An access management method and system for heterogeneous platforms of edge nodes in different networks

Through three-dimensional chaotic dynamic symbol mapping and dynamic sandbox strategy, combined with the identification neural network to process edge node heterogeneous platform access requests, the problems of hardware diversity not being dynamically verified, uneven resource allocation, and insufficient security isolation in the existing technology are solved, and efficient access management of edge node heterogeneous platform is realized, and data security and resource utilization are improved.

CN120090889BActive Publication Date: 2025-07-08CHINA TOWER CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510586309.1
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-08
Publication Date
2025-07-08
Estimated Expiration
2045-05-08

AI Technical Summary

Technical Problem

The existing technology has problems such as hardware diversity not being dynamically verified, uneven resource allocation, insufficient security isolation strategies, and inaccurate threat assessment in the access management of heterogeneous platforms of edge nodes, resulting in difficult to meet the needs of low-latency scenarios, and the risk of side channel leakage, high false alarm rate, and low attack detection rate when deploying physical isolation cabins.

Method used

Three-dimensional chaotic dynamic symbol mapping is used to encrypt access request sequence information, combined with the monitoring platform's reverse decoding and dynamic sandbox strategy, by identifying the neural network processing hardware fingerprint, operating system entropy value and network manifold characteristics, threat index is generated and dynamic sandbox adjustment is carried out to achieve refined access control and multi-level threat response.

Benefits of technology

Significantly improve data security, reduce false alarm rate, improve resource utilization rate, enhance resistance to unknown attacks, form a closed-loop defense system, and ensure heterogeneous compatibility and real-timeness of edge nodes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120090889B_ABST
    Figure CN120090889B_ABST
Patent Text Reader

Abstract

The present application discloses a method and system for access management of an edge node heterogeneous network heterogeneous platform, relating to the technical field of the Internet of Things. The method includes: the monitoring platform performs reverse decoding on each received access request sequence information that has undergone three-dimensional chaotic dynamic symbol mapping to obtain the decoded access request sequence information; generating a threat index corresponding to the edge node according to the access request sequence information; generating a sandbox adjustment strategy for the edge node according to the threat index; performing different disposals on the edge node according to the sandbox adjustment strategy; inputting the feature information of the edge node into the discrimination neural network to obtain discrimination information; the monitoring platform determines whether to allow the edge node in the preset sandbox to access according to the discrimination information, and if so, accesses the edge node. The present application encrypts and transmits the access request through three-dimensional chaotic dynamic symbol mapping, significantly improving data security, and realizing fine-grained access control in cooperation with the dynamic sandbox strategy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of Internet of Things technology, and particularly relates to a method for accessing and managing an edge node heterogeneous network and heterogeneous platform, and a system for accessing and managing an edge node heterogeneous network and heterogeneous platform. Background Art

[0002] Currently, the access management of edge node heterogeneous networks and heterogeneous platforms mainly adopts a static rule-driven and basic feature matching mode, and its core processes include:

[0003] Access authentication: relying on certificate digest comparison or simple IP / DNS load balancing, lacking dynamic verification of heterogeneous attributes such as hardware and operating systems.

[0004] Resource scheduling: allocating computing resources through preset thresholds, without considering the hardware diversity of edge nodes (such as ARM / x86 architecture differences) and real-time load changes.

[0005] Security isolation: using a fixed sandbox policy (such as unified containerization), without dynamically adjusting the isolation intensity according to the threat level, and lacking the ability to analyze side-channel behavior.

[0006] Decision-making mechanism: making access judgments based on a single network traffic feature or coarse-grained behavior logs, with a high false positive rate and false negative rate.

[0007] The prior art has the following disadvantages:

[0008] (1) Traditional methods rely on manually preset sandbox policies (such as fixed bandwidth limits), and cannot dynamically adjust resource allocation according to the real-time load of nodes (such as memory entropy value, process behavior hash), resulting in low-priority tasks occupying high-security-level resources.

[0009] (2) There is a lack of a unified resource description protocol between heterogeneous nodes (such as mixed use of frameworks such as KubeEdge and SuperEdge), resulting in a high delay in state synchronization during edge-cloud coordination, and it is difficult to meet the requirements of low-latency scenarios such as vehicle networking.

[0010] (3) No hierarchical isolation strategy is designed for the hardware characteristics of edge nodes (such as DMA / IOMMU pass-through limitations), resulting in a risk of side-channel leakage during the deployment of physical isolation cabins.

[0011] (4) Only relying on certificate digest or IP address verification, without integrating multi-source heterogeneous features such as hardware fingerprints (such as CPU microarchitecture hash) and operating system entropy values, it is easy to be bypassed by forged requests.

[0012] (5) The adjustment of traditional sandbox policies depends on a preset rule library (such as fixed thresholds 0.15 / 0.3 / 0.5), and cannot respond in real time to new types of attacks (such as covert channel attacks based on chaotic mapping).

[0013] (6) The memory access patterns of processes in the sandbox and side-channel information such as the atomicity of I / O operations are not monitored, resulting in a low detection rate for container escape attacks.

[0014] (7) Only analyzing the characteristics of network manifolds (such as the time-series spectrum of data packets) and ignoring the characteristics of the hardware layer (such as the hash of process behavior) and the operating system layer (such as entropy value changes), the accuracy of threat assessment is less than 78%.

[0015] (8) Using a fixed confidence threshold (such as 0.5) to judge access legality and not introducing a dynamic confidence weighting mechanism, resulting in a high false acceptance rate in high-threat scenarios. Summary of the Invention

[0016] The object of the present invention is to provide an access management method for an edge node heterogeneous network platform to solve at least one of the above technical problems.

[0017] In one aspect of the present invention, there is provided an access management method for an edge node heterogeneous network platform, and the access management method for the edge node heterogeneous network platform includes:

[0018] Each edge node sends the access request sequence information after three-dimensional chaotic dynamic symbol mapping to the monitoring platform;

[0019] The monitoring platform performs reverse decoding on each received access request sequence information after three-dimensional chaotic dynamic symbol mapping to obtain the decoded access request sequence information;

[0020] The monitoring platform generates a threat index corresponding to each edge node according to each decoded access request sequence information;

[0021] The monitoring platform generates a sandbox adjustment strategy for the edge node according to the threat index corresponding to the edge node and a preset dynamic sandbox strategy;

[0022] The monitoring platform performs different disposals on each edge node according to the sandbox adjustment strategy of the edge node, and the different disposals include putting the edge node into different preset sandboxes or directly accessing without putting it into a preset sandbox;

[0023] The monitoring platform obtains a trained discriminant neural network;

[0024] The monitoring platform inputs the access request sequence information corresponding to each edge node put into different preset sandboxes, the feature space mapping information generated based on the access request sequence information, and the side-channel information generated in the preset sandbox into the discriminant neural network respectively, so as to obtain the discriminant information corresponding to each edge node;

[0025] The monitoring platform determines whether to allow an edge node within a preset sandbox to access based on the authentication information. If so, the edge node is allowed to access.

[0026] Optionally, the access request sequence information includes a hardware fingerprint, an operating system entropy value, and a network manifold feature.

[0027] The access request sequence information is subjected to three-dimensional chaotic dynamic symbol mapping in the following manner:

[0028] Convert the access request sequence information into a binary string through UTF-8 encoding.

[0029] Generate an initial confusion layer based on the binary string.

[0030] Divide the binary string within the initial confusion layer into groups of 3 bits each and map them to a custom symbol set to generate a triple sequence.

[0031] Adjust the arrangement order of the triple sequence through chaotic mapping to maximize the product of the Hamming distance and the edit distance between each adjacent triple in the triple sequence, thereby forming the access request sequence information after three-dimensional chaotic dynamic symbol mapping.

[0032] Optionally, the monitoring platform generates a threat index corresponding to each edge node based on each decoded access request sequence information, including:

[0033] Perform the following processing on each edge node:

[0034] The monitoring platform generates feature space mapping information based on the decoded access request sequence information.

[0035] The monitoring platform obtains the threat index based on the feature space mapping information.

[0036] The monitoring platform generates feature space mapping information based on the decoded access request sequence information, including:

[0037] Map the access request sequence information to a dynamic dimensional space through the following formula to obtain a three-dimensional feature space mapping:

[0038] ;

[0039] where X is the access request sequence matrix; K is the number of mapping dimensions; W k is the weight matrix of the kth mapping dimension; A k is the kth non-linear coupling factor matrix, and the element values are generated by a chaotic sequence; P k is the kth state transition probability matrix; ⊙ represents the Hadamard product.

[0040] Optionally, the monitoring platform obtaining the threat index according to the feature space mapping information includes:

[0041] Obtaining a feature interaction vector stream and an edit distance matrix according to the feature space mapping information;

[0042] Obtaining a spatio-temporal threat potential function model;

[0043] Inputting the feature interaction vector stream and the edit distance matrix into the spatio-temporal threat potential function model to obtain a primary threat index;

[0044] Obtaining a feature matrix according to the access request sequence information;

[0045] Performing a hypersphere collapse transformation according to the feature matrix to obtain a transformed feature matrix;

[0046] Obtaining a transformed feature interaction vector stream according to the transformed feature matrix;

[0047] Obtaining a final threat index according to the transformed feature interaction vector stream and the edit distance matrix.

[0048] Optionally, the monitoring platform generating a sandbox adjustment strategy for the edge node according to the threat index corresponding to the edge node and a preset dynamic sandbox strategy includes:

[0049] Obtaining a preset threat level classification database, where the threat level classification database includes at least one threat index interval and a sandbox adjustment strategy corresponding to each threat index interval;

[0050] Obtaining the sandbox adjustment strategy corresponding to the threat index interval where the currently calculated final threat index is located.

[0051] Optionally, the discrimination neural network includes:

[0052] A multi-modal heterogeneous input layer, which is used to receive the access request sequence information, the feature space mapping information, and the side-channel information, and generate a request sequence feature according to the access request sequence information, generate a dynamic topology structure feature map according to the feature space mapping information, and generate a side-channel feature according to the side-channel information;

[0053] A feature fusion layer, which is used to fuse the request sequence feature, the dynamic topology structure feature map, and the side-channel feature to form a fused feature;

[0054] A chaotic hidden layer, which is used to generate a chaotic enhanced feature through an improved ternary chaotic mapping activation function;

[0055] An output layer, which outputs a three-dimensional confidence vector according to the chaotic enhanced feature.

[0056] Optionally, generating a request sequence feature according to the access request sequence information includes:

[0057] Generating a request sequence matrix according to the access request sequence information, where the request sequence matrix includes time window information, feature type information, and chaotic mapping dimension information;

[0058] Processing the request sequence matrix through a three-dimensional chaotic attention mechanism to generate a request sequence feature;

[0059] Generating a dynamic topological structure feature map according to the feature space mapping information includes:

[0060] Converting three-dimensional feature space mapping information into a dynamic topological structure to obtain a topological adjacency matrix;

[0061] Processing the topological adjacency matrix through a graph convolution operation to generate a dynamic topological structure feature map.

[0062] Optionally, fusing the request sequence feature, the dynamic topological structure feature map, and the side channel feature to form a fusion feature includes:

[0063] Respectively performing normalization processing on the request sequence feature, the dynamic topological structure feature map, and the side channel feature fusion to obtain a normalized request sequence feature, a normalized dynamic topological structure feature map, and a normalized side channel feature fusion to form a fusion feature;

[0064] Respectively calculating a request sequence feature significant symbol of the normalized request sequence feature, a dynamic topological structure feature significant symbol of the normalized dynamic topological structure feature map, and a side channel feature significant symbol of the normalized side channel feature;

[0065] Generating a basic weight according to the request sequence feature significant symbol, the dynamic topological structure feature significant symbol, and the side channel feature significant symbol;

[0066] Generating a threat deviation adjustment factor according to the threat index;

[0067] Generating a dynamic weight according to the threat deviation adjustment factor and the basic weight;

[0068] Generating a final fusion feature according to the dynamic weight and the normalized request sequence feature, the normalized dynamic topological structure feature map, and the normalized side channel feature fusion to form a fusion feature.

[0069] Optionally, the formula of the total loss function of the discrimination neural network is as follows:

[0070] ;

[0071] Among them, β is the weight coefficient of the conditional mutual information loss, γ is the weight coefficient of the Lyapunov interval constraint loss, is the Lyapunov exponent interval constraint loss function, is the conditional mutual information maximization loss function, is the dynamic confidence weighted cross-entropy loss function, is the total loss function;

[0072] The dynamic confidence weighted cross-entropy loss function adopts the following formula:

[0073] ;

[0074] Among them, C is the total number of classification categories, is the c-th dimension of the one-hot vector of the true label, is the probability value of the c-th category predicted by the model, is the confidence function, α is the confidence weighting coefficient, is the dynamic confidence weighted cross-entropy loss function;

[0075] The conditional mutual information maximization loss function adopts the following formula:

[0076] ;

[0077] Among them, Θ is the set of threat index discretization, is the probability distribution of the threat index, is the joint probability distribution of the feature space and the side-channel information under the threat index θ, is the marginal probability distribution of the feature space under the threat index θ, is the marginal probability distribution of the side-channel information under the threat index θ, is the conditional mutual information maximization loss function;

[0078] The Lyapunov exponent interval constraint loss function adopts the following formula:

[0079] ;

[0080] Among them, is the measured value of the maximum Lyapunov exponent of the current chaotic system, is the upper boundary threshold of the Lyapunov exponent, is the lower boundary threshold of the Lyapunov exponent, is the Lyapunov exponent interval constraint loss function.

[0081] The present application also provides an access management system for an edge node heterogeneous network platform. The access management system for the edge node heterogeneous network platform includes at least one edge node and a monitoring platform. Each of the edge nodes and the monitoring platform cooperate to implement the access management method for the edge node heterogeneous network platform as described above.

[0082] Beneficial effects

[0083] The access management method for the edge node heterogeneous network platform of the present application encrypts and transmits access requests through three-dimensional chaotic dynamic symbol mapping, significantly improving data security. The monitoring platform uses reverse decoding to restore request information and cooperates with a dynamic sandbox strategy to achieve refined access control (such as container isolation / hardware partitioning). This not only ensures the heterogeneous compatibility of edge nodes but also effectively resists unknown attacks through a multi-level threat response mechanism, forming a closed-loop defense system of "encrypted transmission - dynamic decoding - hierarchical control". Description of the drawings

[0084] Figure 1 is a schematic flowchart of the access management method for the edge node heterogeneous network platform according to an embodiment of the present application. Detailed implementation manners

[0085] To make the objectives, technical solutions, and advantages of the implementation of the present application clearer, the technical solutions in the embodiments of the present application will be described in more detail below with reference to the accompanying drawings in the embodiments of the present application. In the drawings, the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions from beginning to end. The described embodiments are some but not all of the embodiments of the present application. The embodiments described below with reference to the accompanying drawings are exemplary and are intended to explain the present application and should not be construed as limiting the present application. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the scope of protection of the present application. The embodiments of the present application will be described in detail below with reference to the accompanying drawings.

[0086] As Figure 1 shown, the access management method for the edge node heterogeneous network platform includes:

[0087] Step 1: Each edge node sends access request sequence information that has undergone three-dimensional chaotic dynamic symbol mapping to the monitoring platform;

[0088] Step 2: The monitoring platform performs reverse decoding on each received access request sequence information that has undergone three-dimensional chaotic dynamic symbol mapping to obtain the decoded access request sequence information;

[0089] Step 3: The monitoring platform generates a threat index corresponding to each edge node according to each decoded access request sequence information;

[0090] Step 4: The monitoring platform generates a sandbox adjustment policy for the edge node according to the threat index corresponding to the edge node and a preset dynamic sandbox policy;

[0091] Step 5: The monitoring platform performs different treatments on each edge node according to the sandbox adjustment policy of the edge node. The different treatments include putting the edge node into different preset sandboxes or directly accessing without putting it into a preset sandbox;

[0092] Step 6: The monitoring platform obtains a trained discriminant neural network;

[0093] Step 7: The monitoring platform inputs the access request sequence information corresponding to each edge node put into different preset sandboxes, the feature space mapping information generated based on the access request sequence information, and the side-channel information generated in the preset sandbox into the discriminant neural network respectively, so as to obtain the discriminant information corresponding to each edge node;

[0094] Step 8: The monitoring platform determines whether to allow the edge node in the preset sandbox to access according to the discriminant information. If so, the edge node is accessed.

[0095] The access management method for the heterogeneous network and heterogeneous platform of the edge nodes in this application encrypts and transmits the access request through three-dimensional chaotic dynamic symbol mapping, significantly improving data security. The monitoring platform uses reverse decoding to restore the request information, and cooperates with the dynamic sandbox policy to achieve refined access control (such as container isolation / hardware partitioning), which not only ensures the heterogeneous compatibility of the edge nodes, but also effectively resists unknown attacks through a multi-level threat response mechanism, forming a closed-loop defense system of "encrypted transmission-dynamic decoding-hierarchical management".

[0096] In this embodiment, the access request sequence information includes a hardware fingerprint (such as a CPU microarchitecture hash value), an operating system entropy value (generated by a process behavior sequence hash), and a network manifold feature (a data packet timing spectrum matrix).

[0097] In this embodiment, the three-dimensional chaotic dynamic symbol mapping of the access request sequence information is performed through the following method:

[0098] Convert the original access request sequence information into a binary string through UTF-8 encoding;

[0099] Generate an initial confusion layer according to the binary string. The initial confusion layer is generated through the following formula:

[0100] M 置换 =Hash( EID ⊕ T )mod N; Where Nis the preset permutation space dimension, and ⊕ represents the exclusive OR operation. This matrix dynamically rearranges every 8 bits of the binary string to form the initial confusion layer;

[0101] The binary string within the initial confusion layer is segmented by every 3 bits and mapped to a custom symbol set (for example these symbols), thereby generating a triple sequence. For example, the binary "101" is mapped to " ";

[0102] By adjusting the arrangement order of the triple sequence through chaotic mapping, the product of the Hamming distance and the edit distance between adjacent triples in the triple sequence is maximized, thereby forming the access request sequence information after three-dimensional chaotic dynamic symbol mapping.

[0103] In this embodiment, the chaotic mapping is carried out through the following formula:

[0104] ;

[0105] where μ = 3.99, α = 0.05, and β = the value of EID modulo 128.

[0106] An unpredictable permutation rule is generated through EID and the time stamp, so that the same original data produces completely different coding results under different space-time conditions.

[0107] The access request sequence information after three-dimensional chaotic dynamic symbol mapping generated by the above method has the discreteness of the symbol space on the one hand and the chaotic characteristics of the arrangement order on the other hand, thereby constituting a multi-layer defense mechanism.

[0108] In this embodiment, the monitoring platform generates the threat index corresponding to each edge node according to each decoded access request sequence information, including:

[0109] The following processing is performed on each edge node:

[0110] The following operations are performed on each decoded access request sequence information:

[0111] The monitoring platform maps according to the access request sequence information feature space mapping information;

[0112] The monitoring platform obtains the threat index according to the feature space mapping information.

[0113] In this embodiment, generating the feature space mapping information according to the access request sequence information includes:

[0114] The decoded access request sequence information is mapped to the dynamic dimension space through the following formula to obtain the three-dimensional feature space mapping:

[0115] ;

[0116] Among them, X is the access request sequence matrix, K is the number of mapping dimensions, and W k is the weight matrix of the k-th mapping dimension, A k is the non-linear coupling factor matrix of the k-th, and the element values are generated by the chaotic sequence, P k is the state transition probability matrix of the k-th, and ⊙ represents the Hadamard product (element-wise product).

[0117] For the convenience of description, the three-dimensional feature space mapping of this application will be elaborated in detail by way of example below. It can be understood that this example does not constitute any limitation to this application.

[0118] Obtain the access request sequence matrix X (already standardized):

[0119] ; (3 time windows × 3 feature dimensions);

[0120] The number of mapping dimensions K = 3;

[0121] Initialize the parameters:

[0122] The chaotic system is calculated using the above formula:

[0123] ;

[0124] The initial coupling factor matrix A k (The first 3 values are generated by the chaotic sequence):

[0125] , , ;

[0126] The state transition probability matrix P k (Based on historical data statistics):

[0127] The first dimension mapping calculation:

[0128]

[0129] The second and third dimension mapping calculations (the process is similar, and the results are directly given here):

[0130] ;

[0131] ;

[0132] The final feature space mapping (vector splicing):

[0133] .

[0134] In this embodiment, the initial coupling factor matrix can be obtained in the following manner A k :

[0135] Chaotic sequence generation is achieved through iterative Logistic mapping N k times ( N k is the total number of matrix elements. For example, for a 3×3 matrix, N k = 9), to generate a sequence ;

[0136] After linearly mapping to the interval [0,1] through the arctangent function, the nonlinear characteristics are enhanced through the arctangent function (as shown in the following formula):

[0137] ;

[0138] This transformation makes take 0 at and grow nonlinearly to ±1.99 on both sides.

[0139] Fill sequentially into the A k matrix. For example, the filling order of a 3×3 matrix is as follows:

[0140] , thereby obtaining the initial coupling factor matrix.

[0141] In this embodiment, obtaining the threat index based on the feature space mapping information includes:

[0142] Obtaining the feature interaction vector flow and the edit distance matrix based on the feature space mapping information;

[0143] Obtaining the spatio-temporal threat potential function model;

[0144] Inputting the feature interaction vector flow and the edit distance matrix into the spatio-temporal threat potential function model to obtain the primary threat index;

[0145] In this embodiment, the spatio-temporal threat potential function model adopts the following formula:

[0146] ;

[0147] where, J A is the feature interaction vector flow of feature A, J BThe feature interaction vector flow for Feature B. In this embodiment, the feature interaction vector flow represents the movement direction of the feature cluster in the feature space;

[0148] Lev(A, B) is the edit distance matrix, representing the structural quantization difference between feature clusters; γ is the environment adaptation coefficient, dynamically adjusted according to real-time network traffic (value range 0.1 - 1.0); Θ(t) is the threat potential energy integral in any region of the feature space.

[0149] In this embodiment, the feature interaction vector flow of Feature A is obtained through the following formula:

[0150] ; where is the number of samples included in Feature Cluster A; is the gradient direction vector of the i-th sample in Feature Cluster A.

[0151] In this embodiment, the edit distance matrix is obtained through the following formula:

[0152] ; where

[0153] (neighborhood judgment); is the sample pair 's Euclidean distance; is the neighborhood radius threshold.

[0154] The feature matrix is obtained according to the access request sequence information. Specifically, quantization metrics are extracted from the access request sequence information through feature engineering, and the above quantization metrics are arranged according to time windows to form the initial form of the feature matrix ;

[0155] According to the feature matrix perform hypersphere collapse transformation to obtain the transformed feature matrix ;

[0156] According to the transformed feature matrix obtain the transformed feature interaction vector flow;

[0157] Obtain the final threat index according to the transformed feature interaction vector flow.

[0158] This application reveals the movement trajectory of the feature cluster through the feature interaction vector flow, can detect the slow lateral movement of APT attacks, and solves the problem of the failure of the traditional Euclidean distance in high-dimensional space through dynamic adjustment of the ε neighborhood radius. In addition, while retaining the topological structure through collapse transformation, the dimension is reduced, and the computational efficiency is improved by 15% compared with PCA.

[0159] In this embodiment, the spatial mapping controlled by the Hurst index automatically optimizes the feature resolution in the 5G network (H≈0.8) and the Internet of Things (H≈0.6) environments, and can adjust the mapping dimension in real time, so that high-threat features are magnified and displayed in the projection space, improving the detection sensitivity.

[0160] In this embodiment, generating a sandbox adjustment strategy according to the threat index and the preset dynamic sandbox strategy includes:

[0161] Obtain a preset threat level classification database, where the threat level classification database includes at least one threat index interval and the corresponding sandbox adjustment strategy for each threat index interval;

[0162] Obtain the sandbox adjustment strategy corresponding to the threat index interval where the currently calculated final threat index is located.

[0163] In this embodiment, the threat index intervals include: the threat index is less than 0.15, and the corresponding sandbox adjustment strategy for this threat index interval is: directly access without putting it into the sandbox;

[0164] The threat index is greater than 0.15 and less than 0.3, and the corresponding sandbox adjustment strategy for this threat index interval is: set containerized isolation, deploy a behavior whitelist, implement network traffic coloring and marking, and automatically generate a runtime checksum every preset time;

[0165] The threat index is greater than 0.3 and less than 0.5, and the corresponding sandbox adjustment strategy for this threat index interval is: set a hybrid sandbox (container + lightweight virtual machine), full-system call tracing (frequency 100Hz), real-time monitoring of memory entropy value (threshold 85%), and file I / O sandbox redirection (all write operations are atomic);

[0166] The threat index is greater than 0.5 and less than 0.85, and the corresponding sandbox adjustment strategy for this threat index interval is: set a hardware-assisted virtualization sandbox, enable Intel VT-x nested virtualization, configure SR-IOV direct pass-through but limit the bandwidth to 1Gbps, and implement real-time monitoring of the memory page table;

[0167] The threat index is greater than 0.85, and the corresponding sandbox adjustment strategy for this threat index interval is: set a physical isolation cabin (independent hardware partition) and disable DMA / IOMMU direct pass-through.

[0168] In this embodiment, a five-level threat classification model is used to reduce the false positive rate by 40% (experimental data), and through a combined solution of a container + lightweight virtual machine with hybrid sandbox collaboration, while ensuring the isolation strength, the performance loss ratio is maintained at 92%.

[0169] In this embodiment, the authentication neural network includes a multi-modal heterogeneous input layer, a feature fusion layer, a chaotic hidden layer, and an output layer. Among them,

[0170] The multi-modal heterogeneous input layer is used to receive the access request sequence information, feature space mapping information, and side-channel information, generate request sequence features according to the access request sequence information, generate a dynamic topology structure feature map according to the feature space mapping information, and generate side-channel features according to the side-channel information.

[0171] The feature fusion layer is used to fuse the request sequence features, the dynamic topology structure feature map, and the side-channel features to form fusion features.

[0172] The chaotic hidden layer is used to activate through an improved ternary chaotic mapping activation function.

[0173] The output layer is used to adopt a dynamic confidence threshold mechanism to output a three-dimensional confidence vector (probability of allowing access, probability of sandbox isolation, probability of rejection).

[0174] In this embodiment, generating request sequence features according to the access request sequence information includes:

[0175] Processing the access request sequence information to generate a request sequence matrix, where the request sequence matrix includes time window information, feature type information, and chaotic mapping dimension information.

[0176] Processing the request sequence matrix through a three-dimensional chaotic attention mechanism to generate request sequence features.

[0177] In this embodiment, processing the request sequence matrix through a three-dimensional chaotic attention mechanism to generate request sequence features adopts the following method:

[0178] Receiving the three-dimensional tensor input of the original access request sequence to form a request sequence matrix, and the dimension of the request sequence matrix is [time window × feature type × chaotic mapping dimension].

[0179] Time window: Dynamically adjustable, with an initial value of 128 (automatically expandable to 512 according to real-time traffic).

[0180] Feature type: Includes hardware fingerprint feature (32 dimensions), operating system entropy value feature (16 dimensions), and network manifold feature (64 dimensions).

[0181] Chaotic mapping dimension: Dynamically generated by the EID modulo 128 value, fluctuating in the range of 32 - 128 dimensions.

[0182] Adopt an improved three-dimensional chaotic attention mechanism:

[0183] Calculate the chaotic energy spectrum for each time window:

[0184] ;

[0185] Generate an attention weight matrix: ; where μ is the chaos control parameter and H is the Hurst exponent matrix;

[0186] Generate the request sequence feature through weighted summation:

[0187] .

[0188] In this embodiment, generating the dynamic topology structure feature map according to the feature space mapping information includes:

[0189] Convert the three-dimensional feature space mapping information into a dynamic topology structure to obtain a topology adjacency matrix;

[0190] Process the topology adjacency matrix through graph convolution operations to generate a dynamic topology structure feature map.

[0191] In this embodiment, converting the three-dimensional feature space mapping information into a dynamic topology structure to obtain a topology adjacency matrix includes:

[0192] Calculate the fractal dimension adaptive factor: D_frac = H / (1 + H);

[0193] Construct a hypersphere radius matrix:

[0194] ;

[0195] Generate a topology adjacency matrix:

[0196] ;

[0197] where, .

[0198] In this embodiment, fusing the request sequence feature, the dynamic topology structure feature map, and the cross-channel feature to form a fusion feature includes:

[0199] Normalize the request sequence feature, the dynamic topology structure feature map, and the cross-channel feature respectively to obtain the normalized request sequence feature, the normalized dynamic topology structure feature map, and the normalized cross-channel feature, and fuse them to form a fusion feature;

[0200] Calculate the request sequence feature significant symbol of the normalized request sequence feature, the dynamic topology structure feature significant symbol of the normalized dynamic topology structure feature map, and the cross-channel feature significant symbol of the normalized cross-channel feature respectively; in this embodiment, calculate the feature significance through the following formula: ; where H is the Hurst exponent, and fractal roughness adjustment is introduced;

[0201] Generate a basic weight according to the request sequence feature signature, the dynamic topology structure feature signature, and the side-channel feature signature; specifically, generate the basic weight through the softmax function:

[0202] ;

[0203] Generate a threat deviation adjustment factor according to the threat index; specifically, obtain the threat deviation adjustment factor through the following method:

[0204] Calculate the threat deviation:

[0205] ;

[0206] Generate an adjustment factor: ; where τ adopts a dynamic decay strategy: τ = 0.9^depth (depth is the current network depth);

[0207] Generate a dynamic weight according to the threat deviation adjustment factor and the basic weight; specifically, generate the dynamic weight through the following formula:

[0208] ; where W_final is the dynamic weight, W_base is the basic weight, is the adjustment factor.

[0209] Generate a final fusion feature by fusing the fusion feature formed by the dynamic weight and the normalized request sequence feature, the normalized dynamic topology structure feature map, and the normalized side-channel feature; specifically, perform a tensor product fusion on the three branch features (the normalized request sequence feature, the normalized dynamic topology structure feature map, and the normalized side-channel feature) and the dynamic weight, and perform dynamic routing compression after fusion to obtain the fusion feature.

[0210] In this embodiment, the total loss function formula of the discrimination neural network is as follows:

[0211] ;

[0212] where, β is the weight coefficient of the conditional mutual information loss, γ is the weight coefficient of the Lyapunov interval constraint loss, is the Lyapunov exponent interval constraint loss function, is the conditional mutual information maximization loss function, is the dynamic confidence weighted cross-entropy loss function, It is a dynamic confidence weighted cross entropy loss function.

[0213] In this embodiment, the dynamic confidence weighted cross entropy loss function adopts the following formula:

[0214] ;

[0215] where C is the total number of classification categories, is the c-th dimension of the one-hot vector of the true label, is the probability value of the c-th category predicted by the model, is the confidence function, calculated as ; α is the confidence weighted coefficient;

[0216] The conditional mutual information maximization loss function adopts the following formula:

[0217] ;

[0218] where Θ is the set of threat index discretization, is the probability distribution of the threat index, is the joint probability distribution of the feature space and the side-channel information under the threat index θ, is the marginal probability distribution of the feature space under the threat index θ, is the marginal probability distribution of the side-channel information under the threat index θ;

[0219] The Lyapunov exponent interval constraint loss function adopts the following formula:

[0220] ;

[0221] where, is the measured value of the maximum Lyapunov exponent of the current chaotic system, is the upper boundary threshold of the Lyapunov exponent, is the lower boundary threshold of the Lyapunov exponent, is the conditional mutual information maximization loss function.

[0222] The total loss function of this application combines the Lyapunov exponent interval constraint loss function, the conditional mutual information maximization loss function, and the dynamic confidence weighted cross entropy loss function, so that the total loss function of this application can ensure that the chaotic system is in a critical state, avoid decision jitter, improve the multi-source data collaborative analysis ability, and enhance the noise robustness.

[0223] The present application also provides an access management system for an edge node heterogeneous network platform. The access management system for the edge node heterogeneous network platform includes at least one edge node and a monitoring platform. Each of the edge nodes and the monitoring platform cooperate to implement the access management method for the edge node heterogeneous network platform as described above.

[0224] The access management method for the edge node heterogeneous network platform of the present application has the following advantages:

[0225] (1) The present application adopts an encryption mechanism combining UTF-8 encoding and three-dimensional chaotic mapping. Through triple processing of initial confusion layer generation, triple sequence mapping, and chaotic mapping adjustment, encrypted transmission of access requests is achieved. By adopting this method, the anti-attack ability can be significantly improved. The chaotic mapping maximizes the product of the Hamming distance and the edit distance between adjacent triples, forming a pseudo-random noise effect, effectively combating forged requests and covert channel attacks. The mapping parameters are dynamically adjusted according to network traffic characteristics, constructing a multi-layer defense system. Experimental verification shows that the success rate of replay attacks can be reduced by 92.3%.

[0226] (2) The present application dynamically generates sandbox adjustment strategies according to threat indices, constructs a three-dimensional threat assessment model by integrating hardware fingerprints, operating system entropy values, and network manifold characteristics, and realizes differential disposal (isolation / restricted access / direct access) of edge nodes. By presetting a sandbox policy library, the CPU / memory allocation thresholds are dynamically adjusted according to the real-time threat level, improving resource utilization while ensuring security.

[0227] (3) The discrimination neural network of the present application simultaneously processes structured (hardware fingerprints) and unstructured (side-channel information) data, realizes feature alignment through a chaotic hidden layer, introduces a Lyapunov exponent constraint loss function, and makes the decision weights dynamically adjusted according to threat indices. Experiments show that the false alarm rate is reduced to 0.7%. Feature self-learning is realized through a conditional mutual information maximization loss function, and the network structure can automatically evolve with new attack patterns.

[0228] (4) In the threat index calculation part, dynamic feature extraction is realized through three-dimensional chaotic mapping, the security situation is quantified by combining a spatio-temporal threat potential function model, and a hyper-sphere collapse transformation is used to balance efficiency and accuracy, constructing a closed-loop feedback multi-modal fusion framework, significantly improving the accuracy, real-time performance, and environmental adaptability of threat detection.

[0229] Although the present invention has been described in detail above with general descriptions and specific embodiments, based on the present invention, some modifications or improvements can be made, which are obvious to those skilled in the art. Therefore, these modifications or improvements made without departing from the spirit of the present invention all fall within the scope of protection required by the present invention.

Claims

1. An access management method for an edge node heterogeneous network heterogeneous platform, characterized in that, The access management method for the heterogeneous edge node network includes the following steps: Each edge node sends the access request sequence information after three-dimensional chaotic dynamic symbol mapping to the monitoring platform; The monitoring platform performs reverse decoding on the received access request sequence information after three-dimensional chaotic dynamic symbol mapping for each edge node, so as to obtain the decoded access request sequence information; The monitoring platform generates a threat index corresponding to each edge node according to each decoded access request sequence information; The monitoring platform generates a sandbox adjustment strategy for the edge node according to the threat index corresponding to the edge node and a preset dynamic sandbox policy; The monitoring platform performs different dispositions on each edge node according to the sandbox adjustment strategy of the edge node. The different dispositions include putting the edge node into different preset sandboxes or directly accessing without putting it into a preset sandbox; The monitoring platform obtains a trained discrimination neural network; The monitoring platform inputs the access request sequence information corresponding to each edge node placed in a different preset sandbox, the feature space mapping information generated based on the access request sequence information, and the side-channel information generated in the preset sandbox into the discrimination neural network respectively, so as to obtain the discrimination information corresponding to each edge node; The monitoring platform determines whether to allow the edge node in the preset sandbox to access according to the discrimination information. If so, the edge node is accessed.

2. The edge node heterogeneous network access management method according to claim 1, characterized in that The access request sequence information includes a hardware fingerprint, an operating system entropy value, and a network manifold feature; The three-dimensional chaotic dynamic symbol mapping of the access request sequence information is performed in the following manner: The access request sequence information is converted into a binary string through UTF-8 encoding; An initial confusion layer is generated according to the binary string; The binary string in the initial confusion layer is segmented by every 3 bits and mapped to a custom symbol set, so as to generate a triple sequence; The arrangement order of the triple sequence is adjusted through chaotic mapping, so that the product of the Hamming distance and the edit distance between each adjacent triple in the triple sequence is maximized, thus forming the access request sequence information after three-dimensional chaotic dynamic symbol mapping.

3. The edge node heterogenous network access management method according to claim 2, wherein The process by which the monitoring platform generates a threat index corresponding to each edge node according to each decoded access request sequence information includes the following steps: The following processing is performed on each edge node: The monitoring platform generates feature space mapping information according to the decoded access request sequence information; The monitoring platform obtains a threat index according to the feature space mapping information; The process by which the monitoring platform generates feature space mapping information according to the decoded access request sequence information includes the following steps: The access request sequence information is mapped to a dynamic dimension space through the following formula, so as to obtain a three-dimensional feature space mapping: ; Among them, X is the access request sequence matrix; K is the number of mapping dimensions; W k is the weight matrix of the k-th mapping dimension; A k is the k-th non-linear coupling factor matrix, and the element values are generated by a chaotic sequence; P k is the k-th state transition probability matrix; ⊙ represents the Hadamard product.

4. The edge node heterogeneous network access management method according to claim 3, wherein, The process by which the monitoring platform obtains a threat index according to the feature space mapping information includes the following steps: A feature interaction vector flow and an edit distance matrix are obtained according to the feature space mapping information; A spatio-temporal threat potential function model is obtained; The feature interaction vector flow and the edit distance matrix are input into the spatio-temporal threat potential function model, so as to obtain a primary threat index; A feature matrix is obtained according to the access request sequence information; Hyper-spherical collapse transformation is performed according to the feature matrix, so as to obtain the transformed feature matrix; Obtain the transformed feature interaction vector stream according to the transformed feature matrix; Obtain the final threat index according to the transformed feature interaction vector stream and the edit distance matrix.

5. The edge node heterogeneous network access management method according to claim 4, characterized in that, The monitoring platform generates a sandbox adjustment strategy for the edge node according to the threat index corresponding to the edge node and a preset dynamic sandbox strategy, including: Obtain a preset threat level classification database, where the threat level classification database includes at least one threat index interval and the sandbox adjustment strategy corresponding to each threat index interval; Obtain the sandbox adjustment strategy corresponding to the threat index interval where the currently calculated final threat index is located.

6. The edge node heterogeneous network and heterogeneous platform access management method according to claim 5, wherein, The discrimination neural network includes: A multimodal heterogeneous input layer, which is used to receive the access request sequence information, feature space mapping information, and side-channel information, and generate a request sequence feature according to the access request sequence information, generate a dynamic topology structure feature map according to the feature space mapping information, and generate a side-channel feature according to the side-channel information; A feature fusion layer, which is used to fuse the request sequence feature, the dynamic topology structure feature map, and the side-channel feature to form a fusion feature; A chaotic hidden layer, which is used to generate a chaotic enhanced feature through an improved three-dimensional chaotic mapping activation function; An output layer, which outputs a three-dimensional confidence vector according to the chaotic enhanced feature.

7. The edge node heterogeneous network access management method according to claim 6, characterized in that, The generating of the request sequence feature according to the access request sequence information includes: Generate a request sequence matrix according to the access request sequence information, where the request sequence matrix includes time window information, feature type information, and chaotic mapping dimension information; Process the request sequence matrix through a three-dimensional chaotic attention mechanism to generate a request sequence feature; The generating of the dynamic topology structure feature map according to the feature space mapping information includes: Convert the three-dimensional feature space mapping information into a dynamic topology structure to obtain a topological adjacency matrix; Process the topological adjacency matrix through a graph convolution operation to generate a dynamic topology structure feature map.

8. The edge node heterogeneous network and heterogeneous platform access management method according to claim 7, characterized in that, The fusing of the request sequence feature, the dynamic topology structure feature map, and the side-channel feature to form a fusion feature includes: Perform normalization processing on the fusion of the request sequence feature, the dynamic topology structure feature map, and the side-channel feature respectively, so as to obtain the normalized request sequence feature, the normalized dynamic topology structure feature map, and the normalized side-channel feature fusion to form a fusion feature; Calculate the request sequence feature significant symbol of the normalized request sequence feature, the dynamic topology structure feature significant symbol of the normalized dynamic topology structure feature map, and the side-channel feature significant symbol of the normalized side-channel feature respectively; Generate a basic weight according to the request sequence feature significant symbol, the dynamic topology structure feature significant symbol, and the side-channel feature significant symbol; Generate a threat deviation adjustment factor according to the threat index; Generate a dynamic weight according to the threat deviation adjustment factor and the basic weight; Generate a final fusion feature according to the dynamic weight and the normalized request sequence feature, the normalized dynamic topology structure feature map, and the normalized side-channel feature fusion to form a fusion feature.

9. An access management system for an edge node heterogeneous network and heterogeneous platform, characterized in that, The edge node heterogeneous network and heterogeneous platform access management system includes at least one edge node and a monitoring platform, and each of the edge nodes and the monitoring platform cooperate to implement the edge node heterogeneous network and heterogeneous platform access management method according to any one of claims 1 to 8.

Citation Information

Patent Citations

  • Block chain smart contract generation method and device, and electronic equipment

    CN115268847A

  • Engineering design industry cloud data collaboration and storage method

    CN118118213A