System and method for adaptive authentication policy adjustment based on network state
Patent Information
- Application Number
- CN202611247589.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-08-17
- Publication Date
- 2026-09-22
AI Technical Summary
[0002]仓储场景接入大量终端设备,设备多通过无线网络、网络切片接入边缘网关,网络环境复杂多变,同时存在良性拥塞、瞬时抖动、恶意劫持等各类网络异常,给设备身份认证带来安全隐患;现有仓储设备认证方案多采用固定认证策略,无法根据实时网络工况动态调整认证强度:网络优质时持续执行高强度认证,造成带宽、算力资源浪费;网络出现恶意劫持等高危工况时,认证层级不足,易发生设备仿冒、数据窃取风险;当前技术存在缺陷:一是仅单一依据网络时延、带宽等少量指标判断网络风险,缺少多维度特征量化评估手段,风险判定精度低;二是设备身份信任与网络状态相互割裂,无法融合开展综合安全定级;三是认证层级切换无防抖机制,网络瞬时波动易引发认证策略频繁跳变,影响设备业务稳定性;四是网络恢复正常后缺少标准化回退流程,临时授信凭证留存、会话密钥无法自动复原,存在安全残留风险
[0059]1.本发明提出基于网络状态的自适应认证策略调整方法,构建八维网络特征联合评估体系,结合贝叶斯信任模型实现网络工况与设备身份双重安全量化判定,提升仓储设备风险识别精准度;通过有效带宽、射频信噪比、虚假网络特征等多维度数据划分四类网络工况,搭配动态修正链路风险权重,同时融合设备历史认证记录计算有效身份信任基础分值,双向校正得到设备综合风险等级,既能精准区分良性网络拥塞与恶意劫持攻击,避免单一网络指标误判风险;且引入滞回防抖判定规则处理认证层级切换,过滤瞬时网络抖动造成的策略频繁跳转,保障仓储设备业务连续稳定运行,兼顾网络波动适配性与整体安全防护能力。
Smart Images

Figure CN122802266A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of network security technology, specifically an adaptive authentication policy adjustment system and method based on network status. Background Technology
[0002] Warehouse scenarios involve a large number of terminal devices, many of which connect to edge gateways via wireless networks and network slicing. The network environment is complex and variable, with various network anomalies such as benign congestion, momentary jitter, and malicious hijacking, posing security risks to device authentication. Existing warehouse device authentication solutions mostly employ fixed authentication strategies, failing to dynamically adjust authentication strength based on real-time network conditions: Continuously executing high-strength authentication when the network is of high quality wastes bandwidth and computing resources; when high-risk conditions such as malicious hijacking occur, insufficient authentication levels make them susceptible to device impersonation and data theft. Current technology has several shortcomings: First, it relies solely on a few indicators such as network latency and bandwidth to assess network risk, lacking multi-dimensional feature quantification methods, resulting in low accuracy in risk assessment; second, device identity trust and network status are disconnected, making it impossible to integrate them for comprehensive security classification; third, there is no anti-jitter mechanism for authentication level switching, allowing momentary network fluctuations to cause frequent changes in authentication strategies, affecting device service stability; fourth, there is a lack of standardized rollback procedures after network recovery, resulting in the retention of temporary trust credentials and the inability to automatically restore session keys, posing a risk of residual security. In summary, existing fixed authentication models are difficult to adapt to the complex and dynamically changing networks of warehouses, and cannot balance authentication security with equipment operating efficiency. There is an urgent need for a solution that can adaptively adjust authentication strategies based on multi-dimensional network conditions. Summary of the Invention
[0003] To address the shortcomings of existing technologies, this invention proposes an adaptive authentication strategy adjustment system and method based on network status. It collects eight-dimensional network condition characteristics of warehouse equipment, classifies network condition labels, and obtains a quantitative score for network status. A Bayesian trust model is used to calculate the basic score for valid device identity trust, which is coupled to obtain a comprehensive security assessment score. This score is then combined with the condition offset to complete the device risk classification. A five-level authentication benchmark is set, and the assessment score and network condition labels are bidirectionally verified using hysteresis anti-jitter judgment rules to output gradient strategy switching instructions. Based on these instructions, the device authentication rules are updated, and temporary authentication and trust credentials are generated and distributed to the edge gateway. When the network returns to a stable and high-quality state, the condition is determined through sliding window voting, and the initial authentication rules are restored step-by-step along the path. The native session key is reused, and the temporary authentication and trust credentials are destroyed layer by layer. This application balances network fluctuation anti-jitter and security protection, reduces the risk of malicious hijacking, and is suitable for multi-device access scenarios in warehouses.
[0004] To achieve the above objectives, the present invention provides the following technical solution:
[0005] Network state-based adaptive authentication policy adjustment methods include:
[0006] Collect original 8-dimensional network condition feature data of all access devices in the warehouse and classify and label them to obtain network condition labels. Simultaneously generate a network status quantitative score with link risk weight values.
[0007] Retrieve the valid identity trust base score pre-stored in the storage equipment, use the link risk weight value as a weighting coefficient, integrate it with the network status quantitative score to calculate the comprehensive security assessment score, and combine it with the network operating condition label to complete the two-way risk classification of the equipment.
[0008] Retrieve the pre-configured five-level authentication benchmark and hysteresis anti-jitter judgment rules, bidirectionally verify the comprehensive security assessment score and network condition label, and output the gradient policy switching command matching the five-level authentication level.
[0009] Parse the gradient strategy switching command, revise the warehouse equipment authentication execution rules to adapt to the current risk level, and simultaneously issue temporary authentication credit certificates to the connected edge gateway;
[0010] Continuously collect original feature data of eight-dimensional network conditions, update network condition labels in real time, and restore the initial authentication rules step by step from low to high level according to the five-level authentication benchmark when the network condition label returns to a stable and high-quality state. Reuse the original session key of the device before adjustment, destroy the temporary authentication and trust credentials of the edge gateway step by step, and return to the benchmark authentication state.
[0011] Specifically, the process of generating the network state quantization score with link risk weight values includes:
[0012] For each dimension of the original feature data of the eight-dimensional network operating conditions, a corresponding risk impact factor value and an occurrence probability coefficient value are configured, and the risk impact factor value and occurrence probability coefficient value corresponding to the same dimension feature are multiplied to obtain the initial risk weight value of each dimension feature.
[0013] Based on the category corresponding to the network condition label, the dynamic correction coefficient is retrieved from the pre-configured weight correction coefficient mapping table. The initial risk weight value of each feature is updated using the dynamic correction coefficient to obtain the link risk weight value under the current network condition.
[0014] The original values of each dimension in the original feature data of the eight-dimensional network condition are normalized to obtain the normalized value of each feature. Then, the normalized value of each feature is multiplied by the link risk weight value of the corresponding dimension and accumulated to calculate and output the network state quantification score.
[0015] Specifically, the process of outputting the comprehensive security assessment score includes:
[0016] Based on the device identification code stored in the warehouse equipment security management database, retrieve the authentication success and failure records of the corresponding device for the N consecutive historical authentication cycles before the current sampling cycle;
[0017] The retrieved authentication success records and authentication failure records are input into the pre-built Bayesian trust model to calculate and output the effective identity trust base score for the current period.
[0018] The network status quantification score, the effective identity trust base score, and the link risk weight value of each dimension feature in the eight-dimensional network condition raw feature data are obtained. The corresponding first fusion weight coefficient, second fusion weight coefficient, and third fusion weight coefficient are configured respectively. Then, the network status quantification score, the effective identity trust base score, and the link risk weight value of each dimension feature are multiplied by the corresponding first fusion weight coefficient, second fusion weight coefficient, and third fusion weight coefficient respectively. The results are summed to obtain the comprehensive security assessment score.
[0019] Specifically, the step of combining network condition tags to complete the two-way risk classification of equipment includes:
[0020] Based on the specific category to which the network condition label belongs, the corresponding risk offset value is retrieved from the pre-configured condition-risk offset mapping table;
[0021] The comprehensive safety assessment score and the risk offset value are arithmetically summed to obtain the comprehensive risk judgment value of the equipment.
[0022] Read the high-risk threshold value and low-risk threshold value from the pre-configured risk level threshold parameter table;
[0023] If the comprehensive risk assessment value of the equipment is greater than or equal to the high-risk threshold, the corresponding equipment is determined to be at the first risk level; if the comprehensive risk assessment value of the equipment is less than or equal to the low-risk threshold, the corresponding equipment is determined to be at the third risk level; if the comprehensive risk assessment value of the equipment is between the low-risk threshold and the high-risk threshold, the corresponding equipment is determined to be at the second risk level.
[0024] Specifically, the process of retrieving the pre-configured five-level authentication benchmark and hysteresis stabilization judgment rules, bidirectionally verifying the comprehensive security assessment score and network condition labels, and outputting a gradient policy switching instruction matching the five-level authentication level includes:
[0025] Based on the local policy repository, obtain the corresponding certification factor combination requirements, number of certification factors and certification timeout duration for each of the simplified certification benchmark, lightweight certification benchmark, standard certification benchmark, enhanced certification benchmark and global certification benchmark, and form a five-level certification benchmark mapping table.
[0026] The comprehensive security assessment score is matched and queried in the five-level certification benchmark mapping table to obtain the preliminary target certification level;
[0027] The pre-configured risk level score corresponding to the network condition label is compared with the preliminary target authentication level, and the level with the higher authentication level is selected as the final target authentication level.
[0028] The system reads the currently active authentication level from the device's current authentication status register, compares the currently active authentication level with the final target authentication level, and calls the pre-configured hysteresis stabilization judgment rule to perform stabilization judgment. When it is determined that the level switching conditions are met, a gradient strategy switching instruction is generated to switch from the currently active authentication level to the final target authentication level. The hysteresis stabilization judgment rule includes a continuous compliance time threshold for level switching and a hysteresis offset. The hysteresis offset includes a level upgrade hysteresis offset and a level downgrade hysteresis offset.
[0029] Specifically, the process of calling the pre-configured hysteresis stabilization judgment rule to perform stabilization judgment includes:
[0030] When it is determined that the final target authentication level is higher than the current effective authentication level, the difference between the final target authentication level and the current effective authentication level is calculated as the first level difference. If the first level difference is greater than or equal to the level promotion backlash offset, a pre-configured de-jittering delay waiting period is started. During the de-jittering delay waiting period, the final target authentication level is continuously acquired for M sampling times. If the final target authentication level for all M sampling times is higher than the current effective authentication level, it is determined that the level promotion condition is met.
[0031] When it is determined that the final target authentication level is lower than the currently effective authentication level, the difference between the current effective authentication level and the final target authentication level is calculated as the second level difference. If the second level difference is greater than or equal to the level downgrade hysteresis offset, a de-jittering delay waiting period is started. During the de-jittering delay waiting period, the final target authentication level is continuously acquired for M sampling times. If the final target authentication level for all M sampling times is lower than the currently effective authentication level, it is determined that the level downgrade condition is met.
[0032] When it is determined that the level promotion condition or the level demotion condition is met, a level switching permission signal is output as a trigger condition for generating the gradient policy switching instruction; when it is determined that the level promotion condition or the level demotion condition is not met, the current effective authentication level remains unchanged, and the generation of gradient policy switching instructions is prohibited.
[0033] Specifically, the parsing gradient strategy switching instruction revises the warehouse equipment authentication execution rules to adapt to the current risk level and simultaneously issues temporary authentication and credit credentials to the connected edge gateway, including:
[0034] Parse the received gradient policy switching command and extract the target authentication level identifier carried in it;
[0035] Based on the extracted target authentication level identifier, query the pre-configured authentication policy rule base to obtain the target authentication factor combination requirements and target session key derivation method corresponding to the target authentication level;
[0036] The currently effective authentication factor combination requirements and the currently effective session key derivation method are updated to the target authentication factor combination requirements and the target session key derivation method, respectively, to complete the revision of the warehouse equipment authentication execution rules;
[0037] Based on the target authentication level identifier, the corresponding credential validity period is retrieved from the pre-configured level-validity period mapping table;
[0038] Generate the main information of the temporary authentication and credit certificate based on the current identification code and current timestamp of the current warehouse equipment;
[0039] Using the updated target session key derivation method, a credential encryption key is derived from the currently effective session key, and the credential extension information containing the validity period of the credential is encrypted using the credential encryption key to generate a temporary authentication and trust credential.
[0040] The generated temporary authentication and trust credentials are encapsulated into a delivery message, which is then synchronously delivered to the edge gateway via a pre-established encrypted communication link.
[0041] Specifically, the continuous collection of original feature data of the eight-dimensional network operating conditions, the real-time updating of network operating condition labels, and the restoration of the initial authentication rules level by level from low to high according to the five-level authentication benchmark after the network operating condition labels return to a steady state of high quality, including:
[0042] The original feature data of the eight-dimensional network condition of the warehouse access devices are collected according to the preset periodic sampling interval. The updated eight-dimensional feature vector of the current sampling period is obtained and continuously input into the pre-trained lightweight gradient boosting machine classification model to obtain the updated network condition label of the current sampling period.
[0043] Based on a preset sliding time window, multiple updated network condition labels corresponding to multiple consecutive sampling periods within the sliding time window are obtained and majority voting statistics are performed. The network condition label with the most votes is taken as the final updated network condition label at the center time within the sliding time window.
[0044] When the final updated network condition label is detected to have changed from a non-steady-state high-quality type to a steady-state high-quality type, the authentication level recovery process is triggered.
[0045] During the authentication level recovery process, the initial authentication level identifier and initial authentication execution rules recorded by the corresponding device before the level switch are retrieved from the warehouse equipment security management database.
[0046] The initial authentication level identifier is compared with the currently effective authentication level identifier to determine the step-by-step degradation path from the currently effective authentication level to the initial authentication level.
[0047] According to the hierarchical order in the described step-by-step downgrade path, hierarchical downgrade switching instructions are generated and executed level by level.
[0048] Specifically, the reuse of the original session key of the device before adjustment includes:
[0049] In the authentication level recovery process, before executing the first level downgrade switching instruction, the original session key of the device before adjustment is recalculated based on the device factory key derivation seed stored in the warehousing equipment platform, using the hash-based message authentication code key derivation function, and combined with the corresponding device identification code.
[0050] Verify whether the native session key is within a preset valid lifespan. If it is within a valid lifespan, mark the native session key as pending reuse.
[0051] After executing the downgrade switching instruction, the native session key in the reusable state is used to replace the currently effective temporary session key.
[0052] A network state-based adaptive authentication policy adjustment system includes:
[0053] The quantitative scoring module is used to collect raw feature data of the eight-dimensional network conditions of all access devices in the warehouse and output quantitative scores of the network status.
[0054] The security classification module is used to retrieve historical authentication records of warehouse equipment, calculate the basic score of effective identity trust through the Bayesian trust model, and calculate the comprehensive risk judgment value of the equipment by combining the risk offset value corresponding to the working condition, so as to complete the equipment risk classification of the two-way coupling of network and identity.
[0055] The strategy decision module reads the current authentication level of the device, calls the hysteresis anti-shake judgment rules to verify whether the level upgrade conditions and level down conditions are met, and outputs the gradient strategy switching command after the switching requirements are met.
[0056] The authentication rule update module is used to parse gradient policy switching instructions to extract the target authentication level, query and update the device authentication factor combination and session key derivation method to revise the authentication execution rules.
[0057] The status rollback control module retrieves the device's initial authentication configuration when the network condition label changes to steady-state high quality, plans a step-by-step degradation path, and issues hierarchical downgrade switching instructions until the authentication level is completely restored to the baseline authentication state.
[0058] Compared with the prior art, the beneficial effects of the present invention are:
[0059] 1. This invention proposes an adaptive authentication strategy adjustment method based on network status, constructs an eight-dimensional network feature joint evaluation system, and combines a Bayesian trust model to achieve dual security quantification judgment of network conditions and device identity, thereby improving the accuracy of risk identification for warehousing equipment. It classifies four network conditions using multi-dimensional data such as effective bandwidth, radio frequency signal-to-noise ratio, and fake network features, and dynamically corrects link risk weights. Simultaneously, it integrates historical authentication records of devices to calculate a basic score for valid identity trust, and bidirectionally corrects to obtain the comprehensive risk level of the device. This method can accurately distinguish between benign network congestion and malicious hijacking attacks, avoiding the risk of misjudgment based on a single network indicator. Furthermore, it introduces hysteresis anti-jitter judgment rules to handle authentication level switching, filtering out frequent policy jumps caused by instantaneous network jitter, ensuring the continuous and stable operation of warehousing equipment services, and balancing network fluctuation adaptability with overall security protection capabilities.
[0060] 2. This invention proposes an adaptive authentication strategy adjustment method based on network status, realizing a standardized and secure rollback process after network recovery and adaptive switching of five-level gradient authentication, balancing operational efficiency and long-term security management. Based on comprehensive risk matching, a simplified to full-domain five-level authentication strategy is implemented, dynamically updating authentication factors and session key derivation methods, and issuing time-limited temporary authentication credentials to the edge gateway. Lightweight authentication is used in low-risk networks to save bandwidth and computing power, while full-domain enhanced authentication is enabled in high-risk scenarios to resist impersonation and hijacking. When the network returns to a stable and high-quality state, a sliding window voting mechanism confirms the network status, restoring the original authentication rules step-by-step along a hierarchical path, reusing the device's native session key, and destroying the edge gateway's temporary authentication credentials layer by layer, while retaining audit logs. This eliminates security remnants caused by temporary authorization, fully realizing dynamic adjustment and smooth recovery of the authentication strategy. It adapts to the complex network environment of massive access devices in warehouses, effectively balancing authentication security, device computing power consumption, and network transmission efficiency. Attached Figure Description
[0061] Figure 1 This is a schematic diagram of the adaptive authentication strategy adjustment method based on network state according to the present invention;
[0062] Figure 2This is a flowchart illustrating the principle of the adaptive authentication strategy adjustment method based on network state of the present invention.
[0063] Figure 3 This is a diagram illustrating the system architecture for adjusting the adaptive authentication strategy based on network state, as described in this invention. Detailed Implementation
[0064] Example 1:
[0065] Please see Figure 1 and Figure 2 The present invention provides an embodiment of an adaptive authentication policy adjustment method based on network state, the method comprising S1 to S4, including the following steps:
[0066] S1: Collect the original eight-dimensional network condition feature data of all access devices in the warehouse and classify and label them to obtain network condition labels, and simultaneously generate a network status quantitative score with link risk weight values.
[0067] This embodiment uses a large-scale intelligent automated warehouse park as the implementation scenario. The park includes seven categories of devices with full-domain access: AGV handling robots, warehouse rack recognition cameras, temperature and humidity acquisition terminals, inbound and outbound barcode scanning terminals, warehouse PLC control cabinets, edge gateways, and wireless handheld inventory terminals. All devices complete network access through a 5G industrial private network and fiber optic backhaul lines. The park is divided into four network slice areas: raw material warehousing area, finished product storage area, sorting and outbound area, and equipment charging and maintenance area. Each slice is independently allocated with dedicated network bandwidth resources, radio frequency communication channels, and backhaul fiber optic links, providing a complete hardware environment support for the full-domain collection of original feature data of the eight-dimensional network operating conditions.
[0068] Furthermore, the original 8-dimensional network condition characteristic data includes effective bandwidth utilization, end-to-end round-trip delay, jitter data, packet loss type identifier, radio frequency signal-to-noise ratio, slice load, backhaul attenuation, and spoofed network simulation characteristic data. Based on the original 8-dimensional network condition characteristic data, corresponding judgment thresholds are defined: For effective bandwidth utilization, a high bandwidth threshold of 85% and a low bandwidth threshold of 40% are configured; for end-to-end round-trip delay, a low latency threshold of 20ms is configured; jitter data is quantized as latency jitter amplitude, and a jitter threshold of 8ms is configured; the packet loss type identifier is fully named "packet loss event type identifier," which is an enumerated identifier field; the slice load is quantized as network slice resource utilization, and a slice congestion threshold of 70% is configured; backhaul attenuation is quantized as backhaul line optical power attenuation value, and an attenuation alarm threshold of 12dB is configured; the radio frequency signal-to-noise ratio is characterized by the radio frequency received signal strength indication value, and a signal safety threshold of -105dBm is configured; and a spoofed characteristic threshold of 60 is configured based on the dimensionless 0 to 100 range of spoofed network simulation characteristic data.
[0069] Furthermore, the data acquisition plugin synchronously collects raw feature data from the eight-dimensional network operating conditions. Each type of data dimension corresponds to an independent acquisition logic, and the specific acquisition process is detailed as follows:
[0070] The first dimension is the effective bandwidth utilization rate: The acquisition plugin counts the total byte capacity of the uplink and downlink bidirectional data packets transmitted by the device in real time during the current sampling period, and then reads the maximum allowed bandwidth resources allocated to the terminal by the network slice to which the device belongs. The real-time total number of bytes transmitted is compared and converted with the total bandwidth allocated by the slice to obtain the original value of the effective bandwidth utilization rate of the device in the current sampling period. At the same time, the device's unique identification code, sampling timestamp, and network slice number are bound to the temporary storage to prevent data confusion between multiple devices.
[0071] The second dimension is end-to-end round-trip latency: The edge gateway sends a dedicated latency probe data packet to the corresponding warehouse equipment. The data packet carries the current gateway's high-precision timestamp. After receiving the probe packet, the equipment does not perform any additional business processing and immediately sends the probe packet back to the edge gateway. After receiving the back data packet, the edge gateway records the receiving timestamp and uses the receiving timestamp to subtract the sending timestamp to obtain the complete round-trip latency value for this time. After five consecutive probes, the maximum and minimum extreme values are removed, and the average of the remaining three latency values is taken as the original end-to-end round-trip latency data for this sampling period, avoiding the data distortion problem caused by the fluctuation of the single probe signal.
[0072] The third dimension is jitter data: continuously record the end-to-end round-trip delay values for 20 consecutive sampling periods, calculate the difference between the delay values of two adjacent sampling periods, and the value with the largest absolute value among all the difference results is the current delay jitter amplitude, which serves as the original feature data of the jitter dimension. This value can intuitively reflect whether there are irregular and drastic fluctuations in the device's communication delay.
[0073] The fourth dimension is the packet loss type identifier: The edge gateway counts the total number of data packets lost during bidirectional transmission of the device within the sampling period, and analyzes the triggering reason for the loss of each lost data packet, distinguishing four categories: normal service buffer overflow packet loss, line signal attenuation packet loss, channel contention packet loss, and malicious attack active packet dropping; if no packet loss occurs within the sampling period, the packet loss event type identifier is set to an empty field; if packet loss occurs, the corresponding type identifier is filled in according to the dominant cause of packet loss; if multiple packet loss types exist at the same time, the type with the most data packet loss is used as the packet loss type identifier for the current period.
[0074] The fifth dimension is radio frequency signal-to-noise ratio: This is collected only for wireless access warehouse equipment. The edge gateway reads the received signal strength and background noise intensity of the real-time communication between the wireless radio frequency access base station and the equipment, and uses the effective signal strength to subtract the background noise intensity to obtain the original value of radio frequency signal-to-noise ratio. For wired fiber optic direct-connected equipment, this dimension value is uniformly filled with the system's preset stable high value and is not involved in the malicious degradation judgment logic.
[0075] The sixth dimension is slice load: read the channel resources, bandwidth resources, and concurrent connection count of the network slice currently occupied by the device, and calculate the raw value of slice load by weighting and merging them according to the ratio of 0.3, 0.5, and 0.2. The higher the value, the more saturated the current network slice resources are.
[0076] The seventh dimension is backhaul attenuation: For the optical fiber backhaul line connected to the back end of the device's communication link, the real-time optical power values at both ends of the optical module are collected, and the difference between the optical power at the transmitting end and the optical power at the receiving end is calculated. This difference is the original value of backhaul attenuation. The larger the difference, the more severe the signal loss of the optical fiber line.
[0077] The eighth dimension is the data on fake network simulation characteristics: The edge gateway has built-in traffic feature recognition rules to identify three types of malicious simulated traffic in real time: fake device identification data packets, forged business request data packets, and fake probe scan data packets. The total number of such fake data packets within the sampling period is counted as the original value of the fake network simulation characteristics. The higher the value, the more fake traffic is forged in the link, and the higher the risk of link hijacking.
[0078] Furthermore, the network condition labels are divided into four categories: steady-state high quality, instantaneous fluctuations, benign congestion degradation, and malicious hijacking degradation. The specific classification and discrimination logic is as follows:
[0079] When the effective bandwidth utilization rate is greater than the high bandwidth threshold set based on its own characteristics, the end-to-end round-trip latency is less than the low latency threshold set based on its own characteristics, and the packet loss event type identifier is empty, it is judged as a steady-state high-quality label.
[0080] When the effective bandwidth utilization rate is greater than the high bandwidth threshold, the end-to-end round-trip latency is less than the low latency threshold, but the packet loss event type identifier is not empty and the latency jitter amplitude obtained by jitter data quantization is greater than the jitter threshold set based on jitter data, it is identified as an instantaneous fluctuation label.
[0081] When the effective bandwidth utilization rate is between the high bandwidth threshold and the low bandwidth threshold, the network slice resource utilization rate obtained by slice load quantization is greater than the slice congestion threshold set based on slice load, and the backhaul line optical power attenuation value obtained by backhaul attenuation quantization is greater than the attenuation alarm threshold set based on backhaul attenuation, it is identified as a benign congestion degradation label.
[0082] When the effective bandwidth utilization rate is less than the low bandwidth threshold, the radio frequency received signal strength indication value characterizing the radio frequency signal-to-noise ratio is less than the signal security threshold set based on the radio frequency signal-to-noise ratio, the fake network simulation feature data is greater than the fake feature threshold set based on its own features, and the packet loss event type is identified as malicious drop type, it is judged as malicious hijacking degraded label.
[0083] The process of generating the network state quantization score with link risk weight values includes:
[0084] S1.1: Configure the corresponding risk impact factor value and occurrence probability coefficient value for each dimension feature in the original feature data of the eight-dimensional network operating conditions, and multiply the risk impact factor value and occurrence probability coefficient value corresponding to the same dimension feature to obtain the initial risk weight value of each dimension feature.
[0085] Furthermore, the risk impact factor value represents the severity of the harm caused to the operation of warehousing equipment and the security of equipment identity authentication after an anomaly occurs in this dimension. The value range is set from 1 to 10, with a larger value indicating a more severe negative impact. Among them, the risk impact factor for the fake network simulation feature data dimension is assigned a value of 10. An anomaly in this dimension directly indicates that there is malicious hijacking or forged traffic attacks on the link, which can easily lead to major security incidents such as leakage of equipment identity credentials and unauthorized terminal impersonation access. The risk impact factors for the radio frequency signal-to-noise ratio and packet loss type identifier are assigned a value of 8. Low wireless signal and malicious packet loss will directly interrupt the real-time business transmission of the equipment, and are also easy for attackers to launch man-in-the-middle attacks by exploiting communication defects. The risk impact factors for backhaul attenuation and slice load are assigned a value of 6. Slice congestion and fiber attenuation will only cause network lag and business transmission delays, and will not directly generate malicious security risks. The risk impact factors for effective bandwidth utilization, end-to-end round-trip latency, and jitter data are assigned a value of 3, which only affect the smoothness of equipment communication and have the lowest security risk level.
[0086] Furthermore, the probability coefficient represents the level of probability of an anomaly occurring in the daily operation of the warehousing park for that dimension feature. The value range is set from 0.1 to 1.0, with higher values indicating that the dimension feature is more likely to exceed the threshold and exhibit anomalies. The three features of slice load, end-to-end round-trip latency, and jitter data are affected by peak inbound and outbound operations in the park and fluctuate multiple times a day, with a probability coefficient of 0.8. Backhaul attenuation and effective bandwidth utilization only exhibit anomalies during periods of fiber optic aging and concentrated equipment deployment, with a probability coefficient of 0.4. Radio frequency signal-to-noise ratio and packet loss type identification only exhibit anomalies during wireless channel interference and equipment concurrency conflicts, with a probability coefficient of 0.2. Fake network simulation feature data represents malicious attack behavior and rarely occurs in normal daily operation scenarios, with a probability coefficient of 0.1.
[0087] S1.2: Based on the category corresponding to the network condition label, retrieve the dynamic correction coefficient from the pre-configured weight correction coefficient mapping table, and use the dynamic correction coefficient to update the initial risk weight value of each feature dimension to obtain the link risk weight value under the current network condition.
[0088] Furthermore, the configuration logic for the dynamic correction coefficients of the four types of network condition labels is as follows: The steady-state high-quality label represents that the current device communication link has no abnormal risks, and the overall network environment is safe and stable. Therefore, all eight features are equipped with a correction coefficient of 0.5, reducing the initial risk weights and minimizing the impact of feature risks on the overall network score under stable network conditions. The instantaneous fluctuation label only exhibits short-term latency jitter and a small amount of harmless packet loss, without persistent congestion or malicious attacks. The correction coefficients for the slice load, backhaul attenuation, and spurious simulation features are 0.7, while the correction coefficients for the remaining bandwidth, latency, jitter, radio frequency, and packet loss dimensions are 1.0, slightly increasing the weights of fluctuation-related dimensions, while maintaining the original risk levels for the remaining dimensions. For the benign congestion degradation label, caused by peak business activity in the park... With slicing resources saturated and fiber optic line losses exacerbated, and no external malicious attacks, the correction coefficients for the three congestion-related dimensions—slicing load, backhaul attenuation, and effective bandwidth utilization—are set to 1.5, amplifying the risk weight of congestion-related features. The correction coefficients for the remaining dimensions—latency, jitter, packet loss, radio frequency (RF), and spoofing—are set to 0.6, weakening the risk proportion of unrelated dimensions. For malicious hijacking degradation labels, where links exhibit high-risk attack behaviors such as forged traffic, malicious packet loss, and wireless signal interference, the correction coefficients for the three security attack-related dimensions—RF signal-to-noise ratio (RFSNR), packet loss type identifier, and spoofing network simulation features—are set to 2.0, amplifying the weight of malicious risk dimensions. The correction coefficients for the remaining dimensions—bandwidth, latency, jitter, slicing, and backhaul attenuation—are set to 0.8, appropriately reducing the risk proportion of unrelated dimensions.
[0089] Furthermore, after completing the network condition labeling, the current network condition label is used as the search keyword to retrieve eight sets of corresponding dynamic correction coefficients from the weight correction coefficient mapping table. The correction coefficient array is matched one-to-one with the initial risk weight value array according to the dimension. The initial risk weight value of each dimension is multiplied by the corresponding dynamic correction coefficient. The new value obtained after multiplication is the link risk weight value of the current network condition in that dimension.
[0090] S1.3: Normalize the original values of each dimension in the original feature data of the eight-dimensional network condition to obtain the normalized value of each dimension feature. Then multiply the normalized value of each dimension feature by the link risk weight value of the corresponding dimension and sum them to calculate and output the network state quantification score.
[0091] In this embodiment, the normalization process adopts the extreme value standardization method. The control system reads the global maximum and global minimum values of each feature dimension obtained from long-term statistics of the park in advance. For any original feature value of a dimension, the system uses the maximum and minimum extreme values of that dimension as the conversion benchmark to complete the normalization conversion. The closer the converted value is to 1, the more serious the deviation of the current working condition of that dimension from the stable and safe state is, and the higher the risk level. The closer the value is to 0, the more the working condition of that dimension is in the ideal safe range.
[0092] S2: Retrieve the pre-stored valid identity trust base score of the storage equipment, use the link risk weight value as the weighting coefficient, integrate it with the network status quantitative score to calculate the comprehensive security assessment score, and combine it with the network operating condition label to complete the two-way risk classification of the equipment.
[0093] The process of outputting the comprehensive security assessment score includes:
[0094] S2.1: Based on the device identification code stored in the warehouse equipment security management database, retrieve the authentication success and failure records of the corresponding device for the N consecutive historical authentication cycles before the current sampling cycle;
[0095] It should be noted that the warehousing park deploys an independently isolated equipment security management database. This database employs a local encrypted storage architecture, completely physically isolated from the external network. Only the park's internal control server has read-only access permissions. Each connected warehousing device is assigned a dedicated independent storage partition within the database. The partition's unique index is the device's factory-installed identification code, which is permanent and cannot be tampered with. This code distinguishes all AGVs, cameras, terminals, and gateway devices within the park, preventing duplicate or conflicting device identifiers. The database continuously retains complete historical authentication logs for each device. These logs are divided into storage units based on independent authentication cycles. In this embodiment, a single authentication cycle is set to five minutes. Every five minutes, the system automatically performs one round of identity authentication verification on all online warehousing devices. After each authentication cycle is completed, a new authentication record is added to the corresponding device partition. This record clearly indicates whether the authentication result was successful or failed, and simultaneously records the authentication execution timestamp, the authentication level used, and any exceptions triggered during the authentication process.
[0096] In this embodiment, parameter N is the configurable number of sliding window periods. In this warehousing scenario, N is preset to 20, representing the system retrieving all authentication records from the 20 consecutive complete historical authentication periods prior to the current sampling period. This covers all device authentication behaviors within the last 100 minutes, effectively capturing the long-term stable authentication status of the device without consuming excessive database storage resources due to redundant data from excessively long periods. The management system uses the current device identification code as the primary key for retrieval, filtering the 20 most recent authentication period records in the device security management database for that device partition whose timestamps are earlier than the current sampling period. It extracts the authentication success and failure result identifiers from each record, and counts the total number of successful and failed authentications within the 20 periods. These two statistical results are temporarily cached in memory as input data for the Bayesian trust model. After the retrieval is complete, the device security management database read connection is automatically released to avoid database access blocking caused by concurrent retrieval from multiple devices.
[0097] S2.2: Input the retrieved authentication success record and authentication failure record into the pre-built Bayesian trust model, and calculate and output the effective identity trust base score for the current period;
[0098] Furthermore, the structural configuration of the Bayesian trust model includes: setting prior probability baseline parameters, fixing the initial prior probability corresponding to a normal and trustworthy identity to 0.85, fixing the initial prior probability corresponding to an identity with risky tendencies to 0.15, and adding the two types of prior probability parameters to a value equal to 1, satisfying the basic Bayesian operational constraints; then setting likelihood probability judgment parameters, fixing the positive likelihood probability corresponding to the authentication success feature to 0.92, and fixing the negative likelihood probability corresponding to the authentication failure feature to 0.07, with the two likelihood probabilities corresponding to the data matching weights that distinguish between normal and abnormal authentication behaviors; finally setting a score fusion conversion coefficient, uniformly setting the conversion coefficient for converting the posterior probability into a trust baseline score to 100. This conversion coefficient is used to linearly convert probability values in the range of 0 to 1 into intuitive trust scores in the range of 0 to 100. All of the above parameter values are preset fixed values and will not change automatically throughout the entire cycle of model operation.
[0099] Furthermore, the successful authentication records and the failed authentication records are obtained and standardized preprocessing is performed to obtain all feature data of the current period's authentication records. For example, in this embodiment, a set of actual collected data is selected for complete process description. In the current period, a total of 123 successful authentication records and 16 failed authentication records are obtained. Then, the basic statistical features required for Bayesian trust model calculation are extracted for the successful authentication records and the failed authentication records. The core features extracted for successful authentication records are the normal interaction time interval of a single authentication behavior and the matching degree of the fixed device identifier bound to the authentication request initiating device. The normal interaction time interval of a single authentication behavior refers to the actual time spent by the device and the edge gateway to complete a set of identity authentication message interactions. It is compared with the standard compliance time interval obtained by fitting the historical trusted devices in the park to determine whether there is an abnormal interaction delay caused by man-in-the-middle hijacking in this successful authentication. The matching degree of the fixed device identifier bound to the authentication request initiating device refers to the string similarity between the device identifier reported in the authentication message and the unique device identification code fixed by the device at the factory and registered by the platform. It is used to identify whether there is device identifier forgery. The core features extracted for failed authentication records are the number of times the authentication password is triggered incorrectly and the frequency of authentication initiated by unfamiliar device identifiers. After all extraction is completed, the feature data corresponding to the two types of records are converted into a standardized text data sequence without missing items.
[0100] Furthermore, the Bayesian trust model comprises a prior probability calculation layer, a likelihood probability matching layer, and a posterior trust score fusion output layer. All pre-processed feature data of the current period's authentication records are fed into the first layer of the Bayesian trust model: the prior probability calculation layer. The system first reads the overall performance status of the authentication records in the current period. When the number of successfully authenticated records in the current period significantly exceeds the number of failed authentication records, the system retrieves a preset initial prior probability of 0.85 for trusted identity as the baseline prior value for this operation. Taking the current statistical data as an example, the 123 successful records in the current period far exceed the 16 failed records; therefore, the baseline prior probability for this operation is determined to be 0.85. The baseline prior value output from the first layer is completely transmitted to the second layer, the likelihood probability matching layer. The likelihood probability matching layer sequentially traverses all feature data extracted from each authentication record in the current period, comparing each feature to determine whether it belongs to a positive or negative authentication feature, and matching the corresponding preset likelihood probability value. This applies to all positive authentication features corresponding to the 123 successfully authenticated records. A uniform positive likelihood probability of 0.92 is applied, and a uniform negative likelihood probability of 0.07 is applied to all negative authentication features corresponding to the 16 failed authentication records. The system accumulates all the matched likelihood probabilities to obtain the total likelihood sum of positive and negative features. These two accumulated values are then combined with the baseline prior probability from the first layer to complete the standard Bayesian posterior probability calculation process, ultimately outputting a comprehensive posterior probability value in a single interval between zero and one. The comprehensive posterior probability value calculated in the second layer is then completely sent to the third layer, the posterior trust score fusion output layer. The posterior trust score fusion output layer retrieves a pre-set score conversion coefficient of 100 and performs a linear multiplication of the comprehensive posterior probability value with the conversion coefficient to obtain the final effective identity trust base score for the current period. After the conversion, this score is directly output as the sole output result after all authentication records are input into the model, thus completing the Bayesian trust model calculation based on authentication records for a single period.
[0101] Furthermore, the training process of the Bayesian trust model includes: firstly, collecting 15,000 historical authentication records containing both normal and abnormal authentication as a training sample set. Within this training sample set, the proportion of normal authentication samples is set to 80%, and the proportion of abnormal authentication samples is set to 20%. 1,500 samples are then used as an independent verification sample set and do not participate in the training process. During training, the two core parameters—prior probability and likelihood probability—are iteratively updated. The step size of each training iteration is fixed at 0.001, and the total number of iterations is uniformly set to 3,000. Verification is invoked every 100 iterations. The sample set is used to verify the convergence status of the parameters. When the fluctuation range of the output error of the verification sample set is less than 0.002 after 200 consecutive iterations, the model parameters are considered to have converged, and the iterative training process is stopped. The initial credible prior probability of 0.85, risk prior probability of 0.15, positive likelihood probability of 0.92, negative likelihood probability of 0.07, and the 100-score conversion coefficient are all solidified and stored to form a pre-built Bayesian trust model that can be directly retrieved and used. In each subsequent five-minute statistical period, the solidified Bayesian trust model can be directly retrieved to import the current authentication records for real-time score calculation.
[0102] S2.3: Obtain the network status quantification score, the effective identity trust base score, and the link risk weight value of each dimension feature in the eight-dimensional network condition original feature data, and configure the corresponding first fusion weight coefficient, second fusion weight coefficient, and third fusion weight coefficient respectively. Then, multiply the network status quantification score, the effective identity trust base score, and the link risk weight value of each dimension feature by the corresponding first fusion weight coefficient, second fusion weight coefficient, and third fusion weight coefficient respectively, and sum them up to obtain the comprehensive security assessment score.
[0103] This embodiment targets the high network security requirements of industrial warehousing scenarios. The first fusion weight coefficient is preset to 0.45, corresponding to the network status quantification score. This represents the highest proportion of network link risk in the overall security assessment, as wireless communication links in industrial warehousing are highly vulnerable to hijacking and interference attacks. Network risk directly impacts device identity authentication security. The second fusion weight coefficient is 0.35, corresponding to the valid identity trust base score. The device's own historical authentication records are the core basis for determining whether a terminal has been counterfeited, and its weight is the second highest. The third fusion weight coefficient is 0.2, corresponding to the total sum of the eight-dimensional feature link risk weights. This is used to supplement potential risks in the subdivided dimensions, serving as an auxiliary correction item for the overall assessment.
[0104] Furthermore, the control system sequentially retrieves the network status quantification score and multiplies it by the first fusion weight coefficient to obtain the network risk weighted sub-score, corresponding to the real-time network operating conditions. The larger the value, the more severe the network anomaly and the higher the link risk. It then retrieves the effective identity trust baseline score of the storage equipment and performs a reverse conversion calculation based on a unified score range of 0-100 to generate an identity risk conversion score. The specific conversion formula is: the identity risk conversion score equals the difference between 100 and the effective identity trust baseline score. This conversion score is then multiplied by the second fusion weight coefficient to obtain the identity risk weighted sub-score. A larger identity risk weighted sub-score indicates more historical authentication failure records for the equipment and a lower degree of equipment identity trust. The lower the degree, the higher the risk of identity spoofing; retrieve all values of the eight-dimensional link risk weight array, sum them up to obtain the total eight-dimensional link risk weight, and then multiply it by the third fusion weight coefficient to obtain the weighted sub-item score of the subdivided feature risk, corresponding to the potential risk of the subdivided network feature; after completing the calculation of the three weighted sub-item scores, perform a summation operation on the three sub-item scores, and the final value obtained by the summation is the comprehensive security assessment score corresponding to the device in the current sampling period. The comprehensive security assessment score covers three major aspects: real-time network operating conditions, long-term identity credibility of the device, and potential risks of subdivided network features, realizing the coupled quantification of three security elements: network link status, device identity credibility, and single-dimensional network subdivision risk.
[0105] The method of combining network condition tags to complete the two-way risk classification of equipment includes:
[0106] S2.4: Based on the specific category to which the network condition label belongs, query the pre-configured condition-risk offset mapping table to obtain the corresponding risk offset value;
[0107] Furthermore, a mapping table for the local storage conditions and risk offsets of the control server is established. The mapping table uses four types of network condition tags as the primary key for retrieval. Each type of tag is associated with a unique risk offset value. The offset is used to correct the comprehensive security assessment score, reflecting the additional risk increase or risk reduction brought about by different overall network environments. The value can be divided into two categories: positive offset and negative offset. A positive offset value will increase the overall risk assessment, while a negative offset value will decrease the overall risk assessment.
[0108] In this embodiment, the offset configuration rules for the four types of tags are as follows: Steady-state high-quality tags are equipped with a negative offset of -8, indicating that there are no abnormalities in the current network environment, which offsets part of the risk assessment brought by the comprehensive security assessment score; Instantaneous fluctuation tags are equipped with a negative offset of -3, indicating only short-term jitter and packet loss, which slightly reduces the overall risk assessment value; Benign congestion degradation tags are equipped with a positive offset of +5, indicating that service congestion causes continuous network loss, which slightly increases the overall risk assessment; Malicious hijacking degradation tags are equipped with a positive offset of +15, indicating that there is malicious attack behavior on the link, which significantly raises the overall risk assessment level of the device.
[0109] Furthermore, after the system completes the comprehensive security assessment score calculation, it reads the network condition tag bound to the current device, uses the network condition tag as the search keyword to query the condition-risk offset mapping table, and directly extracts the corresponding risk offset value.
[0110] S2.5: The comprehensive safety assessment score and the risk offset value are arithmetically summed to obtain the comprehensive risk judgment value of the equipment. If the risk offset is negative, it is equivalent to subtracting the risk offset from the comprehensive safety assessment score, thus achieving risk reduction; if the risk offset is positive, it is equivalent to adding the absolute value of the risk offset to the comprehensive safety assessment score, thus achieving risk enhancement. It should be noted that regardless of whether the risk offset is positive or negative, the result of the arithmetic summation must be the absolute value.
[0111] S2.6: Read the high-risk threshold value and low-risk threshold value from the pre-configured risk level threshold parameter table;
[0112] This embodiment is adapted to the safety management and control standards of warehousing parks. The preset low-risk threshold value is 30, and the high-risk threshold value is 70. The high-risk threshold value and the low-risk threshold value are fixedly stored in the local risk level threshold parameter table. Each time a risk level determination is performed, the control system automatically reads the two sets of threshold values cached in memory, compares them with the comprehensive risk determination value of the equipment, and completes the automated level classification. The threshold parameters are globally unified, and all warehousing equipment in the park uses the same set of determination standards, ensuring that the risk level determination rules for different areas and different types of equipment are consistent, and avoiding control loopholes caused by differences in regional determination standards.
[0113] S2.7: If the comprehensive risk assessment value of the device is greater than or equal to the high-risk threshold, the device is determined to be at the first risk level. This means that the device has multiple security risks, including unstable identity authentication, abnormal network links, and a high-risk global network environment. It is highly susceptible to security incidents such as identity credential leakage, unauthorized access, and business data hijacking. The authentication verification strength needs to be increased immediately. If the comprehensive risk assessment value of the device is less than or equal to the low-risk threshold, the device is determined to be at the third risk level. The device has stable long-term authentication, all eight-dimensional network conditions are within the safe range, and the global network is a stable and high-quality environment with no security risks. A lightweight and simplified authentication process can be adopted to reduce the device's computing power consumption. If the comprehensive risk assessment value of the device is between the low-risk threshold and the high-risk threshold, the device is determined to be at the second risk level. The device has minor fluctuations in the local network or a small number of historical authentication failure records. There are no high-risk malicious attacks, but there are minor security risks. Maintaining the standard strength authentication strategy can balance security and device operating efficiency. The first risk level is a high-risk level, the second risk level is a medium-risk level, and the third risk level is a low-risk level.
[0114] S3: Retrieve the pre-configured five-level authentication benchmark and hysteresis anti-jitter judgment rules, bidirectionally verify the comprehensive security assessment score and network condition label, and output the gradient policy switching command matching the five-level authentication level.
[0115] The five-level certification benchmark includes five levels: minimalist, lightweight, standard, enhanced, and global.
[0116] This embodiment addresses the differentiated authentication needs of various high-risk devices in a warehousing park by dividing the authentication system into five tiered authentication levels from top to bottom. The security verification strength increases progressively across the five levels, with the required computing power, interaction latency, and number of authentication factors increasing in tandem. This approach balances the operational efficiency of low-risk devices with the security protection needs of high-risk devices. The complete and detailed definition of the five levels is as follows:
[0117] (1) Minimal authentication level: The lowest security verification strength, relying solely on the device's unique identification code to complete one-way verification, without the need for key interaction or multi-factor verification, and the shortest time for a single authentication interaction, is only applicable to low-risk and stable devices;
[0118] (2) Lightweight authentication level: Based on the identity recognition code, a simple static key verification is added, and two-factor authentication is completed. The interaction latency is slightly improved, which is suitable for low-to-medium risk devices with slight network fluctuations and no identity abnormalities.
[0119] (3) Standard authentication level: The default authentication level in the park is integrated with three-factor verification of identity code, session key and device hardware characteristics to balance security and operating efficiency. Most medium-risk devices maintain this level by default.
[0120] (4) Enhanced authentication level: Based on the standard three factors, a second verification of real-time network status is added, and multiple rounds of two-way key interaction are carried out, which greatly increases the complexity of the authentication process and is enabled for medium and high risk devices with congestion and short-term fluctuations.
[0121] (5) Full-domain authentication level: the highest security verification strength, multi-factor cross verification in all dimensions, simultaneous completion of five verifications of identity, key, hardware, network and device operation status, multi-round encrypted session interaction, forced activation for high-risk devices that are maliciously hijacked, and maximized blocking of illegal access behavior.
[0122] The specific steps of S3 include:
[0123] S3.1: Based on the local policy repository, obtain the authentication factor combination requirements, the required number of authentication factors, and the authentication timeout duration corresponding to the simplified authentication benchmark, lightweight authentication benchmark, standard authentication benchmark, enhanced authentication benchmark, and global authentication benchmark, and form a five-level authentication benchmark mapping table.
[0124] The detailed configuration of the parameters for the five-level authentication baseline mapping table in this embodiment is as follows: For the simplified authentication level, the authentication factor combination consists of only the device identification code, with one set of authentication factors. The authentication timeout is preset to 100 milliseconds; if authentication fails to complete within the timeout period, it is automatically considered successful. For the lightweight authentication level, the authentication factor combination consists of two sets: the device identification code and the static local key. There are two sets of authentication factors, and the authentication timeout is preset to 200 milliseconds. A single timeout results in authentication failure, and only after three consecutive failures is the authentication level upgraded. For the standard authentication level, the authentication factor combination consists of three sets: identity recognition, dynamic session key, and device hardware characteristics. For the enhanced authentication level, the authentication factor combination consists of four groups: identity identification code, session key, hardware features, and real-time network verification features. The authentication timeout is preset to 300 milliseconds, and a single timeout is counted in the identity trust decay statistics. For the enhanced authentication level, the authentication factor combination consists of four groups: identity identification code, session key, hardware features, network verification features, and device operating status. The authentication timeout is preset to 800 milliseconds, and failure of any factor verification directly results in authentication failure and triggers a risk alarm.
[0125] S3.2: Match the comprehensive security assessment score with the five-level authentication benchmark mapping table to obtain the preliminary target authentication level;
[0126] In this embodiment, the five-level certification benchmark mapping table is equipped with score range division rules. Each certification level corresponds to a dedicated comprehensive security assessment score range. The higher the score, the higher the security strength of the corresponding certification level. The system quickly locates the preliminary target certification level corresponding to the score through range matching. The range division is adapted to the security control requirements of this warehousing scenario. The specific range matching rules are detailed as follows:
[0127] (1) The comprehensive safety assessment score is [0,20), which matches the simplified certification level. The overall risk of the equipment is extremely low, and the initial target certification level is determined to be simplified.
[0128] (2) The comprehensive safety assessment score is [20, 40), which matches the lightweight certification level. The equipment has a very slight risk, and the initial target certification level is determined to be lightweight.
[0129] (3) The comprehensive safety assessment score is [40, 60), which matches the standard certification level. The equipment risk is at a medium level, and the preliminary target certification level is used as the benchmark.
[0130] (4) The comprehensive security assessment score is [60, 80), which matches the enhanced authentication level. The device has obvious network or identity risks, and the initial target authentication level is determined to be enhanced.
[0131] (5) The comprehensive security assessment score is [80, 100], which matches the full domain certification level. The overall security risk of the equipment is extremely high, and the initial target certification level is determined to be full domain.
[0132] S3.3: Compare the pre-configured risk level score corresponding to the network condition label with the preliminary target authentication level, and select the level with the higher authentication level as the final target authentication level;
[0133] In this embodiment, risk level scores are pre-configured for four types of network condition labels. Each risk level score is bound to a one-to-one five-level authentication level. The higher the risk level score, the stronger the corresponding authentication level. The corresponding scores for the four types of labels are as follows: steady-state high-quality label risk level score of 15, matching the simplified authentication level; instantaneous fluctuation risk level score of 35, matching the lightweight authentication level; benign congestion degradation risk level score of 55, matching the standard authentication level; and malicious hijacking degradation risk level score of 85, matching the full-domain authentication level.
[0134] For example, if the device's overall security assessment score only matches the lightweight authentication level, but the current network condition label is malicious hijacking and deterioration, corresponding to the full-domain authentication level, then the system directly selects the full-domain authentication level as the final target authentication level, prioritizing the satisfaction of high-strength authentication protection requirements in high-risk network environments. Conversely, if the network condition is only stable and excellent, matching the simplified authentication level, but the device's overall security assessment score matches the enhanced authentication level, then the enhanced authentication level is selected as the final target authentication level, prioritizing the control of the device's own identity risk, achieving two-way constraints on network conditions and device identity risk, and enabling a higher-strength authentication strategy when a high risk occurs in either dimension.
[0135] S3.4: Read the currently effective authentication level from the device's current authentication status register, compare the currently effective authentication level with the final target authentication level, and call the pre-configured hysteresis stabilization judgment rule to perform stabilization judgment. When it is determined that the level switching condition is met, generate a gradient strategy switching instruction to switch from the currently effective authentication level to the final target authentication level. The hysteresis stabilization judgment rule includes the continuous compliance time threshold and hysteresis offset of the level switching. The hysteresis offset includes the level upgrade hysteresis offset and the level downgrade hysteresis offset.
[0136] Furthermore, the hysteresis anti-jitter judgment rule is designed to solve the problem of frequent switching of authentication levels caused by short-term instantaneous fluctuations and instantaneous jumps in scores in the warehouse network. It avoids the frequent generation of device keys and frequent issuance and destruction of gateway credentials due to repeated changes in authentication strategies in a short period of time, which would occupy the computing resources of the park network and equipment. The rule includes two core control parameters: the continuous compliance time threshold and the hysteresis offset. This embodiment presets a continuous compliance time threshold of 2 seconds, corresponding to the continuous collection of M sampling time values with a sampling period of 5ms, and continuously collects 400 sets of sampling data within 2 seconds. The hysteresis offset is used to distinguish the leniency of the judgment for level upgrade and level downgrade. When the risk increases, the 2-second anti-shake delay verification is only initiated when the final target certification level is at least 3 levels higher than the current certification level. Therefore, the hysteresis offset for level upgrade is set to 3. When the risk decreases and the certification level is downgraded, the level downgrade is required to initiate the anti-shake verification. If the downgrade is less than 2 levels, downgrade is not allowed. Therefore, the hysteresis offset for level downgrade is set to 2. The judgment standard for upgrading the certification level when the equipment risk increases is more lenient, and the judgment standard for downgrading the certification level when the risk decreases is more stringent. This ensures that certification is quickly strengthened in high-risk scenarios and that certification is slowly restored to a more lenient level in low-risk scenarios, avoiding repeated risk fluctuations.
[0137] The process of calling the pre-configured hysteresis stabilization judgment rules to perform stabilization judgment includes:
[0138] S3.4.1: When it is determined that the final target authentication level is higher than the current effective authentication level, first calculate the difference between the final target authentication level and the current effective authentication level as the first level difference value; if the first level difference value is greater than or equal to the level upgrade backlash offset 3, then start the pre-configured 2s de-jitter delay waiting period, and continuously acquire the final target authentication level at M sampling times within the de-jitter delay waiting period. If the final target authentication level at all M sampling times is higher than the current effective authentication level, then it is determined that the level upgrade condition is met. In this embodiment, M is 400, corresponding to all sampling periods within 2s;
[0139] Furthermore, after all 400 sets of sampled data within the continuous statistical period are completed, the system performs batch verification of the target authentication level at all sampling times. Only when the final target authentication level obtained from all 400 samples is higher than the current effective authentication level of the device, and there is no sampling level that falls back to or below the current effective authentication level, is it determined that the current network and device risk is a continuous increase rather than a temporary score jump caused by instantaneous fluctuations, thus meeting the level upgrade conditions and allowing the authentication level upgrade switching operation to be performed. If the level difference is insufficient for the upgrade back offset, or if there is any sampling target authentication level drop in any of the 400 sets of samples, it is determined to be a short-term instantaneous risk fluctuation, does not meet the level upgrade conditions, maintains the current effective authentication level unchanged, resets the delay waiting period count, and waits for the next round of risk assessment.
[0140] S3.4.2: When it is determined that the final target authentication level is lower than the current effective authentication level, first calculate the difference between the current effective authentication level and the final target authentication level as the second level difference. If the second level difference is greater than or equal to the level downgrade hysteresis offset 2, then start the de-jitter delay waiting period. During the de-jitter delay waiting period, continuously acquire the final target authentication level at M sampling times. If the final target authentication level at all M sampling times is lower than the current effective authentication level, then it is determined that the level downgrade condition is met.
[0141] Furthermore, due to the larger offset setting for tier reduction, the criteria for lowering the authentication level are more stringent. The system must ensure that the final target authentication level obtained from 400 consecutive samples is consistently lower than the current effective authentication level, and that there is no instance of the sampled level rising back to or above the current effective authentication level, before determining that the device risk has completed a continuous decline and meets the tier reduction conditions. If the tier difference is insufficient for the tier reduction offset, or if the target level rises in any sample within the period, it indicates that there are fluctuations in network conditions and device identity trust scores, and the risk has not been stably eliminated. In this case, lowering the authentication level is prohibited, and a high-intensity authentication strategy is maintained. The delay count is reset and a new full-cycle sampling is waited for to prevent premature reduction of security verification strength before the risk is completely eliminated, which could create security control vulnerabilities.
[0142] S3.4.3: When it is determined that the level promotion condition or the level demotion condition is met, a level switching permission signal is output as a trigger condition for generating the gradient policy switching instruction; when it is determined that the level promotion condition or the level demotion condition is not met, the current effective authentication level is maintained unchanged, and the generation of gradient policy switching instructions is prohibited.
[0143] Furthermore, after the system completes the full delay period sampling and verification, it performs corresponding operations in two scenarios:
[0144] (1) First scenario: When the conditions for level promotion or level demotion are met, the control system outputs a high-level level switching permission signal. The high-level level switching permission signal serves as the only trigger signal for the generation of gradient strategy switching instructions. Upon receiving the high-level level switching permission signal, the system immediately enters the instruction generation process. Based on the current effective authentication level and the final target authentication level, the switching direction is marked, such as promotion or demotion, and the target level identifier. The gradient strategy switching instruction data packet is fully encapsulated.
[0145] (2) Second scenario: Neither the level promotion condition nor the level demotion condition is met. The system outputs a low-level signal to prohibit switching, directly terminates the current strategy matching process, does not generate any switching instructions, and the device maintains the current effective authentication level in the register to continue to execute the original authentication rules. At the same time, it resets all counting parameters of hysteresis anti-shake and the delay waiting period timer, and waits for the next sampling period to re-execute the complete risk judgment and level matching process.
[0146] Furthermore, the generated gradient policy switching instruction carries complete identification information, including seven core fields: device unique identification code, switching direction identifier, final target authentication level number, currently effective authentication level number, switching trigger timestamp, current device risk comprehensive judgment value, and current network condition label.
[0147] S4: Parse the gradient strategy switching command, revise the warehouse equipment authentication execution rules to adapt to the current risk level, and simultaneously issue temporary authentication credit credentials to the connected edge gateway;
[0148] The specific steps of S4 include:
[0149] S4.1: Parse the received gradient policy switching instruction and extract the target authentication level identifier carried in it;
[0150] Furthermore, the gradient strategy switching instruction output channel is continuously monitored. Once a switching instruction data packet is detected being pushed to the channel, the complete switching instruction data packet is immediately read, and a layered parsing operation is performed. The core fields are split according to the internal field separator of the gradient strategy switching instruction, and the target authentication level identifier field is extracted separately and cached in memory. The target authentication level identifier is a fixed numerical code, with four levels: minimal authentication level code 1, lightweight authentication level code 2, standard authentication level code 3, enhanced authentication level code 4, and global authentication level code 5. The numerical code facilitates the system to quickly retrieve and match the corresponding parameters in the five-level authentication benchmark mapping table without parsing the text level name, thus improving the parsing and operation speed.
[0151] S4.2: Based on the extracted target authentication level identifier, query the pre-configured authentication policy rule base to obtain the target authentication factor combination requirements and target session key derivation method corresponding to the level;
[0152] Furthermore, the authentication policy rule base is an offline, pre-built, and tamper-proof relational mapping database adapted to the business scenario of hierarchical authentication of terminal identities across the entire domain. The construction process of the authentication policy rule base is as follows: First, the entire business domain is divided into five fixed authentication levels, with the level codes from low to high as follows: Level 1 Basic Visitor Authentication Level, Level 2 Ordinary Terminal Access Authentication Level, Level 3 Business Interaction Authentication Level, Level 4 Confidential Data Access Authentication Level, and Level 5 Core Permission Control Authentication Level. Each authentication level is configured with a unique and non-repeatable text-based level identifier. At the same time, the fixed preset configuration of the internal relational fields and matching algorithm parameters of the rule base is completed. The authentication policy rule base has three types of core relational storage fields: authentication level identifier field, authentication factor combination requirement field, and session key derivation method field. Field matching and retrieval adopts a built-in precise hash matching algorithm. The hash matching algorithm has a fixed hash bucket capacity of 512, a fixed algorithm retrieval conflict threshold of 8, and a fixed single retrieval traversal delay parameter of 12ms. All algorithm parameters are fixed when the rule base is built and cannot be modified independently during business operation.
[0153] Furthermore, the specific steps in S4.2 include:
[0154] (1) Read the target authentication level identifier that has been extracted from the front-end business link. First, determine whether the identifier belongs to the category of the five-level compliance level identifiers pre-stored in the authentication policy rule base. The system has built-in identifier compliance verification standards. The compliance level identifiers only include five categories: Level 1 basic visitor authentication identifier, Level 2 ordinary terminal access authentication identifier, Level 3 business interaction authentication identifier, Level 4 confidential data access authentication identifier, and Level 5 core permission control authentication identifier. If the extracted identifier does not belong to the five categories of compliance identifiers, the query will be terminated directly and an abnormal identifier prompt will be returned. If the extracted identifier belongs to the five categories of compliance identifiers, the identifier format will be standardized, and redundant whitespace characters before and after the identifier will be eliminated. The identifier will be standardized into a standard target authentication level identifier text format that can be recognized by the authentication policy rule base. The standardized standard target authentication level identifier will be retained for retrieval and matching.
[0155] (2) Input the standard target authentication level identifier into the hash matching algorithm. The hash matching algorithm has a fixed text encoding bit length of 64 bits. It performs fixed 64-bit hash encoding on the input level identifier to generate a unique retrieval code value corresponding to the level identifier. Then, the hash matching algorithm divides the retrieval storage partition according to the fixed hash bucket capacity of 512. It locates the corresponding hash storage partition according to the generated retrieval code value. It compares the level identifier encoding in the database with each entry in the corresponding partition. During the comparison process, the number of encoding conflicts is accumulated. When the number of encoding conflicts does not exceed the preset 8-conflict threshold, it directly locates a single completely matching level entry in the database. When the number of encoding conflicts reaches the 8-conflict threshold, it starts a second recursive verification retrieval. The recursive retrieval depth is fixed to three layers until a completely consistent authentication level entry in the database is matched.
[0156] (3) Read the target authentication factor combination requirements from the matching binding level entries. In this embodiment, the five authentication levels are pre-bound with fixed and non-reusable authentication factor combination requirements. All combination requirements are pre-entered into the rule base to complete the association binding. Among them, the first level basic visitor authentication level corresponds to the single device fingerprint factor authentication combination requirement, the second level ordinary terminal access authentication level corresponds to the device fingerprint plus account password two-factor authentication combination requirement, the third level business interaction authentication level corresponds to the device fingerprint plus account password plus real-time SMS verification code three-factor authentication combination requirement, the fourth level confidential data access authentication level corresponds to the device fingerprint plus account password plus hardware key plus face verification four-factor authentication combination requirement, and the fifth level core permission control authentication level corresponds to the device fingerprint plus account password plus hardware key plus face verification plus background manual review five-factor authentication combination requirement.
[0157] (4) Synchronously read the target session key derivation method of the binding level exclusive binding from the matching binding level entries. In this embodiment, the five authentication levels are bound to exclusive key derivation algorithms and a complete set of fixed operating parameters. All key derivation parameters are pre-stored in the rule base associated entries and do not require secondary configuration during the running stage. Among them, the first-level basic visitor authentication level is bound to the SHA-256 key derivation method. The hash iteration number of this derivation algorithm is fixed at 60 times and the key salt length is fixed at 32 bytes. The second-level ordinary terminal access authentication level is bound to the HKDF standard key derivation method. The pseudo-random function iteration round of this derivation algorithm is fixed at 40 rounds, the basic length of the derived key is fixed at 48 bytes, and the salt offset parameter is fixed at 16. The third-level business interaction authentication layer is bound to the PBKDF2 key derivation method, with the algorithm hash unit using the SHA-384 type and the password iteration encryption number fixed at 120 times; the fourth-level confidential data access authentication layer is bound to the ECDH elliptic curve key derivation method, using the secp256r1 fixed elliptic curve parameter group, and the point-to-point key negotiation interaction number fixed at 4 times; the fifth-level core permission control authentication layer is bound to the national cryptographic SM2 collaborative key derivation method, with the block encryption unit length fixed at 64 bytes, the multi-party key aggregation verification number fixed at 6 times, and this time matching the second-level entry, synchronously reading and obtaining the HKDF target session key derivation method with 40 iteration rounds, a basic key length of 48 bytes, and a salting offset parameter of 16;
[0158] (5) Bind and encapsulate the target authentication factor combination requirements obtained in this round of query with the target session key derivation method, and at the same time retrieve the hash matching algorithm's retrieval time data for this retrieval, verify whether the retrieval time is less than the preset 12ms traversal delay parameter. If the verification is successful, output the two types of query results completely. If the verification fails, restart the single hash matching retrieval until the retrieval time meets the standard and output the results.
[0159] S4.3: Update the currently effective authentication factor combination requirements and the currently effective session key derivation method to the target authentication factor combination requirements and the target session key derivation method respectively, and complete the revision of the warehouse equipment authentication execution rules;
[0160] Furthermore, after the control server completes the parameter retrieval, it sends an authentication rule update notification message to the edge gateway bound to the corresponding warehouse device. The message carries the complete target authentication factor combination requirements and the target session key derivation method text parameters. After receiving the update message, the edge gateway synchronously modifies the locally cached authentication execution rule configuration file of the device, overwriting the original effective factor rules and key derivation logic in the file, and completes the local revision of the rules.
[0161] S4.4: Based on the target authentication level identifier, query the pre-configured level-validity period mapping table to obtain the corresponding credential validity period;
[0162] Furthermore, a local storage hierarchy-validity mapping table is implemented on the control server. The hierarchy-validity mapping table uses a five-level hierarchical numerical code as the primary key. Each level is associated with a unique temporary authorization credential validity period. The higher the security level of the authentication, the shorter the validity period of the corresponding temporary credential. Shortening the validity period can reduce the security risks caused by credential leakage in high-risk scenarios. The validity period of credentials in low-risk, relaxed authentication levels is longer, reducing the interaction overhead caused by frequent credential updates by the gateway.
[0163] In this embodiment, the validity period of the five-level supporting credentials is configured as follows: 1200s for the simplified authentication level, 600s for the lightweight authentication level, 300s for the standard authentication level, 120s for the enhanced authentication level, and 30s for the full-domain authentication level. The system retrieves the level-validity period mapping table using the target authentication level's numerical code, extracts the corresponding number of seconds, uses it as the built-in validity period parameter of the temporary credit credential, and writes it into the credential's extended information field to achieve controllable and differentiated configuration of credential validity period under different risk scenarios.
[0164] S4.5: Generate the main information of a temporary authentication and credit certificate based on the current identification code and current timestamp of the warehouse equipment;
[0165] Furthermore, the main information of the temporary authentication and trust credential is the core plaintext identifier field of the credential, used by the edge gateway to identify the device to which the credential belongs and the time of credential generation. The main information of the temporary authentication and trust credential is composed of two fixed fields. The first field is a unique and tamper-proof identification code for the device, ensuring that the credential is bound to the device one by one and cannot be reused across devices. The second field is a high-precision millisecond-level timestamp from the management server, which accurately records the time of credential generation and is used by the gateway to verify the credential generation sequence and intercept expired, replay, and forged credential data packets. After the two fields are concatenated, a complete plaintext credential is generated. The plaintext is not encrypted throughout the process and only serves as the credential identification. After receiving the credential, the gateway can directly read the main information to quickly match the corresponding device cache record without prior decryption, improving the efficiency of gateway credential verification and processing. The main information and the subsequently encrypted time-limited credential extension information are combined to form a complete temporary trust credential.
[0166] S4.6: Using the updated target session key derivation method, derive the credential encryption key from the currently effective session key, and encrypt the credential extension information containing the validity period of the credential using the credential encryption key to generate a temporary authentication and trust credential.
[0167] Furthermore, the specific steps of S4.6 include:
[0168] (1) Retrieve the target session key derivation method. In combination with the authentication level binding rules, in this embodiment, it is assumed that the business scenario uses the HKDF target session key derivation method dedicated to the authentication level of the secondary ordinary terminal access. It is confirmed that the updated standard HKDF derivation operation mode is enabled this time, and the established unmodifiable algorithm parameters are used. At the same time, the original session key that is currently in effect within the link is retrieved. The original session key is the compliant session key that is retained after the identity verification interaction of the previous level. The original encoding length of the key is fixed at 48 bytes. The integrity of the currently effective session key is verified. The system has a built-in key integrity verification byte threshold. The complete key byte count is 48 bytes. If the byte count meets the standard, the key can participate in the derivation operation. If the byte count is missing, the key derivation process is terminated directly and a key damage prompt is returned. This time, the current effective session key byte count is verified to be 48 bytes, which meets the derivation admission conditions.
[0169] (2) Based on the updated HKDF session key derivation method, a dedicated credential encryption key is generated through hierarchical operation. The HKDF algorithm is divided into two progressive operation stages: key extraction and key expansion. First, key extraction is performed. The original session key is pre-processed by salting it with a preset salting offset value of 16. Combined with 40 rounds of fixed pseudo-random function iteration, the 48-byte currently effective session key is subjected to primary desensitization extraction. The output is a 32-byte intermediate key material. Then, the key expansion stage is entered. Based on the 32-byte intermediate key material, the algorithm expands the key field in a directional manner according to the 48-byte derived key base length standard. It is adapted to the dedicated encryption computing power specification for credential encryption and finally derives an independent and dedicated credential encryption key. The fixed byte length of the credential encryption key output in this derivation is 32 bytes. This key is only used for the encryption operation of this temporary credit credential and is independent of the original session key and cannot be mixed. The key is only effective once in a single credential generation cycle.
[0170] (3) Assemble and integrate the complete information of the credential extension to be encrypted. The core collection fields are the validity period of the credential and the supporting compliant extended fields. First, configure the fixed value of the validity period of the temporary authentication credit credential. Combined with the secondary terminal access business standard, the validity period of the credential is uniformly set to 1800 seconds. The system collects the complete credential extension information according to the fixed business format. In addition to the core validity period field, three types of auxiliary extended fields are bound to the terminal device traceability code, the authentication serial number, and the authentication level traceability identifier. All fields are uniformly converted to the platform standard plaintext format. The overall character length of the plaintext information is fixedly controlled at 260 characters. The system automatically removes redundant spaces and redundant line breaks in the plaintext to ensure that the format of the credential extension plaintext information sent to the encryption module is uniform and avoids the encryption offset problem caused by messy format.
[0171] (4) Based on the 32-byte credential encryption key derived from the credential, the AES block encryption algorithm dedicated to the business credit credential is used to complete the plaintext encryption. In this case, the AES 128-bit block encryption mode is selected. The length of the encryption block is fixed at 128 bits, the number of encryption iterations is fixed at 10 rounds, the length of the algorithm initial vector character is fixed at 16 bits, and the initial vector is a random sequence that is fixed offline in the system. It is not dynamically changed during the business encryption stage. At the same time, the encryption padding mode is set to the standard PKCS7 padding mode, and the padding byte unit is fixed at 8 bits.
[0172] (5) The 260-character extended plaintext information of the voucher is sent to the input end of the AES block encryption algorithm. The 32-byte exclusive voucher encryption key is called as the unique encryption key. With 10 rounds of fixed encryption iterations, 16-bit solidified initial vector, and 8-bit PKCS7 padding byte parameters, the entire extended information of the voucher containing the 1800-second voucher validity period is subjected to full-domain symmetric encryption. During the encryption process, the validity period identifier is bound to each field. The encryption permission of the valid validity period field inside the voucher is locked so that it cannot be tampered with. After the encryption operation is completed, the concatenated voucher encrypted ciphertext is output. The ciphertext has an internal, non-removable validity period binding mark. The backend can recognize and read the internal preset 1800-second valid validity period parameter.
[0173] (6) A global validity check header identifier is added to the encrypted ciphertext. The validity check header encoding length is fixed at 24 bits and is used for the background to verify the remaining validity period of the cipher. The verification header parameters and the encrypted ciphertext are bound as an inseparable whole. After integration, a compliant temporary authentication and credit certificate is generated. This certificate is encrypted based on the derived exclusive key and has a built-in fixed validity period of 1800 seconds. It has the ability to automatically verify validity and expire.
[0174] S4.7: Encapsulate the generated temporary authentication and trust credentials into a delivery message, and simultaneously deliver the delivery message to the edge gateway through the encrypted communication link established in advance with the edge gateway.
[0175] Furthermore, a permanent encrypted dedicated communication link is pre-established between the control server and each edge gateway within the area. This link employs a two-way identity pre-verification mechanism, allowing only the control server and authorized edge gateways to send and receive messages. External networks and unauthorized gateways cannot access the link to transmit data. Message transmission is encrypted throughout the entire link, preventing data packet theft or tampering during credential issuance. The control system uses the complete temporary authentication and trust credential as the core payload of the message, adding three auxiliary fields: message verification code, issuance timestamp, and target edge gateway number. This is encapsulated into a standardized issuance message and pushed point-to-point to the corresponding area edge gateway via the encrypted communication link. Upon receiving the message, the edge gateway first verifies the integrity of the message verification code. If the verification passes, it extracts the temporary authentication and trust credential from the message, separates the credential body information from the encrypted extended ciphertext, caches it locally in a dedicated credential storage partition, and binds it to the corresponding device identification code. During device authentication interaction, the edge gateway reads the cached temporary authentication and trust credential to complete the session authorization.
[0176] S5: Continuously collect original feature data of eight-dimensional network conditions, update network condition labels in real time, and restore the initial authentication rules step by step from low to high level according to the five-level authentication benchmark when the network condition label returns to a stable and high-quality state. Reuse the original session key of the device before adjustment, destroy the temporary authentication and trust credentials of the edge gateway step by step, and return to the benchmark authentication state.
[0177] The process involves continuously collecting original feature data of the eight-dimensional network operating conditions, updating network operating condition labels in real time, and restoring the initial authentication rules level by level from low to high according to the five-level authentication benchmark once the network operating condition labels return to a steady state of high quality. This includes:
[0178] S5.1: Collect the original feature data of the eight-dimensional network condition of the warehouse access device according to the preset periodic sampling interval, obtain the updated eight-dimensional feature vector of the current sampling period, and continuously input the updated eight-dimensional feature vector into the pre-trained lightweight gradient boosting machine classification model to obtain the updated network condition label of the current sampling period.
[0179] Furthermore, the specific steps in S5.1 include:
[0180] (1) Define the entire warehousing area collection scope, covering the four major equipment access areas of the warehousing inbound operation area, warehousing sorting operation area, warehousing warehouse area, and warehousing central control room. All wired and wireless access terminals within the entire area are uniformly designated as access devices. The fixed periodic sampling interval for this business is uniformly set, and the periodic sampling interval duration is fixed at 2s. At the same time, the fixed collection dimension for this collection is locked in advance, and the original feature dimension of the eight-dimensional network working condition established in the previous text is strictly followed. The collection order remains fixed and cannot be changed throughout the process.
[0181] (2) According to the periodic sampling interval of 2s, the real-time raw operating condition data of the access devices are collected synchronously across the entire domain. After each 2s timing node, the warehouse network management platform links the edge acquisition gateway to synchronously capture the real-time values of the eight-dimensional raw features of all online access devices in the entire warehouse domain. Among them, the channel resource occupancy ratio weight is fixed at 0.2. The backhaul attenuation is quantized into the backhaul line optical power attenuation value and measured in decibels. The false network simulation feature data is dimensionless scoring data in the range of 0 to 100. After the 2s sampling of a single round, the eight-dimensional raw measured data of the access devices in the entire domain are collected. The null value collection data of offline power failure devices are removed, and the valid online device operating condition data are retained. The data are integrated and collected to form the original eight-dimensional feature dataset of the current sampling period.
[0182] (3) Perform extreme value normalization on the original eight-dimensional feature dataset of the current period to generate an updated eight-dimensional feature vector for the current sampling period of a compliant input model;
[0183] (4) Load the lightweight gradient booster classification model. The lightweight gradient booster classification model adopts a hierarchical tree ensemble structure. The top layer is set with a feature input adaptation layer, the middle layer is a stacked decision tree ensemble learning layer, and the bottom layer is set with a classification output discriminant layer. The three-layer structure has unidirectional data transmission and cannot be reversed. First, set the basic hyperparameters of the lightweight gradient booster classification model. The learning rate is fixed at 0.06, the maximum number of leaf nodes in a single iteration is fixed at 12, the total number of ensemble decision trees is fixed at 46, the maximum depth of a single decision tree is fixed at 5 layers, the regularization coefficient is divided into two categories, the L1 regularization coefficient is fixed at 0.02, the L2 regularization coefficient is fixed at 0.08, the training batch sample size is fixed at 120 groups, and the training early stopping tolerance iteration number is fixed at 25 rounds.
[0184] Furthermore, the pre-training process of the lightweight gradient boosting machine classification model includes: First, a dataset of labeled historical warehouse operating conditions from across the entire network is collected as the training data source, totaling 18,000 sets of eight-dimensional feature samples from warehouse history. The sample labels are manually matched to four categories of operating conditions, with the following sample ratios: steady-state high-quality samples 42%, instantaneous fluctuation samples 28%, benign congestion deterioration samples 17%, and malicious hijacking deterioration samples 13%. 15,200 sets of samples are used as the training set, and 2,800 sets of samples are used as the independent test set. Before training, all historical samples are preprocessed according to the aforementioned normalization and labeling digitization rules. The training process relies on a fixed learning rate of 0.06 to iteratively update the tree node weight parameters. After each round of sample batch training, the classification error of the test set is calculated. When the classification error of the test set no longer decreases after 25 consecutive rounds of iteration, it is determined that the parameters of the lightweight gradient booster classification model have converged and the training is complete. After training, the classification threshold of all tree node weights is fixed, and the four types of working condition labels are bound to the fixed model output codes: steady-state high quality label is coded as 1, instantaneous fluctuation label is coded as 2, benign congestion degradation label is coded as 3, and malicious hijacking degradation label is coded as 4. After training, the model is sealed and finalized to obtain a pre-trained lightweight gradient booster classification model that can be directly used for inference.
[0185] (5) The current sampling period updates the eight-dimensional feature vector and continuously feeds it into the pre-trained lightweight gradient booster classification model to complete the inference classification. First, a single set of updated eight-dimensional feature vectors is fed into the top feature input adaptation layer of the model. The input adaptation layer verifies the three items: vector dimension, normalized interval label, and mapping value. After verification, the feature data is transmitted to the middle layer of 46 fixed structure decision trees integrated learning layer. Each 5-layer deep decision tree relies on the training solidified node weights and combines the predetermined threshold values of all network conditions to perform feature branch discrimination layer by layer. After multiple decision trees output the branch discrimination results simultaneously, the lightweight gradient booster classification model integrates and weightedly fuses the discrimination results of all trees and transmits the fusion result to the bottom classification output discrimination layer. The output discrimination layer matches the preset label encoding rules, outputs the corresponding encoding value, maps to obtain the corresponding network condition text label, and finally outputs the updated network condition label corresponding to the current 2-second sampling period. A new set of updated eight-dimensional feature vectors is generated every 2 seconds and the above inference process is repeated to realize the periodic dynamic update of the warehouse network condition label.
[0186] S5.2: Based on a preset sliding time window, obtain multiple updated network condition labels corresponding to multiple consecutive sampling periods within the sliding time window, and perform majority voting statistical processing on the multiple updated network condition labels, and take the network condition label with the most votes as the final updated network condition label at the center time within the sliding time window.
[0187] Furthermore, to avoid misjudging network condition labels as steady-state and high-quality due to instantaneous signal fluctuations during a single sampling, the system is configured with a sliding time window of 100 sampling periods. The window slides forward in real time, adding a new set of updated network condition labels every 2ms, while removing the oldest expired label in the window, continuously retaining label data for 100 consecutive sampling periods within the window. After each window slide update, the system performs majority voting on the 100 labels in the window, counting the total number of occurrences of each of the four types of labels: steady-state and high-quality, instantaneous fluctuations, benign congestion degradation, and malicious hijacking degradation. The system compares the number of votes for each of the four types of labels and selects the label with the highest number of votes as the final updated network condition label at the current sliding window center moment. If there is a tie in the scenario where the number of votes for two types of labels is completely equal, the system defaults to retaining the label with the higher risk level as the final label. For example, if the number of votes for steady-state and high-quality and instantaneous fluctuations is the same, the final label is determined to be instantaneous fluctuations. The system strictly controls the criteria for determining network condition recovery to prevent misjudging the link as completely safe based on a brief period of signal stability.
[0188] S5.3: When the final updated network condition label is detected to have changed from a non-steady-state high-quality type to a steady-state high-quality type, the authentication level recovery process is triggered;
[0189] Furthermore, the control system continuously compares the final updated network condition label output by each sliding window with the label output by the previous window, monitoring label type switching behavior in real time. Only when the final labels output by two consecutive sliding windows are all steady-state and of high quality, and the label of the previous window is one of three: transient fluctuation, benign congestion degradation, or malicious hijacking degradation, is it determined that the link condition has completed continuous recovery and there is no longer any abnormal network risk, and the complete authentication level recovery process is immediately triggered. If a steady-state and high-quality label appears occasionally in a single window, the recovery process is not triggered, and the current high-intensity authentication strategy continues to be maintained to avoid the illusion of transient stability causing the strategy to fall back prematurely. After the authentication level recovery process is triggered, the system locks all risk assessment and level switching processes for the device, suspends the generation of new gradient strategy switching instructions, and prioritizes the execution of the entire process of level-by-level restoration, credential destruction, and key reuse. Only after all processes are completed does the normal risk assessment cycle resume.
[0190] S5.4: During the authentication level recovery process, retrieve the initial authentication level identifier and initial authentication execution rules recorded by the device before the level switch occurred from the warehouse equipment security management database;
[0191] Furthermore, when the device executes the gradient policy switching command for the first time to advance the tier upgrade, the management system simultaneously writes the original effective authentication tier identifier and complete initial authentication execution rules from the device register before the switching operation into the device's dedicated partition in the device security management library. This is then permanently stored, bound to the switching operation timestamp, as the baseline original configuration for the recovery process. After triggering the authentication tier recovery process, the system uses the device identification code as the primary key to retrieve the initial authentication tier numeric code and complete initial authentication execution rule parameters stored in the partition before the tier switch. These are then cached in the dedicated memory partition for the recovery process, without modifying or overwriting the original storage records. This ensures that every risk recovery accurately restores the baseline authentication configuration before the policy adjustment, preventing configuration loss or incorrect restoration parameters.
[0192] S5.5: Compare the initial authentication level identifier with the currently effective authentication level identifier to determine the step-by-step downgrade path required to gradually reduce the current effective authentication level to the initial authentication level;
[0193] Furthermore, the system reads the cached initial authentication level code and the device's currently effective authentication level code, sorts out all intermediate levels between the two according to the five-level security strength sorting rules, and generates an ordered step-by-step degradation path by sorting them from high to low security strength.
[0194] For example, the logic for generating a step-by-step degradation path is as follows: When the risk of a device increases, it is upgraded from the initial standard level (code 3) to the global level (code 5). The current effective level is 5, the initial level is 3, and there is an enhanced level (code 4) in between. Therefore, the step-by-step degradation path is ordered as global level - enhanced level - standard level. Only one level is downgraded at each step, and direct jumps across levels are not allowed. If the initial level of the device is minimalist (code 1), the current effective level is enhanced (code 4), and there are standard (code 3) and lightweight (code 2) in between, the degradation path is enhanced - standard - lightweight - minimalist. The degradation is strictly downgraded according to the level strength. Each level independently performs a complete switch, credential destruction, and key replacement.
[0195] S5.6: Generate and execute level downgrade switching instructions level by level according to the hierarchical order in the described step-by-step downgrade path.
[0196] Furthermore, the system iterates through the codes of each level in the progressive degradation path array, processes them sequentially according to the array's order, and generates a dedicated level downgrade switching instruction for each intermediate target level in the path. This instruction carries special fields such as the current device identification code, the currently effective level, the target level for this downgrade, the switching direction (degradation), and the recovery process identifier, distinguishing between regular risk switching instructions and recovery process degradation instructions. Once each downgrade switching instruction is generated, it is directly pushed to S4, where S4.1 through S4.7 are executed to complete the single-level degradation operation. Only after the entire single-level process is completed and the edge gateway returns a successful rule revision receipt does the system read the next level code from the path array and generate the next degradation switching instruction. Multi-level degradation operations are not executed in parallel, ensuring the degradation process is executed in an orderly, step-by-step manner.
[0197] The reused native session key of the device before adjustment includes:
[0198] S5.7: In the authentication level recovery process, before executing the first level downgrade switching instruction, based on the device factory key derivation seed stored in the warehousing equipment platform, the message authentication code key derivation function based on hash is used, and combined with the corresponding device identification code, the original session key of the device before adjustment is recalculated.
[0199] Furthermore, the specific steps in S5.7 include:
[0200] (1) Based on the warehouse full-domain hierarchical authentication and control mechanism, the authentication level recovery process of the current authentication level of the device is initiated, which is the process of the device falling back from the high-level permission to the low-level permission. The system background time sequence control unit locks the level recovery time sequence node and accurately determines the time sequence position as inside the current level recovery process. Before the first authentication level downgrade switching instruction is issued and executed, the key recalculation work is carried out in the only pre-emptive time window. The key calculation is not carried out after the level downgrade is executed or during the gap between multiple level switching rounds. This ensures that the key recalculated this time is the original session key corresponding to the device before the level adjustment takes effect. At the same time, the main body of this calculation is locked as the single warehouse access device to be downgraded. The boundary between the full-domain device key and the single device key calculation is distinguished to avoid interference from the full-domain key calculation.
[0201] (2) Targeted retrieval of the device-specific factory key derivation seed stored offline in the warehousing equipment platform. The warehousing equipment platform is equipped with an independent and exclusive key seed for all warehousing access devices. Each warehousing device completes one-to-one writing and solidification at the factory stage. The platform database performs encrypted storage management for each factory key derivation seed. Based on the binding ledger information of the device to be downgraded, the system accurately retrieves the unique factory key derivation seed corresponding to the device. In this business scenario, the fixed text encoding length of the device factory key derivation seed is set to 48 bits. The platform retrieval unit has built-in seed integrity verification logic to determine whether the seed encoding bit length meets the 48-bit fixed standard. If the bit length meets the standard, the seed is deemed compliant and usable. If the bit length is missing or tampered with, the key derivation operation is terminated directly, and a key seed abnormality alarm is reported. The bit length of the factory key derivation seed of the warehousing device to be downgraded in this case is verified to be 48 bits.
[0202] (3) Read the device identification code that is burned and solidified on the motherboard of the warehouse access device. The device identification code is uniformly standardized into a 64-bit standard text encoding format. At the same time, the platform ledger retains the device registration identification code. The hardware read identification code is compared with the platform registration identification code bit by bit. If the comparison is consistent, the device identity is determined to be legitimate and allowed to participate in key derivation operation. If the comparison is inconsistent, the device identity is determined to be forged and the key derivation call permission is directly closed.
[0203] (4) The algorithm for this exclusive key operation is activated, and the algorithm architecture and all fixed preset operating parameters are confirmed. The key operation is completed by the hash-based message authentication code key derivation function. The underlying key derivation function is based on the SHA-256 hash basic unit to build the operation architecture. The overall operation is divided into three progressive operation links: message encapsulation, hash iteration, and digest output. At the same time, all unmodifiable operating parameters of the algorithm are fixed in advance to conform to the unified standard of the warehouse authentication key system. Among them, the total number of underlying hash iterations is fixed at 52 rounds, the algorithm message concatenation salt offset is fixed at 18, and the final output key native encoding length is fixed at 48 bytes. The message verification filling format is uniformly adopted as the 8-bit unit PKCS7 standard filling format. Among them, SHA-256 hash is the existing technology in this field and is not the inventive solution of this application. It will not be described in detail here.
[0204] (5) Two types of core input data are concatenated according to fixed input priority. The first input data is a 48-bit compliant device factory key derivation seed and the second input data is a 64-bit device standard identification code that has been standardized and verified. The factory key derivation seed is set as the key base value of the underlying key and the device identification code is set as a variable authentication message text. The two types of data are concatenated and supplemented by a preset fixed salt offset of 18. After supplementation, the data enters the internal hash operation link. First, the concatenated data is standardized and message encapsulated. Then, 52 rounds of fixed-number SHA-256 hash iteration compression are performed. After the iteration is completed, a fixed-length message digest is generated. The digest field length is standardized by 8-bit PKCS7 filling format. Finally, the original device session key with a length of 48 bytes before adjustment is output. The key byte length is completely matched with the unified specification of the original session key of the second-level authentication level, ensuring the interoperability and compatibility of the key system.
[0205] (6) Perform double verification on the newly calculated original session key of the device before adjustment. The first verification checks whether the key output byte length is 48 bytes. The second verification compares the matching degree of the key hash digest with the original key base digest stored on the platform. After both verifications pass, the recalculated original session key is overwritten and stored as the original session key before the device level downgrade. The key version is locked to the original version before the level adjustment. It is forbidden to generate a new session key after the downgrade in advance. Only after the key is sealed and the background key status is marked as ready can the system allow the issuance of the first level downgrade switching instruction in the authentication level recovery process.
[0206] S5.8: Verify whether the native session key is within a preset valid lifespan. If it is within a valid lifespan, mark the native session key as pending reuse.
[0207] Furthermore, the system incorporates unified lifecycle management rules for the native session keys of built-in devices. In this embodiment, the lifecycle of the native key is set to 7 days. The system reads the original timestamp generated by the key and compares it with the current recovery process start time to determine whether the recalculated native session key is still within the 7-day validity period. Two verification results correspond to different handling logics: First, if the key is still within its valid lifecycle and there is no risk of expiration, the system marks the native session key as pending reuse and stores it in a dedicated key cache, waiting to replace the temporary session key after each level of downgrade is completed. Second, if the key has exceeded its valid lifecycle and cannot be directly reused, the system automatically regenerates a new native baseline session key based on the factory key seed and identification code, and then marks it as pending reuse, ensuring that the key used when restoring the baseline authentication state is compliant and valid, and there is no risk of expiration or invalidation.
[0208] S5.9: After executing the downgrade switching instruction, the native session key in the reusable state is used to replace the currently effective temporary session key.
[0209] Furthermore, after each single-level downgrade switching instruction within the path completes the entire execution process, and the edge gateway completes the revision of the new level authentication rules, the management server synchronously sends a key replacement notification message to the gateway. The message carries the complete parameters of the native session key marked as pending reuse. After receiving the message, the edge gateway overwrites the currently effective temporary session key in the local cache for the risk control phase and sets the native session key as the new effective session key for the device. All subsequent authentication interactions of the device are verified using the native session key, gradually moving away from the temporary key system derived from the risk control phase.
[0210] The step-by-step destruction of temporary authentication credentials at the edge gateway, returning to the baseline authentication state, includes:
[0211] (1) While executing the downgrade switching instruction at each level, generate a temporary authentication and credit certificate destruction notification that matches the downgrade switching instruction at that level;
[0212] (2) Send the generated temporary authentication and credit credential destruction notification to the edge gateway through the aforementioned encrypted communication link;
[0213] (3) The edge gateway queries and deletes the temporary authentication and credit certificate record corresponding to the current device identification code and the current level in its local credential cache according to the received temporary authentication and credit certificate destruction notification;
[0214] (4) After the edge gateway completes the deletion operation, receive the credential invalidation confirmation message returned by it, and record the message in the audit log of the warehouse equipment platform to complete the destruction of the temporary authentication and credit credentials at this level;
[0215] (5) After executing the downgrade switching instruction, reuse the native session key recorded by the device before the downgrade switching occurred and replace the currently effective session key;
[0216] (6) Repeat (1)-(5) for each level in the hierarchical order of the step-down path until all levels in the path have been processed.
[0217] (7) When all the level down switching instructions have been executed and the currently effective authentication level has been restored to the initial authentication level, stop the level switching and complete the baseline authentication state return.
[0218] Example 2:
[0219] Please see Figure 3Another embodiment of the present invention provides: an adaptive authentication policy adjustment system based on network state, comprising:
[0220] The quantitative scoring module 10 is used to collect the original feature data of the eight-dimensional network conditions of the access devices in the entire warehouse, complete the data classification and labeling to generate four types of network condition labels, and output the quantitative score of the network status after normalizing the features of each dimension and weighting and accumulating them. The network condition labels are continuously updated based on the lightweight gradient boosting machine classification model and the sliding time window majority voting mechanism.
[0221] The security classification module 20 is used to retrieve historical authentication records of warehouse equipment, calculate the basic score of effective identity trust through the Bayesian trust model, integrate the network status quantitative score, link risk weight and multiple sets of fusion weight coefficients to obtain the comprehensive security assessment score, calculate the comprehensive risk judgment value of the equipment by combining the risk offset corresponding to the working condition, and classify the equipment risk level into high, medium and low levels according to the high and low risk thresholds, thus completing the equipment risk classification of bidirectional coupling of network and identity.
[0222] The strategy decision module 30 stores a five-level authentication benchmark mapping table, matches the comprehensive security assessment score to obtain the initial target authentication level, and raises the authentication level standard by combining the risk level score corresponding to the network conditions; reads the current authentication level of the device, calls the hysteresis anti-jitter judgment rule to verify whether the level upgrade and level down conditions are met, filters instantaneous network disturbances, and outputs the gradient strategy switching command after meeting the switching requirements to realize stable authentication level switching decision.
[0223] The authentication rule update module 40 is used to parse the gradient policy switching instruction to extract the target authentication level, query and update the device authentication factor combination and session key derivation method to revise the authentication execution rules; based on the level matching credential validity period, combine the device identity code and timestamp to generate the credential body, encrypt the credential extension information through the derived encryption key, generate a temporary authentication and trust credential and send it to the edge gateway through the encrypted link;
[0224] The state rollback control module 50 detects that the network condition label has changed to a steady-state high-quality state, retrieves the initial authentication configuration of the device, plans a step-by-step downgrade path, and issues downgrade switching instructions in layers. Before downgrading, it recalculates and verifies the native session key of the reused device. At each level switch, it synchronously sends a credential destruction notification to the edge gateway, receives gateway failure receipts and retains audit logs, and clears temporary authentication and trust credentials layer by layer until the authentication level is completely restored to the baseline authentication state.
[0225] The embodiments of the present invention have been described above with reference to the accompanying drawings. However, the present invention is not limited to the specific embodiments described above. The specific embodiments described above are merely illustrative and not restrictive. Those skilled in the art can make changes, modifications, substitutions and variations to the above embodiments under the guidance of the present invention without departing from the spirit and scope of the present invention. All of these variations are within the protection scope of the present invention.
Claims
1. A method for adjusting an adaptive authentication strategy based on network state, characterized in that, include: Collect original 8-dimensional network condition feature data of all access devices in the warehouse and classify and label them to obtain network condition labels. Simultaneously generate a network status quantitative score with link risk weight values. Retrieve the valid identity trust base score pre-stored in the storage equipment, use the link risk weight value as a weighting coefficient, integrate it with the network status quantitative score to calculate the comprehensive security assessment score, and combine it with the network operating condition label to complete the two-way risk classification of the equipment. Retrieve the pre-configured five-level authentication benchmark and hysteresis anti-jitter judgment rules, bidirectionally verify the comprehensive security assessment score and network condition label, and output the gradient policy switching command matching the five-level authentication level. Parse the gradient strategy switching command, revise the warehouse equipment authentication execution rules to adapt to the current risk level, and simultaneously issue temporary authentication credit certificates to the connected edge gateway; Continuously collect original feature data of eight-dimensional network conditions, update network condition labels in real time, and restore the initial authentication rules step by step from low to high level according to the five-level authentication benchmark when the network condition label returns to a stable and high-quality state. Reuse the original session key of the device before adjustment, destroy the temporary authentication and trust credentials of the edge gateway step by step, and return to the benchmark authentication state.
2. The adaptive authentication strategy adjustment method based on network state as described in claim 1, characterized in that, The process of generating the network state quantization score with link risk weight values includes: For each dimension of the original feature data of the eight-dimensional network operating conditions, a corresponding risk impact factor value and an occurrence probability coefficient value are configured, and the risk impact factor value and occurrence probability coefficient value corresponding to the same dimension feature are multiplied to obtain the initial risk weight value of each dimension feature. Based on the category corresponding to the network condition label, the dynamic correction coefficient is retrieved from the pre-configured weight correction coefficient mapping table. The initial risk weight value of each feature is updated using the dynamic correction coefficient to obtain the link risk weight value under the current network condition. The original values of each dimension in the original feature data of the eight-dimensional network condition are normalized to obtain the normalized value of each feature. Then, the normalized value of each feature is multiplied by the link risk weight value of the corresponding dimension and accumulated to calculate and output the network state quantification score.
3. The adaptive authentication strategy adjustment method based on network state as described in claim 2, characterized in that, The process of outputting the comprehensive security assessment score includes: Based on the device identification code stored in the warehouse equipment security management database, retrieve the authentication success and failure records of the corresponding device for the N consecutive historical authentication cycles before the current sampling cycle; The retrieved authentication success records and authentication failure records are input into the pre-built Bayesian trust model to calculate and output the effective identity trust base score for the current period. The network status quantification score, the effective identity trust base score, and the link risk weight value of each dimension feature in the eight-dimensional network condition raw feature data are obtained. The corresponding first fusion weight coefficient, second fusion weight coefficient, and third fusion weight coefficient are configured respectively. Then, the network status quantification score, the effective identity trust base score, and the link risk weight value of each dimension feature are multiplied by the corresponding first fusion weight coefficient, second fusion weight coefficient, and third fusion weight coefficient respectively. The results are summed to obtain the comprehensive security assessment score.
4. The adaptive authentication strategy adjustment method based on network state as described in claim 3, characterized in that, The method of combining network condition tags to complete the two-way risk classification of equipment includes: Based on the specific category to which the network condition label belongs, the corresponding risk offset value is retrieved from the pre-configured condition-risk offset mapping table; The comprehensive safety assessment score and the risk offset value are arithmetically summed to obtain the comprehensive risk judgment value of the equipment. Read the high-risk threshold value and low-risk threshold value from the pre-configured risk level threshold parameter table; If the comprehensive risk assessment value of the equipment is greater than or equal to the high-risk threshold, the corresponding equipment is determined to be at the first risk level; if the comprehensive risk assessment value of the equipment is less than or equal to the low-risk threshold, the corresponding equipment is determined to be at the third risk level; if the comprehensive risk assessment value of the equipment is between the low-risk threshold and the high-risk threshold, the corresponding equipment is determined to be at the second risk level.
5. The adaptive authentication strategy adjustment method based on network state as described in claim 4, characterized in that, The process involves retrieving the pre-configured five-level authentication benchmark and hysteresis stabilization judgment rules, bidirectionally verifying the comprehensive security assessment score and network condition labels, and outputting a gradient policy switching instruction matching the five-level authentication level, including: Based on the local policy repository, obtain the corresponding certification factor combination requirements, number of certification factors and certification timeout duration for each of the simplified certification benchmark, lightweight certification benchmark, standard certification benchmark, enhanced certification benchmark and global certification benchmark, and form a five-level certification benchmark mapping table. The comprehensive security assessment score is matched and queried in the five-level certification benchmark mapping table to obtain the preliminary target certification level; The pre-configured risk level score corresponding to the network condition label is compared with the preliminary target authentication level, and the level with the higher authentication level is selected as the final target authentication level. The system reads the currently active authentication level from the device's current authentication status register, compares the currently active authentication level with the final target authentication level, and calls the pre-configured hysteresis stabilization judgment rule to perform stabilization judgment. When it is determined that the level switching conditions are met, a gradient strategy switching instruction is generated to switch from the currently active authentication level to the final target authentication level. The hysteresis stabilization judgment rule includes a continuous compliance time threshold for level switching and a hysteresis offset. The hysteresis offset includes a level upgrade hysteresis offset and a level downgrade hysteresis offset.
6. The adaptive authentication strategy adjustment method based on network state as described in claim 5, characterized in that, The process of calling the pre-configured hysteresis stabilization judgment rules to perform stabilization judgment includes: When it is determined that the final target authentication level is higher than the current effective authentication level, the difference between the final target authentication level and the current effective authentication level is calculated as the first level difference. If the first level difference is greater than or equal to the level promotion backlash offset, a pre-configured de-jittering delay waiting period is started. During the de-jittering delay waiting period, the final target authentication level is continuously acquired for M sampling times. If the final target authentication level for all M sampling times is higher than the current effective authentication level, it is determined that the level promotion condition is met. When it is determined that the final target authentication level is lower than the currently effective authentication level, the difference between the current effective authentication level and the final target authentication level is calculated as the second level difference. If the second level difference is greater than or equal to the level downgrade hysteresis offset, a de-jittering delay waiting period is started. During the de-jittering delay waiting period, the final target authentication level is continuously acquired for M sampling times. If the final target authentication level for all M sampling times is lower than the currently effective authentication level, it is determined that the level downgrade condition is met. When it is determined that the level promotion condition or the level demotion condition is met, a level switching permission signal is output as a trigger condition for generating the gradient policy switching instruction; when it is determined that the level promotion condition or the level demotion condition is not met, the current effective authentication level remains unchanged, and the generation of gradient policy switching instructions is prohibited.
7. The adaptive authentication strategy adjustment method based on network state as described in claim 6, characterized in that, The parsing gradient strategy switching instruction revises the warehouse equipment authentication execution rules to adapt to the current risk level, and simultaneously issues temporary authentication and credit credentials to the connected edge gateway, including: Parse the received gradient policy switching command and extract the target authentication level identifier carried in it; Based on the extracted target authentication level identifier, query the pre-configured authentication policy rule base to obtain the target authentication factor combination requirements and target session key derivation method corresponding to the target authentication level; The currently effective authentication factor combination requirements and the currently effective session key derivation method are updated to the target authentication factor combination requirements and the target session key derivation method, respectively, to complete the revision of the warehouse equipment authentication execution rules; Based on the target authentication level identifier, the corresponding credential validity period is retrieved from the pre-configured level-validity period mapping table; Generate the main information of the temporary authentication and credit certificate based on the current identification code and current timestamp of the current warehouse equipment; Using the updated target session key derivation method, a credential encryption key is derived from the currently effective session key, and the credential extension information containing the validity period of the credential is encrypted using the credential encryption key to generate a temporary authentication and trust credential. The generated temporary authentication and trust credentials are encapsulated into a delivery message, which is then synchronously delivered to the edge gateway via a pre-established encrypted communication link.
8. The adaptive authentication strategy adjustment method based on network state as described in claim 7, characterized in that, The process involves continuously collecting original feature data of the eight-dimensional network operating conditions, updating network operating condition labels in real time, and restoring the initial authentication rules level by level from low to high according to the five-level authentication benchmark once the network operating condition labels return to a steady state of high quality. This includes: The original feature data of the eight-dimensional network condition of the warehouse access devices are collected according to the preset periodic sampling interval. The updated eight-dimensional feature vector of the current sampling period is obtained and continuously input into the pre-trained lightweight gradient boosting machine classification model to obtain the updated network condition label of the current sampling period. Based on a preset sliding time window, multiple updated network condition labels corresponding to multiple consecutive sampling periods within the sliding time window are obtained and majority voting statistics are performed. The network condition label with the most votes is taken as the final updated network condition label at the center time within the sliding time window. When the final updated network condition label is detected to have changed from a non-steady-state high-quality type to a steady-state high-quality type, the authentication level recovery process is triggered. During the authentication level recovery process, the initial authentication level identifier and initial authentication execution rules recorded by the corresponding device before the level switch are retrieved from the warehouse equipment security management database. The initial authentication level identifier is compared with the currently effective authentication level identifier to determine the step-by-step degradation path from the currently effective authentication level to the initial authentication level. According to the hierarchical order in the described step-by-step downgrade path, hierarchical downgrade switching instructions are generated and executed level by level.
9. The adaptive authentication strategy adjustment method based on network state as described in claim 8, characterized in that, The reused native session key of the device before adjustment includes: In the authentication level recovery process, before executing the first level downgrade switching instruction, the original session key of the device before adjustment is recalculated based on the device factory key derivation seed stored in the warehousing equipment platform, using the hash-based message authentication code key derivation function, and combined with the corresponding device identification code. Verify whether the native session key is within a preset valid lifespan. If it is within a valid lifespan, mark the native session key as pending reuse. After executing the downgrade switching instruction, the native session key in the reusable state is used to replace the currently effective temporary session key.
10. A network state-based adaptive authentication policy adjustment system, used to implement the network state-based adaptive authentication policy adjustment method according to any one of claims 1-9, characterized in that, include: The quantitative scoring module is used to collect raw feature data of the eight-dimensional network conditions of all access devices in the warehouse and output quantitative scores of the network status. The security classification module is used to retrieve historical authentication records of warehouse equipment, calculate the basic score of effective identity trust through the Bayesian trust model, and calculate the comprehensive risk judgment value of the equipment by combining the risk offset value corresponding to the working condition, so as to complete the equipment risk classification of the two-way coupling of network and identity. The strategy decision module reads the current authentication level of the device, calls the hysteresis anti-shake judgment rules to verify whether the level upgrade conditions and level down conditions are met, and outputs the gradient strategy switching command after the switching requirements are met. The authentication rule update module is used to parse gradient policy switching instructions to extract the target authentication level, query and update the device authentication factor combination and session key derivation method to revise the authentication execution rules. The status rollback control module retrieves the device's initial authentication configuration when the network condition label changes to steady-state high quality, plans a step-by-step degradation path, and issues hierarchical downgrade switching instructions until the authentication level is completely restored to the baseline authentication state.