Network security access method, device and equipment and storage medium
By employing a trusted federated learning architecture combining federated machine learning and blockchain technology in a distributed system, a secure access authentication model is trained, solving the problem of privacy leakage of access devices in distributed systems, achieving secure and reliable network access authentication, and improving system security.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- BEIJING UNIV OF POSTS & TELECOMM
- Filing Date
- 2023-03-07
- Publication Date
- 2026-07-24
AI Technical Summary
Existing network access authentication methods pose a risk of privacy leaks to access devices in distributed systems, making it difficult to guarantee the security of participating devices or user identities.
Employing a trusted federated learning architecture based on federated machine learning and blockchain technologies, secure authentication is achieved by training a secure access authentication model locally on the access device and recording the model training process on the blockchain, thus avoiding the transmission of raw data.
Without compromising privacy data, it improves the secure access of network devices and users in distributed systems, thereby enhancing the overall security and trustworthiness of the system.
Smart Images

Figure CN116405262B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network access security authentication technology, and in particular to a network security access method, apparatus, device, and storage medium. Background Technology
[0002] With the rapid development of technology, digital technologies, led by artificial intelligence, have provided essential tools for our lives, playing a vital role in fields such as healthcare, manufacturing, and services. For example, devices using technologies like magnetic card identification or RFID (Radio Frequency Identification) are used for access control, while fingerprint and facial recognition are used for access management and data flow. Consequently, to enhance the level of intelligence, the demand for data flow across various industries in China is increasingly strong. Distributed systems are typically used in network data flow. These systems consist of multiple independent computer systems interconnected by a network. By breaking down massive computational problems into sub-problems and distributing them to various terminals, the network's computing resources can be fully utilized. However, the collaborative nature of computation places high demands on the security of the devices involved in the computation, making the leakage of privacy information a potential concern.
[0003] Current network access authentication methods are implemented through device fields or user passwords. During the authentication process, a machine learning model for authentication is distributed to the access device to verify the identity of the user. However, since this machine learning model is trained centrally, its training process requires access to the local data of the access device. Therefore, there is a risk of privacy leakage of the access device, which makes it difficult for the existing network access methods to guarantee the security of the participating devices or user identities. Summary of the Invention
[0004] This invention provides a network security access method, apparatus, device, and storage medium to address the low security of network devices or user network access in distributed network scenarios in the prior art. It realizes an identity security authentication model based on trusted federated learning technology, aggregates training data scattered in the network by exchanging model parameters, effectively protects privacy data security, and records the entire process of model training through a layered blockchain participating in communication, providing data support for user management and security auditing.
[0005] This invention provides a network security access method, the method comprising:
[0006] When an access device participating in federated consensus in a distributed system receives a network security access request, the network security access request is input into the security access authentication model corresponding to the access device, and the authentication result is output.
[0007] The secure access authentication model is trained based on federated machine learning technology and blockchain technology, as well as the local privacy dataset of the access device. The secure access authentication model is used to perform secure authentication on the identity feature data in the access device that receives the network security access request.
[0008] Based on the authentication result, respond to the network security access request to complete the network security access.
[0009] According to a network security access method provided by the present invention, the secure access authentication model includes an input layer, two pooling layers, three convolutional layers, two fully connected layers, and an output layer. The fully connected layers include a unified fully connected layer and a personalized layer.
[0010] The step of inputting the network security access request into the secure access authentication model and outputting the authentication result includes:
[0011] Based on the input layer, according to the original data format of the access device of the federated consensus, the identity feature data corresponding to the network security access request is input into the deep neural network for feature extraction to obtain the identity feature matrix of the access device user.
[0012] Based on the pooling layer, an abstract feature matrix representing the identity features is obtained from the identity feature matrix, and the abstract feature matrix is input into the convolutional layer;
[0013] Based on the convolutional layer, the abstract feature matrix is organized, and the organized abstract feature matrix is then connected to the fully connected layer.
[0014] Based on the unified fully connected layer, an aggregation operation is performed according to the abstract feature matrix to obtain the in-chip model; based on the personalization layer, the in-chip model is updated to obtain the secure access authentication model.
[0015] Based on the output layer, and according to the secure access authentication model, the probability that the identity feature data of the access device is valid in this state is output, and the authentication result is obtained.
[0016] According to a network security access method provided by the present invention, the secure access authentication model is obtained by training based on the following steps:
[0017] Based on the data distribution characteristics of the local privacy dataset, multiple access devices participating in the federated consensus are classified to obtain at least one slice, and the slice includes at least one access device.
[0018] Obtain the machine learning model used to identify network security access within the current slice;
[0019] The machine learning model is distributed to each access device within the current slice, so that the access device can train the machine learning model based on its local privacy dataset to obtain at least one local model;
[0020] The local model is shared by a distributed blockchain service running on the access device, and the sharded model formed by aggregating the local models based on a federated averaging algorithm is used as a secure access authentication model.
[0021] According to a network security access method provided by the present invention, after sharing the local model through a distributed blockchain service running on the access device and using a sharded model formed by aggregating the local models based on a federated averaging algorithm as a secure access authentication model, the method further includes:
[0022] The secure access authentication models corresponding to each shard are aggregated based on the federated averaging algorithm to form a global model;
[0023] The optimized security access authentication model is obtained by adjusting the model parameters of the global model.
[0024] Using the optimized secure access authentication model as the initial machine learning model, the process continues to train the machine learning model based on the local sample dataset of the access device within the current slice, obtaining at least one local model, until the training termination condition is met, resulting in the final secure access authentication model.
[0025] According to a network security access method provided by the present invention, the security access authentication model corresponding to each shard is aggregated based on a federated averaging algorithm to form a global model, including...
[0026] Based on the reputation mechanism, the security access authentication models corresponding to each shard are screened, and the models that meet the reputation score conditions are selected as shard models.
[0027] The fragment models corresponding to each fragment are aggregated based on the federated averaging algorithm to form a global model.
[0028] According to a network security access method provided by the present invention, the method classifies multiple access devices participating in federated consensus based on the data distribution characteristics of a local privacy dataset to obtain at least one shard, including:
[0029] The data distribution characteristics of the local privacy dataset of the access device in the federated consensus are calculated to obtain the feature matrix corresponding to the local privacy dataset.
[0030] Based on the hierarchical clustering algorithm and the feature matrix, the similarity of the local privacy dataset of the access device is calculated to obtain the optimal segmentation scheme for classifying the access device under a preset number of categories.
[0031] Based on decision indicators for network security access, a target layering scheme is selected from the optimal layering scheme. The target layering scheme includes at least one slice and at least one access device within the slice.
[0032] According to a network security access method provided by the present invention, the decision indicators include indicators of data similarity within a cluster, communication overhead, and consensus credibility, wherein the cluster is constructed by the access device with the highest degree of similarity in local privacy data.
[0033] According to a network security access method provided by the present invention, the step of selecting a target layering scheme from the optimal layering scheme based on decision indicators during network security access includes:
[0034] Calculate the average distance between the local privacy datasets of access devices within a cluster to obtain the internal data similarity of the cluster;
[0035] Obtain a blockchain communication network optimized based on the Byzantine consensus algorithm, and calculate the data corresponding to the communication overhead index and the data corresponding to the consensus trust index based on the blockchain communication network.
[0036] The internal data similarity, communication overhead, and consensus credibility are input into a preset reputation calculation model to calculate the reputation score corresponding to each optimal stratification scheme.
[0037] The optimal stratification scheme with the highest reputation score is selected as the target stratification scheme.
[0038] The present invention also provides a network security access device, comprising:
[0039] The security authentication module is used to input a network security access request into the security access authentication model corresponding to the access device when an access device participating in federated consensus in a distributed system receives a network security access request, and output the authentication result.
[0040] The secure access authentication model is trained based on federated machine learning technology and blockchain technology, as well as the local privacy dataset of the access device. The secure access authentication model is used to perform secure authentication on the identity feature data in the access device that receives the network security access request.
[0041] The request-response module is used to respond to the network security access request based on the authentication result, so as to complete the network security access.
[0042] The present invention also provides a network security access device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement any of the network security access methods described above.
[0043] The present invention also provides a non-transitory computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the network security access method as described above.
[0044] The present invention also provides a computer program product, including a computer program that, when executed by a processor, implements any of the network security access methods described above.
[0045] The network security access method, apparatus, device, and storage medium provided by this invention, when an access device participating in federated consensus in a distributed system receives a network security access request, inputs the network security access request into the secure access authentication model corresponding to the access device and outputs an authentication result. The secure access authentication model is trained based on federated machine learning technology, blockchain technology, and the local privacy dataset of the access device. This model is used to securely authenticate the identity feature data of the access device receiving the network security access request. Based on the authentication result, a response is made to the network security access request to complete the network security access. That is, under a trusted federated learning architecture based on federated machine learning technology and blockchain technology, each distributed access device participating in federated learning trains a secure access authentication model based on its local privacy dataset. This achieves training of the secure access authentication model without transmitting original privacy data. Compared with traditional access authentication methods, this avoids the privacy leakage risk caused by centralized model training. Furthermore, since the aggregated model is stored on the blockchain throughout the process, the model training process is traceable, secure, and trustworthy, better meeting the requirements for user access security in a distributed system environment. This achieves secure access for distributed network devices or users and improves the overall system security. Attached Figure Description
[0046] To more clearly illustrate the technical solutions in this invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.
[0047] Figure 1 This is one of the flowcharts illustrating the network security access method provided by the present invention;
[0048] Figure 2 This is a schematic diagram of the federated learning model structure based on layered blockchain in the network security access method provided by this invention;
[0049] Figure 3 This is a schematic diagram of the secure access authentication model structure in the network security access method provided by the present invention;
[0050] Figure 4 This is a structural schematic diagram of the network security access device provided by the present invention. Detailed Implementation
[0051] To make the objectives, technical solutions, and advantages of this invention clearer, the technical solutions of this invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some, not all, of the embodiments of this invention. All other embodiments obtained by those skilled in the art based on the embodiments of this invention without creative effort are within the scope of protection of this invention.
[0052] The following is combined Figures 1-4 The network security access method of the present invention is described with reference to Figure 1 The network security access method includes:
[0053] Step S100: When an access device participating in federated consensus in the distributed system receives a network security access request, the network security access request is input into the security access authentication model corresponding to the access device, and the authentication result is output.
[0054] The secure access authentication model is trained based on federated machine learning technology and blockchain technology, as well as the local privacy dataset of the access device. The secure access authentication model is used to perform secure authentication on the identity feature data in the access device that receives the network security access request.
[0055] Step S200: Respond to the network security access request based on the authentication result to complete the network security access.
[0056] This embodiment aims to train and create a secure access authentication model by using a trusted federated learning algorithm based on federated machine learning and blockchain technology, and the local privacy datasets of each access device participating in federated mutual recognition in a distributed network environment. This avoids the privacy leakage risk caused by centralized model training. Furthermore, since the aggregated secure access authentication model is stored on the blockchain throughout the entire process, the model training process is traceable, secure, and trustworthy. This can better meet the requirements for user access security in a distributed system environment and ensure the security of the identities of participating devices or users when accessing the network.
[0057] In this embodiment, the specific application scenario is:
[0058] With the rapid development of technology, digital technologies, led by artificial intelligence, have provided essential tools for our lives, playing a vital role in fields such as healthcare, manufacturing, and services. For example, devices using technologies like magnetic card identification or RFID (Radio Frequency Identification) are used for access control, while fingerprint and facial recognition are used for access management and data flow. Consequently, to enhance the level of intelligence, the demand for data flow across various industries in China is increasingly strong. Distributed systems are typically used in network data flow. These systems consist of multiple independent computer systems interconnected by a network. By breaking down massive computational problems into sub-problems and distributing them to various terminals, the network's computing resources can be fully utilized. However, the collaborative nature of computation places high demands on the security of the devices involved in the computation, making the leakage of privacy information a potential concern.
[0059] For the reasons mentioned above, current network access authentication methods are implemented through device fields or user passwords. During the authentication process, a machine learning model for authentication is distributed to the access device to verify the identity of the user. However, since this machine learning model is trained centrally, its training process requires access to the local data of the access device. Therefore, there is a risk of privacy leakage of the access device, which makes it difficult for the existing network access methods to guarantee the security of the participating devices or user identities.
[0060] As an example, the network security access method can be applied to a network security access system, which is applied to a network security access device.
[0061] As an example, blockchain technology, with its decentralized, traceable, and tamper-proof characteristics, is well-suited as a trusted database system in a distributed environment.
[0062] As an example, federated learning, as a decentralized machine learning technique, can improve the performance of a local model by sharing the model with other participants without revealing the local dataset.
[0063] As an example, trusted federated learning is a distributed machine learning method that satisfies user privacy and security while also considering model performance. This invention utilizes blockchain technology in a distributed scenario to simultaneously achieve multi-terminal sharing of model data and recording of the machine learning model training process. Based on the inherent immutability of blockchain technology, it ensures model security and traceability.
[0064] The specific steps are as follows:
[0065] Step S100: When an access device participating in federated consensus in the distributed system receives a network security access request, the network security access request is input into the security access authentication model corresponding to the access device, and the authentication result is output.
[0066] The secure access authentication model is trained based on federated machine learning technology and blockchain technology, as well as the local privacy dataset of the access device. The secure access authentication model is used to perform secure authentication on the identity feature data in the access device that receives the network security access request.
[0067] It should be noted that a distributed system consists of multiple independent computer systems interconnected by a network. By breaking down a huge computational problem into subproblems and distributing them to various terminals, the computing resources in the network can be fully utilized.
[0068] As an example, the secure access authentication model is trained using federated machine learning and blockchain technologies, along with the local privacy datasets of the access devices. This model is used to securely authenticate the identity features of the access devices receiving secure access requests. In other words, while protecting the original local privacy data of the access devices through federated learning, it fully utilizes the data and computational resources of the distributed system. Based on the same initial model, each distributed terminal participating in federated learning trains a machine learning model using its local privacy dataset. The model parameters from this training round are shared through a distributed blockchain service running on the access device. The blockchain, through decentralized smart contracts, uses a federated aggregation function to obtain the secure access authentication model for the federated network.
[0069] Therefore, in this embodiment, the present invention proposes a secure access authentication model training algorithm using trusted federated learning. The purpose is to train a secure access authentication model without transmitting original privacy data in a distributed system scenario where they are interconnected through a network, thereby enabling secure access for distributed network devices or users, improving the overall security of the system, and meeting the system's trust requirements.
[0070] As an example, the secure access authentication model is trained based on the following steps:
[0071] Step A1: Based on the data distribution characteristics of the local privacy dataset, classify the multiple access devices participating in the federated consensus to obtain at least one shard, wherein the shard includes at least one access device.
[0072] Step A2: Obtain the machine learning model used to identify network security access within the current shard;
[0073] Step A3: Distribute the machine learning model to each access device within the current segment, so that the access device can train the machine learning model based on its local privacy dataset to obtain at least one local model;
[0074] Step A4: By sharing the local model through the distributed blockchain service running on the access device, the sharded model formed by aggregating the local models based on the federated averaging algorithm is used as the secure access authentication model.
[0075] In the trusted federated learning architecture, devices participating in the federated consensus share updated model parameter data for each round through a distributed blockchain network. During this process, changes in parameters for each participant and their impact on the global model are recorded in a blockchain-based distributed database. Due to the non-repudiation and immutability inherent in blockchain technology, a trusted record of the secure access model training process can be formed, making it highly suitable as a trusted database system in a distributed environment. Therefore, blockchain is used for exchanging model parameters during the training and creation of the secure access authentication model to improve the security requirements for user access in a distributed system environment.
[0076] It's important to note that in federated learning, the data from the participants or access devices used for model training is locally private, and their privacy datasets may vary. When training a machine learning model using datasets with different distributions, its final prediction performance will be reduced or suboptimal. Therefore, it is essential to aggregate participants or access devices with similar characteristics to jointly train a high-performance local model.
[0077] Based on this, according to the data distribution characteristics of the local privacy dataset, multiple access devices participating in the federated consensus are classified. Access devices with similar data distribution characteristics are grouped into a single shard. The corresponding secure access authentication model is trained using the local privacy dataset of the access devices within that shard. Thus, after classifying all access devices in the distributed scenario's federated consensus, at least one shard is formed, with each shard containing at least one access device, and the access devices within a shard exhibiting similar data distribution characteristics.
[0078] As an example, based on the data distribution characteristics of a local privacy dataset, multiple access devices participating in the federated consensus are classified to obtain at least one shard result. The trusted federated learning network can be divided into a three-layer network structure, referring to... Figure 2 These consist of a local model layer, a sharded model layer, and a global model layer. Using a layered network structure can achieve a balance between performance and security during model training, particularly in areas such as model aggregation, network communication, consensus computation, and data security, providing underlying technical guarantees for secure network access authentication.
[0079] In a hierarchical federated learning architecture, local models serve as the data support for distributed machine learning. Devices participating in federated learning train machine learning models to identify secure network access based on locally stored data. However, due to the limited capacity of local datasets, the accuracy and robustness of local models in identifying secure network access are often insufficient for practical needs. Therefore, it is necessary to leverage the local models of other participants within the shard, indirectly utilizing datasets scattered throughout the network, to collaboratively train high-performance machine learning models for secure network access authentication. Compared to typical centralized machine learning training, trusted federated learning, based on network communication and cryptography principles, exchanges local models obtained from local datasets and collaboratively calculates shard models suitable for the shard through a federated averaging algorithm. Because the multi-objective network hierarchical scheme considers the impact of the distribution of collaborating parties' local data on the performance of shard models, and because the data of participants within a shard in a real network has an approximate probability distribution, the performance of the aggregated shard models for secure network access is guaranteed.
[0080] The specific secure access authentication model process is as follows, where the hierarchical federated learning network architecture consists of a three-layer structure: the local model of each participant serves as the basis for the aggregation model, and the sharding model is the final secure access authentication model used for network access security authentication.
[0081] Step a: Define a secure access authentication model as a sharding model, and randomly initialize the model parameters of this secure access authentication model to obtain the machine learning model used for identifying network security access within the current shard. In network security access scenarios, the secure access authentication model mainly determines the legitimacy of the device or user's identity based on the device's physical characteristics or data that can identify the device user's identity characteristics, thereby realizing the business function of access authentication.
[0082] Step b: The initialized shard model (i.e., the machine learning model used to identify network security access within the current shard) is distributed to all participants within the shard (i.e., access devices participating in the federated consensus within the shard). Each participant uses its local privacy dataset to train the initialized shard model and obtain a local model.
[0083] The initialized piecewise model training uses a cross-entropy-based loss function to determine the local model, and its calculation formula is as follows:
[0084]
[0085] y in the formula i This is the prediction result of the model using one-hot encoding. When the classification result is true, y... i =1, otherwise y i =0. In the formula, p iThis represents the true predicted probability output by the model, and its value is within a fixed range after Softmax processing. When the value of the loss function meets the function threshold, the currently trained model is considered a local model. It should be noted that the function threshold is adjusted based on the performance of the local privacy dataset.
[0086] Step c: Based on the local models of each participant, the local models and their parameters are shared through a distributed blockchain service running on the access device. The local models are then aggregated using a federated averaging algorithm to obtain a sharded model with higher performance.
[0087] The federated aggregation formula is as follows:
[0088]
[0089] The above formula yields the fragmentation model, which is also the secure access authentication model used to identify network security access. It can be understood that the model parameters are weighted and averaged according to the size of the participants' local datasets, thus obtaining a secure access authentication model for fragmented networks without transmitting original local user data.
[0090] In this embodiment, the identity security authentication model based on trusted federated learning technology, compared with the traditional centralized machine learning model which requires the transmission of the original set and poses a risk of privacy leakage, aggregates training data scattered in the network by exchanging model parameters, effectively ensuring privacy and data security. Furthermore, the blockchain participating in the communication records the entire process of model training, providing data support for user management and security auditing.
[0091] Furthermore, in distributed machine learning networks, due to differences in participating devices and the size of users' local data, local datasets can vary in quality. Therefore, this invention designs a reputation mechanism to improve the performance of the aggregated sharded model. The reputation mechanism considers the impact of accuracy and timeliness on the aggregated model, and the reputation score is calculated as follows:
[0092] G t =exp[-α*(t) now -t commit )]
[0093]
[0094] G = G t +α*G a
[0095] In the formula, G t This represents a reputation score based on timeliness, when the model is submitted at time t. commit With current time t nowThe closer the representation is to the timeliness of the model, the better; in the formula, G a Based on the authentication accuracy of the local model on the test set, the reputation score of the local model obtained by each participant in the current round of training can be calculated by adding the two with a certain coefficient.
[0096] The local models and sharded models are isomorphic. The federated averaging algorithm uses the local models selected through a reputation mechanism. Therefore, based on the reputation scores of each local model, multiple local models with high reputation scores are selected, and these selected local models participate in federated aggregation to form a secure access authentication model.
[0097] As an example, after sharing the local model through a distributed blockchain service running on the access device, and using the sharded model formed by aggregating the local models based on a federated averaging algorithm as the secure access authentication model, the method further includes:
[0098] Step B1: Aggregate the security access authentication models corresponding to each shard based on the federated averaging algorithm to form a global model;
[0099] Step B2: Adjust the model parameters of the secure access authentication model through the global model to obtain the optimized secure access authentication model;
[0100] Step B3: Using the optimized secure access authentication model as the initial machine learning model, continue to train the machine learning model based on the local sample dataset of the access device in the current slice to obtain at least one local model, until the training termination condition is met to obtain the final secure access authentication model.
[0101] It's important to note that, similar to the sharded model, the global model is formed by aggregating the sharded models generated in each iteration using a federated averaging algorithm. Compared to the sharded model, the global model may perform worse in scenarios involving identifying network security access because the datasets of the participants used between shards may differ. However, since the global model actually indirectly uses the local datasets of all federated learning participants in the distributed network, it has certain advantages in terms of model robustness.
[0102] Therefore, the secure access authentication models corresponding to each shard are aggregated based on the federated averaging algorithm to form a global model. The model parameters are adjusted according to the performance of the global model. These model parameters are determined based on the different weights of the global model to accelerate the bracelet, thus resulting in an optimized secure access authentication model for each shard.
[0103] The optimized secure access authentication model is used as the initial machine learning model (i.e., the initial sharding model) and then redistributed to the access devices within the corresponding shards. The optimized secure access authentication model is then trained again using the local privacy dataset of each access device to obtain a new local model. This new local model is then aggregated to form a new intra-shard model, i.e., the new secure access authentication model. The secure access authentication model formed after multiple iterations of training not only incorporates the probability distribution characteristics of user data from the same type of access devices within the shard but also possesses a certain degree of robustness when combined with the global model.
[0104] Therefore, in this embodiment, the aggregated global model helps the sharded model achieve rapid convergence. At the application level, when the sharded model performs poorly, the global model is used more to help reach a better performance level as quickly as possible. However, since the intra-shard training dataset has an approximate probability distribution, the impact of the global model on the sharded model updates should be reduced when the prediction performance reaches a high level. In the training process of the network security access authentication model, comprehensively applying the global model at different stages can ensure both rapid model convergence and the acquisition of a high-performance model.
[0105] As an example, the aggregation of the secure access authentication models corresponding to each shard based on the federated averaging algorithm to form a global model includes...
[0106] Step B11: Based on the reputation mechanism, the security access authentication models corresponding to each shard are screened, and the models that meet the reputation score conditions are selected as shard models.
[0107] Step B12: Aggregate the shard models corresponding to each shard based on the federated averaging algorithm to form a global model.
[0108] The aggregation process of the global model is similar to that of the sharded model. The sharded models, which have been filtered by the reputation mechanism, are input into the federated average algorithm, and the calculation formula is as follows:
[0109]
[0110] While the global model may be slightly less accurate than the sharded model on data with a specific distribution, it indirectly uses more training data, and the sharded model used for aggregation is filtered by a reputation mechanism. Therefore, when accuracy is low in the early stages of training, combining the global model with the sharded authentication model can accelerate model convergence. Based on this idea, the modified formula for the sharded model is as follows:
[0111] M ′ S =acc*M S +(1-acc)M G
[0112]
[0113] The above steps constitute the training process for one round of the sharded model. In each round of training, the sharded model optimized by the global model in the previous step is redistributed to the participants within each shard, and the optimized sharded model is used as the initial data to continue training the local model. After several rounds of iteration, the sharded model not only contains the probability distribution characteristics of user data in this cluster, but also has a certain degree of robustness when combined with the global model.
[0114] In this embodiment, federated aggregation combined with a reputation mechanism further enhances the performance of the network security access authentication model, enabling secure detection of the legitimacy of access devices or user identities in distributed network scenarios. This effectively ensures the security of distributed network systems in the network access field while also taking into account the performance overhead of model training and maintenance.
[0115] Step S200: Respond to the network security access request based on the authentication result to complete the network security access.
[0116] As an example, based on the access device corresponding to the network security access request, the secure access authentication model of the segment where the access device is located is obtained. Based on this secure access authentication model, the identity feature data of the access device receiving the network security access request is securely authenticated to obtain the authentication result. According to the authentication result, a response is made to the network security access request. If authentication is successful, it indicates that the access device corresponding to the network security access request has the authority to access the network, and the network security access request is responded to; otherwise, no response is made. In this process, the secure access identity authentication algorithm based on trusted federated learning ensures the security of the participating devices or users' identities, thereby improving the security of network security access.
[0117] This invention provides a network security access method, apparatus, device, and storage medium. Compared to the low security of network devices or user network access in current distributed network scenarios, in this invention, when an access device participating in federated consensus in a distributed system receives a network security access request, the network security access request is input into the secure access authentication model corresponding to the access device, and an authentication result is output. The secure access authentication model is trained based on federated machine learning technology, blockchain technology, and the access device's local privacy dataset. The secure access authentication model is used to perform secure authentication on the identity feature data in the access device receiving the network security access request. Based on the authentication result, a response is given to the network security access request to complete the network security access. In other words, under the trusted federated learning architecture based on federated machine learning and blockchain technology, each distributed access device participating in federated learning trains a secure access authentication model based on a local privacy dataset. This enables the training of a secure access authentication model without transmitting the original privacy data. Compared with traditional access authentication methods, this avoids the privacy leakage risk caused by centralized model training. Furthermore, since the aggregated model is stored on the blockchain throughout the entire process, the model training process is traceable, secure, and trustworthy. This can better meet the requirements for user access security in a distributed system environment, thereby achieving secure access for distributed network devices or users and improving the overall security of the system.
[0118] Based on the first embodiment described above, a second embodiment of the network security access method is proposed.
[0119] As an example, the distributed network security access authentication model includes nine layers of neurons, with the main neural network structure referring to... Figure 3 It includes an input layer, two pooling layers, three convolutional layers, two fully connected layers, and an output layer. The fully connected layers include a unified fully connected layer and a personalized layer.
[0120] The dimensions of the input layer and subsequent neurons are determined based on the original data format of the user device in the application scenario, and each neuron in the output layer represents the probability that the user's identity is legitimate in that state.
[0121] In distributed network security access scenarios, factors that can be used to authenticate the correctness of device or device user identities mainly include device radio frequency fingerprint information, user biometric information, and user-held magnetic card characteristics. With the help of various sensor devices and signal processing, the federated device locally generates identity factor data that can be input into the network security access authentication model. For example, using biometric image information as the feature factor input model, the system of the device of this invention can process the raw data into two-dimensional matrix data, which serves as a feature representing the identity of the device user.
[0122] After two input-pooling layers, the model ignores specific features in the original data, obtaining an abstract feature matrix that represents identity factors. Simultaneously, because the overall dimensionality of the pooling layer's factors is reduced, the complexity of subsequent neurons is simplified, reducing computational overhead during each model update. The purpose of convolutional layer C5 is to organize the abstracted feature evidence and reduce data dimensionality, preparing neurons for access to the fully connected layer. In this invention, fully connected layer F6 is a unified fully connected layer, participating in aggregation operations at every step of the federated learning training process, while fully connected layer F7 is a personalized layer, participating only in intra-segment model updates. By setting personalized layers, the network security access authentication models for different segments can have certain differences. A high-performance security authentication model is trained based on the data distribution characteristics of participants within the segment, effectively ensuring the reliability of network security access in a distributed network environment.
[0123] As an example, the step of inputting the network security access request into the secure access authentication model and outputting the authentication result includes:
[0124] Based on the input layer, according to the original data format of the access device of the federated consensus, the identity feature data corresponding to the network security access request is input into the deep neural network for feature extraction to obtain the identity feature matrix of the access device user.
[0125] Based on the pooling layer, an abstract feature matrix representing the identity features is obtained from the identity feature matrix, and the abstract feature matrix is input into the convolutional layer;
[0126] Based on the convolutional layer, the abstract feature matrix is organized, and the organized abstract feature matrix is connected to the fully connected layer;
[0127] Based on the unified fully connected layer, an aggregation operation is performed according to the abstract feature matrix to obtain the in-chip model; based on the personalization layer, the in-chip model is updated to obtain the secure access authentication model.
[0128] Based on the output layer, and according to the secure access authentication model, the probability that the identity feature data of the access device is valid in this state is output, and the authentication result is obtained.
[0129] Based on the first or second embodiment described above, a third embodiment of the network security access method is proposed.
[0130] In federated learning, because the local datasets of participating parties produce different probability distributions depending on user preferences, training the model using non-independent and identically distributed datasets significantly impacts the model aggregation speed and final model performance. Therefore, it is necessary to classify multiple access devices participating in federated consensus based on the data distribution characteristics of the local privacy dataset, obtaining at least one shard. Different shards are used to train and create corresponding secure access authentication models to improve the predictive performance of the secure access authentication models.
[0131] As an example, the data distribution characteristics based on the local privacy dataset are used to classify multiple access devices participating in the federated consensus, resulting in at least one shard, including:
[0132] Step C1: Calculate the data distribution characteristics of the local privacy dataset of the access device in the federated consensus to obtain the feature matrix corresponding to the local privacy dataset;
[0133] Step C2: Based on the hierarchical clustering algorithm and the feature matrix, perform similarity calculation on the local privacy dataset of the access device to obtain the optimal segmentation scheme for classifying the access device under a preset number of categories;
[0134] Step C3: Based on the decision indicators for network security access, select a target layering scheme from the optimal layering scheme. The target layering scheme includes at least one slice and at least one access device within the slice.
[0135] It should be noted that when the local datasets of the participants in federated learning have approximately the same distribution, the machine learning models trained using each local dataset will also have similar parameters. Based on this, the process of generating a hierarchical scheme based on similarity is as follows:
[0136] Step 1: Determine the initial model for training. Since the network access security authentication used in this invention is based on a deep neural network, a deep neural network model is designed, and the parameters of each neuron are randomly initialized. That is, let the initial deep neural network model be M.
[0137] Step 2: Distribute the initial model M to each participant in the federated learning process (i.e., the access device participating in the federated consensus). Each participant trains the initial model M based on its local privacy dataset. Training stops after the model converges; at this point, each participant's model is M. i ′ Here, 'i' represents the identifier of the participant. The neuron parameters of the deep neural network can reflect the distribution characteristics of the local data pairs.
[0138] The changes in neuron parameters before and after training are used to represent the features of the participant's local data. The calculation method is as follows:
[0139] X i =M i ′ -M
[0140] Wherein, vector X i This represents the change in model parameters before and after training for participant i, where i is the participant's label. Using this method, a data feature set C = {X1, X2, X3, ..., X...} is obtained for n participants. n}
[0141] Step 3: Based on the calculated local data feature set, calculate the similarity matrix of each vector using the Gaussian kernel function:
[0142]
[0143] in Here, σ is a hyperparameter, and i and j represent the row and column numbers of the values in the matrix, and also their indices in the data feature set C. For further calculations, we define the degree matrix of the feature data:
[0144]
[0145] The degree matrix is a diagonal matrix, with all off-diagonal elements being 0. The values on the diagonal are calculated from the similarity matrix results, as follows:
[0146]
[0147] Using the degree matrix and similarity matrix, we calculate the Laplacian matrix using the formula L = D – S, which is obtained by subtracting corresponding elements from the matrix. Then, we construct the standardized Laplacian matrix L. std =D -1 / 2 LD -1 / 2 And calculate its eigenvalue λ. i and its corresponding eigenvector f i .
[0148] Step 4, select L std The k smallest eigenvalues form the characteristic matrix F. n×k =(f1,f2,f3,…,f k ), where the eigenvector f i It is an n-dimensional column vector. This step reduces the n-dimensional data features to k dimensions while preserving the characteristics of the dataset itself. Based on the above steps, the feature matrix F corresponding to the local privacy data of the n participants is calculated.
[0149] Step 5: Using a hierarchical clustering algorithm and feature matrix F, perform similarity calculation on the local privacy dataset of the access device to obtain the optimal sharding scheme for classifying the access device under the preset number of categories. The optimal stratification scheme under different number of categories is used as the candidate for the target stratification scheme.
[0150] Specifically, hierarchical clustering constructs a tree-structured classification model by continuously calculating the similarity between different categories based on the similarity between datasets. This invention uses Euclidean distance based on the feature matrix F to measure the similarity between different clusters, calculated as follows:
[0151]
[0152]
[0153] Where C i and C j Given two existing clusters, the similarity between the clusters is measured by calculating the average distance between them. i and q i Let represent the i-th component of points p and q in the feature matrix F. First, each participant is treated as a separate class for merging. In each round of calculation, the two closest classes are merged into a new cluster. This process iterates from bottom to top, forming a tree structure. In the classification tree, each branch represents a new hierarchical optimization scheme.
[0154] Step 6: Based on the decision indicators for network security access, multiple influencing factors need to be considered comprehensively. The final layering scheme to be adopted is determined from the optimal layering scheme, which is the target layering scheme. The target layering scheme includes at least one segment and at least one access device within the segment.
[0155] In this embodiment, blockchain technology is used in a distributed scenario to simultaneously achieve multi-terminal sharing of model data and recording of the machine learning model training process. Based on the immutability of blockchain technology, model security and traceability are guaranteed. Since the non-independent and identically distributed nature of the original data affects the performance of the machine learning model, a hierarchical blockchain optimization scheme can effectively solve this problem. At the same time, reducing the network size required to reach consensus can significantly reduce the computational overhead of intra-chip consensus, improving the overall performance of the model training framework. In other words, the aforementioned hierarchical blockchain optimization algorithm obtains device-specific data features through a feature extraction network and uses a hierarchical clustering model to group devices with similar data features into the same cluster. This makes the data feature distribution among devices within a cluster more similar to the global distribution, thus improving the performance of the obtained model.
[0156] As an example, the decision metrics include metrics such as data similarity within a cluster, communication overhead, and consensus credibility, wherein the cluster is constructed from access devices with the highest degree of similarity in local privacy data.
[0157] It is understandable that after the layering scheme generation algorithm calculates, several candidate layering schemes for the blockchain network can be obtained. In order to determine the final layering architecture to be used in the distributed network from among many schemes, it is necessary to combine the network security access scenario requirements and determine the conditions that the decision algorithm should consider. In the generation of layering schemes, the generation of candidate schemes takes into account the similarity of features of local datasets of participants within the shard. The dataset similarity still needs to be considered in the final decision algorithm, because the approximate feature distribution of training data ensures that the sharding security authentication model has good predictive performance. In addition, since the participants within the shard run the blockchain consensus protocol, the cluster size and intra-shard communication overhead also directly determine the training efficiency of the security authentication model. Therefore, the decision indicators include the data similarity within the cluster, the size of the communication overhead, and the credibility of the consensus.
[0158] Taking the above considerations into account, the step of selecting a target layering scheme from the optimal layering scheme based on network security access decision indicators includes:
[0159] Step C31: Calculate the average distance between the local privacy datasets of access devices within the cluster to obtain the internal data similarity of the cluster;
[0160] Step C32: Obtain the blockchain communication network optimized based on the Byzantine consensus algorithm, and calculate the data corresponding to the communication overhead index and the data corresponding to the consensus trust index based on the blockchain communication network.
[0161] Step C33: Input the data on internal data similarity, communication overhead, and consensus credibility into the preset reputation calculation model to calculate the reputation score corresponding to each of the optimal hierarchical schemes;
[0162] Step C34: Select the optimal stratification scheme with the highest reputation score as the target stratification scheme.
[0163] Since the underlying technology for data sharing is blockchain, the credibility of the consensus result decreases as the number of participants in the consensus mechanism decreases. Furthermore, the size of the participants affects the communication overhead during the consensus protocol's operation. Therefore, a multi-objective blockchain layered optimization method was designed.
[0164] It should be noted that during machine learning model training, the similarity of the feature distributions of the training datasets determines the model's convergence speed and predictive performance. The intra-cluster data similarity metric can measure the similarity of features in the local datasets of participants in federated learning. This invention proposes a similarity metric based on the average intra-cluster distance, calculated as follows:
[0165]
[0166] In the formula, m is the number of participants in the cluster, and k is the dimension of the data features of each participant, which can be obtained using the feature matrix F calculated in the previous section. n×k Calculation. It's important to note that the feature matrix contains features from all participants in the federated learning distributed network; therefore, it's necessary to find the corresponding subset of row vectors for this cluster and substitute them into the formula for calculation.
[0167] Furthermore, in the trusted federated learning technology architecture, devices participating in the federated consensus share the updated model parameter data for each round through a distributed blockchain network. During this process, changes in the parameters of each participant and their impact on the global model are recorded in a blockchain-based distributed database. Due to the non-repudiation and immutability inherent in blockchain technology, a reliable record of the secure access model training process can be formed, making it highly suitable as a trusted database system in a distributed environment.
[0168] However, blockchain technology itself also has some drawbacks. To ensure data consistency in a distributed system, each participant needs to run a proof-of-work mechanism. Since the proof-of-work consensus mechanism used in general blockchain networks has drawbacks such as high computational overhead and slow aggregation speed, it severely consumes the computing resources of the distributed system, placing a huge performance burden on the participating devices. In other words, in the proof-of-work mechanism, participants need to perform mining operations, i.e., continuously running hash calculation models, which will consume a large amount of device computing performance, making it particularly unsuitable for distributed network security access scenarios with diverse participating devices. However, the Practical Byzantine Fault Tolerance (PBT) algorithm itself uses a broadcast mechanism, the performance of which depends on the network size and communication performance. Furthermore, because it adopts the principle of majority rule, the scale of the consensus network also has a significant impact on the security of the ledger data. Therefore, the underlying blockchain communication network of Trusted Federated Learning adopts the PBT consensus algorithm. Compared to the proof-of-work mechanism used in general distributed blockchain networks, PBT has advantages such as fast consensus convergence speed, high transaction throughput, and less consumption of computing resources.
[0169] Therefore, by using Practical Byzantine Fault Tolerance (PBT) instead of Proof-of-Work (PoW) as the consensus mechanism for blockchain networks, and by comprehensively considering the three dimensions of communication overhead, model security, and model accuracy under the PBT algorithm, the target layering scheme for the final blockchain layering optimization is obtained.
[0170] Specifically, the multi-objective blockchain layered optimization process is as follows:
[0171] Based on network protocols and software measurements, a distributed network communication system can be abstracted as a weighted fully connected graph. The internal communication overhead within the cluster can be estimated by the weights distributed among the various device points, serving as one of the indicators for evaluating blockchain layered optimization schemes. The calculation formula is as follows:
[0172]
[0173] This formula calculates the average communication overhead within a cluster, where m is the cluster size and W(A,B) represents the communication overhead between points A and B. Based on the principle of the practical Byzantine consensus mechanism, a transaction requires three rounds of broadcast communication to reach consensus in the network. Therefore, the average network communication overhead can effectively measure the convergence speed of a single transaction.
[0174] Since the consensus mechanism adopts the principle of majority rule, assuming there are f malicious nodes among the participating devices, the data recorded in the distributed ledger is only considered reliable when the network size is greater than 3f+1. Based on this principle, assuming the probability of a single device being attacked follows a binomial distribution, the following formula can be used to calculate the reliability of the consensus:
[0175]
[0176] The formula calculates the reliability probability of the consensus result, where m is the cluster size and p is the average probability that a participating device is a malicious node. When the size and probability of malicious nodes are within an acceptable range, the reliability of transactions in the distributed database can be estimated. Based on the above parameters for evaluating the merits of a layered scheme, this invention proposes a multi-objective blockchain layered optimization scheme decision algorithm. The reputation score calculation method for each scheme is as follows:
[0177]
[0178] By inputting the feature matrix and network parameters of each alternative scheme obtained in the previous section into the model, a score can be obtained for each hierarchical optimization scheme. The target hierarchical scheme with the highest reputation score is taken as the hierarchical blockchain communication network architecture for the final deployment application.
[0179] In this embodiment, device-specific data features are obtained through a feature extraction network, and a hierarchical clustering model is used to group devices with similar data features into the same cluster. This results in a more similar distribution of data features among devices within a cluster compared to the global distribution, improving the performance of the obtained model. Simultaneously, by sharding multiple access devices participating in the federated consensus, the network size required to reach consensus is reduced, significantly decreasing the computational overhead of intra-shard consensus and improving the overall performance of the model training framework. Furthermore, considering various indicators affecting the performance and security of the trusted federated learning model, such as the similarity of the training dataset, intra-shard communication overhead, and consensus security, a blockchain-based hierarchical federated learning network architecture is proposed to achieve a balance between performance and security, providing reliable assurance for the training and use of the distributed network security access authentication model.
[0180] Therefore, in a distributed network environment, since any two nodes can communicate, the network topology can be changed according to actual needs. After obtaining the target layering scheme based on the data distribution characteristics of the local privacy data of the access devices, the layered blockchain communication protocol is run based on the calculation results of the target layering scheme. As the underlying technology of trusted federated learning, the layered blockchain communication network broadcasts local data within the chip using a practical Byzantine consensus protocol. After public and private key signing, other users in the network mutually confirm the correctness of the message and the legitimacy of the user's identity. Once the correctness of the message is confirmed, the broadcast data is stored on the local ledger. Since each stored message is confirmed by a majority of users within the chip, the correctness and consistency of the ledger stored by legitimate users can always be guaranteed, thereby achieving trusted distributed storage.
[0181] The layered blockchain communication protocol serves two purposes: first, leveraging the immutability of the blockchain's underlying layer, it ensures the trustworthiness of shared model data among federated learning participants. Since the multi-objective layered optimization scheme considers the impact of user trustworthiness and shard network size on model security, the security of the federated learning model is within acceptable limits. Second, federated learning, through the traceability of blockchain, stores the model parameters contributed by each participant in a distributed database, offering resistance to single points of failure and denial compared to traditional centralized databases. Records of the model training process provide data support for subsequent trusted authentication functions such as user management and security auditing. Furthermore, the distributed database based on blockchain is highly compatible with the characteristics of federated learning as a distributed machine learning approach.
[0182] Furthermore, when training the federated machine learning model, based on the target layering scheme derived from the multi-objective blockchain layered optimization algorithm, the trusted federated learning network can be divided into a three-layer network structure: a local model layer, a sharded model layer, and a global model layer. Using a layered network structure can achieve a balance between performance and security during model training, encompassing model aggregation, network communication, consensus computation, and data security, providing underlying technical guarantees for secure network access authentication. In other words, within a distributed network structure, by leveraging a federated machine learning model based on a layered blockchain, while ensuring secure authentication of network devices and user access, local privacy data is protected from leakage, achieving a balance between business functionality and data privacy.
[0183] The network security access device provided by the present invention is described below. The network security access device described below and the network security access method described above can be referred to in correspondence.
[0184] The present invention also provides a network security access device, the device comprising:
[0185] The security authentication module is used to input a network security access request into the security access authentication model corresponding to the access device when an access device participating in federated consensus in a distributed system receives a network security access request, and output the authentication result.
[0186] The secure access authentication model is trained based on federated machine learning technology and blockchain technology, as well as the local privacy dataset of the access device. The secure access authentication model is used to perform secure authentication on the identity feature data in the access device that receives the network security access request.
[0187] The request-response module is used to respond to the network security access request based on the authentication result, so as to complete the network security access.
[0188] And / or, the security authentication module further includes:
[0189] The model structure submodule, the secure access authentication model includes one input layer, two pooling layers, three convolutional layers, two fully connected layers and one output layer, the fully connected layer includes a unified fully connected layer and a personalized layer;
[0190] Based on the input layer, according to the original data format of the access device of the federated consensus, the identity feature data corresponding to the network security access request is input into the deep neural network for feature extraction to obtain the identity feature matrix of the access device user.
[0191] Based on the pooling layer, an abstract feature matrix representing the identity features is obtained from the identity feature matrix, and the abstract feature matrix is input into the convolutional layer;
[0192] Based on the convolutional layer, the abstract feature matrix is organized, and the organized abstract feature matrix is connected to the fully connected layer;
[0193] Based on the unified fully connected layer, an aggregation operation is performed according to the abstract feature matrix to obtain the in-chip model; based on the personalization layer, the in-chip model is updated to obtain the secure access authentication model.
[0194] Based on the output layer, and according to the secure access authentication model, the probability that the identity feature data of the access device is valid in this state is output, and the authentication result is obtained.
[0195] And / or, the device further includes:
[0196] The model training module obtains the secure access authentication model based on the following steps:
[0197] The hierarchical submodule is used to classify multiple access devices participating in the federated consensus based on the data distribution characteristics of the local privacy dataset, and obtain at least one shard, wherein the shard includes at least one access device.
[0198] The model acquisition submodule is used to acquire the machine learning model used to identify network security access within the current slice;
[0199] The model training submodule is used to distribute the machine learning model to each access device within the current slice, so that the access device can train the machine learning model based on its local privacy dataset to obtain at least one local model.
[0200] The first model aggregation submodule is used to share the local model through a distributed blockchain service running on the access device, and to use the sharded model formed by aggregating the local models based on the federated averaging algorithm as the secure access authentication model.
[0201] And / or, the model training module further includes:
[0202] The second model aggregation submodule is used to aggregate the security access authentication models corresponding to each shard based on the federated averaging algorithm to form a global model.
[0203] The model optimization submodule is used to adjust the model parameters of the secure access authentication model through the global model to obtain an optimized secure access authentication model.
[0204] The model convergence submodule is used to take the optimized secure access authentication model as the initial machine learning model, and continue to execute the step of training the machine learning model based on the local sample dataset of the access device in the current segment to obtain at least one local model, until the training termination condition is met to obtain the final secure access authentication model.
[0205] And / or, the second model aggregation submodule further includes:
[0206] The model filtering unit is used to filter the security access authentication models corresponding to each shard based on the reputation mechanism, and select the models that meet the reputation score conditions as shard models.
[0207] The model aggregation unit is used to aggregate the shard models corresponding to each shard based on the federated averaging algorithm to form a global model.
[0208] And / or, the hierarchical submodule further includes:
[0209] The feature calculation unit is used to perform data distribution feature calculation on the local privacy dataset of the access device of the federated consensus, and obtain the feature matrix corresponding to the local privacy dataset.
[0210] The hierarchical computing unit is used to perform similarity calculation on the local privacy dataset of the access device according to the hierarchical clustering algorithm and the feature matrix, so as to obtain the optimal segmentation scheme for classifying the access device under a preset number of categories.
[0211] The hierarchical confirmation unit is used to select a target hierarchical scheme from the optimal hierarchical scheme based on decision indicators during network security access. The target hierarchical scheme includes at least one slice and at least one access device within the slice.
[0212] The decision-making indicators include metrics such as data similarity within a cluster, communication overhead, and consensus credibility. The clusters are constructed by access devices with the highest degree of similarity in local privacy data.
[0213] And / or, the hierarchical confirmation unit further includes:
[0214] The first indicator calculation subunit is used to calculate the average distance between the local privacy datasets of access devices within a cluster, and to obtain the internal data similarity of the cluster.
[0215] The second indicator calculation subunit is used to obtain the blockchain communication network optimized based on the Byzantine consensus algorithm, and calculate the data corresponding to the communication overhead index and the data corresponding to the consensus trust index based on the blockchain communication network.
[0216] The reputation calculation subunit is used to input the data of internal data similarity, communication overhead and consensus credibility into the preset reputation calculation model to calculate the reputation score corresponding to each of the optimal hierarchical schemes.
[0217] The stratification confirmation sub-unit is used to select the optimal stratification scheme with the highest reputation score as the target stratification scheme.
[0218] Figure 4 An example is a schematic diagram of the physical structure of a network security access device, such as... Figure 4 As shown, the network security access device may include: a processor 810, a communication interface 820, a memory 830, and a communication bus 840, wherein the processor 810, the communication interface 820, and the memory 830 communicate with each other through the communication bus 840. The processor 810 can call logical instructions in the memory 830 to execute a network security access method, which includes: when an access device participating in federated consensus in a distributed system receives a network security access request, inputting the network security access request into the security access authentication model corresponding to the access device, and outputting an authentication result; wherein the security access authentication model is trained based on federated machine learning technology and blockchain technology, as well as the local privacy dataset of the access device, and the security access authentication model is used to perform security authentication on the identity feature data in the access device receiving the network security access request; and responding to the network security access request according to the authentication result to complete the network security access.
[0219] Furthermore, the logical instructions in the aforementioned memory 830 can be implemented as software functional units and, when sold or used as independent products, can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, essentially, or the part that contributes to the prior art, or a part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0220] On the other hand, the present invention also provides a computer program product, which includes a computer program that can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the network security access method provided by the above methods. The method includes: when an access device participating in federated consensus in a distributed system receives a network security access request, inputting the network security access request into a secure access authentication model corresponding to the access device, and outputting an authentication result; wherein, the secure access authentication model is trained based on federated machine learning technology and blockchain technology, as well as the local privacy dataset of the access device, and the secure access authentication model is used to perform secure authentication on the identity feature data in the access device that receives the network security access request; and responding to the network security access request according to the authentication result to complete the network security access.
[0221] In another aspect, the present invention also provides a non-transitory computer-readable storage medium storing a computer program thereon. When executed by a processor, the computer program is implemented to perform the network security access method provided by the above methods. The method includes: when an access device participating in federated consensus in a distributed system receives a network security access request, inputting the network security access request into a secure access authentication model corresponding to the access device, and outputting an authentication result; wherein the secure access authentication model is trained based on federated machine learning technology and blockchain technology, as well as the local privacy dataset of the access device, and the secure access authentication model is used to perform secure authentication on the identity feature data in the access device receiving the network security access request; and responding to the network security access request according to the authentication result to complete the network security access.
[0222] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the modules can be selected to achieve the purpose of this embodiment according to actual needs. Those skilled in the art can understand and implement this without any creative effort.
[0223] Through the above description of the embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus necessary general-purpose hardware platforms, and of course, it can also be implemented by hardware. Based on this understanding, the above technical solutions, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute the methods described in the various embodiments or some parts of the embodiments.
[0224] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.
Claims
1. A network security access method, characterized in that, The method includes: When an access device participating in federated consensus in a distributed system receives a network security access request, it inputs the network security access request into the security access authentication model corresponding to the access device. The security access authentication model includes an input layer, two pooling layers, three convolutional layers, two fully connected layers, and an output layer. The fully connected layer includes a unified fully connected layer and a personalized layer. Based on the input layer, according to the original data format of the access device of the federated consensus, the identity feature data corresponding to the network security access request is input into the deep neural network for feature extraction to obtain the identity feature matrix of the access device user. Based on the pooling layer, an abstract feature matrix representing the identity features is obtained from the identity feature matrix, and the abstract feature matrix is input into the convolutional layer; Based on the convolutional layer, the abstract feature matrix is organized, and the organized abstract feature matrix is then connected to the fully connected layer. Based on the unified fully connected layer, an aggregation operation is performed according to the abstract feature matrix to obtain the in-chip model; based on the personalization layer, the in-chip model is updated to obtain the secure access authentication model. Based on the output layer, according to the secure access authentication model, the probability of the access device's identity feature data being valid is output to obtain the authentication result; The secure access authentication model is trained based on federated machine learning technology and blockchain technology, as well as the local privacy dataset of the access device. The secure access authentication model is used to perform secure authentication on the identity feature data in the access device that receives the network security access request. Based on the authentication result, respond to the network security access request to complete the network security access.
2. The network security access method according to claim 1, characterized in that, The secure access authentication model is trained based on the following steps: Based on the data distribution characteristics of the local privacy dataset, multiple access devices participating in the federated consensus are classified to obtain at least one slice, and the slice includes at least one access device. Obtain the machine learning model used to identify network security access within the current slice; The machine learning model is distributed to each access device within the current slice, so that the access device can train the machine learning model based on its local privacy dataset to obtain at least one local model; The local model is shared by a distributed blockchain service running on the access device, and the sharded model formed by aggregating the local models based on a federated averaging algorithm is used as a secure access authentication model.
3. The network security access method according to claim 2, characterized in that, After sharing the local model through a distributed blockchain service running on the access device, and using the sharded model formed by aggregating the local models based on a federated averaging algorithm as the secure access authentication model, the method further includes: The secure access authentication models corresponding to each shard are aggregated based on the federated averaging algorithm to form a global model; The optimized security access authentication model is obtained by adjusting the model parameters of the global model. Using the optimized secure access authentication model as the initial machine learning model, the process continues to train the machine learning model based on the local sample dataset of the access device within the current slice, obtaining at least one local model, until the training termination condition is met, resulting in the final secure access authentication model.
4. The network security access method according to claim 3, characterized in that, The method of aggregating the security access authentication models corresponding to each shard based on the federated averaging algorithm to form a global model includes... Based on the reputation mechanism, the security access authentication models corresponding to each shard are screened, and the models that meet the reputation score conditions are selected as shard models. The fragmented models corresponding to each fragment are aggregated based on the federated averaging algorithm to form a global model.
5. The network security access method according to claim 2, characterized in that, The data distribution characteristics based on the local privacy dataset are used to classify multiple access devices participating in the federated consensus, resulting in at least one shard, including: The data distribution characteristics of the local privacy dataset of the access device in the federated consensus are calculated to obtain the feature matrix corresponding to the local privacy dataset. Based on the hierarchical clustering algorithm and the feature matrix, similarity calculation is performed on the local privacy dataset of the access device to obtain the optimal hierarchical scheme for classifying the access device under a preset number of classifications. Based on decision indicators for network security access, a target layering scheme is selected from the optimal layering scheme. The target layering scheme includes at least one slice and at least one access device within the slice.
6. The network security access method according to claim 5, characterized in that, The decision-making metrics include the similarity of data within a cluster, the size of communication overhead, and the credibility of consensus. The clusters are constructed by access devices with the highest similarity of local privacy data.
7. The network security access method according to claim 6, characterized in that, The step of selecting a target layering scheme from the optimal layering scheme based on decision indicators during network security access includes: Calculate the average distance between the local privacy datasets of access devices within a cluster to obtain the internal data similarity of the cluster; Obtain a blockchain communication network optimized based on the practical Byzantine consensus algorithm, and calculate the data corresponding to the communication overhead index and the data corresponding to the consensus trust index based on the blockchain communication network; The internal data similarity, communication overhead, and consensus credibility are input into a preset reputation calculation model to calculate the reputation score corresponding to each of the optimal stratification schemes. The optimal stratification scheme with the highest reputation score is selected as the target stratification scheme.
8. A network security access device, characterized in that, The device includes: The security authentication module is used for: When an access device participating in federated consensus in a distributed system receives a network security access request, it inputs the network security access request into the security access authentication model corresponding to the access device. The security access authentication model includes an input layer, two pooling layers, three convolutional layers, two fully connected layers, and an output layer. The fully connected layer includes a unified fully connected layer and a personalized layer. Based on the input layer, according to the original data format of the access device of the federated consensus, the identity feature data corresponding to the network security access request is input into the deep neural network for feature extraction to obtain the identity feature matrix of the access device user. Based on the pooling layer, an abstract feature matrix representing the identity features is obtained from the identity feature matrix, and the abstract feature matrix is input into the convolutional layer; Based on the convolutional layer, the abstract feature matrix is organized, and the organized abstract feature matrix is then connected to the fully connected layer. Based on the unified fully connected layer, an aggregation operation is performed according to the abstract feature matrix to obtain the in-chip model; based on the personalization layer, the in-chip model is updated to obtain the secure access authentication model. Based on the output layer, according to the secure access authentication model, the probability of the access device's identity feature data being valid is output to obtain the authentication result; The secure access authentication model is trained based on federated machine learning technology and blockchain technology, as well as the local privacy dataset of the access device. The secure access authentication model is used to perform secure authentication on the identity feature data in the access device that receives the network security access request. The request-response module is used to respond to the network security access request based on the authentication result, so as to complete the network security access.
9. A network security access device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the network security access method as described in any one of claims 1 to 7.
10. A non-transitory computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the network security access method as described in any one of claims 1 to 7.