A security authentication gateway system and method based on AI analysis
By introducing AI analysis modules and other working together in the security authentication gateway system, the verification matrix and signature functions are generated, which solves the problem that traditional gateways are difficult to adapt to in a dynamic network environment, and the balance between security and communication speed is achieved, and the security and flexibility of the network are improved.
Patent Information
- Application Number
- CN202510134810.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-07
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-02-07
AI Technical Summary
When facing a dynamic network environment and unstable communication links, traditional security authentication gateways are difficult to dynamically adapt and effectively manage, resulting in attackers accessing resources by disguising or bypassing the authentication mechanism. In microservices and containerized environments, traditional gateways cannot effectively manage dynamically changing service endpoints, making it difficult to balance security and communication speed.
A security authentication gateway system based on AI analysis is adopted, which includes a log verification module, an AI analysis module, a solid-state hardware module, a quantitative decoding module and a conditional latch module. Through the collaborative work of these modules, a verification matrix is generated, a signature function is generated using the AI model, and a communication protocol is exchanged through the IKE negotiation mechanism to dynamically adapt to the network environment to ensure a balance between security and communication speed.
It quickly adapts to the frequent joining or leaving of devices in a dynamic environment, ensures security and improves the communication speed of network communication, effectively prevents playback attacks, supports multi-factor authentication, simplifies user experience, and reduces network management costs.
Smart Images

Figure CN119603077B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of gateway verification, and in particular to a security authentication gateway system and method based on AI analysis. Background Art
[0002] A security authentication gateway is a network security device that manages user access to network resources and prevents unauthorized access and data leakage through authentication, authorization, and encryption technologies. Security authentication gateways are usually set up between vulnerable subnets and provide secure connections and authentication mechanisms through encryption protocols such as SSL / TLS.
[0003] Asymmetric encryption is the mainstream encryption protocol for communication between security gateways. It achieves stable communication between subnets by encrypting and forwarding information multiple times. Under this encryption method, the same data packet must be encrypted or decoded at least three times between networks to complete the communication process, which greatly prolongs the communication time. In addition, the issuance of public keys requires certification by a third-party organization. For temporary confidential communication links, the use of asymmetric encryption requires a large amount of network computing resources.
[0004] In addition, traditional gateways usually rely on static rules and find it difficult to dynamically adapt to changing network environments and unstable communication links, making it possible for attackers to access resources by disguising themselves or bypassing authentication mechanisms. In microservice and containerized environments, traditional gateways are also unable to effectively manage dynamically changing service endpoints, making it difficult to balance security and communication speed. Summary of the invention
[0005] The purpose of the present invention is to provide a security authentication gateway system and method based on AI analysis to solve the problems raised in the above background technology.
[0006] In order to solve the above technical problems, the present invention provides the following technical solutions: a security authentication gateway system based on AI analysis, comprising: a log verification module, an AI analysis module, a solid-state hardware module, a quantization decoding module and a conditional latch module;
[0007] The log verification module is used to obtain the communication records between the source subnet and the destination subnet, use the time series characteristics of the communication records as the diagonal elements of the verification matrix, and randomly extract data from the intranet communication log of a fixed period and add it to the verification matrix until the elements composed of the extracted data and the diagonal elements meet the diagonal matrix conditions, output the generated verification matrix, process the data plaintext through the verification matrix, and update the matrix state once each time VPN communication is performed;
[0008] The AI analysis module is used to process the request information sent by the subnet IP to the routing gateway, transmit the request to the cloud, and the cloud verifies the compliance of the request. After locating the target IP subnet, the parameter seed is randomly generated according to the current clock and the IP of both parties, and the communication protocol and parameter seed are exchanged through the IKE negotiation mechanism. The AI model is used to generate a signature function in the gateways of both communicating parties based on the parameter seed, so that the value of the signature function decays with the communication time, and the non-diagonal element value of the verification matrix is used as the decay coefficient of the signature function;
[0009] The solid-state hardware module is composed of an FPGA chip arranged in front of the terminal gateway and a router or proxy server that undertakes the routing resolution function, which is used to build a physical communication link of the security gateway, receive DNS address information from the cloud, direct the URL addresses of the two communicating parties, and provide data analysis, data latching and clock verification functions;
[0010] The quantization decoding module is used to confirm the sending and receiving time of the information, calculate the function fading coefficient according to the sending time and receiving time of the signature function, restore the verification matrix according to the communication log between the subnets and the non-diagonal element values corresponding to the fading coefficient, decode the data through the verification matrix, obtain the plaintext data packet, and store the response signal of the terminal subnet;
[0011] The conditional latch module is used to construct a verification matrix in the terminal subnet, use the verification matrix to process the response signal, obtain the first data packet, retain the first data packet for a period, and when data is received again, use the received data as the second data packet, wait for the value of the signature function of the first data packet and the value of the signature function of the second function to be lower than a fixed ratio, send the first data packet and decode the second data packet, thereby completing the information exchange process.
[0012] Further, the log verification module includes: a record screening unit and a matrix updating unit;
[0013] The record screening unit is used to store the communication records between subnets and intranet devices, and retrieve the records with the IP address of the application service as the primary key;
[0014] The matrix updating unit is used to randomly extract the communication data between the information source subnet and the information sink subnet and the communication data between the intranet devices, and generate the verification matrix according to the communication data.
[0015] Further, the AI analysis module includes: a cloud channel unit, a public key negotiation unit and an AI signature unit;
[0016] The cloud channel unit is used to provide a communication link between the subnet and the cloud, and transmit the public key, replacement protocol and obtain AI computing power support in the cloud;
[0017] The public key negotiation unit is used to determine the address, network parameters and communication protocol of the source subnet and the destination subnet through IKE negotiation, and the communication protocol includes: SAML, OAuth, OpenID Connect and LDAP standard protocols;
[0018] The AI signature unit is used to randomly generate parameter seeds, generate a signature function using a generative AI model, and set a decay value of the signature function.
[0019] Further, the solid-state hardware module includes: an FPGA unit and a solid-state routing unit;
[0020] The FPGA unit is used to be arranged in front of the terminal gateway as a signal receiver and electronic analyzer. The models of FPGA chips include: Spartan, Artix, Kintex, Virtex and Zynq;
[0021] The solid-state routing unit is used to provide a proxy forwarding service for communication requests and act as a general gateway in the link.
[0022] Further, the quantization decoding module includes: a clock verification unit and a feature restoration unit;
[0023] The clock verification unit is used to analyze the sending time and the delivery time of the communication data, and determine the fading coefficient of the signature function according to the time difference;
[0024] The feature restoration unit is used to restore the fading coefficients to non-diagonal element values of the verification matrix, obtain the diagonal elements of the verification matrix from the communication log, and thus restore the verification matrix.
[0025] Further, the conditional latch module includes: a gateway reconstruction unit, a trigger unit and a signal exchange unit;
[0026] The gateway reconstruction unit is used to generate a verification matrix of the destination gateway, and process the response message into a first data packet in a protocol peer-to-peer manner;
[0027] The trigger unit is used to trigger a clock reset instruction after the destination gateway receives the second data packet sent by the source gateway;
[0028] The signal exchange unit is used to wait for the decay of the signature function of the second data packet when the clock is reset, and when the values of the first and second data packets are lower than the fixed ratio, send the first data packet and perform a decoding operation on the second data packet.
[0029] A security authentication gateway method based on AI analysis, comprising the following steps:
[0030] Step S1. Set up an FPGA chip in front of the gateway. After the gateway receives the access application from the source subnet, parse the URL access address in the application, locate the destination subnet according to the URL, obtain all communication records between the source subnet and the destination subnet, and extract the communication features in the communication records;
[0031] Step S2. Construct a verification matrix, use the communication features as the diagonal elements of the matrix, and randomly extract the intranet communication data of the source subnet and add it to the verification matrix, so that the verification matrix meets the diagonal matrix condition, and use the verification matrix to process the communication data;
[0032] Step S3. The cloud verifies the compliance of the request and randomly generates a parameter seed. The generative AI model generates a signature function based on the parameter seed, processes the signature function, and makes the signature function decay over the communication time. The non-diagonal element value of the verification matrix is used as the decay coefficient of the signature function. The communication protocol is exchanged between the source subnet and the destination subnet through the IKE negotiation mechanism.
[0033] Step S4. The destination subnet receives the data packet, calculates the fading coefficient according to the current value of the signature function, the sending time and the receiving time of the data packet, and restores it to the off-diagonal element value of the verification matrix. The verification matrix is restored from the communication records between the subnets and the off-diagonal element values of the verification matrix, and the data packet is decoded;
[0034] Step S5. The destination subnet replaces the non-diagonal elements in the verification matrix, reconstructs the verification matrix, latches the first data packet sent to the source subnet, and waits for the value of the signature function of the first data packet to meet the value of the signature function of the second function to be lower than the ratio, then sends the first data packet and decodes the second data packet to complete the information exchange.
[0035] Further, step S1 includes:
[0036] Step S11. Setting an FPGA chip, wherein the input pin of the FPGA chip is connected to the gateway, and is used to assist the gateway in data processing. The models of the FPGA chip include: Spartan, Artix, Kintex, Virtex and Zynq;
[0037] Step S12. A server in the source subnet sends an access request to the gateway, locates the sink subnet by the URL address corresponding to the request, searches the communication log, obtains all communication records between the source subnet and the sink subnet, and if no communication record exists, presets the initial communication record between the source subnet and the sink subnet through IKE negotiation;
[0038] Step S13. Extract communication features from the communication records, the communication features including: communication duration, data packet capacity, DNS and ping value, and digitize the communication features according to a unified standard and store them in a database.
[0039] Further, step S2 includes:
[0040] Step S21. Use the communication features obtained in step S13 as diagonal elements to construct a diagonal matrix E1:
[0041] ;
[0042] Wherein, n represents the number of communication features, and R1 to Rn represent the 1st to nth communication feature values, respectively;
[0043] Step S22. Randomly extract communication data from the intranet of the source subnet and add it to the diagonal matrix E1, so that E1 satisfies the diagonal matrix condition. The diagonal matrix condition is: the number of added elements reaches n-1, the matrix is a full rank matrix, and Y i ≠Ri is always established, where Y i represents the i-th off-diagonal element, Ri represents the i-th diagonal element, i∈{1, 2,…, n};
[0044] Step S23. After the communication data is extracted, the verification matrix ER is obtained:
[0045] ;
[0046] Among them, Y1, Y n-1 and Y n-2 Represent the 1st, n-1th and n-2th off-diagonal elements respectively;
[0047] Use the verification matrix to process the plaintext information and obtain the encrypted data packet.
[0048] Further, step S3 includes:
[0049] Step S31. The gateway sends an access request to the cloud, the cloud randomly generates a parameter seed, and the AI model randomly generates a signature function according to the parameter seed. The AI model includes: GAN, VAE, PPO and DQN generative models;
[0050] Step S32: Process the signature function so that the function decays over time:
[0051] ;
[0052] Among them, G(t) represents the signature function after processing, F represents the signature function before processing, and t represents the communication time;
[0053] Step S33. The cloud locates the destination subnet, and uses the IKE negotiation mechanism to exchange communication protocols between the source subnet and the destination subnet, so that the destination subnet obtains the signature function before processing, and attaches the signature function to the data packet and sends it to the destination subnet.
[0054] Further, step S4 includes:
[0055] Step S41. After receiving the signature function, the destination subnet obtains the signature function value and the sending and receiving time of the data packet, substitutes t and G(t) into the signature function F(t) before processing, and restores the value of each non-diagonal element;
[0056] Step S42. Retrieve all communication records with the source subnet in the destination subnet, digitize the communication records to obtain the value of each diagonal element, restore the verification matrix from the diagonal elements and non-diagonal elements, and use the verification matrix to decode the data packet.
[0057] Further, step S5 includes:
[0058] Step S51. Keep the diagonal elements of the verification matrix unchanged, randomly extract communication data from the intranet of the destination subnet as non-diagonal elements to reconstruct the verification matrix, process the response information through the verification matrix, obtain the first data packet, and obtain the signature function of the first data packet;
[0059] Step S52. Wait for the source subnet to send a data packet again, obtain a second data packet, obtain the signature function in the second data packet, compare the values of the signature function between the first data packet and the second data packet, and when the value ratio is lower than the fixed ratio, send the first data packet and decode the second data packet.
[0060] Compared with the prior art, the beneficial effects achieved by the present invention are:
[0061] The present invention can generate a verification matrix according to the historical communication behavior of the subnet, use the verification matrix to process plaintext data, exchange parameter seeds between subnets through the IKE negotiation mechanism, and the AI model generates a signature function according to the parameter seeds. It can quickly adapt to the state of frequent joining or leaving of devices in a dynamic environment, ensuring security while improving the communication speed of network communication.
[0062] The present invention can set the decay coefficient of the signature function with the off-diagonal element values of the verification matrix, so that the function decays with the response time. The terminal then restores the verification matrix according to the sending time and receiving time of the signature function, decodes the plaintext using the verification matrix, and replaces digital verification with a continuous function, thereby ensuring the security of data transmission, preventing malicious traffic, DDoS attacks, SQL injections and other attack methods from affecting gateway communications, effectively preventing replay attacks, supporting multi-factor authentication, and simplifying user experience.
[0063] The present invention can retain a data packet for a period, and when receiving the signature function again, wait for the fading coefficients of the two previous functions to meet a fixed ratio before decoding the previous data packet. Since the attacker cannot determine the plain text content, nor the exact time when the signal is transmitted to the terminal, the authenticity of the device identity and the stability of the communication are ensured, the security and flexibility of the security verification gateway are improved, and the network management cost is reduced. BRIEF DESCRIPTION OF THE DRAWINGS
[0064] The accompanying drawings are used to provide a further understanding of the present invention and constitute a part of the specification. Together with the embodiments of the present invention, they are used to explain the present invention and do not constitute a limitation of the present invention. In the accompanying drawings:
[0065] Figure 1 It is a structural schematic diagram of a security authentication gateway system based on AI analysis of the present invention;
[0066] Figure 2 It is a schematic diagram of the steps of a security authentication gateway method based on AI analysis of the present invention. DETAILED DESCRIPTION
[0067] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0068] See also Figure 1 ,The present invention provides a technical solution: a security authentication gateway system based on AI analysis, comprising: a log verification module, an AI analysis module, a solid-state hardware module, a quantization decoding module and a conditional latch module;
[0069] The log verification module is used to obtain the communication records between the source subnet and the destination subnet, use the time series characteristics of the communication records as the diagonal elements of the verification matrix, and randomly extract data from the intranet communication log of a fixed period and add it to the verification matrix until the elements composed of the extracted data and the diagonal elements meet the diagonal matrix conditions, output the generated verification matrix, process the data plaintext through the verification matrix, and update the matrix state once each time VPN communication is performed;
[0070] The log verification module includes: a record screening unit and a matrix updating unit;
[0071] The record screening unit is used to store the communication records between subnets and intranet devices, and retrieve the records with the IP address of the application service as the primary key;
[0072] The matrix updating unit is used to randomly extract the communication data between the information source subnet and the information sink subnet and the communication data between the intranet devices, and generate the verification matrix according to the communication data.
[0073] The AI analysis module is used to process the request information sent by the subnet IP to the routing gateway, transmit the request to the cloud, and the cloud verifies the compliance of the request. After locating the target IP subnet, the parameter seed is randomly generated according to the current clock and the IP of both parties, and the communication protocol and parameter seed are exchanged through the IKE negotiation mechanism. The AI model is used to generate a signature function in the gateways of both communicating parties based on the parameter seed, so that the value of the signature function decays with the communication time, and the non-diagonal element value of the verification matrix is used as the decay coefficient of the signature function;
[0074] The AI analysis module includes: a cloud channel unit, a public key negotiation unit and an AI signature unit;
[0075] The cloud channel unit is used to provide a communication link between the subnet and the cloud, and transmit the public key, replacement protocol and obtain AI computing power support in the cloud;
[0076] The public key negotiation unit is used to determine the address, network parameters and communication protocol of the source subnet and the destination subnet through IKE negotiation, and the communication protocol includes: SAML, OAuth, OpenID Connect and LDAP standard protocols;
[0077] The AI signature unit is used to randomly generate parameter seeds, generate a signature function using a generative AI model, and set a decay value of the signature function.
[0078] The solid-state hardware module is composed of an FPGA chip arranged in front of the terminal gateway and a router or proxy server that undertakes the routing resolution function, which is used to build a physical communication link of the security gateway, receive DNS address information from the cloud, direct the URL addresses of the two communicating parties, and provide data analysis, data latching and clock verification functions;
[0079] The solid-state hardware module includes: an FPGA unit and a solid-state routing unit;
[0080] The FPGA unit is used to be arranged in front of the terminal gateway as a signal receiver and electronic analyzer. The models of FPGA chips include: Spartan, Artix, Kintex, Virtex and Zynq;
[0081] The solid-state routing unit is used to provide a proxy forwarding service for communication requests and act as a general gateway in the link.
[0082] The quantization decoding module is used to confirm the sending and receiving time of the information, calculate the function fading coefficient according to the sending time and receiving time of the signature function, restore the verification matrix according to the communication log between the subnets and the non-diagonal element values corresponding to the fading coefficient, decode the data through the verification matrix, obtain the plaintext data packet, and store the response signal of the terminal subnet;
[0083] The quantization decoding module includes: a clock verification unit and a feature restoration unit;
[0084] The clock verification unit is used to analyze the sending time and the delivery time of the communication data, and determine the fading coefficient of the signature function according to the time difference;
[0085] The feature restoration unit is used to restore the fading coefficients to non-diagonal element values of the verification matrix, obtain the diagonal elements of the verification matrix from the communication log, and thus restore the verification matrix.
[0086] The conditional latch module is used to construct a verification matrix in the terminal subnet, use the verification matrix to process the response signal, obtain the first data packet, retain the first data packet for a period, and when data is received again, use the received data as the second data packet, wait for the value of the signature function of the first data packet and the value of the signature function of the second function to be lower than a fixed ratio, send the first data packet and decode the second data packet, thereby completing the information exchange process.
[0087] The conditional latch module includes: a gateway reconstruction unit, a trigger unit and a signal exchange unit;
[0088] The gateway reconstruction unit is used to generate a verification matrix of the destination gateway, and process the response message into a first data packet in a protocol peer-to-peer manner;
[0089] The trigger unit is used to trigger a clock reset instruction after the destination gateway receives the second data packet sent by the source gateway;
[0090] The signal exchange unit is used to wait for the decay of the signature function of the second data packet when the clock is reset, and when the values of the first and second data packets are lower than the fixed ratio, send the first data packet and perform a decoding operation on the second data packet.
[0091] like Figure 2 As shown, a security authentication gateway method based on AI analysis includes the following steps:
[0092] Step S1. Set up an FPGA chip in front of the gateway. After the gateway receives the access application from the source subnet, parse the URL access address in the application, locate the destination subnet according to the URL, obtain all communication records between the source subnet and the destination subnet, and extract the communication features in the communication records;
[0093] Step S1 includes:
[0094] Step S11. Setting an FPGA chip, wherein the input pin of the FPGA chip is connected to the gateway, and is used to assist the gateway in data processing. The models of the FPGA chip include: Spartan, Artix, Kintex, Virtex and Zynq;
[0095] Step S12. A server in the source subnet sends an access request to the gateway, locates the sink subnet by the URL address corresponding to the request, searches the communication log, obtains all communication records between the source subnet and the sink subnet, and if no communication record exists, presets the initial communication record between the source subnet and the sink subnet through IKE negotiation;
[0096] Step S13. Extract communication features from the communication records, the communication features including: communication duration, data packet capacity, DNS and ping value, and digitize the communication features according to a unified standard and store them in a database.
[0097] Step S2. Construct a verification matrix, use the communication features as the diagonal elements of the matrix, and randomly extract the intranet communication data of the source subnet and add it to the verification matrix, so that the verification matrix meets the diagonal matrix condition, and use the verification matrix to process the communication data;
[0098] Step S2 includes:
[0099] Step S21. Use the communication features obtained in step S13 as diagonal elements to construct a diagonal matrix E1:
[0100] ;
[0101] Wherein, n represents the number of communication features, and R1 to Rn represent the 1st to nth communication feature values, respectively;
[0102] Step S22. Randomly extract communication data from the intranet of the source subnet and add it to the diagonal matrix E1, so that E1 satisfies the diagonal matrix condition. The diagonal matrix condition is: the number of added elements reaches n-1, the matrix is a full rank matrix, and Y i ≠Ri is always established, where Y i represents the i-th off-diagonal element, Ri represents the i-th diagonal element, i∈{1, 2,…, n};
[0103] Step S23. After the communication data is extracted, the verification matrix ER is obtained:
[0104] ;
[0105] Among them, Y1, Y n-1 and Y n-2 Represent the 1st, n-1th and n-2th off-diagonal elements respectively;
[0106] Use the verification matrix to process the plaintext information and obtain the encrypted data packet.
[0107] Step S3. The cloud verifies the compliance of the request and randomly generates a parameter seed. The generative AI model generates a signature function based on the parameter seed, processes the signature function, and makes the signature function decay over the communication time. The non-diagonal element value of the verification matrix is used as the decay coefficient of the signature function. The communication protocol is exchanged between the source subnet and the destination subnet through the IKE negotiation mechanism.
[0108] Step S3 includes:
[0109] Step S31. The gateway sends an access request to the cloud, the cloud randomly generates a parameter seed, and the AI model randomly generates a signature function according to the parameter seed. The AI model includes: GAN, VAE, PPO and DQN generative models;
[0110] Step S32: Process the signature function so that the function decays over time:
[0111] ;
[0112] Among them, G(t) represents the signature function after processing, F represents the signature function before processing, and t represents the communication time;
[0113] Step S33. The cloud locates the destination subnet, and uses the IKE negotiation mechanism to exchange communication protocols between the source subnet and the destination subnet, so that the destination subnet obtains the signature function before processing, and attaches the signature function to the data packet and sends it to the destination subnet.
[0114] Step S4. The destination subnet receives the data packet, calculates the fading coefficient according to the current value of the signature function, the sending time and the receiving time of the data packet, and restores it to the off-diagonal element value of the verification matrix. The verification matrix is restored from the communication records between the subnets and the off-diagonal element values of the verification matrix, and the data packet is decoded;
[0115] Step S4 includes:
[0116] Step S41. After receiving the signature function, the destination subnet obtains the signature function value and the sending and receiving time of the data packet, substitutes t and G(t) into the signature function F(t) before processing, and restores the value of each non-diagonal element;
[0117] Step S42. Retrieve all communication records with the source subnet in the destination subnet, digitize the communication records to obtain the value of each diagonal element, restore the verification matrix from the diagonal elements and non-diagonal elements, and use the verification matrix to decode the data packet.
[0118] Step S5. The destination subnet replaces the non-diagonal elements in the verification matrix, reconstructs the verification matrix, latches the first data packet sent to the source subnet, and waits for the value of the signature function of the first data packet to meet the value of the signature function of the second function to be lower than the ratio, then sends the first data packet and decodes the second data packet to complete the information exchange.
[0119] Step S5 includes:
[0120] Step S51. Keep the diagonal elements of the verification matrix unchanged, randomly extract communication data from the intranet of the destination subnet as non-diagonal elements to reconstruct the verification matrix, process the response information through the verification matrix, obtain the first data packet, and obtain the signature function of the first data packet;
[0121] Step S52. Wait for the source subnet to send a data packet again, obtain a second data packet, obtain the signature function in the second data packet, compare the values of the signature function between the first data packet and the second data packet, and when the value ratio is lower than the fixed ratio, send the first data packet and decode the second data packet.
[0122] Embodiment: The source subnet needs to send information
[10110] to the sink subnet. There are 3 communication records between the subnets, and the communication characteristics are 2, 3 and 4 respectively. The communication characteristics of 2 intranet communication records are extracted from the source subnet, which are 1 and 6 respectively. After generating the verification matrix, the information is processed using the verification matrix to group the information, and the insufficient part is filled with 0. After processing, a signature function with fading coefficients of 1 and 6 respectively is generated. According to the signature function, the verification matrix is restored in the sink subnet, and the data packet is decoded.
[0123] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device.
[0124] Finally, it should be noted that the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art can still modify the technical solutions described in the aforementioned embodiments or replace some of the technical features therein by equivalents. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present invention shall be included in the protection scope of the present invention.
Claims
1. A security authentication gateway method based on AI analysis, characterized in that: The method comprises the following steps: Step S1. Set up an FPGA chip in front of the gateway. After the gateway receives the access application from the source subnet, parse the URL access address in the application, locate the destination subnet according to the URL, obtain all communication records between the source subnet and the destination subnet, and extract the communication features in the communication records; Step S2. Construct a verification matrix, use the communication features as the diagonal elements of the matrix, and randomly extract the intranet communication data of the source subnet and add it to the verification matrix, so that the verification matrix meets the diagonal matrix condition, and use the verification matrix to process the communication data; Step S3. The cloud verifies the compliance of the request and randomly generates a parameter seed. The generative AI model generates a signature function based on the parameter seed, processes the signature function, and makes the signature function decay over the communication time. The non-diagonal element value of the verification matrix is used as the decay coefficient of the signature function. The communication protocol is exchanged between the source subnet and the destination subnet through the IKE negotiation mechanism. Step S4. The destination subnet receives the data packet, calculates the fading coefficient according to the current value of the signature function, the sending time and the receiving time of the data packet, and restores it to the off-diagonal element value of the verification matrix. The verification matrix is restored from the communication records between the subnets and the off-diagonal element values of the verification matrix, and the data packet is decoded; Step S5. The destination subnet replaces the non-diagonal elements in the verification matrix, reconstructs the verification matrix, latches the first data packet sent to the source subnet, and waits for the value of the signature function of the first data packet to meet the value of the signature function of the second function to be lower than the ratio, then sends the first data packet and decodes the second data packet to complete the information exchange.
2. According to claim 1, a security authentication gateway method based on AI analysis is characterized in that: Step S1 includes: Step S11. Setting an FPGA chip, wherein the input pin of the FPGA chip is connected to the gateway, and is used to assist the gateway in data processing. The models of the FPGA chip include: Spartan, Artix, Kintex, Virtex and Zynq; Step S12. A server in the source subnet sends an access request to the gateway, locates the sink subnet by the URL address corresponding to the request, searches the communication log, obtains all communication records between the source subnet and the sink subnet, and if no communication record exists, presets the initial communication record between the source subnet and the sink subnet through IKE negotiation; Step S13. Extract communication features from the communication records, the communication features including: communication duration, data packet capacity, DNS and ping value, and digitize the communication features according to a unified standard and store them in a database.
3. A security authentication gateway system based on AI analysis, characterized in that: The system includes the following modules: a log verification module, an AI analysis module, a solid-state hardware module, a quantization decoding module, and a conditional latch module; The log verification module is used to obtain the communication records between the source subnet and the destination subnet, use the time series characteristics of the communication records as the diagonal elements of the verification matrix, and randomly extract data from the intranet communication log of a fixed period and add it to the verification matrix until the elements composed of the extracted data and the diagonal elements meet the diagonal matrix conditions, output the generated verification matrix, process the data plaintext through the verification matrix, and update the matrix state once each time VPN communication is performed; The AI analysis module is used to process the request information sent by the subnet IP to the routing gateway, transmit the request to the cloud, and the cloud verifies the compliance of the request. After locating the target IP subnet, the parameter seed is randomly generated according to the current clock and the IP of both parties, and the communication protocol and parameter seed are exchanged through the IKE negotiation mechanism. The AI model is used to generate a signature function based on the parameter seed in the gateways of both communicating parties, so that the value of the signature function decays with the communication time, and the non-diagonal element value of the verification matrix is used as the decay coefficient of the signature function; The solid-state hardware module is composed of an FPGA chip arranged in front of the terminal gateway and a router or proxy server that undertakes the routing resolution function, which is used to build a physical communication link of the security gateway, receive DNS address information from the cloud, direct the URL addresses of the two communicating parties, and provide data analysis, data latching and clock verification functions; The quantization decoding module is used to confirm the sending and receiving time of the information, calculate the function fading coefficient according to the sending time and receiving time of the signature function, restore the verification matrix according to the communication log between the subnets and the non-diagonal element values corresponding to the fading coefficient, decode the data through the verification matrix, obtain the plaintext data packet, and store the response signal of the terminal subnet; The conditional latch module is used to construct a verification matrix in the terminal subnet, use the verification matrix to process the response signal, obtain the first data packet, retain the first data packet for a period, and when data is received again, use the received data as the second data packet, wait for the value of the signature function of the first data packet and the value of the signature function of the second function to be lower than a fixed ratio, send the first data packet and decode the second data packet, thereby completing the information exchange process.
4. According to claim 3, a security authentication gateway system based on AI analysis is characterized in that: The log verification module includes: a record screening unit and a matrix updating unit; The record screening unit is used to store the communication records between subnets and intranet devices, and retrieve the records with the IP address of the application service as the primary key; The matrix updating unit is used to randomly extract the communication data between the information source subnet and the information sink subnet and the communication data between the intranet devices, and generate the verification matrix according to the communication data.
5. According to claim 4, a security authentication gateway system based on AI analysis is characterized in that: The AI analysis module includes: a cloud channel unit, a public key negotiation unit and an AI signature unit; The cloud channel unit is used to provide a communication link between the subnet and the cloud, and transmit the public key, replacement protocol and obtain AI computing power support in the cloud; The public key negotiation unit is used to determine the address, network parameters and communication protocol of the source subnet and the destination subnet through IKE negotiation, and the communication protocol includes: SAML, OAuth, OpenID Connect and LDAP standard protocols; The AI signature unit is used to randomly generate parameter seeds, generate a signature function using a generative AI model, and set a decay value of the signature function.
6. The security authentication gateway system based on AI analysis according to claim 5 is characterized in that: The solid-state hardware module includes: an FPGA unit and a solid-state routing unit; The FPGA unit is used to be arranged in front of the terminal gateway as a signal receiver and electronic analyzer. The models of FPGA chips include: Spartan, Artix, Kintex, Virtex and Zynq; The solid-state routing unit is used to provide a proxy forwarding service for communication requests and act as a general gateway in the link; The quantization decoding module includes: a clock verification unit and a feature restoration unit; The clock verification unit is used to analyze the sending time and the delivery time of the communication data, and determine the fading coefficient of the signature function according to the time difference; The feature restoration unit is used to restore the fading coefficients to non-diagonal element values of the verification matrix, obtain the diagonal elements of the verification matrix from the communication log, and thus restore the verification matrix.
7. The security authentication gateway system based on AI analysis according to claim 6 is characterized in that: The conditional latch module includes: a gateway reconstruction unit, a trigger unit and a signal exchange unit; The gateway reconstruction unit is used to generate a verification matrix of the destination gateway, and process the response message into a first data packet in a protocol peer-to-peer manner; The trigger unit is used to trigger a clock reset instruction after the destination gateway receives the second data packet sent by the source gateway; The signal exchange unit is used to wait for the decay of the signature function of the second data packet when the clock is reset, and when the values of the first and second data packets are lower than the fixed ratio, send the first data packet and perform a decoding operation on the second data packet.
Citation Information
Patent Citations
All-purpose attack resistant security network encoding method based on homomorphic linear subspaces signature
CN107154855A
Model-based predictive interference management
CN115699962A