Zero-trust-fused edge intelligent cooperative processing method and system

By constructing index graph relationships and node weight calculations, the abnormal propagation path compression summary signature of edge intelligent all-in-one machine is solved, and the problems of dynamic authentication and trusted transmission in edge intelligent collaborative processing are realized, and the trusted collaborative calculation and signature verification closed loop of multiple devices on the edge side are improved, which improves the security and traceability of the system.

CN120455181AActive Publication Date: 2025-08-08TAIJI COMPUTER CORPORATION LIMITED
View PDF 0 Cites 4 Cited by

Patent Information

Application Number
CN202510964214.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-14
Publication Date
2025-08-08
Estimated Expiration
2045-07-14

AI Technical Summary

Technical Problem

The existing edge intelligent collaborative processing methods cannot perform dynamic access authentication and real-time behavior verification. The collaborative paths between devices lack a trusted delivery mechanism, and abnormal data is difficult to control independently on the edge side, and it is difficult to realize the closed loop of trusted collaborative computing and signature verification of edge-side multi-device under a converged zero-trust architecture.

Method used

By obtaining the multi-source heterogeneous operation indicators of edge intelligent all-in-one machines, building indicator graph relationships, using time window sliding and information analysis to generate edge sets, perform graph structure expression and inter-node weight calculation, compress and summarize the abnormal propagation path and sign it, and upload it to the cloud verification end for trusted scores and behavior verification.

Benefits of technology

It has achieved the improvement of abnormal state modeling accuracy in edge environments, quickly locate potential security risks, enhance the trustworthiness of edge nodes and system tamper resistance, and realize cross-cycle behavior verification and audit archiving.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120455181A_ABST
    Figure CN120455181A_ABST
Patent Text Reader

Abstract

The invention discloses an edge intelligent cooperative processing method and system fusing zero trust, and relates to the technical field of edge computing security and intelligent cooperative processing, and the method comprises the steps: obtaining a multi-source heterogeneous operation index of an edge intelligent all-in-one machine, and constructing an index graph relation; and generating an edge set in the index graph by adopting a time window sliding and information amount analysis mode. And graph structure expression and inter-node weight calculation of the index graph relation are executed based on a local memory loading mechanism of the edge intelligent all-in-one machine. And carrying out compression abstract processing on the abnormal propagation path, keeping a node sequence structure, signing abstract information through a special key, and storing the abstract information in a local storage. And uploading the signed abstract to a cloud verification end, recovering a path structure in a graph inversion mode, and executing credible scoring and behavior verification. According to the method, credible perception, compression evidence storage and remote verification of edge node behaviors are realized, and a brand-new technical path with popularization significance is provided for security collaboration in an edge computing environment.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of edge computing security and intelligent collaborative processing technology, and specifically to an edge intelligent collaborative processing method and system integrating zero trust. Background Art

[0002] Edge intelligence is widely used in scenarios such as smart manufacturing, urban perception, autonomous driving, and industrial control. However, edge devices are typically deployed in uncontrolled or semi-controlled environments, with limited computing resources and weak security protections. These devices struggle to cope with complex network threats, and are particularly vulnerable to risks such as unauthorized access and data tampering when multiple devices interact collaboratively. Therefore, ensuring data and identity trustworthiness while maintaining collaborative efficiency has become a key research focus in this field.

[0003] Existing edge intelligence collaborative processing mechanisms often rely on centralized trust models or traditional authentication architectures, such as those based on access control lists (ACLs) or role-based access control (RBAC). These mechanisms fail to implement real-time evaluation and dynamic authorization of each access request, leading to security vulnerabilities in scenarios such as device hijacking, session hijacking, or credential leakage. Furthermore, during collaborative computing, state synchronization between edge devices often lacks effective verification mechanisms, making them vulnerable to man-in-the-middle attacks, data injection, and node forgery. Furthermore, most existing systems rely on centralized decision-making for incident response and abnormal behavior detection. This significantly reduces overall processing capacity if communication is interrupted or the central controller fails. As the Zero Trust security concept becomes mainstream, existing edge intelligence systems lack a mechanism for jointly determining multi-dimensional indicators such as access subjects, environmental context, and behavioral trajectories, making it difficult to support the Zero Trust principles of "always verify, least privilege, and dynamic trust." Therefore, how to implement collaborative processing methods at the edge that integrate Zero Trust architecture, ensuring data integrity and identity verification while achieving a closed-loop distributed computing and signature authentication, remains a challenge that current technologies have yet to effectively address. Summary of the Invention

[0004] In view of the above-mentioned problems, the present invention is proposed.

[0005] Therefore, the technical problems solved by the present invention are: the existing edge intelligent collaborative processing methods are unable to perform dynamic access authentication and real-time behavior verification, the collaborative paths between devices lack a trusted transmission mechanism, abnormal data is difficult to autonomously control on the edge side, and how to realize the closed loop of trusted collaborative computing and signature verification of multiple devices on the edge side based on the integrated zero-trust architecture.

[0006] To solve the above technical problems, the present invention provides the following technical solutions: a method for collaborative processing of edge intelligence integrating zero trust, comprising obtaining multi-source heterogeneous operating indicators of an edge intelligent all-in-one machine and constructing an indicator graph relationship, and using time window sliding and information analysis to generate an edge set in the indicator graph.

[0007] Based on the local memory loading mechanism of the edge intelligent all-in-one machine, the graph structure expression of the indicator graph relationship and the weight calculation between nodes are executed.

[0008] The abnormal propagation path is compressed and summarized while maintaining the node sequence structure. The summary information is signed with a dedicated key and saved in local storage.

[0009] The signed summary is uploaded to the cloud verification terminal, and the path structure is restored through graph inversion to perform trust scoring and behavior verification.

[0010] The process of compressing and summarizing the abnormal propagation path while maintaining the node sequence structure involves extracting the abnormal event transmission path from the constructed indicator graph, assigning a sequence identifier and compression weight to each node in the transmission path, and generating transmission path summary data. The transmission path summary is encoded using a sequential weighted hash algorithm, maintaining the original node sequence and identifier consistency. The encoded result is used in the summary signature preparation stage.

[0011] As a preferred embodiment of the zero-trust integrated edge intelligent collaborative processing method described in the present invention, the acquisition of multi-source heterogeneity of the edge intelligent all-in-one device includes collecting operating status data through the built-in sensor unit of the edge intelligent all-in-one device and aligning different types of indicators using a unified timestamp mechanism. Each pair of operating indicators is traversed through a fixed-length sliding time window, the mutual information valuation is calculated, and the correlation is determined. When the set correlation strength threshold is met, it is recorded as an edge in the indicator graph, and the indicator graph structure is established.

[0012] As a preferred solution of the edge intelligent collaborative processing method integrating zero trust described in the present invention, wherein: the edge set in the indicator graph is generated by using time window sliding and information volume analysis, including defining a sliding window sequence within a fixed window length for each type of indicator collection sequence, and calculating the mutual information valuation by statistically analyzing the information entropy and joint distribution between the indicators. Determine whether the mutual information is higher than the trusted correlation threshold set inside the edge intelligent all-in-one machine, and generate side information after maintaining stability within a continuous window. The side information contains direction, strength and time identification, which is used to construct a directed indicator graph.

[0013] As a preferred embodiment of the zero-trust integrated edge intelligent collaborative processing method described in the present invention, the graph structure expression includes: the edge intelligent all-in-one machine loads the side information related to the active indicator nodes in the current cycle during each sampling cycle, and establishes a sparse adjacency matrix for graph expression according to a preset storage structure. The graph structure calculation is performed on the indicator graph structure within two rounds, and the embedded representation of each node is calculated using the weight propagation function. All calculations are completed in the local memory of the edge intelligent all-in-one machine.

[0014] As a preferred embodiment of the zero-trust integrated edge intelligent collaborative processing method described in the present invention, the inter-node weight calculation includes initializing the numerical representation of each indicator node and combining it with the edge set in the memory of the edge intelligent all-in-one machine, and then using weighted aggregation to fuse the representations of adjacent nodes. During the fusion process, dynamic weight values are calculated based on the historical frequency of collaborative occurrences between nodes, edge strength, and node timestamps. The weight values serve as an estimation factor for the potential anomaly propagation capability between indicators to generate the final graph embedding result.

[0015] As a preferred solution of the edge intelligent collaborative processing method integrating zero trust described in the present invention, wherein: the compression summary processing of the abnormal propagation path and maintaining the node sequence structure includes, after completing the embedding construction of the indicator graph, the edge intelligent integrated machine automatically traverses all path sets in the graph, identifies the abnormal event propagation chain, and selects the path with the abnormal trigger weight threshold feature as the processing object. The selected abnormal path is labeled with node sequence, and a sequence sequence is constructed in combination with the edge directionality in the graph, and the propagation position weight of each node in the propagation chain is calculated. The weight is evaluated by the joint function of the propagation time interval and the node coupling degree. The sequence sequence and the propagation position weight are used as the summary construction input together, and the summary encoding is performed by a preset sequential weighted hash algorithm. During the summary encoding process, the edge intelligent integrated machine sequentially executes a weighted hash function on each node number, sequence value and propagation position weight, and outputs a single summary value. The summary value has unidirectionality and sequence preservation. After the summary value is bound to the original node sequence index, it is stored as summary data in the edge intelligent integrated machine cache. The sequential weighted hash algorithm is a set of sequence-sensitive mapping functions, which is sensitive to hash perturbations to changes in node sequence.

[0016] As a preferred embodiment of the zero-trust edge intelligence collaborative processing method described in the present invention, the method of signing the summary information with a dedicated key and storing it in local storage includes the edge intelligent all-in-one device invoking the device's preset local security hardware to perform a summary encryption operation and signing the compressed summary information using asymmetric encryption. The signing operation includes encoding the summary information, generating a summary hash value, and calculating a signature string. The signature string is associated with the timestamp and summary in the local storage to form a signature log file.

[0017] As a preferred embodiment of the zero-trust edge intelligence collaborative processing method described in the present invention, uploading the signed digest to the cloud-based verification terminal includes uploading the signed digest to the cloud within a predetermined communication cycle. The uploaded content includes a compressed digest value, a signature string, device identification information, and a timestamp. The cloud-based verification terminal reconstructs the indicator path based on the received summary information, restores the path by comparing the stored indicator graph structure with the edge information, and verifies the source identity by comparing the device identification.

[0018] As a preferred solution of the edge intelligent collaborative processing method integrating zero trust described in the present invention, wherein: the restoration of the path structure by graph inversion and the execution of trust scoring and behavior verification include performing integrity detection and score calculation on the summary path in the cloud environment, and judging whether there is a tampering risk by comparing whether the node order and weight in the summary are consistent. If the calculated score is higher than the trust threshold, the behavior of the edge intelligent all-in-one machine is recorded as normal, and the trust level is updated. If the calculated score is lower than the trust threshold, the uploaded content is marked as risky, and the relevant path information is written into the exception log for reference.

[0019] Another object of the present invention is to provide an edge intelligent collaborative processing system that integrates zero trust, which can be used to perform graph structure expression of indicator graph relationships and weight calculation between nodes based on the local memory loading mechanism of the edge intelligent all-in-one machine through a graph structure local computing module. The path summary signature storage module is used to compress and summarize the abnormal propagation path and maintain the node sequence structure, which solves the problems of the existing edge intelligent collaborative processing methods that cannot perform dynamic access authentication and real-time behavior verification, the lack of a trusted transmission mechanism for collaborative paths between devices, and the difficulty of autonomously controlling abnormal data on the edge side, as well as how to realize the closed loop of trusted collaborative computing and signature verification of multiple devices on the edge side based on the integrated zero trust architecture.

[0020] As an optimal solution for the edge intelligent collaborative processing system integrating zero trust described in the present invention, it includes: building an indicator graph relationship module, a graph structure local calculation module, a path summary signature storage module, and a cloud-based verification graph inversion module.

[0021] The indicator graph relationship construction module is used to obtain multi-source heterogeneous operation indicators of the edge intelligent all-in-one machine and construct indicator graph relationships, and uses time window sliding and information volume analysis to generate edge sets in the indicator graph.

[0022] The graph structure local computing module is used to perform graph structure expression of indicator graph relationships and weight calculation between nodes based on the local memory loading mechanism of the edge intelligent all-in-one machine.

[0023] The path summary signature storage module is used to perform compression summary processing on the abnormal propagation path and maintain the node sequence structure, sign the summary information with a dedicated key and save it in local storage.

[0024] The cloud-based verification graph inversion module is used to upload the signed summary to the cloud-based verification terminal, restore the path structure through graph inversion, and perform trust scoring and behavior verification.

[0025] A computer device includes a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement a step of an edge intelligent collaborative processing method integrating zero trust.

[0026] A computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of an edge intelligence collaborative processing method integrating zero trust.

[0027] Beneficial effects of the present invention: The edge intelligent collaborative processing method integrated with zero trust provided by the present invention effectively improves the accuracy of abnormal state modeling in edge environments by constructing a graph structure embedding representation of fusion attributes, timestamps and coupling relationships, and achieves the beneficial effect of parallel multi-source data fusion and propagation modeling.

[0028] Through path traversal and anomaly threshold recognition mechanisms, high-risk abnormal propagation paths are automatically identified, enabling rapid location of potential security risks in edge networks. This enhances the system's ability to track complex attack chains, achieving the beneficial effect of accurately tracing the source in multi-hop abnormal propagation scenarios.

[0029] By using a sequential weighted hash algorithm and a propagation position weight calculation formula, the structural features of the abnormal path are compressed into a single summary value, and a local key is used to complete the digital signature. This has the beneficial effect of enhancing the credibility of edge nodes.

[0030] By uploading summary values to the cloud, combining the indicator graph structure with edge information for path inversion, and performing trust scoring and signature verification on the summary path, it not only enhances the trust interaction mechanism of edge-cloud collaboration, but also improves the overall anti-tampering and traceability capabilities of the system, achieving the beneficial effects of cross-cycle behavior verification and audit archiving under the zero-trust model. BRIEF DESCRIPTION OF THE DRAWINGS

[0031] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0032] Figure 1This is an overall flow chart of an edge intelligent collaborative processing method integrating zero trust provided in Example 1 of the present invention.

[0033] Figure 2 This is a schematic diagram of an overall system of an edge intelligent collaborative processing system integrating zero trust provided in Example 2 of the present invention. DETAILED DESCRIPTION

[0034] To make the above-mentioned objects, features, and advantages of the present invention more clearly understood, the following detailed description of the specific embodiments of the present invention is given in conjunction with the accompanying drawings. It is obvious that the described embodiments are only part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary persons in this field without creative work should fall within the scope of protection of the present invention.

[0035] Example 1, with reference to Figure 1 , as an embodiment of the present invention, provides an edge intelligent collaborative processing method integrating zero trust, including: S1: Obtain multi-source heterogeneous operating indicators of the edge intelligent all-in-one machine and build an indicator graph relationship. Use time window sliding and information analysis to generate the edge set in the indicator graph.

[0036] The built-in sensor unit of the edge intelligent all-in-one machine collects operational status data and uses a unified timestamp mechanism to align different types of indicators. For each pair of operational indicators, a fixed-length sliding time window is used to traverse the data, calculate mutual information estimates, and determine correlations. When the set correlation strength threshold is met, it is recorded as an edge in the indicator graph, establishing the indicator graph structure.

[0037] Define a sliding window sequence within a fixed window length for each indicator collection sequence. Calculate the mutual information estimate by statistically analyzing the information entropy and joint distribution between the indicators. Determine whether the mutual information exceeds the trusted correlation threshold set within the edge intelligent appliance and remains stable within consecutive windows. Generate side information. Side information includes direction, intensity, and time stamps, and is used to construct a directed indicator graph.

[0038] Furthermore, for each pair of operating indicator sequences, information theory analysis is performed within the sliding time window, and mutual information is used as the basis for judging the correlation between indicators. In each window, the indicator sequence is calculated and The mutual information value of , to evaluate their joint dependence, the formula is as follows: ; in, Indicates in In the sliding window, The indicator and The mutual information value of the indicators. Indicates the The value space of an indicator in the current window. Indicates the The value space of an indicator in the current window. represents the joint probability distribution, which is the The indicator value is , No. The indicator value is The joint probability of . Indicates the Indicators in the window The marginal probability distribution within . Indicates the Indicators in the window The marginal probability distribution within .

[0039] Next, in order to determine the stable correlation between the indicators, the mutual information value is counted in the continuous sliding window to see whether it meets the set credible correlation strength threshold. If in continuous If the following judgment conditions are met in all windows, it is considered that The indicator and There is a correlation between the indicators: ; in, Indicates the In the sliding window, The indicator and The mutual information value calculated between the indicators. Indicator function, the value is 1 if the condition is met, otherwise it is 0. It represents the mutual information strength threshold set by the edge intelligent all-in-one machine, which is used to determine whether there is a trusted dependency relationship between two indicators. In the present invention, it is set to 0.25. The setting of the value of 0.25 is based on multiple actual measurements and verifications in the experimental environment. It can take into account both the false positive rate and the missed positive rate, and has good discrimination ability in the edge operating environment with a low noise level. Indicates the number of consecutive windows, which is usually the lower limit of the number of stable windows set on the edge to ensure that the side information is not sporadic. Indicates the window index number of the sliding window in the indicator collection sequence.

[0040] Once the correlation between indicators is established, side information will be generated for the indicator pair, including direction (from the leading indicator to the response indicator), strength (based on the mean and variance of the mutual information), and time stamp. The quantitative calculation of edge strength is as follows: ; in, Indicates the index pair arrive In the window The edge strength estimation. Display window Mean internal mutual information. Represents the fluctuation penalty factor, which is used to reduce misjudgment caused by drastic fluctuations in mutual information. Its value range is [0,1].

[0041] It should be noted that the present invention S1 realizes the construction path for identifying the stability correlation between multi-source heterogeneous operating indicators in the edge intelligent integrated machine by integrating the sliding time window mechanism and the information theory mutual information analysis method. By verifying the stability of mutual information in multiple continuous time windows and combining the trusted correlation threshold judgment, sporadic or non-causal indicator correlations are effectively filtered out, thereby generating a structured directed indicator graph. Compared with the single-point judgment, Pearson-based or dynamic time warping (DTW)-based methods in the prior art, it realizes the multi-dimensional discrimination of temporal dependence, information strength and stability between indicators, solves the defect of the existing method that it cannot distinguish between continuous causal correlation and short-term noise coupling, and improves the expression accuracy of the indicator graph structure and the robustness of subsequent anomaly detection.

[0042] S2: Executes the graph structure expression of the indicator graph relationship and the weight calculation between nodes based on the local memory loading mechanism of the edge intelligent all-in-one machine.

[0043] The edge intelligent all-in-one machine loads the side information related to the active indicator nodes in the current period in each sampling period, and establishes a sparse adjacency matrix for graph expression according to the preset storage structure.

[0044] Furthermore, the edge intelligent all-in-one machine loads the side information related to the active indicator nodes in the current period in each sampling period, and uses the sparse adjacency matrix structure to represent the graph relationship. The sparse adjacency matrix is constructed and expressed as: ; in, Indicates at time When the indicator node arrive Whether there is an edge. If so, the edge strength value; otherwise, 0. Indicates an indicator node arrive At the moment The edge strength estimation of comes from the mutual information analysis results in S1. Represents a slave node Pointing to the indicator node The directed edge of .

[0045] Perform graph structure calculations within two rounds on the indicator graph structure, and calculate the embedding representation of each node through the weight propagation function. All calculations are completed in the local memory of the edge intelligent all-in-one machine.

[0046] Furthermore, embedding updates are performed in the following ways: ; in, Indicates time When the indicator node The embedded vector representation of is used to represent its comprehensive features in the graph structure. Represents a nonlinear activation function. The present invention adopts the RELU function to enhance the expression ability. Indicates time When the node The set of adjacent nodes, that is, all nodes with edges connected to A collection of nodes. Representation node To Node The propagation weight coefficient of . Indicates time When the node The raw indicator sample values of are used as the initial embedding input.

[0047] Furthermore, the propagation weight It is determined by combining the three factors of historical synergy frequency, edge strength and time lag, and is defined as follows: ; in, Indicates time When the node For Node The propagation weight value reflects the contribution of the side information in the current aggregation. 、 and It represents the weighting factor, which is used to control the relative weights of the three influencing factors in the propagation weight. In the present invention, the values are set to 0.3, 0.5 and 0.2 respectively. Represents a node pair The frequency of co-occurrence during the historical sampling period, normalized to the interval [0,1]. Represents a node pair The edge strength estimate comes from the adjacency matrix in formula 1 . Representation node and The difference between the latest sampling timestamp and the latest sampling timestamp, in seconds, is used to evaluate the degree of data synchronization lag. It represents the time lag attenuation factor, which is set to 0.05 in the present invention to balance the impact of time on the credibility of transmission.

[0048] By initializing the numerical representation of each indicator node and combining it with the edge set in the edge intelligent appliance's memory, a weighted aggregation approach is used to fuse the representations of adjacent nodes. During the fusion process, dynamic weights are calculated based on the historical frequency of collaborative occurrences between nodes, edge strength, and node timestamps. These weights serve as an estimate of the potential for anomaly propagation between indicators, generating the final graph embedding result.

[0049] Finally, all nodes are embedded Form a node embedding matrix under the current graph structure , as the input for the subsequent summary compression and trusted verification stages, ensuring that all calculations are completed in the local memory of the edge intelligent all-in-one machine, avoiding the privacy leakage risk caused by data on the cloud.

[0050] It should be noted that the S2 design avoids dependence on cloud resources by implementing the construction of indicator graphs and node embedding calculations locally on the edge intelligent all-in-one machine, thereby improving response timeliness and data privacy protection capabilities. This method uses a sparse adjacency matrix to express the structural relationship between periodically active indicators, and performs multi-factor weighted fusion calculations through graph structure propagation functions to effectively model the potential causal relationship and abnormal propagation paths between indicators. In particular, the introduction of three factors, historical collaborative frequency, edge strength, and time lag, in the calculation of propagation weights significantly enhances the stability and interpretability of anomaly identification. It breaks through the problem that existing methods rely on cloud reasoning and cannot dynamically fuse multi-source edge information, and has stronger local computing capabilities and adaptability to complex relationship structures in edge environments.

[0051] S3: Compress and summarize the abnormal propagation path and maintain the node sequence structure. Sign the summary information with a private key and save it in local storage.

[0052] After embedding the indicator graph, the edge intelligent appliance automatically traverses all paths in the graph, identifies the propagation chain of abnormal events, and selects paths that meet the anomaly trigger weight threshold characteristics as processing targets. The selected abnormal paths are labeled with node sequence numbers and, based on the directionality of the edges in the graph, a sequence is constructed. The propagation position weight of each node in the propagation chain is calculated, and the weight is evaluated using a joint function of the propagation time interval and the node coupling degree.

[0053] Furthermore, the propagation position weight calculation formula is expressed as: ; in, Indicates the The first transmission path The propagation position weight of a node is in the range of (0,1], which is used to measure the influence of the node in the abnormal propagation path. Indicates the The propagation time interval between a node and its previous node, in seconds. Indicates the The coupling degree between a node and the previous node comes from the edge strength estimation in the graph structure and ranges from [0,1]. The larger the value, the stronger the coupling. It represents the time penalty factor, which is used to control the influence of propagation delay and is set to 0.1 in the present invention. It represents the coupling adjustment factor, which is used to adjust the negative impact of weak coupling on the weight. It is set to 0.2 in the present invention.

[0054] The sequential sequence and propagation position weight are used as input for digest construction. The digest is encoded using a preset sequential weighted hash algorithm. During the digest encoding process, the edge intelligent appliance sequentially applies a weighted hash function to each node number, sequence value, and propagation position weight, outputting a single digest value. This digest value is unidirectional and sequence-preserving. The digest value is bound to the original node sequence index and stored as summary data in the edge intelligent appliance cache. The sequential weighted hash algorithm is a set of order-sensitive mapping functions and is sensitive to hash perturbations caused by changes in the node order.

[0055] Furthermore, all node numbers, sequential indexes, and propagation position weights are encoded into summary values, and the sequential weighted hash summary generation function is expressed as: ; in, Indicates the The single summary value generated by the propagation path has the characteristics of uniqueness and order preservation. Indicates the The first path A unique identifier for a node. Indicates the sequential index of the node in the path. The value is a positive integer, representing the position of the node in the propagation chain. Represents the propagation position weight of the corresponding node, which comes from the propagation position weight calculation formula. Indicates the path The total number of nodes.

[0056] 、 and Represents the weighting factor in the digest calculation, which is used to control the contribution ratio of different inputs to the hash value. In the present invention, it is set to 1, 3 and 5 respectively. Expressed as a sequence-sensitive hash function, the present invention adopts the SM3 national secret hash algorithm to expand its implementation, which has strong disturbance sensitivity to changes in node order, ensuring the irreversibility and uniqueness of the digest.

[0057] The edge intelligent appliance uses the device's pre-configured local security hardware to perform digest encryption and sign the compressed digest using asymmetric encryption. The signing process includes digest encoding, digest hash value generation, and signature string calculation. The signature string is then stored locally, associated with the timestamp and digest, and stored as a signature log file.

[0058] Furthermore, the signature string generation function is expressed as: ; in, Indicates the The signature string of the propagation path is in ciphertext form. Indicates an asymmetric signing operation using the device's private key for encryption. Represents the path summary value, which is derived from the sequential weighted hash summary generation function. Indicates the timestamp of the digest generation, which is used to bind the unique time identifier when the signature is generated. Represents the concatenation operator, which means that the digest value and timestamp are concatenated as the signature input.

[0059] It should be noted that S3 uses the edge intelligent all-in-one machine to locally complete the identification, compression summary, order preservation and encryption signature operations of abnormal propagation paths, avoiding the privacy leakage risks brought by data upload. Its core lies in constructing a sequential weighted hash summary function that combines the node order and the propagation position weight, and combines it with an asymmetric encryption algorithm for signature binding to achieve unique identification, integrity verification and time traceability of the abnormal chain. Compared with existing technologies, this step not only supports high-level disturbance perception of node sequence changes, but also completes trusted summary compression without the participation of a central server. It has lightweight deployment, high robustness and strong autonomy on the edge side, which is a key breakthrough in traditional centralized log comparison methods.

[0060] S4: Upload the signed summary to the cloud verification end, restore the path structure through graph inversion, and perform trust scoring and behavior verification.

[0061] The signature summary is packaged and uploaded to the cloud within the set communication cycle. The uploaded content includes the compressed summary value, signature string, device identification information, and timestamp. The cloud verifier reconstructs the indicator path based on the received summary information, restores the path by comparing it with the stored indicator graph structure and edge information, and verifies the source identity by comparing it with the device identification.

[0062] Furthermore, after receiving the above uploaded data, the cloud verification end first calls the device public key to decrypt the signature string, obtains the summary value and timestamp after decryption, and compares the consistency with the summary value and timestamp in the uploaded content to confirm the legitimacy of the signature.

[0063] Next, the cloud-based verification end performs a path inversion operation based on the node sequence index and propagation position weight in the summary value, combined with the stored edge information and indicator graph structure (i.e., the graph adjacency matrix and graph node attribute table of the historical version). The basic process includes searching the graph structure one by one to see if there is an edge connection relationship with the previous node according to the node number order in the summary. Determine whether the direction of the edge connection is consistent with the summary order. Determine whether the edge weight estimate is logically consistent with the propagation position weight in the summary (the error does not exceed a preset threshold, which is set to 0.05 in this invention).

[0064] If all of the above conditions are met, the node is marked as restorable and added to the inversion path. Otherwise, the path is marked as inconsistent. After the path inversion is completed, the cloud verification terminal performs the path integrity score calculation.

[0065] In the cloud environment, the summary path is checked for integrity and scored. By comparing the order and weights of the nodes in the summary, the risk of tampering is determined. If the calculated score is above the trust threshold, the edge intelligent all-in-one device is recorded as normal and its trust level is updated. If the calculated score is below the trust threshold, the uploaded content is marked as risky and the relevant path information is written to the exception log for future reference.

[0066] Furthermore, the path integrity score is calculated, and the score consists of the following two parts:

[0067] Node order consistency score: Determines whether the order of nodes in the summary is completely consistent with the order of recoverable paths in the graph.

[0068] Propagation weight deviation score: Compare the summary weight value of each node with the actual estimated value in the graph and calculate whether the deviation value is within the credible interval.

[0069] The final scoring result is recorded as the credibility score value, which is compared with the preset credibility threshold (set to 0.85 in this invention):

[0070] If the trust score value is greater than or equal to 0.85, the summary content is determined to be trustworthy, the edge intelligent all-in-one machine is recorded as a normal node, and its historical trust level is positively updated.

[0071] If the trust score is less than 0.85, the summary is judged to be risky, the uploaded content is recorded as a suspicious path, and the path information is written into the abnormal log list for subsequent analysis.

[0072] In addition, the cloud-based verification terminal archives the uploaded summaries and verification records of all connected devices on a periodic basis, and forms a multi-dimensional traceability list based on the signature timestamp and device identification code to achieve cross-period behavioral verification and risk profiling.

[0073] It should be noted that S4 implements a graph inversion verification mechanism and a trusted scoring model in the cloud to achieve dual verification of the authenticity and integrity of summaries uploaded by edge devices. The design concept uses signature summaries as indexes and combines them with an indicator graph structure to reconstruct paths, ensuring that data has not been tampered with. It also improves judgment accuracy through a dual-factor scoring system based on node order and propagation weight. This effectively addresses the existing challenges of difficult edge computing results verification and insufficient anomaly tracing capabilities, enabling cross-cycle trusted verification and behavioral profiling, and enhancing the system's security, controllability, and traceability.

[0074] Example 2, reference Figure 2 , as an embodiment of the present invention, provides an edge intelligent collaborative processing system integrating zero trust, including an indicator graph relationship construction module 100, a graph structure local calculation module 200, a path summary signature storage module 300, and a cloud-based verification graph inversion module 400.

[0075] S5: The indicator graph relationship construction module 100 is used to obtain multi-source heterogeneous operation indicators of the edge intelligent all-in-one machine and construct an indicator graph relationship, and uses time window sliding and information volume analysis to generate an edge set in the indicator graph.

[0076] The indicator graph relationship construction module 100 includes an indicator collection submodule 101 and an edge set generation submodule 102 .

[0077] The indicator collection submodule 101 is used to obtain operational indicators from multi-source heterogeneous monitoring devices such as CPUs, memory, networks, and temperature and humidity sensors from the edge intelligent all-in-one machine, and periodically construct a sequence of raw indicator vectors. The edge set generation submodule 102 is used to perform joint entropy and mutual information analysis on the collected data based on a sliding time window mechanism, identify highly coupled relationships between indicators, and dynamically update the edge sets in the graph.

[0078] It should be noted that the indicator collection submodule 101 is the starting point for constructing the indicator graph, ensuring the integrity of the data source. The edge set generation submodule 102 constructs edge connections between indicators through information quantity constraints, providing a topological basis for subsequent graph structure expression and graph embedding.

[0079] S6: The graph structure local computing module 200 is used to perform graph structure expression of indicator graph relationships and weight calculation between nodes based on the local memory loading mechanism of the edge intelligent all-in-one machine.

[0080] The graph structure local calculation module 200 includes a graph representation construction submodule 201 and a propagation weight calculation submodule 202. The graph representation construction submodule 201 is used to map the constructed indicator graph into an adjacency matrix and a table of node attribute vectors, and improve access efficiency based on a local cache mechanism. The propagation weight calculation submodule 202 is used to construct a propagation direction and propagation strength matrix between nodes based on the activation sequence and coordination frequency between indicators when an abnormal event occurs.

[0081] It should be noted that the graph expression construction submodule 201 completes the conversion from the original relationship to the graph structure expression. The propagation weight calculation submodule 202 introduces the node timing difference and the frequency coupling factor to achieve a detailed modeling of the potential abnormal path propagation relationship.

[0082] S7: The path summary signature storage module 300 is used to compress and summarize the abnormal propagation path and maintain the node sequence structure, sign the summary information with a dedicated key and save it in local storage.

[0083] The path summary signature storage module 300 includes a summary generation submodule 301 and a signature storage submodule 302 .

[0084] The digest generation submodule 301 generates a fixed-length compressed digest based on the identified anomaly propagation path, using node sequence encoding and a weighted hash algorithm. The signature storage submodule 302 digitally signs the digest value using the local private key built into the edge intelligent all-in-one device and packages and stores the signature content, timestamp, and device identification information in a local secure storage unit.

[0085] It should be noted that the summary generation submodule 301 implements the compressed expression and order preservation of the path structure. The signature storage submodule 302 adds tamper-proof capabilities to the summary information, providing a secure foundation for subsequent trusted verification.

[0086] S8: The cloud-based verification graph inversion module 400 is used to upload the signed summary to the cloud-based verification terminal, restore the path structure through graph inversion, and perform trust scoring and behavior verification.

[0087] The cloud-based verification graph inversion module 400 includes a summary upload submodule 401 and a path inversion verification submodule 402. Summary upload submodule 401 is used to upload the signed summary package (including the signature value, device number, timestamp, and summary value) to the cloud-based verification terminal. Path inversion verification submodule 402 is used to access the existing indicator graph structure in the cloud and perform a graph inversion operation based on the node sequence and weight information in the summary value. This determines whether the summary content is consistent with the historical graph structure, and then uses a trustworthy scoring algorithm to determine its credibility and update the device's trust level.

[0088] It should be noted that the summary upload submodule 401 ensures a smooth signature information path between the edge and the cloud. The path inversion verification submodule 402 is responsible for executing the entire verification closed loop and is a key module for implementing remote behavior verification under a zero-trust architecture.

Claims

1. A method for edge intelligent collaborative processing integrating zero trust, characterized in that: include: Obtain multi-source heterogeneous operating indicators of edge intelligent all-in-one machines and construct indicator graph relationships. Use time window sliding and information volume analysis to generate edge sets in the indicator graph. Based on the local memory loading mechanism of the edge intelligent all-in-one machine, the graph structure expression of the indicator graph relationship and the weight calculation between nodes are executed; Perform compression and summary processing on the abnormal propagation path and maintain the node sequence structure, sign the summary information with a dedicated key and save it in local storage; Upload the signed summary to the cloud verification terminal, recover the path structure through graph inversion, and perform trust scoring and behavior verification; The compression summary processing of the abnormal propagation path and maintaining the node sequence structure includes extracting the abnormal event conduction path from the constructed indicator graph, setting a sequence identifier and a compression weight for each node in the conduction path, and generating conduction path summary data; the conduction path summary is encoded using a sequential weighted hash algorithm to maintain the original node order and identifier consistency, and the encoding result is used in the summary signature preparation stage.

2. The edge intelligent collaborative processing method integrating zero trust as claimed in claim 1, characterized in that: The acquisition of multi-source heterogeneity of the edge intelligent integrated machine includes: The built-in sensor unit of the edge intelligent all-in-one machine collects operating status data and uses a unified timestamp mechanism to align different types of indicators; Each pair of operating indicators is traversed through a fixed-length sliding time window, the mutual information valuation is calculated and the correlation is judged. When the set correlation strength threshold is met, it is recorded as an edge in the indicator graph and the indicator graph structure is established.

3. The edge intelligent collaborative processing method integrating zero trust according to claim 1 or 2, characterized in that: The edge set in the index graph generated by using time window sliding and information analysis includes: Define a sliding window sequence within a fixed window length for each type of indicator collection sequence, and calculate the mutual information estimation by statistically analyzing the information entropy and joint distribution between the indicators; Determine whether the mutual information is higher than the trusted correlation threshold set within the edge intelligent all-in-one machine and generates side information after it remains stable within a continuous window; the side information includes direction, strength and time identifier, which is used to construct a directed indicator graph.

4. The edge intelligent collaborative processing method integrating zero trust as claimed in claim 3, characterized in that: The graph structure expression includes: The edge intelligent all-in-one machine loads the edge information related to the active indicator nodes in the current period in each sampling period, and establishes a sparse adjacency matrix for graph expression according to the preset storage structure; Perform graph structure calculations within two rounds on the indicator graph structure, and calculate the embedding representation of each node through the weight propagation function. All calculations are completed in the local memory of the edge intelligent all-in-one machine.

5. The edge intelligent collaborative processing method integrating zero trust according to claim 1, 2 or 4, characterized in that: The inter-node weight calculation includes: By initializing the numerical representation of each indicator node and combining it with the edge set in the memory of the edge intelligent all-in-one machine, a weighted aggregation method is used to fuse the representations of adjacent nodes. During the fusion process, dynamic weight values are calculated based on the historical frequency of collaborative occurrences between nodes, edge strength, and node timestamps. The weight values are used as an estimation factor of the potential abnormal propagation ability between indicators to generate the final graph embedding result.

6. The edge intelligent collaborative processing method integrating zero trust as claimed in claim 1, characterized in that: The said compressing summary processing of the abnormal propagation path and maintaining the node sequence structure includes: After the indicator graph is embedded and constructed, the edge intelligent all-in-one automatically traverses all path sets in the graph, identifies the abnormal event propagation chain, and selects the paths with the abnormal trigger weight threshold characteristics as the processing objects; The nodes of the selected abnormal paths are sequentially numbered, and a sequential sequence is constructed based on the directionality of the edges in the graph. The propagation position weight of each node in the propagation chain is calculated. The weight is evaluated by the joint function of the propagation time interval and the node coupling degree. The order sequence and propagation position weight are used as the input for digest construction. The digest is encoded using a preset order-weighted hash algorithm. During the digest encoding process, the edge intelligent all-in-one machine sequentially performs a weighted hash function on each node number, order value, and propagation position weight, outputting a single digest value. The digest value is unidirectional and sequence-preserving. The summary value is bound to the original node sequential index and stored as summary data in the edge intelligent all-in-one cache; The sequential weighted hashing algorithm is a set of order-sensitive mapping functions that are sensitive to hash perturbations when the order of nodes changes.

7. The edge intelligent collaborative processing method integrating zero trust as claimed in claim 6, characterized in that: The signing of the summary information by the private key and storing it in local storage includes: The edge intelligent all-in-one device calls the local security hardware preset in the device to perform summary encryption operations and signs the compressed summary information using asymmetric encryption. The signature operation includes digest information encoding, digest hash value generation and signature string calculation. The signature string is associated with the timestamp and digest in local storage to form a signature log file.

8. The edge intelligent collaborative processing method integrating zero trust as claimed in claim 1, characterized in that: The uploading of the signed summary to the cloud verification terminal includes: The signature summary is packaged and uploaded to the cloud within the set communication cycle. The uploaded content includes the compressed summary value, signature string, device identification information and timestamp; The cloud verification end reconstructs the indicator path based on the received summary information, restores the path by comparing the stored indicator graph structure with the edge information, and confirms the source identity by comparing it with the device identification.

9. The edge intelligent collaborative processing method integrating zero trust as claimed in claim 8, characterized in that: The method of restoring the path structure by graph inversion and performing trust scoring and behavior verification includes: Integrity testing and scoring are performed on the summary path in the cloud environment. By comparing the order and weight of the nodes in the summary to determine whether there is a tampering risk, If the calculated score is higher than the trust threshold, the behavior of the edge intelligent all-in-one device is recorded as normal and the trust level is updated; If the calculated score is lower than the trust threshold, the uploaded content is marked as risky and the relevant path information is written to the exception log for future reference.

10. An edge intelligent collaborative processing system integrating zero trust, adopting the edge intelligent collaborative processing method integrating zero trust according to any one of claims 1 to 9, characterized in that: It includes an indicator graph relationship construction module (100), a graph structure local calculation module (200), a path summary signature storage module (300), and a cloud-based verification graph inversion module (400); The indicator graph relationship construction module (100) is used to obtain multi-source heterogeneous operation indicators of the edge intelligent integrated machine and construct an indicator graph relationship, and uses a time window sliding and information volume analysis method to generate an edge set in the indicator graph; The graph structure local calculation module (200) is used to perform graph structure expression of indicator graph relationships and weight calculation between nodes based on the local memory loading mechanism of the edge intelligent all-in-one machine; The path summary signature storage module (300) is used to perform compression summary processing on the abnormal propagation path and maintain the node sequence structure, sign the summary information with a dedicated key and save it in local storage; The cloud verification graph inversion module (400) is used to upload the signed summary to the cloud verification terminal, restore the path structure through graph inversion and perform trust scoring and behavior verification.

11. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the edge intelligent collaborative processing method integrating zero trust are implemented as described in any one of claims 1 to 9.

12. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the edge intelligent collaborative processing method integrating zero trust are implemented as described in any one of claims 1 to 9.

Citation Information

Cited By

  • Railway intelligent operation and maintenance secure transmission method based on multi-modal data fusion and application

    CN120711377A

  • Integrity auditing method and system in edge computing environment

    CN121278787A

  • An integrity auditing method and system in an edge computing environment

    CN121278787B

  • Data security protection method and device in cloud computing and storage medium

    CN121283665A