A 5G communication server access control method and system

By utilizing edge computing architecture and dynamic resource allocation in 5G networks, users are clustered into different groups, and edge allocation weights and computing power allocation coefficients are calculated. This solves the real-time and consistency problems of access control in 5G networks and improves the accuracy and security of access control.

CN120321653BActive Publication Date: 2025-11-28HENAN SHENDE YUANYING ELECTRONIC TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510469499.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-15
Publication Date
2025-11-28
Estimated Expiration
2045-04-15

AI Technical Summary

Technical Problem

In existing 5G networks, the high mobility and short connection cycles of terminal devices make it difficult for traditional access control methods to guarantee the real-time and consistency of attribute data, leading to errors in the judgment of abnormal servers and low access control accuracy.

Method used

By acquiring user risk levels and network environment data, users are clustered into different groups using an edge computing architecture. Edge allocation weights and computing power allocation coefficients are calculated, server levels and locations are dynamically adjusted, and abnormal servers are screened for control.

Benefits of technology

It enables rapid response to 5G communication servers and dynamic resource allocation for access requests, improving the accuracy and security of access control and adapting to the complex environment of 5G networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120321653B_ABST
    Figure CN120321653B_ABST
Patent Text Reader

Abstract

The present application relates to the technical field of network security, and in particular to a 5G communication server access control method and system. The present application clusters users accessing the server at each moment into different clusters; obtains edge distribution weights according to the risk coefficients of the labels of the users in each cluster at each moment and the influence degrees of the corresponding clusters by the labels of the users; obtains edge computing power distribution coefficients according to the label quantities of the users in each cluster at each moment and the edge distribution weights; divides the servers accessed by the users at each moment into different levels by using the edge distribution weights and the edge computing power distribution coefficients; and selects abnormal servers from the servers accessed by the users at each moment for control according to the network environment data of each server and the remaining servers and the level differences. The present application accurately screens abnormal servers and improves the accuracy of access control.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of network security, and particularly relates to a 5G communication server access control method and system. BACKGROUND

[0002] With the rapid development of 5G communication technology, the connectivity and data transmission speed of the network have been greatly improved, which has led to the emergence of emerging application scenarios such as the Internet of Things, intelligent transportation, and remote medical treatment. However, the security risks and access control challenges that follow are also increasingly prominent. In the 5G environment, the explosive growth of the number of users, the diversity of devices, and the demand for real-time data processing make it difficult for traditional access control methods to meet the needs of dynamic and complex network environments.

[0003] In the prior art, the existing mainstream access control technology is mainly based on a role, attribute, or capability model and relies on preset policies and centralized permission management. However, due to the high mobility and short connection period of terminal devices in the 5G network, attributes such as location, network status, security level, etc. need to be dynamically updated in milliseconds, which makes it difficult for mainstream access control technologies that rely on static or low-frequency attribute library updates to guarantee the real-time and consistency of attribute data in policy decision-making. This may cause errors in abnormal server judgment, thereby reducing the accuracy of access control. SUMMARY

[0004] In order to solve the technical problem of abnormal server judgment errors caused by the reliance on static in mainstream access control technology, the purpose of the present application is to provide a 5G communication server access control method and system, and the technical solution adopted is as follows:

[0005] In a first aspect, an embodiment of the present application provides a 5G communication server access control method, which comprises:

[0006] Obtaining the risk coefficients of different labels of each user accessing the server at each time, and the network environment data of the server at each time;

[0007] Clustering the users accessing the server at each time into different clusters; obtaining the edge distribution weight of each cluster at each time according to the risk coefficients of the labels of the users in each cluster at each time and the influence degree of the corresponding cluster affected by the labels of the users;

[0008] Obtaining the edge computing power distribution coefficient of each cluster at each time according to the number of labels of the users in each cluster at each time and the edge distribution weight; and dividing the server accessed by the users at each time into different levels using the edge distribution weight and the edge computing power distribution coefficient of each cluster at each time.

[0009] According to the network environment data of each server and the rest servers and the difference in the level, an abnormal server is selected from the servers accessed by the user at each time for control.

[0010] Further, the clustering of the user accessing the server at each time into different clusters comprises:

[0011] The cumulative sum of the risk coefficients of all labels of each user at each time is taken as a portrait factor of each user at each time; and the users accessing the server at the same time are clustered based on the portrait factor, to obtain a cluster at each time.

[0012] Further, the obtaining of the edge distribution weight of each cluster at each time comprises:

[0013] The variance of the risk coefficients of the same label of all users in each cluster at each time is taken as an intra-cluster variance of the corresponding cluster for each label; and the variance of the risk coefficients of the same label of all users in all clusters at each time is taken as a global variance of each label; and the ratio of the global variance to the intra-cluster variance is taken as a clustering influence degree of each label on each cluster at each time; and the labels corresponding to the maximum N clustering influence degrees are selected from the clustering influence degrees of all labels on each cluster at each time, and are taken as influence labels of each cluster at each time.

[0014] The effective label of each user at each time is selected based on the risk coefficient; and the number of effective labels of all users in each cluster at each time which is same as the influence label at each time is taken as a label influence degree of the corresponding cluster.

[0015] The edge distribution weight of the corresponding cluster is obtained according to the mean of the portrait factors of all users in each cluster, the number of label types of all users, and the label influence degree.

[0016] Further, the obtaining of the edge computing power distribution coefficient of each cluster at each time comprises:

[0017] The ratio of the number of label types of the users in each cluster at each time to the maximum value of the number of label types of the users in all clusters at each time is taken as a type proportion of each cluster at each time.

[0018] The edge computing power distribution coefficient of the corresponding cluster is obtained according to the edge distribution weight and the type proportion of each cluster at each time.

[0019] Further, the division of the servers accessed by the user at each time into different levels comprises:

[0020] The edge distribution weights of all clusters at each time form an analysis set.

[0021] Selecting the largest edge assignment weight in the analysis set as an initial analysis value, taking the server accessed by the user in the class cluster corresponding to the analysis value at each time as the first level server at each time, deleting the analysis value from the analysis set, and updating the analysis set;

[0022] Using the gradient descent method to select the edge assignment weight closest to the analysis value from the updated analysis set, denoted as a new analysis value, taking the server accessed by the user in the class cluster corresponding to the new analysis value at each time as the second level server at each time, deleting the new analysis value from the updated analysis set, and updating the analysis set;

[0023] By analogy, until the updated analysis set is empty.

[0024] Further, the selecting of the abnormal server from the servers accessed by the user at each time comprises:

[0025] The network environment data comprises access frequency and network load; and the product of the access frequency and the network load of each server at each time is taken as the state value of each server at each time;

[0026] For the servers accessed by the user at each time, an optional server is denoted as an analysis server, the level difference between the level of the analysis server and the levels other than the level of the analysis server is negatively correlated and normalized to obtain a level weight; and the absolute value of the difference between the state value of the analysis server at each time and the mean value of the state values of all servers in all levels other than the level of the analysis server at each time is weighted and summed according to the level weight to obtain the neighborhood state difference of the analysis server at each time;

[0027] The sum of the state value of the analysis server at each time and the neighborhood state difference is taken as the abnormal value of the analysis server at each time;

[0028] The server greater than a preset abnormal threshold value is selected from the servers accessed by the user at each time as the abnormal server at each time.

[0029] Further, the mean value of the portrait factor of all users in the class cluster and the number of label categories of all users and the edge assignment weight are positively correlated, and the label influence degree and the edge assignment weight are negatively correlated.

[0030] Further, the method for clustering the users accessing the server at the same time is a hierarchical clustering algorithm.

[0031] Further, the preset abnormal threshold value is 0.7.

[0032] In a second aspect, another embodiment of the present application provides a 5G communication server access control system, which comprises:

[0033] a data acquisition module, configured to acquire a risk coefficient of different labels of each user accessing the server at each time and network environment data of the server at each time;

[0034] an edge distribution analysis module, configured to cluster the users accessing the server at each time into different clusters; and acquire an edge distribution weight of each cluster at each time according to the risk coefficient of the labels of the users in each cluster at each time and an influence degree of the corresponding cluster affected by the labels of the users;

[0035] a server level division module, configured to acquire an edge computing power distribution coefficient of each cluster at each time according to the number of labels of the users in each cluster at each time and the edge distribution weight; and divide the server accessed by the users at each time into different levels by using the edge distribution weight and the edge computing power distribution coefficient of each cluster at each time;

[0036] an access control module, configured to select an abnormal server from the server accessed by the users at each time according to the network environment data and the level difference of each server and the remaining servers, and control the abnormal server.

[0037] The present application has the following beneficial effects:

[0038] In the embodiment of the present application, in order to enable the 5G communication server to quickly respond to access requests, the access pressure of the main server is shared by using an edge computing architecture to realize dynamic resource allocation and intelligent scheduling; the danger of the access server of different users is different, in order to improve the access security, the users accessing the server at each moment are clustered into user clusters of different danger levels; the danger coefficient of the label of the users in the cluster at each moment reflects the access behavior risk of the users in the cluster, the access behavior risk determines the possibility of cooperative processing of the access request, the influence degree of the label of the user on the cluster determines the possibility of cooperative control, the possibility of cooperative processing of the access server of the users in the cluster is analyzed combined with the above factors, and an edge allocation weight is obtained; the number of labels of each user in the cluster reflects the diversity of the service types involved in the request of the users in the cluster, and the edge allocation weight reflects the possibility of access cooperative processing, both of which determine resource allocation to obtain an edge computing power allocation coefficient; the edge server position is allocated combined with the edge allocation weight and the edge computing power allocation coefficient, hierarchical division of the server accessed by the user at each moment is realized, and the server position is adaptively and dynamically adjusted; the network resources occupied by the server will cause abnormal fluctuations of the adjacent edge servers, the farther the distance between the adjacent servers and the server, the lower the value of the abnormal fluctuations of the adjacent servers to the abnormal judgment of the server, and the network environment data of the server reflect the abnormal fluctuations, and the network environment data of each server and the rest servers and the difference in the level can improve the accuracy of the abnormal server screening and improve the access control accuracy. BRIEF DESCRIPTION OF DRAWINGS

[0039] In order to more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, and the advantages thereof, the drawings needed to be used in the embodiments or prior art description will be briefly introduced as follows. Obviously, the drawings in the following description are only some embodiments of the present application, and for those skilled in the art, other drawings can also be obtained without creative labor based on these drawings.

[0040] Figure 1 A step flow chart of a 5G communication server access control method provided by an embodiment of the present application;

[0041] Figure 2 A system structure diagram of a 5G communication server access control system provided by an embodiment of the present application;

[0042] Figure 3 A computer device schematic diagram of a 5G communication server access control device provided by an embodiment of the present application. DETAILED DESCRIPTION

[0043] In order to further illustrate the technical means and effects taken by the present application to achieve the predetermined inventive purpose, the specific implementation, structure, features and effects of the 5G communication server access control method and system according to the present application are described in detail below in combination with the drawings and preferred embodiments. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. In addition, the specific features, structures or characteristics in one or more embodiments can be combined in any suitable form.

[0044] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which the present application belongs.

[0045] The specific scheme of the 5G communication server access control method and system provided by the present application is described below in combination with the drawings.

[0046] Embodiment 1:

[0047] The present application proposes a 5G communication server access control method, please refer to Figure 1 , which shows the step flowchart of the 5G communication server access control method provided by one embodiment of the present application, which includes:

[0048] Step S1: Obtain the risk coefficient of each user of the access server at each time for different labels, and the network environment data of the server at each time.

[0049] When describing the user portrait of the access server, the access behavior is described, and the risk coefficient of each user of the access server for different labels is obtained. The label is used to judge whether the access behavior is abnormal. In the embodiment of the present application, the label includes: regional distribution label, network type label, access active label, and can also be other access behavior data, which is not limited here. The regional distribution label is divided into domestic and foreign, and the risk degree of domestic access is lower than that of foreign access, so the risk coefficients of the user in domestic access and foreign access are set to 0 and 1 respectively; the network type label is divided into 5G, Wi-Fi and broadband, and the risk from large to small is Wi-Fi, 5G and broadband, so the risk coefficients of the users using broadband, 5G and Wi-Fi are set to 0, 1 and 2 respectively; the access active label is divided into high active user and low active user, and the weekly access frequency is greater than or equal to 3 times for high active user and less than 3 times for low active user, so the risk coefficients of high active user and low active user are set to 0 and 1 respectively.

[0050] Obtain the network environment data of the server at each time; in the embodiment of the present application, the network data includes access frequency and network load, and other embodiments can also be other network data.

[0051] For example, high-frequency domestic Wi-Fi users can be automatically assigned high-priority bandwidth, while low-frequency foreign 5G users need to perform security detection and network acceleration strategies simultaneously.

[0052] Step S2: clustering the users accessing the server at each time into different clusters; and obtaining an edge distribution weight of each cluster at each time according to a dangerous coefficient of a label of each user in each cluster at each time and an influence degree of the corresponding cluster on the label of the user.

[0053] In order to enable the 5G communication server to quickly respond to access requests, the access pressure of the main server is shared by using an edge computing architecture, and dynamic resource allocation and intelligent scheduling are realized based on user portraits. The dangerous situations of different users accessing the server are different, in order to improve the access security, users of different dangerous degrees need to be allocated to corresponding servers for processing, such as placing users with higher dangerous degrees in edge servers for processing, so as to reduce the operation pressure and access risk of the main server, and users accessing the server at each time need to be clustered into different dangerous user groups.

[0054] In the embodiment of the application, the cumulative sum of the dangerous coefficients of all labels of each user at each time is taken as a portrait factor of each user at each time; the users accessing the server at the same time are clustered based on the portrait factor, to obtain clusters at each time. The dangerous coefficients of the category labels of the users at each time reflect the user images, and the portrait factor reflects the dynamic dangerous characteristics of the user behavior.

[0055] In one implementation manner of the embodiment of the application, a hierarchical clustering algorithm is selected to cluster the users accessing the server at the same time, and other embodiments can use a K-means clustering algorithm, a DBSCAN algorithm, etc.

[0056] The dangerous coefficients of the labels of the users in the cluster at each time reflect the access behavior risk of the users in the cluster, and the access behavior risk determines the possibility of needing to cooperatively process the access request; the influence degree of the label of the user on the cluster determines the possibility of cooperative control, and the above factors are combined to analyze the possibility of the users in the cluster needing to cooperatively process the access server, to obtain the edge distribution weight.

[0057] Preferably, in some possible implementation manners of the embodiments of the present application, the method for obtaining the edge distribution weight comprises: recording the variance of the risk coefficients of the same label of all users in each class cluster at each time as the cluster-in-variance of each label in the corresponding class cluster, and recording the variance of the risk coefficients of the same label of all users in all class clusters at each time as the global variance of each label; taking the ratio of the global variance to the cluster-in-variance as the clustering influence degree of each label to each class cluster at each time; selecting the labels corresponding to the maximum N clustering influence degrees from the clustering influence degrees of all labels to each class cluster at each time as the influence labels of each class cluster at each time; selecting the effective label of each user at each time based on the risk coefficient; counting the number of the effective labels of all users in each class cluster at each time which are the same as the influence labels at each time as the label influence degree of the corresponding class cluster; and obtaining the edge distribution weight of the corresponding class cluster based on the mean value of the portrait factors of all users in each class cluster, the label category number of all users, and the label influence degree.

[0058] The labels with greater clustering influence on each class cluster are analyzed through F value test analysis; the smaller the cluster-in-variance of each label is than the global variance, that is, the greater the clustering influence degree is, the higher the consistency of each label in each class cluster is, the greater the clustering influence of the label on each class cluster is, and the influence label represents the group characteristics of the users in the class cluster. The greater the number of the effective labels of all users in each class cluster at each time which are the same as the influence labels at each time is, the greater the influence of the influence labels on the users in the class cluster is, and the less the edge distribution is required when the edge server is distributed, the edge distribution weight is smaller.

[0059] In the embodiments of the present application, the product of the mean value of the portrait factors of all users in each class cluster, the label category number of all users, and the reciprocal of the label influence degree is taken as the edge distribution weight of the class cluster. The edge distribution weight is used for distributing the positions of the edge servers.

[0060] In the embodiments of the present application, the mean value of the portrait factor of each user in each cluster, the number of label categories of all users, and the correlation between the label influence degree and the edge allocation weight can also be constructed by other basic mathematical operations, which are not limited or described here.

[0061] In the embodiments of the present application, the effective label is a label whose risk coefficient is not equal to the preset value. The minimum value of the label is 0, which represents that the access behavior is not dangerous and subsequent analysis is meaningless, and therefore the label with a risk coefficient of 0 needs to be excluded.

[0062] In one implementation manner of the embodiments of the present application, N is equal to the quarter of the number of label categories of the user.

[0063] In other embodiments of the present application, the risk coefficients of the same label of all users in each cluster at each time and the risk coefficients of the same label of the users in all clusters at each time are clustered respectively to obtain two cluster center points, and the corresponding values of the cluster center points are sequentially recorded as the first center value of each label in the corresponding cluster and the second center value of each label. The absolute value of the difference between the first center value and the second center value is taken as the clustering influence degree of each label for each cluster at each time.

[0064] Step S3: obtaining the edge computing power allocation coefficient of each cluster at each time according to the number of labels of the users in each cluster at each time and the edge allocation weight; and dividing the servers accessed by the users at each time into different levels by using the edge allocation weight and the edge computing power allocation coefficient of the cluster at each time.

[0065] The local deployment of the server is fixed, and only the edge computing power needs to be allocated to realize the allocation of the location of the edge server; the number of labels of the users in each cluster reflects the diversity of the service types involved in the requests of the users in the cluster, and the edge allocation weight reflects the possibility of access collaborative processing, both of which determine the resource allocation, so as to obtain the edge computing power allocation coefficient. The location of the edge server is allocated in combination with the edge allocation weight and the edge computing power allocation coefficient, the servers accessed by the users at each time are divided into levels, the location of the server is adaptively and dynamically adjusted, and the response speed of the service is improved.

[0066] Preferably, in some possible implementation manners of the embodiments of the present application, the method for obtaining the edge computing power allocation coefficient comprises: taking the ratio of the number of label categories of the users in each cluster at each time to the maximum value of the number of label categories of the users in all clusters at each time as the category proportion of each cluster at each time; and obtaining the edge computing power allocation coefficient of the corresponding cluster according to the edge allocation weight and the category proportion of each cluster at each time.

[0067] The more the category proportion of a class cluster is, the more the service types involved in the user requests in the class cluster are, and the more the multi-label tasks are concurrent, and the more the redundant computing power needs to be reserved to avoid response delay caused by resource contention, and the greater the edge computing power allocation coefficient is. The more the edge allocation weight of a class cluster is, the more the user in the class cluster needs to be cooperatively processed, and the greater the edge computing power is, and the greater the edge computing power allocation coefficient is. Therefore, the edge allocation weight and the category proportion are positively correlated with the edge computing power allocation coefficient.

[0068] In the embodiment of the application, the product of the edge allocation weight and the category proportion of each class cluster at each time is taken as the edge computing power allocation coefficient of the corresponding class cluster. The correlation between the edge allocation weight and the category proportion and the edge computing power allocation coefficient can also be constructed by other basic mathematical operations, which is not limited and elaborated here.

[0069] Preferably, in some possible implementation manners of the embodiment of the application, the method for dividing the server into levels is that: an analysis set is composed of the edge allocation weights of all class clusters at each time; the maximum edge allocation weight in the analysis set is selected as an initial analysis value, the server accessed by the users in the class cluster corresponding to the analysis value at each time is taken as the server of the first level at each time, the analysis value is deleted from the analysis set, and the analysis set is updated; the edge allocation weight closest to the analysis value is selected from the updated analysis set by using the gradient descent method, and is recorded as a new analysis value, the server accessed by the users in the class cluster corresponding to the new analysis value at each time is taken as the server of the second level at each time, the new analysis value is deleted from the updated analysis set, and the analysis set is updated; and the above steps are sequentially repeated until the updated analysis set is empty. The gradient descent method is a known technology to those skilled in the art, and is not described here.

[0070] In the embodiment of the application, the method for selecting the edge allocation weight by using the gradient descent method is that: the square of the absolute value of the difference between the edge allocation weight in the updated analysis set and the analysis value is calculated, and the edge allocation weight corresponding to the smallest square is the edge allocation weight closest to the analysis value in the updated analysis set. The square of the absolute value of the difference between the edge allocation weight in the analysis set and the analysis value is equivalent to a loss function.

[0071] The first level server is a center server, which needs to bear real-time and rapid processing of a large amount of access information, and the edge distribution weight of the cluster that meets the cooperative processing of access requests is greater, so the user in the cluster corresponding to the maximum edge distribution weight in the analysis set is selected as the server accessed by the user at each moment as the first level server at each moment, so as to ensure that a large amount of normal access data can be rapidly processed. The gradient descent method starts from the center server, and gradually finds the optimal edge server, which can adapt to different load changes and network environments, gradually adjusts the distribution strategy, ensures that the server can be dynamically adjusted, and always maintains an optimized state. According to the real-time adjustment of computing power distribution according to the network environment and load condition, it is avoided that some nodes bear too many tasks, and when facing network fluctuations or device failures, the node distribution is quickly responded and adjusted, and the response speed of the service is improved.

[0072] It should be noted that each user can only access one server at each moment; and the level determined by the server each time is sequentially increased.

[0073] Step S4: According to the network environment data of each server and the rest of the servers and the difference in the level, an abnormal server is selected from the server accessed by the user at each moment for control.

[0074] Based on the dynamic optimization of server position distribution, the occupation of network resources by a certain server will cause abnormal fluctuations of adjacent edge servers, and the farther the adjacent server from the certain server, the lower the value of the abnormal fluctuation of the adjacent server to the abnormal judgment of the certain server; the network environment data of the server reflects the abnormal fluctuation, and the network environment data of each server and the rest of the servers and the difference in the level can improve the accuracy of the screening of the abnormal server.

[0075] Preferably, in some possible implementation manners of the embodiment of the application, the screening method of the abnormal server comprises: the network environment data comprises access frequency and network load; the product of the access frequency and the network load of each server at each moment is taken as the state value of each server at each moment; for the server accessed by the user at each moment, an optional server is recorded as an analysis server, the level difference between the level of the analysis server and the rest of the levels except the level of the analysis server is negatively correlated and normalized to obtain a level weight; according to the level weight, the state value of the analysis server at each moment is respectively weighted and summed with the difference absolute value between the state value of the analysis server at each moment and the mean value of the state value of all servers at each moment in all levels except the level of the analysis server, to obtain the neighborhood state difference of the analysis server at each moment; and the sum of the state value and the neighborhood state difference of the analysis server at each moment is taken as the abnormal value of the analysis server at each moment. Wherein, the access frequency represents the number of times of accessing the server by the user within 1 second.

[0076] The external network element attacks the server, and high-frequency access and large network bandwidth are occupied. If the access frequency of the server and the network load are larger, the possibility of the server being attacked by the external network is larger, and the possibility of the server being in an attacked state is larger. Occupying network resources can cause adjacent edge servers to abnormally fluctuate, and affect the data processing speed. When the difference between the possibility of the analysis server and the remaining servers being in an attacked state is smaller, the influence degree of the analysis server on the remaining servers is larger, the analysis server is attacked by the external network more seriously, and the abnormal value is larger. Meanwhile, if the analysis server and the remaining servers are closer in the level, the influence degree of the analysis server on the remaining servers is more referential.

[0077] In a specific implementation manner of the embodiment of the application, the abnormal value Y of the analysis server at each moment is represented by the following formula:

[0078]

[0079] In the formula, K is the state value of the analysis server at each moment; M is the total number of levels of the servers accessed by the user at each moment; C m is the level difference between the level of the analysis server and the remaining mth level except the level of the analysis server, for example, the level difference between the first level and the third level is 2; is the average value of the state values of all servers of the remaining mth level except the level of the analysis server at each moment; is the neighborhood state difference of the analysis server at each moment; || is an absolute value function; and Norm is a normalization function.

[0080] The servers greater than a preset abnormal threshold value are selected as abnormal servers at each moment from the servers accessed by the user at each moment. The abnormal servers are abnormal, and need to be controlled correspondingly. In an implementation manner of the embodiment of the application, the preset abnormal threshold value is 0.7.

[0081] The abnormal server control process is as follows:

[0082] (1)Quickly disconnect the Internet or intranet connection: immediately close the server network port or physical network card to prevent the attacker from continuously penetrating and moving horizontally; suspend external services: stop distributing traffic to the server through the load balancer or gateway to avoid affecting user experience.(2)Isolate the attacked node: remove the attacked server from the edge cluster to prevent the attack from affecting other nodes; limit access range: allow only the operation and maintenance IP to access the management port through the firewall policy to block unauthorized connections.(3)Enable dynamic protection mechanism: use edge firewall or special equipment to identify and intercept malicious traffic, and only allow legitimate requests; enable intrusion detection system: monitor abnormal access behavior such as high-frequency requests and unconventional protocols in real time, and automatically trigger blocking rules.(4)Strengthen access control policy: tighten identity authentication: enable multi-factor authentication and reset all account passwords to avoid secondary intrusion caused by credential leakage; close unnecessary ports and services: disable unused remote management ports and redundant background services to minimize the attack surface.

[0083] Thus far, the present application is completed.

[0084] Embodiment 2

[0085] The present application provides a 5G communication server access control system, please refer to Figure 2 , which shows a system structure diagram of a 5G communication server access control system provided by an embodiment of the present application, the system comprises:

[0086] The data acquisition module 510 is configured to obtain the risk coefficients of different labels of each user accessing the server at each time, and the network environment data of the server at each time.

[0087] The edge distribution analysis module 520 is configured to cluster the users accessing the server at each time into different clusters; according to the risk coefficients of the labels of the users in each cluster at each time, and the influence degree of the corresponding cluster affected by the labels of the users, obtain the edge distribution weight of each cluster at each time.

[0088] The server level division module 530 is configured to obtain the edge computing power distribution coefficient of each cluster at each time according to the number of labels of the users in each cluster at each time and the edge distribution weight; and divide the server accessed by the users at each time into different levels by using the edge distribution weight and the edge computing power distribution coefficient of the cluster at each time.

[0089] The access control module 540 is configured to select an abnormal server from the servers accessed by the users at each time according to the network environment data and the level difference of each server and the remaining servers.

[0090] It should be noted that the device provided in the above embodiment is only exemplified by the division of the above functional modules, and in actual application, the above functions can be completed by different functional modules according to needs, that is, the internal structure of the computer device is divided into different functional modules to complete all or part of the functions described above. In addition, the 5G communication server access control system and the 5G communication server access control method provided in the above embodiment belong to the same concept, and the specific implementation process is detailed in the method embodiment, which will not be repeated here.

[0091] Embodiment 3:

[0092] Figure 3 A computer device schematic diagram of a 5G communication server access control device provided by an embodiment of the application. For example, as shown in the figure, the computer device includes a memory 601, a processor 602, and a computer program 603 stored in the memory 601 and running on the processor 602, wherein the processor 602 executes the computer program 603, so that the computer device can execute any of the above-mentioned 5G communication server access control methods. Figure 3

[0093] In addition, the embodiment of the application also protects a device, which can include a memory and a processor, wherein the memory stores executable program code, and the processor is used to call and execute the executable program code to execute the 5G communication server access control method provided by the embodiment of the application.

[0094] The embodiment can divide the device into functional modules according to the above method examples, for example, corresponding to each functional module, or two or more functions can be integrated in one processing module, and the integrated module can be realized in the form of hardware. It should be noted that the division of modules in the embodiment is illustrative, and is only a logical function division, and another division mode can be used in actual implementation.

[0095] It should be understood that the device provided by the embodiment is used to execute the above-mentioned 5G communication server access control method, so as to achieve the same effect as the above-mentioned implementation method.

[0096] In the case of using integrated units, the device can include a processing module and a storage module. When the device is applied to a device, the processing module can be used to control and manage the actions of the device. The storage module can be used to support the device to execute mutual program codes and the like.

[0097] ​The processing module can be a processor or a controller, which can realize or execute various exemplary logical blocks, modules, and circuits contained in the disclosure of the present application. The processor can also be a combination of computing functions, such as one or more microprocessor combinations, digital signal processing (DSP) and microprocessor combinations, etc. The storage module can be a memory.

[0098] It should be noted that the above-mentioned sequence of the embodiments of the present application is only for description, and does not represent the advantages and disadvantages of the embodiments. The processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multi-task processing and parallel processing are also possible or can be advantageous.

[0099] Each embodiment in the specification is described in a progressive manner, and the same or similar parts between each embodiment can be referred to each other. Each embodiment focuses on the difference from other embodiments.

[0100] The above is only the preferred embodiment of the present application, and is not used to limit the present application. Any modification, equivalent replacement, improvement, etc. made within the principle of the present application shall be included in the protection scope of the present application.

Claims

1. A method for access control of a 5G communication server, characterized in that, The method comprises: obtaining a risk coefficient of different labels of each user accessing a server at each time point and network environment data of the server at each time point; clustering the users accessing the server at each time point into different clusters; obtaining an edge distribution weight of each cluster at each time point according to the risk coefficient of the labels of the users in each cluster at each time point and the influence degree of the corresponding cluster to the labels of the users; obtaining an edge computing power distribution coefficient of each cluster at each time point according to the number of labels of the users in each cluster at each time point and the edge distribution weight; and dividing the server accessed by the users at each time point into different levels by using the edge distribution weight and the edge computing power distribution coefficient of each cluster at each time point; selecting an abnormal server from the server accessed by the users at each time point according to the network environment data and the level difference of each server and the remaining servers to control the abnormal server; the clustering of the users accessing the server at each time point into different clusters comprises: taking the cumulative sum of the risk coefficients of all labels of each user at each time point as a portrait factor of each user at each time point; and clustering the users accessing the server at the same time point based on the portrait factor to obtain a cluster at each time point; the obtaining of the edge distribution weight of each cluster at each time point comprises: respectively taking the variance of the risk coefficients of the same label of all users in each cluster at each time point as an intra-cluster variance of each label in the corresponding cluster, and taking the variance of the risk coefficients of the same label of all users in all clusters at each time point as a global variance of each label; taking the ratio of the global variance to the intra-cluster variance as a clustering influence degree of each label on each cluster at each time point; and selecting N largest clustering influence degrees corresponding labels from the clustering influence degrees of all labels on each cluster at each time point as influence labels of each cluster at each time point; selecting effective labels of each user at each time point based on the risk coefficients; and counting the number of effective labels of all users in each cluster at each time point which are the same as the influence labels as a label influence degree of the corresponding cluster; obtaining an edge distribution weight of the corresponding cluster according to the mean of the portrait factors of all users in each cluster, the number of label types of all users and the label influence degree; the dividing of the server accessed by the users at each time point into different levels comprises: forming an analysis set by using the edge distribution weights of all clusters at each time point; selecting the largest edge distribution weight in the analysis set as an initial analysis value, taking the server accessed by the users in the cluster corresponding to the analysis value at each time point as a first-level server at each time point, deleting the analysis value from the analysis set and updating the analysis set; selecting an edge distribution weight closest to the analysis value from the updated analysis set by using a gradient descent method, taking the edge distribution weight as a new analysis value, taking the server accessed by the users in the cluster corresponding to the new analysis value at each time point as a second-level server at each time point, deleting the new analysis value from the updated analysis set and updating the analysis set; and By analogy, until the updated analysis set is empty.

2. The 5G communication server access control method of claim 1, wherein, The edge computing power distribution coefficient of each class cluster at each time point is obtained, including: The ratio of the number of label categories of the users in each class cluster at each time point to the maximum value of the number of label categories of the users in all class clusters at each time point is taken as the category proportion of each class cluster at each time point; The edge computing power distribution coefficient of the corresponding class cluster is obtained according to the edge distribution weight and the category proportion of each class cluster at each time point.

3. The 5G communication server access control method of claim 1, wherein, The abnormal server is selected from the servers accessed by the user at each time point, including: The network environment data includes the access frequency and the network load; and the product of the access frequency and the network load of each server at each time point is taken as the state value of each server at each time point; For the servers accessed by the user at each time point, an optional server is recorded as an analysis server, the level difference between the level of the analysis server and the levels other than the level of the analysis server is negatively correlated and normalized to obtain a level weight; and the state value of the analysis server at each time point is weighted and summed with the absolute value of the difference between the state value of the analysis server at each time point and the average value of the state values of all servers in all levels other than the level of the analysis server at each time point to obtain the neighborhood state difference of the analysis server at each time point; The sum of the state value of the analysis server at each time point and the neighborhood state difference is taken as the abnormal value of the analysis server at each time point. The server greater than a preset abnormal threshold value is selected as the abnormal server at each time point from the servers accessed by the user at each time point.

4. The 5G communication server access control method of claim 1, wherein, The mean value of the portrait factor of all users in the class cluster is positively correlated with the number of label categories of all users and the edge distribution weight, and the label influence degree is negatively correlated with the edge distribution weight.

5. The 5G communication server access control method of claim 1, wherein, The method for clustering the users accessing the server at the same time point is a hierarchical clustering algorithm.

6. The 5G communication server access control method of claim 3, wherein, The preset abnormal threshold value is 0.

7.

7. A 5G communication server access control system, characterized by, The system comprises: A data acquisition module is configured to acquire a risk coefficient of different labels of each user accessing a server at each time point and network environment data of the server at each time point; An edge distribution analysis module is configured to cluster the users accessing the server at each time point into different class clusters; and acquire an edge distribution weight of each class cluster at each time point according to the risk coefficient of the label of each user in each class cluster at each time point and the influence degree of the label of the corresponding class cluster on the users. A server level division module is configured to acquire an edge computing power distribution coefficient of each class cluster at each time point according to the number of labels of each user in each class cluster at each time point and the edge distribution weight; and divide the servers accessed by the users at each time point into different levels by using the edge distribution weight and the edge computing power distribution coefficient of the class cluster at each time point. An access control module is configured to select an abnormal server from the servers accessed by the users at each time point according to the network environment data and the level difference of each server and the remaining servers, and control the abnormal server. The users accessing the server at each time point are clustered into different class clusters, including: An accumulation of the risk coefficients of all labels of each user at each time is taken as a portrait factor of each user at each time; users accessing a server at the same time are clustered based on the portrait factor, to obtain a class cluster at each time; The edge distribution weight of each class cluster at each time is obtained, including: The variance of the risk coefficients of the same label of all users in each class cluster at each time is taken as an intra-cluster variance of each label in the corresponding class cluster, and the variance of the risk coefficients of the same label of users in all class clusters at each time is taken as a global variance of each label; a ratio of the global variance to the intra-cluster variance is taken as a clustering influence degree of each label on each class cluster at each time; the labels corresponding to the maximum N clustering influence degrees are selected from the clustering influence degrees of all labels on each class cluster at each time, and are taken as influence labels of each class cluster at each time; An effective label of each user at each time is selected based on the risk coefficient; the number of effective labels of all users in each class cluster at each time which are the same as the influence labels at each time is taken as a label influence degree of the corresponding class cluster; An edge distribution weight of the corresponding class cluster is obtained according to the mean of the portrait factors of all users in each class cluster, the number of label categories of all users, and the label influence degree; The servers accessed by the users at each time are divided into different levels, including: The edge distribution weights of all class clusters at each time constitute an analysis set; The maximum edge distribution weight in the analysis set is selected as an initial analysis value, the servers accessed by the users in the class cluster corresponding to the analysis value at each time are taken as the servers of a first level at each time, the analysis value is deleted from the analysis set, and the analysis set is updated; The edge distribution weight closest to the analysis value is selected from the updated analysis set by using a gradient descent method, and is taken as a new analysis value; the servers accessed by the users in the class cluster corresponding to the new analysis value at each time are taken as the servers of a second level at each time, the new analysis value is deleted from the updated analysis set, and the analysis set is updated; The above steps are sequentially repeated until the updated analysis set is empty.

Citation Information

Patent Citations

  • Method to personalize workspace experience based on user's available time

    CN114008646A

  • Network request processing method and device and electronic equipment

    CN114285901A