Smart Device Identity Recognition via Network Layer Entropy
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for identifying smart devices rely on application layer information, which is easily counterfeited, posing security risks as hackers can impersonate devices and occupy cloud server resources, threatening the security of cloud servers.
Innovation Solution
A method that determines the identity of a smart device by calculating the data randomness degree of inter-packet difference data in network data packets, using information entropy and comparing it with a pre-calculated value from identified devices, to differentiate between legitimate and counterfeit devices based on network layer information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If application layer information (device ID, MAC address) is used for device identification, then the identification process is simple and fast, but the security is poor because this information is easy to be counterfeited
Solution Approach 1:
The patent introduces network layer information (IP header fields such as TTL, TOS, IP ID, source port) as an intermediary for device identification. This intermediary layer between the application layer and physical layer provides identification data that is much harder to counterfeit than application layer information, while maintaining reasonable identification efficiency through automated extraction and comparison of these network layer features.
Solution Approach 2:
The patent changes the identification parameters from application layer data (device ID, MAC address) to network layer data (IP header fields). This parameter change fundamentally alters the security characteristics of the identification system, as network layer parameters are automatically generated by the operating system and network stack, making them extremely difficult to replicate or spoof compared to application layer credentials.
2Reliability
If network layer information is used for device identification, then the security is improved because this information is not easy to be counterfeited, but the device complexity increases
Solution Approach 1:
The patent leverages the self-service capability of the network stack to automatically generate and populate IP header fields (TTL, TOS, IP ID, source port) without requiring manual configuration or additional hardware. These fields are automatically filled by the operating system's network protocol implementation, eliminating the need for complex manual setup while providing secure identification data.
Solution Approach 2:
The patent creates a fingerprint copy of the device's network layer characteristics by extracting and comparing key IP header fields. Instead of requiring complex analysis of the entire network communication behavior, the system creates a simplified copy or representation of the device's network identity through these specific header fields, enabling efficient and secure identification without excessive complexity.
3Ease of operation
If traditional identification methods are used, then the system is easy to operate, but hacker attacks can easily occupy cloud server resources
Solution Approach 1:
The patent applies preliminary anti-action by preemptively using network layer information to identify and block potential hacker attempts before they can compromise cloud server resources. By analyzing IP header fields early in the communication process, the system can detect and reject suspicious devices that exhibit hacker-like patterns, preventing resource occupation and attacks before they occur.
Data Source
AI summary
A smart device identity recognition method and system, an electronic device, and a storage medium, are described. The method includes determining a first data randomness degree of inter-packet difference data in a network data packet sent by a smart device to be identified; and determining the identity of said smart device according to a comparison result between the first data randomness degree and a second data randomness degree, and the second data randomness degree is the data randomness degree of inter-packet difference data in a network data packet sent by a identified smart device. According to the smart device identifying method and system, the electronic device, and the storage medium, identity recognition of a smart device can be realized by discrimination of network layer information that is not susceptible to counterfeiting, to ensure that an object served by a cloud server is legitimate and safe.


