Bandwidth denial allocation attack protection method in edge federation task offloading

By employing a two-layer framework of blockchain and reinforcement learning in the edge federated learning network, the problems of DDoS attacks and fraudulent transactions are solved, and the secure allocation of bandwidth resources and transaction auditing are achieved, improving the efficiency and security of offloading computing tasks.

CN115987541BActive Publication Date: 2026-04-17SHAOXING UNIVERSITY +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHAOXING UNIVERSITY
Filing Date
2022-09-27
Publication Date
2026-04-17

AI Technical Summary

Technical Problem

Existing technologies have failed to effectively protect against bandwidth denial-of-allocation attacks caused by DDoS attacks in edge federated learning networks, affecting the efficiency and security of computing task offloading, and have failed to effectively audit fraudulent transactions in the bandwidth resource auction process.

Method used

Employing a two-layer framework based on blockchain and reinforcement learning, a bandwidth resource allocation algorithm is designed by sensing the bidding and transaction behavior of end devices and edge federated service nodes. This algorithm is combined with a deep Q-network model for decision-making, ensuring the secure allocation of bandwidth resources and the trustworthiness of transactions.

Benefits of technology

It effectively resists DDoS attacks, reduces bandwidth resource allocation delays, suppresses malicious transactions, and improves the efficiency and security of offloading computational tasks in edge federated learning networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115987541B_ABST
    Figure CN115987541B_ABST
Patent Text Reader

Abstract

The application discloses a bandwidth rejection allocation attack protection method in edge federal task offloading, and is applied to an edge federal learning network with M terminal devices and N edge federal service nodes, and comprises the following steps in a time slot tau: (1) the terminal device calls the price; (2) a bandwidth resource auctioner collects the bidding vector of all terminal devices in the step (1) and a bandwidth resource allocation request into a waiting queue, and calculates the comprehensive priority value of all bandwidth allocation requests in the waiting queue; (3) the edge federal service node calls the price; (4) after the bandwidth resource auctioner receives the edge federal learning service node to determine the bandwidth resource sales price, the transaction is matched. The application proposes a two-layer multi-access terminal device trusted bandwidth resource allocation framework, which considers the malicious request of the terminal device and the malicious bidding and transaction behavior of the two parties participating in the bandwidth auction, and guarantees the security of the bandwidth resource allocation from two aspects of the auction bandwidth resource allocation request and the transaction process.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of Internet of Things (IoT) technology, and more specifically, relates to a method for protecting against bandwidth denial-of-allocation attacks during federated task offloading. Background Technology

[0002] Edge federated learning, as a distributed learning framework that executes model training tasks locally on devices, greatly protects users' local data privacy. On user devices, after the model is trained locally, multiple devices involved in the training need to offload the local model to edge nodes, resulting in a multi-access edge federated learning network computing mode. In this mode, edge service access points provide low-latency computing services to the multi-access edge federated learning network by allocating bandwidth, enabling edge federated tasks to be quickly offloaded to edge service aggregation nodes. Since the end devices participating in edge federated learning upload and download models on the same wireless network, and multiple end devices share the bandwidth of the same federated learning service node, how to allocate limited bandwidth resources among the end devices participating in model training has a significant impact on the speed and efficiency of federated learning. Simultaneously, malicious end devices can exploit the characteristic of multiple access devices sharing the bandwidth resources of the federated learning service node to launch DDoS (Distributed Denial of Service) attacks, posing a serious security threat to the offloading of edge federated tasks. In edge federated learning networks, when malicious edge federated devices launch a DDoS attack, they first collect information such as the identity, location, and authentication keys of legitimate users by eavesdropping on network communications. When a device is compromised, its ID, location, and bandwidth consumption information are obtained by the attacker. The attacker then launches a bandwidth denial-of-allocation attack, whereby the malicious device modifies its task completion time, bandwidth consumption rate, and bid price, and then sends a fake bandwidth allocation request. Upon receiving the fake bandwidth request, the federated learning service node prioritizes the devices according to their bandwidth service priority and allocates bandwidth resources accordingly. This ultimately leads to some high-priority devices having their bandwidth requests ignored, causing the federated learning model to fail to offload. A reliable edge federated task offloading system must ensure that computational tasks are successfully offloaded within latency-sensitive timeframes when a bandwidth denial-of-allocation attack occurs. Furthermore, in bandwidth resource allocation, edge devices act as bidders for bandwidth resources, while edge federated service nodes act as auctioneers. During the bandwidth resource auction process, any fraudulent transaction by either party will lead to an imbalance in bandwidth allocation and a decrease in the task offloading rate. To counter such attacks, intelligent defense systems can adapt to the bandwidth requirements and status of monitoring devices. Furthermore, with the assistance of blockchain, they can effectively audit fraudulent bandwidth resource transactions between the auctioning parties. Therefore, how to eliminate the impact of bandwidth denial-of-allocation attacks and improve the quality of service for shared bandwidth resources among multiple access devices in edge federated learning networks through secure and reliable bandwidth resource auction algorithms remains a challenging problem.

[0003] To address this challenge, researchers have proposed several auction-based resource allocation methods. J. Xu et al. designed a bandwidth resource allocation algorithm based on an auction mechanism to optimize the overall performance of multiple edge federated learning service nodes in a federated learning service environment. However, this scheme does not consider bandwidth denial attacks launched by DDoS attackers (“Bandwidth Allocation for Multiple Federated Learning Services in Wireless Edge Networks,” in IEEE Transactions on Wireless Communications, vol.21, no.4, pp.2534-2546, April 2022). X. Liu et al., considering the many-to-one task processing mode in indivisible task processing systems, proposed a reliable multi-resource allocation mechanism based on a bilateral auction algorithm. However, this scheme fails to consider the problem of spurious transactions between bilateral auction nodes (“A Truthful Double Auction Mechanism for Multi-Resource Allocation in Crowd Sensing Systems,” in IEEE Transactions on Services Computing, doi:10.1109 / TSC.2021.3075541). G. Gao et al. considered the competition for VM (Virtual Machine) resources among mobile users when processing deadline-sensitive tasks in distributed edge clouds. They modeled the VM resource allocation problem as an n-to-one weighted bipartite graph matching problem and proposed a reliable VM resource allocation mechanism based on auction theory to determine the auction winner. However, this method did not consider the impact of malicious behavior by participating nodes on VM resource allocation during the auction process (“Auction-Based VM Allocation for Deadline-Sensitive Tasks in DistributedEdge Cloud,” in IEEE Transactions on Services Computing, vol. 14, no. 6, pp. 1702-1716, Nov.-Dec. 2021). To effectively utilize limited spectrum resources, R. Zhu et al. proposed a two-stage secure spectrum intelligent sensing system based on blockchain. In the first stage, the system proposes a reverse auction incentive mechanism to optimize the bidding strategy; in the second stage, it proposes an auction algorithm based on unit utility.This system records transactions in the blockchain to ensure transaction security. However, this method does not consider spectrum resource denial attacks during the transaction process and cannot ensure that nodes urgently needing spectrum resources can obtain them in a timely manner (“ABlockchain-Based Two-Stage Secure Spectrum Intelligent Sensing and Sharing Auction Mechanism,” in IEEE Transactions on Industrial Informatics, vol.18, no.4, pp.2773-2783, April 2022). These research schemes also have the following shortcomings:

[0004] (1) The proposed solutions have little consideration for bandwidth denial-of-allocation attacks launched by DDoS attackers during the offloading of computing tasks in edge federated learning networks. Instead, they only consider the conflict of shared bandwidth between edge federated devices. Therefore, they cannot guarantee the performance of distributed federated learning under DDoS attacks. Thus, the application of the proposed solutions in the offloading of computing tasks by multiple access devices in edge federated learning networks is limited, and no corresponding protection methods have been proposed for this type of attack.

[0005] (2) The proposed solutions only consider bandwidth resource allocation based on auction theory, without considering the disruption of the bandwidth priority queue by false bandwidth resource allocation requests initiated by end devices. In particular, as the number of bandwidth bids requested during the offloading of computing tasks by end devices increases, the bandwidth allocation decision space exhibits a significant increase, and existing solutions based on auction theory do not provide corresponding handling methods.

[0006] (3) The proposed solutions only optimize the bandwidth resource auction strategy, without considering the scenario of fraudulent transactions between terminal devices and edge federated service nodes during the bandwidth resource auction process, nor do they incorporate blockchain technology to audit the transactions between the auctioning parties. In particular, as the amount of bandwidth resource transaction data increases, the probability of untrusted transactions between nodes rises, and the existing solutions do not provide corresponding auditing methods. Summary of the Invention

[0007] To address the shortcomings of the above methods, this invention proposes a method and system for protecting against bandwidth denial-of-allocation attacks in edge federated task offloading, based on blockchain and learning algorithms to detect attackers' bidding behavior and suppress malicious behavior of both parties in a transaction, thereby achieving low-latency offloading of federated learning tasks for multiple access devices.

[0008] To achieve the above objectives, according to one aspect of the present invention, a method for protecting against bandwidth denial-of-allocation attacks in edge federation task offloading is provided, applied to an edge federation learning network with M end devices and N edge federation service nodes, comprising the following steps in time slot τ:

[0009] (1) End device bidding: The bid vector sent to the bandwidth resource auction coordinator and kept confidential from the edge federated service node. Among them, bandwidth resource allocation request Terminal device j bids for edge federated service node i;

[0010] For bandwidth resource allocation requests Simultaneously submit a bandwidth allocation request to the bandwidth resource auction coordinator. ID j Indicates the number of end device j, x j ,y j Indicates the location of the end device, q j Indicates bandwidth resource utilization. This indicates the bid price of terminal device j; the bid price of terminal device j Determined using reinforcement learning algorithms;

[0011] (2) The bandwidth resource auctioneer collects the bidding vectors and bandwidth resource allocation requests of all end devices in step (1) into the waiting queue, and calculates the comprehensive priority value of all bandwidth allocation requests in the waiting queue. The comprehensive priority value reflects the priority of the allocated bandwidth resources based on the distance of the end device to the edge federation service node and the time delay of the edge federation task unloading. The greater the distance of the end device to the edge federation service node, or the longer the time delay of the edge federation task unloading, the lower the priority of the allocated bandwidth resources.

[0012] (3) Edge Federation Service Node Bidding: The bandwidth resource auctioneer organizes all collected bandwidth resource allocation requests according to the requested edge federation service nodes, and submits the bandwidth resource allocation requests and their comprehensive priorities to the corresponding edge federation service nodes. Each edge federation service node independently uses a reinforcement learning algorithm to determine its bandwidth resource sales price and submits the sales price to the bandwidth resource auctioneer.

[0013] (4) After receiving the bandwidth resource sales price determined by the edge federated learning service node, the bandwidth resource auctioneer will match the transaction. If the transaction is successfully established, the terminal device that established the transaction and the edge federated learning service node will respectively upload the bandwidth resource transaction record to the smart contract. The smart contract will record and audit the transaction to confirm its success.

[0014] Preferably, in the method for preventing bandwidth denial-of-allocation attacks during edge federation task offloading, step (1) involves the bid price of the end device j. The reinforcement learning algorithm is used to determine the following:

[0015] state Defined as:

[0016]

[0017] in, This represents the bandwidth requirement expected by terminal device j. End device j observes the bandwidth resources allocated to it by edge federation service node i;

[0018] action Defined as the price submitted by end device j in time slot τ. in, The bid price for terminal equipment j;

[0019] reward function Represented as:

[0020]

[0021] in, For end device j, an available task offloading rate is purchased. R(τ) is the desired task offloading rate, which is a rate value proposed by end device j. The bid price for terminal equipment j, The overall priority value of the bandwidth allocation request from end device j to edge federated service node i;

[0022] The strategy of terminal device j is a probability function that gives a specific bandwidth resource bid price given a state, with the goal of maximizing the reward accumulated by terminal device j in the time slot after time τ.

[0023] Preferably, the bandwidth denial-of-allocation attack protection method in the edge federation task offloading has the following expected bandwidth requirements. Calculate using the following method:

[0024]

[0025] in, The basic bandwidth requirement of terminal device j in time slot τ is determined by the amount of tasks offloaded when not under DDoS attack. The maximum value of the bandwidth variation of the end device. The bandwidth level of the time slot τ-end device j is calculated as follows:

[0026]

[0027] Where, η o ∈(0,1) represents the bandwidth resource allocation efficiency. This indicates that the bandwidth resource allocation priority increment of the end device is positive, meaning that the end device can easily obtain bandwidth resources. This indicates that the bandwidth resource allocation priority increment of the end device is negative, meaning that the end device is unlikely to obtain bandwidth resources. The bandwidth level of device j at time slot τ-1.

[0028] Preferably, in the edge federation task offloading bandwidth denial-of-allocation attack protection method, the end device j purchases an available task offloading rate. Represented as:

[0029]

[0030] Where, p j and g j Representing the transmission power and channel gain of terminal device j, respectively, σ 2 d represents noise, and d represents the distance between the end device and the edge federated service node.

[0031] Preferably, in the edge federation task offloading bandwidth denial-of-allocation attack protection method, the expected task offloading rate of the end device j can be calculated as follows:

[0032]

[0033] Among them, T i j (τ) represents the set of time slots in which end device j uses edge federated service node i, and T represents the time when the end device's task is offloaded. λ i =Ε[B i [τ] represents the availability variable of bandwidth resources of edge federated service node i, and the availability status of bandwidth resources of edge federated service node i is B. i (τ) is a random process that follows a Bernoulli distribution, and B i (τ)~Bernoulli(λ i ), B i (τ)∈{0,1} represents the availability of bandwidth resources at edge federated service node i in time slot τ. B i (τ) = 1 indicates that bandwidth resources are available for edge federation service node i; otherwise, B i (τ)=0.

[0034] Preferably, the method for preventing bandwidth denial-of-allocation attacks during edge federation task offloading uses a deep Q-network model for decision-making in step (1).

[0035] Preferably, in the method for preventing bandwidth denial-of-allocation attacks during edge federation task offloading, the end device j's comprehensive priority value for bandwidth allocation requests to edge federation service node i is used. The reciprocal of the weighted sum of the distance between the end device and the edge federation service node, and the time delay of the edge federation task unloading, is calculated as follows:

[0036]

[0037] Where, β t ,β d Indicates weight, This indicates the time delay for unloading edge federation tasks. The distance between terminal device j and edge federated service node i.

[0038] Preferably, in the method for preventing bandwidth denial-of-allocation attacks during edge federation task offloading, step (3) involves the reinforcement learning algorithm used by edge federation service node i to determine its bandwidth resource sales price. Specifically as follows:

[0039] state Defined as:

[0040] in, Let be the overall priority value of the end device j that makes a bandwidth request to edge federated service node i in the waiting queue of time slot τ. Let be the minimum combined priority value of all end devices in the waiting queue of time slot τ that have made bandwidth requests to edge federated service node i. The maximum combined priority value of all end devices that have made bandwidth requests to edge federated service node i in the waiting queue of time slot τ;

[0041] action Defined as the sales price submitted by edge federated service node i in time slot τ. in, The selling price of edge federation service nodes;

[0042] The reward function is expressed as:

[0043]

[0044] Among them, B i (τ) is B i (τ)∈{0,1} represents the availability of bandwidth resources at edge federated service node i in time slot τ. The overall priority value of terminal device j. To represent the penalty for the number of smart contract violations, a smart contract violation will occur if the edge federation service node cannot provide bandwidth resources to the end device;

[0045] The strategy of edge federation service node i is a probability function that gives a specific bandwidth resource sales price given a state, with the goal of maximizing the accumulated reward of edge federation service node i in the time slot after time τ.

[0046] Preferably, the bandwidth denial-of-allocation attack protection method in the edge federation task offloading represents the penalty imposed on the number of smart contract violations. The calculation method is as follows:

[0047]

[0048] in, The highest historical selling price for bandwidth resources for edge federation service nodes. To determine the bandwidth resource allocation priority for edge federated service node prediction end device j, the end device sends a confidential bid vector to the auctioneer. in This indicates that terminal device j bids for edge federated service node i; otherwise... This indicates that in time slot τ, edge federated service node i provides bandwidth service to end device j. If edge federated service node i allocates bandwidth resources to end device j, then... Each edge federation service node's bandwidth resources are allocated to at least one end device, and each end device can be allocated bandwidth by at least one edge federation service node.

[0049] Priority of bandwidth resource allocation for edge federated service node i predicting terminal device j For edge federation service node observation and end device distance calculation.

[0050] Preferably, the method for preventing bandwidth denial-of-allocation attacks during edge federation task offloading uses a deep Q-network model for decision-making in step (3).

[0051] In summary, compared with the prior art, the above-described technical solutions conceived by this invention can achieve the following beneficial effects:

[0052] (1) In order to resist DDoS attackers’ bandwidth denial-of-allocation attacks and minimize the offloading delay of edge federated learning tasks, this invention proposes a two-layer trusted bandwidth resource allocation framework for multiple access devices. This framework takes into account the malicious requests of end devices and the malicious bidding and transaction behavior of both parties participating in the bandwidth auction, and ensures the security of bandwidth resource allocation from two aspects: the request for auctioning bandwidth resource allocation and the transaction process.

[0053] (2) Because malicious end devices can gain priority allocation rights by disrupting the bandwidth resource allocation request queue, the priority allocation rights of the bandwidth resource allocation request queue become uncertain. To address this problem, this invention proposes a two-sided bidding algorithm for bandwidth resource allocation based on reinforcement learning. When the bandwidth resource allocation request queue is uncertain, it combines the bandwidth resource demand of end devices with the hybrid priority of bandwidth resource allocation, and uses a model-free learning method to adaptively optimize the two-sided bidding strategy. Compared with model-based methods, this reduces additional assumptions and computational complexity.

[0054] (3) The participating end devices and edge federation service nodes are selfish. In order to maximize their profits, both parties engage in fraudulent transactions involving bandwidth resources, which greatly reduces the profits of legitimate end devices. To address this problem, this invention further designs a blockchain-based bilateral bandwidth resource transaction auditing mechanism. By auditing transactions in the bandwidth resource allocation request queue, it suppresses malicious transaction behavior by both parties in the auction. Attached Figure Description

[0055] Figure 1 This is a schematic diagram of the steps of the method for protecting against bandwidth denial-of-allocation attacks in edge federation task offloading provided by the present invention;

[0056] Figure 2 This is a schematic diagram of a two-layer trusted bandwidth resource allocation framework for multi-access terminal devices according to an embodiment of the present invention;

[0057] Figure 3 This is the bandwidth resource transaction audit process in an embodiment of the present invention. Detailed Implementation

[0058] To make the objectives, technical solutions, and advantages of this invention clearer, the invention will be further described in detail below with reference to embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the invention. Furthermore, the technical features involved in the various embodiments of this invention described below can be combined with each other as long as they do not conflict with each other.

[0059] The bandwidth denial-of-allocation attack protection method provided by this invention is applied to an edge federation learning network with M end devices and N edge federation service nodes, such as... Figure 1 As shown, the steps in time slot τ include:

[0060] (1) End device bidding: The bid vector sent to the bandwidth resource auction coordinator and kept confidential from the edge federated service node. Among them, bandwidth resource allocation request This indicates that endpoint device j is bidding on edge federated service node i; when the bandwidth resources of endpoint device j are lower than a preset threshold. At that time, there is at least one bandwidth resource allocation request in the bid vector.

[0061] For bandwidth resource allocation requests Simultaneously submit a bandwidth allocation request to the bandwidth resource auction coordinator. ID j Indicates the number of end device j, x j ,y j Indicates the location of the end device, q j Indicates bandwidth resource utilization. This indicates the bid price of terminal device j; the bid price of terminal device j The reinforcement learning algorithm is used to determine the following:

[0062] state Defined as:

[0063]

[0064] in, This represents the bandwidth requirement expected by terminal device j. End device j observes the bandwidth resources allocated to it by edge federated service node i. The expected bandwidth requirement is... Calculate using the following method:

[0065]

[0066] in, The basic bandwidth requirement of terminal device j in time slot τ is determined by the amount of tasks offloaded when not under DDoS attack. The maximum value of the bandwidth variation of the end device. The bandwidth level of the time slot τ-end device j is calculated as follows:

[0067]

[0068] Where, η o ∈(0,1) represents the bandwidth resource allocation efficiency. This indicates that the bandwidth resource allocation priority increment of the end device is positive, meaning that the end device can easily obtain bandwidth resources. This indicates that the bandwidth resource allocation priority increment of the end device is negative, meaning that the end device is unlikely to obtain bandwidth resources. The bandwidth level of device j at time slot τ-1.

[0069] action Defined as the price submitted by end device j in time slot τ. in, The bid price for terminal equipment j;

[0070] reward function Represented as:

[0071]

[0072] in, For end device j, an available task offloading rate is purchased. R(τ) is the desired task offloading rate, which is a rate value proposed by end device j. The bid price for terminal equipment j, The overall priority value of the bandwidth allocation request from end device j to edge federated service node i;

[0073] Terminal device j purchases available task offloading rate Represented as:

[0074]

[0075] Where, p j and g j Representing the transmission power and channel gain of terminal device j, respectively, σ 2 d represents noise, and d represents the distance between the end device and the edge federated service node.

[0076] The expected task offloading rate of terminal device j can be calculated as follows:

[0077]

[0078] Among them, T i j (τ) represents the set of time slots in which end device j uses edge federated service node i, and T represents the time when the end device's task is offloaded. λ i =Ε[B i [τ] represents the availability variable of bandwidth resources of edge federated service node i, and the availability status of bandwidth resources of edge federated service node i is B. i (τ) is a random process that follows a Bernoulli distribution, and B i (τ)~Bernoulli(λ i ), B i (τ)∈{0,1} represents the availability of bandwidth resources at edge federated service node i in time slot τ. B i (τ) = 1 indicates that bandwidth resources are available for edge federation service node i; otherwise, B i (τ)=0.

[0079] The strategy of terminal device j is a probability function that gives a specific bandwidth resource bid price given a state. The goal is to maximize the reward accumulated by terminal device j in the time slot after time τ. A deep Q-network model is preferred for decision-making.

[0080] (2) The bandwidth resource auctioneer collects the bidding vectors and bandwidth resource allocation requests from all end devices in step (1) into a waiting queue, and calculates the comprehensive priority value of all bandwidth allocation requests in the waiting queue. The comprehensive priority value reflects the priority of the allocated bandwidth resources based on the distance of the end device to the edge federation service node and the time delay of the edge federation task unloading. The greater the distance of the end device to the edge federation service node, or the longer the time delay of the edge federation task unloading, the lower the priority of the allocated bandwidth resources. Specifically, the comprehensive priority value of the bandwidth allocation request of end device j to edge federation service node i. The reciprocal of the weighted sum of the distance between the end device and the edge federation service node, and the time delay of the edge federation task unloading, is calculated as follows:

[0081]

[0082] Where, β t ,β d Indicates weight, This indicates the time delay for unloading edge federation tasks. The distance between terminal device j and edge federated service node i;

[0083] (3) Edge Federation Service Node Bidding: The bandwidth resource auctioneer organizes all collected bandwidth resource allocation requests according to the requested edge federation service nodes, and submits the bandwidth resource allocation requests and their comprehensive priorities to the corresponding edge federation service nodes. Each edge federation service node independently uses a reinforcement learning algorithm to determine its bandwidth resource sales price and submits the sales price to the bandwidth resource auctioneer.

[0084] For edge federated service node i, the reinforcement learning algorithm used determines the price of its bandwidth resources. Specifically as follows:

[0085] state Defined as: in, Let be the overall priority value of the end device j that makes a bandwidth request to edge federated service node i in the waiting queue of time slot τ. Let be the minimum combined priority value of all end devices in the waiting queue of time slot τ that have made bandwidth requests to edge federated service node i. The maximum combined priority value of all end devices that have made bandwidth requests to edge federated service node i in the waiting queue of time slot τ;

[0086] action Defined as the sales price submitted by edge federated service node i in time slot τ. in, The selling price of edge federation service nodes;

[0087] The reward function is expressed as:

[0088]

[0089] Among them, B i (τ) is B i (τ)∈{0,1} represents the availability of bandwidth resources at edge federated service node i in time slot τ. The overall priority value of terminal device j. To represent the penalty for each violation of a smart contract, a violation occurs if an edge federation service node cannot provide bandwidth resources to the end device. In this case, the transaction record for bandwidth sold to the end device in the current time slot cannot be found in the blockchain, making the transaction invalid.

[0090]

[0091] in, The highest historical selling price for bandwidth resources for edge federation service nodes. To determine the bandwidth resource allocation priority for edge federated service node prediction end device j, the end device sends a confidential bid vector to the auctioneer. in This indicates that terminal device j bids for edge federated service node i; otherwise... This indicates that in time slot τ, edge federated service node i provides bandwidth service to end device j. If edge federated service node i allocates bandwidth resources to end device j, then... Each edge federation service node's bandwidth resources are allocated to at least one end device, and each end device can be allocated bandwidth by at least one edge federation service node.

[0092] Priority of bandwidth resource allocation for edge federated service node i predicting terminal device j For edge federation service node observation and end device distance calculation.

[0093] The strategy of edge federation service node i is a probability function that gives a specific bandwidth resource sales price given a state. The goal is to maximize the accumulated reward of edge federation service node i in the time slot after time τ. The deep Q network model is preferred for decision-making.

[0094] (4) After receiving the bandwidth resource sales price determined by the edge federated learning service node, the bandwidth resource auctioneer will match the transaction. If the transaction is successfully established, the terminal device that established the transaction and the edge federated learning service node will respectively upload the bandwidth resource transaction record to the smart contract. The smart contract will record and audit the transaction to confirm its success.

[0095] The following is an example:

[0096] A method for protecting against bandwidth denial-of-allocation attacks during edge federation task offloading is proposed, applicable to an edge federation learning network with M end devices and N edge federation service nodes.

[0097] In this invention, the edge federated learning network consists of multiple end devices and edge federated service nodes. The service access point and the micro-cloud server constitute the edge federated service nodes. A two-layer anti-bandwidth denial-of-allocation attack framework is provided as follows: Figure 2 As shown, the trusted bandwidth resource auction layer optimizes the auction strategy between end devices and edge federation service nodes, maximizing the utility for both parties. The bandwidth resource transaction audit layer, as a backend system, primarily constrains fraudulent transactions between the auction parties, ensuring the non-repudiation of the auction results. When multiple devices unload edge federation training tasks, the edge federation service nodes are responsible for allocating bandwidth to the end devices. Since old unloading tasks are completed over time and new unloading tasks are started, bandwidth resource allocation must be performed periodically to adapt to the current task unloading activity. Assuming that in time slot τ, N edge federation service nodes provide bandwidth resource services to M end devices, and the end devices search and compete for idle bandwidth resources among multiple edge federation service nodes.

[0098] Let B i (τ)∈{0,1} represents the availability of bandwidth resources at edge federated service node i in time slot τ. B i (τ) = 1 indicates that bandwidth resources are available for edge federation service node i; otherwise, B i (τ) = 0. Under a DDoS attack, the bandwidth resource availability state B of edge federation service node i. i (τ) is a random process that follows a Bernoulli distribution, and B i (τ)~Bernoulli(λ i ), where λ i =Ε[B i (τ)]. Let λ = [λ1,...,λ N [] represents the availability variables of bandwidth resources of the edge federation service nodes, and these variables are unknown to the end devices. In the initial stage of system operation, each end device j can only select one edge federation service node i to obtain bandwidth resources.

[0099] At this point, the available task offloading rate for terminal device j is expressed as:

[0100]

[0101] Where, p j and g j Let σ represent the transmission power and channel gain of terminal device j, respectively. 2 Let represent noise, and d represent the distance between the end device and the edge federated service node. The expected task offloading rate of the end device can be calculated as:

[0102]

[0103] Among them, T i j (τ) represents the set of time slots used by end device j to access edge federation service node i, and T represents the time for end device task offloading. From the above formula, it can be seen that under a DDoS attack, throughput is determined by two factors: the availability of bandwidth of edge federation service node i and the available rate of each end device j, as well as the time delay for end device task offloading at this rate. Among them o j This represents the size of the task offloaded by end device j. This invention designs a reliable bandwidth resource allocation algorithm to maximize the throughput of computational task offloading by the end device while minimizing latency.

[0104] To suppress proactive DDoS attacks from malicious end devices, the main challenge lies in designing a reliable bandwidth demand model and bandwidth resource trading mechanism for edge federation service nodes. This invention designs a blockchain-based bandwidth demand control method. In this method, each edge federation service node acts as an auctioneer of bandwidth resources, executing an online learning algorithm and allocating bandwidth resources to ensure the bandwidth resource needs of legitimate end devices. Let e ​​represent the set of end devices and f represent the set of edge federation service nodes. End devices, as bidders, acquire the required bandwidth resources, and edge federation service nodes, as auctioneers, allocate bandwidth resources to the end devices. In this auction model, each end device can bid on any edge federation service node in f.

[0105] The time slot τ includes the following steps:

[0106] (1) End device bidding: The bid vector sent to the bandwidth resource auction coordinator and kept confidential from the edge federated service node. Among them, bandwidth resource allocation request This indicates that endpoint device j is bidding on edge federated service node i; when the bandwidth resources of endpoint device j are lower than a preset threshold. At that time, there is at least one bandwidth resource allocation request in the bid vector.

[0107] Define b -j (τ) represents the bidding vector of other bidders, and b -j (τ)={b k (τ)|k∈e\j}.

[0108] During the process of offloading computing tasks from the end device, once the end device j detects that its bandwidth resources are below a specific threshold... At that time, the terminal device initiates at least one bandwidth allocation request.

[0109] Ideally, based on the bids from the end devices, the auctioneer will allocate bandwidth resources to each end device. However, due to the statistical characteristics of the average availability λ of bandwidth resources among edge federated service nodes... i The bandwidth requirements of legitimate and malicious end devices differ, and the bandwidth requirements of malicious end devices are often covert, making it difficult to ascertain their DDoS attack intent. Therefore, it is essential to consider the bandwidth requirements of each end device in its bidding process. In particular, for malicious end devices, this invention considers a bandwidth resource auction model oriented towards end device requirements, namely the Demand-Gale-Sotomayor (DGS) auction, to handle scenarios where multiple bidders bid for the same edge federation service node. This leads to a dominant strategy equilibrium, where each bidder's profit is maximized while ignoring the strategies of other bidders. When the dominant strategy equilibrium is reached, the DGS auction also achieves a minimum price equilibrium.

[0110] For bandwidth resource allocation requests Simultaneously submit a bandwidth allocation request to the bandwidth resource auction coordinator. ID j Indicates the number of end device j, x j ,y j Indicates the location of the end device, q j Indicates bandwidth resource utilization. This indicates the bid price of terminal device j; the bid price of terminal device j The reinforcement learning algorithm is used to determine the following:

[0111] state Defined as:

[0112]

[0113] in, This represents the bandwidth requirement expected by terminal device j. End device j observes the bandwidth resources allocated to it by edge federated service node i. Under a DDoS attack, the hybrid priority of the end device changes, which affects the end device's expected bandwidth requirement. Calculate using the following method:

[0114]

[0115] in, The basic bandwidth requirement of terminal device j in time slot τ is determined by the amount of tasks offloaded when not under DDoS attack. The maximum value of the bandwidth variation of the end device. The bandwidth level of the time slot τ-end device j is calculated as follows:

[0116]

[0117] Where, η o ∈(0,1) represents the bandwidth resource allocation efficiency. This indicates that the bandwidth resource allocation priority increment of the end device is positive, meaning that the end device can easily obtain bandwidth resources. This indicates that the bandwidth resource allocation priority increment of the end device is negative, meaning that the end device is unlikely to obtain bandwidth resources. The bandwidth level of device j at time slot τ-1.

[0118] Under a DDoS attack, the hybrid priority of end devices changes, which affects the expected bandwidth requirements of the end devices.

[0119] action Defined as the price submitted by end device j in time slot τ. in, The bid price for terminal equipment j;

[0120] The dynamic equation for the bandwidth change of end devices shows that the bandwidth requirements of end devices differ when subjected to a DDoS attack and when not subjected to a DDoS attack. This represents the basic bandwidth requirement of terminal device j in time slot τ, which is related to the amount of tasks offloaded when not under DDoS attack. This represents the desired bandwidth requirement. End device j aims to obtain the desired bandwidth resources. Determine its bid price Meanwhile, the edge federation service node i determines its sales price. The goal of the end device is to bid with mixed priority and obtain the lowest price, while meeting the basic bandwidth requirements for its federated learning task offloading. The objective function of the end device can be expressed as follows:

[0121]

[0122]

[0123] in, This indicates satisfaction with the task unloading rate. This represents the minimum bid price for terminal device j. Let represent the maximum bid price for terminal device j. As can be seen from the above formula, the terminal device will maximize its objective function value using the lowest price and a mixed priority.

[0124] reward function Represented as:

[0125]

[0126] in, For end device j, an available task offloading rate is purchased. R(τ) is the desired task offloading rate, which is a rate value proposed by end device j. The bid price for terminal equipment j, The overall priority value of the bandwidth allocation request from end device j to edge federated service node i;

[0127] Terminal device j purchases available task offloading rate Represented as:

[0128]

[0129] Where, p j and g j Representing the transmission power and channel gain of terminal device j, respectively, σ 2 d represents noise, and d represents the distance between the end device and the edge federated service node.

[0130] The expected task offloading rate of terminal device j can be calculated as follows:

[0131]

[0132] Among them, T i j (τ) represents the set of time slots in which end device j uses edge federated service node i, and T represents the time when the end device's task is offloaded. λ i =Ε[B i [τ] represents the availability variable of bandwidth resources of edge federated service node i, and the availability status of bandwidth resources of edge federated service node i is B. i (τ) is a random process that follows a Bernoulli distribution, and B i (τ)~Bernoulli(λ i ), B i (τ)∈{0,1} represents the availability of bandwidth resources at edge federated service node i in time slot τ. B i (τ) = 1 indicates that bandwidth resources are available for edge federation service node i; otherwise, B i (τ)=0.

[0133] The strategy of terminal device j is a probability function that gives a specific bandwidth resource bid price given a state. The goal is to maximize the reward accumulated by terminal device j in the time slot after time τ. A deep Q-network model is preferred for decision-making.

[0134] (2) The bandwidth resource auctioneer collects the bidding vectors and bandwidth resource allocation requests from all end devices in step (1) into a waiting queue, and calculates the comprehensive priority value of all bandwidth allocation requests in the waiting queue. The comprehensive priority value reflects the priority of the allocated bandwidth resources based on the distance of the end device to the edge federation service node and the time delay of the edge federation task unloading. The greater the distance of the end device to the edge federation service node, or the longer the time delay of the edge federation task unloading, the lower the priority of the allocated bandwidth resources. Specifically, the comprehensive priority value of the bandwidth allocation request of end device j to edge federation service node i. The reciprocal of the weighted sum of the distance between the end device and the edge federation service node, and the time delay of the edge federation task unloading, is calculated as follows:

[0135]

[0136] Where, β t ,β d Indicates weight, This indicates the time delay for unloading edge federation tasks. The distance between terminal device j and edge federated service node i;

[0137] For end device j, a higher hybrid priority will result in a higher bandwidth allocation priority. When a malicious end device launches a DDoS attack, the hybrid priority becomes uncertain, causing high-priority end devices to fail to obtain bandwidth allocation. Therefore, this invention combines hybrid priority to optimize the auction price, thereby ensuring that legitimate end devices obtain a reasonable bandwidth allocation priority.

[0138] (3) Edge Federation Service Node Bidding: The bandwidth resource auctioneer organizes all collected bandwidth resource allocation requests according to the requested edge federation service nodes, and submits the bandwidth resource allocation requests and their comprehensive priorities to the corresponding edge federation service nodes. Each edge federation service node independently uses a reinforcement learning algorithm to determine its bandwidth resource sales price and submits the sales price to the bandwidth resource auctioneer.

[0139] Upon receiving a bandwidth resource allocation request, a waiting queue is created. End devices with higher priority are allocated bandwidth resources first. The priority of end devices is defined as time priority and spatial priority. Time priority is defined as the time delay of edge federation task offloading. Similarly, spatial priority is defined as the distance between the end device and the edge federated service node.

[0140] Let the bandwidth resource sales price of the edge federation service node be τ.

[0141] For edge federated service node i, the reinforcement learning algorithm used determines the price of its bandwidth resources. Specifically as follows:

[0142] state Defined as: in, Let be the overall priority value of the end device j that makes a bandwidth request to edge federated service node i in the waiting queue of time slot τ. Let be the minimum combined priority value of all end devices in the waiting queue of time slot τ that have made bandwidth requests to edge federated service node i. The maximum combined priority value of all end devices that have made bandwidth requests to edge federated service node i in the waiting queue of time slot τ;

[0143] action Defined as the sales price submitted by edge federated service node i in time slot τ. in, The selling price of edge federation service nodes;

[0144] The reward function is expressed as:

[0145]

[0146] Among them, B i (τ) is B i (τ)∈{0,1} represents the availability of bandwidth resources at edge federated service node i in time slot τ. The overall priority value of terminal device j. To represent the penalty for each violation of a smart contract, a violation occurs if an edge federation service node cannot provide bandwidth resources to the end device. In this case, the transaction record for bandwidth sold to the end device in the current time slot cannot be found in the blockchain, making the transaction invalid.

[0147]

[0148] in, The highest historical selling price for bandwidth resources for edge federation service nodes. To determine the bandwidth resource allocation priority for edge federated service node prediction end device j, the end device sends a confidential bid vector to the auctioneer. in This indicates that terminal device j bids for edge federated service node i; otherwise... This indicates that in time slot τ, edge federated service node i provides bandwidth service to end device j. If edge federated service node i allocates bandwidth resources to end device j, then... Each edge federation service node's bandwidth resources are allocated to at least one end device, and each end device can be allocated bandwidth by at least one edge federation service node.

[0149] Priority of bandwidth resource allocation for edge federated service node i predicting terminal device j For edge federation service node observation and end device distance calculation.

[0150] The strategy of edge federation service node i is a probability function that gives a specific bandwidth resource sales price given a state. The goal is to maximize the accumulated reward of edge federation service node i in the time slot after time τ. The deep Q network model is preferred for decision-making.

[0151] make This indicates the mixed priority of actual bandwidth resource allocation for terminal device j. This indicates the bandwidth resource allocation priority of the edge federation service node prediction end device j, and Edge Federation Service Node i allocates hybrid priority and bid price based on the bandwidth resources of the end devices. The allocated bandwidth resources are sold at a price of Therefore, the bandwidth resource function allocated by the edge federated service node to end device j is: Furthermore, the bandwidth resource range allocated by the edge federation service node to end device j is:

[0152]

[0153] To prevent DDoS attackers' excessive demands from causing bandwidth allocation service denial and edge federation service nodes from violating the smart contract conditions of bandwidth resource transactions, the edge federation service node's observation device has a hybrid bandwidth resource allocation priority, and displays its selling price to maximize its utility as follows:

[0154]

[0155] Where Ε{·} represents a random variable. The expectation. This indicates the number of times a smart contract has been violated. A smart contract violation occurs if the edge federation service node cannot provide bandwidth resources to the end device. In this case, if no transaction record of bandwidth being sold to the end device in the current time slot can be found in the blockchain, the transaction is considered invalid.

[0156] make This indicates that in time slot τ, edge federated service node i provides bandwidth service to end device j. If edge federated service node i allocates bandwidth resources to end device j, then... Each edge federation service node's bandwidth resources are allocated to at least one end device, and each end device can be allocated bandwidth by at least one edge federation service node. In time slot τ, when...

[0157] At that time, terminal device j completes the bandwidth resource bidding for edge federation service node i and allocates bandwidth resources; otherwise...

[0158] This invention proposes a reinforcement learning-based bilateral bandwidth resource auction algorithm to achieve reliable bandwidth resource allocation during edge federation task offloading under DDoS attacks. This algorithm explores and learns the bilateral auction strategies of end devices and edge federation service nodes, thereby solving the problem of uneven bandwidth allocation caused by the instability of the mixed priority queues of bandwidth resources under DDoS attacks. The decision-makers in this algorithm are the edge federation service nodes and end devices, who observe the current state and take actions through interaction with the auction environment. At each time step, the agents receive a reward signal from the auction environment for performing an action, and the agents maximize the accumulated reward through multi-step decision-making and action. In the bilateral bandwidth resource auction algorithm, the end devices and edge federation service nodes act as agents participating in the auction, and the state space of the bandwidth auction is defined as follows: The bandwidth requirement of end device j is defined as the sum of the end device's expected bandwidth requirement and the bandwidth B allocated by the edge federation service node. i The difference between (τ):

[0159]

[0160] When allocating bandwidth to edge federation service nodes, their bandwidth resource allocation priority queues are observed. Due to DDoS attacks, the bandwidth resource allocation priority queues stored in edge federation service nodes are dynamically changing. A wide range of priority states can be obtained by using mixed priorities.

[0161]

[0162] Given a state s(τ), the agent selects from the action set Choose an action, pass the state space of the bandwidth auction from s(τ) to the next state s(τ+1), and return a numerical reward r(τ+1), where, Here, r(τ+1) is used to evaluate the action a(τ) performed in state s(τ). Here, a(τ) is the price submitted by each agent. and and In the learning algorithm, the edge service node acts as an agent, selling its bandwidth B at the highest price based on the priority of each end device. i (τ) and obtain rewards to maximize its utility. For each edge federation service node i, its reward function is expressed as follows:

[0163]

[0164] For each end device, the expected bandwidth requirements and computational task offload rate are met with the lowest bid price. Therefore, the reward function for end device j in time slot τ is expressed as follows:

[0165]

[0166] In the learning algorithm, the end device and the edge federated service node act as agents. Their policy π(s(τ), a(τ)) is a function of the probability of choosing action a(τ) given state s(τ). The agent's goal is to maximize the accumulated reward over the time slot starting from time τ. The action-value function Q is defined under the policy π(s(τ), a(τ)). π (s(τ),a(τ)) are as follows:

[0167]

[0168] Where γ∈(0,1] represents the discount factor, and the optimal action-value function Q * (s(τ),a(τ)) satisfy the following equation:

[0169] Q * (s(τ),a(τ))=maxQ π (s(τ),a(τ))

[0170] In the learning algorithm, this invention uses Q. π The Q-table of (s(τ),a(τ)) is used to estimate the optimal action-value function Q. * (s(τ),a(τ)), the update rules for the Q table are as follows:

[0171] Q(s(τ),a(τ))=(1-α)Q(s(τ),a(τ))+α(r(τ+1)+γmax(s(τ+1),a(τ+1)))

[0172] Where α∈(0,1) is the learning rate. The bandwidth resource auction algorithm based on reinforcement learning for DDoS attack resistance proposed in this invention has the following steps: In time slot τ, edge federation service nodes and end devices in the current state s(τ) submit their prices using action a(τ), and then obtain a reward r(τ+1) from the environment. Subsequently, the state space of the bandwidth auction is passed to the next state s(τ+1). Next, in time step τ+1, the algorithm uses equation (16) to update the Q value using (s(τ),a(τ)). Specifically, as shown in Algorithm 1:

[0173] Algorithm 1:

[0174] Input: Learning rate α∈(0,1)

[0175] Output: The transaction price of bandwidth resources for end devices and edge federation service nodes.

[0176] Step 1: Initialize Q π (s(τ),a(τ)),τ=0

[0177] Step 2: while the bandwidth resource mixed priority queue is not empty do

[0178] Step 3: The terminal device observes its status. Edge Federation Service Nodes Observe Their Status

[0179] Step 4: Choose the respective actions from a(τ).

[0180] Step 5: Submit price for terminal device Edge Federation Service Nodes bid for services. And each receives a reward r(τ+1).

[0181] Step 6: Update Q π (s(τ),a(τ))

[0182] Step 7: τ = τ + 1

[0183] Step 8: end while

[0184] The bandwidth resource auction process based on blockchain, such as Figure 1 As shown, after the transaction price is determined, the terminal device and edge federated service nodes call the smart and upload the transaction information to the blockchain system, and then the blockchain system audits the legality of the transaction.

[0185] (4) After receiving the bandwidth resource sales price determined by the edge federated learning service node, the bandwidth resource auctioneer will match the transaction. If the transaction is successfully established, the terminal device that established the transaction and the edge federated learning service node will respectively upload the bandwidth resource transaction record to the smart contract. The smart contract will record and audit the transaction to confirm its success.

[0186] The blockchain-based bandwidth resource transaction audit process is as follows: Figure 3 As shown, in each bandwidth resource auction round, the transaction records in the bandwidth resource auction hybrid priority queue are in the Hyperledger. Auditors in the blockchain system verify whether the transaction price has been changed. If it has not been changed by the end device and edge federation service nodes, the auditor marks the transaction record as the final transaction.

[0187] Those skilled in the art will readily understand that the above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, and improvements made within the spirit and principles of the present invention should be included within the scope of protection of the present invention.

Claims

1. A method for protecting against bandwidth denial-of-allocation attacks during edge federation task offloading, characterized in that, Applied to an edge federated learning network with M end devices and N edge federated service nodes, in time slots Includes the following steps: (1) End device bidding: Send a confidential bid vector to the bandwidth resource auction coordinator for edge federated service nodes. Among them, bandwidth resource allocation request Terminal device j bids for edge federated service node i; For bandwidth resource allocation requests At the same time, submit a bandwidth allocation request to the bandwidth resource auction coordinator. ,in This indicates the number of the terminal device j. Indicates the location of the terminal device. Indicates bandwidth resource utilization. This indicates the bid price of terminal device j; the bid price of terminal device j The determination is made using a reinforcement learning algorithm; (2) The bandwidth resource auctioneer collects the bidding vectors and bandwidth resource allocation requests of all end devices in step (1) into the waiting queue, and calculates the comprehensive priority value of all bandwidth allocation requests in the waiting queue. The comprehensive priority value reflects the priority of the allocated bandwidth resources based on the distance of the end device to the edge federation service node and the time delay of the edge federation task unloading. The greater the distance of the end device to the edge federation service node, or the longer the time delay of the edge federation task unloading, the lower the priority of the allocated bandwidth resources. (3) Edge Federation Service Node Bidding: The bandwidth resource auctioneer organizes all the bandwidth resource allocation requests collected according to the edge federation service nodes requested by them, and submits the bandwidth resource allocation requests and their comprehensive priorities to the corresponding edge federation service nodes. Each edge federation service node independently uses a reinforcement learning algorithm to determine its bandwidth resource sales price and submits the sales price to the bandwidth resource auctioneer. (4) After receiving the bandwidth resource sales price determined by the edge federated learning service node, the bandwidth resource auctioneer will match the transaction. If the transaction is successfully established, the terminal device that established the transaction and the edge federated learning service node will respectively upload the bandwidth resource transaction record to the smart contract. The smart contract will record and audit the transaction to confirm its success.

2. The method for protecting against bandwidth denial-of-allocation attacks in edge federation task offloading as described in claim 1, characterized in that, The bid price of the end device j in step (1) The reinforcement learning algorithm is used to determine the value of the parameter, and the specific process is as follows: State is defined as: ; wherein, denotes the bandwidth requirement expected by the end device j, is the bandwidth resource observed by the end device j that the edge federation service node i allocates for it; action Defined as end device j in time slot The submitted price, ;in, The bid price for terminal equipment j; reward function Represented as: ; in, Purchase available task offloading rates for terminal device j. For the desired task unloading rate, and , The bid price for terminal equipment j, The overall priority value of the bandwidth allocation request from end device j to edge federated service node i; The strategy of terminal device j is to give a probability function of bidding for a specific bandwidth resource given a state, with the objective of maximizing the probability of terminal device j's bid price over time. The rewards accumulated during the time slots after the start.

3. The method for protecting against bandwidth denial-of-allocation attacks in edge federation task offloading as described in claim 2, characterized in that, Desired bandwidth requirement The following method is used: ; in, For end device j in time slot The basic bandwidth requirement is determined by the amount of tasks that are offloaded when there is no DDoS attack. The maximum value of the bandwidth variation of the end device. For time interval The bandwidth level of terminal device j is calculated as follows: ; in, This indicates the efficiency of bandwidth resource allocation. This indicates that the bandwidth resource allocation priority increment of the end device is positive, meaning that the end device can easily obtain bandwidth resources. This indicates that the bandwidth resource allocation priority increment of the end device is negative, meaning that the end device is unlikely to obtain bandwidth resources. For time interval The bandwidth level of the terminal device j.

4. The method for protecting against bandwidth denial-of-allocation attacks in edge federation task offloading as described in claim 2, characterized in that, The end device j buys into the available task offloading rate is expressed as: ; wherein, and Pjand denote the transmission power and channel gain of the end device j, respectively, denotes the noise, denotes the distance between the end device and the edge federation service node, is the bandwidth resource availability status for the edge federation service node i.

5. The method of claim 2, wherein the edge federation task offloading with bandwidth denial allocation attack protection method is characterized by, The expected task offloading rate of terminal device j can be calculated as follows: ; in, This indicates that the end device j uses the set of time slots of the edge federated service node i. This indicates the time when the terminal device task is unloaded. For edge federation service node i, the bandwidth resource availability variable represents the available state of the bandwidth resource of edge federation service node i. A random process that follows a Bernoulli distribution, i.e. , Indicates time slot The availability status of bandwidth resources for edge federation service node i; This indicates that bandwidth resources are available for edge federated service node i; otherwise... .

6. The method for protecting against bandwidth denial-of-allocation attacks in edge federation task offloading as described in claim 2, characterized in that, Step (1) uses a deep Q-network model for decision-making.

7. The method for protecting against bandwidth denial-of-allocation attacks in edge federation task offloading as described in claim 1, characterized in that, The overall priority value of the bandwidth allocation request of the end device j to the edge federated service node i The reciprocal of the weighted sum of the distance between the end device and the edge federation service node, and the time delay of the edge federation task unloading, is calculated as follows: ; in, , Indicates weight, , This indicates the time delay for unloading edge federation tasks. The distance between terminal device j and edge federated service node i.

8. The method for protecting against bandwidth denial-of-allocation attacks in edge federation task offloading as described in claim 1, characterized in that, Step (3) the edge federation service node i adopts the reinforcement learning algorithm to determine the bandwidth resource selling price , as follows: State is defined as: ; in, For time slots The overall priority value of the end device j that makes a bandwidth request to edge federated service node i in the waiting queue. For time slots The minimum overall priority value of all end devices in the waiting queue that have made bandwidth requests to edge federated service node i. For time slots The maximum combined priority value of all end devices that have made bandwidth requests to edge federated service node i in the waiting queue; action Defined as edge federated service node i in time slot Submitted sales price , ;in, The selling price of edge federation service nodes; The reward function is expressed as: ; in, Indicates time slot The availability status of bandwidth resources for edge federation service node i. The overall priority value of terminal device j. To represent the penalty for the number of smart contract violations, a smart contract violation will occur if the edge federation service node cannot provide bandwidth resources to the end device; The strategy of edge federated service node i is a probability function that gives a specific bandwidth resource sales price given a state, with the objective of maximizing the probability of edge federated service node i from time... The rewards accumulated during the time slots after the start.

9. The method for protecting against bandwidth denial-of-allocation attacks in edge federation task offloading as described in claim 8, characterized in that, This indicates the penalty for violating a smart contract. The calculation method is as follows: ; in, The highest historical selling price for bandwidth resources for edge federation service nodes. To determine the bandwidth resource allocation priority for edge federated service node prediction end device j, the end device sends a confidential bid vector to the auctioneer. ,in This indicates that terminal device j bids for edge federated service node i; otherwise... ; Indicates time slot Edge federation service node i provides bandwidth services to end device j. If edge federation service node i allocates bandwidth resources to end device j, then Each edge federation service node's bandwidth resources are allocated to at least one end device, and each end device can be allocated bandwidth by at least one edge federation service node. Priority of bandwidth resource allocation for edge federated service node i predicting terminal device j This is used for distance calculation between edge federation service node observations and end devices.

10. The method for protecting against bandwidth denial-of-allocation attacks in edge federation task offloading as described in claim 8, characterized in that, Step (3) uses a deep Q-network model for decision-making.

Citation Information

Patent Citations

  • CPU resource trusted sharing system in sensing edge cloud task unloading of integrated block chain

    CN112783662A

  • Method for the deployment of distributed fog computing and storage architectures in robotic modular components

    EP3407194A2