A cloud-edge collaborative secure access method, device and equipment based on a cache mechanism
By setting up a connection cache table and blacklist mechanism in the cloud-edge collaborative system and using effective connection cache and session keys for terminal access, the problems of network resource waste and synchronization in the Internet of Things system are solved, and efficient terminal management and secure access are achieved.
Patent Information
- Application Number
- CN202211114361.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-14
- Publication Date
- 2025-09-16
- Estimated Expiration
- 2042-09-14
AI Technical Summary
The existing IoT system faces the problem of wasting network resources when facing massive IoT terminal access. Especially when terminal device resources are limited, frequent authentication and connection processes will consume a lot of network resources, and it is difficult to synchronize information between multiple edge nodes.
A cloud-edge collaborative secure access method based on a cache mechanism is adopted. By setting up connection cache tables in terminals, edge nodes and the cloud, the effective connection cache is queried and used for fast connection, repeated authentication is reduced, session keys are used for communication, and the blacklist cache is updated when necessary to synchronize access policies.
It reduces the waste of network resources during terminal access, achieves fast reconnection and encrypted communication, solves the synchronization problem of multiple edge nodes, and improves the synchronization and security of terminal management.
Smart Images

Figure CN115714661B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular to a cloud-edge collaborative secure access method, device and equipment based on a caching mechanism. Background Art
[0002] As the construction of smart IoT systems advances and the scope of IoT perception continues to expand, edge IoT proxies, serving as aggregation access nodes for IoT terminals, have gradually been adopted in various business scenarios. Faced with the access of a wide variety of business terminals with different protocols, especially in scenarios involving massive IoT terminal access, existing IoT systems will face new security challenges.
[0003] Limitations in IoT access and overall management primarily stem from resource constraints on terminal devices, making complex security policies unsupportable on the terminal side. The movement of IoT devices or their frequent joining and leaving the network can cause dramatic changes in network topology. Frequent authentication and connection processes consume significant network resources, creating performance bottlenecks. Especially when a terminal is connected to multiple edge nodes, information synchronization between them becomes difficult. Even if one edge node has already stored the terminal's connection information, other edge nodes still need to reauthenticate before they can connect. Frequent authentication can waste network resources. Summary of the Invention
[0004] In view of this, an embodiment of the present invention provides a cloud-edge collaborative secure access method, apparatus and device based on a caching mechanism to solve the problem of network resource waste during terminal access.
[0005] The technical solutions proposed by the present invention are as follows:
[0006] A first aspect of an embodiment of the present invention provides a cloud-edge collaborative secure access method based on a cache mechanism, comprising: receiving a connection request sent by a terminal, wherein the connection request is generated after the terminal queries its own connection cache table to determine that there is a valid connection cache between the terminal and the edge node and that the network quality requirements are met, and the valid connection cache includes a session key; querying the connection cache table of the local edge node and the connection cache table of other reachable edge nodes to see whether there is the valid connection cache of the terminal; when the valid connection cache exists in the connection cache table of the local edge node or the connection cache table of the other reachable edge nodes, establishing a connection with the terminal according to the session key; when the valid connection cache does not exist in the connection cache table of the local edge node or the connection cache table of the other reachable edge nodes, sending a feedback message to the terminal indicating rejection of the connection and re-authentication.
[0007] Optionally, receive an authentication request sent by the terminal, where the authentication request is generated after the terminal receives the feedback message sent by the edge node; query whether the terminal is in its own blacklist cache or the blacklist cache in the cloud; if the terminal is in its own blacklist cache or the blacklist cache in the cloud, refuse to authenticate the authentication request, otherwise perform two-way authentication with the terminal and establish a connection.
[0008] Optionally, after performing two-way authentication with the terminal, the method further includes: generating connection information and storing the connection information in the connection cache table of the local edge node, the connection cache table of the terminal, and the connection cache table of the cloud.
[0009] Optionally, when the valid connection cache exists in the connection cache table of the local edge node or the connection cache table of the other reachable edge node, a connection is established with the terminal based on the session key, including: when there is a valid connection cache in the connection cache table of the local edge node, a connection is established with the terminal based on the session key; when the valid connection cache does not exist in the connection cache table of the local edge node and there is a valid connection cache in the connection cache table of the other reachable edge node, a connection is established with the terminal based on the session key between the local edge node and the terminal generated by the other reachable edge node.
[0010] Optionally, after establishing a connection with the terminal, it also includes: collecting information uploaded by the terminal; preprocessing and standardizing the collected information to obtain a data copy; extracting features from the data copy, and classifying the extracted features based on an anomaly detection model, and judging whether the terminal behavior is malicious based on the classification results; when the terminal behavior is malicious, generating an alarm message and sending it to the cloud, and the alarm message is stored in a blacklist cache on the cloud.
[0011] Optionally, the cloud-edge collaborative secure access method based on the caching mechanism also includes: when the terminal behavior is non-malicious, classifying and integrating the data copies and adding application tags, merging and compressing the same type of data and uploading them to the cloud; receiving blacklist synchronization information sent by the cloud, the blacklist synchronization information is the cloud classifying the uploaded data according to the anomaly detection model, and when the terminal behavior is judged to be malicious based on the classification result, it is sent to the edge node with the effective connection cache with the terminal; updating its own blacklist cache according to the blacklist synchronization information.
[0012] Optionally, the cloud-edge collaborative secure access method based on the caching mechanism also includes: when the terminal behavior is non-malicious, classifying and integrating the data copies and adding application tags, merging and compressing the same type of data and uploading them to the cloud; saving and pushing the non-malicious data to the corresponding application through the cloud, and the non-malicious data is the data corresponding to the classification of the uploaded data by the cloud according to the anomaly detection model, and judging the terminal behavior as non-malicious according to the classification results.
[0013] The second aspect of an embodiment of the present invention provides a cloud-edge collaborative security access device based on a cache mechanism, including: a request receiving module, used to receive a connection request sent by a terminal, the connection request is generated after the terminal queries its own connection cache table, determines that there is a valid connection cache between the terminal and the edge node and meets the network quality requirements, and the valid connection cache includes a session key; a cache query module, used to query the connection cache table of the local edge node and the connection cache table of other reachable edge nodes whether there is the valid connection cache of the terminal; a connection establishment module, used to establish a connection with the terminal according to the session key when the valid connection cache exists in the connection cache table of the local edge node or the connection cache table of the other reachable edge nodes; a connection rejection module, used to send a feedback message indicating connection rejection and re-authentication to the terminal when the valid connection cache does not exist in the connection cache table of the local edge node or the connection cache table of the other reachable edge nodes.
[0014] Optionally, the cloud-edge collaborative security access device based on the caching mechanism also includes: an authentication request receiving module, used to receive the authentication request sent by the terminal, and the authentication request is generated after the terminal receives the feedback message sent by the edge node; a blacklist query module, used to query whether the terminal is in its own blacklist cache or the blacklist cache in the cloud; an authentication judgment module, used to refuse to authenticate the authentication request when the terminal is in its own blacklist cache or the blacklist cache in the cloud, otherwise perform two-way authentication with the terminal and establish a connection.
[0015] Optionally, the cloud-edge collaborative security access device based on the cache mechanism also includes: a storage module, which is used to generate connection information after performing two-way authentication with the terminal and save the connection information in the connection cache table of the local edge node, the connection cache table of the terminal and the connection cache table of the cloud.
[0016] Optionally, the connection establishment module includes: a first connection sub-module, used to establish a connection with the terminal based on the session key when there is a valid connection cache in the connection cache table of the local edge node; a second connection sub-module, used to establish a connection with the terminal based on the session key between the local edge node and the terminal generated by the other reachable edge node when there is no valid connection cache in the connection cache table of the local edge node and there is a valid connection cache in the connection cache table of the other reachable edge node.
[0017] Optionally, the cloud-edge collaborative security access device based on the caching mechanism also includes: a collection module for collecting information uploaded by the terminal; a data processing module for preprocessing and standardizing the collected information to obtain a data copy; a detection module for extracting features from the data copy, and classifying the extracted features based on an anomaly detection model, and judging whether the terminal behavior is malicious based on the classification results; an alarm module, which generates an alarm message and sends it to the cloud when the terminal behavior is malicious, and the alarm information is stored in the blacklist cache of the cloud.
[0018] Optionally, the cloud-edge collaborative security access device based on the caching mechanism also includes: a first data upload module, which is used to classify and integrate data copies and add application tags when the terminal behavior is non-malicious, and to merge and compress data of the same type and upload them to the cloud; a synchronization module, which is used to receive blacklist synchronization information sent by the cloud, and the blacklist synchronization information is sent by the cloud to the edge node that has the effective connection cache with the terminal when the cloud classifies the uploaded data according to the anomaly detection model and judges that the terminal behavior is malicious based on the classification result; an update module, which is used to update its own blacklist cache according to the blacklist synchronization information.
[0019] Optionally, the cloud-edge collaborative security access device based on the caching mechanism also includes: a second data uploading module, which is used to classify and integrate the data copies and add application tags when the terminal behavior is non-malicious, and to fuse and compress the same type of data and upload them to the cloud; a saving and pushing module, which is used to save and push non-malicious data to the corresponding application through the cloud, and the non-malicious data is the data corresponding to the classification of the uploaded data by the cloud according to the anomaly detection model, and the judgment based on the classification result that the terminal behavior is non-malicious.
[0020] A third aspect of an embodiment of the present invention provides an electronic device, comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, the memory storing computer instructions, and the processor executing the computer instructions to execute the cloud-edge collaborative secure access method based on the caching mechanism as described in the first aspect of the embodiment of the present invention.
[0021] The fourth aspect of an embodiment of the present invention provides a computer-readable storage medium, which stores computer instructions, and the computer instructions are used to enable the computer to execute the cloud-edge collaborative secure access method based on the caching mechanism as described in the first aspect of the embodiment of the present invention.
[0022] It can be seen from the above technical solutions that the embodiments of the present invention have the following advantages:
[0023] An embodiment of the present invention provides a cloud-edge collaborative secure access method, apparatus and equipment based on a cache mechanism, the method comprising: receiving a connection request sent by a terminal, the connection request being generated after the terminal queries its own connection cache table to determine whether there is a valid connection cache between the terminal and the edge node and that network quality requirements are met, the valid connection cache including a session key; querying the connection cache table of the local edge node and the connection cache table of other reachable edge nodes to determine whether there is the valid connection cache of the terminal; when the valid connection cache exists in the connection cache table of the local edge node or the connection cache table of the other reachable edge nodes, establishing a connection with the terminal according to the session key; when the valid connection cache does not exist in the connection cache table of the local edge node or the connection cache table of the other reachable edge nodes, sending a feedback message to the terminal indicating connection rejection and re-authentication. The embodiment of the present invention sets a connection cache table to query whether there is a valid connection cache. When both the terminal and the edge node have a valid connection cache, they can connect based on the valid connection cache, and the edge node can query whether there is a valid connection cache of the terminal in the connection cache table of other reachable edge nodes, thereby expanding the range of the terminal's rapid reconnection. When the terminal is offline for some reason, it can still use the cached session key for communication after it comes back online within the valid time, reducing the resource overhead of re-authentication and solving the problem of network resource waste during terminal access. BRIEF DESCRIPTION OF THE DRAWINGS
[0024] In order to more clearly express the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for describing the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0025] Figure 1 This is a flow chart of a cloud-edge collaborative secure access method based on a cache mechanism in an embodiment of the present invention;
[0026] Figure 2 A schematic diagram of the structure of a connection cache table of a terminal in an embodiment of the present invention;
[0027] Figure 3 This is a schematic diagram of the structure of a connection cache table of an edge node in an embodiment of the present invention;
[0028] Figure 4 This is a schematic diagram of the structure of the cloud connection cache table in an embodiment of the present invention;
[0029] Figure 5 This is a schematic diagram of the structure of a blacklist cache table in an embodiment of the present invention;
[0030] Figure 6 This is a flowchart of another cloud-edge collaborative secure access method based on a caching mechanism in an embodiment of the present invention;
[0031] Figure 7 This is a flowchart of another cloud-edge collaborative secure access method based on a caching mechanism in an embodiment of the present invention;
[0032] Figure 8 This is a module block diagram of a cloud-edge collaborative secure access device based on a caching mechanism in an embodiment of the present invention;
[0033] Figure 9 This is a schematic structural diagram of an electronic device according to an embodiment of the present invention;
[0034] Figure 10 Schematic diagram of the structure of a computer-readable storage medium in an embodiment of the present invention. DETAILED DESCRIPTION
[0035] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0036] The embodiment of the present invention proposes a cloud-edge collaborative secure access method based on a cache mechanism, which is applied to edge nodes, such as Figure 1 As shown, the following steps are included:
[0037] Step S100: receiving a connection request sent by a terminal. The connection request is generated after the terminal queries its own connection cache table and determines that there is a valid connection cache between the terminal and the edge node and that the network quality of service (QoS) requirement is met. The valid connection cache includes a session key.
[0038] Specifically, during the terminal security access phase, the terminal sends a connection request to the corresponding edge node based on its own connection cache table and network quality, and checks whether there is a valid connection cache in its own connection cache table within the valid time. Figure 2 As shown, the cache information of the terminal includes edge ID, session key, connection status and validity time.
[0039] The session key is used to communicate with the edge node, and the validity period indicates how long the session key can be used. The terminal first queries its own connection cache table to determine whether a connection cache with the edge node exists and whether the connection cache is valid. If the current time is within the validity period, the session key is valid, indicating that a valid connection cache exists. If the current time exceeds the validity period, the session key expires and is no longer valid. Network quality requirements include signal strength and signal bandwidth. After verifying that the network quality between itself and the target edge node meets the requirements, the terminal initiates a connection request to the target edge node based on the valid connection cache. The edge node then receives the connection request sent by the terminal.
[0040] Step S200: querying the connection cache table of the local edge node and the connection cache tables of other reachable edge nodes to determine whether there is a valid connection cache of the terminal.
[0041] Specifically, after receiving the connection request sent by the terminal, the local edge node queries its own connection cache table and the connection cache tables of other reachable edge nodes to see whether there is a valid connection cache of the terminal.
[0042] The connection cache table of the edge node is as follows Figure 3 As shown, it includes terminal ID, user name, session key, connection status and validity time. A cache diffusion mechanism is provided in the edge node, and the cache diffusion mechanism exchanges respective cache information with adjacent reachable edge nodes, so that the local edge node can query the connection cache table of other reachable edge nodes, thereby expanding the range in which the terminal can quickly reconnect. By exchanging cache information between adjacent reachable and trusted edge nodes, the connection cache between the terminal and an edge node can be synchronized to another edge node. In this way, when the terminal moves to the coverage range of another edge node, if the connection of the edge node does not have the connection cache of the terminal, the edge node can query the connection cache of the adjacent node. The embodiment of the present invention proposes the concept of cache diffusion. By querying the connection cache of the adjacent reachable edge node, the adjacent reachable edge node can be used to generate a temporary session key for communication between the two parties.
[0043] Step S300: When there is a valid connection cache in the connection cache table of the local edge node or the connection cache table of other reachable edge nodes, a connection is established with the terminal using the session key. After the connection is established, the terminal and the edge node communicate using the session key.
[0044] Step S400: When there is no valid connection cache in the connection cache table of the local edge node or the connection cache table of other reachable edge nodes, a feedback message indicating connection rejection and re-authentication is sent to the terminal.
[0045] Specifically, when a valid connection cache exists in the connection cache table of the local edge node or in the connection cache table of another reachable edge node, a connection is established with the terminal according to the session key, including: when a valid connection cache exists in the connection cache table of the local edge node, a connection is established with the terminal according to the session key; when a valid connection cache does not exist in the connection cache table of the local edge node, but a valid connection cache exists in the connection cache table of another reachable edge node, a connection is established with the terminal according to the session key between the local edge node and the terminal generated by the other reachable edge node. For example, Figure 6 As shown, let the local edge node that receives the connection request be edge node M, and the other reachable edge node be edge node L. If the connection cache table of edge node M contains valid connection information of the terminal, the connection is successfully activated, and edge node M establishes a connection with the terminal based on the session key. If there is no terminal information in the cache table of edge node M, edge node M will send a query request to other edge nodes it can reach, querying whether there is valid connection information of the terminal in their connection cache table. If there is a connection cache of the terminal on edge node L, edge node L will generate a session key for communication between the terminal and edge node M. The terminal and edge node M will cache the corresponding connection information respectively. The validity period of the generated session key should be less than or equal to the validity period of the connection cached by node L. Edge node M can establish a connection with the terminal based on the session key within the validity period; otherwise, edge node M will send a message to the terminal rejecting the connection and re-authenticating.
[0046] A cloud-edge collaborative secure access method based on a cache mechanism in an embodiment of the present invention receives a connection request sent by a terminal, wherein the connection request is generated after the terminal queries its own connection cache table to determine whether there is a valid connection cache with the edge node and that the network quality requirements are met, and the valid connection cache includes a session key; queries the connection cache table of the local edge node and the connection cache table of other reachable edge nodes to see whether there is the valid connection cache of the terminal; when the valid connection cache exists in the connection cache table of the local edge node or the connection cache table of the other reachable edge nodes, establishes a connection with the terminal according to the session key; when the valid connection cache does not exist in the connection cache table of the local edge node or the connection cache table of the other reachable edge nodes, sends a feedback message to the terminal indicating rejection of the connection and re-authentication. The embodiment of the present invention sets a connection cache table to query whether there is a valid connection cache. When both the terminal and the edge node have a valid connection cache, they can connect based on the valid connection cache, and the edge node can query whether there is a valid connection cache of the terminal in the connection cache table of other reachable edge nodes, thereby expanding the range of the terminal's rapid reconnection. When the terminal is offline for some reason, it can still use the cached session key for communication after it comes back online within the valid time, reducing the resource overhead of re-authentication and solving the problem of network resource waste during terminal access.
[0047] In one embodiment, the cloud-edge collaborative secure access method based on the cache mechanism further includes: receiving an authentication request sent by the terminal, the authentication request is generated after the terminal receives a feedback message sent by the edge node; querying whether the terminal is in its own blacklist cache or the blacklist cache of the cloud; if the terminal is in its own blacklist cache or the blacklist cache of the cloud, refusing to authenticate the authentication request, otherwise performing two-way authentication with the terminal and establishing a connection. Figure 5 As shown, the blacklist cache of the edge node or the blacklist cache of the cloud includes the edge ID and the user name. Figure 6 As shown, after the terminal receives the feedback message of connection rejection and re-authentication sent by edge node M, it obtains the nearest edge node N and sends an authentication request to it. Edge node N responds to the authentication request and queries edge node N's own blacklist cache. If the terminal is in its own blacklist cache, edge node N refuses authentication and returns a message of authentication failure. If the terminal is not in its own blacklist cache, it sends a query request to the cloud. If the terminal is in the cloud blacklist cache, edge node N refuses authentication and returns a message of authentication failure. When the terminal is neither in edge node N's own blacklist cache nor in the cloud's blacklist cache, edge node N agrees to authentication, the terminal and edge node N perform two-way authentication, and report the authentication success message to the cloud.
[0048] In one embodiment, after performing bidirectional authentication with the terminal, connection information is generated and stored in the connection cache table of the local edge node, the connection cache table of the terminal, and the connection cache table of the cloud. Specifically, after the terminal performs bidirectional authentication with the edge node N, the edge node reports the successful authentication message to the cloud, and the cloud caches this connection information in the connection cache table of the cloud. The connection cache table of the cloud is as follows: Figure 4 As shown, it includes terminal ID, edge ID, user name, user password, session key, connection status and validity period. In addition, the edge node and terminal also save the connection information in their respective connection cache tables. The connection information at least includes information such as terminal ID, edge ID, user name, user password, session key, connection status and validity period. After each connection is established, the cloud, edge node and terminal cache the connection information through their respective cache tables. In order to solve the problem that multiple edge nodes are difficult to synchronize, a cloud-edge collaboration mechanism is introduced on the basis of the cache mechanism. By modifying the respective cache tables of the cloud and edge, the access authentication process of each terminal at each edge node is controlled to achieve synchronization of terminal management.
[0049] In one embodiment, after establishing a connection with the terminal, the method further includes: collecting information uploaded by the terminal; preprocessing and standardizing the collected information to obtain a data copy; extracting features from the data copy and classifying the extracted features based on an anomaly detection model, and judging whether the terminal behavior is malicious based on the classification results; when the terminal behavior is malicious, generating an alarm message and sending it to the cloud, and the alarm message is stored in the blacklist cache in the cloud. Figure 7 As shown, after the edge node and the terminal establish a connection, the terminal and the edge node communicate using a session key. The edge node collects information uploaded by the terminal connected to it. The collected data is preprocessed and standardized. Preprocessing methods include missing value filling, outlier processing, feature encoding and other operations. Standardization includes Min-Max standardization and z-score standardization. Then, a copy of the preprocessed and standardized data is copied and feature extraction is performed using Principal Component Analysis (PCA). The terminal behavior is classified using an anomaly detection model based on the machine learning algorithm Support Vector Machine (SVM). If the detection results show that the terminal's behavior pattern is abnormal, that is, malicious, an alarm message will be generated and reported to the cloud. After receiving the alarm message, the cloud will add the terminal ID to the blacklist cache.
[0050] In one embodiment, when the terminal's behavior is non-malicious, the data copies are classified and consolidated, application tags are added, and similar data is fused, compressed, and uploaded to the cloud. The cloud then receives blacklist synchronization information. This information is sent to edge nodes with a connection cache to the terminal when the cloud classifies the uploaded data based on an anomaly detection model and determines the terminal's behavior is malicious. The edge node then updates its own blacklist cache based on the blacklist synchronization information. Specifically, if the detection results indicate that the terminal's behavior pattern is normal, i.e., non-malicious, the edge node consolidates the preprocessed and standardized data and adds application tags, namely, adding an application identification field during the data encapsulation process. Simultaneously, similar data is fused and compressed to reduce upload network overhead. The edge node then uploads the consolidated data to the cloud server. The cloud receives anomaly reports and data uploads from all edge nodes and aggregates the data for each terminal. The cloud classifies the terminal's behavior based on all connections and transmission content across different edge nodes using an anomaly detection model based on the machine learning algorithm SVM. If the detection results indicate that the terminal's behavior pattern is malicious, the terminal's information is added to the cloud's blacklist cache. When the blacklist cache in the cloud is changed, all connection caches of the device in the cloud will be deleted first, and blacklist synchronization information will be sent to all edge nodes that have connection caches with the terminal. After the edge node receives the blacklist synchronization information from the cloud, it will make corresponding modifications to the local blacklist cache. When the local blacklist cache is modified accordingly, if the blacklist information is added, the device will be added to the local blacklist cache, and then the current connection cache will be checked to see if the device exists. If so, it will be deleted and the connection will be disconnected. If the blacklist information is reduced, the corresponding terminal will be directly deleted from the local blacklist cache. The present invention utilizes a blacklist mechanism, and the anomaly detection model deployed on the edge node and the cloud can trigger the update of the blacklist cache of the edge node through operations such as adding, deleting, and checking the blacklist, so as to synchronize the access strategies of the cloud server and the edge node for the corresponding terminal and realize linkage. In addition, the blacklist update mechanism is based on cloud-edge dual anomaly detection. The cloud mainly detects terminal behavior, while the edge node mainly performs anomaly detection on the data uploaded by the terminal. Once the blacklist in the cloud database changes, the blacklist update mechanism will be triggered, and the blacklist update information will be sent to all edge nodes that have connection caches with the terminal.
[0051] In one embodiment, when the terminal behavior is non-malicious, the data copies are classified and integrated and application tags are added. The same type of data is fused, compressed, and uploaded to the cloud. The non-malicious data is saved and pushed to the corresponding application through the cloud. The non-malicious data is the data corresponding to the case when the cloud classifies the uploaded data according to the anomaly detection model and determines that the terminal behavior is non-malicious based on the classification results, that is, normal data. Specifically, the cloud stores the data of normal terminals, determines the target application of the data according to the application identification field of the data, and pushes the data to the corresponding application for its use. In this embodiment, the non-malicious data is the data that has been detected twice by the anomaly detection model of the edge node and the cloud to ensure data security.
[0052] The cloud-edge collaborative secure access method based on the cache mechanism of the embodiment of the present invention uses the cache mechanism to reduce the overhead of the frequent authentication process caused by the frequent joining / exit of IoT devices. After the IoT device is offline for a short time and comes online, it can use the cached connection information to quickly establish a connection with the edge node to achieve encrypted communication. In order to solve the problem that multiple edge nodes are difficult to synchronize, a cloud-edge collaborative mechanism is introduced on the basis of the cache mechanism. By modifying the respective connection cache tables of the cloud-edge, the access authentication process of each terminal at each edge node is controlled to achieve synchronization of terminal management. At the same time, the concept of cache diffusion is proposed. By querying the connection cache of adjacent reachable edge nodes, temporary session keys can be generated by adjacent reachable edge nodes for communication between the two parties. In addition, using the blacklist mechanism, the anomaly detection model deployed on the edge node and the cloud can trigger the update of the blacklist cache of the edge node by adding, deleting, and checking the blacklist, so as to synchronize the access policies of the cloud server and the edge node for the corresponding terminal and achieve linkage.
[0053] The embodiment of the present invention also provides a cloud-edge collaborative secure access device based on a cache mechanism, such as Figure 8 As shown, the device includes:
[0054] The request receiving module 1 is used to receive a connection request sent by the terminal. The connection request is generated after the terminal queries its own connection cache table and determines that there is a valid connection cache between the terminal and the edge node and that the network quality requirements are met. The valid connection cache includes a session key. For specific content, please refer to the corresponding part of the above method embodiment and will not be repeated here.
[0055] The cache query module 2 is used to query the connection cache table of the local edge node and the connection cache tables of other reachable edge nodes to see whether there is a valid connection cache of the terminal; the details are shown in the corresponding part of the above method embodiment and will not be repeated here.
[0056] The connection establishment module 3 is used to establish a connection with the terminal according to the session key when there is a valid connection cache in the connection cache table of the local edge node or the connection cache table of other reachable edge nodes; the specific content can be found in the corresponding part of the above method embodiment and will not be repeated here.
[0057] The connection rejection module 4 is used to send a feedback message indicating connection rejection and re-authentication to the terminal when there is no valid connection cache in the connection cache table of the local edge node or the connection cache table of other reachable edge nodes. The details are shown in the corresponding part of the above method embodiment and will not be repeated here.
[0058] A cloud-edge collaborative security access device based on a cache mechanism in an embodiment of the present invention receives a connection request sent by a terminal, wherein the connection request is generated after the terminal queries its own connection cache table to determine whether there is a valid connection cache with the edge node and that the network quality requirements are met, and the valid connection cache includes a session key; queries the connection cache table of the local edge node and the connection cache table of other reachable edge nodes to see whether there is the valid connection cache of the terminal; when the valid connection cache exists in the connection cache table of the local edge node or the connection cache table of the other reachable edge nodes, establishes a connection with the terminal according to the session key; when the valid connection cache does not exist in the connection cache table of the local edge node or the connection cache table of the other reachable edge nodes, sends a feedback message to the terminal indicating rejection of the connection and re-authentication. The embodiment of the present invention sets a connection cache table to query whether there is a valid connection cache. When both the terminal and the edge node have a valid connection cache, they can connect based on the valid connection cache, and the edge node can query whether there is a valid connection cache of the terminal in the connection cache table of other reachable edge nodes, thereby expanding the range of the terminal's rapid reconnection. When the terminal is offline for some reason, it can still use the cached session key for communication after it comes back online within the valid time, reducing the resource overhead of re-authentication and solving the problem of network resource waste during terminal access.
[0059] In one embodiment, the cloud-edge collaborative secure access device based on the cache mechanism further includes:
[0060] An authentication request receiving module, configured to receive an authentication request sent by a terminal, where the authentication request is generated after the terminal receives a feedback message sent by an edge node;
[0061] Blacklist query module, used to query whether the terminal is in its own blacklist cache or the blacklist cache in the cloud;
[0062] The authentication judgment module is used to refuse to authenticate the authentication request when the terminal is in its own blacklist cache or the blacklist cache of the cloud, otherwise perform two-way authentication with the terminal and establish a connection.
[0063] In one embodiment, the cloud-edge collaborative secure access device based on the cache mechanism further includes:
[0064] The saving module is used to generate connection information after performing two-way authentication with the terminal and save the connection information in the connection cache table of the local edge node, the connection cache table of the terminal and the connection cache table of the cloud.
[0065] In one embodiment, the connection establishment module 3 includes:
[0066] A first connection submodule, configured to establish a connection with the terminal according to the session key when a valid connection cache exists in the connection cache table of the local edge node;
[0067] The second connection submodule is configured to establish a connection with the terminal based on a session key between the local edge node and the terminal generated by the other reachable edge nodes when there is no valid connection cache in the connection cache table of the local edge node and there is a valid connection cache in the connection cache table of the other reachable edge nodes.
[0068] In one embodiment, the cloud-edge collaborative secure access device based on the cache mechanism further includes:
[0069] Collection module, used to collect information uploaded by the terminal;
[0070] The data processing module is used to pre-process and standardize the collected information to obtain a data copy;
[0071] The detection module is used to extract features from data copies, classify the extracted features based on the anomaly detection model, and determine whether the terminal behavior is malicious based on the classification results;
[0072] The alarm module generates an alarm message and sends it to the cloud when the terminal behavior is malicious. The alarm message is stored in the blacklist cache of the cloud.
[0073] In one embodiment, the cloud-edge collaborative secure access device based on the cache mechanism further includes:
[0074] The first data upload module is used to classify and integrate data copies and add application tags when the terminal behavior is non-malicious, merge and compress data of the same type, and upload them to the cloud;
[0075] The synchronization module is used to receive blacklist synchronization information sent by the cloud. The blacklist synchronization information is sent to the edge node with a valid connection cache with the terminal when the cloud classifies the uploaded data according to the anomaly detection model and determines that the terminal behavior is malicious based on the classification results;
[0076] The update module is used to update its own blacklist cache according to the blacklist synchronization information.
[0077] In one embodiment, the cloud-edge collaborative secure access device based on the cache mechanism further includes:
[0078] The second data upload module is used to classify and integrate data copies and add application tags when the terminal behavior is non-malicious, merge and compress data of the same type, and upload them to the cloud;
[0079] The saving and pushing module is used to save and push non-malicious data to the corresponding application through the cloud. The non-malicious data is the data corresponding to the case where the cloud classifies the uploaded data according to the anomaly detection model and judges that the terminal behavior is non-malicious based on the classification results.
[0080] The embodiment of the present invention further provides an electronic device, such as Figure 9As shown, it includes: a memory 12 and a processor 11, the memory 12 and the processor 11 are communicatively connected to each other, the memory 12 stores computer instructions, and the processor 11 executes the computer instructions to execute the cloud-edge collaborative secure access method based on the cache mechanism in the above embodiment. The processor 11 and the memory 12 can be connected through a bus or other means. The processor 11 can be a central processing unit (CPU). The processor 11 can also be other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components and other chips, or a combination of the above types of chips. The memory 12, as a non-transitory computer storage medium, can be used to store non-transitory software programs, non-transitory computer executable programs and modules, such as the corresponding program instructions / modules in the embodiments of the present invention. The processor 11 executes various functional applications and data processing of the processor 11 by running non-transitory software programs, instructions, and modules stored in the memory 12, thereby implementing the cloud-edge collaborative secure access method based on a cache mechanism in the above-mentioned method embodiment. The memory 12 may include a program storage area and a data storage area, wherein the program storage area may store operating devices and applications required for at least one function; the data storage area may store data created by the processor 11, etc. In addition, the memory 12 may include a high-speed random access memory 12 and may also include a non-transitory memory 12, such as at least one disk storage 12 device, a flash memory device, or other non-transitory solid-state memory 12 device. In some embodiments, the memory 12 may optionally include a memory 12 remotely located relative to the processor 11, and these remote memories 12 may be connected to the processor 11 via a network. Examples of such networks include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof. One or more modules are stored in the memory 12, and when executed by the processor 11, the cloud-edge collaborative secure access method based on a cache mechanism as in the above-mentioned method embodiment is executed. The specific details of the above-mentioned electronic device can be understood in accordance with the corresponding relevant descriptions and effects in the above-mentioned method embodiment, and will not be repeated here.
[0081] The embodiment of the present invention also provides a computer readable storage medium, such as Figure 10As shown, a computer program 13 is stored thereon, and when the instructions are executed by the processor, the steps of the cloud-edge collaborative secure access method based on the cache mechanism in the above embodiment are implemented. The storage medium also stores audio and video stream data, feature frame data, interaction request signaling, encrypted data, and preset data size, etc. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only memory (ROM), a random access memory (RAM), a flash memory (Flash Memory), a hard disk drive (HDD) or a solid-state drive (SSD), etc.; the storage medium can also include a combination of the above types of memory. Those skilled in the art can understand that all or part of the processes in the above embodiment method can be implemented by instructing the relevant hardware through a computer program. The computer program 13 can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. The storage medium may be a magnetic disk, an optical disk, a read-only memory (ROM), a random access memory (RAM), a flash memory, a hard disk drive (HDD), or a solid-state drive (SSD); the storage medium may also include a combination of the above types of memory.
[0082] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the same. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that the technical solutions described in the above embodiments can still be modified, or some of the technical features thereof can be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A cloud-edge collaborative secure access method based on a cache mechanism, characterized in that: include: receiving a connection request sent by a terminal, where the connection request is generated after the terminal queries its own connection cache table and determines that a valid connection cache exists with the edge node and that network quality requirements are met, the valid connection cache including a session key, and the valid connection cache refers to a connection cache including the session key within a valid time; querying the connection cache table of the local edge node and the connection cache tables of other reachable edge nodes to determine whether there is a valid connection cache of the terminal; When the valid connection cache exists in the connection cache table of the local edge node or the connection cache table of the other reachable edge node, establishing a connection with the terminal according to the session key; When the valid connection cache does not exist in the connection cache table of the local edge node or the connection cache table of the other reachable edge node, a feedback message indicating connection rejection and re-authentication is sent to the terminal.
2. The cloud-edge collaborative secure access method based on a cache mechanism according to claim 1 is characterized in that: Also includes: receiving an authentication request sent by the terminal, where the authentication request is generated after the terminal receives the feedback message sent by the edge node; Check whether the terminal is in its own blacklist cache or the cloud blacklist cache; If the terminal is in its own blacklist cache or the cloud's blacklist cache, the authentication request is rejected. If the terminal is not in either its own blacklist cache or the cloud's blacklist cache, two-way authentication is performed with the terminal and a connection is established.
3. The cloud-edge collaborative secure access method based on a cache mechanism according to claim 2 is characterized in that: After performing two-way authentication with the terminal, the method further includes: Generate connection information and save the connection information in the connection cache table of the local edge node, the connection cache table of the terminal, and the connection cache table of the cloud.
4. The cloud-edge collaborative secure access method based on a cache mechanism according to claim 1 is characterized in that: When the valid connection cache exists in the connection cache table of the local edge node or the connection cache table of the other reachable edge node, establishing a connection with the terminal according to the session key includes: When there is a valid connection cache in the connection cache table of the local edge node, establishing a connection with the terminal according to the session key; When the valid connection cache does not exist in the connection cache table of the local edge node and a valid connection cache exists in the connection cache table of the other reachable edge node, a connection is established with the terminal based on a session key between the local edge node and the terminal generated by the other reachable edge node.
5. The cloud-edge collaborative secure access method based on a cache mechanism according to claim 1 is characterized in that: After establishing a connection with the terminal, the method further includes: Collecting information uploaded by the terminal; Preprocess and standardize the collected information to obtain a data copy; Extracting features from the data copy, classifying the extracted features based on the first anomaly detection model, and determining whether the terminal behavior is malicious based on the classification results; When the terminal behavior is malicious, an alarm message is generated and sent to the cloud, and the alarm message is stored in the blacklist cache of the cloud.
6. The cloud-edge collaborative secure access method based on a cache mechanism according to claim 5 is characterized in that: Also includes: When the terminal behavior is non-malicious, the data copies are classified and integrated and application tags are added, and the same type of data is fused, compressed and uploaded to the cloud; Receiving blacklist synchronization information sent by the cloud, the blacklist synchronization information is sent by the cloud to the edge node having the valid connection cache with the terminal when the cloud classifies the uploaded data according to the second anomaly detection model and determines that the terminal behavior is malicious according to the classification result; Update its own blacklist cache according to the blacklist synchronization information.
7. The cloud-edge collaborative secure access method based on a cache mechanism according to claim 5 is characterized in that: Also includes: When the terminal behavior is non-malicious, the data copies are classified and integrated and application tags are added, and the same type of data is fused, compressed and uploaded to the cloud; The non-malicious data is saved and pushed to the corresponding application through the cloud, and the non-malicious data is the data corresponding to when the cloud classifies the uploaded data according to the second anomaly detection model and determines that the terminal behavior is non-malicious according to the classification result.
8. A cloud-edge collaborative secure access device based on a cache mechanism, characterized in that: include: a request receiving module, configured to receive a connection request sent by a terminal, wherein the connection request is generated after the terminal queries its own connection cache table and determines that there is a valid connection cache with the edge node and that network quality requirements are met, wherein the valid connection cache includes a session key, and the valid connection cache refers to a connection cache that includes the session key within a valid time; a cache query module, configured to query the connection cache table of the local edge node and the connection cache tables of other reachable edge nodes to determine whether there is the valid connection cache of the terminal; a connection establishing module, configured to establish a connection with the terminal according to the session key when the valid connection cache exists in the connection cache table of the local edge node or the connection cache table of the other reachable edge node; The connection rejection module is configured to send a feedback message indicating connection rejection and re-authentication to the terminal when the valid connection cache does not exist in the connection cache table of the local edge node or the connection cache table of the other reachable edge node.
9. An electronic device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the cloud-edge collaborative secure access method based on the cache mechanism as described in any one of claims 1 to 7 by executing the computer instructions.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable the computer to execute the cloud-edge collaborative secure access method based on the cache mechanism as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Cloud edge cooperation system and cluster resource control method and device
CN112925647A
Resource caching method and device, electronic equipment and readable storage medium
CN114125060A