Method and system for security assessment of cryptographic applications in IoT systems based on large models

By leveraging the collaborative work of IoT terminal devices, edge layer devices, and cloud devices, and utilizing a large model to process the feature values ​​of multimodal data from IoT terminal devices, the problem of low efficiency and insufficient accuracy in security assessment of cryptographic applications on IoT terminal devices is solved, achieving efficient and accurate security assessment results.

CN120217357BActive Publication Date: 2025-08-08HANGZHOU HIKVISION DIGITAL TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510671988.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-05-22
Publication Date
2025-08-08
Estimated Expiration
2045-05-22

AI Technical Summary

Technical Problem

Existing technologies cannot effectively assess the cryptographic security of IoT terminal devices. The assessment is inefficient and inaccurate, and it is impossible to accurately obtain the cryptographic security assessment results of IoT terminal devices.

Method used

This paper adopts a cryptographic security assessment method for IoT systems based on a large model. Through the collaborative work of IoT terminal devices, edge layer devices, and cloud devices, multimodal data is used to reduce the dimensionality of feature values, filter them, and select importance parameters. Combined with a large language model, a security assessment is performed to generate accurate cryptographic security assessment results.

Benefits of technology

It enables efficient cryptographic application security assessment of a large number of IoT terminal devices, improves assessment accuracy, reduces the impact on business systems, saves testing manpower, and ensures data security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120217357B_ABST
    Figure CN120217357B_ABST
Patent Text Reader

Abstract

The present application provides a method and system for evaluating the security of cryptographic applications in an Internet of Things system based on a large model, the method comprising: an Internet of Things terminal device acquires a data set and a first eigenvalue set; a dimensionality reduction operation is performed on the first eigenvalue in the first eigenvalue set to obtain a second eigenvalue set, and the second eigenvalue set is sent to an edge layer device; the edge layer device screens the second eigenvalue in the second eigenvalue set to obtain a third eigenvalue set; based on the importance parameter of each third eigenvalue in the third eigenvalue set, a portion of the third eigenvalue is selected from the third eigenvalue set to obtain a fourth eigenvalue set, and the fourth eigenvalue set is sent to a cloud device; the cloud device inputs the fourth eigenvalue set into the large model to obtain a cryptographic security evaluation result of the Internet of Things terminal device, and the cryptographic security evaluation result is that the cryptographic application is secure or the cryptographic application is insecure. The technical solution of the present application can improve the accuracy of cryptographic evaluation detection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of data security technology, and in particular to a method and system for security assessment of cryptographic applications in an Internet of Things system based on a large model. Background Art

[0002] With the rapid development of information technology, the cybersecurity landscape is becoming increasingly challenging. Various security threats, such as ransomware attacks and data leaks, are constantly emerging. Cryptography is a core technology and fundamental support for network security. Therefore, more standardized and regulated management and use of cryptography is crucial. A key approach to achieving this goal is through the use of cryptographic application security assessment technology.

[0003] Cryptographic application security assessment, also known as cryptographic review, is the evaluation of the compliance, correctness, and effectiveness of cryptographic applications in networks and information systems that utilize integrated cryptographic technologies, products, and services. This assessment is not only crucial for standardizing cryptographic applications but also plays an irreplaceable role in maintaining the cryptographic security of networks and information systems, effectively safeguarding network security.

[0004] However, with the rapid development of IoT technology, the number of IoT terminal devices has shown an exponential growth. The types, access methods and network protocols of these IoT terminal devices are diversified. There is no effective way to perform cryptographic application security assessment on these IoT terminal devices. In other words, it is impossible to accurately obtain the cryptographic security assessment results of IoT terminal devices, and there are problems such as low assessment efficiency. Summary of the Invention

[0005] This application provides a large-scale model-based method for evaluating the security of cryptographic applications in an IoT system. The IoT system includes IoT terminal devices, edge layer devices, and cloud devices. The method includes:

[0006] The IoT terminal device obtains a data set and a first eigenvalue set; the data set includes a plurality of multimodal data, and the multimodal data includes at least two types of cryptographic application data; the first eigenvalue set includes a first eigenvalue of each cryptographic application data; for each cryptographic application data, the data security parameter corresponding to the cryptographic application data is processed to obtain the first eigenvalue of the cryptographic application data;

[0007] The Internet of Things terminal device performs a dimensionality reduction operation on the first eigenvalue in the first eigenvalue set to obtain a second eigenvalue set, and sends the second eigenvalue set to the edge layer device;

[0008] The edge layer device filters the second feature values in the second feature value set to obtain a third feature value set; wherein, for each second feature value, if the second feature value does not match the configured security detection template, the second feature value is added to the third feature value set; or, the second feature value is input to the large language model, and the large language model determines whether to add the second feature value to the third feature value set; or, if the second feature value does not match the security detection template, the second feature value is input to the large language model, and the large language model determines whether to add the second feature value to the third feature value set;

[0009] The edge layer device selects some third eigenvalues from the third eigenvalue set based on the importance parameter of each third eigenvalue in the third eigenvalue set to obtain a fourth eigenvalue set, the fourth eigenvalue set including the selected third eigenvalues, and sends the fourth eigenvalue set to the cloud device;

[0010] The cloud device inputs the fourth eigenvalue set into the large model to obtain a password security assessment result of the Internet of Things terminal device, where the password security assessment result is that the password application is secure or the password application is insecure.

[0011] This application provides a large-model-based method for security assessment of cryptographic applications in an IoT system. The method is applied to edge layer devices in an IoT system. The method includes:

[0012] Obtaining a second eigenvalue set, where the second eigenvalue set is obtained by performing a dimensionality reduction operation on the first eigenvalue set by the IoT terminal device; the first eigenvalue set includes a first eigenvalue of the cryptographic application data, where the first eigenvalue is obtained by processing a data security parameter corresponding to the cryptographic application data;

[0013] The second feature values in the second feature value set are screened to obtain a third feature value set; wherein, for each second feature value, if the second feature value does not match the configured security detection template, the second feature value is added to the third feature value set; or, the second feature value is input to the large language model, and the large language model determines whether to add the second feature value to the third feature value set; or, if the second feature value does not match the security detection template, the second feature value is input to the large language model, and the large language model determines whether to add the second feature value to the third feature value set;

[0014] Based on the importance parameter of each third eigenvalue in the third eigenvalue set, some third eigenvalues are selected from the third eigenvalue set to obtain a fourth eigenvalue set, the fourth eigenvalue set includes the selected third eigenvalues, and the fourth eigenvalue set is sent to the cloud device so that the cloud device determines the password security assessment result of the Internet of Things terminal device based on the fourth eigenvalue set, wherein the password security assessment result is that the password application is secure or the password application is insecure.

[0015] The present application provides an Internet of Things system, which includes:

[0016] An IoT terminal device is configured to obtain a data set and a first eigenvalue set; the data set includes a plurality of multimodal data, and the multimodal data includes at least two types of cryptographic application data; the first eigenvalue set includes a first eigenvalue of each cryptographic application data; for each cryptographic application data, processing a data security parameter corresponding to the cryptographic application data to obtain the first eigenvalue of the cryptographic application data; and performing a dimensionality reduction operation on the first eigenvalue in the first eigenvalue set to obtain a second eigenvalue set, and sending the second eigenvalue set to an edge layer device;

[0017] An edge layer device, configured to filter the second feature values in the second feature value set to obtain a third feature value set; wherein, for each second feature value, if the second feature value does not match the configured security detection template, the second feature value is added to the third feature value set; or, the second feature value is input to the large language model, and the large language model is used to determine whether to add the second feature value to the third feature value set; or, if the second feature value does not match the security detection template, the second feature value is input to the large language model, and the large language model is used to determine whether to add the second feature value to the third feature value set; and, based on an importance parameter of each third feature value in the third feature value set, select some third feature values from the third feature value set to obtain a fourth feature value set, the fourth feature value set including the selected third feature values, and send the fourth feature value set to the cloud device;

[0018] The cloud device is used to input the fourth eigenvalue set into the large model to obtain a password security assessment result of the Internet of Things terminal device, where the password security assessment result is that the password application is secure or the password application is insecure.

[0019] The present application provides a computer program product, including a computer program, which, when executed by a processor, implements the above-mentioned large model-based Internet of Things system cryptographic application security assessment method.

[0020] The present application provides an electronic device, comprising: a processor and a machine-readable storage medium, wherein the machine-readable storage medium stores machine-executable instructions that can be executed by the processor; the processor is used to execute the machine-executable instructions to implement the above-mentioned large-model-based Internet of Things system cryptographic application security assessment method.

[0021] The present application provides a machine-readable storage medium, which stores machine-executable instructions that can be executed by a processor; wherein the processor is used to execute the machine-executable instructions to implement the above-mentioned large model-based Internet of Things system cryptographic application security assessment method.

[0022] It can be seen from the above technical solutions that in the embodiment of the present application, a cryptographic application security assessment method for the collaboration of IoT terminal devices, edge layer devices and cloud devices is proposed, and cryptographic application security assessment is realized based on the multimodal data of IoT terminal devices. It is capable of performing cryptographic application security assessment on a large number of IoT terminal devices, accurately obtaining the cryptographic security assessment results of IoT terminal devices, and having high assessment efficiency. It can improve the accuracy of cryptographic assessment detection, reduce the impact on business systems, and save detection human resources. What is transmitted between devices is the eigenvalue of multimodal data, rather than the original data, to avoid leakage of original data and ensure data security. By performing dimensionality reduction operations on the first eigenvalue set, screening the second eigenvalue set, and selecting part of the third eigenvalue of the third eigenvalue set, the amount of data transmission between devices can be reduced, and the most effective data can be selected to complete the cryptographic security assessment results, thereby ensuring the accuracy of the assessment results. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 This is a flowchart of a cryptographic application security assessment method for IoT systems based on a large model;

[0024] Figure 2 This is a flowchart of a cryptographic application security assessment method for IoT systems based on a large model;

[0025] Figure 3 This is a schematic structural diagram of an Internet of Things system in one embodiment of the present application;

[0026] Figure 4 It is a structural diagram of a cryptographic application security assessment device for an Internet of Things system based on a large model;

[0027] Figure 5 It is a hardware structure diagram of an electronic device in one embodiment of the present application. DETAILED DESCRIPTION

[0028] In the embodiment of the present application, a large model-based cryptographic application security assessment method for an Internet of Things system is proposed, which can be applied to an Internet of Things system. The Internet of Things system can include an Internet of Things terminal device, an edge layer device, and a cloud device. Figure 1 FIG. 5 is a flow chart of the method, which may include:

[0029] Step 101: An IoT terminal device obtains a data set and a first eigenvalue set. The data set includes multiple multimodal data, and the multimodal data includes at least two types of cryptographic application data. The first eigenvalue set includes a first eigenvalue for each cryptographic application data item. For each cryptographic application data item, the data security parameter corresponding to the cryptographic application data item is processed to obtain the first eigenvalue for the cryptographic application data item.

[0030] Step 102: The IoT terminal device performs a dimensionality reduction operation on the first eigenvalue in the first eigenvalue set to obtain a second eigenvalue set, and sends the second eigenvalue set to the edge layer device.

[0031] Step 103: The edge layer device filters the second feature values in the second feature value set to obtain a third feature value set. For each second feature value, if the second feature value does not match the configured security detection template, the second feature value is added to the third feature value set; or, the second feature value is input into the large language model, which determines whether to add the second feature value to the third feature value set; or, if the second feature value does not match the security detection template, the second feature value is input into the large language model, which determines whether to add the second feature value to the third feature value set.

[0032] Step 104: The edge layer device selects some third eigenvalues from the third eigenvalue set based on the importance parameter of each third eigenvalue in the third eigenvalue set to obtain a fourth eigenvalue set, where the fourth eigenvalue set includes the selected third eigenvalues, and sends the fourth eigenvalue set to the cloud device.

[0033] Step 105: The cloud device inputs the fourth eigenvalue set into the large model to obtain a password security assessment result of the IoT terminal device. The password security assessment result is that the password application is secure or the password application is insecure.

[0034] Exemplarily, for each multimodal data, the multimodal data includes but is not limited to at least two of the following types of cryptographic application data: cryptographic algorithm call chain data, the cryptographic algorithm call chain data includes security operation information generated when at least one security algorithm is used to perform security operations on the processed data; wherein, based on the cryptographic algorithm call chain data, a data security parameter corresponding to at least one security algorithm is obtained, and the data security parameter is quantified to obtain a first eigenvalue of the cryptographic algorithm call chain data.

[0035] A critical path behavior log includes operation information generated when operating a critical path; wherein, multiple critical path behavior logs are screened for abnormal behavior to obtain a critical path behavior log with abnormal behavior, data security parameters are obtained based on the critical path behavior log, and the data security parameters are quantified to obtain a first characteristic value of the critical path behavior log.

[0036] Encrypted traffic; wherein, multiple encrypted traffics are classified and processed to obtain encrypted traffic that matches the configured address information, data security parameters are obtained based on the encrypted traffic, and the data security parameters are quantified to obtain a first characteristic value of the encrypted traffic; wherein, for the encrypted traffic sent by this IoT terminal device to other devices, it is determined whether the destination address matches the address information; for the encrypted traffic sent by other devices to this IoT terminal device, it is determined whether the source address matches the address information.

[0037] Physical layer operation data, physical layer operation data includes key device operation data generated during the operation of IoT terminal devices; wherein, the physical layer operation data is subjected to fast Fourier transform to obtain power consumption curves of multiple frequency bands; data security parameters are obtained based on the power consumption curve of each frequency band, and the data security parameters are quantified to obtain the first eigenvalue of the physical layer operation data.

[0038] Exemplarily, the edge layer device filters the second feature values within the second feature value set to obtain a third feature value set, which may include, but is not limited to: for each second feature value, the edge layer device obtains attribute information and data security parameters corresponding to the second feature value; if the second feature value corresponds to cryptographic algorithm call chain data, the attribute information is the data type of the data to be processed; if the second feature value corresponds to a critical path behavior log, the attribute information is path information of the critical path; if the second feature value corresponds to encrypted traffic, the attribute information is the destination IP address or source IP address of the encrypted traffic; if the second feature value corresponds to physical layer operation data, the attribute information is the unique device identifier of the IoT terminal device. If the attribute information is inconsistent with the attribute field of the security detection template, it is determined that the second feature value does not match the security detection template; if the attribute information is consistent with the attribute field of the security detection template and the data security parameter does not match the standard field of the security detection template, it is determined that the second feature value does not match the security detection template; if the attribute information is consistent with the attribute field of the security detection template and the data security parameter matches the standard field of the security detection template, it is determined that the second feature value matches the security detection template. Among them, if the data security parameter is consistent with the standard field of the security detection template, then the data security parameter matches the standard field of the security detection template; or, if the data security parameter is inconsistent with the standard field of the security detection template, and the first security level corresponding to the data security parameter is not less than the second security level corresponding to the standard field of the security detection template, then the data security parameter matches the standard field of the security detection template; if the first security level is less than the second security level, the data security parameter does not match the standard field of the security detection template.

[0039] Exemplarily, the edge layer device filters the second feature values within the second feature value set to obtain a third feature value set, which may include, but is not limited to: for each second feature value, obtaining the type of cryptographic application data corresponding to the second feature value and obtaining a reference prompt word corresponding to the type; wherein the reference prompt word may indicate that the second feature value corresponds to cryptographic algorithm call chain data, or the second feature value corresponds to a critical path behavior log, or the second feature value corresponds to encrypted traffic, or the second feature value corresponds to physical layer operation data. The reference prompt word and the second feature value are then input into a large language model; the large language model selects a target security detection template corresponding to the reference prompt word from all configured security detection templates, and determines the template feature value corresponding to the target security detection template. The large language model calculates the similarity between the second feature value and each template feature value; if any similarity is greater than a threshold, the second feature value may be determined not to be added to the third feature value set; if all similarities are less than the threshold, the second feature value may be determined to be added to the third feature value set.

[0040] Exemplarily, the importance parameter includes a contribution parameter value and a similarity parameter value; the edge layer device selects some third eigenvalues from the third eigenvalue set based on the importance parameter of each third eigenvalue in the third eigenvalue set to obtain a fourth eigenvalue set, which may include but is not limited to: for each third eigenvalue in the third eigenvalue set, using a local sensitive hashing algorithm to determine the contribution parameter value of the third eigenvalue; sorting all third eigenvalues in order from large to small based on the contribution parameter value; based on the sorting result, selecting the top K third eigenvalues; for each selected third eigenvalue, calculating the similarity parameter value between the third eigenvalue and each eigenvalue in the LRU queue; if any similarity parameter value is not less than the similarity threshold, it is prohibited to add the third eigenvalue to the fourth eigenvalue set; if all similarity parameter values are less than the similarity threshold, the third eigenvalue is added to the fourth eigenvalue set and the third eigenvalue is stored in the LRU queue. After storing the third eigenvalue in the LRU queue, if the number of eigenvalues in the LRU queue is not greater than the number threshold, the LRU queue is kept unchanged; if the number of eigenvalues in the LRU queue is greater than the number threshold, the first eigenvalue in the LRU queue is deleted.

[0041] Exemplarily, the large model may include a first feature extraction network and a cryptographic security knowledge graph. The first feature extraction network is used to extract feature vectors of binary modal data. The cryptographic security knowledge graph includes multiple nodes, each corresponding to a graph feature vector and cryptographic security assessment information, wherein the cryptographic security assessment information indicates whether the cryptographic application is secure or insecure. The cloud device inputs the fourth eigenvalue set into the large model to obtain a cryptographic security assessment result for the IoT terminal device. This may include, but is not limited to: inputting the fourth eigenvalue set into the first feature extraction network, extracting a first device feature vector corresponding to the fourth eigenvalue set through the first feature extraction network; calculating the similarity between the first device feature vector and the graph feature vector of each node through the large model; and selecting a first target node from the cryptographic security knowledge graph based on the similarity.

[0042] If the cryptographic security assessment information of the first target node indicates that the cryptographic application is secure, then the cryptographic security assessment result of the Internet of Things terminal device is determined to be that the cryptographic application is secure; if the cryptographic security assessment information of the first target node indicates that the cryptographic application is insecure, then the cryptographic security assessment result of the Internet of Things terminal device is determined to be that the cryptographic application is insecure, and a first penetration path is obtained based on the position of the first target node in the cryptographic security knowledge graph. The first penetration path includes the first target node and a node that has a causal dependency relationship with the first target node; based on the first penetration path, the cause of the insecure cryptographic application and the cryptographic application repair suggestion are determined.

[0043] Exemplarily, if the cryptographic security assessment information of the first target node indicates that the cryptographic application is insecure, the cloud device can send a data request message to the edge layer device, so that the edge layer device obtains multimodal data from the IoT terminal device; the cloud device receives a data response message returned by the edge layer device, and the data response message includes the multimodal data. The cloud device generates text modal data, image modal data, and time series modal data based on the multimodal data; if the multimodal data includes cryptographic algorithm call chain data, the text modal data includes the cryptographic algorithm call chain data; if the multimodal data includes critical path behavior logs, the text modal data includes critical path behavior logs; if the multimodal data includes encrypted traffic and there is text data in the encrypted traffic, the text modal data includes text data; if there is image data in the encrypted traffic, the image modal data includes image data; if the multimodal data includes physical layer operation data, the image modal data includes physical layer operation data; wherein, the time series modal data is generated based on the time series information corresponding to the multimodal data. The fourth eigenvalue set is input into the first feature extraction network of the large model to obtain a first eigenvector; text modal data is input into the second feature extraction network of the large model to obtain a second eigenvector; image modal data is input into the third feature extraction network of the large model to obtain a third eigenvector; and time series modal data is input into the fourth feature extraction network of the large model to obtain a fourth eigenvector; the first, second, third, and fourth eigenvectors are fused to obtain a second device eigenvector. The large model is used to calculate the similarity between the second device eigenvector and the graph eigenvectors of each node; based on the similarity, a second target node is selected from the cryptographic security knowledge graph. If the cryptographic security assessment information of the second target node indicates an insecure cryptographic application, the cryptographic security assessment result for the IoT terminal device is determined to be an insecure cryptographic application. Based on the position of the second target node in the cryptographic security knowledge graph, a second penetration path is obtained. Based on the second penetration path, the cause of the insecure cryptographic application and recommendations for remediating the cryptographic application are determined.

[0044] For example, after determining the reasons for insecure password application and password application repair suggestions based on the first penetration path, a password compliance policy can also be generated based on the reasons for insecure password application and the password application repair suggestions; the password compliance policy can be deployed in the sandbox environment of the cloud device to run the password compliance policy in the sandbox environment to perform security operations on the data. On this basis, the reward value corresponding to the password compliance policy can be determined based on the security gain, system efficiency, and operating cost corresponding to the password compliance policy; wherein the security gain can represent the degree of compliance of the password compliance policy with the preset rules, the system efficiency can represent the change in service delay after the password compliance policy is executed, and the operating cost can represent the number of device connection interruptions after the password compliance policy is executed; if the reward value is greater than the threshold, the password compliance policy is deployed to the IoT terminal device; if the reward value is not greater than the threshold, the password compliance policy is prohibited from being deployed to the IoT terminal device.

[0045] It can be seen from the above technical solutions that in the embodiment of the present application, a cryptographic application security assessment method for the collaboration of IoT terminal devices, edge layer devices and cloud devices is proposed, and cryptographic application security assessment is realized based on the multimodal data of IoT terminal devices. It is capable of performing cryptographic application security assessment on a large number of IoT terminal devices, accurately obtaining the cryptographic security assessment results of IoT terminal devices, and having high assessment efficiency. It can improve the accuracy of cryptographic assessment detection, reduce the impact on business systems, and save detection human resources. What is transmitted between devices is the eigenvalue of multimodal data, rather than the original data, to avoid leakage of original data and ensure data security. By performing dimensionality reduction operations on the first eigenvalue set, screening the second eigenvalue set, and selecting part of the third eigenvalue of the third eigenvalue set, the amount of data transmission between devices can be reduced, and the most effective data can be selected to complete the cryptographic security assessment results, thereby ensuring the accuracy of the assessment results.

[0046] In the embodiment of this application, a large model-based Internet of Things system cryptographic application security assessment method is proposed, which is applied to edge layer devices. Figure 2 FIG. 5 is a flow chart of the method, which may include:

[0047] Step 201: Obtain a second eigenvalue set, where the second eigenvalue set is obtained by performing a dimensionality reduction operation on the first eigenvalue set by the IoT terminal device; the first eigenvalue set includes a first eigenvalue of the cryptographic application data, where the first eigenvalue is obtained by processing a data security parameter corresponding to the cryptographic application data.

[0048] Step 202: Filter the second feature values in the second feature value set to obtain a third feature value set; wherein, for each second feature value, if the second feature value does not match the configured security detection template, then add the second feature value to the third feature value set; or, input the second feature value to the large language model, and determine whether to add the second feature value to the third feature value set through the large language model; or, if the second feature value does not match the security detection template, input the second feature value to the large language model, and determine whether to add the second feature value to the third feature value set through the large language model.

[0049] Step 203: Based on the importance parameter of each third eigenvalue in the third eigenvalue set, select some third eigenvalues from the third eigenvalue set to obtain a fourth eigenvalue set, which may include the selected third eigenvalues, and send the fourth eigenvalue set to the cloud device so that the cloud device determines the password security assessment result of the Internet of Things terminal device based on the fourth eigenvalue set, wherein the password security assessment result may be that the password application is secure or the password application is insecure.

[0050] The above technical solutions of the embodiments of the present application are described below in conjunction with specific application scenarios.

[0051] In the embodiments of this application, a method for assessing the security of cryptographic applications in an IoT system based on a large model is proposed. A large model (artificial intelligence large model) refers to a "large parameter" model trained using large-scale data and powerful computing power. Large models are highly versatile and generalizable, and can be applied to fields such as natural language processing, image recognition, and speech recognition. They can be divided into large language models, large visual models, multimodal large models, and basic large models. The IoT system is a network system that connects various physical devices, sensors, software, and other technologies via the internet, enabling them to communicate and exchange data. Cryptographic application security assessment, referred to as cryptographic evaluation, refers to the activity of testing, analyzing, evaluating, and verifying the compliance, correctness, and effectiveness of cryptographic technologies, products, and services used in networks and information systems in accordance with laws, regulations, and standards.

[0052] In the embodiments of the present application, an intelligent detection architecture is proposed that collaborates with IoT terminal devices, edge layer devices, and cloud devices to achieve multimodal data analysis, heterogeneous device adaptation, edge layer device detection reasoning, etc., which can improve the accuracy of confidentiality assessment detection, reduce the impact on business systems, and save detection human resources.

[0053] This system enables security assessment of cryptographic applications by constructing a multimodal cryptographic security knowledge graph. It enables semantic alignment and contextual analysis of cryptographic protocol text, device logs, and network traffic. Through a dynamic prompt fine-tuning mechanism, combined with lightweight model distillation for edge devices and cloud-based causal reasoning, it enables security risk detection and root cause location in low-sample scenarios. It dynamically generates cryptographic compliance policies based on reinforcement learning, distributes them to IoT endpoints in real time to implement reinforcement actions, and updates and optimizes lightweight model parameters for edge devices. This significantly improves the compliance detection coverage and efficiency of cryptographic applications in IoT systems.

[0054] For example, see Figure 3 Figure 2 shows a schematic diagram of the IoT system architecture, which can include IoT terminal devices, edge layer devices, and cloud devices. For IoT terminal devices, the process involves multimodal data collection, feature encoding, and uploading structured feature vectors. For edge layer devices, the process involves lightweight model distillation, dynamic prompt fine-tuning, feature distillation, data compression, and model hot updates. For cloud devices, the process involves multimodal semantic modeling, security risk chain tracing, and dynamic orchestration policy reinforcement. The following describes the processing for IoT terminal devices, edge layer devices, and cloud devices.

[0055] First, the processing process for IoT terminal devices.

[0056] 1. Multimodal Data Collection. During the multimodal data collection process, a data set may be acquired. The data set includes multiple multimodal data (multimodal data refers to multiple types of cryptographic application data). Each multimodal data set may include at least two types of cryptographic application data.

[0057] For example, for each multimodal data, the multimodal data may include, but is not limited to, at least two of the following types of cryptographic application data (taking the example of including all four types of cryptographic application data):

[0058] Cryptographic algorithm call chain data, the cryptographic algorithm call chain data includes security operation information generated when at least one security algorithm is used to perform security operations on the data to be processed, that is, information related to the security operation.

[0059] For example, cryptographic algorithm call chain data can be collected from the network security library, data security library, and cryptographic algorithm library in IoT terminal devices. This cryptographic algorithm call chain data may include, but is not limited to, API call sequences, function buffer addresses, interface parameter status, callers and call frequency, entropy source pool status, and execution error messages. There are no restrictions on the content of this cryptographic algorithm call chain data. For example, the network security library, data security library, and cryptographic algorithm library are related to security algorithms. Cryptographic algorithm call chain data can be automatically collected through system call hooks, and there are no restrictions on the collection method.

[0060] Critical path behavior logs can include operational information generated when performing operations on critical paths. For example, operations on critical paths generate operational information, which can be recorded in the critical path behavior log. For example, critical paths can include, but are not limited to, system call execution paths, core program execution paths, and key storage paths. These paths can also be directories on IoT terminal devices. Operations on critical paths can include, but are not limited to, adding, deleting, modifying, and querying critical paths.

[0061] For example, when performing a modification operation on the core program running path, that is, performing a modification operation on the core program of the core program running path, the operation information of the modification operation can be recorded in the critical path behavior log, such as the operation time, operation object (such as the core program), operator, operation content, etc.

[0062] For example, the inotify kernel module can be used to capture path operation events, obtain critical path operation information, and record the critical path operation information in the critical path behavior log.

[0063] Encrypted traffic (or unencrypted traffic, also known as regular traffic) can be encrypted traffic sent from the IoT terminal device to other devices, or from other devices to the IoT terminal device. Encrypted traffic is the traffic between the IoT terminal device and other devices, and can be TLS (Transport Layer Security) or DTLS (Datagram Transport Layer Security) packets using encryption algorithms. Encrypted traffic can be obtained by mirroring ports or using the kernel module Netfilter.

[0064] Physical layer operation data (i.e., physical layer signals) can include key device operation data generated during the operation of IoT terminal devices. For example, physical layer operation data may include, but is not limited to, intra-cycle power consumption fluctuation graphs, intra-cycle side channel data, and physical interface call data. This data can be used to analyze device attack scenarios and algorithm security risks. For example, an intra-cycle power consumption fluctuation graph (a graph of time and power consumption fluctuations) can reflect power consumption fluctuations of IoT terminal devices at various times, intra-cycle side channel data (a graph of time and side channel) can reflect the side channels of IoT terminal devices at various times, and physical interface call data (a graph of time and interface call) can reflect the interface calls of IoT terminal devices at various times (such as the number of interface calls at that time).

[0065] For example, physical layer operation data can be collected in kernel mode or user mode, with no restrictions on the collection method. When collecting physical layer operation data, the collected signal can also be processed to obtain physical layer operation data. For example, a physical layer signal can be collected, sampled by an ADC, and then power consumption characteristics can be extracted through wavelet transform. This can then be used to obtain the power consumption fluctuations of IoT terminal devices at various times, thereby generating a power consumption fluctuation chart within a cycle.

[0066] 2. Feature Encoding. During the feature encoding process, a first feature value set can be obtained. This first feature value set includes the first feature value of each cryptographic application data. For each cryptographic application data, the data security parameter corresponding to the cryptographic application data is processed to obtain the first feature value of the cryptographic application data.

[0067] In a possible implementation, the feature encoding process may include the following steps:

[0068] Step S11: Data preprocessing and multimodal data alignment.

[0069] For data preprocessing, each cryptographic application data point in the dataset is timestamped (e.g., hardware-level timestamp) to indicate the time it was collected. Timestamping each cryptographic application data point ensures temporal consistency across modal events.

[0070] For multimodal data alignment, multimodal data can be divided into fixed time windows (such as 1s, 2s, etc.). Based on the timestamp of each cryptographic application data item, all cryptographic application data corresponding to the same time window can be determined. This data is referred to as the multimodal data for that time window. For example, for a time window from second 0 to second 1 (1-2, 2-3, etc.), the multimodal data includes cryptographic algorithm call chain data (such as multiple cryptographic algorithm call chain data) collected during that time window, critical path behavior logs collected during that time window, encrypted traffic collected during that time window, and physical layer operation data collected during that time window.

[0071] Step S12: Extract key features of multimodal data.

[0072] Regarding the cryptographic algorithm call chain data (e.g., each cryptographic algorithm call chain data) in the multimodal data, since the cryptographic algorithm call chain data is the security operation information generated when a security algorithm is used to perform security operations on the processing data, the data security parameters corresponding to the security algorithm can be obtained based on the cryptographic algorithm call chain data (e.g., the security operation information). Data security parameters are the parameters used when the security algorithm is used to perform security operations on the processing data. For example, data security parameters may include key generation parameters, identity authentication parameters, permission authentication parameters, data key decryption parameters, data encryption and decryption parameters, data signature operation parameters, secure memory operation function call parameters, algorithm library protection parameters, etc.

[0073] After obtaining the data security parameter, the data security parameter can be quantized to obtain a fixed-length characteristic value (such as an 8-bit integer characteristic value or a 16-bit integer characteristic value), and this fixed-length characteristic value is used as the first characteristic value of the cryptographic algorithm call chain data.

[0074] In summary, for cryptographic algorithm call chain data, the data security parameter, first characteristic value, and attribute information corresponding to the cryptographic algorithm call chain data can be obtained. The attribute information can be the data type of the data to be processed. For example, if the data to be processed is an ID card number, the attribute information can be the ID card type; if the data to be processed is a bank card number, the attribute information can be the bank card type.

[0075] For critical path behavior logs in multimodal data (e.g., multiple critical path behavior logs within a time window), abnormal behavior screening is performed on the multiple critical path behavior logs to obtain critical path behavior logs with abnormal behavior. For each critical path behavior log, if it is determined based on the critical path behavior log that the operation on the critical path was performed during non-working hours, frequently performed within a period, or performed without authorization, then the critical path behavior log is determined to be a critical path behavior log with abnormal behavior.

[0076] After filtering out critical path behavior logs that contain abnormal behavior, and since these logs contain operation information generated when performing operations on the critical path, data security parameters can be obtained based on these logs (e.g., operation information specific to the critical path). For example, data security parameters include the operation object (e.g., system call execution path, core program execution path, key storage path), operation type (e.g., add, delete, modify, query), and the number of operations.

[0077] After obtaining the data security parameter, the data security parameter can be quantized to obtain a fixed-length feature value (such as an 8-bit integer feature value or a 16-bit integer feature value), and this fixed-length feature value can be used as the first feature value of the critical path behavior log.

[0078] To sum up, for the critical path behavior log with abnormal behavior, the data security parameters, first characteristic values and attribute information corresponding to the critical path behavior log can be obtained. The attribute information can be the path information of the critical path, such as the directory where the critical path is located (such as the directory name, etc.).

[0079] For encrypted traffic in multimodal data (e.g., multiple encrypted traffic flows within a time window), the system classifies and processes the encrypted traffic flows to obtain traffic flows that match the configured address information (e.g., IP address and / or port number; the address information to be filtered can be pre-configured). For example, for each encrypted traffic flow, if the encrypted traffic flow is sent from the IoT terminal device to another device, the system determines whether the destination address (e.g., destination IP address and / or destination port number) of the encrypted traffic flows matches the address information. If the encrypted traffic flow is sent from another device to the IoT terminal device, the system determines whether the source address (e.g., destination IP address and / or source port number) of the encrypted traffic flows matches the address information. Based on this, the system can filter out encrypted traffic flows that match the address information from all encrypted traffic flows.

[0080] After filtering out encrypted traffic matching the address information, data security parameters can be obtained based on the encrypted traffic. These data security parameters are information related to the encrypted traffic. For example, data security parameters can include the encrypted traffic length, traffic type, network protocol information (such as protocol version), source address, destination address, TLS / DTLS algorithm type, TLS / DTLS version information, algorithm suite information, protocol handshake type, certificate extensions, session context, etc.

[0081] After obtaining the data security parameter, the data security parameter can also be quantized to obtain a fixed-length characteristic value (such as an 8-bit integer length characteristic value or a 16-bit integer length characteristic value), and this fixed-length characteristic value can be used as the first characteristic value of the encrypted traffic.

[0082] In summary, for encrypted traffic matching this address information, the corresponding data security parameters, first characteristic value, and attribute information can be obtained. For encrypted traffic sent by this IoT terminal device to other devices, this attribute information is the destination IP address of the encrypted traffic; for encrypted traffic sent by other devices to this IoT terminal device, this attribute information is the source IP address of the encrypted traffic.

[0083] For physical layer operation data in multimodal data, such as intra-cycle power consumption fluctuation graphs, intra-cycle side channel data, and physical interface call data, a fast Fourier transform can be performed on the physical layer operation data (such as the intra-cycle power consumption fluctuation graph) to obtain power consumption curves for multiple frequency bands. These power consumption curves are used to represent the energy contribution of each frequency band. For example, a fast Fourier transform can be performed on the physical layer operation data to obtain power consumption curves for the 10MHz band (used to represent the energy contribution of the 10MHz band), the 20MHz band, the 30MHz band, the 40MHz band, and the 50MHz band.

[0084] Data security parameters can be obtained based on the power consumption curve of each frequency band. For example, by using a moving average filter, Hamming weight information 1 of the power consumption curve of the 10MHz frequency band, Hamming weight information 2 of the power consumption curve of the 20MHz frequency band, Hamming weight information 3 of the power consumption curve of the 30MHz frequency band, Hamming weight information 4 of the power consumption curve of the 40MHz frequency band, and Hamming weight information 5 of the power consumption curve of the 50MHz frequency band can be calculated. Based on this, the data security parameters can include Hamming weight information 1, Hamming weight information 2, Hamming weight information 3, Hamming weight information 4, and Hamming weight information 5.

[0085] After obtaining the data security parameters, the data security parameters can be quantized to obtain a fixed-length characteristic value (such as an 8-bit integer length characteristic value or a 16-bit integer length characteristic value), and this fixed-length characteristic value can be used as the first characteristic value of the physical layer operation data.

[0086] To sum up, for the physical layer operation data, the data security parameters, first characteristic value and attribute information corresponding to the physical layer operation data can be obtained. The attribute information is the unique device identifier of the Internet of Things terminal device.

[0087] Step S13: feature dimensionality reduction and structured coding.

[0088] Exemplarily, for each time window, the first eigenvalue set of the time window can be obtained based on the multimodal data of the time window. The first eigenvalue set includes the first eigenvalue of the cryptographic algorithm call chain data, the first eigenvalue of the critical path behavior log, the first eigenvalue of the encrypted traffic, and the first eigenvalue of the physical layer operation data. On this basis, the first eigenvalue set can be subjected to feature dimensionality reduction, such as performing a dimensionality reduction operation on the first eigenvalue in the first eigenvalue set to obtain a second eigenvalue set. For example, a low-rank matrix decomposition operation can be performed on the first eigenvalue set to obtain the second eigenvalue set. The low-rank matrix decomposition is used to perform a dimensionality reduction operation on the first eigenvalue in the first eigenvalue set.

[0089] For example, cloud devices can pre-train a PCA (Principal Components Analysis) model. This model can calculate the covariance matrix using a large amount of sample data (e.g., 100,000 samples) and retain the top 20 principal components. The cloud device can then send the PCA model to the IoT terminal device, which then deploys the model. For example, the IoT terminal device can save the PCA projection matrix (e.g., 20*100) to Flash memory. This allows the IoT terminal device to execute the PCA model, performing only matrix multiplication, thus reducing resource consumption.

[0090] On this basis, after obtaining the first eigenvalue set, the IoT terminal device can use the PCA model to perform a low-rank matrix decomposition operation on the first eigenvalue set to obtain a second eigenvalue set. The second eigenvalue set can include some eigenvalues in the first eigenvalue set, such as the first 20 principal components.

[0091] Exemplarily, after obtaining the second eigenvalue set, the structured feature vector uploading process is performed based on the second eigenvalue set. Alternatively, the second eigenvalue set is structured encoded to obtain a structured encoded second eigenvalue set, and the structured feature vector uploading process is performed based on the second eigenvalue set.

[0092] For example, performing structured encoding on the second eigenvalue set means performing hash map compression on the second eigenvalue set to complete the structured encoding of the second eigenvalue set. For example, during the hash map compression process, an SM3 algorithm may be used to generate a hash value for a high information entropy field (such as a certificate public key), and the last 8 bits or the last 16 bits may be truncated as a compression identifier.

[0093] In summary, multimodal data can be converted into low-dimensional, structured first eigenvalues, thus avoiding the need to transmit the multimodal data itself and ensuring data security. Furthermore, the first eigenvalues retain security-critical information, enabling cryptographic application security assessments based on the first eigenvalues. Furthermore, by performing a low-rank matrix decomposition operation on the first eigenvalue set to generate the second eigenvalue set, the amount of data transmitted is reduced.

[0094] 3. Upload the structured feature vector. During the upload process, a structured feature vector of fixed length (e.g., 100 dimensions) can be generated and encapsulated in the TLV format.

[0095] For example, the structured feature vector may include each second eigenvalue within the second eigenvalue set. For each second eigenvalue, the structured feature vector may also include the data security parameter corresponding to the second eigenvalue and the attribute information corresponding to the second eigenvalue. For example, the first eigenvalue corresponding to the second eigenvalue may be determined, and then the data security parameter and attribute information corresponding to the first eigenvalue may be determined.

[0096] For example, each second characteristic value corresponds to a TLV format, the type field is the attribute information corresponding to the second characteristic value, the length field is the length value of the value field, and the value field can be two information, the first information is the data security parameter corresponding to the second characteristic value, and the second information is the second characteristic value.

[0097] In summary, the IoT terminal device can obtain the second eigenvalue set and send the second eigenvalue set to the edge layer device, which then processes the second eigenvalue set based on the second eigenvalue set.

[0098] Second, the processing process for edge layer devices.

[0099] 1. Lightweight model distillation. During the lightweight model distillation process, edge devices can acquire and deploy a large language model (LLM), also known as a lightweight large language model. The LLM is a highly efficient detection model distilled from the cloud device's large model, used for efficient threat identification. For example, edge devices can be equipped with GPU / NPU acceleration, support INT8 quantized inference, and have a peak computing power of ≥50 TOPS. In this operating environment, the LLM can be run and used to perform related processing.

[0100] For example, edge devices can add trainable hint vectors (e.g., tokens ≤ 32 in length) to the input layer of a large language model. These hint tokens can be used to augment the input text in free form or as prefixes. They are then concatenated with the original input through an attention mechanism to solve specific downstream tasks. Edge devices synchronize the latest samples (e.g., ≤ 100) from cloud devices at a fixed interval (e.g., every 7 days). Based on these samples, they perform low-rank adaptation and fine-tuning on the large language model, updating a small number of model parameters.

[0101] For example, cloud devices use a knowledge distillation architecture to generate detection logic knowledge, then train a large language model and send it to edge devices. The edge devices optimize the large language model, aligning the output distribution of the teacher model using the KL divergence loss function. The edge devices convert the FP32 model to INT8 precision, retaining the statistics of the calibration set (1000 samples). Based on gradient magnitude evaluation, neurons with a contribution of less than 5% in the attention head can be removed, compressing the size of the large language model.

[0102] 2. Model hot update. During the model hot update and collaborative learning process, an incremental update mechanism can be used. The cloud device compresses the model parameter difference (i.e., the parameter difference between the latest large language model and the deployed large language model) into a binary package no larger than a threshold (e.g., 10MB). Edge-layer devices can maintain update area A and update area B. When the model is updated, the new model (i.e., the new model is effective based on the model parameter difference and the deployed large language model) is loaded into the free memory area (e.g., when update area A stores the deployed large language model, the free memory area is update area B). After passing security verification such as digital signature and version size, the traffic is smoothly switched to the new model, that is, the large language model in update area B is used for processing. If the verification fails, switching to the new model is not allowed, and the large language model in update area A is still used for processing.

[0103] Edge-layer devices and cloud-based devices can collaborate on federated learning. Each edge-layer device processes data in parallel, aggregating de-privatized local data over a fixed period (e.g., seven days) to train and fine-tune a large language model. This data generates parameter gradients for the large language model and sends them to the cloud-based device. The cloud-based device aggregates the parameter gradients of each edge-layer device (e.g., by securely aggregating the parameter gradients of multiple edge-layer devices to ensure privacy is not leaked), updates the large language model based on the parameter gradients of each edge-layer device, and sends the updated large language model to each edge-layer device.

[0104] 3. Dynamic prompt fine-tuning. During the dynamic prompt fine-tuning process, the edge layer device can filter the second eigenvalues in the second eigenvalue set to obtain a third eigenvalue set. For example, for each second eigenvalue, if it is determined that the second eigenvalue does not pose a security risk, the second eigenvalue is not added to the third eigenvalue set. If it is determined that the second eigenvalue does pose a security risk, the second eigenvalue is added to the third eigenvalue set. For example, the third eigenvalue set can be obtained in the following manner:

[0105] Method a: For each second feature value in the second feature value set, if the second feature value does not match the configured security detection template, it is determined that the second feature value presents a security risk and the second feature value is added to the third feature value set. If the second feature value matches the configured security detection template, it is determined that the second feature value does not present a security risk and the second feature value is not added to the third feature value set.

[0106] For example, multiple security detection templates (such as a cryptographic application security assessment detection template) can be pre-configured. These security detection templates are used to screen feature values that do not present security risks. Specifically, when a second feature value matches a security detection template, it indicates that the second feature value does not present a security risk. For example, through domain knowledge base injection, multiple (e.g., 1,000 or more) security detection templates can be pre-configured. These security detection templates cover aspects such as network and communication security, device and computing security, and application and data security. This embodiment does not impose any restrictions on these security detection templates, and multiple security detection templates can be configured based on actual needs.

[0107] Exemplarily, a security detection template may include attribute fields and standard fields. In addition to the attribute fields and standard fields, other fields may also be included, and the content of the security detection template is not limited. For example, an example of a security detection template may be: Verify whether XXX of the content to be detected conforms to YYY, where XXX represents the attribute field of the security detection template and YYY represents the standard field of the security detection template.

[0108] For example, multiple security detection templates can be configured for cryptographic algorithm call chain data. For each security detection template, the attribute field of the security detection template can be a data type, such as ID card type, bank card type, etc. The standard fields of the security detection template can be data security parameters, such as key generation parameters, identity authentication parameters, permission authentication parameters, data key decryption parameters, data encryption and decryption parameters, data signature operation parameters, secure memory operation function call parameters, algorithm library protection parameters, etc.

[0109] For example, multiple security detection templates can be configured for critical path behavior logs. For each security detection template, the attribute field can include path information, such as Directory A and Directory B. The standard fields of the security detection template can include data security parameters, such as the operation object (e.g., system call execution path, core program execution path, key storage path), operation type (e.g., add, delete, modify, query), and operation count. For example, standard fields might include: 3 system call execution path query operations, 5 core program execution path query operations, 2 key storage path modification operations, 3 key storage path query operations, etc.

[0110] For example, multiple security detection templates can be configured for encrypted traffic. For each security detection template, the attribute field of the security detection template can be an IP address. The standard fields of the security detection template can be data security parameters such as traffic length, traffic type, network protocol information, TLS / DTLS algorithm type, TLS / DTLS version information, algorithm suite information, protocol handshake type, certificate extensions, etc.

[0111] For example, multiple security detection templates can be configured for physical layer operational data. For each security detection template, the attribute field can be the unique device identifier of the IoT terminal device. The standard field of the security detection template can be a data security parameter, such as the Hamming weight information of power consumption curves for multiple frequency bands. In other words, the standard field of the security detection template is the Hamming weight information for multiple frequency bands.

[0112] Exemplarily, for each second eigenvalue, the edge layer device can obtain the attribute information and data security parameters corresponding to the second eigenvalue. For example, when the IoT terminal device sends a structured eigenvector to the edge layer device, the structured eigenvector can include the data security parameters and attribute information corresponding to each second eigenvalue in the second eigenvalue set. Therefore, the edge layer device can obtain the attribute information and data security parameters corresponding to each second eigenvalue. For example, if the second eigenvalue corresponds to the cryptographic algorithm call chain data, the attribute information is the data type of the data to be processed; if the second eigenvalue corresponds to the critical path behavior log, the attribute information is the path information of the critical path; if the second eigenvalue corresponds to encrypted traffic, the attribute information is the destination IP address or source IP address of the encrypted traffic; if the second eigenvalue corresponds to the physical layer operation data, the attribute information is the unique device identifier of the IoT terminal device.

[0113] Exemplarily, if the attribute information corresponding to the second eigenvalue is inconsistent with the attribute field of the security detection template, that is, the attribute information is different from the attribute fields of all security detection templates, then it is determined that the second eigenvalue does not match the security detection template (does not match all security detection templates). In this way, it is determined that there is a security risk in the second eigenvalue, and the second eigenvalue is added to the third eigenvalue set.

[0114] For example, if the second feature value corresponds to cryptographic algorithm call chain data, multiple security detection templates configured for the cryptographic algorithm call chain data (referred to as security detection template a) are selected from all security detection templates. The attribute information (e.g., data type) is then compared with the attribute fields of each security detection template a. If the attribute information differs from the attribute fields of all security detection templates a, the second feature value is determined to be mismatched with all security detection templates, and the matching process for the second feature value is complete.

[0115] Exemplarily, if the attribute information corresponding to the second eigenvalue is consistent with the attribute field of the security detection template (such as at least one security detection template), and the data security parameter corresponding to the second eigenvalue does not match the standard field of the security detection template, then it is determined that the second eigenvalue does not match the security detection template, it is determined that the second eigenvalue poses a security risk, and the second eigenvalue is added to the third eigenvalue set.

[0116] For example, if the second eigenvalue corresponds to cryptographic algorithm call chain data, multiple security detection templates a configured for the cryptographic algorithm call chain data are selected. If the attribute information is the same as the attribute fields of security detection template a1 and security detection template a2, then it is necessary to compare whether the data security parameters match the standard fields of security detection template a1, and compare whether the data security parameters match the standard fields of security detection template a2. If there is no match with the standard fields of security detection template a1 and the standard fields of security detection template a2, it is determined that the second eigenvalue does not match all security detection templates, the matching process of the second eigenvalue is completed, and the second eigenvalue can be added to the third eigenvalue set.

[0117] Exemplarily, if the attribute information corresponding to the second eigenvalue is consistent with the attribute field of the security detection template (such as at least one security detection template), and the data security parameter corresponding to the second eigenvalue matches the standard field of the security detection template, then it is determined that the second eigenvalue matches the security detection template, it is determined that there is no security risk in the second eigenvalue, and the second eigenvalue is not added to the third eigenvalue set.

[0118] For example, when comparing the data security parameters with the standard fields of security detection template a1 and security detection template a2, if it matches the standard field of security detection template a1 or the standard field of security detection template a2, it is determined that the second feature value matches a security detection template, the matching process of the second feature value is completed, and the second feature value is not added to the third feature value set.

[0119] In one possible implementation, when comparing the data security parameter with the standard field of the security detection template (taking security detection template a1 as an example), if the data security parameter is consistent with the standard field of the security detection template a1, then the data security parameter matches the standard field of the security detection template a1.

[0120] If the data security parameter does not match the standard field of security detection template a1, it is necessary to further compare the first security level corresponding to the data security parameter with the second security level corresponding to the standard field of security detection template a1. If the first security level is not less than the second security level, it indicates that the data security parameter matches the standard field of security detection template a1. If the first security level is less than the second security level, it indicates that the data security parameter does not match the standard field of security detection template a1.

[0121] For example, for the second eigenvalue corresponding to the cryptographic algorithm call chain data, the data security parameter is a parameter used when performing security operations using the security algorithm. The data security parameter can reflect the first security level of the security algorithm, and the first security level can indicate the security level of the security algorithm. The standard field of security detection template a1 is also a data security parameter, and the data security parameter can reflect the second security level of the standard field. Based on this, the first security level and the second security level can be compared. If the first security level is less than the second security level, it means that the security level of security detection template a1 is higher, and the data security parameter of the second eigenvalue cannot reach the security level of security detection template a1. Therefore, the data security parameter does not match the standard field of security detection template a1. If the first security level is not less than the second security level, it means that the data security parameter of the second eigenvalue has a higher security level and can reach the security level of security detection template a1. The data security parameter matches the standard field of security detection template a1.

[0122] For example, for the second characteristic value corresponding to the critical path behavior log, the data security parameters are the operation object, operation type, and number of operations, and the standard fields of the security detection template a1 are the operation object, operation type, and number of operations, which can compare the first security level and the second security level. For example, if the standard field of the security detection template a1 is that the query operation on the key storage path is performed three times, and the data security parameter of the second characteristic value indicates that the query operation is performed four times on the key storage path, then the first security level is lower than the second security level, that is, the greater the number of operations, the lower the security level. If the data security parameter of the second characteristic value indicates that the query operation is performed twice on the key storage path, then the first security level is greater than the second security level.

[0123] For example, for the second characteristic value corresponding to the encrypted traffic, the data security parameter includes parameters related to the encryption algorithm used by the encrypted traffic, such as the TLS / DTLS algorithm type, TLS / DTLS version information, etc. The standard field of the security detection template a1 also includes parameters related to the encryption algorithm used by the encrypted traffic. In this way, the first security level and the second security level can be compared. For example, if the TLS / DTLS version information in the data security parameter is higher than the TLS / DTLS version information in the standard field of the security detection template a1, then the first security level is greater than the second security level, that is, the larger the version, the higher the security level. If the TLS / DTLS version information in the data security parameter is lower than the TLS / DTLS version information in the standard field of the security detection template a1, then the first security level is lower than the second security level.

[0124] For example, for the second characteristic value corresponding to the physical layer operation data, the data security parameter includes Hamming weight information for multiple frequency bands, and the standard field of the security detection template a1 also includes Hamming weight information for multiple frequency bands. Thus, by comparing the Hamming weight information for each frequency band, the first and second security levels can be compared. For example, the Hamming weight information can be a Hamming weight (i.e., Hamming weight) or a Hamming distance. A larger Hamming weight indicates greater power consumption during computation. Therefore, if the Hamming weight in the data security parameter is greater than the Hamming weight in the standard field of the security detection template a1, the power consumption is greater, meaning that the first security level is lower than the second security level. If the Hamming weight in the data security parameter is less than the Hamming weight in the standard field of the security detection template a1, the first security level is higher than the second security level.

[0125] Method b: For each second eigenvalue in the second eigenvalue set, the second eigenvalue is input into the large language model, and the large language model determines whether to add the second eigenvalue to the third eigenvalue set. For example, if the large language model determines that the second eigenvalue presents a security risk, the second eigenvalue may be added to the third eigenvalue set. Alternatively, if the large language model determines that the second eigenvalue does not present a security risk, the second eigenvalue may not be added to the third eigenvalue set.

[0126] Exemplarily, for each second feature value, the type of cryptographic application data corresponding to the second feature value is obtained, and a reference prompt word corresponding to the type is obtained. For example, if the edge layer device determines that the attribute information of the second feature value is a data type, the second feature value is determined to correspond to cryptographic algorithm call chain data. Therefore, the reference prompt word indicates that the second feature value corresponds to the cryptographic algorithm call chain data. For example, the reference prompt word may be the first reference prompt word corresponding to the cryptographic algorithm call chain data. Alternatively, if the edge layer device determines that the attribute information of the second feature value is path information, the second feature value is determined to correspond to a critical path behavior log. Therefore, the reference prompt word indicates that the second feature value corresponds to a critical path behavior log. For example, the reference prompt word may be the second reference prompt word corresponding to the critical path behavior log. Alternatively, if the edge layer device determines that the attribute information of the second feature value is an IP address, the second feature value is determined to correspond to encrypted traffic. Therefore, the reference prompt word indicates that the second feature value corresponds to encrypted traffic. For example, the reference prompt word may be the third reference prompt word corresponding to encrypted traffic. Alternatively, if the edge layer device determines that the attribute information of the second characteristic value is the unique device identifier of the Internet of Things terminal device, it is determined that the second characteristic value corresponds to the physical layer operation data. Therefore, the reference prompt word indicates that the second characteristic value corresponds to the physical layer operation data. For example, the reference prompt word can be the fourth reference prompt word corresponding to the physical layer operation data.

[0127] Exemplarily, the reference prompt word and the second feature value can be input into a large language model; the large language model selects multiple security detection templates corresponding to the reference prompt word from all configured security detection templates, and the security detection template corresponding to the reference prompt word is called a target security detection template.

[0128] For example, multiple security detection templates can be pre-configured. These templates are used to screen for feature values that do not present security risks. These templates may or may not include attribute fields and / or standard fields, and there are no restrictions on the content of these templates. For example, multiple security detection templates s1 can be configured for cryptographic algorithm call chain data, multiple security detection templates s2 can be configured for critical path behavior logs, multiple security detection templates s3 can be configured for encrypted traffic, and multiple security detection templates s4 can be configured for physical layer operation data. Based on this, if the reference prompt is the first reference prompt, all security detection templates s1 are selected as target security detection templates using the large language model. If the reference prompt is the second reference prompt, all security detection templates s2 are selected as target security detection templates using the large language model. If the reference prompt is the third reference prompt, all security detection templates s3 are selected as target security detection templates using the large language model. If the reference prompt is the fourth reference prompt, all security detection templates s4 are selected as target security detection templates using the large language model.

[0129] For example, for each target security detection template, a template feature value corresponding to the target security detection template can be determined using a large language model, such as by performing feature extraction on the target security detection template to obtain the template feature value. This embodiment does not limit the method for obtaining this template feature value. For example, if the target security detection template includes a standard field, and the standard field is a data security parameter, then the data security parameter can be quantized to obtain a fixed-length feature value (e.g., an 8-bit integer feature value or a 16-bit integer feature value), and this fixed-length feature value can be used as the template feature value.

[0130] For example, the similarity (e.g., Euclidean distance, cosine similarity, etc.) between the second eigenvalue and each template eigenvalue (i.e., the template eigenvalue of each target security detection template) can be calculated using a large language model. If any similarity is greater than a threshold (which can be configured based on experience), it indicates that the second eigenvalue matches the target security detection template corresponding to the template eigenvalue, and it is determined that the second eigenvalue does not pose a security risk, and the second eigenvalue can be omitted from the third eigenvalue set. Alternatively, if all similarities are less than the threshold, it indicates that the second eigenvalue does not match all target security detection templates, and it is determined that the second eigenvalue poses a security risk, and the second eigenvalue can be added to the third eigenvalue set.

[0131] For example, during the fine-tuning of dynamic prompts, context-awareness can be used to generate dynamic prompts (i.e., reference prompts) to guide the large language model to focus on specific threat scenarios (i.e., select security detection templates corresponding to the reference prompts for detection), improving the detection of small-shot attacks. Template variables are dynamically populated based on feature values uploaded by IoT devices. For example, this verifies the presence of sensitive fields such as ID card numbers and bank card numbers, the use of encryption algorithms for storage confidentiality and integrity protection, and the key algorithm, key length, and algorithm call chain information. Reference prompts are generated using a rules engine and a large language model. A reinforcement learning algorithm is used to evaluate the effectiveness, accuracy, and false positive rate of the reference prompts, dynamically updating the priority of security detection templates. Based on the feature values uploaded by IoT devices (such as device role, behavior logs, protocol type, and algorithm call chain), corresponding security detection templates are automatically generated and matched.

[0132] For example, during dynamic prompt fine-tuning, candidate detection template topics are initially obtained based on the second eigenvalue within the set. For example, if the algorithm call chain contains key data and algorithm data, the candidate detection template topic set may include entropy source detection and weak algorithm detection. Based on this candidate detection template topic set, the large language model generates candidate prompt words, such as the algorithm parameter RSA-1024. Prompt words for algorithm detection, including algorithm strength detection and key random number quality detection, are generated dynamically based on the latest updated model.

[0133] Method c: For each second eigenvalue in the second eigenvalue set, if the second eigenvalue matches the configured security detection template, it is determined that the second eigenvalue does not pose a security risk, and the second eigenvalue is not added to the third eigenvalue set. Alternatively, if the second eigenvalue does not match the configured security detection template, the second eigenvalue may or may not pose a security risk, and the second eigenvalue is input into the large language model for further analysis, such as determining whether to add the second eigenvalue to the third eigenvalue set through the large language model. If the large language model determines that the second eigenvalue poses a security risk, the second eigenvalue is added to the third eigenvalue set. If the large language model determines that the second eigenvalue does not pose a security risk, the second eigenvalue is not added to the third eigenvalue set.

[0134] 4. Feature distillation and data compression. During the feature distillation and data compression process, based on the importance parameter of each third eigenvalue in the third eigenvalue set, some third eigenvalues are selected from the third eigenvalue set to obtain a fourth eigenvalue set, i.e., the fourth eigenvalue set includes the selected third eigenvalues.

[0135] Exemplarily, during the feature distillation process, a locality-sensitive hashing algorithm is used to determine the contribution parameter value of each third eigenvalue in the set of third eigenvalues. All third eigenvalues are sorted in descending order based on their contribution parameter values; based on the sorting results, the top K third eigenvalues can be selected. Alternatively, all third eigenvalues are sorted in ascending order based on their contribution parameter values; based on the sorting results, the bottom K third eigenvalues can be selected.

[0136] For example, during the feature distillation process, high-value features can be screened, the amount of data transmitted to cloud devices can be reduced, and key threat information can be retained. In order to screen high-value features, the contribution of each third eigenvalue to the detection result, that is, the contribution parameter value, can be calculated through the LSH (Locality Sensitive Hashing) algorithm. Among them, the LSH algorithm is based on the principle of data locality, that is, similar data is often "clustered" together in the feature space. LSH maps similar data to the same or similar hash values by designing a specific hash function, thereby realizing rapid search and screening of similar data. ‌

[0137] Sort all third eigenvalues by contribution parameter value from largest to smallest. The top K third eigenvalues are selected as high priority, and the remaining third eigenvalues are selected as low priority. The value of K can be 40%, 30%, or a fixed value such as 10.

[0138] For example, during the data compression process, for each selected third eigenvalue (e.g., K third eigenvalues), a similarity parameter value between the third eigenvalue and each eigenvalue in the LRU queue can be calculated. If any similarity parameter value is not less than a similarity threshold, the third eigenvalue can be prohibited from being added to the fourth eigenvalue set. If all similarity parameter values are less than the similarity threshold, the third eigenvalue can be added to the fourth eigenvalue set and stored in the LRU queue.

[0139] For example, during the data compression process, the third eigenvalue with a high priority can be compressed (for example, using the LZ4 algorithm (i.e., a high-speed lossless compression algorithm) to compress the third eigenvalue with a high priority), and additional information such as a timestamp, device ID, and threat level label can be added to each third eigenvalue.

[0140] For example, during the data compression process, an LRU (Least Recently Used) queue can be used to maintain a local feature library. The LRU queue is used to store feature values that have been transmitted to the cloud device. In this way, the similarity parameter value (such as Euclidean distance, cosine similarity, etc.) between the third feature value and each feature value in the LRU queue can be calculated. If any similarity parameter value is not less than the similarity threshold, it means that a similar feature value has been transmitted to the cloud device. In this case, the third feature value does not need to be transmitted, and it is prohibited to add the third feature value to the fourth feature value set. If all similarity parameter values are less than the similarity threshold, it means that a similar feature value has not been transmitted to the cloud device. In this case, the third feature value needs to be transmitted, added to the fourth feature value set, and stored in the LRU queue.

[0141] For example, during data compression, expired feature values in the LRU queue can be automatically cleared. Based on this, after storing the third feature value in the LRU queue, if the number of feature values in the LRU queue is not greater than a threshold (which can be configured based on experience), the LRU queue is kept unchanged. If the number of feature values in the LRU queue is greater than the threshold, the first feature value in the LRU queue can be deleted.

[0142] In summary, the edge layer device can obtain the fourth eigenvalue set and send the fourth eigenvalue set to the cloud device, which then processes the fourth eigenvalue set based on the fourth eigenvalue set.

[0143] Third, the processing process for cloud devices.

[0144] 1. Multimodal semantic modeling. During the multimodal semantic modeling process, a large model (AI large model) can be trained and deployed. The large model can include a cryptographic security knowledge graph, a first feature extraction network, a second feature extraction network, a third feature extraction network, and a fourth feature extraction network.

[0145] Exemplarily, a password security knowledge graph can be constructed, which can include multiple nodes. For each node, the node can correspond to a graph feature vector and password security evaluation information, and the password security evaluation information can indicate whether the password application is secure or insecure.

[0146] For example, network security documents include multiple security review strategies (which indicate the laws, regulations, and / or standards that cryptographic applications must comply with), data security documents include multiple security review strategies, personal information protection documents include multiple security review strategies, information security documents include multiple security review strategies, information system security application basic requirements documents include multiple security review strategies, information security technology network security level protection basic requirements documents include multiple security review strategies, cryptographic module security technical requirements documents include multiple security review strategies, and CVE vulnerability database documents include multiple security review strategies. Based on these documents, a large number of security review strategies can be obtained.

[0147] On this basis, a cryptographic security knowledge graph consisting of multiple nodes (e.g., hundreds of thousands of nodes) can be derived from these secret review strategies. There are no restrictions on the process of obtaining this cryptographic security knowledge graph. Each node in the cryptographic security knowledge graph can correspond to one or more secret review strategies, and features of these secret review strategies can be extracted to obtain the graph feature vector corresponding to that node. Because secret review strategies are used to indicate the laws, regulations, and / or standards that cryptographic applications must comply with, they can indicate whether a cryptographic application is secure or insecure, thus providing cryptographic security assessment information corresponding to that node.

[0148] When building a password security knowledge graph, you can also use the NER (Named Entity Recognition) and relationship extraction of the LLM (Large Language Model) to extract the named entities of the secret review strategies from a large number of secret review strategies, and then build nodes of the password security knowledge graph based on these named entities.

[0149] For example, causal graphs can be constructed and converted into Bayesian networks. By inputting observational evidence, posterior probabilities are calculated, and the most likely attack sequence is searched. The generator is trained to simulate attacker behavior, while the discriminator evaluates the plausibility of paths and outputs high-threat paths for rule base enhancement. For example, attack path diagrams can be dynamically drawn based on the causal graph, with nodes representing attack stages, root causes highlighted in red, and edges labeled with causal probabilities and timestamps. LLM generates natural language analysis reports that include defect location and remediation recommendations.

[0150] For example, a causal discovery algorithm can be used to obtain a causal graph. The input for this algorithm can be a dataset, and the output can be a directed acyclic graph, with edge weights representing the strength of causality. Based on the relationship between the edges in the causal graph and the knowledge graph, corresponding laws and regulations, remediation recommendations, and a list of affected devices can be extracted from the cryptographic security knowledge graph. The causal edge weights correspond to the prior probabilities in the conditional probability table, such as the probability that a low entropy value corresponds to a true or false random number and is predictable. Observed data is input, and the posterior probability is calculated using the propagation of new information algorithm. The Viterbi algorithm is then used to find the path with the maximum posterior probability, such as a weak key -> man-in-the-middle attack -> data leak.

[0151] Exemplarily, in addition to the cryptographic security knowledge graph, the large model may also include a first feature extraction network, a second feature extraction network, a third feature extraction network, a fourth feature extraction network and a feature fusion network.

[0152] For example, the large model integrates multi-source heterogeneous data and feature vectors to construct a unified cryptographically secure semantic representation, enabling cross-modal threat correlation analysis. To this end, the large model includes a first feature extraction network, which extracts feature vectors for binary modal data. For example, this network can be a 1D-CNN (Convolutional Neural Network) network, which extracts local features for binary modal data. The large model also includes a second feature extraction network, which extracts feature vectors for text modal data. For example, this network can be a BERT (Bidirectional Encoder Representations from Transformers) encoder network, which extracts semantic features for text modal data. The large model also includes a third feature extraction network, which extracts feature vectors for image modal data. For image modal data, this network is used to extract characteristic features. The large model includes a fourth feature extraction network, which is used to extract feature vectors of time series modal data. For example, the fourth feature extraction network is an LSTM (Long Short-Term Memory) network. For time series modal data, the power consumption time series features are extracted through the LSTM network.

[0153] The large model can also include a feature fusion network, which implements cross-modal feature fusion and alignment. That is, the first feature extraction network inputs the feature vector to the feature fusion network, the second feature extraction network inputs the feature vector to the feature fusion network, the third feature extraction network inputs the feature vector to the feature fusion network, and the fourth feature extraction network inputs the feature vector to the feature fusion network. The feature fusion network performs feature fusion and alignment on the multiple feature vectors mentioned above. In the feature fusion network, a cross-modal attention mechanism can be designed to calculate the similarity weights of text features, binary features, image features, and temporal features, concatenate and weight these features, and then generate a unified vector to input to downstream tasks.

[0154] During the large model training process, positive samples (multimodal data from the same attack event) and negative samples (irrelevant data) can be constructed to minimize contrast loss. The large model can output threat type, compliance level, and confidence score. The protocol text fields are randomly masked, and the large model predicts the masked content based on the context.

[0155] 2. Security risk chain tracing. During the security risk chain tracing process, a set of fourth eigenvalues (e.g., multiple fourth eigenvalues) can be input into the large model, which then outputs a cryptographic security assessment result for the IoT terminal device. This result can indicate whether the cryptographic application is secure or insecure.

[0156] For example, the fourth eigenvalue set can be input into the first feature extraction network of the large model, and the first device feature vector corresponding to the fourth eigenvalue set can be extracted by the first feature extraction network. For example, the first feature extraction network can be a 1D-CNN. In this way, the 1D-CNN can perform local feature extraction on the fourth eigenvalue set to obtain the first device feature vector corresponding to the fourth eigenvalue set.

[0157] The large model calculates the similarity between the first device feature vector and the graph feature vector of each node in the password security knowledge graph. That is, based on the graph feature vector corresponding to each node, the large model can calculate the similarity between the first device feature vector and the graph feature vector. Based on the similarity between the first device feature vector and each graph feature vector, the large model can select a first target node from the password security knowledge graph, e.g., when the similarity between the first device feature vector and the graph feature vector of the first target node is the maximum similarity.

[0158] Since each node of the password security knowledge graph corresponds to password security evaluation information, the large model can obtain the password security evaluation information of the first target node and output the password security evaluation information.

[0159] On this basis, if the cryptographic security assessment information of the first target node indicates that the cryptographic application is secure, then the cryptographic security assessment result of the IoT terminal device can be determined to be a secure cryptographic application. If the cryptographic security assessment information of the first target node indicates that the cryptographic application is insecure, the following method can be used:

[0160] Method 1: Determine that the password security assessment result of the IoT terminal device is that the password application is unsafe. The large model can obtain a first penetration path based on the position of the first target node in the password security knowledge graph. The first penetration path may include the first target node and a node having a causal dependency relationship with the first target node.

[0161] For example, based on a causal graph or a Bayesian network, the causal dependency relationship between each node in the cryptographic security knowledge graph can be determined. Alternatively, when constructing a cryptographic security knowledge graph, the causal dependency relationship between each node in the cryptographic security knowledge graph can also be determined. There is no restriction on this.

[0162] For example, if there is a causal dependency between nodes 1 and 2, this means that if the cryptographic application has a flaw corresponding to node 1, it also has a flaw corresponding to node 2. If the first device feature vector corresponds to the first target node, this means that the cryptographic application of the IoT terminal device has a flaw corresponding to the first target node, and the cryptographic application also has a flaw corresponding to the node with which the first target node is causally dependent.

[0163] Based on this, the large model can find nodes in the cryptographic security knowledge graph that have a causal dependency relationship with the first target node. For example, if the first target node is at position A in the cryptographic security knowledge graph, and position A has a causal dependency relationship with positions B and C, then the nodes with a causal dependency relationship with the first target node are the nodes at position B and the nodes at position C. At this point, the first permeation path can be obtained, which includes the first target node and the nodes with a causal dependency relationship with the first target node.

[0164] For example, after obtaining the first penetration path, the reasons for insecure cryptographic application and suggestions for remediating the application can be determined based on the first penetration path. For example, a mapping table can be pre-configured, which can include the correspondence between the penetration path (i.e., the node name of each node on the penetration path), the reasons for insecure cryptographic application, and suggestions for remediating the application. This mapping table can be configured according to actual needs, and its content is not restricted. Based on this, the mapping table can be queried using the first penetration path (e.g., the node name of the first target node and the node names of nodes with causal dependencies on the first target node) to obtain the reasons for insecure cryptographic application and suggestions for remediating the application.

[0165] For another example, for each node in the password security knowledge graph, in addition to the corresponding graph feature vector and password security assessment information, the node can also correspond to the reasons for insecure password application and password application repair suggestions. For example, since the node corresponds to one or more secret review strategies, which are used to indicate the laws, regulations and / or standard specifications that the password application needs to comply with, the reasons for insecure password application and password application repair suggestions can be analyzed based on the secret review strategies, and then the reasons for insecure password application and password application repair suggestions corresponding to the node can be obtained. On this basis, after obtaining the first penetration path, the reasons for insecure password application and password application repair suggestions corresponding to the first target node and the reasons for insecure password application and password application repair suggestions corresponding to the nodes that have a causal dependency relationship with the first target node can be determined, and then the reasons for insecure password application and password application repair suggestions for the Internet of Things terminal devices can be obtained, that is, the reasons for insecure password application and password application repair suggestions for each node on the first penetration path.

[0166] To summarize, the large model outputs reasons for insecure cryptographic application, such as low key entropy → predictable random numbers → leaked session keys. "Low key entropy" indicates the insecure cryptographic application cause at the first node of the first penetration path, "predictable random numbers" indicates the insecure cryptographic application cause at the second node of the first penetration path, and "leaked session keys" indicates the insecure cryptographic application cause at the third node of the first penetration path. The large model outputs cryptographic application repair suggestions, such as Repair Suggestion a → Repair Suggestion b → Repair Suggestion c. Repair Suggestion a represents the repair suggestion for "low key entropy," Repair Suggestion b represents the repair suggestion for "predictable random numbers," and Repair Suggestion c represents the repair suggestion for "leaked session keys."

[0167] For example, during causal reasoning and attack chain tracing, causal graphs are used to locate root-cause flaws and restore the attacker's multi-step penetration path. The NOTEARS algorithm is used to learn causal dependencies between variables from historical data, such as "low key entropy → predictable random numbers → session key leakage." With each new attack sample, causal edge weights are updated through incremental causal discovery, mapping nodes in the causal graph to the cryptographic security knowledge graph.

[0168] Method 2: If the cryptographic security assessment information of the first target node indicates that the cryptographic application is insecure, the cloud device sends a data request message to the edge device (requesting the IoT terminal device to obtain multimodal data). The edge device then obtains the multimodal data from the IoT terminal device. The cloud device then receives a data response message from the edge device, which includes the multimodal data from the IoT terminal device.

[0169] For example, after receiving a data request message, the edge layer device finds the second eigenvalue corresponding to each fourth eigenvalue in the fourth eigenvalue set from the second eigenvalue set, and obtains multimodal data corresponding to these second eigenvalues from the IoT terminal device (i.e., the IoT terminal device obtains the second eigenvalue through this multimodal data). The multimodal data may include cryptographic algorithm call chain data, critical path behavior logs, encrypted traffic, physical layer operation data, etc. Alternatively, after receiving a data request message, the edge layer device obtains all multimodal data from the IoT terminal device, rather than the multimodal data corresponding to the second eigenvalue corresponding to the fourth eigenvalue.

[0170] After obtaining the multimodal data, the edge layer device sends a data response message to the cloud device. After receiving the data response message, the cloud device parses the multimodal data from the data response message.

[0171] Exemplarily, after obtaining multimodal data, the cloud device can generate text modal data, image modal data, and time series modal data based on the multimodal data. For example, if the multimodal data includes cryptographic algorithm call chain data, the text modal data includes the cryptographic algorithm call chain data. If the multimodal data includes critical path behavior logs, the text modal data includes critical path behavior logs. If the multimodal data includes encrypted traffic and text data exists in the encrypted traffic, the text modal data includes the text data.

[0172] For example, if the multimodal data includes encrypted traffic, and the encrypted traffic contains image data, then the image modal data includes the image data. If the multimodal data includes physical layer operation data (such as intra-cycle power consumption fluctuation graphs, intra-cycle side channel data, etc.), then the image modal data includes the physical layer operation data.

[0173] For example, since multimodal data includes multiple cryptographic algorithm call chain data, multiple critical path behavior logs, multiple encrypted flows, and multiple physical layer operation data within a time window (such as 1 second), it is possible to determine the timing information corresponding to the multimodal data (information related to time series, time series refers to a series of values of the same statistical indicator arranged in chronological order of their occurrence), and generate time series modal data based on the timing information corresponding to the multimodal data. There is no restriction on this process.

[0174] Exemplarily, the fourth eigenvalue set is input into a first feature extraction network (e.g., a 1D-CNN network), which performs feature extraction on the fourth eigenvalue set to obtain a first eigenvector. Text modality data is input into a second feature extraction network (e.g., a BERT network), which performs feature extraction on the text modality data to obtain a second eigenvector. Image modality data is input into a third feature extraction network, which performs feature extraction on the image modality data to obtain a third eigenvector. Time series modality data is input into a fourth feature extraction network (e.g., an LSTM network), which performs feature extraction on the time series modality data to obtain a fourth eigenvector.

[0175] Then, the first eigenvector, the second eigenvector, the third eigenvector and the fourth eigenvector can be input into the feature fusion network of the large model, and the first eigenvector, the second eigenvector, the third eigenvector and the fourth eigenvector can be fused through the feature fusion network to obtain the second device feature vector.

[0176] Exemplarily, the large model calculates the similarity between the second device feature vector and the graph feature vector of each node in the password security knowledge graph. Based on the similarity between the second device feature vector and each graph feature vector, the large model can select a second target node from the password security knowledge graph, e.g., when the similarity between the second device feature vector and the graph feature vector of the second target node is the maximum similarity. Since each node in the password security knowledge graph corresponds to password security assessment information, the large model can obtain the password security assessment information of the second target node and output the password security assessment information of the second target node.

[0177] On this basis, if the cryptographic security assessment information of the second target node indicates that the cryptographic application is secure, then the cryptographic security assessment result of the IoT terminal device is determined to be a secure cryptographic application. If the cryptographic security assessment information of the second target node indicates that the cryptographic application is insecure, then the cryptographic security assessment result of the IoT terminal device is determined to be an insecure cryptographic application. Furthermore, the large model can also obtain a second penetration path based on the position of the second target node in the cryptographic security knowledge graph. The second penetration path can include the second target node and nodes with a causal dependency relationship with the second target node. After obtaining the second penetration path, the cause of the insecure cryptographic application and recommendations for remediating the cryptographic application can be determined based on the second penetration path.

[0178] 3. Dynamic orchestration policy reinforcement: During the dynamic orchestration policy reinforcement process, you can generate a password compliance policy based on the reasons for insecure password application and password application remediation suggestions, and deploy the password compliance policy to IoT terminal devices, or prohibit the deployment of the password compliance policy to IoT terminal devices.

[0179] For example, based on real-time threat analysis results, password compliance policies can be dynamically compiled, distributed, and implemented to achieve adaptive system hardening. For example, a password compliance policy can be generated based on the reasons for insecure password application and password remediation recommendations. The password compliance policy can address the shortcomings of the insecure password application and is generated based on the password remediation recommendations. There are no restrictions on how this password compliance policy can be generated.

[0180] Then, the password compliance policy can be deployed in the sandbox environment of the cloud device (consistent with the environment of the IoT terminal device) to run the password compliance policy in the sandbox environment to perform security operations on the data, which is equivalent to running the password compliance policy in the IoT terminal device to perform security operations on the data.

[0181] During the sandbox environment, the security gain, system efficiency, and operating cost associated with the password compliance policy can be collected. Based on these factors, a reward value corresponding to the password compliance policy can be determined. For example, the reward value R can be determined using the following formula: R = W1 × Security Gain + W2 × System Efficiency − W3 × Operating Cost. This formula is merely an example and is not intended to be limiting. The reward value can be related to the security gain, system efficiency, and operating cost. W1, W2, and W3 represent weighting coefficients, which can be configured based on experience, such as 0.7 for W1, 0.2 for W2, and 0.1 for W3.

[0182] For example, security gain can represent the degree to which a password compliance policy complies with pre-defined rules. Pre-defined rules can be laws, regulations, and standards. The security gain represents the degree of compliance with these laws and regulations for password application security. The security gain of a password compliance policy can be calculated by comparing it with all laws, regulations, and standards. For example, if there are 100 laws and regulations, and the password compliance policy matches 95 of them and does not match 5, the security gain can be 95%.

[0183] For example, system efficiency can represent the change in service latency after a password compliance policy is implemented. If the service time before the password compliance policy was deployed was 3 seconds (i.e., the service time using the original password compliance policy), and after the policy was deployed, the service time was 4 seconds (i.e., the service time using the new policy), the service latency change could be -1 second, indicating an increase in service latency and a decrease in system efficiency. The "-1 second" can be normalized to a value between -1 and 1, and the system efficiency is negative in this case. Alternatively, if the service time after the policy was deployed was 2 seconds (i.e., the service time using the new policy), the service latency change could be +1 second, indicating a decrease in service latency and an increase in system efficiency. The "+1 second" can be normalized to a value between -1 and 1, and the system efficiency is positive in this case.

[0184] Regarding service time, assuming that when the password compliance policy is not deployed, the processing time for data is t, and when the password compliance policy is deployed, the processing time for data is t1. Since the deployment of the password compliance policy involves data security operations, t1 is greater than t, and the difference between t1 and t is the service time.

[0185] For example, the operational cost can represent the number of device connection interruptions after a password compliance policy is implemented (or the cost to operations personnel). After deploying the password compliance policy, the number of device connection interruptions within a preset period can be counted, and this number of device connection interruptions represents the operational cost. This number of device connection interruptions can be normalized to a value between 0 and 1, and the normalized value is used as the operational cost.

[0186] For example, after obtaining a reward value, if the reward value is greater than a threshold (which can be configured based on experience), the cloud device can deploy the password compliance policy to the IoT terminal device. Alternatively, if the reward value is not greater than the threshold, the cloud device prohibits the deployment of the password compliance policy to the IoT terminal device.

[0187] For example, during the dynamic orchestration policy generation and closed-loop process, the NSGA-II algorithm can be used to determine the Pareto-optimal policy set that balances security performance. Policies can then be injected into a simulation environment to monitor system stability and compatibility (for example, whether legacy devices support high-strength cryptographic algorithms). Post-policy execution metrics (for example, an increase in cryptographic application security compliance to 95%) and system load (CPU increase ≤ 5%) are collected. If a new policy causes service anomalies, the system automatically rolls back to the previous stable version, triggering an alarm to notify the administrator.

[0188] It can be seen from the above technical solutions that in the embodiment of the present application, a three-level hierarchical distillation framework of "cloud-based large model-edge-small model-terminal feature encoder" is used for the security assessment of cryptographic applications. The cloud device generates a decision logic knowledge base for cryptographic security detection through LLM, which is compressed into a lightweight model that can be deployed on the edge through attention distillation and quantization-aware training. The IoT terminal device only needs to run a low-power feature extractor to achieve real-time capture and compressed upload of key features. The IoT terminal device probe collects cryptographic operation metadata, the edge layer device performs real-time compliance screening and threat feature extraction, and the large model of the cloud device performs deep correlation analysis and strategy generation. A lightweight adaptation mechanism based on dynamic prompt fine-tuning is designed. The general cryptographic security mode is extracted through LLM, and domain-adaptive prompt words are generated on the edge layer device according to the real-time traffic context, guiding the model to focus on specific attack scenarios. Rapid iteration of the threat detection model can be achieved without full fine-tuning. The large language model is integrated with the knowledge graph in the cryptography field to construct a multimodal semantic representation framework. This large model uniformly encodes heterogeneous data such as encryption protocol text, device logs, and network traffic. Using a neural network, it dynamically extracts relevant features such as the cryptographic algorithm call chain and key lifecycle, solving the challenge of semantic alignment across protocols and layers. A cryptographic causal graph model is embedded within the large model to identify root-cause vulnerabilities in multi-step attack chains. This is combined with an adversarial generative network to simulate attack paths and dynamically generate targeted detection rules.

[0189] Based on the same application concept as the above method, the embodiment of the present application proposes an Internet of Things system, which includes: an Internet of Things terminal device, an edge layer device and a cloud device.

[0190] An IoT terminal device is configured to obtain a data set and a first eigenvalue set; the data set includes a plurality of multimodal data, and the multimodal data includes at least two types of cryptographic application data; the first eigenvalue set includes a first eigenvalue of each cryptographic application data; for each cryptographic application data, processing a data security parameter corresponding to the cryptographic application data to obtain the first eigenvalue of the cryptographic application data; and performing a dimensionality reduction operation on the first eigenvalue in the first eigenvalue set to obtain a second eigenvalue set, and sending the second eigenvalue set to an edge layer device;

[0191] An edge layer device, configured to filter the second feature values in the second feature value set to obtain a third feature value set; wherein, for each second feature value, if the second feature value does not match the configured security detection template, the second feature value is added to the third feature value set; or, the second feature value is input to the large language model, and the large language model is used to determine whether to add the second feature value to the third feature value set; or, if the second feature value does not match the security detection template, the second feature value is input to the large language model, and the large language model is used to determine whether to add the second feature value to the third feature value set; and, based on an importance parameter of each third feature value in the third feature value set, select some third feature values from the third feature value set to obtain a fourth feature value set, the fourth feature value set including the selected third feature values, and send the fourth feature value set to the cloud device;

[0192] The cloud device is used to input the fourth eigenvalue set into the large model to obtain a password security assessment result of the Internet of Things terminal device, where the password security assessment result is that the password application is secure or the password application is insecure.

[0193] Based on the same application concept as the above method, the embodiment of this application proposes a large model-based Internet of Things system cryptographic application security assessment device, which can be applied to edge layer devices in the Internet of Things system, see Figure 4 FIG. 1 is a schematic structural diagram of the device, which may include:

[0194] An acquisition module 41 is configured to acquire a second eigenvalue set, where the second eigenvalue set is obtained by performing a dimensionality reduction operation on the first eigenvalue set by the IoT terminal device; the first eigenvalue set includes a first eigenvalue of the cryptographic application data, where the first eigenvalue is obtained by processing a data security parameter corresponding to the cryptographic application data;

[0195] a processing module 42 configured to filter the second feature values in the second feature value set to obtain a third feature value set; for each second feature value, if the second feature value does not match the configured security detection template, add the second feature value to the third feature value set; or, input the second feature value to the large language model, and determine, via the large language model, whether to add the second feature value to the third feature value set; or, if the second feature value does not match the security detection template, input the second feature value to the large language model, and determine, via the large language model, whether to add the second feature value to the third feature value set;

[0196] a selection module 43 configured to select some third eigenvalues from the third eigenvalue set based on an importance parameter of each third eigenvalue in the third eigenvalue set, to obtain a fourth eigenvalue set; wherein the fourth eigenvalue set includes the selected third eigenvalues;

[0197] The sending module 44 is used to send the fourth eigenvalue set to the cloud device, so that the cloud device determines the password security assessment result of the Internet of Things terminal device based on the fourth eigenvalue set, wherein the password security assessment result is that the password application is secure or the password application is insecure.

[0198] Exemplarily, when the processing module 42 filters the second eigenvalues in the second eigenvalue set to obtain the third eigenvalue set, it is specifically used to: for each second eigenvalue, obtain the attribute information and data security parameters corresponding to the second eigenvalue; wherein, if the second eigenvalue corresponds to the cryptographic algorithm call chain data, the attribute information is the data type of the data to be processed; if the second eigenvalue corresponds to the critical path behavior log, the attribute information is the path information of the critical path; if the second eigenvalue corresponds to the encrypted traffic, the attribute information is the destination IP address or source IP address of the encrypted traffic; if the second eigenvalue corresponds to the physical layer operation data, the attribute information is the unique device identifier of the IoT terminal device;

[0199] If the attribute information is inconsistent with the attribute field of the security detection template, it is determined that the second feature value does not match the security detection template; if the attribute information is consistent with the attribute field of the security detection template, and the data security parameter does not match the standard field of the security detection template, it is determined that the second feature value does not match the security detection template; if the attribute information is consistent with the attribute field of the security detection template, and the data security parameter matches the standard field of the security detection template, it is determined that the second feature value matches the security detection template;

[0200] If the data security parameter is consistent with the standard field of the security detection template, then the data security parameter matches the standard field of the security detection template; or,

[0201] If the data security parameter is inconsistent with the standard field of the security detection template, and the first security level corresponding to the data security parameter is not less than the second security level corresponding to the standard field of the security detection template, then the data security parameter matches the standard field of the security detection template; if the first security level is less than the second security level, then the data security parameter does not match the standard field of the security detection template.

[0202] Exemplarily, when the processing module 42 filters the second feature values in the second feature value set to obtain the third feature value set, it is specifically configured to: for each second feature value, obtain the type of cryptographic application data corresponding to the second feature value, and obtain a reference prompt word corresponding to the type; wherein the reference prompt word indicates that the second feature value corresponds to cryptographic algorithm call chain data, or the second feature value corresponds to a critical path behavior log, or the second feature value corresponds to encrypted traffic, or the second feature value corresponds to physical layer operation data; input the reference prompt word and the second feature value into the large language model; select a target security detection template corresponding to the reference prompt word from all configured security detection templates using the large language model, and determine the template feature value corresponding to the target security detection template; calculate the similarity between the second feature value and each template feature value using the large language model; if any similarity is greater than a threshold, determine not to add the second feature value to the third feature value set; if all similarities are less than the threshold, determine to add the second feature value to the third feature value set.

[0203] Exemplarily, the importance parameter includes a contribution parameter value and a similarity parameter value; the selection module 43 selects some third eigenvalues from the third eigenvalue set based on the importance parameter of each third eigenvalue in the third eigenvalue set, and is specifically used to obtain the fourth eigenvalue set: for each third eigenvalue in the third eigenvalue set, use the local sensitive hashing algorithm to determine the contribution parameter value of the third eigenvalue; sort all third eigenvalues in descending order based on the contribution parameter value; based on the sorting result, select the top K third eigenvalues; for each selected third eigenvalue, calculate the similarity parameter value of the third eigenvalue and each eigenvalue in the LRU queue; if any similarity parameter value is not less than the similarity threshold, prohibit the third eigenvalue from being added to the fourth eigenvalue set; if all similarity parameter values are less than the similarity threshold, add the third eigenvalue to the fourth eigenvalue set, and store the third eigenvalue in the LRU queue;

[0204] After the third eigenvalue is stored in the LRU queue, if the number of eigenvalues in the LRU queue is not greater than the quantity threshold, the LRU queue is kept unchanged; if the number of eigenvalues in the LRU queue is greater than the quantity threshold, the first eigenvalue in the LRU queue is deleted.

[0205] Based on the same application concept as the above method, the present application embodiment proposes an electronic device (such as the Internet of Things terminal device, edge layer device, and cloud device in the above embodiment), see Figure 5As shown, the electronic device includes: a processor 51 and a machine-readable storage medium 52, the machine-readable storage medium 52 stores machine-executable instructions that can be executed by the processor 51; the processor 51 is used to execute the machine-executable instructions to implement the large model-based Internet of Things system cryptographic application security assessment method disclosed in the above example of this application.

[0206] Based on the same application concept as the above method, an embodiment of the present application provides a machine-readable storage medium, on which a number of computer instructions are stored. When the computer instructions are executed by a processor, the large model-based Internet of Things system cryptographic application security assessment method disclosed in the above example can be implemented.

[0207] The machine-readable storage medium may be any electronic, magnetic, optical, or other physical storage device that may contain or store information, such as executable instructions, data, and the like. For example, the machine-readable storage medium may be: RAM (Random Access Memory), volatile memory, non-volatile memory, flash memory, a storage drive (such as a hard disk drive), a solid-state drive, any type of storage disk (such as a CD, DVD, etc.), or similar storage media, or a combination thereof.

[0208] Based on the same application concept as the above method, an embodiment of the present application also provides a computer program product, including a computer program, which, when executed by a processor, implements the large model-based Internet of Things system cryptographic application security assessment method disclosed in the above example of the present application.

[0209] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may take the form of a fully hardware embodiment, a fully software embodiment, or an embodiment combining software and hardware. Furthermore, the embodiments of the present application may take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to magnetic disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0210] The foregoing is merely an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent replacements, improvements, etc. made within the spirit and principles of the present application should all be included within the scope of the claims of the present application.

Claims

1. A large-scale model-based cryptographic application security assessment method for an Internet of Things system, characterized by: The Internet of Things system includes an Internet of Things terminal device, an edge layer device, and a cloud device. The method includes: The IoT terminal device obtains a data set and a first eigenvalue set; the data set includes a plurality of multimodal data, and the multimodal data includes at least two types of cryptographic application data; the first eigenvalue set includes a first eigenvalue of each cryptographic application data; for each cryptographic application data, the data security parameter corresponding to the cryptographic application data is processed to obtain the first eigenvalue of the cryptographic application data; The Internet of Things terminal device performs a dimensionality reduction operation on the first eigenvalue in the first eigenvalue set to obtain a second eigenvalue set, and sends the second eigenvalue set to the edge layer device; The edge layer device filters the second feature values in the second feature value set to obtain a third feature value set; wherein, for each second feature value, if the second feature value does not match the configured security detection template, the second feature value is added to the third feature value set; or, the second feature value is input to the large language model, and the large language model determines whether to add the second feature value to the third feature value set; or, if the second feature value does not match the security detection template, the second feature value is input to the large language model, and the large language model determines whether to add the second feature value to the third feature value set; The edge layer device selects some third eigenvalues from the third eigenvalue set based on the importance parameter of each third eigenvalue in the third eigenvalue set to obtain a fourth eigenvalue set, the fourth eigenvalue set including the selected third eigenvalues, and sends the fourth eigenvalue set to the cloud device; The cloud device inputs the fourth eigenvalue set into the large model to obtain a password security assessment result of the Internet of Things terminal device, where the password security assessment result is that the password application is secure or the password application is insecure.

2. The method according to claim 1, characterized in that For each multimodal data, the multimodal data includes at least two of the following types of cryptographic application data: Cryptographic algorithm call chain data, the cryptographic algorithm call chain data including security operation information generated when at least one security algorithm is used to perform security operations on data to be processed; wherein, based on the cryptographic algorithm call chain data, a data security parameter corresponding to the at least one security algorithm is obtained, and the data security parameter is quantified to obtain a first eigenvalue of the cryptographic algorithm call chain data; A critical path behavior log, wherein the critical path behavior log includes operation information generated when operating on the critical path; wherein a plurality of critical path behavior logs are screened for abnormal behavior to obtain a critical path behavior log containing abnormal behavior; a data security parameter is obtained based on the critical path behavior log; and the data security parameter is quantified to obtain a first characteristic value of the critical path behavior log; Encrypted traffic; wherein, multiple encrypted traffic flows are classified and processed to obtain encrypted traffic flows that match the configured address information, a data security parameter is obtained based on the encrypted traffic flows, and the data security parameter is quantified to obtain a first characteristic value of the encrypted traffic flows; wherein, for encrypted traffic sent by the present IoT terminal device to other devices, whether the destination address matches the address information is determined; and for encrypted traffic sent by other devices to the present IoT terminal device, whether the source address matches the address information is determined; Physical layer operation data, the physical layer operation data including key device operation data generated during the operation of the Internet of Things terminal device; wherein, the physical layer operation data is subjected to a fast Fourier transform to obtain power consumption curves of multiple frequency bands; data security parameters are obtained based on the power consumption curve of each frequency band, and the data security parameters are quantified to obtain a first eigenvalue of the physical layer operation data.

3. The method according to claim 2, characterized in that The edge layer device filters the second eigenvalues in the second eigenvalue set to obtain a third eigenvalue set, including: For each second characteristic value, the edge layer device obtains attribute information and data security parameters corresponding to the second characteristic value; wherein, if the second characteristic value corresponds to cryptographic algorithm call chain data, the attribute information is the data type of the data to be processed; if the second characteristic value corresponds to the critical path behavior log, the attribute information is the path information of the critical path; if the second characteristic value corresponds to encrypted traffic, the attribute information is the destination IP address or source IP address of the encrypted traffic; if the second characteristic value corresponds to physical layer operation data, the attribute information is the unique device identifier of the IoT terminal device; If the attribute information is inconsistent with the attribute field of the security detection template, it is determined that the second feature value does not match the security detection template; if the attribute information is consistent with the attribute field of the security detection template, and the data security parameter does not match the standard field of the security detection template, it is determined that the second feature value does not match the security detection template; if the attribute information is consistent with the attribute field of the security detection template, and the data security parameter matches the standard field of the security detection template, it is determined that the second feature value matches the security detection template; If the data security parameter is consistent with the standard field of the security detection template, then the data security parameter matches the standard field of the security detection template; or, If the data security parameter is inconsistent with the standard field of the security detection template, and the first security level corresponding to the data security parameter is not less than the second security level corresponding to the standard field of the security detection template, then the data security parameter matches the standard field of the security detection template; if the first security level is less than the second security level, then the data security parameter does not match the standard field of the security detection template.

4. The method according to claim 2, characterized in that The edge layer device filters the second eigenvalues in the second eigenvalue set to obtain a third eigenvalue set, including: For each second characteristic value, obtaining a type of cryptographic application data corresponding to the second characteristic value, and obtaining a reference prompt word corresponding to the type; wherein the reference prompt word indicates that the second characteristic value corresponds to cryptographic algorithm call chain data, or the second characteristic value corresponds to a critical path behavior log, or the second characteristic value corresponds to encrypted traffic, or the second characteristic value corresponds to physical layer operation data; Inputting the reference prompt word and the second feature value into the large language model; Selecting a target security detection template corresponding to the reference prompt word from all configured security detection templates using the large language model, and determining a template feature value corresponding to the target security detection template; The large language model is used to calculate the similarity between the second eigenvalue and each template eigenvalue; if any similarity is greater than a threshold, it is determined not to add the second eigenvalue to the third eigenvalue set; if all similarities are not greater than the threshold, it is determined to add the second eigenvalue to the third eigenvalue set.

5. The method according to claim 1, wherein The importance parameters include contribution parameter values and similarity parameter values; The edge layer device selects some third eigenvalues from the third eigenvalue set based on the importance parameter of each third eigenvalue in the third eigenvalue set to obtain a fourth eigenvalue set, including: For each third eigenvalue in the third eigenvalue set, determine a contribution parameter value of the third eigenvalue using a locality sensitive hashing algorithm; sort all the third eigenvalues in descending order based on the contribution parameter values; and select the top K third eigenvalues based on the sorting results; For each selected third eigenvalue, calculate a similarity parameter value between the third eigenvalue and each eigenvalue in the LRU queue; if any similarity parameter value is not less than a similarity threshold, prohibit adding the third eigenvalue to the fourth eigenvalue set; if all similarity parameter values are less than the similarity threshold, add the third eigenvalue to the fourth eigenvalue set and store the third eigenvalue in the LRU queue; After the third eigenvalue is stored in the LRU queue, if the number of eigenvalues in the LRU queue is not greater than the quantity threshold, the LRU queue is kept unchanged; if the number of eigenvalues in the LRU queue is greater than the quantity threshold, the first eigenvalue in the LRU queue is deleted.

6. The method according to claim 1, characterized in that The large model includes a first feature extraction network and a password security knowledge graph, wherein the first feature extraction network is used to extract feature vectors of binary modal data, and the password security knowledge graph includes multiple nodes, each node corresponding to a graph feature vector and password security assessment information, wherein the password security assessment information indicates whether the password application is secure or insecure; The cloud device inputs the fourth eigenvalue set into the large model to obtain a password security assessment result of the IoT terminal device, including: Inputting the fourth eigenvalue set into the first feature extraction network, and extracting a first device feature vector corresponding to the fourth eigenvalue set through the first feature extraction network; Calculating the similarity between the first device feature vector and the graph feature vector of each node using the large model; selecting a first target node from the password security knowledge graph based on the similarity; If the cryptographic security assessment information of the first target node indicates that the cryptographic application is secure, determining that the cryptographic security assessment result of the Internet of Things terminal device is that the cryptographic application is secure; If the cryptographic security assessment information of the first target node indicates that the cryptographic application is insecure, the cryptographic security assessment result of the Internet of Things terminal device is determined to be insecure cryptographic application, and a first penetration path is obtained based on the position of the first target node in the cryptographic security knowledge graph. The first penetration path includes the first target node and a node that has a causal dependency relationship with the first target node; based on the first penetration path, the cause of the insecure cryptographic application and the cryptographic application repair suggestion are determined.

7. The method according to claim 6, characterized in that If the cryptographic security assessment information of the first target node indicates that the cryptographic application is insecure, the method further includes: The cloud device sends a data request message to the edge layer device, so that the edge layer device obtains the multimodal data from the IoT terminal device; the cloud device receives a data response message returned by the edge layer device, wherein the data response message includes the multimodal data; The cloud device generates text modal data, image modal data and time series modal data based on the multimodal data; wherein, if the multimodal data includes cryptographic algorithm call chain data, the text modal data includes cryptographic algorithm call chain data; if the multimodal data includes critical path behavior logs, the text modal data includes critical path behavior logs; if the multimodal data includes encrypted traffic and there is text data in the encrypted traffic, the text modal data includes the text data; if there is image data in the encrypted traffic, the image modal data includes the image data; if the multimodal data includes physical layer operation data, the image modal data includes physical layer operation data; wherein, the time series modal data is generated based on the time series information corresponding to the multimodal data; Inputting the fourth eigenvalue set into the first feature extraction network of the large model to obtain a first eigenvector; inputting the text modality data into the second feature extraction network of the large model to obtain a second eigenvector; inputting the image modality data into the third feature extraction network of the large model to obtain a third eigenvector; inputting the time series modality data into the fourth feature extraction network of the large model to obtain a fourth eigenvector; fusing the first eigenvector, the second eigenvector, the third eigenvector and the fourth eigenvector to obtain a second device feature vector; Calculating the similarity between the second device feature vector and the graph feature vector of each node using the large model; selecting a second target node from the password security knowledge graph based on the similarity; If the cryptographic security assessment information of the second target node indicates that the cryptographic application is insecure, the cryptographic security assessment result of the Internet of Things terminal device is determined to be insecure cryptographic application, and a second penetration path is obtained based on the position of the second target node in the cryptographic security knowledge graph. Based on the second penetration path, the cause of the insecure cryptographic application and the cryptographic application repair suggestion are determined.

8. The method according to claim 6, characterized in that After determining the reason for the insecurity of the password application and the password application repair suggestion based on the first penetration path, the method further includes: generating a password compliance policy based on the reasons for the insecure password application and the password application repair suggestions; Deploying the password compliance policy in a sandbox environment of the cloud device to execute the password compliance policy in the sandbox environment to perform security operations on data; Determine a reward value corresponding to the password compliance policy based on the security gain, system efficiency, and operating cost corresponding to the password compliance policy; wherein the security gain represents the degree of compliance of the password compliance policy with preset rules, the system efficiency represents the change in service delay after the password compliance policy is executed, and the operating cost represents the number of device connection interruptions after the password compliance policy is executed; If the reward value is greater than the threshold, the password compliance policy is deployed to the Internet of Things terminal device; if the reward value is not greater than the threshold, the password compliance policy is prohibited from being deployed to the Internet of Things terminal device.

9. A large-scale model-based cryptographic application security assessment method for an Internet of Things system, characterized in that: The method is applied to an edge layer device in an Internet of Things system, and the method includes: Obtaining a second eigenvalue set, where the second eigenvalue set is obtained by performing a dimensionality reduction operation on the first eigenvalue set by the IoT terminal device; the first eigenvalue set includes a first eigenvalue of the cryptographic application data, where the first eigenvalue is obtained by processing a data security parameter corresponding to the cryptographic application data; The second feature values in the second feature value set are screened to obtain a third feature value set; wherein, for each second feature value, if the second feature value does not match the configured security detection template, the second feature value is added to the third feature value set; or, the second feature value is input to the large language model, and the large language model determines whether to add the second feature value to the third feature value set; or, if the second feature value does not match the security detection template, the second feature value is input to the large language model, and the large language model determines whether to add the second feature value to the third feature value set; Based on the importance parameter of each third eigenvalue in the third eigenvalue set, some third eigenvalues are selected from the third eigenvalue set to obtain a fourth eigenvalue set, the fourth eigenvalue set includes the selected third eigenvalues, and the fourth eigenvalue set is sent to the cloud device so that the cloud device determines the password security assessment result of the Internet of Things terminal device based on the fourth eigenvalue set, wherein the password security assessment result is that the password application is secure or the password application is insecure.

10. An Internet of Things system, characterized in that: The Internet of Things system includes: An IoT terminal device is configured to obtain a data set and a first eigenvalue set; the data set includes a plurality of multimodal data, and the multimodal data includes at least two types of cryptographic application data; the first eigenvalue set includes a first eigenvalue of each cryptographic application data; for each cryptographic application data, processing a data security parameter corresponding to the cryptographic application data to obtain the first eigenvalue of the cryptographic application data; and performing a dimensionality reduction operation on the first eigenvalue in the first eigenvalue set to obtain a second eigenvalue set, and sending the second eigenvalue set to an edge layer device; An edge layer device, configured to filter the second feature values in the second feature value set to obtain a third feature value set; wherein, for each second feature value, if the second feature value does not match the configured security detection template, the second feature value is added to the third feature value set; or, the second feature value is input to the large language model, and the large language model is used to determine whether to add the second feature value to the third feature value set; or, if the second feature value does not match the security detection template, the second feature value is input to the large language model, and the large language model is used to determine whether to add the second feature value to the third feature value set; and, based on an importance parameter of each third feature value in the third feature value set, select some third feature values from the third feature value set to obtain a fourth feature value set, the fourth feature value set including the selected third feature values, and send the fourth feature value set to the cloud device; The cloud device is used to input the fourth eigenvalue set into the large model to obtain a password security assessment result of the Internet of Things terminal device, where the password security assessment result is that the password application is secure or the password application is insecure.

Citation Information

Patent Citations

  • Enterprise equal insurance processing and password application intelligent evaluation system based on big data

    CN119885187A

  • Calculation of Security Risk Score of Network Security Services

    US20240163312A1