A device and method for implementing a mimicking edge access device
By using the multi-mode adjudication module of the mimetic edge access device to adjudicate the response data of heterogeneous edge devices, the unknown vulnerabilities and backdoor attacks of the edge computing platform are solved, and the security protection of the edge computing platform is achieved.
Patent Information
- Application Number
- CN202310177129.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-02-28
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2043-02-28
AI Technical Summary
Edge computing platforms face unknown backdoor and vulnerability attacks. Traditional security mechanisms cannot effectively protect the access of massive heterogeneous edge devices, resulting in increased risks of DDoS attacks and network penetration.
By adopting mimetic edge access devices, the response data of heterogeneous edge access devices is judged through the multi-mode judgment module, suspected attack behaviors are detected and alarms are issued to protect the security of the edge computing platform.
Effectively defend against unknown vulnerabilities and backdoor attacks, promptly detect and handle anomalies, and ensure the security and stability of the edge computing platform.
Smart Images

Figure CN116318906B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of network security technology, and in particular relates to an implementation device and method for a mimicking edge access device. Background Art
[0002] With the rapid development of the Internet of Things (IoT) and 5G technologies, the number of mobile and IoT devices deployed in the physical world, and the data they generate, has exploded. This massive amount of data is rapidly consuming cloud computing network resources, hindering the provision of high-quality services. This has led to the emergence of edge computing. Edge computing migrates some computing, storage, and network application functions from cloud data centers to the edge of the network, providing more stable and reliable services for edge devices. This effectively addresses the issues of high latency, heavy computing and storage loads, and heavy network bandwidth burdens associated with data transmission between cloud data centers and devices.
[0003] However, the real-time nature of edge computing data processing, the heterogeneity of data from multiple sources, the limited terminal resources, and the complexity of access devices make the security mechanisms of traditional cloud computing environments no longer suitable for protecting the massive amounts of data generated by edge devices. In particular, the access of massive heterogeneous devices at the edge poses challenges to authentication and authorization mechanisms. A large number of malicious devices disguised as ordinary access devices launch DDoS attacks against edge computing platforms. Furthermore, the complex network environment at the edge makes end-access devices more vulnerable to network attacks based on unknown vulnerabilities and backdoors, which can then penetrate upwards, rendering the entire edge cloud platform insecure and unstable. Summary of the Invention
[0004] In response to the problems of unknown backdoors and vulnerability attacks faced by edge access devices, the present invention proposes an implementation device and method for a mimetic edge access device. Services are provided simultaneously through multiple heterogeneous edge access devices, and the response data returned by the heterogeneous edge access devices is sent to a multi-mode arbitration module for arbitration, thereby effectively discovering suspected attack behaviors and issuing alarms, further protecting the security of the edge computing platform.
[0005] In order to achieve the above object, the present invention adopts the following technical solutions:
[0006] The present invention provides an implementation device for a mimicking edge access device, comprising:
[0007] A control unit for controlling heterogeneous edge access devices;
[0008] The device monitoring unit is used to monitor the status and decision results of heterogeneous edge access devices in real time and report abnormal situations to the control unit so that the control unit can take measures accordingly;
[0009] The mimetic communication agent unit is used to receive requests from the edge computing platform and distribute them to heterogeneous edge access devices. At the same time, it adjudicates the response data uploaded by the heterogeneous edge access devices and reports the adjudication results to the edge computing platform.
[0010] The control unit is connected to the device monitoring unit and the edge computing platform respectively, the device monitoring unit is connected to the edge computing platform, and the edge computing platform is connected to the heterogeneous edge access device through the mimetic communication agent unit.
[0011] Furthermore, the control unit controls the heterogeneous edge access device, including: the control unit is responsible for lifecycle management, rule formulation, decision algorithm selection, and reporting of abnormal information of the heterogeneous edge access device.
[0012] Furthermore, the control unit and the device monitoring unit run on the edge cloud node; the mimetic communication agent unit runs on the edge computing platform node.
[0013] Furthermore, the mimetic communication agent unit includes a link maintenance module, a message distribution and link maintenance module, a message parsing and data extraction module, a semantic tree data storage module and a multi-mode arbitration module;
[0014] A link maintenance module is used to maintain the link between the mimetic communication agent unit and the edge computing platform, receive requests from the edge computing platform or transmit response results to the edge computing platform;
[0015] The message distribution and link maintenance module is used to maintain the link between the mimetic communication agent unit and the heterogeneous edge access device, and distribute the request message sent by the edge computing platform to the heterogeneous edge access device to the heterogeneous edge access device;
[0016] The message parsing and data extraction module is used to parse the response message returned by the heterogeneous edge access device, extract the key data and store it in the semantic tree data storage module;
[0017] The semantic tree data storage module is used to define the semantic tree storage specification and store the key data extracted from the request message and response message according to the defined semantic tree;
[0018] The multi-mode decision module is used to make decisions on the response data stored in the semantic tree data storage module.
[0019] The present invention also provides a method for implementing a mimetic edge access device, comprising the following steps:
[0020] Step 1: Select a heterogeneous edge access device and connect it to the mimicry implementation device; select an edge computing platform to be protected and establish a link between the edge computing platform and the mimicry implementation device;
[0021] Step 2: The user initiates a data acquisition request to the edge computing platform;
[0022] Step 3: The edge computing platform sends the request message to the mimetic communication agent unit, which distributes the request message to the heterogeneous edge access device.
[0023] Step 4: After receiving the request, the heterogeneous edge access device returns the response data to the mimetic communication agent unit;
[0024] Step 5: The mimetic communication agent unit decides on the request response of the heterogeneous edge access device and sends the decision result to the edge computing platform;
[0025] In step 6, the device monitoring unit obtains the judgment result from the edge computing platform for real-time monitoring, reports the abnormal result to the control unit, and the control unit makes a corresponding decision and sends the decision to the edge computing platform, which executes the decision.
[0026] Furthermore, step 3 specifically includes: the request message initiated by the edge computing platform enters the mimetic communication agent unit through the link maintenance module, the request message is first stored in the semantic tree data storage module, and then the message distribution and link maintenance module distributes the request message to the heterogeneous edge access device.
[0027] Furthermore, step 4 specifically includes: after the heterogeneous edge access device receives the request, the returned response data enters the mimetic communication agent unit through the message distribution and link maintenance module, and the message parsing and data extraction module in the mimetic communication agent unit parses it, extracts the key data and stores it in the semantic tree data storage module according to the defined semantic tree.
[0028] Furthermore, step 5 specifically includes: when the responses of heterogeneous edge access devices for the same request all reach the semantic tree data storage module, the data is sent to the multi-mode decision module for comparison and decision. If there is an anomaly in the comparison result and the other two results are consistent, the consistent result is selected and returned to the edge computing platform. If the three data are completely different, the device result with the highest weight is selected and returned to the edge computing platform.
[0029] Compared with the prior art, the present invention has the following advantages:
[0030] The development of 5G technology has driven the development of edge computing, and the security issues of a large number of edge access devices cannot be effectively guaranteed under the existing edge computing technology, making resource-limited edge access devices vulnerable to attacks from unknown vulnerabilities and backdoors, and then being exploited to launch attacks on the entire edge computing platform. The present invention proposes an implementation device and method for mimicking edge access devices, which adopts the core idea of active defense technology in cyberspace, and is aimed at a large number of lightweight and resource-limited edge access devices. By performing dynamic, heterogeneous, and redundant mimicry transformation on the edge access devices, the response messages are uploaded after being judged by the mimic communication agent unit, effectively defending against attacks on the edge computing platform launched by exploiting unknown vulnerabilities and backdoors of the edge access devices, and enabling attacks to be discovered and processed in a timely manner to prevent further penetration and spread, effectively ensuring the security of the entire edge computing platform. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0032] Figure 1 This is a structural block diagram of an implementation device of a mimetic edge access device according to an embodiment of the present invention;
[0033] Figure 2 It is a flowchart of a method for implementing a mimicking edge access device according to an embodiment of the present invention. DETAILED DESCRIPTION
[0034] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0035] like Figure 1 As shown, the implementation device of the mimicked edge access device in this embodiment includes a control unit, a device monitoring unit and a mimicked communication agent unit.
[0036] The control unit is used to control heterogeneous edge access devices, including: (a) when an abnormal situation occurs, the control unit performs lifecycle management of the heterogeneous edge access devices; (b) rule-making, such as establishing a fault tolerance mechanism. For example, if the heterogeneous edge access devices are equipped with different models of temperature and humidity sensors A1, A2, and A3, and the temperature value of temperature and humidity sensor A1 is 31°C, the temperature value of temperature and humidity sensor A2 is 30°C, and the temperature value of temperature and humidity sensor A3 is 30.5°C, since the objective error is allowed, the fault tolerance value can be set to ±2°C, and the access device does not need to be disconnected in this case. (c) Decision algorithm selection, which can include the following: majority consensus decision, weight-based decision, and random decision. (d) Reporting of abnormal information.
[0037] The device monitoring unit is used to monitor the status of heterogeneous edge access devices (such as whether the access device is accidentally disconnected) and the judgment results in real time, and report abnormal situations to the control unit so that the control unit can take measures to address the abnormal situations.
[0038] The mimetic communication agent unit is used to receive requests from the edge computing platform and distribute them to heterogeneous edge access devices. At the same time, it adjudicates the response data uploaded by the heterogeneous edge access devices and reports the adjudication results to the edge computing platform.
[0039] The connection between these units is as follows: the edge computing platform connects to heterogeneous edge access devices via the mimetic communication agent unit; the device monitoring unit connects to the edge computing platform, obtains the status and adjudication results of heterogeneous edge access devices in real time, and reports abnormal information to the control unit. The control unit is connected to the device monitoring unit and the edge computing platform, receives device abnormality information, and makes corresponding decisions.
[0040] The entire system consists of three parts: edge cloud nodes, an edge computing platform, and end-access devices. Edge cloud nodes are primarily responsible for dynamically adjusting the edge computing platform's deployment strategies and algorithms based on network resource distribution and permanently storing data reported by the edge computing platform. The edge computing platform is primarily responsible for deploying configurations issued by edge cloud nodes and processing data reported by end-access devices. End-access devices, comprised of various IoT devices, are primarily responsible for data collection and reporting. Therefore, the control unit and device monitoring unit, as control-layer components, run on edge cloud nodes. The mimetic communication agent unit, acting as a proxy between the edge computing platform and end-access devices, runs on edge computing platform nodes.
[0041] Specifically, the mimetic communication agent unit includes a link maintenance module, a message distribution and link maintenance module, a message parsing and data extraction module, a semantic tree data storage module and a multi-modal decision module. The functions of each module are as follows.
[0042] The link maintenance module is used to maintain the link between the mimetic communication agent unit and the edge computing platform, receive requests from the edge computing platform or transmit response results to the edge computing platform.
[0043] The message distribution and link maintenance module is used to maintain the link between the mimetic communication agent unit and the heterogeneous edge access device, and distribute the request message sent by the edge computing platform to the heterogeneous edge access device to the heterogeneous edge access device.
[0044] The message parsing and data extraction module is used to parse the response message returned by the heterogeneous edge access device, extract the key data and store it in the semantic tree data storage module. For the heterogeneous temperature and humidity sensors mentioned above, the key data refers to the temperature and humidity values.
[0045] The semantic tree data storage module is used to define the semantic tree storage specification and store the key data extracted from the request message and the response message according to the defined semantic tree.
[0046] The multi-mode decision module is used to make decisions on the response data stored in the semantic tree data storage module. A variety of decision algorithms can be used to make decisions on the response data to cope with various emergencies that may occur in the actual production environment.
[0047] Based on the implementation device of the above-mentioned mimicry edge access device, Figure 2 As shown, this embodiment also proposes a method for implementing a mimicking edge access device, including the following steps:
[0048] Step S101: Select the edge computing platform and heterogeneous edge access devices that need to be protected, such as temperature and humidity sensors A1, A2, and A3 of different models.
[0049] Step S102: deploy a mimetic communication agent unit at the edge computing platform node, wherein the message distribution and link maintenance module is connected to the heterogeneous edge access device, and the link maintenance module is connected to the edge computing platform.
[0050] Step S103, deploying a device monitoring unit and a control unit at the edge cloud node; wherein the control unit is connected to the device monitoring unit and the edge computing platform respectively, and the device monitoring unit is connected to the edge computing platform.
[0051] In step S104, the user initiates a data acquisition request to the edge computing platform. The request message initiated by the edge computing platform enters the mimetic communication agent unit through the link maintenance module.
[0052] In step S105 , the request message is stored in the semantic tree data storage module, and then the message distribution and link maintenance module distributes the request message to the heterogeneous edge access device.
[0053] In step S106, after receiving the request, the heterogeneous edge access device sends the response data to the mimetic communication agent unit through the message distribution and link maintenance module.
[0054] In step S107 , the message parsing and data extraction module in the mimetic communication agent unit parses the returned request response, extracts key data and stores it in the semantic tree data storage module according to the defined semantic tree.
[0055] In step S108, the multi-mode adjudication module adjudicates the data stored in the semantic tree data storage module and sends the adjudication results to the edge computing platform. After all responses from heterogeneous edge access devices to the same request reach the semantic tree data storage module, the data is sent to the multi-mode adjudication module for comparison and adjudication. If one of the comparison results is abnormal and the other two are consistent, the consistent result is selected and returned to the edge computing platform. If all three data are different, the device with the highest weight is selected based on previous judgment results and returned to the edge computing platform.
[0056] Step S109: If there is no abnormality, the user directly obtains the response data through the edge computing platform.
[0057] In step S110, if an abnormal situation occurs, the user can obtain the response data after the judgment through the edge computing platform. At the same time, the device monitoring unit reports the abnormal result to the control unit. The control unit makes a decision such as disconnecting the abnormal edge access device or sending the abnormal information to the administrator in the form of an alarm, and sends the decision to the edge computing platform, which executes the decision.
[0058] It should be noted that, in this article, the terms "comprises", "includes" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, article or apparatus that includes a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements that are inherent to such process, method, article or apparatus.
[0059] Finally, it should be noted that the above description is merely a preferred embodiment of the present invention and is intended only to illustrate the technical solution of the present invention and is not intended to limit the scope of protection of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention are included within the scope of protection of the present invention.
Claims
1. A device for implementing a mimicking edge access device, characterized in that: include: A control unit is responsible for lifecycle management, rule development, adjudication algorithm selection, and exception information reporting for heterogeneous edge access devices, including temperature and humidity sensors of different models. The device monitoring unit is used to monitor the status and decision results of heterogeneous edge access devices in real time and report abnormal situations to the control unit so that the control unit can take measures accordingly; The mimetic communication agent unit is used to receive requests from the edge computing platform and distribute them to heterogeneous edge access devices. At the same time, it adjudicates the response data uploaded by the heterogeneous edge access devices and reports the adjudication results to the edge computing platform. The control unit is connected to the device monitoring unit and the edge computing platform respectively, the device monitoring unit is connected to the edge computing platform, and the edge computing platform is connected to the heterogeneous edge access device through the mimetic communication agent unit; The mimetic communication agent unit includes a link maintenance module, a message distribution and link maintenance module, a message parsing and data extraction module, a semantic tree data storage module and a multi-mode arbitration module; A link maintenance module is used to maintain the link between the mimetic communication agent unit and the edge computing platform, receive requests from the edge computing platform or transmit response results to the edge computing platform; The message distribution and link maintenance module is used to maintain the link between the mimetic communication agent unit and the heterogeneous edge access device, and distribute the request message sent by the edge computing platform to the heterogeneous edge access device to the heterogeneous edge access device; The message parsing and data extraction module is used to parse the response message returned by the heterogeneous edge access device, extract the key data and store it in the semantic tree data storage module; The semantic tree data storage module is used to define the semantic tree storage specification and store the key data extracted from the request message and response message according to the defined semantic tree; The multi-mode decision module is used to make decisions on the response data stored in the semantic tree data storage module.
2. The implementation device of the mimicking edge access device according to claim 1, characterized in that: The control unit and the device monitoring unit run on the edge cloud node; the mimetic communication agent unit runs on the edge computing platform node.
3. A method for implementing a mimicking edge access device, characterized in that: The implementation device of the mimicking edge access device according to claim 1 is implemented, comprising the following steps: Step 1: Select a heterogeneous edge access device and connect it to the mimicry implementation device; select an edge computing platform to be protected and establish a link between the edge computing platform and the mimicry implementation device; Step 2: The user initiates a data acquisition request to the edge computing platform; Step 3: The edge computing platform sends the request message to the mimetic communication agent unit, which distributes the request message to the heterogeneous edge access device. Step 4: After receiving the request, the heterogeneous edge access device returns the response data to the mimetic communication agent unit; Step 5: The mimetic communication agent unit decides on the request response of the heterogeneous edge access device and sends the decision result to the edge computing platform; In step 6, the device monitoring unit obtains the judgment result from the edge computing platform for real-time monitoring, reports the abnormal result to the control unit, and the control unit makes a corresponding decision and sends the decision to the edge computing platform, which executes the decision.
4. The method for implementing a mimicking edge access device according to claim 3, wherein: The step 3 specifically includes: the request message initiated by the edge computing platform enters the mimetic communication agent unit through the link maintenance module, the request message is first stored in the semantic tree data storage module, and then the message distribution and link maintenance module distributes the request message to the heterogeneous edge access device.
5. The method for implementing a mimicking edge access device according to claim 4, wherein: The step 4 specifically includes: after the heterogeneous edge access device receives the request, the returned response data enters the mimetic communication agent unit through the message distribution and link maintenance module, the message parsing and data extraction module in the mimetic communication agent unit parses the message, extracts the key data and stores it in the semantic tree data storage module according to the defined semantic tree.
6. The method for implementing a mimicking edge access device according to claim 5, wherein: The step 5 specifically includes: when the responses of heterogeneous edge access devices for the same request all reach the semantic tree data storage module, the data is sent to the multi-mode decision module for comparison and decision; if there is an anomaly in the comparison result and the other two results are consistent, the consistent result is selected and returned to the edge computing platform; if the three data are completely different, the device result with the highest weight is selected and returned to the edge computing platform.
Citation Information
Patent Citations
Implementation method of mimicry industrial edge computing gateway
CN113422721A