Public security front-end equipment access control method based on RADIUS authentication
Through dynamic key generation and real-time traffic analysis based on RADIUS authentication, combined with LSTM model and DPI detection, the problems of static authentication prone to counterfeiting and rigid policy in the access control of public security front-end equipment are solved, and the security of device access and efficient traceability of abnormal events are achieved.
Patent Information
- Application Number
- CN202510531954.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-25
- Publication Date
- 2025-07-18
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
In the prior art, the static authentication mechanism of the front-end equipment of the public security is prone to counterfeiting, the strategy is rigid and the detection is lagging behind, the real-time response capability is lacking, and the log dispersion leads to inefficient positioning of abnormal events.
Using a method based on RADIUS authentication, dynamic key generation, dual encryption mechanism, real-time traffic analysis and multi-level policy adjustment, combined with LSTM model and DPI detection, the security of device access and real-time response capabilities are realized, and the device log and network log are integrated for abnormal traceability.
It effectively resists MAC address forgery and key leakage attacks, improves the security of device access and real-time response capabilities, and realizes accurate traceability and efficient positioning of abnormal events.
Smart Images

Figure CN120342710A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of public security network device access control, and specifically provides a method for access control of public security front-end devices based on RADIUS authentication. Background Art
[0002] Access control of public security front-end devices refers to ensuring that only authorized devices such as cameras and sensors can access the public security network through network authentication and policy management, preventing unauthorized device access and network attacks, and ensuring data security and network stability.
[0003] However, the existing technologies have the following core problems: the static authentication mechanism is easy to be counterfeited. For example, relying on the MAC address whitelist cannot cope with dynamic key leakage or counterfeiting attacks; the policies are rigid and the detection is lagging, lacking the ability to adjust dynamic policies based on real-time traffic analysis and unable to quickly respond to abnormal traffic; at the same time, the logs are scattered and difficult to trace. The device logs, authentication logs, and network logs cannot be associated and analyzed, resulting in low efficiency in locating abnormal events. Therefore, a method for access control of public security front-end devices based on RADIUS authentication is proposed. Summary of the Invention
[0004] (1) Technical Problems to be Solved
[0005] In view of the deficiencies of the existing technologies, the present invention provides a method for access control of public security front-end devices based on RADIUS authentication, which significantly improves the security, real-time response ability, and abnormal event traceability efficiency of access control of public security front-end devices, and solves the problems of counterfeiting attacks, policy rigidity, and log dispersion existing in the existing technologies.
[0006] (2) Technical Solutions
[0007] To achieve the above-mentioned purpose of significantly improving the security, real-time response ability, and abnormal event traceability efficiency of access control of public security front-end devices, the present invention provides the following technical solutions: A method for access control of public security front-end devices based on RADIUS authentication, comprising the following steps:
[0008] S1. Deploy a RADIUS server, an optical modem, a switch, and front-end devices to establish a physical connection;
[0009] S2. Preset the MAC address whitelist of front-end devices in the RADIUS server and assign a unique dynamic key to each device;
[0010] S3. When a front-end device initiates a network access request through an optical modem or a switch, it carries the device MAC address, device type identifier, and dynamic key;
[0011] S4. The RADIUS server verifies the legitimacy of the device:
[0012] S5. Compare the MAC address with the hash value of the whitelist;
[0013] S6. Verify whether the dynamic key is within the validity period, and decrypt and verify the key through the national cryptographic SM4 algorithm;
[0014] S7. If the verification passes, the RADIUS server generates an access policy according to the device type, including the range of allowed access IP addresses, the maximum bandwidth limit, the allowed port numbers and protocol types, and the device heartbeat detection period;
[0015] S8. Send the access policy to the optical modem / switch through the extended attributes of the RADIUS protocol;
[0016] S9. The optical modem / switch performs MAC address binding, VLAN isolation, and traffic filtering according to the policy;
[0017] S10. The RADIUS server monitors the device traffic pattern in real time. If abnormal traffic or heartbeat timeout is detected, trigger dynamic policy adjustment and record the log;
[0018] S11. Integrate device logs, authentication logs, and network logs through the log analysis platform to generate a visual report.
[0019] Preferably, for the said S1, the configuration of the optical modem or switch includes the following steps:
[0020] Step 1: MAC address binding: Bind the device MAC address to the physical port, and only allow devices with the bound MAC address to access;
[0021] Step 2: VLAN division: Police service traffic is allocated to VLAN 100, management traffic is allocated to VLAN 200, and unauthorized traffic is discarded;
[0022] Step 3: Traffic filtering rules: Prohibit the device from accessing unauthorized IP addresses and disable unauthorized protocols.
[0023] Preferably, for the said S2, the generation of the dynamic key includes the following steps:
[0024] Step 1: The RADIUS server uses the device MAC address and the preset timestamp as inputs, and generates a key seed through the SHA-256 hash algorithm;
[0025] Step 2: Use the national cryptographic SM2 asymmetric encryption algorithm to encrypt the key seed to generate a dynamic key;
[0026] Step 3: Set the validity period of the dynamic key to TTL (Time to Live), preset to 900 seconds, and trigger re-authentication after expiration.
[0027] Preferably, for the S7, the dynamic generation of the access policy is based on the following algorithm:
[0028] Step 1: Analyze historical device traffic data using an LSTM neural network model. The input features of the LSTM model include traffic rate, protocol type, port number, and timestamp.
[0029] Step 2: Train the model with normal traffic data for the past 3 months to predict the current traffic pattern.
[0030] Step 3: When the real-time traffic deviates from the predicted value by more than a preset threshold (±15%), it is determined as abnormal traffic.
[0031] Step 4: Select the policy adjustment level through a decision tree algorithm: Level 1 reduces the bandwidth to 50%, Level 2 blocks non-essential ports, and Level 3 forcibly disconnects the connection and triggers a manual review.
[0032] Preferably, for the S10, the detection of abnormal traffic includes the following steps:
[0033] Step 1: Perform deep packet inspection (DPI) on the device traffic for the five-tuple.
[0034] Step 2: Detect the following abnormal patterns: port scanning behavior (accessing more than 10 different ports within 1 minute), illegal protocols, and missing heartbeat packets exceeding 3 consecutive timeouts.
[0035] Step 3: Trigger the policy rollback mechanism to restore the device policy to the initial configuration.
[0036] Preferably, for the S11, the log analysis includes the following steps:
[0037] Step 1: Real-time synchronize the logs to the log analysis platform through Kafka. The message format is in JSON structure, including timestamp, device MAC, event type, and policy adjustment record.
[0038] Step 2: Use Logstash to clean the logs and extract key fields (device ID, abnormal type, occurrence time).
[0039] Step 3: Establish an index through Elasticsearch to support querying by time (last 1 hour), device type (camera / sensor), and abnormal level (Level 1 / Level 2 / Level 3).
[0040] Step 4: The Kibana interface displays the heat map (geographical location distribution) and time series graph (traffic mutation trend) of abnormal events.
[0041] A public security front-end device access control system based on RADIUS authentication, including a RADIUS server module, a network device module, an anomaly detection module, a log analysis module, and a management terminal;
[0042] The RADIUS server module stores a MAC whitelist and a dynamic key database, and integrates an LSTM model prediction engine and a policy generation unit; the network device module's optical modem / switch supports MAC binding, VLAN division, and traffic filtering functions; the anomaly detection module includes a DPI detection engine, a heartbeat monitoring unit, and a policy adjustment trigger; the log analysis module includes a Kafka message queue, an Elasticsearch index library, and a Kibana visualization interface; the management terminal provides a policy configuration interface, an alarm notification setting, and an artificial review entry.
[0043] Preferably, the communication between the RADIUS server module and the network device module includes:
[0044] Using the Vendor-Specific Attributes field of the extended RADIUS protocol (RFC 2865), the following custom attributes are defined:
[0045] Attribute 1: Dynamic key validity period (unit: seconds, preset to 900 seconds);
[0046] Attribute 2: Access policy priority (levels 1-5, level 1 is the highest priority);
[0047] Attribute 3: Device heartbeat detection period (unit: seconds, preset to 30 seconds);
[0048] The communication process encryption uses the national standard SM9 identity-based cryptography algorithm, and the key negotiation is based on the Elliptic Curve Diffie-Hellman (ECDH) protocol.
[0049] (III) Beneficial effects
[0050] Compared with the prior art, the present invention provides a public security front-end device access control method based on RADIUS authentication, which has the following beneficial effects:
[0051] 1. The access control method for public security front-end devices based on RADIUS authentication solves the problem that static authentication is easily counterfeited through dynamic key generation and double-encryption mechanism. The RADIUS server module generates an SHA-256 hash seed based on the device MAC address and timestamp, and uses the national cryptography SM2 asymmetric encryption algorithm to generate a dynamic key with a validity period of only 900 seconds. The key is transmitted through the Vendor-Specific Attributes field that extends the RADIUS protocol, and the SM9 algorithm is used to encrypt the communication link. At the same time, the optical modem / switch module executes the MAC address binding and VLAN isolation strategy to separate the public security service traffic from the management traffic. When a device accesses, the RADIUS server module verifies the timeliness of the dynamic key and decrypts and verifies it through the SM4 algorithm to ensure that the key cannot be tampered with or counterfeited during transmission and use, effectively resisting MAC address forgery and key leakage attacks.
[0052] 2. The access control method for public security front-end devices based on RADIUS authentication has an LSTM model built in the RADIUS server module. It trains and predicts the normal traffic pattern through the traffic data of the past three months, and analyzes the five-tuple traffic characteristics (source / destination IP, port, protocol) in real time. When the DPI detection engine discovers port scanning (accessing more than 10 ports within 1 minute) or the traffic deviates from the predicted value by ±15%, it triggers the decision tree algorithm to adjust the access policy: level one reduces the bandwidth, level two blocks the port, and level three disconnects the connection. At the same time, the anomaly detection module monitors the device survival status in real time through the heartbeat monitoring unit (with a 30-second cycle), and forcibly rolls back the policy if there are three consecutive timeouts. The log analysis module integrates the Kafka message queue, Elasticsearch index library, and Kibana visualization interface, and correlates and analyzes the device logs, authentication logs, and network logs to achieve accurate traceability and real-time alarm of abnormal events. Description of the Drawings
[0053] Figure 1 It is the flowchart of the access control method for public security front-end devices of the present invention. Detailed Embodiments
[0054] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the embodiments and drawings of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0055] Please refer to Figure 1 , an access control method for public security front-end devices based on RADIUS authentication, including the following steps:
[0056] S1. Deploy the RADIUS server, optical modem, switch and front-end devices, and establish a physical connection;
[0057] S2. Preset the MAC address whitelist of the front-end devices in the RADIUS server, and assign a unique dynamic key to each device;
[0058] S3. When the front-end device initiates a network access request through the optical modem or switch, it carries the device MAC address, device type identifier and dynamic key;
[0059] S4. The RADIUS server verifies the device legitimacy:
[0060] S5. Compare the hash value of the MAC address with the whitelist;
[0061] S6. Verify whether the dynamic key is within the validity period, and decrypt and verify the key through the national cryptography SM4 algorithm;
[0062] S7. If the verification passes, the RADIUS server generates an access policy according to the device type, including the allowed IP address range, maximum bandwidth limit, allowed port numbers and protocol types, and device heartbeat detection period;
[0063] S8. Send the access policy to the optical modem / switch through the extended attributes of the RADIUS protocol;
[0064] S9. The optical modem / switch performs MAC address binding, VLAN isolation and traffic filtering according to the policy;
[0065] S10. The RADIUS server monitors the device traffic pattern in real time. If abnormal traffic or heartbeat timeout is detected, it triggers dynamic policy adjustment and records the log;
[0066] S11. Integrate the device logs, authentication logs and network logs through the log analysis platform to generate a visual report.
[0067] A public security front-end device access control system based on RADIUS authentication, including a RADIUS server module, a network device module, an anomaly detection module, a log analysis module and a management terminal;
[0068] The RADIUS server module stores the MAC whitelist and the dynamic key database, and integrates the LSTM model prediction engine and the policy generation unit; the network device module, i.e., the optical modem / switch, supports MAC binding, VLAN division, and traffic filtering functions; the anomaly detection module includes a DPI detection engine, a heartbeat monitoring unit, and a policy adjustment trigger; the log analysis module includes a Kafka message queue, an Elasticsearch index library, and a Kibana visualization interface; the management terminal provides a policy configuration interface, an alarm notification setting, and an artificial review entry.
[0069] Embodiment 1:
[0070] In this embodiment, the dynamic access control of public security front-end devices is realized through the RADIUS authentication protocol. The core innovation points include a dynamic key generation mechanism, an LSTM-based traffic prediction model, multi-level anomaly detection, and a policy dynamic adjustment mechanism to ensure the security of device access and the timeliness of policies.
[0071] The RADIUS server uses a PowerEdge R740 server (Intel Xeon Silver 4214 CPU with dual 14 cores, 64GB DDR4 memory, 2×1TB SATA hard disks, and dual gigabit network cards), runs the Ubuntu Server 22.04 LTS operating system, installs FreeRADIUS v4.1.0, and configures the MySQL database to store dynamic keys and the MAC whitelist.
[0072] The optical modem and the core switch are connected to the RADIUS server through Gigabit Ethernet, and front-end devices (such as cameras, sensors) are connected to the optical modem or switch ports through network cables.
[0073] The dynamic key generation uses the national secret SM2 asymmetric encryption: taking the device MAC address and the current UTC timestamp (second-level precision) as inputs, generating a 64-character key seed through SHA-256 hashing, and then using the SM2 public key to encrypt and generate a 256-bit dynamic key. The validity period is default 900 seconds (stored in the MySQL database table dynamic_keys, with fields including MAC address, encrypted key, and expiration time).
[0074] After the RADIUS server verifies the key validity, it issues an access policy to the optical modem / switch through the extended attribute (Vendor1234), including VLANID (such as VLAN100 for public security service traffic), maximum bandwidth (such as 10Mbps), allowed IP range (CIDR format), and heartbeat detection period (30 seconds); the optical modem configures static MAC address binding through the CLI (mac-address-table static <mac>vlan <id>) and enable IEEE 802.1X authentication (radius-server host 192.168.0.100 auth-port 1812).
[0075] The LSTM-based traffic prediction model utilizes 3 months of historical data (traffic rate, protocol type, port number, MAC address). After collecting and cleaning the data through the NetFlow protocol, it is input into a 2-layer stacked LSTM network (128 neurons in each layer, Dropout = 0.2). With a 5-minute time window as the input unit, the feature dimensions include traffic rate, protocol type, source port, and destination port.
[0076] When the deviation between the real-time traffic and the predicted value exceeds ±15%, the policy adjustment is triggered. The decision tree algorithm executes according to the anomaly level: the first-level policy reduces the bandwidth to 50% of the original value, the second-level policy blocks unnecessary ports (such as 8080), and the third-level policy forcibly disconnects the connection and records the MAC address in the blacklist.
[0077] Example Two:
[0078] In this example, the national secret SM2 asymmetric encryption and SM4 symmetric encryption are used to achieve secure key transmission and data encryption, ensuring that the authentication process complies with the standards of the National Cryptography Administration. The core innovation points include dynamic key generation and a dual-algorithm cooperation mechanism.
[0079] The SM2 key pair is generated through the OpenSSL tool:
[0080] The private key is stored in the Hardware Security Module (HSM), and the public key is distributed to the front-end devices.
[0081] The key seed (SHA-256 hash result) is encrypted by the SM2 public key and transmitted to the RADIUS server, and the server decrypts and verifies it using the private key.
[0082] The key validity period is stored in the MySQL database table dynamic_keys, and the fields include MAC address, encryption key, and expiration time.
[0083] The re-authentication process is triggered 30 seconds before the key expires, generating a new key and updating the storage.
[0084] The first 16 bytes are extracted from the key encrypted by SM2 to obtain the SM4 key, and the ECB mode is used to encrypt the communication data between the device and the server. The key rotation period is synchronized with the dynamic key.
[0085] Example Three:
[0086] This embodiment describes the collaborative workflow of system components (RADIUS server, optical modem / switch, log analysis platform) and the DPI-based anomaly detection mechanism to ensure the security of network access and the real-time nature of policies.
[0087] The RADIUS server and the optical modem / switch interact through the RADIUS protocol:
[0088] After the device initiates an authentication request, the optical modem forwards it to the server for MAC address and key verification; the server returns access policies (such as VLAN100, bandwidth limit), and the optical modem / switch configures VLAN and traffic filtering rules (such as access-list 100 deny ip 192.168.2.0 0.0.0.255 any); when the policy is updated, the server issues a new policy through the Access-Accept packet of the RADIUS protocol, and the device updates the configuration in real time.
[0089] Anomaly detection monitors traffic through the five-tuple (source / destination IP, port, protocol):
[0090] Access to more than 10 different ports within 1 minute triggers a port scan alarm; detecting an unauthorized protocol (such as Telnet) or three consecutive heartbeat timeouts (no custom heartbeat packet HEARTBEAT=OK received within 90 seconds) triggers an alarm; the policy rollback mechanism immediately restores the initial configuration (such as VLAN100, bandwidth 10Mbps), and the optical modem clears the current VLAN binding and resets the traffic filtering rules.
[0091] Example 4:
[0092] This embodiment constructs a log analysis system based on Kafka-Elasticsearch-Kibana, supporting full-link log collection, real-time analysis, and visualization. The core innovation points include multi-dimensional log correlation analysis and visualization alarms.
[0093] Kafka deploys a 3-partition topic security_logs to receive JSON-formatted logs (including timestamp, MAC address, event type, action).
[0094] Log example:
[0095] {"timestamp":"2023-11-01T12:34:56Z","mac":"00:1A:2B:3C:4D:5E","event_type":"PORT_SCAN","action":"BLOCK_PORT"}
[0096] After Logstash cleans the invalid fields, it writes to the Elasticsearch index security_logs. The fields include the time field (@timestamp), MAC address (keyword type), and event type (keyword type).
[0097] The Kibana dashboard displays a heat map (abnormal event distribution based on IP geographical location), a time series graph (statistics of the number of abnormalities per hour), and a pie chart (proportion of abnormalities classified by device type); the alarm rules include: port scanning triggers email notifications, and heartbeat timeout triggers SMS alarms.
[0098] Example 5:
[0099] This example provides the system's daily maintenance, fault troubleshooting, and automatic recovery processes to ensure high availability and maintainability. The core innovation points include automatic fault switching and fine-grained log analysis.
[0100] Daily maintenance: Check the RADIUS log ( / var / log / freeradius / radius.log) every day and analyze the reasons for Access-Reject; perform a key database backup (mysqldump command) every week; update the MAC whitelist every quarter.
[0101] Fault troubleshooting: When the device cannot be authenticated, check the physical connection and the MAC whitelist (SELECT * FROM devices WHERE mac = ' <mac>'), key validity period (SELECT * FROM keys WHERE valid_until > NOW()); If the problem persists, restart the RADIUS service (systemctl restart freeradius).
[0102] Automatic recovery: When the RADIUS server fails, the standby server automatically takes over through Keepalived (virtual IP 192.168.0.100); The master-slave replication architecture of MySQL enables failover, and the slave library is automatically upgraded to the master library and the service is restored.
[0103] In summary, this access control method for public security front-end devices based on RADIUS authentication solves the problem that static authentication is easily forged through dynamic key generation and double-encryption mechanism; The RADIUS server module generates an SHA-256 hash seed based on the device MAC address and timestamp, and uses the national cipher SM2 asymmetric encryption algorithm to generate a dynamic key with a validity period of only 900 seconds; The key is transmitted through the Vendor-Specific Attributes field that extends the RADIUS protocol, and the SM9 algorithm is used to encrypt the communication link; At the same time, the optical modem / switch module executes the MAC address binding and VLAN isolation policies to separate the public security service traffic from the management traffic; When the device accesses, the RADIUS server module verifies the timeliness of the dynamic key and decrypts and verifies it through the SM4 algorithm to ensure that the key cannot be tampered with or forged during transmission and use, effectively resisting MAC address forgery and key leakage attacks.
[0104] Moreover, this access control method for public security front-end devices based on RADIUS authentication has an LSTM model built into the RADIUS server module, which trains and predicts the normal traffic pattern through the traffic data of the past 3 months, and analyzes the five-tuple traffic characteristics (source / destination IP, port, protocol) in real time; When the DPI detection engine discovers port scanning (accessing more than 10 ports within 1 minute) or the traffic deviates from the predicted value by ±15%, it triggers the decision tree algorithm to adjust the access policy: level 1 reduces the bandwidth, level 2 blocks the port, and level 3 disconnects the connection; At the same time, the anomaly detection module monitors the device survival status in real time through the heartbeat monitoring unit (30-second cycle), and forcibly rolls back the policy after 3 consecutive timeouts; The log analysis module integrates the Kafka message queue, Elasticsearch index library, and Kibana visualization interface, correlates and analyzes the device logs, authentication logs, and network logs, realizes accurate traceability and real-time alarm of abnormal events, and solves the problems of forgery attacks, rigid policies, and scattered logs existing in the prior art.
[0105] All relevant modules involved in this system are hardware system modules or functional modules that combine computer software programs or protocols in the prior art with hardware. The computer software programs or protocols themselves involved in this functional module are all well-known technologies to those skilled in the art and are not the improvements of this system. The improvement of this system lies in the interaction relationship or connection relationship between each module, that is, the overall structure of the system is improved to solve the corresponding technical problems to be solved by this system.
[0106] Although the embodiments of the present invention have been shown and described, those of ordinary skill in the art can understand that various changes, modifications, substitutions, and variations can be made to these embodiments without departing from the principles and spirit of the present invention. The scope of the present invention is defined by the appended claims and their equivalents.< / mac> < / id> < / mac>
Claims
1. A method for access control of public security front-end devices based on RADIUS authentication, characterized in that, It includes the following steps: S1. Deploy a RADIUS server, an optical network terminal (ONT), a switch, and front-end devices, and establish a physical connection; S2. Preset the MAC address whitelist of the front-end devices in the RADIUS server, and assign a unique dynamic key to each device; S3. When a front-end device initiates a network access request through the ONT or the switch, it carries the device MAC address, device type identifier, and dynamic key; S4. The RADIUS server verifies the device legitimacy: S5. Compare the hash value of the MAC address with that of the whitelist; S6. Verify whether the dynamic key is within the validity period, and decrypt and verify the key through the national cryptographic SM4 algorithm; S7. If the verification passes, the RADIUS server generates an access policy according to the device type, including the allowed IP address range, maximum bandwidth limit, allowed port numbers and protocol types, and device heartbeat detection period; S8. Send the access policy to the ONT / switch through the extended attributes of the RADIUS protocol; S9. The ONT / switch performs MAC address binding, VLAN isolation, and traffic filtering according to the policy; S10. The RADIUS server monitors the device traffic pattern in real time. If abnormal traffic or heartbeat timeout is detected, trigger dynamic policy adjustment and record the log; S11. Integrate device logs, authentication logs, and network logs through a log analysis platform to generate a visualization report.
2. The method for access control of public security front-end devices based on RADIUS authentication according to claim 1, characterized in that, In S1, the configuration of the ONT or the switch includes the following steps: Step 1: MAC address binding: Bind the device MAC address to the physical port, and only allow devices with the bound MAC address to access; Step 2: VLAN division: Allocate public security service traffic to VLAN 100, management traffic to VLAN 200, and discard unauthorized traffic; Step 3: Traffic filtering rules: Prohibit devices from accessing unauthorized IP addresses and disable unauthorized protocols.
3. A method for access control of public security front-end devices based on RADIUS authentication according to claim 1, characterized in that In S2, the dynamic key generation includes the following steps: Step 1: The RADIUS server uses the device MAC address and the preset timestamp as inputs, and generates a key seed through the SHA-256 hash algorithm; Step 2: Use the national cryptographic SM2 asymmetric encryption algorithm to encrypt the key seed to generate a dynamic key; Step 3: Set the validity period of the dynamic key to TTL (Time to Live), preset to 900 seconds, and trigger re-authentication after expiration.
4. A method for access control of public security front-end devices based on RADIUS authentication according to claim 1, characterized in that, In S7, the dynamic generation of the access policy is based on the following algorithm: Step 1: Use an LSTM neural network model to analyze historical device traffic data. The input features of the LSTM model include traffic rate, protocol type, port number, and timestamp; Step 2: The model is trained with normal traffic data for the past 3 months to predict the current traffic pattern; Step 3: When the real-time traffic deviates from the predicted value by more than the preset threshold (±15%), it is determined as abnormal traffic; Step 4: Select the policy adjustment level through the decision tree algorithm: Level 1 reduces the bandwidth to 50%, Level 2 blocks unnecessary ports, and Level 3 forcibly disconnects and triggers manual review.
5. A method for access control of public security front-end devices based on RADIUS authentication according to claim 1, characterized in that, In S10, the detection of abnormal traffic includes the following steps: Step 1: Perform deep packet inspection (DPI) of the five-tuple of the device traffic; Step 2: Detect the following abnormal patterns: port scanning behavior (accessing more than 10 different ports within 1 minute), illegal protocols, and more than 3 consecutive timeouts in the absence of heartbeat packets; Step 3: Trigger the policy rollback mechanism to restore the device policy to the initial configuration.
6. The access control method for public security front-end devices based on RADIUS authentication according to claim 1, characterized in that The S11, log analysis includes the following steps: Step 1: Real-time synchronize the logs to the log analysis platform through Kafka. The message format is in JSON structure, including timestamp, device MAC, event type, and policy adjustment records; Step 2: Use Logstash to clean the logs and extract key fields (device ID, abnormal type, occurrence time); Step 3: Establish an index through Elasticsearch to support querying by time (last 1 hour), device type (camera / sensor), and abnormal level (level 1 / level 2 / level 3); Step 4: The Kibana interface displays the heat map (geographical location distribution) and time series graph (traffic mutation trend) of abnormal events.
7. A public security front-end device access control system based on RADIUS authentication, characterized in that, Including RADIUS server module, network device module, abnormal detection module, log analysis module, and management terminal; The RADIUS server module stores the MAC whitelist and dynamic key database, and integrates the LSTM model prediction engine and policy generation unit; The network device module, optical modem / switch, supports MAC binding, VLAN division, and traffic filtering functions; the abnormal detection module includes a DPI detection engine, a heartbeat monitoring unit, and a policy adjustment trigger; the log analysis module includes a Kafka message queue, an Elasticsearch index library, and a Kibana visualization interface; the management terminal provides a policy configuration interface, alarm notification settings, and an artificial review entry.
8. The access control system for public security front-end devices based on RADIUS authentication according to claim 7, characterized in that, The communication between the RADIUS server module and the network device module includes: Adopt the Vendor-Specific Attributes field of the extended RADIUS protocol (RFC 2865) to define the following custom attributes: Attribute 1: Dynamic key validity period (unit: second, preset to 900 seconds); Attribute 2: Admission policy priority (levels 1-5, level 1 is the highest priority); Attribute 3: Device heartbeat detection period (unit: second, preset to 30 seconds); The communication process encryption uses the national cipher SM9 identity-based cryptographic algorithm, and the key negotiation is based on the elliptic curve Diffie-Hellman (ECDH) protocol.