-dimensional parameters such as communication frequency, packet size, and time interval to construct behavioral feature vectors and calculating deviations from preset baselines allows for comprehensive analysis of communication behavior, avoiding the limitations of isolated parameter detection, improving anomaly detection accuracy, and reducing false alarm rates. This forms a full-link security framework of device authentication, data verification, and behavior detection, providing underlying support for the system's proactive defense capabilities. It builds a security barrier from device access and data transmission to behavior monitoring, indirectly laying the foundation for solving the problem of delayed risk response. Attached Figure Description

[0038] To more clearly illustrate the technical solutions in the embodiments or related technologies of this application, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0039] Figure 1 This is a flowchart of an IoT security authentication communication method according to the present invention;

[0040] Figure 2 This is a structural diagram of an Internet of Things (IoT) security authentication communication system according to the present invention. Detailed Implementation

[0041] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.

[0042] The implementation environment of this invention includes IoT devices, edge gateways, cloud servers, and blockchain nodes. In IoT security protection scenarios, terminal devices submit hardware features to the edge gateway to generate dynamic credentials. The edge gateway and cloud server work together to complete device authentication and hash chain segmentation verification. When an anomaly is detected, the cloud server triggers the SDN controller to block the abnormal link in real time, and at the same time synchronizes the risk features to the blockchain node to generate an audit chain, forming a closed-loop interaction of "feature authentication - data verification - anomaly blocking - source tracing and evidence storage", ensuring that the entire process response from attack identification to proactive defense is completed within 200ms.

[0043] In one embodiment, such as Figure 1 As shown, an IoT security authentication communication method is provided. This embodiment illustrates the method applied to a terminal, but it is understood that the method can also be applied to a server, or to a system including both a terminal and a server, and implemented through interaction between the terminal and the server. In this embodiment, the method includes the following steps:

[0044] S101: Obtain the target device's hardware identifier, communication protocol version, and computing capability parameters, and integrate them to generate a device feature vector.

[0045] Hardware identifiers, such as MAC addresses and serial numbers, accurately distinguish different devices and possess uniqueness and stability. Communication protocol versions reflect the rules and standards followed by the device during communication. Different versions of communication protocols differ in functionality and security; obtaining this parameter helps subsequent authentication and communication processes adapt to the corresponding rules. Computational capability parameters reflect the device's data processing capabilities, such as CPU performance and memory capacity, determining the device's processing efficiency and feasibility in encryption and verification operations, and providing important reference value for the design and implementation of the overall secure authentication communication process. Integrating the obtained hardware identifiers, communication protocol versions, and computational capability parameters can be achieved using specific mathematical algorithms or data processing methods, transforming these different types of data into a unified vector form. For example, the hardware identifier can be encoded, the communication protocol version can be represented numerically, and the computational capability parameters can be normalized and combined in a certain order to form a multi-dimensional vector. This comprehensively and concisely summarizes the key characteristics of the target device, providing an accurate device information foundation for subsequent generation of dynamic credentials using encryption algorithms.

[0046] S102, the device feature vector is processed using an encryption algorithm to obtain a dynamic credential, and the device is authenticated using the dynamic credential based on the device authentication rules to obtain a list of authenticated devices.

[0047] This process employs encryption algorithms such as AES (an efficient and secure symmetric encryption algorithm) or RSA (an asymmetric encryption algorithm), using the device feature vector as input. After processing, the algorithm outputs a dynamic credential. Because the device feature vector contains information such as the device's hardware identifier, communication protocol version, and computing power parameters, the generated dynamic credential is unique and dynamic. Device authentication rules are the basis for determining the legitimacy of a device. These rules can be formulated based on the system's security requirements and actual application scenarios, including requirements for the format, validity period, and encryption key verification of the dynamic credential. For example, it may stipulate that the dynamic credential must be valid within a specific time frame, or that the encryption key of the credential must match a key pre-stored in the system. During device authentication, the dynamic credential is checked according to the device authentication rules. The format of the dynamic credential is verified to meet the requirements; if the format is incorrect, device authentication fails. The validity period of the dynamic credential is checked; if the credential has expired, authentication also fails. The encryption key of the dynamic credential is verified to ensure its legitimate origin and that it has not been tampered with. A device is deemed legitimate only when its dynamic credentials meet all authentication rules. After device authentication, information on all authenticated devices is collected to form a list of authenticated devices. This list records relevant information about legitimate devices, such as their hardware identifiers and dynamic credentials, and forms the foundation for secure communication within the system.

[0048] S103. Based on the list of certified devices, obtain the communication data stream of the certified devices, use hash chain technology to generate segmented check codes for the communication data stream, and determine the integrity of the communication data stream based on the segmented check codes to generate an integrity verification result.

[0049] This involves extracting data transmitted during communication from the communication network between authentication devices according to certain rules and mechanisms, forming a communication data stream. A hash chain is a data structure built on a hash function. It obtains the next hash value by hashing the previous hash value and the current data block, and so on, forming a chain structure with unidirectional and unique characteristics. The acquired communication data stream can be divided according to a fixed byte length or data logic, and a hash function can be used to perform hash operations to obtain the initial hash value of each data segment, generating a corresponding segment checksum for each data segment in the entire communication data stream. At the receiving end, the received communication data stream is regenerated with segment checksums according to the same segmentation rules and hash chain technology. The regenerated segment checksums are then compared one by one with the segment checksums sent by the sending end. If all segment checksums match, the data is complete; if there are mismatched segment checksums, the integrity of the communication data stream has been compromised. Based on the comparison results above, a clear integrity verification result is generated. This result can be a simple Boolean value such as complete or incomplete, or it can be a report containing more detailed information, such as which data segments have mismatched checksums, possible tampering locations, etc., which facilitates further corresponding measures, such as requiring data retransmission or issuing a security alert.

[0050] S104. Based on the verification results, extract the frequency, packet size and time interval parameters of the communication data stream, construct the communication behavior feature vector, and calculate the deviation of the communication behavior feature vector from the preset baseline. If the deviation exceeds the preset threshold, it is determined that there is abnormal behavior and the corresponding abnormal detection result is generated.

[0051] The verification results determine whether subsequent parameter extraction, feature vector construction, deviation calculation, and abnormal behavior judgment are carried out. If the verification results show that the data is complete, the extracted parameters have high reliability; if incomplete, further analysis is needed to determine whether it is a data transmission problem or a real device anomaly. For communication data stream frequency: this refers to the number of communication data packets sent or received within a certain time range, which can be obtained by statistically analyzing the number of data packets per unit time, reflecting the activity level of device communication; packet size: this refers to the amount of data contained in each communication data packet. Packet size has different distribution characteristics under different communication applications and business scenarios, and can be directly obtained by reading relevant fields of the data packet; time interval: the time difference between the sending or receiving of two adjacent data packets, reflecting the rhythm and regularity of communication, obtained by recording the timestamps of the data packets and calculating the difference between adjacent timestamps. Combining the extracted frequency, packet size, and time interval into a multi-dimensional vector, for example, using frequency, packet size, and time interval as the three dimensions of the vector, can comprehensively and concisely describe the communication behavior characteristics of the device. A preset baseline can be obtained by analyzing and statistically analyzing a large number of historical typical communication behaviors under normal operating conditions, representing the communication pattern under normal conditions, and serving as a reference standard for judging whether communication behavior is abnormal. Various mathematical methods can be used to calculate deviation, such as Euclidean distance and cosine similarity. Taking the Euclidean distance algorithm as an example, the deviation is measured by the geometric distance between the communication behavior feature vector and the preset baseline vector in multidimensional space; the larger the distance, the greater the deviation. The preset threshold can be set based on security requirements and historical data experience. When the calculated deviation exceeds the preset threshold, it indicates that the current communication behavior differs significantly from the normal mode, and abnormal behavior is identified. Once abnormal behavior is identified, corresponding anomaly detection results are generated. The results can include relevant information about the abnormal behavior, such as the time of occurrence, the devices involved, and the specific value of the deviation, so that system administrators can take appropriate security measures in a timely manner, such as isolating the abnormal devices and further investigating the cause of the anomaly.

[0052] The aforementioned IoT security authentication communication method integrates the target device's hardware identifier, communication protocol version, and computing power parameters to generate a device feature vector. This vector is then processed using an encryption algorithm to obtain a dynamic credential, which is used to authenticate the device based on device authentication rules, resulting in a list of authenticated devices. This effectively confirms device legitimacy, prevents unauthorized device access, and solves the identity authentication problem. Based on the authenticated device list, the communication data stream is obtained, and a segmented checksum is generated using hash chain technology to verify its integrity. This promptly detects tampering during data transmission, ensuring data accuracy and solving the data integrity verification problem. Based on the verification results, the frequency, packet size, and time interval parameters of the communication data stream are extracted to construct a communication behavior feature vector. The deviation from a preset baseline is calculated to determine abnormal behavior, enabling real-time monitoring of device communication status and timely detection of abnormal communication behavior. This solves the problem of difficult-to-detect abnormal communication behavior and comprehensively improves the security and reliability of system communication.

[0053] In one embodiment, the corresponding anomaly detection results are generated, including:

[0054] S201, Perform cluster analysis on the behavioral feature vectors of communication data streams based on the physical topology of devices, and integrate the cluster analysis results to form an abnormal pattern library;

[0055] S202, extract the time-series data of the number of authentication failures from the device authentication record to form a first time series, extract the time-series data of data tampering events from the communication integrity verification record to form a second time series, and extract the time-series data of the frequency of abnormal behavior triggering from the abnormal pattern library to form a third time series.

[0056] S203, based on the same preset time window, calculate the authentication failure rate of the first time series, the data tampering rate of the second time series, and the anomaly occurrence rate of the third time series respectively;

[0057] S204 compares the authentication failure rate, data tampering rate, or anomaly occurrence rate with the corresponding preset thresholds. When any one of them exceeds the corresponding threshold, a preliminary anomaly detection result is generated.

[0058] Specifically, the physical topology of devices reflects their actual connection and layout within the network. Devices within the same physical topology area often exhibit similar communication behavior patterns. Cluster analysis can group devices with similar behavioral feature vectors into one category, and the abnormal communication behavior patterns represented by each category can be organized and summarized to form an abnormal pattern library. Time-series data on authentication failure counts are extracted from device authentication records and arranged chronologically to form a first time series, showing the trend of device authentication failures over time. Time-series data on data tampering events are extracted from communication integrity verification records and arranged chronologically to obtain a second time series, reflecting the occurrence patterns of tampering events during data transmission. Time-series data on the trigger frequency of abnormal behaviors are extracted from the abnormal pattern library to construct a third time series, helping to understand the frequency changes of abnormal behaviors in different time periods. A fixed time period, such as one day or one week, is selected as a preset time window. Within this time window, the authentication failure rate (the proportion of authentication failures to total authentication attempts) for the first time series, the data tampering rate (the proportion of data tampering events to total communication attempts) for the second time series, and the anomaly occurrence rate (the proportion of abnormal behavior triggers to total monitoring attempts) for the third time series are calculated respectively. This provides a clear picture of the severity of anomalies in different aspects of the system during this period. The calculated authentication failure rate, data tampering rate, and anomaly occurrence rate are compared with pre-set corresponding thresholds. These pre-set thresholds are determined based on the system's security requirements and historical data experience, representing the upper limit of tolerable anomalies. When any ratio exceeds its corresponding threshold, it indicates that the anomaly has exceeded the acceptable range. At this point, a preliminary anomaly detection result is generated, indicating a potential security risk so that appropriate measures can be taken in a timely manner.

[0059] In one embodiment, after generating the initial anomaly detection result, the method further includes:

[0060] S301 calculates a comprehensive security score based on authentication failure rate, data tampering rate, and anomaly occurrence rate using a pre-defined weighted evaluation model.

[0061] S302, based on the preset risk level mapping table, maps and matches the comprehensive safety score, dividing it into three levels: when the comprehensive safety score S<0.4, it is mapped to low risk; when 0.4≤S<0.7, it is mapped to medium risk; when S≥0.7, it is mapped to high risk, and generates an anomaly comprehensive detection result containing three levels of labels: high risk, medium risk, and low risk.

[0062] For example, authentication failure rate, data tampering rate, and anomaly occurrence rate serve as the foundational data for calculating the comprehensive security score. These metrics reflect the current security status of the system from different dimensions, such as device authentication, data integrity, and the frequency of abnormal behavior triggering. A pre-defined weighted evaluation model assigns different weights to each of these metrics. The weights can be determined based on the importance of each indicator to system security. For instance, data tampering may have more serious consequences for the system, thus receiving a relatively higher weight. This model multiplies each ratio by its corresponding weight and then sums the results to obtain a comprehensive value reflecting the system's security status—the comprehensive security score. A higher score indicates a higher security risk. A pre-defined risk level mapping table, developed based on extensive historical data and security experience, divides the comprehensive security score into different risk intervals, assigning a risk level label to each interval: a three-tiered label system (S≥0.7 for high risk, 0.4≤S<0.7 for medium risk, and S<0.4 for low risk). This system effectively correlates the comprehensive security score with the actual level of risk. The calculated comprehensive security score is compared with a risk level mapping table to determine the risk range in which the score falls. Based on the matched risk range, an anomaly detection result is generated, which can intuitively inform users of the current risk level faced by the system, enabling them to take corresponding security measures according to different risk levels. For example, for high-risk levels, dynamic credential optimization, two-factor authentication, and verification cycle shortening are simultaneously activated; for medium-risk levels, only verification cycle shortening is activated; and for low-risk levels, routine monitoring is maintained.

[0063] In one embodiment, S401, the calculation expression of the weighted evaluation model in the comprehensive safety score is obtained by using a preset weighted evaluation model:

[0064]

[0065] Where t represents the current time window index, t k This represents the historical time window index, λ represents the time decay factor, and w k Let w represent the baseline weights of each time unit within the sliding window, and satisfy ∑w k =1, Indicates the authentication failure rate. Indicates the data tampering rate. C represents the incidence rate of abnormalities. max T0 represents the maximum allowed authentication failure rate threshold, and A represents the normalized baseline value for the tampering rate. th The threshold for anomaly incidence is represented by α, β, and γ, which are dynamic weighting coefficients and satisfy α+β+γ=1. tanh(·) represents the hyperbolic tangent function.

[0066] Specifically, the current time window index t is a quantified marker of time. In practical scenarios, time windows are typically divided according to certain time intervals, and t is the number of the currently processed time window within the entire time series. It is used to clarify which specific time window the current calculation is based on, ensuring that the calculation corresponds to a specific time stage and reflects the security status at that moment. Historical time window index t k This is used to index relevant data within historical time windows, considering trends in security conditions and historical information to avoid bias arising from evaluations based solely on current data. The baseline weight w for each time unit within the sliding window... k This is used to balance the impact of data from different historical time windows on the overall security score. The authentication failure rate C(t), data tampering rate T(t), and anomaly occurrence rate A(t) are calculated from the dimensions of device authentication security, communication data transmission integrity, and frequency of abnormal behavior triggering, respectively, and compared with a preset maximum allowable authentication failure rate threshold. max tampering rate normalized baseline value T0 and anomaly occurrence rate saturation threshold A th By comparison, the comprehensive safety score calculated under the constraints of dynamic weighting coefficients α, β, and γ can more flexibly reflect the actual safety situation.

[0067] In one embodiment, when the overall anomaly detection result is high-risk, the following steps are performed:

[0068] S501, based on a comprehensive security score, dynamically updates the key length parameter of the encryption algorithm using a preset dynamic credential optimization strategy;

[0069] S502 updates the preset baseline of the communication behavior feature vector based on the high-frequency abnormal behavior feature vector in the comprehensive anomaly detection results using the sliding window mean algorithm.

[0070] For example, under high security risk conditions, a dynamic optimization credential strategy triggered by a comprehensive security score can enhance the security of dynamic credentials by adjusting the key length parameter of the encryption algorithm. For instance, when using symmetric encryption algorithms such as AES, the key length can be dynamically increased from 128 bits to 256 bits. The preset strategy can define a mapping relationship between the comprehensive security score and the key length. For example, the key length increases by 32 bits for every 10% increase in the score, ensuring that the key strength dynamically matches the risk level. High-frequency abnormal behavior feature vectors indicate that the current device's communication pattern continuously deviates from the preset baseline, and the original baseline can no longer accurately reflect normal communication behavior. For example, if the device generates abnormal traffic after being implanted with malicious programs, a sliding window mean algorithm can be used to perform real-time rolling average processing on historical normal communication data to generate a new preset baseline. Specifically, centered on the current time window, a sliding window containing recent high-frequency abnormal behavior data is selected, such as the last 100 communication cycles. After removing abnormal data points, the mean, variance, and other statistics of the remaining normal data are calculated to reconstruct the baseline values ​​for parameters such as communication frequency, packet size, and time interval. To avoid the problem of insufficient adaptability of traditional fixed baselines to dynamic communication scenarios, the baseline can be dynamically adjusted according to reasonable changes in device communication modes by incorporating the latest normal behavior data in real time. This reduces false alarms or missed alarms caused by outdated baselines and improves the fitting accuracy of anomaly detection models to real-time communication behavior.

[0071] In one embodiment, when the anomaly detection result is high-risk, the following defense mechanism is triggered:

[0072] S601, based on elliptic curve encryption technology, performs two-factor authentication on communication data streams;

[0073] S602 utilizes network access control technology to block the communication link of devices that are detected to be behaving abnormally.

[0074] S603, based on the characteristics of hash chain technology, adjusts the generation period of segmented check codes, and the adjusted generation period does not exceed 1 / 2 of the original period.

[0075] Specifically, elliptic curve cryptography (ECD) offers high security and low computational complexity. Based on the mathematical problem of elliptic curve discrete logarithms, it requires a much shorter key length than traditional algorithms like RSA for the same security level, making it suitable for the lightweight computing needs of IoT devices. Building upon existing dynamic credential authentication, a two-factor authentication mechanism is added: the first factor is the aforementioned dynamic credential generated based on the device's feature vector; the second factor can be a temporary session key generated using an elliptic curve cryptography algorithm, combined with the device's hardware fingerprint for secondary verification. Both communicating parties must simultaneously pass two-factor authentication to establish a connection. During the authentication process, the ECDH algorithm (a key exchange protocol based on elliptic curve cryptography) is used to negotiate the session key, ensuring the security of key transmission. This elevates the security of device authentication from a single credential to a multi-layered protection system of credential + hardware features + encrypted negotiation. Network access control technology achieves fine-grained control over abnormal devices through real-time monitoring and policy management of network traffic. For devices exhibiting abnormal communication behavior, the access control policies of the SDN controller (Software-Defined Network Controller, used to manage network traffic) or hardware firewall are triggered. By dynamically generating access control lists or flow rules, bidirectional communication blocking is implemented on the device's IP / MAC address, severing its connection with other devices in the authentication device list. The blocking policy can be set with a time limit, such as automatic release after 10 minutes, and blocking logs are recorded simultaneously for security auditing. This enables real-time discovery and immediate isolation of abnormal devices, preventing them from becoming attack springboards for spreading risks. Hash chain technology uses chained hash value association to achieve data integrity verification. Shortening the generation cycle increases the verification frequency and enhances the sensitivity to detecting local data tampering. After adjusting the generation cycle of segmented checksums, communication data streams can be segmented at a finer granularity, such as splitting a 1024-byte data block into 512 bytes. Each segment generates a hash value in real time and links it to the preceding hash value, forming a denser verification chain. This constructs a dynamic defense system across the entire authentication-access-transmission chain, solving the problems of delayed risk response and coarse-grained verification, achieving precise response and proactive defense in high-risk scenarios.

[0076] In one embodiment, when the overall anomaly detection result is at a high-risk level, the following steps are further performed:

[0077] S701, based on the communication topology data between abnormal devices and authentication devices, performs graph structure analysis on the adjacency matrix generated by the communication handshake frequency to obtain a set of risk propagation paths;

[0078] S702, based on the spatiotemporal correlation characteristics of communication data streams, uses a similarity comparison algorithm between a preset baseline and real-time data streams to perform abnormal link screening, and obtains a set of abnormal interaction links with a matching degree lower than a threshold.

[0079] S703, based on the risk diffusion path set and the abnormal interaction link set, uses smart contract technology to perform topological fingerprint and dynamic credential association encapsulation processing to obtain a blockchain audit record chain containing timestamps.

[0080] For example, communication topology data describes the connection relationships and communication structure between devices, reflecting how each device communicates with the others. Simultaneously, an adjacency matrix is ​​generated based on the communication handshake frequency, reflecting the frequency of communication and connection relationships between devices. By analyzing the adjacency matrix using graph structure features such as connectivity and path length, paths that abnormal devices might spread risk to other certified devices can be identified, resulting in a risk propagation path set. The spatiotemporal correlation characteristics of communication data flows consider the temporal and spatial correlation of communication data flows, such as the time sequence of data transmission, the time interval of data interaction between different devices, and the location of devices in the network topology. An abnormal link screening process is performed using a similarity comparison algorithm between a preset baseline and the real-time data flow. The preset baseline represents the communication pattern and characteristics under normal circumstances. By comparing the real-time data flow with the preset baseline, it can be determined whether the current communication is abnormal. If the similarity is below a certain threshold, it indicates that the communication link may be abnormal. The resulting set of abnormal interaction links with a matching degree below the threshold may include attack entry points or links already affected by attacks, requiring timely handling to prevent further risk propagation. Integrating the information from the risk propagation path set and the abnormal interaction link set provides a more comprehensive description of the security threats faced by the system. Topological fingerprints are a characteristic representation of network topology. Through smart contract technology (a type of contract written in computer code and stored on the blockchain that can be executed automatically), topological fingerprints are associated with dynamic credentials and encapsulated to ensure data security and immutability, resulting in a blockchain audit record chain containing timestamps. The timestamps record the time each audit record was generated, giving the audit records chronological order and traceability. The characteristics of blockchain guarantee the integrity and immutability of audit records, which can be used for subsequent security audits, troubleshooting, and liability determination, providing strong support for system security.

[0081] The aforementioned IoT security authentication communication method acquires the target device's hardware identifier, communication protocol version, and computing power parameters, integrates them to generate a device feature vector, processes the data using an encryption algorithm to obtain dynamic credentials, and performs device authentication based on device authentication rules. This solves the rigidity problem of traditional static credentials being easily cracked and lacking flexibility, achieving dynamic authentication based on real-time device features. Hash chain technology is used to generate segmented check codes for the communication data stream of the authenticated device to determine integrity, enabling finer-grained real-time detection of data integrity, timely detection of local tampering, and reduction of attack interference, improving the coarse-grained problems of long verification cycles and fixed block divisions in traditional methods. Based on the integrity verification results, the frequency, packet size, and time interval parameters of the communication data stream are extracted to construct a communication behavior feature vector and calculate the deviation from a preset baseline. Combined with cluster analysis based on the device's physical topology, an anomaly pattern library is formed. Time-series data is extracted from device authentication records, communication integrity verification records, and the anomaly pattern library to calculate the authentication failure rate, data tampering rate, and anomaly occurrence rate. After generating preliminary anomaly detection results, a weighted evaluation model is used. The system calculates a comprehensive security score and generates anomaly detection results with three-level labels based on a risk level mapping table. This enables dynamic baseline analysis of multi-dimensional characteristics of communication behavior, avoiding the single-parameter deficiency of isolated parameter detection, improving anomaly detection accuracy, and reducing false alarm rate. When the anomaly detection result is high-risk, steps such as dynamically updating the key length parameter of the encryption algorithm and updating the preset baseline of the communication behavior feature vector are executed. This triggers defense mechanisms such as two-factor authentication, communication link blocking, and adjustment of the segmented checksum generation cycle. Furthermore, based on communication topology data and spatiotemporal correlation characteristics, graph structure analysis, anomaly link screening, and association encapsulation processing using smart contract technology are performed to obtain a blockchain audit record chain. This enables timely correlation of authentication failures, data tampering, and multi-source time-series data of anomalies, quantifying comprehensive security risks and triggering dynamic defense mechanisms. This addresses the problem of delayed risk response and forms a full-link security framework of device authentication, data verification, and behavior detection, providing underlying support for the system's proactive defense capabilities and building a security barrier from device access and data transmission to behavior monitoring.

[0082] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.

[0083] Based on the same inventive concept, this application also provides an IoT security authentication communication system for implementing the IoT security authentication communication method described above. The solution provided by this system is similar to the implementation described in the above method; therefore, the specific limitations of one or more IoT security authentication communication system embodiments provided below can be found in the limitations of the IoT security authentication communication method described above, and will not be repeated here.

[0084] In one exemplary embodiment, such as Figure 2 As shown, an IoT security authentication communication system is provided, including:

[0085] The device feature extraction module 11 is used to obtain the hardware identifier, communication protocol version and computing capability parameters of the target device, and integrate them to generate a device feature vector;

[0086] The dynamic credential authentication module 12 is used to process the device feature vector using an encryption algorithm to obtain a dynamic credential, and to perform device authentication using the dynamic credential based on the device authentication rules to obtain a list of authenticated devices.

[0087] The data integrity verification module 13 is used to obtain the communication data stream of the certified devices based on the list of certified devices, generate segmented verification codes for the communication data stream using hash chain technology, and determine the integrity of the communication data stream based on the segmented verification codes to generate integrity verification results.

[0088] The behavior anomaly detection module 14 is used to extract the frequency, packet size and time interval parameters of the communication data stream based on the verification results, construct the communication behavior feature vector, and calculate the deviation of the communication behavior feature vector from the preset baseline. If the deviation exceeds the preset threshold, it is determined that there is abnormal behavior and the corresponding anomaly detection result is generated.

[0089] In one embodiment, the behavior anomaly detection module 14 is further configured to:

[0090] Cluster analysis based on device physical topology is performed on the behavioral feature vectors of communication data streams, and the results of the cluster analysis are integrated to form an abnormal pattern library;

[0091] The first time series is formed by extracting the time series data of the number of authentication failures from the device authentication records, the second time series is formed by extracting the time series data of data tampering events from the communication integrity verification records, and the third time series is formed by extracting the time series data of the frequency of abnormal behavior triggering from the abnormal pattern library.

[0092] Based on the same preset time window, the authentication failure rate of the first time series, the data tampering rate of the second time series, and the anomaly occurrence rate of the third time series are calculated respectively.

[0093] The authentication failure rate, data tampering rate, or anomaly occurrence rate are compared with preset thresholds. When any one of them exceeds the corresponding threshold, a preliminary anomaly detection result is generated.

[0094] In one embodiment, the behavior anomaly detection module 14 is further configured to:

[0095] A comprehensive security score is calculated based on the authentication failure rate, data tampering rate, and anomaly occurrence rate using a pre-defined weighted evaluation model.

[0096] Based on a preset risk level mapping table, the comprehensive safety score is mapped and matched, and divided into three levels: when the comprehensive safety score S < 0.4, it is mapped to low risk; when 0.4 ≤ S < 0.7, it is mapped to medium risk; and when S ≥ 0.7, it is mapped to high risk. An anomaly comprehensive detection result containing three levels of labels: high risk, medium risk, and low risk is generated.

[0097] In one embodiment, the behavior anomaly detection module 14 is further configured to calculate a comprehensive security score using the following formula:

[0098]

[0099] Where t represents the current time window index, t k This represents the historical time window index, λ represents the time decay factor, and w k Let w represent the baseline weights of each time unit within the sliding window, and satisfy ∑w k =1, Indicates the authentication failure rate. Indicates the data tampering rate. C represents the incidence rate of abnormalities. max T0 represents the maximum allowed authentication failure rate threshold, and A represents the normalized baseline value for the tampering rate. th The threshold for anomaly incidence is represented by α, β, and γ, which are dynamic weighting coefficients and satisfy α+β+γ=1. tanh(·) represents the hyperbolic tangent function.

[0100] In one embodiment, the behavior anomaly detection module 14 is further configured to:

[0101] When the overall anomaly detection result is high-risk, perform the following steps:

[0102] Based on a comprehensive security score, the key length parameter of the encryption algorithm is dynamically updated using a preset dynamic credential optimization strategy;

[0103] Based on the high-frequency abnormal behavior feature vectors in the comprehensive anomaly detection results, the preset baseline of the communication behavior feature vectors is updated using the sliding window mean algorithm.

[0104] In one embodiment, the behavior anomaly detection module 14 is further configured to:

[0105] When the comprehensive anomaly detection result is at a high-risk level, the following defense mechanism is triggered:

[0106] Two-factor authentication is performed on communication data streams based on elliptic curve encryption technology.

[0107] Using network access control technology, communication links are blocked for devices that are detected to exhibit abnormal behavior;

[0108] Based on the characteristics of hash chain technology, the generation period of segmented check codes is adjusted, and the adjusted generation period does not exceed 1 / 2 of the original period.

[0109] In one embodiment, the behavior anomaly detection module 14 is further configured to:

[0110] When the overall anomaly detection result is high-risk, the following steps are further performed:

[0111] Based on the communication topology data between abnormal devices and authentication devices, graph structure analysis is performed using the adjacency matrix generated by the communication handshake frequency to obtain a set of risk propagation paths.

[0112] Based on the spatiotemporal correlation characteristics of communication data streams, an abnormal link screening process is performed using a similarity comparison algorithm between a preset baseline and real-time data streams to obtain a set of abnormal interaction links with a matching degree lower than a threshold.

[0113] Based on the risk diffusion path set and the abnormal interaction link set, smart contract technology is used to perform topological fingerprint and dynamic credential association encapsulation processing to obtain a blockchain audit record chain containing timestamps.

[0114] In one embodiment, a computer device is provided, including a memory and a processor, the memory storing a computer program, the processor executing the computer program to implement the steps of the IoT security authentication communication method as described above.

[0115] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon, which, when executed by a processor, implements the steps in the above method embodiments.

[0116] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can be referred to in the description of the method embodiments. The device embodiments described above are merely illustrative. The components described as separate parts may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this disclosure according to actual needs. Those skilled in the art can understand and implement this without creative effort.

[0117] The above-described embodiments are merely illustrative of several implementation methods of the embodiments of this application, and their descriptions are relatively specific and detailed. However, they should not be construed as limiting the scope of the patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of the embodiments of this application, and these modifications and improvements all fall within the protection scope of the embodiments of this application.

Claims

1. A secure authentication communication method for the Internet of Things, characterized in that, The method includes: Obtain the target device's hardware identifier, communication protocol version, and computing power parameters, and integrate them to generate a device feature vector; The device feature vector is processed using an encryption algorithm to obtain a dynamic credential. Based on the device authentication rules, the dynamic credential is used to authenticate the device and obtain a list of authenticated devices. Based on the list of certified devices, the communication data stream of the certified devices is obtained, a hash chain technique is used to generate a segmented check code for the communication data stream, and the integrity of the communication data stream is determined based on the segmented check code to generate an integrity check result. Based on the verification results, the frequency, packet size, and time interval parameters of the communication data stream are extracted to construct a communication behavior feature vector. The deviation of the communication behavior feature vector from the preset baseline is calculated. If the deviation exceeds the preset threshold, it is determined that there is abnormal behavior, and a corresponding abnormal detection result is generated.

2. The method according to claim 1, characterized in that, The generation of corresponding anomaly detection results includes: The behavioral feature vectors of the communication data stream are subjected to clustering analysis based on the physical topology of the devices, and the results of the clustering analysis are integrated to form an abnormal pattern library. The first time series is formed by extracting the time series data of the number of authentication failures from the device authentication records, the second time series is formed by extracting the time series data of data tampering events from the communication integrity verification records, and the third time series is formed by extracting the time series data of the frequency of abnormal behavior triggering from the abnormal pattern library. Based on the same preset time window, the authentication failure rate of the first time series, the data tampering rate of the second time series, and the anomaly occurrence rate of the third time series are calculated respectively. The authentication failure rate, data tampering rate, or anomaly occurrence rate are compared with preset corresponding thresholds. When any one of them exceeds the corresponding threshold, a preliminary anomaly detection result is generated.

3. The method according to claim 2, characterized in that, After generating the initial anomaly detection results, the following is also included: Based on the authentication failure rate, data tampering rate, and anomaly occurrence rate, a comprehensive security score is calculated using a preset weighted evaluation model. Based on a preset risk level mapping table, the comprehensive safety score is mapped and matched, and divided into three levels: when the comprehensive safety score S < 0.4, it is mapped to low risk; when 0.4 ≤ S < 0.7, it is mapped to medium risk; and when S ≥ 0.7, it is mapped to high risk. An anomaly comprehensive detection result containing three levels of labels: high risk, medium risk, and low risk is generated.

4. The method according to claim 3, characterized in that, The calculation expression of the weighted evaluation model used to calculate the comprehensive safety score is as follows: Where t represents the current time window index, t k This represents the historical time window index, λ represents the time decay factor, and w k Let w represent the baseline weights of each time unit within the sliding window, and satisfy ∑w k =1, Indicates the authentication failure rate. Indicates the data tampering rate. C represents the incidence rate of abnormalities. max T0 represents the maximum allowed authentication failure rate threshold, and A represents the normalized baseline value for the tampering rate. th The threshold for anomaly incidence is represented by α, β, and γ, which are dynamic weighting coefficients and satisfy α+β+γ=1. tanh(·) represents the hyperbolic tangent function.

5. The method according to claim 3, characterized in that, When the comprehensive anomaly detection result is at a high-risk level, the following steps are performed: Based on the comprehensive security score, the key length parameter of the encryption algorithm is dynamically updated using a preset dynamic credential optimization strategy; Based on the high-frequency abnormal behavior feature vector in the comprehensive anomaly detection results, the preset baseline of the communication behavior feature vector is updated using the sliding window mean algorithm.

6. The method according to claim 3, characterized in that, When the overall anomaly detection result is high-risk, the following defense mechanism is triggered: Based on elliptic curve cryptography, two-factor authentication is performed on the communication data stream; Using network access control technology, communication links are blocked for devices that are detected to exhibit abnormal behavior; Based on the characteristics of the hash chain technology, the generation period of the segmented check code is adjusted, and the adjusted generation period does not exceed 1 / 2 of the original period.

7. The method according to claim 3, characterized in that, When the overall anomaly detection result is high-risk, the following steps are further performed: Based on the communication topology data between abnormal devices and authentication devices, graph structure analysis is performed using the adjacency matrix generated by the communication handshake frequency to obtain a set of risk propagation paths. Based on the spatiotemporal correlation characteristics of the communication data stream, an abnormal link screening process is performed using a similarity comparison algorithm between a preset baseline and the real-time data stream to obtain a set of abnormal interaction links with a matching degree lower than a threshold. Based on the aforementioned risk diffusion path set and abnormal interaction link set, smart contract technology is used to perform topological fingerprint and dynamic credential association encapsulation processing to obtain a blockchain audit record chain containing timestamps.

8. An Internet of Things (IoT) security authentication communication system, characterized in that, The device includes: The device feature extraction module is used to obtain the hardware identifier, communication protocol version, and computing capability parameters of the target device, and integrate them to generate a device feature vector; The dynamic credential authentication module is used to process the device feature vector using an encryption algorithm to obtain a dynamic credential, and to perform device authentication using the dynamic credential based on device authentication rules to obtain a list of authenticated devices. The data integrity verification module is used to obtain the communication data stream of the authentication devices based on the authentication device list, generate segmented verification codes for the communication data stream using hash chain technology, determine the integrity of the communication data stream based on the segmented verification codes, and generate an integrity verification result. The behavior anomaly detection module is used to extract the frequency, packet size and time interval parameters of the communication data stream based on the verification result, construct a communication behavior feature vector, and calculate the deviation of the communication behavior feature vector from a preset baseline. If the deviation exceeds a preset threshold, it is determined that there is abnormal behavior and a corresponding anomaly detection result is generated.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7.