Low-interaction secure handshake method, device and system based on spatio-temporal context constraint, order deviation extraction and polarity hedging verification, chip and storage medium
By combining local physical feature anchors, spatiotemporal context, and simulated front-end polarity offset verification, a low-interaction security handshake method is proposed, which solves the problem of security determination relying on external logical credentials in existing technologies. This method achieves efficient security handshake and fine-grained control, thereby improving the security and availability of network communication.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-03-09
- Publication Date
- 2026-04-14
AI Technical Summary
The existing network communication and device access security system relies on explicit key exchange, certificate chain verification, static credentials and password factors. It has problems such as over-reliance on external logical credentials for identity and session security determination, high session establishment interaction costs, easy replay or simulation of context information, lack of layered control over boundary mismatch states, and difficulty in balancing security and availability in high-value scenarios and controlled access scenarios.
A low-interaction security handshake method based on local physical feature anchors, spatiotemporal context, and simulated front-end polarity offset verification is adopted. By extracting local physical feature anchors, obtaining spatiotemporal context related to the current session, generating sequence offset parameters, constructing session mapping factors, and performing polarity offset verification, differential matching, and closure audit at the receiving or verifying end, multi-value state processing is achieved.
It improves the anti-replay and anti-spoofing capabilities of secure handshakes, supports low-interaction handshakes without explicit transmission of long-term keys, adapts to one-way triggering and implicit acknowledgment, reduces the chance of invalid payloads entering higher-level logic, achieves fine-grained boundary control, and enhances the ability to resist high-frequency probing and differential analysis.
Smart Images

Figure FT_1 
Figure FT_2 
Figure FT_3
Abstract
Description
Technical Field
[0001] This invention relates to the fields of network security communication, device authentication, trusted access control, hardware security, analog-digital hybrid verification, payment and settlement security, private network access control, and in-memory computing security processing. In particular, it relates to a low-interaction security handshake and admission control technology solution that combines local device physical characteristics, spatiotemporal context, sequence deviation extraction, and analog front-end polarity offset verification. Background Technology
[0002] Existing network communication and device access security systems typically rely on explicit key exchange, certificate chain verification, static credentials, password factors, or external security software logic to implement session establishment and access control. While these solutions have reached a high level of maturity in many scenarios, they still have several shortcomings.
[0003] First, existing solutions rely heavily on logical credentials independent of the physical state of specific devices for identity and session security determination. If these credentials are copied, replayed, forged, or reused on unauthorized devices, in unauthorized locations, or during unauthorized time windows, the system still needs to rely on higher-level protection mechanisms for remediation, thus increasing implementation complexity.
[0004] Secondly, the traditional secure handshake process involves numerous interaction rounds in some scenarios, making it less suitable for high real-time services, restricted links, wide-area heterogeneous links, edge devices, and offline scenarios. Especially in high-value services, short-window access, or controlled access to private networks, the additional interactions and explicit key processing introduce a probe surface, a state exposure surface, and an implementation burden.
[0005] Third, many existing security controls mainly occur at the digital logic layer, protocol stack layer, or application layer. Even if there are exploitable physical differences and environmental coupling characteristics in the underlying devices, these characteristics are often not effectively incorporated into the session establishment and access admission chain, resulting in the system lacking integrated constraints of "device-environment-time-historical state".
[0006] Fourth, for scenarios such as high-value bank operations, spatiotemporal window access for private network terminals, offline signatures, restricted resource access, and controlled model loading, relying solely on passwords, certificates, or single-time logic verification is insufficient to simultaneously meet the requirements of low interaction, high availability, anti-replay, anti-reproducibility, and anti-high-frequency probing.
[0007] Fifth, many existing systems still rely on binary "pass / fail" logic for input judgment, making it difficult to develop finer-grained protection strategies for boundary conditions, weak mismatch states, and high-frequency probing behaviors. This allows attackers to exploit boundary feedback, power consumption differences, retry opportunities, or sampling correlations to gradually approach the allowance conditions. Explanation of differences from existing technologies
[0008] Existing physically unclonable function-based solutions primarily utilize device manufacturing deviations to generate physical fingerprints or challenge-response relationships, focusing on extracting device-related features. This invention goes beyond simply extracting physical features; it incorporates local physical feature anchors and spatiotemporal context into the session-level sequence deviation generation chain, and further performs in-situ polarity offset verification at the simulation front end, ensuring that device state, environmental conditions, session history, and current load all participate in closed-loop auditing. Therefore, this invention is substantially different from solutions that rely solely on static physical features of the device.
[0009] Existing low-interaction authentication protocols focus on reducing handshake rounds, compressing challenge-response processes, or lowering computational complexity, with the main decision-making process still occurring at the digital logic layer. In contrast, this invention, besides enabling unidirectional triggering, single round trips, or implicit confirmation, decentralizes key decision-making actions to the analog front-end. Matching results are formed through in-situ physical superposition, cancellation, integration, comparison, or leakage, and the subsequent logical branch is determined by a multi-valued state processing unit. Therefore, this invention differs fundamentally from purely logic-layer low-interaction protocols.
[0010] Existing context-aware authentication methods often use factors such as time, location, and device status as digital tags for comparison or as additional factors in calculations. This invention, however, preferably uses spatiotemporal context to act on the readout path, threshold path, integration path, or gating path through hardware-environment coupling, causing it to first change the device response and then participate in sequence offset generation and closure auditing. Therefore, this invention does not simply superimpose context onto the original authentication process, but establishes a causal chain of "context—hardware response—sequence offset—analog front-end hedging".
[0011] Therefore, it is necessary to propose a new technical solution that enables secure handshake and access control to no longer rely solely on upper-layer logic credentials, but further introduces local device physical characteristics, spatiotemporal context, session history, and analog front-end in-situ offset verification mechanism to form a low-interaction security closed loop with physical-logical collaboration. Purpose of the invention
[0012] The purpose of this invention is to provide a low-interaction secure handshake method, device, system, chip, and storage medium based on spatiotemporal context constraints, sequence deviation extraction, and polarity offset verification, so as to at least partially solve the following problems existing in the prior art: security determination relies too much on external logical credentials, lack of device physical root constraints, high session establishment interaction cost, context information is easily replayed or simulated, lack of hierarchical control over boundary mismatch states, and difficulty in balancing security and usability in high-value scenarios and controlled access scenarios. Technical solution
[0013] To achieve the above objectives, this invention proposes a platform-based technical solution. This solution uses local physical feature anchors as the device-side foundation, spatiotemporal context as the environment and operational-side foundation, sequence deviation parameters as the session binding hub, simulated front-end polarity offset verification as the physical-logic interface, and multi-value state processing as the final release, restricted release, or blocking control mechanism.
[0014] In one aspect, the present invention provides a low-interaction secure handshake method, comprising: extracting local physical feature anchors; obtaining spatiotemporal context related to the current session; generating sequence offset parameters based on the nonlinear distribution of local physical feature anchors, spatiotemporal context, and the state of physical nodes within the device; constructing a session mapping factor based on the sequence offset parameters and performing constraint mapping on the payload to be processed; performing polarity offset verification, differential matching, residual auditing, or closure auditing at the analog front end of the receiving end, verification end, or local processing end; entering a fully matched state, a partially matched state, or a non-matched state according to the matching result, and performing at least one of session establishment, access admission, payload recovery, restricted release, fuzziness suppression, or blocking zeroing.
[0015] In another aspect, the present invention provides a safety device, system, or chip, comprising: a hardware unit for extracting local physical feature anchor points; a processing unit for acquiring and coupling spatiotemporal context; a computation unit for generating sequence deviation parameters; an encoding unit for projecting and constraining the load; a verification unit for performing polarity offset verification at the simulation front end; a state control unit for performing multi-valued state processing; and a control unit for performing anomaly handling and summary maintenance.
[0016] In another aspect, the present invention also provides a computer-readable storage medium having a program stored thereon, which, when executed by a processor, implements the steps of parameter configuration, context management, threshold control, state transition, exception summary recording, and policy scheduling in the aforementioned method. Platform co-core
[0017] The core of this invention is not in a single industry scenario, but in a unified platform mechanism: by utilizing the physical characteristics of local devices, spatiotemporal context, sequence deviation, and analog front-end polarity hedging, security determination is extended from simple logical authorization to a closed audit structure involving device status, environmental conditions, session history, and current load. Explanation of the mechanism of technical effect formation
[0018] The technical effect of this invention stems from the synergistic effect of multiple causal chains. Local physical feature anchors provide device-side basic constraints for the system, enabling the same logic input to correspond to different local reference conditions on different devices; spatiotemporal context provides environment-side and operational-side constraints for the system, ensuring that the current session no longer exists independently of specific time, region, environment, and historical state; sequence deviation parameters transform local physical feature anchors and spatiotemporal context into binding parameters, residual parameters, or mapping parameters that can be used for the current session; simulated front-end polarity offset verification further transforms the above binding parameters into an in-situ physical screening process, allowing the verification results to directly affect subsequent logic branches; and the multi-valued state processing mechanism separates and processes perfect matches, boundary mismatches, and obvious mismatches, thereby improving security while maintaining a certain level of engineering usability.
[0019] Therefore, the technical effect of this invention does not come from the isolated superposition of a single module, but from the overall synergy of a continuous causal chain of "device physical root - environment coupling root - session deviation root - analog front-end closure audit - multi-value state control". Effect
[0020] Extending the security foundation from pure logic credentials to the physical roots of devices and the coupling roots of the environment increases the difficulty of off-site reproduction, replay, and counterfeiting.
[0021] It supports low-interaction handshakes that do not require explicit transmission of long-term keys, and is adaptable to one-way triggering, one-way round trip, implicit acknowledgment, and restricted link scenarios.
[0022] By simulating in-situ polarity offset verification at the front end, the verification result can directly control the selection, restriction, or truncation of logic branches, reducing the chance of invalid loads entering higher-level logic.
[0023] By processing multi-valued states—fully matched, partially matched, and unmatched—fine-grained control under boundary conditions is achieved, and the ability to counter high-frequency probing, differential analysis, and side-channel sampling is improved.
[0024] By splitting the payload asymmetrically, the complete causal chain can be distributed among the local end, the receiver, or the verification end, reducing the risk of a single point of interception leading to a complete recovery.
[0025] It can be deployed in parallel with existing certificate systems, password systems, token systems, and private network authentication systems as an underlying security enhancement layer, without requiring a complete replacement of the existing infrastructure.
[0026] It is suitable for various scenarios such as high-value bank operations, payment and settlement authentication, spatiotemporal window access for government / private network terminals, offline signature, restricted resource access, and model integrity verification. Attached Figure Description
[0027] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the embodiments will be briefly described below. It should be understood that the following drawings are merely illustrative, and those skilled in the art can obtain other forms of drawings based on these drawings without creative effort.
[0028] Figure 1 is a block diagram of the overall structure of the platform of the present invention.
[0029] Figure 2 is a flowchart of the basic low-interaction secure handshake of the present invention.
[0030] Figure 3 is a flowchart of the local physical feature anchor point extraction process.
[0031] Figure 4 is a flowchart of spatiotemporal context acquisition and hardware-environment coupling.
[0032] Figure 5 is a flowchart of the sequence deviation generation process.
[0033] Figure 6 is a flowchart of load projection and constraint coding.
[0034] Figure 7 is a block diagram of the analog front-end polarity offset verification circuit.
[0035] Figure 8 is a schematic diagram of a ternary / multi-valued matching state machine.
[0036] Figure 9 is a structural block diagram of a constrained handshake implementation example in a banking scenario.
[0037] Figure 10 is a structural block diagram of an implementation example of spatiotemporal window access for government / private network terminals. Detailed Implementation
[0038] The technical solution of the present invention will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the embodiments described herein are only for explaining the present invention and are not intended to limit the scope of protection of the present invention. All equivalent substitutions, modifications, deletions, and combinations made within the spirit and principle of the present invention should be included within the scope of protection of the present invention. Terminology Definition
[0039] Local Physical Feature Anchors: As used in this specification, "local physical feature anchors" refer to device-related characteristics formed by the state parameters of multiple physical nodes within the hardware carrier, which can be used for subsequent mapping, verification, auditing, or control. These state parameters may include at least one of conductivity state, resistance state, polarization state, leakage current state, threshold voltage state, oscillation state, and their derived parameters. The local physical feature anchors can originate from natural differences caused by manufacturing deviations, or from stable or semi-stable distribution characteristics jointly formed by aging, thermal noise disturbances, readout deviations, and environmental coupling responses. In this invention, the local physical feature anchors are not required to be absolutely constant at all times, but are required to have repeatability and sufficient distinguishability under preset time windows, readout conditions, or verification conditions.
[0040] Spatiotemporal context: As used in this specification, "spatiotemporal context" refers to a combination of time, space, environment, operational status, and historical information related to the current session, access, authentication, deblocking, payload recovery, or instruction execution. The spatiotemporal context may include at least one of the following: timestamp, time window identifier, location information, relative displacement information, oscillator drift parameters, temperature parameters, acceleration parameters, gravity perturbation parameters, power supply perturbation parameters, link status parameters, historical handshake digests, historical access digests, and previous session residual digests. In one embodiment of this invention, the spatiotemporal context does not simply participate in calculations as an external digital tag, but rather participates in the generation of subsequent sequence bit deviations by forming a bias, perturbation, or modulation of array readout behavior through the coupling response of the hardware carrier and environmental physical quantities.
[0041] Sequence bias: As used in this specification, "sequence bias" refers to a deviation quantity, deviation vector, deviation sequence, or deviation constraint that is jointly determined by the local physical feature anchor point, spatiotemporal context, and the nonlinear distribution of the physical node states within the hardware carrier, and can be used for subsequent load mapping, polarity offset verification, closure auditing, and logic branch control. The sequence bias can be formed through mapping combination, weighted superposition, differential calculation, segmented quantization, threshold transformation, sequence expansion, matrix projection, residual compression, or state switching. Sequence bias is not equivalent to a single time difference or a single position difference, but rather a comprehensive deviation reflecting the relative relationship between device state, context conditions, and session history.
[0042] Implementation of the sequence deviation parameter: In engineering implementation, the sequence deviation parameter is not limited to a single mathematical representation. It can be expressed as a vector form, residual form, mapping matrix form, multi-valued state index form, polarity constraint sequence form, local mapping mask form, or a combination of the above forms. Different representations can be used for load projection, threshold adjustment, state partitioning, segmented recovery, or local constraint preservation. As long as it can reflect the binding relationship between the local physical feature anchor point and the spatiotemporal context to the current session, and can be used by subsequent polarity offset verification or closure audit, it can be regarded as an implementation of the sequence deviation parameter in this invention.
[0043] Session mapping factor: As used in this specification, "session mapping factor" refers to a set of parameters derived from sequence deviation used to bind the load to be processed to the current session. The session mapping factor can be represented as at least one of the following: deviation vector, residual parameter, mapping matrix, multi-valued state index, and polarity constraint sequence. The session mapping factor can be directly applied to the construction of the handshake load, or used to control the verification parameters, gating path, integration window, or comparison threshold of the simulation front end.
[0044] Polarity offsetting: As used in this specification, "polarity offsetting" refers to the process at the analog front-end of the receiving end, verification end, or local processing end, where in-situ physical superposition or cancellation is performed on the load, mapping factor, residual parameter, or their derived signals related to the current session to determine whether they meet preset matching conditions. Polarity offsetting can be achieved through differential bit line current superposition, differential word line voltage cancellation, cross-node charge sharing, local grounding discharge, charge pump-driven threshold verification, comparison amplification, integration threshold determination, or residual threshold auditing, etc. The output of polarity offsetting directly determines the selection, restriction, or truncation of subsequent logic branches; therefore, it is not simply a software determination, but a causal interface between the analog domain and the logic domain.
[0045] Closure Audit: As used in this specification, "closure audit" refers to the process of verifying the consistency between the payload to be processed, local physical feature anchors, spatiotemporal context, sequence deviation, session mapping factor, and simulation front-end hedging results. When the above factors meet the causal closure condition within the preset tolerance range, the system determines that it can be allowed; otherwise, it determines that it needs to be restricted, blocked, cleared, reduced, or enter a restricted mode. Closure audit can be performed within a single device or collaboratively between the sender, receiver, and verifier.
[0046] Matching Results: The term "matching results" in this specification includes at least three categories: fully matched, partially matched, and mismatched. A fully matched state corresponds to the load to be processed meeting the preset release conditions with the current session constraints; a partially matched state corresponds to a weak mismatch where the residual parameters are within a preset range; and a mismatched state corresponds to a state where the residual parameters exceed the preset tolerance or a critical constraint is missing. Different matching results correspond to different control strategies.
[0047] Fuzzy Suppression: As used in this specification, "fuzzy suppression" refers to the system's non-deterministic restriction of the current payload in a partially matched state, rather than directly implementing complete allowance or complete blockage. This restriction is achieved through methods such as output limiting, feedback gain adjustment, integral window adjustment, gating reduction, partial bleeding, comparison threshold drift, delayed injection, or anomaly summary recording. The purpose of fuzzy suppression is to improve the system's ability to counter high-frequency probing, differential analysis, side-channel sampling, and progressive convergence attacks.
[0048] Asymmetric load splitting: As used in this specification, "asymmetric load splitting" refers to splitting the load to be processed into at least two unequal parts. One part is retained at the local processing end in the form of residual constraints, local constraints, or local mappings, while the other part is sent to the receiving or verification end. The receiving or verification end only allows session establishment, load recovery, or command release when the received part and the locally retained part meet preset closure audit conditions. This method prevents complete recovery from simply intercepting the outgoing part, thereby improving system security and replay resistance.
[0049] Low-interaction secure handshake: As used in this specification, "low-interaction secure handshake" refers to a handshake process that does not require explicit transmission of long-term keys and can be completed through one-way triggering, single round trip, implicit acknowledgment, segmented triggering, or enhanced methods deployed in parallel with existing protocols to establish a session or secure access. Low interaction does not preclude additional acknowledgments in necessary scenarios, but its core purpose is to reduce the burden of explicit interaction and decentralize security decisions to the device and analog front-end layers.
[0050] Multi-value state processing unit: As used in this specification, "multi-value state processing unit" refers to a hardware unit or hardware / software co-operation unit capable of switching the system to a fully matched, partially matched, or mismatched state based on polarity offsetting results, residual parameters, and preset thresholds, and executing different control strategies for different states. The multi-value state processing unit can be implemented in conjunction with a comparator amplifier, gating circuit, bleeder circuit, threshold adjustment module, state machine controller, or stored control logic.
[0051] Historical State Summary: As used in this specification, "historical state summary" refers to summary information extracted from one or more preceding sessions, accesses, handshakes, verifications, exception handling, or runtime trajectories. The historical state summary is used to associate the current session with the preceding state chain, thereby restricting simple copying, static replay, or recurrence of sessions out of context. One of the common-core implementation methods: Basic low-interaction secure handshake implementation
[0052] This embodiment presents a basic low-interaction secure handshake process based on local physical feature anchors, spatiotemporal context, sequence offset extraction, and polarity offset verification. This embodiment is used to illustrate the platform co-core of the present invention and does not constitute a limitation on specific device types, communication link types, or service scenarios.
[0053] At the sending end, the system first reads the state parameters of multiple physical nodes within the local hardware carrier to generate local physical feature anchors. This reading can occur either before the handshake begins or after the handshake request is triggered. To improve stability, the sending end can filter, average, differentiate, or select steady-state regions from the results of multiple read cycles to obtain local physical feature anchors that meet preset consistency requirements.
[0054] Subsequently, the sending end obtains the spatiotemporal context related to the current session. The spatiotemporal context may include at least one of the following: current timestamp, predefined time window identifier, location information, oscillator drift, ambient temperature, power supply disturbance, link status, and historical state summary of previous sessions. Preferably, the sending end does not directly use the spatiotemporal context as an independent plaintext field for subsequent verification, but rather uses it as input to participate in local physical response modulation and sequence offset generation.
[0055] The transmitting end generates sequence deviation parameters based on local physical feature anchors, spatiotemporal context, and the nonlinear distribution of physical node states within the hardware carrier. These sequence deviation parameters can be further constructed as session mapping factors, deviation vectors, residual parameters, or mapping matrices. Then, the transmitting end associates the payload to be processed with the session mapping factor and performs at least one of the following processing methods: projection, transformation, labeling, segmentation, or constraint encoding, to form a handshake payload. The handshake payload can be a complete payload, or a derived representation, constrained representation, or segmented representation of the payload.
[0056] At the receiving or verifying end, the system also reads the local physical feature anchor point of the local hardware carrier and obtains the current spatiotemporal context. Then, the receiving or verifying end generates the corresponding sequence offset parameter or hedging reference parameter based on its own side. Preferably, the receiving or verifying end does not need to explicitly receive the long-term key, nor does it need to perform multi-round key negotiation in the traditional sense. Instead, based on the current spatiotemporal conditions, local device conditions, and the received handshake payload, it directly performs at least one of polarity hedging verification, differential matching, residual auditing, and closure auditing at the analog front end.
[0057] When the polarity offset result meets the preset release conditions, the system enters a fully matched state, performing session establishment, access permission, command release, or data unsealing. When the polarity offset result is within the preset weak mismatch range, the system enters a partially matched state, performing output limiting, integral window adjustment, gating reduction, fuzziness suppression, or restricted release. When the polarity offset result exceeds the preset tolerance or a critical context is missing, the system enters a mismatch state, performing actions such as refusing session establishment, refusing data recovery, temporary load clearing, partial write protection, partial circuit breaking, or switching to restricted mode.
[0058] In a preferred implementation, this embodiment supports three types of handshake modes. The first type is a one-way triggered handshake, where the sending end sends a handshake payload after constraint mapping, and the receiving end directly grants access after completing closure audit locally, without sending back explicit confirmation information. The second type is a one-way round-trip handshake, where the receiving end returns a simplified or restricted confirmation signal after closure audit. The third type is an implicit confirmation handshake, where the receiving end confirms the session by deciding whether to continue accepting subsequent service payloads, whether to open a certain local control path, or whether to output a specific controlled response. All three modes belong to the implementation forms of the low-interaction secure handshake described in this invention.
[0059] In one implementation, the handshake payload can also be sent in a segmented triggering manner, and the final session establishment can be completed at the receiving end or the verification end based on the closed relationship between each segment and the local constraint, thereby forming a segmented triggering handshake. Second implementation method of co-core: Example of generating local physical feature anchor points
[0060] This embodiment presents a method for generating local physical feature anchor points. It should be understood that the purpose of this embodiment is to illustrate how the present invention anchors security to the physical state of the device, rather than basing security solely on abstract computational rules.
[0061] In one implementation, the hardware carrier includes at least one of self-pointing cell arrays, crossover arrays, memristor arrays, ferroelectric cell arrays, phase-change cell arrays, static random access memory arrays, dynamic random access memory arrays, or analog memory arrays. Due to differences in manufacturing processes, doping variations, stress distributions, aging trajectories, thermal noise disturbances, and readout deviations, multiple physical nodes in the array will exhibit different conductivities, resistances, polarizations, leakage currents, or threshold voltage distributions.
[0062] During the initialization phase, the system reads the aforementioned distribution one or more times to obtain a set of state parameters for multiple physical nodes. Preferably, the system can perform steady-state filtering, anomaly removal, differential enhancement, partition mapping, segmented quantization, sorting indexing, or multiple read intersection calculations on the state parameter set to reduce the instability caused by a single noisy readout. The processed result forms the local physical feature anchor points of the device under the current operating conditions.
[0063] In a preferred embodiment, the anchor point generation process can be divided into three stages. The first stage is the original state acquisition stage, in which array physical nodes are sampled using a low-perturbation readout method to avoid unacceptable write-type perturbations to the device state. The second stage is the distribution and sorting stage, in which the sampling results are grouped, sorted, threshold-filtered, interval-encoded, or differentially combined according to preset rules to form a repeatable set of local features. The third stage is the anchor point solidification stage, in which the local feature set is converted into a subsequently callable anchor point representation, such as a feature vector, index sequence, state mask, sparse matrix, or residual set.
[0064] In another implementation, the system allows local physical feature anchors to drift slowly over long-term use, but requires that this drift be traceable, filterable, and tolerable under a preset calibration mechanism. To this end, the system can set up an anchor maintenance process to re-update, freeze, or recalibrate anchors upon device manufacturing, initial activation, scheduled maintenance, reaching a certain aging threshold, or detecting significant environmental changes. Preferably, anchor updates do not completely replace anchors, but rather retain a partial summary of the old anchors as part of the historical state summary, ensuring that subsequent session establishment remains consistent with the device's historical trajectory.
[0065] In this embodiment, the local physical feature anchor point serves at least the following purposes: as the basic input for generating sequence offsets; as a local verification reference for the receiving or verifying end; as a source for constructing session mapping factors; and as a physical root constraint in closed-loop auditing. Therefore, the security starting point in this invention is not an external key independent of the device in the traditional sense, but rather originates from the physical state distribution of the device itself.
[0066] Examples of anchor point stability region screening, drift tolerance, and recalibration mechanisms: In a preferred embodiment, the system sets stable region screening rules for physical nodes participating in anchor point construction. Preferably, no fewer than a preset number of stable nodes participate in the anchor point backbone construction, and the repeatability, amplitude fluctuation, noise sensitivity, and drift trend of the same node within a preset time window are compared through multiple sampling. For nodes with poor repeatability but high distinguishability, the system can use them as auxiliary anchor point sources instead of directly incorporating them into the anchor point backbone.
[0067] Furthermore, the anchor points can adopt a three-layer structure: the first layer is the main anchor point layer, composed of nodes with high stability; the second layer is the auxiliary anchor point layer, composed of nodes with high distinguishability but slightly larger fluctuations; and the third layer is the history summary layer, used to retain important summary information of existing anchor points. In this way, when devices age, the environment changes slowly, or local nodes drift, the system can prioritize relying on the main anchor point layer to maintain basic consistency, while using the auxiliary anchor point layer to enhance distinguishability, and using the history summary layer to maintain the continuity of the session chain.
[0068] In a further embodiment, when anchor point consistency drops below a preset threshold but remains within a tolerable range, the system preferably performs reduced-weight usage, partial resampling, or adaptive threshold adjustment, rather than immediately triggering full recalibration. When anchor point consistency further drops below the preset recalibration threshold, the system enters restricted mode or maintenance mode and executes the recalibration process after satisfying preset safety conditions. Preferably, the recalibration process does not completely delete old anchor points, but rather uses a smooth transition through "old anchor point summary retention + gradual takeover of new anchor points".
[0069] Through the above design, the present invention can improve the stability and maintainability during long-term operation while ensuring that the anchor point has device-related distinguishability, and reduce the risk of misjudgment or missed judgment caused by the natural aging of the device.
[0070] Third implementation of co-core implementation: Hardware-environment coupled context example In this embodiment, it is explained how the spatiotemporal context participates in the security handshake and access control through hardware-environment coupling response, thereby avoiding the context being understood as ordinary external data that can be easily copied.
[0071] In one implementation, the system acquires time and spatial parameters. Time parameters may include the current time, nanosecond or microsecond-level time window numbers, task period numbers, transaction period numbers, or local clock offsets. Spatial parameters may include location coordinates, area labels, geofence identifiers, relative displacement, or routing domain labels. If these time and spatial parameters are simply fed directly into subsequent logic as independent numerical fields, replay attacks, environment simulation, and context copying outside the device may still occur. Therefore, in this invention, it is preferable to first apply the time and spatial parameters to the readout process, integration process, gating process, or threshold setting process of the hardware carrier, making them behave as biases or modulations at the device response level, before participating in sequence offset generation.
[0072] For example, in a preferred embodiment, when reading the array node current, the system selects different integration window lengths, sampling orders, or reference thresholds based on the current time window, so that the same device forms different repeatable readout trajectories under different time windows. In another preferred embodiment, the position parameters can be derived from the positioning module, or reflected by the small biases caused by local magnetic field strength, power supply ripple characteristics, ambient temperature gradient, structural attitude changes, or gravitational perturbations on the array readout current, threshold distribution, or oscillation characteristics. Thus, even if an attacker copies the time tag or position tag itself, if the device and environmental coupling conditions are different, it will still be difficult to obtain sequence deviation parameters consistent with the original session.
[0073] In a further embodiment, the system can also combine oscillator drift, power supply disturbances, link jitter, temperature shifts, acceleration changes, and historical state summaries to form a contextual composite quantity. This contextual composite quantity can influence subsequent polarity offsetting results through dynamic adjustments to the comparison threshold, modulation of the array readout order, offsetting of the reference level of multi-valued state cells, gating control of local discharge paths, or switching of residual parameter segment boundaries. Thus, the spatiotemporal context is no longer an externally attached label but becomes part of the device behavior.
[0074] In a preferred embodiment, the system may employ a context loss degradation strategy. When a context source becomes unavailable, such as when the positioning module is unavailable, the temperature sensor malfunctions, or the link status is unknown, the system does not necessarily stop working. Instead, it reduces the weight corresponding to that context source or switches it to a substitute context value, while simultaneously tightening the tolerance of other context parameters. This preserves the system's operability in complex environments without compromising overall security.
[0075] The key to this embodiment is that the context-based security determination is not a simple "read and compare," but rather a process of "reading—coupling—modulation—generating bias—re-verification." This makes it difficult for pure software simulations detached from hardware to fully reproduce the context constraint relationships required by this invention.
[0076] Example of modulation of readout path and threshold path by context parameters: In a preferred embodiment, the time window parameter can be directly applied to the integration path and the sampling path. For example, different time windows correspond to different integration lengths, sampling orders, sampling start phases, or integration end times, allowing the same array to form different readout trajectories at different times. The region parameter can be applied to the threshold path; for example, different region labels correspond to different sets of reference thresholds, comparison window boundaries, or gating enable conditions.
[0077] In another implementation, endogenous quantities such as power supply disturbances, oscillator drift, and link delay jitter can act on the readout bias path, causing slight repeatable shifts in the readout current, readout voltage, or oscillation characteristics of the array nodes; exogenous quantities such as temperature, magnetic field, acceleration, attitude, and gravity perturbations can act on the compensation path or selection path, affecting the selection of local nodes, threshold drift, or reference channel switching.
[0078] With the above modulation method, the context no longer participates in the calculation statically as an independent tag, but participates in the session binding as a physical influence on the readout path, integration path, threshold path and gate path, making it difficult for pure software replay to replicate the real device response conditions required by this invention. Fourth implementation method of co-core: Simulated front-end polarity hedging embodiment
[0079] In this embodiment, we explain how to perform polarity offset verification at the analog front end to directly correlate the physical layer response with the logic layer control.
[0080] In one implementation, the receiving end, verification end, or local processing end includes an analog front-end, a current or voltage comparison unit, a gating unit, a discharge unit, and a cooperating digital control unit. Upon receiving the handshake load, the system generates one or more offset reference quantities based on local physical feature anchor points, spatiotemporal context, and generated sequence deviation parameters. Then, the electrical signal corresponding to the handshake load is physically superimposed or canceled with the offset reference quantities at the analog front-end.
[0081] The in-situ physical superposition or cancellation can be implemented in various ways. For example, differential bit line current superposition can be used to determine whether the load signal and the local reference signal tend to zero or a preset window; differential word line voltage cancellation can be used to determine whether the potential difference between them is less than the tolerance threshold; and threshold verification driven by cross-node charge sharing, local grounding discharge, or charge pump can be used to characterize the matching degree in the analog domain. Preferably, the polarity offset result is not fully digitized first, but a round of gating or screening is completed at the analog front end, and only the results that meet the conditions or are at the boundary conditions are sent to the subsequent digital logic, reducing the chance of invalid attempts entering higher-level logic.
[0082] In a preferred embodiment, the system sets three threshold intervals at the analog front end, corresponding to a fully matched interval, a partially matched interval, and a mismatch interval, respectively. When the superimposed current, voltage, residual, or integral falls into the fully matched interval, the analog front end outputs a pass-through gating signal, allowing subsequent session establishment, instruction execution, or data recovery; when it falls into the partially matched interval, the analog front end outputs a restricted control signal and performs fuzzy suppression in conjunction with the multi-value state processing unit; when it falls into the mismatch interval, the analog front end outputs a blocking signal, triggering partial discharge, load zeroing, write protection, or restricted mode switching.
[0083] In another implementation, the analog front-end and digital control unit work collaboratively. The digital control unit can dynamically adjust the reference threshold, integration time, discharge intensity, comparison sensitivity, or gating sequence of the analog front-end based on the current spatiotemporal context and historical state summary. Thus, the same handshake payload may correspond to different release windows and different partial matching intervals under different contextual conditions. This helps improve the system's resistance to high-frequency probing, differential analysis, and asymptotic attacks.
[0084] It should be emphasized that in this invention, "polarity offsetting" does not merely refer to an abstract sense of opposite signs or numerical subtraction, but rather to the use of in-situ physical superposition or cancellation at the analog front end to achieve real coupling between device states, context conditions, and load states at the levels of current, voltage, charge, or integral quantities, thereby determining subsequent logic branches. Therefore, this embodiment further enhances the physical implementation attributes of this invention.
[0085] Equivalent implementation of polarity offset verification: In this invention, polarity offset verification is not limited to a specific fixed analog circuit structure. Besides differential bit line current superposition and differential word line voltage cancellation, it can also be implemented using methods such as charge sharing, charge integration, partial discharge, integration threshold determination, comparison amplification, reference channel switching, and a combination of analog front-end initial screening and digital domain verification. As long as the implementation method can perform in-situ physical superposition, cancellation, integration, comparison, or discharge of the load and local reference quantity at the analog front-end or an equivalent location, and the result directly affects subsequent logic branches, it can be considered an equivalent implementation of the polarity offset verification of this invention.
[0086] By adding the above equivalent implementation description, the core technical concept of this invention can be avoided by third parties simply by replacing the specific front-end circuit form. Fifth implementation of the common core method: Three-valued / multi-valued matching state machine embodiment
[0087] This embodiment illustrates how to construct a three-valued or multi-valued matching state machine based on the polarity hedging result to replace the traditional binary "pass / fail" single-decision logic.
[0088] In one implementation, the multi-valued state processing unit receives hedging results, residual parameters, and threshold configuration parameters from the simulation front end. The system first determines whether the current result falls within the fully matched interval. If so, it enters the fully matched state. In the fully matched state, the system can perform at least one of the following: session establishment, access admission, load recovery, command release, data desealing, or subsequent process initiation. In this state, the system can record a historical state summary of the current session for use in the next round of session constraints.
[0089] If the current result does not fall within the complete matching range, but the residual parameter is within the preset weak mismatch range, the system enters a partially matching state. A partially matching state is not equivalent to a failure state. In this state, the system preferably does not return a completely explicit pass or fail feedback, but instead performs one or more ambiguity suppression actions according to the current security policy. These actions include reducing the output amplitude, shortening or lengthening the integration window, changing the gating order, reducing transmission capacity, limiting the range of accessible resources, allowing only restricted payloads to pass, writing an anomaly digest, or triggering a one-time additional check. Through these processes, the possibility of attackers obtaining stable boundary feedback by repeatedly fine-tuning the input can be reduced.
[0090] If the current result significantly exceeds the preset tolerance, or if key spatiotemporal context is missing, historical state summaries are inconsistent, or local anchor point verification fails, the system enters a mismatch state. While in a mismatch state, the system can perform actions such as refusing to establish a session, refusing data recovery, clearing temporary payloads, implementing local write protection, local circuit breaking, disabling local departmental controls, switching to restricted mode, or recording abnormal residual summaries.
[0091] In a further embodiment, the state machine is not limited to three values and can be extended to multi-valued states. For example, the partially matched state can be further divided into mild, moderate, and severe weak mismatches, allowing the system to employ different levels of fuzziness suppression, gating restrictions of different durations, or anomaly recording strategies for different levels of boundary conditions. This design can further improve the system's resolution and resistance to analysis of complex probing behaviors.
[0092] In this embodiment, the value of the multi-valued state machine lies in: firstly, enabling the system to maintain fine-grained control under physical boundary conditions, rather than simply applying a "one-size-fits-all" approach; secondly, making the partially matched state an important buffer against side-channel attacks, differential power analysis, and sampling correlation attacks; and thirdly, enabling the system to balance security and availability without significantly increasing the number of interactions.
[0093] State machine defense implementation for high-frequency probing and boundary approach: In a preferred embodiment, when the system detects multiple weak mismatch events consecutively within a preset time window, it preferably does not maintain the original fixed threshold, but instead dynamically tightens the perfect match interval, expands the partial match interval, increases the abnormal summary record level, and appropriately extends the duration of the restricted mode. In this way, as the attacker gradually approaches the boundary through high-frequency repeated probing, the system's effective feedback window will be compressed.
[0094] In another embodiment, the system can randomize or semi-randomize the response actions of partially matched states, such as randomly shifting the integral window, randomly switching partial reference thresholds, randomly delaying and limiting feedback, changing the local control sequence, or changing the output limiting ratio within a safe range. Preferably, the system does not return explicit, fixed, and repeatable boundary information for weakly mismatched boundary inputs, but instead reduces the possibility of an attacker obtaining a stable response model through fuzzy suppression and limited control.
[0095] Furthermore, when a preset number of boundary weak mismatch events occur consecutively within a short period of time, the system can perform retry throttling, temporarily freeze the recalibration entry, restrict sensitive interfaces, trigger secondary local resampling, extend the duration of the restricted mode, or switch to a higher security level to prevent attackers from using boundary probing to force the system into an exploitable recalibration or degradation window. Sixth implementation method of co-core: Asymmetric load splitting example
[0096] This embodiment illustrates how asymmetric payload splitting can distribute the complete causal chain between the local processing end and the receiving / verification end, thereby improving the system's resistance to interception, replay, and reproduction outside the local environment.
[0097] In one implementation, the payload to be processed is split into a first payload part and a second payload part before transmission. The first payload part is preferably not directly transmitted externally, but rather retained at the local processing end in the form of residual constraints, local mapping constraints, local state masks, anchor-related parameters, or historical summary associations. The second payload part is then transmitted to the receiving end or verification end after being constrained by a session mapping factor. The two parts can be asymmetrical in terms of information content, representation, or operational mechanism, thereby avoiding simple splicing and reconstruction.
[0098] On the sending side, the local processing unit first generates a sequence deviation parameter based on local physical feature anchor points and spatiotemporal context, and then determines the splitting strategy based on this sequence deviation parameter. Preferably, the system does not split the payload to be processed evenly, but instead determines which information to keep locally and which information to send out based on security level, real-time requirements, link capacity, or service type. For high-security scenarios, the weight of the locally retained portion can be increased; for high-real-time scenarios, the information density of the sent portion can be appropriately increased, while still retaining necessary local constraints.
[0099] At the receiving or verifying end, after receiving the second payload portion, the system cannot immediately complete a full recovery. Instead, it needs to perform a closed-loop audit by combining the local physical feature anchor point, spatiotemporal context, and the constraint relationship corresponding to the first payload portion. Only when the received second payload portion meets the preset closed-loop conditions with the local or pre-stored first payload portion will the system perform session establishment, data recovery, command release, or payload desealing. If only the second payload portion is intercepted, or only the first payload portion is copied without meeting the current spatiotemporal context and local anchor point conditions, a full recovery cannot be completed.
[0100] In a preferred embodiment, the first payload portion is stored in the security chip of the terminal initiating the transaction, while the second payload portion is sent to the verification end. After the verification end completes the initial polarity offset verification, it still needs to wait for the constraint relationship corresponding to the first payload portion to meet preset conditions before allowing entry into the final release state. In this way, even if the outbound link is monitored, it is difficult for an attacker to construct a reusable complete payload based solely on the outbound content.
[0101] In another preferred embodiment, the first payload portion does not exist in a fixed plaintext form, but is dynamically updated based on the local anchor, historical state summary, and current context. In this way, asymmetric payload splitting not only increases the physical dispersion of information but also incorporates local device state and session history into the final release condition.
[0102] Through this embodiment, the present invention further realizes a security structure in which the complete causal chain is not fully unfolded in a single message, a single node, or at a single moment, but is distributed among devices, the environment, session history, and segmented payloads. This significantly improves the system's resistance to replication attacks, replay attacks, and single-point interception attacks. One industry implementation method: Constrained handshake and dual verification in a banking scenario
[0103] This embodiment illustrates how the present invention is applied in scenarios such as banking, payment clearing, and high-privilege financial operations. The core of this embodiment does not lie in changing the existing banking business message format itself, but in sinking the security access conditions for high-value transactions, critical instructions, or high-privilege sessions to a hardware-inherent constraint layer composed of local physical feature anchors, spatiotemporal context, and simulated front-end polarity hedging verification.
[0104] In one implementation, bank counter terminals, self-service terminals, clearing gateways, dedicated payment terminals, or their corresponding security coprocessors incorporate hardware arrays with local physical feature anchor point extraction capabilities. The hardware array can be a memristor array, ferroelectric unit array, crossbar array, analog memory array, or other array structures capable of stably outputting the relevant distribution characteristics of the devices. Before performing high-value operations, the security coprocessor reads the states of multiple physical nodes in the array to generate local physical feature anchor points for the terminal's current session.
[0105] Subsequently, the system collects the spatiotemporal context of the current operation. The spatiotemporal context preferably includes at least one of the following: the location label corresponding to the counter or window, the spatial identifier of the business area where the terminal is located, the identifier of the current business time window, the historical state summary corresponding to the teller's login session, terminal power supply disturbance parameters, local area network link state parameters, and a strategy label related to the current transaction type. Preferably, some spatiotemporal context is obtained through hardware-environment coupling response. For example, power supply ripple corresponding to the terminal's location, ambient temperature gradient, local magnetic field bias, changes in the shielding environment within the cabinet, or local oscillator drift can all act on the hardware array readout path or comparison path, thereby modulating the sequence deviation generation.
[0106] In a preferred embodiment, when a teller initiates a large-amount transfer, limit adjustment, key update, settlement confirmation, or high-privilege account operation, the business instruction is not directly sent to the upper-level business processing module, but first enters the security coprocessor. The security coprocessor generates sequence deviation parameters based on local physical feature anchors, the current window position label, the current business time window, and the historical state summary of the teller's session, and constructs the business instruction as a handshake payload or a constrained payload. Then, the handshake payload undergoes polarity offset verification with a reference quantity formed based on the aforementioned parameters at the local simulation front end.
[0107] When the polarity offset result falls within the complete match range, the system determines that the transaction request meets the closed audit conditions jointly determined by the current device, current personnel, current time, current location, and current session history, and therefore allows the request to be sent to the subsequent transaction processing link. When the result falls within the partial match range, the system enters the partial match state. At this time, instead of directly rejecting the request, a restricted release policy can be implemented, such as allowing only queries and disallowing transfers, requiring a secondary verification process, allowing only low-limit operations, or adding a one-time local resampling to confirm the existence of environmental transient disturbances. When the result falls within the non-match range, the system refuses to send the business instruction to the subsequent link and performs at least one of the following: temporary load clearing, abnormal summary recording, partial write protection, and restricting the terminal from attempting the same high-privilege operation again within a predetermined time.
[0108] In another preferred embodiment, this embodiment can form a dual verification based on location-related environmental bias and session history constraints. The geographic lock is not solely represented by a location coordinate string, but is formed by a location tag and the local environment's physical bias; similarly, the identity lock is not solely represented by the teller's account, password, or external token, but is determined by the local physical feature anchor of the current terminal hardware, the historical state summary of the current login session, and the context policy corresponding to this type of high-privilege operation. Therefore, even if an attacker obtains the account password, business message format, or partial records of a single legitimate operation, as long as the attacker's terminal, local environment, or time window changes, the attacker may be unable to form an effective polarity offset result at the simulated front end because the sequence deviation parameter cannot meet the preset conditions.
[0109] In a further embodiment, when a terminal is moved to another location without authorization, even if the terminal hardware itself is not damaged, the system can tighten the matching window due to changes in the location-related environmental coupling response. For example, after the terminal is moved away from the authorized counter, its power supply path, temperature distribution, local link status, cabinet shielding conditions, or environmental disturbances change, causing the sequence deviation parameter generated by the environmental quantities to deviate from the original set window. At this time, the system can automatically enter a partially matched state or a non-matched state, and execute a restricted mode or blocking mode for operations such as large transactions, sensitive information export, and settlement confirmation.
[0110] In a preferred constrained handshake embodiment, the complete security decision criteria are not exposed between the terminal and the gateway. The sending terminal only sends the handshake payload or service payload derivation representation constrained by the session mapping factor, while the gateway or authentication terminal performs closed auditing based on its own stored policy parameters, local physical anchor digests, or access area context. Throughout the process, explicit transmission of long-term keys is not required, nor is it required to explicitly expose all local constraints. Even if an attacker monitors the communication link, they can only observe the constrained payload expression and cannot obtain all the device-side, environment-side, and historical constraints necessary to form complete access conditions.
[0111] In a further embodiment, the geographic lock is preferably formed in conjunction with the environmental bias, power supply path characteristics, local area network domain characteristics, or local access domain characteristics of the terminal's location; the identity lock is preferably formed in conjunction with the terminal's local physical feature anchor point, the teller's current session's historical state summary, and the current high-sensitivity operation strategy. If any key condition is not met, the system can directly restrict or block high-sensitivity operations such as large-amount transfers, limit adjustments, settlement confirmations, and key updates, without affecting general queries or low-risk operations.
[0112] In another implementation, the present invention can also be deployed in parallel with existing banking security systems. For example, it can be used as a secondary authentication layer for high-value transactions, a high-privilege counter operation access layer, an ATM or self-service terminal access verification layer, a clearing node enhanced access layer, or an HSM peripheral enhanced verification layer. In this case, the present invention does not require replacing existing certificate systems, password systems, or auditing systems, but rather enhances them with physical root constraints and low-interaction hardware authentication mechanisms. This reduces the cost of large-scale modifications to existing systems and significantly improves protection against replay attacks, spoofing, location migration, and terminal replacement through front-end hardware verification.
[0113] It should be understood that in this embodiment, "bank" can refer broadly to banks, securities firms, insurance companies, payment institutions, clearing organizations, financial infrastructure nodes, and other institutions with strict auditing requirements for high-value instructions and high-privilege sessions. Any implementation method that achieves high-value operation access control based on local physical feature anchors, spatiotemporal context, sequence deviation extraction, and polarity hedging verification falls within the protection scope of this invention. Industry Implementation Method Two: Spatiotemporal Window Access Implementation Example for Government / Private Network Terminals
[0114] This embodiment illustrates the application of the present invention in scenarios requiring joint control of "time window + area window + device window," including government terminals, private network terminals, controlled office terminals, portable secure terminals, mobile dedicated nodes, and others. This embodiment emphasizes that the core of the present invention is not simply adding location or time tags to the terminal, but rather deeply binding the authorization window to the physical implementation conditions of the terminal through local physical feature anchors, spatiotemporal context, and polarity offset verification.
[0115] In one implementation, the dedicated terminal integrates a security coprocessor and a local physical feature anchor extraction array. Before powering on, accessing the private network, requesting access to sensitive resources, executing controlled commands, or decrypting protected data, the security coprocessor first reads the status of the local array nodes and generates local physical feature anchors. Then, the terminal collects the spatiotemporal context related to the current task. The spatiotemporal context may include at least one of the following: task time window, task area label, location identifier of the terminal's current office area or equipment area, current link access domain, oscillator drift, ambient temperature, attitude change, acceleration status, and previous session history summary.
[0116] In a preferred embodiment, the system sets "spatiotemporal window admission conditions." These conditions mean that the system only allows the establishment of a session, decryption of data, opening of specific interfaces, or execution of sensitive instructions when the terminal is located within an authorized area and within an authorized time window, and its current local physical feature anchor point and environmental coupling response can jointly generate sequence deviation parameters that meet preset conditions. In other words, authorization is not only determined by the upper-layer logical permission table but also by the underlying device state and the current physical environment.
[0117] In a further embodiment, the regional window and the time window preferably participate in session binding simultaneously, and regional tolerance and time tolerance can be set separately. When the terminal exceeds the regional tolerance, exceeds the time window tolerance, or when there is a significant inconsistency between the regional label and the environmental coupling characteristics, the system can directly enter the mismatch state and block access to sensitive resources; when in the partially matched state, the system preferably only allows access to low-sensitivity resources, short-term restricted sessions, or additional confirmation procedures.
[0118] For example, in one implementation, a terminal needs to access restricted files within a predetermined time window in a certain office area. The system first reads the local physical feature anchor point, then obtains the current time window and area label, and modulates these two types of information into the array readout process. Specifically, the current time window can determine the sampling clock, integration window, or threshold segmentation; the local link characteristics, local electromagnetic environment, power supply disturbances, or temperature distribution corresponding to the area label can affect the readout current or comparison threshold. Then, the terminal generates sequence deviation parameters based on the above information and constructs the file access request as a constrained load. Only when the polarity offset result of the local simulation front end meets the preset closure audit condition will the system allow the file to be unsealed or the interface to be opened.
[0119] In another preferred embodiment, the portable terminal is authorized for use within a specific task time period, but is required to automatically lose sensitive access capabilities after leaving the designated area. To this end, the system does not rely on a single geographic coordinate string comparison, but instead writes the area window into the spatiotemporal context through hardware-environment coupling. Thus, when the terminal is taken away from the predetermined area, even if an attacker maintains clock synchronization and forges the upper-level location tag, the sequence deviation parameter may still deviate from the preset window due to changes in the environmental coupling response, causing the polarity offset verification to enter a partially matched or unmatched state. In the partially matched state, the system may only allow access to low-sensitivity information, limit session duration, or require additional confirmation; in the unmatched state, the system directly blocks sensitive operations and clears temporary payloads.
[0120] In a further embodiment, the present invention can also be used for establishing temporary sessions between private network nodes. For example, node A initiates a controlled session request to node B. Node A generates a handshake payload based on its local physical feature anchor and current spatiotemporal context. After receiving the handshake payload, node B does not need to perform traditional multi-round explicit key negotiation. Instead, based on its local anchor, current area window, current time window, and the handshake payload sent by node A, it performs polarity offset verification at its local simulated front end. Only when the verification passes will node B open a controlled port, allow a controlled command stream, or send back a controlled response. In this case, the handshake conditions are not only related to the message itself, but also to the current spatiotemporal window and device state of node B, thereby reducing the possibility of the session being copied and reproduced in different locations, times, and devices.
[0121] In one implementation, the system can combine historical state summaries to achieve a "heritable but not detachable" session mechanism. For example, after a terminal establishes a session within an authorized area, it can continue to perform related operations within the same area for a short period of time; however, if the terminal leaves the area, crosses a time window, or experiences a prolonged interruption, new access requests must regenerate the sequence offset parameters and re-execute the closure audit. In this way, session continuity is supported by historical state summaries, but it will not extend indefinitely in any subsequent scenario due to a single legitimate authorization.
[0122] In a preferred embodiment, the present invention can further distinguish between "temporary authorization" and "long-term authorization". For temporary authorization, the system can set a higher weight for the time window, a narrower regional tolerance, and tend to restrict access or directly block access in partially matched states. For long-term authorization, the system can appropriately relax the tolerance for some environmental disturbances, but still require the local physical feature anchor point to remain continuous with the historical state summary. In this way, the present invention can adapt to both strict short-term task scenarios and long-term controlled access scenarios.
[0123] In a further embodiment, the present invention can also be deployed in parallel with existing terminal management systems, access control systems, private network authentication systems, or data container systems. In this case, the upper-layer system is responsible for business permission configuration, role allocation, and audit logging, while the present invention is responsible for the underlying physical root binding, spatiotemporal window closure auditing, and simulated front-end access screening. Together, they form a two-layer control structure of "logical permissions + physical access".
[0124] It should be understood that the term "government / private network terminal" in this embodiment is not limited to a specific industry terminal, but rather refers to any controlled terminal, edge node, portable node, or access device that needs to limit access capabilities to a specific device, a specific region, a specific time window, and a specific session history chain. The technical concept of this invention can be applied to any implementation method that uses local physical feature anchors, spatiotemporal context, sequence deviation extraction, and polarity offset verification to achieve window-based access control. The accompanying illustrations and their corresponding text blocks are shown in the attached figures.
[0125] To make the technical solution of the present invention clearer, the system structure, processing flow, and typical application implementation of the present invention will be further described below with reference to the accompanying drawings. It should be understood that the accompanying drawings are only for illustrative purposes and do not constitute a limitation on the scope of protection of the present invention.
[0126] Figure 1 is a block diagram of the overall structure of the platform of the present invention. The overall structure of the platform shown in Figure 1 includes at least the following modules: local physical feature anchor point extraction module, spatiotemporal context acquisition module, sequence deviation generation module, load projection and constraint encoding module, simulation front-end polarity offset verification module, multi-value state processing module, output control and anomaly handling module, and historical state summary maintenance module.
[0127] Figure 2 is a flowchart of the basic low-interaction security handshake process. The diagram adopts the 201-209 system, corresponding to anchor point extraction, context acquisition, deviation generation, payload construction, payload transmission, local reference generation, front-end offsetting, status determination, and release / restriction / blocking handling.
[0128] Figure 3 shows the flowchart for local physical feature anchor point extraction. The figure uses the 301-306 system to illustrate the processes of low-perturbation sampling, state acquisition, filtering / quantization, local feature formation, anchor point representation, and summary updating.
[0129] Figure 4 is a flowchart of spatiotemporal context acquisition and hardware-environment coupling. The figure uses the 401-407 architecture to illustrate how time windows, regions / locations, environments / operations, and historical summaries enter the coupling path and form biases / modulations to the device response, ultimately serving as sequence offset inputs.
[0130] Figure 5 is a flowchart of the sequence deviation generation process. The figure illustrates the process by which the physical anchor point and the spatiotemporal context are mapped and combined, differentially calculated, segmented quantized or matrix projected to form deviation parameters and session mapping factors.
[0131] Figure 6 is a flowchart of load projection and constraint encoding. The figure illustrates how loads are associated with session mapping factors, residual parameters, or mapping matrices, and how they form an asymmetric load splitting structure when needed.
[0132] Figure 7 shows the block diagram of the analog front-end polarity offset verification circuit. The figure illustrates the relationship between the input load path, the local reference path, the differential superposition / cancellation unit, the comparison and discharge unit, and the gated output unit.
[0133] Figure 8 is a schematic diagram of a ternary / multi-valued matching state machine. The figure illustrates the transition relationships between the fully matched, partially matched, and mismatched states, as well as the corresponding release, fuzzy suppression, and blocking actions. The partially matched state preferably corresponds to the weak mismatch interval.
[0134] Figure 9 is a structural block diagram of a constrained handshake implementation in a banking scenario. The diagram illustrates the relationship between the security coprocessor, the local physical feature anchor array, the spatiotemporal context constraint module, the business processing module, and the verification terminal.
[0135] Figure 10 is a structural block diagram of an embodiment of spatiotemporal window access control for government / private network terminals. The diagram illustrates the relationship between the dedicated terminal, security coprocessor, local anchor array, regional / time window constraint module, simulated front-end verification module, and resource access control module. Explanation of range-based and scenario-based parameter configuration
[0136] In this invention, local physical feature anchor points, spatiotemporal context, sequence deviation, simulated front-end polarity offsetting results, and multi-valued state processing results can all be configured through preset parameters, thresholds, tolerance boundaries, and calibration rules. It should be understood that the parameters, thresholds, and tolerances are not limited to unique fixed values, but can be set according to device type, application scenario, security level, environmental disturbance level, link characteristics, and real-time requirements. Any implementation that still conforms to the main chain described in this invention—"anchor point extraction—context coupling—sequence deviation generation—load constraint—simulated front-end polarity offsetting—multi-valued state control"—can be considered an equivalent implementation of this invention.
[0137] Preferably, the system sets readout amplitude threshold, repeatability threshold, and stable region screening threshold for anchor point extraction; sets fixed time window, sliding time window, or overlapping time window for time parameters; sets regional tolerance, access domain tolerance, or environmental coupling tolerance for spatial parameters; sets configurable tolerance boundaries for environmental disturbances; and divides fully matched intervals, partially matched intervals, and unmatched intervals through at least two residual threshold boundaries.
[0138] In high-security scenarios, a narrower full-match interval, stricter context consistency requirements, and stronger partial-match suppression strategies are preferred. In high-availability scenarios, the local tolerance can be appropriately increased, but the key context and local physical feature anchor points must still maintain closed constraints. The aforementioned parameters can be either fixed thresholds or scenario-based thresholds that are dynamically adjusted based on time windows, regional windows, environmental stability, and historical state summaries.
[0139] In a preferred embodiment, recalibration does not require the complete replacement of the original anchor points and thresholds. Instead, it can be performed using a "preservation of old parameter summaries + gradual takeover of new parameters" approach. That is, the system retains the information related to the old parameters in the historical state summaries while gradually increasing the weight of the new parameters, enabling the system to smoothly transition from the old state to the new state and avoiding a complete break in the session chain due to a single recalibration.
[0140] In one implementation, the system can enter a degraded operation mode when certain context sources are temporarily unavailable, certain environmental quantities experience short-term anomalies, or certain device nodes experience slight drift. In degraded operation mode, the weights and tolerance boundaries of various parameters can be adjusted to maintain minimum availability while preserving basic safety. For example, the dependence on location parameters can be reduced, the consistency requirements for historical state summaries can be increased, or the tolerance for local environmental disturbances can be expanded while tightening the residual threshold. Implementation methods for handling abnormal operating conditions and boundary scenarios
[0141] In this invention, to enhance the feasibility of the system in complex real-world environments, several abnormal operating conditions and boundary scenarios also need to be considered. These are described below with reference to typical cases.
[0142] For clock asynchrony or time window boundary jitter, the system preferentially uses a time window rather than a single point time for judgment, and allows session availability to be maintained within a preset tolerance through integral window compensation, sampling order adjustment, or threshold offset. For location missing, area label missing, or abnormal location source, the system can adopt a degradation strategy: using the continuity of access domain characteristics, environmental bias, historical state summary, and local physical feature anchor points as alternative constraints, and appropriately tightening the tolerance of other parameters.
[0143] For sensor anomalies or inconsistent context sources, the system can set consistency verification strategies for different context sources. When conflicts occur between multiple context sources, the risk level is prioritized and the system enters a partially matched or unmatched state. For anchor point drift caused by increased array noise or device aging, the system can compensate through multiple resampling, node re-screening, dynamic adjustment of residual thresholds, and anchor point recalibration.
[0144] For link jitter, segment loss, and asymmetric load recovery failure, the system can set segment tolerance and recovery time limit on the receiving side. If the missing segment does not affect the core constraints required for closed auditing, it can enter the partially matched state and perform restricted release; if the missing segment causes the closed auditing to fail, it enters the unmatched state. Power consumption / thermal side-channel defense implementation examples
[0145] In a preferred embodiment, to reduce the impact of differential power consumption sampling, thermal sampling, or electromagnetic boundary sampling on the system, the system may introduce measures such as random integral windows, pseudo-reference injection, hedging timing disturbances, local equalization discharge, random switching of reference paths, or changes in local comparison order under partially matched states or boundary conditions. Preferably, the system does not return completely explicit and completely stable binary feedback to weak mismatch inputs at the boundary, but instead reduces the possibility of attackers constructing stable boundary models from external observations through fuzzy suppression.
[0146] In another implementation, the system can increase the anomaly level for consecutive weak mismatch events and simultaneously change the local output limiting and integral window, so that the power consumption or thermal trajectory obtained by repeated sampling maintains a limited difference, thereby increasing the difficulty of model reconstruction after high-precision sampling. Fatigue bombing and recalibration window defense implementation examples
[0147] In a preferred embodiment, when the system continuously experiences partially matched states or weak boundary mismatch events, it is preferable not to immediately initiate the recalibration process. Instead, it first enters a restricted mode and checks whether a preset number of stable resampling results, a continuity condition for historical state summaries, and additional confirmation conditions from the administrator or verification side are simultaneously met. The controlled recalibration process is only permitted when at least two of the security conditions are met.
[0148] Furthermore, during recalibration, high-sensitivity interfaces are preferably closed, high-value operations are restricted, some write channels are frozen, and the recalibration process itself is written to the historical state summary. If recalibration fails, is interrupted, or a context conflict occurs, the system maintains restricted mode or enters a higher level of locked state, instead of directly restoring normal access capability. Example of Environment Replay and Multi-Source Consistency Verification
[0149] In a preferred embodiment, the system does not rely on a single environmental source to form context coupling, but requires the participation of at least two heterogeneous context sources, such as time windows and oscillator drift, region labels and local link domain characteristics, ambient temperature and power supply disturbances, acceleration and attitude bias, etc. The system preferably performs consistency checks between different context sources, and maintains a fully matched state only when multiple sources jointly satisfy a preset relationship.
[0150] In another implementation, if the system detects that the waveform or bias of a certain environmental source is inconsistent with the historical state summary, or that there is a significant conflict with other environmental sources, it is preferable to tighten the threshold, lower the clearance level, or enter a partially matching state. Through this multi-source consistency constraint, the system can reduce the feasibility of an attacker constructing a false context by replaying environmental ripples, location tags, or time tags along a single path. Summary of Implementation Methods and Alternative Implementation Methods
[0151] The method of the present invention can be executed by at least one of a security device, a communication device, a payment terminal, a gateway device, an edge node, a trusted execution unit, a security coprocessor, a memory computing chip, or a mixed-signal array chip.
[0152] This invention can be implemented using a single chip or through a multi-chip collaborative implementation. In single-chip implementation, the local physical feature anchor point extraction module, spatiotemporal context acquisition module, sequence deviation generation module, load projection and constraint encoding module, simulated front-end polarity offset verification module, multi-value state processing module, output control and anomaly handling module, and historical state summary maintenance module can be integrated within the same chip. In multi-chip collaborative implementation, the security coprocessor can handle anchor point extraction, deviation generation, and front-end offset functions, the main processor can handle the business logic, and the trusted storage can handle historical summaries and parameter storage.
[0153] This invention can also be implemented through board-level or module-level structures, such as adding security expansion cards, hybrid analog-digital front-end boards, or pluggable security modules to existing servers, countertop terminals, gateway devices, dedicated terminals, or edge nodes. It can also employ a software-controlled and hardware-executed collaborative approach: time window division, parameter loading, threshold issuance, historical summary management, and policy switching are completed by software, firmware, or microcode; anchor point extraction, simulated front-end hedging, comparison amplification, partial bleeding, and multi-value state switching are completed by digital circuits, analog circuits, or a combination thereof.
[0154] To accommodate different processes and cost conditions, the system can adopt a purely digital approximation implementation scheme, that is, first convert the local physical feature anchor points and context coupling results into digital representations, and then complete part of the sequence deviation generation, residual calculation and state determination in the digital domain. However, it is preferable to retain at least one in-situ response link related to the physical front end. In a more preferred implementation, the system adopts an analog enhancement implementation scheme, that is, complete the main polarity offset verification and the first round of state screening in the analog front end, and only send the boundary results and release results to the digital domain.
[0155] This invention can employ either a centralized or distributed authentication architecture. It can also be deployed in parallel with existing certificate systems, token systems, password systems, trusted execution environments, hardware security modules, device management systems, access control systems, private network authentication systems, or data container systems as a foundational enhanced security layer, without requiring a complete replacement of existing infrastructure. Simplified implementation of resource-constrained devices
[0156] For resource-constrained devices, this invention can be implemented in a simplified manner. For example, it can retain only a small number of stable physical nodes as anchor points, collect only a small number of context parameters, set only three-state matching results, or implement only local partial closure auditing while delegating the final decision to the upper-level node. Preferably, the simplified implementation still retains at least one type of device physical anchor point, at least one type of key context, and at least one front-end physical verification step, thereby reducing implementation complexity while maintaining the core causal chain of this invention. As long as the basic elements of device-related anchor points, context participation, sequence deviation generation, offset verification, and state control are still present, it still belongs to the equivalent implementation of this invention. Replaceable modules, equivalent transformations and non-restrictive descriptions
[0157] In the foregoing embodiments, physical node parameters such as conductance state, resistance state, polarization state, leakage current state, threshold voltage state, and oscillation state are mentioned multiple times. It should be understood that these parameters are only typical forms of device characterization and do not constitute the only limitation. Any other physical quantity, derived parameter, combined feature, or statistical feature that can reflect the distribution of multiple physical node states within the device and can be used to construct local physical feature anchors can be used as an equivalent replacement.
[0158] In the foregoing embodiments, context sources such as timestamps, time windows, location information, region tags, power supply disturbances, temperature parameters, acceleration parameters, oscillator drift, link status, and historical status summaries are mentioned multiple times. It should be understood that this invention does not limit the context to simultaneously containing all of these sources, nor does it limit their acquisition order, weight allocation, or fusion method. As long as the context can participate in sequence offset generation in a direct or coupled modulation manner and ultimately affect the polarity offset result and subsequent logic branches, it falls within the scope of protection of this invention.
[0159] In the foregoing embodiments, the order deviation can be generated through mapping combination, weighted superposition, differential calculation, segmented quantization, threshold transformation, sequence expansion, matrix projection, residual compression, and state switching. It should be understood that this invention does not limit the use of a specific mathematical expression, mapping structure, or encoding form. Any deviation, constraint, residual, index, or control quantity formed based on local physical feature anchor points and spatiotemporal context, and usable by subsequent verification modules, can be considered an equivalent technical implementation of the "order deviation" in this invention.
[0160] In the aforementioned embodiments, polarity offsetting can be achieved through differential bit line current superposition, differential word line voltage cancellation, cross-node charge sharing, local grounding discharge, charge pump-driven threshold verification, comparison amplification, integration threshold determination, and analog front-end initial screening. It should be understood that this invention does not limit the use of a specific analog circuit structure. Any method that can perform in-situ physical superposition, cancellation, comparison, discharge, integration, or gating processing on the current load and local reference quantity at the analog front-end or an equivalent location, and whose result directly affects the implementation of subsequent logic branches, can be considered an equivalent implementation of the "polarity offsetting verification" in this invention.
[0161] In the foregoing embodiments, multi-valued state processing includes at least a fully matched state, a partially matched state, and a non-matched state. It should be understood that the three states are only a basic implementation. Without changing the core idea of this invention, the partially matched state can be further subdivided, and more intermediate states, recovery states, locked states, or read-only states can be introduced in a specific system. As long as these states are still distinguished based on the hedging results and residual parameters, and correspond to different intensities of release, restriction, blocking, or recovery control, they still constitute an equivalent implementation of this invention.
[0162] In the foregoing embodiments, the payload to be processed can be split into a locally retained portion and an externally transmitted portion. It should be understood that this splitting can occur at the bit level, field level, segment level, residual level, as well as at the parameter level, index level, or derived representation level. The retained portion does not necessarily exist in plaintext form, but can be represented as local residual constraints, state masks, local mapping parameters, historical summary binding relationships, or other constraints that are not directly transmitted externally. Any scheme that completes closed-loop auditing by dispersing the complete causal chain into different nodes, different payload portions, or different time steps can be considered an equivalent transformation of this invention.
[0163] While the foregoing embodiments primarily illustrate scenarios such as high-value bank operations and government / private network terminal access, this invention is not limited to these specific applications. Any scenario involving device access authentication, secure communication handshake, controlled resource access, offline signature, sensitive data decryption, model integrity verification, multi-path constrained transmission, controlled terminal management, geographical locks, or time window control, as long as the platform main chain of this invention is used to implement secure access, restricted access, or blocking control, falls within the scope of this invention.
[0164] In the foregoing embodiments, for ease of explanation, the system is often divided into modules such as anchor point extraction, context acquisition, sequence deviation generation, load encoding, polarity offset verification, multi-value state processing, and anomaly handling. It should be understood that this division primarily serves illustrative purposes and does not imply that each module must exist physically independently. In specific implementations, multiple modules can be combined into the same hardware unit, the same processor core, the same firmware process, or the same state machine, or they can be distributed across different chips, different nodes, or different time steps. As long as the overall system still achieves the technical functions and causal relationships of this invention, it does not affect its inclusion within the scope of protection of this invention.
[0165] Although the foregoing description primarily focuses on the method, the technical concepts of this invention are equally applicable to various forms of objects, including devices, systems, chips, board-level modules, executable programs, firmware logic, microcode logic, and computer-readable storage media. For those skilled in the art, configuring the aforementioned method steps as device modules, system structures, chip units, or program instructions based on the technical teachings of this specification is a logical technical transformation and should not be construed as a completely new solution departing from the core ideas of this invention. Ending Remarks
[0166] In summary, this invention proposes a low-interaction security handshake and admission control platform mechanism based on local physical feature anchors, spatiotemporal context, sequence offset extraction, and simulated front-end polarity offset verification. This mechanism incorporates device physical state, environmental coupling conditions, session history, and current load into a closed audit chain, extending security decisions beyond upper-layer logic authorization or explicit key negotiation to a multi-layered admission structure that is physically-logically coordinated.
[0167] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit the present invention. Although the present invention has been described in detail with reference to several specific embodiments, those skilled in the art can make various equivalent substitutions, modifications, deletions, or combinations of the technical features, module forms, parameter configurations, connection relationships, process sequences, state divisions, and application scenarios without departing from the spirit and substance of the present invention. All technical solutions falling within the scope of the claims of the present invention and their equivalents should be covered within the protection scope of the present invention.
Claims
1. A low-interaction secure handshake method based on spatiotemporal context constraints, order deviation extraction, and polarity offset verification, characterized in that, include: S1. Obtain local physical feature anchor points of the communication end, access end, or verification end. These anchor points are generated from the state parameters of multiple physical nodes within the hardware carrier. The state parameters include at least one of conductance state, resistance state, polarization state, leakage current state, and threshold voltage state. S2. Obtain context parameters related to the current session. These context parameters include at least one of time parameters, spatial parameters, environmental parameters, operating state parameters, and historical state summaries. S3. Generate sequence deviation parameters based on the local physical feature anchor points, the context parameters, and the nonlinear distribution of the physical node states within the hardware carrier. Construct at least one of the following from the sequence deviation parameters: session mapping factor, deviation vector, residual parameter, and mapping matrix. S4. Perform projection, transformation, labeling, segmentation, and constraint coding on the payload to be processed. At least one of the following processes is performed to associate the payload to be processed with at least one of the session mapping factor, bias vector, residual parameter, and mapping matrix to obtain a handshake payload to be transmitted or verified; S5, at the receiving end, verification end, or local processing end, based on the corresponding local physical feature anchor point and context parameter, at least one of polarity offset verification, differential matching, residual auditing, and closure auditing is performed on the handshake payload at the analog front end to obtain a matching result, which is directly used to control the selection, restriction, or truncation of subsequent logic branches; S6, when the matching result meets the preset conditions, at least one of session establishment, access admission, payload recovery, instruction release, and data desealing is performed; when the matching result does not meet the preset conditions, at least one of gating suppression, differential reduction, payload zeroing, denial admission, partial blocking, and write protection is performed.
2. The method according to claim 1, characterized in that, The local physical feature anchors are derived from the stable or semi-stable distribution characteristics formed by multiple physical nodes in at least one of the following: self-pointing cell array, cross array, memristor array, ferroelectric cell array, phase change cell array, static random access memory array, dynamic random access memory array, and analog memory array, under the influence of manufacturing deviations, aging deviations, thermal noise disturbances, or readout deviations.
3. The method according to claim 1, characterized in that, The context parameters include at least one of the following: timestamp, time window identifier, location information, relative displacement information, oscillator drift parameters, temperature parameters, acceleration parameters, gravity perturbation parameters, power supply perturbation parameters, link status parameters, historical handshake summary, historical access summary, and previous session residual summary. At least some of the context parameters are obtained through the coupling response between the hardware carrier and environmental physical quantities. The coupling response is manifested as biasing, perturbing, or modulating the physical node's readout current, readout voltage, threshold distribution, polarization state, or oscillation characteristics.
4. The method according to claim 1, characterized in that, The sequence deviation parameter is generated by performing at least one of the following processes on the local physical feature anchor point and context parameter: mapping combination, weighted superposition, differential calculation, segmented quantization, threshold transformation, sequence expansion, matrix projection, residual compression, or state switching, and forms at least one of the following for subsequent verification: session mapping factor, deviation vector, residual parameter, mapping matrix, multi-valued state index, or polarity constraint sequence.
5. The method according to claim 1, characterized in that, The polarity offset verification is achieved through in-situ physical superposition or cancellation of the simulated front end. The implementation methods include at least one of differential bit line current superposition, differential word line voltage cancellation, cross node charge sharing, local grounding discharge, charge pump driven threshold verification, comparison amplification, and residual threshold audit. The matching result of the polarity offset verification includes at least a fully matched state, a partially matched state, and a mismatched state, wherein the partially matched state corresponds to a weak mismatch state where the residual parameter is within a preset range.
6. The method according to claim 1, characterized in that, The low-interaction security handshake is at least one of the following: handshake without explicit transmission of long-term keys, one-way triggered handshake, one-round-trip handshake, implicit confirmation handshake, segmented triggered handshake, and enhanced handshake deployed in parallel with existing security protocols.
7. The method according to claim 1, characterized in that, When the matching result is a complete match, at least one of the following is executed: session establishment, access admission, load recovery, and command release. When the matching result is a partial match, at least one of the following is executed: output limiting, feedback gain adjustment, integral window adjustment, gating reduction, fuzziness suppression, restricted release, and abnormal summary recording. When the matching result is a non-match, at least one of the following is executed: refuse to establish session, refuse data recovery, temporary load clearing, local write protection, local circuit breaking, and switching to restricted mode.
8. The method according to claim 1, characterized in that, The method is executed by a security device, a communication device, a payment terminal, a gateway device, an edge node, a trusted execution unit, a security coprocessor, a memory computing chip, or a hybrid analog-digital array chip. The device or chip includes a hardware unit for extracting local physical feature anchor points, a processing unit for generating sequence deviation parameters, and a verification unit for performing polarity offset verification. The verification unit includes a multi-value state processing unit for switching the corresponding output control strategy between a fully matched state, a partially matched state, and a non-matched state.
9. The method according to claim 1, characterized in that, The payload to be processed is split into a first payload part and a second payload part. The first payload part is retained in the form of residual constraints at the local processing end, and the second payload part is sent to the receiving end or the verification end. The receiving end or the verification end will only complete the closed audit and perform session establishment, data recovery or instruction release when the second payload part, the local physical feature anchor point, the context parameters and the constraint relationship corresponding to the first payload part together meet the preset conditions.