Edge node heterogeneous network heterogeneous platform access management method and system

Through the combination of three-dimensional chaotic dynamic symbol mapping and identification neural network, the sandbox strategy is dynamically adjusted, and problems such as insufficient dynamic resource adjustment and high state synchronization delay between heterogeneous nodes in the access management of heterogeneous networks and heterogeneous platforms are solved, thereby achieving efficient security control and resource management.

CN120090889AActive Publication Date: 2025-06-03CHINA TOWER CO LTD

Patent Information

Application Number
CN202510586309.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-08
Publication Date
2025-06-03
Estimated Expiration
2045-05-08

AI Technical Summary

Technical Problem

The existing access management methods for heterogeneous networks of edge nodes have problems such as insufficient dynamic resource adjustment, high state synchronization delay between heterogeneous nodes, risk of side channel leakage, insufficient fusion of multi-source features, and high misplacement rate due to static confidence thresholds.

Method used

Encrypted access requests through three-dimensional chaotic dynamic symbol mapping, the monitoring platform reversely decodes to generate threat indexes, dynamically adjusts sandbox strategies, and uses identification neural networks to process multimodal data for refined access control.

Benefits of technology

It significantly improves data security and resource utilization, reduces false alarm rates and missed alarm rates, enhances its resistance to unknown attacks, and forms a closed-loop defense system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120090889A_ABST
    Figure CN120090889A_ABST
Patent Text Reader

Abstract

The invention discloses an edge node heterogeneous network heterogeneous platform access management method and system, and relates to the technical field of Internet of Things. The method comprises the following steps: a monitoring platform performs reverse decoding on each piece of received access request sequence information mapped by a three-dimensional chaotic dynamic symbol so as to obtain decoded access request sequence information; generating a threat index corresponding to the edge node according to the access request sequence information; generating a sandbox adjustment strategy of the edge node according to the threat index; carrying out different treatments on the edge nodes according to a sandbox adjustment strategy; inputting the feature information of the edge nodes into the identification neural network to obtain identification information; and the monitoring platform judges whether the edge node in the preset sandbox is allowed to access according to the identification information, and if yes, the edge node is accessed. According to the method, the access request is encrypted and transmitted through three-dimensional chaotic dynamic symbol mapping, the data security is remarkably improved, and fine access control is realized in cooperation with a dynamic sandbox strategy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the technical field of the Internet of Things, and particularly relates to a method for accessing and managing an edge node heterogeneous network and heterogeneous platform, and a system for accessing and managing an edge node heterogeneous network and heterogeneous platform. Background Art

[0002] Currently, the access management of edge node heterogeneous networks and heterogeneous platforms mainly adopts a static rule-driven and basic feature matching mode, and its core processes include: Access authentication: relying on certificate digest comparison or simple IP / DNS load balancing, lacking dynamic verification of heterogeneous attributes such as hardware and operating systems.

[0003] Resource scheduling: allocating computing resources through preset thresholds, without considering the hardware diversity of edge nodes (such as differences in ARM / x86 architectures) and real-time load changes.

[0004] Security isolation: using a fixed sandbox policy (such as unified containerization), without dynamically adjusting the isolation intensity according to the threat level, and lacking the ability to analyze side-channel behaviors.

[0005] Decision-making mechanism: making access judgments based on a single network traffic feature or coarse-grained behavior logs, with a high false alarm rate and a high miss rate.

[0006] The prior art has the following disadvantages: (1) Traditional methods rely on manually preset sandbox policies (such as fixed bandwidth limits), and cannot dynamically adjust resource allocation according to the real-time load of nodes (such as memory entropy values, process behavior hashes), resulting in low-priority tasks occupying high-security-level resources.

[0007] (2) There is a lack of a unified resource description protocol between heterogeneous nodes (such as mixed use of frameworks such as KubeEdge and SuperEdge), resulting in a high delay in state synchronization during edge-cloud collaboration, and it is difficult to meet the requirements of low-latency scenarios such as vehicle-to-everything (V2X).

[0008] (3) No hierarchical isolation strategy is designed for the hardware characteristics of edge nodes (such as DMA / IOMMU pass-through restrictions), resulting in a risk of side-channel leakage during the deployment of physical isolation cabins.

[0009] (4) Only relying on certificate digest or IP address verification, without integrating multi-source heterogeneous features such as hardware fingerprints (such as CPU microarchitecture hashes) and operating system entropy values, it is easy to be bypassed by forged requests.

[0010] (5) The adjustment of traditional sandbox policies depends on a preset rule library (such as fixed thresholds of 0.15 / 0.3 / 0.5), and cannot respond in real time to new types of attacks (such as covert channel attacks based on chaotic maps).

[0011] (6) The memory access patterns of processes in the unmonitored sandbox and side-channel information such as the atomicity of I / O operations are not monitored, resulting in a low detection rate for container escape attacks.

[0012] (7) Only analyzing network manifold features (such as the time-series spectrum of data packets) and ignoring hardware layer features (such as process behavior hashes) and operating system layer features (such as entropy value changes), the accuracy of threat assessment is less than 78%.

[0013] (8) Using a fixed confidence threshold (such as 0.5) to judge access legality and not introducing a dynamic confidence weighting mechanism, resulting in a relatively high false acceptance rate in high-threat scenarios. Summary of the Invention

[0014] The purpose of the present invention is to provide an access management method for an edge node heterogeneous network platform to at least solve the above-mentioned technical problems.

[0015] In one aspect of the present invention, an access management method for an edge node heterogeneous network platform is provided. The access management method for the edge node heterogeneous network platform includes: Each edge node sends access request sequence information after three-dimensional chaotic dynamic symbol mapping to the monitoring platform; The monitoring platform performs reverse decoding on each received access request sequence information after three-dimensional chaotic dynamic symbol mapping to obtain the decoded access request sequence information; The monitoring platform generates a threat index corresponding to each edge node according to each decoded access request sequence information; The monitoring platform generates a sandbox adjustment strategy for the edge node according to the threat index corresponding to the edge node and a preset dynamic sandbox strategy; The monitoring platform performs different dispositions on each edge node according to the sandbox adjustment strategy of the edge node. The different dispositions include putting the edge node into different preset sandboxes or directly accessing without putting it into a preset sandbox; The monitoring platform obtains a trained discrimination neural network; The monitoring platform inputs the access request sequence information corresponding to each edge node placed in a different preset sandbox, the feature space mapping information generated based on the access request sequence information, and the side-channel information generated in the preset sandbox into the discrimination neural network respectively to obtain the discrimination information corresponding to each edge node; The monitoring platform determines whether to allow the edge node in the preset sandbox to access according to the discrimination information. If so, the edge node is accessed.

[0016] Optionally, the access request sequence information includes a hardware fingerprint, an operating system entropy value, and a network manifold feature; The access request sequence information is subjected to three-dimensional chaotic dynamic symbol mapping through the following method: Convert the access request sequence information into a binary string through UTF-8 encoding; Generate an initial confusion layer based on the binary string; Divide the binary string in the initial confusion layer into groups of 3 bits each and map them to a custom symbol set to generate a triple sequence; Adjust the arrangement order of the triple sequence through chaotic mapping to maximize the product of the Hamming distance and the edit distance between adjacent triples in the triple sequence, thereby forming the access request sequence information after three-dimensional chaotic dynamic symbol mapping.

[0017] Optionally, the monitoring platform generates a threat index corresponding to each edge node based on each decoded access request sequence information, including: Perform the following processing on each edge node: The monitoring platform generates feature space mapping information based on the decoded access request sequence information; The monitoring platform obtains a threat index based on the feature space mapping information; The monitoring platform generates feature space mapping information based on the decoded access request sequence information, including: Map the access request sequence information to a dynamic dimensional space through the following formula to obtain a three-dimensional feature space mapping: ; where X is the access request sequence matrix; K is the number of mapping dimensions; W k is the weight matrix of the k-th mapping dimension; A k is the k-th non-linear coupling factor matrix, and the element values are generated by a chaotic sequence; P k is the k-th state transition probability matrix; ⊙ represents the Hadamard product.

[0018] Optionally, the monitoring platform obtains a threat index based on the feature space mapping information, including: Obtain a feature interaction vector flow and an edit distance matrix based on the feature space mapping information; Obtain a spatio-temporal threat potential function model; Input the feature interaction vector flow and the edit distance matrix into the spatio-temporal threat potential function model to obtain a primary threat index; Obtain a feature matrix based on the access request sequence information; Perform a hypersphere collapse transformation based on the feature matrix to obtain a transformed feature matrix; Obtain a transformed feature interaction vector flow based on the transformed feature matrix; Obtain a final threat index based on the transformed feature interaction vector flow and the edit distance matrix.

[0019] Optionally, the monitoring platform generating a sandbox adjustment policy for the edge node according to the threat index corresponding to the edge node and a preset dynamic sandbox policy includes: Obtain a preset threat level classification database, where the threat level classification database includes at least one threat index interval and the corresponding sandbox adjustment policy for each threat index interval; Obtain the sandbox adjustment policy corresponding to the threat index interval where the currently calculated final threat index is located.

[0020] Optionally, the authentication neural network includes: A multimodal heterogeneous input layer, which is used to receive the access request sequence information, feature space mapping information, and side-channel information, and generate a request sequence feature according to the access request sequence information, generate a dynamic topology structure feature map according to the feature space mapping information, and generate a side-channel feature according to the side-channel information; A feature fusion layer, which is used to fuse the request sequence feature, the dynamic topology structure feature map, and the side-channel feature to form a fusion feature; A chaotic hidden layer, which is used to generate a chaotic enhanced feature through an improved ternary chaotic mapping activation function; An output layer, which outputs a three-dimensional confidence vector according to the chaotic enhanced feature.

[0021] Optionally, the generating a request sequence feature according to the access request sequence information includes: Generate a request sequence matrix according to the access request sequence information, where the request sequence matrix includes time window information, feature type information, and chaotic mapping dimension information; Process the request sequence matrix through a three-dimensional chaotic attention mechanism to generate a request sequence feature; The generating a dynamic topology structure feature map according to the feature space mapping information includes: Convert the three-dimensional feature space mapping information into a dynamic topology structure to obtain a topology adjacency matrix; Process the topology adjacency matrix through a graph convolution operation to generate a dynamic topology structure feature map.

[0022] Optionally, the fusing the request sequence feature, the dynamic topology structure feature map, and the side-channel feature to form a fusion feature includes: Perform normalization processing on the request sequence feature, the dynamic topology structure feature map, and the side-channel feature fusion respectively to obtain a normalized request sequence feature, a normalized dynamic topology structure feature map, and a normalized side-channel feature fusion to form a fusion feature; Calculate the request sequence feature significant identifier of the normalized request sequence features, the dynamic topology structure feature significant identifier of the normalized dynamic topology structure feature map, and the side-channel feature significant identifier of the normalized side-channel features respectively; Generate a basic weight according to the request sequence feature significant identifier, the dynamic topology structure feature significant identifier, and the side-channel feature significant identifier; Generate a threat deviation adjustment factor according to the threat index; Generate a dynamic weight according to the threat deviation adjustment factor and the basic weight; Generate a final fusion feature by fusing the dynamic weight and the normalized request sequence features, the normalized dynamic topology structure feature map, and the normalized side-channel features to form a fusion feature.

[0023] Optionally, the formula of the total loss function of the discrimination neural network is as follows: ; Wherein, β is the weight coefficient of the conditional mutual information loss, γ is the weight coefficient of the Lyapunov interval constraint loss, is the Lyapunov exponent interval constraint loss function, is the conditional mutual information maximization loss function, is the dynamic confidence weighted cross-entropy loss function, is the total loss function; The dynamic confidence weighted cross-entropy loss function adopts the following formula: ; Wherein, C is the total number of classification categories, is the c-th dimension of the one-hot vector of the true label, is the probability value of the c-th class predicted by the model, is the confidence function, α is the confidence weighting coefficient, is the dynamic confidence weighted cross-entropy loss function; The conditional mutual information maximization loss function adopts the following formula: ; Wherein, is the discretized set of threat indices, is the probability distribution of the threat index, is the joint probability distribution of the feature space and the side-channel information under the threat index θ, is the marginal probability distribution of the feature space under the threat index θ, is the marginal probability distribution of the side-channel information under the threat index θ, is the conditional mutual information maximization loss function; The Lyapunov exponent interval constraint loss function adopts the following formula: ; where is the measured value of the maximum Lyapunov exponent of the current chaotic system, is the upper boundary threshold of the Lyapunov exponent, is the lower boundary threshold of the Lyapunov exponent, is the Lyapunov exponent interval constraint loss function.

[0024] This application also provides an edge node heterogeneous network access management system. The edge node heterogeneous network access management system includes at least one edge node and a monitoring platform. Each of the edge nodes and the monitoring platform cooperate to implement the edge node heterogeneous network access management method as described above.

[0025] The edge node heterogeneous network access management method of this application encrypts and transmits access requests through three-dimensional chaotic dynamic symbol mapping, significantly improving data security. The monitoring platform uses reverse decoding to restore request information and cooperates with dynamic sandbox strategies to achieve refined access control (such as container isolation / hardware partitioning), which not only ensures the heterogeneous compatibility of edge nodes but also effectively resists unknown attacks through a multi-level threat response mechanism, forming a closed-loop defense system of "encrypted transmission - dynamic decoding - hierarchical control". BRIEF DESCRIPTION OF THE DRAWINGS

[0026] Figure 1 is a schematic flowchart of the edge node heterogeneous network access management method according to an embodiment of this application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0027] To make the purpose, technical solutions, and advantages of the implementation of this application clearer, the technical solutions in the embodiments of this application will be described in more detail below with reference to the drawings in the embodiments of this application. In the drawings, the same or similar reference numerals represent the same or similar elements or elements with the same or similar functions from beginning to end. The described embodiments are some but not all of the embodiments of this application. The embodiments described below with reference to the drawings are exemplary and are intended to explain this application and should not be construed as a limitation of this application. Based on the embodiments in this application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of this application. The embodiments of this application will be described in detail below with reference to the drawings.

[0028] As Figure 1 shown, the edge node heterogeneous network access management method includes: Step 1: Each edge node sends the access request sequence information after three-dimensional chaotic dynamic symbol mapping to the monitoring platform; Step 2: The monitoring platform performs reverse decoding on each received access request sequence information after three-dimensional chaotic dynamic symbol mapping to obtain the decoded access request sequence information; Step 3: The monitoring platform generates a threat index corresponding to each edge node according to each decoded access request sequence information; Step 4: The monitoring platform generates a sandbox adjustment strategy for the edge node according to the threat index corresponding to the edge node and a preset dynamic sandbox strategy; Step 5: The monitoring platform performs different disposals on each edge node according to the sandbox adjustment strategy of the edge node. The different disposals include putting the edge node into different preset sandboxes or directly accessing without putting it into a preset sandbox; Step 6: The monitoring platform obtains a trained discrimination neural network; Step 7: The monitoring platform inputs the access request sequence information corresponding to each edge node placed in a different preset sandbox, the feature space mapping information generated based on the access request sequence information, and the side-channel information generated in the preset sandbox into the discrimination neural network respectively to obtain the discrimination information corresponding to each edge node; Step 8: The monitoring platform determines whether to allow the edge node in the preset sandbox to access according to the discrimination information. If so, the edge node is accessed.

[0029] The access management method for the heterogeneous network and heterogeneous platform of edge nodes in this application encrypts and transmits access requests through three-dimensional chaotic dynamic symbol mapping, significantly improving data security. The monitoring platform uses reverse decoding to restore request information and cooperates with the dynamic sandbox strategy to achieve fine-grained access control (such as container isolation / hardware partitioning). It not only ensures the heterogeneous compatibility of edge nodes but also effectively resists unknown attacks through a multi-level threat response mechanism, forming a closed-loop defense system of "encrypted transmission - dynamic decoding - hierarchical control".

[0030] In this embodiment, the access request sequence information includes a hardware fingerprint (such as a CPU microarchitecture hash value), an operating system entropy value (generated by hashing the process behavior sequence), and a network manifold feature (a data packet time series spectrum matrix).

[0031] In this embodiment, the three-dimensional chaotic dynamic symbol mapping of the access request sequence information is performed by the following method: Convert the original access request sequence information into a binary string through UTF-8 encoding; Generate an initial confusion layer according to the binary string. The initial confusion layer is generated by the following formula: M 置换 =Hash(EID ⊕ T )mod N; Among them, N is the preset permutation space dimension, and ⊕ represents the exclusive OR operation. This matrix dynamically rearranges every 8 bits of the binary string to form an initial confusion layer; The binary string in the initial confusion layer is segmented by every 3 bits and mapped to a custom symbol set (such as symbols like ∆, □, ○, ◇, ★), thereby generating a triple sequence. For example, the binary "101" is mapped to "∆"; The order of the triple sequence is adjusted through chaotic mapping to maximize the product of the Hamming distance and the edit distance between adjacent triples in the triple sequence, thereby forming the access request sequence information after three-dimensional chaotic dynamic symbol mapping.

[0032] In this embodiment, the chaotic mapping is performed through the following formula: ; Among them, μ = 3.99, α = 0.05, and β = the EID modulo 128 value.

[0033] An unpredictable permutation rule is generated through the EID and the timestamp, so that the same original data produces completely different coding results under different space-time conditions.

[0034] The access request sequence information after three-dimensional chaotic dynamic symbol mapping generated by the above method has the discreteness of the symbol space on the one hand and the chaotic characteristics of the arrangement order on the other hand, thereby constituting a multi-layer defense mechanism.

[0035] In this embodiment, the monitoring platform generates a threat index corresponding to each edge node according to each decoded access request sequence information, including: The following processing is performed on each edge node: The following operations are performed on each decoded access request sequence information: The monitoring platform maps according to the access request sequence information feature space mapping information; The monitoring platform obtains the threat index according to the feature space mapping information.

[0036] In this embodiment, generating the feature space mapping information according to the access request sequence information includes: The decoded access request sequence information is mapped to a dynamic dimension space through the following formula to obtain a three-dimensional feature space mapping: ; Among them, X is the access request sequence matrix, K is the number of mapping dimensions, W k is the weight matrix of the kth mapping dimension, A kis the k-th non-linear coupling factor matrix, and the element values are generated by a chaotic sequence, P k is the k-th state transition probability matrix, and ⊙ represents the Hadamard product (element-wise product).

[0037] For the sake of description, the three-dimensional feature space mapping of this application will be elaborated in detail by way of example below. It can be understood that this example does not constitute any limitation to this application.

[0038] Obtain the access request sequence matrix X (already standardized): ; (3 time windows × 3 feature dimensions); The mapping dimension number K = 3; Initialize parameters: The chaotic system is calculated using the above formula: ; The initial coupling factor matrix A k (the first 3 values are generated by the chaotic sequence): ; The state transition probability matrix P k (based on historical data statistics): First dimension mapping calculation:

[0039] Second and third dimension mapping calculations (the process is similar, and the results are directly given here): ; ; Final feature space mapping (vector splicing): .

[0040] In this embodiment, the initial coupling factor matrix A can be obtained in the following manner k : The chaotic sequence is generated by iterating the Logistic map N k times ( N k is the total number of matrix elements. For example, for a 3×3 matrix, N k = 9), generating the sequence ; After linearly mapping to the interval [0,1] through the arctangent function, the non-linear characteristics are enhanced through the arctangent function (as shown in the following formula): ; This transformation makes At = 0.5, it takes 0 and non-linearly grows to ±1.99 on both sides.

[0041] Fill sequentially into the A k matrix. For example, the filling order of a 3×3 matrix is as follows: , thereby obtaining the initial coupling factor matrix.

[0042] In this embodiment, obtaining the threat index from the feature space mapping information includes: Obtaining the feature interaction vector flow and the edit distance matrix according to the feature space mapping information; Obtaining the spatio-temporal threat potential function model; Inputting the feature interaction vector flow and the edit distance matrix into the spatio-temporal threat potential function model, thereby obtaining the primary threat index; In this embodiment, the spatio-temporal threat potential function model adopts the following formula: ; where J A is the feature interaction vector flow of feature A, J B is the feature interaction vector flow of feature B. In this implementation, the feature interaction vector flow represents the movement direction of the feature cluster in the feature space; Lev(A,B) is the edit distance matrix, representing the structural quantization difference between feature clusters; is the environment adaptation coefficient, dynamically adjusted according to the real-time network traffic (value range 0.1 - 1.0); is the threat potential energy integral of any region in the feature space.

[0043] In this embodiment, the feature interaction vector flow of feature A is obtained through the following formula: ; where is the number of samples included in feature cluster A; is the gradient direction vector of the i-th sample in feature cluster A.

[0044] In this embodiment, the edit distance matrix is obtained through the following formula: ; where (neighborhood judgment); is the Euclidean distance of the sample pair ( , ); is the neighborhood radius threshold.

[0045] Obtain a feature matrix according to the access request sequence information. Specifically, extract quantization metrics from the access request sequence information through feature engineering, and arrange the above quantization metrics according to time windows to form the initial form of the feature matrix. ; Perform a hypersphere collapse transformation according to the feature matrix so as to obtain the transformed feature matrix ; Obtain the transformed feature interaction vector flow according to the transformed feature matrix ; Obtain the final threat index according to the transformed feature interaction vector flow.

[0046] This application reveals the movement trajectory of feature clusters through the feature interaction vector flow, can detect the slow lateral movement of APT attacks, and solves the problem that the traditional Euclidean distance fails in high-dimensional spaces through dynamic adjustment of the ε-neighborhood radius. In addition, while retaining the topological structure through the collapse transformation, the dimension is reduced, and the computing efficiency is improved by 15% compared with PCA.

[0047] In this embodiment, the space mapping controlled by the Hurst index automatically optimizes the feature resolution in the 5G network (H≈0.8) and Internet of Things (H≈0.6) environments, can adjust the mapping dimension in real time, and magnifies and displays high-threat features in the projection space, improving the detection sensitivity.

[0048] In this embodiment, generating a sandbox adjustment strategy according to the threat index and a preset dynamic sandbox strategy includes: Obtain a preset threat level classification database, where the threat level classification database includes at least one threat index interval and the sandbox adjustment strategy corresponding to each threat index interval; Obtain the sandbox adjustment strategy corresponding to the threat index interval where the currently calculated final threat index is located.

[0049] In this embodiment, the threat index intervals include: the threat index is less than 0.15, and the sandbox adjustment strategy corresponding to this threat index interval is: directly access without putting it into the sandbox; The threat index is greater than 0.15 and less than 0.3, and the sandbox adjustment strategy corresponding to this threat index interval is: set containerized isolation, deploy a behavior whitelist, implement network traffic coloring marking, and automatically generate a runtime checksum every preset time; The threat index is greater than 0.3 and less than 0.5, and the sandbox adjustment strategy corresponding to this threat index interval is: set a hybrid sandbox (container + lightweight virtual machine), full-system call tracing (frequency 100Hz), real-time monitoring of the memory entropy value (threshold 85%), and file I / O sandbox redirection (all write operations are atomized); The threat index is greater than 0.5 and less than 0.85. The sandbox adjustment strategy corresponding to this threat index range is as follows: Set up a hardware-assisted virtualization sandbox, enable Intel VT-x nested virtualization, configure SR-IOV passthrough but limit the bandwidth to 1 Gbps, and implement real-time monitoring of memory page tables. The threat index is greater than 0.85. The sandbox adjustment strategy corresponding to this threat index range is as follows: Set up a physical isolation pod (independent hardware partition) and disable DMA / IOMMU passthrough.

[0050] In this embodiment, a five-level threat classification model is used to reduce the false positive rate by 40% (experimental data), and a combined solution of container + lightweight virtual machine with hybrid sandbox collaboration is adopted to maintain a 92% performance loss ratio while ensuring the isolation strength.

[0051] In this embodiment, the authentication neural network includes a multi-modal heterogeneous input layer, a feature fusion layer, a chaotic hidden layer, and an output layer. Among them, The multi-modal heterogeneous input layer is used to receive the access request sequence information, feature space mapping information, and side-channel information, generate request sequence features according to the access request sequence information, generate a dynamic topology structure feature map according to the feature space mapping information, and generate side-channel features according to the side-channel information. The feature fusion layer is used to fuse the request sequence features, the dynamic topology structure feature map, and the side-channel features to form fused features. The chaotic hidden layer is used to activate the function through an improved ternary chaotic mapping. The output layer is used to adopt a dynamic confidence threshold mechanism to output a three-dimensional confidence vector (allow access probability, sandbox isolation probability, reject probability).

[0052] In this embodiment, generating request sequence features according to the access request sequence information includes: Process the access request sequence information to generate a request sequence matrix, which includes time window information, feature type information, and chaotic mapping dimension information. Process the request sequence matrix through a three-dimensional chaotic attention mechanism to generate request sequence features. In this embodiment, processing the request sequence matrix through a three-dimensional chaotic attention mechanism to generate request sequence features adopts the following method: Receive the three-dimensional tensor input of the original access request sequence and form a request sequence matrix, where the dimension of the request sequence matrix is [time window × feature type × chaotic mapping dimension]. Time window: Dynamically adjustable, with an initial value of 128 (automatically expandable to 512 according to real-time traffic). Feature types: including hardware fingerprint features (32 - dimensional), operating system entropy value features (16 - dimensional), and network manifold features (64 - dimensional). Chaotic mapping dimension: Dynamically generated by the value of EID modulo 128, fluctuating within the range of 32 - 128 dimensions; An improved three - dimensional chaotic attention mechanism is adopted: Calculate the chaotic energy spectrum for each time window: ; Generate an attention weight matrix: ; where μ is the chaotic control parameter and H is the Hurst exponent matrix; Generate the request sequence features through weighted summation: .

[0053] In this embodiment, generating the dynamic topological structure feature map according to the feature space mapping information includes: Convert the three - dimensional feature space mapping information into a dynamic topological structure to obtain the topological adjacency matrix; Process the topological adjacency matrix through graph convolution operations to generate the dynamic topological structure feature map.

[0054] In this embodiment, converting the three - dimensional feature space mapping information into a dynamic topological structure to obtain the topological adjacency matrix includes: Calculate the fractal dimension adaptive factor: ; Construct the hypersphere radius matrix: ; Generate the topological adjacency matrix: ; where, .

[0055] In this embodiment, fusing the request sequence features, the dynamic topological structure feature map, and the side - channel features to form the fused features includes: Normalize the request sequence features, the dynamic topological structure feature map, and the side - channel features respectively to obtain the normalized request sequence features, the normalized dynamic topological structure feature map, and the normalized side - channel features, and fuse them to form the fused features; Calculate the request sequence feature significant symbol of the normalized request sequence features, the dynamic topological structure feature significant symbol of the normalized dynamic topological structure feature map, and the side - channel feature significant symbol of the normalized side - channel features respectively; in this embodiment, calculate the feature significance through the following formula: ; where H is the Hurst exponent, and the fractal roughness is introduced for adjustment; Generate a base weight according to the request sequence feature signature, the dynamic topology structure feature signature, and the side-channel feature signature; specifically, generate the base weight through the softmax function: ; Generate a threat deviation adjustment factor according to the threat index; specifically, obtain the threat deviation adjustment factor through the following method: Calculate the threat deviation: ; Generate an adjustment factor: ; where τ adopts a dynamic attenuation strategy: (depth is the current network depth); Generate a dynamic weight according to the threat deviation adjustment factor and the base weight; specifically, generate the dynamic weight through the following formula: ; where W_final is the dynamic weight, W_base is the base weight, W is the adjustment factor.

[0056] Generate a final fusion feature by fusing the dynamic weight, the normalized request sequence feature, the normalized dynamic topology structure feature map, and the normalized side-channel feature to form a fusion feature; specifically, perform a tensor product fusion on the three branch features (the normalized request sequence feature, the normalized dynamic topology structure feature map, and the normalized side-channel feature) and the dynamic weight, and perform dynamic routing compression after fusion to obtain the fusion feature.

[0057] In this embodiment, the total loss function formula of the discrimination neural network is as follows: ; where, β is the weight coefficient of the conditional mutual information loss, γ is the weight coefficient of the Lyapunov interval constraint loss, is the Lyapunov exponent interval constraint loss function, is the conditional mutual information maximization loss function, is the dynamic confidence weighted cross-entropy loss function, is the dynamic confidence weighted cross-entropy loss function.

[0058] In this embodiment, the dynamic confidence weighted cross-entropy loss function adopts the following formula: ; where C is the total number of classification categories, is the c-th dimension of the one-hot vector of the true label, is the probability value of the c-th category predicted by the model, is the confidence function, calculated as ; α is the confidence weighting coefficient; The conditional mutual information maximization loss function adopts the following formula: ; where is the discretized set of threat indices, is the probability distribution of the threat index, is the joint probability distribution of the feature space and side-channel information under the condition of the threat index θ, is the marginal probability distribution of the feature space under the condition of the threat index θ, is the marginal probability distribution of side-channel information under the condition of the threat index θ; The Lyapunov exponent interval constraint loss function adopts the following formula: ; where is the measured value of the maximum Lyapunov exponent of the current chaotic system, is the upper boundary threshold of the Lyapunov exponent, is the lower boundary threshold of the Lyapunov exponent, is the conditional mutual information maximization loss function.

[0059] The total loss function of this application combines the Lyapunov exponent interval constraint loss function, the conditional mutual information maximization loss function, and the dynamic confidence weighted cross-entropy loss function, so that the total loss function of this application can ensure that the chaotic system is in a critical state, avoid decision jitter, improve the multi-source data collaborative analysis ability, and enhance the noise robustness.

[0060] This application also provides an edge node heterogeneous network platform access management system, and the edge node heterogeneous network platform access management system includes at least one edge node and a monitoring platform, and each of the edge nodes and the monitoring platform cooperate to implement the edge node heterogeneous network platform access management method as described above.

[0061] The edge node heterogeneous network platform access management method of this application has the following advantages: (1) This application adopts an encryption mechanism that combines UTF-8 encoding with three-dimensional chaotic mapping. Through triple processing of initial confusion layer generation, triple sequence mapping, and chaotic mapping adjustment, it realizes the encrypted transmission of access requests. In this way, the anti-attack ability can be significantly improved. The chaotic mapping maximizes the product of the Hamming distance and the edit distance between adjacent triples, forming a pseudo-random noise effect, effectively countering forged requests and covert channel attacks. The mapping parameters are dynamically adjusted according to the network traffic characteristics to build a multi-layer defense system. Experiments have verified that the success rate of replay attacks can be reduced by 92.3%.

[0062] (2) This application dynamically generates sandbox adjustment strategies according to the threat index, constructs a three-dimensional threat assessment model by integrating hardware fingerprints, operating system entropy values, and network manifold characteristics, and realizes differential disposal (isolation / restricted access / direct access) of edge nodes. By presetting a sandbox policy library, the CPU / memory allocation threshold is dynamically adjusted according to the real-time threat level, improving resource utilization while ensuring security.

[0063] (3) The discriminant neural network of this application processes both structured (hardware fingerprints) and unstructured (side-channel information) data simultaneously. It realizes feature alignment through a chaotic hidden layer, introduces a Lyapunov exponent constraint loss function, and makes the decision weights dynamically adjusted according to the threat index. Experiments show that the false alarm rate is reduced to 0.7%. Feature self-learning is realized through the conditional mutual information maximization loss function, and the network structure can automatically evolve with new attack patterns.

[0064] (4) In the threat index calculation part, dynamic feature extraction is realized through three-dimensional chaotic mapping, the security situation is quantified by combining the spatio-temporal threat potential function model, and the hypersphere collapse transformation is used to balance efficiency and accuracy, constructing a closed-loop feedback multi-modal fusion framework, significantly improving the accuracy, real-time performance, and environmental adaptability of threat detection.

[0065] Although the present invention has been described in detail with general descriptions and specific embodiments above, based on the present invention, some modifications or improvements can be made, which are obvious to those skilled in the art. Therefore, these modifications or improvements made without departing from the spirit of the present invention all fall within the scope of protection required by the present invention.

Claims

1. A method for managing access to heterogeneous edge node platforms, characterized in that: The edge node heterogeneous network and heterogeneous platform access management method includes: Each edge node sends access request sequence information mapped by three-dimensional chaotic dynamic symbols to the monitoring platform; The monitoring platform reversely decodes each received access request sequence information after three-dimensional chaotic dynamic symbol mapping, thereby obtaining the decoded access request sequence information; The monitoring platform generates a threat index corresponding to each edge node based on each decoded access request sequence information; The monitoring platform generates a sandbox adjustment strategy for the edge node based on the threat index corresponding to the edge node and the preset dynamic sandbox strategy; The monitoring platform performs different treatments on each edge node according to the sandbox adjustment strategy of the edge node, and the different treatments include placing the edge node into different preset sandboxes or directly accessing the edge node without placing it into the preset sandbox; The monitoring platform obtains the trained identification neural network; The monitoring platform inputs the access request sequence information corresponding to each edge node placed in different preset sandboxes, the feature space mapping information generated based on the access request sequence information, and the side channel information generated in the preset sandbox into the identification neural network, thereby obtaining the identification information corresponding to each edge node; The monitoring platform determines whether to allow the edge node in the preset sandbox to access based on the identification information. If so, the edge node is allowed to access.

2. The edge node heterogeneous network and heterogeneous platform access management method according to claim 1, characterized in that: The access request sequence information includes hardware fingerprint, operating system entropy value, and network manifold characteristics; The access request sequence information is subjected to three-dimensional chaotic dynamic symbol mapping in the following manner: Convert the access request sequence information into a binary string through UTF-8 encoding; Generate an initial obfuscation layer based on the binary string; The binary string in the initial obfuscation layer is split into 3-bit segments and mapped into a custom symbol set to generate a triple sequence. The arrangement order of triplet sequence is adjusted through chaotic mapping to maximize the product of Hamming distance and edit distance of each adjacent triplet in the triplet sequence, thereby forming access request sequence information after three-dimensional chaotic dynamic symbol mapping.

3. The edge node heterogeneous network and heterogeneous platform access management method as claimed in claim 2, characterized in that: The monitoring platform generates a threat index corresponding to each edge node according to each decoded access request sequence information, including: The following processing is performed on each edge node: The monitoring platform generates feature space mapping information according to the decoded access request sequence information; The monitoring platform obtains the threat index based on the feature space mapping information; The monitoring platform generates feature space mapping information according to the decoded access request sequence information, including: The access request sequence information is mapped to the dynamic dimensional space through the following formula to obtain a three-dimensional feature space mapping: ; Where X is the access request sequence matrix; K is the number of mapping dimensions; W k is the weight matrix of the kth mapping dimension; A k is the kth nonlinear coupling factor matrix, whose element values ​​are generated by chaotic sequences; P k is the k-th state transition probability matrix; ⊙ represents the Hadamard product.

4. The edge node heterogeneous network and heterogeneous platform access management method as claimed in claim 3, characterized in that: The monitoring platform obtains the threat index according to the feature space mapping information, including: Acquire feature interaction vector flow and edit distance matrix according to feature space mapping information; Obtaining a spatiotemporal threat potential function model; Inputting the feature interaction vector flow and the edit distance matrix into the spatiotemporal threat potential function model to obtain a primary threat index; Acquire a feature matrix according to access request sequence information; Performing a hypersphere collapse transformation according to the characteristic matrix, thereby obtaining a transformed characteristic matrix; Obtaining a transformed feature interaction vector flow according to the transformed feature matrix; The final threat index is obtained based on the transformed feature interaction vector flow and edit distance matrix.

5. The edge node heterogeneous network and heterogeneous platform access management method as claimed in claim 4, characterized in that: The monitoring platform generates a sandbox adjustment strategy for the edge node according to the threat index corresponding to the edge node and the preset dynamic sandbox strategy, including: Obtain a preset threat level classification database, where the threat level classification database includes at least one threat index interval and a sandbox adjustment strategy corresponding to each threat index interval; Get the sandbox adjustment policy corresponding to the threat index interval in which the final threat index currently calculated is located.

6. The edge node heterogeneous network and heterogeneous platform access management method as claimed in claim 5, characterized in that: The discriminative neural network comprises: A multimodal heterogeneous input layer, the multimodal heterogeneous input layer is used to receive the access request sequence information, the feature space mapping information and the side channel information, and generate a request sequence feature according to the access request sequence information, generate a dynamic topology structure feature map according to the feature space mapping information, and generate a side channel feature according to the side channel information; A feature fusion layer, the feature fusion layer is used to fuse the request sequence feature, the dynamic topology structure feature map and the side channel feature to form a fusion feature; A chaotic hidden layer, wherein the chaotic hidden layer is used to generate a chaotic enhancement feature through an improved ternary chaotic mapping activation function; An output layer outputs a three-dimensional confidence vector according to the chaos enhancement feature.

7. The edge node heterogeneous network and heterogeneous platform access management method according to claim 6, characterized in that: Generating a request sequence feature according to the access request sequence information comprises: Generate a request sequence matrix according to the access request sequence information, wherein the request sequence matrix includes time window information, feature type information, and chaos map dimension information; The request sequence matrix is ​​processed by a three-dimensional chaotic attention mechanism to generate request sequence features; Generating a dynamic topological structure feature map according to feature space mapping information includes: Convert the three-dimensional feature space mapping information into a dynamic topological structure to obtain a topological adjacency matrix; The topological adjacency matrix is ​​processed through a graph convolution operation to generate a dynamic topological structure feature graph.

8. The edge node heterogeneous network and heterogeneous platform access management method according to claim 7, characterized in that: The fusing of the request sequence feature, the dynamic topology structure feature graph and the opposite channel feature to form a fused feature comprises: Normalizing the request sequence feature, the dynamic topology structure feature map, and the opposite side channel feature fusion respectively, so as to obtain the normalized request sequence feature, the normalized dynamic topology structure feature map, and the normalized opposite side channel feature fusion to form a fusion feature; Respectively calculating the request sequence feature significance of the normalized request sequence feature, the dynamic topology structure feature significance of the normalized dynamic topology structure feature graph, and the side channel feature significance of the normalized side channel feature; Generate a basic weight according to the request sequence feature salient symbol, the dynamic topology structure feature salient symbol, and the side channel feature salient symbol; Generate a threat deviation adjustment factor based on the threat index; Generate a dynamic weight according to the threat deviation adjustment factor and the basic weight; A fused feature is formed according to the dynamic weight and the normalized request sequence feature, the normalized dynamic topology structure feature graph, and the normalized side channel feature fusion to generate a final fused feature.

9. The edge node heterogeneous network and heterogeneous platform access management method according to claim 8, characterized in that: The total loss function formula of the identification neural network is as follows: ; in, β is the weight coefficient of conditional mutual information loss, γ is the weight coefficient of Lyapunov interval constraint loss, is the Lyapunov exponential interval constraint loss function, Maximize the loss function for conditional mutual information, is the dynamic confidence weighted cross entropy loss function, is the total loss function; The dynamic confidence weighted cross entropy loss function adopts the following formula: ; Where C is the total number of classification categories, is the c-th dimension of the one-hot vector of the true label, is the probability value of the cth category predicted by the model, is the confidence function, α is the confidence weighting coefficient, is the dynamic confidence weighted cross entropy loss function; The conditional mutual information maximization loss function adopts the following formula: ; in, is the discretized set of threat indices, is the probability distribution of threat index, is the joint probability distribution of feature space and side channel information under the threat index θ, is the marginal probability distribution of the feature space under the condition of threat index θ, is the marginal probability distribution of side channel information under the threat index θ, Maximize the loss function for conditional mutual information; The Lyapunov exponential interval constraint loss function adopts the following formula: ; in, is the maximum measured value of the Lyapunov exponent of the current chaotic system, is the upper boundary threshold of the Lyapunov exponent, is the lower boundary threshold of the Lyapunov exponent, is the Lyapunov exponential interval constraint loss function.

10. An edge node heterogeneous network and heterogeneous platform access management system, characterized in that: The edge node heterogeneous network platform access management system includes at least one edge node and a monitoring platform, and each of the edge nodes and the monitoring platform cooperate to implement the edge node heterogeneous network platform access management method as described in any one of claims 1 to 9.

Citation Information

Patent Citations

  • Block chain smart contract generation method and device, and electronic equipment

    CN115268847A

  • Engineering design industry cloud data collaboration and storage method

    CN118118213A

  • Internet of Things control method and platform based on OpenHarmony

    CN119814596A

  • Safety access control method and system for DNS (Domain Name Server) analysis

    CN119865372A

  • Channel access method, apparatus and system, and storage medium

    WO2018006759A1

Cited By

  • Disordered factor self-organizing bidirectional calculation data security processing method and system

    CN120474684A

  • Disorder factor self-organizing bidirectional computing data security processing method and system

    CN120474684B

  • Cloud mobile phone equipment fingerprint disguising method and related equipment

    CN120768541A

  • Topology verification method, device, equipment and medium for water supply network

    CN120805371A

  • Edge scene-oriented prediction method based on space-time quantum federated learning

    CN121503589A