Authentication key generation method and device of boundary device, terminal device and storage medium
By collecting real-time context information from border devices and combining it with national cryptographic hash algorithms and dynamic parameters to generate one-time authorization authentication keys, the problems of key reuse and man-in-the-middle attacks under static key mechanisms are solved, thereby improving the security and reliability of device authentication.
Patent Information
- Application Number
- CN202511761781.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-11-27
- Publication Date
- 2026-01-13
AI Technical Summary
In existing methods for generating authentication keys for border devices, static keys or key mechanisms with fixed-period updates are prone to key reuse, posing a security risk of man-in-the-middle attacks and resulting in low security for device authentication.
Real-time context information of boundary devices is collected, context feature values are generated using the national cryptographic hash algorithm, and combined with the packet loss rate threshold judgment result and electromagnetic interference level, key derivation operation is performed with the master root key and random root key to generate a one-time authorization authentication key. The parameter weights are adjusted by improving the entropy method and the 3σ criterion method, and the number of iterations or key length is increased to deal with attacks.
The generated authentication keys are highly random and unpredictable, effectively preventing key reuse, preventing man-in-the-middle attacks, and improving the security and reliability of device authentication.
Smart Images

Figure CN121334656A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of wireless communication, and in particular to a method and device for generating an authentication key of a boundary device, a terminal device and a storage medium. BACKGROUND
[0002] With the wide application of industrial Internet of Things, intelligent terminals and other boundary devices, the security of device authentication is facing severe challenges.
[0003] The existing method for generating an authentication key of a boundary device usually adopts a static key or a fixed-period updated key mechanism to generate a key for boundary device authentication. However, the key generated by the static key or the fixed-period updated key mechanism has the problem of key reuse, and is prone to security risks of man-in-the-middle attacks, resulting in low security of device authentication. SUMMARY
[0004] The present application provides a method and device for generating an authentication key of a boundary device, a terminal device and a storage medium, which can solve the technical problem of low security of device authentication caused by the key reuse of the key generated by the static key or the fixed-period updated key mechanism in the prior art.
[0005] The present application provides a method for generating an authentication key of a boundary device, comprising: collecting real-time context information of the boundary device; generating a corresponding context feature value according to the real-time context information by using a national secret hash algorithm; using the context feature value, the packet loss rate threshold judgment result and the electromagnetic interference level as input data, performing key derivation operation in combination with a master root key and a random root key to generate a one-time authorization authentication key.
[0006] Further, the generating of the corresponding context feature value according to the real-time context information by using the national secret hash algorithm comprises: preprocessing the real-time context information, adjusting the parameter weight in the real-time context information to obtain first adjusted information; calculating the parameter weight in the first adjusted information by using an improved entropy value method, and rearranging the second adjusted information according to the parameter weight to obtain second adjusted information; generating a corresponding context feature value according to the second adjusted information by using a national secret hash algorithm.
[0007] Further, the preprocessing of the real-time context information, the adjustment of the parameter weight in the real-time context information and the obtaining of the first adjusted information comprise: The 3σ criterion method is used to detect whether the parameters in the real-time implementation context information are abnormal, if there is network parameter abnormality, the network parameter weight is lowered to a first preset value, and if there is physical parameter abnormality, the physical parameter weight is raised to a second preset value.
[0008] Further, after the context feature value, the packet loss rate threshold judgment result and the electromagnetic interference level are taken as input data, the master root key and the random root key are combined to perform key derivation operation, and a one-time authorization authentication key is generated, the method further includes: The man-in-the-middle attack detection is performed on the one-time authorization authentication key, and when it is detected that the packet loss rate is out of limit and the electromagnetic interference is greater than or equal to a preset level, the iteration number or the key length is increased.
[0009] Further, the man-in-the-middle attack detection on the one-time authorization authentication key includes: A quantum random challenge value is generated according to the user operation behavior characteristic code segment and the vibration frequency hash value; Response information generated by the boundary device according to the quantum random challenge value, the one-time authorization authentication key, the real-time signal strength and the electromagnetic interference level within a preset time is received; A detection result is generated according to the response information.
[0010] Further, the context information includes a basic parameter group, a dynamic variable group and an environment perception group, wherein the basic parameter group includes device physical position, network environment, running state and timestamp, the dynamic variable group includes recent 3 times of communication packet loss rate, signal strength fluctuation value and user operation behavior characteristic code; and the environment perception group includes electromagnetic interference intensity, temperature and humidity and vibration frequency.
[0011] The application also provides an authentication key generation device of a boundary device, including: A real-time context information acquisition module is configured to acquire real-time context information of the boundary device; A context feature value generation module is configured to generate a corresponding context feature value according to the real-time context information by using a national secret hash algorithm; An authentication key generation module is configured to take the context feature value, the packet loss rate threshold judgment result and the electromagnetic interference level as input data, combine a master root key and a random root key to perform key derivation operation, and generate a one-time authorization authentication key.
[0012] Further, the context feature value is generated according to the real-time context information by using the national secret hash algorithm, and includes: The real-time context information is preprocessed, the parameter weight in the real-time context information is adjusted, and first adjusted information is obtained; The parameter weight in the first adjusted information is calculated by improving the entropy method, and the second adjusted information is obtained by rearranging according to the parameter weight. The corresponding context feature value is generated according to the second adjusted information by using the national secret hash algorithm.
[0013] The application further provides a terminal device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, and when the computer program is executed by the processor, the authentication key generation method of the border device is realized.
[0014] The application further provides a computer readable storage medium, including a stored computer program, and when the computer program is executed, the device where the computer readable storage medium is located executes the authentication key generation method of the border device.
[0015] The application has the following beneficial effects: The application combines the master root key, the random root key, and the dynamic parameters such as the packet loss rate threshold judgment result and the electromagnetic interference level to perform key derivation operation, so that the generated one-time authorization authentication key has high randomness and unpredictability, can effectively avoid the occurrence of key reuse, and can effectively avoid the security risk of man-in-the-middle attack, and effectively improve the security of device authentication.
[0016] Further, the application generates a quantum random challenge value by combining the user operation behavior feature code segment and the vibration frequency hash value, so that the challenge value generated each time is highly random and unpredictable, so that the attacker is difficult to predict the challenge value through a preset mode or algorithm, thereby effectively preventing replay attacks and man-in-the-middle attacks, and improving the security and reliability of device authentication. BRIEF DESCRIPTION OF DRAWINGS
[0017] In order to more clearly illustrate the technical solutions of the present application, the following will briefly introduce the drawings needed in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application, and other drawings can also be obtained by those skilled in the art without creative labor.
[0018] Figure 1 is a flowchart of an authentication key generation method of a border device provided by an embodiment of the application; Figure 2 is a structural schematic diagram of an authentication key generation device of a border device provided by an embodiment of the application. DETAILED DESCRIPTION
[0019] In order to make the objects, technical solutions and advantages of the present application clearer, the following will clearly and completely describe the technical solutions in the present application in conjunction with the accompanying drawings of the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative work fall within the scope of protection of the present application.
[0020] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application belongs; the terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting of this application; the use of the terms "including," "comprising," "having" and "with" and any variations thereof in this specification and in the claims are intended to cover both the inclusive and exclusive cases.
[0021] In the description of the embodiments of the present application, the technical terms "first", "second", etc. are only used to distinguish different objects, and cannot be understood as indicating or implying relative importance or implicitly indicating the number, specific order or primary and secondary relationship of the indicated technical features. In the description of the embodiments of the present application, the meaning of "a plurality of" is two or more, unless otherwise explicitly and specifically limited.
[0022] Reference herein to "an embodiment" means that a particular feature, structure, or characteristic described in connection with the embodiment can be included in at least one embodiment of the present application. The appearance of the phrase in various places in the specification does not necessarily all refer to the same embodiment, nor is it necessarily independent or alternative embodiments to other embodiments. Those skilled in the art explicitly and implicitly understand that the embodiments described herein can be combined with other embodiments.
[0023] In the description of the embodiments of the present application, the term "and / or" is only a description of the association relationship of the associated objects, which means that there can be three relationships, for example, A and / or B, which can represent the three cases of A alone, A and B together, and B alone. In addition, the character " / " in this paper generally represents that the front and rear associated objects are a "or" relationship.
[0024] In the description of the embodiments of the present application, the term "a plurality of" refers to two or more (including two), and similarly, "a plurality of groups" refers to two or more groups (including two groups), and "a plurality of pieces" refers to two or more pieces (including two pieces).
[0025] In the description of the embodiments of this application, unless otherwise expressly specified and limited, technical terms such as "installation," "connection," "joining," and "fixing" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral part; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; they can refer to the internal communication of two components or the interaction between two components. For those skilled in the art, the specific meaning of the above terms in the embodiments of this application can be understood according to the specific circumstances.
[0026] See Figure 1 To address the security risks of key reuse and man-in-the-middle attacks inherent in existing technologies that generate keys using static or fixed-period key mechanisms, resulting in low security for device authentication, an embodiment of this invention provides a method for generating authentication keys for border devices, comprising: S1. Collect real-time context information of boundary devices; In this embodiment of the invention, a boundary device refers to a device deployed at the boundary of a network or system, used to implement functions such as network isolation, security control, and data monitoring. Boundary devices can be routers, gateways, etc.
[0027] The context information includes a basic parameter group, a dynamic variable group, and an environmental awareness group. The basic parameter group includes the device's physical location, network environment, operating status, and timestamp. The dynamic variable group includes the packet loss rate of the last three communications, signal strength fluctuation value, and user operation behavior feature code. The environmental awareness group includes electromagnetic interference intensity, temperature and humidity, and vibration frequency.
[0028] In this embodiment of the invention, the physical location of the device includes latitude and longitude coordinates, physical address of the access point, location movement rate, and movement trajectory entropy value.
[0029] S2. Use the national cryptographic hash algorithm to generate corresponding context feature values based on real-time context information; S3. Using context feature values, packet loss rate threshold judgment results, and electromagnetic interference level as input data, perform key derivation operations by combining the master root key and the random root key to generate a one-time authorization authentication key.
[0030] In this embodiment of the invention, during the key derivation operation, the number of iterations can be dynamically correlated with timestamps, temperature, signal strength fluctuations, electromagnetic interference intensity, and vibration frequency. When preset conditions are met, an exponential growth or quantum random doubling mechanism is triggered.
[0031] In this embodiment of the invention, packet loss rate refers to the proportion of data packets lost in network communication. The packet loss rate threshold judgment result refers to whether the packet loss rate in the current network environment exceeds a preset threshold. This can be achieved by using network monitoring tools to monitor network traffic in real time, statistically analyzing packet transmission and reception, and calculating the packet loss rate. A packet loss rate threshold (e.g., 5%) can be set according to the application scenario and security requirements. When the real-time monitored packet loss rate exceeds this threshold, the judgment result is "exceeds the threshold"; otherwise, it is "does not exceed the threshold." Electromagnetic interference level refers to the intensity or severity of electromagnetic interference in the environment in which the device is located, and can be divided into Level 1, Level 2, and Level 3 interference based on severity. Electromagnetic interference sensors are installed in the boundary device to monitor the electromagnetic environment around the device in real time. These sensors can measure parameters such as electromagnetic field strength and frequency distribution. Based on the sensor measurement data, electromagnetic interference is divided into three levels: Level 1, Level 2, and Level 3 interference. For example, an electromagnetic field strength below a certain threshold can be defined as Level 1 interference, between two thresholds as Level 2 interference, and exceeding a high threshold as Level 3 interference.
[0032] In this embodiment of the invention, the calculation rule for the number of iterations is as follows: Base iteration count: Initially 10,000 iterations, increasing by 500 iterations for each additional day (86,400 seconds) of timestamp, and adjusted based on the degree of temperature deviation from the normal range (increasing or decreasing by 50 iterations for every 5°C deviation). Signal strength and electromagnetic interference linkage: Increasing the iteration count by 200 iterations for every 10% increase in signal strength fluctuation beyond the baseline value; when the product of the fluctuation value and the electromagnetic interference intensity exceeds the safety threshold, the iteration count is reduced by a natural constant. It exhibits exponential growth from the bottom. Multi-parameter weighted sum triggering mechanism: When the weighted sum of packet loss rate, signal strength fluctuation value, and vibration frequency (with weights of 0.4, 0.3, and 0.3 respectively) exceeds the safety threshold, a random number from 1 to 5 is generated based on the built-in quantum random number generator in the hardware security module. The number of iterations doubled. Second-rate.
[0033] In this embodiment of the invention, it may also include dynamic variable correlation judgment, that is, real-time calculation of the multi-parameter correlation matrix between the dynamic variable group and the environmental perception group. When the absolute value of the Pearson correlation coefficient between the packet loss rate and the electromagnetic interference intensity is >0.7, and the absolute value of the Spearman correlation coefficient between the signal strength fluctuation and the temperature is >0.6, it is determined to be a composite anomaly, the quantum random root key is activated and a physical security alarm is triggered.
[0034] In this embodiment of the invention, the rules for calculating and determining the correlation coefficient of the multi-parameter correlation matrix are as follows: Pearson correlation coefficient: used to quantify the linear relationship between packet loss rate and electromagnetic interference intensity; the calculation formula is as follows: in The Pearson correlation coefficient represents the relationship between packet loss rate and electromagnetic interference intensity. The closer the absolute value is to 1, the stronger the linear correlation between the two. This represents the packet loss rate of the i-th sample (from the dynamic variable set); This represents the average packet loss rate for all samples. This represents the electromagnetic interference intensity value of the i-th sample (from the environmental perception group). This represents the average electromagnetic interference intensity of all samples.
[0035] Spearman correlation coefficient: used to quantify the nonlinear relationship between signal intensity fluctuations and temperature values; the calculation formula is as follows: in, The difference in ranks between the two sets of parameters. This represents the sample size.
[0036] Judgment condition: when If the condition is identified as a composite anomaly, the system will automatically switch to the quantum random root key and trigger a physical security alarm.
[0037] In this embodiment of the invention, after generating a one-time authorization authentication key, the boundary device can be authorized and authenticated based on the one-time authorization authentication key.
[0038] This invention combines the master root key, random root key, packet loss rate threshold judgment result, and electromagnetic interference level and other dynamic parameters to perform key derivation operations, so that the generated one-time authorization authentication key has a high degree of randomness and unpredictability, which can effectively avoid key reuse and thus effectively avoid the security risk of man-in-the-middle attacks, and effectively improve the security of device authentication.
[0039] In one embodiment, step S2, generating corresponding context feature values based on real-time context information using the national cryptographic hash algorithm, includes: S21. Preprocess the real-time context information, adjust the parameter weights in the real-time context information, and obtain the first adjusted information; In this embodiment of the invention, preprocessing may include: The 3σ criterion method is used to detect whether the parameters in the real-time implementation context information are abnormal. If there are abnormal network parameters, the weight of the network parameters is reduced to the first preset value; if there are abnormal physical parameters, the weight of the physical parameters is increased to the second preset value.
[0040] In this embodiment of the invention, a weight value corresponding to each set of parameters can be preset before preprocessing. The first preset value can be 30%, and the second preset value can be 20%.
[0041] In this embodiment of the invention, the detection process of the 3σ criterion method can be as follows: S211, Dynamic Standard Deviation Modeling: Calculates the real-time mean of parameters using a sliding window (default 30 periods). and standard deviation The window updates dynamically over time.
[0042] S212, Anomaly Detection Threshold: When the parameter value satisfy When the value is not found, it is considered an outlier.
[0043] S213. Differentiated weight adjustment: When network parameters (packet loss rate, signal strength) are abnormal, the weight is reduced to 30% of the normal weight; when physical parameters (temperature, vibration) are abnormal, the weight is increased by 20%, and an anomaly marker (type + confidence level) is embedded in the context feature value.
[0044] By dynamically adjusting the standard deviation based on historical data, we can avoid misjudging normal parameter drift during long-term equipment operation using fixed thresholds. At the same time, we can highlight the impact of abnormal physical environment through differentiated weight adjustments.
[0045] This invention employs an improved 3σ criterion to identify anomalous parameters through the dynamic standard deviation of historical data. It also performs differentiated weight adjustments for network-related (packet loss rate, signal strength) and physical-related (temperature, vibration) anomalies (network-related anomalies are reduced to 30%, physical-related anomalies are increased by 20%), while embedding anomaly markers into the feature values. This step is linked to the generation of contextual feature values, reducing interference from anomalous data on the key, making the generated key more reflective of the device's true security status, and lowering the authentication misjudgment rate caused by parameter noise.
[0046] S22. Calculate the parameter weights in the first adjusted information by improving the entropy method, and rearrange them according to the parameter weights to obtain the second adjusted information; In this embodiment of the invention, the calculation process of the improved entropy method includes: S221. Parameter standardization: Standardize the basic parameter set. Dynamic variable group Environmental Perception Group The parameter values are normalized to Intervals are used to eliminate the influence of different units of measurement. S222. Information Entropy Calculation: Based on the parameter standardization results, calculate the information entropy of each parameter. The lower the entropy value, the higher the parameter's distinctiveness and the greater its initial weight.
[0047] S223, Cross-group weighting adjustment: Introducing a dynamic variable group fluctuation correction factor, the calculation formula is as follows: ; Where f is the fluctuation correction factor for the dynamic variable group. It is an adjustment factor, CV max It is the preset maximum coefficient of variation threshold. The coefficient of variation is for the dynamic variable group; the weights of the environmental perception group are adjusted to... , The original weights for the environmental perception group. Adjust the weights for the environmental perception group. Simultaneously, proportionally adjust the weights of the other two groups to ensure the total weight sums to 1.
[0048] In this embodiment of the invention, the more drastic the fluctuations of the dynamic variable group (such as packet loss rate and signal strength), the larger the correction factor and the higher the weight of the environmental perception group (such as temperature and vibration), so as to achieve dynamic adjustment of "strengthening the influence of physical environment parameters when the network state is unstable".
[0049] S23. Using the national cryptographic hash algorithm, generate the corresponding context feature value based on the second adjusted information.
[0050] The improved entropy method of this invention can dynamically adjust parameter weights according to changes in real-time context information, thereby better adapting to changes in different environments and device states during the key generation process and effectively improving the reliability of key generation.
[0051] In one embodiment, after step S3, using context feature values, packet loss rate threshold judgment results, and electromagnetic interference level as input data, and performing key derivation operations with the master root key and random root key to generate a one-time authorization authentication key, the method further includes: S4. Perform man-in-the-middle attack detection on the one-time authorization authentication key. When the packet loss rate exceeds the limit and the electromagnetic interference is greater than or equal to the preset level, increase the number of iterations or the key length.
[0052] Among these measures, man-in-the-middle attack detection is performed on one-time authorization authentication keys, including: S41. Generate a quantum random challenge value based on the user's operation behavior feature code fragment and vibration frequency hash value; S42. Receive response information generated by the boundary device within a preset time based on the quantum random challenge value, one-time authorization authentication key, real-time signal strength, and electromagnetic interference level; S43. Generate detection results based on the response information.
[0053] In this embodiment of the invention, a dynamic threshold is used when verifying the response: the verification threshold is increased by 20% when the signal strength fluctuation difference exceeds 5%, and an additional 30% is increased when the electromagnetic interference level increases by more than 1 level. A tiered penalty is applied when verification fails: the first failure is only logged; when the number of consecutive failures is positively correlated with the square of the packet loss rate, the key is revoked and the device lockout time is extended by the square of the number of failures (up to 60 minutes).
[0054] In this embodiment of the invention, the challenge value is embedded with the user's operation feature code and vibration frequency hash. The response time decreases with temperature, the verification threshold fluctuates with signal strength, and the electromagnetic interference level is dynamically adjusted (e.g., the threshold increases by 30% when electromagnetic interference escalates). The failure penalty is positively correlated with the square of the packet loss rate. This deep integration with prior parameter acquisition and weight calculation enables attack detection to be environmentally adaptable, accurately identifying man-in-the-middle attacks in complex scenarios while avoiding misjudgments. The penalty intensity matches the risk level, thereby effectively improving the intelligence level of defense.
[0055] In one embodiment, hardware physical features extracted by the PUF circuit can also be used as hidden inputs when performing key derivation operations. These features change dynamically with slight variations in temperature and voltage, and the generated key contains the irreversible hash value of these features.
[0056] Furthermore, it also includes setting an adaptive multi-level lifecycle for the key: the basic validity period is bound to a timestamp, the number of operations is limited to 1, the environmental variable association period is associated with signal strength fluctuations, and the physical security period is associated with vibration frequency. When the vibration frequency exceeds the limit, the lifecycle is forcibly compressed to 30% of the original validity period.
[0057] The adaptive multi-level lifecycle links key validity with timestamps, number of operations, signal strength fluctuations, and vibration frequency. In particular, when the vibration frequency exceeds the limit, it forcibly compresses the key to 30% of its original validity. This mechanism is linked with S1's environmental awareness group data and anomaly markers, making the key's "survival" entirely dependent on the device's security status. Once the physical environment (such as severe vibration, which may indicate device tampering) or network status becomes abnormal, the key immediately becomes invalid, eliminating the risk of key abuse in insecure scenarios from a time perspective.
[0058] Furthermore, embodiments of the present invention also include the ability to establish a blockchain-based key usage log: recording the key generation time, context information digest, real-time values of three sets of parameters and usage status. The log is stored in a chain and contains environmental awareness group digital fingerprints. It can only be read and written through the internal interface of the hardware security module. When updating, it is necessary to verify the consistency between the user operation behavior feature code and the electromagnetic interference intensity.
[0059] In this invention, the hardware physical characteristics extracted by the PUF circuit (dynamically changing with temperature and voltage) serve as the key hiding input, uniquely binding the key to the device's physical attributes (making it impossible to copy). The blockchain-based log, through chained storage and environmentally aware digital fingerprinting, ensures the key's traceability throughout its entire lifecycle. The combination of these two elements forms a closed loop of "physical layer unclonable + logical layer immutable," preventing key forgery and providing reliable evidence for tracing security incidents. This effectively solves the problems of easily tampered logs and the unbinding of keys from devices in traditional systems.
[0060] This invention generates quantum random challenge values by combining user operation behavior feature code fragments and vibration frequency hash values. This makes each generated challenge value highly random and unpredictable, making it difficult for attackers to predict the challenge value through preset patterns or algorithms. This effectively prevents replay attacks and man-in-the-middle attacks, and improves the security and reliability of device authentication.
[0061] In one embodiment, the overall process for generating the key can be as follows: Phase 1: Multi-dimensional information collection (triggering condition: authorization request initiated).
[0062] Parameter acquisition: Basic parameter group: latitude and longitude, access point address, location movement rate, network protocol type, CPU utilization, timestamp, etc. are collected through location sensors, network interfaces, and device monitoring modules.
[0063] Dynamic variable group: The packet loss rate and signal strength fluctuation value of the most recent 3 communications are obtained through the communication analyzer, and the operation behavior feature code (such as operation sequence hash) is extracted through the user interface.
[0064] Environmental Sensing Group: Collects electromagnetic interference intensity (level 1-5), temperature, humidity, and vibration frequency through electromagnetic sensors, thermometers, hygrometers, and vibration sensors.
[0065] Data aggregation: The three types of parameters are aggregated into a raw dataset, and the collection timestamp is marked to ensure that the time synchronization accuracy is ≤1ms.
[0066] Phase 2: Preprocessing and Feature Value Generation.
[0067] Outlier filtering (improved 3σ criterion): A dynamic standard deviation model is constructed based on the equipment's historical data over the past 90 days to calculate the real-time mean. with standard deviation .
[0068] If the parameter value satisfies This is considered abnormal. Network parameters (packet loss rate, signal strength): weights reduced to 30% of normal weights, and "network anomaly" flags embedded.
[0069] Physical parameters (temperature, vibration): weight increased by 20%, and anomaly confidence (e.g., "high confidence physical anomaly").
[0070] Weight calculation (improved entropy method): Calculate the information entropy of the three sets of parameters. The lower the entropy value, the higher the weight (initial weight allocation).
[0071] Environmental perception group weight adjustment: CV(Y) is the coefficient of variation (standard deviation / mean) of the dynamic variable group. The more drastic the network fluctuations, the higher the weight of the environment perception group.
[0072] Eigenvalue generation: All parameters (including anomaly markers) are concatenated in descending order of weight.
[0073] Context feature values are generated using the national cryptographic SM3 algorithm. The initial vector is composed of device hardware identifier (such as CPU serial number), real-time mean of dynamic variable group, and anomaly marker of environmental perception group.
[0074] Phase 3: HSM key derivation and generation.
[0075] Input parameter preparation: Core inputs: context feature values, packet loss rate threshold judgment result (whether it exceeds the preset threshold, such as 10%), and electromagnetic interference level.
[0076] Root key selection: In normal scenarios (packet loss rate not exceeding the limit or electromagnetic interference < level 3): use the master root key.
[0077] High-risk scenarios (packet loss rate exceeds the limit and electromagnetic interference ≥ level 3): Automatically switch to quantum random root key, improving the derivation complexity coefficient by 50%.
[0078] Key derivation operations: Basic iteration count = 10000 + (timestamp days × 500) ± (temperature deviation correction value, ±50 times for every 5℃ deviation).
[0079] Enhanced iteration: Increase the number of iterations by 200 for every 10% increase in signal strength fluctuation beyond the baseline value; if the fluctuation value × electromagnetic interference level > safety threshold, the number of iterations is increased accordingly. Exponential growth (α is the excess volatility ratio).
[0080] Quantum random number doubling: If the weighted sum of packet loss rate, signal strength fluctuation, and vibration frequency exceeds the security threshold, a random number between 1 and 5 is generated based on the built-in quantum random number generator in the hardware security module. The number of iterations doubled. times.
[0081] PUF Enhancement: Extract the physical characteristic parameters of the device's PUF circuit (which vary slightly with temperature and voltage) and use them as hidden inputs for the derived function.
[0082] The generated one-time authorization key contains an irreversible hash value of the physical characteristic (ensuring unique binding to the device).
[0083] Phase 4: Security Mechanisms and Verification Man-in-the-middle attack detection: HSM generates quantum random challenge values, embedding user operation behavior feature code fragments and vibration frequency hash values.
[0084] Boundary devices must respond within the temperature-controlled time (response time is reduced by 10% for every 10°C increase in temperature). The response information = challenge value + current key + real-time signal strength + electromagnetic interference level.
[0085] Verification threshold is dynamically adjusted: when the signal strength fluctuation difference is greater than 5%, the threshold is increased by 20%; when the electromagnetic interference level increases by more than 1 level, the threshold is increased by an additional 30%.
[0086] Penalty mechanism: The first failure is only logged; when the number of consecutive failures is positively correlated with the square of the packet loss rate, the key is revoked and the device is locked for a period equal to the number of failures² (maximum 60 minutes).
[0087] Dynamic variable association judgment: HSM calculation of multi-parameter correlation matrix: Pearson correlation coefficient between packet loss rate and electromagnetic interference intensity .
[0088] Spearman correlation coefficient between signal strength fluctuation and temperature .
[0089] If the above conditions are met, it is determined to be a composite anomaly, and the device is immediately switched to the quantum random root key, triggering a local audio-visual alarm.
[0090] Adaptive multi-level lifecycle: Basic validity period: bound to a timestamp (e.g., 1 hour).
[0091] Number of uses: Only 1 use allowed.
[0092] Environmental correlation period: The signal will fail immediately if the signal strength fluctuation exceeds the preset range.
[0093] Physical safety period: When the vibration frequency exceeds the range, the lifespan is compressed to 30% of the original effective period.
[0094] Phase 5: Blockchain-based log recording.
[0095] Log content includes: key generation time, context feature value summary, real-time values of three sets of parameters, usage status (success / failure), exception marker, and PUF feature hash.
[0096] Storage rules: A chained storage structure is adopted, and each block contains the hash of the previous block and the environment-aware group digital fingerprint (SM3 hash).
[0097] Access control: Reading and writing are only allowed through the internal HSM interface. Log updates require verification of the consistency between the user operation behavior signature code and the electromagnetic interference intensity.
[0098] Phase 6: Output Results.
[0099] Verification successful: "Authorization successful" is returned, allowing the device to perform the requested operation.
[0100] Verification failed: Returns "Authorization failed", triggers key revocation and device locking, and logs the reason for failure.
[0101] Implementing the embodiments of the present invention has the following beneficial effects: This invention combines the master root key, random root key, packet loss rate threshold judgment result, and electromagnetic interference level and other dynamic parameters to perform key derivation operations, so that the generated one-time authorization authentication key has a high degree of randomness and unpredictability, which can effectively avoid key reuse and thus effectively avoid the security risk of man-in-the-middle attacks, and effectively improve the security of device authentication.
[0102] Furthermore, this embodiment of the invention generates quantum random challenge values by combining user operation behavior feature code fragments and vibration frequency hash values, making each generated challenge value highly random and unpredictable. This makes it difficult for attackers to predict the challenge values using preset patterns or algorithms, thereby effectively preventing replay attacks and man-in-the-middle attacks and improving the security and reliability of device authentication.
[0103] like Figure 2 As shown, based on the above method embodiments, corresponding apparatus embodiments are provided; An embodiment of the present invention provides an authentication key generation device for a border device, comprising: Real-time context information acquisition module 10 is used to acquire real-time context information of boundary devices; The context feature value generation module 20 is used to generate corresponding context feature values based on real-time context information using the national cryptographic hash algorithm. The authentication key generation module 30 is used to generate a one-time authorization authentication key by taking the context feature value, the packet loss rate threshold judgment result and the electromagnetic interference level as input data, and combining the master root key and the random root key to perform key derivation operation.
[0104] In one embodiment, a national cryptographic hash algorithm is used to generate corresponding context feature values based on real-time context information, including: The real-time context information is preprocessed, and the parameter weights in the real-time context information are adjusted to obtain the first adjusted information; The parameter weights in the first adjusted information are calculated by improving the entropy method, and the second adjusted information is obtained by rearranging the parameters according to the parameter weights. The national cryptographic hash algorithm is used to generate the corresponding context feature value based on the second adjusted information.
[0105] In one embodiment, the real-time context information is preprocessed to adjust the parameter weights in the real-time context information, resulting in first adjusted information, including: The 3σ criterion method is used to detect whether the parameters in the real-time implementation context information are abnormal. If there are abnormal network parameters, the weight of the network parameters is reduced to the first preset value; if there are abnormal physical parameters, the weight of the physical parameters is increased to the second preset value.
[0106] In one embodiment, after using context feature values, packet loss rate threshold judgment results, and electromagnetic interference levels as input data, and performing key derivation operations by combining the master root key and the random root key to generate a one-time authorization authentication key, the method further includes: Man-in-the-middle attack detection is performed on the one-time authorization authentication key. When the packet loss rate exceeds the limit and the electromagnetic interference is greater than or equal to the preset level, the number of iterations or the key length is increased.
[0107] In one embodiment, man-in-the-middle attack detection of a one-time authorization authentication key includes: A quantum random challenge value is generated based on user operation behavior feature code fragments and vibration frequency hash values; The receiving boundary device generates response information based on the quantum random challenge value, one-time authorization authentication key, real-time signal strength, and electromagnetic interference level within a preset time. The detection results are generated based on the response information.
[0108] In one embodiment, the context information includes a basic parameter group, a dynamic variable group, and an environmental awareness group. The basic parameter group includes the device's physical location, network environment, operating status, and timestamp. The dynamic variable group includes the packet loss rate of the last three communications, signal strength fluctuation value, and user operation behavior feature code. The environmental awareness group includes electromagnetic interference intensity, temperature and humidity, and vibration frequency.
[0109] It is understood that the above-described device embodiments correspond to the method embodiments of the present invention, and can implement the authentication key generation method for boundary devices provided by any of the above-described method embodiments of the present invention.
[0110] It should be noted that the device embodiments described above are merely illustrative, and some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, in the accompanying drawings of the device embodiments provided by this invention, the connection relationships between modules indicate that they have communication connections, which can specifically be implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement this without any creative effort.
[0111] Based on the above-described embodiments of the authentication key generation method for border devices, another embodiment of the present invention provides a terminal device, which includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the authentication key generation method for border devices according to any embodiment of the present invention.
[0112] For example, in this embodiment, the computer program can be divided into one or more modules, one or more modules are stored in memory and executed by a processor to complete the present invention. One or more module elements can be a series of computer program instruction segments capable of performing a specific function, which describe the execution process of the computer program in a terminal device.
[0113] Terminal devices can be computing devices such as desktop computers, laptops, handheld computers, and cloud servers. Terminal devices may include, but are not limited to, processors and memory.
[0114] The processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor. The processor is the control center of the terminal device, connecting all parts of the terminal device through various interfaces and lines.
[0115] Based on the above-described method embodiments, another embodiment of the present invention provides a computer-readable storage medium including a stored computer program, wherein, when the computer program is running, it controls the device where the computer-readable storage medium is located to execute the authentication key generation method of the boundary device of any of the above-described method embodiments of the present invention.
[0116] The modules / units integrated into the device / terminal equipment, if implemented as software functional units and sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, all or part of the processes in the methods of the above embodiments of the present invention can also be implemented by a computer program instructing related hardware. The computer program can be stored in a computer-readable storage medium, and when executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable files, or certain intermediate forms. The computer-readable medium can include: any entity or device capable of carrying computer program code, recording media, USB flash drives, portable hard drives, magnetic disks, optical disks, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc.
[0117] The above are preferred embodiments of the present invention. It should be noted that, for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications are also considered to be within the scope of protection of the present invention.
Claims
1. A method for generating authentication keys for a border device, characterized in that, include: Collect real-time context information of boundary devices; The national cryptographic hash algorithm is used to generate corresponding context feature values based on the real-time context information; Using the context feature value, packet loss rate threshold judgment result, and electromagnetic interference level as input data, a key derivation operation is performed by combining the master root key and the random root key to generate a one-time authorization authentication key.
2. The authentication key generation method for border devices as described in claim 1, characterized in that, The process of using the national cryptographic hash algorithm to generate corresponding context feature values based on the real-time context information includes: The real-time context information is preprocessed, and the parameter weights in the real-time context information are adjusted to obtain the first adjusted information. The parameter weights in the first adjusted information are calculated by an improved entropy method, and the second adjusted information is obtained by rearranging the parameters according to the parameter weights. Using the national cryptographic hash algorithm, a corresponding context feature value is generated based on the second adjusted information.
3. The authentication key generation method for border devices as described in claim 2, characterized in that, The step of preprocessing the real-time context information and adjusting the parameter weights in the real-time context information to obtain the first adjusted information includes: The 3σ criterion is used to detect whether the parameters in the real-time implementation context information are abnormal. If there are abnormal network parameters, the weight of the network parameters is reduced to a first preset value; if there are abnormal physical parameters, the weight of the physical parameters is increased to a second preset value.
4. The authentication key generation method for border devices as described in claim 1, characterized in that, After generating a one-time authorization authentication key by performing key derivation operations using the context feature value, packet loss rate threshold judgment result, and electromagnetic interference level as input data, combined with the master root key and random root key, the process further includes: The one-time authorization authentication key is subjected to man-in-the-middle attack detection. When the packet loss rate exceeds the limit and the electromagnetic interference is greater than or equal to the preset level, the number of iterations or the key length is increased.
5. The authentication key generation method for border devices as described in claim 1, characterized in that, The man-in-the-middle attack detection of the one-time authorization authentication key includes: A quantum random challenge value is generated based on user operation behavior feature code fragments and vibration frequency hash values; The receiving boundary device generates response information based on the quantum random challenge value, the one-time authorization authentication key, the real-time signal strength, and the electromagnetic interference level within a preset time. The detection result is generated based on the response information.
6. The authentication key generation method for border devices as described in claim 1, characterized in that, The context information includes a basic parameter group, a dynamic variable group, and an environmental awareness group. The basic parameter group includes the device's physical location, network environment, operating status, and timestamp. The dynamic variable group includes the packet loss rate of the last three communications, signal strength fluctuation value, and user operation behavior feature code. The environmental awareness group includes electromagnetic interference intensity, temperature and humidity, and vibration frequency.
7. An authentication key generation device for a border device, characterized in that, include: The real-time context information acquisition module is used to acquire real-time context information of the boundary devices; The context feature value generation module is used to generate corresponding context feature values based on the real-time context information using the national cryptographic hash algorithm. The authentication key generation module is used to generate a one-time authorization authentication key by taking the context feature value, packet loss rate threshold judgment result and electromagnetic interference level as input data, and combining the master root key and the random root key to perform key derivation operation.
8. The authentication key generation device for a border device as described in claim 7, characterized in that, The process of using the national cryptographic hash algorithm to generate corresponding context feature values based on the real-time context information includes: The real-time context information is preprocessed, and the parameter weights in the real-time context information are adjusted to obtain the first adjusted information. The parameter weights in the first adjusted information are calculated by an improved entropy method, and the second adjusted information is obtained by rearranging the parameters according to the parameter weights. Using the national cryptographic hash algorithm, a corresponding context feature value is generated based on the second adjusted information.
9. A terminal device, characterized in that, The device includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, it implements the authentication key generation method for a border device as described in any one of claims 1-6.
10. A computer-readable storage medium, characterized in that, include: A stored computer program, wherein, when the computer program is executed, it controls the device containing the computer-readable storage medium to perform the authentication key generation method for a border device as described in any one of claims 1-6.