Power wireless local area network multi-domain data processing method and system based on credible authentication
Through the trusted authentication model and multimodal feature extraction, combined with confidence-weighted fusion and dynamic correlation analysis, a cross-domain correlation feature set is generated, which solves the shortcomings of device reliability evaluation and cross-domain data processing in power wireless LANs, realizes multi-domain collaborative optimization and resource intelligent scheduling, and improves the security and operation efficiency of the network.
Patent Information
- Application Number
- CN202510686460.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-27
- Publication Date
- 2025-08-29
- Estimated Expiration
- 2045-05-27
AI Technical Summary
The existing power wireless LAN lacks a dynamic and multi-dimensional credibility assessment mechanism, which is difficult to effectively resist the access of equipment forged identity or abnormal behavior. Cross-domain data processing fails to deeply explore the inherent connection between the equipment operation status, network transmission quality and business operation semantics, resulting in unreasonable resource scheduling and lagging abnormal responses.
The trusted authentication model is used to authenticate the terminal equipment, generate a terminal authentication data set, and obtain the device's operating status, network transmission quality and service operation semantic features through multi-modal feature extraction processing. Combined with confidence-weighted fusion and dynamic correlation analysis, a cross-domain correlation feature set is generated, and a pre-trained multi-domain collaborative analysis model is used for spatiotemporal context aggregation, and a multi-domain collaborative optimization strategy is generated to realize dynamic resource reconfiguration.
It improves the security and operation efficiency of power wireless LAN in complex business scenarios, ensures device identity legality and communication compliance, realizes active defense of intelligent scheduling and abnormal behaviors, and forms a complete optimization closed loop from strategy formulation to execution feedback.
Smart Images

Figure CN120568337A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a method and system for processing multi-domain data in a power wireless local area network based on trusted authentication. Background Art
[0002] In the field of power wireless local area networks, with the rapid increase in business diversification and device access, network security and efficient operation face severe challenges. In existing technologies, terminal device authentication often relies on a single identity or static password, lacking a dynamic, multi-dimensional credibility assessment mechanism, making it difficult to effectively prevent the access of forged identities or abnormal behavior devices. At the same time, cross-domain data processing is often limited to simple data aggregation or rule matching, failing to deeply explore the inherent connections between device operating status, network transmission quality, and business operation semantics, resulting in unreasonable resource scheduling and delayed abnormal response. In addition, existing network optimization strategies are mostly based on preset rules or local analysis, lacking the ability to aggregate and coordinate spatiotemporal context from a global perspective, and are difficult to adapt to complex and changing power business scenarios. Therefore, there is an urgent need for an innovative power wireless local area network data processing method that can comprehensively consider the credibility of terminal devices, cross-domain data characteristics, and business semantics to achieve multi-domain collaborative optimization and dynamic resource reconfiguration. Summary of the Invention
[0003] In view of the above-mentioned problems, in combination with the first aspect of the present invention, an embodiment of the present invention provides a method for processing multi-domain data in a power wireless local area network based on trusted authentication, the method comprising:
[0004] Calling the trusted authentication model to perform credibility authentication processing on the terminal devices in the power wireless local area network to generate a terminal authentication data set, which includes device identity characteristics, communication protocol compliance characteristics and real-time behavior credibility scores;
[0005] Obtain cross-domain raw data streams of multiple service domains in the power wireless local area network, perform multimodal feature extraction processing on the cross-domain raw data streams, and obtain device operation status features, network transmission quality features, and service operation semantic features;
[0006] Performing credibility weighted fusion processing on the device operation status features based on the terminal authentication data set to generate a trusted device operation feature set, and dynamically correlating and analyzing the trusted device operation feature set with the network transmission quality features to generate a cross-domain correlation feature set;
[0007] Calling a pre-trained multi-domain collaborative analysis model to perform spatiotemporal context aggregation processing on the cross-domain correlation feature set and the business operation semantic feature to generate a multi-domain collaborative optimization strategy set, wherein the multi-domain collaborative optimization strategy set includes a resource scheduling priority sequence, abnormal operation interception rules, and protocol adaptive adjustment parameters;
[0008] Based on the multi-domain collaborative optimization strategy set, dynamic resource reconfiguration processing is performed on the service domain nodes of the power wireless local area network, a network optimization execution instruction set is generated, and the network optimization execution instruction set is fed back to the terminal device to trigger a trusted communication link upgrade operation.
[0009] On the other hand, an embodiment of the present invention also provides a multi-domain data processing system for a power wireless local area network based on trusted authentication, including a processor and a machine-readable storage medium, wherein the machine-readable storage medium is connected to the processor, the machine-readable storage medium is used to store programs, instructions or codes, and the processor is used to execute the programs, instructions or codes in the machine-readable storage medium to implement the above method.
[0010] Based on the above aspects, the embodiments of the present application realize a global closed-loop optimization mechanism from terminal device credibility verification to cross-domain data fusion, multi-domain collaborative optimization strategy generation, and then to network dynamic resource reconfiguration, significantly improving the security and operation efficiency of the power wireless LAN in complex business scenarios. Specifically, a comprehensive credibility assessment of terminal devices is performed through a trusted authentication model, which not only ensures the identity legitimacy and communication compliance of the access device, but also dynamically reflects the credibility of the device's operating status through a real-time behavioral credibility scoring mechanism. On this basis, multimodal feature extraction is performed on the cross-domain original data stream, effectively integrating multi-dimensional information such as device operating status, network transmission quality, and business operation semantics. Through credibility weighted fusion and dynamic correlation analysis, the credibility of the terminal device is closely combined with the operating status and network transmission quality to generate a cross-domain correlation feature set with high credibility and business relevance. The pre-trained multi-domain collaborative analysis model can deeply explore the potential connection between cross-domain correlation features and business operation semantics through spatiotemporal context aggregation processing, and generate a multi-domain collaborative optimization strategy set including resource scheduling priority, abnormal operation interception rules, and protocol adaptive adjustment parameters, realizing intelligent scheduling of power wireless LAN resources and active defense against abnormal behaviors. Ultimately, based on this set of optimization strategies, the business domain nodes are dynamically reconfigured for resources, and the feedback is fed back to the terminal devices to trigger the upgrade of the trusted communication link, forming a complete optimization closed loop from strategy formulation to execution feedback. This not only improves the overall performance and reliability of the network, but also enhances the ability to respond to complex business scenarios and potential security threats. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] Figure 1It is a schematic diagram of the execution flow of the multi-domain data processing method of the power wireless local area network based on trusted authentication provided by an embodiment of the present invention.
[0012] Figure 2 The figure is a schematic diagram of exemplary hardware and software components of a multi-domain data processing system for a power wireless local area network based on trusted authentication provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0013] The present invention will be described in detail below with reference to the accompanying drawings. Figure 1 This is a flow chart of a method for processing multi-domain data in a power wireless local area network based on trusted authentication provided by an embodiment of the present invention. The method for processing multi-domain data in a power wireless local area network based on trusted authentication is introduced in detail below.
[0014] Step S110: calling a trusted authentication model to perform a credibility authentication process on a terminal device in the power wireless local area network, and generating a terminal authentication data set, wherein the terminal authentication data set includes device identity features, communication protocol compliance features, and real-time behavior credibility scores.
[0015] For example, in a specific power production scenario, a power plant uses a power wireless LAN to connect terminal devices distributed throughout the plant. These terminal devices, including various sensors, smart meters, and control terminals, are used to monitor power production parameters in real time and execute control commands. When these terminal devices are connected to the power wireless LAN, they must undergo trustworthiness authentication to ensure network security and reliability.
[0016] Step S111: obtaining the device identity certificate and protocol interaction log submitted by the terminal device when accessing the power wireless local area network, performing certificate chain verification processing on the device identity certificate, and obtaining the device identity authentication result and the certificate authority trust score.
[0017] For example, when a terminal device initiates an access request, it submits its device identity certificate and protocol interaction log to the authentication system. The device identity certificate is issued by an authoritative certificate authority and verifies the device's legal identity. It contains key information such as the device's unique identifier, certificate validity period, and certificate authority information. The protocol interaction log records the protocol rules and interactions followed by the device during communication with the network.
[0018] For example, a temperature sensor's device ID might record its serial number as "TS-00123," with a validity period from January 1, 2024, to January 1, 2025, and the issuing authority as "PowerCertAuthority." Protocol interaction logs might include information such as the protocol version and encryption algorithm used when the sensor communicates with the network.
[0019] After receiving this information, the authentication system performs certificate chain verification on the device identity certificate. Certificate chain verification begins with the endpoint certificate and continues up through the root certificate. First, the authentication system checks whether the format of the device identity certificate complies with standard specifications, such as the certificate encoding method and field integrity. Next, it verifies the validity of the certificate signature. This requires decrypting and verifying the signature using the certificate authority's public key. If the signature verification passes, the authentication system further verifies the legitimacy of the certificate authority, confirming its trustworthiness by querying a preconfigured trust list.
[0020] For each certificate authority, a trust score range (for example, from 0 to 100) can be pre-set based on its historical performance and reputation. For example, if PowerCert Authority has a good history, its trust score is set to 90. During the verification process, if the certificate chain passes all verifications and the device identity is valid, the device identity is confirmed to be valid and the certificate authority trust score is 90.
[0021] Step S112: performing protocol compliance analysis on the protocol interaction log to extract the protocol version matching degree, encryption algorithm compliance identifier, and session key update period.
[0022] After verifying the device's identity certificate, you can perform detailed protocol compliance analysis on the protocol interaction log. The protocol interaction log records a series of protocol interactions between the device and the network during communication. By analyzing this information, you can extract key compliance indicators.
[0023] Taking the temperature sensor's protocol interaction log as an example, we first analyze the protocol version match. Power wireless LANs typically specify the standard protocol version to use. For example, let's assume the current network specifies IEEE802.11ax. The authentication system extracts the sensor's actual protocol version from the protocol interaction log. If the sensor also uses IEEE802.11ax, the protocol version match is 100%. If the sensor uses the older IEEE802.11n version, the protocol version match might be 30%, depending on the degree of difference from the standard version.
[0024] Next, the encryption algorithm compliance flag is extracted. For example, to ensure communication security, the network may require the use of a specific encryption algorithm, such as "AES-256." The authentication system checks the encryption algorithm used by the sensor, as recorded in the protocol interaction log. If the specified "AES-256" is used, the encryption algorithm compliance flag is "compliant." If another non-permitted encryption algorithm, such as "DES," is used, the encryption algorithm compliance flag is "non-compliant."
[0025] Finally, the session key update cycle is extracted. To enhance communication security, the network requires devices to regularly update their session keys. Assume the specified update cycle is every 12 hours. The authentication system analyzes the sensor's actual session key update interval from the protocol interaction log. If the sensor updates its session key every 10 hours, its session key update cycle meets the requirement; if it updates only every 24 hours, it does not meet the requirement.
[0026] Step S113: calling a trusted authentication model to perform a trustworthy fusion output on the device identity authentication result, the certificate authority trustworthiness score, the protocol version matching degree, the encryption algorithm compliance identifier, and the session key update period to generate the real-time behavior trustworthiness score.
[0027] After obtaining key information such as device authentication results, certificate authority trust scores, protocol version matching, encryption algorithm compliance identification, and session key update cycle, the pre-trained trusted authentication model can be called for credibility fusion output.
[0028] The trusted authentication model is trained based on extensive historical data and comprehensively assesses the trustworthiness of a terminal device's real-time behavior based on various input information. For example, let's assume the device's authentication result is legitimate, the certificate authority's trustworthiness score is 90, the protocol version match is 100%, the encryption algorithm compliance indicator is "compliant," and the session key update cycle meets requirements.
[0029] The trusted authentication model weights this information, with different weights assigned to different information items. For example, the device authentication result and the certificate authority trust score may be weighted higher, while the protocol version match, cryptographic algorithm compliance indicator, and session key renewal period may be weighted relatively lower. Assume that the device authentication result has a weight of 0.3, the certificate authority trust score has a weight of 0.3, the protocol version match has a weight of 0.1, the cryptographic algorithm compliance indicator has a weight of 0.15, and the session key renewal period has a weight of 0.15.
[0030] If the device identity authentication result is legal, it can be quantified as a fixed score, such as 100 points; the protocol version matching degree can be directly used as its percentage value; the encryption algorithm compliance mark of "compliant" can be quantified as 100 points, and "non-compliant" can be quantified as 0 points; the session key update period that meets the requirements can be quantified as 100 points, and non-compliant can be quantified as 0 points.
[0031] The calculation process of the real-time behavior credibility score is: (100×0.3+90×0.3+100×0.1+100×0.15+100×0.15)=97 points.
[0032] Step S114: Dynamically compare the real-time behavior trust score with a preset trust threshold. If the real-time behavior trust score is greater than or equal to the trust threshold, generate a device identity legal identification and a communication protocol compliance identification, and associate the device identity legal identification, the communication protocol compliance identification and the real-time behavior trust score and store them as the terminal authentication data set.
[0033] In this embodiment, a trust threshold can be preset, for example, 80 points. When the real-time behavior trust score of the temperature sensor is 97 points, the real-time behavior trust score is compared with the trust threshold. Since 97 points is greater than 80 points, it indicates that the trustworthiness of the terminal device is high.
[0034] At this point, you can generate a device identity legality flag and a communication protocol compliance flag. The device identity legality flag indicates that the device's identity has been verified to be legal, and the communication protocol compliance flag indicates that the protocol followed by the device during communication complies with network regulations.
[0035] Finally, the device identity legitimacy identifier, communication protocol compliance identifier, and real-time behavior trust score can be associated and stored as a terminal authentication data set. The storage format can be a database record. For example, in a database table named "TerminalAuthenticationData", a new record is created containing information such as the device unique identifier "TS-00123", the device identity legitimacy identifier "legal", the communication protocol compliance identifier "compliant", and the real-time behavior trust score "97 points" for subsequent data analysis and processing.
[0036] Step S120: obtaining cross-domain original data streams of multiple service domains in the power wireless local area network, performing multimodal feature extraction processing on the cross-domain original data streams, and obtaining device operation status features, network transmission quality features, and service operation semantic features.
[0037] In the power wireless LAN, there are multiple different business domains, such as the power monitoring business domain, the power control business domain, and the power dispatching business domain. These business domains will generate a large amount of cross-domain raw data streams, including equipment operation logs, network transmission messages, business operation instructions, etc.
[0038] For example, a temperature sensor in the power monitoring business domain and a smart switch in the power control business domain record ambient temperature data in real time and generate a device operation log. The smart switch also records its on / off status and operation information. During network transmission, network messages containing this data are generated, and operators issue operational commands to control the temperature sensor sampling frequency or switch the smart switch on and off.
[0039] In this way, these cross-domain raw data streams can be collected and processed for multimodal feature extraction.
[0040] Step S121: Perform time series analysis on the device operation log in the cross-domain original data stream, extract the device power consumption fluctuation sequence, CPU load average and memory usage peak, and normalize and splice the device power consumption fluctuation sequence, the CPU load average and the memory usage peak to generate the device operation status characteristics.
[0041] Taking the device operation log of a temperature sensor as an example, the device operation log is a log file that records various operating parameters of the device in chronological order. This embodiment performs time series analysis on the log file.
[0042] First, extract the device power consumption fluctuation sequence. The power consumption of a temperature sensor varies under different operating conditions. This embodiment extracts power consumption values from the device operation log at regular intervals (e.g., every minute) to form a power consumption value sequence. Assume that over a continuous 10-minute period, the power consumption values of the temperature sensor are 20mW, 22mW, 21mW, 23mW, 22mW, 24mW, 23mW, 25mW, 24mW, and 26mW, respectively. This constitutes a device power consumption fluctuation sequence.
[0043] Next, extract the average CPU load. If the temperature sensor has a certain level of computing power, its CPU will experience varying load conditions. For example, you can record CPU load values every 5 minutes over a period of time (e.g., 1 hour) and then calculate the average of these values. Assuming 12 CPU load values were recorded within 1 hour, namely 10%, 12%, 11%, 13%, 12%, 14%, 13%, 15%, 14%, 16%, 15%, and 17%, the average CPU load is (10+12+11+13+12+14+13+15+14+16+15+17) ÷ 12 = 13.5%.
[0044] Then, extract the peak memory usage. For example, you can monitor the memory usage of a temperature sensor over a period of time (e.g., one day) and record the maximum memory usage. Assume that the memory usage of the temperature sensor varies at different times throughout the day, with the maximum value reaching 30%. Therefore, the peak memory usage is 30%.
[0045] Finally, the device power consumption fluctuation series, CPU load average, and memory usage peak are normalized and spliced. Normalization is to unify data of different ranges to the same scale to facilitate subsequent processing. For the device power consumption fluctuation series, assuming that its original range is between 20mW and 26mW, it is normalized to the range of 0 to 1. Corresponding normalization is also performed for the CPU load average of 13.5% and the memory usage peak of 30%. After normalization, these data are spliced in the set order to form the device operation status feature. For example, the normalized device power consumption fluctuation series is placed in front, followed by the normalized CPU load average, and finally the normalized memory usage peak, thereby generating a device operation status feature containing multiple dimensions of data.
[0046] Step S122: Perform protocol parsing on the network transmission messages in the cross-domain original data stream, extract the transmission delay distribution, bandwidth utilization and packet loss rate trend, perform weighted calculation on the transmission delay distribution, the bandwidth utilization and the packet loss rate trend based on preset network quality assessment rules, and generate the network transmission quality characteristics.
[0047] In this embodiment, the network transmission message is a data unit transmitted in the power wireless local area network, and includes information such as the source address, destination address, data content, and transmission time.
[0048] Taking the network transmission of messages between a temperature sensor and a smart switch as an example, we first extract the transmission delay distribution. For example, we can record the transmission time of each message from the sender (temperature sensor) to the receiver (smart switch). Then, we count the number of messages with different transmission delays over a period of time (e.g., one hour) to form a transmission delay distribution. Assume that within one hour, there are 100 messages with transmission delays between 10ms and 20ms, 200 messages between 20ms and 30ms, 150 messages between 30ms and 40ms, and so on. This constitutes the transmission delay distribution.
[0049] Next, extract the bandwidth utilization. For example, you can calculate the ratio of the actual network bandwidth used to the total network bandwidth over a period of time (e.g., one hour). Assuming the total network bandwidth is 100 Mbps and the average actual bandwidth used over one hour is 30 Mbps, the bandwidth utilization is 30%.
[0050] Then, extract the packet loss rate trend. For example, you can record the packet loss situation at different time periods within a period of time (such as a day), calculate the packet loss rate for each time period, and observe its changing trend. For example, the packet loss rate is 2% from 9:00 to 10:00 in the morning, 3% from 10:00 to 11:00, and 2.5% from 11:00 to 12:00, etc., to form a packet loss rate trend.
[0051] Based on the preset network quality assessment rules, a weighted calculation is performed on transmission delay distribution, bandwidth utilization, and packet loss rate trends. The preset network quality assessment rules assign different weights to each metric, such as 0.4 for transmission delay distribution, 0.3 for bandwidth utilization, and 0.3 for packet loss rate trends.
[0052] For transmission delay distribution, we can quantify and score each delay interval based on its importance. For example, packets with transmission delays between 10ms and 20ms are given higher scores, while packets with delays above 30ms are given lower scores. A weighted average is then calculated. Bandwidth utilization and packet loss rate trends are also quantified and scored based on their impact on network quality. Finally, these quantified scores are weighted and calculated to generate network transmission quality characteristics. For example, if the quantified score for transmission delay distribution is 80, the quantified score for bandwidth utilization is 70, and the quantified score for packet loss rate trend is 75, the calculated network transmission quality characteristics are (80 × 0.4 + 70 × 0.3 + 75 × 0.3) = 76.5.
[0053] Step S123: Perform semantic segmentation processing on the business operation instructions in the cross-domain original data stream to obtain a set of operation instruction text fragments, call the pre-trained semantic analysis model to perform intent recognition processing on the set of operation instruction text fragments, generate a business operation intention vector and a semantic compliance score, and associate the business operation intention vector with the semantic compliance score for encoding processing to generate the business operation semantic feature.
[0054] In this embodiment, the business operation instruction is generally an instruction issued by an operator for controlling a device or executing a set task, and exists in a text form.
[0055] For example, consider the operator's instruction for a temperature sensor: "Adjust the temperature sensor's sampling frequency to once per minute." Semantic segmentation is first performed. Semantic segmentation involves segmenting the entire instruction text into semantic units, generating a set of instruction text segments. For this instruction, the resulting set of segmented instruction text segments might include "adjust," "temperature sensor," "sampling frequency," "adjust to," and "once per minute."
[0056] Next, a pre-trained semantic analysis model is used to perform intent recognition on the set of operation instruction text fragments. This pre-trained semantic analysis model is trained on a large amount of business operation instruction data and can understand the semantics of the text fragments and the operator's intent. This semantic analysis model analyzes each operation instruction text fragment and identifies the operator's intent. For example, the instruction above is intended to adjust the sampling frequency of the temperature sensor.
[0057] The semantic analysis model can convert identified intents into business operation intent vectors. A business operation intent vector is a multidimensional vector, with each dimension representing a different intent characteristic. Assume that a business operation intent vector has five dimensions, representing intent characteristics such as adjusting device parameters, controlling device power, querying device status, starting a task, and stopping a task. For an instruction to adjust the temperature sensor sampling frequency, the value of the "adjust device parameters" dimension is 1, and the values of the other dimensions are 0, forming a business operation intent vector of [1, 0, 0, 0, 0].
[0058] The semantic analysis model also assesses the semantic compliance of operational instructions, generating a semantic compliance score. Semantic compliance refers to whether an operational instruction adheres to the business rules and security requirements of the power wireless LAN. For example, if an operational instruction requires adjusting the sampling frequency of a temperature sensor to a value outside its normal operating range, the instruction has low semantic compliance. Assume that the evaluation results in a semantic compliance score of 90 for this instruction.
[0059] Finally, the business operation intent vector and the semantic compliance score are associated and encoded. This association encoding process combines the business operation intent vector and the semantic compliance score according to predefined rules to generate a business operation semantic feature. For example, the semantic compliance score can be added as an additional dimension to the business operation intent vector, forming a new vector [1, 0, 0, 0, 0, 90], which constitutes the business operation semantic feature.
[0060] Step S130: Based on the terminal authentication data set, the device operation status characteristics are subjected to credibility weighted fusion processing to generate a trusted device operation characteristic set, and the trusted device operation characteristic set is subjected to dynamic correlation analysis processing with the network transmission quality characteristics to generate a cross-domain correlation characteristic set.
[0061] After obtaining the terminal authentication data set and the device operation status characteristics, a credibility weighted fusion process can be performed. The real-time behavior credibility score in the terminal authentication data set reflects the credibility of the terminal device and is used to weight the device operation status characteristics.
[0062] Step S131: extracting a real-time behavior credibility score from the terminal authentication data set, and determining a device operation feature weighting coefficient according to a mapping relationship between the real-time behavior credibility score and a preset scoring interval.
[0063] Taking the temperature sensor as an example, its real-time behavior credibility score can be extracted from the terminal authentication data set, assuming it is 97 points. In this embodiment, a mapping relationship between the scoring interval and the weighting coefficient of the device operation feature is preset. For example, the weighting coefficient range corresponding to the scoring interval of 80-100 points is 0.8-1.0. The scoring interval is divided into 20 small intervals, and each interval corresponds to an increment of the weighting coefficient. 97 points is within the scoring interval of 80-100 points. Through linear mapping calculation, (97-80) ÷ (100-80) × (1.0-0.8) + 0.8 = 0.97, that is, the device operation feature weighting coefficient is 0.97. The device operation feature weighting coefficient will be used for subsequent weighted processing of the device operation status characteristics to reflect the degree of influence of the credibility of the terminal device on its operation status characteristics.
[0064] Step S132: performing sliding window mean calculation processing on the device power consumption fluctuation sequence, CPU load mean and memory usage peak in the device operation status characteristics to obtain the power consumption fluctuation mean, CPU load mean sequence and memory usage mean sequence.
[0065] For example, for the device operating status characteristics of a temperature sensor, the device power consumption fluctuation sequence, the average CPU load, and the peak memory usage are important components. First, consider the device power consumption fluctuation sequence. Assume that the previously extracted device power consumption fluctuation sequence is the power consumption values for 10 consecutive minutes: 20mW, 22mW, 21mW, 23mW, 22mW, 24mW, 23mW, 25mW, 24mW, and 26mW. A sliding window average calculation is used, with a sliding window size of 3 minutes.
[0066] The first window contains the first three data points (20mW, 22mW, and 21mW), with an average of (20+22+21)÷3=21mW. The second window contains the second to fourth data points (22mW, 21mW, and 23mW), with an average of (22+21+23)÷3=22mW. This process continues in this way, ultimately resulting in a sequence of power consumption fluctuation averages.
[0067] For the average CPU load, assume that the CPU load values recorded every five minutes over an hour were 10%, 12%, 11%, 13%, 12%, 14%, 13%, 15%, 14%, 16%, 15%, and 17%, respectively. Using a sliding window of size 3, the average of the first window (10%, 12%, and 11%) is (10 + 12 + 11) ÷ 3 = 11%. The average values for subsequent windows are calculated sequentially to obtain a sequence of CPU load averages.
[0068] For the memory usage peak, assuming that the memory usage peak data monitored at different times of the day are divided according to a set time interval (such as 1 hour), and the sliding window average is used for calculation, a memory usage mean sequence can also be obtained.
[0069] Step S133: Based on the device operation characteristic weighting coefficient, the power consumption fluctuation mean, the CPU load mean sequence and the memory occupancy mean sequence are dynamically weighted and fused to generate weighted device power consumption characteristics, weighted CPU load characteristics and weighted memory occupancy characteristics.
[0070] The weighting coefficient for the device operating characteristics has been determined to be 0.97. For the power consumption fluctuation mean sequence, each mean value in the sequence is multiplied by this weighting coefficient. For example, the first mean value in the power consumption fluctuation mean sequence, 21 mW, is weighted to 21 × 0.97 = 20.37 mW. This process is repeated for the entire power consumption fluctuation mean sequence to obtain the weighted device power consumption characteristics.
[0071] For the CPU load mean sequence, each mean in the sequence is also multiplied by 0.97. For example, if the first CPU load mean is 11%, the weighted value is 11 × 0.97 = 10.67%. After processing the entire sequence, the weighted CPU load feature is obtained.
[0072] For the memory usage mean sequence, the same method is used, multiplying each mean by 0.97 to obtain the weighted memory usage feature. This dynamic weighted fusion process associates the device operating status features with the reliability of the terminal device. The operating status features of highly reliable devices are given higher weight in subsequent processing.
[0073] Step S134: performing timing alignment and splicing processing on the weighted device power consumption characteristics, the weighted CPU load characteristics, and the weighted memory usage characteristics to generate the trusted device operation characteristic set.
[0074] After obtaining the weighted device power consumption, CPU load, and memory usage characteristics, we need to perform time series alignment and splicing. Because these characteristics are calculated based on time series data, we need to ensure that they are consistent in time.
[0075] Assume that the weighted device power consumption, CPU load, and memory usage characteristics each have data at 10 time points. The weighted device power consumption, CPU load, and memory usage characteristics values at the first time point are concatenated sequentially to form a new multidimensional data point. The same concatenation operation is then performed on the data at the second time point, and so on. Finally, these 10 concatenated data points are combined to generate a trusted device operation feature set. This trusted device operation feature set integrates the device's power consumption, CPU load, and memory usage, and takes into account the trustworthiness of the terminal device.
[0076] Step S135: performing timestamp alignment processing on the weighted device power consumption features, weighted CPU load features, and weighted memory usage features in the trusted device operation feature set to obtain a timing synchronization device operation feature sequence.
[0077] After obtaining the trusted device operation feature set, timestamp alignment is required because the weighted device power consumption features, weighted CPU load features, and weighted memory usage features may be collected or calculated at different time scales.
[0078] Taking a temperature sensor as an example, the weighted device power consumption feature may collect data once a minute, the weighted CPU load feature may collect data once every 5 minutes, and the weighted memory usage feature may collect data once every 10 minutes. First, determine a unified time scale, such as a 1-minute time interval. For the weighted CPU load feature, evenly distribute the data every 5 minutes to these 5 1-minute time points; for the weighted memory usage feature, evenly distribute the data every 10 minutes to these 10 1-minute time points. In this way, the weighted device power consumption feature, weighted CPU load feature, and weighted memory usage feature are synchronized in time, forming a time-series synchronized device operation feature sequence. Each time point in this time-series synchronized device operation feature sequence contains comprehensive information on device power consumption, CPU load, and memory usage.
[0079] Step S136: performing sliding window statistical processing on the transmission delay distribution, bandwidth utilization and packet loss rate trends in the network transmission quality characteristics to generate a transmission delay mean sequence, a bandwidth utilization mean sequence and a packet loss rate mean sequence.
[0080] In this embodiment, taking the transmission delay distribution as an example, it is assumed that the previously obtained statistical data on the number of packets in different transmission delay intervals within one hour is divided into minute segments, and the sliding window size is set to 5 minutes.
[0081] For the first 5-minute window, add the number of packets in each transmission delay interval within that 5-minute window and divide by 5 to obtain the average number of packets in each transmission delay interval within that 5-minute window, thus forming the mean transmission delay value for that window. Then, slide the window back 1 minute and perform the same calculation on the new 5-minute data. This continues in this manner, ultimately resulting in a sequence of mean transmission delay values.
[0082] For bandwidth utilization, assume that the previously collected bandwidth utilization data is collected every 5 minutes within an hour. Similarly, using a sliding window of size 3, calculate the average bandwidth utilization within each window to obtain a sequence of bandwidth utilization mean values.
[0083] For packet loss rate trends, assume that we have previously recorded packet loss rate data for each hour of a day. Using sliding window statistics, for example, with a window size of 6 hours, we calculate the average packet loss rate within each window to generate a sequence of mean packet loss rates. This sliding window statistical processing can smooth out fluctuations in the data and more clearly reflect the changing trends in network transmission quality.
[0084] Step S137: Call the pre-trained association analysis model to perform multivariate correlation calculation on the timing synchronization device operation feature sequence, the transmission delay mean sequence, the bandwidth utilization mean sequence and the packet loss rate mean sequence to generate the correlation between device power consumption and transmission delay, the correlation between CPU load and bandwidth utilization, and the correlation between memory occupancy and packet loss rate.
[0085] In this embodiment, the pre-trained association analysis model is trained based on a large amount of historical data and is capable of analyzing the correlation between different variables. For the calculation of the correlation between device power consumption and transmission delay, the relationship between the weighted device power consumption characteristics and the transmission delay mean sequence in the timing synchronization device operation feature sequence can be analyzed. By comparing the changes in device power consumption and transmission delay at different time points, the degree of correlation between them is calculated. For example, if at certain time points, the transmission delay increases as the device power consumption increases, it indicates that there is a positive correlation between the two; conversely, if the transmission delay decreases as the device power consumption increases, there is a negative correlation. The model will calculate a specific correlation value based on this data. Assume that the calculated correlation between device power consumption and transmission delay is 0.7.
[0086] To calculate the correlation between CPU load and bandwidth utilization, we can analyze the correlation between the weighted CPU load characteristics and the mean bandwidth utilization sequence in the timing synchronization device's operational signature sequence. Similarly, we calculate the correlation between the two at different time points, assuming the correlation is 0.6.
[0087] To calculate the correlation between memory usage and packet loss rate, we can analyze the relationship between the weighted memory usage characteristics and the packet loss rate mean sequence in the timing synchronization device operation feature sequence. Assume that the calculated correlation between memory usage and packet loss rate is 0.5.
[0088] Therefore, the above correlation value reflects the relationship between the device operating status and the network transmission quality.
[0089] Step S138: performing multi-dimensional vector processing on the correlation between the device power consumption and transmission delay, the correlation between the CPU load and bandwidth utilization, and the correlation between the memory occupancy and packet loss rate to generate the cross-domain correlation feature set.
[0090] In this embodiment, the correlation between device power consumption and transmission delay, the correlation between CPU load and bandwidth utilization, and the correlation between memory usage and packet loss rate can be combined into a vector in a set order. For example, the correlation between device power consumption and transmission delay of 0.7 is placed in the first dimension, the correlation between CPU load and bandwidth utilization of 0.6 is placed in the second dimension, and the correlation between memory usage and packet loss rate of 0.5 is placed in the third dimension to form a three-dimensional vector [0.7, 0.6, 0.5]. This three-dimensional vector is the cross-domain correlation feature set, which integrates the correlation information between device operating status and network transmission quality and will be used for subsequent multi-domain collaborative analysis.
[0091] Step S140: Call the pre-trained multi-domain collaborative analysis model to perform spatiotemporal context aggregation processing on the cross-domain correlation feature set and the business operation semantic features to generate a multi-domain collaborative optimization strategy set, which includes a resource scheduling priority sequence, abnormal operation interception rules and protocol adaptive adjustment parameters.
[0092] In this embodiment, the pre-trained multi-domain collaborative analysis model can comprehensively consider information from multiple aspects such as device operation, network transmission, and business operations, and mine the spatiotemporal contextual relationships therein to generate optimization strategies.
[0093] Step S141: normalizing the correlation between device power consumption and transmission delay, the correlation between CPU load and bandwidth utilization, and the correlation between memory occupancy and packet loss rate in the cross-domain correlation feature set to obtain a normalized correlation feature vector.
[0094] The correlation between device power consumption and transmission delay, CPU load and bandwidth utilization, and memory usage and packet loss rate in the cross-domain correlation feature set are normalized. The purpose of normalization is to unify data from different ranges to a common scale to facilitate model processing.
[0095] Assume that the correlation between device power consumption and transmission delay ranges from 0 to 1, the correlation between CPU load and bandwidth utilization ranges from 0 to 0.8, and the correlation between memory usage and packet loss rate ranges from 0 to 0.6. Using the minimum-maximum normalization method, for a correlation of 0.7 between device power consumption and transmission delay, the normalized calculation is (0.7 - 0) ÷ (1 - 0) = 0.7; for a correlation of 0.6 between CPU load and bandwidth utilization, the normalized calculation is (0.6 - 0) ÷ (0.8 - 0) = 0.75; and for a correlation of 0.5 between memory usage and packet loss rate, the normalized calculation is (0.5 - 0) ÷ (0.6 - 0) ≈ 0.83. These three normalized values are combined into a vector [0.7, 0.75, 0.83], which forms the normalized correlation feature vector.
[0096] Step S142: performing feature dimensionality reduction processing on the business operation intention vector and the semantic compliance score in the business operation semantic feature to obtain a low-dimensional semantic feature vector.
[0097] In this embodiment, the business operation intention vector may be a high-dimensional vector containing multiple intention features. In order to reduce the dimension of the data and improve the processing efficiency of the model, dimensionality reduction processing is required.
[0098] Assume that the business operation intent vector is [1, 0, 0, 0, 0, 90], where the first five dimensions represent different intent features, and the sixth dimension is the semantic compliance score. Dimensionality reduction is performed using principal component analysis (PCA). First, the covariance matrix of the business operation intent vector is calculated. Then, the eigenvalues and eigenvectors of the covariance matrix are calculated, and the eigenvectors with the largest eigenvalues are selected to form the projection matrix. Assuming that the first two eigenvectors are selected to form the projection matrix, the business operation intent vector is projected into this low-dimensional space, resulting in a two-dimensional low-dimensional semantic feature vector, assumed to be [0.8, 0.2].
[0099] Step S143: performing spatiotemporal position encoding processing on the standardized association feature vector and the low-dimensional semantic feature vector to generate a spatiotemporal context feature matrix.
[0100] In this embodiment, the spatiotemporal position encoding process is to associate and integrate different types of features in the spatiotemporal dimension.
[0101] Suppose the normalized correlation feature vector is [0.7, 0.75, 0.83] and the low-dimensional semantic feature vector is [0.8, 0.2]. First, each feature vector is assigned a timestamp representing its position in the time series. Then, they are encoded based on the timestamp and feature vector dimensionality. For example, the normalized correlation feature vector and the low-dimensional semantic feature vector are arranged in chronological order, and a time code is added to the front of each vector. Assume that the time code represents the time point using a number, with the first time point being 1 and the second time point being 2. The normalized correlation feature vector [0.7, 0.75, 0.83] is encoded as [1, 0.7, 0.75, 0.83], and the low-dimensional semantic feature vector [0.8, 0.2] is encoded as [2, 0.8, 0.2]. These two encoded vectors are combined to form a matrix [[1, 0.7, 0.75, 0.83], [2, 0.8, 0.2]], which is the spatiotemporal context feature matrix.
[0102] Step S144: calling the multi-domain collaborative analysis model to perform multi-head attention aggregation processing on the spatiotemporal context feature matrix to generate resource scheduling priority weights, abnormal operation detection thresholds, and protocol adjustment sensitivity parameters.
[0103] In this embodiment, the multi-head attention mechanism enables the multi-domain collaborative analysis model to focus on different information in different representation subspaces, thereby capturing the relationship between features more comprehensively.
[0104] When processing the spatiotemporal context feature matrix, the multi-domain collaborative analysis model takes each vector in the matrix as input and performs a weighted summation of these vectors through multiple attention heads to obtain different attention representations. For example, if there are three attention heads, each will calculate the spatiotemporal context feature matrix based on its own weight matrix, resulting in three different attention representations. These three attention representations are then concatenated and linearly transformed to obtain the final aggregated representation.
[0105] Based on this aggregated representation, the multi-domain collaborative analysis model generates resource scheduling priority weights, abnormal operation detection thresholds, and protocol adjustment sensitivity parameters. The resource scheduling priority weights are used to determine the priority order of different business domains or devices during resource allocation. For example, the calculated resource scheduling priority weights are [0.6, 0.3, 0.1], indicating that the resource scheduling priorities of business domains A, B, and C decrease in sequence. The abnormal operation detection threshold is used to determine whether a business operation is abnormal. Assuming the generated abnormal operation detection threshold is 0.8, when a characteristic value of a business operation exceeds this threshold, the operation is considered to be an abnormal operation. The protocol adjustment sensitivity parameter is used to guide the adaptive adjustment of the communication protocol. Assuming the generated protocol adjustment sensitivity parameter is 0.5, it indicates that the sensitivity of the protocol adjustment is moderate.
[0106] Step S145: Generate the resource scheduling priority sequence according to the resource scheduling priority weight, generate the abnormal operation interception rule based on the abnormal operation detection threshold, and generate the protocol adaptive adjustment parameter according to the protocol adjustment sensitivity parameter, and associate the resource scheduling priority sequence, abnormal operation interception rule and protocol adaptive adjustment parameter to store as the multi-domain collaborative optimization strategy set.
[0107] Assume that the resource scheduling priority weights are [0.6, 0.3, 0.1], and the corresponding business domains are business domain A, business domain B, and business domain C. Sorting the weights from large to small, the priority order is business domain A > business domain B > business domain C. This is the resource scheduling priority sequence.
[0108] Generate abnormal operation interception rules based on the abnormal operation detection threshold. Assuming the abnormal operation detection threshold is 0.8, the abnormal operation interception rule can be set as follows: when a key feature value of a business operation exceeds 0.8, immediately intercept the operation and record the relevant operation information.
[0109] The protocol adaptation adjustment parameters are generated based on the protocol adjustment sensitivity parameter. Assuming the protocol adjustment sensitivity parameter is 0.5, the protocol adaptation adjustment parameters may include the heartbeat interval adjustment value, the encryption algorithm switch flag, and the session key rotation period. For example, based on the sensitivity parameter, the heartbeat interval adjustment value is calculated to increase by 50%, the encryption algorithm switch flag indicates switching to a more advanced encryption algorithm, and the session key rotation period is shortened to 80% of the original value.
[0110] Finally, the resource scheduling priority sequence, abnormal operation interception rules, and protocol adaptive adjustment parameters are associated and stored as a multi-domain collaborative optimization strategy set. This information can be stored in a database table, with each record containing fields such as the resource scheduling priority sequence, abnormal operation interception rules, and protocol adaptive adjustment parameters, to facilitate subsequent query and use.
[0111] Step S150: Dynamically reconfigure resources of the service domain nodes of the power wireless local area network based on the multi-domain collaborative optimization strategy set, generate a network optimization execution instruction set, and feed back the network optimization execution instruction set to the terminal device to trigger a trusted communication link upgrade operation.
[0112] After obtaining the multi-domain collaborative optimization strategy set, it is necessary to perform dynamic resource reconfiguration on the service domain nodes of the power wireless LAN to achieve network optimization and upgrade of trusted communication links.
[0113] Step S151: extracting the resource scheduling priority sequence from the multi-domain collaborative optimization strategy set, performing priority sorting processing on the computing resource pools of the service domain nodes according to the resource scheduling priority sequence, and generating a resource allocation queue.
[0114] In this embodiment, it is assumed that the resource scheduling priority sequence is business domain A > business domain B > business domain C. The computing resource pool of the business domain node includes computing resources such as CPU computing power and memory space.
[0115] First, calculate the total amount of various resources in the computing resource pool. Assume that the computing resource pool has 1000 CPU units and 500 GB of memory space. Based on the resource scheduling priority sequence, allocate more computing resources to business domain A, less resources to business domain B, and fewer resources to business domain C.
[0116] A proportional allocation approach can be used, with the allocation ratio determined based on priority. Assume that Business Domain A is allocated 60% of resources, Business Domain B is allocated 30%, and Business Domain C is allocated 10%. Business Domain A then receives 600 compute units of CPU power (1000 x 60%) and 300 GB of memory space (500 x 60%). Business Domain B receives 300 compute units of CPU power (1000 x 30%) and 150 GB of memory space (500 x 30%). Business Domain C receives 1000 x 10% and 100 compute units of CPU power (1000 x 10%) and 500 x 10% of memory space (50 GB).
[0117] Arrange each business domain and its allocated resources in order of priority to create a resource allocation queue. The queue is as follows: Business Domain A (CPU power 600 CU, memory 300 GB), Business Domain B (CPU power 300 CU, memory 150 GB), Business Domain C (CPU power 100 CU, memory 50 GB). This resource allocation queue will serve as the basis for subsequent resource allocation operations.
[0118] Step S152: Based on the abnormal operation interception rule, pattern matching processing is performed on the real-time operation instruction flow of the business domain node. If an operation instruction matching the abnormal operation interception rule is detected, an operation interception signal is generated and an alarm log record is triggered.
[0119] During operation, business domain nodes continuously generate real-time operation instruction streams containing various business operation information. According to the abnormal operation interception rules generated earlier, when a key characteristic value of an operation exceeds 0.8, it is determined to be an abnormal operation.
[0120] In this embodiment, real-time monitoring and pattern matching can be performed on the real-time operation instruction stream. For example, an operation instruction may contain some quantitative feature values, such as the operation complexity score and the operation risk assessment value. Taking the operation complexity score as the key feature value, the complexity score of each operation instruction can be extracted in real time and compared with the abnormal operation detection threshold of 0.8.
[0121] Suppose, at a certain moment, a business domain node receives an operation instruction with a calculated complexity score of 0.9. Since 0.9 is greater than 0.8, this indicates that the operation instruction matches the abnormal operation interception rule. At this point, an operation interception signal can be immediately generated, preventing the execution of the abnormal operation. Simultaneously, an alarm log can be triggered, recording detailed information about the abnormal operation, including the content of the operation instruction, the time the operation was initiated, and the complexity score. Alarm logs can be stored in a dedicated log file to facilitate subsequent auditing and analysis.
[0122] Step S153: Dynamically adjust the parameters of the communication protocol stack of the service domain node according to the protocol adaptive adjustment parameters to generate a protocol update instruction set, which includes a heartbeat interval adjustment value, an encryption algorithm switching identifier, and a session key rotation period.
[0123] Based on the protocol adaptive adjustment parameters generated previously, the communication protocol stack of the service domain node is dynamically adjusted. The protocol adaptive adjustment parameters include the heartbeat interval adjustment value, the encryption algorithm switching flag, and the session key rotation period.
[0124] Assume that the heartbeat interval adjustment value is increased by 50%, the encryption algorithm switching flag is switched to a more advanced encryption algorithm, and the session key rotation period is shortened to 80% of the original period.
[0125] For the heartbeat interval, assuming the original heartbeat interval is 10 seconds, after increasing it by 50%, the new heartbeat interval is 10×(1+50%)=15 seconds. For the encryption algorithm, the encryption algorithm currently used in the communication protocol stack can be switched to a more advanced encryption algorithm based on the encryption algorithm switching flag, such as switching from AES-128 to AES-256. For the session key rotation period, assuming the original session key rotation period is 12 hours, after shortening it to 80% of the original period, the new session key rotation period is 12×80%=9.6 hours.
[0126] These adjusted parameters are combined into a protocol update instruction set in the following format: the heartbeat interval is adjusted to 15 seconds, the encryption algorithm is switched to AES-256, and the session key rotation period is adjusted to 9.6 hours. This protocol update instruction set will be used to update the communication protocol stack of the business domain node.
[0127] Step S154: performing instruction encoding processing on the resource allocation queue, the operation interception signal, and the protocol update instruction set to generate the network optimization execution instruction set.
[0128] To facilitate transmission and execution across the network, resource allocation queues, operation interception signals, and protocol update instruction sets need to be encoded. Instruction encoding converts this information into a data format that network devices can recognize and execute.
[0129] For the resource allocation queue, each business domain and its allocated resource information is encoded according to the specified encoding rules. For example, binary encoding is used to convert the business domain's identifier, CPU power, and memory space values into binary strings. For example, suppose business domain A's identifier is encoded as 001, its CPU power of 600 compute units is encoded as 1001011000, and its memory space of 300GB is encoded as 100101100. These codes are combined to form the encoded information for business domain A in the resource allocation queue. The same encoding process is performed for business domains B and C, and then they are concatenated in order of priority.
[0130] The operation intercept signal is encoded as a specified binary identifier, for example, 111 represents the operation intercept signal. For the protocol update instruction set, the heartbeat interval adjustment value, encryption algorithm switch flag, and session key rotation period are encoded according to the encoding rules. For example, a 15-second heartbeat interval is encoded as 00001111, switching the encryption algorithm to AES-256 is encoded as 0101, and a 9.6-hour session key rotation period, converted to 576 minutes, is encoded as 1001000000.
[0131] Finally, the encoded resource allocation queue, operation interception signal, and protocol update instruction set are combined in a set order to generate a network optimization execution instruction set. This network optimization execution instruction set contains all the instruction information for network optimization and will be sent to the terminal device for execution.
[0132] Step S155: performing instruction parsing processing on the resource allocation queue in the network optimization execution instruction set, generating resource scheduling configuration parameters, and sending the resource scheduling configuration parameters to the resource manager of the terminal device to trigger a computing resource reallocation operation.
[0133] In this embodiment, instruction parsing is performed on the resource allocation queue in the network optimization execution instruction set. Instruction parsing is to restore the encoded resource allocation queue into readable resource allocation information.
[0134] According to the aforementioned encoding rules, the encoded information in the resource allocation queue is decoded. For example, the business domain identifier, CPU power, and memory space values are extracted from the binary code. The decoded information is converted into resource scheduling configuration parameters in the following format: Business Domain A is allocated 600 CPU power and 300 GB of memory; Business Domain B is allocated 300 CPU power and 150 GB of memory; Business Domain C is allocated 100 CPU power and 50 GB of memory.
[0135] These resource scheduling configuration parameters are sent to the terminal device's resource manager. The resource manager is the module in the terminal device responsible for managing computing resource allocation. Upon receiving the resource scheduling configuration parameters, the resource manager reallocates computing resources based on these parameters. For example, the resource manager might adjust the CPU time slices allocated to each business domain, allocating more CPU time to business domain A and 300GB of memory space to it, and so on, completing the reallocation of computing resources.
[0136] Step S156: performing signal encoding processing on the operation interception signal to generate an operation interception instruction, and sending the operation interception instruction to the instruction filter of the terminal device to enable a real-time operation interception service.
[0137] In this embodiment, the operation interception signal is encoded so that it can be recognized by the terminal device's instruction filter. The operation interception signal is previously encoded as a binary identifier 111, which is further encapsulated into an operation interception instruction. The operation interception instruction may include information such as the operation interception signal encoding, the instruction source identifier, and the instruction's validity period.
[0138] The operation interception instruction is sent to the terminal device's instruction filter. The instruction filter is a module in the terminal device that filters operation instructions. Upon receiving the operation interception instruction, the real-time operation interception service is activated. When a new operation instruction enters the instruction filter, the filter checks the instruction according to the operation interception rules. If it is determined to be an abnormal operation, the instruction is immediately intercepted and prevented from execution. For example, if an operation instruction with a complexity score exceeding 0.8 is received, the instruction filter will reject the instruction to ensure the operational security of the terminal device.
[0139] Step S157: Perform protocol encapsulation processing on the heartbeat interval adjustment value, the encryption algorithm switching flag and the session key rotation period in the protocol update instruction set, generate a protocol update data packet, and send the protocol update data packet to the protocol stack of the terminal device to trigger a communication protocol upgrade operation.
[0140] In this embodiment, the heartbeat interval adjustment value, encryption algorithm switching flag, and session key rotation period in the protocol update instruction set are packaged in a protocol. Protocol encapsulation is the process of packaging these parameter information in the format of the communication protocol to form a complete protocol update data packet.
[0141] First, determine the protocol's packet format, which typically consists of a header and data section. The header includes the packet type, destination address, and source address, while the data section contains the specific parameters for the protocol update. Add the heartbeat interval adjustment value of 15 seconds, the encryption algorithm switch flag to AES-256, and the session key rotation period of 9.6 hours to the data section according to the protocol's encoding method.
[0142] For example, in the header, the packet type is set to a protocol update packet, the destination address is the terminal device's protocol stack address, and the source address is the network optimization system's address. In the data portion, the heartbeat interval adjustment value is encoded as a specified byte sequence, the encryption algorithm switch flag is encoded as a corresponding code, and the session key rotation period is also encoded accordingly.
[0143] The encapsulated protocol update packet is sent to the terminal device's protocol stack. Upon receiving the packet, the protocol stack parses it and, based on the parsing results, performs communication protocol upgrades. For example, this includes adjusting the heartbeat interval to 15 seconds, switching the encryption algorithm to AES-256, and shortening the session key rotation period to 9.6 hours, thereby improving communication security and stability.
[0144] Step S158: Monitor the network status indicators of the terminal device after executing the computing resource reallocation operation, the real-time operation interception service and the communication protocol upgrade operation. If the network status indicators reach the preset optimization target threshold, a trusted communication link upgrade completion mark is generated.
[0145] In this embodiment, after the terminal device performs the computing resource reallocation operation, the real-time operation interception service, and the communication protocol upgrade operation, it is necessary to monitor network status indicators, including network bandwidth utilization, transmission delay, packet loss rate, etc.
[0146] In this embodiment, data on these network status indicators can be collected in real time. For example, network bandwidth utilization, transmission delay, and packet loss rate data can be collected at regular intervals (e.g., 1 minute) using a network monitoring tool. Preset optimization target thresholds are set based on network optimization requirements, such as increasing network bandwidth utilization to over 80%, reducing transmission delay to under 20 milliseconds, and reducing packet loss rate to under 1%.
[0147] Compare the real-time collected network status indicators with pre-set optimization target thresholds. Assume that after a period of monitoring, network bandwidth utilization reaches 82%, transmission latency is reduced to 18 milliseconds, and packet loss rate is reduced to 0.8%. These indicators all meet the pre-set optimization target thresholds. At this point, a trusted communication link upgrade completion indicator can be generated. This trusted communication link upgrade completion indicator can be a designated signal or flag indicating that the terminal device's communication link has been successfully upgraded, effectively improving network security and performance.
[0148] Furthermore, the method may further comprise the following steps:
[0149] Step S210: Obtain a device identity certificate sample set, a protocol interaction log sample set, and a trusted authentication tag set of historical terminal devices, wherein the trusted authentication tag set includes a device identity legitimacy identifier, a protocol compliance identifier, and a behavior trust score.
[0150] In this embodiment, when training the trusted authentication model, a large amount of historical data must first be obtained as training samples. For example, a sample set of terminal device identity certificates, a sample set of protocol interaction logs, and a set of trusted authentication tags can be collected from the historical records of the power wireless local area network.
[0151] A device identity certificate sample collection contains the device identity certificate information for multiple end devices, such as certificates for different sensors, smart meters, and other devices. Each device identity certificate contains the device's unique identifier, certificate validity period, and certificate authority information. Assume that a sample collection of device identity certificates for 1,000 end devices has been collected, covering devices of different types and from different time periods.
[0152] The protocol interaction log sample collection records the protocol interactions between these terminal devices during communication. For example, the log contains information such as the protocol version, encryption algorithm, and session key update period used when the device communicates with the network. We also collected 1,000 corresponding protocol interaction log samples, each corresponding to the device identity certificate samples.
[0153] The trusted authentication tag set is a collection of tags based on the actual historical data, including device identity legitimacy, protocol compliance, and behavior trustworthiness scores. Device identity legitimacy is categorized as "legal" or "illegal," protocol compliance is categorized as "compliant" or "non-compliant," and the behavior trustworthiness score is a value between 0 and 100. For example, a device identity certificate sample and its corresponding protocol interaction log sample, after manual review or historical system analysis, are labeled with a device identity legitimacy tag of "legal," a protocol compliance tag of "compliant," and a behavior trustworthiness score of 90.
[0154] Step S211: performing certificate chain parsing processing on the device identity certificate sample set to obtain certificate authority credibility sample features and certificate validity period sample features.
[0155] In this embodiment, certificate chain parsing is a process that starts from the terminal device's certificate and verifies step by step to the root certificate, while extracting key sample features.
[0156] For each device identity certificate sample, the certificate format is first checked to ensure compliance with standard specifications and the signature is valid. The certificate signature is then decrypted and verified using the issuing authority's public key. If the signature verification passes, the legitimacy of the issuing authority is further verified. Based on the issuing authority's historical performance and reputation, each certificate authority is assigned a trustworthiness score, which represents the sample trustworthiness characteristic of the certificate authority. For example, the trustworthiness score for "PowerCertAuthority" is 90, and the trustworthiness score for "SafeNetCert" is 85.
[0157] At the same time, certificate validity period information is extracted from the device identity certificate and used as a sample feature for the certificate validity period. A certificate validity period typically includes a start date and an end date. For example, a device identity certificate is valid from January 1, 2024, to January 1, 2025. The certificate validity period can be converted to a numerical value, such as calculating the number of days a certificate is valid. The device identity certificate has a validity period of 365 days. After processing 1,000 device identity certificate samples, 1,000 sets of certificate authority credibility sample features and certificate validity period sample features were obtained.
[0158] Step S212: performing protocol field extraction processing on the protocol interaction log sample set to obtain protocol version matching degree sample features, encryption algorithm identification sample features, and session key update period sample features.
[0159] In this embodiment, the protocol interaction log contains a large amount of protocol-related information, and sample features are obtained by extracting key fields.
[0160] For each protocol interaction log sample, we first extract the protocol version information and compare it with the standard protocol version specified by the network to calculate the protocol version match. For example, if the standard protocol version specified by the network is "IEEE802.11ax," and the device recorded in the protocol interaction log is also using the "IEEE802.11ax" protocol version, the protocol version match is 100%. If it is using the older version "IEEE802.11n," the protocol version match is calculated based on the degree of difference from the standard version, for example, 30%. This yields the protocol version match sample signature.
[0161] Next, extract the encryption algorithm identification information. To ensure communication security, networks often require the use of specific encryption algorithms, such as "AES-256." Check the device's encryption algorithm from the protocol interaction log. If the specified "AES-256" is used, the encryption algorithm identification sample signature will be "AES-256." If another non-allowed encryption algorithm, such as "DES," is used, the encryption algorithm identification sample signature will be "DES."
[0162] Finally, extract the session key update cycle information. The network requires devices to regularly update session keys. Assume the specified session key update cycle is every 12 hours. Analyze the device's actual session key update interval from the protocol interaction log to obtain sample characteristics of the session key update cycle. For example, a device's session key update cycle is every 10 hours. By processing 1,000 protocol interaction log samples, we obtain 1,000 sets of protocol version matching sample characteristics, encryption algorithm identification sample characteristics, and session key update cycle sample characteristics.
[0163] Step S213: Construct an initial trusted authentication model, input the certificate authority credibility sample features, the certificate validity period sample features, the protocol version matching sample features, the encryption algorithm identifier sample features and the session key update cycle sample features into the initial trusted authentication model for multi-feature fusion processing to generate a predicted behavior credibility score.
[0164] In this embodiment, the initial trusted authentication model can adopt a neural network structure, such as a multi-layer perceptron (MLP). The initial trusted authentication model includes an input layer, a hidden layer, and an output layer. The number of neurons in the input layer is determined by the number of input features. Here, there are five features: certificate authority credibility sample feature, certificate validity period sample feature, protocol version matching sample feature, encryption algorithm identifier sample feature, and session key update period sample feature, totaling five features, so the input layer has five neurons.
[0165] The certificate authority credibility sample features, certificate validity period sample features, protocol version matching sample features, encryption algorithm identification sample features and session key update cycle sample features are preprocessed, for example, the certificate authority credibility sample features and protocol version matching sample features are normalized to the range of 0 to 1, and the encryption algorithm identification sample features are encoded and converted into numerical values.
[0166] The preprocessed sample features are input into the initial trusted authentication model. Within the model, neurons in the input layer transmit feature information to the hidden layer, where neurons perform nonlinear transformations and feature fusion on the input information. After processing through multiple hidden layers, the information is passed to the output layer, where neurons output a predicted behavior score. For example, for the first sample, the certificate authority trustworthiness sample feature is 0.9 (normalized), the certificate validity period sample feature is 365 days (after some numerical conversion), the protocol version match sample feature is 1.0 (normalized), the encryption algorithm identifier sample feature is encoded as 2, and the session key renewal period sample feature is 10 hours (after numerical conversion). After these feature values are input into the initial trusted authentication model, they are weighted summed by neurons in the hidden layer and processed using a nonlinear activation function, such as using a sigmoid function to map the input value to a range of 0 to 1. After being propagated through multiple layers, the output layer outputs a predicted behavior trustworthiness score. For example, if the score is 0.85, converting it to a range of 0 to 100 will result in a score of 85. By performing this process on 1,000 sets of sample features in sequence, we can obtain 1,000 predicted behavior credibility scores.
[0167] Step S214: Perform loss calculation based on the predicted behavior credibility score and the behavior credibility score in the trusted authentication tag set to generate a model training loss value, and perform parameter iterative optimization on the initial trusted authentication model based on the model training loss value until the model training loss value converges to obtain the trained trusted authentication model.
[0168] In this embodiment, the mean square error (MSE) may be used as the loss function, that is, the square of the difference between the predicted behavior credibility score and the true behavior credibility score of each sample is calculated, and then the average value is obtained.
[0169] For example, if the predicted behavior confidence score for the first sample is 85, and the corresponding true behavior confidence score in the trusted authentication label set is 90, the difference is 85 - 90 = -5 points, and the square of the difference is (-5) × (-5) = 25. This calculation is performed for all 1,000 samples, and then the squares of the differences are added together and divided by the number of samples, 1,000, to obtain the model training loss. Assume that the calculated model training loss is 10.
[0170] Based on the model training loss, the initial trusted authentication model is iteratively optimized. The gradient descent algorithm is used. The core idea of this algorithm is to calculate the gradient of the loss function with respect to the model parameters and then update the model parameters in the opposite direction of the gradient to reduce the loss value.
[0171] First, the gradient of the loss function with respect to the model parameters (such as weights and biases in a neural network) is calculated. Backpropagation can be used to efficiently calculate gradients. For each parameter, an update is performed based on the magnitude and direction of the gradient. For example, for a weight parameter, assuming its gradient is 0.1 and the learning rate is set to 0.01, the update amount for that weight parameter is -0.01 × 0.1 = -0.001. Subtracting this update amount from the weight parameter completes the parameter update.
[0172] The above process of sample input, loss calculation, gradient calculation, and parameter update is repeated continuously, with each iteration gradually reducing the model training loss. Iterations are stopped when the model training loss decreases to a very small value and no longer changes significantly after multiple iterations, i.e., convergence is reached. Assuming that after 1000 iterations, the model training loss converges to below 1, a trained trustworthy authentication model is obtained. This model can then be used to authenticate the trustworthiness of new terminal devices and generate accurate real-time behavioral trustworthiness scores.
[0173] Furthermore, the method may further comprise the following steps:
[0174] Step S310: Obtain a historical cross-domain correlation feature sample set, a historical business operation semantic sample set, and a multi-domain collaborative optimization strategy label set, wherein the multi-domain collaborative optimization strategy label set includes a resource scheduling priority sequence label, an abnormal operation interception rule label, and a protocol adaptive adjustment parameter label.
[0175] In this embodiment, a large amount of historical data needs to be collected to train the multi-domain collaborative analysis model. A historical cross-domain correlation feature sample set, a historical business operation semantic sample set, and a multi-domain collaborative optimization strategy label set are obtained from the historical records of the power wireless local area network.
[0176] The historical cross-domain correlation feature sample collection contains information on the correlation between device operating status and network transmission quality over multiple time periods. For example, the correlation between device power consumption and transmission delay, the correlation between CPU load and bandwidth utilization, and the correlation between memory usage and packet loss rate. Assume that historical cross-domain correlation feature samples are collected over 500 time periods, and each sample contains the specific values of these three correlations.
[0177] The historical business operation semantic sample collection records historical business operation instructions and their related semantic information, such as the business operation intent vector and semantic compliance score. For example, 500 business operation instruction samples were collected, and each sample was semantically analyzed to obtain the corresponding business operation intent vector and semantic compliance score.
[0178] The multi-domain collaborative optimization strategy tag set is an optimization strategy information annotated based on historical actual conditions. It includes resource scheduling priority sequence tags, abnormal operation interception rule tags, and protocol adaptive adjustment parameter tags. The resource scheduling priority sequence tag clarifies the resource scheduling priority order for different business domains, for example, business domain A > business domain B > business domain C. The abnormal operation interception rule tag specifies the rules for determining abnormal operations, such as determining an operation complexity score exceeding 0.8 as an abnormal operation. The protocol adaptive adjustment parameter tag contains specific protocol adjustment parameters, such as adjusting the heartbeat interval to 15 seconds, switching the encryption algorithm to AES-256, and adjusting the session key rotation period to 9.6 hours.
[0179] Step S311: performing standardization processing on the historical cross-domain correlation feature sample set to obtain a standardized cross-domain correlation feature sample set.
[0180] In this embodiment, the historical cross-domain correlation feature sample set is standardized in order to unify data of different ranges to the same scale to facilitate model processing.
[0181] For each sample in the historical cross-domain correlation feature sample set, including the correlation between device power consumption and transmission delay, CPU load and bandwidth utilization, and memory usage and packet loss rate, a minimum-maximum normalization method is used to first find the minimum and maximum values of each correlation feature across all samples.
[0182] For example, the minimum value of the correlation between device power consumption and transmission delay in 500 samples is 0.2, and the maximum value is 0.8; the minimum value of the correlation between CPU load and bandwidth utilization is 0.1, and the maximum value is 0.7; the minimum value of the correlation between memory usage and packet loss rate is 0.05, and the maximum value is 0.6.
[0183] For the first sample, the correlation between device power consumption and transmission delay is 0.3, and the standardized calculation process is (0.3-0.2)÷(0.8-0.2)=0.1÷0.6≈0.17; the correlation between CPU load and bandwidth utilization is 0.2, and the standardized calculation process is (0.2-0.1)÷(0.7-0.1)=0.1÷0.6≈0.17; the correlation between memory usage and packet loss rate is 0.1, and the standardized calculation process is (0.1-0.05)÷(0.6-0.05)=0.05÷0.55≈0.09.
[0184] By performing such standardization processing on all 500 samples, we can obtain a set of standardized cross-domain correlation feature samples.
[0185] Step S312: performing dimensionality reduction processing on the historical business operation semantic sample set to obtain a low-dimensional business operation semantic sample set.
[0186] In this embodiment, the historical business operation semantic sample set is subjected to dimensionality reduction processing to reduce the dimension of the data and improve the processing efficiency of the model. The principal component analysis (PCA) method is used for dimensionality reduction.
[0187] First, the business operation intention vector and semantic compliance score in the historical business operation semantic sample set are combined into a high-dimensional vector. Assuming that the business operation intention vector has five dimensions and the semantic compliance score is the sixth dimension, each sample is a six-dimensional vector.
[0188] Calculate the covariance matrix of these 500 6-dimensional vectors. The covariance matrix reflects the correlations between the dimensions. Then, find the eigenvalues and eigenvectors of the covariance matrix. The eigenvalues indicate the importance of each eigenvector, and select the eigenvectors with the largest eigenvalues to form the projection matrix.
[0189] Assume that after calculation, the first two eigenvectors are selected to form the projection matrix. Project each 6-dimensional business operation semantic sample vector into this 2-dimensional low-dimensional space to obtain a 2-dimensional low-dimensional business operation semantic sample vector. For example, the 6-dimensional vector of the first sample is [1, 0, 0, 0, 0, 90], and after projection, the 2-dimensional vector [0.8, 0.2] is obtained. Perform this dimensionality reduction process on all 500 samples to obtain a set of low-dimensional business operation semantic samples.
[0190] Step S313: Construct an initial multi-domain collaborative analysis model, input the standardized cross-domain correlation feature sample set and the low-dimensional business operation semantic sample set into the initial multi-domain collaborative analysis model for spatiotemporal context aggregation processing, and generate a predicted resource scheduling priority sequence, predicted abnormal operation interception rules, and predicted protocol adaptive adjustment parameters.
[0191] In this embodiment, the initial multi-domain collaborative analysis model can adopt a deep learning-based architecture, such as the Transformer architecture, which can well process sequence data and perform context aggregation.
[0192] The standardized cross-domain correlation feature sample set and the low-dimensional business operation semantic sample set are input into the initial multi-domain collaborative analysis model. The input samples are first encoded and the standardized cross-domain correlation features and low-dimensional business operation semantic features are converted into vector representations that the model can process.
[0193] Within the model, a multi-head attention mechanism is used to aggregate spatiotemporal context. This allows the model to focus on different information in different representation subspaces, thereby more comprehensively capturing the relationships between features. For example, for the correlation between device power consumption and transmission delay in standardized cross-domain correlation features and the business operation intent in low-dimensional business operation semantic features, the model uses the multi-head attention mechanism to calculate the correlation weights between them and aggregate the relevant information.
[0194] After processing through multiple layers of attention and feedforward neural networks, the model outputs a predicted resource scheduling priority sequence, predicted abnormal operation interception rules, and predicted protocol adaptive adjustment parameters. For example, the predicted resource scheduling priority sequence is business domain B > business domain A > business domain C; the predicted abnormal operation interception rule is that operations with a complexity score exceeding 0.9 are considered abnormal; and the predicted protocol adaptive adjustment parameters include adjusting the heartbeat interval to 20 seconds, switching the encryption algorithm to AES-192, and adjusting the session key rotation period to 10 hours. 500 sets of samples are processed sequentially to obtain 500 sets of prediction results.
[0195] Step S314: Perform weighted loss calculation based on the first difference between the predicted resource scheduling priority sequence and the resource scheduling priority sequence label, the second difference between the predicted abnormal operation interception rule and the abnormal operation interception rule label, and the third difference between the predicted protocol adaptive adjustment parameter and the protocol adaptive adjustment parameter label to generate a total model loss value.
[0196] In this embodiment, a normalization method can be used to process the first difference. For the predicted resource scheduling priority sequence and the resource scheduling priority sequence label, the Kendall's rank correlation coefficient (Kendall's stau) is used to measure the similarity between them. The value of this coefficient ranges from -1 to 1. The closer the value is to 1, the more similar the two are, and the closer the value is to -1, the greater the difference is.
[0197] Assume that the predicted resource scheduling priority sequence is business domain B > business domain A > business domain C, and the resource scheduling priority sequence label is business domain A > business domain B > business domain C. By calculating the Kendall rank correlation coefficient, its value is -0.33 (specific calculation process: first determine all possible business domain pairs, here there are three pairs: business domain A-business domain B, business domain A-business domain C, business domain B-business domain C. Compare the order consistency of each pair of business domains in the predicted sequence and the label sequence, divide the number of inconsistent logarithms by the total number of logarithms to obtain a value, and then calculate -0.33 according to the Kendall rank correlation coefficient formula). In order to convert it into a difference metric, subtract the absolute value of the coefficient from 1, and the first difference metric value is 1-|-0.33|=0.67.
[0198] Secondly, the difference between the predicted abnormal operation interception rule and the abnormal operation interception rule label mainly involves the difference in thresholds. Similarly, normalization is used to convert the threshold difference into a value between 0 and 1.
[0199] Suppose the predicted abnormal operation interception rule defines an operation as abnormal if its complexity score exceeds 0.9, while the abnormal operation interception rule labels an operation as abnormal if its complexity score exceeds 0.8. First, calculate the difference in thresholds: |0.9 - 0.8| = 0.1. Since the thresholds for abnormal operation interception rules typically range from 0 to 1, this difference is used directly as the second difference metric, i.e., 0.1.
[0200] In addition, the protocol adaptive adjustment parameters include the heartbeat interval, encryption algorithm and session key rotation period, and the differences in these parameters need to be handled separately and integrated.
[0201] Heartbeat interval variance: Assume the predicted heartbeat interval is adjusted to 20 seconds, and the protocol adaptively adjusts the parameter tag to 15 seconds. To normalize this, first determine a reasonable heartbeat interval range, assuming a maximum heartbeat interval of 60 seconds and a minimum heartbeat interval of 5 seconds. The normalized variance is calculated as (|20 - 15|) ÷ (60 - 5) = 5 ÷ 55 ≈ 0.09.
[0202] Encryption algorithm variance: For encryption algorithms, quantification is performed based on factors such as the security level and complexity of the encryption algorithm. Assume that the quantization value of AES-128 is 1, the quantization value of AES-192 is 2, and the quantization value of AES-256 is 3. The predicted encryption algorithm is AES-192, and the label is AES-256. The quantization value of the variance is |2-3|=1. To normalize, assume that the maximum difference in the quantization value of the encryption algorithm is 3 (from the lowest security level to the highest security level). The normalized value of the encryption algorithm variance is 1÷3≈0.33.
[0203] Difference in session key rotation period: Assume the predicted session key rotation period is 10 hours and the labeled period is 9.6 hours. Determine a reasonable range for session key rotation periods, assuming a maximum period of 24 hours and a minimum period of 1 hour. The normalized difference is calculated as (|10-9.6|) ÷ (24-1) = 0.4 ÷ 23 ≈ 0.02.
[0204] The weighted sum of these three normalized difference values yields a third difference metric. Assuming the weights of the heartbeat interval, encryption algorithm, and session key rotation period are 0.2, 0.6, and 0.2, respectively, the third difference metric is 0.09 × 0.2 + 0.33 × 0.6 + 0.02 × 0.2 = 0.018 + 0.198 + 0.004 = 0.22.
[0205] Finally, assign a different weight to each difference. Suppose the first difference has a weight of 0.3, the second difference has a weight of 0.3, and the third difference has a weight of 0.4. Multiply the first, second, and third differences by their corresponding weights and add them together to get the total model loss. That is, 0.67 × 0.3 + 0.1 × 0.3 + 0.22 × 0.4 = 0.201 + 0.03 + 0.088 = 0.319.
[0206] Step S315: performing back propagation optimization processing on the initial multi-domain collaborative analysis model based on the total loss value of the model until the total loss value of the model reaches a preset convergence condition, thereby obtaining the trained multi-domain collaborative analysis model.
[0207] In this embodiment, the back propagation algorithm is an important method for calculating gradients and updating model parameters in deep learning.
[0208] First, the gradient of the loss function with respect to the model parameters (such as weights and biases in the Transformer architecture) is calculated based on the total model loss. Using the chain rule, starting from the output layer, the gradient is calculated layer by layer and the gradient information is back-propagated to the parameters of each layer.
[0209] Then, an optimization algorithm (such as the Adam optimization algorithm) is used to update the model parameters based on the calculated gradients. The Adam optimization algorithm combines the concepts of momentum and adaptive learning rates to more efficiently update parameters. For example, a weight parameter is updated based on its gradient and the Adam optimization algorithm's update rule, adjusting the weight parameter toward a lower loss.
[0210] The process of sample input, loss calculation, gradient calculation, and parameter update is repeated continuously, with each iteration gradually reducing the total model loss. The preset convergence condition can be that the total model loss is less than a set threshold, such as 0.1, or that the change in the total model loss over multiple consecutive iterations is less than an extremely small value. Assuming that after 2000 iterations, the total model loss converges to 0.08, meeting the preset convergence condition, the trained multi-domain collaborative analysis model is obtained. This can then be used to process new cross-domain correlation features and business operation semantic features to generate accurate multi-domain collaborative optimization strategies.
[0211] Figure 2 The following diagram illustrates exemplary hardware and software components of a trusted authentication-based multi-domain data processing system 100 for a power wireless local area network, which can implement the concepts of the present invention, according to some embodiments of the present invention. For example, the processor 120 can be used in the trusted authentication-based multi-domain data processing system 100 for a power wireless local area network, and can be used to perform the functions of the present invention.
[0212] The trusted authentication-based multi-domain data processing system 100 for a power wireless LAN can be a general-purpose server or a special-purpose server, both of which can be used to implement the trusted authentication-based multi-domain data processing method for a power wireless LAN of the present invention. Although only one server is shown in the present invention, for convenience, the functions described in the present invention can be implemented in a distributed manner on multiple similar platforms to balance the processing load.
[0213] For example, the power wireless local area network multi-domain data processing system 100 based on trusted authentication may include a network port 110 connected to the network, one or more processors 120 for executing program instructions, a communication bus 130, and different forms of storage media 140, such as a disk, ROM, or RAM, or any combination thereof. Exemplarily, the power wireless local area network multi-domain data processing system 100 based on trusted authentication may also include program instructions stored in ROM, RAM, or other types of non-transitory storage media, or any combination thereof. The method of the present invention can be implemented according to these program instructions. The power wireless local area network multi-domain data processing system 100 based on trusted authentication also includes an input / output (I / O) interface 150 between the computer and other input and output devices.
[0214] For ease of explanation, only one processor is described in the multi-domain data processing system 100 for a power wireless LAN based on trusted authentication. However, it should be noted that the multi-domain data processing system 100 for a power wireless LAN based on trusted authentication in the present invention may also include multiple processors, so the steps performed by one processor described in the present invention may also be performed jointly or individually by multiple processors. For example, if the processor of the multi-domain data processing system 100 for a power wireless LAN based on trusted authentication executes steps A and B, it should be understood that steps A and B may also be executed jointly by two different processors or individually in one processor. For example, the first processor executes step A, the second processor executes step B, or the first processor and the second processor execute steps A and B together.
[0215] In addition, an embodiment of the present invention further provides a readable storage medium, in which computer-executable instructions are preset. When a processor executes the computer-executable instructions, the above-mentioned power wireless local area network multi-domain data processing method based on trusted authentication is implemented.
[0216] It should be noted that in order to simplify the description of the present invention and thus help understand one or more embodiments of the invention, in the foregoing description of the embodiments of the present invention, multiple features are sometimes combined into one embodiment, figure or description thereof.
Claims
1. A multi-domain data processing method for a power wireless local area network based on trusted authentication, characterized in that: The method comprises: Calling the trusted authentication model to perform credibility authentication processing on the terminal devices in the power wireless local area network to generate a terminal authentication data set, which includes device identity characteristics, communication protocol compliance characteristics and real-time behavior credibility scores; Obtain cross-domain raw data streams of multiple service domains in the power wireless local area network, perform multimodal feature extraction processing on the cross-domain raw data streams, and obtain device operation status features, network transmission quality features, and service operation semantic features; Performing credibility weighted fusion processing on the device operation status features based on the terminal authentication data set to generate a trusted device operation feature set, and dynamically correlating and analyzing the trusted device operation feature set with the network transmission quality features to generate a cross-domain correlation feature set; Calling a pre-trained multi-domain collaborative analysis model to perform spatiotemporal context aggregation processing on the cross-domain correlation feature set and the business operation semantic feature to generate a multi-domain collaborative optimization strategy set, wherein the multi-domain collaborative optimization strategy set includes a resource scheduling priority sequence, abnormal operation interception rules, and protocol adaptive adjustment parameters; Based on the multi-domain collaborative optimization strategy set, dynamic resource reconfiguration processing is performed on the service domain nodes of the power wireless local area network, a network optimization execution instruction set is generated, and the network optimization execution instruction set is fed back to the terminal device to trigger a trusted communication link upgrade operation.
2. The method for processing multi-domain data in a power wireless local area network based on trusted authentication according to claim 1, characterized in that: The calling of the trusted authentication model to perform credibility authentication processing on the terminal equipment in the power wireless local area network to generate a terminal authentication data set includes: Obtain the device identity certificate and protocol interaction log submitted by the terminal device when accessing the power wireless LAN, perform certificate chain verification on the device identity certificate, and obtain the device authentication result and the certificate authority trust score; Perform protocol compliance analysis on the protocol interaction log to extract the protocol version matching degree, encryption algorithm compliance identification and session key update period; Invoking a trusted authentication model to perform a trustworthy fusion output on the device identity authentication result, the certificate authority trustworthiness score, the protocol version matching degree, the encryption algorithm compliance identifier, and the session key update period to generate the real-time behavior trustworthiness score; A dynamic comparison is performed based on the real-time behavior trust score and a preset trust threshold. If the real-time behavior trust score is greater than or equal to the trust threshold, a device identity legality identifier and a communication protocol compliance identifier are generated, and the device identity legality identifier, the communication protocol compliance identifier and the real-time behavior trust score are associated and stored as the terminal authentication data set.
3. The method for multi-domain data processing in a power wireless local area network based on trusted authentication according to claim 1, characterized in that: The multimodal feature extraction processing is performed on the cross-domain original data stream to obtain device operation status features, network transmission quality features and service operation semantic features, including: Performing time series analysis on the device operation logs in the cross-domain raw data stream to extract the device power consumption fluctuation sequence, CPU load average, and memory usage peak, and normalizing and splicing the device power consumption fluctuation sequence, the CPU load average, and the memory usage peak to generate the device operation status feature; Performing protocol parsing on the network transmission messages in the cross-domain original data stream, extracting transmission delay distribution, bandwidth utilization and packet loss rate trend, performing weighted calculation on the transmission delay distribution, the bandwidth utilization and the packet loss rate trend based on preset network quality assessment rules, and generating the network transmission quality features; The business operation instructions in the cross-domain original data stream are semantically segmented to obtain a set of operation instruction text fragments, and a pre-trained semantic analysis model is called to perform intent recognition processing on the set of operation instruction text fragments to generate a business operation intention vector and a semantic compliance score, and the business operation intention vector and the semantic compliance score are associated and encoded to generate the business operation semantic feature.
4. The method for multi-domain data processing in a power wireless local area network based on trusted authentication according to claim 1, characterized in that: The performing credibility weighted fusion processing on the device operation status features based on the terminal authentication data set to generate a trusted device operation feature set includes: Extracting a real-time behavior trust score from the terminal authentication data set, and determining a device operation feature weighting coefficient based on a mapping relationship between the real-time behavior trust score and a preset score interval; Perform sliding window average calculation on the device power consumption fluctuation sequence, the CPU load mean, and the memory usage peak in the device operation status characteristics to obtain the power consumption fluctuation mean, the CPU load mean sequence, and the memory usage mean sequence; Dynamically weighting and fusing the power consumption fluctuation mean, the CPU load mean sequence, and the memory occupancy mean sequence based on the device operation feature weighting coefficient to generate a weighted device power consumption feature, a weighted CPU load feature, and a weighted memory occupancy feature; The weighted device power consumption characteristics, the weighted CPU load characteristics, and the weighted memory occupancy characteristics are time-series aligned and spliced to generate the trusted device operation characteristic set.
5. The method for multi-domain data processing in a power wireless local area network based on trusted authentication according to claim 1, characterized in that: The dynamically correlating and analyzing the trusted device operation feature set with the network transmission quality feature to generate a cross-domain correlation feature set includes: Performing timestamp alignment processing on the weighted device power consumption characteristics, weighted CPU load characteristics, and weighted memory usage characteristics in the trusted device operation feature set to obtain a timing synchronization device operation feature sequence; Performing sliding window statistical processing on the transmission delay distribution, bandwidth utilization, and packet loss rate trends in the network transmission quality characteristics to generate a transmission delay mean sequence, a bandwidth utilization mean sequence, and a packet loss rate mean sequence; Calling a pre-trained correlation analysis model to perform multivariate correlation calculation on the timing synchronization device operation feature sequence, the transmission delay mean sequence, the bandwidth utilization mean sequence, and the packet loss rate mean sequence to generate a correlation between device power consumption and transmission delay, a correlation between CPU load and bandwidth utilization, and a correlation between memory usage and packet loss rate; The correlation between the device power consumption and transmission delay, the correlation between the CPU load and bandwidth utilization, and the correlation between the memory occupancy and packet loss rate are subjected to multi-dimensional vector processing to generate the cross-domain correlation feature set.
6. The method for multi-domain data processing in a power wireless local area network based on trusted authentication according to claim 1, characterized in that: The calling of the pre-trained multi-domain collaborative analysis model to perform spatiotemporal context aggregation processing on the cross-domain correlation feature set and the business operation semantic feature to generate a multi-domain collaborative optimization strategy set includes: Normalizing the correlation between device power consumption and transmission delay, the correlation between CPU load and bandwidth utilization, and the correlation between memory usage and packet loss rate in the cross-domain correlation feature set to obtain a standardized correlation feature vector; Performing feature dimensionality reduction processing on the business operation intention vector and the semantic compliance score in the business operation semantic feature to obtain a low-dimensional semantic feature vector; Performing spatiotemporal position encoding processing on the standardized association feature vector and the low-dimensional semantic feature vector to generate a spatiotemporal context feature matrix; Calling a multi-domain collaborative analysis model to perform multi-head attention aggregation processing on the spatiotemporal context feature matrix to generate resource scheduling priority weights, abnormal operation detection thresholds, and protocol adjustment sensitivity parameters; The resource scheduling priority sequence is generated according to the resource scheduling priority weight, the abnormal operation interception rule is generated based on the abnormal operation detection threshold, and the protocol adaptive adjustment parameter is generated according to the protocol adjustment sensitivity parameter. The resource scheduling priority sequence, abnormal operation interception rule and protocol adaptive adjustment parameter are associated and stored as the multi-domain collaborative optimization strategy set.
7. The method for multi-domain data processing in a power wireless local area network based on trusted authentication according to claim 1, characterized in that: The method of dynamically reconfiguring resources on the service domain nodes of the power wireless local area network based on the multi-domain collaborative optimization strategy set, generating a network optimization execution instruction set, and feeding back the network optimization execution instruction set to the terminal device to trigger a trusted communication link upgrade operation includes: Extracting the resource scheduling priority sequence from the multi-domain collaborative optimization strategy set, performing priority sorting on the computing resource pools of the business domain nodes according to the resource scheduling priority sequence, and generating a resource allocation queue; Performing pattern matching processing on the real-time operation instruction stream of the business domain node based on the abnormal operation interception rule, and generating an operation interception signal and triggering an alarm log record if an operation instruction matching the abnormal operation interception rule is detected; Dynamically adjust the parameters of the communication protocol stack of the service domain node according to the protocol adaptive adjustment parameters to generate a protocol update instruction set, wherein the protocol update instruction set includes a heartbeat interval adjustment value, an encryption algorithm switching identifier, and a session key rotation period; Performing instruction encoding processing on the resource allocation queue, the operation interception signal, and the protocol update instruction set to generate the network optimization execution instruction set; Performing instruction parsing processing on the resource allocation queue in the network optimization execution instruction set to generate resource scheduling configuration parameters, and sending the resource scheduling configuration parameters to the resource manager of the terminal device to trigger a computing resource reallocation operation; performing signal encoding processing on the operation interception signal to generate an operation interception instruction, and sending the operation interception instruction to an instruction filter of the terminal device to enable a real-time operation interception service; Performing protocol encapsulation processing on the heartbeat interval adjustment value, the encryption algorithm switching flag, and the session key rotation period in the protocol update instruction set to generate a protocol update data packet, and sending the protocol update data packet to the protocol stack of the terminal device to trigger a communication protocol upgrade operation; Monitor the network status indicators of the terminal device after executing the computing resource reallocation operation, the real-time operation interception service and the communication protocol upgrade operation. If the network status indicators reach a preset optimization target threshold, generate a trusted communication link upgrade completion mark.
8. The method for multi-domain data processing in a power wireless local area network based on trusted authentication according to any one of claims 1 to 7, characterized in that: The training method of the trusted authentication model includes: Obtain a sample set of device identity certificates, a sample set of protocol interaction logs, and a set of trusted authentication labels for historical terminal devices, wherein the trusted authentication label set includes a device identity legitimacy identifier, a protocol compliance identifier, and a behavior trust score; Performing certificate chain parsing on the device identity certificate sample set to obtain certificate authority credibility sample features and certificate validity period sample features; Performing protocol field extraction processing on the protocol interaction log sample set to obtain protocol version matching sample features, encryption algorithm identification sample features, and session key update period sample features; Constructing an initial trusted authentication model, inputting the certificate authority credibility sample feature, the certificate validity period sample feature, the protocol version matching sample feature, the encryption algorithm identifier sample feature, and the session key update period sample feature into the initial trusted authentication model for multi-feature fusion processing to generate a predicted behavior credibility score; Loss calculation is performed based on the predicted behavior credibility score and the behavior credibility score in the trusted authentication tag set to generate a model training loss value. Parameters of the initial trusted authentication model are iteratively optimized based on the model training loss value until the model training loss value converges, thereby obtaining the trained trusted authentication model.
9. The method for processing multi-domain data in a power wireless local area network based on trusted authentication according to any one of claims 1 to 7, characterized in that: The training method of the multi-domain collaborative analysis model includes: Acquire a historical cross-domain correlation feature sample set, a historical business operation semantic sample set, and a multi-domain collaborative optimization strategy label set, wherein the multi-domain collaborative optimization strategy label set includes a resource scheduling priority sequence label, an abnormal operation interception rule label, and a protocol adaptive adjustment parameter label; Standardizing the historical cross-domain correlation feature sample set to obtain a standardized cross-domain correlation feature sample set; Performing dimensionality reduction processing on the historical business operation semantic sample set to obtain a low-dimensional business operation semantic sample set; Constructing an initial multi-domain collaborative analysis model, inputting the standardized cross-domain correlation feature sample set and the low-dimensional business operation semantic sample set into the initial multi-domain collaborative analysis model for spatiotemporal context aggregation processing, and generating a predicted resource scheduling priority sequence, predicted abnormal operation interception rules, and predicted protocol adaptive adjustment parameters; Performing weighted loss calculation processing based on a first difference between the predicted resource scheduling priority sequence and the resource scheduling priority sequence label, a second difference between the predicted abnormal operation interception rule and the abnormal operation interception rule label, and a third difference between the predicted protocol adaptive adjustment parameter and the protocol adaptive adjustment parameter label to generate a total model loss value; The initial multi-domain collaborative analysis model is subjected to back propagation optimization processing based on the total loss value of the model until the total loss value of the model reaches a preset convergence condition, thereby obtaining the trained multi-domain collaborative analysis model.
10. A multi-domain data processing system for power wireless local area network based on trusted authentication, characterized in that: It includes a processor and a memory, the memory is connected to the processor, the memory is used to store programs, instructions or codes, and the processor is used to execute the programs, instructions or codes in the memory to implement the multi-domain data processing method of the power wireless local area network based on trusted authentication as described in any one of claims 1 to 9.
Citation Information
Patent Citations
Cross-domain network security policy automatic generation and protection policy collaboration method and system
CN119449428A
Multi-factor security authentication method and device based on AI adaptive identification and block chain
CN119603075A
Remote office network security protection method and system based on big data
CN119728311A
Industrial Internet of Things security authentication method and system based on zero-knowledge proof
CN119743270A
Network security verification method and system for security system
CN119996092A
Cited By
Internet of Things data transmission method
CN120880785A
Automatic logistics conveying line scheduling optimization method and device and related medium
CN120952283A
An automated logistics conveying line scheduling optimization method and device and related medium
CN120952283B
Authentication method based on super SIM (Subscriber Identity Module), combined enhancement authentication method and device
CN121692165A