An AI dynamic security transmission system based on a SASE framework
Patent Information
- Application Number
- CN202511180532.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-22
- Publication Date
- 2025-12-23
- Estimated Expiration
- 2045-08-22
AI Technical Summary
The existing SASE architecture lacks a targeted dynamic adjustment mechanism to meet the high bandwidth and low latency data transmission requirements of AI applications, making it difficult to balance security and transmission efficiency.
An AI-driven dynamic secure transmission system based on the SASE framework is adopted, which includes AI-driven dynamic authentication, real-time multi-dimensional risk assessment and network status prediction. By dynamically adjusting transmission parameters and encryption strategies, and combining API gateway, network status awareness, security risk assessment, dynamic transmission optimization and adaptive encryption module, the system achieves synergistic optimization of security and transmission efficiency.
It significantly improves transmission performance while ensuring data security, meets the needs of AI applications for low latency and high security, is suitable for complex scenarios such as cloud AI training, edge inference nodes and cross-regional collaboration, and is compatible with heterogeneous network environments.
Smart Images

Figure CN120811744B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The application relates to the technical field of artificial intelligence security and network security integration, and in particular to an AI dynamic security transmission system based on a SASE framework. BACKGROUND
[0002] SASE (Secure Access Service Edge) is a cloud architecture model that integrates network connection and security capabilities. Its core goal is to provide "on-demand, globally consistent" security access services for enterprises by integrating traditional dispersed network and security functions into a unified cloud platform, especially suitable for distributed office, multi-cloud collaboration and digital transformation scenarios. With the development of AI applications to the edge and cloud collaboration, and the popularity of remote work, multi-branch collaboration and other scenarios, AI application data transmission faces complex network environment challenges. Traditional security architecture is difficult to adapt to dynamically changing access locations and diverse network links, and there is a problem of difficulty in balancing security protection and transmission efficiency.
[0003] Patent No. CN109688115B discloses a data security transmission system, which is composed of a communication server, a security terminal, a security server and a communication terminal. The security terminal is located at the data outlet of the communication terminal, and is connected to the communication terminal through a special joint, and is connected to the communication server through a network interface; the security server is located at the data outlet of the information system, and is connected to the router or switch, and is bypassed between the communication server and the security terminal.
[0004] For the above and existing related technologies, the inventors believe that the following defects often exist: the SASE architecture integrates network access and security services, but it still lacks a targeted dynamic adjustment mechanism under the unique high-bandwidth, low-latency data transmission requirements of AI applications. For example, if only security encryption is focused on and transmission path optimization is ignored in real-time transmission of AI training data, it will result in high latency affecting training effectiveness; and simply pursuing transmission speed may sacrifice security, causing data leakage. SUMMARY
[0005] The technical problem to be solved by the present application is that in the prior art, when the SASE architecture integrates network access and security services, it still lacks a targeted dynamic adjustment mechanism under the unique high-bandwidth, low-latency data transmission requirements of AI applications. Therefore, we propose an AI dynamic security transmission system based on a SASE framework.
[0006] To achieve the above purpose, the following technical scheme is adopted in the present application: an AI dynamic security transmission system based on a SASE framework, comprising:
[0007] The SASE fusion access module is used for integrating network access and security functions, including identity authentication, access control and encryption tunnel establishment, adopts an AI-driven dynamic identity verification mechanism, combines user behavior characteristics, device fingerprints and real-time risk scores to generate dynamic access credentials, and realizes safe access control of the AI application node.
[0008] The API gateway module is used as a unified entrance of the system to the outside, is responsible for receiving, routing and scheduling all access requests of AI applications, and provides functions such as protocol conversion, request authentication, traffic control and log recording.
[0009] The network state perception module is used to collect key performance parameters of network links in real time through AI sensors deployed in edge nodes, and predict future network states by using time series prediction algorithms to provide real-time data support for transmission optimization.
[0010] The security risk assessment module is used to perform multi-dimensional security analysis on access devices, network environment and transmission content through AI models, including vulnerability status, threat intelligence and behavior anomaly detection, to generate a risk score of 0-10, and trigger corresponding security strategies accordingly.
[0011] The dynamic transmission optimization module is used to dynamically adjust transmission parameters according to the prediction results of the network state perception module and the scores of the security risk assessment module.
[0012] The adaptive encryption module is used to dynamically select and adjust encryption algorithm strength and data verification mechanism according to the scores of the security risk assessment module and the sensitivity level of the transmitted data.
[0013] Preferably, the system further comprises:
[0014] The transmission quality analysis module is used to perform in-depth analysis on the performance of the current transmission link according to the data collected by the network state perception module, identify transmission bottlenecks and evaluate service quality, to generate decision basis for transmission optimization.
[0015] The performance monitoring module is used to continuously monitor the running state, resource usage and transmission task execution efficiency of each module of the system, and trigger an alarm or optimization mechanism when a performance anomaly is detected.
[0016] The policy decision engine module is used to comprehensively analyze and judge the network state, transmission quality and security risk assessment results, and generate or dynamically adjust policy instructions for access control, transmission protocol and encryption strength in real time, to realize the collaborative optimization of security and transmission efficiency.
[0017] A quantum key distribution module is responsible for the generation, dynamic distribution, update and revocation lifecycle management of keys in encrypted communication to support the adaptive encryption module and ensure the forward security of communication.
[0018] Preferably, the system further comprises:
[0019] A model self-optimization module is used to continuously train and optimize AI prediction models, risk assessment models and transmission strategies in the system by using security logs and performance data accumulated during system operation.
[0020] A model vulnerability assessment module is used to assess the security vulnerabilities of the AI models being transmitted, including model leakage, reverse attack and poisoning attack risks, and provide vulnerability scores and reinforcement suggestions.
[0021] A strategy fuse module is used to monitor the system operation state and security situation in real time, and when detecting abnormal conditions such as continuous high-risk attacks, resource exhaustion or severe performance degradation, it is used to forcibly start the fuse mechanism, immediately interrupt the current connection or switch to a degraded security strategy, and automatically restore the service when the risk falls below the threshold.
[0022] A log audit module is used to comprehensively collect, aggregate and persistently store operation logs, performance indicators and security events generated by each module in the system, and provide multi-dimensional correlation analysis and traceability based on time, event type, risk level, etc. to meet the requirements of security audit, fault diagnosis and compliance.
[0023] Preferably, the SASE fusion access module specifically includes:
[0024] An identity authentication module is used to verify the authenticity of the initiator of the access request, and through the integration of multi-factor authentication, biometric identification and dynamic behavior analysis technology based on AI algorithms, it comprehensively judges the user identity, device fingerprint and real-time context information, and generates a short-term valid dynamic credential as the basis for allowing access to the system.
[0025] An access control module is used to make authorization decisions on the network resources, data or services requested by the access entity based on the pre-set security policy and dynamic risk assessment results after the identity authentication is passed, and by executing role-based or attribute-based access control rules, it ensures that the access entity can only access the resources explicitly authorized by it.
[0026] An encryption tunnel module is used to establish a secure data transmission channel between the access entity and the system, and by invoking the IPsec, TLS or QUIC protocol stack, it is responsible for the negotiation, establishment, maintenance and termination of the transmission channel, and performs end-to-end encryption and integrity protection on all data transmitted therein.
[0027] Preferably, the network state awareness module specifically comprises:
[0028] A network parameter collection module for collecting bandwidth, latency, jitter and packet loss rate key performance parameters of the transmission path in real time or periodically through the probe agent deployed in the edge node and network link, to provide original data basis for evaluating real-time transmission quality and subsequent prediction;
[0029] A node load monitoring module for continuously monitoring and collecting resource utilization state indicators of the network edge node and core processing node, including CPU utilization, memory occupancy, active connection number and throughput, to determine the current processing capacity and potential bottleneck of the node;
[0030] A network state prediction module for receiving historical and real-time time series data provided by the network parameter collection module and the node load monitoring module, and using a time series prediction algorithm to predict the network state trend in a future period, thereby providing a decision basis for the pre-adjustment of the transmission optimization strategy.
[0031] Preferably, the network state prediction module predicts the network state trend in a future period as follows:
[0032] Let S(t) be the network state prediction value in the future t minutes, and its calculation formula is:
[0033]
[0034] In the formula: S0 represents the real-time value of the network state collected at the current time, including the current bandwidth, current latency, current jitter and current node load; ΔS avg represents the average change of the network state in the past T win minutes; T win represents the historical data statistical window length; λ represents the time decay coefficient; γ represents the packet loss sensitivity coefficient; and L represents the current network packet loss rate.
[0035] Preferably, the security risk assessment module specifically comprises:
[0036] A device vulnerability analysis module for scanning and feature matching the software version, system patch status and open port service of the access terminal or AI application node, and associating with a general vulnerability disclosure database, to analyze the known security vulnerabilities existing in the device and assess the potential risk of being exploited;
[0037] A threat intelligence analysis module for receiving the source IP address, geographic location and network environment information of the access request, and querying internal and external threat intelligence feeds in real time, to determine whether the access source is in a high-risk area where botnets, malicious mining or advanced persistent threat activities are frequent;
[0038] a data sensitivity level evaluation module, configured to automatically identify and classify the type of the transmission data according to a predefined data classification strategy and content recognition algorithm before or during the data transmission, and determine the sensitivity level thereof accordingly;
[0039] a multi-dimensional risk evaluation module, configured to receive and aggregate the output results from the device vulnerability analysis module, the threat intelligence analysis module and the data sensitivity level evaluation module, generate a comprehensive quantitative security risk score through a weighted scoring model, and provide the score to the policy decision engine to trigger the corresponding dynamic security control policy.
[0040] Preferably, the multi-dimensional risk evaluation module calculates the security risk score according to the following formula:
[0041]
[0042] wherein: r i represents the standardized input value of the i-th risk dimension, the device vulnerability risk r v , the threat intelligence risk r j , and the data sensitivity risk r d ; n represents the total number of risk dimensions; ω i represents the weight coefficient of the i-th risk dimension; and ΔT is used to introduce the dynamic influence of the behavior anomaly analysis.
[0043] Preferably, the dynamic transmission optimization module specifically includes:
[0044] a transmission parameter adjustment module, configured to dynamically calculate and set the transmission window size, retransmission timeout time and sending rate parameters according to the prediction results provided by the network state perception module and the risk score output by the security risk evaluation module, so as to adapt to the network fluctuation and security condition under the premise of ensuring transmission reliability;
[0045] a transmission protocol switching module, configured to dynamically switch between QUIC, TCP and different variants of the protocols based on the judgment results of real-time network bandwidth, latency and security risk level, enable the low-latency protocol to improve the transmission efficiency when the network condition is excellent and the risk is low, and switch to the high-reliability protocol to ensure data integrity and security when the network is congested or the risk is increased;
[0046] a data verification module, configured to automatically enable the data fragmentation transmission and redundancy verification mechanism when the transmission link quality deteriorates or the security risk increases, generate a verification code for each data fragment and perform integrity verification at the receiving end, so as to ensure the accuracy of data transmission in unreliable networks or potential attack environments;
[0047] The transmission path selection module is used for analyzing state indexes and security scores of multiple selectable network paths in real time by calling a path calculation algorithm, and dynamically selecting and switching to an optimal transmission path according to requirements of current applications on latency, bandwidth and security, so as to avoid unstable links with high latency, high jitter or high risk.
[0048] Preferably, the adaptive encryption module dynamically selects an adaptive encryption algorithm according to the risk score output by the security risk assessment module and the data sensitivity level evaluation result, and the rules are as follows: when the risk score is greater than or equal to a threshold value and the data is of a core sensitive type, a high-strength encryption algorithm is selected; and when the risk score is less than the threshold value and the data is of a non-sensitive type, a lightweight encryption algorithm is selected, so as to reduce performance loss.
[0049] Technical effects and advantages of the present application:
[0050] In the present application, through deep fusion of AI-driven dynamic identity verification, real-time multi-dimensional risk assessment and network state prediction, dynamic cooperative adjustment of security policies and transmission parameters is realized, effectively solving the dilemma that security strength and transmission efficiency cannot be considered in the traditional SASE architecture, while ensuring data security and significantly improving transmission performance, especially meeting the dual requirements of low latency and high security for AI applications; the system perceives link changes and risk situations in advance by means of AI prediction capability based on real-time collected network indicators and security threat data, and actively triggers encryption strategy optimization, protocol switching and path selection and other operations, so as to fundamentally avoid performance jitter or data leakage risks caused by passive response; in addition, the system has excellent generalization ability and can be stably applied to various complex scenarios such as cloud AI training, edge reasoning nodes and cross-regional collaboration, and is widely compatible with heterogeneous network environments such as 5G, satellite communication and optical fiber, providing high-reliable, adaptive and fully-controlled data security transmission protection for various AI businesses. BRIEF DESCRIPTION OF DRAWINGS
[0051] The disclosure of the present application will be described with reference to the accompanying drawings. It should be understood that the drawings are for illustrative purposes only and are not intended to limit the scope of protection of the present application. In the drawings, the same reference numerals are used to refer to the same components:
[0052] Figure 1 FIG. 1 is a schematic diagram of the overall architecture of an AI dynamic security transmission system based on a SASE framework according to the present application;
[0053] Figure 2 FIG. 2 is a logic diagram of the AI dynamic security transmission system based on the SASE framework according to the present application;
[0054] Figure 3 FIG. 3 is a schematic diagram of a SASE fusion access module architecture of the AI dynamic security transmission system based on the SASE framework according to the present application;
[0055] Figure 4 A network state perception module architecture diagram of an AI dynamic security transmission system based on a SASE framework according to the present application;
[0056] Figure 5 A security risk assessment module architecture diagram of an AI dynamic security transmission system based on a SASE framework according to the present application;
[0057] Figure 6 A dynamic transmission optimization module architecture diagram of an AI dynamic security transmission system based on a SASE framework according to the present application;
[0058] Figure 7 A core data flow schematic diagram of an AI dynamic security transmission system based on a SASE framework according to the present application;
[0059] Figure 8 An AI-driven closed-loop schematic diagram of an AI dynamic security transmission system based on a SASE framework according to the present application. DETAILED DESCRIPTION
[0060] It is easy to understand that, according to the technical solution of the present application, a person skilled in the art can propose a plurality of structure modes and implementation modes that can be replaced with each other without changing the essential spirit of the present application. Therefore, the following specific embodiments and drawings are only exemplary descriptions of the technical solution of the present application, and should not be regarded as the whole or as the limitation or restriction of the technical solution of the present application.
[0061] REFERENCE Figure 1 - Figure 8 As shown in the drawings, the present application provides a technical solution: an AI dynamic security transmission system based on a SASE framework, comprising: a SASE fusion access module that integrates network access and security functions and adopts an AI-driven dynamic identity verification mechanism; an API gateway module as a unified entry to process access requests; a network state perception module that collects network parameters through AI sensors and predicts states; a security risk assessment module that generates a quantitative risk score; a dynamic transmission optimization module that adjusts transmission parameters; and a self-adaptive encryption module that dynamically selects encryption algorithms.
[0062] The specific idea is: first, establish a real-time network state prediction model to predict the quality change of the transmission path in advance; second, design a multi-dimensional risk assessment mechanism to quantify security threats in different dimensions; and finally, build parameter dynamic adjustment rules to automatically optimize encryption strength, transmission protocols and other elements according to environmental changes.
[0063] Access stage: The AI application node initiates an access request. The SASE converged access module first collects the device information, location information, and user identity information of the node and sends them to the security risk assessment module. The risk assessment module combines the threat intelligence library to generate an initial risk score (e.g., 3 points) and determines it as low risk. The SASE converged access module performs AI dynamic identity verification, and after verification, it establishes an encrypted tunnel (using TLS1.3).
[0064] Transmission process: The network state perception module monitors the link bandwidth in real time and finds it to be 100Mbps with a latency of 15ms. It predicts that the bandwidth will remain stable for the next 5 minutes. The dynamic transmission optimization module selects the QUIC protocol and sets the initial transmission window to 1MB. Meanwhile, the adaptive encryption module uses AES-256 encryption based on the sensitivity level (high) of the transmitted AI training data.
[0065] Dynamic adjustment: After 10 minutes, the network state perception module detects that the link bandwidth has dropped to 30Mbps and predicts that it will continue to decline. The security risk assessment module finds that the network where the access node is located has suspicious scanning behavior, and the risk score rises to 7 points. The dynamic transmission optimization module immediately switches to the TCP protocol, reduces the transmission window to 256KB, and enables data fragmentation transmission. The adaptive encryption module increases the hash chain verification mechanism and generates a verification hash for every 1KB of data.
[0066] End stage: The AI application node completes data transmission, the SASE converged access module closes the encrypted tunnel, records the security log and performance data of this transmission, and uses them to optimize the AI prediction model and risk assessment model.
[0067] SASE converged access module: Integrates network access and security functions, including identity authentication, access control, encrypted tunnel (such as IPsec, TLS1.3), etc. Uses AI-driven dynamic identity verification mechanism, combines user behavior characteristics, device fingerprint, and real-time risk score to generate dynamic access credentials. For example, for the access of AI training nodes, not only the node identity is verified, but also historical access behavior is analyzed to determine whether there are abnormalities, and whether to enable additional biometric secondary verification.
[0068] API gateway module: Provides a unified API interface for external systems (such as ITSM, SIEM) or administrators to configure, query, and manage. As the unified entrance of the system, it receives, routes, and schedules all access requests of AI applications, and provides protocol conversion, request authentication, traffic control, and log recording functions to ensure the security and controllability of API calls.
[0069] Network state perception module: Real-time collection of network link bandwidth, latency, jitter, packet loss rate and node load through AI sensors deployed on edge nodes. Time series prediction algorithms such as LSTM are used to predict future network state changes for the next 5-10 minutes, providing data support for transmission optimization.
[0070] Security risk assessment module: Based on AI model analysis of access request security risks, including access device vulnerability status, network threat intelligence (such as whether it is a high-risk IP area), data transmission content sensitivity level, etc. A multi-dimensional risk scoring model (0-10 points) is used, and when the risk score exceeds the threshold (such as 6 points), the enhanced security strategy is triggered.
[0071] Dynamic transmission optimization module: Based on the prediction results of the network state perception module and the score of the security risk assessment module, dynamically adjust the transmission parameters. When the network bandwidth is sufficient and the risk is low, use large window TCP transmission or QUIC protocol to accelerate transmission; when the network is congested or the risk is high, automatically switch to low-bandwidth encryption transmission mode, and enable data fragmentation and redundancy checking mechanism. At the same time, AI algorithm selects the optimal transmission path in real time to avoid high delay or high risk links.
[0072] Adaptive encryption module: Dynamically adjust the encryption strength according to the data sensitivity level and the security level of the transmission link. For AI model parameters and other core sensitive data, use AES-256 encryption combined with hash chain verification on high-risk links; for non-sensitive log data, lightweight encryption algorithms can be used on low-risk links to reduce performance loss.
[0073] Among them, the SASE fusion access module refers to the integration of identity authentication, access control and encrypted tunnel establishment functions, which can be implemented by multi-factor authentication and device fingerprint recognition technology, and dynamic credentials are generated by analyzing user behavior characteristics. The API gateway module refers to the request processing unit that supports protocol conversion and traffic control, which can be implemented by reverse proxy architecture, and access compliance is ensured through request authentication and routing strategy. The network state perception module refers to the data collection system deployed on the edge node, which can be implemented by distributed probes to collect bandwidth and latency parameters, and LSTM neural network is used for time series prediction. The security risk assessment module refers to a multi-dimensional threat analysis engine, which can be implemented by using vulnerability scanning tools and threat intelligence interfaces, and the risk value is output by a weighted scoring model. The dynamic transmission optimization module refers to the transmission parameter adaptive adjustment unit, which can be implemented by using congestion control algorithms to dynamically calculate window size and sending rate. The adaptive encryption module refers to the encryption strength dynamic selection component, which can be implemented by using AES and ChaCha20 algorithm library to switch encryption levels according to data sensitivity.
[0074] Specifically, the system performs dynamic identity verification through the SASE converged access module, collects device fingerprints and user operation behavior characteristics in real time when the edge device initiates a connection request, and generates dynamic credentials in combination with threat intelligence data. The API gateway module performs protocol conversion and traffic shaping on access requests to ensure standardized processing of heterogeneous request standards for different AI applications. The network state perception module continuously monitors the quality of the transmission path and uses prediction algorithms to predict the bandwidth fluctuation trend in the future period to provide decision basis for dynamic transmission optimization. The security risk assessment module scans device vulnerabilities and detects abnormal behavior during data transmission, and immediately raises the risk score when a port scanning attack is identified. The dynamic transmission optimization module adjusts the transmission window in advance and switches to a high-reliability protocol according to the predicted bandwidth decline trend to avoid latency caused by data retransmission. The adaptive encryption module automatically enables high-strength encryption algorithms when sensitive model parameters are detected during transmission, and switches to lightweight algorithms when transmitting log data.
[0075] Through the above scheme, dynamic balance between security protection and transmission efficiency is achieved. In the AI inference service invocation scenario, the system dynamically adjusts the transmission protocol according to the real-time network bandwidth prediction result to avoid inference delay caused by network congestion. In the model parameter synchronization process, a man-in-the-middle attack is identified through multi-dimensional risk assessment to trigger encryption strength upgrade to prevent parameter leakage. In the low-risk data distribution, lightweight encryption is used to reduce the occupation of computing resources to ensure the transmission throughput in high-concurrency scenarios.
[0076] Referring to Figure 1 In the embodiment, the application further proposes a transmission quality analysis module, a performance monitoring module, a policy decision engine module, and a quantum key distribution module.
[0077] The transmission quality analysis module is configured to perform in-depth analysis on the performance of the current transmission link according to the data collected by the network state perception module, identify transmission bottlenecks and evaluate service quality to generate decision basis for transmission optimization;
[0078] The performance monitoring module is configured to continuously monitor the running state, resource usage, and execution efficiency of each module of the system, and trigger an alarm or optimization mechanism when a performance anomaly is detected;
[0079] The policy decision engine module is configured to comprehensively analyze and judge the network state, transmission quality, and security risk assessment results, and generate or dynamically adjust policy instructions for access control, transmission protocol, and encryption strength in real time to achieve coordinated optimization of security and transmission efficiency;
[0080] The quantum key distribution module is configured to be responsible for the generation, dynamic distribution, update, and revocation lifecycle management of keys in encrypted communication to support the adaptive encryption module and ensure the forward security of communication.
[0081] The transmission quality analysis module refers to a component for deep analysis of transmission link performance, which can be implemented by combining a data packet capture technology with a network probe, and by analyzing bandwidth utilization, time delay distribution and packet loss mode, a network congestion point or a device performance bottleneck can be identified. The performance monitoring module refers to a component for continuously tracking system resource status, which can be implemented by combining a resource monitoring agent with an abnormality detection algorithm, and by collecting CPU load rate, memory occupancy rate and thread blocking state, potential system-level faults can be predicted. The strategy decision engine module refers to a component for executing multi-dimensional strategy optimization, which can be implemented by a dynamic decision model based on reinforcement learning, and by fusing network status indicators, security risk scores and transmission quality data, a coordinated control instruction considering both security and efficiency can be generated. The quantum key distribution module refers to a component for implementing quantum attack-resistant key management, which can be implemented by combining the BB84 protocol with a post-quantum cryptographic algorithm, and by dynamically generating non-reproducible quantum keys, the forward security of encrypted communication can be ensured.
[0082] Specifically, the transmission quality analysis module performs feature extraction and correlation analysis on the raw data collected by the network state perception module, for example, a sudden time delay event is associated with the CPU overload state of a specific edge node to identify a transmission bottleneck caused by insufficient computing resources. The performance monitoring module polls the running state data of each module, and when it detects that the memory occupancy rate continuously exceeds the set threshold, it triggers a resource recycling mechanism or a load balancing operation. The strategy decision engine module dynamically adjusts the encryption algorithm strength and transmission protocol type according to real-time network bandwidth fluctuations, data sensitivity levels and threat intelligence scores, for example, when the network bandwidth drops to a critical value, the encryption strength of non-sensitive data is downgraded from AES-256 to AES-128 to improve transmission efficiency. The quantum key distribution module works cooperatively with the quantum channel and the classical channel, regularly updates the session key and destroys the expired key to prevent historical communication from being cracked by quantum computing.
[0083] Through the above scheme, the problem of insufficient transmission quality monitoring granularity in a dynamic network environment is solved, and the transmission bottleneck caused by device performance or link quality can be accurately located; the passive response defect of traditional system performance monitoring is overcome, and early warning of resource leakage or overload risk is realized; the static binding relationship between security policy and transmission efficiency is broken, and the optimal balance between the two is realized through a dynamic decision model; at the same time, through the quantum-resistant key management mechanism, the long-term threat of quantum computing to the encryption system is effectively prevented.
[0084] The application further proposes a combination scheme of a model self-optimization module, a model vulnerability evaluation module, a strategy fuse module and a log audit module.
[0085] A model self-optimization module for continuously training and optimizing AI prediction models, risk assessment models, and transmission strategies in the system using security logs and performance data accumulated during system operation;
[0086] A model vulnerability assessment module for specifically assessing the security vulnerabilities of the transmitted AI models, including model leakage, reverse attack, and poisoning attack risks, and providing vulnerability scores and reinforcement suggestions;
[0087] A strategy fuse module for real-time monitoring of system operation status and security posture, and for forcibly starting a fuse mechanism, immediately interrupting the current connection or switching to a degraded security strategy when detecting abnormal conditions such as continuous high-risk attacks, resource exhaustion, or severe performance degradation, and for automatically restoring services when the risk falls below the threshold;
[0088] A log audit module for comprehensively collecting, aggregating, and persistently storing operation logs, performance indicators, and security events generated by each module in the system, and providing multi-dimensional correlation analysis and traceability based on time, event type, risk level, to meet security audit, fault diagnosis, and compliance requirements.
[0089] The model self-optimization module refers to a functional module that uses security logs and performance data generated during system operation to iteratively update AI prediction models and risk assessment models through machine learning algorithms. It can be implemented using an incremental learning framework combined with an online training mechanism, for example, by inputting abnormal events in historical transmission logs into the risk assessment model as training samples to dynamically adjust model parameters. The model vulnerability assessment module refers to a specialized analysis module for detecting security vulnerabilities in transmitted AI model files. It can be implemented using static code analysis combined with dynamic sandbox testing techniques, for example, by decompiling the model structure to detect potential backdoor code or by injecting abnormal input data to observe model output to determine attack resistance. The strategy fuse module refers to a security control module that triggers emergency responses based on pre-set threshold conditions. It can be implemented using a sliding window statistics and multi-index linkage judgment mechanism, for example, by triggering a fuse action when CPU utilization exceeds 90% for 5 minutes and risk score is higher than 8. The log audit module refers to a component that implements full operation record storage and structured analysis. It can be implemented using a distributed log collection framework combined with time series database technology, for example, by collecting node logs using Flume and storing them in Elasticsearch to establish indexes.
[0090] Specifically, the model self-optimization module acquires real-time operational data from the network state awareness module and the security risk assessment module to construct an online training dataset. It then uses an incremental gradient descent algorithm to update the weight parameters of the risk assessment model, enabling it to adapt to changes in new attack patterns. The model vulnerability assessment module performs a static structure scan before AI model transmission to detect unencrypted sensitive parameters or reversible model structures. It also injects noisy data through simulated poisoning attacks to assess model robustness and generate hardening suggestions. The policy circuit breaker module employs a dual-threshold detection mechanism. When system resource utilization exceeds a hard threshold or the security risk score breaks through a critical value, it immediately terminates the current high-risk connection and switches to a basic encryption protocol, while simultaneously initiating a resource reclamation process to release occupied computing resources. The log auditing module establishes a timestamp-based event correlation model, aggregating and recombining operation logs scattered across edge nodes by transaction ID to form a complete operation chain for auditors to trace.
[0091] The above solution achieves full lifecycle security protection for AI model transmission. It can automatically generate reinforcement solutions when model leakage risks are detected, complete service degradation switching within 300 milliseconds in the event of a DDoS attack, and provide complete operation log records that can be traced back 180 days, meeting the audit requirements of critical information infrastructure.
[0092] Reference Figure 1 and Figure 3 As shown in this implementation scheme: This application further proposes a SASE converged access module, including an identity authentication module, an access control module, and an encrypted tunnel module.
[0093] The identity authentication module verifies user identity through multi-factor authentication and AI dynamic behavior analysis technology. Specifically, it integrates fingerprint recognition, dynamic SMS verification codes, and user behavior pattern analysis algorithms to generate time-sensitive dynamic access credentials to mitigate the risk of credential theft. The access control module employs a role- and attribute-based dual-constraint authorization decision mechanism. This is achieved through a policy engine that real-time analyzes user role tags and environmental risk indicators in resource access requests, enabling fine-grained access control in dynamic network environments. The encrypted tunnel module is a secure channel establishment unit supporting multiple protocol stack calls. It automatically matches IPsec, TLS, or QUIC protocol stacks using protocol negotiation algorithms, optimizing encrypted transmission efficiency based on network conditions.
[0094] Specifically, the identity authentication module collects device fingerprint data and user interaction behavior characteristics, uses a machine learning model to detect abnormal login patterns, and generates dynamic credentials with a validity period of 5-30 minutes. The access control module dynamically adjusts the access permission range after authentication, for example, when it detects that the access device has an unpatched vulnerability, it automatically restricts its access to sensitive data. The encryption tunnel module prioritizes network delay and bandwidth conditions when establishing a connection, enabling the multiplexing mechanism of the QUIC protocol in low-delay scenarios, and switching to the strong encryption mode of the IPsec protocol in high-security demand scenarios.
[0095] The scheme blocks credential reuse attacks through a dynamic credential generation mechanism, dynamically shrinks access permissions through real-time risk assessment, and dynamically balances encryption strength and transmission performance through protocol stack intelligent switching. Through the above scheme, the present application solves the problem of easy theft of identity authentication credentials in a dynamic network environment, implements fine-grained access control based on real-time risk assessment, and simultaneously reduces transmission delay under the premise of ensuring end-to-end data security through an adaptive encryption protocol selection mechanism.
[0096] Referring to Figure 1 and Figure 4 In the present embodiment, the present application further proposes a network state awareness module, including a network parameter acquisition module, a node load monitoring module, and a network state prediction module.
[0097] The network parameter acquisition module is a component that acquires transmission path performance parameters in real time through probe agents deployed in edge nodes and network links, and can be implemented by combining active probing and passive listening, and is used to obtain bandwidth, delay, jitter, and packet loss rate, etc. bottom layer indicators that directly affect transmission quality. The node load monitoring module is a component that continuously monitors the resource utilization state of network nodes, and can collect CPU utilization, memory occupancy, and throughput indicators through operating system interfaces or hardware performance counters, and is used to identify node processing capacity bottlenecks to avoid transmission interruption. The network state prediction module is a component that predicts future network trends based on time series data, and can use LSTM neural networks or ARIMA algorithms to process historical and real-time data, and is used to establish a dynamic network model to predict bandwidth fluctuations and delay surges.
[0098] Specifically, the network parameter collection module periodically acquires real-time performance data of the transmission path through the probe agents distributed in the physical link, providing original data basis for subsequent analysis. The node load monitoring module synchronously acquires resource usage indicators of the edge node and the core node, and judges whether the node is in an overload state by associating CPU utilization and active connection number. After receiving the above two types of data, the network state prediction module uses a time series prediction algorithm to mine patterns from historical data, and generates network state trend prediction values in the future period in combination with real-time data. For example, when it is predicted that the bandwidth of a specific link will decrease in the next 5 minutes, the transmission optimization module can switch to a backup path in advance. Thus, a closed-loop processing flow is formed from data collection, state analysis to trend prediction, enabling the transmission strategy adjustment to be proactive.
[0099] Compared with the prior art, the traditional scheme usually only relies on static monitoring data of a single node, cannot predict network state changes, and leads to lag in transmission parameter adjustment. The scheme can realize all-link data acquisition by deploying multi-dimensional probe agents, can identify bandwidth fluctuations and node overload risks in advance in combination with node resource monitoring and prediction algorithms, and enables the transmission optimization strategy to have an active adaptive capability.
[0100] Through the above scheme, the application solves the problem of low transmission efficiency caused by dynamic changes in the network environment in the traditional architecture, and provides accurate decision-making basis for dynamically adjusting the transmission window size, retransmission timeout time and path selection by real-time sensing of link performance and node load and predicting future state trends, thereby maintaining the balance between transmission reliability and efficiency in a complex network environment.
[0101] The application further proposes a prediction calculation method of the network state prediction module for the network state trend in a future period, specifically:
[0102] Let the network state prediction value S(t) in the future t minutes (5≤t≤10) be represented by bandwidth, delay, etc. The calculation formula is:
[0103]
[0104] In the formula, S0 represents the real-time value of the network state collected at the current time (such as the current bandwidth, the current delay), which can be realized by real-time collection of bandwidth, delay, jitter and node load data by sensors deployed in the edge node, and is used to reflect the instantaneous state of the network environment and provide a real-time observation benchmark for the prediction model; ΔS avg represents the average change amount of the network state in the past T win minutes (a positive value represents an increase, and a negative value represents a decrease), which can be specifically calculated by a sliding window algorithm. winthe change trend of the bandwidth, the time delay, and the like within a minute, for capturing the periodic fluctuation law of the network state; win represents the historical data statistical window length (unit: minute), which can be set as a configurable parameter of 5-15 minutes according to the stability of the network environment, for balancing the sensitivity of the prediction model to short-term fluctuations and long-term trends; λ represents a time decay coefficient (0<λ<1), for weakening the influence of long-term historical data on prediction, which can be realized by dynamically weighting the influence of the historical change amount through an exponential decay function, for making the recent network state change have a greater influence on the prediction result; γ represents a packet loss sensitivity coefficient (γ>0), reflecting the accelerating effect of the packet loss rate on the network state deterioration, which can be set as an adjustable parameter of 0.1-0.5 according to the network type and application demand, for quantifying the nonlinear influence of the packet loss rate on the transmission quality; and L represents the current network packet loss rate (value range 0≤L≤1), which can be realized by statistically calculating the packet loss proportion within a unit time, for reflecting the reliability state of the network link.
[0105] Specifically, the prediction model collects bandwidth, time delay, jitter, and node load data as basic observation values in real time, combines the historical change trend statistically calculated by the sliding window, and constructs a dynamic prediction function. In the calculation process, the time decay coefficient exponentially weights the historical change amount, so that the prediction result is closer to the change direction of the current network state. At the same time, the product term of the packet loss sensitivity coefficient and the real-time packet loss rate is introduced into the prediction formula, for quantifying the cumulative influence of packet loss on the transmission path quality. For example, when the network packet loss rate continuously increases, the prediction model will automatically increase the state prediction value of the future period, triggering the transmission path switching or protocol adjustment operation in advance. Thus, the model can fuse real-time observation data, historical trends, and dynamic factors of packet loss to generate network state prediction results with real-time response capability and trend predictability.
[0106] The scheme constructs a complex prediction model containing a time decay factor and a packet loss sensitivity, which not only reflects the network state in real time, but also predicts the future change trend based on historical data. This forward-looking prediction mechanism enables the transmission optimization module to actively adjust the transmission parameters before the network performance deteriorates, avoiding transmission interruption or efficiency reduction caused by decision lag. Through the above scheme, the present application solves the transmission optimization lag problem caused by the lack of dynamic prediction in the prior art. Specifically, when the network state gradually deteriorates, the prediction model can identify the bandwidth decrease or time delay increase trend in advance, triggering the transmission path switching or protocol optimization operation; in the high packet loss rate scenario, the model accurately quantifies the cumulative influence of packet loss on the transmission quality through weighted calculation of the sensitivity coefficient, driving the early use of the data verification mechanism or the redundant transmission strategy. Thus, the system can complete the transmission parameter adjustment before the network fluctuation occurs, ensuring the continuity and efficiency of AI application data transmission.
[0107] Referring to Figure 1 and Figure 5 As shown in the embodiment: the application further proposes a security risk assessment module, including a device vulnerability analysis module, a threat intelligence analysis module, a data sensitivity level assessment module and a multi-dimensional risk assessment module. The device vulnerability analysis module is used to scan the software features of the access terminal and match with the vulnerability database, the threat intelligence analysis module is used to query the threat intelligence data of the access source, the data sensitivity level assessment module is used to identify the transmission data classification, and the multi-dimensional risk assessment module is used to aggregate three types of risk factors to generate a quantitative score.
[0108] The device vulnerability analysis module is used to scan and match the software version, system patch status and open port service of the access terminal or AI application node, and associate with the common vulnerability disclosure (CVE) database, to analyze the known security vulnerabilities existing in the device and evaluate the potential risk of being exploited.
[0109] The threat intelligence analysis module is used to receive the source IP address, geographic location and network environment information of the access request, and query the internal and external threat intelligence feeds in real time, to determine whether the access source is in a high-risk area with frequent activities of botnet, malicious mining or advanced persistent threat (APT).
[0110] The data sensitivity level assessment module is used to automatically identify and classify the type of transmission data (such as model parameters, training data, personal identification information) according to the pre-defined data classification strategy and content recognition algorithm before or during data transmission, and determine its sensitivity level accordingly.
[0111] The multi-dimensional risk assessment module is used to receive and aggregate the output results from the device vulnerability analysis module, the threat intelligence analysis module and the data sensitivity level assessment module, generate a comprehensive quantitative security risk score through a weighted scoring model, and provide the score to the policy decision engine to trigger the corresponding dynamic security control policy.
[0112] The device vulnerability analysis module refers to a technical component that actively scans the device system version, patch status and open port, and performs feature matching with the general vulnerability disclosure database. It can be implemented by combining a vulnerability scanning engine with a CVE database query interface, and is used to identify known security vulnerabilities and potential exploitation risks of the device. The threat intelligence analysis module refers to a technical unit that queries internal and external threat intelligence sources in real time based on the source IP address and network environment information of the access request. It can be implemented by combining a threat intelligence subscription service with an IP reputation scoring system, and is used to determine whether the access source is in a high-risk area of malicious activity. The data sensitivity level evaluation module refers to a processing unit that automatically identifies the transmission content based on predefined classification strategies. It can be implemented by combining natural language processing algorithms with regular expression matching, and is used to dynamically determine the sensitivity of the data. The multi-dimensional risk assessment module refers to a processing engine that calculates the weighted sum of device vulnerabilities, threat intelligence and data sensitivity. It can be implemented by combining a linear weighting model with a dynamic weight adjustment algorithm, and is used to generate a quantitative score that triggers security policies.
[0113] Specifically, the device vulnerability analysis module identifies unpatched high-risk vulnerabilities by actively scanning device features. For example, if an access device is detected to have an unpatched Apache Log4j vulnerability, a corresponding vulnerability risk value will be generated. The threat intelligence analysis module queries threat intelligence sources in real time. When it is found that the access source IP is marked as a botnet control node, the threat intelligence risk score will be increased. The data sensitivity level evaluation module identifies personal privacy data during transmission and automatically classifies it as core sensitive data. The multi-dimensional risk assessment module inputs the above three types of risk values into a weighted model. For example, when the device vulnerability risk weight is set to 0.5, the threat intelligence risk is 0.3, and the data sensitivity is 0.2, the risk score is calculated and transmitted to the policy decision engine to trigger encryption strength adjustment or access control policies.
[0114] The scheme fuses three types of heterogeneous data sources, including device state, real-time threat intelligence and data content sensitivity, to construct a multi-dimensional risk assessment system. For example, when a vulnerability is detected in an access device but the transmitted data is of a non-sensitive type, the overuse of high security policies can be avoided to prevent resource waste. When core data is being transmitted, strict protection is maintained even if the device risk is low, thereby achieving precise adaptation of security control policies. Through the above scheme, the problem of single risk assessment dimension in traditional security architecture is solved, and dynamic risk quantitative assessment is achieved. The device vulnerability analysis module actively identifies known vulnerabilities, avoiding the lag of traditional passive defense. The threat intelligence analysis module integrates real-time threat data, breaking through the update bottleneck of static rule library. The data sensitivity evaluation module automatically classifies data, replacing the inefficient mode of manual annotation. The multi-dimensional risk assessment module generates a dynamic score through a weighting model, enabling security policies to accurately match the actual risk level. For example, when transmitting medical image data and detecting suspicious activities in the access source, high-strength encryption and path switching strategies are automatically triggered to ensure security while avoiding excessive resource consumption.
[0115] The application further proposes a formula for calculating the security risk score of the multi-dimensional risk assessment module, which is:
[0116]
[0117] In the formula, r i represents the standardized input value of the i-th risk dimension, the device vulnerability risk r v , the threat intelligence risk r j , the data sensitivity risk r d , (for example, the device vulnerability risk r v , the threat intelligence risk r j , the data sensitivity risk rd, etc.), the value range of each r i is [0, 1]; n represents the total number of risk dimensions; ω i represents the weight coefficient of the i-th risk dimension; ΔT is used to introduce the dynamic influence of behavior anomaly analysis, and its value is determined by another function:
[0118] ΔT = 2·tanh(α·(T-β))
[0119] T: the original anomaly score output by the behavior anomaly analysis module (without a fixed range).
[0120] β: behavior anomaly threshold. When the behavior is normal (T < β), (T-β) is negative, ΔT is negative, and the basic risk score is deducted, reflecting that "trusted behavior can reduce overall risk".
[0121] Alpha: abnormal modulation sensitivity. When abnormal behavior is detected (T > beta), (T-beta) is positive, delta T is positive, the basic risk score is increased, and the "abnormal behavior significantly amplifies the overall risk" is reflected.
[0122] wherein the standardized input value r i refers to converting risk indicators of different dimensions into numerical values of a unified dimension, which can be realized by normalization processing or range standardization method, so that the device vulnerability score, threat intelligence score and data sensitivity score can be superimposed and calculated. The weight coefficient ω i refers to the importance parameter allocated to different risk dimensions according to the actual application scene, which can be realized by dynamic adjustment algorithm based on analytic hierarchy process or entropy weight method to adapt to the influence of network environment change on risk dimension priority. The dynamic influence parameter delta T is a dynamic correction term generated by real-time behavior anomaly detection result, which can be realized by sliding window statistics or time series based anomaly detection model, and is used to reflect the immediate influence of sudden security events on risk score.
[0123] Specifically, the device vulnerability risk r v is generated by scanning the software version, patch status and open port service of the access device, and matching with the vulnerability database; the threat intelligence risk r j is generated by querying the IP address and geographic location of the access source, and identifying high-risk areas after associating with the threat intelligence library; and the data sensitivity risk r d is generated by classifying the transmission data type by content recognition algorithm, and generating standardized score according to predefined strategy. The weight coefficient ω i of each risk dimension is adjusted dynamically according to the network environment, for example, the weight of threat intelligence is increased during the period of high incidence of network attacks, and the weight of data sensitivity is increased during the peak period of data transmission. The dynamic influence parameter delta T is automatically increased by real-time monitoring of user behavior mode, and when abnormal login frequency or abnormal data transmission behavior is detected, the risk score correction amount is automatically increased. Through the combination of weighted summation and dynamic correction, discrete risk indicators are aggregated into a single quantitative score, which provides accurate basis for security policy adjustment.
[0124] The scheme can adjust the risk assessment model according to the real-time network state and security situation by combining the dynamic weight coefficient and the behavior anomaly dynamic correction term, and improve the response speed and assessment accuracy of unknown threats. Through the above scheme, the problems of single risk assessment dimension and inflexible static weight distribution in traditional methods are solved, and dynamic comprehensive assessment of multi-dimensional security risk is realized. By combining standardized input values and dynamic weights, risk indicators of different dimensions are effectively integrated, avoiding evaluation bias caused by heterogeneous data; by introducing a behavior anomaly dynamic influence parameter, the impact of sudden security events on the overall risk level can be reflected in a timely manner, overcoming the defect of static model response lag. The scheme enables security policy adjustment to accurately match the real-time risk level, ensuring comprehensive assessment while improving policy execution efficiency.
[0125] Referring to Figure 1 and Figure 6 , in the embodiment, the application further proposes a dynamic transmission optimization module, including a transmission parameter adjustment module, a transmission protocol switching module, a data verification module, and a transmission path selection module.
[0126] The transmission parameter adjustment module is configured to dynamically calculate and set the transmission window size, retransmission timeout time, and sending rate parameters based on the prediction results provided by the network state perception module and the risk score output by the security risk assessment module, to adapt to network fluctuations and security conditions while ensuring transmission reliability.
[0127] The transmission protocol switching module is configured to dynamically switch between QUIC, TCP and different variants of the protocols based on the judgment results of real-time network bandwidth, latency and security risk level, and enable low-latency protocols when network conditions are good and risk is low to improve transmission efficiency, and switch to high-reliability protocols when network congestion or risk increases to ensure data integrity and security.
[0128] The data verification module is configured to automatically enable data fragmentation transmission and redundancy verification mechanism when the transmission link quality deteriorates or the security risk increases, generate a check code for each data fragment and perform integrity verification at the receiving end to ensure the accuracy of data transmission in unreliable networks or potential attack environments.
[0129] The transmission path selection module is configured to analyze the state indicators and security scores of multiple selectable network paths in real time by calling a path calculation algorithm, and dynamically select and switch to the optimal transmission path according to the current application's requirements for latency, bandwidth and security, to avoid unstable links with high latency, high jitter or high risk.
[0130] The transmission parameter adjustment module refers to a component for dynamically setting transmission parameters according to a network state prediction result and a security risk score, and can be specifically implemented by using a TCP congestion control algorithm and a sliding window mechanism, and the sending window size is adjusted by real-time calculation of the bandwidth delay product, so as to improve the transmission efficiency on the premise of ensuring reliability. The transmission protocol switching module refers to a component for selecting a transmission protocol according to network conditions and security levels, and can be specifically implemented by using protocol stack hot switching technology, for example, automatically switching from the QUIC protocol to the TCP BBR protocol when network jitter is detected to exceed a threshold, to ensure transmission stability in a high packet loss environment. The data verification module refers to a component for implementing a fragmentation verification mechanism, which can be specifically implemented by using Reed-Solomon error correction code technology, and the data is fragmented and then a redundant verification block is attached, and the lost fragments are recovered at the receiving end through a verification matrix, to enhance the data integrity in an unstable link. The transmission path selection module refers to a component for dynamically selecting an optimal transmission path, which can be specifically implemented by using a multi-constraint shortest path algorithm, for example, combining the Dijkstra algorithm and a security score matrix to calculate the weighted optimal path of delay, bandwidth and security factor.
[0131] Specifically, the network state perception module collects link quality indicators every 5 seconds, and the security risk assessment module updates the risk score every 30 seconds. The transmission parameter adjustment module calculates the upper limit of the sending rate according to the bandwidth prediction value and the security score, for example, when the risk score exceeds 6 points, the sending window is automatically reduced to reduce the data exposure risk. The transmission protocol switching module continuously monitors the end-to-end delay, and when the round-trip time is detected to exceed 200 ms and the security score is less than 4 points, it automatically switches from the TCP Cubic protocol to the QUIC protocol to reduce the header overhead. The data verification module activates the redundancy verification when the link packet loss rate exceeds 2%, and each data packet is divided into 8 fragments and 2 redundant fragments are attached. The transmission path selection module performs path reevaluation every hour, and when it is detected that a certain path has a security score less than 5 points for 3 consecutive times, it is removed from the selectable path list.
[0132] Through the above scheme, the dynamic cooperation of transmission parameters and security strategies is realized. When the network bandwidth fluctuation exceeds 20%, the transmission parameter adjustment module can complete the window size reconfiguration within 1 second, avoiding data retransmission caused by sudden congestion. When the security score suddenly rises to 8 points due to a DDoS attack, the system automatically enables the fragmentation verification mechanism and switches to a high-reliability transmission path, reducing the service interruption time during the attack from 15 minutes in the traditional scheme to 30 seconds. For the common link instability problem in edge computing scenarios, the data verification module can ensure that the data integrity rate is maintained at 99.9% in a 10% packet loss rate environment, which is 15% higher than the traditional CRC verification.
[0133] The application further proposes that the adaptive encryption module dynamically selects an adaptive encryption algorithm according to the risk score output by the security risk assessment module and the data sensitivity level evaluation result, selects a high-strength encryption algorithm when the risk score is greater than or equal to a threshold value and the data is of a core sensitive type, and selects a lightweight encryption algorithm when the risk score is less than the threshold value and the data is of a non-sensitive type.
[0134] The risk score output by the security risk assessment module refers to a 0-10 quantized evaluation value generated by an AI model for multi-dimensional security analysis of device vulnerabilities, threat intelligence, and behavior anomalies, and can be specifically implemented by using an algorithm based on a weighted scoring model, and is used to reflect the comprehensive security situation of the current network environment. The data sensitivity level evaluation result refers to a judgment result of the value of the transmission data and the impact of the leakage according to a pre-defined classification strategy, and can be specifically implemented by using an automatic classification mechanism based on a content recognition algorithm, and is used to measure the security protection needs of the data itself. The high-strength encryption algorithm refers to an encryption method with a long key length and a complex operation process, and can be specifically implemented by using AES-256 or the national standard SM4 algorithm, and is used to provide the highest level of security protection when core sensitive data is transmitted. The lightweight encryption algorithm refers to an encryption method with low computational resource consumption, and can be specifically implemented by using ChaCha20 or AES-128 algorithm, and is used to balance security and transmission efficiency in a low-risk scenario.
[0135] Specifically, the encryption strength is dynamically adapted by establishing a dual evaluation mechanism of security risk and data sensitivity. When the security risk score exceeds a pre-set threshold value and the transmission data is judged to be of a core sensitive type, the system automatically calls a high-strength encryption algorithm, and increases the key length and the number of encryption rounds to improve the attack resistance; when the risk score is lower than the threshold value and the data is classified as a non-sensitive type, the system switches to a lightweight encryption algorithm, and simplifies the encryption operation process to reduce the computational overhead. This dynamic adjustment mechanism is based on real-time security situation and data value evaluation results, and establishes a quantitative correlation rule between encryption strength and transmission efficiency, to ensure that the security protection needs and resource consumption in different scenarios are optimally balanced.
[0136] The combination of the dual evaluation mechanism and the dynamic switching rule effectively solves the problem of resource waste caused by static encryption strategies, and avoids the mismatch between protection strength and data value that may be caused by a single risk evaluation dimension. Through the above scheme, real-time optimization of security protection and transmission efficiency can be achieved in the process of AI application data transmission. When core sensitive data is transmitted in a high-risk network environment, the system automatically enhances the encryption strength to resist potential attacks; when ordinary data is transmitted in a low-risk scenario, the system reduces the encryption strength to improve the transmission speed. This dynamic adjustment mechanism not only avoids the transmission delay caused by excessive encryption, but also prevents the data leakage risk caused by insufficient encryption, so that the configuration of encryption resources accurately matches the actual security needs.
[0137] The technical scope of the present application is not limited to the above-described embodiments, and various modifications and changes can be made to the above-described embodiments without departing from the technical idea of the present application, and these modifications and changes should be included in the scope of the present application.
Claims
1. An AI dynamic security transmission system based on a SASE framework, characterized in that, Comprise: SASE fusion access module, for responsible for the integration of network access and security functions, including identity authentication, access control and encryption tunnel establishment, using AI-driven dynamic identity verification mechanism, combined with user behavior characteristics, device fingerprint and real-time risk score to generate dynamic access credentials, realize the security access control of AI application node; API gateway module, for as the unified entrance of the system, responsible for receiving, routing and scheduling all access requests of AI application, while providing protocol conversion, request authentication, traffic control and log recording; Network state perception module, for real-time collection of key performance parameters of network link by AI sensors deployed in edge nodes, and prediction of future network state by time series prediction algorithm, providing real-time data support for transmission optimization; Security risk assessment module, for multi-dimensional security analysis of access devices, network environment and transmission content by AI model, including vulnerability status, threat intelligence, behavior anomaly detection, generating 0-10 risk score, and triggering corresponding security policy accordingly; Dynamic transmission optimization module, for dynamically adjusting transmission parameters according to the prediction results of network state perception module and the score of security risk assessment module; Adaptive encryption module, for dynamically selecting and adjusting encryption algorithm strength and data verification mechanism according to the score of the security risk assessment module and the sensitivity level of the transmitted data; The network state perception module specifically comprises: Network parameter collection module, for real-time or periodic collection of bandwidth, delay, jitter and packet loss rate key performance parameters of transmission path by deploying probe agents in edge nodes and network links, providing original data basis for evaluating real-time transmission quality and subsequent prediction; Node load monitoring module, for continuously monitoring and collecting resource utilization state indicators of network edge nodes and core processing nodes, including CPU utilization, memory occupancy, active connection number and throughput, to judge the current processing capacity and potential bottleneck of the node; Network state prediction module, for receiving historical and real-time time series data provided by the network parameter collection module and node load monitoring module, and using time series prediction algorithm to predict the network state trend in the future period, thereby providing decision basis for pre-adjustment of transmission optimization strategy; The network state prediction module predicts the network state trend in the future period as follows: Let the network state prediction value in the future t minutes be S(t), and its calculation formula is: In the formula, S0 represents the real-time value of the network state collected at the current moment, including the current bandwidth, current delay, current jitter and current node load; ΔS avg represents the average change amount of the network state in the past T win minutes; T win represents the historical data statistical window length; λ represents the time decay coefficient; γ represents the packet loss sensitivity coefficient; and L represents the current network packet loss rate. The security risk assessment module specifically comprises: Device vulnerability analysis module, for scanning and feature matching of software version, system patch status and open port service of access terminal or AI application node, and associating with general vulnerability disclosure database, to analyze known security vulnerabilities of the device and evaluate the potential risk of being exploited; The threat intelligence analysis module is configured to receive the source IP address, geographical location, and network environment information of the access request, and query internal and external threat intelligence feeds in real time to determine whether the access source is in a high-risk area where botnets, malicious mining, or advanced persistent threat activities frequently occur; The data sensitivity level evaluation module is configured to automatically identify and classify the type of the transmission data according to a predefined data classification strategy and a content recognition algorithm before or during data transmission, and determine the sensitivity level of the transmission data according to the identification and classification; The multi-dimensional risk evaluation module is configured to receive and aggregate the output results from the device vulnerability analysis module, the threat intelligence analysis module, and the data sensitivity level evaluation module, generate a comprehensive quantitative security risk score through a weighted scoring model, and provide the score to the policy decision engine to trigger a corresponding dynamic security control policy; The formula for calculating the security risk score by the multi-dimensional risk evaluation module is as follows: wherein: r i represents the standardized input value of the i-th risk dimension, the device vulnerability risk r v , the threat intelligence risk r j , the data sensitivity risk r d ; n represents the total number of risk dimensions; ω i represents the weight coefficient of the i-th risk dimension; and ΔT is used to introduce the dynamic influence of the behavior anomaly analysis.
2. The SASE framework based AI dynamic security transport system according to claim 1, wherein: The system further comprises: The transmission quality analysis module is configured to analyze the performance of the current transmission link in depth according to the data collected by the network state perception module, identify transmission bottlenecks, and evaluate the quality of service to generate decision basis for transmission optimization; The performance monitoring module is configured to continuously monitor the running state, resource usage, and execution efficiency of the transmission task of each module of the system, and trigger an alarm or an optimization mechanism when a performance anomaly is detected; The policy decision engine module is configured to comprehensively analyze the network state, transmission quality, and security risk evaluation results, generate or dynamically adjust policy instructions for access control, transmission protocol, and encryption strength in real time to achieve the coordinated optimization of security and transmission efficiency; The quantum key distribution module is configured to be responsible for the generation, dynamic distribution, update, and lifecycle management of the key in encrypted communication to support the adaptive encryption module and ensure the forward security of the communication.
3. The SASE framework based AI dynamic security transport system of claim 2, wherein: The system further comprises: The model self-optimization module is configured to continuously train and optimize the AI prediction model, risk evaluation model, and transmission strategy in the system by using the security logs and performance data accumulated during system operation; The model vulnerability evaluation module is configured to evaluate the security vulnerability of the AI model itself, including the risk of model leakage, reverse attack, and poisoning attack, and provide vulnerability score and reinforcement suggestions; The policy fuse module is configured to monitor the system running state and security situation in real time, and when detecting abnormal conditions such as continuous high-risk attacks, resource exhaustion, or severe performance degradation, forcibly start the fuse mechanism to immediately interrupt the current connection or switch to a degraded security policy, and automatically restore the service when the risk falls below the threshold; The log audit module is configured to comprehensively collect, aggregate, and persistently store the running logs, performance indicators, and security events generated by each module of the system, and provide multi-dimensional correlation analysis and traceability based on time, event type, risk level, etc., to meet the requirements of security audit, fault diagnosis, and compliance.
4. The SASE framework based AI dynamic security transport system of claim 1, wherein: The SASE fusion access module specifically comprises: An identity authentication module is configured to verify the authenticity of the initiator of the access request, to comprehensively judge the user identity, device fingerprint and real-time context information by integrating multi-factor authentication, biometric identification and dynamic behavior analysis technology based on AI algorithm, and to generate a short-term valid dynamic credential as the basis for allowing access to the system; An access control module is configured to make authorization decisions on the network resources, data or services requested to be accessed according to the preset security policy and dynamic risk assessment results after the identity authentication passes, and to ensure that the access entity can only access the resources explicitly authorized by executing role-based or attribute-based access control rules; An encryption tunnel module is configured to establish a secure data transmission channel between the access entity and the system, to be responsible for the negotiation, establishment, maintenance and termination of the transmission channel by calling the IPsec, TLS or QUIC protocol stack, and to perform end-to-end encryption and integrity protection on all data transmitted therein.
5. The SASE framework based AI dynamic security transport system of claim 1, wherein: The dynamic transmission optimization module specifically includes: A transmission parameter adjustment module is configured to dynamically calculate and set the transmission window size, retransmission timeout time and sending rate parameters based on the prediction results provided by the network state perception module and the risk score output by the security risk assessment module, to adapt to network fluctuations and security conditions under the premise of ensuring transmission reliability; A transmission protocol switching module is configured to dynamically switch between QUIC, TCP and different variants of the protocol based on the judgment results of real-time network bandwidth, latency and security risk level, to enable low-latency protocols when network conditions are good and risks are low, and to switch to high-reliability protocols when network congestion or risk increases; A data verification module is configured to automatically enable data fragmentation transmission and redundancy checking mechanism when the transmission link quality deteriorates or the security risk increases, to generate a check code for each data fragment and perform integrity verification at the receiving end; A transmission path selection module is configured to analyze the state indicators and security scores of multiple selectable network paths in real time by calling path calculation algorithms, and to dynamically select and switch to the optimal transmission path according to the current application's requirements for latency, bandwidth and security.
6. The SASE framework based AI dynamic security transport system of claim 1, wherein: The adaptive encryption module dynamically selects the appropriate encryption algorithm according to the risk score output by the security risk assessment module and the data sensitivity level evaluation results, and the rules are as follows: when the risk score is greater than or equal to the threshold and the data is of the core sensitive type, a high-strength encryption algorithm is selected; when the risk score is less than the threshold and the data is of the non-sensitive type, a lightweight encryption algorithm is selected.
Citation Information
Patent Citations
A data security transmission system
CN109688115B
Multi-source data fusion prediction method and device for security situation awareness AI large model
CN119892490A
Dynamic security risk assessment and intelligent response system and method based on AI
CN120321033A