Dynamic behavior authentication security system and method for industrial Internet of Things equipment
By using a dynamic behavior authentication system, a Behavior Consistency Index (BCI) is generated by aggregating multi-channel signal streams and unweighted norms. Combined with an active challenge to calculate the Coherence Consistency Index (ACCI), the problem of authentication being vulnerable to attacks and misjudgments in existing technologies is solved, thus achieving accurate identity authentication and security for industrial IoT devices.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHENZHEN HENGKONG TECH CO LTD
- Filing Date
- 2026-02-04
- Publication Date
- 2026-05-01
AI Technical Summary
Existing industrial IoT device authentication methods rely on static keys and single network parameters, which are vulnerable to attacks, have a high false positive rate, and lack security. In particular, they can easily lead to the tampering or interruption of the production process in industrial settings.
A dynamic behavior authentication system is adopted, which acquires multi-channel signal streams through a data acquisition module, performs baseline denoising and distributed processing, generates the Behavioral Consistency Index (BCI) by combining unweighted norm aggregation, and calculates the Coherence Consistency Index (ACCI) through active challenge to achieve dual evaluation and security measures.
It enables precise identification of industrial IoT devices, reduces the detection capability of spoofed devices, improves the robustness and accuracy of authentication, avoids misjudgment and production interruption, and ensures the safety and continuity of industrial production.
Smart Images

Figure CN121967035A_ABST
Abstract
Description
A dynamic behavior authentication security system and method for industrial IoT devices Technical Field
[0001] This invention relates to the field of authentication security technology, specifically to a dynamic behavior authentication security system and method for industrial Internet of Things (IoT) devices. Background Technology
[0002] In industrial production, key equipment such as PLCs, CNC machine tools, industrial robots, smart sensors, and frequency converters are connected to the Industrial Internet of Things (IIoT) via industrial Ethernet, fieldbus, or 5G private networks. Their authenticity and security are directly related to the stable operation of the production process and information security.
[0003] Existing industrial IoT device authentication methods largely rely on static keys, digital certificates, or single network parameter verification, which has certain shortcomings. First, static keys and certificates are vulnerable to leakage, copying, or forgery; once obtained by attackers, they can bypass authentication mechanisms. Second, single network layer parameter authentication cannot cover abnormal behavior at the physical layer, easily leading to situations where "fake devices" pass network communication verification but actually pose security risks. Furthermore, some methods rely solely on averages or thresholds, lacking comprehensive analysis of the complex dynamic characteristics of device operation, resulting in a high false positive rate.
[0004] The aforementioned shortcomings can lead to various abnormal effects in practical applications. For example, when spoofed devices infiltrate industrial networks, they may initially appear "normal," but their physical side-channel behavior differs from that of genuine devices. Ultimately, this could result in the alteration of production processes or the replacement of control logic, posing serious security risks. Furthermore, over-reliance on a single threshold for judgment can easily lead to two types of problems: firstly, misjudging normal devices as abnormal, causing production interruptions; and secondly, judging abnormal devices as normal, allowing security vulnerabilities to be exploited. Especially in industrial settings where continuity and security are highly sensitive, any authentication misjudgment or delayed detection can directly lead to production line shutdowns, equipment damage, or even safety accidents, posing a significant threat to enterprise production safety and data security. Summary of the Invention
[0005] To address the shortcomings of existing technologies, this invention provides a dynamic behavior authentication security system and method for industrial IoT devices, solving the problems mentioned in the background section.
[0006] To achieve the above objectives, the present invention provides the following technical solution: a dynamic behavior authentication security system for industrial IoT devices, comprising a data acquisition module, a data preprocessing module, a feature aggregation module, a comprehensive behavior consistency assessment module, a response coherence analysis module, and a control execution module; the data acquisition module is responsible for acquiring dynamic parameters of the device, including electromagnetic radiation spectrum, power supply ripple, micro-current jitter, micro-vibration entropy, thermal transient recovery, clock phase noise, and network delay jitter, forming a raw multi-channel signal stream; the data preprocessing module is used for baseline denoising, environmental compensation, normalization, and sliding window distributed processing, and constructing a multi-functional... The system references a fingerprint database; the feature aggregation module calculates the deviation of each parameter based on the distribution distance and aggregates them into physical layer deviation and network layer deviation using an unweighted norm method; the comprehensive behavioral consistency assessment module generates a behavioral consistency index (BCI) based on the deviations of the two major categories of physical and network parameters, and performs the first assessment and classification; the response coherence analysis module injects micro-disturbance challenges into gray area devices, collects multi-dimensional responses under disturbances, and calculates the active challenge coherence consistency index (ACCI); the control execution module executes device permission adjustments, network segment isolation, degraded operation, or security linkage measures based on the dual assessment results of BCI and ACCI.
[0007] Preferably, the data acquisition module includes a side-channel parameter acquisition unit, a network and timing jitter acquisition unit, and an environmental baseline labeling unit; the side-channel parameter acquisition unit is used to acquire physical side-channel information during device operation, including: electromagnetic radiation spectral characteristic statistics. Phase noise slope Power supply ripple and microcurrent characteristics By capturing the true response of structural components, bearings, and heat dissipation paths to perturbations, a dynamic fingerprint of "physics-causality" is constructed, and the following data is obtained: entropy of micro-vibration reproduction of the casing. and thermal transient recovery constant The network and timing jitter acquisition unit is used to collect dynamic parameters of the device at the network communication and clock layers, including: fractional Allan deviation. Message arrival interval residual The environmental baseline labeling unit is used to record auxiliary information related to the environment and operating conditions in real time, including: ambient temperature, background electromagnetic noise, operating condition labels for equipment load, speed and medium viscosity, and trend separation of thermal and vibration channels.
[0008] Preferably, the data preprocessing module includes a time synchronization unit and a distributed modeling processing unit. The time synchronization unit is responsible for the time alignment and environmental baseline correction of multi-channel data. It achieves unified synchronization of electromagnetic, current, vibration, temperature and network timing through a PTP / IEEE1588 high-precision clock, and establishes environmental noise and temperature benchmarks in the early stage of acquisition, and subtracts EM background noise, environmental thermal drift and power supply baseline. The distributed modeling processing unit is used to transform the acquired raw time-series signal into a statistical distribution rather than a single mean. It uses sliding window technology to convert the electromagnetic spectrum, ripple energy, vibration entropy, thermal recovery time and timing residual into empirical distribution function EDF or probability histogram, and performs normalization processing.
[0009] Preferably, the feature aggregation module includes a single-parameter distribution difference calculation unit and a multi-parameter deviation aggregation unit; the single-parameter distribution difference calculation unit is used to analyze each parameter one by one and calculate the degree of difference between the current empirical distribution and the reference distribution. ; ;in Indicates the current window distribution. Represents the reference distribution, and the output variance. It belongs to [0,1], and the larger the value, the more severe the deviation. The parameters covered include electromagnetic characteristics. Phase noise Power supply ripple Current fluctuation Vibrational entropy thermal constant and network timing parameters , ; This represents the current empirical distribution function for a specific parameter f. With reference distribution function The biggest difference between them ∈[0,1].
[0010] Preferably, the multi-parameter bias aggregation unit is used to perform unweighted aggregation of all single-parameter difference results to obtain the overall outlier, using L2 norm aggregation: ; ; ;in, Includes the deviation of all physical parameters. The biases, including those of network parameters, are directly synthesized using the L2 norm, avoiding the need for manually setting weights.
[0011] Preferably, the comprehensive behavioral consistency assessment module includes a deviation vector synthesis unit, a consistency index calculation unit, and a threshold determination unit; the deviation vector synthesis unit is used to uniformly model the overall deviation values from the physical domain and the network domain to form a comprehensive deviation vector, with the following input: Combine the two unweighted norm results into a two-dimensional bias vector. This forms a holistic characterization of multidimensional anomalies, enabling comparison of parameter differences from different sources within a single coordinate system; the consistency index calculation unit is used to calculate the comprehensive behavioral consistency index (BCI) using the exponential decay formula; ;in, Indicates the overall deviation intensity of physical side channel parameters. Indicates the overall deviation strength of network or timing parameters. The physical bias and network bias form a two-dimensional vector, and its 2-norm is the magnitude of the combined bias, with a value range of (0,1).
[0012] Preferably, the threshold determination unit is used to make an initial authentication determination based on the Comprehensive Behavioral Consistency Index (BCI) value; a threshold T is set. pass and abnormal threshold T alert When BCI≥T pass When BCI ≤ T, it indicates that the device's current behavior is consistent with the reference model, and it directly passes authentication, is determined to be a "normal device," and continues to work normally; when BCI ≤ T alert When the difference between the device behavior and the reference model exceeds the threshold T, it indicates that the difference is greater than the threshold T. pass If more than 30% of the devices are malfunctioning, they are directly identified as "malfunctioning devices," and the system immediately implements isolation or alarm security measures to prevent potential attacks or spoofed devices from continuing to operate; when T alert <BCI<T pass At this time, the device is neither completely normal nor necessarily abnormal, and enters the gray zone state. In the gray zone, the system will trigger the active challenge verification module to make a further judgment through secondary authentication (coherence + latency consistency).
[0013] Preferably, the response coherence analysis module includes a disturbance injection unit and a coherence consistency calculation unit. The disturbance injection unit is used to inject micro-disturbance challenges into the device in the gray zone state, including electromagnetic pulse disturbances, minor power supply voltage fluctuations, clock phase disturbances, or network packet disturbances. Through small, controllable external intervention, the device generates responses in side channel and network parameters, amplifying its normal or abnormal differences. The coherence consistency calculation unit is used to analyze the multidimensional signal after disturbance injection, calculate the Active Challenge Coherence Consistency Index (ACCI), and perform calculations for each parameter. Define "coherent differences" under proactive challenges. Aggregate the physical domain and network domain using their respective L2 norms: ; ; ; This represents the difference distribution of the parameter collected after the "active perturbation challenge". This represents the reference difference distribution in the fingerprint database under the same challenge conditions. For maximum distributional variability; domain-specific 2-norm aggregation C phys C net : to {Φ EM ,β PN ,ρ PWR ,δ I ,R vib ,τ th} is classified into the physical domain, {σ y (τ),θ lat Classified as network or time series domain; continue to use the "unweighted L2 norm" aggregation idea to avoid manual weight setting and maintain consistency with D. phys / D net A consistent style.
[0014] Preferably, the control execution module includes a decision-making unit and a safety execution unit; the decision-making unit is used to classify the equipment safety level by combining the dual judgment results from the Behavioral Consistency Index (BCI) and the Active Challenge Coherence Index (ACCI); when BCI ≥ T pass Furthermore, if ACCI is normal, the device is considered a trusted device and its original permissions are maintained; when BCI ≤ T alert The ACCI (Association for Coherence and Conformity Index) indicates a severe mismatch, classifying the device as abnormal and triggering isolation and alarms. When in the gray zone, the ACCI is used to provide further results. The security execution unit receives instructions from the decision-making unit and implements specific control operations, including: device permission adjustment: reducing access permissions or allowing only local operation; network segment isolation: isolating abnormal devices from the main industrial network; degraded operation: maintaining minimal available functionality of the device to prevent production interruption; security linkage: linking with other security devices or upper-level monitoring platforms to issue alarms.
[0015] A dynamic behavior authentication security method for industrial IoT devices includes the following modules: Step 1: Collect dynamic parameters of the device, including electromagnetic radiation spectrum, power ripple, micro-current jitter, micro-vibration entropy, thermal transient recovery, clock phase noise, and network delay jitter, forming a raw multi-channel signal stream; Step 2: Perform baseline denoising, environmental compensation, normalization, and sliding window distribution processing, and construct a multi-condition reference fingerprint library; Step 3: Calculate the deviation of each parameter based on the distribution distance, and aggregate them into physical layer deviation and network layer deviation through an unweighted norm method; Step 4: Generate a Behavioral Consistency Index (BCI) based on the deviations of the two major categories of physical and network parameters, and perform the first evaluation and classification judgment; Step 5: Inject micro-disturbance challenges into devices in the gray area, collect multi-dimensional responses under disturbances, and calculate the Active Challenge Coherence Consistency Index (ACCI); Step 6: Based on the dual evaluation results of BCI and ACCI, implement device permission adjustment, network segment isolation, degraded operation, or security linkage measures.
[0016] This invention provides a dynamic behavior authentication security system and method for industrial Internet of Things (IoT) devices, which has the following beneficial effects: (1) When the system is running, it collects dynamic parameters of the device, including electromagnetic radiation spectrum, power ripple, micro current jitter, micro vibration entropy, thermal transient recovery, clock phase noise and network delay jitter, forming an original multi-channel signal stream, performing baseline noise reduction, environmental compensation, normalization and sliding window distribution processing, and constructing a multi-condition reference fingerprint library. Based on the distribution distance, the deviation of each parameter is calculated and aggregated into physical layer deviation and network layer deviation through the unweighted norm method. Based on the deviation of the two major categories of physical and network parameters, a behavior consistency index (BCI) is generated, and the first evaluation and classification judgment are performed. Micro-disturbance challenges are injected into gray zone devices, multi-dimensional responses under disturbance are collected, and active challenge coherence consistency index (ACCI) is calculated. Based on the dual evaluation results of BCI and ACCI, device permission adjustment, network segment isolation, downgrade operation or security linkage measures are implemented.
[0017] (2) This invention forms a complete dynamic authentication system by setting up a data acquisition module, a data preprocessing module, a feature aggregation module, a comprehensive behavior consistency assessment module, a response coherence analysis module, and a control execution module. During equipment operation, this system can collect multi-dimensional dynamic parameters in real time, such as electromagnetic radiation spectrum, power ripple, micro-current jitter, thermal transient recovery, clock phase noise, and network latency. Through distributed modeling, feature aggregation, and consistency assessment, it completes the entire chain of tasks from data acquisition, feature extraction, behavior modeling to authentication decision-making. This enables a comprehensive determination of the authenticity of the identity and the credibility of the behavior of industrial IoT devices, ensuring the continuous and safe operation of the system under complex working conditions.
[0018] (3) Compared with existing technologies that rely heavily on static keys, digital certificates, or single network layer parameters for verification, this invention has significant improvements. On the one hand, side-channel acquisition and multi-dimensional parameter fusion avoid the risk of a single fingerprint being copied or forged, achieving dual authentication based on both physical-causal and network dynamics. On the other hand, by using the unweighted norm and exponential decay formula to calculate the Behavioral Consistency Index (BCI) and combining it with an active challenge mechanism to calculate the Coherent Consistency Index (ACCI), this invention overcomes the limitations of traditional authentication that relies solely on a single threshold judgment, solving the defects of high false positive rate and easy bypass. Especially under gray zone judgment, secondary verification is performed through perturbation injection and coherence analysis, improving the robustness and reliability of the authentication process.
[0019] (4) This invention achieves more accurate and comprehensive dynamic behavior authentication for industrial IoT devices. On the one hand, it enhances the system's ability to detect spoofed devices, tampered devices, and chronic latent attacks, effectively reducing security risks. On the other hand, through dual evaluation and hierarchical control, the authentication decision-making is more hierarchical, ensuring security while avoiding production interruptions due to misjudgment. Ultimately, this invention significantly outperforms existing technologies in terms of accuracy, robustness, and practicality of device identity authentication, achieving the goal of improving security protection levels and ensuring the continuity and reliability of industrial production. Attached Figure Description
[0020] Figure 1 is a block diagram of a dynamic behavior authentication security system for industrial IoT devices according to the present invention; Figure 2 is a schematic diagram of the steps of a dynamic behavior authentication security method for industrial IoT devices according to the present invention; Figure 3 is a schematic diagram of the process of the dynamic behavior authentication system for industrial IoT devices according to the present invention. Detailed Implementation
[0021] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention. Embodiment 1
[0022] This invention provides a dynamic behavior authentication security system for industrial IoT devices. Referring to Figure 1, it includes a data acquisition module, a data preprocessing module, a feature aggregation module, a comprehensive behavior consistency assessment module, a response coherence analysis module, and a control execution module. The data acquisition module is responsible for collecting dynamic parameters of the device, including electromagnetic radiation spectrum, power supply ripple, micro-current jitter, micro-vibration entropy, thermal transient recovery, clock phase noise, and network delay jitter, forming a raw multi-channel signal stream. The data preprocessing module performs baseline denoising, environmental compensation, normalization, and sliding window distributed processing, and constructs a multi-condition reference fingerprint database. The feature aggregation module calculates the deviation of each parameter based on the distribution distance and aggregates them into physical layer deviation and network layer deviation using an unweighted norm method. The comprehensive behavioral consistency assessment module generates the behavioral consistency index (BCI) based on the deviations of the two major categories of physical and network parameters, and performs the first assessment and classification. The response coherence analysis module injects micro-disturbance challenges into gray area devices, collects multi-dimensional responses under disturbances, and calculates the active challenge coherence consistency index (ACCI). The control execution module executes device permission adjustments, network segment isolation, degraded operation, or security linkage measures based on the dual assessment results of BCI and ACCI.
[0023] In this embodiment, dynamic parameters of the collected devices, including electromagnetic radiation spectrum, power supply ripple, micro-current jitter, micro-vibration entropy, thermal transient recovery, clock phase noise, and network delay jitter, are used to form a raw multi-channel signal stream. This stream is preprocessed, and a multi-condition reference fingerprint database is constructed. The deviations of each parameter are calculated based on the distribution distance and aggregated into physical layer deviations and network layer deviations using an unweighted norm method. A Behavioral Consistency Index (BCI) is generated based on the deviations of these two categories of parameters for the first evaluation and classification. Micro-disturbance challenges are injected into devices in the gray area, and multi-dimensional responses under disturbances are collected. An Active Challenge Coherence Consistency Index (ACCI) is calculated. Based on the dual evaluation results of BCI and ACCI, device permission adjustments, network segment isolation, degraded operation, or security linkage measures are implemented. Example 2
[0024] This embodiment is an explanation based on Embodiment 1. Please refer to Figure 1. Specifically, the data acquisition module includes a side-channel parameter acquisition unit, a network and timing jitter acquisition unit, and an environmental baseline labeling unit. The side-channel parameter acquisition unit is used to acquire physical side-channel information during device operation, including: electromagnetic radiation spectral characteristic statistics. Phase noise slope Power supply ripple and microcurrent characteristics By capturing the true response of structural components, bearings, and heat dissipation paths to perturbations, a dynamic fingerprint of "physics-causality" is constructed, and the following data is obtained: entropy of micro-vibration reproduction of the casing. and thermal transient recovery constant The network and timing jitter acquisition unit is used to collect dynamic parameters of the device at the network communication and clock layers, including: fractional Allan deviation. Message arrival interval residual The environmental baseline labeling unit is used to record auxiliary information related to the environment and operating conditions in real time, including: ambient temperature, background electromagnetic noise, operating condition labels for equipment load, speed and medium viscosity, and trend separation of thermal and vibration channels.
[0025] The data preprocessing module includes a time synchronization unit and a distributed modeling processing unit. The time synchronization unit is responsible for the time alignment and environmental baseline correction of multi-channel data. It achieves unified synchronization of electromagnetic, current, vibration, temperature and network timing through a PTP / IEEE1588 high-precision clock, and establishes environmental noise and temperature benchmarks in the early stage of acquisition, and subtracts EM background noise, environmental thermal drift and power supply baseline. The distributed modeling processing unit is used to transform the acquired raw time-series signals into statistical distributions rather than a single mean. It uses sliding window technology to convert electromagnetic spectrum, ripple energy, vibration entropy, thermal recovery time and timing residuals into empirical distribution functions (EDF) or probability histograms, and performs normalization processing.
[0026] In this embodiment, the present invention, by setting up a data acquisition module and a data preprocessing module, can comprehensively acquire physical side channel characteristics and network dynamic parameters during device operation, and combine environmental baseline annotation to achieve real-time correction of operating conditions, thereby constructing a dynamic fingerprint with causal correlation. A high-precision clock is used to achieve synchronous acquisition of multi-channel signals, and a distributed modeling approach is adopted to transform the original time-series signals into statistical distribution features, effectively avoiding information loss and judgment bias caused by single mean features. This design not only enhances the completeness and accuracy of device behavior characteristics, but also significantly improves the anti-interference capability in complex environments, providing a stable and reliable data foundation for subsequent feature aggregation and consistency evaluation. Example 3
[0027] This embodiment is an explanation of Embodiment 1. Please refer to Figure 1. Specifically, the feature aggregation module includes a single-parameter distribution difference calculation unit and a multi-parameter deviation aggregation unit. The single-parameter distribution difference calculation unit is used to analyze each parameter one by one and calculate the degree of difference between the current empirical distribution and the reference distribution. ; ;in Indicates the current window distribution. Represents the reference distribution, and the output variance. It belongs to [0,1], and the larger the value, the more severe the deviation. The parameters covered include electromagnetic characteristics. Phase noise Power supply ripple Current fluctuation Vibrational entropy thermal constant and network timing parameters , ; This represents the current empirical distribution function for a specific parameter f. With reference distribution function The biggest difference between them ∈[0,1].
[0028] The multi-parameter bias aggregation unit is used to perform unweighted aggregation of all single-parameter difference results to obtain the overall outlier, using L2 norm aggregation: ; ; ;in, Includes the deviation of all physical parameters. The biases, including those of network parameters, are directly synthesized using the L2 norm, avoiding the need for manually setting weights.
[0029] The comprehensive behavioral consistency assessment module includes a deviation vector synthesis unit, a consistency index calculation unit, and a threshold determination unit. The deviation vector synthesis unit is used to uniformly model the overall deviation values from the physical domain and the network domain to form a comprehensive deviation vector. Input: Combine the two unweighted norm results into a two-dimensional bias vector. This forms a holistic characterization of multidimensional anomalies, enabling comparison of parameter differences from different sources within a single coordinate system; the consistency index calculation unit is used to calculate the comprehensive behavioral consistency index (BCI) using the exponential decay formula; ;in, Indicates the overall deviation intensity of physical side channel parameters. Indicates the overall deviation strength of network or timing parameters. The physical bias and network bias form a two-dimensional vector, and its 2-norm is the magnitude of the combined bias, with a value range of (0,1).
[0030] The threshold determination unit is used to make an initial authentication determination based on the Comprehensive Behavioral Consistency Index (BCI) value; a threshold T is set to pass the threshold. pass and abnormal threshold T alert When BCI≥T pass When BCI ≤ T, it indicates that the device's current behavior is consistent with the reference model, and it directly passes authentication, is determined to be a "normal device," and continues to work normally; when BCI ≤ T alert When the difference between the device behavior and the reference model exceeds the threshold T, it indicates that the difference is greater than the threshold T. pass If more than 30% of the devices are malfunctioning, they are directly identified as "malfunctioning devices," and the system immediately implements isolation or alarm security measures to prevent potential attacks or spoofed devices from continuing to operate; when T alert <BCI<Tpass At this time, the device is neither completely normal nor necessarily abnormal, and enters the gray zone state. In the gray zone, the system will trigger the active challenge verification module to make a further judgment through secondary authentication (coherence + latency consistency).
[0031] In this embodiment, the present invention, by setting a feature aggregation module and a comprehensive behavior consistency evaluation module, can first calculate the distribution differences of each physical side channel and network timing parameter, and then achieve the overall aggregation of multi-parameter deviations through an unweighted L2 method, effectively avoiding the subjectivity and uncertainty caused by manual weight setting. Furthermore, the overall deviation between the physical domain and the network domain is uniformly modeled as a two-dimensional vector, and an exponential decay formula is used to generate the Comprehensive Behavior Consistency Index (BCI), enabling quantitative comparison of abnormal features from different sources in the same coordinate system. By setting pass thresholds and anomaly thresholds, the present invention can not only quickly complete the hierarchical determination of normal and abnormal devices, but also trigger subsequent secondary authentication for devices in the gray zone state, thereby achieving a refined and hierarchical authentication process. This design significantly improves the accuracy and robustness of device behavior determination, reduces the false positive and false negative rates, and solves the defects of single authentication methods and insufficient detection capabilities in existing technologies. Example 4
[0032] This embodiment is an explanation of Embodiment 1. Please refer to Figure 1. Specifically: the response coherence analysis module includes a disturbance injection unit and a coherence consistency calculation unit. The disturbance injection unit is used to inject micro-disturbance challenges into the device in the gray zone state, including electromagnetic pulse disturbances, minor power supply voltage fluctuations, clock phase disturbances, or network packet disturbances. Through small, controllable external intervention, the device generates responses in side channel and network parameters, amplifying its normal or abnormal differences. The coherence consistency calculation unit is used to analyze the multidimensional signal after disturbance injection, calculate the active challenge coherence consistency index (ACCI), and perform calculations for each parameter. Define "coherent differences" under proactive challenges. Aggregate the physical domain and network domain using their respective L2 norms: ; ; ; This represents the difference distribution of the parameter collected after the "active perturbation challenge". This represents the reference difference distribution in the fingerprint database under the same challenge conditions. For maximum distributional variability; domain-specific 2-norm aggregation C phys C net : to {Φ EM ,β PN ,ρ PWR ,δ I ,R vib ,τ th} is classified into the physical domain, {σy (τ),θ lat Classified as network or time series domain; continue to use the "unweighted L2 norm" aggregation idea to avoid manual weight setting and maintain consistency with D. phys / D net A consistent style.
[0033] The control execution module includes a decision-making unit and a safety execution unit. The decision-making unit combines the dual judgment results from the Behavioral Consistency Index (BCI) and the Active Challenge Coherence Index (ACCI) to classify the equipment's safety level. When BCI ≥ T... pass Furthermore, if ACCI is normal, the device is considered a trusted device and its original permissions are maintained; when BCI ≤ T alert The ACCI (Association for Coherence and Conformity Index) indicates a severe mismatch, classifying the device as abnormal and triggering isolation and alarms. When in the gray zone, the ACCI is used to provide further results. The security execution unit receives instructions from the decision-making unit and implements specific control operations, including: device permission adjustment: reducing access permissions or allowing only local operation; network segment isolation: isolating abnormal devices from the main industrial network; degraded operation: maintaining minimal available functionality of the device to prevent production interruption; security linkage: linking with other security devices or upper-level monitoring platforms to issue alarms.
[0034] In this embodiment, the present invention, by setting up a response coherence analysis module and a control execution module, can actively inject micro-disturbance challenges when the device is in a gray zone state. Through minor disturbances on the electromagnetic, power, clock, or network sides, it effectively amplifies the differences in multi-dimensional parameters between normal and abnormal devices. The coherence consistency calculation unit generates an active challenge coherence consistency index (ACCI) and performs a dual comparison with the previous BCI judgment results, thereby forming a more accurate basis for hierarchical authentication. Furthermore, the control execution module implements dynamic security management of the device based on the dual-index judgment results, including permission adjustment, network segment isolation, degraded operation, and security linkage. This ensures that abnormal devices are isolated in a timely manner to prevent the spread of potential attacks, while maintaining the basic availability of the industrial system while ensuring security. This design breaks through the limitations of traditional passive authentication, realizing a closed-loop authentication mechanism of "passive detection + active challenge," significantly improving the accuracy, robustness, and defense capabilities of the authentication system. Example 5
[0035] A dynamic behavior authentication security method for industrial IoT devices, as shown in Figure 2, specifically includes the following modules: Step 1: Collect dynamic parameters of the device, including electromagnetic radiation spectrum, power ripple, micro-current jitter, micro-vibration entropy, thermal transient recovery, clock phase noise, and network delay jitter, forming the original multi-channel signal stream; Step 2: Perform baseline denoising, environmental compensation, normalization, and sliding window distribution processing, and construct a multi-condition reference fingerprint library; Step 3: Calculate the deviation of each parameter based on the distribution distance, and aggregate them into physical layer deviation and network layer deviation through an unweighted norm method; Step 4: Generate a Behavioral Consistency Index (BCI) based on the deviations of the two major categories of physical and network parameters, and perform the first evaluation and classification judgment; Step 5: Inject micro-disturbance challenges into devices in the gray area, collect multi-dimensional responses under disturbance, and calculate the Active Challenge Coherence Consistency Index (ACCI); Step 6: Based on the dual evaluation results of BCI and ACCI, implement device permission adjustment, network segment isolation, degraded operation, or security linkage measures.
[0036] In this embodiment, the method of the present invention is implemented in six steps to achieve full-process dynamic authentication of industrial IoT devices. First, multi-dimensional physical side-channel and network dynamic parameters are collected to ensure comprehensive and reliable authentication basis. Then, through baseline denoising, environmental compensation, and distributed modeling, environmental interference is effectively eliminated while retaining the true characteristics of device operation. On this basis, the deviation strength between the physical layer and the network layer is calculated using distribution distance and unweighted norm, and the Behavioral Consistency Index (BCI) is further generated for the first judgment. For devices in the gray zone, the difference is amplified by perturbation challenge, and the Active Challenge Coherence Consistency Index (ACCI) is calculated to form a second verification. Finally, the dual results of BCI and ACCI are combined to implement security measures such as permission adjustment, network segment isolation, degraded operation, or security linkage. This method realizes a dual authentication mechanism of "passive consistency assessment + active challenge verification", which not only improves the accuracy and robustness of abnormal device identification, but also takes into account security and the availability of industrial systems, overcoming the shortcomings of existing technologies such as single authentication methods, high false judgment rate, and insufficient security protection.
[0037] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A dynamic behavior authentication security system for industrial Internet of Things (IoT) devices, characterized in that: The system comprises a data acquisition module, a data preprocessing module, a feature aggregation module, a comprehensive behavioral consistency assessment module, a response coherence analysis module, and a control execution module. The data acquisition module is responsible for collecting dynamic parameters of the equipment, including electromagnetic radiation spectrum, power supply ripple, micro-current jitter, micro-vibration entropy, thermal transient recovery, clock phase noise, and network delay jitter, forming a raw multi-channel signal stream. The data preprocessing module performs baseline denoising, environmental compensation, normalization, and sliding window distribution processing, and constructs a multi-condition reference fingerprint database. The feature aggregation module calculates the deviation of each parameter based on the distribution distance and aggregates them into physical layer deviation and network layer deviation using an unweighted norm method. The comprehensive behavioral consistency assessment module generates a behavioral consistency index (BCI) based on the deviations of the two main categories of physical and network parameters, performing the first assessment and classification. The response coherence analysis module is used to inject micro-disturbance challenges into gray zone devices, collect multi-dimensional responses under disturbances, and calculate the active challenge coherence consistency index (ACCI). The control execution module is used to execute device permission adjustments, network segment isolation, degraded operation, or security linkage measures based on the dual evaluation results of BCI and ACCI.
2. The dynamic behavior authentication security system for industrial IoT devices according to claim 1, characterized in that: The data acquisition module includes a side channel parameter acquisition unit, a network and timing jitter acquisition unit, and an environmental baseline labeling unit; The side-channel parameter acquisition unit is used to acquire physical side-channel information during device operation, including: electromagnetic radiation spectral characteristic statistics. Phase noise slope Power supply ripple and microcurrent characteristics By capturing the true response of structural components, bearings, and heat dissipation paths to perturbations, a dynamic fingerprint of "physics-causality" is constructed, and the following data is obtained: entropy of micro-vibration reproduction of the casing. and thermal transient recovery constant The network and timing jitter acquisition unit is used to collect dynamic parameters of the device at the network communication and clock layers, including: fractional Allan deviation. Message arrival interval residual The environmental baseline labeling unit is used to record auxiliary information related to the environment and operating conditions in real time, including: ambient temperature, background electromagnetic noise, operating condition labels for equipment load, speed and medium viscosity, and trend separation of thermal and vibration channels.
3. The dynamic behavior authentication security system for industrial IoT devices according to claim 1, characterized in that: The data preprocessing module includes a time synchronization unit and a distributed modeling processing unit. The time synchronization unit is responsible for the time alignment and environmental baseline correction of multi-channel data. It achieves unified synchronization of electromagnetic, current, vibration, temperature and network timing through a PTP / IEEE 1588 high-precision clock, and establishes environmental noise and temperature benchmarks in the early stage of acquisition, subtracting EM background noise, environmental thermal drift and power supply baseline. The distributed modeling processing unit is used to transform the acquired raw time-series signals into statistical distributions rather than a single mean. It uses sliding window technology to convert electromagnetic spectrum, ripple energy, vibration entropy, thermal recovery time and timing residuals into empirical distribution functions (EDF) or probability histograms, and performs normalization processing.
4. The dynamic behavior authentication security system for industrial IoT devices according to claim 1, characterized in that: The feature aggregation module includes a single-parameter distribution difference calculation unit and a multi-parameter deviation aggregation unit; the single-parameter distribution difference calculation unit is used to analyze each parameter individually and calculate the degree of difference between the current empirical distribution and the reference distribution. ; ;in Indicates the current window distribution. Represents the reference distribution, and the output variance. It belongs to [0,1], and the larger the value, the more severe the deviation. The parameters covered include electromagnetic characteristics. Phase noise Power supply ripple Current fluctuation Vibrational entropy thermal constant and network timing parameters 、 ; This represents the current empirical distribution function for a specific parameter f. With reference distribution function The biggest difference between them ∈[0,1]。 5. The dynamic behavior authentication security system for industrial IoT devices according to claim 4, characterized in that: The multi-parameter deviation aggregation unit is used to perform unweighted aggregation of all single-parameter difference results to obtain the overall outlier, using L2 aggregation: ; ; ;in, Includes the deviation of all physical parameters. The biases, including those of network parameters, are directly synthesized using the L2 norm, avoiding the need for manually setting weights.
6. The dynamic behavior authentication security system for industrial IoT devices according to claim 1, characterized in that: The comprehensive behavioral consistency assessment module includes a deviation vector synthesis unit, a consistency index calculation unit, and a threshold determination unit. The deviation vector synthesis unit is used to uniformly model the overall deviation values from the physical domain and the network domain to form a comprehensive deviation vector. Input: Combine the two unweighted norm results into a two-dimensional bias vector. This forms a holistic characterization of multidimensional anomalies, enabling comparisons of parameter differences from different sources within a single coordinate system; The consistency index calculation unit is used to calculate the overall behavioral consistency index (BCI) using the exponential decay formula. ;in, Indicates the overall deviation intensity of physical side channel parameters. Indicates the overall deviation strength of network or timing parameters. The physical bias and network bias form a two-dimensional vector, and its norm is the magnitude of the combined bias, with a value range of (0,1).
7. The dynamic behavior authentication security system for industrial IoT devices according to claim 6, characterized in that: The threshold determination unit is used to make the initial certification determination based on the Comprehensive Behavioral Consistency Index (BCI) value. Set via threshold T pass and abnormal threshold T alert When BCI≥T pass When BCI ≤ T, it indicates that the device's current behavior is consistent with the reference model, and it directly passes authentication, is determined to be a "normal device," and continues to work normally; when BCI ≤ T alert When the difference between the device behavior and the reference model exceeds the threshold T, it indicates that the difference is greater than the threshold T. pass If more than 30% of the devices are malfunctioning, they are directly identified as "malfunctioning devices," and the system immediately implements isolation or alarm security measures to prevent potential attacks or spoofed devices from continuing to operate; when T alert <BCI<T pass At this time, the device is neither completely normal nor necessarily abnormal, and enters the gray zone state. In the gray zone, the system will trigger the active challenge verification module to make a further judgment through secondary authentication (coherence + latency consistency).
8. The dynamic behavior authentication security system for industrial IoT devices according to claim 1, characterized in that: The response coherence analysis module includes a disturbance injection unit and a coherence consistency calculation unit. The disturbance injection unit injects micro-disturbance challenges into devices in a gray zone state, including electromagnetic pulse disturbances, minor power supply voltage fluctuations, clock phase disturbances, or network packet disturbances. Through small, controllable external intervention, it induces responses in the device's side-channel and network parameters, amplifying normal or abnormal differences. The coherence consistency calculation unit analyzes the multi-dimensional signal after disturbance injection, calculates the Active Challenge Coherence Consistency Index (ACCI), and performs calculations for each parameter. Define "coherent differences" under proactive challenges. Aggregate the physical domain and network domain using their respective L2 norms: ; ; ; This represents the difference distribution of the parameter collected after the "active perturbation challenge". This represents the reference difference distribution in the fingerprint database under the same challenge conditions. For maximum distributional variability; domain-specific 2-norm aggregation C phys C net : will {Φ EM ,β PN ,ρ PWR ,δ I ,R vib ,τ th } is classified into the physical domain, {σ y (τ),θ lat Classified as network or time series domain; continue to use the "unweighted L2 norm" aggregation idea to avoid manual weight setting and maintain consistency with D. phys / D net A consistent style.
9. The dynamic behavior authentication security system for industrial IoT devices according to claim 1, characterized in that: The control execution module includes a decision-making unit and a safety execution unit; the decision-making unit is used to classify the equipment safety level by combining the dual judgment results from the Behavioral Consistency Index (BCI) and the Active Challenge Coherence Index (ACCI). When BCI≥T pass Furthermore, the ACCI status indicates normal operation, classifying it as a trusted device and maintaining its original permissions. When BCI≤T alert Or ACCI indicates a serious mismatch, which is judged as an abnormal device and triggers isolation and alarms; when it is in the gray zone, the results are given in combination with the active challenge coherence consistency index ACCI. The safety execution unit is used to receive instructions from the decision-making unit and implement specific control operations, including: device permission adjustment: reducing access permissions or allowing only local operation; network segment isolation: isolating abnormal devices from the main industrial network; degraded operation: maintaining the minimum available functions of the device to prevent production interruption; safety linkage: linking with other safety devices or upper-level monitoring platforms to issue alarms.
10. A dynamic behavior authentication security method for industrial IoT devices, applied to the dynamic behavior authentication security system for industrial IoT devices as described in any one of claims 1 to 9, characterized in that: The system includes the following modules: Step 1: Collect dynamic parameters of the equipment, including electromagnetic radiation spectrum, power ripple, micro-current jitter, micro-vibration entropy, thermal transient recovery, clock phase noise, and network delay jitter, forming the original multi-channel signal stream; Step 2: Perform baseline denoising, environmental compensation, normalization, and sliding window distribution processing, and construct a multi-condition reference fingerprint library; Step 3: Calculate the deviation of each parameter based on the distribution distance, and aggregate them into physical layer deviation and network layer deviation through an unweighted norm method; Step 4: Generate the Behavioral Consistency Index (BCI) based on the deviations of the two major categories of physical and network parameters, and perform the first evaluation and classification judgment; Step 5: Inject micro-disturbance challenges into gray area equipment, collect multi-dimensional responses under disturbances, and calculate the Active Challenge Coherence Consistency Index (ACCI); Step 6: Based on the dual evaluation results of BCI and ACCI, implement equipment permission adjustment, network segment isolation, degraded operation, or security linkage measures.