Internet of things card abnormal flow identification and multistage response control system
Through the hybrid intelligent model of quantum-inspired CNN and gradient mask adversarial training and the quantum key two-way authentication mechanism, the problem of encrypted traffic being difficult to identify and resist attacks in IoT card traffic control is solved, and highly secure and robust traffic control is achieved.
Patent Information
- Application Number
- CN202511300770.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-12
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2045-09-12
AI Technical Summary
The existing traffic control of IoT cards has problems such as difficulty in accurately identifying anomalies without decrypting encrypted traffic, susceptibility to adversarial attacks, and insufficient security and robustness.
A hybrid intelligent model of quantum-inspired CNN and gradient mask adversarial training is used to detect encrypted traffic anomalies. A two-way authentication mechanism is built in combination with quantum keys. Through high-frequency authentication of high-risk equipment and full lifecycle management of keys, accurate anomaly identification and quantum-level security protection are achieved.
It significantly improves the security, robustness and reliability of IoT card traffic control, and achieves highly robust detection of encrypted traffic and resistance to quantum computing attacks.
Smart Images

Figure CN120812593A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of Internet of Things, in particular to an abnormal traffic identification and multi-level response control system for Internet of Things card. BACKGROUND
[0002] The Internet of Things card (Internet of Things Card, IoT Card for short) is an embedded SIM card specially designed for Internet of Things devices (non-traditional personal communication devices) to provide network access and data transmission services. The core function is to realize low-power, high-reliability, and wide-coverage data interaction between Internet of Things devices and cloud platforms, and between devices through mobile communication networks (such as 2G / 3G / 4G / 5G / NB-IoT / eMTC), supporting the intelligent operation of Internet of Things applications. It is widely used in industrial sensors, smart meters, vehicle terminals, shared devices, etc. It undertakes key communication tasks such as device remote data reporting and command receiving, and is the core infrastructure of "device networking" in the Internet of Things system. With the explosive growth of the scale of Internet of Things devices and the diversification of application scenarios, the demand for traffic control of Internet of Things cards is becoming increasingly urgent. On the one hand, the data transmitted by Internet of Things cards often involves sensitive content such as industrial control instructions and user privacy information. In order to protect data security, encrypted communication methods are used in most scenarios. On the other hand, the massive access of devices also significantly increases the risk of malicious attacks (such as traffic hijacking, fake device access, and adversarial sample injection), which puts higher requirements on the security, accuracy, and attack resistance of traffic control. In the prior art, the traditional traffic control of Internet of Things cards has the problems of low security, poor robustness, and insufficient reliability, because encrypted traffic cannot be decrypted for accurate identification of abnormalities, conventional detection models are vulnerable to adversarial attacks, and identity authentication and key management are vulnerable to quantum computing attacks.
[0003] Therefore, the present application provides an abnormal traffic identification and multi-level response control system for Internet of Things card to solve the above technical problems. SUMMARY
[0004] The application aims to provide an Internet of Things card abnormal traffic identification and multi-level response control system, which converts the preprocessed traffic features into low-dimensional core fingerprints, realizes high robustness detection of encrypted traffic anomalies by combining a quantum heuristic CNN and a gradient mask adversarial training hybrid intelligent model, quantizes the abnormal degree by risk scoring and dynamically updates the baseline to ensure detection accuracy, effectively solves the pain points of "difficulty in identifying without decryption and vulnerability to adversarial attacks" in traditional encrypted traffic detection, constructs a two-way authentication mechanism based on quantum keys, resists quantum computing attacks by combining post-quantum cryptographic algorithms, strengthens dynamic monitoring through high-risk device high-frequency authentication, and ensures the timeliness and irrecoverability of the key by key life cycle management, together providing "abnormal accurate identification" and "quantum-level security protection" for the system, significantly improving the security, robustness and reliability of Internet of Things card traffic control.
[0005] To achieve the above-mentioned purpose, the application provides the following technical scheme: The application provides an Internet of Things card abnormal traffic identification and multi-level response control system, comprising a quantum key distribution and generation module, a data acquisition and preprocessing module, an abnormal traffic identification module, a multi-level response execution module and a quantum security management module. The quantum key distribution and generation module: based on quantum random number generation and quantum state transmission, combined with a classical post-processing protocol to complete secure key distribution; The data acquisition and preprocessing module: used for acquiring traffic call records and data packet features of the Internet of Things card, and performing normalization, denoising and feature vectorization processing; The abnormal traffic identification module: used for high robustness anomaly detection and risk scoring of the behavior fingerprint of encrypted traffic by a hybrid intelligent model of quantum feature distillation and adversarial enhancement without decrypting the communication content; The multi-level response execution module: used for automatically executing the grading response actions of log auditing, bandwidth throttling or communication blocking according to the abnormal score level; The quantum security management module: based on quantum keys for two-way identity authentication of the Internet of Things card and the access device, supporting continuous authentication against quantum computing attacks and key life cycle management.
[0006] The quantum key distribution and generation module comprises a quantum random number generation unit, a quantum state transmission and receiving unit, a classical post-processing unit and a channel monitoring unit. The quantum random number generation unit: based on the superposition characteristics of single-photon quantum states to generate high-entropy random numbers; The quantum state transmission and receiving unit: used for sending or receiving single-photon polarization states of encoded key information through a quantum channel; The classical post-processing unit is used for performing basis vector matching, LDPC error correction and SHA-3 privacy amplification, and converting original quantum data into a final key meeting security standards. The channel monitoring unit is used for monitoring photon attenuation and noise intensity in quantum state transmission in real time, and triggering key distribution suspension and alarm when an anomaly occurs.
[0007] The data acquisition and preprocessing module includes a multi-dimensional acquisition unit, a data cleaning unit, a feature standardization unit, and a feature storage unit. The multi-dimensional acquisition unit is used to capture the traffic characteristics and call information of the IP address, protocol type, data packet length, and frame interval of the Internet of Things card. The data cleaning unit is used to remove noise data such as empty packets and duplicate packets, and process them according to service priority. The feature standardization unit is used to discretize features through one-hot encoding and normalize continuous features through Z-Score, and output vectors of uniform dimensions. The feature storage unit is used to encrypt and store the preprocessed feature vectors.
[0008] The abnormal traffic identification module includes a quantum feature distillation unit, a hybrid intelligent detection unit, a risk scoring unit, and a baseline updating unit. The quantum feature distillation unit is used to map traffic features to quantum states, extract correlation information through entanglement gates, and collapse to core features while compressing dimensions and retaining key fingerprints. The hybrid intelligent detection unit is used to combine quantum-inspired CNN and gradient mask adversarial training to identify abnormal patterns of encrypted traffic behavior with high robustness. The risk scoring unit calculates a risk value of 0-100 based on abnormal matching degree, baseline deviation degree, and historical correlation degree to quantify the severity of the anomaly. The baseline updating unit is used to dynamically update the normal behavior baseline using recent traffic data from legitimate devices, and automatically iterates every 24 hours.
[0009] In the quantum feature distillation unit, traffic features are mapped to quantum states, correlation information is extracted through entanglement gates, and core features are collapsed while compressing dimensions and retaining key fingerprints. The specific operations are as follows: A1: Normalize the preprocessed traffic feature vector to obtain an input vector of dimension d ; A2: Use angle encoding to map each feature component to the rotation angle of a quantum bit, and construct an initial quantum state: , where, is a single-bit rotation gate around the y-axis with a rotation angle of ; is the initial state of d qubits; A3: Extracting the nonlinear correlation between features by a multi-layer parametric quantum circuit, including single-bit rotation gates and adjacent bit entanglement gates; A4: Measuring the output state of the quantum circuit to obtain the expected value as a low-dimensional quantum embedded feature; A5: Outputting the measurement result as the core behavior fingerprint.
[0010] The hybrid intelligent detection unit combines quantum heuristic CNN and gradient mask adversarial training to perform high-robustness abnormal pattern recognition on encrypted traffic behavior, and the specific operation is as follows: B1: Quantum heuristic CNN model construction and feature extraction: The quantum heuristic CNN includes a three-level structure of "quantum heuristic convolution layer → classical convolution layer → fully connected layer": ① Input the M-dimensional core feature vector output by the quantum feature distillation unit into the quantum heuristic convolution layer, and extract the spatial correlation of the features through the quantum entanglement filter kernel. The filter kernel is composed of K quantum bits, and the feature transformation formula is: , wherein, is the input core feature matrix, is the quantum filter kernel parameter, and the initial value is provided by the quantum random number generation unit, is the entanglement coefficient, taking a value of 0.8-1.0, and the strong correlation feature position takes 1.0, is the output feature of the quantum heuristic convolution layer; ② Input into 2 layers of classical convolution layers and 1 layer of maximum pooling layers to complete feature dimension reduction and local pattern extraction; ③ Output the feature vector through the fully connected layer as the basic feature for abnormal pattern recognition; B2: Gradient mask adversarial training execution: Based on the CNN structure in B1, the model's ability to resist adversarial attacks is improved through the gradient mask mechanism, which specifically includes: ① Generating adversarial samples: A small perturbation is added to the input normal traffic feature vector using the fast gradient sign method, and the perturbation amplitude is controlled to be 3%-5% of the standard deviation of the feature vector , and the perturbation formula is: , wherein, is the normal traffic feature, is the model cross-entropy loss function, a gradient of the loss function with respect to an input feature, a generated adversarial sample; ② Gradient mask optimization: during the model back propagation process, a mask matrix M is added to the gradient matrix, and the gradient formula after masking is: wherein, is a Hadamard product, which avoids the model from over-relying on the feature dimension vulnerable to attack; ③ Hybrid sample training: normal samples and adversarial samples are mixed in a ratio of 4:1 to input the model, and the model is iteratively trained for 50-80 rounds. The final model has an identification accuracy of ≥98.2% for encrypted traffic abnormal patterns and ≥97.5% for adversarial samples, and a false detection rate of ≤1.5%.
[0011] The multi-level response execution module includes a level determination unit, a response action execution unit, a response escalation unit, and a backtracking and recovery unit, wherein: The level determination unit is configured to divide the low, medium, and high levels according to the risk score; The response action execution unit is configured to trigger the graded operations of log auditing, bandwidth throttling, and communication blocking; The response escalation unit is configured to automatically upgrade the response level when the low or medium risk response does not eliminate the abnormality within 1 hour; The backtracking and recovery unit is configured to remove the restriction and restore the normal bandwidth if the device passes the re-authentication after the high-risk blocking.
[0012] The quantum security management module includes a bidirectional authentication unit, an anti-quantum attack unit, a continuous authentication unit, and a key lifecycle unit, wherein: The bidirectional authentication unit performs identity verification between the device and the Internet of Things card based on quantum keys; The anti-quantum attack unit is configured to use post-quantum cryptographic algorithms to reinforce the authentication process and resist the risk of key cracking by quantum computing; The continuous authentication unit is configured to trigger high-frequency authentication every 5 minutes for high-risk devices to strengthen dynamic security monitoring; The key lifecycle unit is configured to manage key generation, activation, 7-day period update, and key destruction for logging out of the device.
[0013] The bidirectional authentication unit performs identity verification between the device and the Internet of Things card based on quantum keys, and the specific operation is as follows: C1: The network side sends an authentication challenge message to the Internet of Things card; C2: The Internet of Things card generates a message authentication code using the pre-shared quantum key for the challenge message and transmits it back to the network side; C3: The network side verifies the correctness of the message authentication code, and if it passes, initiates a reverse authentication and sends a new challenge to the device; C4: The device uses the same or paired quantum key generation response message authentication code and returns; C5: After the network test completes verification, a bidirectional trusted connection is established.
[0014] The key life cycle unit manages key generation, activation, 7-day period update, and key destruction of the device, and the specific operation is as follows: D1: When the device is first accessed, the quantum key distribution process is triggered, the initial key is generated, and is marked as an "activated" state; D2: Start the period timer, when the key usage time reaches 7 days, automatically trigger the key update process; D3: Start a new round of quantum key distribution, generate a new key and securely distribute it to the device and the network side; D4: After the new key is activated, the original key state is marked as "expired" and is prohibited for encryption or authentication; D5: When the device is removed or out of contact for more than a predetermined threshold, all key copies associated with the device are immediately cleared.
[0015] Compared with the prior art, the beneficial effects of the present application are: The present application realizes high robustness detection of encrypted traffic anomalies by converting the pre-processed traffic features into low-dimensional core fingerprints, combining a hybrid intelligent model of quantum heuristic CNN and gradient mask adversarial training, and quantifying the anomaly degree with risk scoring and guaranteeing detection accuracy with baseline dynamic updating, effectively solving the pain points of "difficulty in identifying without decryption and vulnerability to adversarial attacks" in traditional encrypted traffic detection, and building a bidirectional authentication mechanism based on quantum keys, combining post-quantum cryptographic algorithms to resist quantum computing attacks, and strengthening dynamic monitoring through high-risk device high-frequency authentication, and ensuring key timeliness and irreversibility through key life cycle management, together providing "accurate anomaly identification" and "quantum-level security protection" for the system, significantly improving the security, robustness and reliability of the Internet of Things card traffic control. BRIEF DESCRIPTION OF DRAWINGS
[0016] Fig. 1 The system diagram of the present application, an Internet of Things card abnormal traffic identification and multi-level response control system.
[0017] Fig. 2 The overall architecture diagram of the present application, an Internet of Things card abnormal traffic identification and multi-level response control system.
[0018] Fig. 3 The key life cycle management flowchart of the present application, an Internet of Things card abnormal traffic identification and multi-level response control system.
[0019] BRIEF DESCRIPTION OF DRAWINGS: 100. Quantum key distribution and generation module; 101. Quantum random number generation unit; 102. Quantum state transmission and reception unit; 103. Classical post-processing unit; 104. Channel monitoring unit; 200. Data acquisition and preprocessing module; 201. Multi-dimensional acquisition unit; 202. Data cleaning unit; 203. Feature standardization unit; 204. Feature storage unit; 300. Abnormal traffic identification module; 301. Quantum feature distillation unit; 302. Hybrid intelligent detection unit; 303. Risk scoring unit; 304. Baseline update unit; 400. Multi-level response execution module; 401. Level determination unit; 402. Response action execution unit; 403. Response upgrade unit; 404. Backtracking and recovery unit; 500. Quantum security management module; 501. Bidirectional authentication unit; 502. Anti-quantum attack unit; 503. Continuous authentication unit; 504. Key life cycle unit. DETAILED DESCRIPTION
[0020] The following will be combined with the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of the present invention.
[0021] Example
[0022] like Figs. 1-3 As shown, this embodiment provides an IoT card abnormal traffic identification and multi-level response control system, including a quantum key distribution and generation module 100, a data acquisition and preprocessing module 200, an abnormal traffic identification module 300, a multi-level response execution module 400, and a quantum security management module 500. The quantum key distribution and generation module 100 performs secure key distribution based on quantum random number generation and quantum state transmission in combination with a classical post-processing protocol. The data acquisition and preprocessing module 200 collects traffic call records and data packet features of the IoT card and performs normalization, denoising, and feature vectorization. The abnormal traffic identification module 300 performs highly robust anomaly detection and risk scoring on the behavioral fingerprint of encrypted traffic without decrypting the communication content using a hybrid intelligent model combining quantum feature distillation and anti-adversarial enhancement. The multi-level response execution module 400 automatically executes graded response actions such as log auditing, bandwidth throttling, or communication blocking based on the anomaly score level. The quantum security management module 500 performs bidirectional identity authentication between the IoT card and the access device based on quantum keys, supporting continuous authentication and key lifecycle management against quantum computing attacks.
[0023] It should be noted that the quantum key distribution and generation module 100 provides basic security key support for the system, the data acquisition and preprocessing module 200 collects and processes the Internet of Things card traffic data and inputs the abnormal traffic identification module 300, the abnormal traffic identification module 300 completes the encrypted traffic anomaly detection and scoring with the help of quantum and intelligent models, the results drive the multi-level response execution module 400 to execute the hierarchical response action, and the quantum security management module 500 realizes the bidirectional identity authentication of the Internet of Things card and the access equipment, the anti-quantum attack continuous authentication and the key life cycle management based on the quantum key.
[0024] It should be noted that in the present embodiment, the quantum key distribution and generation module 100 includes a quantum random number generation unit 101, a quantum state transmission and receiving unit 102, a classical post-processing unit 103, and a channel monitoring unit 104, wherein: the quantum random number generation unit 101 generates high-entropy random numbers based on the superposition characteristics of single-photon quantum states; the quantum state transmission and receiving unit 102 is used to send or receive single-photon polarization states of encoded key information through a quantum channel; the classical post-processing unit 103 is used to perform basis vector comparison, LDPC error correction and SHA-3 privacy amplification, and convert the original quantum data into the final key that meets the security standard; and the channel monitoring unit 104 is used to monitor the photon attenuation and noise intensity in quantum state transmission in real time, and trigger key distribution suspension and alarm when abnormal.
[0025] It should be noted that the quantum random number generation unit 101 generates high-entropy random numbers as key basic materials, the quantum state transmission and receiving unit 102 completes the transmission and reception of single-photon polarization states of encoded key information through a quantum channel, the classical post-processing unit 103 performs basis vector comparison, error correction and privacy amplification on the original quantum data to generate the final key that meets the security standard, and the channel monitoring unit 104 monitors the quantum state transmission state in real time and triggers key distribution suspension and alarm when abnormal.
[0026] Further, it needs to be explained that the high-entropy random number generated by the quantum random number generation unit 101 needs to meet the NIST SP 800-22 randomness detection standard, and the generation rate is not less than 1 Mbps, and the bit error rate is ≤0.001%; the generated random number needs to be synchronized to the classical post-processing unit 103 through the quantum security management module 500 The classical channel (using AES-256 encryption) is used as the "random reference basis" for the comparison of the base vectors, ensuring the consistency of the base vector selection at both ends. The abnormality judgment threshold of the channel monitoring unit 104 is set as: the optical fiber quantum channel photon attenuation rate > 3dB / km, the free space quantum channel noise intensity > -60dBm; when the monitoring data exceeds the threshold for 100ms, it is determined that the channel is eavesdropped / interfered, and the quantum state transmission and receiving unit 102 is immediately triggered to pause key distribution, and sends "key distribution exception" alarm to the two-way authentication unit 501 of the quantum security management module 500, and synchronously freezes the access permission of the authentication equipment in this period.
[0027] In the present embodiment, it also needs to be explained that the data acquisition and preprocessing module 200 includes a multi-dimensional acquisition unit 201, a data cleaning unit 202, a feature standardization unit 203, and a feature storage unit 204. Among them: the multi-dimensional acquisition unit 201 is used to capture the traffic characteristics and call information of the IP address, protocol type, data packet length, and frame interval of the Internet of Things card; the data cleaning unit 202 is used to remove noise data such as empty packets and duplicate packets, and process according to service priority; the feature standardization unit 203 is used to discretize features through one-hot encoding and normalize continuous features through Z-Score, and output vectors of uniform dimensions; the feature storage unit 204 is used to encrypt and store the feature vectors after preprocessing.
[0028] Among them, it needs to be explained that the multi-dimensional acquisition unit 201 captures the traffic characteristics and call information of the IP address, protocol type, etc. of the Internet of Things card, the data cleaning unit 202 removes noise such as empty packets and duplicate packets from the collected data and processes according to service priority, the feature standardization unit 203 converts the processed data into uniform dimension vectors through one-hot encoding and Z-Score normalization, and the feature storage unit 204 encrypts and stores the feature vectors after final preprocessing.
[0029] Further, it needs to be explained that the service priority of the data cleaning unit 202 is divided into three levels according to "real-time + importance": ① Level 1: industrial control instructions, device control signals (such as load regulation instructions of smart power grids), processing delay ≤100ms; ② Level 2: regular monitoring data (such as device heartbeat packets, temperature and humidity collection values), processing delay ≤500ms; ③ Level 3: historical archive data (such as traffic call data 72 hours ago), processing delay ≤10s.
[0030] The feature standardization unit 203 processes "protocol type" (TCP / UDP / CoAP, etc., after encoding, 8 bits are occupied) and "source / destination IP" (after encoding, 32 bits are occupied) through one-hot encoding, normalizes "packet length" and "interframe interval time" and the like continuous features to [0, 1] through Z-Score standardization, and finally outputs a 128-dimensional feature vector; the feature storage unit 204 uses the session key provided by the quantum key distribution and generation module 100, encrypts the feature vector through the SM4 national encryption algorithm, and stores it. The storage period is consistent with the effective period of the Internet of Things card access, and it is automatically desensitized and destroyed after expiration.
[0031] In the embodiment, it also needs to be explained that the abnormal traffic identification module 300 includes a quantum feature distillation unit 301, a hybrid intelligent detection unit 302, a risk scoring unit 303, and a baseline updating unit 304, wherein: the quantum feature distillation unit 301 is used to map traffic features to quantum states, extract correlation information through entangling gates, and collapse to core features, compressing dimensions while retaining key fingerprints; the specific operation is as follows: A1: normalize the preprocessed traffic feature vector to obtain an input vector with dimension d ; A2: use angle encoding to map each feature component to the rotation angle of a quantum bit to construct an initial quantum state:
[0032] wherein, is a single-bit rotation gate around the y-axis, and the rotation angle is ; is the initial state of d quantum bits; A3: extract the nonlinear correlation between features through a multi-layer parametric quantum circuit containing single-bit rotation gates and adjacent bit entangling gates; A4: measure the output state of the quantum circuit to obtain the expectation value as a low-dimensional quantum embedded feature; A5: output the measurement result as a core behavior fingerprint. The hybrid intelligent detection unit 302 is used to combine quantum heuristic CNN and gradient mask adversarial training to identify abnormal patterns of encrypted traffic with high robustness; the specific operation is as follows: B1: quantum heuristic CNN model construction and feature extraction: the quantum heuristic CNN includes a three-level structure of "quantum heuristic convolution layer → classical convolution layer → fully connected layer": ① input the M-dimensional core feature vector output by the quantum feature distillation unit 301 into the quantum heuristic convolution layer, extract the spatial correlation of the features through quantum entanglement filtering kernels, and the filtering kernel is composed of K quantum bits. The feature transformation formula is: , wherein, is the input core feature matrix, Quantum filter kernel parameters are provided with initial values by the quantum random number generation unit 101, The entanglement coefficient is 0.8-1.0, and the strong correlation feature position is 1.0, Quantum-inspired convolutional layer output features; ② Input 2 layers of classical convolutional layers and 1 layer of maximum pooling layers to complete feature dimension reduction and local pattern extraction; ③ output a feature vector through a fully connected layer as the basic feature of abnormal pattern recognition; B2: Gradient mask adversarial training is performed: based on the CNN structure in B1, the model's ability to resist adversarial attacks is improved through the gradient mask mechanism, which specifically includes: ① generating adversarial samples: a small perturbation is added to the input normal traffic feature vector using the fast gradient sign method, and the perturbation amplitude Control is the standard deviation of the feature vector 3%-5%, and the perturbation formula is:
[0033] Wherein, is the normal traffic feature, is the model cross-entropy loss function, is the gradient of the loss function to the input feature, is the generated adversarial sample; ② Gradient mask optimization: in the model backpropagation process, a mask matrix M is added to the gradient matrix, and the masked gradient formula is: , wherein, is the Hadamard product, which avoids the model from relying too much on the feature dimensions that are vulnerable to attacks; ③ mixed sample training: normal samples and adversarial samples are mixed in a ratio of 4:1 and input into the model, and the model is iteratively trained for 50-80 rounds. The final model has an identification accuracy of ≥98.2% for encrypted traffic abnormal patterns and ≥97.5% for adversarial samples, and a false detection rate of ≤1.5%. The risk scoring unit 303 calculates a risk value of 0-100 based on the abnormal matching degree, baseline deviation degree, and historical correlation degree to quantify the severity of the anomaly; the baseline updating unit 304 is used to dynamically update the normal behavior baseline using recent traffic data from legitimate devices, and is automatically iterated every 24 hours.
[0034] It should be noted that the quantum feature distillation unit 301 maps the traffic features output by the preprocessing data acquisition and preprocessing module 200 to quantum states, extracts correlations, and collapses to generate core behavior fingerprints. The mixed intelligent detection unit 302 implements high-robustness identification of encrypted traffic abnormal patterns based on the core features through quantum-inspired CNN and gradient mask adversarial training. The risk scoring unit 303 calculates a risk value based on the abnormal matching degree, baseline deviation degree, and historical correlation degree to quantify the severity of the anomaly. The baseline updating unit 304 periodically updates the normal behavior baseline using traffic data from legitimate devices.
[0035] Further, it needs to be explained that in step B1 ②, the parameters of the classical convolution layer are: 32 3x3 convolution kernels in the first layer, step 1, 64 3x3 convolution kernels in the second layer, step 1, and a maximum pooling layer (2x2 pooling kernel, step 2). The risk score calculation formula is: wherein, the (abnormal matching degree) is the cosine similarity (normalized to 0-100 points) of the flow and the attack feature library, the (baseline deviation degree) is the Euclidean distance (normalized to 0-100 points) of the flow behavior and the normal baseline, the (historical correlation degree) is the proportion of abnormal times of the device in the past 7 days (normalized to 0-100 points); the grade division threshold is: low risk (0-30 points), medium risk (31-70 points), and high risk (71-100 points), and directly determine high risk.
[0036] In the present embodiment, it also needs to be explained that the multi-level response execution module 400 includes a grade determination unit 401, a response action execution unit 402, a response upgrade unit 403, and a backtracking and recovery unit 404, wherein: the grade determination unit 401 is used to divide the three abnormal grades of low, medium and high according to the risk score; the response action execution unit 402 is used to trigger the graded operations of log auditing, bandwidth throttling, and communication blocking; the response upgrade unit 403 is used to automatically upgrade the response level when the low or medium risk response does not eliminate the abnormality for 1 hour; and the backtracking and recovery unit 404 is used to remove the restriction and restore the normal bandwidth if the device passes the re-authentication after high-risk blocking.
[0037] It needs to be explained that the grade determination unit 401 divides the three abnormal grades of low, medium and high according to the risk score output by the abnormal flow identification module 300, the response action execution unit 402 triggers the graded operations of log auditing, bandwidth throttling, and communication blocking, the response upgrade unit 403 automatically upgrades the response level when the low or medium risk response does not eliminate the abnormality for 1 hour, and the backtracking and recovery unit 404 removes the restriction and restores the normal bandwidth if the device passes the re-authentication of the quantum security management module 500 after high-risk blocking.
[0038] Further, it needs to be explained that the response action execution rules in the response action execution unit 402 are as follows: ① low risk: the log audit needs to record "source IP, destination IP, packet length time sequence, abnormal time stamp", and upload to the quantum security management module 500 after encryption for archiving (save for 90 days); ② medium risk: bandwidth throttling to 50% of the average bandwidth of the device for nearly 24 hours, detecting abnormality every 30 minutes, and restoring bandwidth if there is no abnormality for 3 times in a row; ③ high risk: cutting off L3 layer IP forwarding, freezing the device's access permission, and synchronously pushing the alarm to the administrator terminal. After the high-risk blocking in the backtracking and recovery unit 404 lasts for 10 minutes, the re-authentication is automatically triggered (performed by the two-way authentication unit 501 of the quantum security management module 500), and the re-authentication needs to additionally verify the "binding relationship between the device MAC address and the access certificate"; after verification, 80% of the bandwidth is restored first and monitored for 1 hour, and if there is no abnormality, it is restored to 100%; if the verification fails, the blocking is extended to 24 hours, triggering manual review.
[0039] In the present embodiment, it also needs to be explained that the quantum security management module 500 includes a two-way authentication unit 501, an anti-quantum attack unit 502, a continuous authentication unit 503, and a key life cycle unit 504, wherein: the two-way authentication unit 501 performs identity verification between the device and the Internet of Things card based on quantum key pairs; the specific operation is as follows: C1: the network side sends an authentication challenge message to the Internet of Things card; C2: the Internet of Things card generates a message authentication code using the pre-shared quantum key for the challenge message and returns it to the network side; C3: the network side verifies the correctness of the message authentication code, and if it is correct, initiates a reverse authentication and sends a new challenge to the device; C4: the device generates a response message authentication code using the same or paired quantum key and returns it; C5: the network tests the verification to be completed and establishes a two-way trusted connection. The anti-quantum attack unit 502 is used to use post-quantum cryptographic algorithms to reinforce the authentication process and resist the risk of key cracking by quantum computing; the continuous authentication unit 503 is used to trigger high-frequency authentication every 5 minutes for high-risk devices to strengthen dynamic security monitoring; and the key life cycle unit 504 is used to manage key generation, activation, 7-day period update, and key destruction for device logout. The specific operation is as follows: D1: when the device is first accessed, the quantum key distribution process is triggered to generate an initial key and mark it as "activated"; D2: start the period timer, and when the key usage time reaches 7 days, automatically trigger the key update process; D3: start a new round of quantum key distribution, generate a new key and safely distribute it to the device and the network side; D4: after the new key is activated, mark the original key as "expired" and prohibit it from being used for encryption or authentication; and D5: when the device is logged out or loses connection for more than a preset threshold, immediately clear the device-associated key copy.
[0040] It should be noted that the bidirectional authentication unit 501 completes the identity verification of the device and the Internet of Things card through the challenge-response mechanism based on the quantum key provided by the quantum key distribution and generation module 100, the anti-quantum attack unit 502 uses a post-quantum cryptographic algorithm to reinforce the authentication process to resist quantum computing cracking risks, the continuous authentication unit 503 triggers high-frequency authentication every 5 minutes for the high-risk device determined by the abnormal traffic identification module 300, and the key life cycle unit 504 is responsible for the whole cycle management of the quantum key from generation, activation, 7-day period update to device key destruction.
[0041] Further, it should be noted that the anti-quantum attack unit 502 uses the CRYSTALS-Kyber algorithm (NIST post-quantum cryptographic standard) to reinforce the authentication process, wherein the key encapsulation uses the Kyber-768 parameter set, and the digital signature uses the CRYSTALS-Dilithium algorithm (Dilithium-3 parameter set), so as to ensure that the cracking difficulty of the authentication information is high in the quantum computing environment The high-risk device determination standard of the continuous authentication unit 503 is: ① the risk score output by the abnormal traffic identification module 300 is greater than or equal to 71 points; ② the medium-risk response is triggered for 3 times or more in the past 24 hours; any one condition triggers high-frequency authentication every 5 minutes, and the high-frequency authentication lasts for 24 hours without abnormality, and then the authentication cycle is restored to the normal authentication cycle (every 30 minutes). In step D2, the key update warning time is “24 hours before expiration”, at which time the device is pushed with “key update notification”; in step D5, the “disconnection preset threshold” is 72 hours (no communication record of the device), and the key destruction adopts the mode of “3 random number overwriting + physical isolation storage area”, and the overwriting random number is provided by the quantum random number generation unit 101, so as to ensure that the old key cannot be recovered.
[0042] In the description of the present specification, the description referring to the terms “one embodiment”, “example”, “specific example” and the like means that the specific features, structures, materials or characteristics described in connection with the embodiment or example are contained in at least one embodiment or example of the present application. In the present specification, the illustrative description of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials or characteristics described can be combined in any one or more embodiments or examples in a suitable manner.
[0043] The preferred embodiments of the application disclosed above are only to facilitate the elucidation of the application. The preferred embodiments do not describe all the details of the application and limit the application to the specific embodiments described. Obviously, many modifications and variations can be made in light of the teachings above. The description is chosen and described in order to best explain the principles of the application and its practical application to thereby enable others skilled in the art to best utilize the application and get the best results from the application. The application is only limited by the claims and their full scope and equivalents.
Claims
1. An IoT card abnormal traffic identification and multi-level response control system, characterized in that: The system comprises a quantum key distribution and generation module (100), a data acquisition and preprocessing module (200), an abnormal traffic identification module (300), a multi-level response execution module (400), and a quantum security management module (500), wherein: The quantum key distribution and generation module (100) is based on quantum random number generation and quantum state transmission, combined with a classical post-processing protocol to complete secure key distribution; The data collection and preprocessing module (200) is used to collect traffic call records and data packet features of the Internet of Things card, and perform normalization, denoising and feature vectorization processing; The abnormal traffic identification module (300) is used to perform high-robust anomaly detection and risk scoring on the behavioral fingerprint of encrypted traffic through a hybrid intelligent model of quantum feature distillation and anti-adversarial enhancement without decrypting the communication content; The multi-level response execution module (400) is used to automatically execute hierarchical response actions such as log auditing, bandwidth limiting or communication blocking according to the abnormality scoring level; The quantum security management module (500) performs two-way identity authentication on the Internet of Things card and the access device based on the quantum key, and supports continuous authentication and key lifecycle management against quantum computing attacks.
2. The abnormal traffic identification and multi-level response control system for Internet of Things cards according to claim 1 is characterized in that: The quantum key distribution and generation module (100) comprises a quantum random number generation unit (101), a quantum state transmission and reception unit (102), a classical post-processing unit (103), and a channel monitoring unit (104), wherein: The quantum random number generating unit (101) generates a high entropy random number based on the superposition characteristics of single-photon quantum states; The quantum state transmission and reception unit (102) is used to transmit or receive single photon polarization states encoding key information through a quantum channel; The classical post-processing unit (103) is used to perform basis vector comparison, LDPC error correction and SHA-3 privacy amplification, and convert the original quantum data into a final key that meets security standards; The channel monitoring unit (104) is used to monitor the photon attenuation and noise intensity in quantum state transmission in real time, and trigger the key distribution suspension and alarm when an abnormality occurs.
3. The abnormal traffic identification and multi-level response control system for Internet of Things cards according to claim 1 is characterized in that: The data acquisition and preprocessing module (200) comprises a multi-dimensional acquisition unit (201), a data cleaning unit (202), a feature standardization unit (203), and a feature storage unit (204), wherein: The multi-dimensional acquisition unit (201) is used to capture the traffic characteristics and call record information of the IP address, protocol type, data packet length, and frame interval of the Internet of Things card; The data cleaning unit (202) is used to remove noise data such as empty packets and duplicate packets and process them according to service priority; The feature normalization unit (203) is used to encode discrete features through one-hot encoding and Z-Score normalization of continuous features, and output a vector of uniform dimension; The feature storage unit (204) is used to encrypt and store the pre-processed feature vector.
4. The abnormal traffic identification and multi-level response control system for Internet of Things cards according to claim 1 is characterized in that: The abnormal traffic identification module (300) includes a quantum feature distillation unit (301), a hybrid intelligent detection unit (302), a risk scoring unit (303), and a baseline updating unit (304), wherein: The quantum feature distillation unit (301) is used to map the traffic feature into a quantum state, extract the associated information through the entanglement gate and collapse it into the core feature, compress the dimension while retaining the key fingerprint; The hybrid intelligent detection unit (302) is used to combine quantum-inspired CNN with gradient mask adversarial training to perform highly robust abnormal pattern recognition on encrypted traffic behavior; The risk scoring unit (303) calculates a risk value of 0-100 based on the abnormal matching degree, baseline deviation degree, and historical correlation degree to quantify the severity of the abnormality; The baseline updating unit (304) is used to dynamically update the normal behavior baseline using recent traffic data of legitimate devices, and automatically iterate once every 24 hours.
5. The abnormal traffic identification and multi-level response control system for Internet of Things cards according to claim 4 is characterized in that: The quantum feature distillation unit (301) maps the traffic feature into a quantum state, extracts the associated information through an entanglement gate and collapses it into a core feature, compresses the dimension while retaining the key fingerprint. The specific operation is as follows: A1: Normalize the preprocessed traffic feature vector to obtain an input vector of dimension d ; A2: Using angle coding, each feature component Mapped to the rotation angle of the quantum bit, construct the initial quantum state: , in, is a single-bit revolving door around the y-axis, and the rotation angle is ; is the initial state of d qubits; A3: Extract nonlinear correlations between features through multi-layer parametric quantum circuits, including single-bit rotation gates and adjacent bit entanglement gates; A4: Measure the output state of the quantum circuit and obtain the expected value as a low-dimensional quantum embedding feature; A5: Output the measurement results as the core behavioral fingerprint.
6. The abnormal traffic identification and multi-level response control system for Internet of Things cards according to claim 4 is characterized in that: The hybrid intelligent detection unit (302) combines quantum-inspired CNN with gradient mask adversarial training to perform highly robust abnormal pattern recognition on encrypted traffic behavior. The specific operations are as follows: B1: Quantum-inspired CNN model construction and feature extraction: The quantum-inspired CNN includes a three-level structure of "quantum-inspired convolutional layer → classical convolutional layer → fully connected layer": ① Input the M-dimensional core feature vector output by the quantum feature distillation unit (301) into the quantum-inspired convolution layer, and extract the spatial correlation of the features through the quantum entanglement filter kernel. The filter kernel is composed of K quantum bits, and the feature transformation formula is: , in, is the input core feature matrix, is the quantum filter kernel parameter, and the initial value is provided by the quantum random number generation unit (101). is the entanglement coefficient, ranging from 0.8 to 1.0, with a strong correlation feature position taking 1.
0. Output features for the quantum-inspired convolutional layer; ② General Input two layers of classic convolutional layers and one layer of maximum pooling layer to complete feature dimensionality reduction and local pattern extraction; ③ Output feature vectors through the fully connected layer as the basic features for abnormal pattern recognition; B2: Gradient masked adversarial training execution: Based on the CNN structure in B1, the gradient masking mechanism is used to improve the model's ability to resist adversarial attacks. Specifically, it includes: ① Generate adversarial samples: Use the fast gradient sign method to add a small perturbation to the input normal traffic feature vector, and the perturbation amplitude Control is the standard deviation of the eigenvector 3%-5% of the perturbation formula is: , in, Normal traffic characteristics, is the model cross entropy loss function, is the gradient of the loss function with respect to the input features, is the generated adversarial example; ② Gradient mask optimization: During the model back propagation process, a mask matrix M is added to the gradient matrix. The gradient formula after masking is: ,in, It is the Hadamard product, which prevents the model from over-relying on feature dimensions that are vulnerable to attacks; ③ Mixed sample training: Normal samples and adversarial samples are mixed and input into the model in a 4:1 ratio. It is iterated for 50-80 rounds. The final model has an accuracy rate of ≥98.2% for abnormal patterns of encrypted traffic and an accuracy rate of ≥97.5% for adversarial samples, with a false positive rate of ≤1.5%.
7. The abnormal traffic identification and multi-level response control system for Internet of Things cards according to claim 1 is characterized in that: The multi-level response execution module (400) includes a level determination unit (401), a response action execution unit (402), a response upgrade unit (403), and a backtracking and recovery unit (404), wherein: The level determination unit (401) is used to classify the abnormality into three levels: low, medium and high according to the risk score; The response action execution unit (402) is used for triggering hierarchical operations such as log auditing, bandwidth limiting, and communication blocking; The response upgrade unit (403) is used to automatically upgrade the response level when the abnormality is not eliminated within 1 hour of low or medium risk response; The backtracking and recovery unit (404) is used to release the restriction and restore normal bandwidth if the device passes the re-authentication after high-risk blocking.
8. The abnormal traffic identification and multi-level response control system for Internet of Things cards according to claim 1 is characterized in that: The quantum security management module (500) comprises a two-way authentication unit (501), an anti-quantum attack unit (502), a continuous authentication unit (503), and a key lifecycle unit (504), wherein: The two-way authentication unit (501) performs mutual identity verification between the device and the Internet of Things card based on the quantum key; The anti-quantum attack unit (502) is used to use a post-quantum cryptographic algorithm to strengthen the authentication process and resist the risk of quantum computing cracking the key; The continuous authentication unit (503) is used to trigger high-frequency authentication every 5 minutes for high-risk devices to strengthen dynamic security monitoring; The key lifecycle unit (504) is used to manage key generation, activation, 7-day cycle update and key destruction of deregistered devices.
9. The abnormal traffic identification and multi-level response control system for Internet of Things cards according to claim 8 is characterized in that: The two-way authentication unit (501) performs mutual identity verification between the device and the IoT card based on the quantum key, and the specific operations are as follows: C1: The network sends an authentication challenge message to the IoT card; C2: The IoT card uses the pre-shared quantum key to generate a message authentication code for the challenge message and transmits it back to the network side; C3: The network verifies the correctness of the message authentication code. If it passes, it initiates reverse authentication and sends a new challenge to the device. C4: The device uses the same or paired quantum key to generate a response message authentication code and returns it; C5: After the network test is completed and verified, a two-way trusted connection is established.
10. The abnormal traffic identification and multi-level response control system for Internet of Things cards according to claim 8 is characterized in that: The key lifecycle unit (504) manages key generation, activation, 7-day cycle update, and key destruction of deregistered devices. The specific operations are as follows: D1: When the device is first connected, the quantum key distribution process is triggered, the initial key is generated and marked as "activated"; D2: Start the cycle timer. When the key usage time reaches 7 days, the key update process is automatically triggered. D3: Start a new round of quantum key distribution, generate new keys and securely distribute them to devices and the network. D4: After the new key is activated, the original key status is marked as "expired" and cannot be used for encryption or authentication; D5: When a device is deregistered or disconnected for more than a preset threshold, all key copies associated with the device are immediately cleared.
Citation Information
Patent Citations
Chaotic synchronization key distribution method and system based on optical fiber channel feature extraction
CN113541919A
Estimation method and device of distillable key, equipment and storage medium
CN116346334A
Method for realizing quantum continuous learning based on quantum data by dynamically adjusting model structure
CN117634630A
Communication interface conversion method for multi-source heterogeneous equipment
CN118611871A
Intelligent network intrusion detection system based on 5G network
CN120302291A
Cited By
Computer network traffic anomaly detection method and system based on deep learning
CN122372345A