A terminal device security protection method and system
Patent Information
- Application Number
- CN202611107939.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-07-24
- Publication Date
- 2026-09-25
AI Technical Summary
[0003]现有技术利用区块链和零知识证明的分级认证来进行安全防护,其根据设备和用户的重要性和权限级别设计多级别权限认证的安全防护方法,以解决传统安全防护方法在多级别权限管理中的复杂性和低效率问题,提升跨信任域认证的安全性和效率
[0023]在上述方案获取目标终端设备的设备静态属性,并经由预设初始认证算法获取初始安全认证级别,从而实现对目标终端设备基础风险水平的初步评估;随后为使最终得到的用于安全防护的设备认证策略与目标终端设备的实时风险状态相匹配,本方案还依据设备运行动态属性对上述初始安全认证级别进行动态校正生成与目标终端设备的实时风险状态相匹配的设备动态认证级别,并依据该设备动态认证级别生成设备认证策略进行安全防护,能够使高风险的关键终端设备在面临威胁时可触发更强的设备认证策略进行安全防护,且低风险终端设备也能维持恰当的防护,从而在整体上实现了安全防护与终端设备实时风险状态的精准适配,提高终端设备安全防护的精准性。
Smart Images

Figure CN122824474A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of security protection technology, and in particular to a method and system for protecting terminal devices. Background Technology
[0002] With the rapid development of the Internet of Things (IoT), the security protection of terminal devices has become a key link in ensuring the stable operation of IoT systems. Currently, existing security protection methods mainly revolve around device identity authentication, data encryption, and access control. However, the IoT has high requirements for the authorization authentication of each terminal device, which determines the stability of terminal device security protection.
[0003] Existing technologies utilize blockchain and zero-knowledge proof-based hierarchical authentication for security protection. These technologies employ multi-level permission authentication based on the importance and permission levels of devices and users to address the complexity and inefficiency of traditional security methods in multi-level permission management, thereby improving the security and efficiency of cross-trust domain authentication. However, because existing technologies primarily rely on preset static permission hierarchies for hierarchical authentication, they lack awareness and responsiveness to the real-time operational status of terminal devices. This leads to a disconnect between authentication levels and the actual security status of the terminal devices, potentially resulting in insufficient protection for high-risk critical devices while over-protecting low-risk ordinary devices. This mismatch between the strength of security protection and the actual risks faced by the devices significantly reduces the accuracy of terminal device security protection and fails to meet the high security demands of the IoT environment. Summary of the Invention
[0004] The present invention aims to provide a method and system for protecting terminal devices, so as to solve the above-mentioned technical problems and improve the accuracy of terminal device security protection.
[0005] To address the aforementioned technical problems, this invention provides a terminal device security protection method, comprising the following steps: Obtain the static and dynamic attributes of the target terminal device; Based on the device's static attributes, an initial security authentication level is obtained using a preset initial authentication algorithm. The device's dynamic operating attributes are used to generate a security level adjustment amount under a preset dynamic adjustment assignment table. Based on the security level adjustment amount and the initial security authentication level, dynamic correction processing is performed to obtain the device's dynamic authentication level. Based on the device's dynamic authentication level, a device authentication policy is generated under a preset authentication strength configuration algorithm, and the target terminal device is protected based on the device authentication policy.
[0006] In the above scheme, static device attributes refer to the inherent characteristic parameters of the target terminal device that remain relatively stable over a long period of time; dynamic device attributes refer to the performance and status parameters of the target terminal device that change over time and with changing operating conditions during real-time operation, directly reflecting the current risk status of the target terminal device. This scheme first obtains the static attributes of the target terminal device and then obtains an initial security authentication level through a preset initial authentication algorithm, thereby achieving a preliminary assessment of the basic risk level of the target terminal device. Subsequently, to match the device authentication strategy with the real-time risk status of the target terminal device, this scheme dynamically corrects the initial security authentication level based on the dynamic device attributes to generate a dynamic device authentication level that matches the real-time risk status of the target terminal device. The device authentication strategy generated based on this dynamic authentication level provides security protection, enabling high-risk critical terminal devices to trigger stronger authentication strategies for security protection when facing threats, while also ensuring appropriate protection for low-risk terminal devices. This achieves precise adaptation between security protection and the real-time risk status of the terminal device, improving the accuracy of terminal device security protection.
[0007] Furthermore, the step of obtaining the static attributes and dynamic operating attributes of the target terminal device includes: obtaining the basic attributes and real-time operating data of the target terminal device; and performing feature extraction on the basic attributes and real-time operating data to generate the static attributes and dynamic operating attributes of the device.
[0008] The above scheme extracts static attributes that characterize the long-term stability of the equipment from the basic attributes of the equipment, and extracts dynamic attributes that reflect the instantaneous changes in the state of the equipment from the real-time operation data of the equipment. This enables the subsequent processing flow to use the dynamic and static attributes of the equipment to effectively reflect the security risks of the target terminal equipment, avoiding misjudgments of authentication levels caused by messy or inconsistent original data, thereby improving the accuracy of terminal equipment security protection.
[0009] Furthermore, the step of extracting features from the device's basic attributes and the device's real-time operating data to generate static and dynamic attributes of the device includes: extracting features from the device's basic attributes to obtain the device's functional importance, basic risk value, and deployment environment risk coefficient; extracting features from the device's real-time operating data to obtain the device's operating state deviation, device vulnerability severity, and device communication anomaly frequency; generating static attributes of the device based on the device's functional importance, basic risk value, and deployment environment risk coefficient, and generating dynamic attributes of the device based on the device's operating state deviation, vulnerability severity, and communication anomaly frequency.
[0010] The above scheme first extracts the following static attributes from the acquired basic device attributes: the device function importance representing the criticality of the target terminal device in the Internet of Things, the device risk baseline value representing the inherent security vulnerability of the target terminal device, and the deployment environment risk coefficient representing the threat level of the physical or network environment in which the target terminal device is located. Then, it extracts the following dynamic attributes from the acquired real-time device operation data: the device operation state deviation representing the deviation between the current operating performance and the baseline state, the device vulnerability severity representing the threat level of the target terminal device, and the device communication anomaly frequency representing the frequency of abnormal network communication behavior of the target terminal device. These dynamic attributes are used for subsequent dynamic correction. Based on the above static and dynamic attributes, the authentication policy generated by this scheme can more accurately represent the security status of the target terminal device, thereby improving the accuracy of terminal device security protection.
[0011] Further, obtaining the initial security authentication level based on the device's static attributes using a preset initial authentication algorithm includes: obtaining the functional importance weight, device risk weight, and environmental risk weight corresponding to the device's static attributes in a preset static authentication weight allocation table; generating a device functional importance level based on the functional importance weight and the device functional importance of the device's static attributes; generating a device configuration security level based on the device risk weight and the device risk base value of the device's static attributes; generating a deployment environment security level based on the environmental risk weight and the deployment environment risk coefficient of the device's static attributes; and fusing the device functional importance level, the device configuration security level, and the deployment environment security level to obtain the initial security authentication level.
[0012] In the above embodiments, the corresponding functional importance weight, device risk weight, and environmental risk weight are obtained based on the static attributes of the device. Then, based on the functional importance weight and the device functional importance, a device functional importance degree representing the criticality of the device is generated. Based on the device risk weight and the device risk base value, a device configuration security degree representing the inherent vulnerability of the device is generated. Based on the environmental risk weight and the deployment environment risk coefficient, a deployment environment security degree representing the level of external threats is generated. Furthermore, the device functional importance degree, the device configuration security degree, and the deployment environment security degree are integrated to obtain an initial security certification level. This initial security certification level can accurately reflect the relative risk level of the device in network access or static scenarios, thereby improving the overall accuracy of subsequent terminal device security protection.
[0013] Further, the step of generating a security level adjustment amount from the device's dynamic operating attributes under a preset dynamic adjustment assignment table, and performing dynamic correction processing based on the security level adjustment amount and the initial security authentication level to obtain the device's dynamic authentication level, includes: obtaining the operating state offset weight, vulnerability severity weight, and communication anomaly weight corresponding to the device's dynamic operating attributes in the preset dynamic adjustment assignment table; generating the device's real-time operating deviation degree based on the operating state offset weight and the device's operating state deviation degree of the device's dynamic operating attributes; generating the device's real-time vulnerability severity degree based on the vulnerability severity weight and the device's vulnerability severity of the device's dynamic operating attributes; generating the device's real-time communication anomaly degree based on the communication anomaly weight and the device's communication anomaly frequency of the device's dynamic operating attributes; fusing the device's real-time operating deviation degree, the device's real-time vulnerability severity, and the device's real-time communication anomaly degree to obtain a security level adjustment amount; and correcting the initial security authentication level under the security level adjustment amount to obtain the device's dynamic authentication level.
[0014] In the above scheme, the operating state offset weight, vulnerability severity weight, and communication anomaly weight are first obtained based on the dynamic attributes of the device operation. Then, the real-time operating deviation degree of the device is generated based on the operating state offset weight and the device operating state deviation degree. The real-time vulnerability severity of the device is generated based on the vulnerability severity weight and the device vulnerability severity degree. The real-time communication anomaly degree of the device is generated based on the communication anomaly weight and the device communication anomaly frequency. Then, the security level adjustment amount obtained by fusion is used to correct the initial security authentication level to obtain a device dynamic authentication level that matches the real-time risk state of the target terminal device, reducing the lag of the subsequently obtained device authentication strategy and thus improving the accuracy of terminal device security protection.
[0015] Furthermore, the step of generating a device authentication policy based on the device dynamic authentication level under a preset authentication strength configuration algorithm, and performing security protection on the target terminal device based on the device authentication policy, includes: generating a device authentication strength value based on the device dynamic authentication level under a preset authentication strength configuration coefficient; generating a device authentication policy based on the device authentication strength under preset minimum strength configuration thresholds and maximum strength configuration thresholds, and performing security protection on the target terminal device based on the device authentication policy.
[0016] Further, in the step of generating a device authentication policy based on the device authentication strength under a preset minimum strength configuration threshold and a maximum strength configuration threshold, and performing security protection on the target terminal device based on the device authentication policy, the step of generating a device authentication policy based on the device authentication strength under the preset minimum strength configuration threshold and the maximum strength configuration threshold includes: confirming that the device authentication strength is not greater than the preset minimum strength configuration threshold, then generating a device authentication policy set to single-factor authentication; otherwise, determining that the device authentication strength is not greater than the preset maximum strength configuration threshold; confirming that the device authentication strength is not greater than the preset maximum strength configuration threshold, then generating a device authentication policy set to two-factor authentication; otherwise, generating a device authentication policy set to multi-factor authentication.
[0017] The above scheme generates a device authentication strength value based on the device's dynamic authentication level and a preset authentication strength configuration coefficient. Subsequently, it generates a differentiated device authentication strategy based on the device authentication strength value under preset minimum and maximum strength configuration thresholds. According to the device authentication strategy, it performs security protection on the target terminal device that matches its current dynamic authentication level. This enables core terminal devices to automatically upgrade to multi-factor authentication when high-risk vulnerabilities are found, thereby improving the security strength of critical terminal devices. Meanwhile, ordinary devices use lightweight single-factor authentication to avoid ineffective resource consumption and improve the accuracy of terminal device security protection.
[0018] Furthermore, in the step of generating a device authentication policy based on the device authentication strength under preset minimum and maximum strength configuration thresholds, and performing security protection on the target terminal device according to the device authentication policy, the step of performing security protection on the target terminal device according to the device authentication policy includes: obtaining the total device authentication strength and the total authentication resource quantity, and obtaining the device resource ratio based on the device authentication strength value, the total device authentication strength, and the total authentication resource quantity; and performing security protection on the target terminal device based on the device resource ratio and the device authentication policy.
[0019] Before implementing the device authentication strategy, the above scheme determines and obtains the proportion of device resources that the device should receive based on the total device authentication strength, total authentication resource quantity, and device authentication strength value. Then, it combines this proportion of device resources with the device authentication strategy to protect the target terminal device. This ensures that high-risk terminal devices with high device authentication strength can obtain sufficient resources to guarantee the execution of their strong device authentication strategy, prevents low-risk devices with low authentication strength from excessively occupying limited resources, optimizes the overall resource utilization rate, avoids reducing the effectiveness of security protection due to improper resource allocation, and improves the efficiency of security protection for the target terminal device.
[0020] Furthermore, in the step of generating a device authentication policy based on the device authentication strength under preset minimum and maximum strength configuration thresholds, and performing security protection on the target terminal device according to the device authentication policy, the step of performing security protection on the target terminal device according to the device authentication policy includes: obtaining resource information corresponding to the target terminal device, and obtaining the resource configuration device set and total resource capacity corresponding to the resource information; one of the resource configuration devices in the resource configuration device set is the target terminal device; obtaining the resource adaptation coefficient of each resource configuration device in the resource configuration device set according to the resource configuration device set and the resource information; obtaining the device resource ratio based on the device authentication strength value, the resource adaptation coefficient, and the total resource capacity; and performing security protection on the target terminal device according to the device resource ratio and the device authentication policy.
[0021] The above scheme obtains resource adaptation coefficients based on the resource allocation device set, which reflect the differentiated resource requirements and utilization efficiency of different devices in terms of function and performance. The device resource ratio is obtained by taking the device authentication strength value, resource adaptation coefficient and total resource capacity of the target terminal device. Finally, this resource ratio is combined with the device authentication strategy to protect the security of the target terminal device. This ensures that limited resources can be preferentially allocated to terminal devices with high authentication strength and good adaptability to the resource, realizes the accurate allocation of different resources to different types of devices, and improves the efficiency of security protection of target terminal devices under the differentiated requirements of multiple types of resources in the Internet of Things.
[0022] This invention also provides a terminal device security protection system for implementing any of the terminal device security protection methods described above, comprising: a device information acquisition module for acquiring the static attributes and dynamic attributes of the target terminal device; a primary security authentication level evaluation module for acquiring an initial security authentication level based on the static attributes of the device under a preset initial authentication algorithm; a dynamic authentication level evaluation module for generating a security level adjustment amount from the dynamic attributes of the device under a preset dynamic adjustment assignment table, and performing dynamic correction processing based on the security level adjustment amount and the initial security authentication level to obtain a dynamic authentication level of the device; and a security protection module for generating a device authentication strategy based on the dynamic authentication level of the device under a preset authentication strength configuration algorithm, and performing security protection on the target terminal device based on the device authentication strategy.
[0023] The above scheme obtains the static attributes of the target terminal device and obtains an initial security authentication level through a preset initial authentication algorithm, thereby achieving a preliminary assessment of the basic risk level of the target terminal device. Subsequently, in order to match the final device authentication strategy for security protection with the real-time risk status of the target terminal device, this scheme also dynamically corrects the initial security authentication level based on the device's dynamic operating attributes to generate a dynamic device authentication level that matches the real-time risk status of the target terminal device. Based on this dynamic device authentication level, a device authentication strategy is generated for security protection. This enables high-risk critical terminal devices to trigger stronger device authentication strategies for security protection when facing threats, while low-risk terminal devices can also maintain appropriate protection. Thus, overall, it achieves accurate adaptation between security protection and the real-time risk status of terminal devices, improving the accuracy of terminal device security protection. Attached Figure Description
[0024] To more clearly illustrate the technical solution of this application, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0025] Figure 1 This is a flowchart illustrating the technical implementation of a terminal device security protection method according to an embodiment of the present invention. Figure 2 This is a schematic diagram of a terminal device security protection system architecture provided in an embodiment of the present invention. Detailed Implementation
[0026] To make the objectives, technical solutions, and advantages of this application clearer, the technical solutions of this application will be clearly and completely described below with reference to the accompanying drawings of the embodiments. Obviously, the described embodiments are only some embodiments of this application, not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0027] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this application pertains; the terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit the application; the terms “comprising” and “having”, and any variations thereof, in the specification, claims, and foregoing description of the drawings are intended to cover non-exclusive inclusion.
[0028] In the description of the embodiments of this application, technical terms such as "first" and "second" are used only to distinguish different objects and should not be construed as indicating or implying relative importance or implicitly specifying the number, specific order, or primary and secondary relationship of the indicated technical features. In the description of the embodiments of this application, "multiple" means two or more, unless otherwise explicitly defined.
[0029] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of this application. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.
[0030] In the description of the embodiments in this application, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this document generally indicates that the preceding and following related objects have an "or" relationship.
[0031] In the description of the embodiments of this application, the term "multiple" refers to two or more (including two), similarly, "multiple sets" refers to two or more (including two sets), and "multiple pieces" refers to two or more (including two pieces).
[0032] In the description of the embodiments of this application, unless otherwise expressly specified and limited, technical terms such as "installation," "connection," "joining," and "fixing" should be interpreted broadly. For example, they can refer to a fixed connection, a detachable connection, or an integral part; they can refer to a mechanical connection or an electrical connection; they can refer to a direct connection or an indirect connection through an intermediate medium; they can refer to the internal communication of two components or the interaction between two components. For those skilled in the art, the specific meaning of the above terms in the embodiments of this application can be understood according to the specific circumstances.
[0033] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0034] Please see Figure 1 This embodiment provides a terminal device security protection method, including the following steps: Step S1: Obtain the static attributes and dynamic attributes of the target terminal device; Step S2: Obtain the initial security authentication level based on the device's static attributes using a preset initial authentication algorithm; Step S3: Generate a security level adjustment amount by setting the device's dynamic operating attributes under a preset dynamic adjustment assignment table, and perform dynamic correction processing based on the security level adjustment amount and the initial security authentication level to obtain the device's dynamic authentication level; Step S4: Generate a device authentication policy based on the device dynamic authentication level and a preset authentication strength configuration algorithm, and perform security protection on the target terminal device based on the device authentication policy.
[0035] In the above embodiments, static device attributes refer to the inherent characteristic parameters of the target terminal device that remain relatively stable over a long period of time; dynamic device attributes refer to the performance and status parameters of the target terminal device that change over time and with changing operating conditions during real-time operation, directly reflecting the current risk status of the target terminal device. This embodiment first obtains the static attributes of the target terminal device and then obtains an initial security authentication level through a preset initial authentication algorithm, thereby achieving a preliminary assessment of the basic risk level of the target terminal device. Subsequently, to match the device authentication strategy with the real-time risk status of the target terminal device, this embodiment dynamically corrects the initial security authentication level based on the dynamic device attributes to generate a dynamic device authentication level that matches the real-time risk status of the target terminal device. The device authentication strategy generated based on this dynamic authentication level enables high-risk critical terminal devices to trigger stronger authentication strategies for security protection when facing threats, while low-risk terminal devices can also maintain appropriate protection. This achieves accurate adaptation between security protection and the real-time risk status of the terminal device, improving the accuracy of terminal device security protection.
[0036] Furthermore, the step of obtaining the static attributes and dynamic operating attributes of the target terminal device includes: obtaining the basic attributes and real-time operating data of the target terminal device; and performing feature extraction on the basic attributes and real-time operating data to generate the static attributes and dynamic operating attributes of the device.
[0037] The above embodiments extract static attributes that characterize the long-term stable characteristics of the device from the basic attributes of the device, and extract dynamic attributes that reflect the instantaneous state changes of the device from the real-time operation data of the device. This enables the dynamic and static attributes of the device used in subsequent processing to effectively reflect the security risks of the target terminal device, avoiding misjudgments of authentication levels caused by messy or inconsistent original data, thereby improving the accuracy of terminal device security protection.
[0038] In one embodiment, the static attributes and real-time operating data of the target terminal device are obtained by collecting device functional parameters, deployment location, operating status, vulnerability information, and communication logs in real time through sensors and communication interfaces. The static attributes include static information such as function type, deployment location, and historical risk records. The real-time operating data is specifically obtained by collecting device operating parameters hourly after the control terminal device enters real-time monitoring mode. This real-time operating data includes dynamic data such as CPU load, communication data packet verification results, and vulnerability scan reports.
[0039] Furthermore, the step of extracting features from the device's basic attributes and the device's real-time operating data to generate static and dynamic attributes of the device includes: extracting features from the device's basic attributes to obtain the device's functional importance, basic risk value, and deployment environment risk coefficient; extracting features from the device's real-time operating data to obtain the device's operating state deviation, device vulnerability severity, and device communication anomaly frequency; generating static attributes of the device based on the device's functional importance, basic risk value, and deployment environment risk coefficient, and generating dynamic attributes of the device based on the device's operating state deviation, vulnerability severity, and communication anomaly frequency.
[0040] The above embodiments first extract the following static attributes from the acquired basic device attributes: the device function importance representing the criticality of the target terminal device in the Internet of Things, the device risk base value representing the inherent security vulnerability of the target terminal device, and the deployment environment risk coefficient representing the threat level of the physical or network environment in which the target terminal device is located. Then, the embodiments extract the following dynamic attributes from the acquired real-time device operation data: the device operation state deviation representing the deviation between the current operating performance and the baseline state, the device vulnerability severity representing the threat level of the target terminal device's security vulnerabilities, and the device communication anomaly frequency representing the frequency of abnormal network communication behavior of the target terminal device. These dynamic attributes are used for subsequent dynamic correction. Based on the above static and dynamic attributes, the authentication policy generated in this embodiment can more accurately represent the security status of the target terminal device, thereby improving the accuracy of terminal device security protection.
[0041] Further, obtaining the initial security authentication level based on the device's static attributes using a preset initial authentication algorithm includes: obtaining the functional importance weight, device risk weight, and environmental risk weight corresponding to the device's static attributes in a preset static authentication weight allocation table; generating a device functional importance level based on the functional importance weight and the device functional importance of the device's static attributes; generating a device configuration security level based on the device risk weight and the device risk base value of the device's static attributes; generating a deployment environment security level based on the environmental risk weight and the deployment environment risk coefficient of the device's static attributes; and fusing the device functional importance level, the device configuration security level, and the deployment environment security level to obtain the initial security authentication level.
[0042] In the above embodiments, the corresponding functional importance weight, device risk weight, and environmental risk weight are obtained based on the static attributes of the device. Then, based on the functional importance weight and the device functional importance, a device functional importance degree representing the criticality of the device is generated. Based on the device risk weight and the device risk base value, a device configuration security degree representing the inherent vulnerability of the device is generated. Based on the environmental risk weight and the deployment environment risk coefficient, a deployment environment security degree representing the level of external threats is generated. Furthermore, the device functional importance degree, the device configuration security degree, and the deployment environment security degree are integrated to obtain an initial security certification level. This initial security certification level can accurately reflect the relative risk level of the device in network access or static scenarios, thereby improving the overall accuracy of subsequent terminal device security protection.
[0043] In one embodiment, the formula for integrating the importance of device functions, the security level of device configuration, and the security level of the deployment environment to generate the initial security authentication level is as follows: ; in, As a weight for functional importance, For equipment risk weights, For environmental risk weights, Due to the importance of equipment functions, This serves as the baseline value for equipment risk. To deploy environmental risk coefficients, This is the initial security authentication level.
[0044] And the importance of the functions of the above-mentioned equipment A higher value for functional importance indicates a more important function. Generally, the functional importance of the device corresponding to the scheduling terminal is... The importance of the device functions corresponding to ordinary data acquisition terminals Equipment risk baseline value It is assessed based on the number of historical vulnerabilities and attack records of the device; deployment environment risk coefficient. Typically, deployments in core data centers correspond to deployment environment risk levels. Deployment environment risk coefficient corresponding to deployment in ordinary outdoor environments ; ,and .
[0045] It should be noted that the functional importance weight, equipment risk weight, and environmental risk weight are obtained by directly assigning values based on the actual application scenario using an assignment method.
[0046] Further, the step of generating a security level adjustment amount from the device's dynamic operating attributes under a preset dynamic adjustment assignment table, and performing dynamic correction processing based on the security level adjustment amount and the initial security authentication level to obtain the device's dynamic authentication level, includes: obtaining the operating state offset weight, vulnerability severity weight, and communication anomaly weight corresponding to the device's dynamic operating attributes in the preset dynamic adjustment assignment table; generating the device's real-time operating deviation degree based on the operating state offset weight and the device's operating state deviation degree of the device's dynamic operating attributes; generating the device's real-time vulnerability severity degree based on the vulnerability severity weight and the device's vulnerability severity of the device's dynamic operating attributes; generating the device's real-time communication anomaly degree based on the communication anomaly weight and the device's communication anomaly frequency of the device's dynamic operating attributes; fusing the device's real-time operating deviation degree, the device's real-time vulnerability severity, and the device's real-time communication anomaly degree to obtain a security level adjustment amount; and correcting the initial security authentication level under the security level adjustment amount to obtain the device's dynamic authentication level.
[0047] In the above embodiments, firstly, the operating state offset weight, vulnerability severity weight, and communication anomaly weight are obtained based on the device's dynamic operating attributes. Then, the real-time operating deviation degree of the device is generated based on the operating state offset weight and the device's operating state deviation degree. The real-time vulnerability severity of the device is generated based on the vulnerability severity weight and the device's vulnerability severity degree. The real-time communication anomaly degree of the device is generated based on the communication anomaly weight and the device's communication anomaly frequency. Subsequently, the fused security level adjustment amount is used to correct the initial security authentication level to obtain a device dynamic authentication level that matches the real-time risk state of the target terminal device, reducing the lag of the subsequently obtained device authentication strategy and thus improving the accuracy of terminal device security protection.
[0048] In one embodiment, the formula for generating the security level adjustment amount and correcting the device's dynamic authentication level based on the initial security authentication level under the security level adjustment amount is as follows: ; ; in, As the weight for the running state offset, Assigning a weight based on the severity of the vulnerability. For communication anomaly weights, The deviation of the equipment's operating status. Depending on the severity of the device vulnerability, This is a frequency indicating abnormal device communication. Adjustment amount for safety level, The device's dynamic authentication level at time t.
[0049] And the deviation of the above-mentioned equipment operating status It is valued based on the deviation of the operating status, with a larger value indicating a greater deviation; the severity of the equipment vulnerability. It assigns a value based on the severity of vulnerabilities present in the device; a higher value indicates a more severe vulnerability. The frequency of abnormal device communication... The value is determined based on the frequency of device communication anomalies; the larger the value, the higher the frequency of device communication anomalies. ,and Furthermore, by limiting the dynamic authentication level of the device. To avoid excessive fluctuations.
[0050] Furthermore, the step of generating a device authentication policy based on the device dynamic authentication level under a preset authentication strength configuration algorithm, and performing security protection on the target terminal device based on the device authentication policy, includes: generating a device authentication strength value based on the device dynamic authentication level under a preset authentication strength configuration coefficient; generating a device authentication policy based on the device authentication strength under preset minimum strength configuration thresholds and maximum strength configuration thresholds, and performing security protection on the target terminal device based on the device authentication policy.
[0051] Further, in the step of generating a device authentication policy based on the device authentication strength under a preset minimum strength configuration threshold and a maximum strength configuration threshold, and performing security protection on the target terminal device based on the device authentication policy, the step of generating a device authentication policy based on the device authentication strength under the preset minimum strength configuration threshold and the maximum strength configuration threshold includes: confirming that the device authentication strength is not greater than the preset minimum strength configuration threshold, then generating a device authentication policy set to single-factor authentication; otherwise, determining that the device authentication strength is not greater than the preset maximum strength configuration threshold; confirming that the device authentication strength is not greater than the preset maximum strength configuration threshold, then generating a device authentication policy set to two-factor authentication; otherwise, generating a device authentication policy set to multi-factor authentication.
[0052] The above embodiments generate device authentication strength values based on the device's dynamic authentication level and a preset authentication strength configuration coefficient. Subsequently, the device authentication strength values are used to generate differentiated device authentication strategies under preset minimum and maximum strength configuration thresholds. Based on these device authentication strategies, security protection is applied to the target terminal device to match its current dynamic authentication level. This enables core terminal devices to automatically upgrade to multi-factor authentication when high-risk vulnerabilities are found, thereby improving the security strength of critical terminal devices. Meanwhile, ordinary devices use lightweight single-factor authentication to avoid ineffective resource consumption and improve the accuracy of terminal device security protection.
[0053] In one embodiment, the formula for generating the device authentication strength value based on the device dynamic authentication level is as follows: ; in, This is the equipment certification strength value, and , This is the proportionality coefficient. These are nonlinear coefficients. Let be the device's dynamic authentication level at time t. The formula for generating the device authentication strength value D allows us to achieve the goal of a higher dynamic authentication level leading to a faster increase in the device authentication strength value.
[0054] In the above embodiments, the device authentication policy is set as follows: ; in, Configure a threshold for minimum intensity. Configure a threshold for the maximum intensity.
[0055] Furthermore, in the single-factor authentication, two-factor authentication, and multi-factor authentication described in the above embodiments, the authentication factors include password, device certificate, biometrics, dynamic verification code, and QR code. This embodiment uses the device authentication strength value... The scope of the system is used to configure different numbers and strengths of authentication factors for devices with different authentication strengths. This enables different security protection strategies to be provided based on the authentication strength value of the target terminal device. More resources can be concentrated on high-risk devices, which can effectively avoid resource waste compared to the traditional average allocation scheme, and significantly improve resource utilization efficiency while ensuring system security.
[0056] The differentiated device authentication strategy adopted in the above embodiments, such as the scheduling server's core control device, has a device authentication strength value D greater than the maximum strength configuration threshold. If a high-risk vulnerability is detected, the device authentication strategy is set to multi-factor authentication to activate a multi-factor authentication process that includes biometric verification for security protection, thereby enhancing the security strength of critical nodes. The dynamic device authentication level obtained in the above embodiments can change in real time with the device status, so that when the device experiences communication anomalies or operational deviations, a corresponding device authentication strategy can be generated to improve the protection level, achieving the goal of risk-response-in-depth defense.
[0057] In the above embodiments, when it is confirmed that the device authentication strength is not greater than the preset minimum strength configuration threshold, a device authentication policy set to single-factor authentication is generated. Under this single-factor authentication policy, the target terminal device triggers a single-factor password authentication process for security protection. When it is confirmed that the device authentication strength is greater than the preset minimum strength configuration threshold but not greater than the preset maximum strength configuration threshold, a device authentication policy set to two-factor authentication is generated. This two-factor authentication policy triggers a two-factor authentication process of password and device certificate for security protection. When it is confirmed that the device authentication strength is greater than the preset maximum strength configuration threshold, a device authentication policy set to multi-factor authentication is generated. This multi-factor authentication policy activates a multi-factor authentication process including biometric verification for security protection.
[0058] Furthermore, in the step of generating a device authentication policy based on the device authentication strength under preset minimum and maximum strength configuration thresholds, and performing security protection on the target terminal device according to the device authentication policy, the step of performing security protection on the target terminal device according to the device authentication policy includes: obtaining the total device authentication strength and the total authentication resource quantity, and obtaining the device resource ratio based on the device authentication strength value, the total device authentication strength, and the total authentication resource quantity; and performing security protection on the target terminal device based on the device resource ratio and the device authentication policy.
[0059] Before executing the device authentication strategy, the above embodiments determine and obtain the proportion of device resources that the device should receive based on the total device authentication strength, total authentication resource quantity, and device authentication strength value. Then, this proportion of device resources is combined with the device authentication strategy to protect the target terminal device. This ensures that high-risk terminal devices with high device authentication strength can obtain sufficient resources to guarantee the execution of their strong device authentication strategy, prevents low-risk devices with low authentication strength from excessively occupying limited resources, optimizes the overall resource utilization rate, avoids reducing the effectiveness of security protection due to improper resource allocation, and improves the efficiency of security protection for the target terminal device.
[0060] In one embodiment, the formula for obtaining the device resource percentage is as follows: ; in, The percentage of device resources for the target terminal device L. The authentication strength value of the target terminal device L. For the overall equipment certification strength, T This refers to the total amount of authentication resources. The above embodiment determines the resource allocation ratio of the target terminal device based on the ratio of the current terminal device's authentication strength value to the total device authentication strength, thus prioritizing resource allocation for high-risk target terminal devices.
[0061] Furthermore, in the step of generating a device authentication policy based on the device authentication strength under preset minimum and maximum strength configuration thresholds, and performing security protection on the target terminal device according to the device authentication policy, the step of performing security protection on the target terminal device according to the device authentication policy includes: obtaining resource information corresponding to the target terminal device, and obtaining the resource configuration device set and total resource capacity corresponding to the resource information; one of the resource configuration devices in the resource configuration device set is the target terminal device; obtaining the resource adaptation coefficient of each resource configuration device in the resource configuration device set according to the resource configuration device set and the resource information; obtaining the device resource ratio based on the device authentication strength value, the resource adaptation coefficient, and the total resource capacity; and performing security protection on the target terminal device according to the device resource ratio and the device authentication policy.
[0062] The above embodiments obtain resource adaptation coefficients based on the resource configuration device set, which reflect the differentiated resource requirements and utilization efficiency of different devices in terms of function and performance. The device resource ratio is obtained by using the device authentication strength value, resource adaptation coefficient and total resource capacity of the target terminal device. Finally, this resource ratio is combined with the device authentication strategy to protect the security of the target terminal device. This ensures that limited resources can be preferentially allocated to terminal devices with high authentication strength and good adaptability to the resource, realizes the accurate allocation of different resources to different types of devices, and improves the efficiency of security protection of target terminal devices under the differentiated requirements of multiple types of resources in the Internet of Things.
[0063] In one embodiment, obtaining resources The formula for the percentage of equipment resources under the corresponding resource information is as follows: ; in, The percentage of device resources for the target terminal device L. In order to have resources Total resource capacity Let K be the resource adaptation coefficient. Different devices have different requirements for resource K. Based on this formula, different types of devices can be accurately allocated to different resources. For the online effective utilization rate of equipment L; The certification strength of the i-th general-purpose device; Let be the online effective utilization rate of the i-th terminal; This is the service priority correction coefficient for the i-th terminal.
[0064] It should be noted that the equipment resource allocation includes the specific proportion of resources such as model computing power and bandwidth. It prioritizes the allocation of high-priority resources to core terminal devices with higher dynamic authentication levels, such as scheduling servers, and monitors resource utilization in real time to ensure that resource allocation matches the security requirements of terminal devices. Furthermore, the entire resource allocation process is recorded by a distributed database.
[0065] Please see Figure 2 This embodiment also provides a terminal device security protection system for implementing any of the above terminal device security protection methods, including: The device information acquisition module is used to acquire the static attributes and dynamic operating attributes of the target terminal device. The initial security authentication level assessment module is used to obtain the initial security authentication level based on the static attributes of the device under a preset initial authentication algorithm. The dynamic authentication level evaluation module is used to generate a security level adjustment amount from the dynamic attributes of the device operation under a preset dynamic adjustment assignment table, and to perform dynamic correction processing based on the security level adjustment amount and the initial security authentication level to obtain the device dynamic authentication level. The security protection module is used to generate a device authentication policy based on the device's dynamic authentication level and a preset authentication strength configuration algorithm, and to provide security protection for the target terminal device based on the device authentication policy.
[0066] It is understood that the above-described device embodiments correspond to the method embodiments of the present invention, and can implement the terminal device security protection method provided by any of the above-described method embodiments of the present invention.
[0067] It should be noted that the system embodiments described above are merely illustrative, and some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs.
[0068] Furthermore, in the accompanying drawings of the system embodiments provided by this invention, the connection relationships between modules indicate that they have communication connections, which can be specifically implemented as one or more communication buses or signal lines. Those skilled in the art can understand and implement this without any inventive effort.
[0069] In the above embodiment, the static attributes of the target terminal device are obtained, and an initial security authentication level is obtained through a preset initial authentication algorithm, thereby achieving a preliminary assessment of the basic risk level of the target terminal device. Subsequently, in order to match the final device authentication strategy for security protection with the real-time risk status of the target terminal device, this embodiment also dynamically corrects the initial security authentication level based on the device's dynamic operating attributes to generate a dynamic device authentication level that matches the real-time risk status of the target terminal device. Based on this dynamic device authentication level, a device authentication strategy is generated for security protection. This enables high-risk critical terminal devices to trigger stronger device authentication strategies for security protection when facing threats, while low-risk terminal devices can also maintain appropriate protection. Thus, overall, the security protection is accurately matched with the real-time risk status of the terminal device, improving the accuracy of terminal device security protection.
[0070] The above description represents the preferred embodiments of the present invention. It should be noted that those skilled in the art can make various improvements and modifications without departing from the principles of the present invention, and these improvements and modifications are also considered to be within the scope of protection of the present invention.
Claims
1. A method for protecting the security of terminal devices, characterized in that, Includes the following steps: Obtain the static and dynamic attributes of the target terminal device; Based on the device's static attributes, an initial security authentication level is obtained using a preset initial authentication algorithm. The device's dynamic operating attributes are used to generate a security level adjustment amount under a preset dynamic adjustment assignment table. Based on the security level adjustment amount and the initial security authentication level, dynamic correction processing is performed to obtain the device's dynamic authentication level. Based on the device's dynamic authentication level, a device authentication policy is generated under a preset authentication strength configuration algorithm, and the target terminal device is protected based on the device authentication policy.
2. The terminal device security protection method according to claim 1, characterized in that, The acquisition of the target terminal device's static attributes and dynamic operating attributes includes: Obtain the target terminal device's basic device attributes and real-time operating data; The device's basic attributes and real-time operating data are used to extract features to generate static attributes and dynamic attributes of the device.
3. The terminal device security protection method according to claim 2, characterized in that, The step of extracting features from the device's basic attributes and the device's real-time operating data to generate static attributes and dynamic operating attributes of the device includes: The basic attributes of the equipment are used to extract features to obtain the importance of equipment functions, the basic value of equipment risk, and the risk coefficient of the deployment environment. The device's real-time operating data is used to extract features to obtain the deviation of the device's operating status, the severity of the device's vulnerabilities, and the frequency of abnormal device communication. Static attributes of the device are generated based on the device's functional importance, the device's basic risk value, and the deployment environment risk coefficient. Dynamic attributes of the device's operation are generated based on the device's operational status deviation, the severity of the device's vulnerabilities, and the frequency of the device's communication anomalies.
4. The terminal device security protection method according to claim 3, characterized in that, The process of obtaining the initial security authentication level based on the device's static attributes using a preset initial authentication algorithm includes: Obtain the functional importance weight, equipment risk weight, and environmental risk weight of the device's static attributes in a preset static authentication weight allocation table; The importance of a device function is generated based on the functional importance weights and the device functional importance of the device's static attributes; The equipment configuration security level is generated based on the equipment risk weight and the basic equipment risk value of the equipment static attributes; The deployment environment security level is generated based on the environmental risk weights and the deployment environment risk coefficients of the static attributes of the equipment. The initial security authentication level is obtained by integrating the importance of the device functions, the security level of the device configuration, and the security level of the deployment environment.
5. A terminal device security protection method according to claim 3, characterized in that, The step of generating a security level adjustment amount based on the device's dynamic operating attributes under a preset dynamic adjustment assignment table, and performing dynamic correction processing based on the security level adjustment amount and the initial security authentication level to obtain the device's dynamic authentication level includes: Obtain the operating state offset weight, vulnerability severity weight, and communication anomaly weight of the device's dynamic operating attributes in a preset dynamic adjustment assignment table; The real-time operating deviation of the device is generated based on the operating state offset weight and the device operating dynamic attribute of the device operating state deviation. The real-time vulnerability severity of the device is generated based on the vulnerability severity weight and the device vulnerability severity of the device's dynamic operating attributes; The real-time communication anomaly level of the device is generated based on the communication anomaly weight and the device communication anomaly frequency of the device's dynamic operating attributes. The real-time deviation of the device's operation, the severity of the device's real-time vulnerabilities, and the degree of abnormality in the device's real-time communication are fused together to obtain the security level adjustment amount; The device dynamic authentication level is obtained by correcting the initial security authentication level under the security level adjustment amount.
6. The terminal device security protection method according to claim 1, characterized in that, The step of generating a device authentication policy based on the device's dynamic authentication level under a preset authentication strength configuration algorithm, and providing security protection for the target terminal device based on the device authentication policy, includes: Based on the device's dynamic authentication level, a device authentication strength value is generated under a preset authentication strength configuration coefficient; The device authentication strength is used to generate a device authentication policy under the preset minimum strength configuration threshold and maximum strength configuration threshold, and the target terminal device is protected according to the device authentication policy.
7. A terminal device security protection method according to claim 6, characterized in that, In the process of generating a device authentication policy based on a preset minimum and maximum strength configuration thresholds for the device authentication strength, and providing security protection for the target terminal device according to the device authentication policy, the step of generating the device authentication policy based on the preset minimum and maximum strength configuration thresholds for the device authentication strength includes: If the device authentication strength is confirmed to be no greater than the preset minimum strength configuration threshold, a device authentication policy set to single-factor authentication is generated; otherwise, it is determined that the device authentication strength is no greater than the preset maximum strength configuration threshold. If the device authentication strength is confirmed to be no greater than the preset maximum strength configuration threshold, a device authentication strategy set to two-factor authentication is generated; otherwise, a device authentication strategy set to multi-factor authentication is generated.
8. A terminal device security protection method according to claim 6, characterized in that, In the step of generating a device authentication policy based on the device authentication strength within a preset minimum and maximum strength configuration threshold, and then performing security protection on the target terminal device based on the device authentication policy, the step of performing security protection on the target terminal device based on the device authentication policy includes: Obtain the total device authentication strength and total authentication resource quantity, and obtain the device resource ratio based on the device authentication strength value, the total device authentication strength, and the total authentication resource quantity; Security protection is provided for the target terminal device based on the device resource ratio and the device authentication policy.
9. A terminal device security protection method according to claim 6, characterized in that, In the step of generating a device authentication policy based on the device authentication strength within a preset minimum and maximum strength configuration threshold, and then performing security protection on the target terminal device based on the device authentication policy, the step of performing security protection on the target terminal device based on the device authentication policy includes: Obtain resource information corresponding to the target terminal device, and obtain the resource configuration device set and total resource capacity corresponding to the resource information; the resource configuration device in the resource configuration device set is the target terminal device; Based on the resource configuration device set and the resource information, obtain the resource adaptation coefficient of each resource configuration device in the resource configuration device set; The device resource ratio is obtained based on the device authentication strength value, the resource adaptation coefficient, and the total resource capacity. Security protection is provided for the target terminal device based on the device resource ratio and the device authentication policy.
10. A terminal device security protection system, characterized in that, A terminal device security protection method as described in any one of claims 1 to 9 includes: The device information acquisition module is used to acquire the static attributes and dynamic operating attributes of the target terminal device. The initial security authentication level assessment module is used to obtain the initial security authentication level based on the static attributes of the device under a preset initial authentication algorithm. The dynamic authentication level evaluation module is used to generate a security level adjustment amount from the dynamic attributes of the device operation under a preset dynamic adjustment assignment table, and to perform dynamic correction processing based on the security level adjustment amount and the initial security authentication level to obtain the device dynamic authentication level. The security protection module is used to generate a device authentication policy based on the device's dynamic authentication level and a preset authentication strength configuration algorithm, and to provide security protection for the target terminal device based on the device authentication policy.