Method and system for resource allocation of smart city based on redundancy control strategy
By optimizing the allocation of information security resources among smart cities through redundancy control strategies, the problem of resource allocation in the spread of information security risks among smart cities is solved, and more efficient information security protection is achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- FOSHAN UNIVERSITY
- Filing Date
- 2022-09-08
- Publication Date
- 2026-05-05
AI Technical Summary
As smart cities become increasingly reliant on cloud computing and the Internet of Things, information security risks are spreading, leading to multi-faceted challenges to urban information security. How to rationally allocate resources to mitigate these risks has become a key challenge.
By introducing a redundancy control strategy, analyzing the characteristics of substitutable external resources among smart cities, and adopting independent, joint, and collaborative sharing strategies, the allocation of information security resources is optimized. The resource allocation amount is determined by using the redundancy control strategy and intrusion probability, and a Nash equilibrium solution is established to optimize resource allocation.
It effectively reduced the probability of unauthorized user intrusion, reduced information security risks, improved the information security level of smart cities, and avoided excessive waste of resource allocation.
Smart Images

Figure CN116405511B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of information processing technology, and more specifically to a method and system for resource allocation in smart cities based on a redundancy control strategy, a computer-readable storage medium, and an electronic device. Background Technology
[0002] Since its inception, smart cities have been valued worldwide. While improving the level of urban intelligence, they have also provided more convenient conditions for people's lives. However, because smart cities rely heavily on new technologies such as cloud computing and the Internet of Things, the application of these technologies has brought the hidden danger of information risk spread, posing a multi-faceted impact on urban information security. How to rationally allocate the current digital resources of cities and minimize these information security risks has become a practical problem that must be faced for the healthy development of smart cities.
[0003] A smart city is an open, shared, and ecologically sustainable system, involving various exchanges and decision-making processes among cities regarding information security. Smart cities possess interchangeable external resources, meaning that an unauthorized intrusion into one city will not necessarily result in losses for other cities. Therefore, effective improvements are needed when analyzing resource allocation across cities. Summary of the Invention
[0004] This application first describes and models the problem based on the characteristics of replaceable external resources. Then, it explores information security resource allocation methods under two scenarios: independent strategy and joint strategy. It analyzes the impact of factors such as the scale of smart cities or network systems, the probability of unauthorized user intrusion, and the replacement rate of smart cities or network systems on the above two scenarios. It also compares the Nash equilibrium solutions under these two scenarios and optimizes the allocation based on the actual situation. At the same time, it supplements the joint strategy among smart cities or network systems by introducing a collaborative mechanism.
[0005] According to one aspect of the present invention, a method for resource allocation in a smart city based on a redundancy control strategy is provided, the method comprising:
[0006] Identify multiple smart cities with alternative external resources, wherein the alternative external resources refer to at least two smart cities that store the same part or all of their data resources, and when part or all of the data resources of the first smart city are maliciously tampered with or maliciously deleted, the second smart city can determine whether to use the same part or all of the data resources stored in the second smart city as the first smart city to restore the data resources of the first smart city through a data resource substitution method.
[0007] Determine the allocation amount of information security resources for each smart city. jThe losses E that can be recovered by the organization's information security resources;
[0008] Based on the information security resource allocation quota for each smart city x j Given the recoverable loss E from the unit's information security resources, determine the probability p of successful intrusion by unauthorized users for each smart city after information security resource configuration. j :
[0009]
[0010] Where j is a natural number and 2 ≤ j ≤ n, where n is the number of smart cities with alternative external resources, β is the probability of an unauthorized user intruding into a smart city, where the probability of an unauthorized user intruding into each smart city is the same, and v is the probability of a smart city being successfully intruded into by an unauthorized user without information security resource configuration, where v is the same for each smart city; and
[0011] Determine redundancy control strategies among multiple smart cities with alternative external resources, and determine the resource allocation amount for each smart city when allocating resources based on the redundancy control strategies and intrusion probability.
[0012] Preferably, it also includes the intrusion probability p of each smart city being successfully compromised by an unauthorized user after the information security resources have been configured. j Determine the probability P of an unauthorized user attacking and successfully infiltrating the current smart city, assuming that the user fails to attack any other smart city besides the current smart city. B :
[0013]
[0014] Where p1 represents the probability that an unauthorized user successfully intrudes into the current smart city B. This represents the probability that an unauthorized user fails to attack any smart city other than the current smart city and then turns to attack the current smart city B.
[0015] Preferably, a redundancy control strategy is determined among multiple smart cities with alternative external resources. Based on the redundancy control strategy and intrusion probability, the resource allocation amount for each smart city is determined, including:
[0016] When the redundancy control strategy among multiple smart cities with alternative external resources is determined to be an independent strategy, the expected loss C of each or the I-th smart city is... I Take the minimum value as the loss function Min C for each or the i-th smart city. I :
[0017]
[0018] The aforementioned independent strategy means that when some or all of the data resources of the first smart city in a multi-smart city are maliciously tampered with or deleted, the second smart city will not use its own stored data resources that are the same as those of the first smart city to restore the data resources of the first smart city through data resource substitution.
[0019] Among them, L I L represents the amount of data loss after a smart city is successfully compromised by an unauthorized user. I The same; β is the probability that an illegal user chooses to attack any smart city, where β is the same for each smart city; σ is the data substitution rate among smart cities with alternative external resources; determined based on formulas (5.1) and (5.2). Let k be the probability that the j-th smart city (j = 3, 4, ..., n) is successfully invaded by an unauthorized user, where k is a natural number.
[0020] Substitute formula (5.1) into formula (5.3) to determine:
[0021]
[0022] Because in formula (5.4) With x j Irrelevant, settings Taking the partial derivative of formula (5.4), we can determine:
[0023]
[0024] By taking the partial derivative of formula (5.5), we can determine the second derivative of formula (5.4):
[0025]
[0026] Based on formula (5.6), Heng is established, therefore in At that point, the loss function C I Find the minimum value Min C I ;
[0027] When the redundancy control strategies among multiple smart cities with alternative external resources are determined to be independent strategies, the Nash equilibrium solution is obtained. The resource allocation of each smart city is based on the Nash equilibrium solution as an independent redundancy control strategy. in It satisfies formula (5.7):
[0028]
[0029] Preferably, it also includes, satisfy And because The principle of constancy is established, thus determining that as the number of smart cities with alternative external resources for information security increases, the amount of resources allocated to information security in smart cities will also increase. It will decrease accordingly, that is It is negatively correlated with n, and when hour, Zero;
[0030] As n increases, It will decrease, thus leading to Increase, and since v∈[0,1], therefore It will inevitably decrease accordingly.
[0031] Preferably, it also includes, when the redundancy control strategy among multiple smart cities with alternative external resources is determined to be an independent strategy, the resource allocation amount of the smart city for any unauthorized user's intrusion probability β∈[0,1]. Compared to the probability of intrusion β, which monotonically increases, that is... Heng was established.
[0032] Preferably, it further includes, when the redundancy control strategy among multiple smart cities with alternative external resources is determined to be an independent strategy, for the data substitution rate σ∈[0,1] among the multiple smart cities with alternative external resources, the resource allocation amount of the smart city... Compared to the data substitution rate σ, which is monotonically decreasing, that is Heng was established.
[0033] Preferably, a redundancy control strategy is determined among multiple smart cities with alternative external resources. Based on the redundancy control strategy and intrusion probability, the resource allocation amount for each smart city is determined, including:
[0034] When the redundancy control strategy among multiple smart cities with alternative external resources is determined to be a joint strategy, the probability of a smart city being successfully intruded upon by an unauthorized user after configuring information security resources is set as p, and the amount of information security resources configured by the smart city is set as x. The loss function C of the smart city cluster composed of multiple smart cities with the redundancy control strategy determined to be a joint strategy is then defined. J Minimum value Min C J :
[0035]
[0036] The aforementioned joint strategy refers to the situation where, when some or all of the data resources of the first smart city in a multi-smart city are maliciously tampered with or deleted, the second smart city will use its own stored data resources, which are identical to those of the first smart city, to restore the data resources of the first smart city through data resource substitution.
[0037] Substituting formula (5.1) into formula (5.8), we get:
[0038]
[0039] set up Taking the partial derivative of formula (5.9), we get:
[0040]
[0041] Taking the partial derivative of equation (5.10) further, we obtain the second derivative of equation (5.9):
[0042]
[0043] in, Heng is established, therefore in At that point, the loss function C J Find the minimum value Min C J ;
[0044] When the redundancy control strategy among multiple smart cities with alternative external resources is determined to be a joint strategy, the Nash equilibrium solution is obtained. The Nash equilibrium solution is used as a redundancy control strategy for the resource allocation of each smart city in the joint strategy.
[0045]
[0046] Preferably, it further includes, when the redundancy control strategy among multiple smart cities with alternative external resources is determined to be a joint strategy, when At the same time, as the number of smart cities with alternative external resources for information security increases, the resource allocation of smart cities will also increase. It will decrease accordingly, that is It is negatively correlated with n.
[0047] Preferably, it also includes, when the redundancy control strategy among multiple smart cities with alternative external resources is determined to be a joint strategy, the resource allocation amount of the smart city for any unauthorized user's intrusion probability β∈[0,1]. As the intrusion probability β monotonically increases, that is... Heng was established.
[0048] Preferably, it further includes, when the redundancy control strategy among multiple smart cities with alternative external resources is determined to be a joint strategy, for the data substitution rate σ∈[0,1] among the multiple smart cities with alternative external resources, the resource allocation amount of the smart city... As the data substitution rate σ monotonically increases, that is... Heng was established.
[0049] Preferably, it also includes when hour, Redundancy control strategy is an independent strategy for resource allocation in smart cities Resource allocation for smart cities with a less-than-redundancy control strategy as a joint strategy The expected cost C of a smart city with redundant control strategy as an independent strategy is then calculated. I The expected cost C of a smart city with a joint strategy but less than redundancy control strategy J .
[0050] Preferably, a redundancy control strategy is determined among multiple smart cities with alternative external resources. Based on the redundancy control strategy and intrusion probability, the resource allocation amount for each smart city is determined, including:
[0051] When the redundancy control strategy among multiple smart cities with alternative external resources is determined to be a collaborative sharing strategy, based on the data substitution rate δ∈[0,1] among the smart cities with alternative external resources, the amount of collaborative resource allocation obtained by the j-th smart city from other smart cities is determined as follows: Determine the loss function C for the j-th smart city. cj Minimum value Min C cj :
[0052]
[0053] The aforementioned collaborative sharing strategy refers to each smart city redundantly storing different data sets and sharing the redundantly stored data sets with smart cities that need the data sets;
[0054] set up Substituting formula (5.1) into formula (5.12), we get:
[0055]
[0056] The resource allocation for a smart city with a redundancy control strategy of collaborative sharing is determined by formula (5.13):
[0057]
[0058] Preferably, it also includes the amount of data loss when a smart city is successfully compromised by an unauthorized user. At that time, the redundancy control strategy is the resource allocation of a smart city based on the collaborative sharing strategy. Resource allocation in smart cities with independent redundancy control strategies Large resource allocation in smart cities, where redundancy control strategies are based on collaborative sharing strategies. Resource allocation for redundancy control strategies versus joint strategies The expected cost C of a smart city with a small redundancy control strategy and a collaborative sharing strategy. cj The expected cost C of a smart city with a redundant control strategy as an independent strategy I Low.
[0059] Preferably, it further includes, when the redundancy control strategy among multiple smart cities with alternative external resources is determined to be a collaborative sharing strategy, when... At that time, the resource allocation of smart cities Monotonically increasing, and when At that time, the resource allocation of smart cities Monotonically decreasing.
[0060] According to another aspect of the present invention, a system for resource allocation in a smart city based on data sharing type is provided, the system comprising:
[0061] A first determining device is used to determine multiple smart cities with alternative external resources, wherein the alternative external resources refer to at least two smart cities among the multiple smart cities that store the same part or all of their data resources, and when part or all of the data resources of the first smart city are maliciously tampered with or maliciously deleted, the second smart city can determine whether to use the same part or all of the data resources stored in the second smart city as the first smart city to restore the data resources of the first smart city by means of data resource substitution.
[0062] The second determining device is used to determine the allocation quota x of information security resources for each smart city. j The losses E that can be recovered by the organization's information security resources;
[0063] The third determining device is used to allocate a certain amount of information security resources for each smart city. j Given the recoverable loss E from the unit's information security resources, determine the probability p of successful intrusion by unauthorized users for each smart city after information security resource configuration. j :
[0064]
[0065] Where j is a natural number and 2 ≤ j ≤ n, where n is the number of smart cities with alternative external resources, β is the probability of an unauthorized user intruding into a smart city, where the probability of an unauthorized user intruding into each smart city is the same, and v is the probability of a smart city being successfully intruded into by an unauthorized user without information security resource configuration, where v is the same for each smart city; and
[0066] The fourth determining device is used to determine the redundancy control strategy among multiple smart cities with alternative external resources, and to determine the resource allocation amount for each smart city when allocating resources based on the redundancy control strategy and the intrusion probability.
[0067] According to another aspect of the present invention, a computer-readable storage medium is provided, characterized in that the storage medium stores a computer program for performing the methods described in any of the above embodiments.
[0068] According to another aspect of the present invention, an electronic device is provided, comprising:
[0069] processor;
[0070] Memory used to store the processor's executable instructions;
[0071] The processor is configured to read the executable instructions from the memory and execute the instructions to implement the method described in any of the above embodiments.
[0072] According to another aspect of the present invention, a computer program product is provided, including computer-readable code, which, when run on a device, enables a processor in the device to perform the method described in any of the above embodiments.
[0073] When information security resources are substitutable, the information security level of a smart city or network system can significantly impact the security environment of other connected smart city or network system clusters. This is especially true given the complex external environment, the suddenness of unauthorized user intrusions, and the uncertainties in resource allocation within smart city or network systems. These factors make information security resource allocation decisions for smart city or network system clusters more difficult. For smart cities or network systems with substitutable external resources, the degree of resource substitutability affects the probability of unauthorized user intrusion, thus influencing the expected cost of the smart city or network system. Therefore, this application incorporates the substitution rate between substitutable smart cities or network systems into the model, while also considering the impact of different influencing factors such as the scale of the smart city or network system and the probability of unauthorized user intrusion on resource allocation. It analyzes and discusses both independent and joint strategies, and proposes introducing a collaborative mechanism to address potential over-allocation issues in the independent strategy process. Attached Figure Description
[0074] Exemplary embodiments of the present invention can be more fully understood by referring to the following figures:
[0075] Figure 1 This is a schematic diagram illustrating the factors influencing information security according to an embodiment of the present invention;
[0076] Figure 2 This is a schematic diagram of the information security factor indicator system according to an embodiment of the present invention;
[0077] Figure 3 A schematic diagram illustrating factors affecting information security in smart cities for identifying threat sources according to embodiments of the present invention;
[0078] Figure 4 A schematic diagram illustrating factors affecting information security in smart cities for vulnerability identification according to an embodiment of the present invention;
[0079] Figure 5 This is a schematic diagram illustrating the factors affecting the information security of smart cities according to embodiments of the present invention.
[0080] Figure 6 This is a schematic diagram of an information security resource configuration framework according to an embodiment of the present invention;
[0081] Figure 7 This is a schematic diagram illustrating the relationships between information security entities within a smart city according to an embodiment of the present invention.
[0082] Figure 8 This is a schematic diagram illustrating the relationship between entities responsible for information security of complementary external resources in cities, according to an embodiment of the present invention.
[0083] Figure 9 This is a schematic diagram illustrating the relationships between entities responsible for information security of alternative external resources in cities, according to an embodiment of the present invention.
[0084] Figure 10 This is a schematic diagram illustrating the relationships between entities responsible for information security of weakly associated external resources in cities, according to an embodiment of the present invention.
[0085] Figure 11 A flowchart illustrating a method for resource allocation in a smart city based on a redundancy control strategy according to an embodiment of the present invention;
[0086] Figure 12 This is a flowchart of a method for resource allocation in a network system based on a redundancy control strategy according to an embodiment of the present invention;
[0087] Figure 13a According to an embodiment of the present invention, β is the resource allocation quota. A diagram illustrating the impact;
[0088] Figure 13b To provide σ as a resource allocation quota according to an embodiment of the present invention A diagram illustrating the impact;
[0089] Figure 14a According to an embodiment of the present invention, β is the resource allocation quota. A diagram illustrating the impact;
[0090] Figure 14b To provide σ as a resource allocation quota according to an embodiment of the present invention A diagram illustrating the impact;
[0091] Figure 15a To provide δ as a resource allocation quota according to an embodiment of the present invention A diagram illustrating the impact;
[0092] Figure 15b This is a schematic diagram illustrating the effect of δ on the expected loss according to an embodiment of the present invention;
[0093] Figure 16 This is a schematic diagram of a system for resource allocation in a smart city based on a redundancy control strategy according to an embodiment of the present invention.
[0094] Figure 17 This is a schematic diagram of the structure of a network system that performs resource allocation based on a redundancy control strategy according to an embodiment of the present invention; Detailed Implementation
[0095] It should be understood that, because this application primarily involves digital content such as data resources, data storage, data content, information resources, or digital information, the smart city in this application can be considered as a network cluster, network system, data system, data storage system, network resource collection, or network resource body. Therefore, this application essentially relates to methods and systems for internal resource allocation based on data parameters of smart cities, network clusters, network systems, data systems, data storage systems, network resource collections, or network resource bodies.
[0096] However, because network systems are highly dependent on new technologies such as cloud computing and the Internet of Things, the application of these technologies has brought about the potential for information risk diffusion, posing a multi-faceted impact on the information security of network systems. How to rationally allocate the resources of current network systems and minimize these information security risks has become a practical problem that must be addressed for the healthy development of current network systems.
[0097] Information security is a relatively abstract concept. It mainly involves checking system threats and vulnerabilities and using various methods to manage them, thereby preventing accidental or malicious information damage, leakage, and modification, and avoiding system malfunctions. The main characteristics of information security include: (1) Integrity. It requires that information is not deleted, modified, or forged during its transmission or storage, and that there be no delays, loss, or out-of-order actions, ensuring the integrity of the data. That is, the information is completely and accurately delivered from the source to the true destination without any illegal tampering. (2) Confidentiality. It requires strict control over all checkpoints where information leakage may occur, ensuring that information is not eavesdropped on or leaked. That is, information cannot be leaked to any unauthorized user, process, or entity during each process of generation, transmission, storage, and processing. (3) Availability. It requires ensuring that authorized entities can obtain the information and resources they require, and that the information and resources are available. (4) Controllability. The system must be able to control how information resource users use the information, meaning that information resource applicants are always under the effective control of the information system. (5) Non-repudiation. The system must establish an effective accountability mechanism, meaning that information users must be held responsible for their own actions.
[0098] Information resource allocation refers to the rational combination and distribution of information resources based on information security needs, in order to achieve the best security results. Information resources (or data resources, digital resources) generally include data resources, software resources, equipment resources, human resources, service resources, and other resources.
[0099] Data resources primarily refer to the physical or electronic data stored in the system, including documents and electronic files. Documents include contracts, faxes, reports, plans, proposals, daily data, and incoming / outgoing documents; electronic files include technical solutions, technical reports, information forms, system configuration files, program source code, and database forms. Software resources primarily refer to the software installed in the connected information system used to process, store, or transmit various types of information. This includes application software, utility software, and system software. Equipment resources primarily refer to the hardware facilities or physical equipment connected to the information system, forming the foundation of information resources. This includes host equipment, network equipment, storage equipment, security equipment, and cabling systems. Service resources refer to services that can be purchased or ordered and provide assistance or convenience to certified users. This includes system maintenance services, technical support services, and monitoring and management services. Other resources refer to resources other than those mentioned above that can provide corresponding direct or hidden value.
[0100] Game theory refers to the process by which multiple participants make decisions based on known information, with their decisions mutually constraining each other, and through continuous reasoning, choose the strategy that maximizes efficiency. Essentially, game theory involves obtaining basic information about participants from a complex environment, constructing appropriate mathematical models to simulate their behavior, and seeking the optimal outcome.
[0101] A Nash equilibrium is a solution found in the mathematical model described above that yields optimal decisions for all participants. In a Nash equilibrium, if some participants' equilibrium policy points remain unchanged, and the remaining participants cannot influence others by altering their own decisions, then the Nash equilibrium is stable.
[0102] Evolutionary game theory offers a novel perspective on game equilibrium, proposing an evolutionarily stable strategy, a dynamic equilibrium that provides a new approach to Nash equilibrium and the selection of equilibrium strategies. This theory posits that if the vast majority of participants choose an evolutionarily stable strategy, mutations by a minority of participants cannot infiltrate the group.
[0103] A game theory problem can be transformed into the following mathematical expression:
[0104] GT = {P, St} i Ut i} (2.1)
[0105] In the formula, GT represents the game problem;
[0106] P represents the set of participants, P = {1, 2, ..., n}, where n is the total number of participants;
[0107] {St i} represents the participant's policy set, St i Let represent the strategy of the i-th participant, where i ∈ P;
[0108] Ut i Let represent the payoff function for the i-th participant, where i ∈ P.
[0109] Evolutionary stable strategies in evolutionary game theory can also be transformed into mathematical descriptions:
[0110] Assume that the participant set P contains The proportion of participants is mutated, with the mutation strategy being y and the normal strategy being x. That is, there is a probability γ that a participant will choose strategy y, and a probability 1-γ that a participant will choose strategy x. The payoff for the mutation strategy is Ut(y, γy+(1-γ)x). If for any mutation strategy y≠x, and if there exists... The inequality Ut(x, γy+(1-γ)x) > Ut(y, γy+(1-γ)x) is satisfied for all If both of these hold true, then x is an evolutionarily stable strategy.
[0111] As can be seen from the above description, an evolutionarily stable strategy needs to satisfy the following conditions simultaneously:
[0112] For any strategy that satisfies y≠x, the following must be true:
[0113] (1) Balance, i.e., Ut(x, x) ≥ Ut(y, x);
[0114] (2) Stability, that is, if Ut(x, x) = Ut(y, x), then Ut(x, y) > Ut(y, y).
[0115] In one embodiment, determining the information security resource allocation influencing factor index system includes: identifying the influencing factors of resource allocation related to information security and establishing a corresponding index system. This is fundamental to reducing information security risks of network systems or data systems in smart cities under the background of big data. From an information security perspective, and considering the current situation of smart cities, the primary indicators of the information security influencing factor index system can be summarized into four aspects: resources, threat sources, vulnerabilities, and security measures. Figure 1 As shown.
[0116] Information resources encompass many types, but it's clear that the higher the value of a resource, the greater the potential risks in practice. Based on the definitions of smart cities and information resources, resource influencing factors are subdivided into three secondary indicators: technological factors, infrastructure, and incremental data resources. Further information security risk analysis is then conducted to obtain tertiary indicators, the results of which are as follows: Figure 2 As shown.
[0117] The number of information security technicians has a significant impact on information security. These individuals, possessing cybersecurity skills, provide assurance for the information security of smart cities. Technician certification is crucial because uncertified technicians who gain unauthorized access could easily lose control of information, thus compromising security. Core equipment is important because most information security infrastructure and key technologies can be controlled by uncontrollable entities, posing significant security risks. Some systems may contain vulnerabilities or backdoors, making information easily tampered with or stolen. The Internet of Things (IoT) infrastructure is vital because, with the continuous development of IoT, its role in smart cities is becoming increasingly important, supporting various urban application services. Attacks on IoT infrastructure can easily compromise personal privacy or business security. The leakage of secrets could even lead to system paralysis; wireless network equipment is mainly considered because WIFI is an essential part of urban infrastructure and provides many conveniences for smart cities, but there is also a risk of information leakage during data transmission; application systems can directly affect the construction and development of smart cities, and their maturity can reflect the level of urban information security; as for the increase in direct data resources, it refers to the data resources (including various software, data, hardware, or software-data-hardware combinations) directly used for information security construction in smart cities. The amount of data resource increase plays a decisive role in the construction and protection of information security to a large extent; the increase in indirect data resources mainly refers to the increase in resources used for information security through other means or for other purposes, which also plays a certain role in protecting information security.
[0118] Threat Sources: A threat is an objectively existing factor that may pose a potential risk to the information security of a smart city. Threat source influencing factors are further subdivided into two secondary indicators: technical threats and operational threats. Further information security risk analysis is then conducted on these secondary indicators to obtain tertiary indicators, as shown below. Figure 3As shown in the diagram. The physical environment primarily considers system interruptions caused by external disasters, leading to the loss of important data or files and increasing the probability of information security risks. Hardware and software primarily consider their failure rates; since smart city systems contain a large amount of hardware and software, failures can lead to service interruptions, data corruption, or loss, causing information security risks. Data primarily considers data theft and data tampering, which are currently the most prominent problems facing smart cities. Hacker intrusions can lead to the leakage of personal information and trade secrets, and sensitive data is easily lost or mismanaged, making it difficult to guarantee data confidentiality. Operational management focuses on preventing uncertainties and unreasonable network operation states, taking a risk-oriented approach and emphasizing the development of reasonable regulations for medium- and high-risk systems to ensure the healthy development of smart city information security. Technical threats are the most difficult security factor to control in threat source identification; in many incidents, internal system operations have compromised the integrity, confidentiality, and availability of information systems.
[0119] Vulnerability: Vulnerability primarily considers the possibility of attacks targeting smart city information systems in the context of big data, where vulnerabilities can be exploited. Vulnerability influencing factors are further subdivided into two secondary indicators: technical vulnerability and operational vulnerability. Further information security risk analysis is conducted to obtain tertiary indicators, as shown in the following results. Figure 4 As shown. Among them, IoT devices are the foundation of smart cities, but many important devices are vulnerable to damage due to their widespread and open distribution; the network mainly considers system vulnerabilities, defects in network components, and incorrect system configurations, and preventing these potential threats can effectively ensure the information security of smart cities; applications are numerous and varied in smart cities, many of which use open-source software, creating vulnerabilities for malicious attacks; data is constantly generated in smart cities and is crucial, but its storage, transmission, access, and encryption are prone to various vulnerabilities, leading to data theft and tampering; the physical environment mainly considers the internal and external environment surrounding the devices, supporting protective equipment, and security equipment.
[0120] Setting up operational strategies is primarily based on the consideration that, in the context of big data in smart cities, standardizing information security work and formulating secure operational strategies to achieve information security risk prevention and control is an inevitable path. Operation and maintenance technology can promote the effective implementation of information security work and ensure the stable operation of information systems. At the same time, operation and maintenance technology can implement protection responsibilities and prevent information security risks from occurring. Security operation and maintenance management is mainly considered because, with the continuous advancement of information security construction in smart cities, its importance is gradually being recognized. It mainly focuses on the daily maintenance and management of information security, and once unstable factors are discovered, reasonable measures are taken immediately.
[0121] Security measures: Security measures serve as a barrier to protect the information security of smart cities, effectively reducing the risk of security incidents, minimizing vulnerabilities, and providing technical support and management mechanisms for certain resources. The influencing factors of security measures are further subdivided into two categories of secondary indicators: preventative measures and protective measures. Further information security risk analysis is conducted on these secondary indicators to obtain tertiary indicators, as shown in the following results. Figure 5 As shown. Intrusion prevention and detection is a crucial component of information security, effectively preventing denial-of-service attacks on network infrastructure. Antivirus software is essential because network viruses have become a high-risk area threatening information security; currently, the best approach is to install powerful antivirus software. However, since viruses often precede antivirus software, the coverage of antivirus software is quite important. Patch upgrades are necessary because application software vulnerabilities are constantly emerging, leading to diverse attack methods. Updating with patches can effectively prevent information security incidents. Emergency plans are crucial because network information security incidents are often sudden and can cause significant losses; developing reasonable information security emergency plans can effectively reduce information security risks and harms.
[0122] Threat identification primarily considers training automatic identification models using basic public information security knowledge and professional information security expertise to enhance the information security risk identification capabilities of smart cities. The operational status detection mechanism addresses the need for an orderly, standardized, and unified operational status detection mechanism for the healthy and efficient operation of smart cities. Access control is crucial because numerous open application interfaces in the system create conditions for unauthorized access; restricting user permissions controls information security risks and ensures information is not illegally accessed. Identity authentication is also an effective information security risk prevention measure; by identifying the visitor's identity, the types of resources they can access are determined, preventing access to information outside their authorized scope, and facilitating the tracking of stolen information. Data encryption and auditing are primarily considered in the context of big data; encrypting data effectively prevents information from being spied on and can guarantee data integrity to a certain extent. Data backup and recovery are critical for ensuring data security; when a system malfunctions or data is lost, the system can be immediately restored to its original state.
[0123] An Evolutionary Game Theory Framework for Information Security Resource Allocation in Smart Cities
[0124] The basic framework, for example, is that with the continuous development and progress of new technologies such as artificial intelligence, big data, the Internet of Things, cloud computing, and virtual reality, the development and construction of smart cities are constantly being realized, but they also face great threats and challenges in areas such as information security. To effectively address these threats and challenges, based on a full understanding of the factors influencing the allocation of information security resources, this paper utilizes the currently popular evolutionary game theory to construct a reasonable and effective theoretical framework for information security resource allocation, enabling it to play its due role in ensuring information security. Through the analysis of the influencing factor indicator system, it can be seen that in smart cities, hardware and software, data, networks, applications, the external environment, and management are common aspects that all influencing factors need to address. For a city within a city, one issue to consider is how to plan limited resources effectively, avoid the limitations of the aforementioned influencing factors, and maximize the efficiency of all resources to ensure better information security. For a city that interacts with the outside world, considering all resources within the city as a whole, some external resources can complement internal resources, some can be substituted for each other, and some have weak correlations. How to rationally allocate these resources to improve the effectiveness of urban information security is another issue that needs to be considered. In summary, the information security resource allocation problem for a smart city involves analyzing how to allocate resources both internally and externally. Based on game theory, this application derives its information security resource allocation framework, as follows: Figure 6 As shown.
[0125] Allocation of resources within the city
[0126] Within a city, information security stakeholders can be categorized into service providers, users, and network management systems (or external systems, external data systems). Users can be further divided into legitimate users and illegitimate users. The relationships between these information security stakeholders are as follows: Figure 7 As shown. The service provider is the bearer of information security and the provider of data / services, and it has certain connections with both the network management system and users. The service provider provides sufficient information security guarantees to the network management system and users, preventing unauthorized users from seizing resources, and must provide normal data services to legitimate users (including the network management system). The network management system plays a certain supervisory role over the service provider's behavior through incentive and punishment measures. Users decide their asset allocation based on whether to purchase or subscribe to the service provider's products and services. Therefore, for the service provider, to realize its own interests, it must consider both service and economic factors when selecting and allocating various information security products and services, aiming to achieve the best results with the least output. Users are the users of information security; they can choose to legally obtain the data and services provided by the service provider, or they can choose to illegally intrude into the information system, profiting through theft, spying, or tampering. The network management system is the supervisor of information security and also one of the users; it can obtain the data and services provided by the service provider and can also supervise the service provider through incentive and punishment measures.
[0127] Allocation of complementary external resources
[0128] Regarding complementary external resources for smart cities, if a smart city is compromised by malicious users, the intrusion may not affect other smart cities. For example, if components of a certain type of equipment are manufactured by smart cities A and B, a malicious user cannot obtain the final assembly information of the equipment if they only intrude into smart city A or smart city B. Only when both smart cities A and B are compromised can all the information about the equipment be obtained. This increases the difficulty of intrusion and thus protects information security to a certain extent. However, in reality, information security-related companies between the two smart cities may be unwilling to cooperate. Therefore, for complementary external resources for smart cities, resource allocation needs to be considered in both non-cooperative and fully cooperative scenarios. Furthermore, incentive agreements can be signed when companies cooperate, meaning that if a company in smart city A is attacked, resulting in the impact on company in smart city B, then company in smart city A must provide corresponding data resources to company in smart city B. The relationship between information security entities of complementary external resources for smart cities is as follows: Figure 8 As shown.
[0129] Alternative configuration of external resources
[0130] For smart cities to have substitutable external resources, if an unauthorized user successfully intrudes into smart city A, but the incremental gains from intruding into smart city B are significantly less than the costs, then the resources in smart cities A and B are substitutable. For substitutable external resources, an unauthorized user can obtain the required resources in either smart city and immediately cease the attack after obtaining the resources. Conversely, if the attack fails in smart city A, the unauthorized user may continue to attack smart city B. For example, smart city A is the production location of a certain device, and smart city B is the sales location of the same device. Smart cities A and B are connected by a network. A can query information such as the device's inventory, sales volume, and unit price in B. If an unauthorized user wants to obtain this information, they can achieve their goal by attacking either A or B. The relationship between the information security subjects regarding substitutable external resources in smart cities is as follows: Figure 9 As shown.
[0131] Configuration of weakly related external resources
[0132] For weakly interconnected external resources in smart cities, information security benefits are primarily achieved through information sharing, allowing smart cities to relatively reduce investment. For two smart cities, A and B, if information sharing is chosen, unauthorized user information, system vulnerabilities, and patch upgrades will be mutually accessible, enabling relevant service providers to prepare in advance. If information sharing is not chosen, it's equivalent to each smart city having to undertake information security construction alone, thus reverting to a problem of resource allocation within the smart city itself.
[0133] Figure 11 This is a flowchart of a method for resource allocation in a smart city based on a redundancy control strategy according to an embodiment of the present invention. Method 1100 includes:
[0134] Step 1101: Identify multiple smart cities with alternative external resources, wherein the alternative external resources refer to at least two smart cities that store the same part or all of their data resources, and when part or all of the data resources of the first smart city are maliciously tampered with or maliciously deleted, the second smart city can determine whether to use the same part or all of the data resources stored in the second smart city as the first smart city to restore the data resources of the first smart city through a data resource substitution method;
[0135] Step 1102: Determine the information security resource allocation quota x for each smart city. j The losses E that can be recovered by the organization's information security resources;
[0136] Step 1103, based on the information security resource allocation quota x for each smart city jGiven the recoverable loss E from the unit's information security resources, determine the probability p of successful intrusion by unauthorized users for each smart city after information security resource configuration. j :
[0137]
[0138] Where j is a natural number and 2 ≤ j ≤ n, where n is the number of smart cities with alternative external resources, β is the probability of an unauthorized user intruding into a smart city, where the probability of an unauthorized user intruding into each smart city is the same, and v is the probability of a smart city being successfully intruded into by an unauthorized user without information security resource configuration, where v is the same for each smart city; and
[0139] Step 1104: Determine the redundancy control strategy among multiple smart cities with alternative external resources, and determine the resource allocation amount for each smart city when allocating resources based on the redundancy control strategy and the intrusion probability.
[0140] Figure 12 This is a flowchart of a method for resource allocation in a network system based on a redundancy control strategy according to an embodiment of the present invention. Method 1100 includes:
[0141] Step 1101: Identify multiple network systems with alternative external resources, wherein the alternative external resources refer to at least two network systems that store the same partial or all data resources, and when the partial or all data resources of the first network system are maliciously tampered with or maliciously deleted, the second network system can determine whether to use the partial or all data resources stored in the second network system that are the same as those of the first network system to restore the data resources of the first network system by means of data resource substitution.
[0142] Step 1102: Determine the information security resource allocation quota x for each network system. j The losses E that can be recovered by the organization's information security resources;
[0143] Step 1103: Based on the information security resource allocation quota x for each network system j Given the recoverable loss E from the unit's information security resources, determine the probability p of each network system being successfully compromised by an unauthorized user after information security resource configuration. j :
[0144]
[0145] Where j is a natural number and 2 ≤ j ≤ n, where n is the number of network systems with alternative external resources, β is the probability of an unauthorized user intruding into a network system, where the probability of an unauthorized user intruding into each network system is the same, and v is the probability of a network system being successfully intruded into by an unauthorized user without information security resource configuration, where v is the same for each network system; and
[0146] Step 1104: Determine the redundancy control strategy among multiple network systems with alternative external resources, and determine the resource allocation amount for each network system when configuring resources based on the redundancy control strategy and the intrusion probability.
[0147] In one embodiment, it further includes the intrusion probability p of each smart city or network system being successfully compromised by an unauthorized user after information security resource configuration. j Determine the probability P of an unauthorized user attacking and successfully infiltrating the current smart city or network system, assuming that all other smart city or network systems besides the current smart city or network system have failed to attack it. B :
[0148]
[0149] Where p1 represents the probability that an unauthorized user successfully intrudes into the current smart city or network system B. This represents the probability that an unauthorized user fails to attack any smart city or network system other than the current smart city or network system B, and then turns to attack the current smart city or network system B.
[0150] In one embodiment, a redundancy control strategy is determined among multiple smart city or network systems with alternative external resources. Based on the redundancy control strategy and intrusion probability, the resource allocation amount for each smart city or network system during resource configuration is determined, including:
[0151] When the redundancy control strategy among multiple smart city or network systems with alternative external resources is determined to be an independent strategy, the expected loss C of each or the I-th smart city or network system is set as follows: I Take the minimum value as the loss function Min C for each or the i-th smart city or network system. I :
[0152]
[0153] The independent strategy refers to the fact that when some or all of the data resources of the first smart city or network system are maliciously tampered with or deleted, the second smart city or network system will not use its own stored data resources that are the same as those of the first smart city or network system to restore the data resources of the first smart city or network system through data resource substitution.
[0154] Among them, L I L represents the amount of data loss after a smart city or network system is successfully compromised by an unauthorized user, where L is the data loss for each smart city or network system. I The same for all smart cities or network systems; β is the probability that an unauthorized user will choose to attack any smart city or network system, where β is the same for each smart city or network system; σ is the data substitution rate among smart cities or network systems with alternative external resources; determined based on formulas (5.1) and (5.2). Let k be the probability that the j-th smart city or network system (j = 3, 4, ..., n) is successfully invaded by an unauthorized user, where k is a natural number.
[0155] Substitute formula (5.1) into formula (5.3) to determine:
[0156]
[0157] Because in formula (5.4) With x j Irrelevant, settings Taking the partial derivative of formula (5.4), we can determine:
[0158]
[0159] By taking the partial derivative of formula (5.5), we can determine the second derivative of formula (5.4):
[0160]
[0161] Based on formula (5.6), Heng is established, therefore in At that point, the loss function C I Find the minimum value Min C I ;
[0162] When the redundancy control strategies among multiple smart city or network systems with alternative external resources are determined to be independent strategies, the Nash equilibrium solution is obtained. The resource allocation of each smart city or network system using the Nash equilibrium solution as a redundancy control strategy as an independent strategy. in It satisfies formula (5.7):
[0163]
[0164] In one embodiment, it also includes, satisfy And because The principle of constancy holds true, thus determining that as the number of smart cities or network systems with alternative external resources for information security increases, the amount of resources allocated to information security in smart cities or network systems will also increase. It will decrease accordingly, that is It is negatively correlated with n, and when hour, Zero;
[0165] As n increases, It will decrease, thus leading to Increase, and since v∈[0,1], therefore It will inevitably decrease accordingly.
[0166] In one embodiment, it further includes, when the redundancy control strategy among multiple smart city or network systems with alternative external resources is determined to be an independent strategy, the resource allocation amount of the smart city or network system for any unauthorized user's intrusion probability β∈[0,1] is... Compared to the probability of intrusion β, which monotonically increases, that is... Heng was established.
[0167] In one embodiment, it further includes, when the redundancy control strategy among multiple smart city or network systems with alternative external resources is determined to be an independent strategy, for the data substitution rate σ∈[0,1] among the multiple smart city or network systems with alternative external resources, the resource allocation amount of the smart city or network system... Compared to the data substitution rate σ, which is monotonically decreasing, that is Heng was established.
[0168] In one embodiment, a redundancy control strategy is determined among multiple smart city or network systems with alternative external resources. Based on the redundancy control strategy and intrusion probability, the resource allocation amount for each smart city or network system during resource configuration is determined, including:
[0169] When the redundancy control strategy among multiple smart city or network systems with alternative external resources is determined to be a joint strategy, the probability of a smart city or network system being successfully intruded upon by an unauthorized user after information security resource configuration is set as p, and the information security resource configuration limit of the smart city or network system is set as x. The loss function C of the smart city or network system group consisting of multiple smart city or network systems with the redundancy control strategy determined to be a joint strategy is defined.J Minimum value Min C J :
[0170]
[0171] The aforementioned joint strategy refers to the situation where, when some or all of the data resources of the first smart city or network system are maliciously tampered with or deleted, the second smart city or network system will use its own stored data resources, which are identical to those of the first smart city or network system, to restore the data resources of the first smart city or network system through data resource substitution.
[0172] Substituting formula (5.1) into formula (5.8), we get:
[0173]
[0174] set up Taking the partial derivative of formula (5.9), we get:
[0175]
[0176] Taking the partial derivative of equation (5.10) further, we obtain the second derivative of equation (5.9):
[0177]
[0178] in, Heng is established, therefore in At that point, the loss function C J Find the minimum value Min C J ;
[0179] When the redundancy control strategy among multiple smart city or network systems with alternative external resources is determined to be a joint strategy, the Nash equilibrium solution is obtained. The Nash equilibrium solution is used as a redundancy control strategy for the resource allocation of each smart city or network system in the joint strategy.
[0180]
[0181] In one embodiment, it further includes, when the redundancy control strategy among multiple smart city or network systems with alternative external resources is determined to be a joint strategy, when... At the same time, as the number of smart cities or network systems with alternative external resources for information security increases, the resource allocation of smart cities or network systems will also increase. It will decrease accordingly, that is It is negatively correlated with n.
[0182] In one embodiment, it further includes, when the redundancy control strategy among multiple smart city or network systems with alternative external resources is determined to be a joint strategy, the resource allocation amount of the smart city or network system for any unauthorized user's intrusion probability β∈[0,1] is... As the intrusion probability β monotonically increases, that is... Heng was established.
[0183] In one embodiment, it further includes, when the redundancy control strategy among multiple smart city or network systems with alternative external resources is determined to be a joint strategy, for the data substitution rate σ∈[0,1] among the multiple smart city or network systems with alternative external resources, the resource allocation amount of the smart city or network system is... As the data substitution rate σ monotonically increases, that is... Heng was established.
[0184] In one embodiment, it also includes, when hour, Redundancy control strategies are independent strategies for resource allocation in smart city or network systems. Resource allocation for smart city or network systems with redundancy control strategies that are joint strategies. The expected cost C of a smart city or network system with a redundancy control strategy as an independent strategy is then determined. I The expected cost C of a smart city or network system with a redundancy control strategy as a joint strategy is less than the redundancy control strategy. J .
[0185] In one embodiment, a redundancy control strategy is determined among multiple smart city or network systems with alternative external resources. Based on the redundancy control strategy and intrusion probability, the resource allocation amount for each smart city or network system during resource configuration is determined, including:
[0186] When the redundancy control strategy among multiple smart city or network systems with alternative external resources is determined to be a collaborative sharing strategy, based on the data substitution rate δ∈[0,1] among the smart city or network systems with alternative external resources, the amount of collaborative resource allocation obtained by the j-th smart city or network system from other smart city or network systems is determined as follows: Determine the loss function C for the j-th smart city or network system. cj Minimum value Min C cj :
[0187]
[0188] The aforementioned collaborative sharing strategy refers to each smart city or network system redundantly storing different data sets and sharing the redundantly stored data sets with smart cities or network systems that need the data sets;
[0189] set up Substituting formula (5.1) into formula (5.12), we get:
[0190]
[0191] The resource allocation for a smart city or network system with a redundancy control strategy of collaborative sharing is determined by formula (5.13):
[0192]
[0193] In one embodiment, it also includes the amount of data loss after a smart city or network system is successfully compromised by an unauthorized user. At that time, the redundancy control strategy is the resource allocation of smart city or network systems with a collaborative sharing strategy. Resource allocation for smart city or network systems with independent redundancy control strategies. Large resource allocation for smart city or network systems with redundancy control strategies based on collaborative sharing strategies. Resource allocation for redundancy control strategies versus joint strategies The expected cost C of a smart city or network system with low redundancy control strategy and a collaborative sharing strategy is low. cj The expected cost C of a smart city or network system with a redundant control strategy as an independent strategy. I Low.
[0194] In one embodiment, it further includes, when the redundancy control strategy among multiple smart city or network systems with alternative external resources is determined to be a collaborative sharing strategy, when... At that time, the resource allocation of smart cities or network systems Monotonically increasing, and when At that time, the resource allocation of smart cities or network systems Monotonically decreasing.
[0195] Information security in smart cities or network systems can replace external resource allocation methods.
[0196] Modeling based on technical problems
[0197] Problem Description: Since unauthorized users can attack other smart city or network systems connected to a single smart city or network system, and can relatively easily migrate from a more secure system to a less secure one, the information security level of a smart city or network system is determined by its resource allocation amount and quantity within a smart city network. This determination impacts other connected smart city or network systems, thus exhibiting significant externalities. Specifically, this application primarily considers the analysis of substitutable external resources. If, after a successful intrusion into a smart city or network system, the incremental benefit of intruding into other connected smart city or network systems is significantly lower than the cost, then the resources of that smart city or network system and its connected systems constitute substitutable resources. In this scenario, once an unauthorized user successfully intrudes into a smart city or network system, they obtain the necessary information and will not attempt to intrude into other smart city or network systems. Conversely, if the intrusion fails, the user may attempt to intrude into other connected smart city or network systems. The following two examples illustrate this problem well:
[0198] 1. After gaining system access to the hospital information system of smart city A or network system through intrusion, an unauthorized user can obtain a large amount of patient information and then use this information to sell unapproved drugs to patients for profit. The unauthorized user can obtain patient information without further intrusion into the same type of hospital in smart city B or network system.
[0199] 2. Large supermarkets and shopping malls exchange electronic data with their suppliers via satellite. This allows them to monitor the sales situation of goods in real time, and suppliers can immediately replenish stock if shortages are detected. If a large supermarket or shopping mall is connected to smart city or network system A, while its supplier is connected to smart city or network system B, an unauthorized user could easily steal its information by attacking either system.
[0200] For substitutable external resources, the information security level of a smart city determines the overall information security status of the smart city or network system cluster. Technical analysis reveals that if a smart city or network system improves its own information security level, unauthorized users will attack other vulnerable smart cities or network systems. Regarding substitutable external resources, it's clear that the degree of substitutability between smart cities or network systems affects the probability of unauthorized user intrusion, thus impacting the expected cost of information security construction. Therefore, the degree of substitutability must be considered in the model, along with other influencing factors such as the scale of the smart city or network system and the probability of unauthorized intrusion. Furthermore, resource allocation methods under both independent and collaborative strategies are discussed. By comparing the differences between the two, an information sharing and collaboration mechanism is introduced to further optimize information security resource allocation.
[0201] Problem Modeling: As shown in Formula (2.1), any game theory problem can be described as: GT = {P, St, Ut}. Regarding substitutable external resources, the interconnectedness of smart cities or network systems makes them vulnerable to attacks by unauthorized users. Furthermore, a successful attack on any one smart city or network system allows access to information about all associated smart cities or network systems. From... Figure 9 The inter-entity relationship diagram shows that if an unauthorized user successfully attacks smart city B or its network system, it will directly affect the information security of smart cities A and C or their network systems. The degree of impact is related to their substitutability.
[0202] Assumption 1: Unauthorized users have no prior information about the vulnerabilities in the information security of any smart city or network system. The probability of an unauthorized user intruding into any smart city or network system is the same, denoted as β. Assumption 2: The substitution rate among substitutable smart cities or network systems is the same, denoted as σ. After a smart city or network system is successfully intruded into by an unauthorized user, the loss (or data loss, information loss, network loss, etc.) borne by each smart city or network system is the same, denoted as L. I Assumption 3: When a smart city or network system lacks information security resource configuration, the probability of successful intrusion by an unauthorized user is the same, denoted as v.
[0203] Assuming the number of smart cities or network systems capable of replacing external resources is n, and the probability of the j-th (j = 1, 2, ..., n) smart city or network system being successfully intruded upon by an unauthorized user after information security resource configuration is p. j The information security resource allocation quota is x. j The loss recovered by the unit's information security resources (or unit's data resources) is E, and the expected loss after the smart city or network system configures information security resources is C. jFrom formula (4.1), we can obtain the probability p of the j-th smart city or network system being successfully invaded by an unauthorized user. j :
[0204]
[0205] Considering the substitutability of resources between smart cities or network systems, an unauthorized user who successfully intrudes into one smart city or network system can obtain any information they need and will not attempt to intrude into other smart cities or network systems. However, if their intrusion into one smart city or network system fails, they will choose other smart cities or network systems to attack. Figure 9 For example, if an unauthorized user wants to maximize their gains, the probability P of successfully infiltrating smart city B's network system is... B for:
[0206]
[0207] In formula (5.1), p1 is the probability that an unauthorized user successfully intrudes into the B smart city or network system. This indicates the probability that other smart city or network systems will not be successfully compromised by unauthorized users and will instead be attacked by smart city or network system B.
[0208] Information security configuration methods between complementary external resources under different circumstances
[0209] Information security resource allocation for smart cities or network systems under independent strategy:
[0210] This application mainly analyzes the resource allocation under the independent strategy of smart cities with alternative external resources. From formulas (5.1) and (5.2), it can be seen that the probability of a smart city or network system j (j = 1, 2, ..., n) being successfully intruded upon by an unauthorized user is... Then the expected loss C of a smart city or network system I Take the minimum value as its loss function:
[0211]
[0212] Substituting formula (5.1) into formula (5.3), we get:
[0213]
[0214] Because in formula (5.4) With x j Irrelevant, let Taking the partial derivative of formula (5.4) yields:
[0215]
[0216] Taking the partial derivative of equation (5.5) further yields the second derivative of equation (4.4):
[0217]
[0218] As can be seen from formula (5.6), Heng is established, therefore in At that point, the loss function C I We can obtain a minimum value, thus we can draw the following conclusion 1.
[0219] Conclusion 1: Under the independent strategy of smart cities with alternative external resources, the optimal resource allocation (or resource quantity) for each smart city or network system is: At that time, the game obtains a Nash equilibrium solution, where It satisfies formula (5.7).
[0220]
[0221] Based on formula (5.7), the impact of factors such as the scale of the associated smart city or network system, the probability of unauthorized user intrusion, and the resource substitution rate on the allocation of information security resources for the smart city or network system can be further analyzed. Conclusion 1 shows that... satisfy And because Assuming that the assumption holds true, and considering the characteristics of replaceable external resources, and taking into account the independent strategy, we can draw the following conclusion by analyzing the relationship between the scale of the smart city or network system and the information security resource allocation of the smart city or network system.
[0222] Conclusion 2: Under the independent strategy scenario, as the scale of smart cities or network systems becomes larger and information security can be replaced by external resources, the optimal resource allocation for information security in smart cities or network systems will vary. It will decrease accordingly, that is It is negatively correlated with n, and when hour, It is zero.
[0223] This is because as n increases, It will decrease, thus leading to Increase, and since v∈[0,1], therefore This will inevitably decrease. This indicates that under the independent strategy, as the scale of alternative smart cities or network systems increases, each smart city or network system will correspondingly reduce its resource allocation. Since alternative resources can cause over-allocation under the independent strategy, increasing the scale of smart cities or network systems can alleviate this problem to some extent. However, the scale of smart cities or network systems cannot be increased indefinitely; there is a certain critical threshold. When the scale of a smart city or network system exceeds this threshold, the smart city or network system will not allocate resources.
[0224] Under the independent policy scenario, analyzing the relationship between the probability of unauthorized user intrusion and the allocation of information security resources for smart cities or network systems leads to the following conclusion: Conclusion 3: Under the independent policy scenario, for any unauthorized user intrusion probability β∈[0,1], the optimal allocation of information security resources for smart cities or network systems... It will monotonically increase, that is Heng was established.
[0225] Conclusion 3 shows that in the smart city alternative external resource allocation model, the information security allocation of each smart city or network system will increase with the increase of the probability of unauthorized user intrusion. When the probability of unauthorized user intrusion increases, the smart city or network system will increase investment accordingly to prevent unauthorized intrusion, thereby improving the information security level of the smart city or network system.
[0226] Under the independent strategy scenario, analyzing the relationship between the resource substitution rate between smart city or network systems and the information security resource allocation of smart city or network systems leads to the following conclusion: Conclusion 4: Under the independent strategy scenario, for any resource substitution rate σ∈[0,1] between smart city or network systems, the optimal information security resource allocation of the smart city or network system monotonically decreases, i.e. Heng was established.
[0227] Conclusion 4 indicates that, under the independent strategy scenario, as the resource substitution rate between smart cities or network systems increases, the optimal resource allocation for information security in smart cities or network systems will increase accordingly. This means that the higher the resource substitution rate between smart cities or network systems, the greater the investment in data resources related to information security should be; conversely, the lower the substitution rate, the more appropriate the investment in data resources can be to reduce expected costs.
[0228] Information security resource allocation for smart cities or network systems under a joint strategy:
[0229] Compared to the independent strategy scenario, the joint strategy differs significantly. Since a joint strategy is employed, let's assume the probability of a smart city or network system being successfully compromised by an unauthorized user after configuring information security resources is denoted as p, and the allocation amount (or allocation amount, data resource amount, resource amount, data amount, etc.) of information security resources for the smart city or network system is denoted as x. Then, through problem modeling and formula (5.2), the loss function for the group of smart city or network systems under this scenario can be derived:
[0230]
[0231] Substituting formula (5.1) into formula (5.8), we get:
[0232]
[0233] make Taking the partial derivative of formula (5.9) yields:
[0234]
[0235] Taking the partial derivative of equation (5.10) further yields the second derivative of equation (5.9):
[0236]
[0237] As can be seen from formula (5.11), Heng is established, therefore in At that point, the loss function C J We can obtain a minimum value, thus we can draw the following conclusion 5.
[0238] Conclusion 5: Under the scenario of joint strategies among smart cities with alternative external resources, the optimal resource allocation amount (or resource quantity) for a smart city or network system. At that time, the game obtains a Nash equilibrium solution.
[0239] Compare the optimal resource allocation obtained from conclusions 1 and 5. and Obviously The resource allocation quota is less than If the resource allocation quota is limited, the information security level achieved by a smart city or network system under an independent strategy will be lower than that under a joint strategy.
[0240] By further analyzing the impact of each parameter on the optimal resource allocation under the joint strategy, we can obtain the following conclusions 6 to 8.
[0241] Conclusion 6: In the case of a joint strategy, when At the same time, as the scale of smart cities or network systems increases with the association of complementary external resources for information security, the optimal resource allocation for information security in smart cities or network systems becomes increasingly important. It will decrease accordingly, that is It is negatively correlated with n.
[0242] Conclusion 6 indicates that, under the joint strategy, if the smart city or network system suffers a loss of L... I When the resource allocation exceeds a certain threshold, the resource allocation amount for a smart city or network system decreases as the scale of the smart city or network system cluster increases. Furthermore, both Conclusions 2 and 6 show that for smart cities or network systems where information security can be replaced by external resources, regardless of whether an independent or collaborative strategy is employed, the optimal resource allocation amount decreases as the scale of the smart city or network system cluster increases.
[0243] Conclusion 7: Under the joint strategy, for any unauthorized user intrusion probability β∈[0,1], the optimal resource allocation (or resource quantity) for information security in smart cities or network systems is... As β monotonically increases, that is Heng was established.
[0244] Conclusion 7 indicates that under the joint strategy, the optimal resource allocation quota increases with the probability of unauthorized user intrusion. This trend is consistent with that in Conclusion 3 regarding the independent strategy; that is, regardless of whether the strategy is independent or joint, the optimal resource allocation quota for a smart city or network system increases with the probability of intrusion. Furthermore, because... In the case of an independent strategy, an increased probability of intrusion indicates that smart cities or network systems need to withstand greater information security risks, while a joint strategy can effectively reduce these risks to a certain extent. Therefore, for alternative external sources, a joint strategy can ensure a higher level of information security and alleviate the problem of excessive resource allocation associated with independent strategies.
[0245] Conclusion 8: Under the joint strategy, for any resource substitution rate σ∈[0,1] between smart cities or network systems, the optimal resource allocation for information security of smart cities or network systems is... As σ monotonically increases, that is Heng was established.
[0246] Conclusion 8 shows that under the joint strategy, the optimal resource allocation amount will increase with the increase of the resource substitution rate of smart cities or network systems. This is the same trend as in Conclusion 4 under the independent strategy. That is, regardless of whether it is an independent strategy or a joint strategy, the optimal resource allocation amount of smart cities or network systems will increase with the increase of the resource substitution rate between smart cities or network systems. This indicates that the substitution rate of information resources in smart cities or network systems largely determines the resource allocation for information security.
[0247] In summary, for smart cities or network systems with alternative external resources for information security, the resource allocation quota of smart cities or network systems varies with the scale of the smart city or network system cluster, the probability of unauthorized user intrusion, and the resource substitution rate of smart cities or network systems. However, regardless of whether it is an independent strategy or a joint strategy, the trend of change is consistent.
[0248] Introducing a collaborative mechanism
[0249] By analyzing and comparing the two scenarios of independent and joint strategies, and Based on the resource allocation amount and expected cost, it can be seen that the optimal resource allocation for a smart city or network system under the independent strategy is higher than that under the joint strategy, thus leading to the following conclusion 9.
[0250] Conclusion 9: When hour, The optimal resource allocation amount (or resource quantity) obtained under the independent strategy of smart cities or network systems. Less than the optimal resource allocation amount (or resource quantity) under the joint strategy. Then, the expected cost C in the case of an independent strategy I The expected cost C is less than that under the joint strategy. J .
[0251] Conclusion 9 indicates that the optimal data resource replenishment amount for smart cities or network system clusters with substitutable external resources under independent strategy is lower than that under joint strategy, and its expected cost is also lower. When smart cities or network systems implement independent strategies, if any one of the smart cities or network system clusters with substitutable external resources increases its information security resource allocation, it will reduce the probability of unauthorized users successfully intruding into that smart city or network system, thereby increasing the probability of unauthorized users attacking other smart cities or network systems. This will promote the information security resource allocation of other smart cities or network systems, thus improving the overall information security level of the smart city or network system cluster. Conclusion 9 also illustrates that there is an implicit layer of competition among smart cities or network systems with substitutable external resources, which may lead to over-allocation of information security resources within the smart city or network system cluster.
[0252] Conclusion 9 shows that if smart cities or network systems adopt independent strategies, it may lead to over-allocation of resources. Therefore, it is necessary to consider introducing a collaborative mechanism to ensure that the overall optimal resource allocation of the smart city or network system group reaches its best state. Based on the above, information sharing can be used to facilitate collaboration among alternative external resources, thereby addressing the problem of over-allocation.
[0253] Assumption 4: Smart cities or network systems ignore information leakage when sharing information.
[0254] Assumption 5: Any smart city or network system can obtain information from other alternative smart cities or network systems, meaning that the smart city or network system can utilize the resource allocation of other smart cities or network systems to make information security resource allocation decisions. Assume δ∈[0,1] represents the information security sharing rate between smart city or network system j and other smart cities or network systems. Then, the information security resource allocation amount that smart city or network system j obtains from other smart cities or network systems is:
[0255] Assuming that 5 holds true, the loss function C of the smart city or network system j can be obtained. c :
[0256]
[0257] make Substituting formula (4.1) into formula (5.12), we get:
[0258]
[0259] The optimal resource allocation amount (or resource quantity) under this condition can be obtained from formula (5.13):
[0260]
[0261] Compare this with the optimal resource allocation under independent and joint strategies. In comparison, it can be seen that This indicates that under information sharing, the optimal resource allocation for a smart city or network system cluster is larger than under an independent strategy but smaller than under a joint strategy. Therefore, this mechanism can effectively solve the problem of over-allocation of resources. Simultaneously, the expected costs are compared, including the losses incurred if the smart city or network system is successfully compromised by an unauthorized user. hour, The expected cost of a smart city or network system in this scenario. Less than the expected cost in the case of an independent strategy Therefore, under the information sharing mechanism, smart cities or network system clusters can reduce both resource allocation costs and expected costs, thus leading to the following conclusion 10.
[0262] Conclusion 10: For smart cities or network system clusters with alternative external resources, under information sharing conditions, the losses incurred if the smart city or network system is successfully compromised by an unauthorized user. At that time, the optimal resource allocation for smart cities or network systems Optimal resource allocation compared to the independent strategy case It needs to be larger than the optimal resource allocation under the joint strategy. It should be small, and its expected cost C cj C compared to the independent strategy case I It should be low.
[0263] Conclusion 10 clearly shows that if the losses in a smart city or network system exceed a certain threshold, compared with the independent strategy, the smart city or network system, under the condition of information sharing, can not only solve the problem of over-allocation of resources in the smart city or network system, but also reduce the expected cost, and can better solve the practical problem.
[0264] Further analysis of the relationship between the optimal resource allocation and the resource substitution rate of smart cities or network systems under this condition reveals that... Therefore, it can be deduced that as the replacement rate of smart cities or network systems increases, the optimal resource allocation of each smart city or network system within a group of smart cities or network systems will increase. Furthermore, due to... The optimal resource allocation for smart cities or network systems that provide alternative resources will decrease as information sharing increases, leading to the following conclusion:
[0265] Conclusion 11: For smart cities or network system clusters with alternative external resources, under the condition of information sharing within the smart city or network system cluster, for At that time, the optimal resource allocation for a smart city or network system cluster Monotonically increasing, while for At that time, the optimal resource allocation for a smart city or network system cluster Monotonically decreasing.
[0266] Conclusion 11 shows that the optimal resource allocation for each smart city or network system within a smart city or network system cluster increases with the increase in the smart city or network system substitution rate, and decreases with the increase in the information sharing rate between smart cities or network systems. Furthermore, after introducing a collaborative mechanism, when δ = 0, When δ = 1, In other words, if no coordination mechanism is introduced between smart cities or network systems, it will degenerate into an independent strategy; if a coordination mechanism is fully introduced between smart cities or network systems, it will evolve into a joint strategy.
[0267] In summary, when a collaborative mechanism is introduced for information sharing, the optimal information security resource allocation for a smart city or network system with substitutable resources will be greater than the optimal allocation under the independent strategy, while its expected cost will be lower. The optimal resource allocation for each smart city or network system within a group decreases as the degree of information sharing among them increases. When smart cities or network systems fully share information, their optimal information security resource allocation will reach the optimal level for the entire group. Therefore, introducing a collaborative mechanism can effectively incentivize smart cities or network systems to allocate resources rationally.
[0268] Results and Analysis
[0269] 1. Through numerical simulation, compare the optimal resource allocation amount (resource allocation quantity) and expected cost of smart city or network system under independent strategy and joint strategy. At the same time, analyze the trend of the impact of smart city or network system size n, illegal user intrusion probability β, and substitution rate σ between smart city or network systems on optimal resource allocation and expected cost under numerical conditions, i.e. numerical analysis under different conditions.
[0270] 2. Explore the impact of information security sharing rate δ of smart cities or network systems on optimal resource allocation and expected costs, i.e., numerical analysis after introducing a collaborative mechanism.
[0271] In reality, the number of complementary external resources associated with a smart city or network system is unlikely to be large, generally not exceeding four. Therefore, this application sets the scale of the smart city or network system to n=3 and n=4 in the numerical simulation. Since it is impossible and unnecessary to consider all values for certain parameters in actual numerical simulations, this application only considers a few representative values, assuming L=400, v=0.5, and E=0.1.
[0272] Numerical analysis under different conditions
[0273] Resource allocation under an independent strategy:
[0274] When n=3, the substitution rate σ between smart cities or network systems and the probability β of a smart city or network system being invaded by illegal users are set to gradually increase by 0.1 from 0.1 to 0.9, so that the impact of σ and β on resource allocation can be analyzed. The resource allocation amount and expected loss are shown in Tables 5.1 and 5.2.
[0275] Table 5.1 Resource allocation based on σ and β under independent strategy Impact
[0276]
[0277] Table 5.2 The impact of σ and β on expected loss in the case of independent strategy
[0278]
[0279] Further analysis of Tables 5.1 and 5.2 reveals the following results when σ is fixed at 0.1 and β takes values of [0.1, 0.9], and when β is fixed at 0.1 and σ takes values of [0.1, 0.9], respectively. Figure 13a and Figure 13b The results are shown.
[0280] from Figure 13a and Figure 13b It is evident that as β increases, the resource allocation amount It also continues to increase, verifying the correctness of conclusion 3; as σ continues to increase, the resource allocation amount It also continues to increase, verifying the correctness of conclusion 4.
[0281] When n=4, the substitution rate σ between smart cities or network systems is set to gradually increase by 0.1 from 0.1 to 0.9, and the probability β of a smart city or network system being invaded by an unauthorized user is set to 0.1. The resource allocation amount and expected loss are shown in Table 5.3.
[0282] Table 5.3 Partial resource allocation and expected loss when n=4 under the independent strategy case.
[0283]
[0284] Comparing the results in Table 5.3 with those in Tables 5.1 and 5.2, it can be seen that as n increases, the resource allocation amount... As the loss decreases, the expected loss also decreases, verifying the correctness of conclusion 2.
[0285] Resource allocation under a joint strategy:
[0286] When n=3, the substitution rate σ between smart cities or network systems and the probability of unauthorized user intrusion β are set to gradually increase by 0.1 from 0.1 to 0.9, so that the impact of σ and β on resource allocation can be analyzed. The resource allocation amount and expected loss are shown in Tables 5.4 and 5.5.
[0287] Table 5.4 Resource allocation amounts for σ and β under joint strategy Impact
[0288]
[0289]
[0290] Table 5.5 Impact of σ and β on expected loss under the combined strategy
[0291]
[0292] Further analysis of Tables 5.4 and 5.5 reveals the following results when σ is fixed at 0.1 and β takes values of [0.1, 0.9], and when β is fixed at 0.1 and σ takes values of [0.1, 0.9], respectively: Figure 14a and Figure 14b The results are shown.
[0293] from Figure 14a and Figure 14b It is evident that as β increases, the resource allocation amount It also continues to increase, verifying the correctness of conclusion 7; as σ continues to increase, the resource allocation amount It also continues to increase, verifying the correctness of conclusion 8.
[0294] When n=4, the substitution rate σ between smart cities or network systems is set to gradually increase by 0.1 from 0.1 to 0.9, and the probability β of a smart city or network system being invaded by illegal users is set to 0.1. The resource allocation amount and expected loss are shown in Table 5.6.
[0295] Table 5.6 Partial resource allocation and expected loss when n=4 under the joint strategy.
[0296]
[0297] Comparing the results in Table 5.6 with those in Tables 5.4 and 5.5, it can be seen that as n increases, the resource allocation amount... As the loss decreases, the expected loss increases, verifying the correctness of conclusion 6.
[0298] Numerical analysis after introducing a collaborative mechanism:
[0299] When σ = 0.1 and β = 0.1, the information security sharing rate δ between smart cities or network systems is set to gradually increase by 0.1 from 0.1 to 0.9. This allows us to analyze the impact of δ on resource allocation. The resource allocation amount and expected loss are shown in Table 5.7.
[0300] Table 5.7 Resource Allocation Amount and Expected Loss After Introducing the Collaboration Mechanism
[0301]
[0302] The results obtained in Table 5.7 can be graphically displayed as follows: Figure 15a , Figure 15b The results are shown.
[0303] As can be clearly seen from the graph above, as δ continuously increases, the resource allocation amount... The loss decreases continuously, while the expected loss increases as δ increases, verifying the correctness of conclusion 11.
[0304] Figure 16 This is a schematic diagram of a system for resource allocation in a smart city based on a redundancy control strategy according to an embodiment of the present invention. The system 1600 includes: a first determining device 1601, configured to determine multiple smart cities with alternative external resources, wherein the alternative external resources refer to at least two smart cities storing the same partial or all of their data resources, and when some or all of the data resources of the first smart city are maliciously tampered with or maliciously deleted, the second smart city can determine whether to use the same partial or all of the data resources stored in the second smart city as those of the first smart city to restore the data resources of the first smart city through a data resource substitution method;
[0305] The second determining device 1602 is used to determine the allocation quota x of information security resources for each smart city. j The losses E that can be recovered by the organization's information security resources;
[0306] The third determining device 1603 is used to determine the allocation quota x of information security resources for each smart city. jGiven the recoverable loss E from the unit's information security resources, determine the probability p of successful intrusion by unauthorized users for each smart city after information security resource configuration. j :
[0307]
[0308] Where j is a natural number and 2 ≤ j ≤ n, where n is the number of smart cities with alternative external resources, β is the probability of an unauthorized user intruding into a smart city, where the probability of an unauthorized user intruding into each smart city is the same, and v is the probability of a smart city being successfully intruded into by an unauthorized user without information security resource configuration, where v is the same for each smart city; and
[0309] The fourth determining device 1604 is used to determine the redundancy control strategy among multiple smart cities with alternative external resources, and to determine the resource allocation amount for each smart city when allocating resources based on the redundancy control strategy and the intrusion probability.
[0310] Figure 17 This is a schematic diagram of a system for configuring network system resources based on a redundancy control strategy according to an embodiment of the present invention. System 1700 includes: a first determining device 1701, used to determine multiple network systems having alternative external resources, wherein the alternative external resources refer to at least two network systems that store the same partial or all of their data resources, and when some or all of the data resources of the first network system are maliciously tampered with or maliciously deleted, the second network system can determine whether to use the same partial or all of the data resources stored in the second network system as those of the first network system to restore the data resources of the first network system through a data resource substitution method;
[0311] The second determining device 1702 is used to determine the allocation quota x of information security resources for each network system. j The losses E that can be recovered by the organization's information security resources;
[0312] The third determining device 1703 is used to determine the allocation quota x of information security resources for each network system. j Given the recoverable loss E from the unit's information security resources, determine the probability p of each network system being successfully compromised by an unauthorized user after information security resource configuration. j :
[0313]
[0314] Where j is a natural number and 2 ≤ j ≤ n, where n is the number of network systems with alternative external resources, β is the probability of an unauthorized user intruding into a network system, where the probability of an unauthorized user intruding into each network system is the same, and v is the probability of a network system being successfully intruded into by an unauthorized user without information security resource configuration, where v is the same for each network system; and
[0315] The fourth determining device 1704 is used to determine the redundancy control strategy among multiple network systems with alternative external resources, and to determine the resource allocation amount when configuring resources for each network system based on the redundancy control strategy and the intrusion probability.
[0316] In one embodiment, it further includes a fifth determining device, configured to determine the probability p of each smart city being successfully compromised by an unauthorized user after information security resource configuration. j Determine the probability P of an unauthorized user attacking and successfully infiltrating the current smart city, assuming that the user fails to attack any other smart city besides the current smart city. B :
[0317]
[0318] Where p1 represents the probability that an unauthorized user successfully intrudes into the current smart city B. This represents the probability that an unauthorized user fails to attack any smart city other than the current smart city and then turns to attack the current smart city B.
[0319] In one embodiment, the fourth determining device is specifically used to, when determining that the redundancy control strategy among multiple smart cities with alternative external resources is an independent strategy, calculate the expected loss C of each or the I-th smart city. I Take the minimum value as the loss function Min C for each or the i-th smart city. I :
[0320]
[0321] The aforementioned independent strategy means that when some or all of the data resources of the first smart city in a multi-smart city are maliciously tampered with or deleted, the second smart city will not use its own stored data resources that are the same as those of the first smart city to restore the data resources of the first smart city through data resource substitution.
[0322] Among them, L I L represents the amount of data loss after a smart city is successfully compromised by an unauthorized user. IThe same; β is the probability that an illegal user chooses to attack any smart city, where β is the same for each smart city; σ is the data substitution rate among smart cities with alternative external resources; determined based on formulas (5.1) and (5.2). Let k be the probability that the j-th smart city (j = 3, 4, ..., n) is successfully invaded by an unauthorized user, where k is a natural number.
[0323] Substitute formula (5.1) into formula (5.3) to determine:
[0324]
[0325] Because in formula (5.4) With x j Irrelevant, settings Taking the partial derivative of formula (5.4), we can determine:
[0326]
[0327] By taking the partial derivative of formula (5.5), we can determine the second derivative of formula (5.4):
[0328]
[0329] Based on formula (5.6), Heng is established, therefore in At that point, the loss function C I Find the minimum value Min C I ;
[0330] When the redundancy control strategies among multiple smart cities with alternative external resources are determined to be independent strategies, the Nash equilibrium solution is obtained. The resource allocation of each smart city is based on the Nash equilibrium solution as an independent redundancy control strategy. in It satisfies formula (5.7):
[0331]
[0332] In one embodiment, satisfy And because The principle of constancy is established, thus determining that as the number of smart cities with alternative external resources for information security increases, the amount of resources allocated to information security in smart cities will also increase. It will decrease accordingly, that is It is negatively correlated with n, and when hour, Zero;
[0333] As n increases, It will decrease, thus leading to Increase, and since v∈[0,1], therefore It will inevitably decrease accordingly.
[0334] In one embodiment, it further includes, when the redundancy control strategies among multiple smart cities with alternative external resources are determined to be independent strategies, the intrusion probability β ∈ [0, 1, ..., resource allocation of the smart city] for any unauthorized user is... Compared to the probability of intrusion β, which monotonically increases, that is... Heng was established.
[0335] In one embodiment, it further includes, when the redundancy control strategy among multiple smart cities with alternative external resources is determined to be an independent strategy, the data substitution rate σ among the smart cities with alternative external resources is σ∈[0, 1, ..., the resource allocation amount of the smart city]. Compared to the data substitution rate σ, which is monotonically decreasing, that is Heng was established.
[0336] In one embodiment, the fourth determining device is specifically used to, when determining that the redundancy control strategy among multiple smart cities with alternative external resources is a joint strategy, set the probability of a smart city being successfully intruded upon by an unauthorized user after configuring information security resources as p, set the information security resource configuration limit of the smart city as x, and determine the loss function C of the smart city cluster composed of multiple smart cities with the redundancy control strategy as a joint strategy. J Minimum value Min C J :
[0337]
[0338] The aforementioned joint strategy refers to the situation where, when some or all of the data resources of the first smart city in a multi-smart city are maliciously tampered with or deleted, the second smart city will use its own stored data resources, which are identical to those of the first smart city, to restore the data resources of the first smart city through data resource substitution.
[0339] Substituting formula (5.1) into formula (5.8), we get:
[0340]
[0341] set up Taking the partial derivative of formula (5.9), we get:
[0342]
[0343] Taking the partial derivative of equation (5.10) further, we obtain the second derivative of equation (5.9):
[0344]
[0345] in, Heng is established, therefore in At that point, the loss function C J Find the minimum value Min C J ;
[0346] When the redundancy control strategy among multiple smart cities with alternative external resources is determined to be a joint strategy, the Nash equilibrium solution is obtained. The Nash equilibrium solution is used as a redundancy control strategy for the resource allocation of each smart city in the joint strategy.
[0347] In one embodiment, it further includes, when the redundancy control strategy among multiple smart cities with alternative external resources is determined to be a joint strategy, when... At the same time, as the number of smart cities with alternative external resources for information security increases, the resource allocation of smart cities will also increase. It will decrease accordingly, that is It is negatively correlated with n.
[0348] In one embodiment, it further includes, when the redundancy control strategy among multiple smart cities with alternative external resources is determined to be a joint strategy, the intrusion probability β ∈ [0, 1, ..., resource allocation of the smart city] for any unauthorized user is... As the intrusion probability β monotonically increases, that is... Heng was established.
[0349] In one embodiment, it further includes, when the redundancy control strategy among multiple smart cities with alternative external resources is determined to be a joint strategy, the data substitution rate σ among the smart cities with alternative external resources is σ∈[0, 1, ..., the resource allocation amount of the smart city]. As the data substitution rate σ monotonically increases, that is... Heng was established.
[0350] In one embodiment, it also includes, when hour, Redundancy control strategy is an independent strategy for resource allocation in smart cities Resource allocation for smart cities with a less-than-redundancy control strategy as a joint strategy The expected cost C of a smart city with redundant control strategy as an independent strategy is then calculated. IThe expected cost C of a smart city with a joint strategy but less than redundancy control strategy J .
[0351] In one embodiment, the fourth determining device is specifically used to determine, when the redundancy control strategy among multiple smart cities with alternative external resources is determined to be a collaborative sharing strategy, the amount of collaborative resource allocation obtained by the j-th smart city from other smart cities based on the data substitution rate δ∈[0,1] among the multiple smart cities with alternative external resources. Determine the loss function C for the j-th smart city. cj Minimum value Min C cj :
[0352]
[0353] The aforementioned collaborative sharing strategy refers to each smart city redundantly storing different data sets and sharing the redundantly stored data sets with smart cities that need the data sets;
[0354] set up Substituting formula (5.1) into formula (5.12), we get:
[0355]
[0356] The resource allocation for a smart city with a redundancy control strategy of collaborative sharing is determined by formula (5.13):
[0357]
[0358] In one embodiment, it also includes the amount of data loss when a smart city is successfully compromised by an unauthorized user. At that time, the redundancy control strategy is the resource allocation of a smart city based on the collaborative sharing strategy. Resource allocation in smart cities with independent redundancy control strategies Large resource allocation in smart cities, where redundancy control strategies are based on collaborative sharing strategies. Resource allocation for redundancy control strategies versus joint strategies The expected cost C of a smart city with a small redundancy control strategy and a collaborative sharing strategy. cj The expected cost C of a smart city with a redundant control strategy as an independent strategy I Low.
[0359] In one embodiment, it further includes, when the redundancy control strategy among multiple smart cities with alternative external resources is determined to be a collaborative sharing strategy, when... At that time, the resource allocation of smart cities Monotonically increasing, and when At that time, the resource allocation of smart cities Monotonically decreasing.
Claims
1. A method for resource allocation in smart cities based on a redundancy control strategy, the method comprising: Identify multiple smart cities with alternative external resources, wherein the alternative external resources refer to at least two smart cities that store the same part or all of their data resources, and when part or all of the data resources of the first smart city are maliciously tampered with or maliciously deleted, the second smart city can determine whether to use the same part or all of the data resources stored in the second smart city as the first smart city to restore the data resources of the first smart city through a data resource substitution method. Determine the allocation amount of information security resources for each smart city. Losses that can be recovered by the organization's information security resources ; Based on the allocation quota of information security resources for each smart city Losses that can be recovered by the organization's information security resources Determine the probability of successful intrusion by unauthorized users in each smart city after information security resource configuration. : (5.1) Where j is a natural number and 2≤j≤n, and n is the number of smart cities with alternative external resources. This represents the probability of an unauthorized user intruding into a smart city, where the probability of an unauthorized user intruding into each smart city is the same. This represents the probability that a smart city will be successfully compromised by an unauthorized user without proper information security resource configuration, where each smart city... Same; and Determine the redundancy control strategy among multiple smart cities with alternative external resources, and determine the resource allocation amount for each smart city when allocating resources based on the redundancy control strategy and intrusion probability. It also includes the probability of successful intrusion by unauthorized users based on the information security resource configuration of each smart city. Determine the probability that an unauthorized user will successfully attack and compromise the current smart city, assuming that attacks on every other smart city have failed. : (5.2) in, The probability of an unauthorized user successfully intruding into the current smart city B. This represents the probability that an unauthorized user fails to attack any smart city other than the current smart city and then turns to attack the current smart city B. This includes determining redundancy control strategies among multiple smart cities with alternative external resources, and determining the resource allocation amount for each smart city based on the redundancy control strategies and intrusion probability, including: When the redundancy control strategy among multiple smart cities with alternative external resources is determined to be a collaborative sharing strategy, the data substitution rate among these smart cities is based on this strategy. Determine the amount of collaborative resource allocation that the j-th smart city obtains from other smart cities. Determine the loss function for the j-th smart city. minimum value : (5.12) The aforementioned collaborative sharing strategy refers to each smart city redundantly storing different data sets and sharing the redundantly stored data sets with smart cities that need the data sets; set up Substituting formula (5.1) into formula (5.12), we get: (5.13) The resource allocation for a smart city with a redundancy control strategy of collaborative sharing is determined by formula (5.13): (5.14)。 2. The method according to claim 1, wherein a redundancy control strategy is determined among multiple smart cities with alternative external resources, and the resource allocation amount for each smart city is determined based on the redundancy control strategy and intrusion probability, comprising: When the redundancy control strategy among multiple smart cities with alternative external resources is determined to be an independent strategy, the expected loss of each or the I-th smart city is... Take the minimum value as the loss function for each or the i-th smart city. : (5.3) The aforementioned independent strategy means that when some or all of the data resources of the first smart city in a multi-smart city are maliciously tampered with or deleted, the second smart city will not use its own stored data resources that are the same as those of the first smart city to restore the data resources of the first smart city through data resource substitution. in, This represents the amount of data loss after a smart city is successfully compromised by an unauthorized user, where each smart city... same; For unauthorized users, the probability of attacking any smart city is selected, where each smart city... same; The data substitution rate among smart cities with alternative external resources; determined based on formulas (5.1) and (5.2). For the j-th smart city The probability of a successful intrusion by an unauthorized user, where k is a natural number; Substitute formula (5.1) into formula (5.3) to determine: (5.4) Because in formula (5.4) and Irrelevant, settings Taking the partial derivative of formula (5.4), we can determine: (5.5) By taking the partial derivative of formula (5.5), we can determine the second derivative of formula (5.4): (5.6) Based on formula (5.6), Heng is established, therefore in At that point, the loss function Get the minimum value ; When the redundancy control strategies among multiple smart cities with alternative external resources are determined to be independent strategies, the Nash equilibrium solution is obtained. The Nash equilibrium solution is used as the resource allocation for each smart city with an independent redundancy control strategy. ,in It satisfies formula (5.7): (5.7)。 3. The method according to claim 2, further comprising: satisfy And because The principle of constancy is established, thus determining that as the number of smart cities with alternative external resources for information security increases, the amount of resources allocated to information security in smart cities will also increase. It will decrease accordingly, that is and It is negatively correlated, and when hour, Zero; Among them, due to the following The increase, It will decrease, thus leading to Increase, and due to ,so It will inevitably decrease accordingly.
4. The method according to claim 3, further comprising, when the redundancy control strategies among multiple smart cities with alternative external resources are determined to be independent strategies, the intrusion probability for any unauthorized user. Resource allocation in smart cities Compared to the probability of intrusion It will monotonically increase, that is Heng was established.
5. The method according to claim 3, further comprising, when determining that the redundancy control strategy among multiple smart cities with alternative external resources is an independent strategy, the data substitution rate among the smart cities with alternative external resources. Resource allocation in smart cities Compared to data replacement rate Monotonically decreasing, that is Heng was established.
6. The method according to claim 1, wherein a redundancy control strategy is determined among multiple smart cities with alternative external resources, and the resource allocation amount for each smart city is determined based on the redundancy control strategy and intrusion probability, comprising: When the redundancy control strategy among multiple smart cities with alternative external resources is determined to be a joint strategy, the probability of a smart city being successfully compromised by an unauthorized user after its information security resource configuration is set to... The allocation of information security resources for smart cities will be set as follows: The loss function of a smart city cluster consisting of multiple smart cities with a joint strategy for redundancy control is determined. minimum value : (5.8) The aforementioned joint strategy refers to the situation where, when some or all of the data resources of the first smart city in a multi-smart city are maliciously tampered with or deleted, the second smart city will use its own stored data resources, which are identical to those of the first smart city, to restore the data resources of the first smart city through data resource substitution. Substituting formula (5.1) into formula (5.8), we get: (5.9) Taking the partial derivative of formula (5.9), we get: (5.10) Taking the partial derivative of equation (5.10) further, we obtain the second derivative of equation (5.9): (5.11) in, Heng is established, therefore in At that point, the loss function Get the minimum value ; When the redundancy control strategy among multiple smart cities with alternative external resources is determined to be a joint strategy, the Nash equilibrium solution is obtained. The Nash equilibrium solution is used as a redundancy control strategy for the resource allocation of each smart city in the joint strategy. : 。 7. The method of claim 6, further comprising, when determining that the redundancy control strategy among multiple smart cities with alternative external resources is a joint strategy, when... At the same time, as the number of smart cities with alternative external resources for information security increases, the resource allocation of smart cities will also increase. It will decrease accordingly, that is and Negative correlation .
8. The method of claim 6, further comprising, when determining that the redundancy control strategy among multiple smart cities with alternative external resources is a joint strategy, the intrusion probability for any unauthorized user. Resource allocation in smart cities With the probability of intrusion Monotonically increasing, that is Heng was established.
9. The method of claim 6, further comprising, when determining that the redundancy control strategy among multiple smart cities with alternative external resources is a joint strategy, specifying the data substitution rate among the smart cities with alternative external resources. Resource allocation in smart cities With data substitution rate Monotonically increasing, that is Heng was established.
10. The method of claim 6, further comprising, when hour, Redundancy control strategy is an independent strategy for resource allocation in smart cities. Resource allocation for smart cities with a less-than-redundancy control strategy as a joint strategy The redundant control strategy is the expected cost of a smart city with an independent strategy. The expected cost of a smart city with a less-than-redundant control strategy as a joint strategy .
11. The method according to claim 1, further comprising: the amount of data loss after a smart city is successfully compromised by an unauthorized user. At that time, the redundancy control strategy is the resource allocation of a smart city based on the collaborative sharing strategy. Resource allocation in smart cities with independent redundancy control strategies Large resource allocation in smart cities, where redundancy control strategies are based on collaborative sharing strategies. Resource allocation for redundancy control strategies versus joint strategies The expected cost of a smart city with a small redundancy control strategy and a collaborative sharing strategy. The expected cost of a smart city with a redundant control strategy as an independent strategy Low.
12. The method of claim 1, further comprising, when determining that the redundancy control strategy among multiple smart cities with alternative external resources is a collaborative sharing strategy, when... At that time, the resource allocation of smart cities Monotonically increasing, and when At that time, the resource allocation of smart cities Monotonically decreasing.
13. A system for resource allocation in smart cities based on data sharing types, the system comprising: A first determining device is used to determine multiple smart cities with alternative external resources, wherein the alternative external resources refer to at least two smart cities among the multiple smart cities that store the same part or all of their data resources, and when part or all of the data resources of the first smart city are maliciously tampered with or maliciously deleted, the second smart city can determine whether to use the same part or all of the data resources stored in the second smart city as the first smart city to restore the data resources of the first smart city by means of data resource substitution. The second determining device is used to determine the allocation quota of information security resources for each smart city. Losses that can be recovered by the organization's information security resources ; The third determining device is used to allocate information security resources based on the quota for each smart city. Losses that can be recovered by the organization's information security resources Determine the probability of successful intrusion by unauthorized users in each smart city after information security resource configuration. : (5.1) Where j is a natural number and 2≤j≤n, and n is the number of smart cities with alternative external resources. This represents the probability of an unauthorized user intruding into a smart city, where the probability of an unauthorized user intruding into each smart city is the same. This represents the probability that a smart city will be successfully compromised by an unauthorized user without proper information security resource configuration, where each smart city... Same; and The fourth determining device is used to determine the redundancy control strategy among multiple smart cities with alternative external resources, and to determine the resource allocation amount of each smart city when allocating resources based on the redundancy control strategy and the intrusion probability. It also includes the probability of successful intrusion by unauthorized users based on the information security resource configuration of each smart city. Determine the probability that an unauthorized user will successfully attack and compromise the current smart city, assuming that attacks on every other smart city have failed. : (5.2) in, The probability of an unauthorized user successfully intruding into the current smart city B. This represents the probability that an unauthorized user fails to attack any smart city other than the current smart city and then turns to attack the current smart city B. This includes determining redundancy control strategies among multiple smart cities with alternative external resources, and determining the resource allocation amount for each smart city based on the redundancy control strategies and intrusion probability, including: When the redundancy control strategy among multiple smart cities with alternative external resources is determined to be a collaborative sharing strategy, the data substitution rate among these smart cities is based on this strategy. Determine the amount of collaborative resource allocation that the j-th smart city obtains from other smart cities. Determine the loss function for the j-th smart city. minimum value : (5.12) The aforementioned collaborative sharing strategy refers to each smart city redundantly storing different data sets and sharing the redundantly stored data sets with smart cities that need the data sets; set up Substituting formula (5.1) into formula (5.12), we get: (5.13) The resource allocation for a smart city with a redundancy control strategy of collaborative sharing is determined by formula (5.13): (5.14)。 14. A computer-readable storage medium, characterized in that, The storage medium stores a computer program for performing the method according to any one of claims 1-12.
15. An electronic device comprising: processor; Memory used to store the processor's executable instructions; The processor is configured to read the executable instructions from the memory and execute the instructions to implement the method of any one of claims 1-12.
Citation Information
Patent Citations
Smart city service configuration based on information grid service
CN105931168A
IDS resource configuration method and device and computer readable storage medium
CN110381020A