Implementation method of security mechanism based on digital twin network and endogenous security architecture

By constructing a digital twin network and DHR architecture in telecommunications networks, the resource consumption and performance bottlenecks associated with introducing DHR architecture into telecommunications networks have been resolved. This has enabled the integrated development of security and performance, reduced network construction and maintenance costs, and enhanced the ability to defend against unknown threats.

CN121125145APending Publication Date: 2025-12-12CHINA MOBILE COMM LTD RES INST +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510417944.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-03
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

How to introduce DHR architecture into telecommunications networks to ensure security while reducing its resource consumption, and solve the performance bottlenecks and resource consumption problems that DHR architecture may cause in telecommunications networks.

Method used

By constructing a digital twin network in the telecommunications network and deploying a dynamic heterogeneous redundancy (DHR) architecture, information processing and security policy generation are performed using the set of execution entities in the physical network and the digital twin network. This enables the repair or replacement of abnormal execution entities, and combines a feedback controller and a scheduling management module for security analysis and policy distribution.

Benefits of technology

It achieves the integrated development of security and performance in telecommunications networks, reduces the resource consumption of the DHR architecture, reduces network construction and maintenance costs, and improves the ability to prevent unknown threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121125145A_ABST
    Figure CN121125145A_ABST
Patent Text Reader

Abstract

The embodiment of the invention provides an implementation method of a security mechanism based on a digital twin network and an endogenous security architecture. According to the implementation method of the security mechanism based on the digital twin network and the endogenous security architecture provided by the embodiment of the invention, the influence of construction and operation of a plurality of heterogeneous executors on network construction cost, operation and maintenance cost, service performance, time delay and the like after the digital twin network is introduced into a mobile communication network is solved; and fusion development of safety, cost and performance can be realized. In addition, according to the embodiment of the invention, the problems that homogeneous devices are mutually active and standby, after attacks of vulnerabilities, backdoors and the like occur, no alternative products exist, and unknown vulnerabilities and backdoors cannot be detected can be solved.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of mobile communication, in particular to a realization method of a security mechanism based on a digital twin network (DTN) and an endogenous security architecture. BACKGROUND

[0002] Based on the philosophical principle that external causes act through internal causes and internal causes play a decisive role, the related technology proposes a network space endogenous security theory. Without relying on prior knowledge, the network attack problem of unknown endogenous security based on target objects is solved, and the interwoven problem of functional safety and network security is solved in an integrated manner. The main goal is to develop an endogenous security theory and technical system that does not rely on (but does not exclude) prior knowledge such as vulnerability backdoor discovery and attack feature analysis, establish a set of practical specifications for effectively solving the common problems of network space endogenous security, and provide quantifiable design and verifiable measurement of network security and functional safety capabilities with innovative dynamic heterogeneous redundancy (DHR) structure to effectively prevent unknown unknown security threats. The endogenous security architecture based on DHR has high security and high security guarantee for unknown vulnerabilities, backdoors, viruses or Trojan horses and other threats in the network space. The dynamic heterogeneous redundancy architecture aims to prevent network space endogenous security risks and security risks through a generalized robust control mechanism.

[0003] The security capability implementation based on the DHR architecture does not need to preinstall security features and is suitable for protecting vulnerability, backdoor, virus and Trojan type attacks. However, the DHR architecture needs multiple heterogeneous executors and has a relatively complex processing flow, which will increase the cost of software and hardware, energy consumption, etc., and may form a performance bottleneck when dealing with DDoS attacks. Currently, the DHR architecture has not been applied in the telecommunications network. How to fully utilize the security advantages of the DHR architecture and reduce its consumption of telecommunications network resources has become a key problem in introducing the DHR architecture to protect the security of the telecommunications network. SUMMARY

[0004] At least one embodiment of the present application provides a realization method of a security mechanism based on a digital twin network and an endogenous security architecture, which is used to introduce the DHR architecture into the telecommunications network to protect the security of the telecommunications network while reducing the consumption of the DHR architecture to the telecommunications network resources.

[0005] In order to solve the above technical problems, the present application is implemented as follows:

[0006] In a first aspect, the embodiments of the present application provide an endogenous security architecture based on a digital twin network, comprising:

[0007] A digital twin network is constructed based on a physical network, wherein the physical network comprises at least one access network execution body, at least one core network execution body, and a security management center; the digital twin network comprises a twin access network execution body corresponding to the access network execution body, a twin core network execution body corresponding to the core network execution body, and a twin security management center corresponding to the security management center.

[0008] The digital twin network further comprises a dynamic heterogeneous redundancy (DHR) architecture; the DHR architecture comprises an execution body set, the execution body set comprising an access network execution body set and / or a core network execution body set, the access network execution body set comprising the twin access network execution body and an additional access network execution body, and the core network execution body set comprising the twin core network execution body and an additional core network execution body; wherein the twin access network execution body and the additional access network execution body are heterogeneous execution bodies, and the twin core network execution body and the additional core network execution body are heterogeneous execution bodies.

[0009] Optionally, the DHR architecture is configured to process information received from the physical network by using at least two execution bodies in the execution body set to obtain a first processing result, generate a first decision result based on the first processing result and send the first decision result to the twin security management center, wherein the first decision result comprises information of an abnormal execution body, receive a first security policy from the twin security management center, repair or replace the abnormal execution body based on the first security policy, and process information received from the physical network by using a new execution body after the repair or replacement to obtain a second processing result, and generate a second decision result based on the second processing result and send the second decision result to the twin security management center.

[0010] The twin security management center is configured to perform security analysis on the first decision result, generate a first security policy and send the first security policy to the DHR architecture, wherein the first security policy comprises repair or replacement information for the abnormal execution body, and perform security analysis on the second decision result, and in a case where the abnormal execution body is a twin execution body and the new execution body is normal, send a second security policy to a security management center of the physical network, wherein the second security policy comprises repair or replacement information for a target execution body, and the target execution body is an access network execution body and / or a core network execution body corresponding to the abnormal execution body.

[0011] Optionally, the DHR architecture is further configured to, in a case where the first decision result is generated, update the execution body set based on information of the abnormal execution body contained in the first decision result, and after the repair or replacement of the abnormal execution body, update the execution body set based on the new execution body after the repair or replacement.

[0012] Optionally, the access network execution body comprises at least one access network unit, and the access network unit comprises at least one access network component; the core network execution body comprises at least one core network unit, and the core network unit comprises at least one core network component;

[0013] The DHR architecture further comprises a feedback controller and a scheduling management module; wherein,

[0014] The twin security management center is further configured to:

[0015] In a case where the abnormal condition of the abnormal execution body can be alleviated, the first security policy indicating a first component of the abnormal execution body under attack and a repair method thereof is generated, and the first security policy is sent to the abnormal execution body, wherein the first component comprises at least one of an access network unit, an access network component, a core network unit, and a core network component; and after the abnormal execution body is repaired, a first instruction is sent to the feedback controller, and the first instruction is used to request that a new execution body after repair be added to the execution body set;

[0016] In a case where the abnormal condition of the abnormal execution body cannot be alleviated, the first security policy indicating the first component of the abnormal execution body under attack and a replacement suggestion thereof is generated, and a second instruction is sent to the feedback controller, and the second instruction is used to request that the first component be replaced, and a new execution body after replacement is added to the execution body set;

[0017] The abnormal execution body is further configured to, in a case where the first security policy is received, perform repair according to the first security policy to obtain a new execution body after repair;

[0018] The feedback controller is further configured to, according to the received first instruction, add the new execution body after repair to the execution body set, or, according to the received second instruction, replace the first component to obtain a new execution body after replacement, and add the new execution body after replacement to the execution body set.

[0019] Optionally, the DHR architecture further comprises an input agent module, a policy decision module, and an output selection module; wherein,

[0020] The input agent module is configured to receive information from the physical network and distribute the information to at least two execution bodies in the execution body set for processing;

[0021] The policy decision module is configured to generate a first ruling result according to the first processing result and send the first ruling result to the output selection module, and generate a second ruling result according to the second processing result and send the second ruling result to the output selection module;

[0022] The output selection module is configured to receive the first and second adjudication results and send them to the twin security management center.

[0023] Optionally, the policy decision module is further configured to send information of the abnormal execution body to the feedback controller after generating the first adjudication result.

[0024] The feedback controller is configured to execute scheduling of the abnormal execution body based on a preset scheduling policy through the scheduling management module, and send execution body update information to the input agent module according to a scheduling result, wherein, in a case where the abnormal execution body is a twin execution body, the abnormal twin execution body is replaced.

[0025] Optionally, the physical network includes a first access network execution body as a primary device and a second access network execution body as a backup device; wherein, in a case where the first access network execution body and the second access network execution body are homogeneous devices, the digital twin network includes one twin access network execution body corresponding to the first access network execution body or the second access network execution body; in a case where the first access network execution body and the second access network execution body are heterogeneous devices, the digital twin network includes a first twin access network execution body corresponding to the first access network execution body and a second twin access network execution body corresponding to the second access network execution body.

[0026] The physical network includes a first core network execution body as a primary device and a second core network execution body as a backup device; wherein, in a case where the first core network execution body and the second core network execution body are homogeneous devices, the digital twin network includes one twin core network execution body corresponding to the first core network execution body or the second core network execution body; in a case where the first core network execution body and the second core network execution body are heterogeneous devices, the digital twin network includes a first twin core network execution body corresponding to the first core network execution body and a second twin core network execution body corresponding to the second core network execution body.

[0027] Optionally, in a case where the first access network execution body and the second access network execution body are heterogeneous devices, and the abnormal execution body includes the first twin access network execution body and / or the second twin access network execution body, when the first security policy indicating the first component of the abnormal execution body under attack and a replacement suggestion thereof is generated, the replacement suggestion contains information of a second component for replacing the first component, and the second component and the first component are heterogeneous components.

[0028] In the case that the first core network execution body and the second core network execution body are heterogeneous devices, and the abnormal execution body includes the first twin core network execution body and / or the second twin core network execution body, when the first security policy indicating the first component of the abnormal execution body under attack and the replacement suggestion thereof are generated, the replacement suggestion contains information of a second component for replacing the first component, and the second component and the first component are heterogeneous components.

[0029] In a second aspect, the embodiments of the present application provide an implementation method of an endogenous security mechanism based on a digital twin network, applied to the endogenous security architecture based on the digital twin network in the first aspect, and the method comprises:

[0030] processing information received from the physical network by using at least two execution bodies in the execution body set to obtain a first processing result; generating a first decision result according to the first processing result and sending the first decision result to the twin security management center, wherein the first decision result contains information of an abnormal execution body; and receiving a first security policy from the twin security management center, repairing or replacing the abnormal execution body based on the first security policy, and processing information received from the physical network by using the new execution body after the repair or replacement to obtain a second processing result; generating a second decision result according to the second processing result and sending the second decision result to the twin security management center;

[0031] performing security analysis on the first decision result by the twin security management center to generate a first security policy and send the first security policy to the DHR architecture, wherein the first security policy includes repair or replacement information for the abnormal execution body; and performing security analysis on the second decision result, and in the case that the abnormal execution body is a twin execution body and the new execution body is normal, sending a second security policy to the security management center of the physical network, wherein the second security policy includes repair or replacement information for a target execution body, and the target execution body is an access network execution body and / or a core network execution body corresponding to the abnormal execution body.

[0032] Optionally, the method further comprises:

[0033] In the case that the first decision result is generated, updating the execution body set according to the information of the abnormal execution body contained in the first decision result; and after the abnormal execution body is repaired or replaced, updating the execution body set according to the new execution body after the repair or replacement.

[0034] Optionally, the access network execution body comprises at least one access network unit, and the access network unit comprises at least one access network component; the core network execution body comprises at least one core network unit, and the core network unit comprises at least one core network component; the DHR architecture further comprises a feedback controller and a scheduling management module; the method further comprises:

[0035] In the case that the abnormal condition of the abnormal execution body can be alleviated, the first security policy indicating the first component attacked in the abnormal execution body and the repair method thereof is generated, and the first security policy is sent to the abnormal execution body, wherein the first component comprises at least one of the following: an access network unit, an access network component, a core network unit, and a core network component; and after the abnormal execution body is repaired, a first instruction is sent to the feedback controller, and the first instruction is used to request that the new execution body after repair is added to the execution body set;

[0036] In the case that the abnormal condition of the abnormal execution body cannot be alleviated, the first security policy indicating the first component attacked in the abnormal execution body and the replacement suggestion thereof is generated, and a second instruction is sent to the feedback controller, and the second instruction is used to request that the first component is replaced, and the new execution body after replacement is added to the execution body set;

[0037] In the case that the abnormal execution body receives the first security policy, the abnormal execution body is repaired according to the first security policy, and the new execution body after repair is obtained;

[0038] The feedback controller adds the new execution body after repair to the execution body set according to the first instruction, or replaces the first component according to the second instruction, obtains the new execution body after replacement, and adds the new execution body after replacement to the execution body set.

[0039] Optionally, the DHR architecture further comprises an input agent module, a policy decision module, and an output selection module; the method further comprises:

[0040] The input agent module receives information from the physical network and distributes the information to at least two execution bodies in the execution body set for processing;

[0041] The policy decision module generates a first ruling result according to the first processing result and sends the first ruling result to the output selection module, and generates a second ruling result according to the second processing result and sends the second ruling result to the output selection module;

[0042] The output selection module receives the first ruling result and the second ruling result and sends the first ruling result and the second ruling result to the twin security management center.

[0043] Optionally, the method further comprises:

[0044] The policy decision module sends information of the abnormal execution body to the feedback controller after generating the first decision result;

[0045] The feedback controller executes scheduling of the abnormal execution body based on a preset scheduling policy through the scheduling management module, and sends execution body update information to the input agent module according to a scheduling result, wherein, in a case where the abnormal execution body is a twin execution body, the twin abnormal execution body is replaced.

[0046] Optionally, the physical network includes a first access network execution body as a master device and a second access network execution body as a backup device; wherein, in a case where the first access network execution body and the second access network execution body are homogeneous devices, the digital twin network includes one twin access network execution body corresponding to the first access network execution body or the second access network execution body; in a case where the first access network execution body and the second access network execution body are heterogeneous devices, the digital twin network includes a first twin access network execution body corresponding to the first access network execution body and a second twin access network execution body corresponding to the second access network execution body.

[0047] The physical network includes a first core network execution body as a master device and a second core network execution body as a backup device; wherein, in a case where the first core network execution body and the second core network execution body are homogeneous devices, the digital twin network includes one twin core network execution body corresponding to the first core network execution body or the second core network execution body; in a case where the first core network execution body and the second core network execution body are heterogeneous devices, the digital twin network includes a first twin core network execution body corresponding to the first core network execution body and a second twin core network execution body corresponding to the second core network execution body.

[0048] Optionally, in a case where the first access network execution body and the second access network execution body are heterogeneous devices, and the abnormal execution body includes the first twin access network execution body and / or the second twin access network execution body, when the first security policy for indicating a first component in the abnormal execution body under attack and a replacement suggestion of the first component is generated, the replacement suggestion contains information of a second component for replacing the first component, and the second component and the first component are heterogeneous components.

[0049] In a case where the first core network enforcer and the second core network enforcer are heterogeneous devices to each other, and the abnormal enforcer includes the first twin core network enforcer and / or the second twin core network enforcer, when the first security policy indicating the first component in the abnormal enforcer attacked and the replacement suggestion thereof are generated, the replacement suggestion contains information of a second component for replacing the first component, and the second component and the first component are heterogeneous components to each other.

[0050] In a third aspect, an embodiment of the present application provides a terminal based on an endogenous security architecture of a digital twin network, comprising a processor, a memory, and a program stored in the memory and executable on the processor, and the program is executed by the processor to implement the steps of the method in the second aspect.

[0051] In a fourth aspect, an embodiment of the present application provides a computer readable storage medium, and the computer readable storage medium stores a program, and the program is executed by a processor to implement the steps of the method in any one of the second aspect.

[0052] In a fifth aspect, an embodiment of the present application provides a computer program product comprising computer instructions, and the computer instructions are executed by a processor to implement the steps of the method in any one of the second aspect.

[0053] Compared with the prior art, the implementation method of the security mechanism based on the digital twin network and the endogenous security architecture provided by the embodiment of the present application solve the problem that after the digital twin network is introduced into the mobile communication network, the construction, operation of the multiple heterogeneous enforcers bring influences on the network construction cost, operation and maintenance cost, service performance and time delay, and the fusion development of security, cost and performance can be realized. In addition, the embodiment of the present application can also solve the problem that the homogeneous devices are mutually primary and backup, and after the attack of the vulnerability and backdoor, there is no alternative product, and the unknown vulnerability and backdoor cannot be detected. BRIEF DESCRIPTION OF DRAWINGS

[0054] Various other advantages and benefits will become apparent to those of ordinary skill in the art upon reading the following detailed description of the preferred embodiments. The accompanying drawings are included to provide a description of the preferred embodiments and are not intended to limit the scope of the present application. Moreover, the same reference numerals are used throughout the same figures. In the drawings:

[0055] Figure 1 A schematic diagram of a DHR architecture of a related technology;

[0056] Figure 2 A schematic diagram of an endogenous security architecture of a DTN based on an embodiment of the present application;

[0057] Figure 3An interaction example diagram for the implementation method of the endogenous security mechanism of the embodiment of the present application;

[0058] Figure 4 Another schematic diagram of the endogenous security architecture based on the DTN of the embodiment of the present application. DETAILED DESCRIPTION

[0059] The terms "first", "second", and the like in the present application are used to distinguish similar objects, and are not used to describe a specific order or sequence. It should be understood that the terms thus used can be interchanged under appropriate circumstances, so that the embodiments of the present application can be implemented in an order other than that illustrated or described herein, and the objects distinguished by "first", "second" are generally of a kind and are not limited in number, for example, the first object can be one or more. In addition, "or" in the present application means at least one of the connected objects. For example, "A or B" covers three scenarios, namely, scenario one: including A and not including B; scenario two: including B and not including A; scenario three: including A and B. The character " / " generally represents that the objects before and after are in an "or" relationship.

[0060] The term "indication" in the present application can be a direct indication (or explicit indication) or an indirect indication (or implicit indication). Among them, the direct indication can be understood as that the sender explicitly informs the receiver of specific information, operations to be performed or requested results, etc. in the sent indication; the indirect indication can be understood as that the receiver determines the corresponding information according to the indication sent by the sender, or judges and determines the operations to be performed or the requested results according to the judgment result.

[0061] To help understand the present application, the DHR architecture of the related art is first described.

[0062] Figure 1 A schematic diagram of a DHR architecture of the related art. The DHR architecture includes an input agent, a plurality of heterogeneous execution bodies (such as execution bodies 1, 2, …, n) that are functionally equivalent, a heterogeneous execution body library, a policy decision module, an output selection module, and a feedback controller. The input agent module distributes a service request sequence to K heterogeneous but functionally equivalent execution bodies according to the instructions of the feedback controller. The policy decision module generates a decision policy according to the decision parameters (including algorithms) given by the system, determines the compliance of the multi-mode output vector content (i.e. the output of the selected K execution bodies), and selects or forms a service response sequence. Once an unexpected decision state is found, the feedback control link is activated, and the feedback controller module is activated. After the feedback controller module is activated, it will issue a scheduling command to the policy scheduling, and the policy scheduling module will issue operation instructions such as migration, replacement, or online / offline cleaning recovery to the abnormal execution body that leads to the unexpected decision.

[0063] The DHR architecture based on dynamic selection of execution bodies increases the uncertainty of the attack chain, reduces the success rate of attacks, and reduces the misjudgment rate by excluding failures caused by hardware and software design defects and physical mechanism defects through multi-mode arbitration. The above two measures increase the difficulty and cost of attackers, while also ensuring reliability. Unlike traditional security defense methods (such as intrusion detection, prevention, tolerance, or isolation, antivirus, leak plugging, etc.), DHR analyzes the execution results of different execution bodies to determine whether there is an attack threat, so it does not need to pre-configure attack features.

[0064] With the development of 5G large-scale applications and 6G research, the network is researching towards full SBA, distributed autonomous networking, and integrated fusion of sensing and computing intelligence. New architectures, new businesses, and new elements will make the network more open, with a larger exposure surface, and vulnerabilities and backdoors in open-source software more easily exploited by attackers. In addition to traditional security attacks, attackers, with the help of AI, will constantly identify unknown vulnerabilities. Traditional security protection and detection devices are based on prior knowledge and have weak capabilities in identifying unknown vulnerabilities. The DHR-based architecture does not rely on prior knowledge features, giving it an absolute advantage in identifying unknown vulnerabilities.

[0065] The present application proposes an endogenous security architecture and mechanism based on DTN, which deploys a DHR architecture in the DTN and at least two heterogeneous execution bodies (e.g., as primary and backup devices) in the physical network. The complete DHR architecture is run in the DTN to identify security attacks on the heterogeneous execution bodies in the physical network, and the DTN is used for security analysis and repair measure verification. The security policy is sent to the physical network, so that security attacks on the physical network can be discovered and accurately repaired in a timely manner, improving the security of the physical telecommunications network while having little impact on physical telecommunications network resources and business performance, effectively integrating security, performance, and cost for development.

[0066] The embodiment of the present application proposes an endogenous security architecture based on DTN, as shown in Figure 2 The embodiment of the present application proposes an endogenous security architecture based on DTN, as shown in

[0067] A digital twin network (DTN) is constructed based on a physical network, wherein the physical network includes at least one access network execution body, at least one core network execution body, and a security management center. The digital twin network (DTN) includes a twin execution body corresponding to each function in the physical network, for example, the digital twin network (DTN) includes a twin access network execution body corresponding to the access network execution body, a twin core network execution body corresponding to the core network execution body, and a twin security management center corresponding to the security management center, etc.

[0068] Specifically, the access network execution body can include at least one access network unit, for example, the access network execution body can include an access network unit such as a CU and a DU. The access network unit can include at least one access network component, for example, the CU can be composed of one or more components. Correspondingly, the twin access network execution body corresponding to the access network execution body can include: the twin access network unit corresponding to the access network unit; the twin access network unit corresponding to the access network unit can include: the twin access network component corresponding to the access network component.

[0069] Similarly, the core network execution body can include at least one core network unit, and the core network unit can include at least one core network component; the twin core network execution body corresponding to the core network execution body can include: the twin core network unit corresponding to the core network unit; the twin core network unit corresponding to the core network unit can include: the twin core network component corresponding to the core network component.

[0070] It should be noted that the physical network can also include other functional modules, such as a transport network module, etc. These functional modules can be one device, one module, multiple devices or multiple modules cooperating with each other, and the embodiments of the present application do not make specific limitations thereto. In addition, the digital twin network is also referred to as a network digital twin.

[0071] The digital twin network (DTN) also includes a dynamic heterogeneous redundancy (DHR) architecture. The DHR architecture includes an execution body set, the execution body set includes an access network execution body set and / or a core network execution body set, the access network execution body set includes the twin access network execution body and an additional access network execution body, and the core network execution body set includes the twin core network execution body and an additional core network execution body; wherein the twin access network execution body and the additional access network execution body are heterogeneous execution bodies, and the twin core network execution body and the additional core network execution body are heterogeneous execution bodies. Here, the twin execution body includes the twin access network execution body and / or the twin core network execution body.

[0072] In the embodiments of the present application, the physical network includes an access network execution body, a core network execution body, and a security management center. The functional units in the physical network can work in a master-backup mode, specifically, one set of functional units can be deployed, or multiple sets of heterogeneous or homogeneous functional units can be deployed, and the embodiments of the present application do not make specific limitations thereto. For example, the physical network includes one or more sets of access network execution bodies, and the multiple sets of access network execution bodies can be heterogeneous or homogeneous. The physical network can also include one or more sets of core network execution bodies, and the multiple sets of core network execution bodies can be heterogeneous or homogeneous. The core network execution body can also be referred to as a core network device or an access network function.

[0073] The access network executor can also be referred to as a radio access network (RAN) device, a radio access network function or a radio access network executor. The access network executor can include a base station, a wireless local area network (WLAN) access point (AP) or a wireless fidelity (WiFi) node, etc. The base station can be referred to as a node B (NB), an evolved node B (eNB), a next generation node B (gNB), a new radio node B (NR node B), an access point, a relay base station (RBS), a serving base station (SBS), a base transceiver station (BTS), a radio base station, a radio transceiver, a basic service set (BSS), an extended service set (ESS), a home node B (HNB), a home evolved node B, a transmission reception point (TRP) or some other suitable term in the art, as long as the same technical effect is achieved. The base station is not limited to a specific technical term, and the access network executor in the following embodiments of the present application is taken as an example to illustrate the structure of the access network executor using a DU (distributed unit) and a CU (central unit).

[0074] For example, Figure 2 In the access network executor, the access network executor includes two sets of access network executors, namely an access network executor a and an access network executor b. The access network executor a includes a CU a and a DU a, and the access network executor b includes a CU b and a DU b. In the embodiments of the present application, the access network executor a and the access network executor b can be homogeneous or heterogeneous structures, i.e., each corresponding function (such as the CU a and the CU b) is a homogeneous or heterogeneous structure, which is not limited in the embodiments of the present application.

[0075] The core network execution body can include, but is not limited to, at least one of the following: a core network node, a core network function, a mobility management entity (MME), an access and mobility management function (AMF), a session management function (SMF), a user plane function (UPF), a policy control function (PCF), a policy and charging rules function (PCRF), an edge application server discovery function (EASDF), a unified data management (UDM), a unified data repository (UDR), a home subscriber server (HSS), a centralized network configuration (CNC), a network repository function (NRF), a network exposure function (NEF), a local NEF (L-NEF), a binding support function (BSF), an application function (AF), and the like. It should be noted that in the embodiments of the present application, only the core network execution body in the NR system is taken as an example for introduction, and the specific type of the core network execution body is not limited.

[0076] For example, Figure 2 In the embodiment, the core network execution body includes two sets of core network execution bodies, namely a core network execution body a and a core network execution body b. The core network execution body a includes a mobility management function a, a session management function a, a virtual infrastructure a, and a hardware infrastructure a. The core network execution body b includes a mobility management function b, a session management function b, a virtual infrastructure b, and a hardware infrastructure b. In the embodiments of the present application, the core network execution body a and the core network execution body b can be homogeneous or heterogeneous structures, that is, each corresponding function (such as the mobility management function a and the mobility management function b) is a homogeneous or heterogeneous structure, which is not limited in the embodiments of the present application.

[0077] In the embodiments of the present application, the physical network is a real existing mobile communication network constructed by hardware and software. For example, Figure 2 In the example shown, the devices or functions of the physical network have simple heterogeneous characteristics. For example, the access network execution body a (which can also be referred to as base station a) includes two access network units developed in C language, such as CU a and DU a, which are used as the main devices of the traditional base station on one hand and are used to construct the twin access network execution body a in the DHR architecture based on the above-mentioned base station on the other hand. In addition, the access network execution body b (which can also be referred to as base station b) has two access network units developed in Java language, such as CU b and DU b, which are used as the standby devices of the traditional base station on one hand and are used to construct the twin access network execution body b in the DHR architecture based on the above-mentioned base station on the other hand. After the devices are connected to the network, the CU a and the DU a are used as the main base station to process the signaling and data of the UE and the core network.

[0078] Similarly, the hardware infrastructure a (such as x86 server), the virtual infrastructure a (such as Cent OS+KVM), the mobility management a and the session management a in the core network, and the core network functions (such as developed in C++ language) constitute a cloud-based main core network system, i.e., the core network execution body a. In addition, the twin core network execution body a in the DHR architecture is also constructed based on the above-mentioned cloud-based main core network system. The hardware infrastructure b (such as ARM server), the virtual infrastructure b (such as Euler+XEN), the mobility management function b and the session management function b in the core network, and the core network functions (such as developed in Python language) constitute a cloud-based standby core network system, i.e., the core network execution body b. In addition, the twin core network execution body b in the DHR architecture is also constructed based on the above-mentioned cloud-based standby core network system. The transmission and bearing devices are also deployed in a similar manner. The security management center in the physical network (which can also be deployed according to the field, such as the access network security management center and the core network security management center) is responsible for receiving the security policy from the twin network and issuing it to the related network element execution, and is also responsible for receiving the security log, security event and other information from the network element. Through data collection, the asset information, the running state, the security event and other data of the network element of the physical network are safely reported to the digital twin network. The security management center is a naming of the above-mentioned function set, which can be implemented as a separate module in implementation, or the network management (such as OMC) of the network element can be used to implement the above-mentioned functions. The access network security management center and the core network security management center can be two independent function units, or can be combined as one function unit.

[0079] The digital twin network is constructed according to data obtained from the physical network, and is the same as the physical network, including a twin access network executive corresponding to an access network executive in the physical network and a twin core network executive corresponding to a core network executive in the physical network.

[0080] The embodiment of the present application further constructs at least one additional access network executive in the digital twin network, which is heterogeneous with the twin access network executive, and forms an access network executive set together with the existing twin access network executive.

[0081] The embodiment of the present application further constructs at least one additional core network executive in the digital twin network, which is heterogeneous with the twin core network executive, and forms a core network executive set together with the existing twin core network executive.

[0082] The embodiment of the present application further deploys an input agent module, a scheduling management module, a policy decision module, an output selection module and a feedback controller in the digital twin network, which together with the above-mentioned executive set forms a complete DHR architecture.

[0083] After obtaining the relevant information sent by the UE to the physical network and the network element security event reported by the security management center of the physical network, the digital twin network runs the DHR architecture to identify security risks, trace attacks, and form risk prediction and security policies, and then issues the security policies to the security management center of the physical network.

[0084] For example, as shown in Figure 2 When the access network executive a and the access network executive b are heterogeneous with each other, the DHR architecture can include a twin access network executive a corresponding to the access network executive a and a twin access network executive b corresponding to the access network executive b. In addition, the DHR architecture can further include an additional access network executive c or more additional access network executives (not shown in the figure). These additional access network executives are heterogeneous with the twin access network executive a and the twin access network executive b. That is, the additional access network executives are heterogeneous with the twin access network executives. The above-mentioned additional access network executives and the twin access network executives together form an access network executive set. Figure 2

[0085] If the access network executive a and the access network executive b are isomorphic with each other, at this time, the DHR architecture can only include one twin access network executive corresponding to the access network executive a or the access network executive b. In addition, the DHR architecture can further include one or more additional access network executives. These additional access network executives are heterogeneous with the above-mentioned twin access network executive.

[0086] Similarly, as shown in Figure 2 ​As shown, when the core network execution entity a and core network execution entity b are heterogeneous structures, the DHR architecture may include: a twin core network execution entity a corresponding to core network execution entity a, and a twin core network execution entity b corresponding to core network execution entity b. Additionally, the DHR architecture may also include an additional core network execution entity c or more additional core network execution entities (…). Figure 2 (Not shown in the image). These additional core network execution entities are heterogeneous with the twin core network execution entity a, and also heterogeneous with the twin core network execution entity b. That is, the additional core network execution entities and the twin core network execution entities are heterogeneous to each other. The above-mentioned additional core network execution entities and twin core network execution entities together constitute the access network execution entity set.

[0087] If core network execution entity a and core network execution entity b are isomorphic, then the DHR architecture may include only one twin core network execution entity corresponding to core network execution entity a or core network execution entity b. Alternatively, the DHR architecture may include one or more additional core network execution entities. These additional core network execution entities are heterogeneous in structure from the aforementioned twin core network execution entities.

[0088] To mitigate the impact of deploying a complete DHR architecture in the physical network on network construction costs, service performance, and latency, this application embodiment deploys a DHR architecture in a digital twin network that includes devices that are heterogeneous to those in the physical network. By running the DHR architecture in the digital twin network, security attacks are detected, and the physical network is coordinated to perform device migration, vulnerability patching, etc., thereby achieving an optimal balance between security, cost, and performance. Furthermore, the physical network deploys primary and backup devices in a heterogeneous manner, with the primary device operating normally. Of course, the primary and backup devices can also be homogeneous devices; this application embodiment does not specifically limit this.

[0089] In this embodiment, the DHR architecture is configured to utilize at least two executors in the executor set to process information received from the physical network (e.g., relevant information sent by the UE to the physical network, network element security events reported by the physical network security management center) to obtain a first processing result; generate a first adjudication result based on the first processing result and send it to the twin security management center, wherein the first adjudication result includes information about the abnormal executor; and receive a first security policy from the twin security management center, repair or replace the abnormal executor based on the first security policy, and use the repaired or replaced new executor to process the information received from the physical network to obtain a second processing result; generate a second adjudication result based on the second processing result and send it to the twin security management center.

[0090] The twin security management center is configured to perform security analysis on the first decision result, generate a first security policy and send the first security policy to the DHR architecture, the first security policy including repair or replacement information for the abnormal execution body; and perform security analysis on the second decision result, and in the case that the abnormal execution body is a twin execution body and the new execution body is normal, send a second security policy to the security management center of the physical network, the second security policy including repair or replacement information for a target execution body, the target execution body being an access network execution body and / or a core network execution body corresponding to the abnormal execution body.

[0091] Further, the DHR architecture is further configured to, in the case that the first decision result is generated, update the execution body set according to information of the abnormal execution body contained in the first decision result; and, after the abnormal execution body is repaired or replaced, update the execution body set according to a new execution body after repair or replacement.

[0092] In the embodiments of the present application, the access network execution body includes at least one access network unit, and the access network unit includes at least one access network component. The core network execution body includes at least one core network unit, and the core network unit includes at least one core network component.

[0093] As shown in Figure 2 The DHR architecture further includes a feedback controller and a scheduling management module; wherein,

[0094] The twin security management center is further configured to:

[0095] (1) in the case that the abnormal condition of the abnormal execution body can be alleviated, generate the first security policy for indicating a first component in the abnormal execution body that is attacked and a repair method of the first component, and send the first security policy to the abnormal execution body, wherein the first component includes at least one of the following: an access network unit, an access network component, a core network unit, and a core network component; and after the abnormal execution body is repaired, send a first instruction to the feedback controller, the first instruction being used to request that a new execution body after repair be added to the execution body set;

[0096] (2) in the case that the abnormal condition of the abnormal execution body cannot be alleviated, generate the first security policy for indicating a first component in the abnormal execution body that is attacked and a replacement suggestion of the first component, and send a second instruction to the feedback controller, the second instruction being used to request that the first component be replaced and that a new execution body after replacement be added to the execution body set;

[0097] The abnormal execution body is further configured to, in the case that the first security policy is received, perform repair according to the first security policy to obtain a new execution body after repair;

[0098] The feedback controller is further configured to add the repaired new execution body into the execution body set according to the received first instruction, or replace the first component according to the received second instruction to obtain a new execution body after replacement, and add the new execution body after replacement into the execution body set.

[0099] As shown in Figure 2 The DHR architecture further includes an input agent module, a policy decision module, and an output selection module; wherein,

[0100] The input agent module is configured to receive information from the physical network and distribute the information to at least two execution bodies in the execution body set for processing;

[0101] The policy decision module is configured to generate a first decision result according to the first processing result and send the first decision result to the output selection module, and generate a second decision result according to the second processing result and send the second decision result to the output selection module;

[0102] The output selection module is configured to receive the first decision result and the second decision result and send the first decision result and the second decision result to the twin security management center.

[0103] Further, the policy decision module is further configured to send information of the abnormal execution body to the feedback controller after generating the first decision result;

[0104] The feedback controller is configured to perform scheduling of abnormal execution bodies based on a preset scheduling strategy through the scheduling management module, and send execution body update information to the input agent module according to the scheduling result, wherein, in the case that the abnormal execution body is a twin execution body, the abnormal twin execution body is replaced.

[0105] Optionally, the physical network includes a first access network execution body as a primary device and a second access network execution body as a backup device; wherein, in the case that the first access network execution body and the second access network execution body are homogenous devices, the digital twin network includes one twin access network execution body, the twin access network execution body corresponds to the first access network execution body or the second access network execution body; in the case that the first access network execution body and the second access network execution body are heterogeneous devices, the digital twin network includes a first twin access network execution body corresponding to the first access network execution body, and a second twin access network execution body corresponding to the second access network execution body.

[0106] Similarly, the physical network includes a first core network executor as a primary device and a second core network executor as a backup device; wherein, in the case that the first core network executor and the second core network executor are homogenous devices, the digital twin network includes one twin core network executor corresponding to the first core network executor or the second core network executor; in the case that the first core network executor and the second core network executor are heterogeneous devices, the digital twin network includes: a first twin core network executor corresponding to the first core network executor; and a second twin core network executor corresponding to the second core network executor.

[0107] Optionally, in the case that the first access network executor and the second access network executor are heterogeneous devices, and the abnormal executor includes the first twin access network executor and / or the second twin access network executor, when the first security policy indicating the first component in the abnormal executor that is attacked and the replacement suggestion thereof is generated, the replacement suggestion contains information of a second component for replacing the first component, and the second component and the first component are heterogeneous components. Here, the first component can be specifically an access network unit and / or an access network component.

[0108] In the case that the first core network executor and the second core network executor are heterogeneous devices, and the abnormal executor includes the first twin core network executor and / or the second twin core network executor, when the first security policy indicating the first component in the abnormal executor that is attacked and the replacement suggestion thereof is generated, the replacement suggestion contains information of a second component for replacing the first component, and the second component and the first component are heterogeneous components. Here, the first component can be specifically a core network unit and / or a core network component.

[0109] The embodiments of the present application also provide an implementation method of the endogenous security mechanism, applied to Figure 2 The endogenous security architecture based on the digital twin network shown in the figure, the method comprises:

[0110] S1, using at least two executors in the executor set, processing information received from the physical network to obtain a first processing result; generating a first decision result according to the first processing result and sending it to the twin security management center, the first decision result containing information of an abnormal executor; and receiving a first security policy from the twin security management center, repairing or replacing the abnormal executor based on the first security policy, and using the new executor after repair or replacement to process information received from the physical network to obtain a second processing result; generating a second decision result according to the second processing result and sending it to the twin security management center.

[0111] S2, performing security analysis on the first decision result by the twin security management center, generating a first security policy and sending the first security policy to the DHR architecture, the first security policy including repair or replacement information for the abnormal execution body; and performing security analysis on the second decision result, and in a case that the abnormal execution body is a twin execution body and the new execution body is normal, sending a second security policy to a security management center of the physical network, the second security policy including repair or replacement information for a target execution body, the target execution body being an access network execution body and / or a core network execution body corresponding to the abnormal execution body.

[0112] Optionally, the method further includes:

[0113] In a case that the first decision result is generated, updating the execution body set according to information of the abnormal execution body contained in the first decision result; and in a case that the abnormal execution body is repaired or replaced, updating the execution body set according to the new execution body after repair or replacement.

[0114] Optionally, the method further includes:

[0115] In a case that the abnormal condition of the abnormal execution body can be alleviated, the twin security management center generates the first security policy for indicating a first component of the abnormal execution body that is attacked and a repair method of the first component, and sends the first security policy to the abnormal execution body, wherein the first component includes at least one of an access network unit, an access network component, a core network unit, and a core network component; and in a case that the abnormal execution body is repaired, sends a first instruction to the feedback controller, the first instruction being used to request that the new execution body after repair is added to the execution body set.

[0116] In a case that the abnormal condition of the abnormal execution body cannot be alleviated, the twin security management center generates the first security policy for indicating a first component of the abnormal execution body that is attacked and a replacement suggestion of the first component, and sends a second instruction to the feedback controller, the second instruction being used to request that the first component is replaced and the new execution body after replacement is added to the execution body set.

[0117] In a case that the abnormal execution body receives the first security policy, the abnormal execution body is repaired according to the first security policy to obtain the new execution body after repair.

[0118] The feedback controller adds the new execution body after repair to the execution body set according to the received first instruction, or replaces the first component to obtain the new execution body after replacement of the component according to the received second instruction, and adds the new execution body after replacement of the component to the execution body set.

[0119] Optionally, the method further comprises:

[0120] The input agent module receives information from the physical network and distributes to at least two execution bodies in the execution body set for processing;

[0121] The policy decision module generates a first ruling result according to the first processing result and sends it to the output selection module, and generates a second ruling result according to the second processing result and sends it to the output selection module;

[0122] The output selection module receives the first ruling result and the second ruling result and sends them to the twin security management center.

[0123] Optionally, the method further comprises:

[0124] The policy decision module sends the information of the abnormal execution body to the feedback controller after generating the first ruling result;

[0125] The feedback controller executes the scheduling of the abnormal execution body based on the preset scheduling strategy through the scheduling management module, and sends the execution body update information to the input agent module according to the scheduling result, wherein, in the case that the abnormal execution body is a twin execution body, the abnormal twin execution body is replaced.

[0126] Optionally, the physical network of the embodiment of the application comprises a first access network execution body as a master device and a second access network execution body as a backup device; wherein, in the case that the first access network execution body and the second access network execution body are homogenous devices, the digital twin network comprises one twin access network execution body, which corresponds to the first access network execution body or the second access network execution body; in the case that the first access network execution body and the second access network execution body are heterogeneous devices, the digital twin network comprises: a first twin access network execution body corresponding to the first access network execution body; a second twin access network execution body corresponding to the second access network execution body;

[0127] The physical network comprises a first core network executor as a master device and a second core network executor as a backup device; wherein, in the case that the first core network executor and the second core network executor are homogenous devices, the digital twin network comprises one twin core network executor corresponding to the first core network executor or the second core network executor; in the case that the first core network executor and the second core network executor are heterogeneous devices, the digital twin network comprises: a first twin core network executor corresponding to the first core network executor; and a second twin core network executor corresponding to the second core network executor.

[0128] Optionally, in the case that the first access network executor and the second access network executor are heterogeneous devices, and the abnormal executor comprises the first twin access network executor and / or the second twin access network executor, when the first security policy indicating the first component in the abnormal executor that is attacked and the replacement suggestion thereof is generated, the replacement suggestion comprises information of a second component for replacing the first component, and the second component and the first component are heterogeneous components. Here, the first component can be specifically a first access network unit and / or a first access network component, and the second component can be specifically a second access network unit and / or a second access network component.

[0129] In the case that the first core network executor and the second core network executor are heterogeneous devices, and the abnormal executor comprises the first twin core network executor and / or the second twin core network executor, when the first security policy indicating the first component in the abnormal executor that is attacked and the replacement suggestion thereof is generated, the replacement suggestion comprises information of a second component for replacing the first component, and the second component and the first component are heterogeneous components. Here, the first component can be specifically a first core network unit and / or a first core network component, and the second component can be specifically a second core network unit and / or a second core network component.

[0130] The implementation method of the above endogenous security mechanism of the embodiment of the present application is further described below through an example diagram of interaction between various functions / modules.

[0131] Example 1: Related flow of abnormality detection and handling by a heterogeneous twin executor a

[0132] Figure 3 For the flow of example 1. In the execution Figure 3Before the middle process, a digital twin network has been built according to the data collected by the physical network, and a DHR architecture has been built according to the requirements of network security applications in the twin application layer of the digital twin network, which is used for security monitoring of devices in the physical network. The DHR architecture in the twin network can be deployed separately in access networks, core networks, and other subfields (such as access network DHR architecture and core network DHR architecture), or the access network, core network, and other subfields can share the same DHR architecture to form an end-to-end DHR architecture. As shown in FIG. 8, the process includes: Figure 3

[0133] Step 1. After the input agent module (sometimes also referred to as the input agent in this paper) receives information (such as access requests sent by UEs) obtained from the physical network, the information is distributed to selected executors. The selection of which executors to select in the initial stage of system operation can be configured by the administrator, and usually needs to include the above-mentioned twin executors (i.e., twin executors corresponding to access network executors / core network executors in the physical network, such as twin access network executor a, twin access network executor b, twin core network executor a, and twin core network executor b).

[0134] Step 2. After the executors receive the information sent by the input agent, they process the information and generate processing results.

[0135] Step 3. The executors send the results of processing the information to the policy decision module.

[0136] Step 4. The policy decision module makes a decision on the processing results of all executors received according to decision parameters (such as the number of executors, the number of normal output results, etc.), related algorithms (such as voting, weighted voting, etc.), and obtains a decision result, which includes abnormal executor information (such as an abnormal executor list containing the names of abnormal executors, abnormal features, etc.) and correct processing results. Here, it is assumed that the abnormal executors include the twin executor a (such as the twin access network executor a / twin core network executor a) and do not include the twin executor b (such as the twin access network executor b / twin core network executor b), and can also include additional executors.

[0137] Step 5. The policy decision module sends the abnormal executor information in the decision result to the feedback controller, which can include an abnormal executor list (containing the twin executor a) and abnormal features.

[0138] Step 6. The feedback controller decides to replace, reorganize, clean, etc. the abnormal executors according to the preset scheduling strategy, etc., and executes the scheduling of abnormal executors in the scheduling management module. For the twin executor a, the replacement method is used (for example, using other executors such as additional executors to replace the twin executor a, and then the twin executor a can be repaired. After repair, if it passes the verification, it can be re-added to the executor set). ​

[0139] Step 7. The feedback controller sends the body update information to the input agent module, which can be the updated body distribution list.

[0140] Step 8. The policy decision module sends the verdict to the output selection module.

[0141] Step 9. The output selection module sends the verdict to the authorized verdict subscriber (such as the security management center). The security management center as a verdict subscriber needs to successfully subscribe to the verdict in advance to the output selection module. When the output selection module receives the verdict, it sends the result to the security management center of the digital twin network (i.e., the twin security management center).

[0142] Note: The policy decision module performs step 5, and the time of step 8 is not sequential.

[0143] Step 10. The twin security management center analyzes the verdict information and identifies the security attack (such as the exploitation of vulnerabilities or backdoors) of the twin body a. For example, the security management center compares the execution results of each component of the twin body a with the execution results of each component of a certain body with correct output, finds the components with inconsistent execution results, and simulates the input and output of these components multiple times to identify the input that will cause output errors, thereby identifying unknown vulnerabilities. If it can be mitigated, such as vulnerabilities or backdoors have a repair mechanism, a security policy is generated, which contains the specific components of the twin body a that are attacked, the repair method (such as the network element operating system prohibiting certain function calls, etc.), and steps 11 and 12 are executed. If there is no mitigation mechanism, a security policy is generated, which contains the specific components of the twin body a that are attacked, component replacement recommendations (such as selecting the same type of components in body b), and directly enters step 13.

[0144] Step 11. The twin security management center sends an execution security policy request to the body a for repair.

[0145] Step 12. The body a repairs according to the security policy request and returns an execution security policy response. Then go to step 14.

[0146] Step 13. The twin security management center sends a reorganization body instruction to the feedback controller, including the repair success information of the twin body a (twin body a identifier, repaired component identifier), the new body a after the repair component joins the body set request, etc. For the replacement component scenario, the reorganization body instruction includes the replacement twin body a information (twin body a identifier, replaced component identifier, replacement component identifier), the replacement component after the new body a joins the body set request, etc.

[0147] Step 14. The feedback controller, according to the received recombined execution body instruction, links the repaired twin execution body a or the new execution body a after replacing the attacked component to the scheduling management module to join the execution body set.

[0148] Step 15. The feedback controller sends the execution body update information to the input agent.

[0149] Step 16. Steps 1 to 9 are executed, and the twin security management center receives the subscribed execution body result to perform security analysis. If the repaired twin execution body a or the new execution body a after replacing the attacked component is found to be normal, step 17 is executed. Otherwise, the twin security management center analyzes whether the security attack suffered by the repaired twin execution body a or the new execution body a after replacing the attacked component can be mitigated, and if so, steps 101 to 17 are executed; if not, steps 13 to 17 are executed.

[0150] Step 17. The security policy is sent to the security management center of the physical network, including the identification of the twin execution body a, the identification of the specific component in the twin execution body a that is attacked, the repair method or replacement component suggestion (such as switching the service of the component to a backup component), etc.

[0151] Step 18. The security management center of the physical network and the network element perform repair on the network element (such as the access network execution body and / or the core network execution body) corresponding to the twin execution body a according to the security policy, and for the replacement component scenario, switch the service of the component to a backup component.

[0152] For the scenario of switching to a backup component, when the replaced component in the original network element finds a mitigation mechanism and is repaired, it can be added to the execution body set for verification, and after confirming the security, it is re-added to the execution body a to ensure the heterogeneity of the execution body a and the execution body b. Or use a new component that is heterogeneous with the execution body b, verify it in the DTN, and then add it to the execution body a to ensure the heterogeneity of the execution body a and the execution body b.

[0153] Example 2: Related process of twin execution body b detecting and handling an anomaly

[0154] The twin execution body a and the twin execution body b are heterogeneous structures. The process is generally similar to the process shown in Figure 3 . Assume that the twin execution body b is a backup device in the physical network, so when the process in Figure 3 , in step 10, the twin security management center of the digital twin network detects that the reason for the anomaly of the twin execution body b is that a component is unrepairable and needs to be replaced, a new component (such as component b) that is heterogeneous with the twin execution body a needs to be selected. In step 17, the replacement component suggestion includes the name, supplier, and other information of the suggested replacement component.

[0155] For the scenario of replacing to new components, when the replaced component (such as component a) in the original executor b finds a mitigation mechanism and is repaired, it can be added to the executor set for verification through the DTN, and after confirming the safety, the replaced component in the original executor b that is repaired can be used to replace the new component (such as component b) when the new component temporarily cannot be mitigated.

[0156] Example 3: Related process of isomorphic twin executors a and b both detecting and handling exceptions

[0157] Reference Figure 3 In the process shown, in step 10, the security management center of the digital twin network can detect multiple abnormal reasons, and the subsequent actions will be different:

[0158] a) Some components of the twin executor a and the twin executor b are attacked, but the components have a mitigation mechanism, and step 11 is performed. The security policy needs to include the repair method of the attacked components of the executor a and the executor b. In steps 12 to 18, component repair, recombined executor verification, and security policy containing the repaired component issued to the security management center of the physical network are all related to the network elements (such as access network executors and / or core network executors) corresponding to the twin executor a and the twin executor b.

[0159] b) Some components of the twin executor a and the twin executor b are attacked, but the components do not have a mitigation mechanism, and step 11 is performed. The security policy needs to include the replacement method of the attacked components of the twin executor a and the twin executor b. In steps 12 to 18, component replacement, recombined executor verification, and security policy containing the replaced component issued to the security management center of the physical network are all related to the twin executor a and the twin executor b. If some components of the twin executor a and the twin executor b are temporarily without a mitigation mechanism, the security management center does not specify the name of the replaced component in the replacement suggestion.

[0160] c) Some components of the twin executor a and the twin executor b are attacked, one component of a twin executor has a mitigation mechanism, and the other component does not have a mitigation mechanism, and step 11 is performed. The security policy needs to include the repair method of the attacked component and the replacement method of the attacked component. In steps 12 to 18, component repair / replacement, recombined executor verification, and security policy containing the repaired / replaced component issued to the security management center of the physical network are all related to the network elements (such as access network executors and / or core network executors) corresponding to the respective twin executor a and twin executor b. If some components of the executor a or the executor b are temporarily without a mitigation mechanism, the security management center does not specify the name of the replaced component in the replacement suggestion.

[0161] It should be further noted that the primary and backup devices deployed in the physical network in the embodiments of the present application can also be homogeneous, at which time they correspond to the same execution body in the digital twin network, such as the twin execution body a. In this scenario, the twin execution body a is generated in the digital twin network according to the physical network mapping, and other heterogeneous additional execution bodies are constructed in the digital twin network, and then the steps in the method are executed Figure 3 In step 1, the system runs the selected execution body in the initial stage, which usually contains the twin execution body a. If the component of the twin execution body a in the digital twin network mapped from the physical network is attacked, the security management center judges that there is a mitigation mechanism in step 10, and executes steps 11 and 12. If there is no mitigation mechanism, a security policy is generated, which contains the specific component of the twin execution body a that is attacked, the component replacement suggestion, and directly executes step 13. The subsequent steps 14 to 18 are the same, except that the replacement suggestion in step 17 is not the backup device component, but other recommended components or no specific replacement component is specified.

[0162] From the above, it can be seen that the embodiments of the present application solve the influence of the construction, operation of the multiple heterogeneous execution bodies of the digital twin network on the network construction cost, operation and maintenance cost, business performance and time delay after the introduction of the mobile communication network, and can realize the integrated development of security, cost and performance. In addition, the embodiments of the present application can also solve the problem that the homogeneous devices are mutually primary and backup, and after the attack of vulnerabilities, backdoors and the like, there is no alternative product, and the unknown vulnerabilities and backdoors cannot be detected.

[0163] Another embodiment of the present application provides an endogenous security architecture based on a digital twin network, as shown in Figure 4 The processor 400 executes the program or instruction to implement each process of the implementation method embodiment of the above endogenous security mechanism, and can achieve the same technical effect. To avoid repetition, it will not be described here.

[0164] The transceiver 410 is used to receive and send data under the control of the processor 400.

[0165] In the above embodiment, the method for constructing the digital twin network is described, and the method for constructing the digital twin network is also applicable to the method for constructing the endogenous security architecture based on the digital twin network. Figure 4In particular embodiments, the bus architecture can include any number of interconnecting buses and bridges, depending on the specific application of the processor 400 and the overall design constraints. The bus architecture can link together various circuits such as one or more processors represented by the processor 400, and the memory represented by the memory 420. The bus architecture can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and thus, not described further. The bus interface provides an interface to the transceiver 410, which can be a plurality of elements including a transmitter and a receiver, providing a means for communicating with various other apparatus over a transmission medium. The processor 400 is responsible for managing the bus architecture and general processing, including the processing for the operations performed by the processor 400. The memory 420 can store data for use by the processor 400 in executing operations.

[0166] The embodiment of the present application further provides a computer readable storage medium, which stores a computer program. The computer program is executed by a processor to implement each process of the embodiment of the implementation method of the endogenous security mechanism based on a digital twin network, and can achieve the same technical effects. To avoid repetition, details are not described herein. The computer readable storage medium is, for example, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disk.

[0167] The embodiment of the present application further provides a computer program product, which includes computer instructions. The computer instructions are executed by a processor to implement each process of the embodiment of the implementation method of the endogenous security mechanism based on a digital twin network, and can achieve the same technical effects. To avoid repetition, details are not described herein.

[0168] It should be noted that in this document, the terms "comprising", "containing" or any other variant thereof are intended to cover non-exclusive inclusions, so that processes, methods, articles or apparatuses including a series of elements not only include those elements, but also include other elements not explicitly listed or inherent to such processes, methods, articles or apparatuses. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of another identical element in the process, method, article or apparatus including the element.

[0169] Those skilled in the art can clearly understand the above-mentioned embodiment method can be realized by means of software and necessary general hardware platform, of course, also can be through hardware, but many cases the former is the better embodiment. Based on such understanding, the technical solutions of the present application essentially or say the part of the contribution to the prior art can be embodied in the form of software product, the computer software product is stored in a storage medium (such as ROM / RAM, disk, optical disk), including a number of instructions to make a terminal (may be a mobile phone, computer, server, air conditioner, or network equipment, etc.) executes the method described in various embodiments of the present application.

[0170] The embodiments of the present application are described above in combination with the drawings, but the present application is not limited to the above-mentioned specific embodiments, the above-mentioned specific embodiments are only illustrative, but not limited, those skilled in the art can make many forms without departing from the purpose of the present application and the scope protected by the claims under the inspiration of the present application, all belong to the protection of the present application.

Claims

1. An endogenous security architecture based on digital twin network, characterized in that, The method comprises: constructing a digital twin network based on a physical network, wherein the physical network comprises at least one access network executor, at least one core network executor, and a security management center; the digital twin network comprises a twin access network executor corresponding to the access network executor, a twin core network executor corresponding to the core network executor, and a twin security management center corresponding to the security management center; the digital twin network further comprises a dynamic heterogeneous redundancy (DHR) architecture; the DHR architecture comprises an executor set, the executor set comprising an access network executor set and / or a core network executor set, the access network executor set comprising the twin access network executor and an additional access network executor, and the core network executor set comprising the twin core network executor and an additional core network executor; wherein the twin access network executor and the additional access network executor are heterogeneous executors, and the twin core network executor and the additional core network executor are heterogeneous executors.

2. The endogenous security architecture of claim 1, wherein the DHR architecture is configured to process information received from the physical network by using at least two executors in the executor set to obtain a first processing result, generate a first decision result based on the first processing result and send the first decision result to the twin security management center, wherein the first decision result comprises information of an abnormal executor, and receive a first security policy from the twin security management center, repair or replace the abnormal executor based on the first security policy, and process information received from the physical network by using a new executor after the repair or replacement to obtain a second processing result; generate a second decision result based on the second processing result and send the second decision result to the twin security management center; the twin security management center is configured to perform security analysis on the first decision result, generate a first security policy and send the first security policy to the DHR architecture, wherein the first security policy comprises repair or replacement information for the abnormal executor, and perform security analysis on the second decision result, and in a case where the abnormal executor is a twin executor and the new executor is normal, send a second security policy to a security management center of the physical network, wherein the second security policy comprises repair or replacement information for a target executor, and the target executor is an access network executor and / or a core network executor corresponding to the abnormal executor.

3. The endogenous security architecture of claim 2, wherein the DHR architecture is further configured to, in a case where the first decision result is generated, update the executor set based on information of the abnormal executor contained in the first decision result, and after the abnormal executor is repaired or replaced, update the executor set based on the new executor after the repair or replacement.

4. The endogenous security architecture of claim 2, wherein The access network execution body comprises at least one access network unit, and the access network unit comprises at least one access network component; the core network execution body comprises at least one core network unit, and the core network unit comprises at least one core network component; The DHR architecture further comprises a feedback controller and a scheduling management module; wherein, The twin security management center is further configured to: in the case that the abnormal condition of the abnormal execution body can be alleviated, generate the first security policy for indicating the first component in the abnormal execution body that is attacked and a repair method thereof, and send the first security policy to the abnormal execution body, wherein the first component comprises at least one of the following: an access network unit, an access network component, a core network unit, and a core network component; and after the abnormal execution body is repaired, send a first instruction to the feedback controller, wherein the first instruction is used to request that a new execution body after repair be added to the execution body set; in the case that the abnormal condition of the abnormal execution body cannot be alleviated, generate the first security policy for indicating the first component in the abnormal execution body that is attacked and a replacement suggestion thereof, and send a second instruction to the feedback controller, wherein the second instruction is used to request that the first component be replaced, and a new execution body after replacement be added to the execution body set; The abnormal execution body is further configured to, in the case that the first security policy is received, perform repair according to the first security policy to obtain a new execution body after repair; The feedback controller is further configured to, according to the received first instruction, add the new execution body after repair to the execution body set, or, according to the received second instruction, replace the first component to obtain a new execution body after replacement, and add the new execution body after replacement to the execution body set.

5. The endogenous security architecture of claim 4, wherein, The DHR architecture further comprises an input agent module, a policy decision module, and an output selection module; wherein, The input agent module is configured to receive information from the physical network and distribute the information to at least two execution bodies in the execution body set for processing; The policy decision module is configured to generate a first ruling result according to the first processing result and send the first ruling result to the output selection module, and generate a second ruling result according to the second processing result and send the second ruling result to the output selection module; The output selection module is configured to receive the first ruling result and the second ruling result and send the first ruling result and the second ruling result to the twin security management center.

6. The endogenous security architecture of claim 5, wherein, The policy decision module is further configured to, after the first ruling result is generated, send information of the abnormal execution body to the feedback controller; The feedback controller is configured to execute scheduling of the abnormal execution body based on a preset scheduling strategy and through the scheduling management module, and send execution body update information to the input agent module according to a scheduling result, wherein in the case that the abnormal execution body is a twin execution body, the abnormal twin execution body is replaced.

7. The endogenous security architecture of claim 6, wherein, The physical network includes a first access network executor as a primary device and a second access network executor as a backup device; wherein, in the case that the first access network executor and the second access network executor are homogenous devices, the digital twin network includes one twin access network executor corresponding to the first access network executor or the second access network executor; in the case that the first access network executor and the second access network executor are heterogeneous devices, the digital twin network includes a first twin access network executor corresponding to the first access network executor and a second twin access network executor corresponding to the second access network executor; The physical network includes a first core network executor as a primary device and a second core network executor as a backup device; wherein, in the case that the first core network executor and the second core network executor are homogenous devices, the digital twin network includes one twin core network executor corresponding to the first core network executor or the second core network executor; in the case that the first core network executor and the second core network executor are heterogeneous devices, the digital twin network includes a first twin core network executor corresponding to the first core network executor and a second twin core network executor corresponding to the second core network executor.

8. The endogenous security architecture of claim 7, wherein, In the case that the first access network executor and the second access network executor are heterogeneous devices, and the abnormal executor includes the first twin access network executor and / or the second twin access network executor, when the first security policy indicating the first component in the abnormal executor that is attacked and the replacement suggestion thereof is generated, the replacement suggestion contains information for replacing a second component of the first component, and the second component and the first component are heterogeneous components; In the case that the first core network executor and the second core network executor are heterogeneous devices, and the abnormal executor includes the first twin core network executor and / or the second twin core network executor, when the first security policy indicating the first component in the abnormal executor that is attacked and the replacement suggestion thereof is generated, the replacement suggestion contains information for replacing a second component of the first component, and the second component and the first component are heterogeneous components.

9. An implementation method of an endogenous security mechanism based on a digital twin network, applied to the endogenous security architecture based on a digital twin network in claim 1, characterized in that, The method comprises: processing information received from the physical network by using at least two execution bodies in the execution body set to obtain a first processing result; generating a first decision result according to the first processing result and sending the first decision result to the twin security management center, the first decision result containing information of an abnormal execution body; and receiving a first security policy from the twin security management center, repairing or replacing the abnormal execution body based on the first security policy, and processing information received from the physical network by using the new execution body after the repair or replacement to obtain a second processing result; generating a second decision result according to the second processing result and sending the second decision result to the twin security management center; by the twin security management center, performing security analysis on the first decision result to generate a first security policy and send the first security policy to the DHR architecture, the first security policy including repair or replacement information for the abnormal execution body; and performing security analysis on the second decision result, and in the case that the abnormal execution body is a twin execution body and the new execution body is not abnormal, sending a second security policy to the security management center of the physical network, the second security policy including repair or replacement information for a target execution body, the target execution body being an access network execution body and / or a core network execution body corresponding to the abnormal execution body.

10. The method of claim 9, wherein, Further comprising: in the case of generating the first decision result, updating the execution body set according to the information of the abnormal execution body contained in the first decision result; and, after repairing or replacing the abnormal execution body, updating the execution body set according to the new execution body after the repair or replacement.

11. The method of claim 9, wherein, The access network execution body includes at least one access network unit, and the access network unit includes at least one access network component; the core network execution body includes at least one core network unit, and the core network unit includes at least one core network component; The DHR architecture further includes a feedback controller and a scheduling management module; the method further includes: in the case that the abnormal condition of the abnormal execution body can be alleviated, the twin security management center generates the first security policy for indicating a first component in the abnormal execution body that is attacked and a repair method of the first component, and sends the first security policy to the abnormal execution body, wherein the first component includes at least one of the following: an access network unit, an access network component, a core network unit, and a core network component; and after the abnormal execution body is repaired, sends a first instruction to the feedback controller, the first instruction being used to request that a new execution body after the repair be added to the execution body set; in the case that the abnormal condition of the abnormal execution body cannot be alleviated, the twin security management center generates the first security policy for indicating a first component in the abnormal execution body that is attacked and a replacement suggestion of the first component, and sends a second instruction to the feedback controller, the second instruction being used to request that the first component be replaced and that a new execution body after the replacement be added to the execution body set; The abnormal execution body, upon receiving the first security policy, repairs according to the first security policy to obtain a repaired new execution body; The feedback controller, according to the received first instruction, adds the repaired new execution body to the execution body set, or, according to the received second instruction, replaces the first component to obtain a new execution body after replacement of the component, and adds the new execution body after replacement of the component to the execution body set.

12. The method of claim 11, wherein, The DHR architecture further comprises an input agent module, a policy decision module and an output selection module; the method further comprises: The input agent module receives information from the physical network and distributes to at least two execution bodies in the execution body set for processing; The policy decision module generates a first ruling result according to the first processing result and sends it to the output selection module; and generates a second ruling result according to the second processing result and sends it to the output selection module; The output selection module receives the first ruling result and the second ruling result and sends them to the twin security management center.

13. The method of claim 12, wherein, Further comprising: After the policy decision module generates the first ruling result, it sends the information of the abnormal execution body to the feedback controller; The feedback controller, based on a preset scheduling strategy, executes the scheduling of the abnormal execution body through the scheduling management module, and according to the scheduling result, sends execution body update information to the input agent module, wherein, in the case of the abnormal execution body being a twin execution body, the abnormal twin execution body is replaced.

14. The method of claim 13, wherein The physical network comprises a first access network execution body as a primary device and a second access network execution body as a backup device; wherein, in the case that the first access network execution body and the second access network execution body are homogenous devices to each other, the digital twin network comprises one twin access network execution body corresponding to the first access network execution body or the second access network execution body; in the case that the first access network execution body and the second access network execution body are heterogeneous devices to each other, the digital twin network comprises: a first twin access network execution body corresponding to the first access network execution body; a second twin access network execution body corresponding to the second access network execution body; The physical network comprises a first core network execution body as a primary device and a second core network execution body as a backup device; wherein, in the case that the first core network execution body and the second core network execution body are homogenous devices to each other, the digital twin network comprises one twin core network execution body corresponding to the first core network execution body or the second core network execution body; in the case that the first core network execution body and the second core network execution body are heterogeneous devices to each other, the digital twin network comprises: a first twin core network execution body corresponding to the first core network execution body; a second twin core network execution body corresponding to the second core network execution body.

15. The method of claim 14, wherein In the case that the first access network enforcer and the second access network enforcer are heterogeneous devices, and the abnormal enforcer includes the first twin access network enforcer and / or the second twin access network enforcer, when the first security policy indicating the first component in the abnormal enforcer that is attacked and the replacement suggestion thereof is generated, the replacement suggestion contains information for replacing the second component of the first component, and the second component and the first component are heterogeneous components. In the case that the first core network enforcer and the second core network enforcer are heterogeneous devices, and the abnormal enforcer includes the first twin core network enforcer and / or the second twin core network enforcer, when the first security policy indicating the first component in the abnormal enforcer that is attacked and the replacement suggestion thereof is generated, the replacement suggestion contains information for replacing the second component of the first component, and the second component and the first component are heterogeneous components.

16. An endogenous security architecture based on a digital twin network, characterized in that, Comprise: a transceiver, a processor, a memory, and a program or instructions stored on the memory and executable on the processor; the processor executes the program or instructions to implement the steps of the method of any one of claims 9 to 15.

17. A computer-readable storage medium, characterized in that, The computer program is stored on the computer readable storage medium, and the computer program is executed by the processor to implement the steps of the method of any one of claims 9 to 15.

18. A computer program product, characterised in that, The computer program is stored on the computer readable storage medium, and the computer program is executed by the processor to implement the steps of the method of any one of claims 9 to 15. The computer program is stored on the computer readable storage medium, and the computer program is executed by the processor to implement the steps of the method of any one of claims 9 to 15.