Terminal non-perception authentication method, device, system and electronic equipment
Patent Information
- Application Number
- CN202610935076.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-06-26
- Publication Date
- 2026-09-22
AI Technical Summary
[0006]有鉴于此,有必要提供一种终端无感知认证方法、装置、系统及电子设备,用以解决现有的无感知认证方案容易出现设备识别失效、识别准确率低、误判率高的技术问题
[0017]采用上述实现方式的有益效果是:本发明提供的终端无感知认证方法、装置、系统及电子设备,抓取目标终端的入网报文,基于所述入网报文确定目标终端的MAC类型,在所述MAC类型为随机MAC的情况下,基于智能体无感知采集目标终端的多维度入网特征,本发明针对目标终端的随机MAC,基于智能体无感知采集目标终端的多维度入网特征,并对预处理后的多维度入网特征进行加权融合,生成加密设备指纹,并结合目标终端运行环境生成的辅助标识,构建双因子标识,进而基于双因子标识进行检索和合法性认证,解决了现有无感知认证特征表征维度单一、过度依赖固有MAC地址、易被终端随机MAC绕过、泛化能力弱、设备溯源困难的技术问题。基于双因子标识的认证方式,有效解决了终端MAC随机化、设备伪装对抗导致的认证失效问题。综上,本发明解决了现有的无感知认证方案容易出现设备识别失效、识别准确率低、误判率高的技术问题。
Smart Images

Figure CN122802218A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, specifically to a terminal-invisible authentication method, device, system, and electronic device. Background Technology
[0002] Seamless authentication is a core network security mechanism that optimizes the user network access experience and reduces operational burden in local area network scenarios such as enterprises, campuses, and industrial parks. Traditional seamless authentication solutions heavily rely on the physical MAC address (Media Access Control Address, also known as the LAN address) that is permanently assigned to the device at the factory as a unique identifier for the terminal. After the terminal completes the Portal authentication for the first time, the device binds the account to the physical MAC address. When the terminal accesses the network subsequently, it can be automatically allowed by simply matching the MAC address, without requiring the user to authenticate again.
[0003] With the iterative upgrades of privacy and security mechanisms in mobile terminal systems, mainstream operating systems such as iOS, Android, Windows, and macOS all enable random MAC address generation by default. Each time a terminal initiates a network access request, a new temporary random MAC address is dynamically generated, replacing the fixed physical MAC address for network access. While this mechanism effectively protects user network privacy, it completely disrupts the traditional authentication logic centered on fixed MAC addresses, leading to frequent failures of seamless authentication and a shift from seamless to conscious authentication. Users are required to repeatedly perform Portal authentication, significantly reducing the network access experience and greatly increasing the workload of network maintenance personnel.
[0004] Currently, the mainstream optimization solutions for authentication failure caused by random MAC addresses in the industry mostly use a single UUID (Universally Unique Identifier) to assist in identification and fixed policy whitelists to compensate for the defects. However, existing technologies have obvious shortcomings: First, UUIDs are easily affected by system upgrades, browser version updates, terminal configuration modifications, and changes in the network environment, resulting in poor stability and a high likelihood of device identification failure. Second, static policy configurations have weak generalization capabilities and cannot adapt to massive heterogeneous terminals and complex and ever-changing network access scenarios, resulting in low identification accuracy and high false positive rates.
[0005] In summary, existing seamless authentication solutions are prone to problems such as device recognition failure, low recognition accuracy, and high false positive rate. Summary of the Invention
[0006] In view of this, it is necessary to provide a terminal-invisible authentication method, device, system and electronic device to solve the technical problems of existing non-invisible authentication schemes, such as device recognition failure, low recognition accuracy and high false judgment rate.
[0007] To address the aforementioned problems, in a first aspect, the present invention provides a terminal-invisible authentication method, comprising: Capture the network access packets of the target terminal, determine the MAC type of the target terminal based on the network access packets, and if the MAC type is a random MAC, collect multi-dimensional network access features of the target terminal without the agent's perception. The multi-dimensional network access features are preprocessed, and the preprocessed multi-dimensional network access features are weighted and fused to obtain fused features. An encrypted device fingerprint is generated based on the fused features, and an auxiliary identifier is generated based on the target terminal operating environment. A two-factor identifier is generated based on the encrypted device fingerprint and the auxiliary identifier. The authentication database is matched and searched based on the two-factor identifier, and the target terminal is determined to be a legitimate terminal based on the search results. If it is determined that the target terminal is not a legitimate terminal, Portal authentication is performed on the target terminal. After the Portal authentication is successful, the two-factor identifier, the random MAC, and the account information of the target terminal are associated and bound together, and the bound information is stored in the authentication database.
[0008] In one possible implementation, determining the MAC type of the target terminal based on the network access packet includes: The incoming network packets are subjected to protocol bit verification, OUI vendor library matching verification, and behavior timing verification, and the MAC type of the target terminal is determined based on the results of the protocol bit verification, OUI vendor library matching verification, and behavior timing verification.
[0009] In one possible implementation, the multi-dimensional network entry features include: link layer features, network layer and transport layer features, application layer features, hardware rendering features, and behavioral timing features.
[0010] In one possible implementation, the terminal-invisible authentication method preprocesses the multi-dimensional network access features, performs weighted fusion of the preprocessed multi-dimensional network access features to obtain fused features, and generates an encrypted device fingerprint based on the fused features, including: The multi-dimensional network entry features are subjected to noise reduction, deduplication, and normalization to obtain preprocessed multi-dimensional network entry features; The preprocessed multi-dimensional network access features are weighted and fused to obtain the fused features; The fused features are encrypted using the SM3 hash algorithm to generate an encrypted device fingerprint.
[0011] In one possible implementation, the terminal-invisible authentication method also includes: Collect all access data from the terminal and iteratively optimize the agent based on the all access data.
[0012] In one possible implementation, the terminal-invisible authentication method also includes: Based on the target terminal's device information, user information, and network information, match security protection strategies; If the target terminal is determined to have no abnormal risks based on the security protection strategy, the effective session state of the target terminal is maintained and the network access permissions of the target terminal are opened. If the security protection strategy determines that the target terminal has an abnormal risk, tiered protection actions are performed on the target terminal; the tiered protection actions include: performing secondary authentication to determine whether the target terminal is a legitimate terminal, traffic restriction, or blocking access.
[0013] In one possible implementation, the terminal-invisible authentication method also includes: Audit the entire process of data accessed by the target terminal and generate operation logs for the target terminal; After the target terminal is authenticated by Portal and audited, restore the network packet labels of the target terminal.
[0014] Secondly, the present invention also provides a terminal-invisible authentication device, comprising: The feature acquisition module is used to capture the network access packets of the target terminal, determine the MAC type of the target terminal based on the network access packets, and, in the case that the MAC type is a random MAC, collect multi-dimensional network access features of the target terminal without the agent's perception. The identifier generation module is used to preprocess the multi-dimensional network access features, perform weighted fusion on the preprocessed multi-dimensional network access features to obtain fused features, generate an encrypted device fingerprint based on the fused features, generate an auxiliary identifier based on the target terminal operating environment, and generate a two-factor identifier based on the encrypted device fingerprint and the auxiliary identifier. The legitimacy determination module is used to perform matching and retrieval of the authentication database based on the dual-factor identifier, and determine whether the target terminal is a legitimate terminal based on the retrieval results; The authentication binding module is used to perform Portal authentication on the target terminal when it is determined that the target terminal is not a legitimate terminal. After the Portal authentication is successful, the two-factor identifier, the random MAC, and the account information of the target terminal are associated and bound together, and the bound information is stored in the authentication database.
[0015] Thirdly, the present invention also provides an electronic device, including a memory and a processor, wherein, The memory is used to store programs; The processor, coupled to the memory, is used to execute the program stored in the memory to implement the steps of the terminal-invisible authentication method described in any of the above-described methods.
[0016] Fourthly, the present invention also provides a terminal-invisible authentication system, comprising: the aforementioned electronic device, and a target terminal communicatively connected to the electronic device.
[0017] The beneficial effects of the above implementation method are as follows: The terminal-invisible authentication method, device, system, and electronic device provided by the present invention capture the network access packet of the target terminal, determine the MAC type of the target terminal based on the network access packet, and when the MAC type is random MAC, collect multi-dimensional network access features of the target terminal based on the intelligent agent's non-perceptive collection. The present invention targets the random MAC of the target terminal, collects multi-dimensional network access features of the target terminal based on the intelligent agent's non-perceptive collection, and performs weighted fusion on the preprocessed multi-dimensional network access features to generate an encrypted device fingerprint. Combined with the auxiliary identifier generated by the target terminal's operating environment, a two-factor identifier is constructed. Then, retrieval and legality authentication are performed based on the two-factor identifier. This solves the technical problems of existing non-perceptive authentication methods, such as single feature representation dimensions, over-reliance on inherent MAC addresses, susceptibility to being bypassed by terminal random MAC, weak generalization ability, and difficulty in device traceability. The authentication method based on the two-factor identifier effectively solves the authentication failure problem caused by terminal MAC randomization and device spoofing. In summary, the present invention solves the technical problems of existing non-perceptive authentication schemes, such as easy device identification failure, low identification accuracy, and high false judgment rate. Attached Figure Description
[0018] To more clearly illustrate the technical solutions in the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1 A flowchart of an embodiment of the terminal-invisible authentication method provided by the present invention; Figure 2 A schematic block diagram of an embodiment of the terminal-invisible authentication device provided by the present invention; Figure 3 A flowchart of another embodiment of the terminal-invisible authentication method provided by the present invention; Figure 4 A schematic diagram of an embodiment of the electronic device provided by the present invention. Detailed Implementation
[0020] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. All other embodiments obtained by those skilled in the art based on the embodiments of the present invention without creative effort are within the scope of protection of the present invention.
[0021] In the description of the embodiments of this application, unless otherwise stated, "a plurality of" means two or more.
[0022] In this embodiment of the invention, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion, for example, a process, method, apparatus, product or device that includes a series of steps or modules is not necessarily limited to those steps or modules that are explicitly listed, but may include other steps or modules that are not explicitly listed or that are inherent to such process, method, product or device.
[0023] The naming or numbering of steps in the embodiments of the present invention does not mean that the steps in the method flow must be executed in the time / logical order indicated by the naming or numbering. The execution order of the named or numbered process steps can be changed according to the technical purpose to be achieved, as long as the same or similar technical effect can be achieved.
[0024] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of the invention. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a mutually exclusive, independent, or alternative embodiment. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0025] This invention provides a terminal-invisible authentication method, device, system, and electronic device, which are described below.
[0026] This invention provides a terminal-invisible authentication method, such as... Figure 1 As shown, the method includes: S101. Capture the network access message of the target terminal, determine the MAC type of the target terminal based on the network access message, and if the MAC type is a random MAC, collect the multi-dimensional network access characteristics of the target terminal without the agent's perception.
[0027] Understandably, seamless authentication refers to a lightweight network access authentication mechanism where, after a terminal completes its first Portal authentication, the network security device automatically records and binds the terminal's trusted identifier. This eliminates the need for the terminal to repeatedly enter its account and password when accessing the network subsequently, allowing for automatic identity verification and access control. This approach balances network security with user access experience.
[0028] Random MAC refers to a privacy protection mechanism enabled by default in mainstream terminal operating systems (iOS, Android, Windows, macOS). When a terminal connects to a wireless network, it dynamically generates a temporary virtual MAC address to replace the physical MAC address that is fixed at the factory. Although it can protect user privacy, it directly causes the traditional seamless authentication mechanism based on fixed MAC to become completely ineffective.
[0029] The AI (Artificial Intelligence) agent in this invention is the core scheduling and decision-making unit. It is an integrated authentication and decision-making unit that can collect multi-dimensional terminal features without being noticed, encrypt device fingerprint modeling, make intelligent matching decisions, optimize incremental self-learning, and schedule full-process business. It coordinates the collaborative work of all functional modules.
[0030] S102. The multi-dimensional network access features are preprocessed, and the preprocessed multi-dimensional network access features are weighted and fused to obtain fused features. An encrypted device fingerprint is generated based on the fused features, and an auxiliary identifier is generated based on the target terminal operating environment. A two-factor identifier is generated based on the encrypted device fingerprint and the auxiliary identifier.
[0031] It is understandable that device fingerprinting refers to a unique, stable, and unforgeable terminal device identifier generated by an AI agent based on stable features from multiple dimensions such as the terminal link layer, network layer, transmission layer, application layer, hardware rendering, and behavioral timing, through normalized weighted fusion and national cryptographic hash calculation, achieving a precise device profile of "one device, one fingerprint".
[0032] The auxiliary identifier, or UUID, is an auxiliary device identifier dynamically calculated based on the overall operating environment of the terminal, protocol stack parameters, and application characteristics. It does not rely on fixed information such as hardware serial numbers or user accounts and is used to adapt to minor changes in the terminal environment, enhancing the compatibility and stability of seamless authentication.
[0033] S103. Based on the dual-factor identifier, perform a matching search on the authentication database, and determine whether the target terminal is a legitimate terminal based on the search results.
[0034] Understandably, the AI agent invokes the session management module and authentication database, using a two-factor authentication approach as its core, combined with historical account information, access location, terminal behavior habits, and network environment for multi-dimensional intelligent matching and retrieval. If a match is successfully made with historically trusted terminal data, it is directly determined to be a legitimate terminal, automatically completing seamless authentication and session association; if no valid historical data is found, it is determined to be a new or abnormal terminal, automatically redirecting to the new authentication process.
[0035] S104. If it is determined that the target terminal is not a legitimate terminal, Portal authentication is performed on the target terminal. After the Portal authentication is successful, the dual-factor identifier, the random MAC, and the account information of the target terminal are associated and bound together, and the bound information is stored in the authentication database.
[0036] It is understandable that Portal authentication refers to a network access authentication method based on web page interaction, which supports multiple authentication methods such as account password, SMS verification, and third-party authorization. It is the mainstream access authentication method for enterprise, park, and campus networks.
[0037] For new devices that do not match the history, the system automatically redirects to a standardized Portal authentication page, supporting multiple authentication methods such as account password, SMS verification, and third-party authorization. After a user completes an active authentication and it is successful, the AI agent associates and binds the current device's encrypted device fingerprint, UUID, random MAC address, and user account into a four-tuple, encrypts and stores it in the authentication database, and simultaneously generates a unique trusted session identifier.
[0038] In some embodiments, determining the MAC type of the target terminal based on the network access packet includes: The incoming network packets are subjected to protocol bit verification, OUI (Organization Unique Identifier) vendor library matching verification, and behavior timing verification, and the MAC type of the target terminal is determined based on the results of the protocol bit verification, OUI vendor library matching verification, and behavior timing verification.
[0039] Understandably, when a terminal initiates a wireless or wired network access request, the authentication device captures the network access packets in real time through the network interface. The MAC type discrimination module activates a multi-level discrimination mechanism to accurately distinguish between physical MAC addresses and randomly forged MAC addresses. The specific discrimination criteria include three layers of rules: First, IEEE 802.3 protocol bit verification, parsing the U / L flag bit of the first byte of the MAC address. If the U / L bit is 1, it is determined to be a local random MAC address; if the U / L bit is 0, it is initially determined to be a global physical MAC address. Second, OUI (Organization Unique Identifier) vendor database matching, extracting the vendor code of the first 3 bytes of the MAC address and comparing it with the built-in legitimate OUI feature library. MAC addresses without a matching vendor or with private reserved segments are determined to be forged MAC addresses. Third, behavioral timing verification, MAC addresses that frequently change under the same IP address, have disordered packet frame intervals, or do not conform to the characteristics of a real network card driver are randomly forged MAC addresses, while those that remain fixed for a long time and have stable access behavior are physical MAC addresses. After the discrimination is completed, physical MAC terminals can adapt to traditional authentication logic, while random MAC terminals directly enter the AI intelligent agent's exclusive seamless authentication process.
[0040] In some embodiments, the multi-dimensional network access features include: link layer features, network layer and transport layer features, application layer features, hardware rendering features, and behavioral timing features.
[0041] Understandably, the AI agent passively and silently captures the full-dimensional network access characteristics of the terminal, without the need to deploy a client SDK (Software Development Kit), without user authorization, and without any awareness of the data collection. The collection dimensions cover five major categories: First, link layer characteristics (MAC attributes, OUI vendor information, frame length, frame interval); second, network layer and transport layer characteristics (IP network segment, TTL (Time to Live), TCP (Transmission Control Protocol) window, MSS (Maximum Segment Size), protocol stack fingerprint); third, application layer characteristics (browser UA (User Agent), request headers, application access characteristics); fourth, hardware rendering characteristics (Canvas graphics rendering pixel difference fingerprint); and fifth, behavioral timing characteristics (access period, session cycle, MAC switching frequency).
[0042] In some embodiments, the multi-dimensional network access features are preprocessed, the preprocessed multi-dimensional network access features are weighted and fused to obtain fused features, and an encrypted device fingerprint is generated based on the fused features, including: The multi-dimensional network entry features are subjected to noise reduction, deduplication, and normalization to obtain preprocessed multi-dimensional network entry features; The preprocessed multi-dimensional network access features are weighted and fused to obtain the fused features; The fused features are encrypted using the SM3 hash algorithm to generate an encrypted device fingerprint.
[0043] Understandably, the AI agent performs noise reduction, deduplication, and normalization preprocessing on the collected multi-dimensional raw features. Based on training weights, it weights and fuses different features, generating a unique and stable encrypted device fingerprint using the national cryptographic SM3 hash algorithm. This achieves "one fingerprint per device," meaning that fingerprints are consistent when physical terminal features highly overlap, and unique when spoofed terminals have significantly different features. Simultaneously, a UUID auxiliary identifier is dynamically calculated based on the overall operating environment of the terminal, independent of hardware serial numbers and account information, adapting to minor changes in the terminal's environment. Ultimately, a two-factor trusted identifier of "encrypted device fingerprint + environment UUID" is constructed, significantly improving the stability and anti-interference capability of terminal recognition.
[0044] In some embodiments, the terminal-invisible authentication method further includes: Collect all access data from the terminal and iteratively optimize the agent based on the all access data.
[0045] Understandably, the system collects all data from the terminal in real time, including MAC switching frequency, environmental change records, authentication results, policy matching status, and abnormal behavior data. Based on massive amounts of sample data, the AI agent continuously iterates feature weights, matching thresholds, and MAC discrimination rules, dynamically optimizing the device fingerprint modeling algorithm. It adapts to complex scenarios such as new random MAC variants, system version upgrades, and terminal configuration changes, continuously improving terminal recognition accuracy and system generalization capabilities.
[0046] In some embodiments, the terminal-invisible authentication method further includes: Based on the target terminal's device information, user information, and network information, match security protection strategies; If the target terminal is determined to have no abnormal risks based on the security protection strategy, the effective session state of the target terminal is maintained and the network access permissions of the target terminal are opened. If the security protection strategy determines that the target terminal has an abnormal risk, tiered protection actions are performed on the target terminal; the tiered protection actions include: performing secondary authentication to determine whether the target terminal is a legitimate terminal, traffic restriction, or blocking access.
[0047] Understandably, based on terminal type, user group, access location, device trust level, and real-time network status, a preset, refined security protection strategy is matched. If the terminal identifier matches normally and there are no abnormal risk markers, the session management module maintains a valid session state and allows the terminal network access permissions; for abnormal terminals such as fingerprint mutations, multiple account usage, and high-frequency MAC switching, tiered protection actions such as secondary authentication, traffic restriction, or direct blocking are triggered to achieve precise security control.
[0048] In some embodiments, the terminal-invisible authentication method further includes: Audit the entire process of data accessed by the target terminal and generate operation logs for the target terminal; After the target terminal is authenticated by Portal and audited, restore the network packet labels of the target terminal.
[0049] Understandably, once the terminal authentication verification is successful and the audit record is completed, the forwarding module retains the original network context of the terminal, restores the network packet labels, and forwards the terminal's service traffic normally, ensuring that the user's internet access is seamless, uninterrupted, and lossless, thus completing the closed loop of a single authentication process.
[0050] like Figure 2 As shown, the present invention also provides a terminal-invisible authentication device 200, comprising: The feature acquisition module 201 is used to capture the network access packet of the target terminal, determine the MAC type of the target terminal based on the network access packet, and, when the MAC type is random MAC, collect multi-dimensional network access features of the target terminal without the agent's perception. The identifier generation module 202 is used to preprocess the multi-dimensional network access features, perform weighted fusion on the preprocessed multi-dimensional network access features to obtain fused features, generate an encrypted device fingerprint based on the fused features, generate an auxiliary identifier based on the target terminal operating environment, and generate a two-factor identifier based on the encrypted device fingerprint and the auxiliary identifier. The legality judgment module 203 is used to perform matching and retrieval of the authentication database based on the dual-factor identifier, and determine whether the target terminal is a legitimate terminal based on the retrieval results; The authentication binding module 204 is used to perform Portal authentication on the target terminal when it is determined that the target terminal is not a legitimate terminal. After the Portal authentication is successful, the dual-factor identifier, the random MAC, and the account information of the target terminal are associated and bound together, and the bound information is stored in the authentication database.
[0051] The present invention also provides an electronic device, including a memory and a processor, wherein, The memory is used to store programs; The processor, coupled to the memory, is used to execute the program stored in the memory to implement the steps of the terminal-invisible authentication method as described in any of the preceding claims.
[0052] The present invention also provides a terminal-invisible authentication system, comprising: the aforementioned electronic device, and a target terminal communicatively connected to the electronic device.
[0053] In some embodiments, the method provided by the present invention mainly solves the following technical problems: 1. Traditional seamless authentication relies entirely on fixed physical MAC address identifiers. Once the terminal enables a random MAC mechanism, the identifier becomes completely invalid, leading to repeated authentication for users, poor network access experience, and a surge in network operation and maintenance costs.
[0054] 2. Existing auxiliary identification technologies use a single UUID identifier, which is greatly affected by changes in terminal systems, software, and environment, resulting in insufficient stability and problems such as device identification failure and authentication failure.
[0055] 3. Traditional authentication systems lack intelligent iteration capabilities, with fixed identification rules and matching thresholds. They cannot adapt to different terminal types, system versions, network environments, and new random MAC variant spoofing scenarios, resulting in weak anti-attack capabilities.
[0056] 4. Existing modification solutions often require forcing the terminal to disable the random MAC privacy mechanism, installing client plugins, or modifying terminal configurations, which damages the device's native privacy features and cannot achieve truly seamless and non-intrusive authentication.
[0057] To address the shortcomings of existing technologies, this invention proposes an AI-based seamless authentication scheme. Through multi-dimensional feature fusion modeling, two-factor trusted identification, and AI incremental self-learning mechanism, it completely solves the problem of seamless authentication failure in random MAC scenarios without modifying the terminal, disabling random MAC, or engaging in user interaction.
[0058] This invention constructs an intelligent, seamless authentication system centered on an AI agent, with nine functional modules working in synergy, abandoning the traditional authentication logic based on a single MAC identifier. It accurately distinguishes between physical MAC addresses and randomly forged MAC addresses through MAC type discrimination technology. Relying on the AI agent's seamless acquisition of multi-dimensional hardware and software, protocol stack, hardware rendering, and behavioral temporal features of the terminal, it integrates Canvas hardware fingerprints and environmental UUIDs to generate a two-factor trusted device identifier. Combined with historical sessions and intelligent policy matching, it achieves automatic access control. Simultaneously, it incorporates an incremental self-learning mechanism to continuously optimize the recognition model, coupled with full-process audit logs and refined forwarding control, achieving highly stable, highly accurate, and non-intrusive zero-trust, seamless authentication in random MAC scenarios. (Reference) Figure 3 As shown, the specific method includes the following steps: Step 1: Accurate identification of access trigger and MAC type.
[0059] When a terminal initiates a wireless or wired network access request, the authentication device captures the network access packets in real time through the network interface. The MAC type discrimination module activates a multi-level discrimination mechanism to accurately distinguish between physical MAC addresses and randomly forged MAC addresses. The specific discrimination criteria include three layers of rules: First, IEEE 802.3 protocol bit verification, parsing the U / L flag bit of the first byte of the MAC address. If the U / L bit is 1, it is determined to be a local random MAC address; if the U / L bit is 0, it is initially determined to be a global physical MAC address. Second, OUI (Organization Unique Identifier) vendor database matching, extracting the vendor code of the first 3 bytes of the MAC address and comparing it with the built-in legitimate OUI feature library. MAC addresses without a matching vendor or with private reserved segments are determined to be forged MAC addresses. Third, behavior timing verification, MAC addresses that frequently change under the same IP address, have disordered packet frame intervals, or do not conform to the characteristics of a real network card driver are randomly forged MAC addresses, while those that remain fixed for a long time and have stable access behavior are physical MAC addresses. After the discrimination is completed, physical MAC terminals can adapt to traditional authentication logic, while random MAC terminals directly enter the AI intelligent agent's exclusive seamless authentication process.
[0060] Step 2: Multi-dimensional, non-perceptible feature acquisition by the AI agent.
[0061] AI-powered agents passively and silently capture full-dimensional network access characteristics of terminals, completing data collection without requiring client SDK deployment, user authorization, or user awareness. The collection dimensions cover five major categories: 1) Link layer characteristics (MAC attributes, OUI vendor information, frame length, frame interval); 2) Network and transport layer characteristics (IP network segment, TTL (Time to Live), TCP window, MSS (Maximum Segment Size), protocol stack fingerprint); 3) Application layer characteristics (browser UA (User Agent), request headers, application access characteristics); 4) Hardware rendering characteristics (Canvas graphics rendering pixel difference fingerprint); and 5) Behavioral timing characteristics (access period, session cycle, MAC switching frequency).
[0062] Canvas fingerprint: It belongs to the core high-entropy feature dimension of device fingerprinting. Based on HTML5 Canvas technology, it captures pixel-level minor rendering differences caused by different terminal GPU hardware, system rendering engine, driver version, and font library by drawing fixed graphics, text and gradient effects through standardized front-end drawing. The hardware-level stable identifier generated by hash operation has the characteristics of being extremely difficult to forge in batches.
[0063] Step 3: Device fingerprint encryption generation and two-factor identification construction.
[0064] The AI agent performs noise reduction, deduplication, and normalization preprocessing on the collected multi-dimensional raw features. Based on training weights, it weights and fuses different features to generate a unique and stable encrypted device fingerprint using the national cryptographic SM3 hash algorithm, achieving "one fingerprint per device." Fingerprints are consistent when physical terminal features highly overlap, and unique when spoofed terminals have significantly different features. Simultaneously, a UUID auxiliary identifier is dynamically calculated based on the overall terminal operating environment, independent of hardware serial numbers and account information, adapting to minor changes in the terminal's environment. Ultimately, a two-factor trusted identifier of "encrypted device fingerprint + environment UUID" is constructed, significantly improving the stability and anti-interference capability of terminal recognition.
[0065] Step 4: Multi-dimensional search and intelligent matching of historical conversations.
[0066] The AI agent invokes the session management module and authentication database, using a two-factor authentication approach as its core, and combines historical account information, access location, terminal behavior habits, and network environment for multi-dimensional intelligent matching and retrieval. If a match is successfully made with historically trusted terminal data, the terminal is directly identified as legitimate, and authentication and session association are automatically completed seamlessly. If no valid historical data is found, the terminal is identified as new or abnormal, and the process automatically jumps to creating a new authentication process.
[0067] Step 5: Portal authentication interaction and multi-dimensional information binding.
[0068] For new devices that do not match the history, the system automatically redirects to a standardized Portal authentication page, supporting multiple authentication methods such as account password, SMS verification, and third-party authorization. After a user completes an active authentication and it is successful, the AI agent associates and binds the current device's encrypted device fingerprint, UUID, random MAC address, and user account into a four-tuple, encrypts and stores it in the authentication database, and simultaneously generates a unique trusted session identifier.
[0069] Step Six: AI Incremental Self-Learning Optimization.
[0070] The self-learning optimization module collects all terminal access data in real time, including MAC switching frequency, environment change records, authentication results, policy matching status, and abnormal behavior data. Based on massive sample data, the AI agent continuously iterates feature weights, matching thresholds, and MAC discrimination rules, dynamically optimizing the device fingerprint modeling algorithm. It adapts to complex scenarios such as novel random MAC variants, system version upgrades, and terminal configuration changes, continuously improving terminal recognition accuracy and system generalization capabilities.
[0071] Step 7: Dynamic policy matching and security decision-making for approval.
[0072] The policy matching module matches preset, refined security protection policies based on terminal type, user group, access location, device trust level, and real-time network status. If the terminal identifier matches normally and there are no abnormal risk markers, the session management module maintains the valid session state and allows the terminal network access permissions. For abnormal terminals such as fingerprint mutations, multiple account usage, and high-frequency MAC switching, it triggers tiered protection actions such as secondary authentication, traffic restriction, or direct blocking to achieve precise security control.
[0073] Step 8: Record the entire process audit log.
[0074] The audit and log module records all data throughout the terminal access process, including access time, MAC type, device fingerprint, UUID, authentication method, account information, policy matching results, traffic data, and abnormal alarm information, forming a complete and traceable operation log to meet the operational needs of enterprise network security compliance auditing, fault tracing, and risk tracing.
[0075] Step Nine: Tag Restoration and Normal Traffic Forwarding.
[0076] Once the terminal authentication verification is successful and the audit record is completed, the forwarding module retains the original network context of the terminal, restores the network packet labels, and forwards the terminal's service traffic normally, ensuring that the user's Internet access service is seamless, uninterrupted, and lossless, thus completing the closed loop of a single authentication process.
[0077] To implement the above method, this invention provides an AI-based intelligent agent-based system for solving random MAC authentication without user awareness. Deployed in network security processing equipment, it comprises nine core functional modules that work collaboratively, each with a clearly defined function and a closed-loop logic. 1. AI Intelligent Agent Core Module: The core scheduling and decision-making center of the system, responsible for the seamless collection of multi-dimensional features of the terminal, feature normalization and fusion, generation of encrypted device fingerprints, intelligent matching decision, full module scheduling, self-learning data iteration, and overall coordination of the authentication process.
[0078] 2. MAC Type Identification Module: Through protocol bit verification, OUI vendor matching, and behavioral feature analysis, it accurately distinguishes physical MAC from random / forged MAC, realizes access terminal traffic diversion, and provides a preliminary identification basis for the AI authentication process.
[0079] 3. Two-factor identification module: Based on the feature data collected by the AI agent, it generates encrypted device fingerprint and environment UUID to construct a two-factor trusted terminal identification, solving the problem of insufficient stability of single identification.
[0080] 4. Session Management Module: Responsible for creating new authentication sessions, associating with historical trusted sessions, maintaining session lifecycle, updating session status, binding terminal identifiers and session information, and ensuring that sessions remain valid.
[0081] 5. Portal Authentication Interaction Module: Provides a standardized Web authentication entry point, supports multiple authentication methods such as account password, SMS, and third-party accounts, and completes new terminal identity verification and human-computer interaction.
[0082] 6. Policy Matching Module: It has a built-in fine-grained protection policy library, which realizes dynamic policy matching based on terminal attributes, user groups, access scenarios, and device trust levels, and outputs hierarchical decisions such as allowing, secondary verification, and blocking.
[0083] 7. Self-learning optimization module: Continuously accumulates and integrates sample data, iteratively optimizes feature weights, MAC discrimination rules, and fingerprint modeling algorithms to improve the system's adaptability and recognition accuracy.
[0084] 8. Audit and Log Module: Records the entire process of terminal access, authentication, policy execution, traffic, and anomaly information, providing traceability, auditing, and reporting capabilities to meet compliance requirements.
[0085] 9. Forwarding Module: Responsible for forwarding network packets after authentication, restoring tags, and controlling traffic to ensure normal transmission of business traffic and achieve seamless network access.
[0086] This invention also provides a deep recognition processing device for solving random MAC addresses in seamless authentication based on AI intelligent agents. The device includes a processor, a memory, and a network interface. The memory stores a computer program, which, when executed by the processor, implements all steps of the aforementioned AI-based seamless authentication method for identifying random MAC addresses. The network interface is used for network access packet capture, terminal authentication data interaction, and inter-device communication. The processor is used for scheduling and AI model computation of the AI intelligent agent, MAC type discrimination, two-factor authentication, session management, portal authentication interaction, policy matching, self-learning optimization, auditing and logging, and forwarding modules. The memory stores multi-dimensional feature data of the terminal, Canvas device fingerprints, MAC discrimination rule bases, authentication protection policy tables, session data, and identification audit logs. This processing device can be integrated into network security devices such as firewalls, DNS security gateways, portal authentication gateways, internet behavior management devices, zero-trust access systems, and network intrusion detection systems.
[0087] Compared with existing technologies, this invention integrates multi-dimensional feature perception of AI agents, enhanced device fingerprint encryption, and multi-level MAC deep discrimination technology to achieve high-precision identification of terminal physical MAC and randomly forged MAC. It solves the technical problems of existing non-perceptual authentication features having a single dimension, over-reliance on inherent MAC addresses, susceptibility to being bypassed by terminal random MAC, weak generalization ability, and difficulty in device traceability. By integrating link layer identifier verification, OUI vendor library matching, Canvas hardware rendering fingerprint, and terminal behavior time sequence features, a multi-dimensional two-factor trusted identification system is constructed, effectively solving the authentication failure problem caused by terminal MAC randomization and device spoofing. Relying on an incremental self-learning optimization mechanism, it can continuously adapt to complex scenarios such as new random MAC variants and terminal privacy tampering, significantly improving the anti-attack capability and scenario adaptability of the non-perceptual authentication system. At the same time, combined with dynamic policy matching, fine-grained access control, dynamic session binding, and full-process audit log mechanism, it realizes accurate verification and hierarchical protection of terminal access identity, providing an efficient and reliable technical solution for non-perceptual security authentication under zero-trust architecture, and fully meeting the security protection and compliance operation and maintenance needs of enterprise network access.
[0088] The key technical points of this invention include: 1. AI-driven seamless authentication core architecture: Abandoning the traditional single MAC authentication logic, it passively collects multi-dimensional terminal features through AI agents to generate stable device fingerprints, completely solving the problem of seamless authentication failure caused by random MAC switching of terminals.
[0089] 2. Multi-level MAC type intelligent discrimination technology: It integrates protocol bit identifier verification, OUI vendor library matching, and terminal behavior timing characteristics into a triple discrimination logic to accurately distinguish between physical MAC and random spoofed MAC, thereby achieving accurate traffic distribution for access terminals.
[0090] 3. Device fingerprint + UUID dual-factor identification mechanism: Combining highly stable Canvas hardware fingerprint and environment-adaptive UUID, a dual trusted terminal identification is constructed, taking into account both device uniqueness and environmental compatibility. Minor changes in terminal configuration do not affect the recognition effect.
[0091] 4. AI Incremental Self-Learning Optimization Mechanism: Based on massive access samples, the model parameters, feature weights and discrimination rules are continuously iterated to adapt to complex adversarial scenarios such as new random MAC variants, system upgrades, and terminal spoofing, thereby continuously improving recognition accuracy.
[0092] 5. End-to-end non-intrusive and seamless authentication capability: No manual user operation required, no need to disable terminal random MAC privacy mechanism, no need to install client plugins, no need to modify existing network architecture, and compatible with various terminals and existing authentication systems.
[0093] 6. Refined strategy control and full-chain audit system: Supports hierarchical security policy matching and abnormal risk identification, coupled with full-process log traceability capabilities, taking into account both network security protection and enterprise compliance operation and maintenance needs.
[0094] The beneficial effects of the present invention include: 1. Significantly improved authentication stability: Terminal recognition accuracy ≥99%, completely solving the authentication failure problem caused by random MAC, and reducing the user's duplicate authentication rate to below 1%.
[0095] 2. Seamless access experience: No user interaction required throughout the entire process, no need to disable terminal privacy mechanisms, no need to install plugins, fully preserving the terminal's native privacy features, and providing a smooth network access experience.
[0096] 3. Superior environmental adaptability: Terminal system upgrades, browser updates, network configuration modifications, and IP changes do not affect the device's recognition performance, adapting to a massive number of heterogeneous terminals and complex network scenarios.
[0097] 4. Enhanced security and compliance: Enables full-process traceability of terminal access, anomaly risk detection, and refined access control, meeting the network security compliance and operation and maintenance requirements of enterprises.
[0098] 5. Highly compatible: No need to modify the existing hardware network architecture, it can seamlessly connect to existing Portal, RADIUS, and LDAP authentication systems, with low deployment costs and strong adaptability.
[0099] The terminal-invisible authentication device provided in the above embodiments can implement the technical solutions described in the above terminal-invisible authentication method embodiments. The specific implementation principles of each module or unit can be found in the corresponding content in the above terminal-invisible authentication method embodiments, and will not be repeated here.
[0100] like Figure 4 As shown, the present invention also provides an electronic device 400, which can be an authentication device corresponding to a target terminal. The electronic device 400 includes a processor 401, a memory 402, and a display 403. Figure 4 Only some components of the electronic device 400 are shown, but it should be understood that it is not required to implement all the components shown, and more or fewer components may be implemented instead.
[0101] In some embodiments, memory 402 may be an internal storage unit of electronic device 400, such as a hard disk or memory of electronic device 400. In other embodiments, memory 402 may also be an external storage device of electronic device 400, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc. equipped on electronic device 400.
[0102] Furthermore, the memory 402 may include both internal storage units of the electronic device 400 and external storage devices. The memory 402 is used to store application software and various types of data installed on the electronic device 400.
[0103] In some embodiments, processor 401 may be a central processing unit (CPU), microprocessor, or other data processing chip, used to run program code stored in memory 402 or process data, such as the terminal-invisible authentication method of the present invention.
[0104] In some embodiments, display 403 may be an LED display, a liquid crystal display, a touch-sensitive liquid crystal display, or an OLED (Organic Light-Emitting Diode) touchscreen. Display 403 is used to display information from electronic device 400 and to display a visual user interface. Components 401-403 of electronic device 400 communicate with each other via a system bus.
[0105] In some embodiments of the present invention, when the processor 401 executes the terminal-invisible authentication program in the memory 402, the following steps can be implemented: Capture the network access packets of the target terminal, determine the MAC type of the target terminal based on the network access packets, and if the MAC type is a random MAC, collect multi-dimensional network access features of the target terminal without the agent's perception. The multi-dimensional network access features are preprocessed, and the preprocessed multi-dimensional network access features are weighted and fused to obtain fused features. An encrypted device fingerprint is generated based on the fused features, and an auxiliary identifier is generated based on the target terminal operating environment. A two-factor identifier is generated based on the encrypted device fingerprint and the auxiliary identifier. The authentication database is matched and searched based on the two-factor identifier, and the target terminal is determined to be a legitimate terminal based on the search results. If it is determined that the target terminal is not a legitimate terminal, Portal authentication is performed on the target terminal. After the Portal authentication is successful, the two-factor identifier, the random MAC, and the account information of the target terminal are associated and bound together, and the bound information is stored in the authentication database.
[0106] It should be understood that when the processor 401 executes the terminal-invisible authentication program in the memory 402, in addition to the functions mentioned above, it can also perform other functions, as detailed in the description of the corresponding method embodiments above.
[0107] Furthermore, the embodiments of the present invention do not specifically limit the type of electronic device 400 mentioned. Electronic device 400 can be a mobile phone, tablet computer, personal digital assistant (PDA), wearable device, laptop computer, or other portable electronic device. Exemplary embodiments of portable electronic devices include, but are not limited to, portable electronic devices running iOS, Android, Microsoft, or other operating systems. The aforementioned portable electronic device can also be other portable electronic devices, such as a laptop computer with a touch-sensitive surface (e.g., a touch panel). It should also be understood that in some other embodiments of the present invention, electronic device 400 may not be a portable electronic device, but rather a desktop computer with a touch-sensitive surface (e.g., a touch panel).
[0108] In another aspect, the present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, is implemented to perform the terminal-invisible authentication method provided by the methods described above, the method comprising: Capture the network access packets of the target terminal, determine the MAC type of the target terminal based on the network access packets, and if the MAC type is a random MAC, collect multi-dimensional network access features of the target terminal without the agent's perception. The multi-dimensional network access features are preprocessed, and the preprocessed multi-dimensional network access features are weighted and fused to obtain fused features. An encrypted device fingerprint is generated based on the fused features, and an auxiliary identifier is generated based on the target terminal operating environment. A two-factor identifier is generated based on the encrypted device fingerprint and the auxiliary identifier. The authentication database is matched and searched based on the two-factor identifier, and the target terminal is determined to be a legitimate terminal based on the search results. If it is determined that the target terminal is not a legitimate terminal, Portal authentication is performed on the target terminal. After the Portal authentication is successful, the two-factor identifier, the random MAC, and the account information of the target terminal are associated and bound together, and the bound information is stored in the authentication database.
[0109] Those skilled in the art will understand that all or part of the processes of the methods described in the above embodiments can be implemented by a computer program instructing related hardware, and the program can be stored in a computer-readable storage medium. The computer-readable storage medium may be a disk, optical disk, read-only memory, or random access memory, etc.
[0110] The terminal-invisible authentication method, apparatus, system, and electronic device provided by the present invention have been described in detail above. Specific examples have been used to illustrate the principles and implementation methods of the present invention. The description of the above embodiments is only for the purpose of helping to understand the method and core ideas of the present invention. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of the present invention. Therefore, the content of this specification should not be construed as a limitation of the present invention.
Claims
1. A terminal-invisible authentication method, characterized in that, include: Capture the network access packets of the target terminal, determine the MAC type of the target terminal based on the network access packets, and if the MAC type is a random MAC, collect multi-dimensional network access features of the target terminal without the agent's perception. The multi-dimensional network access features are preprocessed, and the preprocessed multi-dimensional network access features are weighted and fused to obtain fused features. An encrypted device fingerprint is generated based on the fused features, and an auxiliary identifier is generated based on the target terminal operating environment. A two-factor identifier is generated based on the encrypted device fingerprint and the auxiliary identifier. The authentication database is matched and searched based on the two-factor identifier, and the target terminal is determined to be a legitimate terminal based on the search results. If it is determined that the target terminal is not a legitimate terminal, Portal authentication is performed on the target terminal. After the Portal authentication is successful, the two-factor identifier, the random MAC, and the account information of the target terminal are associated and bound together, and the bound information is stored in the authentication database.
2. The terminal-invisible authentication method according to claim 1, characterized in that, Determining the MAC type of the target terminal based on the network access packet includes: The incoming network packets are subjected to protocol bit verification, OUI vendor library matching verification, and behavior timing verification, and the MAC type of the target terminal is determined based on the results of the protocol bit verification, OUI vendor library matching verification, and behavior timing verification.
3. The terminal-invisible authentication method according to claim 1, characterized in that, The multi-dimensional network access features include: link layer features, network layer and transport layer features, application layer features, hardware rendering features, and behavioral timing features.
4. The terminal-invisible authentication method according to claim 1, characterized in that, The multi-dimensional network access features are preprocessed, and the preprocessed multi-dimensional network access features are weighted and fused to obtain fused features. An encrypted device fingerprint is then generated based on the fused features, including: The multi-dimensional network entry features are subjected to noise reduction, deduplication, and normalization to obtain preprocessed multi-dimensional network entry features; The preprocessed multi-dimensional network access features are weighted and fused to obtain the fused features; The fused features are encrypted using the SM3 hash algorithm to generate an encrypted device fingerprint.
5. The terminal-invisible authentication method according to claim 1, characterized in that, Also includes: Collect all access data from the terminal and iteratively optimize the agent based on the all access data.
6. The terminal-invisible authentication method according to claim 1, characterized in that, Also includes: Based on the target terminal's device information, user information, and network information, match security protection strategies; If the target terminal is determined to have no abnormal risks based on the security protection strategy, the effective session state of the target terminal is maintained and the network access permissions of the target terminal are opened. If the security protection strategy determines that the target terminal has an abnormal risk, tiered protection actions are performed on the target terminal; the tiered protection actions include: performing secondary authentication to determine whether the target terminal is a legitimate terminal, traffic restriction, or blocking access.
7. The terminal-invisible authentication method according to any one of claims 1-6, characterized in that, Also includes: Audit the entire process of data accessed by the target terminal and generate operation logs for the target terminal; After the target terminal is authenticated by Portal and audited, restore the network packet labels of the target terminal.
8. A terminal-invisible authentication device, characterized in that, include: The feature acquisition module is used to capture the network access packets of the target terminal, determine the MAC type of the target terminal based on the network access packets, and, in the case that the MAC type is a random MAC, collect multi-dimensional network access features of the target terminal without the agent's perception. The identifier generation module is used to preprocess the multi-dimensional network access features, perform weighted fusion on the preprocessed multi-dimensional network access features to obtain fused features, generate an encrypted device fingerprint based on the fused features, generate an auxiliary identifier based on the target terminal operating environment, and generate a two-factor identifier based on the encrypted device fingerprint and the auxiliary identifier. The legitimacy determination module is used to perform matching and retrieval of the authentication database based on the dual-factor identifier, and determine whether the target terminal is a legitimate terminal based on the retrieval results; The authentication binding module is used to perform Portal authentication on the target terminal when it is determined that the target terminal is not a legitimate terminal. After the Portal authentication is successful, the two-factor identifier, the random MAC, and the account information of the target terminal are associated and bound together, and the bound information is stored in the authentication database.
9. An electronic device, characterized in that, Including memory and processor, among which, The memory is used to store programs; The processor, coupled to the memory, is used to execute the program stored in the memory to implement the steps of the terminal-invisible authentication method as described in any one of claims 1 to 7.
10. A terminal-invisible authentication system, characterized in that, include: The electronic device of claim 9, and the target terminal communicatively connected to the electronic device.