Smart Device Identity Recognition via Network Layer Entropy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for identifying smart devices rely on application layer information, which is easily counterfeited, posing security risks as hackers can impersonate devices and occupy cloud server resources, threatening the security of cloud servers.

Innovation Solution

A method that determines the identity of a smart device by calculating the data randomness degree of inter-packet difference data in network data packets, using information entropy and comparing it with a pre-calculated value from identified devices, to differentiate between legitimate and counterfeit devices based on network layer information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If application layer information (device ID, MAC address) is used for device identification, then the identification process is simple and fast, but the security is poor because this information is easy to be counterfeited

Engineering Contradiction:
Improveidentification process simplicityVSAvoididentification security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces network layer information (IP header fields such as TTL, TOS, IP ID, source port) as an intermediary for device identification. This intermediary layer between the application layer and physical layer provides identification data that is much harder to counterfeit than application layer information, while maintaining reasonable identification efficiency through automated extraction and comparison of these network layer features.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent changes the identification parameters from application layer data (device ID, MAC address) to network layer data (IP header fields). This parameter change fundamentally alters the security characteristics of the identification system, as network layer parameters are automatically generated by the operating system and network stack, making them extremely difficult to replicate or spoof compared to application layer credentials.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If network layer information is used for device identification, then the security is improved because this information is not easy to be counterfeited, but the device complexity increases

Engineering Contradiction:
Improveidentification securityVSAvoididentification system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages the self-service capability of the network stack to automatically generate and populate IP header fields (TTL, TOS, IP ID, source port) without requiring manual configuration or additional hardware. These fields are automatically filled by the operating system's network protocol implementation, eliminating the need for complex manual setup while providing secure identification data.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a fingerprint copy of the device's network layer characteristics by extracting and comparing key IP header fields. Instead of requiring complex analysis of the entire network communication behavior, the system creates a simplified copy or representation of the device's network identity through these specific header fields, enabling efficient and secure identification without excessive complexity.

Inventive Principle:
Principle #26Copying

3Ease of operation

If traditional identification methods are used, then the system is easy to operate, but hacker attacks can easily occupy cloud server resources

Engineering Contradiction:
Improvesystem operation easeVSAvoidhacker attack impact
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies preliminary anti-action by preemptively using network layer information to identify and block potential hacker attempts before they can compromise cloud server resources. By analyzing IP header fields early in the communication process, the system can detect and reject suspicious devices that exhibit hacker-like patterns, preventing resource occupation and attacks before they occur.

Inventive Principle:
Principle #9Preliminary anti-action

Data Source

PatentUS11943220B2Smart device identity recognition method and system, electronic device, and storage medium
Publication Date: 2024.03.26 MIDEA GROUP CO LTD
  • US11943220B2 patent drawing
  • US11943220B2 patent drawing
  • US11943220B2 patent drawing

AI summary

A smart device identity recognition method and system, an electronic device, and a storage medium, are described. The method includes determining a first data randomness degree of inter-packet difference data in a network data packet sent by a smart device to be identified; and determining the identity of said smart device according to a comparison result between the first data randomness degree and a second data randomness degree, and the second data randomness degree is the data randomness degree of inter-packet difference data in a network data packet sent by a identified smart device. According to the smart device identifying method and system, the electronic device, and the storage medium, identity recognition of a smart device can be realized by discrimination of network layer information that is not susceptible to counterfeiting, to ensure that an object served by a cloud server is legitimate and safe.