CPU card data writing method and device based on deep learning

Through deep learning technology, lightweight neural networks and multi-level security protection mechanisms are deployed, which solves the problem of writing performance and security of CPU cards under resource constraints, and realizes intelligent prediction and multi-level security guarantees to adapt to complex application environments.

CN120387160AInactive Publication Date: 2025-07-29NANJING DIANKUQUWAN TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510511586.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-23
Publication Date
2025-07-29
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

The existing CPU card data writing technology cannot intelligently predict write requirements under resource constraints, and the security protection mechanism is weak, making it difficult to take into account performance and security, especially in the wake-up scenario of mini-programs.

Method used

Using a deep learning-based method, a lightweight neural network model is deployed to predict write requests, combining a two-stage write protection system, a control flow integrity protection algorithm and a data flow monitoring system, a behavioral image algorithm is used to identify and respond exceptions.

Benefits of technology

It realizes efficient and secure write performance in resource-constrained environments, dynamically adapts to different scenario requirements, reduces write latency and throughput improvement, and adapts to CPU card applications in resource-constrained environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120387160A_ABST
    Figure CN120387160A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of embedded system security, and discloses a CPU card data writing method and device based on deep learning, and the CPU card data writing method based on deep learning comprises the steps: deploying a lightweight neural network model to carry out writing request prediction; establishing a two-stage write-in protection system to identify an abnormal write-in behavior; realizing a control flow integrity protection algorithm to prevent code injection attacks; constructing a data flow monitoring system to guarantee the security of sensitive data; and detecting an abnormal write-in mode by using a behavior portrait algorithm. By integrating various security technologies, the method realizes the balance between the write-in performance and the security protection in a resource-limited CPU card environment. The CPU card supports small program intelligent awakening and write-in demand prediction, prevents multi-dimensional security threats, solves the problems that a traditional CPU card is insufficient in data write-in dynamic adaptive capacity and prone to being attacked, and improves the data processing capacity of the CPU card in high-security scenes of financial payment and identity authentication.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of embedded system security, and particularly to a method and device for writing CPU card data based on deep learning. Background Art

[0002] With the rapid development of fintech and Internet of Things technologies, the CPU card, as an important security carrier, has been widely used in multiple fields such as payment, identity authentication, and public transportation. Writing data to the CPU card is one of its core functions and has a decisive impact on the card's performance and security. In recent years, to improve the user experience and functional richness, the mini-program wake-up technology has been gradually applied to the CPU card, enabling the card to automatically activate specific application programs in appropriate scenarios and provide more intelligent services.

[0003] However, the existing CPU card data writing technologies face multiple technical challenges in supporting the mini-program wake-up scenario: First, due to resource constraints, traditional CPU cards cannot effectively predict the writing requirements in different application scenarios and adopt a fixed data writing strategy, resulting in low performance in complex and changeable application environments; second, the security protection mechanism is weak, especially lacking effective recognition and prevention capabilities for complex attack means such as control flow hijacking and data flow anomalies; third, it is difficult to balance security and performance. Existing solutions either focus on improving performance at the expense of security or strengthen the security mechanism at the expense of the card's response speed and processing efficiency. The existing technologies mainly include: writing control technologies based on fixed rules, which are simple and easy to implement but lack adaptability; basic data encryption and integrity verification mechanisms, which can only resist basic attacks but are powerless against complex threats; isolated execution environment technologies, which enhance security isolation but increase system complexity and resource consumption. These technologies all have obvious deficiencies in the application scenarios of CPU cards supporting mini-program wake-up and cannot meet the growing intelligent and secure requirements.

[0004] Therefore, there is an urgent need for a new method for writing CPU card data that can intelligently predict writing requirements under resource constraints, provide multi-level security guarantees, and maintain high-efficient data processing performance to meet the special requirements of the mini-program wake-up scenario. Summary of the Invention

[0005] The present invention discloses a method and device for writing CPU card data based on deep learning, aiming to solve the problems of multi-physical field interaction effects, too long test cycles, insufficient environmental control accuracy, and separation of environmental conditions and load conditions existing in the prior art.

[0006] The present invention provides a method for writing CPU card data based on deep learning, including the following steps:

[0007] Deploy a lightweight neural network model, collect historical write behavior data in the CPU card, extract features of time, address, and data size, predict write requests, and pre-allocate resources;

[0008] Establish a two-stage write protection system, verify the legality of write requests through static rules, calculate the behavior score by combining dynamic behavior analysis, and achieve the identification and protection of abnormal write requests;

[0009] Implement a control flow integrity protection algorithm, construct a fine-grained control flow graph, calculate the basic block hash value, and verify the legality of instruction jumps in real time during the calculation of the basic block hash value to prevent control flow hijacking and code injection attacks;

[0010] Build a data flow monitoring system, add security tags to sensitive data, track the propagation path of tagged data in the system, execute access control policies, and prevent unauthorized access and data leakage;

[0011] Apply the behavior profiling algorithm, establish a write behavior benchmark model through the hidden Markov model, calculate the likelihood probability of the new write sequence, identify abnormal write patterns, and execute corresponding response measures.

[0012] Furthermore, the forward propagation calculation of the lightweight neural network model includes:

[0013] h1 = σ act (W1·X + b1);

[0014] h2 = σ act (W2·h1 + b2);

[0015] Y pred = W3·h2 + b3;

[0016] Among them, X is the input feature vector, including features of time interval, address correlation, and data size distribution; h1 and h2 are the outputs of the hidden layer; Y pred is the prediction result, including the time, address, size, and type of the predicted next write; W1, W2, and W3 are weight matrices; b1, b2, and b3 are bias vectors; σ act is the activation function.

[0017] Furthermore, in the two-stage write protection system:

[0018] The static rule verification calculates the static rule check score through the rule matching algorithm:

[0019]

[0020] Among them, W i is the write request, r j is the security rule, wj is the rule weight, Match(W i , r j ) is the matching degree; Score static is the static rule check score; m represents the number of rules written into the security rule library;

[0021] The dynamic behavior analysis obtains the dynamic behavior score by calculating the deviation between the write request and the historical behavior:

[0022]

[0023] Among them, Score dynamic is the dynamic behavior score, k is the number of feature values, represents the j-th feature value of the write request, μ j and σ j are the historical average and standard deviation of the feature respectively, and λ j is the feature weight.

[0024] Furthermore, the two-stage write protection system further includes a decision fusion step:

[0025] Combining the static rule check score and the dynamic behavior score, calculate the comprehensive security score:

[0026] Score final (W i ) = γ · Score static (W i ) + (1 - γ) · Score dynamic (W i );

[0027] Among them, Score final (W i ) is the comprehensive security score of the request W i , Score static (W i ) is the static rule check score of the request W i , Score dynamic (W i ) is the dynamic behavior score of the request W i , and γ is the weight factor of the static rule and the dynamic behavior;

[0028] When Score final is lower than the security threshold θ, trigger the corresponding protection measures, including rejecting the current write request, reducing the write priority, adding additional verification steps or recording warning logs.

[0029] Furthermore, in the control flow integrity protection algorithm:

[0030] The construction of the fine-grained control flow graph establishes the control flow relationship between basic blocks by analyzing the last instruction of each basic block:

[0031]

[0032] E = {e ij | B i can directly transfer to B j};

[0033] Among them, B i , B j represent basic blocks, I i,1 , I i,2 , respectively represent the 1st, 2nd, n i th instructions in basic block B i , n i represents the number of instructions in the basic block, E represents the legal control flow transfer from basic block B i to B j , and e ij represents the edge between basic blocks;

[0034] The lightweight CRC32 algorithm is used to calculate the basic block hash value, combined with the instruction sequence and context information of the basic block:

[0035]

[0036] Among them, H(B i ) represents the hash value of B i , | | represents the string concatenation operation, and ctx i represents the context information of the basic block.

[0037] Furthermore, the control flow integrity protection algorithm also includes: implementing a shadow stack mechanism, pushing the return address onto both the normal stack and the shadow stack when a function is called, comparing the return addresses of the two stacks when the function returns, and triggering a security exception when they do not match to prevent return address hijacking attacks.

[0038] Furthermore, in the data flow monitoring system:

[0039] The sensitive data is added with security tags using a compact bit vector representation method and is implemented in the following way:

[0040] tag(d) = EncodeSecurity(TypeInfo(d), SourceInfo(d), SensitivityLevel(d));

[0041] Among them, tag(d) represents the security label of data object d, EncodeSecurity is the security label encoding function, TypeInfo(d) represents the data type information, SourceInfo(d) represents the data source information, and SensitivityLevel(d) represents the sensitivity level;

[0042] Track the propagation path of the tagged data in the system, and its calculation formula is:

[0043] tag(d dst ) = PropagateTag(op, tag(d src ), tag(d dst ));

[0044] Among them, PropagateTag is the tag propagation function, which calculates the target data tag tag(d src ) according to the operation type op and the source data tag tag(d dst ), and d dst represents the target data.

[0045] Furthermore, in the behavior portrait algorithm: The hidden Markov model is defined as a five-tuple λ = (S, V, π, A, B), where:

[0046] S = {s1, s2,..., s N} is the set of hidden states, and s1, s2, s N represent the 1st, 2nd, and Nth hidden states respectively. N is the total number of hidden states, representing different modes of the write behavior;

[0047] V = {v1, v2,..., v M} is the set of observation symbols, and v1, v2, v M represent the 1st, 2nd, and Mth observation symbols respectively. M is the total number of observation symbols, corresponding to different types of write operations;

[0048] is the initial state distribution, and π1, π2, represent the 1st, 2nd, and N1th initial states respectively. N1 is the total number of states;

[0049] A = {a ij} is the state transition matrix, and a ij = P(q t+1 = s j | q t = s i ); It represents the probability of transitioning to state s i at the next moment t + 1 under the condition of being in state s j at moment t; q tDenotes the state at time t, q t+1 Denotes the state at time t+1;

[0050] B={b j (k)} is the observation probability matrix, b j (k)=P(o t =v k |q t =s j ); Denotes the probability of observing symbol v j under state s k ; where, o t Denotes the observed value at time t.

[0051] Furthermore, the behavior portrait algorithm further includes: calculating the likelihood probability of the newly written sequence, identifying abnormal writing patterns and performing corresponding response measures:

[0052] For the new write operation sequence O new , calculate its log-likelihood probability LL(O new |λ) under the trained HMM model λ:

[0053] LL(O new |λ)=logP(O new |λ);

[0054] Where, Denotes the joint probability of observing sequence O new and the state sequence is q under the given model λ;

[0055] If the log-likelihood probability is lower than the preset threshold θ LL , then it is determined as an abnormal writing behavior;

[0056] Where, the threshold θ LL is determined based on the distribution statistics of normal data:

[0057] θ LL =μ LL -k·σ LL ;

[0058] Where, μ LL and σ LL are respectively the mean and standard deviation of the log-likelihood probabilities of normal samples, k is the sensitivity adjustment factor, μ LL is the mean of the log-likelihood probabilities of normal samples, and σ LL is the standard deviation of the log-likelihood probabilities of normal samples.

[0059] The present invention provides a CPU card data writing device based on deep learning, including a memory and one or more processors. Executable code is stored in the memory. When the one or more processors execute the executable code, it is used to implement the above-mentioned CPU card data writing method based on deep learning.

[0060] The beneficial effects of the present invention are as follows:

[0061] Through an innovative lightweight neural network model and a multi-level security protection mechanism, dual breakthroughs in performance and security are achieved. The system adopts an intelligent pre-allocation technology to optimize the writing efficiency. Experimental data shows that the writing delay is reduced and the throughput is increased, and the performance is particularly prominent during peak hours.

[0062] Its adaptive model can dynamically adjust strategies according to the usage environment and user habits, accurately identify the operation sequence, and provide intelligent context support for the wake-up of small programs. It is particularly worth mentioning that while achieving the above breakthroughs, through a specially optimized algorithm design, the additional resource consumption is controlled at an extremely low level - the memory occupancy does not exceed 32KB, the CPU overhead increase is low, and the power consumption increase is low, perfectly adapting to resource-constrained environments. The present invention fundamentally solves the key technical problems of dynamic adaptability, security protection, and performance balance in CPU card data writing, and opens up a new technical path for smart card applications. BRIEF DESCRIPTION OF THE DRAWINGS

[0063] Figure 1 It is a flowchart of a CPU card data writing method based on deep learning according to the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0064] Now, the subject matter described herein will be discussed with reference to exemplary embodiments. It should be understood that discussing these embodiments is only to enable those skilled in the art to better understand and thus implement the subject matter described herein. Without departing from the protection scope of the content of this specification, changes can be made to the functions and arrangements of the elements discussed. Each example can omit, substitute, or add various processes or components as needed. Additionally, the features described in some examples can also be combined in other examples.

[0065] In at least one embodiment of the present invention, a CPU card data writing method based on deep learning is disclosed. As Figure 1 shown, it includes the following steps:

[0066] Step 1: Deploy a lightweight neural network model, collect historical writing behavior data in the CPU card, extract features of time, address, and data size, predict writing requests, and pre-allocate resources;

[0067] Step 1.1: Data collection;

[0068] Collect the historical writing behavior data in the CPU card, including the writing time series T = {t1, t2,..., t n}, the writing address sequence A = {a1, a2,..., a n}, the writing data size sequence S = {s1, s2,..., s n} and the writing type sequence C seq = {c1, c2,... c n}, where t1, t2, t n respectively represent the timestamps of the 1st, 2nd, and nth writes, a1, a2, a n respectively represent the memory addresses of the 1st, 2nd, and nth writes, s1, s2, s n respectively represent the data sizes of the 1st, 2nd, and nth writes, c1, c2, c n respectively represent the operation types of the 1st, 2nd, and nth writes, and n is the number of historical writing behaviors.

[0069] Step 1.2, feature extraction;

[0070] Based on the collected historical data, calculate the time interval feature ΔT:

[0071] ΔT = {t2 - t1, t3 - t2,..., t n - t n-1};

[0072] where t2 - t1, t3 - t2, t n - t n-1 respectively represent the intervals between the 1st, 2nd, and n - 1 adjacent writing behaviors, and n is the number of historical writing behaviors.

[0073] Address correlation feature Corr(A):

[0074] Corr(A) = {sim(a i , a j )|i, j ∈ [1, n]};

[0075] where sim is the address similarity function; a i , a j respectively represent the addresses of the ith and jth writes.

[0076] Data size distribution feature Dist(S):

[0077] Dist(S) = {freq(s)|s ∈ S};

[0078] where freq is the frequency statistics function; s represents the data size; S represents the data sequence size.

[0079] Step 1.3, model inference;

[0080] Input the extracted features into the lightweight neural network model, which adopts a multi-layer perceptron structure and calculates through forward propagation:

[0081] h1 = σ act (W1·X + b1);

[0082] h2 = σ act (W2·h1 + b2);

[0083] Y pred = W3·h2 + b3;

[0084] where X is the input feature vector, including features of time interval, address correlation, and data size distribution; h1 and h2 are the outputs of the hidden layers; Y pred is the prediction result, including the predicted time, address, size, and type of the next write; W1, W2, and W3 are weight matrices; b1, b2, and b3 are bias vectors; σ act is the activation function, and the ReLU function σ act (x) = max(0, x), where x represents the linear combination input value in the neural network.

[0085] The lightweight neural network model in this embodiment is optimized specifically for the resource-constrained CPU card environment. The specific implementation adopts the following structure: The input layer receives 13 features (including 5 time interval features, 5 address correlation features, and 3 data size distribution features), the first hidden layer contains 8 neurons, the second hidden layer contains 4 neurons, and the output layer generates 4 prediction values (time, address, size, type). The model parameters are quantized, compressing 32-bit floating-point numbers into 8-bit fixed-point numbers, and the total number of parameters is controlled within 1KB, enabling efficient operation even on a CPU card with only a few hundred KB of memory.

[0086] Step 1.4, resource allocation;

[0087] According to the prediction result Y pred , pre-allocate an appropriate amount of buffer resources, set the write priority, and adjust the corresponding write strategy to achieve dynamic optimization of the write performance. The pre-allocated buffer size is calculated as:

[0088] Buffer size = α buf ·S pred + β·σ S ;

[0089] where Buffer size is the pre-allocated buffer size, S predis the predicted write data size, σ S is the standard deviation of the historical write size, α buf and β are adjustable parameters that respectively control the weights of the predicted value and the fluctuation redundancy.

[0090] Step 2: Establish a two-stage write protection system. Verify the legality of the write request through static rules, and calculate the behavior score by combining dynamic behavior analysis to identify and protect against abnormal write requests;

[0091] Step 2.1: Static rule verification;

[0092] Establish a set of write security rule libraries R = {r1, r2,..., r m}, where r1, r2, r m respectively represent the 1st, 2nd, and mth rules, m represents the number of rules in the write security rule library, and each rule defines the parameter range and constraint conditions of legal write operations. For each write request W i = (a i , d i , s i , t i ), where a i is the write address, d i is the write data, s i is the data size, t i is the operation timestamp, and execute the rule matching algorithm:

[0093]

[0094] where, Match(W i , r j ) is the matching degree between the request W i and the rule r j , with a value range of [0, 1]; r j represents the jth rule, w j is the weight coefficient of the rule r j ; Score static is the static rule check score.

[0095] The static rule library in this embodiment includes the following types of rules: address range check rules (verifying whether the written address is within the allowed memory area), data format rules (verifying whether the data conforms to the predefined format and checksum requirements), operation frequency rules (verifying whether the time interval of the write operation is reasonable), and write size rules (verifying whether the amount of data written at one time is within the allowed range). The rule library is loaded into the protected area during the initialization of the CPU card and can be dynamically updated according to the security policy. The rule matching algorithm adopts an optimized prefix tree structure, reducing the matching complexity from O(m) to O(logm) to ensure efficient execution in a resource-constrained environment.

[0096] Step 2.2, dynamic behavior analysis;

[0097] Maintain a write behavior feature vector where, respectively represent the first, second, and kth eigenvalue of the write request W i , k is the number of eigenvalues, represents the jth eigenvalue of the write request W i . The features include: write frequency, time interval between adjacent writes, distribution characteristics of the write address, and data entropy value. For a new write request W i , calculate the dynamic behavior score Score dynamic (W i ):

[0098]

[0099] where, μ j and σ j are respectively the historical average and standard deviation of the jth feature, and λ j is the feature weight. The closer the dynamic score is to 1, the more normal the behavior is, and the closer it is to 0, the more abnormal the behavior is.

[0100] The dynamic behavior analysis uses an exponentially weighted moving average algorithm based on time decay to update the feature statistics:

[0101]

[0102] where, is the updated average value of the jth feature, is the historical average value of the jth feature, α decay is the time decay factor, with a value range of (0, 1), is the updated standard deviation of the jth feature, the historical standard deviation of the jth feature, controlling the decay rate of the influence of historical data. This algorithm allows the model to gradually adapt to the slow changes in normal behavior patterns while maintaining high sensitivity to sudden anomalies.

[0103] Step 2.3, decision fusion;

[0104] Combine the static score and the dynamic score to calculate the comprehensive security score Score final (W i ):

[0105] Score final (W i ) = γ · Score static (W i ) + (1 - γ) · Score dynamic (W i );

[0106] Where γ is the weight factor of the static rule and the dynamic behavior. When Score final is lower than the security threshold θ, trigger the corresponding protection measures, including rejecting the current write request, reducing the write priority, adding additional verification steps, or recording a warning log.

[0107] The decision fusion algorithm adopts an adaptive weight adjustment strategy in different application scenarios: in a stable operating environment, the static rule weight is higher; in a frequently changing usage scenario, the dynamic behavior weight is higher. This adaptive mechanism can be automatically adjusted according to the false positive rate and false negative rate of the system to ensure minimizing the impact on normal operations while maintaining high security.

[0108] Step 3, implement the control flow integrity protection algorithm, construct a fine-grained control flow graph, calculate the basic block hash value, and verify the instruction jump legality in real time during the calculation of the basic block hash value to prevent control flow hijacking and code injection attacks;

[0109] Step 3.1, static control flow graph construction;

[0110] Perform static analysis on the CPU card write processing program to construct a control flow graph (CFG) G = (V, E) at the basic block level, where V represents the set of basic blocks and E represents the set of legal jump edges. Each basic block B i ∈V contains a series of sequentially executed instructions, and the edge e ij ∈E between basic blocks represents a legal control flow transfer from basic block B i to B j .

[0111] Adopt an improved interval-based algorithm to construct the control flow graph. This algorithm first identifies the basic blocks of the program:

[0112]

[0113] Among them, I i,1 、I i,2 、 respectively represent the 1st, 2nd, and nth i instructions in the basic block B i ; I i,j represents the jth instruction in the basic block B i ; n i represents the number of instructions in the basic block. Then, by analyzing the last instruction (usually a jump instruction) of each basic block, the control flow relationship between basic blocks is established:

[0114] E = {e ij | B i can directly transfer to B j};

[0115] To improve the efficiency in resource - constrained environments, this embodiment compresses and stores the control flow graph in the form of an adjacency list, and uses a hash table to accelerate the lookup operation, reducing the edge lookup complexity from O(|E|) to O(1).

[0116] Step 3.2, Control flow hash calculation;

[0117] Calculate a unique hash value H for each basic block as the identity identifier of the basic block. The hash value calculation uses the lightweight CRC32 algorithm, combining the instruction sequence and context information of the basic block:

[0118]

[0119] where, | | represents the string concatenation operation, and ctx i represents the context information of the basic block B i including the function identifier and relative position.

[0120] To enhance security, this embodiment also introduces a random seed σ to make the same instruction sequence generate different hash values in different instances, preventing pre - calculation attacks:

[0121]

[0122] Step 3.3, Verify the control flow during program runtime;

[0123] During the program execution, whenever a control flow transfer occurs, execute the following verification algorithm:

[0124] function VerifyControlFlowTransfer(source basic block Bsrc, target basic block Bdst):

[0125] Calculate the source basic block hash value Hsrc = H(Bsrc);

[0126] Find the legal target set T = {Bj|(Bsrc, Bj) ∈ E};

[0127] For each possible target Bt ∈ T:

[0128] If Bdst = Bt then;

[0129] Return a legal transfer;

[0130] Return an illegal transfer;

[0131] Where Bj represents a legal target basic block;

[0132] When an illegal transfer is detected, trigger the security exception handling mechanism, including: terminating the current execution process, recording the attack behavior log, and activating the emergency protection mode.

[0133] Step 3.4, Shadow Stack protection;

[0134] Implement a dedicated Shadow Stack mechanism for return address hijacking attacks. The Shadow Stack maintains a copy of the return address of the calling function:

[0135] function callFunction(Target function address Ftarget, Return address Raddr):

[0136] Push the return address Raddr onto the normal stack;

[0137] Push the return address Raddr onto the Shadow Stack;

[0138] Jump to Ftarget;

[0139] function functionReturn():

[0140] Pop the return address Rnormal from the normal stack;

[0141] Pop the return address Rshadow from the Shadow Stack;

[0142] If Rnormal ≠ Rshadow then

[0143] Trigger a security exception;

[0144] Otherwise;

[0145] Jump to Rnormal;

[0146] The Shadow Stack is stored in a protected memory area and is prevented from being modified by the attacker through memory isolation technology, effectively guarding against stack overflow and return address tampering attacks, generating the final fine-grained control flow graph G = (V, E, φ), where V represents the set of basic blocks, represents the set of legal jump edges, φ: V → {0,1} 32Represents the basic block hash mapping function. In practical applications, this technology enables the CPU to maintain the integrity of the control flow when dealing with complex multi-layer nested function calls (such as performing encryption operations or multi-step authentication processes), preventing attackers from jumping to sensitive operation codes by modifying the return address.

[0147] Step 4: Build a data flow monitoring system, add security tags to sensitive data, track the propagation path of tagged data in the system, and enforce access control policies to prevent unauthorized access and data leakage;

[0148] Step 4.1: Sensitive data tagging;

[0149] Add security tags (SecurityTag) to sensitive data in the system, and establish a data classification system C sec ={c1, c2,..., c k} where c1, c2, c k represent the 1st, 2nd, and kth classifications respectively, and each classification corresponds to data with different security levels. For each data object d in memory, assign a corresponding security tag tag(d) ∈ C sec , and the tagging can be achieved in the following way:

[0150] tag(d)=EncodeSecurity(TypeInfo(d), SourceInfo(d), SensitivityLevel(d));

[0151] where EncodeSecurity is the security tag encoding function, TypeInfo(d) represents data type information (such as keys, personal identity information, transaction amounts), SourceInfo(d) represents data source information, and SensitivityLevel(d) represents the sensitivity level (such as public, internal, confidential, highly confidential).

[0152] Step 4.2: Data flow tracing;

[0153] Implement a fine-grained data flow tracing mechanism to monitor the propagation path of tagged data in the system. For each data operation op(d src , d dst ), execute the tag propagation rule:

[0154] tag(d dst )=PropagateTag(op, tag(d src ), tag(d dst ));

[0155] Among them, PropagateTag is a tag propagation function that calculates the target data tag tag(d src ) based on the operation type op and the source data tag tag(d dst ). The tag propagation function implements an information flow control strategy to ensure that high-sensitivity data does not flow to containers with low security levels.

[0156] Step 4.3, access control execution;

[0157] When sensitive data is accessed, an accurate access control policy is executed according to the permission level of the subject (code module) and the security label of the data:

[0158]

[0159] Among them, d is sensitive data, tag(d) is the security label of data d, subject is the code module executing the current operation, and the CheckPolicy function checks whether the subject has permission to access data with a specific label according to a predefined security policy matrix.

[0160] Step 4.4, violation handling;

[0161] When a data flow violation of the security policy is detected, a corresponding security response mechanism is triggered:

[0162] function handle data flow violation(violation type type, source data dsrc, target location ddst):

[0163] Record the violation details (type, dsrc, ddst, current context);

[0164] Determine the response level level = MapTypeToLevel(type) according to the violation type;

[0165] switch(level):

[0166] case Low risk:

[0167] Record a warning log;

[0168] Continue execution but mark the data as contaminated;

[0169] case Medium risk:

[0170] Block the current data transfer operation;

[0171] Send a warning notice;

[0172] case High risk:

[0173] Terminate the current execution process;

[0174] Activate data protection emergency measures;

[0175] When possible, clear sensitive data;

[0176] In different application scenarios, the system can dynamically adjust the security response strategy according to business requirements.

[0177] Step 5: Apply the behavior profiling algorithm, establish a baseline model for write behavior through the Hidden Markov Model, calculate the likelihood probability of the new write sequence, identify abnormal write patterns, and execute corresponding response measures;

[0178] Step 5.1: Behavior feature extraction;

[0179] Extract multi-dimensional behavior features from the CPU card write operation and construct a feature vector F feat =(f1, f2,..., f n ), where f1, f2, f n represent the 1st, 2nd, and nth features respectively, n is the number of features, and the feature dimensions include:

[0180] Time dimension feature f t : The time interval sequence of write operations and its statistical characteristics;

[0181] Spatial dimension feature f s : The distribution characteristics of write addresses and the address span;

[0182] Frequency dimension feature f f : The frequency distribution of write operations per unit time;

[0183] Content dimension feature f c : The entropy value and format features of the written data;

[0184] Context dimension feature f ctx : The pre-order and post-order operation patterns of write operations;

[0185] To adapt to the resource-constrained CPU card environment, this method optimizes feature extraction: adopts an incremental feature update algorithm, and each write operation only requires O(1) computational complexity to update the feature statistics; uses feature importance analysis technology to identify the most discriminative feature subset in the initial training stage, reducing the original n-dimensional feature space to k dimensions (k << n), significantly reducing subsequent calculation and storage overhead.

[0186] Step 5.2: Behavior model training sub-step;

[0187] Based on the extracted historical behavior features, a benchmark model of the writing behavior is established through the Hidden Markov Model (HMM). The HMM is defined as a five-tuple λ = (S, V, π, A, B), where:

[0188] S = {s1, s2,..., s N} is the set of hidden states, where s1, s2, s N represent the 1st, 2nd, and Nth hidden states respectively, and N is the total number of hidden states, representing different patterns of the writing behavior;

[0189] V = (v1, v2,..., v M} is the set of observed symbols, where v1, v2, v M represent the 1st, 2nd, and Mth observed symbols respectively, and M is the total number of observed symbols, corresponding to different types of writing operations;

[0190] is the initial state distribution, where π1, π2, represent the 1st, 2nd, and N1th initial states respectively, and N1 is the total number of states;

[0191] A = {a ij} is the state transition matrix, where a ij = P(q t+1 = s j |q t = s i ); which represents the probability of transitioning to state s i at the next moment t + 1 under the condition of being in state s j at moment t; q t represents the state at moment t, and q t+1 represents the state at moment t + 1;

[0192] B = {b j (k)} is the observation probability matrix, where b j (k) = P(o t = v k |q t = s j ); which represents the probability of observing symbol v j in state s k ; where, o t represents the observed value at moment t;

[0193] The model training adopts an improved Baum-Welch algorithm to learn the model parameters from a large number of normal writing operation sequences. To improve the training efficiency, the K-means clustering method is first used to initialize the model parameters, and then the Expectation-Maximization (EM) iteration is used for optimization. The training process is as follows:

[0194] Initialization: Use K-means clustering to initialize the number of states N and the model parameters λ (0) =(A (0) , B (0) , π (0) ), where A (0) is the initial state transition matrix, B (0) is the initial observation probability matrix, and π (0) is the initial state distribution;

[0195] Forward calculation: Calculate the forward probability α t (i) = P(o1, o2,..., o t , q t = s i |λ), where λ represents the given model, o1, o2, o t represent the lengths of the 1st, 2nd, and t-th observation sequences respectively, t is the time of the observation sequence, and q t = s i means being in state s i at time t;

[0196] Backward calculation: Calculate the backward probability β t (i) = P(o t+1 , o t+2 ,..., o T |q t = s i , λ), where o t+1 , o t+2 , O T represent the lengths of the (t + 1)-th, (t + 2)-th, and T-th observation sequences respectively, and T is the length of the observation sequence;

[0197] Calculate the temporary variables:

[0198]

[0199] where γ t (i) represents the probability of being in state s i at time t given the observation sequence O and the model λ; ξ t (i, j) represents the joint probability of being in state s i at time t and in state s j at time t + 1 given the observation sequence O and the model λ, α t (i), β t (i) represent the probabilities of being in state s i at time t respectively, and β t+1 (j) represents the probability of being in state s j at time t + 1.

[0200] Update model parameters:

[0201]

[0202] Among them, b j (k) new are the updated initial state distribution, the updated state transition probability, and the updated observation probability respectively;

[0203] Iteration: If P(O|λ new ) - P(O|λ old ) < ∈, then stop; otherwise, return to step 2 to continue the iteration. Among them, ∈ is the convergence threshold, λ old is the model given by history, and λ new is the updated model;

[0204] Step 5.3, Anomaly detection;

[0205] For the new write operation sequence O new = {o1, o2,..., o T}, where o1, o2, o T represent the 1st, 2nd, and Tth observation sequences respectively, and T is the length of the observation sequence. Calculate its log-likelihood probability LL(O new |λ) under the trained model λ:

[0206]

[0207] Among them, represents the joint probability of observing the sequence O new and the state sequence is q under the given model λ.

[0208] Use the forward algorithm to calculate efficiently:

[0209]

[0210] Among them, α T (i) is the forward probability at the end time T of the sequence, and N is the number of hidden states. If the log-likelihood probability is lower than the preset threshold θ LL , then it is determined as an abnormal write behavior:

[0211]

[0212] The threshold θ LL is determined based on the distribution statistics of normal data, and is usually set to the mean of the log-likelihood probabilities of normal samples minus 2 - 3 times the standard deviation:

[0213] θ LL = μ LL - k·σ LL ;

[0214] Among them, k is the sensitivity adjustment factor. The larger k is, the looser the detection is; the smaller k is, the stricter the detection is; μ LL is the mean of the logarithmic likelihood probability of normal samples, and σ LL is the standard deviation of the logarithmic likelihood probability of normal samples.

[0215] Step 5.4, Adaptive update;

[0216] To adapt to the natural evolution of user behavior, the system updates the behavior model regularly. For the verified normal write sequences, the incremental learning method is used to update the model parameters:

[0217] λ new = UpdateModel(λ old , O verified );

[0218] Among them, λ new and λ old represent the updated model parameters and the original model parameters before update respectively. UpateModel represents the model update function, and Overified represents the verified normal write operation sequence.

[0219] The update adopts a weighted fusion strategy to control the influence degree of new samples on the original model:

[0220] A new = (1 - η)·A old + η·A new ;

[0221] B new = (1 - η)·B old + η·B new ;

[0222] Among them, A new and B new represent the updated state transition probability matrix and the updated observation probability matrix respectively. A old and B old represent the original state transition probability matrix and the original observation probability matrix respectively. A new and B new represent the state transition probability matrix calculated based on the new verified sequence and the observation probability matrix calculated based on the new verified sequence respectively. η ∈ (0, 1) is the learning rate parameter, which controls the model update speed. A smaller η makes the model more stable, and a larger η makes the model adapt to the new behavior pattern faster.

[0223] The adaptive update mechanism shows good adaptability in different application scenarios: in a long-term stable enterprise environment, the system can maintain a low learning rate to reduce false alarms; in a consumer scenario where behavior patterns change rapidly, the system will automatically increase the learning rate to quickly adapt to the new behavior patterns of users.

[0224] In an embodiment of the present invention, an example of the aforementioned method for writing data to a CPU card based on deep learning is provided:

[0225] Application scenario description: A mobile payment system based on a CPU card launched by a certain bank supports the following services: - Small and fast payment: No password input is required, with a single transaction limit of 300 yuan and a daily cumulative limit of 1000 yuan. - Standard payment: Password verification is required, with a single transaction limit of 5000 yuan and a daily cumulative limit of 20000 yuan. - Large payment: Dual verification of password and fingerprint is required, with a single transaction limit of 50000 yuan and no daily cumulative limit.

[0226] In this system, the most critical security challenges are to prevent forged transactions, tampering of transaction amounts, and leakage of user privacy data, while ensuring the response performance and user experience in high-concurrency scenarios (such as morning and evening rush hours and large-scale promotional activities). Hereinafter, we will demonstrate the specific implementation process of each step of this method through simulating a typical payment process:

[0227] In this financial payment system, a lightweight neural network model is trained and deployed based on historical transaction data. For a typical user, the system has collected the following feature data, as shown in Table 1:

[0228] Table 1: Example of user historical transaction data features:

[0229]

[0230] Based on this data, the neural network model can predict that around 12:00 noon from Monday to Friday, the probability of this user making a small payment for dining near the company reaches 85%. Accordingly, the system will:

[0231] Automatically pre-allocate transaction processing resources at 11:30 am every working day

[0232] Preheat relevant payment mini-programs

[0233] Optimize the transaction process for dining merchants

[0234] When the actual predicted time arrives, the user only needs to lightly touch the CPU card to complete the small payment, and the average transaction time is shortened from the original 3.2 seconds to 0.8 seconds.

[0235] During a certain transaction process, the system detected a suspicious write request pattern. The processing process of this protection system is shown in Table 2:

[0236] Table 2: Abnormal Transaction Detection and Handling Process:

[0237]

[0238] The system integrated the results of static rules and dynamic behavior analysis, and the final security score was 0.38, which was lower than the security threshold of 0.6. Therefore, the two-factor authentication mechanism was triggered, requiring the user to provide fingerprint verification. Since the attacker attempting fraud could not provide the correct fingerprint, the transaction was successfully intercepted, preventing a fraud transaction with an amount close to 5000 yuan.

[0239] In the payment application, the control flow integrity protection algorithm protects the critical code path of write operations. The workflow of this technology when intercepting a code injection attack is shown in Table 3:

[0240] Table 3: Control Flow Hijacking Attack Detection Process:

[0241]

[0242] Through this protection mechanism, the system successfully intercepted an attack attempt that exploited a buffer overflow vulnerability to attempt to tamper with the payment amount and execute unauthorized code. The entire protection process was completed in less than 5 milliseconds, with no obvious impact on the normal transaction process.

[0243] During the payment process, the system strictly monitors the data flow of sensitive data (such as user card numbers, transaction amounts, passwords). The working process of the system during a data leakage attempt is shown in Table 4:

[0244] Table 4: Sensitive Data Flow Monitoring and Protection Process:

[0245]

[0246] In this instance, the data flow monitoring system successfully intercepted two sensitive data leakage attempts, one targeting the user's password in plaintext and the other targeting the transaction session key. The system not only blocked the data flow to unauthorized destinations but also triggered corresponding security responses, effectively protecting the user's property security.

[0247] Comprehensive Security Application Scenario Example: The firmware update of Internet of Things devices is a high-risk operation that requires strict security control. This system combines control flow integrity protection and data flow monitoring technologies to ensure the security of the update process, as shown in Table 5:

[0248] Table 5: Firmware Update Security Protection Process:

[0249] Update Phase Protection Measures Security Effect Firmware Download Data Source Verification, Integrity Check Prevent Downloading of Forged Firmware from Unauthorized Sources Firmware Storage Data Marking, Access Control Prevent Unauthorized Reading or Modification of Firmware Firmware Verification Signature Check, Integrity Check Ensure Firmware Has Not Been Tampered With Installation Process Control Flow Monitoring, Rollback Mechanism Prevent Execution of Malicious Code During Installation First Run Behavior Portrait Comparison Detect Abnormal Behavior Patterns After Installation

[0250] Through this security mechanism, the system has successfully intercepted multiple attack attempts to implant backdoor programs through firmware updates, ensuring the secure operation of the device.

[0251] Verification of the core technical effects: For the two core technical effects of the present invention, namely, improved writing performance and enhanced security protection, we have collected the following data through laboratory tests and real-scenario deployments:

[0252] Verification of the improved writing performance effect: This method improves the data writing performance of CPU cards through intelligent prediction and resource optimization. The performance of the traditional method and the method of the present invention in different scenarios is compared, as shown in Table 6:

[0253] Table 6: Results of the writing performance comparison test:

[0254] Performance Metrics Application Scenarios Traditional Methods Methods of the Present Invention Improvement Magnitude Average Response Time (ms) Financial Payment 320 96 70.0% Average Response Time (ms) Internet of Things Devices 185 62 66.5% Write Hit Rate (%) Financial Payment 48 92 91.7% Write Hit Rate (%) Internet of Things Devices 52 89 71.2% Peak Throughput (times / second) Financial Payment 28 65 132.1% Peak Throughput (times / second) Internet of Things Devices 36 82 127.8% Energy Consumption (mJ / operation) Financial Payment 4.2 2.3 45.2% Energy Consumption (mJ / operation) Internet of Things Devices 3.8 2.1 44.7%

[0255] The above data shows that the method of the present invention improves the efficiency of data writing in various application scenarios. Especially in the high-concurrency financial payment scenario, the response time is reduced by more than 70%, and the energy consumption is reduced by about 45%. This is of great significance for improving the user experience and extending the service life of the device.

[0256] Verification of the enhanced security protection effect: This method adopts a multi-level security protection mechanism, providing more efficient security protection than the traditional method. The comparison of security protection capabilities is shown in Table 7:

[0257] Table 7: Results of the security protection effect comparison test:

[0258] Attack Type Detection Metrics Traditional Methods Methods of the Present Invention Improvement Magnitude Forged Write Request Detection Rate (%) 65.3 98.7 51.1% Forged Write Request False Alarm Rate (%) 8.6 0.5 94.2% Control Flow Hijacking Detection Rate (%) 32.1 99.8 210.9% Control Flow Hijacking Response Time (ms) 126 4.8 96.2% Sensitive Data Theft Protection Coverage Rate (%) 58.7 99.2 68.9% Abnormal Behavior Patterns Detection Rate (%) 76.5 94.3 23.3% Comprehensive Security Score CVSS Score Decrease 2.1 8.4 300.0%

[0259] The security test results show that the method of the present invention has an increased detection rate for various attacks. Especially for the control flow hijacking attack, the detection rate has increased from 32.1% of the traditional method to 99.8%. At the same time, the response time has been shortened from 126 milliseconds to 4.8 milliseconds, enabling the system to respond quickly before the attack causes actual damage. In addition, the significant reduction in the false alarm rate (from 8.6% to 0.5%) also means an improvement in the user experience and a reduction in the operation and maintenance costs.

[0260] Based on the above verification results, this method provides excellent performance while ensuring high security, and is particularly suitable for application scenarios with high requirements for both security and response speed, such as financial payment and intelligent Internet of Things environments.

[0261] The embodiments of the present invention have been described above, but these embodiments are not limited to the above specific implementation manners. The above specific implementation manners are merely illustrative rather than restrictive. Under the inspiration of these embodiments, those of ordinary skill in the art can also make more equivalent embodiments in various forms, all of which fall within the protection scope of these embodiments.

Claims

1. A method for writing data to a CPU card based on deep learning, characterized in that, It includes the following steps: Deploy a lightweight neural network model, collect historical write behavior data in the CPU card, extract features of time, address, and data size, predict write requests, and pre-allocate resources; Establish a two-stage write protection system, verify the legality of write requests through static rules, calculate behavior scores by combining dynamic behavior analysis, and achieve the identification and protection of abnormal write requests; Implement a control flow integrity protection algorithm, construct a fine-grained control flow graph, calculate the hash value of basic blocks, and verify the legality of instruction jumps in real time during the calculation of basic block hash values to prevent control flow hijacking and code injection attacks; Build a data flow monitoring system, add security tags to sensitive data, track the propagation path of tagged data in the system, execute access control policies, and prevent unauthorized access and data leakage; Apply a behavior profiling algorithm, establish a write behavior benchmark model through a hidden Markov model, calculate the likelihood probability of a new write sequence, identify abnormal write patterns, and execute corresponding response measures.

2. The data writing method for the CPU card based on deep learning according to claim 1, wherein The forward propagation calculation of the lightweight neural network model includes: h1 = σ act (W1·X + b1); h2 = σ act (W2·h1 + b2); Y pred = W3·h2 + b3; Among them, X is the input feature vector, including features of time interval, address correlation, and data size distribution; h1 and h2 are the outputs of the hidden layers; Y pred is the prediction result, including the predicted time, address, size, and type of the next write; W1, W2, and W3 are weight matrices; b1, b2, and b3 are bias vectors; σ act is the activation function.

3. A method for writing CPU card data based on deep learning according to claim 1, characterized in that In the two-stage write protection system: Static rule verification calculates the static rule check score through a rule matching algorithm: Among them, W i is a write request, r j is a security rule, w j is the rule weight, Match(W i , r j ) is the matching degree; Score static is the static rule check score; m represents the number of rules written into the security rule library; Dynamic behavior analysis obtains the dynamic behavior score by calculating the deviation between the write request and historical behavior: Among them, Score dynamic is the dynamic behavior score, k is the number of eigenvalue, represents the j-th eigenvalue of the write request, μ j and σ j are respectively the historical average value and the standard deviation of the feature, λ j is the feature weight.

4. A method for writing CPU card data based on deep learning according to claim 3, characterized in that, The two-stage write protection system also includes a decision fusion step: Combine the static rule check score and the dynamic behavior score to calculate the comprehensive security score: Score final (W i ) = γ·Score static (W i ) + (1 - γ)·Score dynamic (W i ); Among them, Score final (W i ) is the comprehensive security score of request W i , Score static (W i ) is the static rule check score of request W i , Score dynamic (W i ) is the dynamic behavior score of request W i , and γ is the weight factor of static rules and dynamic behaviors; When Scor final is below the safety threshold θ, corresponding protective measures are triggered, including rejecting the current write request, reducing the write priority, adding additional verification steps, or recording a warning log.

5. A method for writing CPU card data based on deep learning according to claim 1, characterized in that, In the control flow integrity protection algorithm: The construction of the fine-grained control flow graph analyzes the last instruction of each basic block to establish the control flow relationship between basic blocks: E = {e ij | B i that can be directly transferred to B j}; Among them, B i and B j represent basic blocks, I i,1 and I i,2 , respectively represent the 1st, 2nd, and n i th instructions in basic block B i , where n i represents the number of instructions in the basic block, E represents a legal control flow transfer from basic block B i to B j , and e ij represents an edge between basic blocks; The calculation of the basic block hash value uses a lightweight CRC32 algorithm, combined with the instruction sequence and context information of the basic block: Among them, H(B i ) represents the hash value of B i , || represents the string concatenation operation, and ctx i represents the context information of the basic block.

6. The data writing method for the CPU card based on deep learning according to claim 5, wherein The control flow integrity protection algorithm also includes: implementing a shadow stack mechanism, pushing the return address onto both the normal stack and the shadow stack when a function is called, and comparing the return addresses of the two stacks when the function returns. When they do not match, a security exception is triggered to prevent return address hijacking attacks.

7. A method for writing data to a CPU card based on deep learning according to claim 1, characterized in that, In the data flow monitoring system: Adding security tags to sensitive data uses a compact bit vector representation method and is achieved through the following method: tag(d) = EncodeSecurity(TypeInfo(d), SourceInfo(d), SensitivityLevel(d)); where tag(d) represents the security tag of data object d, EncodeSecurity is the security tag encoding function, TypeInfo(d) represents the data type information, SourceInfo(d) represents the data source information, and SensitivityLevel(d) represents the sensitivity level; Track the propagation path of tagged data in the system, and its calculation formula is: tag(d dst ) = PropagateTag(op, tag(d src ), tag(d dst )); Among them, PropagateTag is a tag propagation function that calculates the target data tag tag(d src ) according to the operation type op and the source data tag tag(d dst ), where d dst represents the target data.

8. A method for writing data to a CPU card based on deep learning according to claim 1, characterized in that In the behavior profiling algorithm: The hidden Markov model is defined as a five-tuple λ = (S, V, π, A, B), where: S = {s1, s2,..., s N} is the set of hidden states, where s1, s2, s N represent the 1st, 2nd, and Nth hidden states respectively, and N is the total number of hidden states, representing different patterns of the write operation; V = {v1, v2,..., v M} is a set of observed symbols, where v1, v2, v M represent the 1st, 2nd, and Mth observed symbols respectively, and M is the total number of observed symbols, corresponding to different types of writing operations; is the initial state distribution, π1, π2, represent the 1st, 2nd, and N1th initial states respectively, where N1 is the total number of states; A = {a ij} is the state transition matrix, where a ij = P(q t+1 = s j |q t = s i ); which represents the probability of transitioning to state s i at the next time step t + 1, given that the state at time t is s j ; q t represents the state at time t, and q t+1 represents the state at time t + 1; B = {b j (k)} is the observation probability matrix, where b j (k) = P(o t = v k |q t = s j ) represents the probability of observing the symbol v j in the state s k . Here, o t represents the observation value at time t.

9. A method for writing CPU card data based on deep learning according to claim 8, characterized in that, The behavior profiling algorithm also includes: calculating the likelihood probability of a new write sequence, identifying abnormal write patterns, and executing corresponding response measures: For the new write operation sequence O new , calculate its log-likelihood probability LL(O new / λ): LL(O new ||λ) = log P(O new ||λ); Among them, represents the joint probability of observing the sequence O under the given model λ new and the state sequence is q; If the log-likelihood probability is lower than the preset threshold θ LL , it is determined as an abnormal writing behavior; Among them, the threshold θ LL is determined based on the distribution statistics of normal data: θ LL = μ LL - k·σ LL ; Among them, μ LL and σ LL are the mean and standard deviation of the log-likelihood probability of normal samples respectively, k is the sensitivity adjustment factor, μ LL is the mean of the log-likelihood probability of normal samples, and σ LL is the standard deviation of the log-likelihood probability of normal samples.

10. A CPU card data writing device based on deep learning, characterized in that, It includes a memory and one or more processors. Executable code is stored in the memory. When the one or more processors execute the executable code, it is used to implement a method for writing CPU card data based on deep learning described in any one of claims 1-9.