Dynamic key automatic isolation method and system for industrial Internet

By real-time monitoring and dynamic adjustment of key distribution to optimize key arrangement, the security and adaptability issues of key management in the industrial Internet in existing technologies are solved, and the protection capabilities of network security systems and the efficiency of identifying abnormal behaviors are improved.

CN120528699BActive Publication Date: 2025-09-16JIANGSU SMART WORKSHOP TECHNOLOGY RESEARCH INSTITUTE CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202511007309.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-07-22
Publication Date
2025-09-16
Estimated Expiration
2045-07-22

AI Technical Summary

Technical Problem

Existing key management methods are difficult to cope with high-frequency and complex network attacks in the Industrial Internet. The frequency of key usage is insufficiently monitored and there is a lack of dynamic adjustment mechanism, which makes the key arrangement easy to be predicted by attackers. There is a lack of comprehensive management of multi-dimensional security attributes and it is difficult to adapt to the complex environment of multiple nodes and heterogeneous devices.

Method used

By real-time monitoring of key usage frequency and distribution, adjusting key distribution priority based on network delay data, using matrix transformation algorithm to optimize key arrangement order, using clustering and behavior analysis algorithms to identify high-risk nodes, and dynamically adjusting key distribution, the security and adaptability of the key system are improved.

Benefits of technology

It improves the security and adaptability of key management in the industrial Internet environment, reduces potential attack threats, optimizes key distribution, achieves flexible adaptation to heterogeneous devices, improves the efficiency and accuracy of abnormal behavior identification, and enhances the protection capabilities of network security systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120528699B_ABST
    Figure CN120528699B_ABST
Patent Text Reader

Abstract

The present application provides a dynamic key automatic isolation method and system for the industrial Internet, which relates to the field of computer technology to improve the security of the key system. The method includes: determining high-risk nodes in a network security system and obtaining network delay data of the high-risk nodes; the abnormal behavior score of the high-risk node is greater than a preset score; based on the network delay data, adjusting the key distribution priority of the high-risk node to obtain an adjusted key distribution priority; the adjusted key distribution priority is negatively correlated with the network delay data; using a matrix transformation algorithm to reconstruct the key arrangement order of the high-risk node to obtain a new key; based on the adjusted key distribution priority and the new key, providing security services for the high-risk node.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a method and system for automatic isolation of dynamic keys for the industrial Internet. Background Art

[0002] With the increasing popularity of the internet and the continuous advancement of network technology, cryptographic techniques are increasingly being applied to portable, less secure mobile devices, making it easier for attackers to compromise these devices and obtain cryptographic keys. However, for traditional cryptographic systems that rely entirely on secret keys, once a key is leaked, all cryptographic operations related to that key become invalid. Therefore, key self-protection technology is being applied in a growing number of fields as an effective method to minimize key leakage.

[0003] The basic idea behind key isolation technology is to split a user's private key into two parts: a temporary private key stored on the user device and a helper key stored on the helper. The user device has strong computing power but poor security, while the helper has weak computing power but strong physical security. The entire lifecycle is divided into several time periods. Throughout the system lifecycle, while the user's public key remains unchanged, the temporary private key for each time period is regularly updated through interaction between the user device and the helper. Users use different temporary private keys in different time periods. Leaking the temporary private key in one time period does not compromise the security of other time periods, significantly reducing the potential harm caused by key leakage.

[0004] Most of the existing key isolation solutions rely on static or periodically updated key generation strategies, which are difficult to cope with high-frequency and complex network attacks and can easily lead to keys being predicted or cracked. Summary of the Invention

[0005] Based on the above technical problems, the present application provides a dynamic key automatic isolation method and system for the industrial Internet to improve the security of the key system.

[0006] In the first aspect, the present application provides a dynamic key automatic isolation method for the industrial Internet, the method comprising: determining high-risk nodes in a network security system and obtaining network delay data of the high-risk nodes; the abnormal behavior score of the high-risk node is greater than a preset score; based on the network delay data, adjusting the key distribution priority of the high-risk node to obtain an adjusted key distribution priority; the adjusted key distribution priority is negatively correlated with the network delay data; using a matrix transformation algorithm to reconstruct the key arrangement order of the high-risk node to obtain a new key; based on the adjusted key distribution priority and the new key, providing security services for the high-risk node.

[0007] In one possible implementation, determining high-risk nodes in a network security system includes: obtaining the key usage frequency of each node in the network security system, and performing cluster analysis on nodes whose key usage frequency is greater than a preset frequency through a cluster analysis algorithm to determine abnormal usage pattern nodes; obtaining key usage data of abnormal usage pattern nodes, analyzing the key usage data through a behavior analysis algorithm to obtain an abnormal behavior score, and determining abnormal usage pattern nodes whose abnormal behavior score is greater than a preset score as high-risk nodes.

[0008] In one possible implementation, based on the network delay data, the key distribution priority of the high-risk node is adjusted to obtain the adjusted key distribution priority, including: if the network delay data is greater than or equal to a preset threshold, the key distribution priority of the high-risk node is reduced according to a preset coefficient to obtain the adjusted key distribution priority; if the network delay data is less than the preset threshold, the key distribution priority of the high-risk node is increased according to the preset coefficient to obtain the adjusted key distribution priority.

[0009] In one possible implementation, the method further includes: extracting key features of the new key; the key features are used to reflect the sparsity and uniformity of the new key; inputting the key features into a trained isolation efficiency evaluation model to quantitatively analyze the key isolation effect of the new key to obtain an isolation coefficient; based on the isolation coefficient and the attack success rate in historical records, determining a quantitative score of the isolation efficiency of the new key; the attack success rate is negatively correlated with the isolation coefficient.

[0010] In one possible implementation, the method also includes: obtaining operating status data of high-risk nodes; the operating status data includes central processing unit usage and memory occupancy; weighting the central processing unit usage, memory occupancy and network delay data, and determining a quantitative score of the isolation efficiency of the new key based on the weighted result.

[0011] The technical solution provided by this application brings at least the following beneficial effects:

[0012] (1) This application discloses a method for managing industrial Internet keys. After identifying high-risk nodes in a network security system, the method readjusts the key allocation priority of the high-risk nodes based on network delay data and reallocates keys to the high-risk nodes. Furthermore, this application provides security services for high-risk nodes based on the adjusted key allocation priority and new keys, rather than using pre-set fixed-period keys. This method can effectively improve the security and adaptability of key management in the industrial Internet environment, reduce potential attack threats, optimize key distribution, and achieve flexible adaptation to heterogeneous devices.

[0013] (2) This application uses a cluster analysis algorithm to perform cluster analysis on nodes with a key usage frequency greater than a preset frequency, and determines abnormal usage pattern nodes. Cluster analysis helps to subdivide abnormal behavior. Furthermore, this application uses a behavioral analysis algorithm to analyze key usage data to obtain abnormal behavior scores, and identifies abnormal usage pattern nodes with abnormal behavior scores greater than a preset score as high-risk nodes. Such analysis provides a fine-grained basis for device management. This application focuses on the core goal of abnormal node detection, supports each other, and ensures logical consistency from data collection to threat classification. The detailed design of each step helps to improve the efficiency and accuracy of abnormal behavior identification, providing a reliable basis for network security analysis.

[0014] (3) This application targets nodes with higher latency by lowering their key allocation priority and prioritizing them for nodes with lower latency. This adjustment ensures that key allocation is more inclined towards nodes with stable performance. This application precisely locates high-risk nodes, provides real-time data support through network monitoring, optimizes key usage efficiency through random allocation, and ensures distribution reliability through distributed storage. These steps support each other and jointly enhance the protection capabilities of the network security system.

[0015] (4) This application inputs key features into a trained isolation efficiency evaluation model to quantitatively analyze the key isolation effect of the new key and obtain the isolation coefficient. The calculation of the isolation coefficient takes into account the global characteristics of the distribution to avoid security risks caused by local density. This application determines the quantitative score of the isolation efficiency of the new key based on the isolation coefficient and the attack success rate in historical records. Historical data shows that the attack success rate is negatively correlated with the uniformity of key spacing. The attack success rate of a sequence with uniform spacing is less than 5%, while that of a sequence with dense distribution may be as high as 20%. Through data comparison methods, the correlation between the isolation coefficient and the attack success rate is analyzed to generate a quantitative score.

[0016] On the second aspect, the present application provides a dynamic key automatic isolation system for the industrial Internet, which includes a dynamic key automatic isolation device, which includes a determination unit and a processing unit; the determination unit is used to determine high-risk nodes in the network security system and obtain network delay data of the high-risk nodes; the abnormal behavior score of the high-risk node is greater than the preset score; the processing unit is used to adjust the key allocation priority of the high-risk node based on the network delay data to obtain an adjusted key allocation priority; the adjusted key allocation priority is negatively correlated with the network delay data; the processing unit is also used to use a matrix transformation algorithm to reconstruct the key arrangement order of the high-risk node to obtain a new key; the processing unit is also used to provide security services for the high-risk node based on the adjusted key allocation priority and the new key.

[0017] In one possible implementation, the determination unit is specifically used to: obtain the key usage frequency of each node in the network security system, and perform cluster analysis on the nodes whose key usage frequency is greater than the preset frequency through a cluster analysis algorithm to determine the abnormal usage pattern nodes; obtain the key usage data of the abnormal usage pattern nodes, analyze the key usage data through a behavior analysis algorithm to obtain an abnormal behavior score, and determine the abnormal usage pattern nodes whose abnormal behavior score is greater than the preset score as high-risk nodes.

[0018] In one possible implementation, the processing unit is specifically used to: if the network delay data is greater than or equal to a preset threshold, then reduce the key distribution priority of the high-risk node according to a preset coefficient to obtain an adjusted key distribution priority; if the network delay data is less than the preset threshold, then increase the key distribution priority of the high-risk node according to the preset coefficient to obtain an adjusted key distribution priority.

[0019] In a third aspect, the present application provides an electronic device comprising: a processor and a memory; the memory stores instructions executable by the processor; when the processor is configured to execute the instructions, the electronic device implements the method of the first aspect described above.

[0020] In a fourth aspect, the present application provides a computer program product, which, when running in an electronic device, enables the electronic device to execute the method related to the above-mentioned first aspect to implement the method of the above-mentioned first aspect.

[0021] In a fifth aspect, the present application provides a computer-readable storage medium, which includes: software instructions; when the software instructions are executed in an electronic device, the electronic device implements the method of the first aspect above.

[0022] The beneficial effects of the second to fifth aspects mentioned above can be referred to the first aspect and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] In order to more clearly illustrate the technical solutions in the embodiments of the present application, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0024] Figure 1 A schematic diagram of the structure of a network security system provided in an embodiment of the present application;

[0025] Figure 2 A schematic diagram of the composition of an electronic device provided in an embodiment of the present application;

[0026] Figure 3A flow chart of a method for automatic isolation of dynamic keys for the Industrial Internet provided in an embodiment of the present application;

[0027] Figure 4 A schematic diagram of the composition of the state key automatic isolation device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0028] In order to enable ordinary people in the art to better understand the technical solutions of the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings.

[0029] It should be noted that the terms "first," "second," and the like in the specification and claims of this application and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or precedence. It should be understood that the terms used in this manner are interchangeable where appropriate so that the embodiments of the application described herein can be implemented in an order other than those illustrated or described herein. The implementations described in the following exemplary embodiments do not represent all implementations consistent with the present application. Instead, they are merely examples of apparatus and methods consistent with certain aspects of the present application, as detailed in the appended claims.

[0030] In addition, in the description of the embodiments of this application, unless otherwise specified, " / " means or. For example, A / B can mean A or B. "And / or" in this article is simply a description of the association relationship between related objects, indicating that three relationships can exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone. In addition, in the description of the embodiments of this application, "plurality" means two or more than two.

[0031] Before explaining the embodiments of the present application in detail, some relevant terms and related technologies involved in the embodiments of the present application are first introduced.

[0032] As a core technology driving the digital transformation of the manufacturing industry, the Industrial Internet is crucial for ensuring data security and system stability. Its security system directly impacts production efficiency and economic benefits. Within the Industrial Internet, dynamic key management is a critical component of ensuring communication security. The key generation, distribution, and isolation mechanisms determine the system's ability to resist attacks.

[0033] However, existing key management methods mostly rely on static or periodically updated key generation strategies, making them incapable of coping with high-frequency and complex network attacks and prone to key prediction or cracking. Furthermore, existing methods lack the ability to monitor key usage frequency and distribution, and lack dynamic mechanisms for adjusting security attributes, making them difficult to adapt to the complex multi-node, heterogeneous device environment of the Industrial Internet.

[0034] These limitations make key management inadequate in scenarios with high real-time requirements and diverse attack vectors. The core challenge of key management in the Industrial Internet lies in achieving efficient isolation and optimized security properties of keys in a dynamic environment.

[0035] Specifically, insufficient real-time monitoring of key usage frequency prevents the timely detection of unusual usage patterns. The lack of a dynamic adjustment mechanism for key distribution makes key permutations easily predictable by attackers. Furthermore, a lack of comprehensive management of multi-dimensional security attributes makes it difficult to enhance the randomness and unpredictability of keys through flexible matrix transformations. These unresolved technical issues make key management difficult to address with sophisticated attacks, increasing the risk of system intrusion.

[0036] In view of the above problems, an embodiment of the present application provides a dynamic key automatic isolation method for the industrial Internet, which can monitor the frequency and distribution of key usage in real time, dynamically adjust security attributes through a multi-dimensional key matrix, and use a matrix transformation algorithm to optimize the key arrangement order to improve the security of the key system.

[0037] The following describes in detail the dynamic key automatic isolation method for the industrial Internet provided by the embodiment of the present application in conjunction with the accompanying drawings.

[0038] The dynamic key automatic isolation method for the industrial Internet provided in the embodiment of the present application can be applied to network security systems. Figure 1 FIG. 1 shows a schematic diagram of the structure of the network security system. Figure 1 As shown, the network security system 10 includes a dynamic key automatic isolation device 11 and multiple network nodes 12. The network nodes 12 are connected to each other using a wired or wireless method. The dynamic key automatic isolation device 11 and the multiple network nodes 12 are connected to each other using a wired or wireless method. Specifically, the dynamic key automatic isolation device 11 can be connected to multiple network nodes separately or to a single network node, which is not limited in this embodiment of the present application.

[0039] The dynamic key automatic isolation device 11 can be any electronic device with data processing capabilities. For example, the dynamic key automatic isolation device 11 can be a server, a computer, or a server cluster consisting of multiple servers. In some embodiments, the server cluster can also be a distributed cluster. Optionally, the server can be a central server, and the server can also be implemented on a cloud platform. For example, the cloud platform can include a private cloud, a public cloud, a hybrid cloud, a community cloud, a distributed cloud, an inter-cloud, a multi-cloud, etc., or any combination thereof. The embodiments of the present application are not limited to this.

[0040] The execution subject of the dynamic key automatic isolation method for the industrial Internet provided in the embodiment of the present application can be the above-mentioned dynamic key automatic isolation device 11. As mentioned above, the dynamic key automatic isolation device 11 can be an electronic device with data processing capabilities such as a computer or a server. Optionally, the dynamic key automatic isolation device 11 can also be a processor (such as a central processing unit (CPU)) in the aforementioned electronic device; or, the dynamic key automatic isolation device 11 can also be an application (application, APP) with a model training function installed in the aforementioned electronic device; or, the dynamic key automatic isolation device 11 can also be a functional module with a model training function in the aforementioned electronic device, etc. The embodiment of the present application does not impose any restrictions on this.

[0041] For simplicity of description, the following description will be made by taking the dynamic key automatic isolation device 11 as an electronic device as an example.

[0042] Figure 2 This is a schematic diagram of the composition of the electronic device provided in the embodiment of the present application. Figure 2 As shown, the electronic device may include: a processor 20 , a memory 21 , a communication line 22 , a communication interface 23 , and an input / output interface 24 .

[0043] The processor 20 , the memory 21 , the communication interface 23 and the input / output interface 24 may be connected via a communication line 22 .

[0044] The processor 20 is used to execute the instructions stored in the memory 21 to implement the fault analysis method provided in the following embodiments of the present application. The processor 20 can be a CPU, a general-purpose processor network processor (NP), a digital signal processor (DSP), a microprocessor, a microcontroller (MCU), a programmable logic device (PLD), or any combination thereof. The processor 20 can also be any other device with processing functions, such as a circuit, a device, or a software module, which is not limited in the embodiments of the present application. In one example, the processor 20 can include one or more CPUs, such as Figure 2 As an optional implementation, the electronic device may include multiple processors, for example, in addition to the processor 20, it may also include a processor 25 ( Figure 2 The dashed line is shown as an example).

[0045] Memory 21 is used to store instructions. For example, the instructions can be computer programs. Optionally, the memory 21 can be a read-only memory (ROM) or other type of static storage device that can store static information and / or instructions, or a random access memory (RAM) or other type of dynamic storage device that can store information and / or instructions. It can also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM) or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), a magnetic disk storage medium, or other magnetic storage device, etc., and the embodiments of the present application are not limited to this.

[0046] It should be noted that the memory 21 may exist independently of the processor 20 or may be integrated with the processor 20. The memory 21 may be located inside the electronic device or outside the electronic device, which is not limited in the embodiment of the present application.

[0047] The communication line 22 is used to transmit information between the various components included in the electronic device.

[0048] Communication interface 23 is used to communicate with other devices or other communication networks. Such other communication networks may include Ethernet, radio access networks (RAN), wireless local area networks (WLAN), etc. Communication interface 23 may be a module, circuit, transceiver, or any other device capable of communication.

[0049] The input / output interface 24 is used to implement human-computer interaction between a user and the electronic device, for example, to implement action interaction or information interaction between the user and the electronic device.

[0050] For example, the input / output interface 24 may be a mouse, keyboard, display screen, or touch screen screen, etc. Action interaction or information interaction between a user and the electronic device may be achieved through the mouse, keyboard, display screen, or touch screen screen, etc.

[0051] It should be noted that Figure 2 The structure shown in the figure does not constitute a limitation on the electronic device, except Figure 2 In addition to the components shown, the electronic device may include more or fewer components than shown, or a combination of certain components, or a different arrangement of components.

[0052] The following introduces the dynamic key automatic isolation method for the industrial Internet provided in an embodiment of the present application.

[0053] Figure 3 The flow chart of the method for automatic isolation of dynamic keys for industrial Internet provided in the embodiment of the present application is shown. Figure 2 The electronic device of the hardware structure shown is executed as Figure 3 As shown, the method includes S301 to S304.

[0054] S301: Determine high-risk nodes in a network security system and obtain network delay data of the high-risk nodes.

[0055] Among them, the abnormal behavior score of the high-risk node is greater than the preset score.

[0056] As one possible implementation, the electronic device can obtain the key usage frequency of each node in the network security system and, using a cluster analysis algorithm, perform cluster analysis on nodes with a key usage frequency greater than a preset frequency to identify nodes with abnormal usage patterns. Furthermore, the electronic device can obtain key usage data for nodes with abnormal usage patterns and analyze this data using a behavioral analysis algorithm to obtain an abnormal behavior score. Nodes with abnormal usage patterns that have an abnormal behavior score greater than a preset value can be identified as high-risk nodes.

[0057] In one possible implementation, obtaining a node identifier and device type from a data source node is the basis for constructing a key usage frequency analysis. The node identifier is a unique number for each device, such as a device ID; the device type describes the device category, such as a server, router, or IoT device.

[0058] For example, in a smart home scenario, a node identifier could be the serial number of a smart door lock, such as SN123456, and the device type could be "smart door lock." Through the distributed data collection module, the system can collect key usage data from each node in real time. The distributed collection module utilizes multi-node parallel processing to ensure efficient data collection.

[0059] For example, the acquisition module collects key usage records from 1,000 smart door locks every second. The records contain timestamps and usage counts.

[0060] Specifically, time windowing is used to organize collection timestamps. Using a 5-minute window, the system categorizes timestamps into consecutive time periods, such as 2025-04-21 08:00:00 to 08:05:00. For example, if a smart door lock uses a key 10 times within this window, the frequency is recorded as 10 times / 5 minutes. If the timestamps in the original key usage frequency dataset are complete, i.e., without missing data, the system groups them by node identifier and device type.

[0061] For example, consider grouping all smart door lock data together and calculating their frequency mean and variance. Time series analysis methods, such as the moving average method, extract features from frequency statistics and generate a time series feature set containing features such as mean and peak.

[0062] For example, the average frequency of a group of smart door locks is 8 times / 5 minutes, and the peak is 15 times / 5 minutes.

[0063] In one embodiment, a sliding time window is used to analyze the dynamic changes in key frequency. The system calculates the frequency trend of each window with a 10-minute window and a step size of 5 minutes.

[0064] For example, if the frequency of a window increases from 8 to 12 times, it indicates increased usage intensity. The K-means algorithm clusters the feature set to identify trend patterns, such as "stable," "increasing," or "declining." Suppose the clustering results show that a certain smart door lock cluster exhibits an "increasing" pattern, indicating a continued increase in usage frequency.

[0065] Preferably, through correlation analysis, the system generates dynamic trends of key usage frequencies for each device type in different time windows.

[0066] For example, smart door locks have higher frequency at night than during the day, while the opposite is true for routers.

[0067] It should be noted that the final trend distribution results can reveal the usage patterns of the equipment.

[0068] For example, the trend distribution of smart door locks shows a peak between 6:00 PM and 10:00 PM, indicating that users frequently unlock their doors at night. This finding can be used to optimize device resource allocation, such as prioritizing bandwidth for high-frequency devices, thereby improving system response speed.

[0069] For example, the analysis can also reveal unusual patterns, such as frequent nighttime use of a door lock, which could indicate a security risk and trigger an alarm. The interplay of various implementations ensures comprehensive and reliable analysis results, contributing to efficient system operation.

[0070] Understandably, the advantages of these methods lie in their real-time nature and accuracy. Distributed data collection ensures extensive data coverage, time series analysis captures dynamic changes, K-means clustering simplifies trend identification, and association analysis uncovers relationships between devices. These technologies collectively enhance the accuracy of key usage frequency analysis, providing strong support for smart home system optimization and security management.

[0071] For example, obtaining the node identifier, device type, and packet size from the data source node forms the basis for constructing key usage frequency and packet analysis. The node identifier is the unique device number, such as the serial number SL789012 for a smart light in a smart home. The device type refers to the device category, such as "smart light." The packet size records the amount of communication data, in bytes, during each key usage.

[0072] In one possible implementation, the distributed collection module collects data from 500 smart lights per second, recording data including the node identifier SL789012, the device type "smart light," and a data packet size of, for example, 512 bytes. This collection method ensures comprehensive data coverage of the device network.

[0073] Specifically, time windowing is used to organize collection timestamps. Using a 10-minute time window, the system categorizes timestamps into consecutive time periods, such as 2025-04-21 09:00:00 to 09:10:00. Assuming a smart light uses a key eight times within this window, with an average data packet size of 600 bytes, this data is recorded as a frequency of 8 times / 10 minutes, with a data packet size of 600 bytes / time. If the timestamps in the original key usage frequency dataset are complete and not missing, the system groups them by node identifier and device type to generate a dataset for the smart light.

[0074] In one embodiment, a preset threshold determination method is used to detect abnormal frequency statistics. Assuming the normal frequency range for smart lights is 5 to 10 times / 10 minutes, the system sets a threshold of 12 times / 10 minutes. If a smart light's frequency reaches 15 times / 10 minutes, it is marked as an abnormal node and included in the abnormal frequency node set.

[0075] Preferably, thresholds are set based on historical data analysis to ensure a low false positive rate. This approach can quickly screen out potentially abnormal devices.

[0076] It should be noted that the set of abnormal frequency nodes provides input for subsequent cluster analysis. The K-means algorithm clusters the frequency statistics and packet sizes of abnormal nodes to identify abnormal usage patterns.

[0077] For example, the system analyzes 100 anomalous smart lights, characterized by a frequency of 15 times per 10 minutes and a packet size of 800 bytes. K-means classifies the data into two categories: one with high frequency but small packets, likely indicating frequent switching of lights; the other with high frequency and large packets, likely indicating anomalous communication. The result generates a set of node identifiers for anomalous usage patterns, such as SL789012 and SL789013.

[0078] Understandably, cluster analysis helps segment abnormal behavior.

[0079] For example, a pattern of frequent light on and off might be due to user habits, while anomalous communication could indicate a device attack. By using a collection of node identifiers, the system can pinpoint specific devices and trigger further inspection. This approach improves the accuracy of anomaly detection and supports smart home network optimization.

[0080] For example, a smart light SL789012 transmitted 900-byte packets 15 times within 10 minutes. Clustering results indicate an abnormal communication pattern. Based on this information, the system can prioritize monitoring of this device to ensure network security. In another embodiment, combined with device type analysis, the system discovered that the abnormal pattern of smart lights often occurs at night, possibly due to increased external interference. This analysis provides a granular basis for device management.

[0081] For example, when obtaining key usage data for abnormal nodes from a set of node identifiers, the node behavior logs can be collected through a distributed log collection system. Assume that in an IoT device network, devices with node identifiers N1, N2, and N3 are marked as abnormal. The data collection tool extracts the key call timestamps, call frequencies, and associated operation types, such as encryption or decryption requests, for these nodes. In one possible implementation, the tool aggregates the logs by minute, generating a behavioral pattern dataset containing call counts and operation types.

[0082] For example, the N1 node called the key 100 times within 5 minutes, 80 of which were encryption requests, which is significantly higher than the average of 20 calls for normal nodes.

[0083] Specifically, when the behavior analysis algorithm generates a feature vector, it can construct multidimensional features based on time series and operation types.

[0084] It's important to note that feature vectors may include dimensions such as call frequency, operation type ratio, and time distribution uniformity. For example, for node N1, its feature vector might be [100, 0.8, 0.2], representing the number of calls, the ratio of encryption operations, and time distribution uniformity, respectively. The algorithm uses principal component analysis or feature selection techniques to retain key dimensions to reduce computational complexity. This approach clearly characterizes the node's behavior, facilitating subsequent matching.

[0085] In one embodiment, a cosine similarity algorithm is used to quantify the degree of anomaly when performing feature matching with a pre-established matching template. The matching template can be a baseline vector generated based on historically normal node behavior, such as [20, 0.5, 0.9]. By calculating the cosine similarity between N1's feature vector and the template, a similarity score is obtained. For example, 0.3 indicates a deviation from normal behavior.

[0086] Preferably, the anomaly score combines the similarity score with contextual factors, such as device type or network traffic spikes, to further refine the score.

[0087] For example, N1 is a high-load device and its score may be adjusted to 0.4 to reflect the device characteristics.

[0088] For example, when the anomaly score exceeds a preset threshold (such as 0.5), the logistic regression algorithm generates a classification label for potential attack threats. The logistic regression model is trained based on historically labeled data, with input features including anomaly score, call frequency, and operation type ratio. For example, node N1 has an anomaly score of 0.4, which does not exceed the threshold, and the model might output a "non-threat" label. However, for node N2, which has a score of 0.6, the model might output a "potential threat" label.

[0089] Understandably, the classification results are combined with the device context. For example, if N2 is a critical server with a higher priority, the classification label will trigger an alert. This approach ensures accurate and targeted threat identification.

[0090] In one possible implementation, the above process can be extended to dynamic threshold adjustment. For example, if network traffic surges, the call frequency of a healthy node might rise to 50 times. The system would then update the threshold and template based on real-time traffic to avoid misjudgments. This extended solution improves robustness through adaptive mechanisms.

[0091] It's important to note that the implementation of all technical topics revolves around the core goal of abnormal node detection, supporting each other and ensuring logical consistency from data collection to threat classification. The detailed design of each step helps improve the efficiency and accuracy of identifying abnormal behavior, providing a reliable basis for network security analysis.

[0092] S302: Based on the network delay data, adjust the key distribution priority of the high-risk node to obtain an adjusted key distribution priority.

[0093] Among them, the adjusted key distribution priority is negatively correlated with the network delay data.

[0094] As a possible implementation method, if the network delay data is greater than or equal to a preset threshold, the electronic device will reduce the key distribution priority of the high-risk node according to the preset coefficient to obtain the adjusted key distribution priority; if the network delay data is less than the preset threshold, the electronic device will increase the key distribution priority of the high-risk node according to the preset coefficient to obtain the adjusted key distribution priority.

[0095] Specifically, assuming that high-risk nodes have been marked in the network security system and the node identifiers and threat levels are stored in the database, a SQL query statement can be used to filter out node identifiers with threat levels above a certain threshold to generate a list of high-risk nodes.

[0096] For example, a network contains 1,000 nodes, and a query finds 10 nodes marked as high risk, with identifiers N001 to N010. These identifiers will serve as the basis for subsequent analysis.

[0097] It should be noted that database query tools need to ensure efficient indexing to support fast retrieval of large-scale node data.

[0098] In one possible implementation, communication protocol and network delay data of high-risk nodes are obtained, and real-time transmission data can be collected through network monitoring tools.

[0099] For example, use Wireshark or a custom monitoring tool to capture TCP / IP packets between nodes and extract the communication protocol type, such as HTTP or HTTPS, as well as network latency. Assume that the latency of node N001 is 200 milliseconds, significantly higher than the average of 50 milliseconds, indicating a possible anomaly. After collecting this data, you can determine the node's communication characteristics, such as protocol frequency and latency distribution.

[0100] Preferably, the monitoring tool needs to support real-time and high concurrency to cope with large-scale network traffic.

[0101] Specifically, a randomized allocation algorithm is used to adjust the key arrangement based on the node communication characteristics. The randomized allocation algorithm can rearrange the key priorities by generating a pseudo-random sequence.

[0102] For example, the algorithm lowers the key distribution priority for node N001, which has high latency, and prioritizes key distribution to nodes with latency below 50 milliseconds, such as N002. Suppose the original key sequence is K1, K2, K3, but after adjustment it becomes K2, K1, K3, with K2 assigned to the low-latency node. This adjustment ensures that key distribution favors nodes with stable performance.

[0103] It is understandable that random allocation needs to balance fairness and efficiency to avoid excessive bias towards certain nodes.

[0104] For example, using the adjusted key permutation, a distributed storage tool can be used to update the key distribution scheme. Distributed storage tools like Hadoop or Redis can store key sequences on high-risk nodes. Assuming that the new key sequence is assigned to N001 through N010, the Redis cluster uses key-value pairs to store the keys, ensuring fast access.

[0105] In one embodiment, after the keys are distributed, the system verifies the key update status of each node to ensure that no key is missed.

[0106] It should be noted that distributed storage needs to ensure data consistency and high availability to prevent key distribution interruptions.

[0107] In one embodiment, the above solution forms a complete process from high-risk node identification to key distribution optimization.

[0108] For example, database queries ensure accurate location of high-risk nodes, network monitoring provides real-time data support, randomized key allocation optimizes key usage efficiency, and distributed storage ensures reliable distribution. These steps support each other and collectively enhance the protection capabilities of the network security system.

[0109] Preferably, the entire process can be automated to reduce manual intervention and improve response speed.

[0110] S303: Reconstruct the key arrangement sequence of the high-risk node using a matrix transformation algorithm to obtain a new key.

[0111] One possible implementation involves acquiring multidimensional security attribute data, collecting operational status and packet size through sensors and network monitoring tools, and formatting the collected data using standardized protocols to produce a structured dataset. A matrix transformation algorithm is then used to perform multidimensional reconstruction of the key permutation. The structured dataset is then combined with a preset transformation matrix through matrix multiplication to generate a multidimensionally reconstructed key permutation sequence. If the randomness of the reconstructed multidimensional key permutation sequence falls below a preset threshold, the sequence is matrix-decomposed using a singular value decomposition algorithm. The decomposed eigenvectors are then recombined to produce a key permutation sequence with enhanced randomness. This enhanced key permutation sequence is then matched against the original key distribution scheme using a sequence alignment tool, and the key distribution parameters are updated to generate an optimized key permutation sequence.

[0112] For example, sensors and network monitoring tools can be used to collect multi-dimensional security attribute data, including real-time acquisition of operational status and packet size. Operational status can include CPU usage and memory usage of nodes, while packet size reflects communication traffic characteristics.

[0113] In one possible implementation, sensors are deployed on network nodes to collect their operational status. For example, if a node's CPU utilization is 80%, far exceeding the average of 50%, this could indicate an anomaly. Network monitoring tools such as NetFlow analyzers capture packet sizes. For example, if the average packet size for a node is 1500 bytes, 500 bytes above the normal range, this data is formatted using a standardized protocol such as JSON to generate a structured dataset, ensuring consistency and compatibility.

[0114] Specifically, a matrix transformation algorithm is used to perform multidimensional reconstruction of the key arrangement. This algorithm combines a structured data set with a preset transformation matrix through matrix multiplication to generate a new key sequence. Assuming the original key sequence is K1, K2, and K3, and the data set includes CPU usage and packet size, the transformation matrix is ​​weighted according to the security policy.

[0115] In one embodiment, matrix multiplication reduces the priority of the node keys with high CPU usage, generating a multi-dimensional reconstruction sequence, such as K2, K3, and K1. This reconstruction enhances the flexibility of key distribution.

[0116] It should be noted that if the randomness of the multidimensional reconstructed sequence falls below a threshold, the singular value decomposition algorithm is used for optimization. The randomness threshold can be set to an entropy value of 0.8. If the sequence entropy is only 0.6, processing is required. Singular value decomposition decomposes the sequence into eigenvectors, which are then recombined to generate a new sequence.

[0117] For example, after decomposition, the main eigenvectors are extracted and K2, K3, and K1 are adjusted to K3, K1, and K2, which increases the entropy to 0.85. This method ensures the unpredictability of the sequence.

[0118] Preferably, based on the enhanced randomness of the sequence, a sequence alignment tool is used to update the key distribution parameters. Sequence alignment tools, such as BLAST-inspired algorithms, compare the new sequence with the original distribution scheme. Assuming the original scheme prioritized low-load nodes, the new sequence takes packet size into account. After comparison, the parameters are updated to favor nodes with stable packet sizes, such as nodes with packet size fluctuations of less than 10%. This ultimately generates an optimized key permutation sequence, improving distribution efficiency.

[0119] In one embodiment, the above process forms a closed loop from data collection to key optimization. Sensors and monitoring tools provide diverse data, standardized protocols ensure data availability, matrix transformation and singular value decomposition improve sequence quality, and sequence alignment ensures accurate updates. These links support each other and jointly optimize the adaptability of key distribution.

[0120] S304: Based on the adjusted key allocation priority and the new key, provide security services for high-risk nodes.

[0121] As a possible implementation method, the electronic device can issue new keys to high-risk nodes according to the adjusted key distribution priority, thereby providing security services for the high-risk nodes.

[0122] In some embodiments, the electronic device can also extract key features of the new key; these key features reflect the sparsity and uniformity of the new key. Furthermore, the electronic device can input these key features into a trained isolation efficiency evaluation model to quantitatively analyze the key isolation effectiveness of the new key and obtain an isolation coefficient. Based on the isolation coefficient and the historical attack success rate, the electronic device determines a quantitative score for the isolation efficiency of the new key; the attack success rate is negatively correlated with the isolation coefficient.

[0123] As a possible implementation method, isolation parameters are obtained from the optimized key permutation sequence. A parameter extraction algorithm is used to analyze the key distribution characteristics in the key permutation sequence. The characteristics of the permutation position and interval distance of each key are quantified to obtain an isolation parameter set. Based on the isolation parameter set, an isolation efficiency evaluation algorithm is used to calculate the isolation coefficient. The isolation coefficient is determined by weighted calculation of the distribution uniformity of each key interval in the isolation parameter set. If the isolation coefficient is higher than a preset threshold, the attack success rate data is obtained from historical records. A data comparison method is used to perform a correlation analysis between the isolation coefficient and the attack success rate to obtain a quantitative score. The quantitative score is compared with the pre-established scoring standard, and a record analysis method is used to verify the consistency of the quantitative score with the score distribution in the historical records to determine the final quantitative score of the key isolation efficiency.

[0124] For example, the process of obtaining isolation parameters from an optimized key permutation sequence aims to extract key features from the key distribution to ensure isolation between keys. The isolation parameters reflect the positional distribution and spacing characteristics of the keys in the sequence. In one possible implementation, a parameter extraction algorithm can be used to generate a feature vector based on the key position and the spacing between adjacent keys. Assume a key sequence contains 10 keys with a position distribution of [1, 3, 6, 10, 15, 22, 30, 40, 52, 66], and the extracted spacing is [2, 3, 4, 5, 7, 8, 10, 12, 14]. These parameters are quantized to form an isolation parameter set that describes the sparsity and uniformity of the key distribution.

[0125] Specifically, the isolation efficiency evaluation algorithm calculates the isolation coefficient by analyzing the isolation parameter set to measure the uniformity of the key distribution.

[0126] In one embodiment, the algorithm weights the variance and mean of the separation distances. Assuming the mean of the separation distances is 7.2 and the variance is 15, with weights of 0.6 and 0.4, respectively, the isolation coefficient can be calculated to reflect the uniformity of the distribution. If the coefficient is above a preset threshold, such as 0.85, it indicates that the key distribution has good isolation.

[0127] It should be noted that the calculation of the isolation coefficient takes into account the global characteristics of the distribution to avoid safety hazards caused by local density.

[0128] Preferably, when the isolation coefficient meets the threshold requirement, attack success rate data is extracted from historical records to further verify the isolation effect.

[0129] For example, historical data shows that attack success rates are negatively correlated with key spacing uniformity. Evenly spaced sequences have an attack success rate of less than 5%, while densely spaced sequences can have an attack success rate as high as 20%. By comparing data, we analyze the correlation between the isolation coefficient and attack success rate and generate a quantitative score. Assuming an isolation coefficient of 0.9 and an attack success rate of 3%, the comparative analysis yields a quantitative score of 92, indicating high isolation efficiency.

[0130] It is understandable that the quantitative scores need to be compared with the preset scoring criteria to ensure consistency.

[0131] In one possible implementation, the scoring criteria stipulate that scores above 90 are excellent and scores between 80 and 90 are good. The record analysis method further verifies the stability of the score distribution.

[0132] For example, historical scores are concentrated in the range of 85-95, and the current score is 92, which conforms to the distribution pattern and indicates that the key isolation efficiency is stable. In another embodiment, if the score deviates from the historical distribution, for example, below 80 points, parameter adjustment may be triggered to re-optimize the key sequence.

[0133] For example, the final quantitative score for key isolation efficiency can be verified in multiple dimensions to ensure reliability.

[0134] In one embodiment, in addition to the attack success rate, the key collision probability can be introduced as a secondary indicator. Assuming the collision probability is less than 0.01%, combined with an isolation coefficient of 0.9 and a score of 92, these multiple indicators jointly support the superiority of isolation efficiency. This multi-faceted analysis ensures a comprehensive and accurate assessment and provides a reliable basis for key distribution optimization.

[0135] In some embodiments, the electronic device may also obtain operational status data of high-risk nodes; the operational status data may include CPU usage and memory occupancy. Furthermore, the electronic device weights the CPU usage, memory usage, and network latency data and determines a quantitative score for the isolation efficiency of the new key based on the weighted result.

[0136] As a possible implementation approach, operating status and network latency data are collected from heterogeneous devices. Data collection tools are used to monitor the devices in real time. These data are synchronized using timestamps to generate a device operating dataset. Based on this dataset, a quantitative scoring algorithm is used to calculate key isolation efficiency. If the operating status is stable and the network latency is below a preset threshold, the scoring weight is increased. The quantitative scoring result is calculated using the scoring formula S=w1R+w2(1 / L), where S is the score, R is the operating status value, L is the network latency, and w1 and w2 are the weights. Based on the quantitative scoring results, a device adaptation algorithm is used to fine-tune the key distribution strategy. A K-means clustering algorithm is used to group devices by type and frequency statistics to determine key distribution priorities. Based on the key distribution priorities, a type matching analysis tool is used to match device types with frequency statistics. If the matching degree exceeds a preset threshold, a key management solution adapted for heterogeneous environments is generated, resulting in the final key management solution.

[0137] For example, the process of acquiring operational status and network latency data from heterogeneous devices aims to provide real-time insights into device performance and provide a data foundation for evaluating key isolation efficiency. Operational status reflects device stability, such as CPU utilization and memory usage; network latency measures data transmission efficiency. In one possible implementation, a data collection tool periodically collects operational status and latency data using built-in sensors and network probes on the devices.

[0138] For example, if the collection period is 1 second and the operating status of a device shows 20% CPU usage, 30% memory usage, and 10 milliseconds network latency, timestamp synchronization ensures data alignment, forming a device operation dataset that includes time, status, and latency.

[0139] Specifically, a quantitative scoring algorithm evaluates key isolation efficiency based on device operation datasets. The scoring weight is increased when the operating status is stable (for example, CPU usage fluctuation is less than 5%) and network latency is below a threshold (for example, 50 milliseconds).

[0140] For example, if the operating status value R of a device is 0.9 (after normalization), the delay L is 10 milliseconds, the weights w1 and w2 are 0.6 and 0.4, the scoring formula calculates a higher score, reflecting the superior key isolation efficiency.

[0141] It should be noted that the scoring formula takes into account device performance and network conditions to ensure a comprehensive evaluation.

[0142] In one embodiment, the device adaptation algorithm fine-tunes the key distribution strategy based on the quantitative score. The K-means clustering algorithm groups devices by type (e.g., server, mobile device) and frequency statistics (e.g., data request frequency).

[0143] For example, 100 devices can be divided into three groups: high-frequency servers, medium-frequency workstations, and low-frequency mobile devices. After grouping, key distribution priorities are determined, with sparse keys being allocated preferentially to high-frequency devices to improve security.

[0144] Preferably, the priority sorting is based on device type and frequency of use to ensure the rationality of key distribution.

[0145] It is understood that the type matching analysis tool further optimizes the key management solution by comparing device types and frequency statistics to calculate the matching degree.

[0146] For example, a server with a frequency of 100 times per second and a high-performance computing type has a 90% match, exceeding the 80% threshold. Devices with a high match generate an adaptive key management solution, such as dynamically updating keys for high-frequency servers to reduce the risk of intensive key allocation.

[0147] In one embodiment, the final key management scheme includes device grouping, priority, and matching results, forming an efficient key management strategy in a heterogeneous environment.

[0148] For example, low-frequency mobile devices use static keys, while high-frequency servers use periodically updated dynamic keys, taking into account both security and efficiency.

[0149] The technical solution provided by the embodiment of the present application brings at least the following beneficial effects: the frequency of node key usage is collected in real time through distributed data collection, and dynamic change trends are extracted using time series analysis. In response to abnormal usage patterns, the present application uses clustering analysis and behavioral analysis algorithms to identify potential attack threats and reallocate keys to high-risk nodes. The key arrangement is multi-dimensionally reconstructed through a matrix transformation algorithm to enhance randomness. The present invention also uses an isolation efficiency evaluation algorithm to quantitatively analyze the key isolation effect, and fine-tune the key distribution strategy according to the status of heterogeneous devices. This method can effectively improve the security and adaptability of key management in the industrial Internet environment, reduce potential attack threats, optimize key distribution, and achieve flexible adaptation to heterogeneous devices.

[0150] The above mainly introduces the solution provided by the embodiment of the present application from the perspective of the method. In order to realize the above functions, it includes hardware structures and / or software modules corresponding to the execution of each function. It should be easy to realize that the technical goals in this field are combined with the units and algorithm steps of each example described in the embodiments disclosed herein, and the present application can be implemented in the form of hardware or a combination of hardware and computer software. Whether a function is executed in the form of hardware or computer software driving hardware depends on the specific application and design constraints of the technical solution. Professional technical goals can use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0151] In an exemplary embodiment, the present application also provides a dynamic key automatic isolation device. Figure 4 This is a schematic diagram of the composition of the dynamic key automatic isolation device provided in the embodiment of the present application. Figure 4 As shown, the dynamic key automatic isolation device includes: a determination unit 401 and a processing unit 402.

[0152] Determination unit 401 is used to determine high-risk nodes in the network security system and obtain network delay data of the high-risk nodes; the abnormal behavior score of the high-risk node is greater than the preset score; processing unit 402 is used to adjust the key distribution priority of the high-risk node based on the network delay data to obtain an adjusted key distribution priority; the adjusted key distribution priority is negatively correlated with the network delay data; processing unit 402 is also used to use a matrix transformation algorithm to reconstruct the key arrangement order of the high-risk node to obtain a new key; processing unit 402 is also used to provide security services for the high-risk node based on the adjusted key distribution priority and the new key.

[0153] In one possible implementation, the determination unit 401 is specifically used to: obtain the key usage frequency of each node in the network security system, and perform cluster analysis on the nodes whose key usage frequency is greater than the preset frequency through a cluster analysis algorithm to determine the abnormal usage pattern nodes; obtain the key usage data of the abnormal usage pattern nodes, analyze the key usage data through a behavior analysis algorithm to obtain an abnormal behavior score, and determine the abnormal usage pattern nodes whose abnormal behavior score is greater than the preset score as high-risk nodes.

[0154] In one possible implementation, the processing unit 402 is specifically used to: if the network delay data is greater than or equal to a preset threshold, then reduce the key allocation priority of the high-risk node according to a preset coefficient to obtain an adjusted key allocation priority; if the network delay data is less than the preset threshold, then increase the key allocation priority of the high-risk node according to the preset coefficient to obtain an adjusted key allocation priority.

[0155] It should be noted that Figure 4 The module division described is illustrative and represents only one logical functional division. Actual implementations may employ different divisions. For example, two or more functions may be integrated into a single processing module. These integrated modules may be implemented as either hardware or software functional units.

[0156] In an exemplary embodiment, the present application also provides a computer-readable storage medium including software instructions, which, when executed on an electronic device, enables the electronic device to execute any one of the methods provided in the above embodiments.

[0157] In an exemplary embodiment, the present application also provides a computer program product including computer-executable instructions, which, when executed on an electronic device, enables the electronic device to execute any one of the methods provided in the above embodiments.

[0158] The above embodiments can be implemented in whole or in part through software, hardware, firmware, or any combination thereof. When implemented using a software program, they can be implemented in whole or in part in the form of a computer program product. This computer program product includes one or more computer-executable instructions. When the computer-executable instructions are loaded and executed on a computer, the processes or functions according to the embodiments of the present application are fully or partially generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer-executable instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer-executable instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server or data center that includes one or more available media. Available media can include magnetic media (e.g., floppy disks, hard disks, tapes), optical media (e.g., DVDs), or solid-state drives (SSDs).

[0159] Although the present application is described herein in conjunction with various embodiments, in the process of implementing the claimed application, those skilled in the art may understand and implement other variations of the disclosed embodiments by reviewing the drawings, the disclosure, and the appended claims. In the claims, the word "comprising" does not exclude other components or steps, and "a" or "an" does not exclude multiple situations. A single processor or other unit may implement several functions listed in the claims. Certain measures are recorded in different dependent claims, but this does not mean that these measures cannot be combined to produce good results.

[0160] Although the present application has been described with reference to specific features and embodiments thereof, it is apparent that various modifications and combinations may be made thereto without departing from the spirit and scope of the present application. Accordingly, this specification and the drawings are merely illustrative of the present application as defined by the appended claims and are deemed to cover any and all modifications, variations, combinations or equivalents within the scope of the present application. Obviously, those skilled in the art may make various modifications and variations to the present application without departing from the spirit and scope of the present application. Thus, the present application is intended to include such modifications and variations as fall within the scope of the claims of the present application and their equivalents.

[0161] The above is only a specific embodiment of the present application, but the scope of protection of the present application is not limited thereto. Any changes or replacements within the technical scope disclosed in the present application should be included in the scope of protection of the present application. Therefore, the scope of protection of the present application should be based on the scope of protection of the claims.

Claims

1. A method for automatic isolation of dynamic keys for industrial Internet, characterized in that: The method comprises: Identifying high-risk nodes in a network security system and obtaining network delay data of the high-risk nodes; the abnormal behavior score of the high-risk nodes is greater than a preset score; Based on the network delay data, adjusting the key distribution priority of the high-risk node to obtain an adjusted key distribution priority; wherein the adjusted key distribution priority is negatively correlated with the network delay data; Reconstructing the key arrangement order of the high-risk node using a matrix transformation algorithm to obtain a new key; providing security services for the high-risk node based on the adjusted key distribution priority and the new key; Wherein, determining high-risk nodes in the network security system includes: Obtaining the key usage frequency of each node in the network security system, and performing cluster analysis on nodes whose key usage frequency is greater than a preset frequency using a cluster analysis algorithm to determine nodes with abnormal usage patterns; Obtaining key usage data of the abnormal usage pattern node, analyzing the key usage data using a behavior analysis algorithm to obtain an abnormal behavior score, and determining an abnormal usage pattern node with an abnormal behavior score greater than a preset score as a high-risk node; The method further comprises: Extracting key features of the new key; the key features are used to reflect the sparsity and uniformity of the new key; Inputting the key features into a trained isolation efficiency evaluation model to quantitatively analyze the key isolation effect of the new key to obtain an isolation coefficient; A quantitative score of the isolation efficiency of the new key is determined based on the isolation coefficient and the attack success rate in the historical records; the attack success rate is negatively correlated with the isolation coefficient.

2. The method according to claim 1, characterized in that The step of adjusting the key distribution priority of the high-risk node based on the network delay data to obtain an adjusted key distribution priority includes: If the network delay data is greater than or equal to a preset threshold, the key distribution priority of the high-risk node is reduced according to a preset coefficient to obtain an adjusted key distribution priority; If the network delay data is less than the preset threshold, the key distribution priority of the high-risk node is increased according to the preset coefficient to obtain an adjusted key distribution priority.

3. The method according to claim 1, characterized in that The method further comprises: Obtaining the operating status data of the high-risk node; the operating status data includes the CPU usage rate and the memory occupancy rate; The central processing unit usage rate, the memory occupancy rate and the network delay data are weighted, and a quantitative score of the isolation efficiency of the new key is determined according to the weighted result.

4. A dynamic key automatic isolation system for industrial Internet, characterized in that: Used to implement the method according to any one of claims 1 to 3, the dynamic key automatic isolation system includes a dynamic key automatic isolation device, and the device includes a determination unit and a processing unit; The determining unit is configured to determine a high-risk node in the network security system and obtain network delay data of the high-risk node; the abnormal behavior score of the high-risk node is greater than a preset score; The processing unit is configured to adjust the key distribution priority of the high-risk node based on the network delay data to obtain an adjusted key distribution priority; wherein the adjusted key distribution priority is negatively correlated with the network delay data; The processing unit is further configured to reconstruct the key arrangement sequence of the high-risk node using a matrix transformation algorithm to obtain a new key; The processing unit is further configured to provide security services for the high-risk node based on the adjusted key allocation priority and the new key.

5. The system according to claim 4, characterized in that The determining unit is specifically configured to: Obtaining the key usage frequency of each node in the network security system, and performing cluster analysis on nodes whose key usage frequency is greater than a preset frequency using a cluster analysis algorithm to determine nodes with abnormal usage patterns; Obtain key usage data of the abnormal usage pattern node, analyze the key usage data using a behavior analysis algorithm to obtain an abnormal behavior score, and determine the abnormal usage pattern node with an abnormal behavior score greater than a preset score as a high-risk node.

6. The system according to claim 4, characterized in that The processing unit is specifically configured to: If the network delay data is greater than or equal to a preset threshold, the key distribution priority of the high-risk node is reduced according to a preset coefficient to obtain an adjusted key distribution priority; If the network delay data is less than the preset threshold, the key distribution priority of the high-risk node is increased according to the preset coefficient to obtain an adjusted key distribution priority.

7. An electronic device, characterized in that: include: processor and memory; The memory stores instructions executable by the processor; When the processor is configured to execute the instructions, the electronic device implements the method according to any one of claims 1 to 3.

8. A computer-readable storage medium, characterized in that The readable storage medium includes: software instructions; When the software instructions are executed in an electronic device, the electronic device is enabled to implement the method according to any one of claims 1 to 3.

Citation Information

Patent Citations

  • Network security risk assessment method and device based on artificial intelligence, and medium

    CN119788345A

  • Computer network big data security protection method and system

    CN119892504A