Multi-dimensional equipment security verification method and device, terminal equipment and storage medium

By integrating biometrics, equipment characteristics, and environmental characteristics into power equipment to generate multi-dimensional identifiers, and combining this with dynamic certificate verification, the problem of equipment being easily hacked in existing technologies is solved, thereby improving equipment security.

CN122001679APending Publication Date: 2026-05-08POWER DISPATCHING CONTROL CENT OF GUANGDONG POWER GRID CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
POWER DISPATCHING CONTROL CENT OF GUANGDONG POWER GRID CO LTD
Filing Date
2026-03-25
Publication Date
2026-05-08

AI Technical Summary

Technical Problem

Existing biometric and physical password-based device security verification methods are merely a single-dimensional combination of security technologies, making them vulnerable to unauthorized decryption and resulting in weak protection for critical devices.

Method used

By fusing multi-dimensional information such as user biometrics, device characteristics, and environmental characteristics obtained from the target device, a first local identifier is generated. A dynamic certificate is then generated in the cloud, and combined with multiple biometric matching operations, the security of device control is ensured.

Benefits of technology

It improves the security of device verification, increases the difficulty of unauthorized cracking, and enhances the security of device control verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122001679A_ABST
    Figure CN122001679A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-dimensional equipment security verification method and device, terminal equipment and a storage medium, and belongs to the technical field of electric power security, and the method comprises the steps that target equipment obtains a first biological feature of a to-be-verified user, and performs primary biological feature matching with a plurality of preset second biological features in the target equipment; if matching succeeds, acquiring equipment features and environment features, and generating a first local identifier; transmitting the first local identifier to a cloud, so that the cloud generates a dynamic certificate according to the first local identifier, and transmitting the dynamic certificate to the target equipment; acquiring a third biological characteristic of the user to be verified, and performing secondary biological characteristic matching; and if the secondary biological characteristics are successfully matched, analyzing the dynamic certificate and generating a second local identifier, matching the second local identifier with the first local identifier, and when the matching is successful, endowing the target equipment with a control right. By implementing the invention, the problem that the equipment in the prior art is easy to be illegally cracked can be solved, and the equipment verification security is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of power safety technology, and in particular to a multi-dimensional device safety verification method, apparatus, terminal equipment, and storage medium. Background Technology

[0002] In power systems, security protection measures for the operation and maintenance control of critical equipment in substations are extremely important. Traditional security methods involve recording the biometrics of the person in charge of the equipment and then combining them with corresponding physical passwords to achieve equipment security verification. Biometrics include, but are not limited to, one or more of fingerprints, facial features, irises, and voiceprints, while physical passwords include, but are not limited to, digital passwords and ID cards.

[0003] However, existing security verification methods for critical devices that rely on biometrics and physical passwords are essentially just a combination of security technologies on a single dimension. From the device processing perspective, once the biometrics and physical password are obtained, control of the device can be granted. This means that during unauthorized cracking, control can be gained simply by cracking each biometric and physical password separately. This simplistic approach to device security verification results in weak overall protection for critical devices, making them vulnerable to unauthorized cracking. Therefore, there is an urgent need for a verification method that can improve device security. Summary of the Invention

[0004] This invention provides a multi-dimensional device security verification method, apparatus, terminal device, and storage medium, which can effectively solve the problem that existing devices are easily cracked and improve device verification security.

[0005] An embodiment of the present invention provides a multi-dimensional device security verification method, comprising: When the target device detects a user verification operation, the target device acquires the first biometric feature of the user to be verified and performs a biometric matching between the first biometric feature and several preset second biometric features in the target device. If a biometric match is successful, the target device acquires its own device features and environmental features, and performs multi-dimensional information fusion based on the first biometric feature, device features and environmental features to generate the first local identifier of the target device. The target device transmits the first local identifier to the cloud, so that the cloud generates a dynamic certificate based on the first local identifier and transmits the dynamic certificate to the target device; When the target device receives the dynamic certificate, the target device obtains the third biometric feature of the user to be verified, and performs a secondary biometric matching between the third biometric feature and several preset second biometric features in the target device. If the secondary biometric matching is successful, the target device parses the dynamic certificate and generates a second local identifier. The second local identifier is then matched with the first local identifier. If the identifier matching is successful, the target device grants the user to be verified control over the target device.

[0006] Furthermore, the first biometric feature, the second biometric feature, and the third biometric feature each include one or a combination of fingerprints, facial features, irises, and voiceprints; The device features include: device identification and device voltage sampling data; wherein, the device voltage sampling data includes: device sampling time data and device sampling voltage value data; The environmental characteristics include: equipment substation code and equipment GPS coordinates.

[0007] Furthermore, the step of fusing multi-dimensional information based on the first biometric feature, device feature, and environmental feature to generate the first local identifier of the target device includes: Obtain the device key of the target device, perform an XOR operation on the device key and the first biometric feature to obtain the first biometric feature to be encrypted, and encrypt the first biometric feature to be encrypted according to the hash function to obtain the first biometric feature to be fused. The voltage fluctuation during the sampling time is generated based on the equipment sampling time data and the equipment sampling voltage value data. The equipment features to be fused are generated based on the equipment identifier, the equipment sampling voltage value data, and the voltage fluctuation during the sampling time. The environmental features to be fused are generated based on the equipment's substation code and its GPS coordinates. A first local identifier for the target device is generated based on the first biometric feature to be fused, the device feature to be fused, and the environmental feature to be fused.

[0008] Further, the step of transmitting the first local identifier to the cloud, so that the cloud generates a dynamic certificate based on the first local identifier, includes: The first local identifier is encrypted to obtain an encrypted first local identifier; The encrypted first local identifier is transmitted to the cloud so that the cloud can parse the encrypted first local identifier and generate a dynamic certificate.

[0009] Further, the step of parsing the encrypted first local identifier and generating a dynamic certificate includes: Obtain the preset cloud key and parse the encrypted first local identifier to obtain the first local identifier and the original encryption time of the encrypted first local identifier; Obtain the first current time, and determine the encrypted transmission delay based on the first current time and the original encryption time; When the encrypted transmission delay is no greater than a first preset time threshold, a dynamic certificate is generated based on the first local identifier.

[0010] Further, the step of parsing the dynamic certificate and generating a second local identifier includes: Obtain the original encryption time and the second current time when receiving the dynamic certificate, and determine the certificate verification delay based on the second current time and the original encryption time; When the certificate verification delay is no greater than the second preset time threshold, the dynamic certificate is parsed and a second local identifier is generated.

[0011] Further, encrypting the first local identifier to obtain an encrypted first local identifier includes: The first local identifier is encrypted using an identifier-based asymmetric cryptographic algorithm to obtain an encrypted first local identifier.

[0012] Based on the above method embodiments, the present invention provides corresponding apparatus embodiments; One embodiment of the present invention provides a multi-dimensional device security verification device, including: a multi-dimensional feature fusion module, a dynamic certificate generation module, and an identifier verification module; The multi-dimensional feature fusion module is used to obtain the first biometric feature of the user to be verified when the target device detects a user verification operation, and perform a biometric feature matching between the first biometric feature and a number of preset second biometric features in the target device; if the biometric feature matching is successful, the target device obtains its own device features and environmental features, and performs multi-dimensional information fusion based on the first biometric feature, device features and environmental features to generate the first local identifier of the target device. The dynamic certificate generation module is used by the target device to transmit the first local identifier to the cloud, so that the cloud generates a dynamic certificate based on the first local identifier and transmits the dynamic certificate to the target device. The identification verification module is used to, when the target device receives the dynamic certificate, obtain the third biometric feature of the user to be verified, and perform a secondary biometric matching between the third biometric feature and a number of preset second biometric features in the target device; if the secondary biometric matching is successful, the target device parses the dynamic certificate and generates a second local identifier, and performs an identifier matching between the second local identifier and the first local identifier; when the identifier matching is successful, the target device grants the user to be verified control over the target device.

[0013] Another embodiment of the present invention provides a terminal device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the multi-dimensional device security verification method described in the above-described embodiments of the invention.

[0014] Another embodiment of the present invention provides a storage medium including a stored computer program, wherein, when the computer program is executed, it controls the device where the storage medium is located to perform a multi-dimensional device security verification method as described in the above-described embodiment of the invention.

[0015] The following benefits can be obtained by implementing the present invention: This invention provides a multi-dimensional device security verification method, apparatus, terminal device, and storage medium. The device security verification method, when verifying a user on a target device, acquires first biometric features, device features, and environmental features. It then fuses these features across multiple dimensions to generate a first local identifier containing the fused information. By combining the first biometric features, device features, and environmental features, the resulting first local identifier becomes more complex, making it more difficult to crack the first local identifier and the dynamic certificate generated based on it during transmission. This increases the difficulty of unauthorized decryption during data transmission, thereby improving the security of user access to device control and enhancing the overall security of device verification. Attached Figure Description

[0016] Figure 1 This is a flowchart illustrating a multi-dimensional device security verification method provided in an embodiment of the present invention.

[0017] Figure 2 This is a schematic diagram of the structure of a multi-dimensional device security verification device provided in an embodiment of the present invention. Detailed Implementation

[0018] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0019] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions in this application will be clearly and completely described below with reference to the accompanying drawings of the embodiments of this application. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application. Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application pertains; the terminology used herein is for the purpose of describing specific embodiments only and is not intended to limit this application; the terms "comprising" and "having," and any variations thereof, in the specification, claims, and the foregoing description of the accompanying drawings of this application are intended to cover non-exclusive inclusion. In the description of the embodiments of this application, technical terms such as "first," "second," etc., are only used to distinguish different objects and should not be construed as indicating or implying relative importance or implicitly indicating the number, specific order, or primary or secondary relationship of the indicated technical features. In the description of the embodiments of this application, "a plurality of" means two or more, unless otherwise explicitly specified. The reference to "embodiment" herein means that a specific feature, structure, or characteristic described in connection with the embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art will understand, explicitly and implicitly, that the embodiments described herein can be combined with other embodiments. In the description of the embodiments of this application, the term "and / or" is merely a description of the association relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, and B existing alone. Additionally, the character " / " in this document generally indicates that the preceding and following related objects have an "or" relationship. In the description of the embodiments of this application, the term "multiple" refers to two or more (including two); similarly, "multiple groups" refers to two or more groups (including two groups), and "multiple pieces" refers to two or more pieces (including two pieces). In the description of the embodiments of this application, unless otherwise expressly specified and limited, technical terms such as "installation," "connection," "joining," and "fixing" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral part; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; they can refer to the internal communication of two components or the interaction between two components. For those skilled in the art, the specific meaning of the above terms in the embodiments of this application can be understood according to the specific circumstances.

[0020] like Figure 1As shown, to address the problem of existing technology devices being easily hacked, an embodiment of the present invention provides a multi-dimensional device security verification method. This method is applied to the device side and includes: Step S1: When the target device detects a user verification operation, the target device acquires the first biometric feature of the user to be verified, and performs a biometric matching between the first biometric feature and several preset second biometric features in the target device. Step S2: If a biometric match is successful, the target device acquires its own device features and environmental features, and performs multi-dimensional information fusion based on the first biometric feature, device features and environmental features to generate the first local identifier of the target device; Step S3: The target device transmits the first local identifier to the cloud, so that the cloud generates a dynamic certificate based on the first local identifier and transmits the dynamic certificate to the target device; Step S4: When the target device receives the dynamic certificate, the target device obtains the third biometric feature of the user to be verified, and performs a secondary biometric matching between the third biometric feature and several preset second biometric features in the target device; Step S5: If the secondary biometric matching is successful, the target device parses the dynamic certificate and generates a second local identifier. The second local identifier is matched with the first local identifier. When the identifier matching is successful, the target device grants the user to be verified control over the target device.

[0021] For step S1, when the device end of the power equipment (i.e. the target device mentioned above) detects that a user is performing a verification operation on the target device to obtain control of the device, the target device first obtains the first biometric feature of the user to be verified through the interactive device on the device, including but not limited to fingerprint lock, camera and microphone.

[0022] In a preferred embodiment, the first, second, and third biometric features each include one or a combination of fingerprint, facial features, iris, and voiceprint; the device features include device identification and device voltage sampling data; wherein the device voltage sampling data includes device sampling time data and device sampling voltage value data; the environmental features include device substation code and device GPS coordinates.

[0023] Specifically, in this invention, the first, second, and third biometric features are all obtained from one or a combination of fingerprints, facial features, irises, and voiceprints. The first biometric feature refers to the biometric feature generated by the user to be verified during their initial interaction with the target device, obtained through the target device's interaction device. The second biometric feature is the biometric feature of a pre-stored, verified user in the target device, equivalent to the biometric feature of a user who can control the target device. The third biometric feature refers to the biometric feature generated by the user to be verified during their second interaction with the target device, obtained through the target device's interaction device.

[0024] In step S1, after obtaining the first biometric feature of the user to be verified, the target device performs a biometric match against several pre-stored second biometric features to determine whether the user to be verified is a user who has been authorized by the target device in the past. If not, the target device issues an alarm and refuses to execute subsequent steps. If yes, then step S2 is executed.

[0025] For step S2, after passing the verification in step S1, the target device acquires its own device characteristics, including device identifier (i.e., device ID) and device voltage sampling data; wherein, the device voltage sampling data includes: device sampling time data and device sampling voltage value data; simultaneously, the target device acquires its own environmental characteristics, including device substation code and device global positioning system coordinates (i.e., device GPS coordinates). Based on the first biometric feature, device characteristics, and environmental characteristics, multi-dimensional information fusion is performed to generate the first local identifier of the target device.

[0026] In a preferred embodiment, the step of fusing multi-dimensional information based on the first biometric feature, device feature, and environmental feature to generate a first local identifier for the target device includes: obtaining the device key of the target device; performing an XOR operation on the device key and the first biometric feature to obtain a first biometric feature to be encrypted; encrypting the first biometric feature to be encrypted according to a hash function to obtain a first biometric feature to be fused; generating a voltage fluctuation amount during the device sampling time based on device sampling time data and device sampling voltage value data; generating a device feature to be fused based on the device identifier, device sampling voltage value data, and voltage fluctuation amount during the device sampling time; generating an environmental feature to be fused based on the device substation code and device GPS coordinates; and generating a first local identifier for the target device based on the first biometric feature to be fused, the device feature to be fused, and the environmental feature to be fused.

[0027] Specifically, for the first biometric feature, the device key of the target device must first be obtained. An XOR operation is then performed between the device key and the first biometric feature to obtain the first biometric feature to be encrypted. This XOR operation increases randomness, making the first biometric feature data impossible to decrypt in reverse. A hash function is then introduced to encrypt the first biometric feature to be encrypted, resulting in the first biometric feature to be fused. This process of determining the first biometric feature to be fused can be represented as: in, Indicates the first biological characteristic to be fused; Represents a cryptographic hash function; Indicates the primary biological characteristic; Indicates the device key; This is the XOR operator.

[0028] For equipment characteristics, the voltage fluctuation within the sampling time is generated using equipment sampling time data and equipment sampling voltage value data. The corresponding processing formula can be expressed as: in, This indicates the voltage fluctuation during the device's sampling time. Indicates the number of sampling points in the sliding window; Indicates the first The voltage value sampled next; Indicates the first The voltage value was sampled once.

[0029] Based on the device identifier, the device sampled voltage value data, and the voltage fluctuation during the device sampling time, the device features to be fused are generated, and the corresponding processing formula can be expressed as: in, Indicates the characteristics of the devices to be merged; Represents the device ID hash; This indicates the voltage fluctuation during the device's sampling time. This represents the sampled voltage value data from the device; This is a voltage check code used to detect bit errors in the transmission of voltage data.

[0030] For environmental features, the Bos-Choherry code is first used to convert the equipment substation code into a 15-bit error-correcting code to resist transmission errors. Then, geohashing is used to convert the equipment GPS coordinates into a 6-bit string. Finally, the environmental features to be fused are obtained, and the corresponding processing formula can be expressed as: in, Indicates the substation code of the equipment; This represents the hash fusion value of the equipment's substation code; For Bos-Joherry codes; Indicates the device's GPS coordinates; For geo-hash; Indicates the average longitude of the region; Indicates the standard deviation of longitude; Indicates the average latitude of the region; Indicates the standard deviation of latitude; Represents the real part of GPS longitude; Indicates real-time electromagnetic intensity; Indicates the base station reference field strength; Represents the normalization coefficients; final output This reflects the current intensity of electromagnetic interference; Indicates the environmental characteristics to be integrated; Represents a normalized vector of GPS coordinates; This represents the imaginary part of GPS latitude.

[0031] Finally, based on the first biometric feature to be fused, the device feature to be fused, and the environmental feature to be fused, a first local identifier for the target device is generated, which can be represented as: in, This is the first local identifier; Represents a key-based hash message authentication function; Indicates the first biological characteristic to be fused; Indicates the characteristics of the devices to be merged; Indicates the environmental characteristics to be integrated; This indicates the device sampling time data; This represents the key for the key-based hash message authentication function; Representation operators are used to concatenate multiple inputs sequentially into a binary stream of data.

[0032] By triple binding of primary biometrics, device characteristics, and environmental characteristics, and utilizing... The key dependency ensures that attackers cannot forge the first local identifier. .

[0033] For step S3, the first local identifier is transmitted to the cloud so that the cloud generates a dynamic certificate based on the first local identifier and transmits the dynamic certificate to the target device.

[0034] In a preferred embodiment, transmitting the first local identifier to the cloud so that the cloud can generate a dynamic certificate based on the first local identifier includes: encrypting the first local identifier to obtain an encrypted first local identifier; and transmitting the encrypted first local identifier to the cloud so that the cloud can parse the encrypted first local identifier and generate a dynamic certificate.

[0035] In a preferred embodiment, encrypting the first local identifier to obtain an encrypted first local identifier includes: encrypting the first local identifier using an identifier-based asymmetric cryptographic algorithm to obtain an encrypted first local identifier.

[0036] Specifically, in this invention, the function used to encrypt the first local identifier is an identifier-based asymmetric cryptographic algorithm, namely SM9, and its encryption process can be expressed as follows: in, Indicates the first local identifier of encryption; It is an identifier-based asymmetric cryptographic algorithm; For cloud public keys; Indicates the first local identifier; Indicates the device's GPS coordinates; Indicates the level of operation permission.

[0037] The encrypted first local identifier obtained after encryption The data is transmitted to a cloud server, which then generates a dynamic certificate.

[0038] In a preferred embodiment, parsing the encrypted first local identifier and generating a dynamic certificate includes: obtaining a preset cloud key to parse the encrypted first local identifier, obtaining the first local identifier and the original encryption time of the encrypted first local identifier; obtaining a first current time, determining the encryption transmission delay based on the first current time and the original encryption time; and generating a dynamic certificate based on the first local identifier when the encryption transmission delay is not greater than a first preset time threshold.

[0039] Specifically, the cloud server obtains a preset cloud key to parse the encrypted first local identifier, obtaining the first local identifier and its original encryption time. Simultaneously, it obtains the cloud server's current time and determines the encryption transmission delay. A dynamic certificate is generated based on the first local identifier only if the encryption transmission delay is no greater than a first preset time threshold. If the encryption transmission delay exceeds the first preset time threshold, the verification is considered timed out, and a verification failure message is sent to the user to be verified. In this invention, the first preset time threshold is set to 5 seconds.

[0040] When generating a dynamic certificate, a dynamic risk coefficient is first generated. This generation process can be represented as follows: in, Indicates the dynamic risk coefficient. ; express Activation function Indicates proportional weight; This indicates the voltage fluctuation during the device's sampling time. Indicates the maximum allowable voltage of the system; Indicates real-time GPS coordinates. Indicates the coordinates of the device's registered address; This represents the Euclidean distance function.

[0041] Dynamic certificates are three-part structures, and their generation can be represented as follows: in, Indicates a dynamic certificate; This indicates 256-bit encryption; This indicates the key corresponding to the 256 encryption, using the key. Hide the target device's real ID; Indicates the first local identifier; This indicates the device sampling time data; It is a time function; This is a hash operation; Indicates the dynamic risk coefficient; It is a hash algorithm; Represents a random number; Indicates the level of operation permission; It is a time offset function based on the operation permission level; This is the serial number of the dynamic certificate.

[0042] The cloud server transmits the generated dynamic certificate to the target device so that the device can perform subsequent steps.

[0043] In step S4, when the target device receives the dynamic certificate transmitted from the cloud, it performs a second biometric acquisition of the user's biometrics to obtain the user's third biometric. This third biometric is then matched against several preset second biometrics in the target device. If the second biometric match is successful, the dynamic certificate is received using the third biometric. If the second biometric match fails, the user is notified that the security verification has failed, and an alarm message is issued.

[0044] For step S5, in a preferred embodiment, parsing the dynamic certificate and generating a second local identifier includes: obtaining the original encryption time and the second current time when receiving the dynamic certificate; determining the certificate verification delay based on the second current time and the original encryption time; and parsing the dynamic certificate and generating a second local identifier when the certificate verification delay is not greater than a second preset time threshold.

[0045] Specifically, before parsing the dynamic certificate, a time validity verification is required. This involves obtaining the original encryption time and the target device's second current time when receiving the dynamic certificate. The certificate verification delay is then determined based on the second current time and the original encryption time. The dynamic certificate is only parsed if the certificate verification delay is no greater than a second preset time threshold. If the certificate verification delay exceeds the second preset time threshold, the user to be verified is notified that the security verification has failed, and an alarm message is issued.

[0046] When parsing a dynamic certificate, the reconstructed second local identifier is obtained by reconstructing the local identifier based on the dynamic certificate. The parsing process can be represented as follows: in, Indicates the second local identifier; Indicates the device key; The XOR operator; Indicates the characteristics of the devices to be merged; Indicates the third biological characteristic; Indicates the environmental characteristics to be integrated; Represents a key-based hash message authentication function; This represents the key for the key-based hash message authentication function; This indicates the sampling time data of the device.

[0047] The matching of the first local identifier and the second local identifier is verified by designing a verification function to verify whether the identifier issued by the cloud is consistent with the locally reconstructed identifier. The verification process can be represented as follows: in, This indicates the matching between the first local identifier and the second local identifier, and is used to verify whether the identifier distributed from the cloud is consistent with the identifier reconstructed locally; Indicating consistency of risk, due to and All numbers are random, making them impossible for attackers to forge. ; This represents the verification result of the verification function on the matching of the first local identifier and the second local identifier. Its value is a Boolean logic result: True if the first and second local identifiers match, and False if they do not match. When the consistency verification of the first and second local identifiers passes, control of the target device is granted to the user being verified.

[0048] Based on the above method embodiments, the present invention provides corresponding apparatus embodiments.

[0049] like Figure 2 As shown, an embodiment of the present invention provides a multi-dimensional device security verification device, including: a multi-dimensional feature fusion module, a dynamic certificate generation module, and an identifier verification module; The multi-dimensional feature fusion module is used to obtain the first biometric feature of the user to be verified when the target device detects a user verification operation, and perform a biometric feature matching between the first biometric feature and a number of preset second biometric features in the target device; if the biometric feature matching is successful, the target device obtains its own device features and environmental features, and performs multi-dimensional information fusion based on the first biometric feature, device features and environmental features to generate the first local identifier of the target device. The dynamic certificate generation module is used by the target device to transmit the first local identifier to the cloud, so that the cloud generates a dynamic certificate based on the first local identifier and transmits the dynamic certificate to the target device. The identification verification module is used to, when the target device receives the dynamic certificate, obtain the third biometric feature of the user to be verified, and perform a secondary biometric matching between the third biometric feature and a number of preset second biometric features in the target device; if the secondary biometric matching is successful, the target device parses the dynamic certificate and generates a second local identifier, and performs an identifier matching between the second local identifier and the first local identifier; when the identifier matching is successful, the target device grants the user to be verified control over the target device.

[0050] For the multi-dimensional feature fusion module, when the device end of the power equipment (i.e. the target device mentioned above) detects that a user is performing a verification operation on the target device to obtain control of the device, the target device first obtains the first biometric feature of the user to be verified through the interactive device on the device, including but not limited to fingerprint lock, camera and microphone.

[0051] In a preferred embodiment, the first, second, and third biometric features each include one or a combination of fingerprint, facial features, iris, and voiceprint; the device features include device identification and device voltage sampling data; wherein the device voltage sampling data includes device sampling time data and device sampling voltage value data; the environmental features include device substation code and device GPS coordinates.

[0052] Specifically, in this invention, the first, second, and third biometric features are all obtained from one or a combination of fingerprints, facial features, irises, and voiceprints. The first biometric feature refers to the biometric feature generated by the user to be verified during their initial interaction with the target device, obtained through the target device's interaction device. The second biometric feature is the biometric feature of a pre-stored, verified user in the target device, equivalent to the biometric feature of a user who can control the target device. The third biometric feature refers to the biometric feature generated by the user to be verified during their second interaction with the target device, obtained through the target device's interaction device.

[0053] In the multi-dimensional feature fusion module, after acquiring the first biometric feature of the user to be verified, the target device performs a biometric match against several pre-stored second biometric features to determine whether the user to be verified is a user who has been authorized by the target device in the past. If not, the target device issues an alarm and refuses to execute subsequent steps. If yes, the following steps are executed.

[0054] After verification by the multi-dimensional feature fusion module, the target device acquires its own device characteristics, including device identifier (i.e., device ID) and device voltage sampling data. The device voltage sampling data includes device sampling time data and device sampling voltage value data. Simultaneously, the target device acquires its own environmental characteristics, including the device substation code and the device's Global Positioning System coordinates (i.e., device GPS coordinates). Based on the first biometric feature, device characteristics, and environmental characteristics, multi-dimensional information fusion is performed to generate the target device's first local identifier.

[0055] In a preferred embodiment, the step of performing multi-dimensional information fusion based on the first biometric feature, device feature, and environmental feature to generate a first local identifier for the target device includes: Obtain the device key of the target device, perform an XOR operation on the device key and the first biometric feature to obtain the first biometric feature to be encrypted, and encrypt the first biometric feature to be encrypted according to the hash function to obtain the first biometric feature to be fused. The voltage fluctuation during the sampling time is generated based on the equipment sampling time data and the equipment sampling voltage value data. The equipment features to be fused are generated based on the equipment identifier, the equipment sampling voltage value data, and the voltage fluctuation during the sampling time. The environmental features to be fused are generated based on the equipment substation code and the equipment's GPS coordinates; the first local identifier of the target equipment is generated based on the first biometric feature to be fused, the equipment feature to be fused, and the environmental features to be fused.

[0056] Specifically, for the first biometric feature, the device key of the target device must first be obtained. An XOR operation is then performed between the device key and the first biometric feature to obtain the first biometric feature to be encrypted. This XOR operation increases randomness, making the first biometric feature data impossible to decrypt in reverse. A hash function is then introduced to encrypt the first biometric feature to be encrypted, resulting in the first biometric feature to be fused. This process of determining the first biometric feature to be fused can be represented as: in, Indicates the first biological characteristic to be fused; Represents a cryptographic hash function; Indicates the primary biological characteristic; Indicates the device key; This is the XOR operator.

[0057] For equipment characteristics, the voltage fluctuation within the sampling time is generated using equipment sampling time data and equipment sampling voltage value data. The corresponding processing formula can be expressed as: in, This indicates the voltage fluctuation during the device's sampling time. Indicates the number of sampling points in the sliding window; Indicates the first The voltage value sampled next; Indicates the first The voltage value was sampled once.

[0058] Based on the device identifier, the device sampled voltage value data, and the voltage fluctuation during the device sampling time, the device features to be fused are generated, and the corresponding processing formula can be expressed as: in, Indicates the characteristics of the devices to be merged; Represents the device ID hash; This indicates the voltage fluctuation during the device's sampling time. This represents the sampled voltage value data from the device; This is a voltage check code used to detect bit errors in the transmission of voltage data.

[0059] For environmental features, the Bos-Choherry code is first used to convert the equipment substation code into a 15-bit error-correcting code to resist transmission errors. Then, geohashing is used to convert the equipment GPS coordinates into a 6-bit string. Finally, the environmental features to be fused are obtained, and the corresponding processing formula can be expressed as: in, Indicates the substation code of the equipment; This represents the hash fusion value of the equipment's substation code; For Bos-Joherry codes; Indicates the device's GPS coordinates; For geo-hash; Indicates the average longitude of the region; Indicates the standard deviation of longitude; Indicates the average latitude of the region; Indicates the standard deviation of latitude; Represents the real part of GPS longitude; Indicates real-time electromagnetic intensity; Indicates the base station reference field strength; Represents the normalization coefficients; final output This reflects the current intensity of electromagnetic interference; Indicates the environmental characteristics to be integrated; Represents a normalized vector of GPS coordinates; This represents the imaginary part of GPS latitude.

[0060] Finally, based on the first biometric feature to be fused, the device feature to be fused, and the environmental feature to be fused, a first local identifier for the target device is generated, which can be represented as: in, This is the first local identifier; Represents a key-based hash message authentication function; Indicates the first biological characteristic to be fused; Indicates the characteristics of the devices to be merged; Indicates the environmental characteristics to be integrated; This indicates the device sampling time data; This represents the key for the key-based hash message authentication function; Representation operators are used to concatenate multiple inputs sequentially into a binary stream of data.

[0061] By triple binding of primary biometrics, device characteristics, and environmental characteristics, and utilizing... The key dependency ensures that attackers cannot forge the first local identifier. .

[0062] The dynamic certificate generation module transmits the first local identifier to the cloud so that the cloud generates a dynamic certificate based on the first local identifier and transmits the dynamic certificate to the target device.

[0063] In a preferred embodiment, transmitting the first local identifier to the cloud so that the cloud can generate a dynamic certificate based on the first local identifier includes: encrypting the first local identifier to obtain an encrypted first local identifier; and transmitting the encrypted first local identifier to the cloud so that the cloud can parse the encrypted first local identifier and generate a dynamic certificate.

[0064] In a preferred embodiment, encrypting the first local identifier to obtain an encrypted first local identifier includes: The first local identifier is encrypted using an identifier-based asymmetric cryptographic algorithm to obtain an encrypted first local identifier.

[0065] Specifically, in this invention, the function used to encrypt the first local identifier is an identifier-based asymmetric cryptographic algorithm, namely SM9, and its encryption process can be expressed as follows: in, Indicates the first local identifier of encryption; It is an identifier-based asymmetric cryptographic algorithm; For cloud public keys; Indicates the first local identifier; Indicates the device's GPS coordinates; Indicates the level of operation permission.

[0066] The encrypted first local identifier obtained after encryption The data is transmitted to a cloud server, which then generates a dynamic certificate.

[0067] In a preferred embodiment, parsing the encrypted first local identifier and generating a dynamic certificate includes: Obtain a preset cloud key to parse the encrypted first local identifier, and obtain the first local identifier and the original encryption time of the encrypted first local identifier; obtain a first current time, and determine the encryption transmission delay based on the first current time and the original encryption time; when the encryption transmission delay is not greater than a first preset time threshold, generate a dynamic certificate based on the first local identifier.

[0068] Specifically, the cloud server obtains a preset cloud key to parse the encrypted first local identifier, obtaining the first local identifier and its original encryption time. Simultaneously, it obtains the cloud server's current time and determines the encryption transmission delay. A dynamic certificate is generated based on the first local identifier only if the encryption transmission delay is no greater than a first preset time threshold. If the encryption transmission delay exceeds the first preset time threshold, the verification is considered timed out, and a verification failure message is sent to the user to be verified. In this invention, the first preset time threshold is set to 5 seconds.

[0069] When generating a dynamic certificate, a dynamic risk coefficient is first generated. This generation process can be represented as follows: in, Indicates the dynamic risk coefficient. ; express Activation function Indicates proportional weight; This indicates the voltage fluctuation during the device's sampling time. Indicates the maximum allowable voltage of the system; Indicates real-time GPS coordinates. Indicates the coordinates of the device's registered address; This represents the Euclidean distance function.

[0070] Dynamic certificates are three-part structures, and their generation can be represented as follows: in, Indicates a dynamic certificate; This indicates 256-bit encryption; This indicates the key corresponding to the 256 encryption, using the key. Hide the target device's real ID; Indicates the first local identifier; This indicates the device sampling time data; It is a time function; This is a hash operation; Indicates the dynamic risk coefficient; It is a hash algorithm; Represents a random number; Indicates the level of operation permission; It is a time offset function based on the operation permission level; This is the serial number of the dynamic certificate.

[0071] The cloud server transmits the generated dynamic certificate to the target device so that the device can perform subsequent steps.

[0072] For the identification verification module, when the target device receives the dynamic certificate transmitted from the cloud, it performs a second biometric acquisition of the user's biometrics to obtain the user's third biometric. This third biometric is then matched against several preset second biometrics in the target device. If the second biometric match is successful, the dynamic certificate is received using the third biometric. If the second biometric match fails, the user is notified that the security verification has failed, and an alarm message is issued.

[0073] In a preferred embodiment, parsing the dynamic certificate and generating a second local identifier includes: Obtain the original encryption time and the second current time when receiving the dynamic certificate; determine the certificate verification delay based on the second current time and the original encryption time; when the certificate verification delay is not greater than a second preset time threshold, parse the dynamic certificate and generate a second local identifier.

[0074] Specifically, before parsing the dynamic certificate, a time validity verification is required. This involves obtaining the original encryption time and the target device's second current time when receiving the dynamic certificate. The certificate verification delay is then determined based on the second current time and the original encryption time. The dynamic certificate is only parsed if the certificate verification delay is no greater than a second preset time threshold. If the certificate verification delay exceeds the second preset time threshold, the user to be verified is notified that the security verification has failed, and an alarm message is issued.

[0075] When parsing a dynamic certificate, the reconstructed second local identifier is obtained by reconstructing the local identifier based on the dynamic certificate. The parsing process can be represented as follows: in, Indicates the second local identifier; Indicates the device key; The XOR operator; Indicates the characteristics of the devices to be merged; Indicates the third biological characteristic; Indicates the environmental characteristics to be integrated; Represents a key-based hash message authentication function; This represents the key for the key-based hash message authentication function; This indicates the sampling time data of the device.

[0076] The matching of the first local identifier and the second local identifier is verified by designing a verification function to verify whether the identifier issued by the cloud is consistent with the locally reconstructed identifier. The verification process can be represented as follows: in, This indicates the matching between the first local identifier and the second local identifier, and is used to verify whether the identifier distributed from the cloud is consistent with the identifier reconstructed locally; Indicating consistency of risk, due to and All numbers are random, making them impossible for attackers to forge. ; This represents the verification result of the verification function on the matching of the first local identifier and the second local identifier. Its value is a Boolean logic result: True if the first and second local identifiers match, and False if they do not match. When the consistency verification of the first and second local identifiers passes, control of the target device is granted to the user being verified.

[0077] It should be noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Furthermore, in the accompanying drawings of the device embodiments provided by this invention, the connection relationships between modules indicate that they have communication connections, which can be specifically implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement this without any creative effort.

[0078] Those skilled in the art will clearly understand that, for convenience and brevity, the specific working process of the device described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.

[0079] Based on the above method embodiments, the present invention provides corresponding terminal device embodiments.

[0080] One embodiment of the present invention provides a terminal device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements a multi-dimensional device security verification method as described in any one of the present invention.

[0081] The terminal device can be a desktop computer, laptop, handheld computer, or cloud server, etc. The terminal device may include, but is not limited to, a processor and a memory.

[0082] The processor can be a Central Processing Unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor or any conventional processor. The processor is the control center of the terminal device, connecting all parts of the terminal device via various interfaces and lines.

[0083] The memory can be used to store the computer program. The processor implements various functions of the terminal device by running or executing the computer program stored in the memory and calling data stored in the memory. The memory may mainly include a program storage area and a data storage area. The program storage area may store the operating system, at least one application program required for a function, etc.; the data storage area may store data created based on the use of the mobile phone, etc. In addition, the memory may include high-speed random access memory, and may also include non-volatile memory, such as hard disk, RAM, plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, at least one disk storage device, flash memory device, or other volatile solid-state storage device.

[0084] Based on the above method embodiments, the present invention provides corresponding storage medium embodiments.

[0085] One embodiment of the present invention provides a storage medium including a stored computer program, wherein, when the computer program is executed, it controls the device where the storage medium is located to execute a multi-dimensional device security verification method as described in any one of the present invention.

[0086] The storage medium is a computer-readable storage medium, and the computer program is stored in the computer-readable storage medium. When the computer program is executed by a processor, it can implement the steps of the various method embodiments described above. The computer program includes computer program code, which can be in the form of source code, object code, executable file, or some intermediate form. The computer-readable medium can include: any entity or device capable of carrying the computer program code, recording media, USB flash drive, portable hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc.

[0087] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications are also considered to be within the scope of protection of the present invention.

Claims

1. A multi-dimensional device security verification method, characterized in that, include: When the target device detects a user verification operation, the target device acquires the first biometric feature of the user to be verified and performs a biometric matching between the first biometric feature and several preset second biometric features in the target device. If a biometric match is successful, the target device acquires its own device features and environmental features, and performs multi-dimensional information fusion based on the first biometric feature, device features and environmental features to generate the first local identifier of the target device. The target device transmits the first local identifier to the cloud, so that the cloud generates a dynamic certificate based on the first local identifier and transmits the dynamic certificate to the target device; When the target device receives the dynamic certificate, the target device obtains the third biometric feature of the user to be verified, and performs a secondary biometric matching between the third biometric feature and several preset second biometric features in the target device. If the secondary biometric matching is successful, the target device parses the dynamic certificate and generates a second local identifier. The second local identifier is then matched with the first local identifier. If the identifier matching is successful, the target device grants the user to be verified control over the target device.

2. The multi-dimensional device security verification method as described in claim 1, characterized in that, The first biometric feature, the second biometric feature, and the third biometric feature all include one or a combination of fingerprints, facial features, irises, and voiceprints. The device features include: device identification and device voltage sampling data; wherein, the device voltage sampling data includes: device sampling time data and device sampling voltage value data; The environmental characteristics include: equipment substation code and equipment GPS coordinates.

3. The multi-dimensional device security verification method as described in claim 2, characterized in that, The step of fusing multi-dimensional information based on the first biometric feature, device feature, and environmental feature to generate a first local identifier for the target device includes: Obtain the device key of the target device, perform an XOR operation on the device key and the first biometric feature to obtain the first biometric feature to be encrypted, and encrypt the first biometric feature to be encrypted according to the hash function to obtain the first biometric feature to be fused. The voltage fluctuation during the sampling time is generated based on the equipment sampling time data and the equipment sampling voltage value data. The equipment features to be fused are generated based on the equipment identifier, the equipment sampling voltage value data, and the voltage fluctuation during the sampling time. The environmental features to be fused are generated based on the equipment's substation code and its GPS coordinates. A first local identifier for the target device is generated based on the first biometric feature to be fused, the device feature to be fused, and the environmental feature to be fused.

4. The multi-dimensional device security verification method as described in claim 3, characterized in that, The step of transmitting the first local identifier to the cloud, so that the cloud generates a dynamic certificate based on the first local identifier, includes: The first local identifier is encrypted to obtain an encrypted first local identifier; The encrypted first local identifier is transmitted to the cloud so that the cloud can parse the encrypted first local identifier and generate a dynamic certificate.

5. The multi-dimensional device security verification method as described in claim 4, characterized in that, The process of parsing the encrypted first local identifier and generating a dynamic certificate includes: Obtain the preset cloud key and parse the encrypted first local identifier to obtain the first local identifier and the original encryption time of the encrypted first local identifier; Obtain the first current time, and determine the encrypted transmission delay based on the first current time and the original encryption time; When the encrypted transmission delay is no greater than a first preset time threshold, a dynamic certificate is generated based on the first local identifier.

6. The multi-dimensional device security verification method as described in claim 5, characterized in that, The process of parsing the dynamic certificate and generating a second local identifier includes: Obtain the original encryption time and the second current time when receiving the dynamic certificate, and determine the certificate verification delay based on the second current time and the original encryption time; When the certificate verification delay is no greater than the second preset time threshold, the dynamic certificate is parsed and a second local identifier is generated.

7. The multi-dimensional device security verification method as described in claim 6, characterized in that, The step of encrypting the first local identifier to obtain an encrypted first local identifier includes: The first local identifier is encrypted using an identifier-based asymmetric cryptographic algorithm to obtain an encrypted first local identifier.

8. A multi-dimensional device security verification device, characterized in that, include: Multi-dimensional feature fusion module, dynamic certificate generation module, and identifier verification module; The multi-dimensional feature fusion module is used to obtain the first biometric feature of the user to be verified when the target device detects a user verification operation, and perform a biometric feature matching between the first biometric feature and a number of preset second biometric features in the target device; if the biometric feature matching is successful, the target device obtains its own device features and environmental features, and performs multi-dimensional information fusion based on the first biometric feature, device features and environmental features to generate the first local identifier of the target device. The dynamic certificate generation module is used by the target device to transmit the first local identifier to the cloud, so that the cloud generates a dynamic certificate based on the first local identifier and transmits the dynamic certificate to the target device. The identification verification module is used to, when the target device receives the dynamic certificate, obtain the third biometric feature of the user to be verified, and perform a secondary biometric matching between the third biometric feature and a number of preset second biometric features in the target device; if the secondary biometric matching is successful, the target device parses the dynamic certificate and generates a second local identifier, and performs an identifier matching between the second local identifier and the first local identifier; when the identifier matching is successful, the target device grants the user to be verified control over the target device.

9. A terminal device, characterized in that, The device includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor, when executing the computer program, implements a multi-dimensional device security verification method as described in any one of claims 1 to 7.

10. A storage medium, characterized in that, The storage medium includes a stored computer program, wherein, when the computer program is executed, it controls the device where the storage medium is located to perform a multi-dimensional device security verification method as described in any one of claims 1 to 7.