5G-based data security sharing methods, equipment, and sharing systems

By constructing state vectors and performing inverse game theory, the optimal path of the attacker is dynamically identified, and guiding variables and fitness functions are generated. This solves the problem of low policy response adaptability in existing technologies, achieves a balance between encryption strength, access control and transmission efficiency, and improves the efficiency and security of policy updates for secure data sharing.

CN120416837BActive Publication Date: 2025-10-31BEIJING STARRY END TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510818816.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-18
Publication Date
2025-10-31
Estimated Expiration
2045-06-18

AI Technical Summary

Technical Problem

Existing technologies lack dynamic modeling mechanisms for attack paths, have low policy response adaptability, and struggle to achieve a balance between encryption strength, access control, and transmission efficiency under dynamic changes in network slicing status and user context.

Method used

The 5G-based data security sharing method constructs a state vector by acquiring network slice status and user context data, performs reverse game theory to deduce the attacker's optimal path, calculates game payoff, generates guiding variables, constructs a fitness function, performs parameter selection, crossover and mutation, and configures encryption methods, access rules and scheduling strategies.

Benefits of technology

It achieves accurate characterization of the communication environment and user behavior, dynamically identifies potential security threat paths, improves policy update efficiency, enhances the trade-off assessment between security and resource efficiency, and improves the ability to identify differences in the policy evolution process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120416837B_ABST
    Figure CN120416837B_ABST
Patent Text Reader

Abstract

This invention discloses a 5G-based data security sharing method, device, and system, relating to the field of information security technology. The method includes: acquiring network slice status and user context data to construct a state vector; performing inverse game theory based on the state vector to deduce the attacker's optimal path and calculate the game payoffs for both attacker and defender; generating multiple policy individuals based on the game payoffs and constructing a payoff matrix to generate guiding variables; constructing a fitness function by combining the guiding variables and game payoffs, and outputting the fitness score of each policy individual; performing sensitivity evaluation on policy parameters based on the fitness scores and calculating the mutation rate; performing parameter selection, crossover, and mutation based on fitness and mutation rate to obtain an updated set of policy parameters; selecting the policy parameter group with the highest fitness and configuring encryption methods, access rules, and scheduling strategies. This improves the efficiency of encryption strategy selection, enhances the accuracy of access control, and mitigates the risks of secure data sharing.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, specifically to a data security sharing method, device, and sharing system based on 5G. Background Technology

[0002] With the widespread deployment of 5G networks and the rapid expansion of application scenarios, the demand for high-frequency data transmission and diversified sharing is increasing daily. Sensitive data interactions between user terminals and cloud platforms are exhibiting high-density, multi-channel characteristics. Against this backdrop, data security issues are particularly prominent. Traditional static security configuration mechanisms are insufficient to meet the requirements of balancing security and transmission efficiency in dynamic network environments. Especially under network slicing architectures, different service types have significantly different requirements for bandwidth, latency, and security levels, leading to configuration redundancy or protection imbalances in static security strategies.

[0003] Current technologies primarily configure fixed security policies through preset encryption levels or access control rules, but lack the ability to adapt to changes in network conditions and user behavior. They cannot effectively engage in game theory and policy evolution in complex scenarios such as potential attacker path variations and resource constraint fluctuations. Furthermore, some studies have attempted to introduce game theory models for security policy optimization, but these are mostly based on forward game theory, neglecting the optimal avoidance behavior of attackers under multi-path and multi-policy choices, resulting in blind spots in defense effectiveness. Therefore, a secure sharing method that integrates network slice state awareness, inverse game theory deduction, and dynamic parameter evolution mechanisms is urgently needed. Summary of the Invention

[0004] In view of the above-mentioned problems, the present invention is proposed.

[0005] Therefore, the technical problems solved by this invention are: the lack of a dynamic modeling mechanism for attack paths, low policy response adaptability, difficulty in simultaneously balancing encryption strength, access control and transmission efficiency, and how to automatically generate and adjust security policy parameter groups under dynamic changes in network slicing status and user context.

[0006] To address the aforementioned technical problems, this invention provides the following technical solution: a 5G-based data security sharing method, comprising:

[0007] Obtain network slice status and user context data, and construct a state vector;

[0008] Based on the state vector, an inverse game is performed to derive the attacker's optimal path and calculate the game payoffs between the attacker and the defender.

[0009] Multiple strategy individuals are generated based on game payoffs, and a payoff matrix is ​​constructed to generate guiding variables;

[0010] By combining the guiding variable and the game payoff, a fitness function is constructed to output the fitness score of each individual strategy.

[0011] Based on the fitness score, perform a sensitivity assessment on the strategy parameters and calculate the mutation rate;

[0012] Based on fitness and mutation rate, parameter selection, crossover, and mutation are performed to obtain an updated set of strategy parameters;

[0013] Select the policy parameter group with the highest adaptability, and configure the encryption method, access rules and scheduling policy.

[0014] As a preferred embodiment of the 5G-based data security sharing method described in this invention, the network slice status includes real-time bandwidth allocation, network latency, encrypted channel availability, and slice resource remaining rate; the user context information includes user level tags, access request types, and access frequency statistics; the construction of the state vector includes normalizing the network slice status and user context information respectively, and then concatenating them to form a state vector.

[0015] As a preferred embodiment of the 5G-based data security sharing method described in this invention, the step of deriving the attacker's optimal path includes generating a policy parameter set containing encryption strength level, access control granularity, and transmission path type based on the state vector and multiple candidate policy parameters; for each policy parameter set, calculating the attacker's gain value under multiple attack paths according to the current state vector, and selecting the path with the greatest attacker gain from the attack path set as the attacker's optimal path.

[0016] The calculation of the game payoff between the attacker and the defender includes applying the attacker's optimal path to each set of strategy parameters and evaluating the corresponding changes in the attacker's payoff; and calculating the defender's payoff value based on the implementation cost of each set of strategy parameters and the risk of attack success in the corresponding state.

[0017] As a preferred embodiment of the 5G-based data security sharing method described in this invention, the construction of the benefit matrix includes: calculating the attacker's benefit, the defender's benefit, and the change in defense pressure for multiple policy parameter groups based on the current state vector; combining the three benefit data corresponding to each policy parameter group into a policy benefit vector, and arranging them in order according to the policy index to form a benefit matrix containing multiple policy benefit vectors.

[0018] The generation of guiding variables includes: based on each strategy payoff vector in the payoff matrix, taking the defender's payoff and the change in defense pressure as positive factors and the attacker's payoff as negative factors according to preset weights; performing a linear weighted combination of the positive and negative factors to obtain the corresponding preliminary guiding variables; calculating the mean and standard deviation of all preliminary guiding variables, and setting a screening threshold based on the calculation results; and selecting preliminary guiding variables that are not less than the screening threshold as guiding variables.

[0019] As a preferred embodiment of the 5G-based data security sharing method described in this invention, the output of the fitness score of each strategy individual includes constructing a fitness function according to a preset weight based on the guiding variable and the defender's and attacker's gains corresponding to each strategy parameter group in the gain matrix, and calculating the fitness score of each strategy parameter group.

[0020] The fitness function performs a combined mapping with the guiding variable and the defender's gain as positive factors and the attacker's gain as a negative factor, and outputs a set of fitness scores.

[0021] As a preferred embodiment of the 5G-based data security sharing method described in this invention, the calculation of the mutation rate includes: for each policy parameter group, performing perturbation operations on three parameter dimensions: encryption strength level, access control granularity, and transmission path type; comparing the changes in fitness scores before and after the perturbation; calculating the sensitivity values ​​corresponding to each parameter dimension; normalizing the sensitivity values ​​of the three dimensions; constructing a parameter-level mutation rate vector for each policy parameter group; and outputting the adaptive mutation rate set of all policy parameter groups in the current round.

[0022] As a preferred embodiment of the 5G-based data security sharing method of the present invention, the updated strategy parameter set includes: constructing an elite candidate set based on the fitness scores of all strategy parameter groups in the previous round; randomly selecting two strategy parameter groups from the elite candidate set, and performing dimension-level parameter exchange according to a preset cross-probability on three parameter dimensions: encryption strength level, access control granularity, and transmission path type, respectively, to generate multiple cross-strategy parameter groups; identifying the mutation priority dimension according to the parameter-level mutation rate vector corresponding to each strategy parameter group, performing a perturbation operation with the maximum mutation probability on the mutation priority dimension, and setting the mutation probability with a decreasing ratio on the other two dimensions to complete the mutation operation and obtain the updated strategy parameter set.

[0023] The selection of the strategy parameter set with the highest fitness includes selecting the strategy parameter set with the highest fitness score from the updated strategy parameter set as the optimal control strategy for the current round.

[0024] The configuration of encryption methods, access rules, and scheduling strategies includes configuring encryption algorithm levels based on encryption strength levels in the strategy parameter group; configuring resource access rules based on access control granularity; and configuring data scheduling targets based on transmission path types.

[0025] As a preferred embodiment of the 5G-based data security sharing method system described in this invention, it includes: a state awareness module, a game modeling module, a guiding variable generation module, a fitness evaluation module, a mutation rate calculation module, and a strategy evolution and configuration module;

[0026] The state awareness module is used to acquire network slice state and user context information, and normalize them respectively. The normalized data is then concatenated into a state vector for subsequent game modeling and strategy evaluation.

[0027] The game modeling module is used to perform reverse game reasoning based on the state vector and multiple candidate strategy parameter groups to deduce the attacker's optimal path; and to calculate the attacker's payoff, defender's payoff, and defense pressure change value under each strategy parameter group to form a strategy payoff matrix.

[0028] The guiding variable generation module is used to calculate preliminary guiding variables based on the strategy return matrix according to the preset positive and negative factor weighting rules, and to set a screening threshold based on the mean and standard deviation, thereby extracting a set of guiding variables for strategy compression evaluation.

[0029] The fitness evaluation module is used to construct a fitness function by combining the guiding variable with the defender's and attacker's gains corresponding to each strategy parameter group, and to calculate and output the fitness score set for each strategy parameter group.

[0030] The mutation rate calculation module is used to perform perturbations on three dimensions—encryption strength level, access control granularity, and transmission path type—for each policy parameter group, calculate the sensitivity changes of each parameter dimension, normalize them, and generate an adaptive mutation rate set.

[0031] The strategy evolution and configuration module is used to perform selection, crossover and mutation operations on individual strategies based on fitness scores and mutation rate sets to obtain an updated set of strategy parameters; and select the strategy parameter group with the highest fitness from it, and configure encryption method, access rules and scheduling strategy according to it.

[0032] A computer device includes a memory and a processor, the memory storing a computer program, and the processor executing the computer program as steps to implement a 5G-based data secure sharing method.

[0033] A computer-readable storage medium having a computer program stored thereon, the computer program being executed by a processor to implement the steps of a 5G-based data secure sharing method.

[0034] The beneficial effects of this invention are as follows: The 5G-based data security sharing method provided by this invention constructs a state vector by fusing network slice status and user context information, enabling precise characterization of the communication environment and user behavior; it dynamically identifies potential security threat paths by deriving the attacker's optimal path based on inverse game theory; it constructs a multi-dimensional policy parameter set including encryption strength, access granularity, and path type, and achieves a trade-off assessment of security and resource efficiency through a game payoff matrix and guiding variable extraction mechanism; the fitness function integrates guiding variables, defender payoffs, and attacker payoffs, enabling accurate evaluation of policy merits; it introduces sensitivity analysis based on parameter perturbation and a normalized mutation rate modeling mechanism to improve the ability to identify differences during parameter evolution; and it effectively improves policy update efficiency through fitness-driven crossover and sensitivity-guided priority mutation operations. Attached Figure Description

[0035] To more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings used in the following description of the embodiments will be briefly introduced. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0036] Figure 1 The overall flowchart of the 5G-based data security sharing method provided in the first embodiment of the present invention is shown. Detailed Implementation

[0037] To make the above-mentioned objects, features, and advantages of the present invention more apparent and understandable, specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of the present invention, and not all of them. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of the present invention.

[0038] Example 1, referring to Figure 1 As one embodiment of the present invention, a 5G-based data security sharing method is provided, comprising:

[0039] S1: Obtain network slice state and user context data, construct state vectors, perform reverse game theory, deduce the attacker's optimal path, and calculate the game payoff between the attacker and the defender.

[0040] Network slicing layer status parameters, including: real-time bandwidth allocation b tNetwork latency d t Encrypted channel availability e t Slice resource remaining rate r t User context information, including: user level tag u t Access request type q t Safety Sensitivity Level l t Access frequency statistics f t .

[0041] The network slice state and user context data are normalized, and the normalized network slice state and user context data are combined into a state vector s. t :

[0042] s t =[b t ,d t ,e t ,r t ,u t ,q t ,l t ,f t ]

[0043] Three parameters are set for each candidate strategy: encryption strength level. (Corresponding to AES-128, 192, 256); Access control granularity (Coarse, Medium, Fine); Transmission Path Type (Bandwidth priority, encryption priority, low latency priority); combined to obtain the policy vector:

[0044]

[0045] Where i represents the strategy number and t represents the iteration round; Let represent the complete policy vector of the i-th policy individual at time t.

[0046] The game is set as attacker vs. defender; the defender adjusts strategy parameters. Reduce the attacker's current state s t The optimal attack benefit is defined under state s; the attacker is defined in state s. t Next strategy The profit function U atk The benefit is determined by the stealability of the target data and the cost of the attack, expressed by the formula:

[0047]

[0048] Among them, f steal Indicates based on state l t (Security sensitivity), e t(Encrypted Channel) and Strategy The probability of data being stolen derived from (encryption level); f cost The function represents the attack cost estimation function; α represents the attack benefit weighting factor; β represents the attack cost weighting factor; l t This indicates the current user's security sensitivity level; This indicates the level of granularity of access control in the policy parameters.

[0049] According to U atk Solve for all strategies:

[0050]

[0051] Among them, z * Z represents the optimal attack path that an attacker might choose given the current state and strategy; Z represents the attack path space available to the attacker in the current state; argmax z This means searching for the path that maximizes the objective function among all possible attack paths.

[0052] The defensive benefit to a defender against each strategy under the same conditions is defined as follows:

[0053]

[0054] Where γ represents the defender's payoff preference coefficient; Prob succ This represents an estimated probability of a successful attack. θ1 represents the processing latency or computational resource weight caused by encryption strength; θ2 represents the resource consumption weight caused by access control complexity; θ3 represents the impact weight of path strategy on transmission overhead (such as bandwidth); θ4 represents the current network latency d. t Weighting of the impact on the system's response speed.

[0055] Based on the attacker's optimal path z * Calculate the defensive pressure on each strategy after it is attacked:

[0056]

[0057] in, Represents the i-th strategy individual At time t, the optimal attack path z for the attacker. * The reverse pressure value of the game that is borne at that time.

[0058] By integrating network slice status parameters such as real-time bandwidth allocation, network latency, encrypted channel availability, and resource availability with contextual information such as user level labels, access request types, and security sensitivity levels, a normalized state vector is constructed, enabling a multi-dimensional dynamic characterization of the network environment and access behavior. Compared to traditional security assessment methods that rely solely on static permission settings, this approach can more accurately reflect the current communication situation and potential risks.

[0059] This method introduces an inverse game theory mechanism to model the strategic adversarial relationship between attackers and defenders. By constructing an attacker's payoff function based on stealability and attack cost, it can deduce the attacker's optimal path in the current state. Unlike traditional security modeling methods that typically assume the attack path is known or fixed, this method dynamically identifies the attacker's payoff-maximizing behavioral path through game theory, exhibiting stronger predictability and targeting.

[0060] The defender's payoff function comprehensively considers the probability of attack success, the processing resource consumption caused by encryption strength, the complexity of access control, and the transmission loss under the path strategy. It can accurately evaluate the defense value of each set of strategy parameters under different states. At the same time, it introduces a defense pressure index to measure the load change that the system bears during the game. Unlike traditional methods that simply use access control or encryption strength as a security measure, this mechanism achieves a quantitative balance between security, performance, and resource consumption, thereby enhancing the rationality and practicality of strategy configuration.

[0061] S2: Generate multiple strategy individuals based on game payoffs, construct a payoff matrix, and generate guiding variables.

[0062] Generate a set of individual strategies:

[0063]

[0064] Among them, P t Denotes the set of strategy individuals in round t; This represents all N individual policy parameters generated in round t; This represents the strategy parameter combination of the i-th strategy individual in round t; i represents the strategy index, which ranges from 1 to N; t represents the current evolution round. This represents the encryption strength level of the i-th strategy in round t (e.g., AES-128 / 192 / 256); This indicates the access control granularity level (e.g., coarse / medium / fine) of the i-th strategy in round t; This indicates the transmission path type (e.g., bandwidth priority / encryption priority / delay priority) for the i-th strategy in round t.

[0065] Construct a three-dimensional game payoff vector based on each set of strategy parameters:

[0066]

[0067] Stack the payoff vectors corresponding to all strategies into a payoff matrix:

[0068]

[0069] in, This represents the three-dimensional game payoff vector for the i-th strategy in round t; This indicates that the attacker is in the state vector s t Next strategy The benefits; This indicates that the defender is in state vector s t Next strategy The benefits; Representation strategy The change in defensive pressure under the attacker's optimal path; R t R represents the complete payoff matrix constructed in round t, containing three-dimensional payoff information for all N strategies; N×3 Represents the payoff matrix R t It belongs to the N×3 real matrix space (N rows and 3 columns).

[0070] To integrate and compress the multidimensional return performance of the strategy, the guiding variable is calculated:

[0071]

[0072] in, λ represents the guiding variable for the i-th strategy in round t; d The mapping weighting factor representing the defender's payoff; λ a The mapping weight factor representing the attacker's gain; λ v The mapping weighting factor represents the defensive pressure; This represents the change in defensive pressure for the i-th strategy in round t.

[0073] Output the set of bootstrap variables:

[0074]

[0075] Furthermore, to improve the efficiency of strategy evolution, the mean and standard deviation of all guiding variables are calculated.

[0076]

[0077] Set selection threshold

[0078]

[0079] Select a subset of strategies with superior gradient performance.

[0080]

[0081] in, Let represent the mean of the set of guiding variables in round t; This represents the standard deviation of the set of guiding variables in round t. This represents the dynamic threshold value for the selection of the guiding variables in the t-th round; This indicates that in round t, the guiding variable is greater than or equal to the threshold. A subset of sparse strategies; This indicates all conditions that are met. The set of policy-guiding variables is used to select high-performing individuals. The sparsity control process is used to eliminate redundant policy individuals in the policy space, reducing the complexity of subsequent evolutionary operations.

[0082] By constructing a set of policy parameters including encryption strength level, access control granularity, and transmission path type, and combining this with the attacker's payoff, defender's payoff, and changes in defense pressure output by the game model, a three-dimensional game payoff vector set that accurately characterizes the multi-dimensional policy effectiveness can be formed. Compared to traditional methods based solely on static policy evaluation, this scheme can dynamically reflect the security and efficiency performance of policies in complex game scenarios, providing more discriminative data support for subsequent evolution.

[0083] By stacking three-dimensional game payoff vectors to form a payoff matrix and designing based on mapping factor weights, a guiding variable compression mechanism is introduced to achieve a compressed mapping representation of high-dimensional strategy effectiveness, significantly reducing the dimensionality of strategy evaluation. Simultaneously, the adjustability of the weight factors allows for flexible adjustment of the evaluation focus according to security preferences, overcoming the limitations of existing technologies that rely on single evaluation indicators and lack the ability to adjust security biases, effectively enhancing the adaptability and practicality of strategy selection.

[0084] Furthermore, a statistical analysis mechanism based on mean and standard deviation is introduced at the level of guiding variables to construct a dynamic screening threshold and implement sparsity control. This enables the selection of a subset of strategies with outstanding guiding variable performance from numerous individual strategies. This gradient advantage screening method not only improves the convergence speed of the strategy evolution stage but also significantly reduces the computational complexity of evolution, avoiding problems such as blind evolution and redundant computation in traditional methods, and effectively improving the overall safety decision-making efficiency of the system.

[0085] S3: Combine the guiding variable and the game payoff to construct a fitness function and output the fitness score of each strategy individual; based on the fitness score, perform sensitivity evaluation on the strategy parameters and calculate the mutation rate.

[0086] To comprehensively reflect the balance between safety and efficiency of various strategies during the evolutionary process, it is necessary to unify the measurement of guiding variables and game payoffs to form a comparable fitness score. Based on guiding variables... Construct a fitness function using the defender's payoff and the attacker's payoff in the i-th row of the game payoff matrix:

[0087]

[0088] Where ω1+ω2+ω3=1, ω k ∈[0,1];

[0089] Output fitness score set F t :

[0090]

[0091] in, Represents the fitness score of the i-th policy parameter group in round t.

[0092] To identify the key policy dimensions affecting fitness, sensitivity assessments need to be performed on the policy parameters. For each policy... The parameter values ​​are perturbed one by one, with the perturbation amplitude ∈, and the fitness difference before and after the perturbation is calculated.

[0093]

[0094] in, This indicates that the i-th policy individual has a certain level of encryption strength. The absolute value of the change in fitness value after perturbation; This indicates the granularity of access control for the i-th policy individual. The absolute value of the change in fitness value after perturbation; This indicates that the i-th policy individual is in the dimension of transmission path type. The absolute value of the change in fitness value after perturbation.

[0095] Normalize the sensitivity of each parameter to generate an adaptive variability rate:

[0096]

[0097] in, This represents the normalized sensitivity of the i-th strategy on the encryption strength dimension E; This represents the normalized sensitivity of the i-th policy on the access control granularity dimension A; This represents the normalization sensitivity of the i-th strategy on the transmission path type dimension T;

[0098] Constructing a parametric-level variability vector:

[0099]

[0100] Output mutation rate set:

[0101]

[0102] in, η represents the parameter-level mutation rate vector of the i-th strategy in round t; t Let represent the set of adaptive mutation rates for all strategy individuals in round t.

[0103] The fitness function incorporates the guiding variable, defender's payoff, and attacker's payoff into the scoring model, forming a unified metric and establishing a trade-off between security and system overhead. By constructing a multidimensional fitness function that integrates multiple game payoff factors, it can not only reflect the actual protective capability of the strategy in the current state but also comprehensively evaluate its efficiency in utilizing system resources, effectively avoiding the limitation of traditional methods where security and efficiency cannot be reconciled.

[0104] The sensitivity assessment mechanism employs parameter perturbation and fitness difference calculation to identify the degree of influence of each policy parameter on the overall policy effect. By introducing the perturbation amplitude ε and analyzing the fitness differences resulting from changes in three parameter dimensions (encryption strength, access control granularity, and transmission path type), the contribution of each parameter can be quantitatively identified. Compared to fixed or empirically set mutation probability methods, this approach has higher personalized identification capabilities and can dynamically determine the key policy dimensions that most need adjustment.

[0105] The normalized mutation rate model can transform the sensitivity values ​​of the three dimensions into comparable weight vectors, providing a precise control basis for evolutionary strategy optimization. By constructing a parameter-level mutation rate vector and forming an overall adaptive mutation rate set, subsequent policy mutation operations have clear regulatory objectives and differential optimization capabilities, improving the accuracy and effectiveness of policy updates and avoiding the slow convergence speed or getting trapped in local optima caused by blind mutation in traditional evolutionary mechanisms.

[0106] S4: Based on fitness and mutation rate, perform parameter selection, crossover and mutation to obtain the updated set of policy parameters; select the policy parameter group with the highest fitness and configure the encryption method, access rules and scheduling strategy.

[0107] Based on the fitness scores of all strategy individuals in the previous round Following a roulette wheel selection method or a proportional selection mechanism, individuals with higher fitness scores are prioritized for inclusion in the candidate breeding pool, forming an elite candidate set. This set is used for the next step of crossover and mutation operations, ensuring that high-fit individuals have a greater chance of being retained.

[0108] From candidate strategy set Two parent policy parameter sets are randomly selected. and The dimensions are reorganized according to probability proportions to form two new individuals: each policy parameter set p t =[E t A t ,T t ], at encryption strength E t Access control granularity A t Transmission path type T t Exchanges are performed along each dimension; the crossover method depends on a preset crossover probability threshold P. c It can be set according to a fixed ratio or a state-related dynamic value; all newly generated individuals constitute a candidate new strategy set.

[0109] Parametric mutation rate vector for each strategy individual Based on the relative magnitudes of the normalization sensitivity values, the following mutation priority rule is set: when When this is the case, priority should be given to the encryption strength level E of this strategy. t Perform mutation; when At that time, priority is given to access control granularity A. t Perform mutation; when When, priority is given to transmission path type T. t Perform mutation. Priority mutation operations refer to those that use the highest mutation probability. The parameters are perturbed for the corresponding dimension, while the mutation probability of the other dimensions is reduced according to the decreasing ratio.

[0110] From the updated policy parameter set P t+1 In the middle, select the policy parameter set p with the highest fitness score. * ∈P t+1 As the optimal control strategy for the current round, the following configuration output is executed:

[0111] Encryption method configuration: based on p * Encryption strength level E in * Select the corresponding encryption algorithm level (such as AES-128, AES-256).

[0112] Access control configuration: Based on access control granularity A * Adjust resource access strategies (e.g., coarse-grained at the role level, fine-grained at the request level).

[0113] Scheduling strategy configuration: based on transmission path type T * Set communication scheduling goals (such as delay priority, encryption priority, bandwidth priority).

[0114] The above configuration is synchronized to the encryption control module, access control module, and data transmission scheduling module to achieve end-to-end data security sharing optimization.

[0115] By constructing an elite candidate set and introducing a roulette wheel selection or proportional selection mechanism, policy individuals with higher fitness scores are preferentially retained during policy updates. This significantly improves the evolutionary algorithm's ability to preserve excellent solutions and avoids the loss of superior policies that may occur during random updates. Compared to traditional indiscriminate random selection methods, this strategy enables directional optimization during policy evolution, improving convergence speed and stability.

[0116] During policy updates, cross-operations are limited to three dimensions: encryption strength level, access control granularity, and transmission path type. Dimensional recombination is performed based on dynamic cross-operation probabilities, effectively controlling the perturbation range of the understanding space. Combined with a mutation priority rule based on normalized sensitivity, key perturbations are implemented on highly sensitive parameter dimensions, improving the targeting and efficiency of policy updates. Compared to traditional equal-probability mutation mechanisms, this mechanism achieves a dynamic balance between resource allocation and security policies.

[0117] By comparing the fitness of all policy individuals after the current round of updates, the parameter group with the highest fitness is selected and mapped to specific encryption algorithm selection, access control policy settings, and transmission scheduling method configurations, achieving synergistic optimization of security and communication performance. This approach breaks away from the static preset logic of traditional policy configuration processes, possessing the capabilities of automatic policy evolution, adaptive adjustment, and modular deployment, significantly improving the security dynamic responsiveness and resource utilization efficiency of the data sharing process.

[0118] Example 2 is an embodiment of the present invention, which provides a data security sharing method based on 5G. In order to verify the beneficial effects of the present invention, scientific demonstration is carried out through economic benefit calculation and simulation experiment.

[0119] A network slicing environment and a user access simulation environment were deployed on an enterprise-level 5G edge computing platform to verify the effectiveness of the proposed data security sharing method. The platform supports dynamic slice configuration, has a user level classification mechanism and access frequency recording function, and allows access to encryption modules and resource access control policies with different security levels. First, the state vector required for the experiment was constructed. Four network slice state indicators (real-time bandwidth allocation, network latency, encryption channel availability, and slice resource remaining rate) and three user context information items (user level, access type, and access frequency) were collected. All indicators were normalized and then concatenated into the state vector.

[0120] For the current state vector, a set of candidate policy parameter groups is generated. Each group includes encryption strength level (3 levels), access control granularity (3 levels), and transmission path type (3 types), totaling 27 policy groups. Then, inverse game theory is performed to derive the attacker's optimal path, calculating the attacker's payoff, defender's payoff, and changes in defense pressure under each policy group, constructing a payoff matrix. Based on the payoff matrix, using defender's payoff and defense pressure as positive factors and attacker's payoff as a negative factor, a guiding variable is generated through linear weighting. The mean and standard deviation are calculated, and after determining the screening threshold, high-value guiding variables are retained.

[0121] Continuing to combine the guiding variable and the three benefit data, a fitness function is constructed to output the fitness score of each policy individual. Perturbations are applied to each set of policy parameters, and the sensitivity across three dimensions—encryption strength, access control, and path type—is calculated and normalized to a mutation rate. Based on fitness and mutation rate, elite individuals are selected for cross-recombination and sensitivity-guided mutation to generate a new set of policy parameters. Finally, the individual with the highest fitness is selected for configuring and executing encryption method (AES-256), access rules (request-level control), and path scheduling (bandwidth priority).

[0122] Example of network state vector (after normalization): 0.74, 0.35, 0.88, 0.61, 0.67, 0.42, 0.90.

[0123] The attacker's payoff has a mean range of 0.12 and 0.91, with a standard deviation of 0.23.

[0124] The defender's payout has a mean range of 0.23 and 0.94, with a standard deviation of 0.19.

[0125] The range of defense pressure variation is -0.15 to 0.36.

[0126] The guiding variable has a mean of 0.57, a standard deviation of 0.14, and a threshold of 0.61.

[0127] The percentage of effective guiding variables selected was 37.04%.

[0128] The highest policy fitness value is 0.87, corresponding to the policy (AES-256, request-level control, bandwidth priority).

[0129] Sensitivity normalization example (strategy 7) η E =0.41,η A =0.28,η T =0.31.

[0130] Before optimization, the average system response time was 123.67ms; after optimization, it was reduced to 98.45ms.

[0131] The attack interception success rate increased from 72.30% to 88.65%.

[0132] Experimental data demonstrate that this method significantly optimizes several key performance indicators. Firstly, in the state vector construction stage, unified normalization and fusion of multi-dimensional network slice states and user context features enhance the real-time responsiveness of subsequent game modeling, effectively improving the accuracy of attack path evaluation. The resulting payoff matrix not only quantifies defense gains and attack costs but also incorporates a "defense pressure change value" to construct a ternary payoff vector, achieving indirect modeling of the defense system's response load—a rare and innovative approach in the current field.

[0133] In the process of generating guiding variables, a linear mapping strategy using positive and negative factors is employed. This not only reflects the strengths and weaknesses of the strategy but also strengthens the connection between "game-feedback-evolution." Statistical data shows that the effective guiding variable selection rate is 37.04%, indicating that the mechanism possesses good discriminative power. Particularly noteworthy is the fitness function construction stage, which integrates guiding variables, attacker payoffs, and defender payoffs into a unified evaluation framework, avoiding the one-sidedness of relying on a single payoff.

[0134] The innovation in mutation rate calculation lies in the "sensitivity-driven adaptive perturbation mechanism." By introducing perturbation experiments, the three dimensions of encryption strength, access control, and path type are quantified and normalized after difference analysis. This allows for the dynamic identification of the impact of each policy dimension on the overall fitness, thus enabling targeted parameter perturbation in subsequent mutation operations. Compared to traditional static mutation rate designs, this sensitivity-driven mechanism makes policy evolution more directional. In the experiment, the fitness of the ultimately selected policy group was 0.87, significantly better than the mean.

[0135] At the system level, the implementation plan effectively reduced the response time during data sharing from 123.67ms to 98.45ms, an improvement of 20.42%; simultaneously, the attack interception success rate increased by 16.35%. These figures demonstrate the method's clear advantages in improving system security and resource scheduling efficiency. Due to the parameter-level mutation rate guidance and fitness optimization mechanism, the final output combination of encryption level, access granularity, and scheduling strategy is more synergistic, forming a more robust set of security control strategies.

[0136] Example 3, an embodiment of the present invention, provides a data security sharing method system based on 5G, including a state awareness module, a game modeling module, a guiding variable generation module, a fitness evaluation module, a mutation rate calculation module, and a strategy evolution and configuration module;

[0137] The state awareness module is used to acquire network slice state and user context information, and normalize them respectively. The normalized data is then concatenated into a state vector for subsequent game modeling and strategy evaluation.

[0138] The game modeling module is used to perform reverse game reasoning based on the state vector and multiple candidate strategy parameter groups to deduce the attacker's optimal path; and to calculate the attacker's payoff, defender's payoff, and defense pressure change value under each strategy parameter group to form a strategy payoff matrix.

[0139] The guiding variable generation module is used to calculate preliminary guiding variables based on the strategy return matrix according to the preset positive and negative factor weighting rules, and to set a screening threshold based on the mean and standard deviation, thereby extracting a set of guiding variables for strategy compression evaluation.

[0140] The fitness evaluation module is used to construct a fitness function by combining the guiding variable with the defender's and attacker's gains corresponding to each strategy parameter group, and to calculate and output the fitness score set for each strategy parameter group.

[0141] The mutation rate calculation module is used to perform perturbations on three dimensions—encryption strength level, access control granularity, and transmission path type—for each policy parameter group, calculate the sensitivity changes of each parameter dimension, normalize them, and generate an adaptive mutation rate set.

[0142] The strategy evolution and configuration module is used to perform selection, crossover and mutation operations on individual strategies based on fitness scores and mutation rate sets to obtain an updated set of strategy parameters; and select the strategy parameter group with the highest fitness from it, and configure encryption method, access rules and scheduling strategy according to it.

[0143] If a function is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this invention, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods of the various embodiments of this invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0144] The logic and / or steps represented in the flowchart or otherwise described herein, for example, can be considered as a sequenced list of executable instructions for implementing logical functions, and can be embodied in any computer-readable medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (such as a computer-based system, a processor-included system, or other system that can fetch and execute instructions from, an instruction execution system, apparatus, or device). For the purposes of this specification, "computer-readable medium" can be any means that can contain, store, communicate, propagate, or transmit programs for use by, or in conjunction with, an instruction execution system, apparatus, or device.

[0145] More specific examples (a non-exhaustive list) of computer-readable media include: electrical connections (electronic devices) having one or more wires, portable computer disk drives (magnetic devices), random access memory (RAM), read-only memory (ROM), erasable and editable read-only memory (EPROM or flash memory), fiber optic devices, and portable optical disc read-only memory (CDROM). Furthermore, computer-readable media can even be paper or other suitable media on which programs can be printed, because programs can be obtained electronically, for example, by optically scanning the paper or other medium, followed by editing, interpreting, or otherwise processing as necessary, and then stored in computer memory.

[0146] It should be understood that various parts of the present invention can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in memory and executed by a suitable instruction execution system. For example, if implemented in hardware, as in another embodiment, it can be implemented using any combination of the following techniques known in the art: discrete logic circuits having logic gates for implementing logical functions on data signals, application-specific integrated circuits (ASICs) having suitable combinational logic gates, programmable gate arrays (PGAs), field-programmable gate arrays (FPGAs), etc. It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.

[0147] It should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit it. Although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications or equivalent substitutions can be made to the technical solutions of the present invention without departing from the spirit and scope of the technical solutions of the present invention, and all such modifications or substitutions should be covered within the scope of the claims of the present invention.

Claims

1. A 5G-based data security sharing method, characterized in that, include: Obtain network slice state and user context data, and construct a state vector; Based on the state vector, an inverse game is performed to derive the attacker's optimal path and calculate the game payoffs between the attacker and the defender. Multiple strategy individuals are generated based on game payoffs, and a payoff matrix is ​​constructed to generate guiding variables; By combining the guiding variable and the game payoff, a fitness function is constructed to output the fitness score of each individual strategy. Based on the fitness score, perform a sensitivity assessment on the strategy parameters and calculate the mutation rate; Based on fitness and mutation rate, parameter selection, crossover, and mutation are performed to obtain an updated set of strategy parameters; Select the policy parameter group with the highest adaptability, and configure the encryption method, access rules and scheduling policy; The construction of the benefit matrix includes: calculating the attacker's benefit, the defender's benefit, and the change in defense pressure for multiple policy parameter groups based on the current state vector; combining the three benefit data corresponding to each policy parameter group into a policy benefit vector, and arranging them in order according to the policy index to form a benefit matrix containing multiple policy benefit vectors. The generation of guiding variables includes, based on each strategy benefit vector in the benefit matrix, taking the defender's benefit and the change in defense pressure as positive factors and the attacker's benefit as a negative factor according to preset weights. By performing a linear weighted combination of positive and negative factors, the corresponding preliminary guiding variables are obtained; Calculate the mean and standard deviation of all initial guiding variables, and set the screening threshold based on the calculation results; Preliminary guiding variables that are not less than the screening threshold are selected as guiding variables; The updated set of policy parameters includes constructing an elite candidate set based on the fitness scores of all policy parameter groups in the previous round. Two policy parameter groups are randomly selected from the elite candidate set. Dimensional parameter exchanges are performed on the three parameter dimensions of encryption strength level, access control granularity, and transmission path type according to a preset cross-probability, generating multiple cross-policy parameter groups. Based on the parameter-level mutation rate vector corresponding to each policy parameter group, mutation priority dimensions are identified. Perturbation operations are performed on the mutation priority dimensions with the highest mutation probability, while mutation probabilities are set at decreasing ratios on the other two dimensions to complete the mutation operation and obtain the updated policy parameter set. The selection of the strategy parameter set with the highest fitness includes selecting the strategy parameter set with the highest fitness score from the updated strategy parameter set as the optimal control strategy for the current round. The configuration of encryption methods, access rules, and scheduling strategies includes configuring encryption algorithm levels based on encryption strength levels in the strategy parameter group; configuring resource access rules based on access control granularity; and configuring data scheduling targets based on transmission path types.

2. The 5G-based data security sharing method as described in claim 1, characterized in that: The network slice status includes real-time bandwidth allocation, network latency, encrypted channel availability, and slice resource remaining rate; User context information includes user level tags, access request types, and access frequency statistics; The construction of the state vector includes normalizing the network slice state and the user context information respectively, and then concatenating them to form a state vector.

3. The 5G-based data security sharing method as described in claim 2, characterized in that: The process of deriving the attacker's optimal path includes generating a set of policy parameters based on the state vector and multiple candidate policy parameters, which includes encryption strength level, access control granularity and transmission path type; for each set of policy parameters, calculating the attacker's profit value under multiple attack paths according to the current state vector, and selecting the path with the greatest attacker profit from the set of attack paths as the attacker's optimal path. The calculation of the game payoff between the attacker and the defender includes applying the attacker's optimal path to each set of strategy parameters and evaluating the corresponding changes in the attacker's payoff; and calculating the defender's payoff value based on the implementation cost of each set of strategy parameters and the risk of attack success in the corresponding state.

4. The 5G-based data security sharing method as described in claim 3, characterized in that: The output fitness score of each strategy individual includes constructing a fitness function according to preset weights based on the guiding variable and the defender's and attacker's gains corresponding to each strategy parameter group in the payoff matrix, and calculating the fitness score of each strategy parameter group. The fitness function performs a combined mapping with the guiding variable and the defender's gain as positive factors and the attacker's gain as a negative factor, and outputs a set of fitness scores.

5. The 5G-based data security sharing method as described in claim 4, characterized in that: The calculation of the mutation rate includes performing perturbation operations on three parameter dimensions—encryption strength level, access control granularity, and transmission path type—for each policy parameter group, comparing the changes in fitness scores before and after the perturbation, and calculating the sensitivity value corresponding to each parameter dimension; normalizing the sensitivity values ​​of the three dimensions, constructing a parameter-level mutation rate vector for each policy parameter group, and outputting the adaptive mutation rate set of all policy parameter groups in the current round.

6. A system employing the 5G-based data security sharing method as described in any one of claims 1 to 5, characterized in that: It includes a state awareness module, a game modeling module, a guiding variable generation module, a fitness evaluation module, a mutation rate calculation module, and a strategy evolution and configuration module; The state awareness module is used to acquire network slice state and user context information, and normalize them respectively. The normalized data is then concatenated into a state vector for subsequent game modeling and strategy evaluation. The game modeling module is used to perform reverse game reasoning based on the state vector and multiple candidate strategy parameter groups to deduce the attacker's optimal path; and to calculate the attacker's payoff, defender's payoff, and defense pressure change value under each strategy parameter group to form a strategy payoff matrix. The guiding variable generation module is used to calculate preliminary guiding variables based on the strategy return matrix according to the preset positive and negative factor weighting rules, and to set a screening threshold based on the mean and standard deviation, thereby extracting a set of guiding variables for strategy compression evaluation. The fitness evaluation module is used to construct a fitness function by combining the guiding variable with the defender's and attacker's gains corresponding to each strategy parameter group, and to calculate and output the fitness score set for each strategy parameter group. The mutation rate calculation module is used to perform perturbations on three dimensions—encryption strength level, access control granularity, and transmission path type—for each policy parameter group, calculate the sensitivity changes of each parameter dimension, normalize them, and generate an adaptive mutation rate set. The strategy evolution and configuration module is used to perform selection, crossover and mutation operations on individual strategies based on fitness scores and mutation rate sets to obtain an updated set of strategy parameters; and select the strategy parameter group with the highest fitness from it, and configure encryption method, access rules and scheduling strategy according to it.

7. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the 5G-based data security sharing method as described in any one of claims 1 to 5.

8. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the 5G-based data security sharing method as described in any one of claims 1 to 5.

Citation Information

Patent Citations

  • Integrated strategy learning method, device and equipment oriented to incomplete information game

    CN114881194A

  • Attack and defense game modeling and equilibrium analysis method based on 5G graph structure network

    CN116095670A