Intelligent terminal security authentication method based on traffic shaping and multi-stage handshake negotiation
By using a smart terminal authentication traffic analysis platform and multi-stage handshake negotiation technology, the shortcomings of traffic shaping and identity verification in smart terminal authentication are solved, realizing dynamic traffic management and multi-level security authentication, thereby improving authentication efficiency and security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- CHENGDU SUN HIGH-TECH CO LTD
- Filing Date
- 2026-05-07
- Publication Date
- 2026-06-05
AI Technical Summary
Existing technologies lack dynamic traffic shaping capabilities and multi-stage handshake verification in smart terminal authentication, resulting in traffic congestion, resource waste, and insufficient identity authentication security, making it difficult to adapt to the authentication needs of multiple scenarios in complex network environments.
Traffic data is collected through a smart terminal authentication traffic analysis platform. A dynamic shaping strategy is generated by combining the traffic shaping strategy with a convolutional optimization decision model. Multi-stage handshake negotiation is performed, and the integrity of the handshake process and multi-scale feature recognition of terminal identity are used to generate a comprehensive authentication result.
It enables dynamic adjustment of traffic allocation based on terminal type and scenario, improves authentication efficiency and stability, enhances the ability to resist identity forgery and data tampering, builds a multi-layered security protection system, and meets the authentication requirements of high security and high adaptability.
Smart Images

Figure CN122160186A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of IoT smart terminal authentication technology, and in particular to a smart terminal security authentication method based on traffic shaping and multi-stage handshake negotiation. Background Technology
[0002] With the rapid popularization of IoT technology, smart terminals are increasingly used in industrial control, smart homes, public services, and other fields, resulting in an explosive growth in the number of connected terminals. Significant differences exist in the hardware configurations, communication protocols, and security capabilities of various terminals, leading to a continuous increase in security risks when terminals access the network. Terminal authentication, as the first line of defense for network security, needs to address multiple security threats such as irregular traffic transmission, identity forgery, and data tampering. Traditional authentication methods, often relying on a single identity identifier or a simple handshake process, are ill-suited to the diverse authentication needs of complex network environments. Against this backdrop, authentication technologies integrating traffic management and multi-stage negotiation have become a key direction for improving the security of smart terminal access. These technologies require precise traffic control, complete handshake verification, and comprehensive identity recognition to build a multi-layered security protection system that meets the high-security and highly adaptable authentication requirements of smart terminals.
[0003] Existing technologies have two prominent drawbacks: First, traffic control lacks dynamic adaptability. Most authentication methods do not tailor to terminal traffic characteristics, but only adopt fixed traffic restriction strategies. They cannot adjust traffic allocation rules according to terminal type, transmission scenario, and authentication priority, leading to traffic congestion or resource waste, which affects authentication efficiency and stability. Second, identity authentication is simplistic and handshake integrity verification is insufficient. Existing technologies often rely on a single hardware identifier or password for identity verification, failing to fully explore multi-scale terminal feature information. At the same time, the handshake negotiation process only performs simple verification on key links, without forming a full-process integrity adaptation and verification mechanism. This makes it difficult to effectively resist attacks such as identity forgery and handshake data tampering, resulting in insufficient authentication security and reliability. Summary of the Invention
[0004] To overcome the shortcomings and deficiencies of existing technologies, this invention provides a smart terminal security authentication method based on traffic shaping and multi-stage handshake negotiation.
[0005] The technical solution adopted in this invention is a smart terminal security authentication method based on traffic shaping and multi-stage handshake negotiation, comprising the following steps: S1, collecting traffic data to be authenticated from the smart terminal through a smart terminal authentication traffic analysis platform, and extracting traffic transmission rate, data packet length distribution, data transmission interval, protocol type identifier, terminal access port information, data encryption identifier, and traffic calibration parameters; S2, calling the traffic shaping strategy convolution optimization decision model, constructing a multi-dimensional traffic feature matrix based on the collected traffic calibration parameters, performing in-depth traffic feature extraction by sliding the convolution kernel through the feature matrix, and generating a dynamic traffic shaping strategy in combination with the priority weight allocation rules of smart terminal security authentication; S3, initiating the multi-stage handshake negotiation process, in which the smart terminal and the authentication server sequentially complete the initial connection request sending, authentication protocol version confirmation, and encryption algorithm... The process involves several steps: S4, S5, S6, S7, S8, S9, S10, S2, S3, S4, S5, S6, S7, S8, S9, S10, S2, S3, S4, S11, S2, S3, S4, S12, S3, S4, S13, S2, S3, S4, S14, S2, S3, S4, S1 ...4, S1, S3, S4, S1, S4, S1, S4, S1, S3, S4, S1, S4, S1, S4, S1, S3, S4, S1, S4, S1, S4, S1, S3, S4, S1, S4, S1, S4, S1, S4, S1, S3, S4, S1, S4, S1, S4, S1, S4, S1, S4, S1, S4, S1, S4, S1, S4, S1, S4, S1, S4, S1, S4, S1, S4, S1, S4, S1, S4, S1, S4, S1, S4, S1, S4, S1, S4, S1, S4, S1, S4, S1, S4, S
[0006] Furthermore, the expression for the convolution optimization decision model of the flow shaping strategy is: ,
[0007] in, This represents the optimal flow shaping strategy decision value. These are the model weight coefficients. This is the convolution operation function. A multidimensional flow characteristic matrix, The convolution kernel matrix, It is the Sigmoid activation function. Let i be the weighting factor for the i-th flow parameter. Let i be the standardized value of the i-th flow calibration parameter. Number of parameters to calibrate the flow rate. This is the flow regulation coefficient. As an indicator of traffic transmission stability, It is the natural logarithm function.
[0008] Furthermore, the expression for the handshake process integrity adaptation verification algorithm is as follows: ,
[0009] in, This is the handshake integrity check value. For hash operation functions, This is a collection of multi-stage handshake interaction data. For XOR operation, To preset the verification baseline hash value, For the actual negotiation parameters of the j-th handshake step, For the standard negotiation parameters of the j-th handshake step, The number of handshake steps. To verify the adaptation coefficient, As an integrity compensation factor, This serves as a validity indicator for the data interaction in the k-th handshake phase. The number of handshake data items involved in the verification.
[0010] Furthermore, the expression for the terminal identity multi-scale feature recognition model is: ,
[0011] in, For terminal identity recognition confidence level, Let x be the weight coefficient of the x-th identity feature. Let x be the extracted value of the x-th multi-scale identity feature. The number of identity feature dimensions. Let y be the difference weight of the y-th feature. Let y be the actual value of the terminal feature. This represents the average value of the terminal characteristics. For the number of dimensions of feature comparison, The hyperbolic tangent activation function is used. For feature fusion coefficients, Let z be the weighting factor for the z-th historical behavior feature. Let z be the feature value of the historical authentication behavior. The number of historical behavioral characteristics.
[0012] Furthermore, the traffic parameter acquisition model expression of the intelligent terminal authentication traffic analysis platform is as follows: ,
[0013] in, The overall results of the flow parameter collection, This is the data acquisition accuracy coefficient. Let t be the time weight of the t-th collection period. This is the raw traffic data for the t-th time period. Number of data collection periods For data integration coefficients, Let u be the acquisition sensitivity coefficient of the u-th parameter. Let u be the original collected value of the u-th flow parameter. This represents the total number of traffic parameters collected.
[0014] Furthermore, the permission determination model expression for the smart terminal security authentication is as follows: ,
[0015] in, This is the final authentication result value. Weighting coefficients for permission determination. Let w be the error value of the w-th authentication step. The number of certification error assessment steps, is the weighting factor for the w-th error evaluation stage.
[0016] Further, S2 includes the following sub-steps: S21, the intelligent terminal authentication traffic analysis platform organizes the collected traffic calibration parameters according to a preset data format, removes invalid parameter data, constructs an initial traffic parameter set, and stores them according to parameter type differences; S22, the feature processing module of the traffic shaping strategy convolution optimization decision model is called to map the initial traffic parameter set into a multi-dimensional traffic feature matrix, where the row dimension of the matrix corresponds to the traffic parameter type and the column dimension corresponds to the parameter collection time series; S23, the model performs sliding convolution operation on the multi-dimensional traffic feature matrix through a convolution kernel of a preset size to extract traffic feature vectors of different scales, compresses the feature dimension through pooling operation, and retains the calibration feature information; S24, combined with the priority weight allocation rules of intelligent terminal security authentication, the extracted calibration feature vectors are weighted and calculated to generate a dynamic traffic shaping strategy including traffic rate limit threshold, data packet scheduling order, and data transmission delay control range.
[0017] Further, S3 includes the following sub-steps: S31, the smart terminal sends initial connection request data including terminal identification information, access request type, and authentication requirement description to the authentication server, initiating a multi-stage handshake negotiation process; S32, after receiving the initial connection request, the authentication server responds with response data including a list of authentication protocol versions, supported encryption algorithm suite information, and server identity identifier, completing the initial negotiation of protocol version and algorithm suite; S33, the smart terminal selects the appropriate authentication protocol version and encryption algorithm suite based on the server's feedback information, sends negotiation confirmation information and public key data required for session key negotiation, and the authentication server generates a session key after receiving it and encrypts it with the public key before sending it back; S34, the smart terminal decrypts to obtain the session key, sends session key verification data, and after successful verification by the authentication server, sends a handshake completion identifier and records the interaction data and negotiation results of each step.
[0018] Further, S4 includes the following sub-steps: S41, extracting interactive data from each stage of the multi-stage handshake negotiation, including request data, response data, negotiation parameter configuration information, and data transmission identifiers, and constructing a handshake data sequence in chronological order; S42, calling the hash calculation module of the handshake process integrity adaptation verification algorithm to perform segmented hash operations on the handshake data sequence, generating hash values for each segment of data and combining them into complete verification data; S43, retrieving the handshake integrity verification benchmark for the corresponding authentication scenario from the preset benchmark database for smart terminal security authentication, including the standard hash value sequence and the allowable deviation range of negotiation parameters; S44, comparing the complete verification data with the preset verification benchmark segment by segment, calculating the comparison consistency coefficient, and generating the handshake process integrity verification result based on the coefficient threshold.
[0019] Further, S5 includes the following sub-steps: S51, obtaining the hardware device identifier, operating system version information, software installation list, network access record, and historical authentication log of the smart terminal through the smart terminal authentication traffic analysis platform; S52, classifying the original identity data, assigning hardware-related data, software-related data, and behavior-related data to their corresponding feature categories, and removing duplicate and abnormal data; S53, activating the terminal identity multi-scale feature recognition model, extracting features from the classified identity data, and generating multi-scale feature vectors of hardware feature vector, software feature vector, and behavior feature vector; S54, performing dimensional normalization processing on the multi-scale feature vectors, fusing the feature vectors of each dimension into a comprehensive identity feature vector through the model's feature fusion module, and completing the preliminary identification of the terminal identity based on the comparison between the comprehensive feature vector and the preset identity feature library.
[0020] Compared with the prior art, the present invention has the following beneficial effects:
[0021] This invention proposes a smart terminal security authentication method based on traffic shaping and multi-stage handshake negotiation. It comprehensively collects core traffic parameters through a smart terminal authentication traffic analysis platform, deeply mines traffic features using a convolutional optimization decision model based on traffic shaping strategies, and generates dynamic shaping strategies. This method abandons the traditional fixed traffic control mode and can flexibly adjust traffic allocation rules according to terminal type, transmission scenario, and authentication priority, effectively avoiding traffic congestion and resource waste, and improving authentication efficiency and stability. The multi-stage handshake negotiation process fully records interaction data, and a handshake process integrity adaptation verification algorithm achieves full-process data integrity verification. Simultaneously, it activates a multi-scale feature recognition model for terminal identity to extract multi-dimensional identity features such as hardware, software, and behavior, overcoming the shortcomings of existing technologies such as single identity authentication dimensions and insufficient handshake verification. This method can accurately resist attacks such as identity forgery and data tampering, significantly improving authentication security and reliability. Finally, by integrating the traffic shaping effect, handshake verification results, and identity recognition results, an authentication conclusion is output, constructing a multi-layered, comprehensive security protection system that fully meets the high-security and high-adaptability authentication needs of smart terminals in complex network environments. Attached Figure Description
[0022] Figure 1 This is a flowchart illustrating the overall process of the method of the present invention.
[0023] Figure 2 This is a flowchart of method step S2 of the present invention;
[0024] Figure 3 This is a flowchart of method step S3 of the present invention;
[0025] Figure 4 This is a flowchart of method step S4 of the present invention;
[0026] Figure 5 This is a flowchart of step S5 of the method of the present invention. Detailed Implementation
[0027] It should be noted that, unless otherwise specified, the embodiments and features described in this application can be combined with each other. The application will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0028] like Figure 1As shown, the smart terminal security authentication method based on traffic shaping and multi-stage handshake negotiation includes the following steps: S1, collecting traffic data to be authenticated from the smart terminal through a smart terminal authentication traffic analysis platform, and extracting traffic transmission rate, data packet length distribution, data transmission interval, protocol type identifier, terminal access port information, data encryption identifier, and traffic calibration parameters; S2, calling the traffic shaping strategy convolution optimization decision model, constructing a multi-dimensional traffic feature matrix based on the collected traffic calibration parameters, performing in-depth traffic feature extraction by sliding the convolution kernel through the feature matrix, and generating a dynamic traffic shaping strategy in combination with the priority weight allocation rules of smart terminal security authentication; S3, initiating the multi-stage handshake negotiation process, in which the smart terminal and the authentication server sequentially complete the initial connection request sending, authentication protocol version confirmation, and encryption algorithm suite negotiation. S4. The handshake process is initialized through session key negotiation, and the handshake response duration, data interaction integrity identifier, and negotiation parameter consistency results of each stage are recorded synchronously. S5. The integrity adaptation and verification algorithm of the handshake process is used to verify the integrity of the interactive data generated by the multi-stage handshake negotiation, and the verification result is generated by comparing the verification data with the preset verification benchmark. S6. The terminal identity multi-scale feature recognition model is activated to extract the hardware device identifier, operating system version information, software installation feature set, historical authentication behavior trajectory, and network access feature multi-scale identity features of the smart terminal. After feature dimension normalization processing, the terminal identity is initially identified. S7. The final authentication result is output based on the combined effect of traffic shaping strategy execution, handshake integrity verification result, and terminal identity recognition result, according to the permission determination rules of smart terminal security authentication.
[0029] Step S1 involves using a smart terminal authentication traffic analysis platform to collect traffic data and extract core parameters. The platform has a built-in high-speed data capture module that supports real-time capture of authentication traffic generated when various smart terminals, such as industrial control terminals, smart home devices, and mobile office terminals, access the network. The collection frequency is set to 20 times per second to ensure coverage of traffic changes throughout the terminal's access period. During the collection process, the platform accurately extracts six core parameters from the raw traffic data. These include: traffic transmission rate, calculated by statistically analyzing the total amount of data sent and received by the terminal per unit time, ranging from 1Mbps to 1000Mbps; data packet length distribution, which statistically analyzes the minimum, maximum, and average length of a single data packet, with a minimum length of 64 bytes, a maximum length of 1500 bytes, and an average length determined by the average length of 1000 consecutive data packets; data transmission interval, recording the time difference between two adjacent data packets, and statistically analyzing 500 sets of data to form a distribution pattern; protocol type identification, which distinguishes communication protocols such as TCP, UDP, and MQTT by parsing the header fields of the data packets; terminal access port information, including the physical port number (1 to 65535) and port type; and data encryption identification, which determines the encryption status by detecting whether the data packet contains an encryption algorithm field. The comprehensive traffic parameters obtained in this step provide basic data support for subsequent traffic shaping, identity recognition, and other processes, ensuring that subsequent technical operations are based on real and valid data and guaranteeing the accuracy of the authentication process.
[0030] Step S2 calls the traffic shaping strategy convolution optimization decision model to generate a dynamic traffic shaping strategy. First, based on the six core traffic parameters collected in Step S1, a multi-dimensional traffic feature matrix with 6 rows and 1000 columns is constructed according to parameter type. Matrix elements correspond to the specific values of each parameter at different collection time points, fully presenting the temporal changes and correlations of traffic parameters. The model uses a 3×3 convolution kernel, sliding through the feature matrix with a stride of 1, extracting shallow, middle, and deep traffic features layer by layer through 10 rounds of convolution operations, retaining key feature information after each round of convolution. Combining the priority weight allocation rules of smart terminal security authentication, three priority levels are set according to application scenarios: 0.6 for industrial control terminals, 0.3 for smart home devices, and 0.1 for mobile office terminals. The extracted feature vectors are then weighted. Differentiated control schemes are formulated for terminals with different priorities. The traffic rate limit threshold for the highest priority terminals is no less than 500Mbps, and the data transmission delay is controlled within 10ms; the traffic rate threshold for medium priority terminals is no less than 200Mbps, and the delay is controlled within 50ms; the traffic rate threshold for ordinary priority terminals is no less than 100Mbps, and the delay is controlled within 100ms. Finally, a dynamic traffic shaping strategy including rate limiting, scheduling order, and delay control is generated to achieve reasonable allocation of traffic resources.
[0031] Step S3 initiates the multi-phase handshake negotiation process. The smart terminal and the authentication server sequentially complete four stages of interaction and record key data. First, the smart terminal sends an initial connection request containing 16-bit identification information, access request type, and authentication security level (basic, intermediate, advanced), once per second, repeating three times if no response is received. Within 100ms, the authentication server responds with response data containing three protocol versions (V1.0, V2.0, V3.0), eight encryption algorithm suites, and a 24-bit server identifier, confirming the protocol version. The smart terminal selects an algorithm suite based on the security level: ECC for advanced level, RSA for intermediate level, and AES for basic level, sending negotiation confirmation information and 2048-bit public key data. Within 200ms, the authentication server generates a 128-bit session key and encrypts it before sending it back. Within 300ms, the smart terminal decrypts and sends the key verification data. After successful verification, the server sends a handshake completion identifier. The entire process synchronously records the handshake response time (accurate to milliseconds), data interaction integrity identifiers, and negotiation parameter consistency results of each stage, providing comprehensive data support for subsequent integrity verification and ensuring that the handshake process is traceable and verifiable.
[0032] Step S4 uses a handshake process integrity adaptation verification algorithm to verify the interactive data. First, it extracts request data, response data, negotiation parameter configuration information, and data transmission identifiers from the four handshake stages in Step S3, constructing a complete handshake data sequence in chronological order to ensure no data omissions. Then, it calls the algorithm's hash calculation module, using the SHA-256 algorithm to perform segmented hashing on the data sequence, with each segment being 500 bytes. It calculates the 256-bit hash value for each segment and combines them in the order of the segments to form complete verification data. Finally, it retrieves the verification benchmark for the corresponding authentication scenario from a preset benchmark database. This includes a standard hash value sequence matching the number of verification data segments, and allowable deviation ranges for negotiation parameters: no deviation in protocol version number, no deviation in algorithm suite identifier, allowable deviation of key length ±0 bits, and allowable deviation of response time ±50ms. The complete verification data is compared segment by segment with the preset benchmark. The consistency coefficient (0 to 1) of each segment hash value is calculated. The average coefficient of all segments is calculated. If the average value is not lower than 0.9, the verification is considered to have passed. If it is lower than 0.9, the verification is considered to have failed. A clear verification result is generated to provide a basis for authentication decision and to ensure that the handshake data has not been tampered with.
[0033] Step S5 activates the terminal identity multi-scale feature recognition model to complete preliminary identity recognition. Five types of raw identity data are obtained through the intelligent terminal authentication traffic analysis platform: hardware device identifiers (CPU model, memory capacity from 1GB to 32GB, 16-digit hard drive serial number, 12-digit MAC address); operating system version information (system name and specific version number); software installation feature set (name, version number, and installation time of all terminal applications); historical authentication behavior trajectory records of authentication time, location, result, and network environment over the past 6 months; and network access feature statistics (common SSIDs, IP allocation methods, and access duration over the past 3 months). The raw data is classified into three categories: hardware, software, and behavior. A deduplication algorithm is used to remove duplicate records, and a threshold of 3 times the standard deviation is set to remove abnormal data. The model extracts features from the classified data, generating a 10-dimensional hardware feature vector, an 8-dimensional software feature vector, and a 12-dimensional behavioral feature vector. The three types of vectors are normalized to the range of 0 to 1, and then fused into a 30-dimensional comprehensive identity feature vector through weighted summation. This vector is then compared with the standard vector in the preset identity feature library. If the similarity is not less than 0.85, the initial identity recognition is completed, ensuring the comprehensiveness and accuracy of terminal identity recognition.
[0034] Step S6 outputs the final authentication conclusion by integrating multi-dimensional results. First, it evaluates the effectiveness of the traffic shaping strategy, statistically analyzing the traffic transmission rate compliance rate (actual rate to limit threshold ratio ≥ 0.9 is considered compliant), packet scheduling accuracy, and data transmission latency compliance rate, with weights of 0.4, 0.3, and 0.3 respectively. A weighted average is calculated to obtain an evaluation score from 0 to 100, with 80 points and above considered excellent, 60 to 79 points considered good, and below 60 points considered unqualified. The verification results (pass or fail) from Step S4 and the identity recognition results (identity confirmed or questionable) from Step S5 are collected and integrated to form an authentication evaluation dataset. According to the permission determination rules, authentication is considered successful only if three conditions are met simultaneously: a traffic shaping effect score ≥ 60 points, a successful handshake integrity verification, and terminal identity confirmation. Access permissions are granted according to priority: the highest priority terminal receives full permissions, intermediate terminals receive partial permissions, and ordinary terminals receive basic permissions. If any condition is not met, authentication fails, access is denied, and the type of unmet condition is recorded. Generate an authentication report containing the authentication result, permission level (if successful), and reason for failure (if unsuccessful), and send it back to the server and terminal. At the same time, store the report, raw data, and evaluation process data in the authentication log database for no less than one year to complete the security authentication process and ensure network access security.
[0035] Preferably, the expression for the flow shaping strategy convolution optimization decision model is: ,
[0036] in, This represents the optimal flow shaping strategy decision value. These are the model weight coefficients. This is the convolution operation function. A multidimensional flow characteristic matrix, The convolution kernel matrix, It is the Sigmoid activation function. Let i be the weighting factor for the i-th flow parameter. Let i be the standardized value of the i-th flow calibration parameter. Number of parameters to calibrate the flow rate. This is the flow regulation coefficient. As an indicator of traffic transmission stability, It is the natural logarithm function.
[0037] Specifically, the traffic shaping strategy convolutional optimization decision model is based on the multidimensional correlation of traffic features and the differentiated requirements of authentication priorities. It constructs a formula by fusing convolutional feature extraction, parameter weighting fusion, and transmission stability correction. Considering the spatial distribution characteristics of core traffic parameters, convolutional operations are used to mine deep correlations between parameters. Then, an activation function is used to perform nonlinear mapping on standardized parameters. Finally, a logarithmic function is introduced to correct the impact on traffic transmission stability, forming a multidimensional collaborative decision-making model structure. The model parameter values have been calibrated through extensive experiments. The weight coefficients are all set between 0 and 1, with the convolution operation weight coefficient set at 0.4, the activation function output weight coefficient at 0.3, and the logarithmic correction term weight coefficient at 0.3. The number of core traffic parameters is fixed at 6, corresponding to the 6 types of core parameters collected. The traffic adjustment coefficient ranges from 0.1 to 0.5 and is dynamically adjusted according to network load. The traffic transmission stability index is calculated by statistically analyzing the transmission rate variance of 1000 sets of continuous traffic data, with a value range of 0.8 to 1.0. In implementation, the collected core traffic parameters are first standardized and then input into the model. A 3×3 convolutional kernel is used to perform sliding operations on the multidimensional traffic feature matrix to extract feature mapping values. Then, the six standardized parameters are summed according to weight factors (all around 0.17) and input into the activation function. Simultaneously, the logarithmic correction value of the traffic transmission stability index is calculated. The three are then weighted and summed according to weight coefficients to obtain the optimal traffic shaping strategy decision value. This model achieves precise adaptation of the traffic shaping strategy to the terminal authentication scenario through multi-module collaborative computation, improving the dynamism and rationality of traffic control.
[0038] Preferably, the expression for the handshake process integrity adaptation verification algorithm is: ,
[0039] in, This is the handshake integrity check value. For hash operation functions, This is a collection of multi-stage handshake interaction data. For XOR operation, To preset the verification baseline hash value, For the actual negotiation parameters of the j-th handshake step, For the standard negotiation parameters of the j-th handshake step, The number of handshake steps. To verify the adaptation coefficient, As an integrity compensation factor, This serves as a validity indicator for the data interaction in the k-th handshake phase. The number of handshake data items involved in the verification.
[0040] Specifically, the handshake process integrity adaptation verification algorithm calculates the consistency between the hash characteristics of the handshake data and the negotiated parameters, combining the anti-interference ability of XOR operation, the deviation assessment capability of root mean square error, and the full-process coverage of validity identifiers. First, the handshake interaction data is converted into fixed-length feature values through hash operation. The difference features are obtained by comparing the hash value with the preset benchmark hash value using XOR operation. Then, the consistency of the parameters is assessed by calculating the root mean square error of the negotiated parameters. Finally, the validity identifier product is introduced to correct local data deviations, forming the full-process integrity verification logic. Regarding parameter values, the number of handshake stages is fixed at four, corresponding to the four core stages of the multi-stage handshake; the number of handshake data items involved in the verification is eight, including request data, response data, negotiated parameters, and other key data; the verification adaptation coefficient is set to 1.2, and the integrity compensation factor is set to 0.8, both determined to be optimal values through multiple verification experiments; the preset verification benchmark hash value is generated through the standard handshake process and is 256 bits in length; the deviation between the actual negotiated parameters and the standard negotiated parameters is calculated by comparing each parameter, with a deviation threshold set at 5%. During implementation, the handshake data set is first segmented and hashed. Each segment's hash value is then XORed with a preset baseline hash value. Next, the root mean square error (RMSE) of eight parameters across the four handshake stages is calculated. Finally, the ratio of the XOR result to the RMS error is multiplied by a verification fit coefficient, and then the product of an integrity compensation factor and a validity identifier is added to obtain the handshake integrity verification value. This algorithm, through multi-dimensional verification logic, achieves accurate assessment of data integrity during the handshake process and effectively identifies data tampering.
[0041] Preferably, the expression for the terminal identity multi-scale feature recognition model is: ,
[0042] in, For terminal identity recognition confidence level, Let x be the weight coefficient of the x-th identity feature. Let x be the extracted value of the x-th multi-scale identity feature. The number of identity feature dimensions. Let y be the difference weight of the y-th feature. Let y be the actual value of the terminal feature. This represents the average value of the terminal characteristics. For the number of dimensions of feature comparison, The hyperbolic tangent activation function is used. For feature fusion coefficients, Let z be the weighting factor for the z-th historical behavior feature. Let z be the feature value of the historical authentication behavior. The number of historical behavioral characteristics.
[0043] Specifically, the terminal identity multi-scale feature recognition model is based on the hierarchy and correlation of identity features, integrating feature weighted summation, difference assessment, and behavioral feature fusion to construct a formula. Multi-scale identity features are weighted and summed to highlight the influence of key features. Then, the effectiveness of features is assessed by calculating the difference between actual features and average features. Finally, hyperbolic tangent fusion of historical behavioral features is introduced to enhance the robustness of identity recognition, forming a model structure for multi-dimensional feature collaborative recognition. Parameter values are determined through extensive sample training. The number of identity feature dimensions is 30, including hardware, software, and behavioral features; the number of feature comparison dimensions is 20, selecting the core features with the highest recognizability; the number of historical behavioral features is 15, including key behaviors such as historical authentication time and location; the weight coefficients of each feature are between 0 and 1, with a total weight of 0.4 for hardware features, 0.3 for software features, and 0.3 for behavioral features; the feature fusion coefficient is 0.6 to ensure a reasonable contribution from historical behavioral features; the average terminal feature value is calculated by statistically analyzing the feature averages of 1000 similar terminals. In implementation, 30-dimensional multi-scale identity features are first extracted and weighted by coefficients. Then, the difference between the 20-dimensional core features and their corresponding average values is calculated. The degree of difference is assessed using weighted root mean square error. Simultaneously, 15 historical behavioral features are weighted and summed before being input into a hyperbolic tangent function. The ratio of the feature summation result to the difference assessment result is multiplied by the hyperbolic tangent output value to obtain the terminal identity recognition confidence level. This model achieves accurate terminal identity recognition and improves the reliability of identity authentication through multi-scale feature fusion and difference assessment.
[0044] Preferably, the traffic parameter acquisition model expression of the intelligent terminal authentication traffic analysis platform is: ,
[0045] in, The overall results of the flow parameter collection, This is the data acquisition accuracy coefficient. Let t be the time weight of the t-th collection period. This is the raw traffic data for the t-th time period. Number of data collection periods For data integration coefficients, Let u be the acquisition sensitivity coefficient of the u-th parameter. Let u be the original collected value of the u-th flow parameter. This represents the total number of traffic parameters collected.
[0046] Specifically, the traffic parameter acquisition model of the intelligent terminal authentication traffic analysis platform is based on the temporal correlation of multi-time period data and the sensitivity requirements of parameter acquisition. It integrates time-series weighted summation and nonlinear correction of the Sigmoid function to construct the formula. The raw traffic data from different time periods are weighted and summed to highlight the importance of data from key time periods. Then, the Sigmoid function is used to nonlinearly correct the acquired parameter values, compensating for sensitivity differences during the acquisition process, thus forming an acquisition model that synergistically optimizes temporal and sensitivity aspects. Regarding parameter values, the number of data collection periods was set to 10, with each period lasting 1 second, covering traffic data within 10 seconds. A total of 6 traffic parameters were collected, corresponding to core traffic parameters. The collection accuracy coefficient was set to 0.95 to ensure data collection accuracy. The time weights for each period were allocated according to the collection sequence, with more recent periods having higher weights, ranging from 0.05 to 0.2. The data integration coefficient was set to 0.8 to balance the contribution of time-series summation and sensitivity correction. The collection sensitivity coefficients for each parameter were set according to their importance: the traffic transmission rate sensitivity coefficient was 0.3, the data packet length distribution was 0.2, and the remaining parameters were all 0.1. During implementation, the raw traffic data from the 10 periods were first weighted and summed according to time weights. Then, the raw collected values of the 6 traffic parameters were multiplied by their corresponding sensitivity coefficients and input into the Sigmoid function to calculate the correction values for each parameter and multiply them. Finally, the time-series weighted sum was multiplied by the collection accuracy coefficient, and the product of the data integration coefficient and the correction value was added to obtain the comprehensive result of the traffic parameter collection. This model improves the accuracy and stability of traffic parameter collection through time series optimization and sensitivity correction, providing reliable data support for subsequent certification processes.
[0047] Preferably, the permission determination model expression for the smart terminal security authentication is: ,
[0048] in, This is the final authentication result value. Weighting coefficients for permission determination. Let w be the error value of the w-th authentication step. The number of certification error assessment steps, is the weighting factor for the w-th error evaluation stage.
[0049] Specifically, the permission determination model for smart terminal security authentication is based on the synergy of multi-stage authentication results and the necessity of error assessment. It integrates the weighted summation of results from each stage with error correction to construct a formula. First, the traffic shaping decision value, handshake verification value, and identity recognition confidence are weighted and integrated to highlight the impact of core authentication stages. Then, the authentication deviation is corrected by calculating the sum of squared errors of each authentication stage, forming a multi-stage collaborative and error-corrected permission determination logic. The parameter values were determined through extensive testing in various authentication scenarios. The weight coefficients for permission determination are all between 0 and 1, the weight for traffic shaping decision value is 0.3, the weight for handshake verification value is 0.4, the weight for identity recognition confidence is 0.2, and the weight for error correction is 0.1. There are 5 authentication error assessment stages, including traffic collection, feature extraction, handshake negotiation, integrity verification, and identity recognition. The weight factors for each error assessment stage are allocated according to the degree of error impact: traffic collection error weight is 0.2, feature extraction error weight is 0.2, handshake negotiation error weight is 0.2, integrity verification error weight is 0.2, and identity recognition error weight is 0.2. The error value for each stage is calculated by the deviation between the actual result and the standard result, and the value range is 0 to 0.1. In implementation, the optimal decision value for traffic shaping, the handshake integrity verification value, and the terminal identity recognition confidence level are first multiplied by their corresponding weight coefficients and summed. Then, the sum of the squared errors of the five authentication steps multiplied by their corresponding weight factors is calculated, the square root is multiplied by the error correction weight, and the correction value is subtracted from the sum of the previous steps to obtain the final authentication result. This model achieves accurate determination of authentication permissions through multi-step collaboration and error correction, improving the comprehensiveness and reliability of security authentication.
[0050] Preferred, such as Figure 2 As shown, S2 includes the following sub-steps: S21, the intelligent terminal authentication traffic analysis platform organizes the collected traffic calibration parameters according to a preset data format, removes invalid parameter data, constructs an initial traffic parameter set, and stores them according to the differences in parameter types; S22, the feature processing module of the traffic shaping strategy convolution optimization decision model is called to map the initial traffic parameter set into a multi-dimensional traffic feature matrix, where the row dimension of the matrix corresponds to the traffic parameter type and the column dimension corresponds to the parameter collection time series; S23, the model performs sliding convolution operation on the multi-dimensional traffic feature matrix through a convolution kernel of a preset size to extract traffic feature vectors of different scales, compresses the feature dimension through pooling operation, and retains the calibration feature information; S24, combined with the priority weight allocation rules of intelligent terminal security authentication, the extracted calibration feature vectors are weighted and calculated to generate a dynamic traffic shaping strategy including traffic rate limit threshold, data packet scheduling order, and data transmission delay control range.
[0051] Specifically, step S2 achieves accurate generation of the dynamic traffic shaping strategy through four consecutive operations. In sub-step S21, the intelligent terminal authentication traffic analysis platform organizes the six types of core traffic parameters collected in step S1 according to a preset format, uses a data cleaning mechanism to remove invalid data that exceeds the normal value range or is missing key fields, and then stores them according to parameter type, using a partitioned storage mode to ensure efficient data retrieval. In sub-step S22, the feature processing module of the traffic shaping strategy convolution optimization decision model is called to map the initial traffic parameter set into a multi-dimensional traffic feature matrix with 6 rows and 1000 columns, fully preserving temporal features and correlations. In sub-step S23, the model uses a 3×3 convolution kernel with a stride of 1 for sliding convolution, extracting key features through 10 rounds of convolution and 2×2 max pooling, reducing computational complexity. In step S24, a weighted calculation is performed based on the three-level priority weight allocation rules (0.6 for industrial control terminals, 0.3 for smart home devices, and 0.1 for mobile office terminals) to generate a dynamic strategy that includes rate limit thresholds (maximum ≥500Mbps, intermediate ≥200Mbps, and normal ≥100Mbps), scheduling order, and latency control range (maximum ≤10ms, intermediate ≤50ms, and normal ≤100ms). This ensures that traffic management is accurately matched with terminal type and authentication requirements, improving its targeting and effectiveness.
[0052] Preferred, such as Figure 3 As shown, step S3 includes the following sub-steps: S31, the smart terminal sends initial connection request data, including terminal identification information, access request type, and authentication requirement description, to the authentication server to initiate a multi-stage handshake negotiation process; S32, after receiving the initial connection request, the authentication server sends response data, including a list of authentication protocol versions, supported encryption algorithm suite information, and server identity identifier, completing the initial negotiation of protocol version and algorithm suite; S33, the smart terminal selects the appropriate authentication protocol version and encryption algorithm suite based on the server's feedback information, sends negotiation confirmation information and public key data required for session key negotiation, and the authentication server generates a session key and sends it back after encrypting it with the public key; S34, the smart terminal decrypts and obtains the session key, sends session key verification data, and after successful verification, the authentication server sends a handshake completion identifier and records the interaction data and negotiation results of each step.
[0053] Specifically, step S3, the multi-phase handshake negotiation process, is broken down into four steps, fully covering the entire process. It clarifies technical parameters, interaction logic, and implementation details, ensuring orderliness and data integrity. In step S31, after the smart terminal accesses the network, it sends an initial connection request once per second, containing a 16-bit identifier, access type, and three security levels. If there is no response, the request is repeated three times before termination. In step S32, the authentication server responds within 100ms with response data containing three protocol versions, eight encryption algorithm suites, and a 24-bit server identifier. The smart terminal completes the initial negotiation after compatibility testing. In step S33, the smart terminal selects an algorithm suite (Advanced ECC, Intermediate RSA, Basic AES) according to the security level, sends a negotiation confirmation message and a 2048-bit public key, and the authentication server generates a 128-bit session key and provides encrypted feedback within 200ms. In step S34, the smart terminal decrypts and sends the key verification data within 300ms. After the server verifies the data, it sends a handshake completion flag. The response time (accurate to milliseconds), integrity flag, and parameter consistency results of each step are recorded simultaneously to provide comprehensive and accurate data support for subsequent verification and ensure that the handshake process is traceable and verifiable.
[0054] Preferred, such as Figure 4 As shown, step S4 includes the following sub-steps: S41, extracting interactive data from each stage of the multi-stage handshake negotiation, including request data, response data, negotiation parameter configuration information, and data transmission identifier, and constructing a handshake data sequence in chronological order; S42, calling the hash calculation module of the handshake process integrity adaptation verification algorithm to perform segmented hash operations on the handshake data sequence, generating hash values for each segment of data and combining them into complete verification data; S43, retrieving the handshake integrity verification benchmark for the corresponding authentication scenario from the preset benchmark database for smart terminal security authentication, including the standard hash value sequence and the allowable deviation range of negotiation parameters; S44, comparing the complete verification data with the preset verification benchmark segment by segment, calculating the comparison consistency coefficient, and generating the handshake process integrity verification result based on the coefficient threshold.
[0055] Specifically, step S4, the handshake process integrity verification, is divided into four steps: data extraction, verification data generation, benchmark retrieval, and comparison verification. Clear technical parameters, operational standards, and implementation methods are defined to achieve comprehensive verification. In step S41, request data, response data, negotiation parameters, and transmission identifiers are extracted from the four handshake stages in step S3, and a complete data sequence is constructed sequentially to ensure no omissions. In step S42, the hash calculation module of the handshake process integrity adaptation verification algorithm is called, using the SHA-256 algorithm to hash in 500-byte segments, generating 256-bit segmented hash values, which are then combined into complete verification data. In step S43, a preset verification benchmark is retrieved according to the authentication scenario, including the standard hash value sequence and the allowable deviation range of the negotiation parameters (no deviation in protocol version and algorithm suite, key length deviation ±0 bits, response time deviation ±50ms). In step S44, the complete verification data is compared with the benchmark segment by segment, the consistency coefficient between 0 and 1 is calculated, and the mean is calculated to be ≥0.9 to pass and <0.9 to fail. A verification report is generated, and the accuracy of the verification is ensured by quantitative standards and strict thresholds, effectively identifying data tampering behavior.
[0056] Preferred, such as Figure 5 As shown, step S5 includes the following sub-steps: S51, obtaining the hardware device identifier, operating system version information, software installation list, network access record, and historical authentication log of the smart terminal through the smart terminal authentication traffic analysis platform; S52, classifying the original identity data, assigning hardware-related data, software-related data, and behavior-related data to their corresponding feature categories, and removing duplicate and abnormal data; S53, activating the terminal identity multi-scale feature recognition model, extracting features from the classified identity data, and generating multi-scale feature vectors of hardware feature vector, software feature vector, and behavior feature vector; S54, performing dimensional normalization processing on the multi-scale feature vectors, fusing the feature vectors of each dimension into a comprehensive identity feature vector through the model's feature fusion module, and completing the preliminary identification of the terminal identity based on the comparison between the comprehensive feature vector and the preset identity feature library.
[0057] Specifically, step S5, terminal identity multi-scale feature recognition, is broken down into four steps: data acquisition, classification processing, feature extraction, feature fusion, and recognition. The technical parameters, processing standards, and implementation details are clearly defined to achieve comprehensive and accurate recognition. In step S51, five types of raw identity data are acquired through a dedicated acquisition interface, including hardware device identifiers (CPU model, 1GB-32GB memory, 16-digit hard drive serial number, 12-digit MAC address), operating system version, software installation feature set, 6 months of historical authentication trajectory, and 3 months of network access features. The interface supports multiple protocols to ensure effective data acquisition. In step S52, the data is classified into three categories: hardware, software, and behavior. A deduplication algorithm is used to remove duplicate records, and anomalies are removed using a threshold of 3 times the standard deviation to ensure data accuracy and purity. In step S53, the terminal identity multi-scale feature recognition model is activated, and after discretization and normalization, 10-dimensional hardware, 8-dimensional software, and 12-dimensional behavior feature vectors are generated. In step S54, the three types of vectors are normalized to the 0-1 interval, and then fused into a 30-dimensional comprehensive feature vector through weighted summation. This vector is then compared with a preset feature library, and if the similarity is ≥0.85, preliminary identification is completed, ensuring comprehensive and accurate identity recognition.
[0058] The formula in this invention integrates different scalar and vector parameters for calculation. It eliminates parameter type differences through standardization, weight allocation, and dimension adaptation mechanisms, achieving collaborative computation of multi-dimensional data. First, all parameters undergo unified standardization. Vector parameters (such as multi-dimensional traffic feature matrices and multi-scale identity feature vectors) are transformed into one-dimensional values through feature extraction, pooling, or fusion. Scalar parameters (such as traffic transmission stability indicators and handshake response time) are directly normalized, ensuring that the value range of all parameters is unified within the 0-1 range. For example, a 10-dimensional hardware feature vector is transformed into a single feature value through weighted summation, placing it on the same numerical dimension as the scalar traffic adjustment coefficient. Second, scientific weight allocation clarifies the contribution of different types of parameters. For instance, in the traffic shaping strategy model, the vector transformation value output by convolution is assigned a weight of 0.4, while the standardized scalar parameter is assigned a weight of 0.3, ensuring that different types of parameters play a reasonable role in the formula. Finally, dimensionality adaptation is achieved through nonlinear mapping functions (such as activation functions and logarithmic functions), organically fusing the deep features extracted from vectors with the basic scalar indicators. For example, in the terminal identity recognition model, the fused value of the multi-dimensional feature vectors and the mean difference of scalar features are computationally compatible through function mapping. This design retains the multi-dimensional correlation information of vector parameters while leveraging the quantitative representation role of scalar parameters, achieving effective synergy between different types of parameters and ensuring the rationality of formula calculations and the reliability of results.
[0059] This intelligent terminal security authentication method, based on traffic shaping and multi-stage handshake negotiation, constructs a multi-dimensional collaborative authentication system. Through technological integration, it achieves a dual improvement in authentication security and adaptability. It utilizes a dedicated traffic analysis platform to comprehensively capture various traffic parameters of terminal access, and deeply mines traffic characteristics through targeted decision models to generate dynamically adaptable traffic shaping strategies. This breaks the limitations of traditional fixed traffic control, allowing for flexible adjustment of traffic allocation based on terminal type, transmission scenario, and authentication priority. This avoids traffic congestion affecting authentication efficiency and eliminates resource waste, fully adapting to diverse traffic needs in complex network environments. Simultaneously, the multi-stage handshake negotiation process comprehensively covers key stages such as connection request, protocol confirmation, algorithm negotiation, and key initialization. Coupled with a dedicated integrity verification mechanism, it achieves end-to-end data verification. Furthermore, by combining multi-scale terminal identity feature recognition, it comprehensively verifies terminal identity from multiple dimensions, including hardware, software, and behavior, significantly improving authentication accuracy.
[0060] This method addresses the lack of dynamic adaptability in traditional traffic management by abandoning fixed restriction models and generating dynamic shaping strategies based on comprehensively collected traffic parameters. This enables the rational allocation of traffic resources and significantly improves authentication efficiency and stability. Furthermore, it addresses the shortcomings of existing technologies, such as single-dimensional identity authentication and insufficient handshake verification. Through multi-stage handshake negotiation, it fully records interaction data and performs end-to-end integrity verification. Simultaneously, it fully leverages multi-dimensional terminal feature information for comprehensive identity recognition, effectively resisting attacks such as identity forgery and data tampering, and significantly enhancing authentication security and reliability. This multi-technology collaborative, end-to-end management design constructs a multi-layered security barrier, fully meeting the high-security and highly adaptable authentication needs of smart terminals.
[0061] In the description of this invention, it should be noted that, unless otherwise explicitly specified and limited, the terms "set," "install," "connect," "link," and "fix" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral connection; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; and they can refer to the internal communication between two components. Those skilled in the art will understand the specific meaning of the above terms in this invention based on the specific circumstances.
[0062] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various equivalent changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A smart terminal security authentication method based on traffic shaping and multi-stage handshake negotiation, characterized in that, Includes the following steps: S1 collects traffic data of smart terminals to be authenticated through the smart terminal authentication traffic analysis platform, and extracts traffic transmission rate, data packet length distribution, data transmission interval, protocol type identifier, terminal access port information, data encryption identifier traffic calibration parameters; S2, invoke the traffic shaping strategy convolution optimization decision model, construct a multi-dimensional traffic feature matrix based on the collected traffic calibration parameters, perform in-depth traffic feature extraction by sliding the convolution kernel through the feature matrix, and generate a dynamic traffic shaping strategy by combining the priority weight allocation rules of smart terminal security authentication. S3, initiate the multi-stage handshake negotiation process. The smart terminal and the authentication server sequentially complete the initial connection request sending, authentication protocol version confirmation, encryption algorithm suite negotiation, and session key negotiation initial handshake phase, and synchronously record the handshake response duration, data interaction integrity identifier, and negotiation parameter consistency result of each phase. S4 employs a handshake process integrity adaptation verification algorithm to perform integrity verification on the interactive data generated by multi-stage handshake negotiation, and generates verification results by comparing the verification data with a preset verification benchmark. S5 activates the terminal identity multi-scale feature recognition model, extracts the hardware device identifier, operating system version information, software installation feature set, historical authentication behavior trajectory, and network access feature of the smart terminal, and completes the initial identification of the terminal identity after feature dimension normalization. S6 integrates the execution effect of the traffic shaping strategy, the handshake integrity verification result, and the terminal identity recognition result, and outputs the final authentication result based on the permission determination rules of smart terminal security authentication.
2. The smart terminal security authentication method based on traffic shaping and multi-stage handshake negotiation according to claim 1, characterized in that, The expression for the convolution optimization decision model of the flow shaping strategy is: , in, This represents the optimal flow shaping strategy decision value. These are the model weight coefficients. This is the convolution operation function. A multidimensional flow characteristic matrix, The convolution kernel matrix, It is the Sigmoid activation function. Let i be the weighting factor for the i-th flow parameter. Let i be the standardized value of the i-th flow calibration parameter. Number of parameters to calibrate the flow rate. This is the flow regulation coefficient. As an indicator of traffic transmission stability, It is the natural logarithm function.
3. The smart terminal security authentication method based on traffic shaping and multi-stage handshake negotiation according to claim 2, characterized in that, The expression for the handshake process integrity adaptation verification algorithm is: , in, This is the handshake integrity check value. For hash operation functions, This is a collection of multi-stage handshake interaction data. For XOR operation, To preset the verification baseline hash value, For the actual negotiation parameters of the j-th handshake step, For the standard negotiation parameters of the j-th handshake step, The number of handshake steps. To verify the adaptation coefficient, As an integrity compensation factor, This serves as a validity indicator for the data interaction in the k-th handshake phase. The number of handshake data items involved in the verification.
4. The smart terminal security authentication method based on traffic shaping and multi-stage handshake negotiation according to claim 3, characterized in that, The expression for the terminal identity multi-scale feature recognition model is: , in, For terminal identity recognition confidence level, Let x be the weight coefficient of the x-th identity feature. Let x be the extracted value of the x-th multi-scale identity feature. The number of identity feature dimensions. Let y be the difference weight of the y-th feature. Let y be the actual value of the terminal feature. This represents the average value of the terminal characteristics. For the number of dimensions of feature comparison, The hyperbolic tangent activation function is used. For feature fusion coefficients, Let z be the weighting factor for the z-th historical behavior feature. Let z be the feature value of the historical authentication behavior. The number of historical behavioral characteristics.
5. The smart terminal security authentication method based on traffic shaping and multi-stage handshake negotiation according to claim 4, characterized in that, The traffic parameter acquisition model expression of the intelligent terminal authentication traffic analysis platform is as follows: , in, The overall results of the flow parameter collection, This is the data acquisition accuracy coefficient. Let t be the time weight of the t-th collection period. This is the raw traffic data for the t-th time period. Number of data collection periods For data integration coefficients, Let u be the acquisition sensitivity coefficient of the u-th parameter. Let u be the original collected value of the u-th flow parameter. This represents the total number of traffic parameters collected.
6. The smart terminal security authentication method based on traffic shaping and multi-stage handshake negotiation according to claim 5, characterized in that, The permission determination model expression for the smart terminal security authentication is as follows: , in, This is the final authentication result value. Weighting coefficients for permission determination. Let w be the error value of the w-th authentication step. The number of certification error assessment steps, is the weighting factor for the w-th error evaluation stage.
7. The smart terminal security authentication method based on traffic shaping and multi-stage handshake negotiation according to claim 6, characterized in that, S2 includes the following steps: S21, the intelligent terminal authentication traffic analysis platform organizes the collected traffic calibration parameters according to the preset data format, removes invalid parameter data, constructs an initial traffic parameter set, and stores them according to the differences in parameter types; S22, call the feature processing module of the traffic shaping strategy convolution optimization decision model to map the initial traffic parameter set into a multi-dimensional traffic feature matrix, where the row dimension of the matrix corresponds to the traffic parameter type and the column dimension corresponds to the parameter collection time series; S23, the model performs sliding convolution operation on the multidimensional flow feature matrix through convolution kernels of preset size to extract flow feature vectors of different scales, and compresses the feature dimension while retaining the calibration feature information through pooling operation; S24, combining the priority weight allocation rules of smart terminal security authentication, performs weighted calculation on the extracted calibration feature vector to generate a dynamic traffic shaping strategy that includes traffic rate limit threshold, data packet scheduling order, and data transmission delay control range.
8. The smart terminal security authentication method based on traffic shaping and multi-stage handshake negotiation according to claim 7, characterized in that, S3 includes the following steps: S31, the smart terminal sends initial connection request data, including terminal identification information, access request type, and authentication requirement description, to the authentication server to initiate the multi-stage handshake negotiation process; S32, after receiving the initial connection request, the authentication server sends back response data including a list of authentication protocol versions, information on supported encryption algorithm suites, and server identity identifier, completing the initial negotiation of protocol versions and algorithm suites; S33, the smart terminal selects the appropriate authentication protocol version and encryption algorithm suite based on the server feedback information, sends negotiation confirmation information and public key data required for session key negotiation, and the authentication server generates a session key and sends it back after encrypting it with the public key; S34, the smart terminal decrypts and obtains the session key, sends session key verification data, and after the authentication server verifies the key, it sends a handshake completion flag and records the interaction data and negotiation results of each step.
9. The smart terminal security authentication method based on traffic shaping and multi-stage handshake negotiation according to claim 8, characterized in that, S4 includes the following sub-steps: S41, extract interactive data from each stage of the multi-phase handshake negotiation, including request data, response data, negotiation parameter configuration information, and data transmission identifier, and construct a handshake data sequence in chronological order; S42, call the hash calculation module of the handshake process integrity adaptation verification algorithm to perform segmented hash operation on the handshake data sequence, generate the hash value of each segment of data and combine them into complete verification data; S43, retrieve the handshake integrity verification benchmark for the corresponding authentication scenario from the preset benchmark database of smart terminal security authentication, including the standard hash value sequence and the allowable deviation range of negotiation parameters; S44 compares the complete verification data with the preset verification benchmark segment by segment, calculates the comparison consistency coefficient, and generates the handshake process integrity verification result based on the coefficient threshold.
10. The smart terminal security authentication method based on traffic shaping and multi-stage handshake negotiation according to claim 9, characterized in that, S5 includes the following steps: S51 obtains the hardware device identifier, operating system version information, software installation list, network access record, and original identity data of the smart terminal through the smart terminal authentication traffic analysis platform; S52, classify the original identity data, and classify hardware-related data, software-related data, and behavioral-related data into their respective feature categories, and remove duplicate and abnormal data; S53 activates the terminal identity multi-scale feature recognition model, extracts features from the classified identity data, and generates multi-scale feature vectors including hardware feature vectors, software feature vectors, and behavioral feature vectors. S54 performs dimensionality normalization on the multi-scale feature vectors, and then merges the feature vectors of each dimension into a comprehensive identity feature vector through the feature fusion module of the model. Based on the comparison between the comprehensive feature vector and the preset identity feature library, the initial identification of the terminal identity is completed.