Servicinized wireless routing equipment access management system and method based on NFC (Near Field Communication) touch control
By introducing touch link integrity verification and dynamic key evolution tree modules into NFC touch network configuration, the problem that existing NFC touch network configuration cannot resist replay attacks and man-in-the-middle attacks is solved, achieving high security and convenient network access management, which is suitable for home and micro-enterprise environments.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-17
- Publication Date
- 2026-04-14
AI Technical Summary
Most existing NFC touch-based network configuration tools are only used to transmit Wi-Fi credentials and do not involve the integrity verification of the touch link between the terminal, cloud, and router. Therefore, they cannot effectively resist replay attacks and man-in-the-middle attacks.
The NFC-based service-oriented wireless routing device access management system introduces Touch Link Integrity Verification (TCV), calculates and compares TCV values using the cloud and router respectively, and establishes different key branches for different terminals using a dynamic key evolution tree module, thereby achieving collaborative verification and network resource control between the end, cloud, and router.
It significantly reduces the risk of replay attacks and man-in-the-middle attacks during NFC touch network configuration, enables network and service synergy, improves network security and operator service reliability, and reduces the burden of manual configuration for users.
Smart Images

Figure CN121865266A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of interdisciplinary technology of communication equipment and network security, and particularly relates to a service-oriented wireless routing device access management system and method based on NFC touch control. Background Technology
[0002] With the explosive growth in the number of smart terminals and IoT devices, the following application scenarios are commonly seen in home and micro-enterprise environments:
[0003] 1. Users want to be able to configure internet access simply by tapping their phone against the router, eliminating the need to remember complex Wi-Fi passwords or log into management pages, thus improving ease of use;
[0004] 2. For short-term internet access by guests, a secure guest access mechanism is needed that allows for easy connection while preventing access to sensitive home devices (NAS, cameras, printers, etc.).
[0005] 3. A large number of IoT devices (cameras, door locks, sensors, smart home gateways, etc.) are connected to the network and need to be automatically identified and isolated in restricted subnets to reduce the risk of attacks and lateral movement.
[0006] 4. Operators or service providers hope to use home routers as "service entry points" to trigger value-added services such as broadband speed-up, cloud storage, and parental controls on demand, thereby achieving synergy between the network and services.
[0007] Most existing NFC touch-based network configuration tools are only used to transmit Wi-Fi credentials and do not involve the integrity verification of the touch link between the terminal, cloud, and router. Therefore, they cannot effectively resist replay attacks and man-in-the-middle attacks. Summary of the Invention
[0008] The purpose of this invention is to provide a service-oriented wireless routing device access management system based on NFC touch control, which aims to solve the problem that most existing NFC touch network configurations are only used to transmit Wi-Fi credentials, without building a touch link integrity verification involving the terminal, cloud, and router, and thus cannot effectively resist replay attacks and man-in-the-middle attacks.
[0009] This invention is implemented as follows: a service-oriented wireless routing device access management system based on NFC touch control. The system includes a routing device, a mobile terminal, and a cloud management server. Both the routing device and the mobile terminal are connected to the cloud management server. The mobile terminal is used to interact with the routing device and submit authentication information to the cloud management server. The cloud management server is connected to the routing device and is used to authenticate the mobile terminal based on the authentication information. The routing device is used to receive the authentication result from the cloud management server and establish a connection with the mobile terminal.
[0010] Preferably, the routing device includes a main control processor, an NFC interaction module, a router random number generation module, a touch link integrity verification module, a dynamic key evolution tree module, a network resource control module, and a service policy triggering module.
[0011] Preferably, the main control processor is used to run the routing operating system and local control logic for NFC information parsing, TCV collaborative calculation, key evolution, and network policy distribution; the NFC interaction module is used to transmit router identification information to the mobile terminal via an NFC tag or active mode when the mobile terminal is near it; the router random number generation module is used to generate a router-side random salt value R-Salt using a true random number generator or a high-quality pseudo-random number generator for participation in TCV calculation.
[0012] Preferably, the touch link integrity verification module is used to calculate the TCV value in collaboration with the cloud after receiving the cloud signature C-Sign issued by the cloud management server and the M-Salt and TSID reported by the mobile terminal: the local calculation result is compared with the cloud calculation result to confirm the legality of the same touch session; the dynamic key evolution tree module is used to derive branch keys based on the scene identifier Scene_ID and the device identifier Dev_ID, starting from the securely stored root key Key0, to establish different key branches for the master terminal, guest terminal and IoT device respectively; the network resource control module works with the router kernel and switching chip to automatically configure according to the scene prediction results; the service policy triggering module connects with the operator or service provider's backend system, reports events and triggers the corresponding service policies.
[0013] Preferably, the mobile terminal includes an NFC parsing module, a random salt value generation module, and a three-factor authentication packaging module. The NFC parsing module is used to interact with the router's NFC, parse the TSID, router identifier, and fingerprint digest, and pass them to the upper-layer App. The random salt value generation module generates a random salt value M-Salt on the mobile terminal side for TCV calculation. The three-factor authentication packaging module constructs three-factor authentication information based on the user login state, device digital certificate, and device fingerprint features, and reports it to the cloud management server along with the TSID and M-Salt.
[0014] Preferably, the cloud management server includes a three-factor security authentication module, a touch link integrity collaboration module, a device behavior profiling module, a scene prediction strategy engine, and a dynamic key evolution control module.
[0015] Preferably, the three-factor authentication module is used to verify the legality and validity of the token, the signature chain and revocation status of the device digital certificate, and whether the device fingerprint features are consistent with historical records, and calculates the risk score; the touch link integrity collaboration module generates a cloud signature C-Sign after authentication, shares TSID, M-Salt, C-Sign and R-Salt information with the router, and participates in the calculation and verification of TCV; the device behavior profile module constructs a behavior profile based on the terminal's historical touch records, internet access behavior, risk events, and TCV failure / success statistics, and outputs the device trustworthiness and risk score.
[0016] Preferably, the scenario prediction strategy engine determines the scenario type based on behavioral profiles, current access location, and user account attribute characteristics; the dynamic key evolution control module converts the scenario prediction results into control instructions for the KET module on the router side, specifies the key branch and derived parameters to be used, and sends them to the router and mobile terminal through a secure channel.
[0017] Another object of the present invention is to provide a service-oriented wireless routing device access management method based on NFC touch control, applied to the service-oriented wireless routing device access management system based on NFC touch control as described in any one of claims 1-8, the method comprising:
[0018] S1: NFC Touch Control and Basic Information Exchange: When the mobile terminal approaches the NFC area of the router, the NFC module triggers a touch event; the router sends the TSID, router serial number and router fingerprint digest to the mobile terminal; the mobile terminal generates an M-Salt and hands the TSID and M-Salt to the upper-layer App;
[0019] S2: Three-factor authentication request reporting: The mobile terminal App packages the TOKEN, device digital certificate, device fingerprint, TSID and M-Salt together and sends them to the cloud management server through an encrypted connection;
[0020] S3: Cloud-based three-factor authentication and C-Sign generation: The cloud management server verifies the legality and validity of the token, verifies the trustworthiness of the certificate chain, checks whether it has been revoked, performs consistency and risk analysis on the device fingerprint, obtains the risk level, and when all three factors pass, the cloud generates a cloud signature C-Sign and sends the TSID, M-Salt and C-Sign to the router.
[0021] S4: End-to-Cloud-to-Router TCV Collaborative Calculation and Verification: The router generates R-Salt, and the cloud and router calculate respectively: TCV = Hash(TSID + M-Salt + C-Sign + R-Salt). The calculation results are compared: only when the TCVs of the two ends are consistent, the touch link is deemed trustworthy; otherwise, the current access process is rejected.
[0022] S5: Behavioral profiling and scenario prediction: The cloud inputs the current TCV success events, three-factor authentication results and historical behavioral data into the behavioral profiling module. The device behavioral profiling module outputs device credibility and risk score indicators. The scenario prediction strategy engine determines the scenario type based on the behavioral profile, user account information and device category.
[0023] S6: Key Evolution and Distribution: The cloud-based dynamic key evolution control module generates key branch selection instructions and derived parameters according to the scenario type. The router takes the root key Key0, Scene_ID, and Dev_ID as inputs and derives the corresponding branch key Key_branch. It then synchronizes a portion of the parameters of Key_branch or its derived session key to the mobile terminal.
[0024] S7: Network resource configuration and service-oriented policy triggering: The router's network resource control module automatically executes the corresponding policy based on the scenario type.
[0025] Preferably, the method further includes S8: Log recording and proactive risk handling: The router and cloud record TCV verification failure events, abnormal scenario switching and abnormal access behavior logs; when high-risk behavior is detected, the terminal privileges are automatically reduced, the connection is switched to a more stringent IoT scenario or the establishment of a new session is rejected.
[0026] This invention provides a service-oriented wireless routing device access management system based on NFC touch control. By introducing Touch Link Integrity Verification (TCV), it uses the touch sequence number (TSID), terminal random salt value (M-Salt), cloud signature (C-Sign), and router random salt value (R-Salt) as hash inputs. The cloud and router independently calculate and compare the TCVs. Because the TCV is simultaneously bound to the terminal-side random value, the cloud authentication result, and the router-side random value, even if an attacker intercepts some parameters, they cannot successfully replay the event at another time or on another device. Furthermore, this invention can design the TSID as a one-time identifier, marking it as invalid after the first successful TCV verification, thereby further preventing the reuse of the same touch session. Compared to existing solutions that only transmit Wi-Fi credentials in NFC, this invention can significantly reduce the risk of replay attacks and man-in-the-middle attacks during NFC touch network configuration at the protocol level. Attached Figure Description
[0027] Figure 1 An architecture diagram of a service-oriented wireless routing device access management system based on NFC touch control provided in an embodiment of the present invention;
[0028] Figure 2 A schematic diagram of the data flow for three-factor authentication and initial data exchange based on NFC touch provided in an embodiment of the present invention;
[0029] Figure 3 The timing diagram for calculating the Touch Link Integrity Verification (TCV) and the end-to-cloud-to-router collaborative verification provided in this embodiment of the invention;
[0030] Figure 4 Data flow and processing flowchart of the device behavior profiling and scene prediction strategy engine provided in the embodiments of the present invention.
[0031] Figure 5 A schematic diagram of the data flow for branching and key distribution in the dynamic key evolution tree (KET) provided in this embodiment of the invention;
[0032] Figure 6 This is a schematic diagram of the state machine and data flow for triggering scenario-based network resource control and service-oriented strategies, provided in an embodiment of the present invention. Detailed Implementation
[0033] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention.
[0034] like Figure 1 The diagram shown is an architecture diagram of a service-oriented wireless routing device access management system based on NFC touch control provided in an embodiment of the present invention. The system includes a routing device, a mobile terminal, and a cloud management server. Both the routing device and the mobile terminal are connected to the cloud management server. The mobile terminal is used to interact with the routing device and submit authentication information to the cloud management server. The cloud management server is connected to the routing device and is used to authenticate the mobile terminal based on the authentication information. The routing device is used to receive the authentication result from the cloud management server and establish a connection with the mobile terminal.
[0035] In this embodiment of the invention, the system comprises three main parts: a routing device, a mobile terminal, and a cloud management server.
[0036] Routing devices include:
[0037] (1) Main control processor (CPU / SoC / MCU): runs the routing operating system and local control logic, and is responsible for NFC information parsing, TCV collaborative calculation, key evolution and network policy distribution.
[0038] (2) NFC interaction module: Deployed on the front panel of the router casing, it is used to transmit the router identification information (such as TSID, router serial number, hardware fingerprint digest, etc.) to the mobile terminal via NFC tag or active mode when the mobile terminal is close.
[0039] (3) Router random number generation module: Generates a random salt value R-Salt on the router side through a true random number generator (TRNG) or a high-quality pseudo random number generator (PRNG) for use in TCV calculation.
[0040] (4) Touch Link Integrity Verification Module (TCV Module): After receiving the cloud signature C-Sign issued by the cloud management server and the M-Salt and TSID reported by the mobile terminal, the module works with the cloud to calculate the TCV value: TCV = Hash(TSID + M-Salt + C-Sign + R-Salt); and compares the local calculation result with the cloud calculation result to confirm that it is the same legitimate touch session.
[0041] (5) Dynamic Key Evolution Tree Module (KET Module): Starting from the securely stored root key Key0, branch keys are derived according to the scene identifier Scene_ID and the device identifier Dev_ID: Key_branch=KDF(Key0,Scene_ID||Dev_ID); different key branches are established for the master terminal, the guest terminal and the IoT device respectively, and session keys, guest temporary keys, etc. can be further derived.
[0042] (6) Network Resource Control Module: Works with the router kernel and switching chip to automatically configure based on scenario prediction results: different SSID / VLANID; Layer 2 (L2) isolation rules between terminals; uplink / downlink bandwidth limits and priority queues (QoS); access control lists (ACLs), such as allowing IoT terminals to access cloud server IPs only.
[0043] (7) Service policy triggering module: It connects with the back-end system of the operator or service provider, and reports events and triggers corresponding service policies (such as broadband speed-up, cloud storage mounting, video surveillance packages, etc.) in situations such as master binding scenario and specific IoT device access scenario.
[0044] Mobile terminals include:
[0045] (1) NFC parsing module: responsible for interacting with the router's NFC, parsing information such as TSID, router identifier, and fingerprint digest, and passing it to the upper-layer App.
[0046] (2) Random Salt Value Generation Module (M-Salt Module): Generates random salt value M-Salt on the mobile terminal side for TCV calculation to prevent session predictability.
[0047] (3) Three-factor authentication packaging module: The three-factor authentication information is composed of user login state (token), device digital certificate (DeviceCert), device fingerprint features (such as IMEI / OS fingerprint / application signature), and is reported to the cloud management server along with TSID and M-Salt.
[0048] (4) Local key storage and tunnel module (optional): Used to store branch keys or derived parameters issued by the cloud. In some implementations, it can also establish an encrypted tunnel between the end and the router (such as WireGuard / IPSec) for traffic management.
[0049] The cloud management server includes:
[0050] (1) Three-factor security authentication module: used to verify the legality and validity of the TOKEN, the signature chain and revocation status of the device digital certificate, whether the device fingerprint features are consistent with the historical records, and to calculate the risk score.
[0051] (2) Touch Link Integrity Coordination Module: After authentication, it generates a cloud signature C-Sign, shares TSID, M-Salt, C-Sign and R-Salt information with the router, and participates in the calculation and verification of TCV.
[0052] (3) Device Behavior Profiling Module: Based on information such as terminal historical touch records, internet access behavior, risk events, and TCV failure / success statistics, a behavioral profile is constructed, and the device trustworthiness and risk score are output. (Note: This module generates quantitative indicators for network control by analyzing technical data, which is a technical means.)
[0053] (4) Scene prediction strategy engine: Based on behavioral profiles, current access location (NFC touch location / router identifier), user account attributes and other features, determine the scene type: owner binding scene; visitor access scene; IoT device access scene; special high-risk scene (e.g., abnormal touch location, many historical risks).
[0054] (5) Dynamic Key Evolution Control Module: Converts the scenario prediction results into control instructions for the KET module on the router side, specifies the key branch and derived parameters to be used, and sends them to the router and mobile terminal through a secure channel (such as TLS) to achieve end-to-end router key synchronization.
[0055] This invention also provides a service-oriented wireless routing device access management method based on NFC touch control, the specific steps of which are as follows:
[0056] S1: NFC Touch Control and Basic Information Exchange: When the mobile terminal approaches the NFC area of the router, the NFC module triggers a touch event; the router sends initial information such as TSID, router serial number, and router fingerprint digest to the mobile terminal; the mobile terminal generates M-Salt and hands TSID and M-Salt to the upper-layer App.
[0057] S2: Three-Factor Authentication Request Reporting: The mobile terminal App packages the TOKEN, device digital certificate, device fingerprint, TSID, and M-Salt together and sends them to the cloud management server via an encrypted connection (HTTPS / QUIC, etc.).
[0058] S3: Cloud-based three-factor authentication and C-Sign generation: The cloud management server verifies the legality and validity of the token; verifies the trustworthiness of the certificate chain and checks whether it has been revoked; performs consistency and risk analysis on the device fingerprint to obtain the risk level; when all three factors pass, the cloud generates a cloud signature C-Sign and sends the TSID, M-Salt, and C-Sign to the router.
[0059] S4: End-to-Cloud-to-Router TCV Collaborative Calculation and Verification: The router generates R-Salt; the cloud and the router calculate respectively: TCV = Hash(TSID + M-Salt + C-Sign + R-Salt); the calculation results are compared: only when the TCVs of both ends are consistent is the touch link considered trustworthy, otherwise the current access process is rejected; the TSID can be marked as invalid after the first successful TCV verification to prevent replay.
[0060] S5: Behavioral profiling and scenario prediction: The cloud inputs the current TCV success event, three-factor authentication result and historical behavior data into the behavioral profiling module; the behavioral profiling module outputs indicators such as device credibility and risk score; the scenario prediction strategy engine determines the scenario type (owner / visitor / IoT, etc.) based on the behavioral profile, user account information, and device category (mobile phone / TV / IoT module, etc.).
[0061] S6: Key Evolution and Distribution: The cloud-based dynamic key evolution control module generates key branch selection instructions and derived parameters according to the scenario type; the router's KET module derives the corresponding branch key Key_branch from the root key Key0 and Scene_ID, Dev_ID; depending on the implementation requirements, a portion of the parameters of Key_branch or its derived session key can be synchronized to the mobile terminal to generate wireless access credentials or encrypted tunnel keys.
[0062] S7: Network Resource Configuration and Service-Oriented Policy Triggering: The router's network resource control module automatically completes the following based on the scenario type: For master terminals connected to the main network SSID / VLAN, home LAN access is enabled, ensuring bandwidth priority; for guest terminals connected to the guest VLAN, access to the home LAN is prohibited, allowing only public network access; for IoT devices connected to the IoT VLAN, access to the pre-configured cloud platform IP / port is permitted, prohibiting lateral scanning and inter-terminal access. The service policy triggering module reports to the operator's backend when key events such as master binding or specific IoT device access occur, triggering the activation of value-added services or policy adjustments.
[0063] S8: Log recording and proactive risk handling (optional): The router and cloud record TCV verification failure events, abnormal scene switching, abnormal access behavior, etc.; when high-risk behavior is detected, the terminal privileges can be automatically reduced, switched to a more stringent IoT scene, or the establishment of new sessions can be rejected.
[0064] This invention not only completes three-factor authentication based on token, device certificate, and device fingerprint in the cloud, but also inputs the authentication results and TCV verification results into the behavior profiling module and scenario prediction strategy engine to obtain access scenarios such as owner, visitor, and IoT. The output of scenario prediction directly drives the branch selection of the dynamic key evolution tree (KET) on the router side and the configuration of network resources such as VLAN, ACL, bandwidth, and mutual access permissions. For example, in the owner scenario, the terminal is assigned a main network VLAN, allowing global LAN access and giving it a high bandwidth priority; in the visitor scenario, the terminal is assigned a visitor VLAN, prohibiting access to internal sensitive resources and only allowing access to the Internet; in the IoT scenario, the terminal is assigned an IoT VLAN, and ACLs restrict it to access only the preset cloud platform address and prohibit inter-terminal access. Compared with the existing technology where authentication and network control are separated and policies cannot adapt, this invention realizes automatic linkage from identity authentication to network topology and access control, enabling the network to adaptively adjust according to terminal category and risk status.
[0065] This invention employs a Dynamic Key Evolution Tree (KET), based on the root key Key0, and derives different branch keys and session keys according to the access scenario identifier Scene_ID and device identifier Dev_ID. By maintaining separate key branches for scenarios such as owner, guest, and IoT, and setting limited validity periods for guest branches and shorter update cycles for high-risk IoT devices, this invention can achieve independent revocation and update operations for different scenarios and devices without changing the root key. When a guest terminal or IoT device is determined to be high-risk, only its corresponding branch key needs to be revoked or its validity period shortened; other terminals are unaffected. Compared to traditional schemes using a single Wi-Fi password or unified key, this invention significantly improves the security and operational flexibility of key management, and reduces the risk of large-scale security incidents due to key leakage.
[0066] This invention utilizes a behavior profiling module and a scenario prediction strategy engine to comprehensively consider various characteristics of the terminal, such as touch frequency, usage time distribution, historical risk events, and access service types, to automatically determine whether the terminal belongs to the owner, guest, or IoT device scenario. Based on this, the system automatically selects the corresponding KET branch and network policy, eliminating the need for users to manually configure different SSIDs or complex firewall rules for each type of device. For ordinary users, a simple NFC touch operation is all that's needed to automatically complete complex security policies and network isolation configurations in the background, greatly reducing the burden of manual configuration and improving the overall user experience.
[0067] This invention incorporates a service policy triggering module within a service-oriented wireless router. When a user successfully binds their device, a specific IoT device connects, or a specific event is detected, the router reports the event to the operator or service platform, triggering the activation or adjustment of value-added services such as broadband speed upgrades, home cloud services, and video surveillance packages. Since this event triggering is based on TCV verification, three-factor authentication, and behavioral profiling, operators can more accurately identify genuine users and devices, reducing the risk of fraudulent activations and malicious abuse. Thus, this invention, while ensuring convenient terminal access and LAN security, also provides operators and service providers with a unified and reliable service entry point, possessing significant commercial expansion value.
[0068] The NFC interaction, hash function, key derivation function (KDF), VLAN, ACL, QoS, and other technologies employed in this invention can all be implemented on existing router hardware and operating systems. The behavior profiling and scenario prediction modules can also be implemented based on common data analysis or rule engines, without introducing entirely new protocol standards. Through modular design, this invention allows for the tailoring of functional modules on routers of different performance levels, making it suitable for home-level routing devices as well as expanding to small business gateways or carrier-customized CPE devices, demonstrating good engineering feasibility and scalability.
[0069] like Figure 1 The diagram shown is a block diagram of the overall system architecture:
[0070] This figure illustrates the overall architecture of the system of the present invention, which includes three main parts: a mobile terminal, a service-oriented wireless routing device, and a cloud management server.
[0071] The mobile terminal side includes: an NFC parsing module, an M-Salt generation module, a three-factor authentication packaging module, and a local key storage module, etc.
[0072] The routing device includes: an NFC interaction module, a random number generation module R-Salt, a TCV module, a KET module, a network resource control module, and a service policy triggering module, etc.
[0073] The cloud management server side includes: a three-factor security authentication module, a touch link integrity collaboration module, a behavior profiling module, a scene prediction strategy engine, and a dynamic key evolution control module.
[0074] Figure 1 Data flow description:
[0075] 1. Data Stream F1-1: NFC Touch Basic Information Stream:
[0076] Direction: Router NFC module → Mobile terminal NFC parsing module;
[0077] Contents include: TSID, router serial number, router fingerprint digest, etc.
[0078] 2. Data Flow F1-2: Three-Factor Authentication Request Flow:
[0079] Direction: Mobile App → Cloud Management Server;
[0080] Contents include: TOKEN, device digital certificate, device fingerprint, TSID, M-Salt, etc.
[0081] 3. Data Flow F1-3: C-Sign and TCV Collaborative Information Flow:
[0082] Direction: Cloud management server → Router TCV module;
[0083] Contents include: TSID, M-Salt, C-Sign, TCV verification commands, etc.
[0084] 4. Data Flow F1-4: Scene Prediction and Key Control Flow
[0085] Direction: Cloud-based scenario prediction strategy engine → Router KET module and network resource control module;
[0086] Contents include: scenario type (owner / visitor / IoT), key branch selection instructions, and policy parameters.
[0087] 5. Data Flow F1-5: Service Policy Reporting Flow:
[0088] Direction: Router service policy triggering module → Carrier / Service Platform;
[0089] Contents include: event binding, access scenario information, and terminal type statistics.
[0090] Figure 2 Data flow diagram for NFC touch-based three-factor authentication and initial data exchange:
[0091] This diagram illustrates in detail the process from when a user touches the NFC sensor to completing three-factor authentication.
[0092] Step T2-1: The mobile terminal uses NFC to read the TSID, router serial number, etc.
[0093] Step T2-2: The terminal generates an M-Salt and packages it together with the TOKEN, device certificate, and device fingerprint;
[0094] Step T2-3: The terminal initiates an authentication request to the cloud;
[0095] Step T2-4: Generate C-Sign after successful cloud verification.
[0096] Figure 2 Data flow description:
[0097] 1. Data stream F2-1: TSID propagation stream;
[0098] Direction: Router → Mobile Terminal;
[0099] Contents: TSID, Router ID, Fingerprint digest;
[0100] Function: Identifies the current touch session and the target router.
[0101] 2. Data Flow F2-2: Three-Factor Authentication Request Flow:
[0102] Direction: Mobile terminal → Cloud;
[0103] Contents: TOKEN + DeviceCert + Fingerprint + TSID + M-Salt;
[0104] Function: To complete the integrated verification of user identity, device identity, and device fingerprint.
[0105] 3. Data Flow F2-3: Cloud Authentication Results and C-Sign Distribution Flow:
[0106] Direction: Cloud → Router (synchronize some information to the terminal when necessary);
[0107] Contents: C-Sign, authentication result marking, and subsequent TCV calculation instructions.
[0108] Figure 3 Verify the TCV coordination timing diagram for touch link integrity;
[0109] This diagram illustrates the time sequence in which the cloud and router collaborate to complete TCV calculation and verification.
[0110] After three-factor authentication is successful, both the cloud and the router simultaneously hold TSID, M-Salt, and C-Sign; the router generates R-Salt; both parties calculate TCV and compare the results.
[0111] Figure 3 Data flow description:
[0112] 1. Data Flow F3-1: R-Salt Generation and Holding Flow:
[0113] Direction: Inside the router;
[0114] Content: R-Salt;
[0115] Function: To introduce router-side randomness to this touch session.
[0116] 2. Data Stream F3-2: TCV Calculation Input Stream:
[0117] Areas of expertise: Cloud / router internal algorithm modules;
[0118] Contents: TSID, M-Salt, C-Sign, R-Salt;
[0119] 3. Data stream F3-3: TCV verification result stream:
[0120] Direction: Cloud or router → Scene prediction engine / network resource control module;
[0121] Content: TCV match / non-match flag;
[0122] Function: The access process continues only if TCV matches; otherwise, it terminates.
[0123] Figure 4 Data flow diagram for device behavior profiling and scenario prediction strategy engine;
[0124] This diagram illustrates how the cloud aggregates various behavioral data into profiles and outputs scene types.
[0125] Figure 4 Data flow description:
[0126] 1. Data Stream F4-1: Behavioral Data Reporting Stream
[0127] Direction: Router / Mobile Terminal → Cloud-based Behavioral Profiling Module;
[0128] Contents include: touch time, internet usage duration, type of service accessed, TCV success rate, and risk event records.
[0129] 2. Data Flow F4-2: Image Generation and Storage Flow
[0130] Direction: Behavioral profiling module → Profiling database;
[0131] Content: Device credibility, risk score, usage habit feature vector, etc.
[0132] 3. Data Flow F4-3: Scene Prediction Request and Response Flow:
[0133] Direction: TCV success events → Scene prediction strategy engine → Dynamic key control module;
[0134] Content: The request includes the device ID and profile characteristics; the response includes the scenario type, policy parameters, etc.
[0135] Figure 5 A data flow graph for the KET branch derivation and distribution of the dynamic key evolution tree;
[0136] This diagram illustrates how the root key Key0 derives branch keys for different scenarios, and how necessary information is securely transmitted to routers and mobile terminals.
[0137] Figure 5 Data flow description:
[0138] 1. Data Flow F5-1: Scene Command Flow:
[0139] Direction: Scene prediction strategy engine → KET module;
[0140] Contents: Scene_ID, Dev_ID, risk level, etc.
[0141] 2. Data Stream F5-2: Key Derivation Stream:
[0142] Direction: Inside the KET module;
[0143] Content: Key0→Key_master→Key_branch→Session_Key;
[0144] Function: Generate keys level by level according to the scenario, supporting different branches such as owner, visitor, and IoT.
[0145] 3. Data Stream F5-3: Key Parameter Distribution Stream:
[0146] Direction: KET module → Router network control module / Mobile terminal;
[0147] Content: The derived key or parameters used to generate the key (such as salt value, counter);
[0148] Function: Used to configure Wi-Fi credentials, access tokens, or encrypted tunnel keys.
[0149] Figure 6 The state machine data flow diagram for scenario-based network resource control and service-oriented strategies is as follows:
[0150] This diagram illustrates how the system switches between different network states based on the scenario and simultaneously triggers service policies. Figure 6 Data flow description:
[0151] 1. Data Stream F6-1: Status Input Stream:
[0152] Direction: Scene prediction engine → Network resource control module;
[0153] Content: Scenario type, risk level, key branch information.
[0154] 2. Data Flow F6-2: Network Policy Distribution Flow:
[0155] Direction: Network resource control module → Router operating system / switching chip;
[0156] Contents include: VLAN ID, SSID configuration, ACL rules, QoS parameters, etc.
[0157] 3. Data Flow F6-3: Service Triggered Reporting Flow:
[0158] Direction: Service policy triggering module → Carrier / Service Platform;
[0159] Contents include: owner binding events, specific IoT device launch events, and package change suggestions.
[0160] 4. Data Flow F6-4: Status Feedback Flow:
[0161] Direction: Carrier / Service Platform → Router / Cloud;
[0162] Contents include service activation results, policy update instructions, etc., used to further adjust local network policies.
[0163] Example 1: System hardware and software configuration example:
[0164] 1. Hardware configuration:
[0165] Router main control: adopts a multi-core network processor (such as ARM Cortex-A53 architecture SoC) and integrates a gigabit Ethernet switching chip;
[0166] Wireless module: Supports dual-band Wi-Fi 6, providing main network SSID and guest SSID;
[0167] NFC module: An NFC control chip supporting the ISO14443 Type A / B protocol, via I... 2 Connect to the master controller via C or SPI bus;
[0168] Secure storage module: Used to store sensitive information such as root key Key0 and device certificates;
[0169] Mobile terminal: running Android or iOS system, supporting NFC function, and having an access management app provided by the operator or manufacturer installed.
[0170] 2. Software Modules:
[0171] The router runs embedded Linux and uses a daemon process to implement NFC monitoring, TCV calculation, KET derivation, and network policy distribution.
[0172] The cloud-based microservice architecture provides services such as three-factor authentication, behavioral profiling, scenario prediction, and KET control.
[0173] The mobile app provides an NFC touch guidance interface, allowing users to complete the "near-to-confirm" operation in two steps.
[0174] Example 2: Pseudocode explanation of TCV calculation:
[0175] Taking the router side as an example, the TCV calculation process is illustrated below (pseudocode):
[0176]
[0177]
[0178] The cloud can use the same input to perform TCV calculations and compare the results with the router through a secure channel.
[0179] Example 3: Network policy configuration example for the corresponding scenario:
[0180] Master binding scenario:
[0181] Assign a main network VLAN (e.g., VLAN 10); allow access to all subnets and management pages on the local area network; QoS priority is the highest; binding an account can trigger the operator's broadband speed-up package.
[0182] Visitor access scenarios:
[0183] Assign a visitor VLAN (e.g., VLAN 20);
[0184] Access to sensitive IP addresses such as internal NAS and cameras is prohibited.
[0185] Internet access only;
[0186] The visitor key is valid for 24 hours and must be reactivated via NFC touch upon expiration.
[0187] IoT device access scenarios:
[0188] Assign IoT VLANs (e.g., VLAN 30);
[0189] ACL rules only allow access to the vendor's cloud platform IP and specific ports;
[0190] Disallow terminals in this VLAN to access each other;
[0191] It enables dedicated monitoring and risk control of IoT device behavior in the cloud.
[0192] The above embodiments demonstrate that the present invention has good feasibility on existing hardware and software platforms.
[0193] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the protection scope of the present invention.
Claims
1. A service-oriented wireless routing device access management system based on NFC touch control, characterized in that, The system includes a routing device, a mobile terminal, and a cloud management server. Both the routing device and the mobile terminal are connected to the cloud management server. The mobile terminal is used to interact with the routing device and submit authentication information to the cloud management server. The cloud management server is connected to the routing device and is used to authenticate the mobile terminal based on the authentication information. The routing device is used to receive the authentication result from the cloud management server and establish a connection with the mobile terminal.
2. The NFC-based touch-based service-oriented wireless routing device access management system according to claim 1, characterized in that, The routing device includes a main control processor, an NFC interaction module, a router random number generation module, a touch link integrity verification module, a dynamic key evolution tree module, a network resource control module, and a service policy triggering module.
3. The NFC-based touch-based service-oriented wireless routing device access management system according to claim 2, characterized in that, The main control processor is used to run the routing operating system and local control logic, and is used for NFC information parsing, TCV collaborative calculation, key evolution and network policy distribution; the NFC interaction module is used to transmit router identification information to the mobile terminal through NFC tag or active mode when the mobile terminal is close. The router random number generation module is used to generate a random salt value R-Salt on the router side using a true random number generator or a high-quality pseudo-random number generator, which is then used in TCV calculation.
4. The NFC-based touch-based service-oriented wireless routing device access management system according to claim 3, characterized in that, The Touch Link Integrity Verification module, upon receiving the cloud signature C-Sign from the cloud management server and the M-Salt and TSID reported by the mobile terminal, collaborates with the cloud to calculate the TCV value. It compares the local calculation result with the cloud calculation result to confirm the legitimacy of the same touch session. The Dynamic Key Evolution Tree module, starting from the securely stored root key Key0, derives branch keys based on the Scene ID and Device ID Dev ID, establishing different key branches for the master terminal, guest terminal, and IoT device. The Network Resource Control module collaborates with the router kernel and switching chip to automatically configure based on scene prediction results. The Service Policy Triggering module interfaces with the operator's or service provider's backend system, reporting events and triggering corresponding service policies.
5. The NFC-based touch-based service-oriented wireless routing device access management system according to claim 1, characterized in that, The mobile terminal includes an NFC parsing module, a random salt value generation module, and a three-factor authentication packaging module. The NFC parsing module is used to interact with the router's NFC, parse the TSID, router identifier, and fingerprint digest, and pass them to the upper-layer App. The random salt value generation module generates a random salt value M-Salt on the mobile terminal side for TCV calculation. The three-factor authentication packaging module constructs three-factor authentication information based on the user login state, device digital certificate, and device fingerprint features, and reports it to the cloud management server along with the TSID and M-Salt.
6. The NFC-based touch-based service-oriented wireless routing device access management system according to claim 1, characterized in that, The cloud management server includes a three-factor security authentication module, a touch link integrity collaboration module, a device behavior profiling module, a scenario prediction strategy engine, and a dynamic key evolution control module.
7. The NFC-based touch-based service-oriented wireless routing device access management system according to claim 6, characterized in that, The three-factor security authentication module is used to verify the legality and validity of the token, the signature chain and revocation status of the device digital certificate, and whether the device fingerprint features are consistent with historical records, and to calculate a risk score. After successful authentication, the Touch Link Integrity Coordination Module generates a cloud signature C-Sign, which shares TSID, M-Salt, C-Sign, and R-Salt information with the router and participates in TCV calculation and verification. The Device Behavior Profile Module constructs a behavior profile based on the terminal's historical touch records, internet access behavior, risk events, and TCV failure / success statistics, and outputs device trustworthiness and risk score.
8. The NFC-based touch-based service-oriented wireless routing device access management system according to claim 7, characterized in that, The scenario prediction strategy engine determines the scenario type based on behavioral profiles, current access location, and user account attribute characteristics. The dynamic key evolution control module converts the scenario prediction results into control instructions for the KET module on the router side, specifies the key branch and derived parameters to be used, and sends them to the router and mobile terminal through a secure channel.
9. A service-oriented wireless routing device access management method based on NFC touch control, characterized in that, The method, applied to the NFC-based touch-based service-oriented wireless routing device access management system as described in any one of claims 1-8, comprises: S1: NFC Touch Control and Basic Information Exchange: When the mobile terminal approaches the NFC area of the router, the NFC module triggers a touch event; the router sends the TSID, router serial number and router fingerprint digest to the mobile terminal; the mobile terminal generates an M-Salt and hands the TSID and M-Salt to the upper-layer App; S2: Three-factor authentication request reporting: The mobile terminal App packages the TOKEN, device digital certificate, device fingerprint, TSID and M-Salt together and sends them to the cloud management server through an encrypted connection; S3: Cloud-based three-factor authentication and C-Sign generation: The cloud management server verifies the legality and validity of the token, verifies the trustworthiness of the certificate chain, checks whether it has been revoked, performs consistency and risk analysis on the device fingerprint, obtains the risk level, and when all three factors pass, the cloud generates a cloud signature C-Sign and sends the TSID, M-Salt and C-Sign to the router. S4: End-to-Cloud-to-Router TCV Collaborative Calculation and Verification: The router generates R-Salt, and the cloud and router calculate respectively: TCV = Hash(TSID + M-Salt + C-Sign + R-Salt). The calculation results are compared: only when the TCVs of the two ends are consistent, the touch link is deemed trustworthy; otherwise, the current access process is rejected. S5: Behavioral profiling and scenario prediction: The cloud inputs the current TCV success events, three-factor authentication results and historical behavioral data into the behavioral profiling module. The device behavioral profiling module outputs device credibility and risk score indicators. The scenario prediction strategy engine determines the scenario type based on the behavioral profile, user account information and device category. S6: Key Evolution and Distribution: The cloud-based dynamic key evolution control module generates key branch selection instructions and derived parameters according to the scenario type. The router takes the root key Key0, Scene_ID, and Dev_ID as inputs and derives the corresponding branch key Key_branch. It then synchronizes a portion of the parameters of Key_branch or its derived session key to the mobile terminal. S7: Network resource configuration and service-oriented policy triggering: The router's network resource control module automatically executes the corresponding policy based on the scenario type.
10. The service-oriented wireless routing device access management method based on NFC touch control according to claim 9, characterized in that, The method also includes S8: Log recording and proactive risk handling: The router and cloud record TCV verification failure events, abnormal scene switching and abnormal access behavior logs; when high-risk behavior is detected, the terminal privileges are automatically reduced, the connection is switched to a more stringent IoT scene or the establishment of a new session is rejected.