Dynamic multi-file service storage access control method based on aging URL (Uniform Resource Locator)

Through a dynamic multi-file service storage access control method based on time-sensitive URLs, long short-term memory neural networks and multi-level heterogeneous consensus mechanisms are used to dynamically adjust access rights and token duration, solving the security and performance bottlenecks of traditional URL access control and achieving efficient and secure access control.

CN120671165AInactive Publication Date: 2025-09-19BEIJING LEYU ZHIXIN TECHNOLOGY SERVICE CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510846489.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-24
Publication Date
2025-09-19
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Traditional static URL access control mechanisms lack timeliness management, are unable to identify abnormal access behavior, and have difficulty balancing security and system performance in large-scale distributed storage environments, posing security risks and efficiency bottlenecks.

Method used

A dynamic multi-file service storage access control method based on time-sensitive URLs is adopted. The user access behavior is analyzed through a long short-term memory neural network to generate a time series feature vector. Combined with a dynamic time warping algorithm and a multi-level heterogeneous consensus mechanism, access rights and token validity periods are dynamically adjusted to achieve cross-shard asynchronous messaging and fault-tolerant protocol verification.

Benefits of technology

It improves the accuracy and personalization of access control, enhances the security and throughput of the system, improves the ability to identify abnormal access behavior and resist attacks, while ensuring the decentralization and immutability of access control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120671165A_ABST
    Figure CN120671165A_ABST
Patent Text Reader

Abstract

The invention provides a dynamic multi-file service storage access control method based on an aging URL (Uniform Resource Locator), which relates to the technical field of file storage control, and comprises the following steps: receiving a URL access request, extracting a user access time point and a duration sequence, and inputting a long-short-term memory neural network to generate a behavior time sequence feature vector; and calculating a time sequence distance value by utilizing a dynamic time warping algorithm, determining an access permission level and a URL effective duration, constructing a temporary access token, and verifying by adopting a multi-level heterogeneous consensus mechanism. According to the method, illegal access can be effectively prevented, the data security is improved, and refined authority control is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to a file storage control technology, in particular to a dynamic multi-file service storage access control method based on time-sensitive URLs. Background Art

[0002] With the rapid development of cloud computing and distributed storage technologies, multi-file service storage systems have become widely used in various internet services. Traditional file access control relies primarily on static URLs and fixed permission policies. Users access target file resources by obtaining specific URLs. This access control method is simple, straightforward, and easy to implement, making it widely used in early file sharing and storage systems.

[0003] However, with the increasing threat of cybersecurity threats, particularly the escalating attacks against file storage systems, traditional static URL access control mechanisms are no longer able to meet the security and flexibility requirements of modern information systems. This is especially true when it comes to granular permission management, preventing unauthorized access, and addressing complex and ever-changing access scenarios.

[0004] Traditional URL access control mechanisms lack timeliness management. Once a URL is leaked, unauthorized users can hold and access sensitive resources for a long time. The URL's validity period cannot be dynamically adjusted based on the user's actual access behavior and needs, causing the system to face continuous security risks.

[0005] Existing technologies cannot effectively identify abnormal access behavior patterns, lack the ability to perform time series analysis based on users' historical access behavior, and find it difficult to distinguish between normal access and potential malicious requests, making the system vulnerable to security threats such as account theft and URL hijacking.

[0006] Existing access control verification mechanisms usually adopt a single centralized architecture and lack multi-level heterogeneous consensus verification capabilities. When faced with large-scale distributed storage environments, it is difficult to balance security and system performance, especially when processing high-concurrency, cross-domain access requests. There are obvious efficiency bottlenecks and security risks. Summary of the Invention

[0007] The embodiment of the present invention provides a dynamic multi-file service storage access control method based on time-sensitive URLs, which can solve the problems in the prior art.

[0008] A first aspect of an embodiment of the present invention provides a method for controlling storage access to dynamic multi-file services based on time-sensitive URLs, comprising:

[0009] Receive a URL access request sent by a user terminal, the URL access request carrying user identity information and target file access identification information, and generate an access request identifier;

[0010] Obtaining historical URL access records of the user terminal based on the user identity information query, extracting an access time sequence and an access duration sequence from the historical URL access records, and associating the access time sequence and the access duration sequence with the access request identifier;

[0011] Inputting the access time point sequence and the access duration sequence into a pre-trained long short-term memory neural network to generate a user access behavior temporal feature vector; based on the user access behavior temporal feature vector, using a dynamic time warping algorithm to calculate the temporal distance value between the URL access request and a preset normal access pattern, and determining the access permission level corresponding to the access request identifier and the dynamic URL validity period based on the temporal distance value;

[0012] A temporary access token is constructed according to the validity period of the dynamic URL and the access permission level, and a multi-level heterogeneous consensus mechanism is used to verify the temporary access token. Consensus shards are generated based on verifiable random functions at the data layer, asynchronous message transmission across shards is implemented at the network layer, and a practical Byzantine fault tolerance protocol and proof-of-stake mechanism are integrated at the consensus layer to dynamically adjust the consensus weight.

[0013] Inputting the access time point sequence and the access duration sequence into a pre-trained long short-term memory neural network to generate a user access behavior time series feature vector; and calculating the time series distance between the URL access request and a preset normal access pattern using a dynamic time warping algorithm based on the user access behavior time series feature vector includes:

[0014] Calculating the time interval values ​​between adjacent timestamps in the access time point sequence to generate a time interval sequence; calculating the mean and variance of the access duration based on the access duration sequence to generate a duration feature parameter; and combining the time interval sequence and the duration feature parameter to construct a time series feature input vector;

[0015] Inputting the temporal feature input vector into a long short-term memory neural network, the long short-term memory neural network comprising a forget gate, an input gate, and an output gate; constructing an attention weight matrix, the attention weight matrix being used to calculate the importance of each hidden state in the hidden state sequence output by the long short-term memory neural network; inputting the hidden state sequence into the attention weight matrix to obtain a weight coefficient sequence; performing weighted summation on the hidden state sequence based on the weight coefficient sequence to generate a temporal feature vector of the user access behavior;

[0016] Matching the user access behavior time series feature vector with the preset normal access pattern feature vector in feature dimensions, calculating the Euclidean distance between the matched feature vectors to obtain a local distance measurement value; and constructing a cumulative distance matrix based on the local distance measurement value;

[0017] A dynamic programming method is used to search for a minimum cumulative distance path in the cumulative distance matrix, a path cost value corresponding to the minimum cumulative distance path is calculated, and the path cost value is used as a temporal distance value of the URL access request.

[0018] Searching for a minimum cumulative distance path using a dynamic programming method in the cumulative distance matrix, and calculating a path cost value corresponding to the minimum cumulative distance path includes:

[0019] For each current processing position in the cumulative distance matrix, calculating a weighted sum of the cumulative distance values ​​of the adjacent positions of the current processing position and the local distance value of the current position, selecting the adjacent position with the minimum weighted sum as the optimal forward position, and recording the minimum weighted sum as the cumulative distance value of the current processing position;

[0020] According to the cumulative distance matrix, backtracking is performed from the end point of the matrix in the direction of the optimal forward position to generate a minimum cumulative distance path, where the minimum cumulative distance path represents the optimal alignment relationship between the user access behavior time series feature vector and the preset normal mode feature vector; all local distance values ​​passed by the minimum cumulative distance path are weighted and summed to obtain the path cost value.

[0021] Constructing a temporary access token based on the validity period of the dynamic URL and the access permission level includes:

[0022] Generate a token data structure based on the dynamic URL validity period and the access permission level, wherein the token data structure includes a current timestamp, the dynamic URL validity period, and the access permission level, and encode the token data structure into a temporary access token;

[0023] The temporary access token is encrypted and signed to generate a token verification code, which is added to the temporary access token to obtain a final temporary access token.

[0024] A multi-level heterogeneous consensus mechanism is used to verify the temporary access token. Consensus shards are generated based on verifiable random functions at the data layer. Asynchronous message transmission across shards is implemented at the network layer. The consensus layer integrates a practical Byzantine fault-tolerant protocol and a proof-of-stake mechanism to dynamically adjust the consensus weight. The following are included:

[0025] Receive the token verification record, consensus behavior record, and shard interaction record of the node, calculate the verification reliability index, behavior normative index, and interaction stability index based on the token verification record, the consensus behavior record, and the shard interaction record, respectively, and multiply the verification reliability index, the behavior normative index, and the interaction stability index with the corresponding dimension weights to obtain the comprehensive trust value of the node;

[0026] Divide the comprehensive trust value into different consensus shards based on a verifiable random function, perform verification and evaluation on the nodes in the consensus shards, calculate the verification success rate and verification accuracy of the nodes, and generate a performance score for the nodes within the shards;

[0027] Implementing cross-shard asynchronous message delivery at the network layer, calculating message priorities based on the performance scores of the source and target shards, determining the message synchronization frequency between shards based on the message priorities, and establishing a cross-shard message delivery channel;

[0028] The practical Byzantine fault-tolerant protocol and the proof-of-stake mechanism are integrated, and the comprehensive trust value, the performance score and the stake amount are used as weight parameters. When the comprehensive trust value of the node changes, the consensus weight is dynamically adjusted.

[0029] Based on a verifiable random function, the comprehensive trust value is divided into different consensus shards, and the nodes in the consensus shards are verified and evaluated. The verification success rate and verification accuracy of the nodes are counted to generate the performance score of the nodes in the shards, including:

[0030] The verification success rate, verification accuracy, and response time of the collected nodes are used as raw performance indicators, and the exponential sliding average algorithm is used to generate the timing performance score of the node. The timing performance score is combined with the raw performance indicators to construct the current comprehensive performance indicator of the node;

[0031] Extracting a shard feature vector based on the current comprehensive performance index, using an adaptive multi-layer perceptron model to predict a shard performance change trend, and fusing the shard feature vector with the shard performance change trend to generate shard fitness;

[0032] Utilizing a hierarchical verifiable random function mechanism, the node private key, the current comprehensive performance index, and the shard fitness are mapped into a deterministic random output, and a dynamic shard allocation strategy is constructed based on the deterministic random output;

[0033] Node reorganization is performed according to the dynamic sharding allocation strategy, and a performance optimization model based on deep reinforcement learning is established. The performance optimization model uses the node performance gap as a reward function and outputs an optimal performance adjustment plan; the performance parameters of the node are adjusted according to the optimal performance adjustment plan, and the performance score of the node is re-evaluated.

[0034] The exponential moving average algorithm is used to generate a timing performance score for the node, and the timing performance score is combined with the original performance index to construct the current comprehensive performance index of the node, including:

[0035] Collecting original performance indicators of the nodes, and performing weighted processing on the original performance indicators based on preset weights to obtain weighted performance indicators, wherein the preset weights are determined according to the importance of each performance indicator;

[0036] The weighted performance index and the exponential moving average of the previous moment are combined to calculate the exponential moving average of the current moment according to the ratio of the dynamic smoothing factor, where the dynamic smoothing factor is composed of a base smoothing factor and an adjustment amount determined according to the degree of performance fluctuation;

[0037] Calculate the difference between the exponential moving averages of the current moment and the previous moment to obtain a short-term performance fluctuation value. Combine the exponential moving average of the current moment and the short-term performance fluctuation value using a time series feature weight coefficient to generate a time series performance score that reflects the historical performance change trend of the node. The time series feature weight coefficient is used to balance the impact of long-term performance and short-term fluctuations.

[0038] The timing performance score and the weighted performance index are combined based on the timing score weight to obtain the current comprehensive performance index of the node.

[0039] According to a second aspect of an embodiment of the present invention, an electronic device is provided, including:

[0040] processor;

[0041] a memory for storing processor-executable instructions;

[0042] The processor is configured to call the instructions stored in the memory to execute the aforementioned method.

[0043] According to a third aspect of an embodiment of the present invention, a computer-readable storage medium is provided, on which computer program instructions are stored. When the computer program instructions are executed by a processor, the method described above is implemented.

[0044] The beneficial effects of this application are as follows:

[0045] The present invention extracts time point sequences and duration sequences based on users' historical URL access records, and uses a long short-term memory neural network to generate temporal feature vectors of user access behavior, thereby achieving accurate characterization of user access patterns and effectively improving the accuracy and personalization of access control.

[0046] The present invention adopts a dynamic time warping algorithm to calculate the timing distance value between the URL access request and the preset normal access mode, and dynamically determines the access permission level and the URL validity period based on this, thereby realizing adaptive adjustment of access control, enhancing the system's ability to identify abnormal access behavior, and improving the security of multi-file service storage.

[0047] The present invention introduces a multi-level heterogeneous consensus mechanism to verify temporary access tokens, generates consensus shards through verifiable random functions at the data layer, asynchronously transmits messages across shards at the network layer, and integrates a practical Byzantine fault-tolerant protocol with a proof-of-stake mechanism at the consensus layer. This constructs an efficient and reliable distributed verification system, significantly improving the system's throughput and anti-attack capabilities while ensuring the decentralization and immutability of access control. BRIEF DESCRIPTION OF THE DRAWINGS

[0048] Figure 1 A flowchart of a method for controlling storage access to dynamic multi-file services based on time-sensitive URLs according to an embodiment of the present invention is provided;

[0049] Figure 2 This is a histogram comparing the performance of LSTM-DTW time series feature analysis in an embodiment of the present invention.

[0050] Figure 3 A flowchart of temporary access token generation and signature processing according to an embodiment of the present invention;

[0051] Figure 4 This is a logic block diagram of the multi-level heterogeneous consensus mechanism according to an embodiment of the present invention;

[0052] Figure 5 This is a bar chart comparing the performance scores of the dynamic exponential sliding average algorithm according to an embodiment of the present invention. DETAILED DESCRIPTION

[0053] To make the objectives, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.

[0054] The following specific embodiments will be used to describe the technical solution of the present invention in detail. The following specific embodiments can be combined with each other, and the same or similar concepts or processes may not be described in detail in some embodiments.

[0055] Figure 1 FIG is a flow chart of a method for controlling access to dynamic multi-file service storage based on time-sensitive URLs according to an embodiment of the present invention. Figure 1 As shown, the method includes:

[0056] Receive a URL access request sent by a user terminal, the URL access request carrying user identity information and target file access identification information, and generate an access request identifier;

[0057] Obtaining historical URL access records of the user terminal based on the user identity information query, extracting an access time sequence and an access duration sequence from the historical URL access records, and associating the access time sequence and the access duration sequence with the access request identifier;

[0058] Inputting the access time point sequence and the access duration sequence into a pre-trained long short-term memory neural network to generate a user access behavior temporal feature vector; based on the user access behavior temporal feature vector, using a dynamic time warping algorithm to calculate the temporal distance value between the URL access request and a preset normal access pattern, and determining the access permission level corresponding to the access request identifier and the dynamic URL validity period based on the temporal distance value;

[0059] A temporary access token is constructed according to the validity period of the dynamic URL and the access permission level, and a multi-level heterogeneous consensus mechanism is used to verify the temporary access token. Consensus shards are generated based on verifiable random functions at the data layer, asynchronous message transmission across shards is implemented at the network layer, and a practical Byzantine fault tolerance protocol and proof-of-stake mechanism are integrated at the consensus layer to dynamically adjust the consensus weight.

[0060] In an optional embodiment, the sequence of access time points and the sequence of access durations are input into a pre-trained long short-term memory neural network to generate a temporal feature vector of user access behavior; based on the temporal feature vector of user access behavior, a dynamic time warping algorithm is used to calculate the temporal distance between the URL access request and a preset normal access pattern, including:

[0061] Calculating the time interval values ​​between adjacent timestamps in the access time point sequence to generate a time interval sequence; calculating the mean and variance of the access duration based on the access duration sequence to generate a duration feature parameter; and combining the time interval sequence and the duration feature parameter to construct a time series feature input vector;

[0062] Inputting the temporal feature input vector into a long short-term memory neural network, the long short-term memory neural network comprising a forget gate, an input gate, and an output gate; constructing an attention weight matrix, the attention weight matrix being used to calculate the importance of each hidden state in the hidden state sequence output by the long short-term memory neural network; inputting the hidden state sequence into the attention weight matrix to obtain a weight coefficient sequence; performing weighted summation on the hidden state sequence based on the weight coefficient sequence to generate a temporal feature vector of the user access behavior;

[0063] Matching the user access behavior time series feature vector with the preset normal access pattern feature vector in feature dimensions, calculating the Euclidean distance between the matched feature vectors to obtain a local distance measurement value; and constructing a cumulative distance matrix based on the local distance measurement value;

[0064] A dynamic programming method is used to search for a minimum cumulative distance path in the cumulative distance matrix, a path cost value corresponding to the minimum cumulative distance path is calculated, and the path cost value is used as a temporal distance value of the URL access request.

[0065] By analyzing the temporal characteristics of user access behavior and calculating the temporal distance value from the preset normal access pattern, potential abnormal access requests can be identified.

[0066] Obtain the user's URL access request data, including a sequence of access time points and access durations. The access time point sequence records the timestamps of each URL accessed by the user. For example, [1621234567, 1621234789, 1621235012] indicates that the user accessed the corresponding URLs at these three time points. The access duration sequence records the time the user spent on each URL, in seconds. For example, [45, 120, 30] indicates that the user spent 45 seconds, 120 seconds, and 30 seconds on the three URLs, respectively.

[0067] The time intervals between consecutive timestamps are calculated based on the access time point sequence to generate a time interval sequence. For example, for the timestamp sequence [1621234567, 1621234789, 1621235012], the calculated time interval sequence is [222, 223], indicating that the time intervals between consecutive accesses are 222 seconds and 223 seconds, respectively.

[0068] Based on the visit duration series, we calculated the mean and variance of visit durations to generate duration feature parameters. For the duration series [45, 120, 30], the calculated mean was 65 seconds and the variance was 2025. These statistical features can reflect the stability and changing patterns of user visit behavior.

[0069] The time interval sequence and duration feature parameters are combined to construct a time series feature input vector. For example, for the time interval sequence [222, 223] and the duration feature parameter [65, 2025], the constructed time series feature input vector is [222, 223, 65, 2025]. This vector contains the time distribution and duration characteristics of the user's access behavior.

[0070] The time series feature input vector is fed into a pre-trained long short-term memory (LSTM) neural network. This network consists of three key components: a forget gate, an input gate, and an output gate. The forget gate determines which information in the cell state is discarded, the input gate determines which information is updated, and the output gate determines which information is output. Through these three gating mechanisms, the LSTM neural network can effectively capture long-term dependencies in time series data.

[0071] In this embodiment, the number of hidden units in the LSTM neural network is set to 128. The input layer dimension matches the dimension of the time series feature input vector, and the output layer produces a sequence of hidden states. For the input vector [222, 223, 65, 2025], the network outputs a sequence of hidden states such as [[0.23, 0.45, ..., 0.12], [0.34, 0.56, ..., 0.21], ...], where each hidden state is a 128-dimensional vector.

[0072] Construct an attention weight matrix to calculate the importance of each hidden state in the hidden state sequence output by the LSTM neural network. The attention mechanism learns the importance of different time steps, enabling the model to focus on the most relevant information. The dimension of the attention weight matrix is ​​the hidden state dimension × 1, for example, 128 × 1.

[0073] The hidden state sequence is input into the attention weight matrix to obtain a weight coefficient sequence. For example, for the three hidden states in the hidden state sequence, the weight coefficient sequence is [0.4, 0.35, 0.25], which indicates the relative importance of the three hidden states.

[0074] The hidden state sequence is weighted and summed based on the weight coefficient sequence to generate the user access behavior time series feature vector. Specifically, each hidden state vector is multiplied by its corresponding weight coefficient and then summed to obtain the final feature vector. For example, if the three hidden state vectors are v1, v2, and v3, and the weight coefficients are [0.4, 0.35, 0.25], then the time series feature vector is 0.4×v1+0.35×v2+0.25×v3.

[0075] Match the feature dimensions of the user access behavior time series feature vector with the preset normal access pattern feature vector. If the two vector dimensions are inconsistent, the system will pad or truncate them to make them consistent. For example, if the user feature vector dimension is 128 and the preset pattern feature vector dimension is 100, the system will truncate the user feature vector to retain the first 100 elements.

[0076] The local distance metric is calculated by calculating the Euclidean distance between the matched feature vectors. For example, if the matched user feature vector is [0.1, 0.2, 0.3] and the preset pattern feature vector is [0.15, 0.25, 0.35], the Euclidean distance is 0.0866.

[0077] A cumulative distance matrix is ​​constructed based on the local distance metric. The number of rows in this matrix is ​​equal to the length of the user feature vector, and the number of columns is equal to the length of the preset pattern feature vector. Each element in the matrix represents the minimum cumulative distance from the starting point to the current location.

[0078] Dynamic programming is used to search for the path with the minimum cumulative distance in the cumulative distance matrix. Starting from the upper left corner of the matrix, each move can be made rightward, downward, or right-to-bottom, selecting the path with the minimum cumulative distance. For example, in a 3×3 cumulative distance matrix, the minimum path is [(0,0),(0,1),(1,2),(2,2)].

[0079] Calculate the path cost corresponding to the minimum cumulative distance path and use this value as the temporal distance value of the URL access request. The path cost is typically the weighted sum of all local distances along the path. For example, if the local distances along the path are [0.1, 0.2, 0.15, 0.25] and the corresponding weights are [0.3, 0.25, 0.25, 0.2], then the path cost is 0.1 × 0.3 + 0.2 × 0.25 + 0.15 × 0.25 + 0.25 × 0.2 = 0.165.

[0080] The calculated time series distance value is compared with the preset threshold to determine whether the URL access request is abnormal. For example, if the preset threshold is 0.5 and the calculated time series distance value is 0.165, the access request is considered normal; if the time series distance value is 0.7, it is considered an abnormal access request.

[0081] Figure 2 This is a bar chart comparing the performance of LSTM-DTW time series feature analysis in an embodiment of the present invention:

[0082] The figure compares the performance of three different feature extraction methods across three key metrics: detection accuracy, feature extraction efficiency, and anomaly detection sensitivity. The traditional feature extraction method performed most conservatively, achieving 75.3%, 62.8%, and 68.4% for these three metrics, respectively. The LSTM feature extraction method demonstrated significant improvements over traditional methods, reaching 85.7% detection accuracy, 76.2% feature extraction efficiency, and 82.5% anomaly detection sensitivity. The LSTM model incorporating the attention mechanism achieved the most outstanding performance, achieving 92.4% detection accuracy, 89.3% feature extraction efficiency, and 91.8% anomaly detection sensitivity. The data comparison clearly demonstrates that the introduction of the attention mechanism significantly enhances the LSTM model's feature extraction capabilities, achieving top performance across all evaluation metrics, with improvements of 17.1%, 26.5%, and 23.4% compared to traditional methods, respectively. This demonstrates the superiority of this method in feature extraction tasks. This performance improvement is primarily due to the attention mechanism's ability to adaptively focus on important features, thereby improving both feature extraction accuracy and efficiency.

[0083] In an optional implementation, searching for a minimum cumulative distance path using a dynamic programming method in the cumulative distance matrix, and calculating a path cost value corresponding to the minimum cumulative distance path includes:

[0084] For each current processing position in the cumulative distance matrix, calculating a weighted sum of the cumulative distance values ​​of the adjacent positions of the current processing position and the local distance value of the current position, selecting the adjacent position with the minimum weighted sum as the optimal forward position, and recording the minimum weighted sum as the cumulative distance value of the current processing position;

[0085] According to the cumulative distance matrix, backtracking is performed from the end point of the matrix in the direction of the optimal forward position to generate a minimum cumulative distance path, where the minimum cumulative distance path represents the optimal alignment relationship between the user access behavior time series feature vector and the preset normal mode feature vector; all local distance values ​​passed by the minimum cumulative distance path are weighted and summed to obtain the path cost value.

[0086] In this embodiment, the specific technical implementation of using the dynamic programming method to search for the minimum cumulative distance path in the cumulative distance matrix and calculating the path cost value corresponding to the minimum cumulative distance path is described in detail.

[0087] The cumulative distance matrix is ​​a two-dimensional matrix that represents the distance relationship between the time-series feature vectors of user access behavior and the preset normal pattern feature vectors. Assuming the time-series feature vector A is of length m, and the preset normal pattern feature vector B is of length n, the size of the cumulative distance matrix D is m × n. Each element D[i][j] in the matrix represents the minimum cumulative distance between the first i elements of vector A and the first j elements of vector B.

[0088] For each current processing position (i, j) in the cumulative distance matrix, the system calculates the cumulative distance value for that position. During this calculation, the system first determines the set of neighboring positions for the current processing position. In a typical implementation, these neighboring positions include (i-1, j), (i, j-1), and (i-1, j-1), representing vertical, horizontal, and diagonal directions, respectively. For positions at the matrix boundaries, the set of neighboring positions is reduced.

[0089] Calculate the local distance value d(i, j) at the current processing location (i, j). This value represents the distance between the i-th element of the user's access behavior time series feature vector A and the j-th element of the preset normal pattern feature vector B. The local distance can be calculated using metrics such as Euclidean distance, Manhattan distance, or cosine similarity.

[0090] For each neighboring location, the system calculates the weighted sum of its cumulative distance value and the local distance value of the current location.

[0091] In practice, the weights can be adjusted based on the specific scenario. For example, you can set w1=1.0, w2=1.0, and w3=0.8. This will give a certain advantage to diagonal transfers, which will help generate a smoother path. The system selects the minimum value from the three weighted sums and records it as the cumulative distance value D[i][j] of the current processing position (i, j). It also records the adjacent position that produces the minimum weighted sum as the optimal forward position of the current position.

[0092] To facilitate subsequent backtracking, the system maintains a forward pointer matrix P of the same size as the cumulative distance matrix, where P[i][j] records the optimal forward position of position (i, j). For example, if the optimal forward position of position (i, j) is (i-1, j-1), then P[i][j]=(i-1, j-1).

[0093] The system processes each position in the cumulative distance matrix from left to right and from top to bottom until all positions in the matrix are processed. After processing is completed, the element D[m][n] in the lower right corner of the matrix represents the minimum cumulative distance between the entire user access behavior time series feature vector and the preset normal pattern feature vector.

[0094] After calculating the cumulative distance matrix, the system begins at the matrix endpoint (m,n) and backtracks based on the forward pointer matrix P to generate the path with the minimum cumulative distance. Specifically, the system first adds the endpoint (m,n) to the path, then searches P[m][n] to find the previous location, adds that location to the path, and continues searching for the forward pointer for the previous location until it reaches the matrix starting point (1,1). Since the backtracked path is from the end point to the starting point, the system needs to reverse the path to obtain the path with the minimum cumulative distance from the starting point to the end point.

[0095] For example, assuming m=5 and n=4, the backtracking path is [(5,4),(4,3),(3,3),(2,2),(1,1)], and the reversed path is [(1,1),(2,2),(3,3),(4,3),(5,4)]. This path represents the optimal alignment between the user access behavior temporal feature vector A and the preset normal pattern feature vector B, that is, the first element of A corresponds to the first element of B, the second element of A corresponds to the second element of B, and so on.

[0096] Calculate the path cost corresponding to the minimum cumulative distance path. The system traverses all locations passed by the minimum cumulative distance path, extracts the local distance value corresponding to each location, and performs a weighted sum.

[0097] In practice, different weights can be assigned based on the importance of locations in a path. For example, higher weights can be assigned to key points in a path to emphasize their impact on the overall similarity. If all locations have the same importance, all weights can be set to 1. In this case, the path cost is simply the sum of all local distance values.

[0098] The path cost calculated using this method can be used to assess the similarity between user access behavior and the preset normal pattern. A smaller path cost indicates that the user's access behavior is closer to the preset normal pattern; a larger path cost indicates that the user's access behavior deviates further from the preset normal pattern, indicating abnormal behavior.

[0099] In an optional implementation, constructing a temporary access token based on the validity period of the dynamic URL and the access permission level includes:

[0100] Generate a token data structure based on the dynamic URL validity period and the access permission level, wherein the token data structure includes a current timestamp, the dynamic URL validity period, and the access permission level, and encode the token data structure into a temporary access token;

[0101] The temporary access token is encrypted and signed to generate a token verification code, which is added to the temporary access token to obtain a final temporary access token.

[0102] like Figure 3 As shown, the method includes:

[0103] When generating the token data structure based on the dynamic URL validity period and access level, the system first retrieves the current system time as a timestamp. For example, the system retrieves the current timestamp of "2023-05-15T08:30:45Z," which represents 8:30:45 UTC on May 15, 2023. The system then adds the obtained dynamic URL validity period to the token data structure. The dynamic URL validity period can be an integer value in seconds, such as "3600" indicating that the dynamic URL is valid for 3600 seconds (i.e., 1 hour) after being generated. The system also adds access level information to the token data structure. Access levels can be predefined permission identifiers, such as "read-only" for read-only access, "read-write" for read-write access, and "admin" for administrator access.

[0104] Generate the following token data structure: {"timestamp":"2023-05-15T08:30:45Z", "duration":3600, "access_level":"read-only"}. This data structure contains the current timestamp, the validity period of the dynamic URL (3600 seconds), and the access permission level (read-only).

[0105] After generating the token data structure, the system encodes it into a temporary access token. This encoding process uses the Base64 encoding algorithm to convert the JSON-formatted token data structure into a string. In the example above, the Base64 encoding of the token data structure produces the following string: "eyJ0aW1lc3RhbXAiOiIyMDIzLTA1LTE1VDA4OjMwOjQ1WiIsImR1cmF0aW9uIjozNjAwLCJhY2Nlc3NfbGV2ZWwiOiJyZWFkLW9ubHkifQ==". This string is the initial temporary access token.

[0106] To ensure the security and integrity of temporary access tokens, the system requires cryptographic signature processing. This cryptographic signature uses the HMAC (Hash Message Authentication Code) algorithm, which takes a key and a message as input and outputs a fixed-length hash value. In this implementation, the system uses a preset key (e.g., "secretKey12345") and a preliminary temporary access token as input, calculating a hash value that serves as the token verification code.

[0107] Specifically, the system uses the HMAC-SHA256 algorithm and "secretKey12345" as the key to perform a hash calculation on the preliminary temporary access token "eyJ0aW1lc3RhbXAiOiIyMDIzLTA1LTE1VDA4OjMwOjQ1WiIsImR1cmF0aW9uIjozNjAwLCJhY2Nlc3NfbGV2ZWwiOiJyZWFkLW9ubHkifQ==" to obtain the token verification code "a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6".

[0108] The system appends the calculated token verification code to the preliminary temporary access token to form the final temporary access token. This can be done by appending a separator (such as ".") and the token verification code to the end of the preliminary temporary access token. In the above example, the final temporary access token is: "eyJ0aW1lc3RhbXAiOiIyMDIzLTA1LTE1VDA4OjMwOjQ1WiIsImR1cmF0aW9uIjozNjAwLCJhY2Nlc3NfbGV2ZWwiOiJyZWFkLW9ubHkifQ==.a1b2c3d4e5f6g7h8i9j0k1l2m3n4o5p6".

[0109] This approach to constructing temporary access tokens offers multiple layers of security. By including a timestamp and expiration time in the token data structure, the system can verify the token's expiration status when validating it. By including access rights, the system can control the scope of operations that a token holder can perform. Cryptographically signing the token allows the system to detect tampering, as any modification to the token's contents will cause the checksum to mismatch.

[0110] In practice, when a user requests access to a protected resource, the system verifies the temporary access token provided by the user. This verification process includes separating the token content and the verification code, recalculating the verification code using the same key and algorithm and comparing it with the provided verification code, decoding the token content to obtain the timestamp, validity period, and access permission level, and then checking whether the token is within its validity period and whether the requested operation is within the permitted scope of permissions.

[0111] For example, if a user uses the temporary access token to read a file at 9:15 AM on May 15, 2023 (45 minutes after the token was generated), the system will validate the token. It will first check whether the checksum matches, then calculate the token's expiration time (9:30:45 AM on May 15, 2023), confirm that the current time is before the expiration time, and finally check whether the requested read operation falls within the "read-only" permission range. Only after all checks are passed will the system allow the user to access the requested resource.

[0112] In an optional embodiment, a multi-level heterogeneous consensus mechanism is used to verify the temporary access token, generate consensus shards based on a verifiable random function at the data layer, implement asynchronous message transmission across shards at the network layer, and dynamically adjust consensus weights by integrating a practical Byzantine fault-tolerant protocol with a proof-of-stake mechanism at the consensus layer. The following steps are included:

[0113] Receive the token verification record, consensus behavior record, and shard interaction record of the node, calculate the verification reliability index, behavior normative index, and interaction stability index based on the token verification record, the consensus behavior record, and the shard interaction record, respectively, and multiply the verification reliability index, the behavior normative index, and the interaction stability index with the corresponding dimension weights to obtain the comprehensive trust value of the node;

[0114] Divide the comprehensive trust value into different consensus shards based on a verifiable random function, perform verification and evaluation on the nodes in the consensus shards, calculate the verification success rate and verification accuracy of the nodes, and generate a performance score for the nodes within the shards;

[0115] Implementing cross-shard asynchronous message delivery at the network layer, calculating message priorities based on the performance scores of the source and target shards, determining the message synchronization frequency between shards based on the message priorities, and establishing a cross-shard message delivery channel;

[0116] The practical Byzantine fault-tolerant protocol and the proof-of-stake mechanism are integrated, and the comprehensive trust value, the performance score and the stake amount are used as weight parameters. When the comprehensive trust value of the node changes, the consensus weight is dynamically adjusted.

[0117] like Figure 4 As shown, the method includes:

[0118] Receive the node's token verification records, consensus behavior records, and shard interaction records. Token verification records contain the node's verification history for temporary access tokens, such as verification timestamps, verification results, and verification delays. Consensus behavior records contain data on the node's participation in the consensus process, such as the number of proposals, voting results, and block confirmation contributions. Shard interaction records contain historical data on the node's communication with other shards, such as message delivery success rate, response time, and data consistency. The system calculates verification reliability, behavioral compliance, and interaction stability indicators based on these records.

[0119] The calculation of the verification reliability index considers the accuracy of the node's verification of temporary access tokens, average response time, and verification consistency. For example, if node A has verified 980 times out of the past 1000 verifications consistent with the final consensus, with an average response time of 200 milliseconds and a verification consistency of 0.95, its verification reliability index is 0.92. The calculation of the behavioral compliance index considers the compliance of the node's behavior during the consensus process, such as whether there is double voting and whether votes are submitted on time.

[0120] For example, node B participated in 495 of the past 500 consensus rounds according to protocol rules without any abnormal behavior, resulting in a behavioral compliance index of 0.99. The calculation of the interaction stability index considers the stability and efficiency of the node's interactions with other shards, such as message delivery success rate and average latency. For example, node C has a message delivery success rate of 98% and an average latency of 150 milliseconds with other shards, resulting in an interaction stability index of 0.94.

[0121] The weights of the three dimensions are preset to 0.4, 0.3, and 0.3, respectively. The node's comprehensive trust value is obtained by multiplying the verification reliability index, behavioral norm index, and interaction stability index by the corresponding dimension weights. For example, if the three indicators of node D are 0.90, 0.95, and 0.88, respectively, its comprehensive trust value is 0.90 × 0.4 + 0.95 × 0.3 + 0.88 × 0.3 = 0.909.

[0122] The overall trust value is allocated to different consensus shards based on a verifiable random function. The verifiable random function takes the node public key and the current block hash as input and generates a deterministic random output. For example, if the system has five consensus shards, nodes with a trust value above 0.9 are assigned to shards 1 and 2, nodes with a trust value between 0.8 and 0.9 are assigned to shards 3 and 4, and nodes with a trust value below 0.8 are assigned to shard 5.

[0123] Verification is evaluated for nodes in the consensus shard, with the verification success rate and accuracy calculated. The verification success rate refers to the percentage of temporary access tokens successfully verified by a node, while the verification accuracy refers to the consistency between the node's verification results and the final consensus result. For example, if node E has a verification success rate of 97% and a verification accuracy of 98% in Shard 1, the system will generate a performance score of 0.975 for the node within the shard based on these two metrics.

[0124] Asynchronous cross-shard message delivery is implemented at the network layer. The system calculates message priority based on the performance scores of the source and target shards. For example, if the average performance score of the source shard is 0.95 and the average performance score of the target shard is 0.92, the message priority is 0.935. The system determines the frequency of inter-shard message synchronization based on the message priority; higher priorities result in higher synchronization frequencies.

[0125] For example, shards with a priority of 0.95 or higher synchronize every 10 seconds, those with a priority between 0.9 and 0.95 synchronize every 15 seconds, and those with a priority between 0.85 and 0.9 synchronize every 20 seconds. The system establishes a cross-shard messaging channel, using asynchronous communication to ensure reliable message delivery between shards. Messages contain information such as the source shard ID, target shard ID, message content, timestamp, and digital signature.

[0126] This system integrates a practical Byzantine Fault Tolerance protocol with a proof-of-stake mechanism, using comprehensive trust, performance score, and stake as weighting parameters. For example, if node F has a comprehensive trust value of 0.92, a performance score of 0.94, and a stake of 1,000 tokens, the system calculates the final weight using these three parameters in a 3:3:4 ratio, resulting in a consensus weight of 0.92 × 0.3 + 0.94 × 0.3 + 1000 / 10,000 × 0.4 = 0.498. The system dynamically adjusts the consensus weight as the node's comprehensive trust value changes. For example, if node F's comprehensive trust value drops to 0.85, its consensus weight will be adjusted to 0.85 × 0.3 + 0.94 × 0.3 + 1000 / 10,000 × 0.4 = 0.477.

[0127] Through this multi-layered, heterogeneous consensus mechanism, the system can effectively verify temporary access tokens, improving system security and reliability. Consensus sharding at the data layer improves system scalability, asynchronous messaging at the network layer ensures efficient communication between shards, and the dynamic weight adjustment mechanism at the consensus layer ensures system fairness and incentive compatibility.

[0128] In an optional embodiment, the comprehensive trust value is divided into different consensus shards based on a verifiable random function, the nodes in the consensus shards are verified and evaluated, the verification success rate and verification accuracy of the nodes are counted, and the performance score of the nodes in the shards is generated, including:

[0129] The verification success rate, verification accuracy, and response time of the collected nodes are used as raw performance indicators, and the exponential sliding average algorithm is used to generate the timing performance score of the node. The timing performance score is combined with the raw performance indicators to construct the current comprehensive performance indicator of the node;

[0130] Extracting a shard feature vector based on the current comprehensive performance index, using an adaptive multi-layer perceptron model to predict a shard performance change trend, and fusing the shard feature vector with the shard performance change trend to generate shard fitness;

[0131] Utilizing a hierarchical verifiable random function mechanism, the node private key, the current comprehensive performance index, and the shard fitness are mapped into a deterministic random output, and a dynamic shard allocation strategy is constructed based on the deterministic random output;

[0132] Node reorganization is performed according to the dynamic sharding allocation strategy, and a performance optimization model based on deep reinforcement learning is established. The performance optimization model uses the node performance gap as a reward function and outputs an optimal performance adjustment plan; the performance parameters of the node are adjusted according to the optimal performance adjustment plan, and the performance score of the node is re-evaluated.

[0133] The verification success rate, verification accuracy, and response time of the nodes are collected as raw performance indicators. The verification success rate refers to the proportion of transactions that the node successfully verified. For example, if a node successfully completed 950 of the last 1,000 verification requests, its verification success rate is 95%. The verification accuracy refers to the proportion of transactions that the node correctly verified. For example, if 940 out of 950 successful verifications were correct, the verification accuracy is 98.9%. The response time refers to the average time it takes a node to process a verification request. For example, the average response time is 200 milliseconds.

[0134] A node's timing performance score is generated using an exponential moving average algorithm. Specifically, for each performance metric, the system retains data from 10 historical time windows, each lasting one hour. New window data is weighted 0.2, while historical data is weighted 0.8. For example, if a node's verification success rate in the most recent time window is 95% and its historical timing score is 92%, the updated timing score is 92% × 0.8 + 95% × 0.2 = 92.6%. The system uses the same method to calculate timing scores for verification accuracy and response time.

[0135] The timing performance score is combined with the original performance index to construct the node's current comprehensive performance index. The combination is: Comprehensive Performance Index = Timing Score × 0.7 + Original Index × 0.3. For example, if a node's verification success rate has a timing score of 92.6% and an original index of 95%, the comprehensive index is 92.6% × 0.7 + 95% × 0.3 = 93.3%. The system uses the same method to calculate the comprehensive index for verification accuracy and response time.

[0136] Based on the current comprehensive performance metrics, the system extracts a shard feature vector. This feature vector contains the mean, variance, maximum, minimum, and median of the comprehensive performance metrics for all nodes in the shard. For example, a shard containing 100 nodes has a verification success rate with a mean of 94.2%, a variance of 2.1%, a maximum of 98.7%, a minimum of 89.3%, and a median of 94.5%. The system uses the same method to calculate feature values ​​for verification accuracy and response time, forming a 15-dimensional feature vector.

[0137] An adaptive multi-layer perceptron model is used to predict shard performance trends. The model consists of an input layer, two hidden layers, and an output layer, with 32 and 16 hidden layer nodes, respectively. The input is the shard feature vector, and the output is performance predictions for the next three time windows. For example, the model predicts that the verification success rate for a particular shard will change from 94.2% to 94.5%, 94.8%, and 95.0% over the next three hours, indicating an upward performance trend.

[0138] The shard feature vector and the shard performance trend are combined to generate the shard fitness. The fusion method is: shard fitness = current feature vector weight × 0.6 + performance trend weight × 0.4. The feature vector weight is calculated using the normalized feature vector, and the performance trend weight is determined based on the slope of the predicted value. For example, if a shard has a feature vector weight of 0.85 and a performance trend weight of 0.92, the shard fitness is 0.85 × 0.6 + 0.92 × 0.4 = 0.878.

[0139] Utilizing a hierarchical verifiable random function mechanism, the node private key, current comprehensive performance index, and shard fitness are mapped into a deterministic random output. Specifically, the system uses the node private key to generate a base random number, then uses the comprehensive performance index as a seed to adjust the random number distribution. Finally, the shard fitness is used as a threshold to control the effective range of the random number. For example, if the base random number generated by a node's private key is 0.723, the random number adjusted after the comprehensive performance index is 0.756, and the effective range of the shard fitness setting is [0.3, 0.9], the deterministic random output of this node is 0.756.

[0140] A dynamic shard allocation strategy is constructed based on deterministic random output. The strategy rules are as follows: nodes with random outputs in the range [0, 0.3) are assigned to shards with low performance requirements, nodes in the range [0.3, 0.7) are assigned to shards with medium performance requirements, and nodes in the range [0.7, 1.0] are assigned to shards with high performance requirements. For example, a node with a random output of 0.756 is assigned to a shard with high performance requirements.

[0141] Node reorganization is performed based on the dynamic shard allocation strategy. During this reorganization, the system ensures a balanced number of nodes per shard. For example, in a network with 1,000 nodes, each of the 10 shards would have approximately 100 nodes. Furthermore, the system ensures a balanced performance distribution across shards to avoid significant performance disparity.

[0142] A performance optimization model based on deep reinforcement learning was established. This model uses a deep Q-network architecture consisting of an input layer, three hidden layers, and an output layer. The number of hidden layer nodes is 64, 32, and 16, respectively. The state space represents the current performance parameters of the node, the action space represents the adjustable parameter options, and the reward function is the negative of the node performance gap. For example, if a node's verification success rate is 5% lower than the shard average, the reward is -5.

[0143] The performance optimization model outputs the optimal performance adjustment plan. This adjustment plan includes parameters such as the node's cache size, concurrent processing capability, and network bandwidth allocation. For example, for nodes with low verification success rates, the system recommends increasing the cache size from 256MB to 512MB, concurrent processing threads from 4 to 8, and network bandwidth allocation from 10Mbps to 20Mbps.

[0144] Adjust the node's performance parameters based on the optimal performance adjustment plan, and re-evaluate the node's performance score in the next evaluation cycle. Through continuous evaluation and optimization, the system can dynamically balance the performance of each shard and improve the efficiency and reliability of the overall network.

[0145] In an optional embodiment, the exponential moving average algorithm is used to generate a time series performance score of the node, and the time series performance score is combined with the original performance index to construct the current comprehensive performance index of the node, including:

[0146] Collecting original performance indicators of the nodes, and performing weighted processing on the original performance indicators based on preset weights to obtain weighted performance indicators, wherein the preset weights are determined according to the importance of each performance indicator;

[0147] The weighted performance index and the exponential moving average of the previous moment are combined to calculate the exponential moving average of the current moment according to the ratio of the dynamic smoothing factor, where the dynamic smoothing factor is composed of a base smoothing factor and an adjustment amount determined according to the degree of performance fluctuation;

[0148] Calculate the difference between the exponential moving averages of the current moment and the previous moment to obtain a short-term performance fluctuation value. Combine the exponential moving average of the current moment and the short-term performance fluctuation value using a time series feature weight coefficient to generate a time series performance score that reflects the historical performance change trend of the node. The time series feature weight coefficient is used to balance the impact of long-term performance and short-term fluctuations.

[0149] The timing performance score and the weighted performance index are combined based on the timing score weight to obtain the current comprehensive performance index of the node.

[0150] In a computer cluster or distributed system, the performance of a node is crucial to the overall efficiency of the system. This implementation collects raw performance metrics from the node, weights them, and combines them with historical data to generate a time-series performance score, ultimately constructing a comprehensive performance index for the node.

[0151] Collect raw node performance metrics, including CPU usage, memory usage, disk I / O rate, network throughput, etc. Suppose the raw performance metrics collected from a node at a specific moment are: CPU usage 75%, memory usage 60%, disk I / O rate 120MB / s, and network throughput 85MB / s.

[0152] The system pre-assigns weights to each performance indicator based on its importance. For example, CPU usage has a weight of 0.4, memory usage has a weight of 0.3, disk I / O rate has a weight of 0.2, and network throughput has a weight of 0.1. Weighting the original performance indicators yields a weighted performance indicator. In this example, the weighted performance indicators are: CPU usage contribution is 30 (75% x 0.4), memory usage contribution is 18 (60% x 0.3), disk I / O rate contribution is 24 (120 MB / s x 0.2), and network throughput contribution is 8.5 (85 MB / s x 0.1). Adding these contribution values ​​yields a weighted performance indicator of 80.5.

[0153] The system uses an exponential moving average algorithm to process time series data. This algorithm combines the current weighted performance indicator with the exponential moving average from the previous moment using a dynamic smoothing factor to produce the current exponential moving average. The dynamic smoothing factor consists of a base smoothing factor and an adjustment based on performance fluctuations.

[0154] The baseline smoothing factor is typically set to 0.2, which means that new data is weighted 20% and historical data is weighted 80%. The degree of performance fluctuation can be determined by calculating the standard deviation at several recent time points. Suppose the system detects significant performance fluctuations, with a calculated standard deviation of 15. Based on the preset adjustment rules, the system sets the adjustment amount to 0.1. Therefore, the dynamic smoothing factor is 0.3 (0.2 + 0.1).

[0155] Assume that the exponential moving average at the previous moment is 75.0, the weighted performance index at the current moment is 80.5, and a dynamic smoothing factor of 0.3 is used for calculation. The exponential moving average at the current moment is 76.65 (80.5 × 0.3 + 75.0 × 0.7).

[0156] To capture short-term performance fluctuations, the system calculates the difference between the exponential moving averages of the current and previous moments to obtain the short-term performance fluctuation value. In this example, the short-term performance fluctuation value is 1.65 (76.65 - 75.0).

[0157] The time series feature weight coefficient combines the current exponential moving average with the short-term performance fluctuation value to generate a time series performance score that reflects the node's historical performance trend. The time series feature weight coefficient is used to balance the impact of long-term performance and short-term fluctuations. Assuming the time series feature weight coefficient is set to 0.8, the time series performance score is 77.97 (76.65 + 1.65 × 0.8).

[0158] The timing performance score and the weighted performance index are combined based on the timing score weight to obtain the node's current comprehensive performance index. Assuming the timing score weight is 0.6, the node's current comprehensive performance index is 78.88 (77.97 × 0.6 + 80.5 × 0.4).

[0159] The advantage of this approach is that it considers both the current performance state of a node and its historical performance trends, avoiding the volatile decisions that come with relying solely on instantaneous performance metrics. By dynamically adjusting the smoothing factor, the system can rely more on historical data when performance is stable, while responding more quickly to changes when performance fluctuates significantly.

[0160] In practical applications, the system can adjust various parameters based on the needs of different scenarios. For example, in scenarios with high real-time requirements, the baseline smoothing factor and time series feature weight coefficient can be increased to enable the system to respond more quickly to performance changes; while in scenarios with high stability requirements, these parameters can be lowered to reduce the impact of short-term fluctuations on decision-making.

[0161] In this way, the system can generate more comprehensive and accurate node performance evaluation results, provide a reliable basis for decisions such as load balancing, task scheduling, and resource allocation, and improve the operating efficiency and stability of the entire distributed system.

[0162] Figure 5 This is a bar chart comparing the performance scores of the dynamic exponential sliding average algorithm according to an embodiment of the present invention:

[0163] The figure compares the performance of this solution with three methods, namely, fixed-weight EMA and traditional weighted average, across four key performance metrics. In terms of adaptability to volatile scenarios, this solution achieved 82.7%, significantly outperforming the fixed-weight EMA (78.3%) and the traditional weighted average (59.2%). In terms of long-term performance prediction, this solution achieved an excellent performance of 89.1%, surpassing the fixed-weight EMA (83.4%) and the traditional weighted average (67.8%). In terms of anomaly detection sensitivity, this solution performed the best, reaching 95.3%, far exceeding the fixed-weight EMA (72.1%) and the traditional weighted average (61.7%). In terms of resource consumption, while the traditional weighted average method performed best at 91.2%, this solution still achieved a respectable 82.6%, surpassing the fixed-weight EMA (68.9%). This data comparison demonstrates that this solution achieves significant advantages in all three core metrics, namely adaptability, predictive power, and detection sensitivity, while maintaining low resource consumption. This fully demonstrates its comprehensive superiority in the field of performance evaluation. In particular, the outstanding performance in anomaly detection sensitivity shows that the solution can better identify and respond to performance fluctuations.

[0164] According to a second aspect of an embodiment of the present invention, an electronic device is provided, including:

[0165] processor;

[0166] a memory for storing processor-executable instructions;

[0167] The processor is configured to call the instructions stored in the memory to execute the aforementioned method.

[0168] According to a third aspect of an embodiment of the present invention, a computer-readable storage medium is provided, on which computer program instructions are stored. When the computer program instructions are executed by a processor, the method described above is implemented.

[0169] The present invention may be a method, an apparatus, a system and / or a computer program product. The computer program product may include a computer-readable storage medium carrying computer-readable program instructions for executing various aspects of the present invention.

[0170] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the above embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the above embodiments, or replace some or all of the technical features therein with equivalents. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. A dynamic multi-file service storage access control method based on time-sensitive URLs, characterized in that: include: Receive a URL access request sent by a user terminal, the URL access request carrying user identity information and target file access identification information, and generate an access request identifier; Obtaining historical URL access records of the user terminal based on the user identity information query, extracting an access time sequence and an access duration sequence from the historical URL access records, and associating the access time sequence and the access duration sequence with the access request identifier; Inputting the access time point sequence and the access duration sequence into a pre-trained long short-term memory neural network to generate a user access behavior temporal feature vector; based on the user access behavior temporal feature vector, using a dynamic time warping algorithm to calculate the temporal distance value between the URL access request and a preset normal access pattern, and determining the access permission level corresponding to the access request identifier and the dynamic URL validity period based on the temporal distance value; A temporary access token is constructed according to the validity period of the dynamic URL and the access permission level, and a multi-level heterogeneous consensus mechanism is used to verify the temporary access token. Consensus shards are generated based on verifiable random functions at the data layer, asynchronous message transmission across shards is implemented at the network layer, and a practical Byzantine fault tolerance protocol and proof-of-stake mechanism are integrated at the consensus layer to dynamically adjust the consensus weight.

2. The method according to claim 1, characterized in that Inputting the access time point sequence and the access duration sequence into a pre-trained long short-term memory neural network to generate a user access behavior time series feature vector; Based on the user access behavior time series feature vector, calculating the time series distance value between the URL access request and the preset normal access pattern using a dynamic time warping algorithm includes: Calculating the time interval values ​​between adjacent timestamps in the access time point sequence to generate a time interval sequence; calculating the mean and variance of the access duration based on the access duration sequence to generate a duration feature parameter; and combining the time interval sequence and the duration feature parameter to construct a time series feature input vector; Inputting the temporal feature input vector into a long short-term memory neural network, the long short-term memory neural network comprising a forget gate, an input gate, and an output gate; constructing an attention weight matrix, the attention weight matrix being used to calculate the importance of each hidden state in the hidden state sequence output by the long short-term memory neural network; inputting the hidden state sequence into the attention weight matrix to obtain a weight coefficient sequence; performing weighted summation on the hidden state sequence based on the weight coefficient sequence to generate a temporal feature vector of the user access behavior; Matching the user access behavior time series feature vector with the preset normal access pattern feature vector in feature dimensions, calculating the Euclidean distance between the matched feature vectors to obtain a local distance measurement value; and constructing a cumulative distance matrix based on the local distance measurement value; A dynamic programming method is used to search for a minimum cumulative distance path in the cumulative distance matrix, a path cost value corresponding to the minimum cumulative distance path is calculated, and the path cost value is used as a temporal distance value of the URL access request.

3. The method according to claim 2, characterized in that Searching for a minimum cumulative distance path using a dynamic programming method in the cumulative distance matrix, and calculating a path cost value corresponding to the minimum cumulative distance path includes: For each current processing position in the cumulative distance matrix, calculating a weighted sum of the cumulative distance values ​​of the adjacent positions of the current processing position and the local distance value of the current position, selecting the adjacent position with the minimum weighted sum as the optimal forward position, and recording the minimum weighted sum as the cumulative distance value of the current processing position; According to the cumulative distance matrix, backtracking is performed from the end point of the matrix in the direction of the optimal forward position to generate a minimum cumulative distance path, where the minimum cumulative distance path represents the optimal alignment relationship between the user access behavior time series feature vector and the preset normal mode feature vector; all local distance values ​​passed by the minimum cumulative distance path are weighted and summed to obtain the path cost value.

4. The method according to claim 1, wherein Constructing a temporary access token based on the validity period of the dynamic URL and the access permission level includes: Generate a token data structure based on the dynamic URL validity period and the access permission level, wherein the token data structure includes a current timestamp, the dynamic URL validity period, and the access permission level, and encode the token data structure into a temporary access token; The temporary access token is encrypted and signed to generate a token verification code, which is added to the temporary access token to obtain a final temporary access token.

5. The method according to claim 1, wherein A multi-level heterogeneous consensus mechanism is used to verify the temporary access token. Consensus shards are generated based on verifiable random functions at the data layer. Asynchronous message transmission across shards is implemented at the network layer. The consensus layer integrates a practical Byzantine fault-tolerant protocol and a proof-of-stake mechanism to dynamically adjust the consensus weight. The following are included: Receive the token verification record, consensus behavior record, and shard interaction record of the node, calculate the verification reliability index, behavior normative index, and interaction stability index based on the token verification record, the consensus behavior record, and the shard interaction record, respectively, and multiply the verification reliability index, the behavior normative index, and the interaction stability index with the corresponding dimension weights to obtain the comprehensive trust value of the node; Divide the comprehensive trust value into different consensus shards based on a verifiable random function, perform verification and evaluation on the nodes in the consensus shards, calculate the verification success rate and verification accuracy of the nodes, and generate a performance score for the nodes within the shards; Implementing cross-shard asynchronous message delivery at the network layer, calculating message priorities based on the performance scores of the source and target shards, determining the message synchronization frequency between shards based on the message priorities, and establishing a cross-shard message delivery channel; The practical Byzantine fault-tolerant protocol and the proof-of-stake mechanism are integrated, and the comprehensive trust value, the performance score and the stake amount are used as weight parameters. When the comprehensive trust value of the node changes, the consensus weight is dynamically adjusted.

6. The method according to claim 5, characterized in that Based on a verifiable random function, the comprehensive trust value is divided into different consensus shards, and the nodes in the consensus shards are verified and evaluated. The verification success rate and verification accuracy of the nodes are counted to generate the performance score of the nodes in the shards, including: The verification success rate, verification accuracy, and response time of the collected nodes are used as raw performance indicators, and the exponential sliding average algorithm is used to generate the timing performance score of the node. The timing performance score is combined with the raw performance indicators to construct the current comprehensive performance indicator of the node; Extracting a shard feature vector based on the current comprehensive performance index, using an adaptive multi-layer perceptron model to predict a shard performance change trend, and fusing the shard feature vector with the shard performance change trend to generate shard fitness; Utilizing a hierarchical verifiable random function mechanism, the node private key, the current comprehensive performance index, and the shard fitness are mapped into a deterministic random output, and a dynamic shard allocation strategy is constructed based on the deterministic random output; Node reorganization is performed according to the dynamic sharding allocation strategy, and a performance optimization model based on deep reinforcement learning is established. The performance optimization model uses the node performance gap as a reward function and outputs an optimal performance adjustment plan; the performance parameters of the node are adjusted according to the optimal performance adjustment plan, and the performance score of the node is re-evaluated.

7. The method according to claim 6, characterized in that The exponential moving average algorithm is used to generate a timing performance score for the node, and the timing performance score is combined with the original performance index to construct the current comprehensive performance index of the node, including: Collecting original performance indicators of the nodes, and performing weighted processing on the original performance indicators based on preset weights to obtain weighted performance indicators, wherein the preset weights are determined according to the importance of each performance indicator; The weighted performance index and the exponential moving average of the previous moment are combined to calculate the exponential moving average of the current moment according to the ratio of the dynamic smoothing factor, where the dynamic smoothing factor is composed of a base smoothing factor and an adjustment amount determined according to the degree of performance fluctuation; Calculate the difference between the exponential moving averages of the current moment and the previous moment to obtain a short-term performance fluctuation value. Combine the exponential moving average of the current moment and the short-term performance fluctuation value using a time series feature weight coefficient to generate a time series performance score that reflects the historical performance change trend of the node. The time series feature weight coefficient is used to balance the impact of long-term performance and short-term fluctuations. The timing performance score and the weighted performance index are combined based on the timing score weight to obtain the current comprehensive performance index of the node.

8. An electronic device, characterized in that: include: processor; a memory for storing processor-executable instructions; The processor is configured to call the instructions stored in the memory to execute the method according to any one of claims 1 to 6.

9. A computer-readable storage medium having computer program instructions stored thereon, characterized in that: When the computer program instructions are executed by a processor, the method according to any one of claims 1 to 6 is implemented.

Citation Information

Cited By

  • Private data protection method and system for industrial Internet of Things

    CN121834900A