Multi-mode-based device identity cheating detection method, device, product and medium

By employing a multimodal device identity spoofing detection method, which utilizes multiple device fingerprints and historical stability data to calculate the time decay coefficient and dynamically adjust the verification level and threshold, the method solves the problem of insufficient accuracy of single fingerprint authentication and achieves high efficiency and reliability in device identity authentication.

CN121940183APending Publication Date: 2026-04-28BEIJING FULE TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING FULE TECH CO LTD
Filing Date
2026-01-21
Publication Date
2026-04-28

AI Technical Summary

Technical Problem

Existing device authentication methods mainly rely on a single type of device fingerprint, which makes the authentication accuracy susceptible to changes in the device fingerprint and makes it difficult to effectively identify identity fraud.

Method used

A multimodal device identity spoofing detection method is adopted. By acquiring multiple different types of device fingerprints and their historical stability data, the time decay coefficient is calculated, the number of verification levels is dynamically determined, and different device fingerprints are assigned to each level. The verification is performed layer by layer and the threshold is adjusted to improve the authentication accuracy.

Benefits of technology

It improves the accuracy and robustness of device authentication, effectively identifies identity spoofing, and performs adaptive matching and resource optimization when device fingerprints change, ensuring the reliability and efficiency of the verification process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121940183A_ABST
    Figure CN121940183A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-mode-based equipment identity cheating detection method, equipment, a product and a medium, and relates to the technical field of Internet of Things security. The method comprises the steps that multiple different types of device fingerprints of a device to be authenticated and historical stability data corresponding to the device fingerprints are acquired; according to each piece of historical stability data, calculating an aging attenuation coefficient of each equipment fingerprint; determining the number of verification hierarchies needing to be executed by the current authentication according to the time attenuation coefficient of each equipment fingerprint; distributing different device fingerprints for each verification hierarchy; obtaining a verification result of the current verification level according to the device fingerprint of the current verification level and the verification threshold value of the current verification level; when the verification result is passed, the verification threshold value of the next verification level is adjusted according to the difference degree; and according to the verification result of each verification level, determining whether the to-be-authenticated device has an identity cheating behavior. By implementing the technical scheme provided by the invention, the authentication accuracy can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of Internet of Things (IoT) security, specifically to a method, device, product, and medium for detecting device identity spoofing based on multimodality. Background Technology

[0002] With the rapid development of IoT technology, more and more devices are interconnected through networks, making device authentication a crucial link in ensuring the security of IoT systems. Device authentication technology mainly confirms the authenticity of a device's identity by collecting and verifying its characteristic information (i.e., device fingerprint).

[0003] Currently, common device authentication methods primarily rely on single-type device fingerprints for verification. For example, some methods use hardware characteristics of the device (such as CPU serial number, MAC address, etc.) as authentication criteria; others use behavioral characteristics of the device (such as network traffic characteristics, system call sequences, etc.) for identification. These methods have achieved certain results in practical applications.

[0004] However, device fingerprints change dynamically over time and due to environmental factors. For example, fluctuations in the network environment can affect the device's behavioral characteristics, and hardware aging can cause some physical features to shift. When device fingerprints change, authentication methods based on a single feature are prone to misjudgment, affecting the accuracy of authentication. Summary of the Invention

[0005] This application provides a method, device, product, and medium for detecting device identity spoofing based on multimodality, which can improve the accuracy of authentication.

[0006] The first aspect of this application provides a multimodal device identity spoofing detection method, specifically including: Obtain multiple different types of device fingerprints for the device to be authenticated, as well as the historical stability data corresponding to each device fingerprint; Based on the historical stability data, the time decay coefficient of each device fingerprint is calculated, whereby the time decay coefficient represents the rate at which the reliability of the device fingerprint decreases over time. Based on the time decay coefficient of each device's fingerprint and the time interval between the current authentication and the last successful authentication, determine the number of verification levels that need to be performed for the current authentication. Based on the number of verification levels, the time decay coefficient of each device fingerprint, and the preset fingerprint combination strategy, different device fingerprints are assigned to each verification level. The device fingerprint of the current verification level of the device to be authenticated is compared with the reference device fingerprint to obtain the difference degree of the current verification level; The difference is compared with the verification threshold of the current verification level to obtain the verification result of the current verification level. When the verification result is passed, the verification threshold of the next verification level is adjusted according to the degree of difference. After completing the verification at each verification level in sequence, the system determines whether the device to be authenticated has engaged in identity fraud based on the verification results at each level.

[0007] By adopting the above technical solution, multiple different types of device fingerprints and their historical stability data are obtained, and the time decay coefficient of each device fingerprint is calculated, thereby accurately reflecting the credibility change characteristics of different device fingerprints over time. Furthermore, the number of verification levels is dynamically determined based on the time decay coefficient and the authentication time interval, and different device fingerprints are assigned to each verification level, realizing adaptive matching between verification strength and device fingerprint credibility. At the same time, by verifying layer by layer and dynamically adjusting the verification threshold of the next level according to the difference of the current level, the verification process can comprehensively consider the correlation between each level, thereby effectively improving the accuracy of device identity authentication while taking into account the dynamic change characteristics of device fingerprints.

[0008] Optionally, determining the number of verification levels required for the current authentication based on the time decay coefficient of each device's fingerprint and the time interval between the current authentication and the last successful authentication includes: Get the time interval between the current authentication time and the last successful authentication time of the device to be authenticated; Based on the time decay coefficient of each device fingerprint and the time interval, calculate the current remaining confidence value of each device fingerprint; The number of device fingerprints whose remaining credibility value is lower than a preset credibility threshold is counted. Based on the number of device fingerprints and the preset single-layer verification capacity, the number of verification levels that need to be executed for the current authentication is determined, wherein the number of device fingerprints is positively correlated with the number of verification levels.

[0009] By adopting the above technical solution, the product of the time decay coefficient of the device fingerprint and the authentication time interval is calculated to obtain the current remaining trust value of each device fingerprint. Then, the number of device fingerprints with insufficient trust is counted, and the number of verification levels is dynamically determined based on the number of these device fingerprints that need to be verified. This allows the setting of verification levels to be adaptively adjusted according to the actual trust status of the device fingerprint, which avoids over-verification when the trust is high and ensures sufficient verification strength when the trust is low, thereby achieving a reasonable allocation of verification resources.

[0010] Optionally, the step of assigning different device fingerprints to each verification level based on the number of verification levels, the time decay coefficient of each device fingerprint, and a preset fingerprint combination strategy includes: Sort all device fingerprints in ascending order of their age decay coefficient; The device fingerprints that rank first in the order are assigned to the first verification level, which is the first verification level to be executed among all verification levels. Detect whether there is a historical correlation between the device fingerprints assigned in the first verification level. The historical correlation represents the frequency with which different device fingerprints fail simultaneously in the historical verification process. Based on the historical correlation, each verification level is adjusted to obtain the device fingerprint of each verification level.

[0011] By adopting the above technical solution, the device fingerprints are first sorted based on the magnitude of the time decay coefficient. Device fingerprints with smaller time decay and higher stability are preferentially assigned to the first verification level, ensuring that the verification process starts with the fingerprint features with the highest reliability. Furthermore, by detecting the historical correlation between device fingerprints, fingerprint combinations with simultaneous failure characteristics in historical verification are identified, and the fingerprint allocation of the verification level is adjusted accordingly to avoid arranging fingerprints with associated failure risks in the same verification level. This improves the independence and reliability of each verification level and enhances the robustness of the overall verification process.

[0012] Optionally, adjusting each verification level based on the historical correlation to obtain the device fingerprint for each verification level includes: When a target device fingerprint has a historical correlation exceeding a preset correlation threshold, the target device fingerprint is assigned from the first verification level to the next verification level. Identify unassigned device fingerprints other than those in the first verification layer, and select from the unassigned device fingerprints the device fingerprints with the smallest time decay coefficient and a historical correlation with the first verification layer that is lower than a preset correlation threshold to supplement the first verification layer; The next verification level is used as the first verification level. The detection and allocation steps are repeated until the device fingerprint allocation for all verification levels is completed.

[0013] By adopting the above technical solution and setting a preset association threshold as the judgment criterion, target device fingerprints with excessively high historical association are adjusted to different verification levels. The fingerprints with the smallest time decay coefficient and low association are selected from the remaining unassigned fingerprints to supplement them. Through this iterative detection and adjustment process, it is ensured that the device fingerprints in each verification level have both high time stability and low risk of association failure. At the same time, the hierarchical allocation method enables the verification process to achieve progressively increasing verification strength while maintaining the independence of fingerprint features at each level, thereby improving verification reliability while ensuring verification efficiency.

[0014] Optionally, adjusting the verification threshold for the next verification level based on the degree of difference includes: Obtain the initial verification threshold for the next verification level; The confidence bias is calculated based on the degree of difference between the current verification level and the verification threshold of the current verification level. When the confidence deviation exceeds the preset deviation warning value, a threshold tightening coefficient is determined based on the confidence deviation, and the initial verification threshold is lowered using the threshold tightening coefficient to obtain the verification threshold for the next verification level. When the confidence deviation does not exceed the deviation warning value, the initial verification threshold is maintained as the verification threshold for the next verification level.

[0015] By adopting the above technical solution, the confidence deviation is obtained by calculating the difference between the current verification level and the verification threshold. A deviation warning value is set as the trigger condition for dynamic adjustment. When the confidence deviation is large, it indicates that there is a potential risk to the reliability of the current verification result. At this time, the initial threshold of the next verification level is dynamically lowered by the threshold tightening coefficient, thereby realizing the adaptive adjustment of the verification threshold. This threshold adjustment mechanism based on the reliability of the verification result enables the verification process to automatically increase the rigor of subsequent verifications when potential risks are found. It maintains the verification efficiency under normal conditions and ensures the verification accuracy under suspicious conditions, thereby improving the security of the overall verification process.

[0016] Optionally, determining whether the device to be authenticated has engaged in identity spoofing based on the verification results of each verification level includes: The statistical verification results include the number of verification levels that failed verification and the level position of the verification levels that failed verification. When the number of verification levels that fail verification exceeds a preset failure tolerance threshold, it is determined that the device to be authenticated has engaged in identity fraud. When the number of verification levels that fail verification does not exceed the failure tolerance threshold, it is determined whether there is a verification level located in the previous preset number of levels in the level position where the verification level that fails verification is located. If the verification level that failed verification is located in a level position that is within the previous preset number of verification levels, it is determined that the device to be authenticated has engaged in identity fraud. When the verification level that failed verification is not located in the previous preset number of verification levels, the device fingerprint corresponding to the verification level that failed verification is subjected to compensation verification to obtain the compensation verification result, and the device to be authenticated is determined to have identity fraud behavior based on the compensation verification result.

[0017] By adopting the above technical solution and setting a failure tolerance threshold to control the total number of verification failures, while focusing on the results of the first few verification levels, this multi-dimensional judgment mechanism can accurately identify different types of identity spoofing behavior. Furthermore, for cases with fewer verification failure levels and located in subsequent verification levels, a compensation verification mechanism is introduced for in-depth analysis, avoiding misjudgments caused by normal fluctuations in device fingerprints, thus improving the system's fault tolerance while ensuring verification accuracy. This hierarchical judgment strategy can quickly identify obvious spoofing behavior and properly handle boundary situations, thereby achieving a balance between the accuracy and reliability of device identity authentication.

[0018] Optionally, after determining whether the device to be authenticated has engaged in identity spoofing, the method further includes: When it is determined that the device to be authenticated has engaged in identity fraud, the device fingerprint type corresponding to the verification level that failed the verification is identified; Based on the device fingerprint type, the main deception feature dimension is determined, and based on the main deception feature dimension, historical deception patterns similar to the identity deception behavior are matched from a preset deception pattern library. When a historical spoofing pattern is matched, the protection policy corresponding to the historical spoofing pattern is obtained, and a security response measure for the device to be authenticated is generated according to the protection policy. The security response measure includes at least one of device isolation, traffic restriction, or re-authentication.

[0019] By adopting the above technical solution, after detecting identity spoofing, the main spoofing feature dimensions are identified by analyzing the fingerprint types of devices that failed verification. Based on these feature dimensions, similar historical spoofing patterns are matched from the spoofing pattern library to quickly locate the specific type of spoofing behavior. Furthermore, by calling the protection policy corresponding to the matched spoofing pattern, targeted security response measures, including device isolation, traffic restriction, or re-authentication, are automatically generated, realizing a closed-loop process from spoofing detection to security protection. This intelligent protection mechanism based on historical experience not only improves the system's response speed to spoofing behavior but also enhances the accuracy and effectiveness of protection measures, thus providing more comprehensive protection for the identity security of IoT devices.

[0020] In a second aspect, this application provides a multimodal device identity spoofing detection device, which includes: one or more processors and a memory; the memory is coupled to the one or more processors, and the memory is used to store computer program code, which includes computer instructions, and the one or more processors call the computer instructions to cause the multimodal device identity spoofing detection device to perform the method described in the first aspect and any possible implementation thereof.

[0021] Thirdly, this application provides a computer program product containing instructions that, when run on a multimodal device identity spoofing detection device, cause the multimodal device identity spoofing detection device to perform the method described in the first aspect and any possible implementation thereof.

[0022] Fourthly, this application provides a computer-readable storage medium including instructions that, when executed on a multimodal device identity spoofing detection device, cause the multimodal device identity spoofing detection device to perform the method described in the first aspect and any possible implementation thereof. Attached Figure Description

[0023] Figure 1 This is a schematic flowchart of a multimodal device identity spoofing detection method provided in an embodiment of this application; Figure 2 This is a schematic diagram illustrating how to determine the number of verification levels according to an embodiment of this application; Figure 3 This is a schematic diagram of device fingerprint allocation within a verification layer provided in an embodiment of this application; Figure 4 This is an exemplary hardware structure diagram of a multimodal device identity spoofing detection device provided in an embodiment of this application. Detailed Implementation

[0024] To enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments.

[0025] In the description of the embodiments of this application, the words "for example" or "for instance" are used to indicate examples, illustrations, or explanations. Any embodiment or design that is described as "for example" or "for instance" in the embodiments of this application should not be construed as being more preferred or advantageous than other embodiments or design options. Rather, the use of the words "for example" or "for instance" is intended to present the relevant concepts in a specific manner.

[0026] In the description of the embodiments of this application, the term "multiple" means two or more. For example, multiple systems means two or more systems, and multiple screen terminals means two or more screen terminals. Furthermore, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the indicated technical features. Thus, a feature defined with "first" or "second" may explicitly or implicitly include one or more of that feature. The terms "comprising," "including," "having," and variations thereof all mean "including but not limited to," unless otherwise specifically emphasized.

[0027] This application provides a multimodal device identity spoofing detection method, referencing... Figure 1 , Figure 1 This is a flowchart illustrating a multimodal device identity spoofing detection method provided in this application embodiment, including steps S101 to S108, as follows: S101: Obtain multiple different types of device fingerprints of the device to be authenticated, as well as the historical stability data corresponding to each device fingerprint.

[0028] In this embodiment, device fingerprint refers to digital feature information that can uniquely identify the device's identity. Specifically, it can include hardware fingerprints (such as CPU serial number, MAC address, hard disk serial number, etc.), software fingerprints (such as operating system version, installed software list, system configuration parameters, etc.), network fingerprints (such as IP address, network latency characteristics, data packet characteristics, etc.), and behavioral fingerprints (such as device usage patterns, access time patterns, operating habits, etc.). Historical stability data refers to statistical information reflecting the degree of change and reliability of each device fingerprint in the historical authentication process. Specifically, it includes indicators such as the frequency of fingerprint value changes, the magnitude of changes, the duration of continuous stability, and the number of failures. For example, if a hardware fingerprint remains unchanged in the past 30 days, its stability data shows a change frequency of 0 and a stability duration of 30 days.

[0029] Specifically, the process begins by sending a fingerprint collection command to the device to be authenticated via the device information acquisition module. This command includes a list of fingerprint types to be collected and the configuration of collection parameters. Upon receiving the command, the fingerprint acquisition agent on the device begins performing operations such as hardware information scanning, software environment detection, network feature analysis, and behavioral pattern statistics to obtain the corresponding raw fingerprint data. Then, the raw fingerprint data is standardized and features are extracted to generate a standardized device fingerprint vector. Simultaneously, historical authentication records associated with the current device identifier are retrieved from the device authentication history database. The performance of each fingerprint type in historical authentication is statistically analyzed, and historical stability data such as stability score, trend of change, and credibility level of each fingerprint are calculated. Finally, the collected fingerprints of multiple different types are associated with the corresponding historical stability data to obtain the historical stability data for each device fingerprint.

[0030] S102: Based on historical stability data, calculate the time decay coefficient of each device fingerprint. The time decay coefficient represents the rate at which the reliability of the device fingerprint decreases over time.

[0031] In this embodiment, the time decay coefficient represents a quantitative indicator of how quickly the reliability of a device fingerprint decreases over time. The smaller the coefficient value, the slower the time decay of the fingerprint and the better its stability. The larger the coefficient value, the faster the time decay of the fingerprint and the worse its stability. For example, the time decay coefficient of hardware fingerprints is usually 0.01-0.05, indicating that it has high stability, while the time decay coefficient of network fingerprints may be 0.3-0.8, indicating that it changes faster over time.

[0032] Specifically, key stability indicators are extracted from the historical stability data corresponding to each device fingerprint, including parameters such as fingerprint value change frequency, average stable duration, historical failure rate, and the time interval of the most recent update. A time decay coefficient calculation model is established, which comprehensively considers the inherent stability characteristics of fingerprint types and historical performance data. For each device fingerprint, the basic decay rate is first calculated based on the weighted sum of the fingerprint value change frequency multiplied by the first weight coefficient, the inverse of the stable duration multiplied by the second weight coefficient, and the historical failure rate multiplied by the third weight coefficient. Then, the time influence factor is calculated based on the time interval in an exponential function form, with a smaller influence factor for longer time intervals. Next, the type correction coefficient is determined according to the fingerprint type. The correction coefficient for hardware fingerprints is usually set to a small value to reflect its high stability, the correction coefficient for software fingerprints is set to a medium value, and the correction coefficient for network and behavioral fingerprints is set to a large value to reflect its volatility. Finally, the basic decay rate, the time influence factor, and the type correction coefficient are multiplied to calculate the time decay coefficient of the device fingerprint. This calculation process is repeated for all device fingerprints to obtain the time decay coefficient corresponding to each device fingerprint.

[0033] S103: Determine the number of verification levels required for the current authentication based on the time decay coefficient of each device's fingerprint and the time interval between the current authentication and the last successful authentication.

[0034] In this embodiment, the number of verification levels represents the total number of verification steps that need to be executed sequentially to ensure the accuracy of device authentication. Each verification level corresponds to a certain number of device fingerprint verification tasks. The more verification levels there are, the more comprehensive the verification needs to be. For example, when the number of verification levels is 3, it means that the device fingerprint verification of the first level verification, the second level verification, and the third level verification needs to be executed sequentially.

[0035] Specifically, firstly, the time interval between the current authentication time and the last successful authentication time on the device to be authenticated is obtained. This is achieved by querying the device's most recent successful authentication timestamp in the device authentication history database and calculating the difference between it and the current system time. Then, for each device fingerprint, its corresponding time decay coefficient is mathematically calculated with the time interval. The remaining credibility value of the fingerprint at the current moment is calculated according to the exponential decay mode, which is the initial credibility value multiplied by the time decay coefficient as the base and the time interval as the exponent. Next, the number of device fingerprints with a remaining credibility value lower than the preset credibility threshold is counted by comparing the remaining credibility value of each fingerprint with the credibility threshold. Finally, based on the number of device fingerprints that need to be re-verified and the system's preset single-layer verification capacity, a division operation is performed. The number of device fingerprints is divided by the single-layer verification capacity and rounded up to obtain the number of verification levels that need to be executed for the current authentication.

[0036] like Figure 2 As shown, Figure 2 This is a schematic diagram illustrating how to determine the number of verification levels according to an embodiment of this application.

[0037] The figure clearly illustrates the complete process of dynamically determining the number of verification levels based on the time decay characteristics of device fingerprints and the authentication time interval in this invention.

[0038] from Figure 2The upper part of the diagram shows that the system first obtains the time interval t between the current authentication time and the last successful authentication time on the device to be authenticated. This time interval is a key factor affecting the trustworthiness of the device fingerprint. Over time, different types of device fingerprints exhibit different trustworthiness decay rates due to their inherent stability differences. This is where the time-related decay coefficient k comes into play. The diagram shows four typical device fingerprint types with time-related decay coefficients of 0.05, 0.10, 0.40, and 0.65, respectively. These values ​​reflect the stability characteristics of different fingerprint types. Hardware fingerprints (such as fingerprint A) typically have a smaller decay coefficient, indicating that they change slowly over time, while network or behavioral fingerprints (such as fingerprint D) have a larger decay coefficient, indicating that they are more susceptible to the influence of time and environmental factors.

[0039] Figure 2 The middle part of the calculation uses a mathematical function f(t,k) to visually represent the interaction between the time decay coefficient and the time interval. The system uses an exponential decay model to calculate the current remaining confidence value of each device's fingerprint. The calculation results show that the remaining confidence values ​​of fingerprints A and B are 0.92 and 0.85 respectively, remaining at a relatively high level. However, the remaining confidence values ​​of fingerprints C and D have decreased to 0.51 and 0.33 respectively, significantly lower than the system's preset confidence threshold of 0.6. This differentiated confidence change reflects the different performances of different fingerprint types after the same time interval, providing a scientific basis for determining the subsequent verification level.

[0040] Figure 2 The lower half of the diagram illustrates the logic for determining the number of verification levels. The system counts the number of device fingerprints whose remaining credibility is below a preset credibility threshold; in this example, this is fingerprints C and D, a total of two. The system then divides this number of fingerprints requiring priority verification by the preset single-layer verification capacity, rounding up to determine the final number of verification levels to be executed. This dynamic determination mechanism ensures a precise match between verification strength and the actual risk level. When the overall credibility of device fingerprints is high, the number of verification levels is reduced to improve efficiency; when credibility generally decreases, the number of verification levels is increased to ensure security. The entire process demonstrates the intelligent design of this invention in balancing security and efficiency, achieving optimal allocation of verification resources through quantitative analysis of the timeliness characteristics of device fingerprints. S104: Assign different device fingerprints to each verification level based on the number of verification levels, the time decay coefficient of each device fingerprint, and the preset fingerprint combination strategy.

[0041] Specifically, firstly, all device fingerprints are sorted in ascending order of their decay coefficient. The fingerprint list is then rearranged using either quicksort or mergesort algorithms, ensuring the most stable fingerprints are at the front of the sorted sequence. Next, the first number of device fingerprints at the top of the sorted list are assigned to the first verification level. This first verification level is the first one executed, and the number is determined based on the single-layer verification capacity and system performance requirements. Then, historical correlations between the device fingerprints assigned to the first verification level are detected. This is achieved by analyzing historical verification records to calculate the frequency of simultaneous failures of different fingerprint pairs during historical verification. If the frequency of simultaneous failures exceeds a preset correlation threshold, historical correlation is considered to exist. Finally, based on the detected historical correlations, each verification level is adjusted. Highly correlated fingerprints are redistributed to different verification levels. Simultaneously, the remaining device fingerprints are sequentially assigned to the second, third, and subsequent verification levels according to a fingerprint combination strategy. This ensures that fingerprint combinations within each verification level have good independence and complementarity, ultimately yielding the device fingerprints corresponding to each verification level.

[0042] like Figure 3 As shown, Figure 3 This is a schematic diagram of device fingerprint allocation within a verification layer provided in an embodiment of this application.

[0043] This figure illustrates in detail how the present invention achieves the optimal fingerprint allocation strategy by comprehensively considering the time decay coefficient and historical correlation characteristics of device fingerprints, thereby ensuring that each verification level has good independence and reliability.

[0044] from Figure 3 As can be observed on the left side, the system first arranges all device fingerprints to be assigned in ascending order of their time-degradation coefficients, forming a priority queue based on stability. In the example, the time-degradation coefficients of fingerprints A, B, F, C, and D are 0.05, 0.10, 0.12, 0.40, and 0.65, respectively. This sorting ensures that the fingerprints with the highest stability are preferentially assigned to key verification levels. Based on this sorting result, the system assigns fingerprints A, B, and F, which rank at the top, to the first verification level according to a preset first quantity parameter. This allocation strategy ensures that the first round of verification is based on the most reliable device features.

[0045] Figure 3The upper-middle section illustrates the key steps in historical correlation detection. By analyzing the frequency of simultaneous failures among device fingerprints assigned to the first verification level during historical verification processes, the system identifies high correlations exceeding a preset correlation threshold between certain fingerprint pairs. The high correlation warning highlighted in red in the figure indicates that when two or more device fingerprints frequently fail simultaneously in historical authentication, placing them at the same verification level increases the risk of overall verification failure. This correlation detection mechanism reflects the invention's deep consideration of the independence of verification levels.

[0046] Figure 3 The right and lower sections vividly depict the dynamic adjustment process based on historical correlation. When the system detects highly correlated target device fingerprints in the first verification level, it transfers these fingerprints from the current level to the next verification level. Simultaneously, it selects fingerprints from the unassigned device fingerprint pool that have the smallest age decay coefficient and whose historical correlation with the remaining fingerprints in the first verification level is below a preset threshold to supplement the system. In this example, fingerprint F, with high correlation, is moved to the next verification level, while fingerprint C, due to its lack of significant historical correlation with fingerprints A and B and its relatively small age decay coefficient, is selected to supplement the first verification level. This precise adjustment mechanism not only maintains the fingerprint quantity configuration of the first verification level but, more importantly, ensures the optimization of fingerprint combinations within the level. This allows the adjusted first verification level to maintain high stability while avoiding the risk of correlation failure, thus laying a solid foundation for the reliability of the entire multi-level verification system.

[0047] S105: Compare the device fingerprint of the current verification level of the device to be certified with the reference device fingerprint to obtain the difference degree of the current verification level.

[0048] In this application embodiment, the difference degree represents a quantitative indicator of the similarity between the current device fingerprint of the device to be authenticated and the corresponding reference device fingerprint. The difference degree value is usually between 0 and 1. The closer the difference degree is to 0, the more similar the two fingerprints are and the more trustworthy the device identity is. The closer the difference degree is to 1, the greater the difference between the two fingerprints and the more suspicious the device identity is. For example, when the difference degree of the hardware fingerprint is 0.05, it means that it is highly similar to the reference fingerprint. When the difference degree of the network fingerprint is 0.8, it means that there is a significant difference from the reference fingerprint.

[0049] Specifically, firstly, the baseline device fingerprint data corresponding to the device to be authenticated is obtained from the device baseline fingerprint database. This baseline fingerprint data is a standard fingerprint template established by the device during its historical successful authentication process. Then, all device fingerprints assigned to the current verification level are extracted, including different types of fingerprint data such as hardware fingerprints, software fingerprints, network fingerprints, or behavioral fingerprints. Next, each device fingerprint is compared with its corresponding baseline fingerprint one by one, and matching analysis is performed using the appropriate similarity calculation algorithm. For numerical fingerprints, Euclidean distance or cosine similarity calculation method is used; for string fingerprints, edit distance or Hamming distance calculation method is used; and for vector fingerprints, vector angle or Pearson correlation coefficient calculation method is used. Then, the similarity value of each fingerprint is converted into a difference value by subtracting the similarity value. Finally, the difference values ​​of all device fingerprints within the current verification level are calculated by weighted average, and the sum is calculated according to the importance weight of each fingerprint type and divided by the total weight to obtain the difference value of the current verification level.

[0050] S106: Compare the difference with the verification threshold of the current verification level to obtain the verification result of the current verification level.

[0051] In this embodiment, the verification threshold represents a critical numerical standard for determining whether the current verification level has passed. This threshold is dynamically set according to the importance and security requirements of the verification level. Different verification levels correspond to different verification thresholds. When the difference is lower than the verification threshold, it means that the verification of that level has passed. When the difference is higher than or equal to the verification threshold, it means that the verification of that level has failed. For example, the verification threshold of the first verification level is usually set to 0.3, the verification threshold of the second verification level may be set to 0.5, and the verification threshold of subsequent levels is gradually relaxed to improve the verification pass rate.

[0052] Specifically, the process begins by retrieving the preset verification threshold corresponding to the current verification level from the verification configuration database. This threshold is determined based on the current level's sequence number, the fingerprint types it contains, and security policy requirements. Then, the calculated difference degree of the current verification level is compared with this threshold. If the difference degree is less than the threshold, the current verification level is deemed to have passed verification, a successful verification result identifier is generated, and the number of passed fingerprints and the specific difference degree value are recorded. If the difference degree is greater than or equal to the threshold, the current verification level is deemed to have failed verification, a failure result identifier is generated, and the reason for the failure and the specific difference degree exceeding the limit are recorded. Simultaneously, the comparison result, difference degree value, verification threshold, and verification timestamp are recorded in the verification log, forming a complete verification process traceability record. Finally, the verification result of the current verification level is output.

[0053] S107: When the verification result is passed, adjust the verification threshold of the next verification level according to the degree of difference.

[0054] Specifically, first, the initial verification threshold corresponding to the next verification level is obtained from the verification configuration database; then, the numerical difference between the difference degree of the current verification level and the verification threshold of the current verification level is calculated, and this difference is divided by the verification threshold of the current verification level to obtain the relative difference ratio, and then 1 is subtracted from the relative difference ratio to obtain the confidence deviation; next, the calculated confidence deviation is compared with the preset deviation warning value; when the confidence deviation is greater than the deviation warning value, the confidence deviation is multiplied by the preset sensitivity coefficient to obtain the threshold tightening coefficient, and then the initial verification threshold is multiplied by 1 and the result of the threshold tightening coefficient is subtracted to lower the initial verification threshold, resulting in the tightened verification threshold of the next verification level; when the confidence deviation is less than or equal to the deviation warning value, the initial verification threshold is kept unchanged as the verification threshold of the next verification level; finally, the determined verification threshold is updated in the verification configuration for use by the next verification level.

[0055] S108: After completing the verification of each verification level in sequence, determine whether the device to be authenticated has engaged in identity fraud based on the verification results of each verification level.

[0056] In this application embodiment, identity deception refers to the malicious act of a device to be authenticated impersonating a legitimate device by forging or tampering with device fingerprint information. This act is usually manifested as an abnormal difference between the device fingerprint and the historical benchmark or the simultaneous failure of multiple key verification levels. For example, when the device's hardware fingerprint, network fingerprint, and software fingerprint are significantly different from the benchmark fingerprint at the same time, it may indicate that the device is carrying out an identity spoofing attack.

[0057] Specifically, firstly, all completed verification levels are traversed, and the number of verification levels that failed is counted, with the level position number of each failed verification level recorded. Then, the count of failed verification levels is compared with a preset failure tolerance threshold. If the number of failed verification levels is greater than the failure tolerance threshold, the device to be authenticated is directly determined to have engaged in identity spoofing. If the number of failed verification levels is less than or equal to the failure tolerance threshold, the level position of the failed verification levels is further checked to determine if there are any levels with a position number less than or equal to the previously preset number of failed verification levels. The authentication process involves several steps. First, if any authentication level within a pre-set range fails, the device to be authenticated is deemed to have engaged in identity spoofing. Second, if the position number of all failed authentication levels exceeds the pre-set number, a compensation verification process is initiated for the device fingerprints corresponding to these failed authentication levels. This process employs a backup verification algorithm or reduces the verification precision to re-compare the fingerprints, yielding a compensation verification result. Finally, the compensation success rate is calculated based on the success rate of the compensation verification. If the compensation success rate is higher than a pre-set compensation threshold, the device to be authenticated is deemed not to have engaged in identity spoofing. If the compensation success rate is lower than the compensation threshold, the device to be authenticated is deemed to have engaged in identity spoofing.

[0058] Based on the above embodiments, as an optional embodiment, S103: the step of determining the number of verification levels to be executed for the current authentication based on the time decay coefficient of each device fingerprint and the time interval between the current authentication and the last successful authentication may specifically include the following steps: S201: Obtain the time interval between the current authentication time and the last successful authentication time on the device to be authenticated; calculate the current remaining credibility value of each device fingerprint based on the time decay coefficient and time interval of each device fingerprint.

[0059] In the embodiments of this application, the confidence residual value represents a quantitative indicator of the confidence level of a device fingerprint after a certain time interval. This value gradually decreases with the passage of time and the influence of the time decay coefficient. The higher the confidence residual value, the stronger the reliability of the fingerprint at the current moment. For example, the confidence residual value of a hardware fingerprint after 30 days may be 0.85, while the confidence residual value of a behavioral fingerprint after the same time may be only 0.45.

[0060] Specifically, the system first queries the authentication record database to retrieve the historical authentication records of the device to be authenticated and obtains the timestamp of the most recent successful authentication. Then, it obtains the timestamp of the current authentication request and calculates the time difference between the current moment and the last successful authentication moment, quantifying the time interval in hours or days. Next, it iterates through all types of device fingerprints and obtains the time decay coefficient corresponding to each device fingerprint. For each device fingerprint, an exponential decay model is used to calculate the credibility. The initial credibility value of 1 is multiplied by the product of the negative time decay coefficient of the natural constant and the time interval raised to the power of 1, so the remaining credibility value is equal to the negative decay coefficient of the natural constant multiplied by the time interval raised to the power of 1. Finally, the remaining credibility value of each device fingerprint at the current moment is obtained.

[0061] S202: Count the number of device fingerprints whose remaining credibility value is lower than the preset credibility threshold. Based on the number of device fingerprints and the preset single-layer verification capacity, determine the number of verification levels that need to be executed for the current authentication. The number of device fingerprints is positively correlated with the number of verification levels.

[0062] In the embodiments of this application, the single-layer verification capacity represents the maximum number of device fingerprints that each verification level can accommodate for verification. This capacity is set according to the complexity of the verification algorithm and the system processing capability. The larger the single-layer verification capacity, the more types of fingerprints a single verification level can process at the same time. For example, when the single-layer verification capacity is set to 3, each verification level can verify up to 3 different types of device fingerprints at the same time.

[0063] Specifically, firstly, the remaining credibility values ​​of each device fingerprint calculated in the previous step are iterated through, and each remaining credibility value is compared with a preset credibility threshold. Then, the number of device fingerprints with remaining credibility values ​​less than the credibility threshold is counted, and the total number of fingerprints that need to be re-verified is recorded. Next, the preset single-layer verification capacity parameter is obtained from the system configuration. The number of device fingerprints that need to be verified is divided by the single-layer verification capacity to obtain the number of basic layers. When there is a remainder in the division result, the result is rounded up to ensure that all device fingerprints that need to be verified can be assigned to the corresponding verification layer. At the same time, the fingerprints are sorted according to their importance priority, and fingerprints with higher importance are assigned to earlier verification layers first. Finally, the number of verification layers that need to be executed in the current authentication process is determined.

[0064] Based on the above embodiments, as an optional embodiment, S104: the step of assigning different device fingerprints to each verification level according to the number of verification levels, the time decay coefficient of each device fingerprint, and the preset fingerprint combination strategy may specifically include the following steps: S301: Sort all device fingerprints in ascending order of their time decay coefficients; assign the first number of device fingerprints in the sorted order to the first verification level, which is the first verification level executed among all verification levels.

[0065] In this application embodiment, the first quantity represents the specific number of device fingerprints allocated to the first verification level for verification. This quantity is set according to the verification capacity and system performance requirements of the first verification level. The first quantity is usually set to the maximum value of the single-layer verification capacity to make full use of the processing capacity of the first round of verification. For example, when the single-layer verification capacity is 5, the first quantity is usually set to 5, indicating that the first verification level will verify 5 different device fingerprints at the same time.

[0066] Specifically, firstly, the time-depletion coefficient values ​​corresponding to all types of device fingerprints are obtained, including the attenuation coefficients of various fingerprint types such as hardware fingerprints, software fingerprints, network fingerprints, and behavioral fingerprints. Then, an ascending sorting algorithm is used to arrange all device fingerprints according to their time-depletion coefficients from smallest to largest, with fingerprints with smaller time-depletion coefficients listed first and fingerprints with larger time-depletion coefficients listed last. Next, a preset first quantity parameter value is obtained from the system configuration. From the sorting results, a first quantity of device fingerprints in the top column are selected, that is, all device fingerprints from the first position to the first quantity position are selected. These selected device fingerprints are added to the fingerprint allocation list of the first verification level, establishing a binding relationship between the first verification level and the corresponding device fingerprints. Finally, the device fingerprint allocation of the first verification level is completed.

[0067] S302: Detect whether there is a historical correlation between the device fingerprints assigned in the first verification level. The historical correlation represents the frequency of different device fingerprints failing simultaneously in the historical verification process. Adjust each verification level according to the historical correlation to obtain the device fingerprints of each verification level.

[0068] In the embodiments of this application, historical correlation represents the statistical value of the co-occurrence frequency of different device fingerprints failing or being abnormal in multiple past device authentication verification processes. This value reflects the degree of correlation between different fingerprint types in terms of failure time and failure conditions. The higher the historical correlation, the more likely the two fingerprints are to have problems at the same time under the same conditions. For example, when the historical correlation between network fingerprint and geographic location fingerprint is 0.85, it means that in 85% of the historical verifications, the two fingerprints will fail to be verified at the same time.

[0069] Specifically, firstly, the correlation data between all device fingerprints assigned to the first verification level is queried from the historical verification record database. The correlation value is calculated by dividing the number of times each pair of device fingerprints failed simultaneously in historical verification by the total number of verifications. Then, the calculated correlation value is compared with a preset correlation threshold to identify target device fingerprints whose correlation exceeds the threshold. These target device fingerprints are removed from the assignment list of the first verification level and added to the waiting list of the next verification level. Next, fingerprints already assigned to the first verification level are excluded from all device fingerprints to obtain the set of unassigned device fingerprints. The process is then iterated through... The set of unassigned device fingerprints is used to calculate the historical correlation between each unassigned fingerprint and the remaining fingerprints in the first verification level. The device fingerprint with the smallest time decay coefficient and whose correlation with all fingerprints in the first verification level is below the correlation threshold is selected. The selected device fingerprint is added to the first verification level so that the number of fingerprints in the first verification level reaches the preset requirement. Then, the next verification level is set as the current first verification level, and the complete process of correlation detection, fingerprint adjustment and supplementary allocation is repeated. The process is iterated until all verification levels have completed the allocation of device fingerprints and meet the correlation requirements, thus obtaining the device fingerprints of each verification level.

[0070] Based on the above embodiments, as an optional embodiment, S302: the step of adjusting each verification level according to historical correlation to obtain the device fingerprint of each verification level may specifically include the following steps: S401: When there is a target device fingerprint with historical correlation exceeding the preset correlation threshold, the target device fingerprint is assigned from the first verification level to the next verification level.

[0071] In this application embodiment, the target device fingerprint refers to a specific fingerprint type that has an excessively high historical correlation with other device fingerprints in the first verification level. This fingerprint needs to be removed from the current verification level to avoid the spread of the risk of association failure. The target device fingerprint usually refers to the fingerprint type that frequently appears abnormally in historical verification along with the assigned fingerprint. For example, when the correlation between the behavioral fingerprint and the network fingerprint reaches 0.9, the behavioral fingerprint becomes the target device fingerprint that needs to be reassigned.

[0072] Specifically, firstly, all device fingerprints assigned in the first verification level are traversed, and the historical correlation value between each device fingerprint and other fingerprints in the same level is calculated. Then, the calculated correlation value is compared with a preset correlation threshold one by one to identify device fingerprint pairs with correlation values ​​greater than the correlation threshold. From these highly correlated fingerprint pairs, the device fingerprint with a relatively large time decay coefficient is selected as the target device fingerprint. The identified target device fingerprint is deleted from the fingerprint allocation list of the first verification level, and the fingerprint configuration information of the first verification level is updated. At the same time, the target device fingerprint is added to the fingerprint list to be allocated in the next verification level to establish a new hierarchical allocation relationship. The fingerprint allocation record in the verification level configuration table is updated to ensure that the target device fingerprint completes the transfer from the first verification level to the next verification level. Finally, the redistribution of the target device fingerprint is completed.

[0073] S402: Determine the unassigned device fingerprints other than the device fingerprints of the first verification layer, and select the device fingerprint with the smallest time decay coefficient and the historical correlation with the first verification layer that is lower than the preset correlation threshold from the unassigned device fingerprints to supplement the first verification layer.

[0074] In this embodiment, unassigned device fingerprints refer to the remaining device fingerprint types that have not yet been assigned to any verification level during the current verification level allocation process. These fingerprints are waiting to be assigned to a suitable verification level based on their characteristic parameters and correlation requirements. Unassigned device fingerprints typically include fingerprint types remaining after the initial allocation as well as fingerprints adjusted from other levels. For example, when the system has 8 device fingerprint types and the first verification level only allocates 3 types, the remaining 5 fingerprints constitute the set of unassigned device fingerprints.

[0075] Specifically, first, a list of all available device fingerprint types in the system is obtained, including all fingerprint types such as hardware fingerprints, software fingerprints, network fingerprints, and behavioral fingerprints. Then, device fingerprints already assigned to the first verification level are excluded, resulting in a complete set of currently unassigned device fingerprints. Next, each fingerprint in the unassigned device fingerprint set is traversed, and its corresponding time decay coefficient value is obtained. The unassigned device fingerprints are sorted in ascending order of time decay coefficient, with fingerprints with smaller decay coefficients placed at the top. Then, the sorted unassigned device fingerprints are checked one by one, and the historical correlation between each fingerprint and existing fingerprints in the first verification level is calculated. Device fingerprints whose historical correlation with all existing fingerprints in the first verification level is lower than a preset correlation threshold are selected. From the fingerprints that meet the correlation criteria, the device fingerprint with the smallest time decay coefficient is selected as a supplementary object. The selected device fingerprint is added to the fingerprint assignment list of the first verification level, and the configuration information of the first verification level is updated. The above selection and supplementation process is repeated until the first verification level reaches the preset fingerprint quantity requirement or there are no more unassigned fingerprints that meet the criteria to choose from.

[0076] S403: Take the next verification level as the first verification level, and repeat the detection and allocation steps until the device fingerprint allocation for all verification levels is completed.

[0077] In this embodiment, the detection and allocation steps represent a complete operation process of performing historical correlation detection and device fingerprint reassignment on the currently processed verification level. This step includes a series of continuous processing operations such as correlation exceeding threshold detection, target fingerprint transfer, unassigned fingerprint screening, and supplementary allocation. The detection and allocation steps ensure that the device fingerprints in each verification level meet the correlation requirements and make full use of the verification capacity. For example, when processing the second verification level, it is necessary to repeat the same correlation detection and fingerprint adjustment process as the first verification level.

[0078] Specifically, the process begins by moving the verification level processing pointer from the current first verification level to the next verification level, updating the current verification level identifier. Then, the new verification level is set as the current first verification level, and the relevant processing states and temporary variables are reset. Next, the historical correlation detection process is repeated, traversing the device fingerprints assigned in the current verification level, calculating the correlation between fingerprints, and comparing it with a preset threshold. When a target device fingerprint with a correlation exceeding the threshold is found, it is moved from the current verification level to the next verification level. Then, fingerprints with the smallest time-degradation coefficient and meeting the correlation requirements are selected from the remaining unassigned device fingerprints for supplementation. This detection and assignment process is repeated until the current verification level completes fingerprint assignment. It is then checked whether there are any unprocessed verification levels; if so, the processing pointer is moved to the next level and the entire process is repeated. When all predetermined verification levels have completed device fingerprint assignment and there are no remaining unassigned fingerprints, the iteration process ends, and the final verification level configuration result is generated.

[0079] Based on the above embodiments, as an optional embodiment, S107: the step of adjusting the verification threshold of the next verification level according to the degree of difference may specifically include the following steps: S501: Obtain the initial verification threshold for the next verification level; calculate the confidence bias based on the closeness between the difference of the current verification level and the verification threshold of the current verification level.

[0080] In this embodiment, the confidence deviation represents the quantitative value of the deviation between the actual verification result of the current verification level and the expected verification standard. This deviation reflects the rationality of the current verification threshold setting and the reliability of the verification accuracy. The larger the confidence deviation, the more obvious the difference between the judgment result of the current verification level and the preset standard. The smaller the confidence deviation, the closer the verification result is to the expected standard. For example, when the difference is 0.8 and the verification threshold is 0.7, the two are relatively close and the corresponding confidence deviation is small. However, when the difference is 0.9 and the verification threshold is 0.5, it corresponds to a larger confidence deviation.

[0081] Specifically, the process begins by retrieving the initial verification threshold parameter for the next verification level from the verification level configuration table. This threshold is typically preset based on the fingerprint type and security level. Next, the difference value calculated for the current verification level and the verification threshold value for that level are obtained. Then, the difference between the difference value and the verification threshold is calculated, and the absolute value is used to obtain the distance between them. This distance is divided by the verification threshold to obtain the relative deviation ratio, which serves as a quantitative indicator of their closeness. Then, the confidence deviation is calculated based on the closeness. When the closeness is high, the confidence deviation is set to a small positive value; when the closeness is low, the confidence deviation is set to a large positive value. A linear or exponential mapping function is used to convert the closeness into a corresponding confidence deviation value. Finally, the confidence deviation is obtained to guide the threshold adjustment for the next verification level.

[0082] S502: When the confidence deviation exceeds the preset deviation warning value, the threshold tightening coefficient is determined based on the confidence deviation, and the initial verification threshold is lowered through the threshold tightening coefficient to obtain the verification threshold of the next verification level; when the confidence deviation does not exceed the deviation warning value, the initial verification threshold is maintained as the verification threshold of the next verification level.

[0083] In this embodiment, the threshold tightening coefficient represents an adjustment parameter used to reduce the verification threshold to increase the verification rigor. This coefficient is dynamically determined based on the confidence deviation of the current verification level. The value of the threshold tightening coefficient is usually less than 1 and is used to multiply the initial verification threshold to achieve threshold reduction. The smaller the threshold tightening coefficient, the more stringent the verification requirements. For example, when the confidence deviation is large, the threshold tightening coefficient may be set to 0.8, which means that the initial verification threshold will be reduced by 20% to enhance the verification rigor of the next level.

[0084] Specifically, firstly, the calculated confidence deviation value is compared with the preset deviation warning value to determine whether the confidence deviation exceeds the warning threshold. When the confidence deviation is greater than the deviation warning value, the corresponding threshold tightening coefficient is determined based on the magnitude of the deviation value. Typically, an inverse proportional relationship is used to calculate the tightening coefficient, meaning the larger the deviation, the smaller the tightening coefficient. Then, the threshold tightening coefficient is multiplied by the initial verification threshold of the next verification level to obtain the adjusted lower verification threshold. The calculated new verification threshold is set as the final verification threshold of the next verification level, and the verification level configuration information is updated. When the confidence deviation is less than or equal to the deviation warning value, the initial verification threshold of the next verification level remains unchanged without any adjustment. The determined verification threshold is written into the configuration parameters of the next verification level, completing the dynamic adjustment setting of the verification threshold. Finally, a next verification level threshold adapted to the current verification situation is generated.

[0085] Based on the above embodiments, as an optional embodiment, S108: the step of determining whether the device to be authenticated has engaged in identity spoofing based on the verification results of each verification level may specifically include the following steps: S601: The statistical verification result is the number of verification levels that failed verification and the level position of the verification levels that failed verification; when the number of verification levels that failed verification exceeds the preset failure tolerance threshold, it is determined that the device to be authenticated has engaged in identity fraud.

[0086] In this embodiment, the failure tolerance threshold represents the maximum number of verification levels that the system allows a device to fail verification in a multi-level verification process. This threshold is used to balance the requirements of verification security and the convenience of normal device use. The setting of the failure tolerance threshold takes into account factors such as device type, network environment and security level. The lower the failure tolerance threshold, the more stringent the verification requirements. For example, when the system sets the failure tolerance threshold to 2, it means that the device is allowed to fail verification in a maximum of 2 verification levels. Exceeding this number is considered as having a risk of identity fraud.

[0087] Specifically, the process first iterates through all executed verification levels, obtaining the verification result status information for each level, including status indicators such as verification passed, verification failed, or verification abnormal. Then, it filters out verification levels with failed verification results, counts the total number of these levels, and records their corresponding level position numbers. Next, it compares the count of failed verification levels with a preset failure tolerance threshold. When the number of failed verification levels exceeds the failure tolerance threshold, the identity spoofing judgment logic is triggered, marking the device to be authenticated as exhibiting identity spoofing behavior. Simultaneously, the specific level position of the failed verification levels is recorded, providing detailed failure distribution information for subsequent security analysis and risk assessment. The judgment result is written into the device authentication record, including key information such as spoofing behavior identifier, number of failed levels, and failure level position. Finally, a judgment conclusion on the device's identity spoofing behavior is generated.

[0088] S602: When the number of verification levels that fail verification does not exceed the failure tolerance threshold, determine whether there is a verification level located in the previous preset number of verification levels in the level position where the verification level that fails verification is located; when there is a verification level located in the previous preset number of verification levels in the level position where the verification level that fails verification is located, determine that the device to be authenticated has engaged in identity fraud.

[0089] In this embodiment, the pre-preset number of verification levels refers to several verification levels at the forefront of a multi-level verification sequence. These levels are typically configured with the most basic and critical device fingerprint verification requirements. The pre-preset number of verification levels has a high security weight and judgment priority. Verification failure in these critical levels often means that the device has a serious identity problem. For example, when the system sets the pre-preset number to 3, it means that the first 3 verification levels are critical verification levels. Any device verification failure in these levels will be given special attention and strict handling.

[0090] Specifically, the process begins by confirming that the number of failed verification levels is less than or equal to a preset failure tolerance threshold, and then proceeds to further location analysis. Next, the system retrieves the numerical parameters of the previous preset number from the system configuration to determine the range of front-end verification levels requiring close monitoring. Then, it iterates through the list of locations of the failed verification levels, checking the location number of each failed level one by one. The location number of each failed level is compared with the previous preset number to determine if the level falls within that range. If any failed verification level location number is found to be less than or equal to the previous preset number, it is immediately marked as a critical level verification failure. Once a critical level verification failure is detected, the identity spoofing behavior judgment logic is triggered, marking the device to be authenticated as exhibiting identity spoofing behavior.

[0091] S603: When the verification level that failed verification is not located in the previous preset number of verification levels, perform compensation verification on the device fingerprint corresponding to the verification level that failed verification to obtain the compensation verification result, and determine whether the device to be authenticated has identity fraud behavior based on the compensation verification result.

[0092] In this application embodiment, compensation verification refers to a secondary verification process performed on device fingerprints that failed the initial verification using a more lenient verification standard or an alternative verification method. This verification mechanism is used to exclude verification failures caused by non-malicious factors such as network fluctuations, changes in device status, or environmental interference. Compensation verification typically improves the fault tolerance of verification by lowering the verification threshold, extending the collection time, or increasing the number of samples. For example, when a device fingerprint fails in standard verification because its similarity is 0.75, which is lower than the verification threshold of 0.8, compensation verification may adjust the threshold to 0.7 or re-verify by averaging multiple samples.

[0093] Specifically, first, it is confirmed that the location numbers of all failed verification levels are greater than the preset number, meaning that these failed levels do not belong to the critical front-end verification levels. Then, the specific device fingerprint type corresponding to the failed verification levels is extracted, including the category identifier of the failed fingerprint and the original verification data. Next, a compensation verification strategy is formulated for each failed device fingerprint, including adjusting the verification threshold, modifying the similarity calculation method, or increasing the number of data collections. Data collection and feature extraction are performed again on the failed device fingerprints to obtain new fingerprint data samples. The newly collected fingerprint data is then verified using the compensation verification strategy, and the similarity or matching degree of the compensation verification is calculated. Based on the results of the compensation verification, it is determined whether each failed fingerprint can pass the compensation verification. The pass rate and failure rate of the compensation verification are statistically analyzed. When the compensation verification pass rate reaches a preset standard, the device is determined to be a normal device; when a large number of compensation verifications still fail, the device is determined to be engaging in identity spoofing. The compensation verification results and the final identity determination conclusion are recorded in the device authentication log.

[0094] Based on the above embodiments, as an optional embodiment, S108: after determining whether the device to be authenticated has engaged in identity spoofing, a step of generating security measures is further included, which may specifically include the following steps: S701: When it is determined that the device to be authenticated has identity spoofing behavior, identify the device fingerprint type corresponding to the verification level that failed the verification; determine the main spoofing feature dimension according to the device fingerprint type; and match historical spoofing patterns similar to identity spoofing behavior from the preset spoofing pattern library according to the main spoofing feature dimension.

[0095] In this embodiment, the main deception feature dimension represents a set of key feature attributes used to describe and classify identity deception behavior. This dimension is determined based on the type of failed device fingerprint and reflects the performance pattern of deception behavior on different fingerprint features. The main deception feature dimension includes multiple aspects such as hardware feature deception, software feature forgery, abnormal network behavior, and temporal pattern changes. Each type of device fingerprint corresponds to a specific deception feature dimension. For example, when MAC address fingerprint verification fails, it corresponds to the hardware feature deception dimension; when CPU model fingerprint verification fails, it corresponds to the hardware configuration forgery dimension; and when application signature fingerprint verification fails, it corresponds to the software feature forgery dimension.

[0096] Specifically, the process begins by confirming that the system has determined the device to be authenticated has engaged in identity spoofing and obtaining detailed results of the spoofing determination. Then, it iterates through all failed verification levels, extracting the specific device fingerprint type identifier from each failed verification level. Next, based on the mapping table between device fingerprint types and spoofing feature dimensions, the main spoofing feature dimensions corresponding to each failed fingerprint type are determined. Multiple spoofing feature dimensions are then aggregated and weighted to determine the dominant feature dimension combination for the current spoofing behavior. Next, a pre-set spoofing pattern library is accessed, containing various historically collected identity spoofing behavior cases and feature patterns. A feature similarity calculation method is used to match and compare the main feature dimensions of the current spoofing behavior with historical spoofing patterns in the pattern library. The similarity score between each historical pattern and the current spoofing behavior on the feature dimensions is calculated. The historical spoofing patterns with the highest similarity scores are selected as the matching results. Finally, the matched similar historical spoofing patterns and their detailed information are recorded in the current device's security analysis report.

[0097] S702: When a historical spoofing pattern is matched, obtain the protection policy corresponding to the historical spoofing pattern, and generate security response measures for the device to be authenticated based on the protection policy. The security response measures include at least one of device isolation, traffic restriction, or re-authentication.

[0098] In this application embodiment, the security response measures refer to automated security protection and risk control operations taken against identity spoofing devices. These measures are customized based on protection strategies of historical spoofing patterns and are used to prevent or limit the potential threats posed by spoofing devices to the Internet of Things system. The security response measures include a combination of various protection methods such as device isolation, traffic restriction, and re-authentication. For example, when MAC address spoofing is detected, device isolation measures may be generated to disconnect the device from the network. When software feature forgery is detected, traffic restriction measures may be generated to reduce the device's data transmission privileges. When a minor timing anomaly is detected, re-authentication measures may be generated to require the device to re-authenticate.

[0099] Specifically, the process begins by confirming that the system has successfully matched a historical deception pattern similar to the current deception behavior, obtaining detailed information and identifiers of the matched pattern. Then, it extracts the protection policy configuration associated with the matched historical deception pattern from the deception pattern database, including policy type, strictness level, and execution parameters. Next, it analyzes the specific content of the protection policy, identifying the recommended security response measures and execution levels. Based on the specific situation of the device to be authenticated and the network environment, the protection policy is adapted and its parameters optimized. Then, specific security response measure configurations are generated, including the isolation scope and duration of device isolation measures, bandwidth limits and access control rules for traffic restriction measures, and authentication frequency and verification requirements for re-authentication measures. The generated security response measures are then sorted and organized according to priority and execution order. An execution plan for the security response measures is created, including the start time, duration, and termination conditions. The security response measure configurations are distributed to the corresponding network devices and security components, initiating an automated security protection process. The generation process and execution status of the security response measures are recorded, forming a complete security incident handling record.

[0100] The following describes an exemplary device identity spoofing detection device based on multimodal technology, provided by an embodiment of this application. Figure 4 This is an exemplary hardware structure diagram of a multimodal device identity spoofing detection device provided in an embodiment of this application.

[0101] In some embodiments, the multimodal device identity spoofing detection device is a computer device or includes a computer device. The computer device includes a processor, memory, and a network interface connected via a system bus. The processor of the computer device provides computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and internal memory. The non-volatile storage medium stores an operating system, computer programs, and a database. The internal memory provides an environment for the operation of the operating system and computer programs in the non-volatile storage medium. The database of the computer device stores data. The network interface of the computer device is used to communicate with other external terminals or servers via a network connection. In some embodiments, the network interface can be a wired network interface; in some embodiments, the network interface can also be a wireless network interface. When the computer program is executed by the processor, it implements the methods in the embodiments of this application.

[0102] Those skilled in the art will understand that Figure 4The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.

[0103] The above-described embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit it. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.

[0104] As used in the above embodiments, depending on the context, the term "when..." can be interpreted as meaning "if...", "after...", "in response to determining...", or "in response to detecting...". Similarly, depending on the context, the phrase "when determining..." or "if (the stated condition or event) is interpreted as meaning "if determining...", "in response to determining...", "when (the stated condition or event) is detected", or "in response to detecting (the stated condition or event)".

[0105] In the above embodiments, implementation can be achieved entirely or partially through software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented entirely or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, fiber optic, digital subscriber line) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that integrates one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive), etc.

[0106] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. This program can be stored in a computer-readable storage medium, and when executed, it can include the processes described in the above method embodiments. The aforementioned storage medium includes various media capable of storing program code, such as ROM or random access memory (RAM), magnetic disks, or optical disks.

Claims

1. A method for detecting device identity spoofing based on multimodal methods, characterized in that, The method includes: Obtain multiple different types of device fingerprints for the device to be authenticated, as well as the historical stability data corresponding to each device fingerprint; Based on the historical stability data, the time decay coefficient of each device fingerprint is calculated, wherein the time decay coefficient represents the rate at which the reliability of the device fingerprint decreases over time. Based on the time decay coefficient of each device's fingerprint and the time interval between the current authentication and the last successful authentication, determine the number of verification levels that need to be performed for the current authentication. Based on the number of verification levels, the time decay coefficient of each device fingerprint, and the preset fingerprint combination strategy, different device fingerprints are assigned to each verification level. The device fingerprint of the current verification level of the device to be authenticated is compared with the reference device fingerprint to obtain the difference degree of the current verification level; The difference is compared with the verification threshold of the current verification level to obtain the verification result of the current verification level. When the verification result is passed, the verification threshold of the next verification level is adjusted according to the degree of difference. After completing the verification at each verification level in sequence, the system determines whether the device to be authenticated has engaged in identity fraud based on the verification results at each level.

2. The device identity spoofing detection method based on multimodal methods according to claim 1, characterized in that, The determination of the number of verification levels required for the current authentication based on the time decay coefficient of each device's fingerprint and the time interval between the current authentication and the last successful authentication includes: Get the time interval between the current authentication time and the last successful authentication time of the device to be authenticated; Based on the time decay coefficient of each device fingerprint and the time interval, calculate the current remaining confidence value of each device fingerprint; The number of device fingerprints whose remaining credibility value is lower than a preset credibility threshold is counted. Based on the number of device fingerprints and the preset single-layer verification capacity, the number of verification levels that need to be executed for the current authentication is determined, wherein the number of device fingerprints is positively correlated with the number of verification levels.

3. The device identity spoofing detection method based on multimodality according to claim 1, characterized in that, The step of assigning different device fingerprints to each verification level based on the number of verification levels, the time decay coefficient of each device fingerprint, and a preset fingerprint combination strategy includes: Sort all device fingerprints in ascending order of their age decay coefficient; The device fingerprints that rank first in the order are assigned to the first verification level, which is the first verification level to be executed among all verification levels. The system detects whether there is a historical correlation between the device fingerprints assigned in the first verification level. The historical correlation represents the frequency with which different device fingerprints fail simultaneously during historical verification. Based on the historical correlation, each verification level is adjusted to obtain the device fingerprint of each verification level.

4. The device identity spoofing detection method based on multimodality according to claim 3, characterized in that, The step of adjusting each verification level based on the historical correlation to obtain the device fingerprint for each verification level includes: When a target device fingerprint has a historical correlation exceeding a preset correlation threshold, the target device fingerprint is assigned from the first verification level to the next verification level. Identify unassigned device fingerprints other than those in the first verification layer, and select from the unassigned device fingerprints the device fingerprints with the smallest time decay coefficient and a historical correlation with the first verification layer that is lower than a preset correlation threshold to supplement the first verification layer; The next verification level is used as the first verification level. The detection and allocation steps are repeated until the device fingerprint allocation for all verification levels is completed.

5. The device identity spoofing detection method based on multimodality according to claim 1, characterized in that, The adjustment of the verification threshold for the next verification level based on the degree of difference includes: Obtain the initial verification threshold for the next verification level; The confidence bias is calculated based on the degree of difference between the current verification level and the verification threshold of the current verification level. When the confidence deviation exceeds the preset deviation warning value, a threshold tightening coefficient is determined based on the confidence deviation, and the initial verification threshold is lowered using the threshold tightening coefficient to obtain the verification threshold for the next verification level. When the confidence deviation does not exceed the deviation warning value, the initial verification threshold is maintained as the verification threshold for the next verification level.

6. The device identity spoofing detection method based on multimodality according to claim 1, characterized in that, The step of determining whether the device to be authenticated has engaged in identity spoofing based on the verification results of each verification level includes: The statistical verification results include the number of verification levels that failed verification and the level position of the verification levels that failed verification. When the number of verification levels that fail verification exceeds a preset failure tolerance threshold, it is determined that the device to be authenticated has engaged in identity fraud. When the number of verification levels that fail verification does not exceed the failure tolerance threshold, it is determined whether there is a verification level located in the previous preset number of levels in the level position where the verification level that fails verification is located. If the verification level that failed verification is located in a level position that is within the previous preset number of verification levels, it is determined that the device to be authenticated has engaged in identity fraud. When the verification level that failed verification is not located in the previous preset number of verification levels, the device fingerprint corresponding to the verification level that failed verification is subjected to compensation verification to obtain the compensation verification result, and the device to be authenticated is determined to have identity fraud behavior based on the compensation verification result.

7. The device identity spoofing detection method based on multimodality according to claim 1, characterized in that, After determining whether the device to be authenticated has engaged in identity spoofing, the method further includes: When it is determined that the device to be authenticated has engaged in identity fraud, the device fingerprint type corresponding to the verification level that failed the verification is identified; Based on the device fingerprint type, the main deception feature dimension is determined, and based on the main deception feature dimension, historical deception patterns similar to the identity deception behavior are matched from a preset deception pattern library. When a historical spoofing pattern is matched, the protection policy corresponding to the historical spoofing pattern is obtained, and a security response measure for the device to be authenticated is generated according to the protection policy. The security response measure includes at least one of device isolation, traffic restriction, or re-authentication.

8. A device identity spoofing detection device based on multimodal methods, characterized in that, The multimodal device identity spoofing detection device includes: one or more processors and a memory; the memory is coupled to the one or more processors, the memory is used to store computer program code, the computer program code includes computer instructions, and the one or more processors call the computer instructions to cause the multimodal device identity spoofing detection device to perform the method as described in any one of claims 1-7.

9. A computer program product containing instructions, characterized in that, When the computer program product is run on a multimodal device identity spoofing detection device, the multimodal device identity spoofing detection device performs the method as described in any one of claims 1-7.

10. A computer-readable storage medium comprising instructions, characterized in that, When the instruction is executed on a multimodal device identity spoofing detection device, the multimodal device identity spoofing detection device performs the method as described in any one of claims 1-7.