Cryptographic equipment fault diagnosis and repair system and method based on artificial intelligence
Through the AI-based password device fault diagnosis and repair system, the problems of low fault diagnosis efficiency and long repair in the existing technology are solved, and fast and accurate fault diagnosis and automated repair are achieved, which improves the stability and reliability of password devices.
Patent Information
- Application Number
- CN202510487803.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-18
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2045-04-18
AI Technical Summary
The existing cryptographic equipment fault diagnosis methods are inefficient and take time to repair, making it difficult to quickly and accurately determine the cause of the fault, and manual intervention is prone to introduce new problems.
The cryptographic equipment fault diagnosis and repair system based on artificial intelligence is adopted, and the mapping relationship between fault types and data characteristics is learned through artificial intelligence modules, and faults are diagnosed based on the input data characteristics and repair instructions are generated. Combined with the data preprocessing module and the certificate management module, automated fault repair is achieved.
It improves the speed and accuracy of fault diagnosis of password equipment, reduces the time and cost of manual intervention, shortens fault downtime, improves the availability and stability of password equipment, and ensures the confidentiality and integrity of data transmission.
Smart Images

Figure CN120223306A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical fields of artificial intelligence and cryptographic device management, and more particularly to a cryptographic device fault diagnosis and repair system and method based on artificial intelligence. Background Art
[0002] Currently, traditional cryptographic device fault diagnosis methods mainly rely on manual experience and simple rule matching. For example, by checking the error logs of the cryptographic operation service, checking the error information in the system logs, checking the indicator lights of the cryptographic card, etc. to determine the type of fault. However, this method has obvious limitations. There are many types of faults and complex fault phenomena in cryptographic devices, and it is difficult for humans to quickly and accurately determine the cause of the fault. Moreover, simple rule matching is difficult to handle new and complex fault scenarios, resulting in low fault diagnosis efficiency.
[0003] In terms of fault repair, currently it mainly relies on manual intervention. According to the diagnosed cause of the fault, corresponding repair operations are carried out, such as adjusting software configuration, re-creating virtual cryptographic machines and importing backup data, switching to standby cryptographic cards, etc. This method not only takes a long time, affects the normal operation of cryptographic devices, resulting in business interruption, but also easily introduces new problems due to human operation errors. Summary of the Invention
[0004] In view of this, the present invention provides a cryptographic device fault diagnosis and repair system and method based on artificial intelligence, mainly realizing that the cryptographic device management platform diagnoses and automatically repairs the faults of the cryptographic devices (including but not limited to server cryptographic machines, cloud server cryptographic machines, signature verification servers, timestamp servers, security integrated gateways) managed through artificial intelligence, so as to solve the problems of low efficiency of existing cryptographic device fault diagnosis and long time-consuming for fault repair, and improve the stability and reliability of cryptographic devices.
[0005] To achieve the above object, the present invention adopts the following technical solutions:
[0006] In a first aspect, an embodiment of the present invention provides a cryptographic device fault diagnosis and repair system based on artificial intelligence, including:
[0007] A cryptographic device management platform, including an artificial intelligence module, a data preprocessing module, and a certificate management module;
[0008] A cryptographic device, including a device management service module;
[0009] Wherein, the cryptographic device management platform communicates with the cryptographic device through a two-way SSL channel generated by the certificate management module;
[0010] The artificial intelligence module is used to train and learn the mapping relationship between the failure types of the cryptographic device and the characteristics of the failure data, as well as the mapping relationship between the failure types and the repair instructions; and is used to diagnose failures and generate repair instructions according to the input data characteristics.
[0011] The data preprocessing module cleans, unifies the format, fills in missing values, and performs correlation analysis and screening on the data collected from the cryptographic device side, and transmits the processed data to the artificial intelligence module.
[0012] The device management service module is used to manage the cryptographic device, collect data, parse and execute the repair instructions generated by the artificial intelligence module, and complete the failure repair.
[0013] Furthermore, the device management service module includes a device management module, a failure repair module, and a data collection module.
[0014] Among them, the device management module is used to implement the functions of device service configuration and startup, backup key, restore key, create a virtual cryptographic machine, and start a virtual cryptographic machine.
[0015] The failure repair module is used to parse and execute the repair instructions sent by the cryptographic device management platform; and push the repair record to the device management platform; the record content includes the repair time, repair result, and repair instructions.
[0016] The data collection module is used to collect the running data of the cryptographic device in real time, including CPU usage rate, memory usage rate, cryptographic card usage rate, temperature, and voltage data; and also collect the software-level data of the cryptographic device, including: system log, operation log, security log, cryptographic operation service log, and cryptographic card interface log.
[0017] Furthermore, the training process of the artificial intelligence module includes:
[0018] Using the historical failure data set collected by the device management service module, training a failure diagnosis model through a supervised learning algorithm, and the supervised learning algorithm includes one or a combination of a convolutional neural network CNN, a recurrent neural network RNN, and a long short-term memory network LSTM.
[0019] Training a repair instruction generation model, and the model is based on a reinforcement learning framework to generate combined repair instructions according to different failure types.
[0020] Furthermore, the data preprocessing module is specifically used for:
[0021] Data integrity check, using filling methods such as mean / median filling method and interpolation method to fill in the data with missing values and null values; and unifying the data format.
[0022] Remove invalid data, including duplicate records and data irrelevant to fault diagnosis;
[0023] For system operation data, extract the mean, variance, and peak value, and extract abnormal data by comparing statistical data;
[0024] Extract error identification logs from the software-level data of the cryptographic device.
[0025] Further, the establishment process of the bidirectional SSL channel includes:
[0026] The certificate management module generates bidirectional SSL channel certificates based on the national cryptographic SM2. The national cryptographic double certificates include encryption certificates and signature certificates;
[0027] The cryptographic device management platform issues the bidirectional SSL channel certificates to the device management service module through device management messages.
[0028] Further, the fault repair module executes the repair instructions sent by the cryptographic device management platform, including:
[0029] For hardware faults, execute the operation of switching to the standby cryptographic card or restoring the key;
[0030] For software faults, execute the combined instructions of recreating and starting the virtual cryptographic machine and restoring the virtual cryptographic machine data;
[0031] When the repair fails, automatically roll back to the previous stable state and trigger an artificial intervention alarm.
[0032] In a second aspect, an embodiment of the present invention further provides an artificial intelligence-based cryptographic device fault diagnosis and repair method, which uses the artificial intelligence-based cryptographic device fault diagnosis and repair system described in any embodiment of the first aspect, including the following steps:
[0033] S1: Train the artificial intelligence module to establish the mapping relationships between fault types and data characteristics, and between fault types and repair instructions;
[0034] S2: Establish a bidirectional SSL communication channel between the cryptographic device management platform and the cryptographic device;
[0035] S3: Collect the operation data and fault data of the cryptographic device and perform preprocessing;
[0036] S4: Diagnose the fault type through the trained artificial intelligence module and generate repair instructions;
[0037] S5: Execute the repair instructions and record the repair results. For faults that cannot be repaired, trigger artificial intervention;
[0038] S6: Input the artificial repair solution into the artificial intelligence module for continuous optimization.
[0039] As can be seen from the above technical solutions, compared with the prior art, the present invention has the following technical advantages:
[0040] Fault diagnosis based on artificial intelligence can quickly analyze a large amount of data, accurately identify the types and causes of faults, and greatly improve the diagnosis speed and accuracy compared with traditional manual diagnosis and simple rule matching. And it can execute repair operations according to the repair instructions formulated by the artificial intelligence module, reducing the time and cost of manual intervention, shortening the fault downtime of the cryptographic device, and improving its availability and stability. In addition, the two-way SSL channel established by the certificate management module ensures the confidentiality, integrity of data transmission between the cryptographic device management platform and the cryptographic device, and the authenticity of the identities of both communication parties, preventing man-in-the-middle attacks or data tampering. BRIEF DESCRIPTION OF THE DRAWINGS
[0041] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained according to the provided drawings.
[0042] Figure 1 It is a structural block diagram of a cryptographic device fault diagnosis and repair system based on artificial intelligence provided by the present invention.
[0043] Figure 2 It is an overall flowchart of a cryptographic device fault diagnosis and repair method based on artificial intelligence provided by the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0044] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0045] Referring to Figure 1 As shown, an embodiment of the present invention discloses a cryptographic device fault diagnosis and repair system based on artificial intelligence, including:
[0046] A cryptographic device management platform, which includes an artificial intelligence module, a data preprocessing module, and a certificate management module; supports device management message definition and SSL communication;
[0047] The cryptographic device includes a device management service module, which further includes a device management module, a fault repair module, and a data collection module to implement data collection, configuration management, and repair execution.
[0048] The following is a detailed description of each of the above modules:
[0049] Hardware environment:
[0050] The cryptographic device management platform, for example, is deployed on a server with a 4-core CPU and 16GB of memory, equipped with an NVIDIA T4 GPU for accelerated model inference;
[0051] The cryptographic devices are deployed in a cluster, including but not limited to server cryptographic machines, cloud server cryptographic machines, signature verification servers, timestamp servers, security integrated gateways, etc.
[0052] 1. The cryptographic device management platform includes an artificial intelligence module, a data preprocessing module, and a certificate management module, and predefines a set of device management messages to improve the compatibility of device management. It includes messages for fault data collection, system operation data collection, device fault repair, device configuration, etc.
[0053] 1.1 The artificial intelligence module includes two functions: fault diagnosis and formulating fault repair instructions.
[0054] The artificial intelligence module, such as large language models using the transformer architecture, including but not limited to Qwen, Llama.
[0055] Adopt deep learning algorithms to construct a fault-diagnosis-repair model. For example, specifically use a combination of convolutional neural network (CNN), recurrent neural network (RNN), and long short-term memory network (LSTM). CNN can effectively extract local features in data and has advantages in processing image-like features in hardware operation data (such as feature maps generated through data visualization); RNN and LSTM are good at processing time series data and are effective in analyzing time series information in system logs (such as the time sequence of fault occurrences and the time correlation of operation steps).
[0056] The training data comes from the historical fault data of the cryptographic device. Use the historical fault data-solution to train the deep learning model, and update the network parameters through the backpropagation algorithm. According to the performance of the model on the validation set, adjust the hyperparameters of the model, such as learning rate, batch size, number of network layers, etc. Use tuning methods such as grid search and random search to define the value range of hyperparameters and select the hyperparameter combination with the best performance on the validation set.
[0057] The training process includes:
[0058] 1) Using the historical fault data set collected by the device management service module, a fault diagnosis model is trained through a supervised learning algorithm, and the supervised learning algorithm includes one or a combination of a convolutional neural network CNN, a recurrent neural network RNN, and a long short-term memory network LSTM;
[0059] 2) Train a repair instruction generation model, which is based on a reinforcement learning framework and generates combined repair instructions according to different fault types.
[0060] By training the artificial intelligence module, the model learns the mapping relationship between different fault types of the cryptographic device and the fault data features, as well as the mapping relationship between different fault types and repair instructions. The artificial intelligence module diagnoses the fault type according to the input data features.
[0061] The artificial intelligence module designs a perfect repair process and repair instructions for the device fault according to the mapping relationship between different fault types and repair instructions. For hardware faults, such as detecting a password card fault, a combination of instructions such as switching to a standby password card and restoring the password card key is formulated; for software faults, such as a virtual machine startup failure fault, a combination of instructions such as recreating and starting a virtual password machine and restoring the virtual password machine data is formulated, and the instructions are sent down through the device management service. Especially when the repair fails, it automatically rolls back to the previous stable state and triggers an artificial intervention alarm.
[0062] For example:
[0063] (1) The fault diagnosis model (supervised learning) of the artificial intelligence module adopts a CNN-LSTM hybrid architecture:
[0064] CNN part:
[0065] Input layer, receiving the temporal features of the hardware operation data (such as CPU usage rate, temperature, etc.) (dimension: n×m, n is the time step, m is the number of features). Convolutional layer: 2 layers, 32 filters in each layer (size 3×3), activation function ReLU, max pooling layer (pooling size 2×2). Output: flattened into a 1D feature vector.
[0066] LSTM part:
[0067] Input layer: receiving the time series data of the software log (such as the error log timestamp sequence).
[0068] LSTM layer: 2 layers, 64 hidden units in each layer, Dropout rate 0.2.
[0069] Fully connected layer: After concatenating the outputs of CNN and LSTM, input them into the fully connected layer (128 neurons, activation function ReLU), and output the probability distribution of the fault type.
[0070] The loss function is cross-entropy loss. The optimizer uses Adam, with a learning rate of 0.001, decay rates β1 = 0.9 and β2 = 0.999.
[0071] (2)The repair instruction generation model of the artificial intelligence module (based on reinforcement learning) adopts the Deep Deterministic Policy Gradient (DDPG) architecture:
[0072] Actor network:
[0073] Input: Fault type encoding (One-hot vector) and real-time device status (such as resource occupancy rate).
[0074] Structure: 3 fully connected layers (256 - 128 - 64 neurons, activation function ReLU), outputting the continuous action space of repair instructions.
[0075] Critic network:
[0076] Input: Actor output action and device status.
[0077] Structure: 2 fully connected layers (128 - 64 neurons), outputting Q-value evaluation.
[0078] Reward function:
[0079] Successful repair: +10; Failed repair: -5; Partial repair (requiring manual intervention): +2.
[0080] Time penalty: -0.1 per second of delay.
[0081] (3)Data standards and feature engineering
[0082] Data cleaning rules: Records with a null value ratio ≥ 30% are directly excluded. Sensor data outside the measurement range (such as CPU usage > 100%) is considered invalid. Missing value filling: Using linear interpolation method. Categorical data: Using the mode for filling.
[0083] Feature screening, using Pearson correlation coefficient (threshold ≥ 0.7) to screen features strongly related to the fault type.
[0084] Example: The correlation coefficient between the CPU peak value and the "virtual machine resource competition fault" ≥ 0.7, retain this feature.
[0085] (4)Model training parameters
[0086] 1)Supervised learning training
[0087] Dataset division:
[0088] Training set: 70%, Validation set: 15%, Test set: 15%.
[0089] Hyperparameters:
[0090] Batch size: 64, number of iterations: 200, early stopping mechanism (terminate when the validation loss does not decrease for 5 consecutive times).
[0091] Learning rate scheduling: Cosine annealing (initial 0.001, minimum 0.0001).
[0092] 2) Reinforcement learning training
[0093] Exploration strategy: ε-greedy (initial ε = 0.9, decay rate 0.99).
[0094] Experience replay: Buffer capacity 10 4 , sampling batch 32.
[0095] Target network update: Soft update (τ = 0.01).
[0096] (5) Validation and evaluation
[0097] Diagnostic accuracy: Test set accuracy ≥ 95% (while the traditional method is 70%).
[0098] Repair success rate: Automated repair success rate ≥ 90%, average repair time ≤ 5 minutes.
[0099] Comparative experiment:
[0100] Baseline comparison: Compared with traditional rule engines (such as Drools), the fault diagnosis speed is increased by 3 times.
[0101] Ablation experiment: Verify the advantage of the CNN-LSTM hybrid model compared to a single model (accuracy improvement of 12%).
[0102] The artificial intelligence module of the present invention adopts a hybrid neural network architecture (CNN-LSTM), a reinforcement learning strategy (DDPG), through quantitative evaluation metrics (accuracy 95%), by analyzing the real-time data of the cryptographic device, accurately identifying the fault type and cause, compared with traditional manual diagnosis and simple rule matching, greatly improving the diagnosis speed and accuracy. And it can execute repair operations according to the repair instructions formulated by the artificial intelligence module, reducing the time and cost of manual intervention, shortening the fault downtime of the cryptographic device, and improving its usability and stability.
[0103] 1.2. Data preprocessing module, which cleans the data collected from the cryptographic device side (removing invalid data, unifying data formats, filling in missing data, etc.), and screens the fault data and operation data. And transmits the processed data to the artificial intelligence module. The screening method is as follows:
[0104] 1) Data integrity check. Use the filling methods of mean / median filling method and interpolation method to fill in the data with missing values and null values, and unify the data formats, such as dates, times, operation information, etc., for easy data elimination, comparison, and analysis.
[0105] 2) Remove invalid data, including duplicate records and data irrelevant to fault diagnosis. For example, use the Spearman rank correlation coefficient and set the threshold ≤ 0 to represent negative correlation and irrelevance, and eliminate the invalid data.
[0106] 3) For the system operation data, extract the mean, variance, and peak value, and extract abnormal data by comparing the statistical data.
[0107] 4) Extract the error identification log from the software-level data of the cryptographic device.
[0108] In this embodiment, for the system operation index data, extract statistical data such as the mean, variance, and peak value, and extract abnormal data by comparing the statistical data. For example, by comparing the mean, variance, and peak value of the CPU usage rate over a period of time, extract abnormal CPU usage data, etc. In addition, use the correlation analysis algorithm to calculate the correlation coefficient between the data features and the known fault types, and remove the data with low correlation.
[0109] 1.3 When the cryptographic device management platform incorporates a cryptographic device, establish a two-way SSL channel with the cryptographic device.
[0110] 1) When the administrator configures the cryptographic device management platform to incorporate a cryptographic device, the certificate management module generates an SSL certificate according to the established security policy and encryption algorithm. For example, by default, generate a national cryptography SM2 two-way SSL channel certificate. The national cryptography double certificates include an encryption certificate and a signature certificate. This certificate contains key contents such as the identity information, public key, and validity period of the platform. Subsequently, the cryptographic device management platform distributes the SSL certificate to the device management service module of the cryptographic device through a pre-defined device management message. Among them, the pre-defined device management message includes management messages such as fault data collection, system operation data collection, device fault repair, device configuration, virtual machine creation, virtual machine start, and virtual machine stop, and can specifically be in the restful format.
[0111] 2) The device management platform loads the SSL certificate and establishes a two-way SSL channel with the device management service. Thereafter, the data transmission between the platform and the cryptographic device is all carried out through this SSL channel, effectively ensuring the confidentiality, integrity, and identity authenticity of both communication parties.
[0112] 2. A cryptographic device, including a device management service module. The device management service module mainly includes a device management module, a fault repair module, and a data acquisition module. To meet the management requirements of the device management platform, the three modules respectively implement the device configuration interface function, the device fault repair interface function, and the data acquisition interface function.
[0113] 2.1 The device management module is mainly responsible for functions such as device service configuration and startup, backup key, restore key, create virtual cryptographic machine, start virtual cryptographic machine, etc.
[0114] 2.2 The fault repair module is used to parse and execute the repair instructions sent by the device management platform, such as calling the device management module to perform combined operations such as device configuration modification, password operation service startup, and virtual machine fault drift. And push the repair record to the device management platform. The record content includes repair time, repair result, repair instructions, etc.
[0115] 2.3 The data acquisition function module collects the running data of the cryptographic device in real time, including CPU usage rate, memory usage rate, cryptographic card usage rate, temperature, voltage, etc. At the same time, it collects software-level data such as the system log, operation log, security log, password operation service log, and cryptographic card interface log of the cryptographic device; provides the collected data for the data preprocessing module.
[0116] In addition, the device management platform provides functions for manual intervention, viewing repair records, and configuring the fault acquisition module. The administrator can perform manual repairs on faults that cannot be repaired by the artificial intelligence module through the device management platform, view historical repair records, and configure the acquisition cycle, acquisition range parameters, etc. of the fault acquisition module. Input the repair solution into the artificial intelligence module for continuous learning and optimization.
[0117] Refer to Figure 2 As shown, the embodiment of the present invention also provides an artificial intelligence-based cryptographic device fault diagnosis and repair method, based on the artificial intelligence-based cryptographic device fault diagnosis and repair system of the above embodiment. The specific process includes:
[0118] Step 1. Train the artificial intelligence module so that the model learns the mapping relationship between different fault types and fault data characteristics and the mapping relationship between different fault types and repair instructions. Among them, the artificial intelligence module can diagnose the fault type and formulate repair instructions according to the input data characteristics.
[0119] Step 2. The administrator configures a bidirectional SSL channel between the cryptographic device management platform and the cryptographic device. Subsequently, send a request to the device management module to configure parameters such as the acquisition cycle of the data acquisition module.
[0120] Step 3. The data acquisition module collects the running data and fault data of the software and hardware layers and uploads them to the device management platform.
[0121] Step 4. The data preprocessing module cleans the collected data, screens the fault data and operation data, and transfers the processed data to the artificial intelligence module. This includes removing invalid data, unifying the data format, filling in missing data, etc., and screening the fault data and operation data to reduce the impact of invalid data, so as to improve the diagnosis efficiency and accuracy of the artificial intelligence module.
[0122] Step 5. The trained artificial intelligence module receives the fault data and conducts fault diagnosis. According to the mapping relationship between different fault types of the cryptographic device and the characteristics of the fault data, it accurately identifies the fault type and cause.
[0123] Step 6. The artificial intelligence module designs a perfect repair process and repair instructions for the device fault according to the mapping relationship between different fault types and repair instructions, and sends them to the device management service.
[0124] Step 7. The device management service transfers the repair instructions to the fault repair module. The fault repair module executes the repair instructions sent by the artificial intelligence module and pushes the repair record to the device management module. Among them, the fault repair module can execute the repair operation according to the repair instructions formulated by the artificial intelligence module, reducing the time and cost of manual intervention, shortening the fault downtime of the cryptographic device, and improving its availability and stability.
[0125] Step 8. The cryptographic device management platform alarms the un-repaired faults for manual repair, and inputs the repair solution into the artificial intelligence for continuous learning and optimization.
[0126] The present invention can improve the accuracy and efficiency of fault diagnosis of cryptographic devices: The fault diagnosis model based on artificial intelligence can quickly analyze a large amount of data and accurately identify the fault type and cause, greatly improving the diagnosis speed and accuracy compared with traditional manual diagnosis and simple rule matching. In addition, the data transmission between the cryptographic device management platform and the cryptographic device is all carried out through this SSL channel, effectively ensuring the confidentiality, integrity of the data and the identity authenticity of both communication parties.
[0127] In this specification, each embodiment is described in a progressive manner. The key point of each embodiment is to illustrate the differences from other embodiments. The same or similar parts among the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method part.
[0128] The foregoing description of the disclosed embodiments enables those skilled in the art to practice or use the present invention. Various modifications to these embodiments will be readily apparent to those skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Thus, the present invention is not intended to be limited to the embodiments shown herein but is to be accorded the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A cryptographic equipment fault diagnosis and repair system based on artificial intelligence, characterized in that: include: Cryptographic device management platform, including artificial intelligence module, data preprocessing module and certificate management module; Cryptographic devices, including device management service modules; Wherein, the cryptographic device management platform communicates with the cryptographic device through a two-way SSL channel generated by the certificate management module; The artificial intelligence module is used to learn the mapping relationship between the fault type of the cryptographic device and the fault data characteristics, and the mapping relationship between the fault type and the repair instruction through training; and is used to diagnose the fault and generate the repair instruction according to the input data characteristics; The data preprocessing module cleans, unifies the format, fills in missing values, and performs correlation analysis and screening on the data collected from the cryptographic device, and transmits the processed data to the artificial intelligence module; The device management service module is used to manage the cryptographic device, collect data, parse and execute the repair instructions generated by the artificial intelligence module, and complete fault repair.
2. The system according to claim 1, characterized in that The device management service module includes a device management module, a fault repair module and a data acquisition module; The device management module is used to implement the functions of device service configuration and startup, key backup, key recovery, virtual cryptographic machine creation, and virtual cryptographic machine startup; The fault repair module is used to parse and execute the repair instructions sent by the cryptographic device management platform; and push the repair record to the device management platform; the record content includes the repair time, repair results, and repair instructions; The data acquisition module is used to collect the operation data of the cryptographic device in real time, including CPU usage, memory usage, cryptographic card usage, temperature and voltage data; it also collects software-level data of the cryptographic device, including: system log, operation log, security log, cryptographic operation service log, and cryptographic card interface log.
3. The system according to claim 1, characterized in that The training process of the artificial intelligence module includes: Using the historical fault data set collected by the device management service module, the fault diagnosis model is trained by a supervised learning algorithm, wherein the supervised learning algorithm includes one or a combination of a convolutional neural network (CNN), a recurrent neural network (RNN), and a long short-term memory (LSTM) network; A repair instruction generation model is trained, wherein the model is based on a reinforcement learning framework and generates combined repair instructions according to different fault types.
4. The system according to claim 1, characterized in that The data preprocessing module is specifically used for: Data integrity check: use mean / median filling method and interpolation method to fill in missing values and null values; and unify the data format; Remove invalid data, including duplicate records and data irrelevant to fault diagnosis; For system operation data, extract the mean, variance, and peak value, and extract abnormal data by comparing statistical data; Extract error identification logs from the software-level data of the cryptographic device.
5. The system according to claim 1, characterized in that The process of establishing the two-way SSL channel includes: The certificate management module generates a two-way SSL channel certificate based on the national secret SM2, and the national secret double certificate includes an encryption certificate and a signature certificate; The cryptographic device management platform sends the two-way SSL channel certificate to the device management service module through the device management message.
6. The system according to claim 2, characterized in that The fault repair module executes the repair instruction sent by the cryptographic device management platform, including: In case of hardware failure, switch to backup password card or restore key. For software failure, execute a combination of instructions to recreate and start the virtual cipher machine and restore the virtual cipher machine data; When the repair fails, it automatically rolls back to the last stable state and triggers a manual intervention alarm.
7. A cryptographic device fault diagnosis and repair method based on artificial intelligence, characterized in that: Using the artificial intelligence-based cryptographic device fault diagnosis and repair system as described in any one of claims 1 to 6, comprising the following steps: S1: Train the artificial intelligence module to establish the mapping relationship between fault type and data features, and between fault type and repair instructions; S2: Establish a two-way SSL communication channel between the cryptographic device management platform and the cryptographic device; S3: Collect the operation data and fault data of the cryptographic equipment and perform preprocessing; S4: The trained AI module diagnoses the fault type and generates repair instructions; S5: Execute the repair instructions and record the repair results. If the fault is not repaired, manual intervention is triggered. S6: Input the manual repair solution into the artificial intelligence module for continuous optimization.
Citation Information
Patent Citations
Distributed password equipment management system for large-scale network and construction method
CN112905993A
Refrigerator fault intelligent diagnosis method and system based on artificial intelligence
CN119106349A
Automobile real-time fault diagnosis system and diagnosis method based on cloud interaction
CN119148683A
Computer fault diagnosis and repair system and method based on artificial intelligence
CN119396614A
Power grid fault diagnosis system and method based on big data
CN119644045A