An iot card abnormal traffic identification and multi-level response control system
By using a hybrid intelligent model trained with quantum-inspired CNN and gradient mask adversarial training, along with a quantum key bidirectional authentication mechanism, the problem of encrypted traffic being difficult to identify and vulnerable to attack in IoT card traffic management is solved, achieving highly secure and robust traffic management.
Patent Information
- Application Number
- CN202511300770.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-12
- Publication Date
- 2025-11-11
- Estimated Expiration
- 2045-09-12
AI Technical Summary
Traditional IoT SIM card traffic management suffers from problems such as difficulty in accurately identifying anomalies due to encrypted traffic not being decrypted, vulnerability to adversarial attacks, and insufficient security and robustness.
A hybrid intelligent model trained with quantum-inspired CNN and gradient mask is used to detect anomalies in encrypted traffic. A two-way authentication mechanism is built by combining quantum keys. Through high-frequency authentication of high-risk devices and full lifecycle management of keys, accurate anomaly identification and quantum-level security protection are achieved.
It significantly improves the security, robustness, and reliability of IoT card traffic management, and achieves highly robust detection of encrypted traffic and resistance to quantum computing attacks.
Smart Images

Figure CN120812593B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of Internet of Things (IoT) technology, specifically to an IoT card abnormal traffic identification and multi-level response control system. Background Technology
[0002] An Internet of Things (IoT) Card is an embedded SIM card specifically designed to provide network access and data transmission services for IoT devices (non-traditional personal communication devices). Its core function is to enable low-power, highly reliable, and wide-coverage data interaction between IoT devices and cloud platforms, and between devices themselves, via mobile communication networks (such as 2G / 3G / 4G / 5G / NB-IoT / eMTC), supporting the intelligent operation of IoT applications. It is widely used in industrial sensors, smart meters, vehicle terminals, and shared devices, undertaking critical communication tasks such as remote data reporting and command reception, and is a core infrastructure for "device networking" in the IoT system. With the explosive growth in the scale of IoT devices and the diversification of application scenarios, the need for traffic control of IoT Cards is becoming increasingly urgent. On the one hand, the data transmitted by IoT Cards often involves sensitive content such as industrial control commands and user privacy information; to ensure data security, encrypted communication methods are used in most scenarios. On the other hand, the massive number of connected devices also significantly increases the risk of malicious attacks (such as traffic hijacking, spoofed device access, and adversarial sample injection), placing higher demands on the security, accuracy, and anti-attack capabilities of traffic control. In existing technologies, traditional IoT card traffic control suffers from problems such as low security, poor robustness, and insufficient reliability due to the difficulty in accurately identifying anomalies without decrypting encrypted traffic, the vulnerability of conventional detection models to adversarial attacks, and the ease with which identity authentication and key management can be cracked by quantum computing.
[0003] Based on this, the present invention provides an IoT card abnormal traffic identification and multi-level response control system to solve the above-mentioned technical problems. Summary of the Invention
[0004] The purpose of this invention is to provide an IoT card abnormal traffic identification and multi-level response control system. This invention transforms preprocessed traffic features into low-dimensional core fingerprints, and combines a hybrid intelligent model trained with quantum heuristic CNN and gradient mask adversarial training to achieve highly robust detection of encrypted traffic anomalies. Risk scoring quantifies the degree of anomaly, and dynamic baseline updates ensure detection accuracy. This effectively solves the pain points of traditional encrypted traffic detection, namely "difficult to identify without decryption and vulnerable to adversarial attacks." Furthermore, a two-way authentication mechanism is built based on quantum keys, combined with post-quantum cryptography algorithms to resist quantum computing attacks. High-frequency authentication of high-risk devices strengthens dynamic monitoring, and full lifecycle key management ensures key timeliness and irrecoverability. Together, these provide the system with dual protection of "accurate anomaly identification" and "quantum-level security protection," significantly improving the security, robustness, and reliability of IoT card traffic management.
[0005] To achieve the above objectives, the present invention provides the following technical solution:
[0006] This invention provides an IoT card abnormal traffic identification and multi-level response control system, including a quantum key distribution and generation module, a data acquisition and preprocessing module, an abnormal traffic identification module, a multi-level response execution module, and a quantum security management module, wherein:
[0007] The quantum key distribution and generation module: based on quantum random number generation and quantum state transmission, combined with classical post-processing protocols, it completes secure key distribution;
[0008] The data acquisition and preprocessing module is used to collect traffic call detail records and data packet characteristics of IoT cards, and perform normalization, noise reduction and feature vectorization processing.
[0009] The abnormal traffic identification module is used to perform robust anomaly detection and risk scoring on the behavioral fingerprint of encrypted traffic without decrypting the communication content, through a hybrid intelligent model of quantum feature distillation and anti-adversarial enhancement.
[0010] The multi-level response execution module is used to automatically execute graded response actions such as log auditing, bandwidth limiting, or communication blocking based on the anomaly score level.
[0011] The quantum security management module performs two-way authentication between the IoT card and the access device based on quantum keys, and supports continuous authentication and key lifecycle management that are resistant to quantum computing attacks.
[0012] The quantum key distribution and generation module includes a quantum random number generation unit, a quantum state transmission and reception unit, a classical post-processing unit, and a channel monitoring unit, wherein:
[0013] The quantum random number generation unit generates high-entropy random numbers based on the superposition property of single-photon quantum states.
[0014] The quantum state transmission and reception unit is used to send or receive single-photon polarization states of encoded key information through a quantum channel.
[0015] The classical post-processing unit is used to perform basis vector comparison, LDPC error correction and SHA-3 privacy amplification, and to transform the raw quantum data into a final key that meets security standards.
[0016] The channel monitoring unit is used to monitor photon attenuation and noise intensity in quantum state transmission in real time, and triggers key distribution suspension and alarm when abnormalities occur.
[0017] The data acquisition and preprocessing module includes a multi-dimensional acquisition unit, a data cleaning unit, a feature standardization unit, and a feature storage unit, wherein:
[0018] The multi-dimensional acquisition unit is used to capture traffic characteristics and call detail records (CDRs) such as the IP address, protocol type, data packet length, and frame interval of the IoT card.
[0019] The data cleaning unit is used to remove noisy data such as empty and duplicate packets, and processes them according to business priority.
[0020] The feature standardization unit is used to encode discrete features using one-hot encoding and normalize continuous features using Z-Score, outputting a vector of uniform dimension.
[0021] The feature storage unit is used to encrypt and store the preprocessed feature vectors.
[0022] The abnormal traffic identification module includes a quantum feature distillation unit, a hybrid intelligent detection unit, a risk scoring unit, and a baseline update unit, wherein:
[0023] The quantum feature distillation unit is used to map flow features to quantum states, extract related information through entanglement gates and collapse them into core features, compressing dimensions while retaining key fingerprints.
[0024] The hybrid intelligent detection unit is used to combine quantum-heuristic CNN with gradient mask adversarial training to perform highly robust anomaly pattern recognition of encrypted traffic behavior.
[0025] The risk scoring unit calculates a risk value of 0-100 points based on the anomaly matching degree, baseline deviation degree, and historical correlation degree to quantify the severity of the anomaly.
[0026] The baseline update unit is used to dynamically update the normal behavior baseline using recent traffic data from legitimate devices, and iterates automatically once every 24 hours.
[0027] In the quantum feature distillation unit, flux features are mapped to quantum states, and correlation information is extracted and collapsed into core features through entanglement gates. This process compresses dimensionality while retaining key fingerprints. The specific operation is as follows:
[0028] A1: Normalize the preprocessed traffic feature vector to obtain an input vector of dimension d. ;
[0029] A2: Using corner coding, each feature component is encoded... Mapping to the rotation angle of the qubit, construct the initial quantum state:
[0030] ,
[0031] in, It is a single-bit rotation gate around the y-axis, with a rotation angle of . ; It is the initial state of d qubits;
[0032] A3: By using multi-layered parametric quantum circuits, including single-qubit rotation gates and neighboring-qubit entanglement gates, nonlinear correlations between features are extracted;
[0033] A4: Measure the output state of the quantum circuit to obtain the desired value. As a low-dimensional quantum embedding feature;
[0034] A5: Output the measurement results as the core behavioral fingerprint.
[0035] The hybrid intelligent detection unit combines quantum-inspired CNN with gradient mask adversarial training to perform highly robust anomaly pattern recognition of encrypted traffic behavior. The specific operation is as follows:
[0036] B1: Quantum Heuristic CNN Model Construction and Feature Extraction: The quantum heuristic CNN includes a three-level structure of "quantum heuristic convolutional layer → classical convolutional layer → fully connected layer":
[0037] ① The M-dimensional core feature vector output by the quantum feature distillation unit is input into a quantum-inspired convolutional layer. Spatial correlation extraction of the features is performed through a quantum entanglement filter kernel, which consists of K qubits. The feature transformation formula is as follows:
[0038] ,
[0039] in, As the input core feature matrix, The parameters of the quantum filter kernel are initially provided by the quantum random number generation unit. The entanglement coefficient ranges from 0.8 to 1.0, with a value of 1.0 for strongly correlated feature locations. To provide features for the output of quantum-inspired convolutional layers;
[0040] ② Input two classical convolutional layers and one max pooling layer to complete feature dimensionality reduction and local pattern extraction;
[0041] ③ The feature vectors output by the fully connected layer serve as the basic features for anomaly pattern recognition;
[0042] B2: Gradient Mask Adversarial Training Execution: Based on the CNN structure in B1, the gradient mask mechanism is used to improve the model's resistance to adversarial attacks, specifically including:
[0043] ① Generate adversarial examples: Use the fast gradient sign method to add a small perturbation to the input normal traffic feature vector, with the perturbation amplitude... Control is the standard deviation of the eigenvectors The disturbance formula is 3%-5% as follows:
[0044] ,
[0045] in, This is a normal flow characteristic. The model's cross-entropy loss function is... The gradient of the loss function with respect to the input features. For generated adversarial examples;
[0046] ② Gradient masking optimization: During the backpropagation of the model, a mask matrix M is added to the gradient matrix. The gradient formula after masking is: ,in, Use Hadamard product to avoid the model from over-relying on vulnerable feature dimensions;
[0047] ③ Mixed sample training: Normal samples and adversarial samples are mixed and input into the model at a ratio of 4:1. The model is trained iteratively for 50-80 rounds. The final model has an accuracy of ≥98.2% in identifying abnormal patterns in encrypted traffic, an accuracy of ≥97.5% in identifying adversarial samples, and a false detection rate of ≤1.5%.
[0048] The multi-level response execution module includes a level determination unit, a response action execution unit, a response escalation unit, and a backtracking and recovery unit, wherein:
[0049] The level determination unit is used to classify abnormalities into three levels: low, medium, and high, based on the risk score.
[0050] The response action execution unit is used to perform tiered operations that trigger log auditing, bandwidth limiting, and communication blocking.
[0051] The response escalation unit is used to automatically escalate the response level if the anomaly is not eliminated within 1 hour in a low- or medium-risk response.
[0052] The backtracking and recovery unit is used to remove restrictions and restore normal bandwidth if the device passes re-authentication after a high-risk block.
[0053] The quantum security management module includes a two-way authentication unit, a quantum attack resistant unit, a continuous authentication unit, and a key lifecycle unit, wherein:
[0054] The two-way authentication unit: uses quantum key distribution to verify the identity of the device and the IoT card;
[0055] The quantum-resistant unit is used to strengthen the authentication process using post-quantum cryptography algorithms to resist the risk of quantum computing cracking the key.
[0056] The continuous authentication unit is used to trigger high-frequency authentication every 5 minutes for high-risk devices, thereby enhancing dynamic security monitoring.
[0057] The key lifecycle unit is used to manage key generation, activation, 7-day cycle updates, and key destruction for device deregistration.
[0058] The two-way authentication unit verifies the identity between the device and the IoT card based on quantum key distribution. The specific operation is as follows:
[0059] C1: The network side sends an authentication challenge message to the IoT card;
[0060] C2: The IoT SIM card uses a pre-shared quantum key pair to generate a message authentication code for the challenge message and sends it back to the network side;
[0061] C3: The network side verifies the correctness of the message authentication code. If it passes, it initiates reverse authentication and sends a new challenge to the device.
[0062] C4: The device uses the same or paired quantum key to generate a response message authentication code and returns it;
[0063] C5: After the network test is completed and verified, a two-way trusted connection is established.
[0064] The key lifecycle unit manages key generation, activation, 7-day cycle updates, and key destruction for device deregistration. The specific operations are as follows:
[0065] D1: When the device is first connected, the quantum key distribution process is triggered to generate an initial key and mark it as "activated";
[0066] D2: Start the cycle timer. When the key usage time reaches 7 days, the key update process will be automatically triggered.
[0067] D3: Initiate a new round of quantum key distribution, generate new keys, and securely distribute them to devices and the network.
[0068] D4: After the new key is activated, the original key will be marked as "expired" and prohibited from being used for encryption or authentication;
[0069] D5: Immediately delete all key copies associated with the device when the device is deregistered or disconnected for more than a preset threshold.
[0070] Compared with the prior art, the beneficial effects of the present invention are:
[0071] This invention transforms preprocessed traffic features into low-dimensional core fingerprints and combines them with a hybrid intelligent model trained using quantum-heuristic CNN and gradient mask adversarial methods to achieve highly robust detection of encrypted traffic anomalies. Risk scoring quantifies the degree of anomaly, and dynamic baseline updates ensure detection accuracy. This effectively addresses the pain points of traditional encrypted traffic detection: "difficult to identify without decryption, and vulnerable to adversarial attacks." Furthermore, a two-way authentication mechanism is built based on quantum keys, combined with post-quantum cryptography algorithms to resist quantum computing attacks. High-frequency authentication of high-risk devices strengthens dynamic monitoring, and full lifecycle key management ensures key timeliness and irrecoverability. Together, these features provide the system with dual protection: "accurate anomaly identification" and "quantum-level security protection," significantly improving the security, robustness, and reliability of IoT card traffic management. Attached Figure Description
[0072] Figure 1 This is a system diagram of an IoT card abnormal traffic identification and multi-level response control system according to the present invention.
[0073] Figure 2 This is an overall architecture diagram of an IoT card abnormal traffic identification and multi-level response control system according to the present invention.
[0074] Figure 3 This is a flowchart of the key lifecycle management process in an IoT card abnormal traffic identification and multi-level response control system according to the present invention.
[0075] Explanation of icon numbers:
[0076] 100. Quantum Key Distribution and Generation Module; 101. Quantum Random Number Generation Unit; 102. Quantum State Transmission and Reception Unit; 103. Classical Post-processing Unit; 104. Channel Monitoring Unit; 200. Data Acquisition and Preprocessing Module; 201. Multi-dimensional Acquisition Unit; 202. Data Cleaning Unit; 203. Feature Standardization Unit; 204. Feature Storage Unit; 300. Abnormal Traffic Identification Module; 301. Quantum Feature Distillation Unit; 302. Hybrid Intelligent Detection Unit; 303. Risk Scoring Unit; 304. Baseline Update Unit; 400. Multi-level Response Execution Module; 401. Level Determination Unit; 402. Response Action Execution Unit; 403. Response Elevation Unit; 404. Backtracking and Recovery Unit; 500. Quantum Security Management Module; 501. Two-way Authentication Unit; 502. Quantum Attack Resistance Unit; 503. Continuous Authentication Unit; 504. Key Lifecycle Unit. Detailed Implementation
[0077] The technical solutions of the present invention will be clearly and completely described below with reference to the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.
[0078] Example
[0079] like Figures 1-3 As shown, this embodiment provides an IoT SIM card abnormal traffic identification and multi-level response control system, including a quantum key distribution and generation module 100, a data acquisition and preprocessing module 200, an abnormal traffic identification module 300, a multi-level response execution module 400, and a quantum security management module 500. Specifically: the quantum key distribution and generation module 100: distributes secure keys based on quantum random number generation and quantum state transmission, combined with classical post-processing protocols; the data acquisition and preprocessing module 200: collects traffic call detail records and data packet characteristics of the IoT SIM card, and performs normalization, noise reduction, and feature vectorization processing; the abnormal traffic identification module 300: performs robust anomaly detection and risk scoring on the behavioral fingerprint of encrypted traffic using a hybrid intelligent model combining quantum feature distillation and anti-adversarial enhancement without decrypting the communication content; the multi-level response execution module 400: automatically executes tiered response actions such as log auditing, bandwidth limiting, or communication blocking based on the anomaly score level; and the quantum security management module 500: performs two-way authentication between the IoT SIM card and access devices based on quantum keys, supporting continuous authentication and key lifecycle management resistant to quantum computing attacks.
[0080] It should be noted that the quantum key distribution and generation module 100 provides basic security key support for the system. The data acquisition and preprocessing module 200 collects and processes IoT card traffic data and then inputs it into the abnormal traffic identification module 300. The abnormal traffic identification module 300 uses quantum and intelligent models to complete the detection and scoring of encrypted traffic anomalies. The result drives the multi-level response execution module 400 to execute hierarchical response actions. The quantum security management module 500 realizes two-way identity authentication between IoT cards and access devices, continuous authentication against quantum attacks, and key lifecycle management based on quantum keys.
[0081] In this embodiment, it should also be noted that the quantum key distribution and generation module 100 includes a quantum random number generation unit 101, a quantum state transmission and reception unit 102, a classical post-processing unit 103, and a channel monitoring unit 104, wherein: the quantum random number generation unit 101 generates high-entropy random numbers based on the superposition characteristics of single-photon quantum states; the quantum state transmission and reception unit 102 is used to send or receive single-photon polarization states of encoded key information through a quantum channel; the classical post-processing unit 103 is used to perform basis vector comparison, LDPC error correction, and SHA-3 privacy amplification to convert the original quantum data into a final key that conforms to security standards; and the channel monitoring unit 104 is used to monitor photon attenuation and noise intensity in quantum state transmission in real time, and trigger key distribution suspension and alarm when abnormalities occur.
[0082] It should be noted that the quantum random number generation unit 101 generates high-entropy random numbers as the basic material for the key, the quantum state transmission and reception unit 102 completes the single-photon polarization state transmission and reception of the encoded key information through the quantum channel, the classical post-processing unit 103 performs basis vector comparison, error correction and privacy amplification on the original quantum data to generate the final key that meets the security standards, and the channel monitoring unit 104 monitors the quantum state transmission status in real time and triggers key distribution suspension and alarm when abnormal.
[0083] Furthermore, it should be noted that the high-entropy random numbers generated by the quantum random number generation unit 101 must meet the NISTSP 800-22 randomness detection standard, with a generation rate of not less than 1 Mbps and a bit error rate ≤ 0.001%. The generated random numbers must be synchronized to the classical post-processing unit 103 through a classical channel (using AES-256 encryption) encrypted by the quantum security management module 500, serving as a "random reference benchmark" for basis vector comparison to ensure the consistency of basis vector selection at both ends. The anomaly judgment threshold of the channel monitoring unit 104 is set as follows: fiber quantum channel photon attenuation rate > 3 dB / km, free space quantum channel noise intensity > -60 dBm. When the monitoring data exceeds the threshold for 100 ms, it is determined that the channel is being eavesdropped / interfered, immediately triggering the quantum state transmission and reception unit 102 to suspend key distribution and sending a "key distribution anomaly" alarm to the bidirectional authentication unit 501 of the quantum security management module 500, simultaneously freezing the access permissions of the devices to be authenticated during that period.
[0084] In this embodiment, it should also be noted that the data acquisition and preprocessing module 200 includes a multi-dimensional acquisition unit 201, a data cleaning unit 202, a feature standardization unit 203, and a feature storage unit 204, wherein: the multi-dimensional acquisition unit 201 is used to capture traffic characteristics and call detail records (CDRs) of the IoT card, such as IP address, protocol type, data packet length, and frame interval; the data cleaning unit 202 is used to remove noise data such as empty packets and duplicate packets and process them according to service priority; the feature standardization unit 203 is used to output a vector of uniform dimension by one-hot encoding discrete features and Z-score normalization of continuous features; and the feature storage unit 204 is used to encrypt and store the preprocessed feature vector.
[0085] It should be noted that the multi-dimensional acquisition unit 201 captures traffic characteristics and call detail records such as the IP address and protocol type of the IoT card; the data cleaning unit 202 removes noise such as empty packets and duplicate packets from the acquired data and processes it according to business priority; the feature standardization unit 203 transforms the processed data into a unified dimension vector through one-hot encoding and Z-Score normalization; and the feature storage unit 204 encrypts and stores the final preprocessed feature vector.
[0086] Furthermore, it should be noted that the business priority of the data cleaning unit 202 is divided into three levels according to "real-time + importance": ① Level 1: Industrial control commands and equipment control signals (such as load adjustment commands of smart grids), with a processing delay of ≤100ms; ② Level 2: Routine monitoring data (such as equipment heartbeat packets and temperature and humidity collection values), with a processing delay of ≤500ms; ③ Level 3: Historical archived data (such as traffic call details from 72 hours ago), with a processing delay of ≤10s.
[0087] The feature standardization unit 203 processes the "protocol type" (TCP / UDP / CoAP, etc., occupying 8 bits after encoding) and "source / destination IP" (occupying 32 bits after encoding) through one-hot encoding, and normalizes continuous features such as "data packet length" and "frame interval time" to [0,1] through Z-Score standardization, finally outputting a 128-dimensional feature vector; the feature storage unit 204 uses the session key provided by the quantum key distribution and generation module 100, and encrypts and stores the feature vector through the SM4 national cryptographic algorithm. The storage period is consistent with the network access validity period of the IoT card, and it is automatically desensitized and destroyed after expiration.
[0088] In this embodiment, it should also be noted that the abnormal traffic identification module 300 includes a quantum feature distillation unit 301, a hybrid intelligent detection unit 302, a risk scoring unit 303, and a baseline update unit 304, wherein: the quantum feature distillation unit 301 is used to map traffic features to quantum states, extract related information through entanglement gates and collapse it into core features, compressing the dimension while retaining key fingerprints; the specific operation is as follows: A1: Normalize the preprocessed traffic feature vector to obtain an input vector of dimension d. A2: Using corner coding, each feature component is... Mapping to the rotation angle of the qubit, construct the initial quantum state:
[0089]
[0090] in, It is a single-bit rotation gate around the y-axis, with a rotation angle of . ; A3: Extract the nonlinear correlation between features using a multi-layered parametric quantum circuit, including single-qubit rotation gates and neighboring-qubit entanglement gates; A4: Measure the output state of the quantum circuit to obtain the desired value. As a low-dimensional quantum embedding feature; A5: Output the measurement result as the core behavioral fingerprint. Hybrid intelligent detection unit 302: Used to combine quantum heuristic CNN with gradient mask adversarial training to perform highly robust anomaly pattern recognition of encrypted traffic behavior; the specific operation is as follows: B1: Quantum heuristic CNN model construction and feature extraction: The quantum heuristic CNN includes a three-level structure of "quantum heuristic convolutional layer → classical convolutional layer → fully connected layer": ① Input the M-dimensional core feature vector output by the quantum feature distillation unit 301 into the quantum heuristic convolutional layer, and extract the spatial correlation of the features through the quantum entanglement filter kernel. The filter kernel consists of K qubits, and the feature transformation formula is:
[0091] ,
[0092] in, As the input core feature matrix, The quantum filter kernel parameters are initially provided by the quantum random number generation unit 101. The entanglement coefficient ranges from 0.8 to 1.0, with a value of 1.0 for strongly correlated feature locations. ② To provide quantum-inspired convolutional layer output features; Inputting two classic convolutional layers and one max-pooling layer completes feature dimensionality reduction and local pattern extraction; ③ Outputting feature vectors through fully connected layers serves as the basic features for abnormal pattern recognition; B2: Gradient mask adversarial training execution: Based on the CNN structure in B1, the model's resistance to adversarial attacks is improved through a gradient masking mechanism, specifically including: ① Generating adversarial examples: Using the fast gradient sign method, a small perturbation is added to the input normal traffic feature vector, with the perturbation amplitude... Control is the standard deviation of the eigenvectors The disturbance formula is 3%-5% as follows:
[0093]
[0094] in, This is a normal flow characteristic. The model's cross-entropy loss function is... The gradient of the loss function with respect to the input features. ② For generated adversarial examples; Gradient mask optimization: During the backpropagation of the model, a mask matrix M is added to the gradient matrix. The gradient formula after masking is: ,in, The model uses Hadamard product to avoid over-reliance on vulnerable feature dimensions; ③ Mixed sample training: Normal samples and adversarial samples are mixed and input into the model at a ratio of 4:1, and iterated for 50-80 rounds. The final model has an accuracy of ≥98.2% in identifying abnormal patterns in encrypted traffic, an accuracy of ≥97.5% in identifying adversarial samples, and a false detection rate of ≤1.5%. Risk scoring unit 303: Calculates a risk value of 0-100 points based on abnormal matching degree, baseline deviation degree, and historical correlation degree to quantify the severity of the abnormality; Baseline update unit 304: Used to dynamically update the normal behavior baseline using recent traffic data from legitimate devices, automatically iterating once every 24 hours.
[0095] It should be noted that the quantum feature distillation unit 301 performs quantum state mapping, correlation extraction, and collapse on the traffic features output by the preprocessing data acquisition and preprocessing module 200 to generate a core behavioral fingerprint. Based on this core feature, the hybrid intelligent detection unit 302 achieves highly robust identification of encrypted traffic anomaly patterns through quantum heuristic CNN and gradient mask adversarial training. The risk scoring unit 303 calculates the risk value by combining the anomaly matching degree, baseline deviation degree, and historical correlation degree to quantify the degree of anomaly. Meanwhile, the baseline update unit 304 periodically updates the normal behavior baseline using legitimate device traffic data.
[0096] Furthermore, it should be noted that the parameters of the classic convolutional layers in step B1② are as follows: the first layer has 32 3×3 convolutional kernels with a stride of 1; the second layer has 64 3×3 convolutional kernels with a stride of 1; and the max pooling layer has 2×2 pooling kernels with a stride of 2. The risk score calculation formula is as follows: ,in, (Anomaly matching degree) is the cosine similarity between the traffic and the attack feature database (normalized to 0-100 points). (Baseline Deviation) is the Euclidean distance between the flow behavior and the normal baseline (normalized to 0-100 points). (Historical correlation) is the percentage of abnormal device occurrences in the past 7 days (normalized to 0-100 points); risk level thresholds: low risk (0-30 points), medium risk (31-70 points), high risk (71-100 points), and... High risk is determined directly based on time period.
[0097] In this embodiment, it should also be noted that the multi-level response execution module 400 includes a level determination unit 401, a response action execution unit 402, a response escalation unit 403, and a backtracking and recovery unit 404, wherein: the level determination unit 401 is used to classify the anomaly level into low, medium, and high levels according to the risk score; the response action execution unit 402 is used to trigger tiered operations such as log auditing, bandwidth limiting, and communication blocking; the response escalation unit 403 is used to automatically escalate the response level when the anomaly is not eliminated within 1 hour in a low or medium risk response; and the backtracking and recovery unit 404 is used to remove the restriction and restore normal bandwidth after a high-risk blocking if the device passes re-authentication.
[0098] It should be noted that the level determination unit 401 classifies the abnormality into three levels: low, medium, and high, based on the risk score output by the abnormal traffic identification module 300. The response action execution unit 402 triggers corresponding tiered operations such as log auditing, bandwidth limiting, and communication blocking. The response upgrade unit 403 automatically upgrades the response level if the abnormality is not eliminated within 1 hour in the low or medium risk response. The backtracking and recovery unit 404, after high-risk blocking, will lift the restriction and restore normal bandwidth if the device passes the re-authentication of the quantum security management module 500.
[0099] Furthermore, it should be noted that the response action execution rules in response action execution unit 402 are as follows: ① Low risk: Log auditing must record "source IP, destination IP, data packet length and sequence, and timestamp of the anomaly occurrence," and upload it to the quantum security management module 500 archive after encryption (stored for 90 days); ② Medium risk: Bandwidth is limited to 50% of the device's average bandwidth over the past 24 hours, and anomalies are detected every 30 minutes. If no anomalies are detected for 3 consecutive times, bandwidth is restored; ③ High risk: L3 layer IP forwarding is cut off, device network access permissions are frozen, and alarms are pushed to the administrator terminal simultaneously. After the high-risk blocking in backtracking and recovery unit 404 lasts for 10 minutes, re-authentication is automatically triggered (executed by the two-way authentication unit 501 of quantum security management module 500). Re-authentication requires additional verification of the "binding relationship between the device MAC address and the network access certificate"; after successful verification, 80% bandwidth is restored first and monitored for 1 hour. If no anomalies are detected, it is restored to 100%; if verification fails, the blocking is extended to 24 hours, triggering manual review.
[0100] In this embodiment, it should also be noted that the quantum security management module 500 includes a two-way authentication unit 501, a quantum attack resistant unit 502, a continuous authentication unit 503, and a key lifecycle unit 504. Specifically: the two-way authentication unit 501 verifies the identity between the device and the IoT card based on a quantum key; the specific operations are as follows: C1: The network side sends an authentication challenge message to the IoT card; C2: The IoT card uses a pre-shared quantum key to generate a message authentication code for the challenge message and sends it back to the network side; C3: The network side verifies the correctness of the message authentication code. If successful, it initiates reverse authentication and sends a new challenge to the device; C4: The device uses the same or paired quantum key to generate a response message authentication code and returns it; C5: After the network test completes the verification, a two-way trusted connection is established. The quantum attack resistant unit 502 is used to strengthen the authentication process using a post-quantum cryptography algorithm to resist the risk of quantum computing cracking the key; the continuous authentication unit 503 is used to trigger high-frequency authentication every 5 minutes for high-risk devices, strengthening dynamic security monitoring; the key lifecycle unit 504 is used to manage key generation, activation, 7-day cycle updates, and key destruction for device deregistration. The specific operations are as follows: D1: When the device is first connected, the quantum key distribution process is triggered, an initial key is generated and marked as "activated"; D2: A periodic timer is started, and when the key usage time reaches 7 days, the key update process is automatically triggered; D3: A new round of quantum key distribution is started, a new key is generated and securely distributed to the device and the network side; D4: After the new key is activated, the original key status is marked as "expired" and prohibited from being used for encryption or authentication; D5: When the device is deregistered or disconnected for more than a preset threshold, the key copy associated with the device is immediately cleared.
[0101] It should be noted that the two-way authentication unit 501 uses the quantum key provided by the quantum key distribution and generation module 100 to complete the identity verification between the device and the IoT card through a challenge-response mechanism. The anti-quantum attack unit 502 uses a post-quantum cryptography algorithm to strengthen the authentication process to resist the risk of quantum computing cracking. The continuous authentication unit 503 triggers high-frequency authentication every 5 minutes for high-risk devices identified by the abnormal traffic identification module 300. The key lifecycle unit 504 is responsible for the full lifecycle management of the quantum key from generation, activation, 7-day cycle update to deregistration and destruction of the device key.
[0102] Furthermore, it should be noted that the quantum-resistant unit 502 employs the CRYSTALS-Kyber algorithm (NIST post-quantum cryptography standard) to strengthen the authentication process. The key encapsulation uses the Kyber-768 parameter set, and the digital signature uses the CRYSTALS-Dilithium algorithm (Dilithium-3 parameter set), ensuring that the authentication information is extremely difficult to crack in a quantum computing environment. The next operation. The high-risk device judgment criteria for the continuous authentication unit 503 are: ① a risk score ≥ 71 points output by the abnormal traffic identification module 300; ② triggering 3 or more medium-risk responses within the past 24 hours; meeting either condition triggers high-frequency authentication every 5 minutes. After 24 hours of continuous high-frequency authentication without any anomalies, the system returns to the regular authentication cycle (every 30 minutes). In step D2, the key update warning time is "24 hours before expiration," at which time a "key update notification" is pushed to the device. In step D5, the "disconnection preset threshold" is 72 hours (the device has no communication records). Key destruction uses a "3-time random number overwrite + physical isolation storage area" method. The overwrite random number is provided by the quantum random number generation unit 101 to ensure that the old key is unrecoverable.
[0103] In the description of this specification, references to terms such as "an embodiment," "example," "specific example," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.
[0104] The preferred embodiments of the present invention disclosed above are merely illustrative of the invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the invention to the specific implementations described. Clearly, many modifications and variations can be made based on the content of this specification. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the invention, thereby enabling those skilled in the art to better understand and utilize the invention. The invention is limited only by the claims and their full scope and equivalents.
Claims
1. An IoT card abnormal traffic identification and multi-level response control system, characterized in that, It includes a quantum key distribution and generation module (100), a data acquisition and preprocessing module (200), an abnormal traffic identification module (300), a multi-level response execution module (400), and a quantum security management module (500), wherein: The quantum key distribution and generation module (100) is based on quantum random number generation and quantum state transmission, combined with classical post-processing protocols to complete secure key distribution; The data acquisition and preprocessing module (200) is used to acquire traffic call detail records and data packet characteristics of IoT cards, and perform normalization, noise reduction and feature vectorization processing. The abnormal traffic identification module (300) is used to perform robust anomaly detection and risk scoring on the behavioral fingerprint of encrypted traffic without decrypting the communication content, through a hybrid intelligent model of quantum feature distillation and anti-adversarial enhancement. The multi-level response execution module (400) is used to automatically execute graded response actions such as log auditing, bandwidth limiting, or communication blocking based on the anomaly rating level. The quantum security management module (500) performs two-way authentication between the IoT card and the access device based on quantum keys, and supports continuous authentication and key lifecycle management that are resistant to quantum computing attacks.
2. The IoT card abnormal traffic identification and multi-level response control system according to claim 1, characterized in that, The quantum key distribution and generation module (100) includes a quantum random number generation unit (101), a quantum state transmission and reception unit (102), a classical post-processing unit (103), and a channel monitoring unit (104), wherein: The quantum random number generation unit (101) generates high-entropy random numbers based on the superposition property of single-photon quantum states; The quantum state transmission and reception unit (102) is used to transmit or receive single-photon polarization states of encoded key information through a quantum channel; The classical post-processing unit (103) is used to perform basis vector comparison, LDPC error correction and SHA-3 privacy amplification, and to convert the raw quantum data into a final key that meets security standards. The channel monitoring unit (104) is used to monitor photon attenuation and noise intensity in quantum state transmission in real time, and trigger key distribution suspension and alarm when abnormalities occur.
3. The IoT card abnormal traffic identification and multi-level response control system according to claim 1, characterized in that, The data acquisition and preprocessing module (200) includes a multi-dimensional acquisition unit (201), a data cleaning unit (202), a feature standardization unit (203), and a feature storage unit (204), wherein: The multi-dimensional acquisition unit (201) is used to capture the traffic characteristics and call detail records of the Internet of Things card, including IP address, protocol type, data packet length, frame interval, etc. The data cleaning unit (202) is used to remove noisy data such as empty packets and duplicate packets, and processes them according to business priority. The feature standardization unit (203) is used to encode discrete features with one-hot encoding and normalize continuous features with Z-Score, outputting a vector of uniform dimension. The feature storage unit (204) is used to encrypt and store the preprocessed feature vector.
4. The IoT card abnormal traffic identification and multi-level response control system according to claim 1, characterized in that, The abnormal traffic identification module (300) includes a quantum feature distillation unit (301), a hybrid intelligent detection unit (302), a risk scoring unit (303), and a baseline update unit (304), wherein: The quantum feature distillation unit (301) is used to map flow features to quantum states, extract related information through entanglement gates and collapse them into core features, compressing dimensions while retaining key fingerprints. The hybrid intelligent detection unit (302) is used to combine quantum heuristic CNN with gradient mask adversarial training to perform highly robust abnormal pattern recognition of encrypted traffic behavior. The risk scoring unit (303) calculates a risk value of 0-100 based on the abnormal matching degree, baseline deviation degree, and historical correlation degree to quantify the severity of the abnormality. The baseline update unit (304) is used to dynamically update the normal behavior baseline using recent traffic data of legitimate devices, and iterates automatically once every 24 hours.
5. The IoT card abnormal traffic identification and multi-level response control system according to claim 4, characterized in that, The quantum feature distillation unit (301) maps the flux features to quantum states, extracts the correlation information through the entanglement gate and collapses it into core features, compressing the dimensionality while retaining the key fingerprint. The specific operation is as follows: A1: Normalize the preprocessed traffic feature vector to obtain an input vector of dimension d. ; A2: Using corner coding, each feature component is encoded... Mapping to the rotation angle of the qubit, construct the initial quantum state: , in, It is a single-bit rotation gate around the y-axis, with a rotation angle of . ; It is the initial state of d qubits; A3: By using multi-layered parametric quantum circuits, including single-qubit rotation gates and neighboring-qubit entanglement gates, nonlinear correlations between features are extracted; A4: Measure the output state of the quantum circuit to obtain the desired value. As a low-dimensional quantum embedding feature; A5: Output the measurement results as the core behavioral fingerprint.
6. The IoT card abnormal traffic identification and multi-level response control system according to claim 4, characterized in that, The hybrid intelligent detection unit (302) combines quantum-inspired CNN with gradient mask adversarial training to perform highly robust anomaly pattern recognition of encrypted traffic behavior. The specific operation is as follows: B1: Quantum Heuristic CNN Model Construction and Feature Extraction: The quantum heuristic CNN includes a three-level structure of "quantum heuristic convolutional layer → classical convolutional layer → fully connected layer": ① The M-dimensional core feature vector output by the quantum feature distillation unit (301) is input into the quantum-inspired convolutional layer. The features are spatially correlated and extracted through a quantum entanglement filter kernel. The filter kernel consists of K qubits. The feature transformation formula is: , in, As the input core feature matrix, The parameters of the quantum filter kernel are initially provided by the quantum random number generation unit (101). The entanglement coefficient ranges from 0.8 to 1.0, with a value of 1.0 for strongly correlated feature locations. To provide features for the output of quantum-inspired convolutional layers; ② Input two classical convolutional layers and one max pooling layer to complete feature dimensionality reduction and local pattern extraction; ③ The feature vectors output by the fully connected layer serve as the basic features for anomaly pattern recognition; B2: Gradient Mask Adversarial Training Execution: Based on the CNN structure in B1, the gradient mask mechanism is used to improve the model's resistance to adversarial attacks, specifically including: ① Generate adversarial examples: Use the fast gradient sign method to add a small perturbation to the input normal traffic feature vector, with the perturbation amplitude... Control is the standard deviation of the eigenvectors The disturbance formula is 3%-5% as follows: , in, This is a normal flow characteristic. The model's cross-entropy loss function is... The gradient of the loss function with respect to the input features. For generated adversarial examples; ② Gradient masking optimization: During the backpropagation of the model, a mask matrix M is added to the gradient matrix. The gradient formula after masking is: ,in, Use Hadamard product to avoid the model from over-relying on vulnerable feature dimensions; ③ Mixed sample training: Normal samples and adversarial samples are mixed and input into the model at a ratio of 4:
1. The model is trained iteratively for 50-80 rounds. The final model has an accuracy of ≥98.2% in identifying abnormal patterns in encrypted traffic, an accuracy of ≥97.5% in identifying adversarial samples, and a false detection rate of ≤1.5%.
7. The IoT card abnormal traffic identification and multi-level response control system according to claim 1, characterized in that, The multi-level response execution module (400) includes a level determination unit (401), a response action execution unit (402), a response escalation unit (403), and a backtracking and recovery unit (404), wherein: The level determination unit (401) is used to classify the three levels of abnormality: low, medium and high, according to the risk score. The response action execution unit (402) is used to perform hierarchical operations such as triggering log auditing, bandwidth limiting, and communication blocking. The response escalation unit (403) is used to automatically escalate the response level when the anomaly is not eliminated within 1 hour in a low or medium risk response. The backtracking and recovery unit (404) is used to remove the restriction and restore normal bandwidth if the device passes re-authentication after a high-risk block.
8. The IoT card abnormal traffic identification and multi-level response control system according to claim 1, characterized in that, The quantum security management module (500) includes a two-way authentication unit (501), a quantum attack resistant unit (502), a continuous authentication unit (503), and a key lifecycle unit (504), wherein: The two-way authentication unit (501) performs identity verification between the device and the IoT card based on quantum key distribution. The quantum-resistant unit (502) is used to strengthen the authentication process with post-quantum cryptography algorithms to resist the risk of quantum computing cracking the key; The continuous authentication unit (503) is used to trigger high-frequency authentication every 5 minutes for high-risk devices, thereby enhancing dynamic security monitoring. The key lifecycle unit (504) is used to manage key generation, activation, 7-day cycle updates, and key destruction for device deregistration.
9. The IoT card abnormal traffic identification and multi-level response control system according to claim 8, characterized in that, The two-way authentication unit (501) performs identity verification between the device and the IoT card based on quantum key distribution, and the specific operation is as follows: C1: The network side sends an authentication challenge message to the IoT card; C2: The IoT SIM card uses a pre-shared quantum key pair to generate a message authentication code for the challenge message and sends it back to the network side; C3: The network side verifies the correctness of the message authentication code. If it passes, it initiates reverse authentication and sends a new challenge to the device. C4: The device uses the same or paired quantum key to generate a response message authentication code and returns it; C5: After the network test is completed and verified, a two-way trusted connection is established.
10. The IoT card abnormal traffic identification and multi-level response control system according to claim 8, characterized in that, The key lifecycle unit (504) manages key generation, activation, 7-day cycle updates, and key destruction for device deregistration. The specific operations are as follows: D1: When the device is first connected, the quantum key distribution process is triggered to generate an initial key and mark it as "activated"; D2: Start the cycle timer. When the key usage time reaches 7 days, the key update process will be automatically triggered. D3: Initiate a new round of quantum key distribution, generate new keys, and securely distribute them to devices and the network. D4: After the new key is activated, the original key will be marked as "expired" and prohibited from being used for encryption or authentication; D5: Immediately delete all key copies associated with the device when the device is deregistered or disconnected for more than a preset threshold.
Citation Information
Patent Citations
Chaotic synchronization key distribution method and system based on optical fiber channel feature extraction
CN113541919A
Estimation method and device of distillable key, equipment and storage medium
CN116346334A