Industrial internet terminal access equipment based on equipment behavior fingerprints
By collecting multi-dimensional device behavior fingerprints and generating multi-dimensional feature vectors through AI processing, combined with mechanical and electrical interlocking mechanisms, high-precision authentication and complete isolation of industrial internet terminal devices are achieved. This solves the problems of vulnerability to attacks and lack of physical isolation in existing technologies, and provides highly reliable security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- NINGBO ZHENGHANG INTELLIGENT SYSTEM CO LTD
- Filing Date
- 2025-12-31
- Publication Date
- 2026-04-28
AI Technical Summary
Existing industrial internet terminal device access authentication methods are susceptible to key leakage, identifier forgery, or exploitation of system-level vulnerabilities, and lack effective physical isolation measures, making it difficult to completely block the attack risks of malicious devices.
The system employs multi-dimensional device behavior fingerprinting based on current ripple, electromagnetic radiation, and time series analysis. Combined with AI processing, it generates multi-dimensional feature vectors, performs high-precision authentication through a decision logic unit, and achieves complete isolation using a dual physical interlocking mechanism of mechanical and electrical components.
It provides highly reliable and accurate identity authentication, effectively resisting persistent threats and completely blocking the communication and power supply of malicious devices through a dual physical isolation mechanism of mechanical and electrical components.
Smart Images

Figure CN121940762A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of Internet terminal technology, specifically relating to an industrial Internet terminal access device based on device behavior fingerprints. Background Technology
[0002] In the Industrial Internet, terminal devices (such as PLCs and sensors) typically connect to the control system via standard interfaces. Existing access authentication largely relies on software mechanisms, such as pre-set keys, digital certificates, or MAC address whitelists. However, these methods are vulnerable to key leaks, identifier forgery, or exploitation of system-level vulnerabilities, making it difficult to identify malicious devices that have been compromised but whose identities appear "legitimate."
[0003] To enhance security, some solutions attempt to construct device fingerprints using side-channel characteristics such as current and electromagnetic radiation. However, most of these solutions rely on single-dimensional data, resulting in weak anti-interference capabilities and limited identification accuracy. Furthermore, they generally lack integration with physical access control, only providing alarms or logical disconnections, failing to completely block risks. In addition, existing access devices generally lack effective physical isolation measures—even if a device is detected as abnormal, its power supply remains on and the physical channel remains open, posing a risk of being used for signal injection or continuous attacks.
[0004] Therefore, there is an urgent need for a terminal access security device that integrates multi-dimensional essential behavioral characteristics, has high-precision identification capabilities, and can achieve dual physical interlocking of mechanical and electrical components. Summary of the Invention
[0005] To solve the above-mentioned technical problems, the present invention provides the following technical solution.
[0006] An industrial internet terminal access device based on device behavior fingerprinting includes an access port and a main controller, and further includes:
[0007] The behavioral fingerprint acquisition module includes a current sensing unit, an electromagnetic radiation sensing unit, and a time-series analysis unit. The current sensing unit is used to sample the current ripple of the access device; the electromagnetic radiation sensing unit is used to collect the near-field electromagnetic spectrum when the access device is working; and the time-series analysis unit is used to capture and record the precise time series of data packet transmission and response.
[0008] The analysis and processing module includes an AI processing unit and a secure storage unit. The input end of the AI processing unit is connected to the output end of the behavior fingerprint acquisition module, and is used to extract and fuse features from the acquired current ripple, electromagnetic spectrum, and time series to generate a multi-dimensional feature vector characterizing the uniqueness of the device. The secure storage unit is connected to the AI processing unit through a secure bus and is used to store a baseline feature vector library of legitimate devices.
[0009] The access control module includes a decision logic unit and a drive circuit; the input terminal of the decision logic unit is connected to the AI processing unit, and is used to receive multi-dimensional feature vectors generated in real time, and output control signals of different levels by calculating the cosine similarity between the feature vector and the corresponding vector in the benchmark feature vector library; the input terminal of the drive circuit is connected to the decision logic unit.
[0010] An interlocking mechanism is provided, with the output of the drive circuit connected to the interlocking mechanism. The interlocking mechanism includes a mechanical blocking component and a relay. The mechanical blocking component is controlled by the drive circuit and is used to insert into or withdraw from the physical channel of the access port. The relay is connected to the drive circuit, and its switching contacts are connected in series in the power circuit of the access port.
[0011] Furthermore, the decision logic unit presets a first similarity threshold, a second similarity threshold, and a third similarity threshold, where the first similarity threshold > the second similarity threshold > the third similarity threshold. When the cosine similarity is less than the first similarity threshold but not less than the second similarity threshold, the decision logic unit outputs a warning signal; when the cosine similarity is less than the second similarity threshold but not less than the third similarity threshold, the decision logic unit outputs a first-level interlock signal to control the drive circuit to drive the relay to disconnect the power supply circuit; when the cosine similarity is less than the third similarity threshold, the decision logic unit outputs a second-level interlock signal to control the drive circuit to simultaneously drive the mechanical blocking component to physically block the access port and disconnect the power supply circuit of the relay.
[0012] Furthermore, it also includes a trap analysis sandbox, which comprises a virtual port simulator, a security domain memory, and a security processor. When the decision logic unit outputs a warning signal, the main controller redirects the network traffic of suspected illegal devices through the virtual port simulator to a simulated industrial protocol stack running in the security domain memory; the security processor executes the simulated industrial protocol stack and injects a test instruction sequence, feeding back the analysis results to the analysis processing module for updating the baseline feature vector library or adjusting the threshold parameters of the decision logic unit.
[0013] Furthermore, it also includes a stealth identification implantation module, which includes a programmable ripple generation circuit. When the device is authenticated as legitimate, the main controller controls the programmable ripple generation circuit to superimpose a specific frequency and encoded identification ripple signal onto the power circuit of the access port. The amplitude of the identification ripple signal is configured so as not to affect normal power supply and to be recognizable by the current sensing unit.
[0014] Furthermore, the access port and the interlocking mechanism are disposed in a locking part within the device housing. The mechanical blocking assembly includes a driver and a gate. The locking part is provided with a guide groove, and the gate is slidably assembled within the guide groove. The driver is connected to the gate and is used to drive the gate to slide along the guide groove to achieve opening or physical blocking of the access port.
[0015] Furthermore, the actuator is a U-shaped nickel-titanium alloy shape memory wire, with both ends fixed to the locking part and the middle connected to the gate. When the driving circuit supplies electricity to heat the nickel-titanium alloy wire, it contracts due to the shape memory effect, causing the gate to slide and block the access port.
[0016] Furthermore, the locking unit is also equipped with a manual reset mechanism, which includes a lock and a reset slider linked to the lock. When the access port is in a blocked state, the reset slider rests against the gate. When the operator uses a key to open the lock, the lock moves the reset slider, pushing the gate back to the open position and simultaneously triggering a reset signal, causing the main controller to control the drive circuit to stop outputting a power-off signal, thereby restoring the relay to the conducting state.
[0017] Furthermore, the lock integrates a biometric identification module, and the unlocking operation of the lock requires both the insertion of a special key and verification of the operator's identity and authorization by the biometric identification module.
[0018] Compared with the prior art, this application has the following beneficial technical effects:
[0019] 1. By leveraging the inherent characteristics of devices—current ripple, near-field electromagnetic spectrum, and precise operating timing—which are deeply tied to hardware circuitry and operating modes, a multi-dimensional, non-intrusive behavioral fingerprint acquisition module was constructed, providing a highly reliable and accurate identity authentication foundation for industrial terminal access.
[0020] 2. The interlocking mechanism provides two independent physical security barriers. The mechanical blocking component acts directly on the physical channel of the access port, fundamentally preventing the transmission of any data signals. Simultaneously, the relay cuts off the power supply to the device, achieving energy-level isolation. This dual physical isolation mechanism effectively resists various persistent threats targeting the communication protocol stack or operating system. Attached Figure Description
[0021] Figure 1 This is a structural framework diagram of industrial internet terminal access devices.
[0022] Figure 2 This is a flowchart of the access process.
[0023] Figure 3 This is a structural diagram of the mechanical blocking component and the manual reset mechanism (connected to the access port).
[0024] Figure 4 This is a structural diagram of the mechanical blocking component and the manual reset mechanism (access port blocking).
[0025] The following is an explanation of the reference numerals in the attached figures:
[0026] 10. Locking unit; 11. Guide groove; 20. Driver; 30. Gate; 40. Lock; 41. Reset slider; 42. Biometric identification module; 50. Access port. Detailed Implementation
[0027] The present invention will now be described in further detail with reference to the accompanying drawings and specific embodiments.
[0028] In the following embodiments, the same or similar reference numerals denote the same or similar components or components having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain the present invention, and should not be construed as limiting the present invention.
[0029] In the description of this invention, it should be understood that terms such as center, longitudinal, transverse, length, width, thickness, upper, lower, front, rear, left, right, vertical, horizontal, top, bottom, inner, outer, clockwise, counterclockwise, etc., indicating orientation or positional relationships, are based on the orientation or positional relationships shown in the accompanying drawings and are only for the convenience of describing and simplifying the description of this invention; therefore, they should not be construed as limiting this invention. Furthermore, terms such as first, second, etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features shown. In the description of this invention, unless otherwise expressly specified and limited, terms such as installation, connection, linking, etc., should be interpreted broadly, and those skilled in the art can understand the specific meaning of the above terms in this utility model according to the specific circumstances.
[0030] refer to Figure 1 and Figure 2 The present invention provides an industrial internet terminal access device based on device behavior fingerprinting. The device includes an access port 50, a main controller, a behavior fingerprint acquisition module, an analysis and processing module, an access control module, and an interlocking mechanism.
[0031] The behavioral fingerprint acquisition module includes a current sensing unit, an electromagnetic radiation sensing unit, and a timing analysis unit. The current sensing unit connects to the power supply line of port 50 in a non-contact or series manner, sampling the current signal flowing through the access device in real time, with a particular focus on extracting its high-frequency ripple components. Simultaneously, the electromagnetic radiation sensing unit is positioned close to access port 50, typically employing a near-field probe or miniature antenna array, to capture the weak near-field electromagnetic radiation spectrum generated by the access device during power-up and communication. The timing analysis unit works in conjunction with the main controller's network protocol stack or dedicated packet capture hardware to accurately record microsecond-level or even nanosecond-level timestamps of data packet transmission, reception, and response, forming precise time-series data. These three types of data collectively constitute the original behavioral characteristics of the device at the electrical, electromagnetic, and behavioral timing levels.
[0032] The analysis and processing module includes an AI processing unit and a secure storage unit. The multimodal raw data collected by the behavioral fingerprint acquisition module is transmitted to this module. The AI processing unit, typically implemented using an embedded neural network acceleration chip or a high-performance microprocessor, is responsible for running a pre-trained deep learning model. The deep learning model first performs a time-frequency domain transformation on the current ripple signal to extract spectral features, then performs dimensionality reduction and feature filtering on the electromagnetic spectrum data, and performs statistical analysis on the time series to obtain pattern features such as delay and jitter. Subsequently, the model fuses and encodes these heterogeneous features, ultimately generating a multidimensional feature vector. This vector is designed to uniquely characterize the hardware characteristics and inherent operating modes of a specific device.
[0033] The generated feature vectors are used for real-time comparison. Furthermore, during the initial legitimate registration or security learning phase of a device, they can be encrypted and stored in a secure storage unit connected to the analysis and processing module via a secure bus (such as an SPI or I2C bus using an encryption protocol), forming a baseline feature vector library for legitimate devices. The secure storage unit is typically an encryption chip or secure element with physical tamper-proof functionality.
[0034] The access control module is responsible for executing the final authentication and isolation decisions, and includes a decision logic unit and driving circuitry. The decision logic unit receives feature vectors generated by the AI processing unit in real time and compares them with a benchmark library stored in the secure storage unit. The comparison algorithm uses cosine similarity calculation to quantify the degree of matching between the real-time vector and the benchmark vector.
[0035] refer to Figure 3 and Figure 4The output of the drive circuit is connected to an interlocking mechanism, which is located in the locking part 10 and includes a mechanical blocking component and a relay. A preferred embodiment of the driver 20 uses a U-shaped nickel-titanium alloy shape memory wire. Both ends of the wire are fixed to the locking part 10, and the middle is connected to the gate 30. Under normal conditions (without power), the wire is in a martensitic state and is relatively long, with the gate 30 in the open position. When the drive circuit heats the wire due to a secondary interlock signal, the wire transforms into an austenitic state and undergoes contraction deformation, thereby pulling the gate 30 along the guide groove 11 into the blocking position. This design is simple, noiseless, and reliable.
[0036] The decision logic unit internally stores three decreasing similarity thresholds: a first similarity threshold, a second similarity threshold, and a third similarity threshold. When the calculated cosine similarity is lower than the first threshold but higher than or equal to the second threshold, it indicates a slight abnormality in device behavior, but not a complete mismatch. At this time, the decision logic unit outputs a warning signal to the main controller. If the similarity further decreases to below the second threshold but higher than or equal to the third threshold, it is judged as a moderate risk, and the decision logic unit outputs a first-level interlock signal. This signal drives the drive circuit in the access control module, causing the drive circuit to control the relay in the interlock mechanism to operate, disconnecting the switch contacts connected in series in the power circuit of access port 50, thereby cutting off the power supply to the suspected illegal device. When the similarity falls below the lowest third threshold, it means that the behavioral fingerprint is seriously mismatched, and the decision logic unit outputs a second-level interlock signal. At this time, the drive circuit will simultaneously drive the relay in the interlock mechanism to disconnect the power circuit and drive the mechanical blocking component to operate.
[0037] The mechanical blocking component specifically includes a gate 30 driven by a driver 20 (such as a micro motor or a specific actuator). This gate 30 is slidably mounted in a guide groove 11 of a specially designed locking part 10 within the device housing. Upon receiving a secondary interlock signal, the driver 20 pushes the gate 30 into the physical slot channel of the access port 50, physically blocking the insertion of any connector or contact of data pins in connected links, achieving complete data channel isolation. This dual physical isolation mechanism of relay de-energization and mechanical gate 30 blocking constitutes a robust barrier against high-level threats.
[0038] To further enhance security response capabilities, the device also integrates a decoy analysis sandbox. When the decision logic unit outputs a warning signal, the main controller does not immediately perform physical isolation but instead activates the sandbox mechanism. Network traffic from suspected unauthorized devices is redirected to the decoy analysis sandbox. The decoy analysis sandbox includes a virtual port simulator, isolated security domain memory, and a separate security processor. The virtual port simulator simulates a real industrial protocol port, the isolated security domain memory securely runs a simulated industrial protocol stack (such as a simulated Modbus TCP or PROFINET stack), and the security processor executes this simulated protocol stack. The security processor injects test command sequences into suspected devices, observes and records their response behavior.
[0039] These response behavior data are fed back to the analysis and processing module, which can be used in two ways: first, if a variant of a new legitimate device is found, the baseline feature vector library can be updated accordingly to enhance the system's adaptability; second, attack patterns can be analyzed to adaptively adjust the similarity threshold parameters of the decision logic unit to optimize the recognition accuracy.
[0040] For certified legitimate devices, the device also possesses the capability for invisible identification implantation. This function is implemented by an invisible identification implantation module, the core of which is a programmable ripple generation circuit. After the device is certified as legitimate, the main controller instructs this circuit to superimpose a weak AC ripple signal, specifically encoded (such as FSK or PSK modulation based on the device ID), onto the power circuit of access port 50. The amplitude of this identification ripple signal is precisely controlled to a level that neither affects the normal operation of the connected device nor fails to be reliably detected by the device's current sensing unit. This is equivalent to adding an invisible "electronic watermark" to the legitimate connection, facilitating rapid identity reconfirmation during subsequent continuous monitoring and preventing the device from being "switched" after connection.
[0041] To ensure recoverability in case of emergencies or system failures, the locking unit 10 is equipped with a manual reset mechanism. This mechanism includes a lock 40 and a reset slider 41 linked to the lock 40. When the access port 50 is in the blocked state, the reset slider 41 is pressed against the gate 30 by a spring. Authorized operators need to use a special key to open the lock 40. The unlocking action will move the reset slider 41 through mechanical linkage, pushing the gate 30 from the blocked position back to the open position. At the same time, this process will trigger a reset signal switch, which is sent to the main controller. The main controller will then control the drive circuit to stop outputting the power-off signal, reset the relay, and thus fully restore the power supply and connection function of the port.
[0042] To enhance the security of manual reset operations, the lock 40 may further integrate a biometric identification module 42 (such as a fingerprint reader). With this configuration, the unlocking operation must meet both the "insertion of a dedicated key" and "passing of biometric verification," ensuring that only authorized personnel can perform the reset and preventing unauthorized physical bypass.
[0043] The scope of protection of this invention includes, but is not limited to, the above embodiments. The scope of protection of this invention is defined by the claims. Any substitutions, modifications, or improvements to this technology that are easily conceived by those skilled in the art fall within the scope of protection of this invention.
Claims
1. An industrial internet terminal access device based on device behavior fingerprinting, comprising an access port (50) and a main controller, characterized in that, Also includes: The behavioral fingerprint acquisition module includes a current sensing unit, an electromagnetic radiation sensing unit, and a timing analysis unit. The current sensing unit is used to sample the current ripple of the access device. The electromagnetic radiation sensing unit is used to collect the near-field electromagnetic spectrum when the access device is working; the time series analysis unit is used to capture and record the precise time series of data packet transmission and response; The analysis and processing module includes an AI processing unit and a secure storage unit. The input end of the AI processing unit is connected to the output end of the behavior fingerprint acquisition module. It is used to extract and fuse features from the acquired current ripple, electromagnetic spectrum and time series to generate a multi-dimensional feature vector that characterizes the uniqueness of the device. The secure storage unit is connected to the AI processing unit via a secure bus and is used to store a baseline feature vector library of legitimate devices. The access control module includes a decision logic unit and a drive circuit; the input terminal of the decision logic unit is connected to the AI processing unit, and is used to receive multi-dimensional feature vectors generated in real time, and output control signals of different levels by calculating the cosine similarity between the feature vector and the corresponding vector in the benchmark feature vector library; the input terminal of the drive circuit is connected to the decision logic unit. An interlocking mechanism is provided, with the output of the drive circuit connected to the interlocking mechanism. The interlocking mechanism includes a mechanical blocking component and a relay. The mechanical blocking component is controlled by the drive circuit and is used to insert into or exit the physical channel of the access port (50). The relay is connected to the drive circuit, and its switch contacts are connected in series in the power circuit of the access port (50).
2. The industrial internet terminal access device according to claim 1, characterized in that, The decision logic unit presets a first similarity threshold, a second similarity threshold, and a third similarity threshold, with the first similarity threshold > the second similarity threshold > the third similarity threshold; When the cosine similarity is less than the first similarity threshold and not less than the second similarity threshold, the decision logic unit outputs a warning signal; When the cosine similarity is less than the second similarity threshold and not less than the third similarity threshold, the decision logic unit outputs a first-level interlock signal to control the drive circuit to drive the relay to disconnect the power supply circuit; when the cosine similarity is less than the third similarity threshold, the decision logic unit outputs a second-level interlock signal to control the drive circuit to simultaneously drive the mechanical blocking component to physically block the access port (50) and disconnect the power supply circuit of the relay.
3. The industrial internet terminal access device according to claim 1, characterized in that, It also includes a trap analysis sandbox, which includes a virtual port simulator, a security domain memory, and a security processor; When the decision logic unit outputs an early warning signal, the main controller redirects the network traffic of the suspected illegal device through the virtual port simulator to the simulated industrial protocol stack running in the security domain memory; the security processor executes the simulated industrial protocol stack and injects a test instruction sequence, feeding back the analysis results to the analysis and processing module for updating the benchmark feature vector library or adjusting the threshold parameters of the decision logic unit.
4. The industrial internet terminal access device according to claim 1, characterized in that, It also includes a stealth identifier implantation module, which includes a programmable ripple generation circuit. Once the device is authenticated as legitimate, the main controller controls the programmable ripple generation circuit to superimpose a specific frequency and coded identification ripple signal onto the power supply loop of the access port (50). The amplitude of the identification ripple signal is configured to not affect normal power supply and to be recognizable by the current sensing unit.
5. The industrial internet terminal access device according to claim 1, characterized in that, The access port (50) and the interlocking mechanism are disposed in the locking part (10) inside the device housing; The mechanical blocking assembly includes a driver (20) and a gate (30); the locking part (10) is provided with a guide groove (11), and the gate (30) is slidably assembled in the guide groove (11); the driver (20) is connected to the gate (30) and is used to drive the gate (30) to slide along the guide groove (11) to realize the opening or physical blocking of the access port (50).
6. The industrial internet terminal access device according to claim 5, characterized in that, The driver (20) is a U-shaped nickel-titanium alloy shape memory alloy wire, with its two ends fixed to the locking part (10) and its middle part connected to the gate (30); When the driving circuit heats the nickel-titanium alloy wire, it contracts due to the shape memory effect, causing the gate (30) to slide to block the access port (50).
7. The industrial internet terminal access device according to claim 5, characterized in that, The locking part (10) is also provided with a manual reset mechanism, which includes a lock (40) and a reset slider (41) that is linked to the lock (40). When the access port (50) is in a blocked state, the reset slider (41) abuts against the gate (30); when the operator uses a key to open the lock (40), the lock (40) drives the reset slider (41) to move, pushes the gate (30) back to the open position, and triggers a reset signal at the same time, so that the main controller controls the drive circuit to stop outputting the power-off signal, thereby restoring the relay to the conducting state.
8. The industrial internet terminal access device according to claim 7, characterized in that, The lock (40) integrates a biometric identification module (42). The opening operation of the lock (40) requires the insertion of a special key and verification of the operator's identity and permissions by the biometric identification module (42).