A network identity authentication credential management method and system of intelligent security hardware

By registering decentralized identity identifiers through blockchain and using global anomaly detection and dynamic trust scoring for intelligent agents, the security risks of centralized identity authentication in smart security hardware are resolved. This enables continuous and reliable monitoring and dynamic access control, thereby improving the reliability and security of network identity authentication.

CN122137530APending Publication Date: 2026-06-02SHENZHEN HOUSELAI TECH CO LTD

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
SHENZHEN HOUSELAI TECH CO LTD
Filing Date
2026-04-16
Publication Date
2026-06-02

AI Technical Summary

Technical Problem

The existing network identity authentication system for smart security hardware has security vulnerabilities due to its centralized model. It cannot effectively identify device hijacking and abnormal operations, resulting in insufficient reliability and security.

Method used

By using blockchain technology to register decentralized identity identifiers for smart security hardware and collecting multi-dimensional behavioral data in real time, trust scores are dynamically generated using global anomaly detection smart agents, and access control is carried out in conjunction with smart contracts.

Benefits of technology

It enables continuous and reliable monitoring of smart security hardware, identifies abnormal behavior, improves the reliability and security of network identity authentication, and prevents device hijacking and malicious operations.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122137530A_ABST
    Figure CN122137530A_ABST
Patent Text Reader

Abstract

This invention discloses a method and system for managing network identity authentication credentials for smart security hardware, relating to the field of Internet of Things (IoT) security technology. The method includes: registering a decentralized identity identifier for each smart security hardware device on a blockchain, and storing a public key credential associated with the decentralized identity identifier on the blockchain as an initial identity credential; real-time collection of behavioral data sequences generated by the smart security hardware during operation, inputting them into a pre-trained global anomaly recognition agent, and outputting a behavioral deviation score; dynamically generating a current trust score, uploading the current trust score and corresponding anomaly event information to the blockchain for evidence storage; and monitoring changes in the trust score based on a smart contract, automatically executing the corresponding access control policy when the current trust score falls below a preset trust threshold to adjust the communication permissions of the smart security hardware in the network. This invention effectively improves the reliability and security of network identity authentication for smart security hardware.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of Internet of Things (IoT) security technology, specifically to a method and system for managing network identity authentication credentials for smart security hardware. Background Technology

[0002] With the rapid development of IoT technology, smart security hardware has been widely used in many scenarios such as smart homes, smart cities, and the industrial internet, bringing convenience to production and life while also becoming a key carrier for network security protection. Existing network identity authentication systems for smart security hardware generally adopt a centralized model, where a certificate authority issues digital certificates to devices. Devices then rely on these certificates to establish a trusted connection with the cloud, completing identity verification before enabling network communication.

[0003] However, centralized identity authentication and credential management methods have many inherent flaws and are difficult to adapt to the security protection needs of smart security hardware. Current trust assessment technologies only occur at the moment of device connection; once a device is authenticated, it is assumed to be trusted throughout the entire process, making it impossible to detect subsequent security risks such as device hijacking and abnormal operations. This becomes a security vulnerability in smart security hardware network identity authentication, resulting in insufficient reliability and security. Summary of the Invention

[0004] This invention provides a method and system for managing network identity authentication credentials for smart security hardware, aiming to solve the technical problem of insufficient reliability and security of network identity authentication for smart security hardware in the prior art.

[0005] In view of the above problems, the present invention provides a method and system for managing network identity authentication credentials for smart security hardware.

[0006] In a first aspect, the present invention provides a method for managing network identity authentication credentials for smart security hardware, comprising: Register a decentralized identity identifier for each smart security hardware device on the blockchain, and associate the public key certificate of the smart security hardware device with the decentralized identity identifier and store it on the blockchain as the initial identity certificate of the smart security hardware device; The system collects behavioral data sequences generated by the intelligent security hardware during operation in real time, inputs the behavioral data sequences into a pre-trained global anomaly recognition agent, and outputs a behavioral deviation score of the intelligent security hardware. The current trust score of the smart security hardware is dynamically generated based on the behavior deviation score, and the current trust score and the corresponding abnormal event information are uploaded to the blockchain for evidence storage. Based on the smart contract deployed on the blockchain, the smart security hardware monitors changes in its trust score. When the current trust score is lower than a preset trust threshold, the smart contract automatically executes the corresponding access control policy to adjust the smart security hardware's communication permissions in the network.

[0007] Secondly, the present invention provides a network identity authentication credential management system for intelligent security hardware, comprising: The blockchain identity registration module is used to register a decentralized identity identifier for each smart security hardware on the blockchain, and associate the public key certificate of the smart security hardware with the decentralized identity identifier and store it on the blockchain as the initial identity certificate of the smart security hardware. The behavior anomaly recognition module is used to collect the behavior data sequence generated by the smart security hardware in real time during operation, input the behavior data sequence into the pre-trained global anomaly recognition agent, and output the behavior deviation score of the smart security hardware. The trust score notarization module is used to dynamically generate the current trust score of the smart security hardware based on the behavior deviation score, and upload the current trust score and the corresponding abnormal event information to the blockchain for notarization. The automatic contract management module is used to monitor changes in the trust score of the smart security hardware based on the smart contract deployed on the blockchain. When the current trust score is lower than a preset trust threshold, the smart contract automatically executes the corresponding access control policy to adjust the communication permissions of the smart security hardware in the network.

[0008] One or more technical solutions provided in this invention have at least the following technical effects or advantages: This invention provides a method and system for managing network identity authentication credentials for smart security hardware. Building upon existing technologies that use blockchain for device identity verification, it utilizes multimodal behavioral data for anomaly identification, aiming to identify compromised devices, hijacked devices, and malicious devices launching internal attacks that possess legitimate identity credentials but exhibit abnormal behavior. First, blockchain is used to establish decentralized and tamper-proof initial identity credentials for smart hardware, mitigating the security risks of centralized trust roots. Second, a pre-trained global anomaly identification agent analyzes device behavior data in real time, dynamically calculating behavioral deviation scores to proactively detect unknown threats. Furthermore, the dynamic trust scores are stored on the blockchain to ensure the transparency and traceability of trust data. Finally, smart contracts automatically execute access control policies based on real-time trust scores, achieving dynamic adaptive adjustment of permissions. This invention effectively improves the reliability and security of network identity authentication for smart security hardware. Attached Figure Description

[0009] Figure 1 A flowchart illustrating a method for managing network identity authentication credentials for smart security hardware, provided in an embodiment of the present invention; Figure 2 This is a schematic diagram of the structure of a network identity authentication credential management system for intelligent security hardware provided in an embodiment of the present invention; The components represented by each number in the attached diagram are explained below: Blockchain identity registration module 11, abnormal behavior identification module 12, trust scoring and evidence storage module 13, module 14, and automatic contract management module 15. Detailed Implementation

[0010] This invention provides a method and system for managing network identity authentication credentials for smart security hardware, which addresses the technical problem of insufficient reliability and security of network identity authentication for smart security hardware in the prior art.

[0011] Example 1, as Figure 1 As shown, the present invention provides a method for managing network identity authentication credentials for smart security hardware, the method comprising: S100: Register a decentralized identity identifier for each smart security hardware on the blockchain, and associate the public key certificate of the smart security hardware with the decentralized identity identifier and store it on the blockchain as the initial identity certificate of the smart security hardware.

[0012] In this embodiment of the invention, a decentralized identity identifier is registered on the blockchain for each smart security hardware device, and the public key certificate of the smart security hardware is associated with and stored on the blockchain as the decentralized identity identifier, serving as the initial identity credential of the smart security hardware. Traditional smart security hardware authentication relies on digital certificates issued by centralized certificate authorities. This not only carries the risk of authentication system paralysis due to attacks or malfunctions of the central server, but also creates identity silos due to different manufacturers relying on independent certification authorities, making cross-domain identity verification difficult. Furthermore, the initial identity credential of a device in a centralized model lacks a reliable, tamper-proof storage medium, making it susceptible to forgery and alteration of identity information. However, the prerequisite for network identity authentication of smart security hardware is that the device possesses a unique, reliable, and cross-domain verifiable initial identity. Therefore, this invention uses blockchain technology to register a decentralized identity identifier for each smart security hardware device and associates and stores the public key certificate with this identifier on the blockchain, constructing an initial identity credential system that does not rely on third parties and is tamper-proof, thus solving the inherent defects of centralized identity registration from the source.

[0013] Step S100 in the method provided in this embodiment of the invention includes: During the production phase or the initial power-on initialization phase of the smart security hardware, a unique device identifier and a pair of asymmetric keys are generated for each piece of smart security hardware. The private key from the asymmetric key pair is written into the secure storage area of ​​the smart security hardware, wherein the secure storage area has a physical anti-read protection mechanism; The public key in the asymmetric key pair and the device identifier are sent to the blockchain, and the identity registration smart contract deployed on the blockchain is invoked; The identity registration smart contract generates a decentralized identity identifier for the smart security hardware based on the device identifier, and records the public key and the decentralized identity identifier in the distributed ledger of the blockchain as a key-value pair, serving as the initial identity credential of the smart security hardware.

[0014] First, during the production or initial power-on initialization phase of the smart security hardware, a unique device identifier and an asymmetric key pair are generated for each piece of smart security hardware. The device identifier is a unique code assigned to the smart security hardware; it serves as the device's physical identity, distinguishing different smart security hardware terminals and ensuring non-repeatability. The asymmetric key pair is a complementary key pair generated based on an asymmetric encryption algorithm, containing a private key and a public key. The private key is unique to the device and must be strictly kept confidential, while the public key can be publicly transmitted. The two keys are paired to achieve data encryption, digital signatures, and signature verification. This invention can use mainstream asymmetric encryption algorithms such as RSA and SM2. During the production or initial power-on initialization phase of the smart security hardware, the manufacturer's device management system automatically generates a unique device identifier for each piece of smart security hardware and simultaneously calls the encryption algorithm to generate the corresponding asymmetric key pair. The generation process is completed in an offline secure environment to avoid key information leakage.

[0015] For example, using an industrial-grade 3D smart sensing camera as smart security hardware, during the camera's production process, the manufacturer's IoT device management system generates a unique device identifier Dev_3D_Sense_202602_001 for the camera in an offline security environment. At the same time, it generates a corresponding asymmetric key pair based on the SM2 national cryptographic algorithm, where the private key is SK_3D_Sense_001 and the public key is PK_3D_Sense_001.

[0016] Next, the private key from the asymmetric key pair is written into the secure storage area of ​​the smart security hardware. This secure storage area has a physical anti-read protection mechanism. The secure storage area refers to a dedicated storage module integrated within the smart security hardware with a physical anti-read protection mechanism. It can resist attacks such as physical disassembly, brute-force attacks, and unauthorized data reading. Common examples include security chips (SE), trusted platform modules (TPM), and embedded security units (eSE). This secure storage area only supports authorized operations within the device itself. Using a manufacturer-specific secure programming tool, the private key is written into the secure storage area of ​​the smart security hardware. Immediately after writing, access to this storage area is locked, and external physical access and unauthorized data reading channels are closed, ensuring that the private key can only be accessed by the device itself.

[0017] For example, the manufacturer uses a dedicated security programming tool for the SM2 algorithm to write the private key SK_3D_Sense_001 corresponding to the smart camera Dev_3D_Sense_202602_001 into the security chip SE-3D01 built into the camera. After programming, the tool locks the physical read access of SE-3D01, so even if the camera is physically disassembled, attackers cannot read the private key stored in the chip through hardware means.

[0018] Next, the public key from the asymmetric key pair and the device identifier are sent to the blockchain, and the identity registration smart contract deployed on the blockchain is invoked. The identity registration smart contract is a programmable automated contract pre-deployed on the blockchain, containing built-in rules for generating decentralized identity identifiers and the logic for associating device information with identity identifiers. It can automatically receive device identity registration requests and execute subsequent on-chain operations without manual intervention. The blockchain adopts an industrial IoT security consortium blockchain, possessing the characteristics of distributed ledger, data immutability, and traceability. It is used to uniformly store the identity information of smart security hardware. The consortium blockchain nodes consist of IoT manufacturers, security service providers, industry regulatory agencies, etc., ensuring data trustworthiness. The smart security hardware transmits the public key and device identifier to the blockchain network through an encrypted edge gateway. The transmission process uses TLS / SSL encryption protocols to ensure data security. After the data is on-chain, the identity registration smart contract deployed on the blockchain is automatically triggered and invoked, entering the decentralized identity identifier generation stage.

[0019] For example, the smart sensor camera Dev_3D_Sense_202602_001 sends its public key PK_3D_Sense_001 and device identifier Dev_3D_Sense_202602_001 to the Industrial Internet of Things Security Alliance Chain through the industrial production line edge gateway EG-Industrial. After the data is successfully uploaded to the chain, the identity registration smart contract Contract_DID_Reg_Industrial, which has been deployed on the chain, is automatically invoked.

[0020] Finally, the identity registration smart contract generates a decentralized identity identifier for the smart security hardware based on the device identifier, and records the public key and the decentralized identity identifier in the distributed ledger of the blockchain as a key-value pair, serving as the initial identity credential of the smart security hardware. A decentralized identity identifier (DID) is a unique identity identifier generated based on blockchain technology without centralized management, conforming to the W3C decentralized identity specification, not relying on third-party certificate authorities, and enabling cross-vendor and cross-platform identity verification. A distributed ledger is a unified ledger jointly maintained by all nodes in a consortium blockchain; once data is written, it is synchronously recorded by all nodes, possessing the characteristics of immutability and traceability. The initial identity credential is the first legitimate identity proof of the smart security hardware on the blockchain, composed of the decentralized identity identifier and the public key linked in a key-value pair, and serves as the basis for subsequent network identity authentication and data interaction signatures.

[0021] Specifically, the identity registration smart contract generates a unique decentralized identity for the smart security hardware based on the received device identifier and according to the preset W3CDID generation algorithm. Then, the decentralized identity and the device public key are written into the distributed ledger of the blockchain in the form of a key-value pair to complete the blockchain identity registration of the device. This key-value pair is the initial identity credential of the smart security hardware.

[0022] For example, the identity registration smart contract Contract_DID_Reg_Industrial generates a unique decentralized identity identifier DID:Industrial:3D_Sense_202602_001 for the smart camera based on the received device identifier Dev_3D_Sense_202602_001 and in accordance with the W3CDID IoT industry standard. Then, the DID and the public key PK_3D_Sense_001 are written into the distributed ledger of the city IoT security alliance chain in the form of key-value pair {DID:Industrial:3D_Sense_202602_001:PK_3D_Sense_001}. This key-value pair is the initial identity credential of the smart camera.

[0023] In this embodiment of the invention, decentralized identity registration of smart security hardware is achieved through blockchain, avoiding the risk of identity authentication system paralysis due to central server failure or attack. Device identifiers, public keys, and decentralized identity identifiers are associated and stored in the blockchain distributed ledger. Utilizing the immutability of the ledger, the uniqueness and credibility of the initial identity credential are guaranteed, effectively preventing the forgery or tampering of device identity information. The private key is written to a secure storage area with physical anti-read protection, achieving secure storage of the private key at the hardware level. This avoids identity credential misuse caused by the theft of the private key, building the first line of defense for device identity security. The generated decentralized identity identifier follows the cross-industry DID standard, breaking down identity silos between different manufacturers and platforms, realizing cross-domain and cross-platform identity verification of smart security hardware, and providing a reliable identity foundation for multi-manufacturer device collaboration. The initial identity credential, constructed in the form of key-value pairs, is synchronously recorded and traceable by all nodes of the blockchain, becoming a reliable basis for subsequent network identity authentication, data signature verification, and trust scoring generation of smart security hardware.

[0024] S200: Collect the behavior data sequence generated by the intelligent security hardware in real time during operation, input the behavior data sequence into the pre-trained global anomaly recognition agent, and output the behavior deviation score of the intelligent security hardware.

[0025] In this embodiment of the invention, behavioral data sequences generated by the intelligent security hardware during operation are collected in real time, and these sequences are input into a pre-trained global anomaly detection agent to output a behavioral deviation score for the intelligent security hardware. Traditional intelligent security hardware authentication is completed only at the moment of device connection; once authentication is successful, the device is assumed to be entirely trustworthy, making it impossible to detect abnormal behaviors during device operation, such as hijacking, unauthorized manipulation, or data leakage. This makes it difficult to detect internal threats and the risk of device compromise in a timely manner. However, intelligent security hardware generates a large amount of multi-dimensional behavioral data during operation, reflecting the device's true operating status. Therefore, it is necessary to collect behavioral data in real time and analyze it using a pre-trained global anomaly detection agent to output a behavioral deviation score. This provides an objective basis for subsequent dynamic trust assessment, achieving an upgrade from instantaneous authentication to continuous trust monitoring.

[0026] Step S200 in the method provided in this embodiment of the invention includes: The real-time acquisition of behavioral data sequences generated by the intelligent security hardware during operation includes: The embedded microcontroller unit embedded in the smart security hardware collects multi-dimensional behavioral data of the smart security hardware in real time at preset time intervals. The multi-dimensional behavioral data includes at least two of the following: network communication traffic characteristic data, central processing unit utilization data, memory utilization data, running process list data, data read and write frequency data, interaction record data with external devices, geographical location change data, and operation log data. The collected multidimensional behavioral data is timestamped and formatted to generate a sequence of behavioral data to be analyzed.

[0027] First, an embedded microcontroller unit (MCU) within the intelligent security hardware collects multi-dimensional behavioral data of the hardware in real time at preset time intervals. This multi-dimensional behavioral data includes at least two of the following: network communication traffic characteristics, CPU utilization, memory usage, running process list, data read / write frequency, interaction records with external devices, geographical location change data, and operation log data. The embedded microcontroller unit (MCU) is a dedicated computing unit embedded within the intelligent security hardware, characterized by low power consumption, high real-time performance, and strong stability. It can independently complete data acquisition, preprocessing, and local computing tasks without relying on external devices. Multi-dimensional behavioral data are multi-dimensional quantitative indicators reflecting the operating status of the intelligent security hardware, comprehensively characterizing the device's behavioral features.

[0028] Specifically, the embedded microcontroller unit inside the intelligent security hardware collects multi-dimensional behavioral data in real time at preset time intervals. The collection process is completed locally on the device to avoid the risk of privacy leakage during data transmission. The multi-dimensional quantitative indicators include network communication traffic characteristics, CPU utilization, memory utilization, running process list, data read and write frequency, external device interaction records, geographical location changes, operation logs, etc. The collected multi-dimensional behavioral data must cover at least two of the above-mentioned specified types to ensure the integrity of behavioral characteristics.

[0029] For example, taking the 3D intelligent sensing camera Dev_3D_Sense_202602_001 as an example, its internal embedded microcontroller unit collects the following multi-dimensional behavioral data in real time at a time interval of 1 second: Network communication traffic characteristic data: Uplink traffic 350KB / s (3D point cloud data transmission), downlink traffic 120KB / s (production line instruction reception), connection port 8883 (MQTT industrial communication protocol); CPU utilization data: average utilization 45% (3D point cloud modeling computing power consumption), peak utilization 68%; Memory utilization data: current utilization 75%, available memory 256MB; Running process list data: main process 3D_Sense_Main, point cloud encoding process PointCloud_Encoder, industrial communication process Industrial_MQTT, security monitoring process Sec_Industrial_Monitor.

[0030] Secondly, the collected multidimensional behavioral data is timestamped and formatted to generate a behavioral data sequence for analysis. Timestamping involves adding a precise time identifier, such as a Unix timestamp, to each piece of collected behavioral data to clarify the order in which the data was generated and ensure the temporal continuity of the behavioral sequence. Formatting involves converting behavioral data of different formats and dimensions into standardized data structures such as JSON or CSV to eliminate data format differences and facilitate subsequent model analysis. The behavioral data sequence is an ordered collection of timestamped multidimensional behavioral data arranged chronologically, serving as the input to the global anomaly detection agent. The collected multidimensional behavioral data is timestamped, adding a precise collection time to each piece of data; then, the data is converted according to a preset standardized format to eliminate format differences between different dimensions, ultimately generating a behavioral data sequence arranged chronologically.

[0031] For example, the embedded microcontroller unit of the 3D smart sensing camera Dev_3D_Sense_202602_001 processes the collected multi-dimensional behavioral data: it adds a millisecond-level timestamp to each data point, such as network traffic data corresponding to 2026-02-28 14:30:01.258 and CPU utilization data corresponding to 2026-02-28 14:30:02.312; it converts the data into JSON format, arranges all standardized data in chronological order, and generates a sequence of behavioral data to be analyzed.

[0032] Furthermore, a global anomaly detection agent is constructed.

[0033] The construction process of the global anomaly detection agent includes: Acquire multi-dimensional historical behavior data of multiple smart security hardware devices under historical operating conditions, and perform data cleaning and outlier removal on the multi-dimensional historical behavior data to obtain cleaned historical behavior data; The cleaned historical behavior data is manually labeled, and the data labeled as normal behavior is used as the positive sample set, and the data labeled as abnormal behavior is used as the negative sample set. A training dataset containing the positive sample set and the negative sample set is constructed. An initial deep neural network model is constructed, and the training dataset is input into the initial deep neural network model for iterative training. The model parameters are optimized through the backpropagation algorithm until the model converges, thus obtaining a pre-trained basic anomaly recognition agent. A federated learning architecture is adopted to distribute the pre-trained basic anomaly recognition agent to multiple edge computing nodes. Each edge computing node uses locally collected real-time behavior data sequences to perform incremental training and local parameter optimization on the received basic anomaly recognition agent, generating a personalized anomaly recognition agent deployed locally on each edge computing node. Each edge computing node encrypts and uploads the updated model parameters of the personalized anomaly detection agent to the central parameter server. The central parameter server performs federated averaging aggregation on the received multiple model parameters to generate an updated global anomaly detection agent. The updated global anomaly detection agent is redistributed to each of the edge computing nodes to replace the personalized anomaly detection agent local to each edge computing node.

[0034] First, multi-dimensional historical behavior data of multiple intelligent safety hardware devices under historical operating conditions is acquired. This data is then cleaned and outlier-removed to obtain cleaned historical behavior data. Historical behavior data refers to the collection of multi-dimensional behavior data generated by multiple intelligent safety hardware devices under historical operating conditions. This data is used to train a global anomaly recognition agent, reflecting the normal and abnormal behavior patterns of the equipment. It must include behavioral data of intelligent safety hardware from different production lines and operating conditions. Data cleaning involves operations such as deduplication, missing value imputation, and noise filtering to eliminate invalid information and interference items in the data. Outlier removal involves identifying and removing extreme values ​​that significantly deviate from the normal range in the historical behavior data to avoid misleading model training. Multi-dimensional historical behavior data of multiple intelligent safety hardware devices under historical operating conditions is acquired, and industrial-grade data cleaning tools are used to perform deduplication, missing value imputation, and noise filtering. Subsequently, statistical methods such as the 3σ principle and box plot analysis are used to identify and remove outliers, resulting in cleaned historical behavior data.

[0035] For example, historical behavioral data from 50 industrial-grade 3D smart sensor cameras of the same model were acquired over the past 60 days, covering different production line conditions such as automotive parts inspection and 3D modeling of electronic components, with a total data volume of 2.8TB. Duplicate timestamp data was removed, and linear interpolation was used to fill in missing 3D point cloud data read / write frequencies, filtering out instantaneous noise data caused by electromagnetic interference from the production line. The 3σ principle was used to identify extreme values ​​where CPU utilization exceeded 90%, and abnormal data where the 3D point cloud data read / write frequency suddenly dropped to 0. Finally, the cleaned historical behavioral data was obtained, for example, with a total data volume of 2.76TB.

[0036] Secondly, the cleaned historical behavior data is manually labeled. Data labeled as normal behavior is used as the positive sample set, and data labeled as abnormal behavior is used as the negative sample set. This forms the training dataset containing both the positive and negative sample sets. Manual labeling refers to industrial safety and 3D sensing technicians marking the cleaned historical behavior data to distinguish between normal and abnormal behaviors, such as equipment hijacking, unauthorized access to 3D production line data, and malicious occupation of computing power. The positive sample set, labeled as normal behavior, is used to train the model to learn the normal behavior patterns of the equipment. The negative sample set, labeled as abnormal behavior, is used to train the model to identify abnormal behavior features of the equipment. The training dataset, composed of both the positive and negative sample sets, forms the foundation for training the global anomaly detection agent.

[0037] Specifically, industrial safety and 3D sensing professionals manually labeled the historical behavior data after cleaning, marking data that conforms to the normal operation of the equipment as normal behavior and data with safety risk characteristics as abnormal behavior. Then, the labeled data were assigned to positive and negative sample sets respectively to construct a training dataset, with the ratio of positive to negative sample sets adjusted to 9.5:0.5 according to the requirements of industrial scenarios.

[0038] For example, 2.76TB of cleaned historical behavior data was manually labeled. The positive sample set contained 25.22 million normal behavior data, such as network traffic, CPU utilization, and process list of 3D smart sensing cameras in the 3D inspection state of automotive parts. The negative sample set contained 1.34 million abnormal behavior data, such as a camera whose CPU utilization consistently exceeded 85% from 10:20:00 to 10:40:00 on 2026-02-18, 3D point cloud data uplink traffic suddenly dropped to 50KB / s, and an unknown process Malware_Industrial_Steal was added. This was labeled as 3D production line data being illegally stolen. A training dataset was constructed, in which the positive sample set accounted for 95% and the negative sample set accounted for 5%.

[0039] Next, an initial deep neural network model is constructed. The training dataset is input into the initial deep neural network model for iterative training. The model parameters are optimized using the backpropagation algorithm until the model converges, resulting in a pre-trained basic anomaly recognition agent. The initial deep neural network model refers to the initial deep learning architecture used for anomaly recognition. For example, a hybrid network combining CNN and LSTM is used to learn the temporal features of behavioral data and related anomaly patterns in 3D point clouds for the behavioral characteristics of 3D sensing devices. Iterative training involves inputting the training dataset into the initial deep neural network model multiple times, calculating the prediction results through forward propagation, and then optimizing the model parameters through the backpropagation algorithm to gradually improve the model's anomaly recognition ability. Model convergence is defined as when the model's loss function value decreases to a preset threshold, such as the cross-entropy loss decreasing to 0.01 and no longer changing significantly. At this point, the model is considered to have converged, possessing stable anomaly recognition capabilities. The basic anomaly recognition agent refers to the initial anomaly recognition model obtained through iterative training, which can serve as the base model for subsequent federated learning.

[0040] Specifically, an initial CNN+LSTM hybrid deep neural network model is constructed, consisting of 2 CNN convolutional layers and 3 LSTM hidden layers, with 256 neurons in each layer and ReLU activation function. The training dataset is input into the model for iterative training, and the model parameters are optimized through backpropagation until the model converges. During the training process, a 5-fold cross-validation method adapted to industrial scenarios is used to evaluate the model performance to ensure the model's generalization ability.

[0041] For example, an initial CNN+LSTM hybrid deep neural network model is constructed, consisting of two CNN convolutional layers for extracting features from 3D sensing data; three LSTM hidden layers, each with 256 neurons; and one output layer with one neuron for outputting a behavior deviation score. The training dataset is input into the model, with a batch size of 128 and a learning rate of 0.001, and iterative training is performed for 120 epochs. After each epoch of training, the model's cross-entropy loss is calculated. For example, the model converges when the loss value drops to 0.007 and shows no significant change for eight consecutive epochs. This yields the pre-trained basic anomaly recognition agent.

[0042] Furthermore, a federated learning architecture is adopted to distribute the pre-trained basic anomaly detection agent to multiple edge computing nodes. Each edge computing node uses locally collected real-time behavioral data sequences to incrementally train and optimize the received basic anomaly detection agent, generating a personalized anomaly detection agent deployed locally on each edge computing node. The federated learning architecture is a distributed machine learning framework where model training is completed locally on multiple edge computing nodes, uploading only model parameters rather than raw data, effectively protecting the data privacy of industrial production lines. Edge computing nodes refer to local computing nodes deployed near industrial production lines. Incremental training refers to secondary training of the model based on the basic anomaly detection agent using locally collected real-time behavioral data sequences. The personalized anomaly detection agent refers to the anomaly detection model obtained through incremental training and local parameter optimization, which can accurately detect abnormal behavior of local devices.

[0043] Specifically, a federated learning architecture is adopted to distribute pre-trained basic anomaly recognition agents to multiple industrial production line edge computing nodes. Each edge computing node uses locally collected real-time behavioral data sequences to incrementally train the received basic anomaly recognition agents, optimize and adjust model parameters through local parameters, and generate personalized anomaly recognition agents deployed locally on each edge computing node.

[0044] For example, the basic anomaly recognition agent is distributed to eight industrial production line edge computing nodes in the company's industrial IoT security alliance chain; among them, the automotive parts inspection production line edge server EG-Industrial uses locally collected behavioral data sequences of Dev_3D_Sense_202602_001 to incrementally train the basic model, setting the learning rate to 0.0005 and iterating for 30 rounds; the model parameters are adjusted through the Adam optimizer to make the model more suitable for the device behavior characteristics of the automotive parts 3D inspection scenario; and a personalized anomaly recognition agent is generated.

[0045] Furthermore, each edge computing node encrypts and uploads the updated model parameters of the personalized anomaly detection agent to the central parameter server. The central parameter server performs federated averaging aggregation on the received model parameters to generate an updated global anomaly detection agent. The central parameter server is the core node in the federated learning architecture, deployed in the company's industrial IoT security management center, and is responsible for receiving the model parameters uploaded by each edge computing node and aggregating and updating them. Federated averaging aggregation is a federated learning parameter aggregation method that weights the model parameters uploaded by each edge computing node according to the amount of data at each node to generate globally updated model parameters, effectively integrating the personalized knowledge of each production line node. The updated global anomaly detection agent refers to the global model obtained through federated averaging aggregation, which integrates the personalized knowledge of each industrial production line edge node and has a more accurate and robust intelligent security hardware anomaly detection capability.

[0046] Specifically, each edge computing node uploads the updated model parameters of the personalized anomaly detection agent to the central parameter server via an industrial-grade encryption protocol; the central parameter server performs federated averaging and aggregation of the received multiple model parameters to generate updated global model parameters, thereby obtaining the updated global anomaly detection agent.

[0047] For example, eight industrial production line edge computing nodes upload their respective personalized anomaly recognition agent parameters to the central parameter server of the industrial IoT security management center via SM4 homomorphic encryption; the central parameter server performs a weighted average of the model parameters based on the amount of local 3D production line data of each node, aggregates the global model parameters, and generates an updated global anomaly recognition agent.

[0048] Finally, the updated global anomaly detection agent is redistributed to each of the edge computing nodes to replace the local personalized anomaly detection agents on each edge computing node. Distributing the updated global anomaly detection agent to each industrial production line edge computing node replaces the original local personalized anomaly detection agent, ensuring that the models on each node are synchronously updated to the globally optimal state, adapting to dynamic adjustment requirements. After receiving and verifying the integrity of the model parameters, each edge computing node replaces its original local personalized anomaly detection agent, completing the model update.

[0049] For example, the central parameter server distributes the updated global anomaly recognition agent to eight industrial production line edge computing nodes; the automotive parts inspection production line edge server EG-Industrial receives the updated global anomaly recognition agent and verifies through SM3 hash verification that the model parameters have not been tampered with; it replaces the original local personalized anomaly recognition agent, completes the model update, and synchronizes the local model to the global optimal state, adapting to the real-time monitoring needs of the automotive parts 3D inspection production line.

[0050] Based on this, the behavioral data sequence is input into a pre-trained global anomaly detection agent, which outputs a behavioral deviation score for the intelligent security hardware. The global anomaly detection agent is a global anomaly detection model that integrates personalized knowledge from edge nodes of various industrial production lines. It can accurately analyze the behavioral data sequence of the intelligent security hardware and output a behavioral deviation score. The behavioral deviation score is a quantitative indicator reflecting the degree of deviation between the current behavior of the intelligent security hardware and the normal industrial production line behavior pattern. A higher score indicates a higher degree of behavioral anomaly, providing an objective basis for subsequent trust assessment. The behavioral deviation score ranges from 0 to 1, with a score ≥ 0.8 indicating a high-risk anomaly. The behavioral data sequence is input into the pre-trained global anomaly detection agent, and the model calculates the degree of deviation between the current behavior and the normal behavior pattern through forward propagation, outputting a behavioral deviation score. The score ranges from 0 to 1, with a score closer to 1 indicating a higher degree of anomaly.

[0051] For example, the behavior data sequence of the 3D smart sensor camera Dev_3D_Sense_202602_001 from 14:30:00 to 14:35:00 on 2026-02-25 is input into the updated global anomaly detection agent; the global anomaly detection agent analyzes and outputs a behavior deviation score of 0.7, indicating that the current behavior of the 3D smart sensor camera deviates significantly from the normal mode of the automotive parts inspection production line, posing a high security risk of 3D inspection data theft.

[0052] In this embodiment of the invention, multi-dimensional behavioral data collection and standardized processing comprehensively characterize the behavioral features of intelligent security hardware, providing input information tailored to industrial scenarios for anomaly identification and improving the accuracy and targeting of anomaly detection. A federated learning architecture is used to train a global anomaly identification agent, integrating personalized knowledge from edge nodes of each production line while protecting the privacy of core data in the industrial production line. This allows the model to adapt to the behavioral features of intelligent security hardware in different industrial scenarios, improving the robustness of anomaly identification. The output behavioral deviation score objectively reflects the degree of anomaly in the behavior of the intelligent security hardware, providing a reliable basis for subsequent dynamic trust score generation, and realizing the transformation from industrial behavioral data to production line risk quantification.

[0053] S300: Dynamically generate the current trust score of the smart security hardware based on the behavior deviation score, and upload the current trust score and the corresponding abnormal event information to the blockchain for evidence storage.

[0054] In this embodiment of the invention, a current trust score for the smart security hardware is dynamically generated based on the behavioral deviation score, and the current trust score and corresponding abnormal event information are uploaded to the blockchain for evidence storage. The trust status of smart security hardware is influenced by multiple dimensions, including the degree of behavioral abnormality, the reliability of model predictions, the hardware's physical security level, and historical performance. Traditional static trust scores or single-dimensional abnormality scores cannot accurately and comprehensively reflect the true trust status of the device. Furthermore, if trust scores and abnormal event information are stored in a centralized manner, they are susceptible to tampering and forgery, failing to meet the actual needs of security auditing and accountability. Therefore, this invention corrects behavioral deviation scores through multi-dimensional factors, dynamically generates a trust score that matches the actual state of the device, and uploads the score and abnormal event information to the blockchain for evidence storage. This ensures both the accuracy and dynamism of the trust score and, relying on the immutability and distributed storage characteristics of the blockchain, achieves reliable data storage and traceability, providing a reliable basis for subsequent access control.

[0055] Step S300 in the method provided in this embodiment of the invention includes: The behavior deviation score output by the global anomaly recognition agent for the behavior data sequence is obtained, and the behavior deviation score is normalized to obtain a standardized deviation score in the range of 0 to 1. The closer the standardized deviation score is to 1, the higher the degree of behavior abnormality. Obtain the model confidence score of the global anomaly detection agent for the current output result; The corrected effective deviation score is calculated based on the standardized deviation score and the model confidence score. The current trust score of the smart security hardware is calculated based on the corrected effective deviation score and the preset initial trust base value, wherein the current trust score is negatively correlated with the corrected effective deviation score. When the behavior deviation score exceeds the preset abnormal behavior judgment threshold, corresponding abnormal event information is generated, wherein the abnormal event information includes at least the abnormal occurrence timestamp, the abnormal type code, the standardized deviation score, and the list of affected resources; The current trust score and the abnormal event information are encapsulated according to a preset data structure, and a digital signature is generated on the encapsulated data using the private key of the smart security hardware, thereby constructing on-chain transaction data containing the current trust score, the abnormal event information, and the digital signature; The on-chain transaction data is broadcast to the blockchain network, where consensus nodes verify the digital signature. Once verified, the current trust score and corresponding abnormal event information are written into a new block and stored in the distributed ledger of the blockchain.

[0056] First, the behavior deviation score output by the global anomaly detection agent for the behavior data sequence is obtained, and the behavior deviation score is normalized to obtain a standardized deviation score in the range of 0 to 1. The closer the standardized deviation score is to 1, the higher the degree of behavior anomaly. Normalization refers to a standardized data processing method that maps the behavior deviation score output by the global anomaly detection agent to the 0-1 range, eliminating differences in the dimensions of the scores and ensuring the uniformity and comparability of the scores. The standardized deviation score refers to the deviation score in the 0-1 range after normalization. The closer the score is to 1, the higher the degree of behavior anomaly of the smart security hardware, which is the core foundational data for subsequent trust score calculation. The min-max normalization algorithm is used to map the original behavior deviation score output by the global anomaly detection agent for the smart security hardware to the 0-1 range. The calculation formula is: Standardized Deviation Score = (Original Deviation Score - Minimum Score) / (Maximum Score - Minimum Score), where the minimum and maximum scores are pre-set based on the historical behavior deviation score distribution of similar smart security hardware.

[0057] For example, the global anomaly detection agent outputs a raw behavior deviation score of 0.92 for the 3D smart sensor camera Dev_3D_Sense_202602_001. Based on the historical score distribution of similar smart security hardware, the preset minimum score is 0 and the maximum score is 1. Normalization calculation: Standardized deviation score = (0.7-0) / (1-0) = 0.7. Finally, the standardized deviation score of the 3D smart sensor camera is 0.7, indicating that its behavior is highly abnormal.

[0058] Next, obtain the model confidence score of the global anomaly recognition agent for the current output result.

[0059] The process of obtaining the model confidence score of the global anomaly detection agent for the current output result includes: Acquire multiple personalized anomaly detection agents deployed across multiple edge computing nodes; The same behavioral data sequence is input into the multiple personalized anomaly recognition agents, and each of the personalized anomaly recognition agents makes predictions independently, outputting multiple behavioral deviation prediction values. Calculate the variance of the predicted values ​​of the multiple behavioral deviations, and determine the normalized reciprocal of the variance as the model confidence score, wherein the model confidence score is negatively correlated with the variance.

[0060] First, multiple personalized anomaly detection agents deployed across various edge computing nodes are acquired. These personalized anomaly detection agents are anomaly detection models deployed on different edge computing nodes, incrementally trained locally, and adapted to the behavioral characteristics of smart security hardware within their respective node regions, possessing personalized anomaly detection capabilities for local devices. Multiple personalized anomaly detection agents deployed in different regions and application scenarios are retrieved from the edge computing node cluster corresponding to the blockchain network. This retrieval process is completed through encrypted communication between nodes, ensuring the security of model transmission.

[0061] For example, eight personalized anomaly recognition agents, named Agent_01 to Agent_08, are retrieved from edge computing nodes of eight different application scenarios to perform multi-model prediction verification on the 3D intelligent sensing camera Dev_3D_Sense_202602_001.

[0062] Secondly, the same behavioral data sequence is input into multiple personalized anomaly detection agents, each of which independently performs predictions and outputs multiple behavioral deviation prediction values. Multi-model independent prediction means that the behavioral data sequence of the same smart security hardware is input into multiple personalized anomaly detection agents, and each agent independently completes anomaly judgment and scoring based on its own trained behavioral features, avoiding the prediction bias of a single model. The behavioral deviation prediction value refers to the anomaly deviation score output by each personalized anomaly detection agent for the same behavioral data sequence, reflecting the independent judgment results of different models on the degree of anomaly of the same smart security hardware behavior. The same behavioral data sequence of the target smart security hardware is input into multiple personalized anomaly detection agents, and each agent independently executes feature extraction and anomaly analysis processes, outputting the corresponding behavioral deviation prediction value.

[0063] For example, the behavioral data sequence of the 3D smart sensing camera Dev_3D_Sense_202602_001 from 14:30:00 to 14:35:00 on 2026-02-25 was input into eight personalized anomaly recognition agents. The behavioral deviation prediction values ​​output by each agent were 0.75, 0.72, 0.78, 0.74, 0.76, 0.71, 0.77, and 0.73, respectively.

[0064] Furthermore, the variance of the multiple behavioral deviation prediction values ​​is calculated, and the normalized reciprocal of the variance is determined as the model confidence score. The model confidence score is negatively correlated with the variance. Variance is a statistical indicator that measures the dispersion of multiple behavioral deviation prediction values. The smaller the variance, the more consistent the prediction results of each personalized anomaly recognition agent, and the higher the overall prediction reliability of the model. The normalized reciprocal refers to the numerical processing method that maps the variance value to the 0-1 interval. The calculation formula is: Normalized reciprocal = 1 / (1 + Variance), ensuring that the result is within the standard interval for easy subsequent calculation. The model confidence score is a score determined based on the normalized reciprocal of the variance and is negatively correlated with the variance. The closer the score is to 1, the higher the consistency of the prediction results of multiple models, and the stronger the prediction confidence. First, the arithmetic mean of the multiple behavioral deviation prediction values ​​is calculated, and then the variance of the data set is calculated based on the mean; subsequently, the normalized reciprocal of the variance is calculated and determined as the model confidence score.

[0065] For example, for the eight predicted deviation values ​​of behavior: 0.60, 0.65, 0.70, 0.70, 0.75, 0.75, 0.80, and 0.85, the arithmetic mean is (0.60 + 0.65 + 0.70 + 0.70 + 0.75 + 0.75 + 0.80 + 0.85) / 8 = 0.725. The variance is calculated by averaging the sum of the squares of the differences between each value and the mean, resulting in a variance ≈ 0.0056. The normalized reciprocal is 1 / (1 + 0.0056) ≈ 0.994, which means the model confidence score is 0.994, indicating that the prediction results of the multiple models are highly consistent and have extremely high confidence.

[0066] Next, the corrected effective deviation score is calculated based on the standardized deviation score and the model confidence score.

[0067] The corrected effective deviation score is calculated based on the standardized deviation score and the model confidence score, including: The security level coefficient of the smart security hardware in the secure storage area is obtained. The security level coefficient is preset according to the strength of the physical anti-read protection mechanism of the secure storage area. The security level coefficient is a real number greater than or equal to 1. The higher the strength of the physical anti-read protection mechanism of the secure storage area, the larger the security level coefficient. Read the historical trust score sequence of the smart security hardware over the past N time periods from the distributed ledger of the blockchain, and calculate the arithmetic average of the historical trust score sequence to obtain a historical performance benchmark value with a value range between 0 and 1. Calculate the difference between 1 and the model confidence score to obtain the model uncertainty factor, and multiply the model uncertainty factor by the standardized deviation score to obtain the deviation score after the first correction; Calculate the ratio of 1 to the security level coefficient to obtain the hardware security attenuation factor. Multiply the deviation score after the first correction by the hardware security attenuation factor to obtain the deviation score after the second correction. Calculate the difference between 1 and the historical performance benchmark value to obtain the historical trust buffer factor. Multiply the deviation score after the second correction by the historical trust buffer factor to obtain the corrected effective deviation score.

[0068] First, the security level coefficient of the smart security hardware in the secure storage area is obtained. This security level coefficient is pre-set based on the strength of the physical anti-read protection mechanism of the secure storage area. The security level coefficient is a real number greater than or equal to 1, and the higher the strength of the physical anti-read protection mechanism, the larger the security level coefficient. The security level coefficient is a pre-set coefficient based on the strength of the physical anti-read protection mechanism of the secure storage area within the smart security hardware, and is a real number greater than or equal to 1. A higher strength of the physical anti-read protection mechanism reflects a stronger physical security protection capability of the hardware itself. The secure storage area refers to a dedicated storage module integrated within the smart security hardware, possessing protection mechanisms such as physical anti-tampering, anti-brute-force attacks, and illegal data reading, used to store security information such as the device's private key. The pre-set security level coefficient is read from the target smart security hardware's local hardware configuration information through a dedicated security interface. The entire reading process is completed locally on the device to ensure the coefficient is not tampered with.

[0069] For example, the 3D smart sensing camera Dev_3D_Sense_202602_001 has a built-in security chip with enhanced protection level. The pre-set security level coefficient is 1.1. This coefficient is read directly through the device's local security interface and used as a parameter for subsequent deviation score correction.

[0070] Secondly, the historical trust score sequence of the smart security hardware over the past N time periods is retrieved from the distributed ledger of the blockchain. An arithmetic average of these historical trust score sequences is calculated to obtain a historical performance benchmark value ranging from 0 to 1. The historical trust score sequence refers to the set of trust scores generated by the target smart security hardware over the past N time periods, stored in the distributed ledger of the blockchain, possessing the characteristics of immutability and traceability. The value of N is pre-set according to the application scenario of the smart security hardware. The historical performance benchmark value is the score obtained by calculating the arithmetic average of the historical trust score sequence, ranging from 0 to 1. The closer the score is to 1, the more reliable the historical operating status of the smart security hardware, serving as a buffer for subsequent deviation score correction. The historical trust score sequence of the target smart security hardware over the past N time periods is retrieved from the distributed ledger of the blockchain; the arithmetic average of all scores in this sequence is calculated to obtain the historical performance benchmark value.

[0071] For example, with a time period of 1 hour and N=20, the historical trust score sequence of the 3D smart sensor camera Dev_3D_Sense_202602_001 over the past 20 hours is read from the blockchain distributed ledger, and the total score is 17. The arithmetic mean is calculated as follows: historical performance benchmark value = 17 / 20 = 0.85, indicating that the overall historical operating status is trustworthy.

[0072] Then, the difference between 1 and the model confidence score is calculated to obtain the model uncertainty factor. This model uncertainty factor is then multiplied by the standardized deviation score to obtain the first-corrected deviation score. The model uncertainty factor, obtained by subtracting 1 from the model confidence score, reflects the degree of uncertainty in the multi-model prediction results. A smaller factor value indicates lower model prediction uncertainty, and vice versa. The first-corrected deviation score is obtained by multiplying the standardized deviation score by the model uncertainty factor, and is used to correct the deviation score bias caused by model prediction uncertainty. First, the model uncertainty factor is calculated using the formula: Model uncertainty factor = 1 - Model confidence score; then, the first-corrected deviation score is calculated using the formula: First-corrected deviation score = Standardized deviation score × Model uncertainty factor. For example, the model uncertainty factor = 1 - 0.994 = 0.006; the first-corrected deviation score = 0.7 × 0.006 = 0.0042.

[0073] Then, the ratio of 1 to the security level coefficient is calculated to obtain the hardware security attenuation factor. The deviation score after the first correction is multiplied by the hardware security attenuation factor to obtain the deviation score after the second correction. The hardware security attenuation factor is obtained by dividing 1 by the security level coefficient, reflecting the attenuation effect of the physical protection capability of the intelligent security hardware on the deviation of abnormal behavior; the larger the security level coefficient, the smaller the attenuation factor, and the greater the correction range of the abnormal deviation score. The deviation score after the second correction is the score obtained by multiplying the deviation score after the first correction by the hardware security attenuation factor, and is used to correct the deviation score deviation caused by the difference in hardware physical protection capability. First, the hardware security attenuation factor is calculated according to the formula: Hardware security attenuation factor = 1 / security level coefficient; then, the deviation score after the second correction is completed according to the formula: Deviation score after the second correction = Deviation score after the first correction × Hardware security attenuation factor. For example, the hardware security attenuation factor = 1 / 1.2 ≈ 0.833; the deviation score after the second correction = 0.0042 × 0.833 ≈ 0.0035.

[0074] Finally, the difference between 1 and the historical performance benchmark is calculated to obtain the historical trust buffer factor. The deviation score after the second correction is multiplied by the historical trust buffer factor to obtain the corrected effective deviation score. The historical trust buffer factor, obtained by subtracting 1 from the historical performance benchmark, reflects the buffering effect of the historical trust performance of the intelligent security hardware on the current abnormal deviation. The closer the historical performance benchmark is to 1, the smaller the buffer factor, and the greater the correction magnitude for the abnormal deviation score. The corrected effective deviation score is the score obtained by multiplying the deviation score after the second correction by the historical trust buffer factor. It is the final deviation score after correction based on the three dimensions of model, hardware, and history, providing the core basis for trust score calculation. First, the historical trust buffer factor is calculated according to the formula: Historical Trust Buffer Factor = 1 - Historical Performance Benchmark Value; then, the final score correction is completed according to the formula: Corrected Effective Deviation Score = Deviation Score After Second Correction × Historical Trust Buffer Factor. For example, the historical trust buffer factor = 1 - 0.85 = 0.15; the corrected effective deviation score = 0.0035 × 0.15 = 0.000525.

[0075] Based on this, the current trust score of the smart security hardware is calculated according to the corrected effective deviation score and the preset initial trust base value. The current trust score is negatively correlated with the corrected effective deviation score. The preset initial trust base value refers to the basic trust score preset for the smart security hardware, with a value of 1.0, representing the highest trust status when the smart security hardware has no abnormal behavior. The current trust score is the score calculated based on the corrected effective deviation score and the preset initial trust base value, and is negatively correlated with the corrected effective deviation score, ranging from 0 to 1. The closer the score is to 1, the higher the current trust level of the smart security hardware. The current trust score of the target smart security hardware is calculated according to the formula: Current Trust Score = Preset Initial Trust Base Value - Corrected Effective Deviation Score. If the calculation result exceeds the 0-1 range, it is truncated; that is, a result less than 0 is taken as 0, and a result greater than 1 is taken as 1. For example, the initial trust base value is preset to 1.0; the current trust score = 1.0 - 0.000525 ≈ 0.9995; the final current trust score of the device is approximately 0.9995, indicating that although the device has detected slight abnormal features, after multi-dimensional factor correction, the overall trust level is still at a very high level.

[0076] Then, when the behavior deviation score exceeds a preset abnormal behavior judgment threshold, corresponding abnormal event information is generated. This abnormal event information includes at least an anomaly occurrence timestamp, anomaly type code, the standardized deviation score, and a list of affected resources. The preset abnormal behavior judgment threshold is a critical value set for judging abnormal behavior in smart security hardware. When the standardized deviation score exceeds this threshold, the device is judged to have abnormal behavior, and the abnormal event information generation process is triggered. Abnormal event information is a data set recording key information about abnormal behavior of smart security hardware, including at least an anomaly occurrence timestamp, anomaly type code, standardized deviation score, and a list of affected resources. The system determines whether the standardized deviation score of the target smart security hardware exceeds the preset abnormal behavior judgment threshold. If it does, abnormal-related information is automatically extracted and organized according to a preset data structure to generate abnormal event information; if it does not exceed the threshold, only the current trust score is recorded, and no abnormal event information is generated.

[0077] For example, the preset threshold for judging abnormal behavior is 0.6. The standardized deviation score of the 3D smart sensing camera Dev_3D_Sense_202602_001 is 0.7, which exceeds the threshold. This triggers the generation of abnormal event information: abnormal occurrence timestamp: 2026-02-25T14:32:15Z; abnormal type code: 003 (minor computing power fluctuation); standardized deviation score: 0.7; list of affected resources: 3D point cloud modeling computing power, minor occupation of industrial communication bandwidth; based on the above information, complete abnormal event information is generated and synchronized to the blockchain for storage.

[0078] Furthermore, the current trust score and the abnormal event information are encapsulated according to a preset data structure, and a digital signature is generated on the encapsulated data using the private key of the smart security hardware, constructing on-chain transaction data containing the current trust score, the abnormal event information, and the digital signature. The preset data structure refers to a standardized data structure adapted to the blockchain network, used to uniformly encapsulate the current trust score and abnormal event information, ensuring the consistency of the on-chain data format. The digital signature is a signature generated using the private key of the smart security hardware to perform asymmetric encryption on the encapsulated data, used to verify the integrity, authenticity, and ownership of the on-chain data. The on-chain transaction data is a data set composed of the encapsulated score and abnormal information, and the digital signature; it is the core data unit submitted to the blockchain network for notarization.

[0079] Specifically, the current trust score of the target smart security hardware and the generated abnormal event information are encapsulated according to a preset data structure; the private key in the device's secure storage area is called to encrypt the encapsulated data and generate a digital signature; the encapsulated data and the digital signature are combined to construct complete on-chain transaction data.

[0080] For example, the relevant data of the 3D smart sensing camera Dev_3D_Sense_202602_001 is processed, the data is encapsulated in JSON format, the encapsulated data is encrypted using the device private key SK_3D_Sense_001, and a digital signature is generated: Sign_3D_Sense_001_20260225_003; the encapsulated data and the digital signature are combined to construct complete on-chain transaction data.

[0081] Finally, the on-chain transaction data is broadcast to the blockchain network, where consensus nodes verify the digital signature. Upon successful verification, the current trust score and corresponding anomaly information are written into a new block and stored in the blockchain's distributed ledger. Blockchain network broadcasting refers to sending the completed on-chain transaction data to all consensus nodes in the blockchain network, achieving synchronous data transmission between nodes. Consensus node verification refers to the consensus nodes in the blockchain network using the public key of the target smart security hardware to verify the digital signature, confirming that the on-chain data has not been tampered with and that the data ownership is legitimate. Distributed ledger storage refers to writing the on-chain transaction data into a newly generated block on the blockchain after successful verification and synchronizing it to all nodes in the blockchain network, storing it in the distributed ledger, and completing permanent storage.

[0082] Specifically, the constructed on-chain transaction data is broadcast to all consensus nodes of the blockchain network; each consensus node uses the public key of the target smart security hardware to verify the digital signature. After the verification is successful, a new block is generated through the blockchain consensus algorithm; the current trust score and abnormal event information are written into the new block and synchronized to the distributed ledger of all nodes to complete the notarization.

[0083] For example, the on-chain transaction data of the 3D smart sensing camera Dev_3D_Sense_202602_001 is processed for notarization: the on-chain transaction data is broadcast to 10 consensus nodes of the blockchain network; each node uses the device public key PK_3D_Sense_001 to verify the digital signature Sign_3D_Sense_001_20260225_003 to confirm that the data is complete, legally owned, and has not been tampered with; a new block is generated through a practical Byzantine fault-tolerant consensus algorithm, and the current trust score of the device (0.9995) and abnormal event information are accurately written into the block and synchronized to the distributed ledger of all nodes of the blockchain to complete permanent notarization. The data is traceable and tamper-proof throughout the process.

[0084] In this embodiment of the invention, relying on the immutability and distributed storage characteristics of blockchain, a trusted record of the entire lifecycle of trust scores and abnormal event information for smart security hardware is achieved. This avoids the risks of data tampering and loss caused by centralized storage, and meets the needs of security auditing, behavior tracing, and responsibility definition in industrial scenarios. A standardized abnormal event information recording system is established, clarifying dimensions such as abnormal time, type, deviation degree, and affected resources, enabling precise tracing of abnormal behavior. This facilitates maintenance personnel to quickly locate problems and take targeted measures, improving the maintenance efficiency of smart security hardware. The entire trust score calculation process is completed locally on the edge node, with only the final trust score and abnormal event information uploaded to the blockchain. This reduces the data transmission volume and node computing load of the blockchain network, balancing the real-time performance of score calculation with the security of blockchain record storage.

[0085] S400: Based on the smart contract deployed on the blockchain, the smart security hardware monitors changes in its trust score. When the current trust score is lower than a preset trust threshold, the smart contract automatically executes the corresponding access control policy to adjust the smart security hardware's communication permissions in the network.

[0086] In this embodiment of the invention, based on a smart contract deployed on the blockchain, changes in the trust score of the smart security hardware are monitored. When the current trust score is lower than a preset trust threshold, the smart contract automatically executes the corresponding access control policy to adjust the communication permissions of the smart security hardware in the network. By deploying a lightweight trust management smart contract on the blockchain, real-time monitoring of the trust score of the smart security hardware and dynamic calculation of personalized preset trust thresholds are achieved. Based on the comparison between the score and the threshold, the network controller is automatically triggered to execute the corresponding communication permission adjustment, completing the blockchain-based intelligent linkage of trust scoring and permission control, and realizing decentralized dynamic management and control of device network access.

[0087] Step S400 in the method provided in this embodiment of the invention includes: A trust management smart contract is deployed on the blockchain, wherein the trust management smart contract predefines a list of smart security hardware addresses that need to be monitored and the triggering rules for trust score update events; The trust management smart contract continuously monitors all transaction inputs and outputs on the blockchain. When it detects that the transaction data contains a trust score update record that matches the address list of the smart security hardware, it reads the current trust score of the smart security hardware from the distributed ledger of the blockchain. The trust management smart contract compares the current trust score with a preset trust threshold. When the current trust score is lower than the preset trust threshold, the trust management smart contract matches and determines the target access control action corresponding to the value range based on the numerical range of the current trust score. The trust management smart contract generates an instruction data packet containing the target access control action and sends the instruction data packet to the network controller; After receiving the instruction data packet, the network controller executes the corresponding network policy adjustment to change the communication permissions of the smart security hardware in the network.

[0088] First, a trust management smart contract is deployed on the blockchain. This smart contract predefines a list of smart security hardware addresses to be monitored and trigger rules for trust score update events. The trust management smart contract is a programmable automated script deployed on the blockchain, specifically designed for trust score management of smart security hardware. It possesses four core functions: monitoring, calculation, triggering, and interaction. The execution results are stored on the blockchain and are tamper-proof. The smart security hardware address list is a unique list of wallet addresses / device identifiers assigned to each smart security hardware device on the blockchain. It is the core monitoring object of the smart contract, and trust score monitoring is only performed on devices within this list. The trust score update event trigger rules refer to the pre-set trigger conditions of the smart contract. When a trust score write / update transaction for a specified device address is detected on the blockchain, the subsequent calculation and execution process of the contract is automatically triggered.

[0089] Specifically, a blockchain smart contract development framework, such as Solidity+Remix, is used to write a trust management smart contract. The contract contains a list of device addresses to be monitored and rules for triggering score updates. The contract is then deployed to the blockchain and initialized through blockchain nodes. The contract address is synchronized to all blockchain consensus nodes and network controllers to achieve address interoperability between the contract and the network management system.

[0090] For example, a TrustControl_Contract_V1.0 smart contract is written based on Solidity. The unique blockchain address corresponding to the 3D smart sensor camera Dev_3D_Sense_202602_001 is written into the contract's listening address list. The predefined triggering rule is that when an on-chain transaction of the trust score update type occurs under this address, the entire process of the contract is immediately triggered. The contract is deployed to the consortium blockchain node, and the contract address is synchronized to the production line network controller.

[0091] Secondly, the trust management smart contract continuously monitors all transaction inputs and outputs on the blockchain. When it detects a trust score update record in the transaction data that matches the list of smart security hardware addresses, it reads the current trust score of the smart security hardware from the distributed ledger of the blockchain. Blockchain transaction input / output monitoring refers to the smart contract's real-time parsing of transaction data in all new blocks on the blockchain, extracting the transaction initiation address, transaction type, and data content fields to achieve comprehensive transaction monitoring. The trust score update record refers to the transaction data uploaded from S300 to the blockchain, containing the current trust score of the smart security hardware, and is marked with a unique transaction type identifier, Trust_Score_Update. It is the core detection target of the smart contract.

[0092] Specifically, the trust management smart contract continuously acquires transaction data from new blocks through a blockchain event subscription mechanism; it parses the fields of each transaction, first matching whether the transaction initiating address is in the listening list, and then matching whether the transaction type is a trust score update. If both matches pass, it is determined to be a valid trigger and proceeds to the next process.

[0093] For example, the TrustControl_Contract_V1.0 smart contract subscribes to new block data of the consortium blockchain in real time. When it detects that the transaction type of the initiating address in block height 12589 is Trust_Score_Update, it determines that the triggering rule is met and immediately starts the subsequent calculation process of the contract.

[0094] Next, the trust management smart contract compares the current trust score with a preset trust threshold.

[0095] The process of determining the preset trust threshold includes: The trust score distribution data of multiple smart security hardware devices under abnormal states in historical security events are obtained from the distributed ledger of the blockchain. Based on the trust score distribution data, a clustering algorithm is used to determine the classification boundary between the normal behavior sample cluster and the abnormal behavior sample cluster, and the trust score value corresponding to the classification boundary is used as the basic trust threshold. The security domain level parameters of the intelligent security hardware are determined based on the security level coefficient of the intelligent security hardware in the secure storage area. Based on the device identifier of the smart security hardware, the sensitivity level parameter of the data processed by the smart security hardware is determined; Based on the decentralized identity identifier of the smart security hardware, determine the positional importance parameters of the smart security hardware in the network topology; The basic trust threshold is weighted and corrected based on the security domain level parameter, the sensitivity level parameter, and the location importance parameter to obtain a preset trust threshold for the smart security hardware.

[0096] First, trust score distribution data for multiple smart security hardware devices in abnormal states during historical security events is obtained from the blockchain's distributed ledger. Blockchain distributed ledger reading involves a smart contract retrieving the latest trust score data and historical security event-related data for a specified device address from the distributed ledger via the blockchain's native interface. The reading process is traceable and the data is tamper-proof. Abnormal state trust score distribution data refers to the set of trust scores stored in the blockchain for similar smart security hardware during security events such as abnormal behavior, computing power hijacking, and data leakage. This data serves as a statistical sample for subsequently determining the basic threshold. Based on the matched device address, the smart contract extracts the current trust score of the device from the distributed ledger; simultaneously, it retrieves trust score data for all security event-related devices in the past six months under the industrial smart sensing device category in the blockchain, forming an abnormal state score sample set.

[0097] For example, the smart contract reads the current trust score of Dev_3D_Sense_202602_001 from the distributed ledger as 0.9995; at the same time, it retrieves the trust score data of 120 3D smart sensing cameras in the consortium blockchain when they experienced anomalies in the past 6 months, forming a sample set.

[0098] Secondly, based on the trust score distribution data, a clustering algorithm is used to determine the classification boundary between normal behavior sample clusters and abnormal behavior sample clusters. The trust score value corresponding to the classification boundary is used as the basic trust threshold. The clustering algorithm uses the unsupervised learning K-means clustering algorithm to perform cluster analysis on the abnormal state trust score distribution data, automatically dividing the normal behavior sample cluster into normal behavior sample clusters and abnormal behavior sample clusters. It is suitable for unlabeled score sample data. The classification boundary refers to the critical value between the normal sample cluster and the abnormal sample cluster after K-means clustering. It is the basic threshold for distinguishing between the trust status of a device and the abnormal risk status, and all devices share this basic value. The basic trust threshold is a general trust threshold determined by the cluster classification boundary. It is the benchmark value for subsequent personalized threshold correction and takes a value between 0 and 1.

[0099] Specifically, the smart contract incorporates a lightweight K-means clustering algorithm module. The algorithm inputs the trust score distribution data for abnormal states and sets the number of clusters k=2. The clusters are categorized as normal or abnormal. The algorithm automatically calculates the center values ​​and classification boundaries of the two sample clusters; the trust score value corresponding to this classification boundary is then used as the basic trust threshold.

[0100] For example, the trust score sample set of 120 abnormal devices is input into the contract's built-in K-means algorithm. After clustering, the cluster center value of normal samples is 0.92, the cluster center value of abnormal samples is 0.71, and the classification boundary is 0.85. Therefore, the basic trust threshold of industrial 3D smart sensing devices is determined to be 0.85.

[0101] Furthermore, based on the security level coefficient of the intelligent security hardware in the secure storage area, the security domain level parameter of the intelligent security hardware is determined. The security domain level parameter is a weighted parameter mapped from the security level coefficient of the intelligent security hardware itself, reflecting the protection level of the physical security domain in which the device resides. Its value is a real number greater than or equal to 1; the higher the protection level, the larger the parameter value. A security domain refers to the device deployment area divided according to the physical protection capabilities of the industrial scenario, such as a core production line area, a general monitoring area, or an external network access area. The security level coefficient corresponds one-to-one with the security domain to which the device belongs. The security level coefficient is used as the security domain level parameter. For example, if the security level coefficient is 1.1, then the security domain level parameter is 1.1.

[0102] Then, based on the device identifier of the smart security hardware, the sensitivity level parameter of the data processed by the smart security hardware is determined. The device identifier is a unique device ID assigned to the smart security hardware by the blockchain, containing information such as device type, data type processed, and application scenario; it is a key identifier distinguishing the data processing attributes of the device. The data sensitivity level parameter is a weighted parameter determined based on the sensitivity of the data processed by the device, reflecting the importance of the data processed by the device. Its value is a real number greater than or equal to 1; the higher the data sensitivity, the larger the parameter value. The smart contract parses the data type field in the device identifier, compares it with a preset data sensitivity grading standard, and matches the corresponding sensitivity level parameter; in industrial scenarios, production line data > process data > general monitoring data.

[0103] For example, after parsing the device identifier Dev_3D_Sense_202602_001 of the target camera, it is determined that it processes core data for 3D point cloud modeling of industrial production lines, which belongs to high-sensitivity data. The contract has a preset classification standard: the sensitivity level parameter corresponding to low data sensitivity is 1.0, the sensitivity level parameter corresponding to medium data sensitivity is 1.1, the sensitivity level parameter corresponding to high data sensitivity is 1.2, and the sensitivity level parameter corresponding to extremely high data sensitivity is 1.3. Therefore, the data sensitivity level parameter is determined to be 1.2.

[0104] Subsequently, based on the decentralized identity identifier (DID) of the smart security hardware, the positional importance parameter of the smart security hardware in the network topology is determined. The decentralized identity identifier (DID) is a unique decentralized identity assigned to the smart security hardware by the blockchain, containing information such as the device's deployment location, node type, and network connectivity within the industrial network topology. It is unverified and immutable. The positional importance parameter is a weighted parameter determined based on the device's positional importance in the network topology, reflecting the device's core status as a network node. Its value is a real number greater than or equal to 1, with a larger value for more core nodes. The smart contract parses the device's DID information, extracts the network topology location field, and matches the corresponding positional importance parameter against a preset node positional importance grading standard. Core nodes are key sensing / computing nodes in the production line network, associated with multiple downstream devices.

[0105] For example, after the DID of the target camera is parsed, it is determined to be a core sensing node of the automotive welding production line, associated with 6 industrial robotic arms and 2 production line controllers, and belongs to the core node; the contract preset classification standard: the position importance parameter corresponding to ordinary nodes is 1.0, the position importance parameter corresponding to important nodes is 1.1, and the position importance parameter corresponding to core nodes is 1.2, so its position importance parameter is determined to be 1.2.

[0106] Finally, the basic trust threshold is weighted and corrected based on the security domain level parameter, the sensitivity level parameter, and the location importance parameter to obtain a preset trust threshold for the smart security hardware. The weighted correction algorithm is a threshold correction formula preset by the smart contract. It takes a weighted average of the three parameters—security domain level, data sensitivity, and location importance—and multiplies it by the basic trust threshold to obtain a personalized threshold for each device. The preset trust threshold is a trust scoring threshold tailored to each smart security hardware device and serves as the criterion for determining network access permissions for that device.

[0107] Specifically, the smart contract uses an equal-weighted correction formula to calculate the preset trust threshold. The formula is: Preset trust threshold = Basic trust threshold × (Security domain level parameter + Data sensitivity level parameter + Location importance parameter) / 3. If the result is greater than 1, it is taken as 1, that is, the upper limit of the trust threshold is 1.

[0108] For example, the target camera's basic trust threshold is 0.85, security domain level parameter is 1.1, data sensitivity parameter is 1.2, and location importance parameter is 1.2; weighted calculation: (1.1+1.2+1.2) / 3≈1.167; preset trust threshold = 0.85×1.167≈0.9920, and finally the personalized preset trust threshold of Dev_3D_Sense_202602_001 is determined to be 0.9920.

[0109] Furthermore, when the current trust score is lower than the preset trust threshold, the trust management smart contract matches and determines the target access control action corresponding to the numerical range of the current trust score. The threshold comparison logic is the core judgment logic of the smart contract, containing only two results: above the threshold and below the threshold, with no intermediate state equal to the threshold, ensuring the uniqueness of the control policy execution. The score threshold matching result: The judgment result generated after the comparison is the core basis for whether to trigger the subsequent access control policy. The subsequent policy matching process is triggered only when the result is below the threshold. The smart contract compares the current trust score with the personalized preset trust threshold; it outputs the judgment result according to the logic that if the current trust score is less than the preset trust threshold, the policy is triggered; if the current trust score is greater than or equal to the preset trust threshold, the policy is not triggered.

[0110] For example, the current trust score is 0.9995, and the preset trust threshold is 0.9920; the comparison result is: 0.9995 > 0.9920, so the access control policy is not triggered; if the device's score subsequently drops to 0.9900 < 0.9920, it is determined that the access control policy has been triggered, and the next steps are initiated.

[0111] Secondly, the trust management smart contract generates an instruction data packet containing the target access control action and sends the instruction data packet to the network controller. The trust score range refers to a pre-defined score segment in the smart contract corresponding to the access control action. The range division is based on the device's pre-defined trust threshold, ranging from high to low as slightly low threshold, moderately low threshold, and severely low threshold. The target access control action is a network permission adjustment action that corresponds one-to-one with the score range, following the principle of matching risk with control intensity; the lower the score, the stricter the control. The instruction data packet is a standardized network instruction generated by the smart contract, containing the device ID, target action, and execution time. It is encrypted using a blockchain encryption algorithm and can only be parsed and executed by the network controller. The smart contract has a pre-defined score range-access control action mapping table; when the current score is determined to be below the pre-defined threshold, the score's corresponding score range is determined, and the corresponding target access control action is matched; an encrypted instruction data packet is generated according to the network controller's standard data format.

[0112] For example, using the target camera's preset threshold of 0.9917 as a baseline, the contract's preset mapping table is as follows: Slightly low threshold: 0.9800~0.9917 corresponds to the action of network communication rate limiting (bandwidth reduced to 50%); Moderately low threshold: 0.9500~0.9800 corresponds to the action of allowing only read-only communication (data upload / write is prohibited); Severely low threshold: <0.9500 corresponds to the action of physical isolation across the entire network (cutting off all network communication). If the device score drops to 0.9850, falling within the slightly low threshold range, the target action is matched as network communication rate limiting; the smart contract generates an encrypted instruction data packet containing the device ID, the rate limiting action, and immediate execution.

[0113] Finally, after receiving the instruction data packet, the network controller executes the corresponding network policy adjustment to change the communication permissions of the smart security hardware in the network. The network controller, a core management device in the industrial network, is responsible for allocating network communication permissions, managing bandwidth, and controlling isolation for all devices on the entire production line, and achieves encrypted two-way communication with the blockchain smart contract. Network policy adjustment refers to the network controller modifying the network communication parameters of the target device in real time according to the instruction data packet of the smart contract, and the adjustment result is synchronously uploaded to the blockchain for evidence storage. Communication permissions are the communication rights of the smart security hardware in the industrial network, including core dimensions such as bandwidth limits, data read / write permissions, and network access range, and are the objects of access control policies.

[0114] Specifically, the smart contract sends instruction data packets to the industrial network controller through a pre-bound encrypted communication interface. After receiving the data packets, the network controller decrypts and verifies the signature using the blockchain public key to confirm the legality and uniqueness of the instruction. After the signature is verified, the network controller immediately performs the corresponding network policy adjustment on the target device and uploads the adjustment result and execution time to the blockchain, where the smart contract completes the notarization.

[0115] For example, the smart contract sends the encrypted instruction data packet to the production line network controller; the controller decrypts and verifies the signature using the contract's public key, confirming that the instruction was legitimately triggered; it immediately performs network bandwidth throttling on Dev_3D_Sense_202602_001, reducing its industrial communication bandwidth from 100Mbps to 50Mbps; at the same time, it uploads "Throttling successful, execution time 2026-02-25T15:02:30Z" to the blockchain, which is written into the block height by the trust management smart contract, completing the entire process of evidence storage.

[0116] In this embodiment of the invention, a trust-scoring-driven intelligent security hardware dynamic access control system is constructed based on blockchain smart contracts, realizing decentralized and automated closed-loop management across the entire chain from score monitoring to permission control. This step continuously monitors on-chain trust score update events through smart contracts, combining clustering algorithms with multi-dimensional parameters such as security domain, data sensitivity, and network location importance to calculate personalized preset trust thresholds for each device. This ensures that threshold determination has both industry-standard statistical basis and adapts to the actual security attributes and application characteristics of individual devices, improving the accuracy and scenario adaptability of threshold settings. Simultaneously, based on the comparison results between the score and the threshold, the smart contract can automatically match access control actions appropriate to the risk level and coordinate with the network controller to complete real-time adjustments to communication permissions. This achieves precise matching between network control strength and device trust risk, resulting in refined dynamic permission control. Furthermore, all operations are recorded on the blockchain, ensuring the immutability and traceability of control actions and avoiding the security risks of centralized intervention. In addition, smart contracts support the periodic recalculation of thresholds and the standardized execution of control actions, further improving the flexibility and efficiency of access control. They also form an effective connection with the dynamic trust score generation process of S300, perfecting the entire technical chain of smart security hardware from trust status assessment to network permission control, and enhancing the intelligence, security and automation level of network access management of smart security hardware in industrial scenarios.

[0117] Through the specific implementation methods described above, the embodiments of the present invention achieve the following technical effects: This invention provides a method and system for managing network identity authentication credentials for smart security hardware. By leveraging decentralized blockchain identity registration, it eliminates reliance on centralized certificate authorities, ensuring that the initial identity of each device is unique, trustworthy, tamper-proof, and verifiable across domains. Utilizing multi-dimensional behavior collection and federated learning for anomaly identification, it achieves continuous monitoring of the smart security hardware's operational status throughout its entire lifecycle, improving anomaly detection accuracy and generalization capabilities. A dynamic trust score is generated by combining model confidence, hardware security level, and historical trust performance, and this score, along with anomaly information, is stored on the blockchain for evidence, ensuring objective and accurate trust assessment and traceable, tamper-proof data. Finally, blockchain smart contracts enable real-time monitoring of the trust score, personalized threshold calculation, and automated permission adjustment, achieving precise matching between device risk and network control intensity. The entire process is decentralized and automated, eliminating the risk of human intervention or tampering. The overall technology effectively solves the problems of traditional smart security hardware, such as single identity authentication, lack of behavior monitoring, static trust assessment, and lagging permission control. It improves the security, intelligence level, and cross-domain collaboration capabilities of device network identity authentication and access control, providing stable and reliable security support for the large-scale deployment of smart security hardware.

[0118] Example 2, as Figure 2As shown, the present invention provides a network identity authentication credential management system for intelligent security hardware, the system comprising: The blockchain identity registration module 11 is used to register a decentralized identity identifier for each smart security hardware on the blockchain, and associate the public key certificate of the smart security hardware with the decentralized identity identifier and store it on the blockchain as the initial identity certificate of the smart security hardware. The behavior anomaly recognition module 12 is used to collect the behavior data sequence generated by the smart security hardware in real time during operation, input the behavior data sequence into the pre-trained global anomaly recognition agent, and output the behavior deviation score of the smart security hardware. The trust score storage module 13 is used to dynamically generate the current trust score of the smart security hardware based on the behavior deviation score, and upload the current trust score and the corresponding abnormal event information to the blockchain for storage. The automatic contract management module 14 is used to monitor changes in the trust score of the smart security hardware based on the smart contract deployed on the blockchain. When the current trust score is lower than a preset trust threshold, the smart contract automatically executes the corresponding access control policy to adjust the communication permissions of the smart security hardware in the network.

[0119] In one embodiment, the blockchain identity registration module 11 is further used for: During the production phase or the initial power-on initialization phase of the smart security hardware, a unique device identifier and a pair of asymmetric keys are generated for each piece of smart security hardware. The private key from the asymmetric key pair is written into the secure storage area of ​​the smart security hardware, wherein the secure storage area has a physical anti-read protection mechanism; The public key in the asymmetric key pair and the device identifier are sent to the blockchain, and the identity registration smart contract deployed on the blockchain is invoked; The identity registration smart contract generates a decentralized identity identifier for the smart security hardware based on the device identifier, and records the public key and the decentralized identity identifier in the distributed ledger of the blockchain as a key-value pair, serving as the initial identity credential of the smart security hardware.

[0120] In one embodiment, the behavior anomaly identification module 12 is further configured to: The real-time acquisition of behavioral data sequences generated by the intelligent security hardware during operation includes: The embedded microcontroller unit embedded in the smart security hardware collects multi-dimensional behavioral data of the smart security hardware in real time at preset time intervals. The multi-dimensional behavioral data includes at least two of the following: network communication traffic characteristic data, central processing unit utilization data, memory utilization data, running process list data, data read and write frequency data, interaction record data with external devices, geographical location change data, and operation log data. The collected multidimensional behavioral data is timestamped and formatted to generate a sequence of behavioral data to be analyzed.

[0121] The construction process of the global anomaly detection agent includes: Acquire multi-dimensional historical behavior data of multiple smart security hardware devices under historical operating conditions, and perform data cleaning and outlier removal on the multi-dimensional historical behavior data to obtain cleaned historical behavior data; The cleaned historical behavior data is manually labeled, and the data labeled as normal behavior is used as the positive sample set, and the data labeled as abnormal behavior is used as the negative sample set. A training dataset containing the positive sample set and the negative sample set is constructed. An initial deep neural network model is constructed, and the training dataset is input into the initial deep neural network model for iterative training. The model parameters are optimized through the backpropagation algorithm until the model converges, thus obtaining a pre-trained basic anomaly recognition agent. A federated learning architecture is adopted to distribute the pre-trained basic anomaly recognition agent to multiple edge computing nodes. Each edge computing node uses locally collected real-time behavior data sequences to perform incremental training and local parameter optimization on the received basic anomaly recognition agent, generating a personalized anomaly recognition agent deployed locally on each edge computing node. Each edge computing node encrypts and uploads the updated model parameters of the personalized anomaly detection agent to the central parameter server. The central parameter server performs federated averaging aggregation on the received multiple model parameters to generate an updated global anomaly detection agent. The updated global anomaly detection agent is redistributed to each of the edge computing nodes to replace the personalized anomaly detection agent local to each edge computing node.

[0122] In one embodiment, the trust scoring and evidence storage module 13 is further configured to: The behavior deviation score output by the global anomaly recognition agent for the behavior data sequence is obtained, and the behavior deviation score is normalized to obtain a standardized deviation score in the range of 0 to 1. The closer the standardized deviation score is to 1, the higher the degree of behavior abnormality. Obtain the model confidence score of the global anomaly detection agent for the current output result; The corrected effective deviation score is calculated based on the standardized deviation score and the model confidence score. The current trust score of the smart security hardware is calculated based on the corrected effective deviation score and the preset initial trust base value, wherein the current trust score is negatively correlated with the corrected effective deviation score. When the behavior deviation score exceeds the preset abnormal behavior judgment threshold, corresponding abnormal event information is generated, wherein the abnormal event information includes at least the abnormal occurrence timestamp, the abnormal type code, the standardized deviation score, and the list of affected resources; The current trust score and the abnormal event information are encapsulated according to a preset data structure, and a digital signature is generated on the encapsulated data using the private key of the smart security hardware, thereby constructing on-chain transaction data containing the current trust score, the abnormal event information, and the digital signature; The on-chain transaction data is broadcast to the blockchain network, where consensus nodes verify the digital signature. Once verified, the current trust score and corresponding abnormal event information are written into a new block and stored in the distributed ledger of the blockchain.

[0123] The process of obtaining the model confidence score of the global anomaly detection agent for the current output result includes: Acquire multiple personalized anomaly detection agents deployed across multiple edge computing nodes; The same behavioral data sequence is input into the multiple personalized anomaly recognition agents, and each of the personalized anomaly recognition agents makes predictions independently, outputting multiple behavioral deviation prediction values. Calculate the variance of the predicted values ​​of the multiple behavioral deviations, and determine the normalized reciprocal of the variance as the model confidence score, wherein the model confidence score is negatively correlated with the variance.

[0124] The corrected effective deviation score is calculated based on the standardized deviation score and the model confidence score, including: The security level coefficient of the smart security hardware in the secure storage area is obtained. The security level coefficient is preset according to the strength of the physical anti-read protection mechanism of the secure storage area. The security level coefficient is a real number greater than or equal to 1. The higher the strength of the physical anti-read protection mechanism of the secure storage area, the larger the security level coefficient. Read the historical trust score sequence of the smart security hardware over the past N time periods from the distributed ledger of the blockchain, and calculate the arithmetic average of the historical trust score sequence to obtain a historical performance benchmark value with a value range between 0 and 1. Calculate the difference between 1 and the model confidence score to obtain the model uncertainty factor, and multiply the model uncertainty factor by the standardized deviation score to obtain the deviation score after the first correction; Calculate the ratio of 1 to the security level coefficient to obtain the hardware security attenuation factor. Multiply the deviation score after the first correction by the hardware security attenuation factor to obtain the deviation score after the second correction. Calculate the difference between 1 and the historical performance benchmark value to obtain the historical trust buffer factor. Multiply the deviation score after the second correction by the historical trust buffer factor to obtain the corrected effective deviation score.

[0125] In one embodiment, the automatic contract management module 14 is further configured to: A trust management smart contract is deployed on the blockchain, wherein the trust management smart contract predefines a list of smart security hardware addresses that need to be monitored and the triggering rules for trust score update events; The trust management smart contract continuously monitors all transaction inputs and outputs on the blockchain. When it detects that the transaction data contains a trust score update record that matches the address list of the smart security hardware, it reads the current trust score of the smart security hardware from the distributed ledger of the blockchain. The trust management smart contract compares the current trust score with a preset trust threshold. When the current trust score is lower than the preset trust threshold, the trust management smart contract matches and determines the target access control action corresponding to the value range based on the numerical range of the current trust score. The trust management smart contract generates an instruction data packet containing the target access control action and sends the instruction data packet to the network controller; After receiving the instruction data packet, the network controller executes the corresponding network policy adjustment to change the communication permissions of the smart security hardware in the network.

[0126] The process of determining the preset trust threshold includes: The trust score distribution data of multiple smart security hardware devices under abnormal states in historical security events are obtained from the distributed ledger of the blockchain. Based on the trust score distribution data, a clustering algorithm is used to determine the classification boundary between the normal behavior sample cluster and the abnormal behavior sample cluster, and the trust score value corresponding to the classification boundary is used as the basic trust threshold. The security domain level parameters of the intelligent security hardware are determined based on the security level coefficient of the intelligent security hardware in the secure storage area. Based on the device identifier of the smart security hardware, the sensitivity level parameter of the data processed by the smart security hardware is determined; Based on the decentralized identity identifier of the smart security hardware, determine the positional importance parameters of the smart security hardware in the network topology; The basic trust threshold is weighted and corrected based on the security domain level parameter, the sensitivity level parameter, and the location importance parameter to obtain a preset trust threshold for the smart security hardware.

[0127] It should be noted that the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A method for managing network identity authentication credentials for intelligent security hardware, characterized in that, The method includes: Register a decentralized identity identifier for each smart security hardware device on the blockchain, and associate the public key certificate of the smart security hardware device with the decentralized identity identifier and store it on the blockchain as the initial identity certificate of the smart security hardware device; The system collects behavioral data sequences generated by the intelligent security hardware during operation in real time, inputs the behavioral data sequences into a pre-trained global anomaly recognition agent, and outputs a behavioral deviation score of the intelligent security hardware. The current trust score of the smart security hardware is dynamically generated based on the behavior deviation score, and the current trust score and the corresponding abnormal event information are uploaded to the blockchain for evidence storage. Based on the smart contract deployed on the blockchain, the smart security hardware monitors changes in its trust score. When the current trust score is lower than a preset trust threshold, the smart contract automatically executes the corresponding access control policy to adjust the smart security hardware's communication permissions in the network.

2. The method for managing network identity authentication credentials for intelligent security hardware according to claim 1, characterized in that, Register a decentralized identity identifier for each smart security device on the blockchain, and associate the public key certificate of the smart security device with the decentralized identity identifier and store it on the blockchain as the initial identity certificate of the smart security device, including: During the production phase or the initial power-on initialization phase of the smart security hardware, a unique device identifier and a pair of asymmetric keys are generated for each piece of smart security hardware. The private key from the asymmetric key pair is written into the secure storage area of ​​the smart security hardware, wherein the secure storage area has a physical anti-read protection mechanism; The public key in the asymmetric key pair and the device identifier are sent to the blockchain, and the identity registration smart contract deployed on the blockchain is invoked; The identity registration smart contract generates a decentralized identity identifier for the smart security hardware based on the device identifier, and records the public key and the decentralized identity identifier in the distributed ledger of the blockchain as a key-value pair, serving as the initial identity credential of the smart security hardware.

3. The method for managing network identity authentication credentials for intelligent security hardware according to claim 1, characterized in that, Real-time acquisition of behavioral data sequences generated by the intelligent security hardware during operation, including: The embedded microcontroller unit embedded in the smart security hardware collects multi-dimensional behavioral data of the smart security hardware in real time at preset time intervals. The multi-dimensional behavioral data includes at least two of the following: network communication traffic characteristic data, central processing unit utilization data, memory utilization data, running process list data, data read and write frequency data, interaction record data with external devices, geographical location change data, and operation log data. The collected multidimensional behavioral data is timestamped and formatted to generate a sequence of behavioral data to be analyzed.

4. The method for managing network identity authentication credentials for intelligent security hardware according to claim 1, characterized in that, The construction process of the global anomaly detection agent includes: Acquire multi-dimensional historical behavior data of multiple smart security hardware devices under historical operating conditions, and perform data cleaning and outlier removal on the multi-dimensional historical behavior data to obtain cleaned historical behavior data; The cleaned historical behavior data is manually labeled, and the data labeled as normal behavior is used as the positive sample set, and the data labeled as abnormal behavior is used as the negative sample set. A training dataset containing the positive sample set and the negative sample set is constructed. An initial deep neural network model is constructed, and the training dataset is input into the initial deep neural network model for iterative training. The model parameters are optimized through the backpropagation algorithm until the model converges, thus obtaining a pre-trained basic anomaly recognition agent. A federated learning architecture is adopted to distribute the pre-trained basic anomaly recognition agent to multiple edge computing nodes. Each edge computing node uses locally collected real-time behavior data sequences to perform incremental training and local parameter optimization on the received basic anomaly recognition agent, generating a personalized anomaly recognition agent deployed locally on each edge computing node. Each edge computing node encrypts and uploads the updated model parameters of the personalized anomaly detection agent to the central parameter server. The central parameter server performs federated averaging aggregation on the received multiple model parameters to generate an updated global anomaly detection agent. The updated global anomaly detection agent is redistributed to each of the edge computing nodes to replace the personalized anomaly detection agent local to each edge computing node.

5. The method for managing network identity authentication credentials for intelligent security hardware according to claim 1, characterized in that, The current trust score of the smart security hardware is dynamically generated based on the behavioral deviation score, and the current trust score and corresponding abnormal event information are uploaded to the blockchain for evidence storage, including: The behavior deviation score output by the global anomaly recognition agent for the behavior data sequence is obtained, and the behavior deviation score is normalized to obtain a standardized deviation score in the range of 0 to 1. The closer the standardized deviation score is to 1, the higher the degree of behavior abnormality. Obtain the model confidence score of the global anomaly detection agent for the current output result; The corrected effective deviation score is calculated based on the standardized deviation score and the model confidence score. The current trust score of the smart security hardware is calculated based on the corrected effective deviation score and the preset initial trust base value, wherein the current trust score is negatively correlated with the corrected effective deviation score. When the behavior deviation score exceeds the preset abnormal behavior judgment threshold, corresponding abnormal event information is generated, wherein the abnormal event information includes at least the abnormal occurrence timestamp, the abnormal type code, the standardized deviation score, and the list of affected resources; The current trust score and the abnormal event information are encapsulated according to a preset data structure, and a digital signature is generated on the encapsulated data using the private key of the smart security hardware, thereby constructing on-chain transaction data containing the current trust score, the abnormal event information, and the digital signature; The on-chain transaction data is broadcast to the blockchain network, where consensus nodes verify the digital signature. Once verified, the current trust score and corresponding abnormal event information are written into a new block and stored in the distributed ledger of the blockchain.

6. The method for managing network identity authentication credentials for intelligent security hardware according to claim 5, characterized in that, Obtain the model confidence score of the global anomaly detection agent for the current output result, including: Acquire multiple personalized anomaly detection agents deployed across multiple edge computing nodes; The same behavioral data sequence is input into the multiple personalized anomaly recognition agents, and each of the personalized anomaly recognition agents makes predictions independently, outputting multiple behavioral deviation prediction values. Calculate the variance of the predicted values ​​of the multiple behavioral deviations, and determine the normalized reciprocal of the variance as the model confidence score, wherein the model confidence score is negatively correlated with the variance.

7. The method for managing network identity authentication credentials for intelligent security hardware according to claim 5, characterized in that, Based on the standardized deviation score and the model confidence score, the corrected effective deviation score is calculated, including: The security level coefficient of the smart security hardware in the secure storage area is obtained. The security level coefficient is preset according to the strength of the physical anti-read protection mechanism of the secure storage area. The security level coefficient is a real number greater than or equal to 1. The higher the strength of the physical anti-read protection mechanism of the secure storage area, the larger the security level coefficient. Read the historical trust score sequence of the smart security hardware over the past N time periods from the distributed ledger of the blockchain, and calculate the arithmetic average of the historical trust score sequence to obtain a historical performance benchmark value with a value range between 0 and 1. Calculate the difference between 1 and the model confidence score to obtain the model uncertainty factor, and multiply the model uncertainty factor by the standardized deviation score to obtain the deviation score after the first correction; Calculate the ratio of 1 to the security level coefficient to obtain the hardware security attenuation factor. Multiply the deviation score after the first correction by the hardware security attenuation factor to obtain the deviation score after the second correction. Calculate the difference between 1 and the historical performance benchmark value to obtain the historical trust buffer factor. Multiply the deviation score after the second correction by the historical trust buffer factor to obtain the corrected effective deviation score.

8. The method for managing network identity authentication credentials for intelligent security hardware according to claim 1, characterized in that, Based on a smart contract deployed on the blockchain, changes in the trust score of the smart security hardware are monitored. When the current trust score falls below a preset trust threshold, the smart contract automatically executes a corresponding access control policy to adjust the communication permissions of the smart security hardware in the network, including: A trust management smart contract is deployed on the blockchain, wherein the trust management smart contract predefines a list of smart security hardware addresses that need to be monitored and the triggering rules for trust score update events; The trust management smart contract continuously monitors all transaction inputs and outputs on the blockchain. When it detects that the transaction data contains a trust score update record that matches the address list of the smart security hardware, it reads the current trust score of the smart security hardware from the distributed ledger of the blockchain. The trust management smart contract compares the current trust score with a preset trust threshold. When the current trust score is lower than the preset trust threshold, the trust management smart contract matches and determines the target access control action corresponding to the value range based on the numerical range of the current trust score. The trust management smart contract generates an instruction data packet containing the target access control action and sends the instruction data packet to the network controller; After receiving the instruction data packet, the network controller executes the corresponding network policy adjustment to change the communication permissions of the smart security hardware in the network.

9. The method for managing network identity authentication credentials for intelligent security hardware according to claim 8, characterized in that, The process of determining the preset trust threshold includes: The trust score distribution data of multiple smart security hardware devices under abnormal states in historical security events are obtained from the distributed ledger of the blockchain. Based on the trust score distribution data, a clustering algorithm is used to determine the classification boundary between the normal behavior sample cluster and the abnormal behavior sample cluster, and the trust score value corresponding to the classification boundary is used as the basic trust threshold. The security domain level parameters of the intelligent security hardware are determined based on the security level coefficient of the intelligent security hardware in the secure storage area. Based on the device identifier of the smart security hardware, the sensitivity level parameter of the data processed by the smart security hardware is determined; Based on the decentralized identity identifier of the smart security hardware, determine the positional importance parameters of the smart security hardware in the network topology; The basic trust threshold is weighted and corrected based on the security domain level parameter, the sensitivity level parameter, and the location importance parameter to obtain a preset trust threshold for the smart security hardware.

10. A network identity authentication credential management system for intelligent security hardware, characterized in that, A method for managing network identity authentication credentials for implementing a smart security hardware according to any one of claims 1-9, the system comprising: The blockchain identity registration module is used to register a decentralized identity identifier for each smart security hardware on the blockchain, and associate the public key certificate of the smart security hardware with the decentralized identity identifier and store it on the blockchain as the initial identity certificate of the smart security hardware. The behavior anomaly recognition module is used to collect the behavior data sequence generated by the smart security hardware in real time during operation, input the behavior data sequence into the pre-trained global anomaly recognition agent, and output the behavior deviation score of the smart security hardware. The trust score notarization module is used to dynamically generate the current trust score of the smart security hardware based on the behavior deviation score, and upload the current trust score and the corresponding abnormal event information to the blockchain for notarization. The automatic contract management module is used to monitor changes in the trust score of the smart security hardware based on the smart contract deployed on the blockchain. When the current trust score is lower than a preset trust threshold, the smart contract automatically executes the corresponding access control policy to adjust the communication permissions of the smart security hardware in the network.