Low-cost Deployment Method of Hint Chain in Zero-Trust Access Network
By introducing verification cost balance VCB factor and sub-cue chain branch boundary SCBB algorithm, the deployment of prompt chains in zero-trust network is optimized, and the conflict between deployment cost and verification cost is solved, and the lower total service cost and higher resource utilization is achieved.
Patent Information
- Application Number
- CN202411721802.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-28
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2044-11-28
AI Technical Summary
The deployment method of prior art prompt chains in zero-trust networks fails to effectively balance deployment costs with verification costs, resulting in low resource utilization and reduced service responsiveness.
The verification cost balance VCB factor and sub-cue chain branch boundary SCBB algorithm are introduced. By optimizing PES node selection and ZT verification strategies, the optimal node is gradually selected to deploy the prompt chain to minimize service costs.
It reduces the total service cost and verification cost, improves resource utilization efficiency and service response speed, adapts to dynamic network needs, and achieves more efficient prompt chain deployment.
Smart Images

Figure CN119603028B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the cross - technical field of new generation information technology and artificial intelligence applications, in particular to a low - cost deployment method of a hint chain in a zero - trust access network. Background Art
[0002] In modern network and distributed computing environments, deployment methods of chained services are widely used in multiple fields, including network function virtualization (NFV), software - defined network (SDN), and cloud computing, etc. Chained services usually refer to a data - flow management method that orderly processes data through a series of service functions (SFs), namely, a service function chain (SFC). Such a chained structure enables data - flow to pass through a series of virtual or physical functions, such as firewalls, load balancers, encryption, etc., on - demand, thereby improving the flexibility and controllability of the network. While ensuring that data - flow passes through each service node in a specific order, the service function chain helps to achieve resource optimization, bandwidth management, and latency control.
[0003] Regarding the problem of optimal deployment of SFC, a large number of studies have proposed different methods. Some scholars have defined the minimum - cost service function chaining and embedding problem (MC - SFCE) and proposed a cost - factor - based SFC optimization algorithm (COFO - SC) to minimize the cost in service function chain delivery. Some other scholars have defined the hybrid service function chain embedding problem (HSFCE) and proposed an embedding algorithm based on hybrid service function chain optimization (HSFCE algorithm) to optimize resource utilization and load balancing in a multi - access edge computing environment. However, directly applying such a deployment method of chained services to implement the deployment of a hint chain under a zero - trust network architecture is difficult to ensure cost optimization.
[0004] In the Cost Factor Optimization for Service Chaining (COFO-SC) algorithm and the Hybrid Service Function Chain Embedding (HSFCE) algorithm, the COFO-SC (Cost Factor Optimization for Service Chaining) algorithm aims to solve the Minimum Cost Service Function Chaining and Embedding (MC-SFCE) problem by introducing cost factors to optimize the embedding of service function chains. The COFO-SC algorithm takes into account network transmission and computing costs in resource allocation and path selection, thus minimizing the overall cost in service function chain delivery. This algorithm not only has significant advantages in transmission efficiency but also provides an embedding strategy with better resource utilization for different service function chain requirements. In addition, COFO-SC has provable performance bounds, ensuring the efficiency and effectiveness of the algorithm.
[0005] In addition, the Hybrid Service Function Chain Embedding (HSFCE) algorithm for the Hybrid Service Function Chain Embedding problem distributes service function chains in a multi-access edge computing (MEC) environment, aiming to optimize resource utilization and load balancing. By reasonably distributing the functional components of service function chains between edge nodes and cloud nodes, this algorithm can reduce latency, improve service quality, and achieve effective resource management. The HSFCE algorithm takes into account the heterogeneity of edge and cloud resources and proposes a hybrid embedding strategy, enabling more efficient utilization of computing resources and network resources in the multi-access edge computing environment.
[0006] In summary, many studies focus on how to efficiently deploy chained services (such as service function chains, SFCs) and have proposed numerous deployment methods. However, directly applying these deployment methods for chained services to a zero-trust (ZT) network to achieve the economic deployment of hint chains still poses challenges. This is mainly because the deployment process of hint chains is closely related to the ZT verification process, and optimizing the deployment cost of hint chains does not necessarily synchronously optimize the ZT verification cost, which may bring some additional problems.
[0007] Specifically, the deployment of the prompt chain usually gives priority to the deployment cost of the generative artificial intelligence content (AIGC) path, and then minimizes the ZT verification cost on this basis as much as possible. However, this step-by-step optimization method may result in higher overall service costs. First, simply optimizing the deployment cost of the AIGC path may affect the efficiency of ZT verification. Especially when bypassing the policy enforcement point (PEP), it may increase unnecessary resource consumption. Second, the computing resources and costs required to implement the virtual policy enforcement point (vPEP) are often underestimated, and additional delays and resource overheads may be introduced during the actual verification process.
[0008] In summary, the disadvantage of the existing solution is that it fails to achieve global optimization between the deployment cost and the verification cost. Relying on a step-by-step strategy of first optimizing the path deployment and then minimizing the verification cost, it is easy to ignore the mutual influence between the two, resulting in a single optimization strategy being difficult to meet the actual needs of complex network scenarios. In addition, this method is insufficient in coping with the dynamic verification requirements in the ZT network, which may lead to a decline in service responsiveness and a reduction in resource utilization. Therefore, designing a joint optimization strategy that can comprehensively consider the deployment and verification costs will be the key to improving the deployment efficiency of the chain service in the ZT network. Summary of the Invention
[0009] To solve the problems existing in the prior art, the object of the present invention is to provide a low-cost deployment method for the prompt chain in the zero-trust access network. The present invention not only solves the conflict problem between the deployment cost and the verification cost of the prompt chain in the ZT network, but also provides an economical, efficient and adaptable deployment method, thereby enhancing the service quality and resource utilization efficiency of the generative artificial intelligence application in the ZT network.
[0010] To achieve the above object, the technical solution adopted by the present invention is: a low-cost deployment method for the prompt chain in the zero-trust access network, comprising the following steps:
[0011] Step 1, introduce a verification cost balance VCB factor to reduce the verification times and related overheads of zero-trust ZT;
[0012] Step 2, propose a sub-prompt chain branch and bound SCB algorithm based on the verification cost balance VCB factor, and gradually select the optimal PES node to deploy the prompt chain, so as to minimize the service cost.
[0013] As a further improvement of the present invention, in Step 1, the calculation method of the verification cost balance VCB factor specifically includes:
[0014] (1) In the non-verification scenario: When consecutive prompts can be deployed on the same PES node, due to the inherent security guarantee within the node, no additional verification is required. Therefore, the value of the verification cost balance VCB factor is equal to the average of the calculation costs of the deployed prompts.
[0015] (2) In the bypass policy enforcement point PEP verification scenario: When consecutive prompts are deployed on different PES nodes, the policy enforcement point PEP is used for zero-trust ZT verification, and the routing cost is incorporated into the VCB calculation to control the overall cost of the service.
[0016] (3) In the virtual policy enforcement point vPEP verification scenario: When using vPEP for verification, no additional routing is required. A vPEP instance is created after the previous prompt instance, which is the carrier of the prompt function deployed on the PES. The VCB value includes the additional calculation cost.
[0017] As a further improvement of the present invention, step 2 specifically includes the following steps:
[0018] Step 2.1. Algorithm initialization: First, initialize the forwarding path. Remove the zero-th prompt of the prompt chain, which is the business starting point, from the source node, and then gradually deploy from the first prompt.
[0019] Step 2.2. Gradually deploy the prompt chain: In each iteration of the algorithm, calculate the VCB value of deploying the current possible prompt set on each PES node, select the node with the lowest VCB value as the optimal deployment node; update the currently deployed sub-path and add it to the total path.
[0020] Step 2.3. Iterative update: After each group of prompts is deployed, update the index and continue to deploy the next prompt set until the entire prompt chain is deployed.
[0021] Step 2.4. Select the GPT server: After all prompts are deployed, select the GPT server with the lowest cost to process the final query and update it to the forwarding path.
[0022] The present invention optimizes the deployment cost and verification cost of the prompt chain in a zero-trust (ZT) network, and solves the cost conflict problem existing in the traditional chained service deployment method in the ZT environment. Specifically, it includes:
[0023] (1) Reduce the overall service cost: By introducing the VCB factor and the SCBB algorithm, the invention aims to achieve efficient deployment of the prompt chain in the ZT network, minimizing the additional calculation and routing costs during the ZT verification process, thereby reducing the total service cost.
[0024] (2) Balance deployment and verification costs: The present invention achieves the balance between deployment costs and verification costs through the flexible selection of three verification methods and the dynamic calculation of the VCB factor, so as to avoid the increase in overall costs caused by excessive focus on a single cost.
[0025] (3) Improve deployment efficiency: Through the Sub - Clue - Chain Branch - and - Bound (SCBB) algorithm, the optimal node is gradually selected to allocate the clue chain, which improves the deployment efficiency of the clue chain on PES nodes, and the best GPT server is selected to process requests, enhancing the response speed and efficiency of the service.
[0026] (4) Adapt to dynamic requirements: The invention takes into account the dynamic verification requirements in the ZT network and provides a flexible clue - chain deployment scheme, which can adapt to the resource limitations and network - state changes of different PES nodes, and achieves a more robust deployment in a complex network environment.
[0027] The beneficial effects of the present invention are as follows:
[0028] 1. Reduce the total service cost: Compared with the PCDF and LOFD schemes, the SCBB algorithm has significant advantages in the total service cost. Experimental results show that the average total service cost of SCBB is 4.67% and 13.89% lower than that of PCDF and LOFD respectively. This is because SCBB reduces the verification requirements by deploying consecutive clues on the same PES node, thereby reducing the verification cost.
[0029] 2. Reduce the verification cost: SCBB is also superior to other schemes in terms of verification cost. By reducing the number of PEP and vPEP verifications, it further saves service overhead. Experimental data show that the verification cost of SCBB is 11.86% and 30.50% lower than that of PCDF and LOFD respectively. This benefits from the design of preferentially deploying consecutive clues on the same PES node in the SCBB strategy, which reduces the number of ZT verifications and thus reduces the resource consumption related to verification.
[0030] 3. Improve the acceptance rate: In terms of resource utilization efficiency, SCBB shows the highest acceptance rate. When 4000 requests are deployed, the acceptance rate of SCBB reaches 56.24%, which is significantly higher than 51.75% of PCDF and 28.18% of LOFD. This is due to the optimization of SCBB in resource allocation and clue - chain deployment path, enabling it to complete more requests more effectively under limited resource conditions.
[0031] 4. Running Time: In terms of running time, SCBB demonstrates high efficiency. The average time to process an AI-SR request is 133.14 milliseconds, which is close to 123.73 milliseconds of LOFD and significantly faster than 191.95 milliseconds of PCDF. This shows the competitiveness of SCBB in deployment efficiency and helps improve the real-time response ability of the system.
[0032] In summary, by optimizing the cost allocation of prompt chain deployment and ZT verification, SCBB achieves lower total service cost and verification cost, higher acceptance rate, and better running efficiency, demonstrating its technical advantages in prompt chain deployment in the ZT network environment. Brief Description of the Drawings
[0033] Figure 1 It is an example diagram of the SCBB algorithm in an embodiment of the present invention;
[0034] Figure 2 It is a schematic diagram of the influence of the prompt chain length in an embodiment of the present invention;
[0035] Figure 3 It is a schematic diagram of average total overhead vs. the number of PEP in an embodiment of the present invention;
[0036] Figure 4 It is a schematic diagram of acceptance rate vs. service requirements in an embodiment of the present invention. Detailed Embodiment
[0037] The embodiments of the present invention will be described in detail below with reference to the accompanying drawings.
[0038] Embodiment
[0039] A low-cost deployment method of prompt chains in a zero-trust access network proposes a strategy to optimize prompt chain deployment and minimize service costs by introducing a verification cost balance (VCB) factor and a sub-prompt chain branch and bound (SCBB) algorithm. Among them, the VCB factor can help reduce the number of ZT verifications and thus achieve the purpose of reducing the overall service cost. The specific implementation steps are as follows:
[0040] 1. VCB Factor Calculation: Three different VCB calculation methods are designed for the following situations respectively:
[0041] (1) No Verification: When consecutive prompts can be deployed on the same PES node, due to inherent security, no additional ZT verification is required, so the VCB value is equal to the average of the calculation costs for deploying this group of prompts.
[0042] (2) PEP Verification: When consecutive prompts are deployed across different PES nodes, use PEP (Policy Enforcement Point) for ZT verification and incorporate routing costs into the VCB calculation to control the overall cost of the service.
[0043] (3) vPEP Verification: When using virtual PEP (vPEP) for verification, although no additional routing is required, a vPEP instance needs to be created after each newly deployed prompt, and the VCB value includes additional computational costs.
[0044] 2. Sub - Prompt Chain Branch - and - Bound (SCBB) Algorithm: The SCBB algorithm proposed based on the VCB factor gradually selects the optimal PES nodes to deploy the prompt chain, thereby achieving minimized service costs. The core steps of the algorithm are as follows:
[0045] (1) Algorithm Initialization: First, initialize the forwarding path (For_Path), starting from the source node (\(\mathbb{S}\)), and remove the first prompt (\(p0\)) of the prompt chain PrC. Then, gradually deploy from the first prompt.
[0046] (2) Gradually Deploy the Prompt Chain: In each iteration of the algorithm, calculate the VCB value of each PES node for deploying the current set of prompts, and select the node with the lowest VCB value as the optimal deployment node. Update the current deployed sub - path Sub_Path and add it to the total path (For_Path).
[0047] (3) Iterative Update: After each set of prompts is deployed, update the index and continue to deploy the next set of prompts until the entire prompt chain is deployed.
[0048] (4) Select the GPT Server: After all prompts are deployed, select the GPT server with the lowest cost to process the final query and update it to the forwarding path.
[0049] This solution effectively resolves the cost conflict between prompt chain deployment and ZT verification, and achieves the minimization of the global service cost through the SCBB algorithm and the calculation of the VCB factor, providing an economical and efficient deployment solution for the prompt chain in the ZT network.
[0050] Example 2
[0051] In this example, using the SCBB (Sub - Prompt Chain Branch - and - Bound) algorithm, the optimized deployment process of the prompt chain is detailed (as Figure 1 shown), aiming to achieve the lowest total service cost. The following is a detailed description of each step:
[0052] 1. The first step (Iteration 1): First, it is necessary to deploy the first prompt p1. According to the topology, both PES nodes A and B are capable of hosting p1. The VCB factors of PES A and B are calculated to be 5 and 6 respectively. It is chosen to deploy p1 on PES A, and a virtual PEP (vPEP) is installed on the source node S for zero-trust (ZT) verification. This choice minimizes the deployment cost of the first step. At this time, the last deployed node in the forwarding path is updated to PES A. This operation not only meets the security requirements of the ZT network but also reduces the number of verifications on the transmission path, saving additional verification costs.
[0053] 2. The second step (Iteration 2): Next, it is necessary to deploy the second prompt p2. At this time, PES nodes C and D can host the deployment of p2. According to the optimized calculation of the SCBB algorithm, it is chosen to jointly deploy the second prompt p2 and the third prompt p3 on the same PES node D. This approach further reduces the ZT verification overhead by deploying consecutive prompts on the same node. To ensure ZT verification requirements, PEP verification is adopted between PES A and PES D. The advantage of this choice is that PEP verification can provide security during transmission without incurring the cost of adding an additional vPEP for each node (the cost of choosing PEP verification is lower). At the same time, since p2 and p3 are jointly deployed on PES D, the number of ZT verifications is reduced, thereby reducing the total verification cost.
[0054] 3. The third step (Iteration 3): When all prompts are deployed, the algorithm enters the final step, which is to select a GPT server to process the final query. The SCBB algorithm selects GPT server G2 to minimize the final service cost. GPT server G2 can not only meet the service requirements but also provides a relatively low transmission cost, further optimizing the deployment cost of the entire prompt chain.
[0055] Detailed calculation of the total service cost: The VCB factors for the first two steps are both 5, carrying 1 and 2 prompt functions respectively, and the cost of selecting server G2 with the minimum service cost in the third step is 3. Therefore, the total cost is: 5+(5*2)+3=18.
[0056] Through the deployment process of the SCBB algorithm, it shows how to achieve cost minimization by reasonably selecting PES nodes and ZT verification strategies. This optimization scheme not only effectively reduces the total service cost by reducing the number and frequency of PEP and vPEP verifications but also fully considers the balance of computing resources and transmission resources on the path. The final result shows that the SCBB algorithm has obvious advantages in terms of resource efficiency and cost control, providing a good solution for the economical and efficient deployment of the prompt chain in the zero-trust network.
[0057] Effect experiment:
[0058] 1. Experimental process:
[0059] In the experiment, this embodiment used the NY-20 topology for network simulation. The network includes 20 nodes, providing 7 prompts, where 4 nodes are randomly selected as GPT servers, 1 to 4 nodes as PEP (Policy Enforcement Point), and the remaining nodes as PES (Prompt Execution Server). The computing power of each PES is 1000 to 2000 CPU cores and supports 4 types of prompt instances. The bandwidth capacity of the link is between 10 and 40 Gbps, and the weights are continuously distributed between 5 and 20. Each AI-SR (Artificial Intelligence Service Request) contains 3 to 7 prompts, each prompt consuming 0.5 to 0.8 CPU cores, and each vPEP consuming 0.6 CPU cores. The bandwidth requirement is between 1 and 5 Mbps, and the source node is randomly selected in the network.
[0060] The experiment was conducted in 80 different networks, with 4000 AI-SR requests in each network. The following three schemes were used as benchmarks for comparison:
[0061] (1) Prompt Chain Deployment Only (PCDO): Deploy AI-SR only using the existing chained service deployment technology, without zero-trust (ZT) verification.
[0062] (2) Prompt Chain Deployment First Approach (PCDF): First obtain the prompt chain path through PCDO, and then select the cheapest ZT verification method for adjacent prompt nodes in the path.
[0063] (3) Local Optimal First Deployment (LOFD): For each prompt node, first select the cheapest verification method, and then find the nearest PES to deploy the next prompt instance.
[0064] 2. Results and data analysis:
[0065] The experimental results show that the SCBB (Sub-Prompt Chain Branch and Bound) algorithm of this embodiment is superior to other benchmark schemes in various key performance indicators:
[0066] (1) Influence of prompt chain length on cost:
[0067] ① Total Service Cost (TC):
[0068] Figure 2(a) in it shows the total service cost under different hint chain lengths. As the hint chain length increases, the service costs of all schemes increase because more hints will directly increase the computing cost and may extend the forwarding path.
[0069] SCBB is always superior to PCDF and LOFD in terms of the total service cost. SCBB shows lower overhead in both CPU computing cost and routing cost. Specifically, the average total service cost of SCBB is 4.67% lower than that of PCDF and 13.89% lower than that of LOFD.
[0070] ② Verification Cost:
[0071] SCBB reduces the number of PEP or vPEP verifications by deploying consecutive hints on the same PES node, significantly reducing the verification cost. In terms of the verification cost, SCBB is 11.86% and 30.50% lower than PCDF and LOFD respectively. Figure 2 (b) in it further verifies this. The SCBB scheme always has the highest "No Verification" ratio under different hint chain lengths, showing the advantage of SCBB in reducing the verification cost. For example, when the hint chain length is 3, the no-verification ratio of SCBB is 43.38%, while those of PCDF and LOFD are 34.4% and 30.01% respectively; when the hint chain length is 7, the no-verification ratio of SCBB increases to 54.50%, while those of PCDF and LOFD are 45.2% and 33.78% respectively.
[0072] (2) Impact of the number of PEP on the cost:
[0073] Figure 3 (It) shows the impact of different numbers of PEP on the total service cost. As the number of PEP increases, the cost of the PCDO scheme rises because more PES are selected as PEP and hint instances cannot be deployed. The performance changes of the SCBB, PCDF, and LOFD schemes are relatively small because the convenience of PEP verification and the deployment cost caused by the reduction of PES offset each other. In this context, SCBB can still maintain lower computing and routing costs and has an advantage over other schemes.
[0074] (3) Acceptance Ratio (AcP):
[0075] Figure 4Shows the average acceptance rate when 4000 requests are deployed in 80 networks. Since the "no verification" ratio of the SCBB scheme is the highest, its resource utilization efficiency is the best, and it is also lower in terms of the total service cost. The numerical values show that the acceptance rate of SCBB is 56.24%, while the acceptance rates of PCDF and LOFD are 51.75% and 28.18% respectively, and SCBB is significantly better than other schemes.
[0076] (4) Runtime:
[0077] In terms of runtime, SCBB shows high efficiency. The average time required to deploy one AI-SR request is 133.14 milliseconds, which is faster than 191.95 milliseconds of PCDF, and slightly higher than 123.73 milliseconds of LOFD. This shows that SCBB not only has advantages in cost control but also can maintain a relatively fast deployment efficiency.
[0078] The above-described embodiments merely represent specific implementation manners of the present invention. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the patent of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present invention, several modifications and improvements can still be made, and these all fall within the protection scope of the present invention.
Claims
1. A low-cost deployment method for hint chains in a zero-trust access network, characterized in that, It includes the following steps: Step 1, introduce the verification cost balance VCB factor to reduce the verification times and related overheads of zero trust ZT; In Step 1, the specific calculation method of the verification cost balance VCB factor includes: (1) In the scenario without verification: when consecutive prompts can be deployed on the same PES node, due to the inherent security guarantee within the node, no additional verification is required. Therefore, the value of the verification cost balance VCB factor is equal to the average of the calculation costs of the deployed prompts; (2) In the scenario of bypass policy enforcement point PEP verification: when consecutive prompts are deployed on different PES nodes, use the policy enforcement point PEP for zero trust ZT verification and incorporate the routing cost into the VCB calculation to control the overall cost of the service; (3) In the scenario of virtual policy enforcement point vPEP verification: when using vPEP for verification, no additional routing is required. Create a vPEP instance after the previous prompt instance, that is, the carrier of the prompt function deployed and installed on the PES. The VCB value includes the additional calculation cost; Step 2, propose the sub - prompt chain branch and bound SCB algorithm based on the verification cost balance VCB factor, and gradually select the optimal PES node to deploy the prompt chain, thereby minimizing the service cost; The specific steps of Step 2 include the following steps: Step 2.1, algorithm initialization: First, initialize the forwarding path. Remove the zero - numbered prompt of the prompt chain, that is, the business starting point, from the source node, and then gradually deploy starting from the first prompt; Step 2.2, gradually deploy the prompt chain: In each iteration of the algorithm, calculate the VCB value of each PES node for deploying the current possible prompt set, select the node with the lowest VCB value as the optimal deployment node; update the currently deployed sub - path and add it to the total path; Step 2.3, iterative update: After each group of prompts is deployed, update the index and continue to deploy the next prompt set until the entire prompt chain is deployed; Step 2.4, select the GPT server: After all prompts are deployed, select the GPT server with the lowest cost to process the final query and update it to the forwarding path.
Citation Information
Patent Citations
Validating correlation between chains of alerts using cloud view
US20180351783A1
Verifying Integrity and Secure Operations of Cloud-Based Software Services
US20220166626A1