Edge video analysis dynamic negotiation authentication method and device fusing quantum key

By constructing a dynamic negotiation authentication mechanism in the edge video analytics system and utilizing the quantum entropy source verification and trust degree coupling evaluation model, the problem of insufficient identity authentication in existing systems is solved, achieving high-security, adaptive authentication and dynamic permission adjustment for edge nodes, thereby improving the system's security and management efficiency.

CN122268647APending Publication Date: 2026-06-23GUANGDONG ZHIYIXU TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
GUANGDONG ZHIYIXU TECHNOLOGY CO LTD
Filing Date
2026-04-09
Publication Date
2026-06-23

AI Technical Summary

Technical Problem

Existing edge video analytics systems lack a real-time identity authentication mechanism that integrates quantum keys and multi-source dynamic information, making it difficult to achieve highly secure and adaptive dynamic negotiation authentication. In particular, in multi-node collaborative analysis scenarios, there is a lack of joint dynamic evaluation of node identity authenticity, key security, and channel reliability.

Method used

By acquiring multi-dimensional authentication data from edge video nodes, identity encoding and key synchronization are performed, a dynamic negotiation key pool is constructed, and quantum entropy source verification and integrity authentication analysis are conducted. A trust coupling evaluation model is established, cross-node authentication correlation is analyzed, a dynamic trust update model is constructed, and a security authentication graph is generated, ultimately achieving real-time identity authentication and dynamic adjustment of access permissions.

Benefits of technology

It enables accurate identification and rapid response to potential security threats, reduces the false negative and false positive rates of spoofed access and internal threats, improves the utilization efficiency and management intelligence of edge computing resources, and ensures the highly reliable and secure operation of the edge video analytics network in dynamic environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122268647A_ABST
    Figure CN122268647A_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of edge video analysis, and more particularly to an edge video analysis dynamic negotiation authentication method and device fusing quantum keys, which acquires multi-dimensional data of edge nodes, constructs a dynamic negotiation key pool through identity coding and key synchronization, performs quantum entropy source inspection and integrity analysis on the key pool, constructs a trust degree coupling model and a cross-node association network, generates an identity trust mapping network, verifies the legality of the network and evaluates the security level by using a dynamic trust updating model, forms a security authentication graph, establishes an evaluation index system to comprehensively quantitatively evaluate the graph, outputs a dynamic negotiation authentication report, generates an early warning decision according to the report, and realizes real-time identity authentication and dynamic adjustment of access rights in combination with quantum key distribution, thereby solving the problems of insufficient randomness of traditional edge authentication keys and lagging trust evaluation, and significantly improving the anti-attack capability, real-time response speed and active defense level of the system in a complex environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of edge video analytics technology, and in particular to an edge video analytics dynamic negotiation authentication method and apparatus that integrates quantum key distribution. Background Technology

[0002] With the widespread application of edge computing and artificial intelligence technologies in fields such as smart security and smart cities, edge video analytics systems are rapidly developing towards distributed, real-time, and intelligent directions. However, edge nodes are typically deployed in open physical environments, facing multiple security threats such as forged access, data tampering, and identity impersonation. Traditional identity verification methods based on static keys or centralized authentication mechanisms are no longer sufficient to meet the security requirements of highly dynamic and low-latency scenarios. Existing authentication systems generally suffer from insufficient key randomness, weak resistance to quantum attacks, and lagging trust assessment. Especially in multi-node collaborative analysis scenarios, the lack of a joint dynamic assessment mechanism for node identity authenticity, key security, and channel reliability limits the overall security protection capability of the system.

[0003] In recent years, quantum key distribution technology, with its unconditional security based on the laws of physics, has provided a new path for high-security key generation and distribution in edge communication. However, a single quantum key mechanism is difficult to directly adapt to the complex and ever-changing edge video service scenarios, especially in the key negotiation process, where the lack of comprehensive consideration of node behavior trustworthiness, environmental disturbances, and historical authentication status can easily lead to legitimate but anomalous authentication risks. In addition, existing edge authentication schemes often neglect the spatiotemporal correlation of multi-source information and fail to effectively integrate multi-dimensional data such as node identity characteristics, channel state, and service behavior for dynamic trust modeling, thus limiting the system's ability to predict and respond to potential security threats.

[0004] The above content is only used to help understand the technical solution of the present invention and does not represent an admission that the above content is prior art. Summary of the Invention

[0005] The main objective of this invention is to provide a dynamic negotiation authentication method and apparatus for edge video analysis that integrates quantum keys, aiming to solve the technical problem that existing edge video analysis systems lack a real-time identity authentication mechanism that integrates quantum keys and multi-source dynamic information, making it difficult to achieve highly secure and adaptive dynamic negotiation authentication.

[0006] To achieve the above objectives, this invention provides a dynamic negotiation authentication method for edge video analysis incorporating quantum key distribution, the method comprising: Obtain multi-dimensional authentication data from edge video nodes, encode the multi-dimensional authentication data for identity and synchronize the key, and obtain a dynamic negotiation key pool; Quantum entropy source verification and integrity authentication analysis are performed on the dynamic negotiation key pool. A trust degree coupling evaluation model is constructed, cross-node authentication correlation is analyzed, and an identity trust mapping network is obtained. A dynamic trust update model is constructed, and the identity trust mapping network is validated and its security level is assessed based on the dynamic trust update model, thereby obtaining a security authentication graph for edge video analysis. Establish an edge node security authentication index system, conduct a comprehensive security level assessment of the edge video analysis security authentication map, and obtain a dynamic negotiation authentication report; Security alert decisions are generated based on the dynamic negotiation authentication report, and real-time identity authentication and dynamic adjustment of access permissions are achieved based on quantum key distribution.

[0007] Optionally, the step of obtaining multi-dimensional authentication data of edge video nodes, performing identity encoding and key synchronization on the multi-dimensional authentication data, and obtaining a dynamic negotiation key pool includes: Acquire multi-dimensional authentication data of edge video nodes, including node identity data, quantum random number data, channel feature perception data, and video analysis service data; Entropy value verification and true randomness extraction are performed on quantum random number data to obtain native quantum key characteristics; hash operation and digital signature are performed on node identity identification data to obtain identity authentication characteristics; Time-domain fluctuation analysis is performed on channel feature sensing data to obtain channel state characteristics; permission level extraction is performed on video analysis service data to obtain service access characteristics; identity coupling analysis is performed based on native quantum key characteristics and identity authentication characteristics to obtain identity key correlation coefficients. The channel state characteristics are corrected based on the identity key association coefficient to obtain the true channel impact characteristics; time alignment and spatial registration are performed based on the true channel impact characteristics, native quantum key characteristics, identity authentication characteristics and service access characteristics to construct a dynamic negotiation key pool.

[0008] Optionally, the step of performing entropy verification and true randomness extraction on the quantum random number data to obtain native quantum key characteristics includes: The NIST randomness test standard was used to verify the entropy source integrity of quantum-generated random numbers to obtain a random number qualification mark; the minimum entropy, collision entropy and deviation from the ideal uniform distribution of the random sequence were calculated to construct the entropy parameter matrix; Randomness analysis is performed based on the entropy parameter matrix to generate quantum key quality classification results; the randomness deviation and relative pass probability of different segments of the same key sequence are calculated to construct key quality feature vectors, which constitute the original quantum key features.

[0009] Optionally, the step of performing quantum entropy source verification and integrity authentication analysis on the dynamic negotiation key pool, constructing a trust coupling evaluation model, analyzing cross-node authentication correlation, and obtaining an identity trust mapping network includes: The quantum random entropy, identity information, and channel characteristic parameters in the dynamic negotiation key pool are compared with the security authentication standard values ​​to obtain the parameter compliance level index; the entropy deviation, identity mismatch degree, and channel abnormal fluctuation amount within the same authentication period are calculated to construct the node trust deviation feature spectrum; the node trust deviation feature spectrum is dimensionless to obtain the relative security trust coefficient. Based on parameter compliance level indicators and relative security trust coefficients, a trust-coupled evaluation model is constructed; multivariate correlation analysis is performed on native quantum key characteristics, identity authentication characteristics and channel impact characteristics to obtain a cross-node correlation matrix; Key security influencing factors are identified based on cross-node association matrices, and a trust association network is constructed. Security features are extracted based on the trust association network and the trust degree coupling evaluation model to obtain an identity trust mapping network.

[0010] Optionally, the step of performing dimensionless processing on the node trust bias feature spectrum to obtain the relative security trust coefficient includes: Set a trust bias threshold range, normalize the node trust bias feature spectrum, and obtain the standardized bias value. The entropy weight method is used to determine the weight coefficients of quantum entropy quality, identity matching degree, and channel consistency; a weighted trust deviation matrix is ​​constructed based on the standardized deviation value and the weight coefficients. The relative security trust coefficient is obtained by calculating the relative deviation ratio of each element in the matrix from the security certification standard value.

[0011] Optionally, the construction of a dynamic trust update model, and the performance evaluation of the legitimacy and security level of the identity trust mapping network based on the dynamic trust update model, thereby obtaining an edge video analytics security authentication graph, includes: An attention mechanism model and a GRU temporal trust prediction model are constructed; the quantum entropy fluctuation feature attention mechanism is fused with the GRU model to construct an initial trust prediction model; the initial trust prediction model is trained using historical authentication data to obtain a dynamic trust update model. A sliding time window method is used to extract temporal trust features from the identity trust mapping network, and the extracted features are input into a dynamic trust update model to obtain trust evolution trend prediction results. Based on the trust evolution trend prediction results and channel state features, a security degradation trend curve is constructed. The security degradation trend curve is compared and analyzed with a preset security level threshold to obtain an edge video analysis security authentication map.

[0012] Optionally, the establishment of an edge node security authentication index system, the comprehensive security level assessment of the edge video analysis security authentication graph, and the acquisition of a dynamic negotiation authentication report include: Establish a multi-dimensional security authentication index system, including key quality index, identity matching index, trust degradation index, and channel coupling index; based on the multi-dimensional security authentication index system, quantify the security authentication map of edge video analysis to obtain edge security indexes; The various edge security indicators are standardized to obtain a normalized security index; the normalized security index is weighted and fused to obtain a comprehensive security score; the security level of edge nodes is classified based on the comprehensive security score; sensitivity analysis is performed on the normalized security index to obtain a security contribution index; and a dynamic negotiation authentication report is generated based on the edge node security level and security contribution index.

[0013] Optionally, the weighted fusion of the normalized security indices to obtain a comprehensive security score includes: A security assessment matrix is ​​constructed, and each normalized security index is mapped to a security risk probability. The fuzzy comprehensive evaluation method is used to calculate the membership degree of the security risk probability to obtain a fuzzy security vector. The weight of each index is determined based on the security contribution index, and the fuzzy security vector is weighted and summed. The weighted result is mapped to the scoring interval [0,100] to obtain a comprehensive security score.

[0014] Optionally, the step of generating a security warning decision based on the dynamic negotiation authentication report includes: Based on the dynamic negotiation authentication report, high-risk nodes and key security parameters are identified, matched with the historical security handling case library, and the optimal access control scheme is inferred; the urgency of handling is assessed based on the security level and trust evolution trend prediction results, and a dynamically updated priority is generated. Based on dynamic update priorities and edge video analytics business plans, key negotiation update window recommendations are formulated; targeted identity authentication hardening strategies are generated according to risk types and security contribution indicators; and security early warning decisions are made based on key negotiation update window recommendations and identity authentication hardening strategies.

[0015] Furthermore, to achieve the above objectives, the present invention also provides an edge video analysis dynamic negotiation authentication device that integrates quantum key distribution, the device comprising: The key synchronization module is used to acquire multi-dimensional authentication data of edge video nodes, encode the multi-dimensional authentication data for identity and synchronize the key to obtain a dynamic negotiation key pool. The trust modeling module performs quantum entropy source verification and integrity authentication analysis on the dynamic negotiation key pool, constructs a trust degree coupling evaluation model, analyzes cross-node authentication correlation, and obtains the identity trust mapping network. The graph construction module builds a dynamic trust update model, and performs legality verification and security level assessment on the identity trust mapping network based on the dynamic trust update model, thereby obtaining a security authentication graph for edge video analysis. The comprehensive assessment module establishes a security certification index system for edge nodes, conducts a comprehensive security level assessment of the edge video analysis security certification graph, and obtains a dynamic negotiation certification report. The dynamic control module generates security warning decisions based on the dynamic negotiation authentication report and realizes real-time dynamic adjustment of identity authentication and access permissions based on quantum key distribution.

[0016] This invention provides a dynamic negotiation authentication method for edge video analysis that integrates quantum key distribution. By introducing quantum entropy source verification and quantum key distribution, this method utilizes the physical properties of quantum mechanics to generate truly random keys, fundamentally solving the predictability problem inherent in traditional pseudo-random number generators. Combined with integrity authentication analysis, it effectively resists replay attacks, man-in-the-middle attacks, and future quantum computing cracking threats, providing an unconditionally secure communication foundation for edge video nodes. This method overcomes the limitations of single-identity authentication by constructing a trust-coupled evaluation model. By integrating multi-dimensional data such as node identity, quantum key quality, channel state characteristics, and service behavior, and analyzing cross-node authentication correlations, it can accurately identify legitimate but anomalous potential risks, such as hijacked normal nodes, significantly reducing the false negative and false positive rates of forged access and internal threats. Utilizing a dynamic trust update model (combining attention mechanisms and temporal prediction), the system can continuously verify the legitimacy and predict trends of the identity trust mapping network. This transforms the authentication mechanism from a static, one-time pass into a real-time adjustment of trust scores based on node behavior evolution trends and security level changes. This enables rapid response to sudden security incidents, meeting the stringent requirements of edge video analytics for low latency and high real-time performance. By establishing an edge node security authentication index system and generating a security authentication graph, abstract security states are transformed into quantifiable comprehensive scores and risk contribution indicators. This not only allows administrators to intuitively grasp the overall network security situation but also enables the automatic derivation of optimal remediation plans and access control policies based on the generated dynamic negotiation authentication reports. This achieves a shift from passive defense to proactive early warning and dynamic permission adjustment, improving the utilization efficiency of edge computing resources and the level of intelligent management. Addressing the open deployment environment and dynamically changing network topology of edge nodes, this method effectively overcomes interference from single-point sensor errors or local network fluctuations through spatiotemporal registration and multi-source data fusion. The cross-node correlation analysis mechanism enhances the overall collaborative defense capability of the system, ensuring that the entire edge video analytics network maintains highly reliable and secure operation even when some nodes are damaged or the channel is unstable. Attached Figure Description

[0017] Figure 1This is a flowchart illustrating an embodiment of the edge video analysis dynamic negotiation authentication method integrating quantum key distribution according to the present invention; Figure 2 This is a structural block diagram of an embodiment of the edge video analysis dynamic negotiation authentication device integrating quantum key distribution according to the present invention.

[0018] The realization of the objective, functional features and advantages of the present invention will be further explained in conjunction with the embodiments and with reference to the accompanying drawings. Detailed Implementation

[0019] It should be understood that the specific embodiments described herein are merely illustrative of the invention and are not intended to limit the invention.

[0020] Reference Figure 1 , Figure 1 This is a flowchart illustrating an embodiment of the edge video analysis dynamic negotiation authentication method integrating quantum key distribution according to the present invention.

[0021] In one embodiment, the edge video analysis dynamic negotiation authentication method with fused quantum keys includes: Step S100: Obtain multi-dimensional authentication data of edge video nodes, encode the multi-dimensional authentication data for identity and synchronize the key, and obtain a dynamic negotiation key pool.

[0022] In this context, edge video nodes can be computing units deployed at the network edge, possessing video acquisition and preliminary analysis capabilities. They can be used to execute local video processing tasks and participate in distributed collaborative analysis. Multi-dimensional authentication data can be a collection of multi-source heterogeneous information used for identity and security status assessment, providing input for dynamic trust modeling. Furthermore, multi-dimensional authentication data can include, but is not limited to, one or more of node identity features, channel state parameters, and service behavior logs. Identity encoding can be the process or result of converting node identity information into structured identifiers, used to achieve the identifiability and verifiability of node identities. In an exemplary embodiment, identity encoding can generate unique identity identifiers based on public key infrastructure or device fingerprints. Key synchronization can be the process of coordinating and consistently updating or distributing keys among multiple nodes, ensuring that both communicating parties use the same and secure session key. In a specific embodiment, key synchronization can achieve key consistency maintenance through quantum key distribution or negotiation protocols. The dynamic negotiation key pool can be a collection of multiple real-time generated and synchronized session keys, used to support the supply of secure communication keys with high frequency and low latency. Furthermore, the dynamic negotiation key pool can be dynamically constructed by combining quantum entropy sources and key negotiation protocols. For example, a dynamically negotiated key pool can serve as an input for quantum entropy source verification and integrity authentication analysis, and can also provide key material for real-time identity authentication.

[0023] Step S200: Perform quantum entropy source verification and integrity authentication analysis on the dynamic negotiation key pool, construct a trust degree coupling evaluation model, analyze cross-node authentication correlation, and obtain the identity trust mapping network.

[0024] The quantum entropy source verification can be a quantum physics-based verification mechanism for the randomness of the key seed, ensuring true randomness in key generation and resisting predictive attacks. In one specific embodiment, the quantum entropy source verification can utilize single-photon detection or quantum state measurement to output an unpredictable bit stream. Integrity authentication analysis can be a security verification process that verifies the message has not been tampered with and its source is trustworthy, serving as a defense against replay attacks and man-in-the-middle attacks. In an exemplary embodiment, integrity authentication analysis can employ digital signatures, message authentication codes, or hash chain mechanisms. The trust coupling evaluation model can be a trust quantification model that integrates multi-dimensional security indicators for joint scoring, enabling it to overcome the limitations of single identity identifiers and identify legitimate but anomalous nodes. Furthermore, the trust coupling evaluation model can integrate identity, key, channel, and behavioral characteristics through weighted fusion or machine learning methods. Cross-node authentication correlation can be the behavioral or state correlation exhibited by different edge nodes during the authentication process, enhancing the detection capability against coordinated attacks or local anomalies. In one specific embodiment, cross-node authentication correlation can serve as an input element of the trust coupling evaluation model and can also support the construction of an identity trust mapping network. An identity trust mapping network can be a dynamic graph structure consisting of nodes as nodes and trust relationships as edges. It can be used to visualize and quantify the trust dependencies between nodes across the entire network. Furthermore, the identity trust mapping network can establish trust connections between nodes based on the results of trust degree coupling evaluation.

[0025] Step S300: Construct a dynamic trust update model, and perform legality verification and security level assessment on the identity trust mapping network based on the dynamic trust update model to obtain the edge video analysis security authentication map.

[0026] The dynamic trust update model can be an algorithmic framework that continuously adjusts trust scores by combining attention mechanisms and temporal prediction capabilities. It can be used to achieve real-time evolution of trust scores and rapid response to security incidents. In a specific embodiment, the dynamic trust update model can utilize temporal modeling techniques such as LSTM and Transformer to capture behavioral evolution trends. Legality verification can be the process of determining whether a node's current behavior conforms to a preset security policy, and can be used as one of the evaluation criteria for the dynamic trust update model. Security level assessment can be a graded determination of the current security status of a node or system, and can be used to provide quantitative basis for access control and early warning decisions. The edge video analytics security authentication graph can be a visualized knowledge graph reflecting the security status of edge nodes and their interrelationships, and can be used to transform abstract security states into understandable and operable graphical representations. Furthermore, the edge video analytics security authentication graph can be constructed based on an identity trust mapping network and security level assessment results.

[0027] Step S400: Establish an edge node security authentication index system, conduct a comprehensive security level assessment of the edge video analysis security authentication map, and obtain a dynamic negotiation authentication report.

[0028] The edge node security authentication indicator system can be a multi-level set of indicators used to measure the security of edge nodes, supporting comprehensive security level assessment and remediation strategy generation. In a specific embodiment, the edge node security authentication indicator system can be designed with indicators from dimensions such as identity authenticity, key security, channel reliability, and behavioral compliance. The comprehensive security level assessment can be a process of scoring the security authentication graph as a whole based on the indicator system, which can be used to generate a global security posture description that can be used for decision-making. The dynamic negotiation authentication report can be a structured output document containing security level, risk points, and recommended measures, which can be used as a direct basis for security warnings and permission adjustments.

[0029] Step S500: Generate security warning decisions based on the dynamic negotiation authentication report, and realize real-time identity authentication and dynamic adjustment of access permissions based on quantum key distribution.

[0030] Among these, security early warning decisions can be a set of security response actions automatically triggered based on authentication reports, which can be used to achieve proactive defense and risk intervention. Quantum key distribution can be a technology that uses the principles of quantum mechanics to securely share keys between communicating parties, which can be used to provide unconditionally secure key distribution channels and resist quantum computing cracking. In an exemplary embodiment, quantum key distribution can transmit key information through a quantum channel based on a standard key distribution protocol. Real-time identity authentication can be a process of verifying the legitimacy of an identity in real time when communication is initiated, which can be used to prevent forged access and identity impersonation. Dynamic adjustment of access permissions can be a mechanism that changes the scope of resource access of a node in real time according to its current trust score, which can be used to achieve adaptive security control under the principle of least privilege. Real-time identity authentication and dynamic adjustment of access permissions based on quantum key distribution can be achieved by using keys generated by secure key distribution to complete identity verification and modifying the access control list in real time according to the trust score, thereby achieving the technical effect of ensuring unconditional security of the authentication process and dynamic changes in permissions with risk. In a specific embodiment, real-time identity authentication and dynamic adjustment of access permissions based on quantum key distribution can be achieved by using newly distributed quantum keys for two-way authentication at each session establishment, or by using quantum keys as token encryption keys and combining them with OAuth2.0 to achieve dynamic permission issuance.

[0031] Taking a smart city traffic monitoring edge network as an example, the edge video analysis dynamic negotiation authentication method fused with quantum keys in this embodiment can use smart cameras deployed at intersections as edge video nodes to continuously collect traffic video streams. The system acquires multi-dimensional authentication data such as device fingerprints, wireless channel quality, and video analysis request frequency in real time, and forms a dynamic negotiation key pool after identity encoding and synchronization with quantum keys. Quantum entropy source verification ensures the true randomness of the key, and integrity authentication analysis is combined to prevent key tampering. The trust coupling evaluation model integrates the node's historical behavior, current key quality, and authentication status of neighboring nodes, and finds that although it holds a legitimate certificate, its video request pattern has changed abruptly, and it is judged as a potentially hijacked node. The dynamic trust update model lowers its trust score based on time-series behavior prediction and marks it as high-risk in the identity trust mapping network. The security authentication graph shows that the trust connection between the node and surrounding normal nodes has been broken. After comprehensive evaluation, a dynamic negotiation authentication report is generated, triggering a security warning decision: temporarily restricting its access to the central database and initiating secondary biometric verification. At the same time, the quantum key distribution system assigns it a new session key, only allowing it to upload the original video stream, and restoring full access after manual review.

[0032] In one embodiment, multi-dimensional authentication data of edge video nodes is acquired, and the multi-dimensional authentication data is subjected to identity encoding and key synchronization to obtain a dynamically negotiated key pool, including: Acquire multi-dimensional authentication data of edge video nodes, including node identity data, quantum random number data, channel feature perception data, and video analysis service data; The node identity data can be raw information uniquely representing the identity of an edge video node, serving as the basic input for identity authentication. Quantum random number data can be a raw random bit stream generated by quantum physics processes, used as an entropy source for generating high-security keys. Channel feature perception data can be a set of physical layer parameters reflecting the real-time state of wireless or wired communication channels, used to assess communication link reliability and potential interference. Video analytics service data can be operation and access logs generated when edge nodes perform intelligent video analysis tasks, reflecting the node's current service behavior patterns and resource usage requirements. Acquiring node identity data, quantum random number data, channel feature perception data, and video analytics service data can be achieved by collecting these four types of raw data from device firmware, the quantum entropy source module, the communication driver layer, and the service log system, respectively. Furthermore, this operation can be implemented through hardware interface polling, event-triggered log subscription, or driver callback mechanisms, thereby forming a complete authentication input set covering identity, key, channel, and service.

[0033] Entropy value verification and true randomness extraction are performed on quantum random number data to obtain native quantum key characteristics; Entropy testing can be a process of quantitatively evaluating the uncertainty of a random number sequence, and can be used to screen high-quality random sources that meet security requirements. In a specific embodiment, entropy testing can use Shannon entropy, minimum entropy, or the NIST test suite to calculate a randomness index. True randomness extraction can be a process of removing bias and correlation from the original quantum random numbers to obtain uniformly independent bits, and can be used to generate standard true random key seeds that can be used for cryptographic applications. For example, true randomness extraction can process the original data using a general hash function or a randomness extractor (such as a Toeplitz matrix). Performing entropy testing and true randomness extraction on quantum random number data can involve first calculating its information entropy, and then generating a uniformly distributed key seed using an extractor. Furthermore, this operation can use SHA-3 as a randomness extractor, or use two general hash families (such as Toeplitz) for extraction, thereby ensuring that the key source possesses true randomness in a cryptographic sense.

[0034] Native quantum key features can be cryptographically usable quantum random key representations obtained through entropy verification and true randomness extraction, serving as a core source of key material in dynamic negotiation key pools. Furthermore, native quantum key features can participate in identity coupling analysis to calculate identity-key correlation coefficients and serve as a key input for constructing dynamic negotiation key pools. Obtaining native quantum key features involves encapsulating the extracted true random bits into a standardized key feature structure, thereby providing a key semantic representation that can be used for subsequent coupling analysis.

[0035] Hash and digitally sign the node identity data to obtain identity authentication features; Hash operations can be one-way mathematical functions that map inputs of arbitrary length to fixed-length digests, and can be used to achieve irreversible compression and integrity protection of identity data. Digital signatures are cryptographic operations that use a private key to encrypt a data digest to prove its origin and integrity, and can be used to ensure that the identity identifier has not been tampered with and that its source is trustworthy. Performing hash operations and digital signatures on node identity data can involve first hashing the original identity data and then signing it with the device's private key. Furthermore, this operation can use ECDSA to sign the SHA-256 digest, or RSA-PSS to sign the identity hash value, thereby generating tamper-proof and verifiable identity credentials.

[0036] Identity authentication features can be structured identity credentials processed by hashing and digital signatures, which can be used to provide a counterfeit-resistant and verifiable identity representation. Furthermore, identity authentication features can be used in conjunction with native quantum key features for identity coupling analysis. Obtaining identity authentication features can be achieved by combining hash values ​​and digital signatures into structured identity feature objects, thereby forming standardized identity authentication inputs.

[0037] Time-domain fluctuation analysis is performed on channel characteristic sensing data to obtain channel state characteristics; Temporal fluctuation analysis can be used to statistically model the changing patterns of channel parameters over time, identifying whether abnormal channel fluctuations are caused by environmental disturbances or malicious interference. In one specific embodiment, temporal fluctuation analysis can calculate the variance, autocorrelation coefficient, or spectral density within a sliding window. Performing temporal fluctuation analysis on channel characteristic sensing data can involve calculating statistical fluctuation indices of channel parameters within a sliding time window. Further, this operation can calculate the local variance of the RSSI sequence or analyze the autocorrelation decay rate of the channel impulse response, thereby identifying abnormal channel patterns. Channel state characteristics can be quantitative indicators of channel stability and reliability extracted after temporal fluctuation analysis, used to initially characterize channel quality as a basis for subsequent corrections. Further, channel state characteristics can be corrected by identity key association coefficients to generate true channel impact characteristics. Obtaining channel state characteristics can involve quantifying the fluctuation analysis results into channel stability scores or classification labels, thereby providing a preliminary channel quality assessment.

[0038] Extract permission levels from video analytics business data to obtain business access characteristics; Permission level extraction can be the process of parsing the current required access level of a node from business data, which can be used to match security controls with actual business needs. In an exemplary embodiment, permission level extraction can be based on parsing operation logs according to preset business-permission mapping rules or a policy engine. Extracting permission levels from video analytics business data can involve mapping business operations to corresponding permission levels according to preset rules. Furthermore, this operation can be based on parsing operation logs using an RBAC model, or using Policy Decision Points (PDPs) to evaluate permission requirements in real time, thereby establishing a correlation between business behavior and security policies. Business access features can be a structured representation reflecting the current required permission level of a node's business, which can be used to provide business context for dynamic permission adjustments. Furthermore, business access features can participate in time alignment and spatial registration, and be integrated into a dynamic negotiation key pool. Obtaining business access features can involve encoding permission levels into structured feature vectors, thereby providing business context for dynamic permission control.

[0039] Identity coupling analysis is performed based on native quantum key characteristics and identity authentication characteristics to obtain the identity key correlation coefficient; Identity coupling analysis can be a correlation modeling process to assess the binding strength between identity authentication features and native quantum key features, used to quantify the logical binding credibility of identity and key. In one embodiment, identity coupling analysis can calculate the consistency measure between the two in timestamps, device context, or key derivation paths. Identity coupling analysis based on native quantum key features and identity authentication features compares the consistency of their timestamps, device contexts, or key derivation paths. Further, this operation can calculate the deviation between the key generation time and the identity registration time, or verify whether the key is derived from the private key corresponding to the device's public key, thereby assessing whether the identity and key belong to the same legitimate entity. The identity-key correlation coefficient can be a numerical indicator characterizing the tightness of coupling between identity authentication features and native quantum key features, and can be used to correct channel state characteristics and eliminate misjudgments caused by identity-key inconsistency. Further, the identity-key correlation coefficient can serve as an adjustment factor for channel state characteristic correction. Obtaining the identity-key correlation coefficient can be achieved by normalizing the coupling analysis results to a correlation strength value between 0 and 1, thereby providing quantifiable identity-key binding credibility.

[0040] The channel state characteristics are corrected based on the identity key association coefficient to obtain the true channel impact characteristics; The channel state feature correction can be a process of weighting or calibrating the original channel state features using the identity key correlation coefficient. This can be used to distinguish whether channel degradation stems from environmental changes of legitimate devices or attacks by unauthorized access. In an exemplary embodiment, the channel state feature correction can use the correlation coefficient as a weighting factor to adjust the channel fluctuation threshold or anomaly judgment boundary. Correcting the channel state features based on the identity key correlation coefficient can involve using the correlation coefficient as an adjustment factor to dynamically adjust the channel anomaly judgment threshold. Furthermore, this operation can multiply the correlation coefficient by the original channel fluctuation value to obtain the corrected feature, or relax the channel anomaly tolerance when the correlation coefficient is low, thereby avoiding channel misjudgments caused by identity-key inconsistency. The real channel impact feature can be a security feature that more accurately reflects the actual impact of the physical channel after identity context correction, which can be used to improve the accuracy of channel assessment under the premise of identity-key consistency. Furthermore, the real channel impact feature can be used as one of the multi-source fusion inputs to participate in the construction of the dynamically negotiated key pool. Obtaining the real channel impact feature can be achieved by outputting a channel feature representation after identity context correction, thereby improving the accuracy of channel assessment in real deployment scenarios.

[0041] Based on the characteristics of real channel influence, native quantum key characteristics, identity authentication characteristics, and service access characteristics, time alignment and spatial registration are performed to construct a dynamic negotiation key pool.

[0042] Time alignment can be the process of unifying asynchronous data from different sensors or modules to the same time base, ensuring the comparability and consistency of multi-dimensional features in the time dimension. In a specific embodiment, time alignment can be based on hardware clock synchronization or interpolation algorithms to align sampling times. Spatial registration can be the process of mapping data from different sources to a unified spatial coordinate system or logical topology, achieving semantic alignment of cross-node or multi-source data in the spatial dimension. For example, spatial registration can establish feature correspondences using node location information or network topology relationships. Time alignment and spatial registration based on real channel influence features, native quantum key features, identity authentication features, and service access features can unify the timestamps and spatial / logical coordinates of the four types of features to form an aligned feature vector sequence. Further, this operation can use the PTP protocol to synchronize the clocks of each module for alignment, or establish spatial mapping relationships based on node IDs for registration, thereby achieving spatiotemporal consistency fusion of multi-source heterogeneous security features. Constructing a dynamic negotiation key pool can be achieved by using the aligned and registered four-dimensional features as metadata and associating them with corresponding session keys to form a structured key pool. Furthermore, this operation can construct a hash table using the key as the key and the four-dimensional feature as the value, or concatenate the feature vector with the key and then encrypt and store it in a secure enclave, thereby generating a highly trusted key resource pool with embedded multi-dimensional security semantics.

[0043] Taking a highway edge video surveillance network as an example, the edge video analysis dynamic negotiation authentication method with fused quantum keys in this embodiment can be an edge camera deployed at the tunnel entrance continuously uploading high-definition video. The system collects its device certificate (node ​​identity identification data), local quantum random number generator output (quantum random number data), 5G channel RSSI sequence (channel feature perception data), and target tracking call log (video analysis service data). The quantum random number is tested for entropy value to confirm that its minimum entropy is greater than 0.99, and a 256-bit native quantum key feature is generated by the Toeplitz extractor; the device certificate is hashed with SHA-256 and signed with the device private key to form an identity authentication feature; the variance of RSSI in the past 10 seconds is analyzed, and the fluctuation is found to be outside the normal range, which is initially marked as a channel anomaly; at the same time, the license plate recognition API that needs to be accessed is extracted from the service log, corresponding to the intermediate permission level, to form a service access feature. Furthermore, the system finds that the difference between the key generation time and the device's most recent heartbeat time exceeds the threshold, and the identity key correlation coefficient is only 0.3. Based on this, the channel state feature is corrected: the weight of the anomaly judgment is reduced, and it is determined that the channel fluctuation may be due to the movement of legitimate devices rather than an attack. Finally, the four types of features are aligned under a unified timestamp (UTC+814:30:05.123) and spatial registration is completed based on the device ID to construct a dynamic negotiation key pool containing the key and its four-dimensional security context for subsequent trust assessment.

[0044] In one embodiment, entropy verification and true randomness extraction are performed on the quantum random number data to obtain native quantum key characteristics, including: The NIST randomness test standard was used to verify the entropy source integrity of quantum-generated random numbers to obtain a random number qualification mark; the minimum entropy, collision entropy and deviation from the ideal uniform distribution of the random sequence were calculated to construct the entropy parameter matrix; Randomness analysis is performed based on the entropy parameter matrix to generate quantum key quality classification results; the randomness deviation and relative pass probability of different segments of the same key sequence are calculated to construct key quality feature vectors, which constitute the original quantum key features.

[0045] The NIST randomness test standard, developed by the National Institute of Standards and Technology (NIST), is a set of test specifications for evaluating the statistical randomness of random number sequences. It provides a standardized method to verify whether quantum random numbers exhibit predictable patterns or systematic biases. Entropy source integrity testing verifies whether the output of a quantum random number generator fully retains the original physical entropy, identifying entropy loss due to equipment failure, environmental interference, or post-processing errors. Furthermore, entropy source integrity testing can use multiple statistical tests in the NIST standard to determine whether the output sequence passes a preset significance threshold. The random number pass / fail marker is a binary judgment indicating whether a quantum random number passes the integrity test, serving as an admission control basis for subsequent key processing. Minimum entropy, defined in information theory as the worst-case uncertainty measure of a random variable, is the maximum probability of a negative logarithm and reflects the key's resistance to guessing under the most unfavorable attack scenarios. Collision entropy, defined based on the probability of repeated values ​​of a random variable, is equal to the negative logarithmic collision probability and can be used to assess the risk of repeated segments in a key sequence. For example, collision entropy can be used to construct an entropy parameter matrix, supplementing statistical properties not covered by minimum entropy.

[0046] The deviation of an ideal uniform distribution can be a statistical distance measure between the actual random sequence distribution and the theoretical uniform distribution, and can be used to quantify the degree to which random numbers deviate from the ideal state. Furthermore, the deviation of an ideal uniform distribution can be calculated using the chi-square test, the Kolmogorov-Smirnov test, or the total variation distance. The entropy parameter matrix can be a structured numerical matrix composed of multi-dimensional entropy indices such as minimum entropy, collision entropy, and deviation, and can be used to achieve fine-grained, multi-faceted characterization of the quality of quantum random numbers. In an exemplary embodiment, the entropy parameter matrix can serve as input for randomness analysis, supporting the generation of quantum key quality classification results. Randomness analysis can be a process of comprehensively evaluating the overall quality of random sequences based on the entropy parameter matrix, and can be used to transform raw entropy indices into operable security level labels. Furthermore, randomness analysis can resolve the entropy parameter matrix through clustering, threshold determination, or multi-classification models. The quantum key quality classification results can be a structured output classifying native quantum keys according to security levels, and can be used to provide a basis for key reliability grading for upper-layer trust models. Different segments of the key sequence can be defined as dividing the same quantum key sequence into multiple continuous subsequences based on time or length, which can be used to support the analysis of local randomness stability. Randomness deviation can be a measure of the difference in entropy or statistical properties between different segments of the same key sequence, and can be used to identify whether there is time-varying interference or hardware aging during key generation. Furthermore, randomness deviation can be used to calculate the temporal consistency dimension in the key quality feature vector.

[0047] The relative pass probability can be the normalized ratio of the probability of each segment passing the NIST test to the overall sequence, and can be used to quantify the reliability fluctuations in local regions of the key. The key quality feature vector can be a multi-dimensional vector representation including the global entropy index, segment deviation, and pass probability, and can be used to comprehensively characterize the randomness strength and temporal stability of the key. Verifying the entropy source integrity of quantum-generated random numbers using the NIST randomness detection standard can be achieved by calling the NIST SP800-22 test suite to perform multiple statistical tests on the quantum random number sequence. Furthermore, this operation can be implemented by executing 15 NIST tests in parallel and combining the p-value, or by performing only core tests such as frequency, block frequency, and run-length tests to reduce latency, thereby filtering out poor-quality random outputs with systematic biases or device malfunctions.

[0048] Obtaining random number qualification markers can be achieved by generating binary markers based on whether all NIST test results pass a preset significance level (e.g., α = 0.01), thus establishing an entry threshold for the key processing flow. Calculating the minimum entropy, collision entropy, and deviation from the ideal uniform distribution of the random sequence can be done by applying information theory formulas and statistical testing methods to calculate these three entropy indices. Furthermore, this operation can be implemented by using a sliding window to estimate the local minimum entropy or by using a histogram method to calculate the collision entropy, thereby quantifying the unpredictability and uniformity of the random sequence from different perspectives. Constructing the entropy parameter matrix can be achieved by organizing the calculated entropy values ​​into a matrix structure according to a preset format, thus forming structured input for subsequent analysis. Randomness analysis based on the entropy parameter matrix can be performed by applying a rule engine or a lightweight classification model to parse the matrix content. Furthermore, this operation can be achieved by setting multi-dimensional thresholds for hard classification or by using an SVM to train a classifier on historical labeled data, thereby generating an interpretable key quality level.

[0049] Generating quantum key quality classification results can output security level labels such as "high / medium / low" and confidence levels, thus providing a basis for key reliability weighting in dynamic trust assessment. Calculating the randomness deviation and relative pass probability of different segments of the same key sequence can be achieved by dividing the key into N segments, calculating the entropy value and NIST pass rate for each segment, and then calculating the inter-segment differences and normalized probabilities. Furthermore, this operation can be implemented by segmenting according to a fixed byte length (e.g., every 256 bits) or by segmenting according to a timestamp-aligned acquisition period, thereby capturing temporal instabilities in the key generation process. Constructing a key quality feature vector can be achieved by concatenating global entropy, segment deviation, and relative pass probability into a fixed-dimensional vector, thus forming a complete description of key quality that includes spatiotemporal stability. Constructing native quantum key features can be achieved by binding the key quality feature vector with the original key material and encapsulating it into a structured secure feature object. Furthermore, this operation can be achieved by storing the feature vector and key ID mapping in JSON format or embedding the feature vector in the key metadata header, thereby providing traceable, hierarchical, and interpretable highly reliable key primitives.

[0050] For example, in the scenario of intelligent security edge nodes in key urban areas, the edge video analysis dynamic negotiation authentication method with fused quantum keys in this embodiment can be as follows: An edge camera has a built-in quantum random number generator that continuously outputs a bit stream. The system first calls the NISTSP800-22 suite to perform 15 tests on it. It finds that the p-value of the "non-overlapping template matching" test is 0.003 (below 0.01), and marks it as unqualified; however, after a hardware reset, all new sequences pass, and it obtains the "qualified" mark. Then, the minimum entropy of the 256-bit sequence is calculated to be 0.992, the collision entropy is 0.987, and the chi-square deviation is 4.2 (below the critical value of 5.99), constructing a 3×1 entropy parameter matrix. The randomness analysis module determines it to be "high security level" according to preset rules. The sequence is further divided into four segments (64 bits each), and the minimum entropy of each segment is calculated to be 0.991, 0.989, 0.993, and 0.995, respectively. The maximum deviation between segments is 0.006, and the relative pass probability is higher than 0.98 for all segments. An 8-dimensional key quality feature vector is constructed. Finally, this vector is bound to the key itself to form the native quantum key feature, which is uploaded to the trust evaluation module. When it is subsequently detected that the minimum entropy of the tail segment of a key suddenly drops to 0.92 and the relative pass probability is lower than 0.7, the system determines that the quality degradation is caused by hardware aging, automatically downgrades the trust score of that node, and triggers a maintenance alarm.

[0051] In one embodiment, quantum entropy source verification and integrity authentication analysis are performed on the dynamic negotiation key pool, a trust coupling evaluation model is constructed, cross-node authentication correlation is analyzed, and an identity trust mapping network is obtained, including: The quantum random entropy, identity information, and channel characteristic parameters in the dynamic negotiation key pool are compared with the security authentication standard values ​​to obtain the parameter compliance level index. Quantum random entropy can be an unpredictable measure of information entropy generated by quantum physical processes, used as the source of randomness for key seeds and for assessing key security. In one embodiment, quantum random entropy can be obtained by real-time acquisition of physical processes such as single-photon arrival time, quantum state collapse results, or vacuum noise through a quantum key distribution device. Identity identification information can be structured data uniquely representing the identity of edge video nodes, used to support identity verification and encoding binding. Furthermore, identity identification information can be obtained by submission by the device during the registration phase and then solidified in a secure storage unit after being signed by a trusted institution. Channel characteristic parameters can be a set of measurable indicators describing the physical state and transmission quality of the communication channel, used to reflect the security and reliability of the current communication environment. In this embodiment, channel characteristic parameters can be obtained by real-time acquisition of the transmission characteristics of the wireless link through a physical layer monitoring module. Security authentication standard values ​​can be preset benchmark thresholds or reference distributions used to measure compliance of various security dimensions, and can be used as a basis for parameter comparison to achieve quantitative compliance judgment.

[0052] The comparison of quantum random entropy, identity information, and channel characteristic parameters in the dynamic negotiation key pool with security authentication standard values ​​can be achieved by calculating the deviation or matching degree of each of the three types of parameters with their corresponding standard values. Further, this operation can be implemented by using a threshold judgment method to determine whether the tolerance range is exceeded, or by using probability density function fitting to calculate the likelihood score, thereby enabling independent compliance determination of the three elements: key, identity, and channel. Obtaining the parameter compliance level index can be achieved by mapping the comparison results to predefined level labels or continuous scores. Further, this operation can be implemented by converting deviations into level labels or values ​​through membership functions or rule mapping, thereby outputting structured compliance assessment results. The parameter compliance level index can be a graded compliance score obtained based on the comparison of parameters in each dimension with standard values, and can be used to provide standardized assessment results for multi-dimensional security elements. In a specific embodiment, the parameter compliance level index may include, but is not limited to, one or more of key compliance level, identity compliance level, and channel compliance level.

[0053] Calculate the entropy deviation, identity mismatch degree, and channel anomaly fluctuation within the same authentication period to construct a node trust deviation feature spectrum. Among these, entropy deviation can be a measure of the difference between the actual quantum random entropy and the standard entropy value, reflecting whether the key generation process deviates from the expected security level. Identity mismatch can be the degree of difference between the current identity and the registered identity template, quantifying the possibility of identity impersonation or forgery. Channel anomaly fluctuation can be the magnitude of the sudden change in the current channel characteristics relative to the steady state, indicating potential man-in-the-middle attacks or physical interference. Calculating entropy deviation, identity mismatch, and channel anomaly fluctuation within the same authentication period can be achieved by synchronously collecting and calculating these three types of deviation indicators within a fixed time window. Furthermore, this operation can be implemented by updating deviation values ​​in real time based on a sliding window or by calculating sudden deviations based on an event-triggered mechanism, thus forming a multidimensional anomaly measurement at a unified time granularity. Constructing a node trust deviation feature spectrum can be achieved by organizing the three types of deviations into a fixed-dimensional feature vector. Furthermore, this operation can be implemented by synchronously collecting and organizing the three types of deviation indicators within a unified authentication period, thus establishing a multidimensional representation of node abnormal behavior. The node trust deviation feature spectrum can be a multi-dimensional deviation vector composed of entropy deviation, identity mismatch degree and channel abnormal fluctuation, which can be used to characterize the comprehensive abnormal features of nodes in multiple security dimensions.

[0054] The node trust bias feature spectrum is dimensionless to obtain the relative security trust coefficient; Obtaining the relative safety trust coefficient can be achieved by converting the dimensionless feature spectrum into trust values ​​through a mapping function. Furthermore, this operation can be implemented by converting the bias spectrum into trust values ​​in the [0, 1] interval through weighted synthesis or nonlinear mapping, thereby generating a unified trust metric that can be used as model input. The relative safety trust coefficient can be a comprehensive credibility value mapped from the dimensionless node trust bias features, and can be used as one of the key inputs to the trust-coupled evaluation model.

[0055] Based on parameter compliance level indicators and relative security trust coefficient, a trust-coupled assessment model is constructed. Based on the parametric compliance level indicators and the relative security trust coefficient, a trust-coupled assessment model is constructed, which can be a joint assessment function that integrates discrete levels and continuous trust coefficients. Furthermore, this operation can be achieved by designing a weighted fusion formula to combine the two types of indicators, or by training a classifier to predict the final trust level using both types of indicators as input, thereby enabling a collaborative assessment of static compliance and dynamic deviations.

[0056] Multivariate correlation analysis was performed on the native quantum key characteristics, identity authentication characteristics, and channel impact characteristics to obtain the cross-node correlation matrix; Among these, native quantum key features can be original key attributes directly derived from the quantum key distribution process, reflecting the physical security of the key generation stage. Identity authentication features can be authentication behavior patterns manifested during authentication interactions, identifying anomalous patterns in identity usage. Channel influence features can be indirect indicators of the channel state's impact on the authentication process, revealing the degree of interference from environmental disturbances on the execution of security protocols. Multivariate correlation analysis of native quantum key features, identity authentication features, and channel influence features can be performed by calculating the joint statistical dependencies of these three types of features across multiple nodes. Furthermore, this operation can be achieved by using mutual information to measure nonlinear correlation or by employing canonical correlation analysis to extract the maximum correlation projection, thereby revealing the inherent coupling mechanism of cross-dimensional security elements. Multivariate correlation analysis can be a quantitative analysis method for the statistical dependencies between multiple security feature variables, used to uncover implicit associations between cross-dimensional security elements. Obtaining the cross-node correlation matrix can be achieved by organizing the correlation analysis results into a weight matrix between node pairs. Furthermore, this operation can be achieved by constructing association weights between node pairs based on the multivariate correlation analysis results, thereby quantifying the similarity or dependency of security behaviors between nodes. A cross-node correlation matrix can be a matrix structure that describes the strength of correlation between different edge nodes in terms of security features. It can be used to reveal potential collaborative behaviors or attack propagation paths between nodes.

[0057] Based on cross-node correlation matrices, key security influencing factors are identified, and a trust correlation network is constructed. Identifying key security influencing factors based on cross-node association matrices can be achieved by screening elements with high influence or high relevance using graph theory or statistical methods. Furthermore, this operation can be implemented by calculating the degree centrality of nodes in the association matrix or by performing variance analysis on the feature columns to screen for significant variables, thereby focusing on nodes or features that play a decisive role in system security. Key security influencing factors can be security features or nodes that play a dominant role in cross-node associations, guiding the construction focus of the trust association network and the allocation of defense resources. Constructing a trust association network can be done by using key factors as node or edge weights to establish a graph structure representing trust dependencies. Further, this operation can be achieved by screening significant connections based on the cross-node association matrix and establishing a graph structure, thus forming a trust topology foundation that can be used for global analysis. The trust association network can be a trust dependency graph between nodes built driven by key security influencing factors, which can be used to support global security situation awareness and anomaly propagation modeling.

[0058] Security features are extracted based on the trust association network and the trust degree coupling evaluation model to obtain the identity trust mapping network.

[0059] Security feature extraction based on trust association networks and trust-coupled evaluation models can be achieved by combining graph structures and node scores to extract high-order security representations. Furthermore, this operation can be implemented by using graph convolutional networks to extract node embeddings or by extracting sub-network-level features based on community detection, thereby generating features that possess both local credibility and global relevance. Obtaining the identity-trust mapping network can be achieved by mapping the extracted security features to a final graph of nodes and their trust relationships. Further, this operation can be implemented by jointly mapping node embeddings and trust scores to a weighted directed graph, thereby outputting a joint identity-trust representation that can be used for authentication decisions.

[0060] For example, in the scenario of a smart park perimeter security edge network, the edge video analysis dynamic negotiation authentication method with fused quantum key distribution in this embodiment can be multiple smart cameras deployed on the park's perimeter wall as edge video nodes, reporting their respective quantum random entropy (e.g., 8.95 bits / byte), identity hash value, and current wireless channel bit error rate (e.g., 1.2 × 10⁻⁻⁻⁶) within the same authentication cycle. 4 The system compares these parameters with security authentication standard values ​​(entropy ≥ 8.9, identity matching tolerance ≤ 0.01, bit error rate ≤ 10⁻³) to obtain parameter compliance level indicators: key compliance (high), identity compliance (medium), and channel compliance (high). Simultaneously, it calculates the entropy deviation (-0.05), identity mismatch degree (0.015), and abnormal channel fluctuation (+0.2 × 10⁻³) within this period. 4 The system constructs a node trust bias feature spectrum. After dimensionless Min-Max transformation, the relative security trust coefficient is 0.87. The trust coupling evaluation model integrates compliance level and trust coefficient, giving a comprehensive trust score of 0.82. The system further performs multivariate correlation analysis on the native quantum key generation rate, identity authentication response delay, and channel delay jitter of all nodes, finding that two adjacent nodes show a strong positive correlation (r = 0.92) in key error rate and identity request frequency, generating a cross-node correlation matrix. Through centrality analysis, one node is identified as a key security influencing factor, and a trust correlation network is constructed accordingly. Finally, the security feature extraction module combines this network with the evaluation results of each node to generate an identity trust mapping network, marking the correlation pair as having a risk of abnormal collaboration. Although the identity is legitimate, the behavior is highly synchronized, suspected of being controlled by the same attacker, triggering an alert and restricting its collaborative analysis permissions.

[0061] In one embodiment, the node trust bias feature spectrum is dimensionless to obtain the relative security trust coefficient, including: By setting a trust bias threshold range, the node trust bias feature spectrum is normalized to obtain the standardized bias value.

[0062] The trust deviation threshold range can be a preset upper and lower limit of acceptable deviation range for different security dimensions. It can be used as a benchmark for normalization processing, mapping the original deviation to a uniform scale. Normalization processing can be an operation that linearly or non-linearly maps the data of each dimension in the node trust deviation feature spectrum to a standard range according to the threshold range. This can be used to eliminate differences in dimensions and magnitudes, making multi-dimensional deviations comparable. The standardized deviation value can be a dimensionless deviation value obtained after normalization processing. It can be used as the input basis for weighted fusion, reflecting the relative deviation degree of each dimension. Setting the trust deviation threshold range can be done by configuring acceptable upper and lower limits for entropy deviation, identity mismatch, and channel fluctuation. Furthermore, setting the trust deviation threshold range can be achieved by statistically setting a dynamic threshold range based on historical operational data or by presetting a fixed threshold range according to security level requirements, thus providing a physically meaningful mapping boundary for subsequent normalization.

[0063] The entropy weight method is used to determine the weight coefficients of quantum entropy quality, identity matching degree, and channel consistency; a weighted trust deviation matrix is ​​constructed based on the standardized deviation value and the weight coefficients.

[0064] Among them, the entropy weighting method can be an objective weighting method that automatically determines weights based on the degree of variation (information entropy) of indicator data. It can be used to avoid subjective weighting bias and make the weights reflect the actual data discrimination. Quantum entropy quality can be a comprehensive index characterizing the reliability of quantum random entropy, composed of entropy value, uniformity, and unpredictability. It can be used as one of the key dimensions of trust assessment to reflect the security of the key source. Identity matching degree can be a quantitative value of the consistency between the current identity identifier and the registration template. It can be used to measure the authenticity of the identity and to detect impersonation or forgery. Channel consistency can be the degree of conformity between the current channel state and the historical stable pattern. It can be used to reflect whether the communication environment is subject to interference or man-in-the-middle attacks. The weight coefficient can be the importance ratio of each security dimension in the comprehensive assessment calculated by the entropy weighting method. It can be used to construct a weighted trust deviation matrix to reflect the differences in contribution between dimensions. The weighted trust deviation matrix can be a structured matrix formed by multiplying the standardized deviation value by the corresponding weight coefficient. It can be used to realize the weighted fusion and structured expression of multi-dimensional security deviations. Furthermore, the weighted trust bias matrix can be implemented by multiplying the standardized bias value of each dimension by its weight and organizing it into a row (node) × column (dimension) matrix.

[0065] The relative security trust coefficient is obtained by calculating the relative deviation ratio of each element in the matrix from the security certification standard value.

[0066] The relative deviation ratio can be the ratio or normalized distance between each element in the weighted trust deviation matrix and its corresponding security certification standard value, and can be used to quantify the degree of deviation of the current state from the ideal security benchmark. Calculating the relative deviation ratio of each element in the matrix from the security certification standard value can be done by calculating the relative error or ratio between the weighted dimension values ​​and their standard values. Obtaining the relative security trust coefficient can be achieved by converting the relative deviation ratio into a trust value using a mapping function (such as 1 − deviation). Furthermore, obtaining the relative security trust coefficient allows the output to be used as a comprehensive credibility index for trust assessment.

[0067] Taking a highway video inspection edge network as an example, the dynamic negotiation authentication method for edge video analysis fused with quantum key distribution in this embodiment can be as follows: The node trust deviation feature spectrum reported by a certain edge video node includes: entropy deviation -0.12 (threshold interval [-0.2, 0]), identity mismatch degree 0.03 (threshold [0, 0.05]), and channel fluctuation +1.8×10⁻ 4 (threshold [0, 2×10⁻) 4 The system first performs normalization, resulting in standardized deviations of 0.6, 0.6, and 0.9. Then, it uses entropy weighting to analyze data from similar nodes across the entire network. It finds that the channel consistency dimension exhibits the least variation (low entropy), thus assigning it a higher weight (e.g., 0.5), while entropy quality and identity matching are weighted at 0.3 and 0.2, respectively. After constructing the weighted trust deviation matrix, the elements are 0.18, 0.12, and 0.45. Comparing this with the security authentication standard value (ideally, the weighted deviation should be close to 0), the total relative deviation ratio is calculated to be 0.75, resulting in a relative security trust coefficient of 0.25 (i.e., 1 − 0.75). This low trust coefficient triggers further system verification, revealing that although the node's identity is legitimate, abnormal channel fluctuations and low key entropy suggest physical tampering. Therefore, its participation in collaborative analysis tasks is restricted.

[0068] In one embodiment, a dynamic trust update model is constructed, and based on this model, the identity trust mapping network is subjected to legitimacy verification and security level assessment to obtain an edge video analytics security authentication graph, including: An attention mechanism model and a GRU temporal trust prediction model are constructed; the quantum entropy fluctuation feature attention mechanism is fused with the GRU model to construct an initial trust prediction model; the initial trust prediction model is trained using historical authentication data to obtain a dynamic trust update model. A sliding time window method is used to extract temporal trust features from the identity trust mapping network, and the extracted features are input into a dynamic trust update model to obtain trust evolution trend prediction results. Based on the trust evolution trend prediction results and channel state features, a security degradation trend curve is constructed. The security degradation trend curve is compared and analyzed with a preset security level threshold to obtain an edge video analysis security authentication map.

[0069] The attention mechanism model is a neural network structure that can assign differentiated weights to different time steps or feature dimensions in the input sequence. It can be used to enhance the model's sensitivity to critical security events (such as abnormal fluctuations in security credentials) and improve feature selection efficiency. The GRU temporal trust prediction model is a sequence prediction model based on gated recurrent units, used to model the temporal evolution of node trust states. It can effectively capture long-term dependencies in historical authentication behavior and support continuous prediction of trust trends. Constructing the attention mechanism model and the GRU temporal trust prediction model can involve designing and initializing the attention module and GRU network structure separately. Furthermore, this operation can be achieved by using a combination of multi-head self-attention and a single-layer GRU, or a combination of channel attention and a bidirectional GRU, thus providing a foundational component with feature focusing and temporal modeling capabilities for subsequent fusion.

[0070] The quantum entropy fluctuation feature attention mechanism can be a customized attention module that uses the random fluctuation features output by the random source as the basis for calculating attention weights. It can be used to focus the model on key fluctuation periods reflecting potential attacks or device failures during the security credential generation process. In one specific embodiment, the quantum entropy fluctuation feature attention mechanism can sample the bitstream from the random source in real time and calculate its local entropy change rate or statistical bias as the basis for attention scoring. The initial trust prediction model can be an untrained base model composed of the quantum entropy fluctuation feature attention mechanism and the GRU temporal trust prediction model. It can be used as a trainable prototype for the dynamic trust update model, integrating temporal modeling and key feature focusing capabilities.

[0071] Integrating the quantum entropy fluctuation feature attention mechanism with the GRU model to construct an initial trust prediction model can be achieved by using quantum entropy fluctuation features as attention weight inputs, guiding the GRU to give higher attention to key time steps. Furthermore, this operation can be implemented by using the attention output as a weighted input to the GRU, or by using the attention weights to adjust the GRU's update gate, thereby enabling joint sensitive modeling of anomalies in security credential generation and changes in trust state. Historical authentication data can be all authentication records completed by edge nodes within a past period and their associated security indicators, used to supervise the training of the initial trust prediction model, allowing it to learn normal and abnormal trust evolution patterns. Training the initial trust prediction model using historical authentication data to obtain a dynamic trust update model can be achieved by using historical trust scores as labels and optimizing model parameters through backpropagation. Furthermore, this operation can be implemented by using a mean squared error loss function for regression training, or by introducing FocalLoss to enhance the learning of low-frequency high-risk samples, thereby enabling the model to learn the normal and abnormal trust evolution patterns from historical patterns.

[0072] The sliding time window method is a technique that extracts local temporal features by sliding a fixed-length window frame by frame across a time series. It is used to capture local dynamic features of trust value changes in an identity trust mapping network. Temporal trust features can be time series segments of trust scores extracted from the identity trust mapping network through the sliding time window. These can be used as input to a dynamic trust update model to characterize the recent trust evolution pattern of nodes. Extracting temporal trust features from an identity trust mapping network using the sliding time window method involves sliding a fixed-length window across the time dimension of the identity trust mapping network to extract continuous trust score sequences. Furthermore, this operation can be implemented by using a 5-minute window that slides every 1 minute, or by dynamically adjusting the window length based on event triggers, thereby generating local temporal features adapted to the input format of the dynamic trust update model.

[0073] The extracted features are input into a dynamic trust update model to obtain a trust evolution trend prediction result. This can be achieved by feeding time-series trust features into a trained fusion model and outputting a trust score prediction for the next N steps. Furthermore, this operation enables a quantitative prediction of the future trend of node trust status. The trust evolution trend prediction result can be the dynamic trust update model's prediction of the direction and magnitude of node trust status changes over a future period, providing a forward-looking basis for security degradation trend modeling. Channel state features can be a set of physical layer or network layer parameters reflecting the quality of the communication link, which can be used as auxiliary input for constructing the security degradation trend curve, distinguishing between channel interference and real security threats. For example, channel state features can include, but are not limited to, one or more of signal-to-noise ratio, bit error rate, and link interruption frequency. Based on the trust evolution trend prediction result and channel state features, a security degradation trend curve is constructed. This can be achieved by fusing the trust prediction value with the current channel quality parameters and fitting a function curve showing the change of security status over time. Furthermore, this operation can be achieved by using a weighted average to fuse trust and channel features and then fitting a curve, or by constructing a dual-input neural network to directly output a degradation curve, thereby distinguishing between temporary trust decline and real security degradation caused by channel jitter.

[0074] The security degradation trend curve can be a trajectory of future changes in node security status generated by combining trust evolution prediction and channel state characteristics. It is used to quantify the development speed and severity of security risks and supports threshold-triggered early warnings. The preset security level thresholds can be a set of critical values ​​pre-defined according to security policies to classify risk levels, serving as decision boundaries for determining whether to trigger an early warning or adjust permissions. Comparing the security degradation trend curve with the preset security level thresholds yields an edge video analysis security authentication map. This allows for determining whether the degradation curve crosses the threshold line within the prediction window and labeling the node's risk level accordingly. Furthermore, this operation allows predictive security assessment results to be mapped onto a visualized authentication map, supporting proactive intervention.

[0075] For example, in the scenario of a highway intelligent monitoring edge cluster, the edge video analysis dynamic negotiation authentication method fused with quantum keys in this embodiment can be as follows: A certain road segment's edge video node recently experienced short-term high-deviation fluctuations in its random source output. Although this did not trigger the expiration of security credentials, it was identified as abnormal by the quantum entropy fluctuation feature attention mechanism. The system uses a sliding time window to extract the node's trust score sequence over the past 30 minutes, inputs it into a dynamic trust update model trained with historical authentication data, and predicts that the trust value will continue to decrease over the next 10 minutes. Simultaneously, channel state characteristics show that the wireless link bit error rate is normal, excluding environmental interference. Based on this, the system constructs a security degradation trend curve, discovering that it will fall below the "high-risk" threshold in 5 minutes. The edge video analysis security authentication graph immediately updates the node's status to "warning," automatically restricting its permission to upload structured analysis results to the central platform, retaining only the original video stream upload, and notifying maintenance personnel to check whether the equipment has been physically tampered with.

[0076] In one embodiment, an edge node security authentication index system is established to conduct a comprehensive security level assessment of the edge video analytics security authentication graph and obtain a dynamic negotiation authentication report, including: Establish a multi-dimensional security authentication index system, including key quality index, identity matching index, trust degradation index, and channel coupling index; based on the multi-dimensional security authentication index system, quantify the security authentication map of edge video analysis to obtain edge security indexes; The various edge security indicators are standardized to obtain a normalized security index; the normalized security index is weighted and fused to obtain a comprehensive security score; the security level of edge nodes is classified based on the comprehensive security score; sensitivity analysis is performed on the normalized security index to obtain a security contribution index; and a dynamic negotiation authentication report is generated based on the edge node security level and security contribution index.

[0077] The multi-dimensional security authentication index system can be a structured evaluation framework composed of multiple specific security dimension indicators, which can be used to decompose abstract security states into quantifiable specific evaluation dimensions. In this embodiment, the multi-dimensional security authentication index system can be constructed based on four core dimensions: key quality, identity matching, trust evolution, and channel state. Furthermore, the multi-dimensional security authentication index system can serve as the calculation basis for edge security indicators and support the generation of comprehensive security scores. The key quality index can be a quantitative parameter that measures the randomness and integrity during quantum key generation and distribution, and can be used to evaluate the unpredictability and tamper resistance of communication keys. In one embodiment, the key quality index can be calculated from the quantum entropy source test results and key error rate statistics. The identity matching degree index can be a measure of the consistency between the current node's behavioral characteristics and the registered identity characteristics, and can be used to identify the risk of identity impersonation or credential theft. In a specific embodiment, the identity matching degree index can be obtained by comparing the real-time collected device fingerprints, behavioral patterns, and benchmark identity database. The trust deterioration degree index can be a parameter that reflects the downward trend or abnormal fluctuation of the node's trust score over time, and can be used to predict potential internal threats or the risk of node hijacking. In this embodiment, the trust deterioration index can be analyzed by slope or variance based on the historical rating sequence of the dynamic trust update model.

[0078] Channel coupling indexes can be parameters describing the stability of communication channels and the correlation between channel states among multiple nodes, and can be used to assess the possibility of network interference and coordinated attacks. In an exemplary embodiment, the channel coupling index can be obtained by analyzing the correlation between signal strength, packet loss rate, and cross-node channel noise. Edge security indicators can be raw security data sets quantified based on a multi-dimensional security authentication indicator system, and can be used to provide raw input data for standardization processing. In this embodiment, edge security indicators can be obtained by extracting and calculating data from each dimension of the edge video analysis security authentication graph. Furthermore, edge security indicators can be a preprocessing object for normalized security indices.

[0079] Establishing a multi-dimensional security authentication indicator system can involve defining specific calculation formulas and collection frequencies for four dimensions: key quality, identity matching degree, trust degradation degree, and channel coupling degree. Furthermore, this system can be established by determining indicator weights and definitions based on expert experience, or by extracting key indicators through cluster analysis of historical security event data, thereby constructing a structured and quantifiable security assessment framework. Quantifying the security authentication graph of edge video analysis based on this multi-dimensional indicator system can be achieved by extracting the original data corresponding to each dimension of the nodes in the security authentication graph and substituting them into the indicator formulas. This operation can be further implemented through real-time streaming calculation of indicator values ​​or batch calculation of indicator statistics based on time windows, thus transforming the topological and state information in the graph into numerical edge security indicators. Standardizing the various edge security indicators can be achieved by using mathematical transformation methods to map indicators with different dimensions to a unified numerical range. A normalized security index can be a standardized security value that is comparable after eliminating dimensional differences, used to address assessment biases caused by inconsistencies in the numerical ranges of indicators across different dimensions.

[0080] The comprehensive security score can be a numerical value representing the overall security status of a node after aggregating various normalized security indices. It can be used to provide a quantitative description of the overall security situation from a single dimension. In this embodiment, the comprehensive security score can be obtained by aggregating the normalized indices of each dimension using a weighted summation or geometric mean method. Furthermore, the comprehensive security score can serve as a direct basis for classifying the security levels of edge nodes. Classifying the security levels of edge nodes based on the comprehensive security score can be achieved by setting multiple threshold breakpoints, mapping continuous comprehensive scores to discrete security level labels. Further, this operation can be implemented using an equidistant threshold division method or a quantile division method based on historical data distribution, thereby enabling hierarchical management of security status and facilitating the execution of differentiated strategies.

[0081] Edge node security levels can be discrete security status categories based on comprehensive security scores, which can be used to achieve hierarchical management of security status and differentiated policy execution. In an exemplary embodiment, edge node security levels can map continuous comprehensive scores to a finite number of level labels by setting threshold ranges. Sensitivity analysis of the normalized security index can be performed by fine-tuning the values ​​of each normalized index and observing the magnitude of changes in the comprehensive score. Furthermore, this operation can be achieved by calculating local sensitivity based on partial derivatives or by performing global sensitivity analysis based on Monte Carlo simulations, thereby identifying the key risk factors that have the greatest impact on overall security.

[0082] Security contribution indicators can be sensitive parameters characterizing the degree of influence of individual security indicators on the overall security score. They can be used to identify key factors leading to security risks and guide precise rectification. In one specific embodiment, the security contribution indicator can be used to assess the marginal impact of indicator changes on the comprehensive score through perturbation analysis or gradient calculation. Generating a dynamic negotiation certification report based on the edge node security level and security contribution indicator can combine security level labels with high-contribution risk indicators to generate a structured document containing rectification recommendations. Furthermore, this operation can be achieved by generating a visual report containing a risk heatmap or a text report containing automated script suggestions, enabling managers not only to know whether the system is safe, but also where and why it is unsafe.

[0083] Taking a financial park edge video surveillance network as an example, the dynamic negotiation authentication method for edge video analysis using fused quantum keys in this embodiment requires edge video nodes deployed in the financial park to undergo strict security authentication. The system first establishes a multi-dimensional security authentication index system, setting four dimensions: key quality, identity matching degree, trust degradation degree, and channel coupling degree. Recently, a node's quantum key error rate has slightly increased (key quality index decreased), and its nighttime video upload behavior pattern differs significantly from daytime (identity matching degree index fluctuates). The system standardizes each edge security index, eliminating dimensional differences to obtain a normalized security index. A weighted fusion calculation yields a comprehensive security score of 65 points (out of 100). Based on a preset threshold, this node is classified as "observation and monitoring level." Sensitivity analysis shows that the key quality index contributes the most to the score decrease (security contribution index). The generated dynamic negotiation authentication report recommends: "Prioritize checking quantum key distribution link loss, and secondly, verify the legality of nighttime services." Based on this, the administrator adjusts the node's access permissions, restricting it to uploading only low-resolution videos and triggering an automatic operation and maintenance script to detect the physical state of the quantum channel, achieving precise governance.

[0084] In one embodiment, the normalized security index is weighted and fused to obtain a comprehensive security score, including: A security assessment matrix is ​​constructed, and each normalized security index is mapped to a security risk probability. The fuzzy comprehensive evaluation method is used to calculate the membership degree of the security risk probability to obtain a fuzzy security vector. The weight of each index is determined based on the security contribution index, and the fuzzy security vector is weighted and summed. The weighted result is mapped to the scoring interval [0, 100] to obtain a comprehensive security score.

[0085] The security assessment matrix can be a two-dimensional data structure describing the mapping relationship between security indicators and risk levels. It can be used to transform deterministic numerical indicators into probability distributions to address data ambiguity. In this embodiment, the security assessment matrix can be constructed by statistically analyzing historical security event data or by pre-setting expert rules to build a table of correspondence between indicators and probabilities. Constructing the security assessment matrix can involve defining a set of indicators and a set of risk assessment statements, and establishing an initial mapping relationship between them. For example, the security assessment matrix can be constructed by building a matrix based on the statistical frequency of historical failure data or by pre-setting risk mapping rules based on expert scoring methods, thereby providing a structured foundation for subsequent probability mapping. The security risk probability can be a numerical value characterizing the likelihood of a specific security indicator triggering a risk event, and can be used to quantify the probability of potential threats occurring in uncertain environments. In an exemplary embodiment, the security risk probability can be calculated based on a normalized security index using a probability density function or a mapping table. Mapping each normalized security index to a security risk probability can be achieved by using a probability distribution function to convert the standardized indicator values ​​into risk occurrence probabilities. In one specific embodiment, this operation can be achieved by using the Sigmoid function for nonlinear probability mapping or by using the Gaussian distribution function for probability density calculation, thereby transforming deterministic values ​​into probability distributions to address the ambiguity in edge security data.

[0086] The fuzzy comprehensive evaluation method can be used to calculate the membership degree of safety risk probabilities by selecting a membership function to operate on the risk probabilities and generate a fuzzy vector. Furthermore, this operation can be achieved by using the maximum-minimum composition operator for fuzzy computation or by using a weighted average operator for fuzzy synthesis, thus avoiding the oversensitivity of traditional linear weighting methods to extreme values ​​and accurately reflecting the gradual change process. The fuzzy safety vector can be an array representing the degree of belonging to each risk level after membership degree calculation, which can be used to reflect the gradual distribution of node safety status among different risk levels. In one embodiment, the fuzzy safety vector can be generated by using the fuzzy comprehensive evaluation method to operate on the membership function of safety risk probabilities. The indicator weight can be a coefficient reflecting the relative importance of each safety indicator in the comprehensive assessment, which can be used to ensure that key risk factors dominate the scoring. In this embodiment, the indicator weight can be dynamically calculated based on the safety contribution indicator; previous schemes may have used the entropy weight method or the analytic hierarchy process. Determining the weight of each indicator based on the safety contribution indicator can be done by reading the contribution value obtained from sensitivity analysis and normalizing it into a weight coefficient. Furthermore, this operation can be achieved by directly using the contribution ratio as a weight or by exponentially smoothing the contribution ratio before using it as a weight, thereby ensuring that key risk factors dominate the scoring and that the scoring reflects the true threat.

[0087] Weighted summation of a fuzzy safety vector can be achieved by multiplying each component of the fuzzy vector by its corresponding index weight and then summing the results. In an exemplary embodiment, this operation can be implemented using an arithmetic weighted average or a geometric weighted average, thereby fusing multidimensional fuzzy information to obtain a single quantified value. The scoring interval [0, 100] can be used to standardize the numerical range of the comprehensive safety status output, enabling standardized quantified output of the safety status for easy and intuitive comparison. Mapping the weighted result to the scoring interval [0, 100] can be achieved by scaling or function transformation to constrain the summation result to between 0 and 100. For example, this operation can be implemented using a linear scaling formula or a piecewise linear interpolation method, thereby achieving standardized quantified output of the safety status.

[0088] For example, in the scenario of an edge video surveillance network in a smart park, the edge video analysis dynamic negotiation authentication method with fused quantum keys in this embodiment can be as follows: After processing the multi-dimensional authentication data of an edge video node, a normalized security index is obtained, where the key quality index is 0.8 and the identity matching index is 0.6. The system constructs a security evaluation matrix and uses a Gaussian distribution function to map these indices to security risk probabilities. Then, a fuzzy comprehensive evaluation method is used, selecting a triangular membership function to calculate the fuzzy security vector. The system reads the security contribution index generated by the previous sensitivity analysis and finds that the key quality contribution is the highest, thus determining the weight of each index. After weighted summation of the fuzzy security vector, the result is mapped to the [0, 100] scoring interval through linear scaling, finally obtaining a comprehensive security score of 75. This score intuitively reflects that the node is currently in a medium security state, and due to the dynamic adjustment of weights, the score accurately reflects the main impact of key quality fluctuations, providing accurate data support for the subsequent generation of dynamic negotiation authentication reports.

[0089] In one embodiment, generating a security alert decision based on the dynamic negotiation authentication report includes: Based on the dynamic negotiation authentication report, high-risk nodes and key security parameters are identified, matched with the historical security handling case library, and the optimal access control scheme is inferred; the urgency of handling is assessed based on the security level and trust evolution trend prediction results, and a dynamically updated priority is generated. Based on dynamic update priorities and edge video analytics business plans, key negotiation update window recommendations are formulated; targeted identity authentication hardening strategies are generated according to risk types and security contribution indicators; and security early warning decisions are made based on key negotiation update window recommendations and identity authentication hardening strategies.

[0090] High-risk nodes can be edge video nodes identified as posing significant security threats or exhibiting abnormal behavior in the current security assessment, and can be prioritized for security early warning and response strategies. Key security parameters are core quantitative indicators affecting node security status assessments, used to identify root causes of risks and guide hardening measures design. For example, key security parameters may include, but are not limited to, one or more of key entropy, channel bit error rate, and authentication failure frequency. A historical security handling case library is a knowledge base storing past security events and their corresponding handling strategies, supporting policy migration and automatic inference based on similar scenarios. In one specific embodiment, the historical security handling case library can be continuously accumulated through log archiving, expert annotation, or reinforcement learning feedback. The optimal access control scheme can be a combination of least privilege access policies generated for the current risk scenario, used to limit the spread of potential threats while ensuring business continuity. Trust evolution trend prediction results can be future trust score change trends output by a dynamic trust update model, used to predict node security status trends and support proactive responses. The urgency assessment can be a quantitative determination of the time window for responding to security threats, used to differentiate between emergency intervention and routine optimization, improving response efficiency. Dynamic update priority can be a weighted execution order of different nodes or strategies based on urgency assessment results, which can be used to guide the allocation of system resources in multi-task security updates.

[0091] Edge video analytics service plans can be scheduling information describing the computation, bandwidth, and task load arrangements of edge nodes over a future period. This can be used as a constraint for planning security update timing to avoid interfering with critical business operations. Key negotiation update window recommendations can be key refresh execution time periods recommended by combining the service plan with security priorities. This can be used to achieve spatiotemporal coordination between security updates and business operations. Risk types can be classifications of the nature of security threats, which can guide the selection of differentiated defense strategies. Security contribution metrics can be quantitative values ​​measuring the importance or influence of a node in a collaborative security network. This can be used to weigh the return on investment of hardening strategies and prioritize the protection of critical nodes. Identity authentication hardening strategies can be enhanced authentication mechanisms customized for specific risk types and node importance, which can be used to improve the authentication strength of high-risk or high-value nodes.

[0092] Based on dynamic negotiation authentication reports, high-risk nodes and key security parameters are identified. This can be achieved by analyzing trust scores, security levels, and anomaly indicators in the authentication reports to filter out nodes below a threshold and their associated parameters. Furthermore, this operation can be implemented by setting multi-dimensional threshold rules or using anomaly detection models, thereby accurately locating the objects requiring intervention and the causes of their risks. Matching historical security handling case libraries to infer the optimal access control scheme can be done by comparing the characteristics of current high-risk nodes with event patterns in the case library to retrieve the most suitable access control policy. Furthermore, this operation can be achieved through semantic similarity matching based on vector embedding or condition-action mapping based on rule engines, thereby enabling policy reuse and intelligent recommendation, reducing delays in manual decision-making. Based on security level and trust evolution trend prediction results, the urgency of handling is assessed. This can be done by combining the current security level with future trust trends to determine whether immediate response is needed or can be postponed. Furthermore, this operation can be achieved by constructing an urgency scoring function that integrates current and predicted indicators or using a decision tree model to classify urgency levels, thereby enabling tiered scheduling of threat responses. Generating dynamically updated priorities can transform urgency assessment results into executable priority labels or numerical weights, thereby providing a sorting basis for subsequent resource scheduling.

[0093] Based on dynamic update priorities and edge video analytics business plans, a key negotiation update window recommendation is formulated. This can be achieved by prioritizing key update tasks during periods of low business load. Furthermore, this operation can be implemented through a time slot reservation mechanism or by using reinforcement learning to optimize the update sequence of multiple nodes, thereby balancing security and service quality and avoiding business interruptions. Based on risk type and security contribution indicators, targeted identity authentication hardening strategies are generated. This can be achieved by combining risk categories (such as forged access) with node importance and selecting corresponding authentication enhancement methods. Further, this operation can be implemented by enabling biometric + quantum key dual-factor authentication for high-contribution + high-risk nodes, and only increasing the key refresh frequency for low-contribution + low-risk nodes, thereby achieving resource-efficient and precise risk-based defense enhancement. The key negotiation update window recommendation and identity authentication hardening strategy constitute a security early warning decision. This can be achieved by packaging the update timing recommendation and authentication strategy into a structured instruction set for the execution engine to call, thus forming an automatically executable closed-loop security response scheme.

[0094] Taking a video surveillance edge network in a key urban area as an example, the dynamic negotiation authentication method for edge video analysis using fused quantum keys in this embodiment can be as follows: An edge video node at an intersection is marked as high-risk in the dynamic negotiation authentication report due to frequent requests to unauthorized database interfaces. Its key security parameters show a sharp drop in trust score and a low key entropy value. The system matches similar "internal abnormal behavior" cases from the historical security handling case library and infers that its database access permissions should be temporarily restricted. Considering that the node's current security level is "high-risk" and the trust evolution trend predicts that it may completely fail within 2 hours, the urgency assessment result is "immediate blocking level," generating the highest dynamic update priority. Considering that the area where the node is located is about to enter the evening peak video collection period (edge ​​video analysis business plan), the system recommends setting the key negotiation update window to the low-load period of 02:00–03:00 that evening. At the same time, due to its high security contribution in road network collaborative analysis, the system generates an identity authentication reinforcement strategy: enabling two-factor authentication based on face + device fingerprint, and shortening the high-security key refresh cycle from 10 minutes to 2 minutes. Ultimately, the aforementioned window period recommendations, together with the hardening strategies, constitute a security early warning decision, which is automatically deployed by the edge controller.

[0095] In addition, refer to Figure 2 To achieve the above objectives, the present invention also provides an edge video analysis dynamic negotiation authentication device that integrates quantum key distribution, the device comprising: The key synchronization module 10 is used to acquire multi-dimensional authentication data of edge video nodes, perform identity encoding and key synchronization on the multi-dimensional authentication data, and obtain a dynamic negotiation key pool. Trust modeling module 20 performs quantum entropy source verification and integrity authentication analysis on the dynamic negotiation key pool, constructs a trust degree coupling evaluation model, analyzes cross-node authentication correlation, and obtains the identity trust mapping network. The graph construction module 30 constructs a dynamic trust update model, and performs legality verification and security level assessment on the identity trust mapping network based on the dynamic trust update model, thereby obtaining the edge video analysis security authentication graph. The comprehensive evaluation module 40 establishes an edge node security certification index system, conducts a comprehensive security level assessment of the edge video analysis security certification map, and obtains a dynamic negotiation certification report. The dynamic control module 50 generates security early warning decisions based on the dynamic negotiation authentication report and realizes real-time identity authentication and dynamic adjustment of access permissions based on quantum key distribution.

[0096] Other embodiments or specific implementations of the edge video analysis dynamic negotiation authentication device with fused quantum key distribution described in this invention can be referred to the above-described method embodiments, and will not be repeated here.

[0097] The above are merely preferred embodiments of the present invention and do not limit the scope of the patent. Any equivalent structural or procedural transformations made based on the description and drawings of the present invention, or direct or indirect applications in other related technical fields, are similarly included within the scope of patent protection of the present invention.

Claims

1. A dynamic negotiation authentication method for edge video analysis incorporating quantum key distribution, characterized in that, The method includes: Obtain multi-dimensional authentication data from edge video nodes, encode the multi-dimensional authentication data for identity and synchronize the key, and obtain a dynamic negotiation key pool; Quantum entropy source verification and integrity authentication analysis are performed on the dynamic negotiation key pool. A trust degree coupling evaluation model is constructed, cross-node authentication correlation is analyzed, and an identity trust mapping network is obtained. A dynamic trust update model is constructed, and the identity trust mapping network is validated and its security level is assessed based on the dynamic trust update model, thereby obtaining a security authentication graph for edge video analysis. Establish an edge node security authentication index system, conduct a comprehensive security level assessment of the edge video analysis security authentication map, and obtain a dynamic negotiation authentication report; Security alert decisions are generated based on the dynamic negotiation authentication report, and real-time identity authentication and dynamic adjustment of access permissions are achieved based on quantum key distribution.

2. The edge video analysis dynamic negotiation authentication method with fused quantum key distribution as described in claim 1, characterized in that, The process of acquiring multi-dimensional authentication data from edge video nodes, performing identity encoding and key synchronization on the multi-dimensional authentication data, and obtaining a dynamically negotiated key pool includes: Acquire multi-dimensional authentication data of edge video nodes, including node identity data, quantum random number data, channel feature perception data, and video analysis service data; Entropy value verification and true randomness extraction are performed on quantum random number data to obtain native quantum key characteristics; hash operation and digital signature are performed on node identity identification data to obtain identity authentication characteristics; Time-domain fluctuation analysis is performed on channel feature sensing data to obtain channel state characteristics; permission level extraction is performed on video analysis service data to obtain service access characteristics; identity coupling analysis is performed based on native quantum key characteristics and identity authentication characteristics to obtain identity key correlation coefficients. The channel state characteristics are corrected based on the identity key association coefficient to obtain the true channel impact characteristics; time alignment and spatial registration are performed based on the true channel impact characteristics, native quantum key characteristics, identity authentication characteristics and service access characteristics to construct a dynamic negotiation key pool.

3. The edge video analysis dynamic negotiation authentication method with fused quantum key distribution as described in claim 2, characterized in that, The process of performing entropy verification and true randomness extraction on quantum random number data to obtain native quantum key characteristics includes: The NIST randomness test standard was used to verify the entropy source integrity of quantum-generated random numbers to obtain a random number qualification mark; the minimum entropy, collision entropy and deviation from the ideal uniform distribution of the random sequence were calculated to construct the entropy parameter matrix; Randomness analysis is performed based on the entropy parameter matrix to generate quantum key quality classification results; the randomness deviation and relative pass probability of different segments of the same key sequence are calculated to construct key quality feature vectors, which constitute the original quantum key features.

4. The edge video analysis dynamic negotiation authentication method with fused quantum key distribution as described in claim 1, characterized in that, The process of performing quantum entropy source verification and integrity authentication analysis on the dynamic negotiation key pool, constructing a trust coupling evaluation model, analyzing cross-node authentication correlations, and obtaining an identity trust mapping network includes: The quantum random entropy, identity information, and channel characteristic parameters in the dynamic negotiation key pool are compared with the security authentication standard values ​​to obtain the parameter compliance level index; the entropy deviation, identity mismatch degree, and channel abnormal fluctuation amount within the same authentication period are calculated to construct the node trust deviation feature spectrum; the node trust deviation feature spectrum is dimensionless to obtain the relative security trust coefficient. Based on parameter compliance level indicators and relative security trust coefficients, a trust-coupled evaluation model is constructed; multivariate correlation analysis is performed on native quantum key characteristics, identity authentication characteristics and channel impact characteristics to obtain a cross-node correlation matrix; Key security influencing factors are identified based on cross-node association matrices, and a trust association network is constructed. Security features are extracted based on the trust association network and the trust degree coupling evaluation model to obtain an identity trust mapping network.

5. The edge video analysis dynamic negotiation authentication method with fused quantum key distribution as described in claim 4, characterized in that, The step of performing dimensionless processing on the node trust bias feature spectrum to obtain the relative security trust coefficient includes: Set a trust bias threshold range, normalize the node trust bias feature spectrum, and obtain the standardized bias value. The entropy weight method is used to determine the weight coefficients of quantum entropy quality, identity matching degree, and channel consistency; a weighted trust deviation matrix is ​​constructed based on the standardized deviation value and the weight coefficients. The relative security trust coefficient is obtained by calculating the relative deviation ratio of each element in the matrix from the security certification standard value.

6. The edge video analysis dynamic negotiation authentication method with fused quantum key distribution as described in claim 1, characterized in that, The construction of a dynamic trust update model, based on which the identity trust mapping network is validated and its security level assessed, yields a security authentication graph for edge video analytics, including: An attention mechanism model and a GRU temporal trust prediction model are constructed; the quantum entropy fluctuation feature attention mechanism is fused with the GRU model to construct an initial trust prediction model; the initial trust prediction model is trained using historical authentication data to obtain a dynamic trust update model. A sliding time window method is used to extract temporal trust features from the identity trust mapping network, and the extracted features are input into a dynamic trust update model to obtain trust evolution trend prediction results. Based on the trust evolution trend prediction results and channel state features, a security degradation trend curve is constructed. The security degradation trend curve is compared and analyzed with a preset security level threshold to obtain an edge video analysis security authentication map.

7. The edge video analysis dynamic negotiation authentication method with fused quantum key distribution as described in claim 1, characterized in that, The establishment of an edge node security authentication index system, the comprehensive security level assessment of the edge video analysis security authentication graph, and the acquisition of a dynamic negotiation authentication report include: Establish a multi-dimensional security authentication index system, including key quality index, identity matching index, trust degradation index, and channel coupling index; based on the multi-dimensional security authentication index system, quantify the security authentication map of edge video analysis to obtain edge security indexes; The various edge security indicators are standardized to obtain a normalized security index; the normalized security index is weighted and fused to obtain a comprehensive security score; the security level of edge nodes is classified based on the comprehensive security score; sensitivity analysis is performed on the normalized security index to obtain a security contribution index; and a dynamic negotiation authentication report is generated based on the edge node security level and security contribution index.

8. The edge video analysis dynamic negotiation authentication method with fused quantum key distribution as described in claim 7, characterized in that, The weighted fusion of the normalized security indices to obtain a comprehensive security score includes: A security assessment matrix is ​​constructed, and each normalized security index is mapped to a security risk probability. The fuzzy comprehensive evaluation method is used to calculate the membership degree of the security risk probability to obtain a fuzzy security vector. The weight of each index is determined based on the security contribution index, and the fuzzy security vector is weighted and summed. The weighted result is mapped to the scoring interval [0,100] to obtain a comprehensive security score.

9. The edge video analysis dynamic negotiation authentication method with fused quantum key distribution as described in claim 1, characterized in that, The generation of security warning decisions based on dynamic negotiation authentication reports includes: Based on the dynamic negotiation authentication report, high-risk nodes and key security parameters are identified, matched with the historical security handling case library, and the optimal access control scheme is inferred; the urgency of handling is assessed based on the security level and trust evolution trend prediction results, and a dynamically updated priority is generated. Based on dynamic update priorities and edge video analytics business plans, key negotiation update window recommendations are formulated; targeted identity authentication hardening strategies are generated according to risk types and security contribution indicators; and security early warning decisions are made based on key negotiation update window recommendations and identity authentication hardening strategies.

10. A dynamic negotiation and authentication device for edge video analysis incorporating quantum key distribution, characterized in that, The device includes: The key synchronization module is used to acquire multi-dimensional authentication data of edge video nodes, encode the multi-dimensional authentication data for identity and synchronize the key to obtain a dynamic negotiation key pool. The trust modeling module performs quantum entropy source verification and integrity authentication analysis on the dynamic negotiation key pool, constructs a trust degree coupling evaluation model, analyzes cross-node authentication correlation, and obtains the identity trust mapping network. The graph construction module builds a dynamic trust update model, and performs legality verification and security level assessment on the identity trust mapping network based on the dynamic trust update model, thereby obtaining a security authentication graph for edge video analysis. The comprehensive assessment module establishes a security certification index system for edge nodes, conducts a comprehensive security level assessment of the edge video analysis security certification graph, and obtains a dynamic negotiation certification report. The dynamic control module generates security warning decisions based on the dynamic negotiation authentication report and realizes real-time dynamic adjustment of identity authentication and access permissions based on quantum key distribution.