5G network distributed service security access enhancement method and power generation side management system

By optimizing the dynamic security authentication module through directed acyclic graph group learning and hierarchical reinforcement learning, the problem of low security for distributed service access in 5G networks is solved, achieving efficient and secure terminal access authentication, adapting to unknown threats and protecting data privacy.

CN121334673APending Publication Date: 2026-01-13STATE GRID HEBEI ELECTRIC POWER CO LTD +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511441233.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-10
Publication Date
2026-01-13

AI Technical Summary

Technical Problem

5G networks suffer from low security in distributed service access, traditional firewalls and intrusion detection systems struggle to cover edge nodes, traditional security access mechanisms are weak against unknown attacks, centralized machine learning model training faces risks of data transmission latency and privacy leaks, and blockchain throughput bottlenecks prevent efficient operation of group learning.

Method used

The model parameters of the dynamic security authentication module are optimized by adopting a directed acyclic graph population learning module, features are extracted by the edge data plane processing module, and network topology is managed by a hierarchical reinforcement learning dynamic partitioning mechanism to build a decentralized secure access system, thereby achieving collaborative optimization of model parameters and security authentication.

Benefits of technology

It improves the security and accuracy of distributed terminal access authentication, reduces the risk of data leakage, enhances the ability to identify unknown threats, ensures the system's adaptive scalability and robustness, and meets the business requirements of low latency and high reliability.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121334673A_ABST
    Figure CN121334673A_ABST
Patent Text Reader

Abstract

The invention provides a 5G network distributed service security access enhancement method and a power generation side management system, and relates to the technical field of mobile communication. The method is realized based on a security access system, the security access system comprises a distributed terminal, an edge data plane processing module, a dynamic security authentication module and a directed acyclic graph group learning module, and the method comprises the following steps: the distributed terminal transmits service flow data to the corresponding edge data plane processing module; the edge data surface processing module performs feature extraction on the service flow data; the optimized dynamic security authentication module judges the access authentication security of the service flow data according to the extracted features; wherein model parameters of the dynamic security authentication module are obtained by optimizing the directed acyclic graph group learning module. According to the invention, the distributed service access security of the 5G network can be improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of mobile communication technology, and in particular to a method for enhancing secure access to distributed services in 5G networks and a power generation-side management system. Background Technology

[0002] With its core characteristics of high bandwidth, low latency, and massive connectivity, 5G communication technology has become a core infrastructure supporting the operation of key sectors such as the Industrial Internet of Things (IIoT), the Internet of Vehicles (IoV), and smart grids. In these scenarios, distributed photovoltaic power station collaborative control, smart grids, and autonomous vehicle platooning control place extremely stringent demands on end-to-end network latency and data processing efficiency. To meet these requirements, one of the core directions of 5G network architecture evolution is to push the core network's User Plane Function (UPF) down to the network edge, deploying it on multi-access edge computing (MEC) nodes close to the data source. Through local traffic offloading and processing, this significantly reduces service latency and alleviates the load on the core network.

[0003] However, while the UPF-based architecture improves business performance, it also poses challenges to the security of distributed business access, directly weakening access security: First, network boundaries expand significantly with the deployment of UPFs, resulting in decentralized and wide-area access points. Traditional centralized firewalls and intrusion detection systems struggle to cover all edge nodes, making it impossible to comprehensively and in real-time monitor and protect against massive edge traffic. Second, distributed control terminals, such as photovoltaic inverters, industrial sensors, and vehicle controllers, are heterogeneous in type and have complex behavior patterns. Furthermore, most terminals are limited by hardware resources, making it impossible to deploy complex security clients. Third, traditional security access mechanisms rely on static rules or attack signatures, which can only identify known threats. They are extremely weak in defending against dynamic and unknown attacks such as zero-day attacks and behavioral masquerading attacks. These types of attacks are the main security risks in distributed business access scenarios, further exacerbating access security risks.

[0004] While the application of machine learning technology has provided a new path for intelligent threat detection, traditional centralized model training methods in distributed scenarios have bottlenecks: on the one hand, aggregating massive amounts of business data from edge terminals to a central node to train models will reintroduce data transmission latency, violating the core intention of UPF's "low latency" and potentially leading to data privacy leaks; on the other hand, the data view of a single edge node is limited, and models trained solely on local data are prone to overfitting, have poor generalization ability, and are difficult to cope with global collaborative attacks.

[0005] Swarm learning, as a decentralized machine learning paradigm, can alleviate data silos and privacy issues by collaborating on model parameters without sharing raw data, thus offering a technological possibility for improving access security. However, its operation relies on decentralized coordination mechanisms to synchronize and aggregate model parameters. Blockchain technology, due to its decentralized and immutable characteristics, is an ideal supporting platform. However, standard single-chain blockchains suffer from severe throughput (TPS) bottlenecks, unable to handle the high-concurrency authentication logs generated daily by massive numbers of terminals in 5G edge scenarios, and also struggling to support high-frequency model parameter interaction requests. This hinders the efficient operation of swarm learning and makes it difficult to update and collaboratively optimize intelligent security models in real time. Ultimately, under the existing technological framework, the potential of swarm learning cannot be fully realized, and the lack of effective technical support for distributed business access security means that the problem of low security in distributed business access remains unresolved. Summary of the Invention

[0006] This invention provides a method for enhancing secure access to distributed services in 5G networks and a power generation-side management system to address the problem of low security in distributed service access in 5G networks.

[0007] In a first aspect, embodiments of the present invention provide a method for enhancing secure access to distributed services in a 5G network, based on a secure access system. The secure access system includes: a distributed terminal, an edge data plane processing module, a dynamic security authentication module, and a directed acyclic graph (DAG) population learning module. The secure access enhancement method includes: Distributed terminals transmit business traffic data to the corresponding edge data plane processing modules; The edge data plane processing module extracts features from business traffic data; The optimized dynamic security authentication module determines the access authentication security of business traffic data based on the extracted features; The model parameters of the dynamic security authentication module are optimized through the directed acyclic graph population learning module.

[0008] In one possible implementation, the directed acyclic graph (DAG) swarm learning module includes a global agent, a partitioned agent, a DAG main chain, and UPF nodes. The model parameters of the dynamic security authentication module are optimized through the DAG swarm learning module, including: The global agent partitions each UPF node, and the partitioned agent elects the corresponding partition leader in the corresponding partition UPF node. Each partition leader obtains the model parameters of the dynamic security authentication module of each UPF node in the corresponding partition, and performs the first-level aggregation of the model parameters to obtain the partition consensus model parameters in the corresponding partition. Each partition leader obtains the partition consensus model parameters sent by other partition leaders, and performs a second-level aggregation of the partition consensus model parameters of each partition to obtain the global model parameters; The partition leader publishes the metadata corresponding to the global model parameters to the directed acyclic graph main chain for notarization; the metadata includes hash value, version number and P2P address; When new global model parameters exist in the directed acyclic graph main chain, each UPF node downloads the global model parameters based on the metadata of the directed acyclic graph main chain and updates the model parameters of the dynamic security authentication module to optimize the dynamic security authentication module.

[0009] In one possible implementation, the directed acyclic graph (UPF) group learning module further includes subchains; the global agent partitions each UPF node, including: The global agent partitions each UPF node based on the load of the corresponding subchain of each partition, the communication overhead and computational load of each partition leader.

[0010] In one possible implementation, each partition leader obtains the model parameters of the dynamic security authentication module of each UPF node within the corresponding partition, and performs a first-level aggregation of the model parameters, including: Each partition leader weights and aggregates the model parameters of the dynamic security authentication module of each UPF node within the corresponding partition to obtain the partition consensus model parameters.

[0011] In one possible implementation, before performing a second-level aggregation of the partition consensus model parameters for each partition, the following is also included: After each partition leader receives a preset number of partition consensus model parameters sent by other partition leaders, a second-level aggregation is performed; in this process, the partition consensus model parameters of each partition are transmitted through a P2P network.

[0012] In one possible implementation, updating the model parameters of the dynamic security authentication module includes: Each UPF node merges the global model parameters with the local model parameters according to a preset ratio; Incremental training is performed using the fused model parameters and local data to obtain the updated model parameters for the dynamic security authentication module.

[0013] In one possible implementation, the edge data plane processing module extracts features from the service traffic data, including: Feature extraction is performed on business traffic data using P4 or eBPF programmable data surfaces; the extracted features include basic features, time-series features, and shallow load features.

[0014] In one possible implementation, access authentication security includes both successful and failed authentication. After assessing the security of access authentication for business traffic data, the following is also included: If authentication is successful, the business traffic data will be forwarded via the flow table; If authentication fails, business traffic data will be blocked through the access control list, and an anomaly alarm log will be generated. The anomaly alarm log includes traffic data characteristics and timestamps.

[0015] In one possible implementation, after blocking business traffic data via access control lists, the following is also included: Within a preset time period, the business traffic data initiated by the distributed terminal is monitored. If authentication fails again, a security alarm is immediately triggered, and the terminal is temporarily isolated.

[0016] Secondly, embodiments of the present invention provide a power generation side management system, including: multiple distributed power generation terminal devices, an edge data plane processing module, a dynamic security authentication module, and a directed acyclic graph group learning module; Among them, the distributed generation terminal equipment is used to collect and transmit business traffic data on the generation side; The edge data plane processing module is used to receive the service traffic data transmitted by the corresponding distributed generation terminal equipment, extract features from the service traffic data, and execute access control policies based on the authentication results. The dynamic security authentication module is used to receive the business traffic characteristics extracted by the edge data plane processing module and to perform real-time assessment of the legality of the access behavior of distributed generation terminal equipment. The directed acyclic graph group learning module is used to achieve collaborative optimization of model parameters of various dynamic security authentication modules; The power generation management system enhances service security access based on the aforementioned 5G network distributed service security access enhancement method.

[0017] In this embodiment of the invention, the raw business traffic generated by the distributed terminals is only transmitted to the corresponding edge data plane processing module for feature extraction according to the process. It does not participate in cross-node transmission nor is it uploaded to any centralized platform. This cuts off the path of sensitive information transmission from the source of data flow, effectively avoiding the risk of core data leakage in distributed scenarios. The model parameters of the dynamic security authentication module are optimized through a directed acyclic graph (DAG) group learning module, ensuring that the dynamic security authentication module can continuously optimize and accurately determine the security of business traffic access authentication. This invention further improves authentication accuracy and enhances the overall security of distributed terminal access authentication while ensuring data privacy is not leaked. Attached Figure Description

[0018] Figure 1 This is an application scenario diagram of the 5G network distributed service security access enhancement method provided in the embodiments of the present invention; Figure 2 This is a flowchart illustrating the implementation of the 5G network distributed service security access enhancement method provided in this embodiment of the invention. Figure 3 This is a schematic diagram of the DAG group learning process provided in an embodiment of the present invention; Figure 4 This is the system architecture based on two-level P2P learning and DAG main chain anchoring provided by the embodiments of the present invention; Figure 5 This is a flowchart of the overall system workflow provided in the embodiments of the present invention. Detailed Implementation

[0019] The embodiments of the present invention will now be described in detail with reference to the accompanying drawings.

[0020] Figure 1 This is an application scenario diagram of the 5G network distributed service security access enhancement method provided in an embodiment of the present invention. (See diagram below.) Figure 1 As shown, the application scenario of this invention is a typical 5G network UPF (User-Defined Grid Function) architecture used to carry distributed control services. For example, in a smart grid scenario, terminals such as photovoltaic power stations, energy storage units, and smart meters distributed in various locations access the network via 5G. Their service traffic, after passing through base stations, directly converges to the UPF nodes deployed at the network edge for processing and distribution, achieving low-latency communication with local MEC applications (such as power grid dispatch and control platforms). Each UPF and its served terminal cluster constitute a local security domain. This invention constructs a decentralized intelligent security framework driven by two core mechanisms: A Swarm Learning Network Based on Directed Acyclic Graphs (DAG) (Responsible for Security Capability Evolution): First, this invention utilizes swarm learning technology based on directed acyclic graphs to connect all dispersed UPF nodes into a collaborative intelligent network. In this network, each node's security model can share learning results (model parameters) without leaking its local original data, thereby achieving global intelligent collaborative evolution and jointly improving the ability to identify unknown threats.

[0021] Dynamic Partition Management in Hierarchical Reinforcement Learning (Responsible for Network Organization and Optimization): To ensure the aforementioned swarm learning network maintains high efficiency and low cost even with massive future node access, this invention further introduces a hierarchical reinforcement learning (HRL) dynamic partitioning mechanism. This mechanism acts as the "intelligent network brain," monitoring the communication load and operational status of the entire learning network in real time, and automatically and dynamically grouping all participating nodes into "partitions," continuously optimizing the network topology to minimize communication overhead and maintain load balance.

[0022] This invention empowers and manages DAG group learning through HRL intelligent partitioning. This design tightly couples the "evolution of security capabilities" with the "efficiency of network organization," aiming to provide a powerful and adaptively scalable advanced secure access authentication solution for 5G edge distributed services.

[0023] See Figure 2 This document illustrates a flowchart of the implementation of a 5G network distributed service security access enhancement method provided in an embodiment of the present invention. The 5G network distributed service security access enhancement method is implemented based on a security access system, which includes: a distributed terminal, an edge data plane processing module, a dynamic security authentication module, and a directed acyclic graph population learning module. The security access enhancement method includes: Step 201: The distributed terminal transmits the service traffic data to the corresponding edge data plane processing module.

[0024] In this embodiment, service traffic is directly transmitted to the Edge Data Plane Processing (EDP) module on the edge side, instead of being transmitted to the remote core network. This shortens the path length from the starting point of data transmission, laying the foundation for subsequent real-time authentication and rapid policy execution on the edge side, and avoiding service interruption or delayed response to security threats due to core network transmission latency.

[0025] Step 202: The edge data plane processing module extracts features from the business traffic data.

[0026] In this embodiment, feature extraction is performed directly in the edge data plane processing module of the edge UPF, eliminating the need to transmit massive amounts of raw traffic to the remote core network or cloud for processing. This significantly reduces data transmission volume (only feature vectors are transmitted instead of raw traffic) and lowers network bandwidth consumption.

[0027] Step 203: The optimized dynamic security authentication module determines the access authentication security of business traffic data based on the extracted features; The model parameters of the dynamic security authentication module are optimized through the directed acyclic graph population learning module.

[0028] In this embodiment, the dynamic security authentication module is deployed on the control plane of the MEC platform and works closely with the UPF. Internally, this module runs a lightweight machine learning model, such as a gradient boosting tree or a small neural network. Based on the traffic characteristics extracted by the Edge Data Plane Processing (EDP) module, this model performs real-time analysis of the legitimacy of terminal access behavior, outputting a trust score or classification result to determine whether the behavior is abnormal.

[0029] like Figure 3This is a schematic diagram of the Directed Acyclic Graph (DAG) population learning process. The power distributed control business communication terminal sends business traffic to the UPF forwarding module, which in turn sends the raw features to the edge data plane processing module. Feature extraction is performed using programmable technologies such as P4, and the dynamic security authentication module determines the legitimacy of the traffic based on the extracted features. The dynamic security authentication module utilizes the DAG population learning module for decentralized collaborative training, thus optimizing the dynamic security authentication module.

[0030] In this embodiment of the invention, the raw business traffic generated by the distributed terminals is only transmitted to the corresponding edge data plane processing module for feature extraction according to the process. It does not participate in cross-node transmission nor is it uploaded to any centralized platform. This cuts off the path of sensitive information transmission from the source of data flow, effectively avoiding the risk of core data leakage in distributed scenarios. The model parameters of the dynamic security authentication module are optimized through a directed acyclic graph (DAG) group learning module, ensuring that the dynamic security authentication module can continuously optimize and accurately determine the security of business traffic access authentication. This invention further improves authentication accuracy and enhances the overall security of distributed terminal access authentication while ensuring data privacy is not leaked.

[0031] In one possible implementation, the directed acyclic graph (DAG) swarm learning module includes a global agent, a partitioned agent, a DAG main chain, and UPF nodes. The model parameters of the dynamic security authentication module are optimized through the DAG swarm learning module, including: The global agent partitions each UPF node, and the partitioned agent elects the corresponding partition leader in the corresponding partition UPF node. Each partition leader obtains the model parameters of the dynamic security authentication module of each UPF node in the corresponding partition, and performs the first-level aggregation of the model parameters to obtain the partition consensus model parameters in the corresponding partition. Each partition leader obtains the partition consensus model parameters sent by other partition leaders, and performs a second-level aggregation of the partition consensus model parameters of each partition to obtain the global model parameters; The partition leader publishes the metadata corresponding to the global model parameters to the directed acyclic graph main chain for notarization; the metadata includes hash value, version number and P2P address; When new global model parameters exist in the directed acyclic graph main chain, each UPF node downloads the global model parameters based on the metadata of the directed acyclic graph main chain and updates the model parameters of the dynamic security authentication module to optimize the dynamic security authentication module.

[0032] In this embodiment, a decentralized model training and reinforcement network is constructed, jointly participated in by all sinking UPF nodes. The core of this network is a hierarchical reinforcement learning management system composed of global and partition-level agents. This system dynamically and intelligently manages the topology (partitioning) of the entire learning network, ensuring efficient model parameter sharing and aggregation capabilities even with a massive node scale. After training the model locally, each node's dynamic security authentication module publishes model updates (such as gradients and weight parameters), rather than the original data, to the DAG-based swarm learning module. Simultaneously, each node asynchronously pulls model updates from other nodes from the DAG swarm learning module and integrates them into its local model through a specific aggregation algorithm, achieving global intelligent collaborative evolution. Figure 3 As shown.

[0033] Each Dynamic Security Authentication Module (DSA) uses traffic data collected and tagged by its host UPF (normal traffic can be determined by whitelists or baseline behavior, while abnormal traffic can be obtained through honeypots or historical attack data) to independently train its security authentication model locally. This ensures that the model can accurately adapt to the specific behavioral patterns of local business.

[0034] The DAG group learning module is responsible for building and maintaining an efficient, scalable, and decentralized model parameter sharing network. It not only utilizes the DAG structure to achieve asynchronous, high-concurrency parameter exchange, but also introduces a hierarchical reinforcement learning mechanism to dynamically organize and optimize the network.

[0035] The model co-evolution process of this invention mainly occurs off-chain, and the final state is notarized through the DAG main chain. After the next generation of global model is generated off-chain, one or more leader nodes package the hash value, version number, and metadata such as the P2P address used to download the model into a lightweight "notarized transaction," which is then published and anchored to the DAG main chain. The DAG main chain does not participate in any model computation; it only serves as an immutable public record of the final consensus result.

[0036] In one possible implementation, the directed acyclic graph (UPF) group learning module further includes subchains; the global agent partitions each UPF node, including: The global agent partitions each UPF node based on the load of the corresponding subchain of each partition, the communication overhead and computational load of each partition leader.

[0037] In this embodiment, the subchain is a high-frequency transaction processing unit in the system. Its function is to provide an independent, high-performance distributed ledger for each partition, specifically for recording the massive authentication logs generated by all UPF nodes within that partition during each authentication execution. By distributing the log recording tasks across parallel subchains, the overall system's trusted audit throughput is greatly improved, and the immutability and traceability of operation records are guaranteed.

[0038] The hierarchical reinforcement learning mechanism is the "brain" that ensures the continuous and efficient operation of the above-mentioned collaborative work.

[0039] Global agent: By monitoring the load of each partition subchain (such as authentication TPS) and the communication overhead and computing load of each partition leader node in the P2P network, it makes macro-level decisions on global repartitioning or authorized local distribution.

[0040] Partition agent: Based on global instructions and the local state of the partition, it performs specific node account migration operations to optimize load balancing and reduce cross-partition communication overhead.

[0041] By sharing only model parameters rather than data, the privacy of business data across nodes is naturally protected. Furthermore, differential privacy techniques can be used to add noise before parameter release, or smart contracts can be used to verify and incentivize node contributions, preventing malicious poisoning attacks.

[0042] Figure 4 This invention demonstrates a system architecture based on two-level P2P learning and DAG main chain anchoring. A global intelligent agent is responsible for the macro-control of the network. Off-chain, the HRL mechanism divides UPF nodes into multiple partitions, each of which elects a leader to complete the first-level model aggregation. Subsequently, all leaders form a P2P network, directly exchanging and merging the global model off-chain. Finally, only the hash of this global model is anchored to the DAG main chain for notarization, serving as a trusted timestamp and consensus proof for the entire network. This achieves the separation of computation and notarization. Figure 5 This is a flowchart of the overall system workflow. This process is continuous and asynchronous on all nodes, enabling the security capabilities of the entire distributed system to be continuously and collaboratively improved.

[0043] In one possible implementation, each partition leader obtains the model parameters of the dynamic security authentication module of each UPF node within the corresponding partition, and performs a first-level aggregation of the model parameters, including: Each partition leader weights and aggregates the model parameters of the dynamic security authentication module of each UPF node within the corresponding partition to obtain the partition consensus model parameters.

[0044] In this embodiment, leader aggregation occurs within a partition (off-chain). In the first stage of group learning, all UPF nodes within the same partition, under the coordination of the partition agent, elect a leader node. Each UPF node submits its local model update to the leader, which then completes the first-level model aggregation locally (off-chain) to form the partition consensus model.

[0045] In one possible implementation, before performing a second-level aggregation of the partition consensus model parameters for each partition, the following is also included: After each partition leader receives a preset number of partition consensus model parameters sent by other partition leaders, a second-level aggregation is performed; in this process, the partition consensus model parameters of each partition are transmitted through a P2P network.

[0046] In this embodiment, segmented P2P fusion (off-chain) occurs in the second phase, where the leader nodes of all segments form a higher-level P2P network. Within this network, they directly broadcast and exchange their respective segment consensus models. After collecting the models from all other segments, each leader independently executes a deterministic global fusion algorithm locally, thereby reaching consensus on the "global model" off-chain.

[0047] In one possible implementation, updating the model parameters of the dynamic security authentication module includes: Each UPF node merges the global model parameters with the local model parameters according to a preset ratio; Incremental training is performed using the fused model parameters and local data to obtain the updated model parameters for the dynamic security authentication module.

[0048] Specifically, the preset ratio is configured by each UPF node based on its local business characteristics. For example, if the local business is special industrial control (such as a customized robot communication protocol in a factory), and the local data is highly representative, local parameters can be set to account for 70% and global parameters for 30%, prioritizing local adaptability. If the local business is general photovoltaic control (consistent with the behavior of most photovoltaic terminals across the network), local parameters can be set to account for 50% and global parameters for 50%, balancing the absorption of threat identification experience across the entire network. A weighted summation algorithm is used. For example, the weight parameter of a certain feature in the model (such as the variance of the data packet arrival interval) is calculated as follows: fused parameter = local parameter × local ratio + global parameter × global ratio. The parameters of all features are calculated according to this rule to form the preliminary fused model parameter set.

[0049] Local data filtering: Select data sources for incremental training, prioritizing local traffic data newly generated after downloading the global model (to ensure data timeliness), and ensuring that features have been extracted and labeled through the EDP module (normal data is labeled as 0, and abnormal data such as attack commands are labeled as 1). The amount of data does not need to be too large (e.g., 1000-5000 samples) to avoid excessive training time affecting real-time authentication.

[0050] Incremental training execution: A lightweight training framework is adopted, using the fused parameters as initial values, and only 1-3 rounds of mini-batch iterative training are performed on the model to fine-tune the parameters to adapt to the features of new local data. For example, if frequent abnormal access from a specific IP appears in the new local data, the weight of that IP feature in the model will be increased accordingly after training, enhancing the local targeted identification capability.

[0051] Model Validation and Replacement: After training, test the model accuracy using a local validation set (e.g., 20% of the labeled data). If the accuracy improves compared to before fusion (e.g., from 92% to 95%), then use the model as the new local DSA model. If the accuracy decreases, readjust the fusion ratio and repeat the training until the preset accuracy requirement is met (e.g., accuracy ≥ 90%).

[0052] In this embodiment, the proportional fusion and incremental training strategies enable the model to not only identify threats across the entire network but also accurately adapt to local business needs, thus solving the shortcomings of the traditional centralized model's one-size-fits-all approach.

[0053] In one possible implementation, the edge data plane processing module extracts features from the service traffic data, including: Feature extraction is performed on business traffic data using P4 or eBPF programmable data surfaces; the extracted features include basic features, time-series features, and shallow load features.

[0054] Specifically, the edge data plane processing module is embedded in the sunken UPF and implemented using programmable data plane technologies such as P4 and eBPF. It is responsible for real-time and efficient feature extraction of terminal service traffic flowing through the UPF, providing raw data for security authentication, and executing access control policies (such as allowing, blocking, and isolating) based on the authentication results. Utilizing programmable data plane technology, it extracts multi-dimensional behavioral features without interrupting the service flow. For distributed photovoltaic control scenarios, features may include: basic features such as source / destination IP, port, protocol type, packet size, and packet rate; time-series features such as the statistical distribution of packet arrival intervals (mean, variance, etc.); and shallow load features such as function codes and register addresses of industrial protocols like Modbus / TCP and DNP3.

[0055] In one possible implementation, access authentication security includes both successful and failed authentication. After assessing the security of access authentication for business traffic data, the following is also included: If authentication is successful, the business traffic data will be forwarded via the flow table; If authentication fails, business traffic data will be blocked through the access control list, and an anomaly alarm log will be generated. The anomaly alarm log includes traffic data characteristics and timestamps.

[0056] In this embodiment, access control policies (such as allowing, blocking, or isolating) are executed based on the authentication result. Based on the authentication result from the dynamic security authentication module, the corresponding traffic is rapidly processed in the data plane using flow tables or access control lists.

[0057] In one possible implementation, after blocking business traffic data via access control lists, the following is also included: Within a preset time period, the business traffic data initiated by the distributed terminal is monitored. If authentication fails again, a security alarm is immediately triggered, and the terminal is temporarily isolated.

[0058] In this embodiment, to avoid malicious terminals repeatedly probing vulnerabilities that might result from a single block, the security response is upgraded from passive single-time interception to proactive tracking and defense. Temporary isolation operations can quickly sever the communication links of high-risk terminals, preventing them from further impacting the local security domain under the UPF (Upgraded Security Function) architecture and ensuring normal access for other legitimate terminals.

[0059] This invention addresses the security access challenges of distributed control services (such as distributed photovoltaics, smart grids, and industrial automation control) under a UPF (Upper Grid Provider) edge architecture for 5G and future wireless networks. It proposes a security access enhancement method based on Directed Acyclic Graph (DAG) swarm learning. As 5G networks deeply integrate with vertical industries, the UPF's deployment at the network edge has become a key architecture for meeting the low latency and high reliability requirements of these services. However, this also shifts the network security boundary forward, exposing massive, heterogeneous terminal access authentication to new threats. This invention constructs a distributed intelligent security authentication framework driven by a two-layer heterogeneous blockchain network and Layered Reinforcement Learning (HRL). The core idea of ​​this framework is the separation of "off-chain computation and on-chain notarization": it utilizes high-performance sharded sub-chains to process massive terminal authentication logs for efficient and reliable auditing; simultaneously, it uses a high-concurrency DAG main chain as a lightweight "trusted notary," anchoring only the final consensus result generated during the off-chain swarm learning process. The Layered Reinforcement Learning (HRL) mechanism acts as the "intelligent brain," dynamically and adaptively optimizing the topology of the entire learning network. This design fundamentally solves the audit performance bottlenecks and model collaboration efficiency bottlenecks faced by traditional blockchain architectures in ultra-large-scale networks without compromising local data privacy, enabling the security capabilities of all edge nodes to evolve efficiently and collaboratively. This method aims to improve the accuracy, response speed, and ability to identify unknown threats in terminal access authentication in distributed control scenarios, while ensuring the system's scalability and robustness.

[0060] Low-latency and efficient authentication: By pushing security authentication and policy enforcement functions down to UPF nodes at the network edge, threats can be detected and responded to locally and quickly. This avoids the huge latency caused by routing traffic back to the central core network for processing, and fully guarantees the performance requirements of latency-sensitive services such as distributed control.

[0061] Swarm intelligence enables continuous evolution: by replacing static rules with machine learning models, it can identify unknown threats and zero-day attacks based on behavioral anomalies. Utilizing swarm learning mechanisms, security models can continuously learn from newly added network traffic data, dynamically adapting to ever-changing business patterns and attack methods.

[0062] Adaptive and highly scalable architecture: Based on a DAG-based decentralized learning architecture, it eliminates the bottleneck of a central server, allowing new nodes to join "plug and play." Furthermore, by introducing a hierarchical reinforcement learning dynamic partitioning mechanism, the network can self-organize and optimize its topology according to changes in business load and node scale. This ensures that the entire swarm learning system maintains high performance and efficiency even when facing massive future edge node access, exhibiting strong system robustness and long-term scalability.

[0063] Privacy Protection and Compliance: The core idea of ​​the group learning framework is to share "knowledge" (model parameters) rather than "data" (raw data), which effectively avoids the risk of leakage of sensitive business data (such as enterprise production data and power grid operation data) in distributed scenarios and solves the data privacy problem of centralized training.

[0064] Network resource optimization: The HRL dynamic partitioning mechanism can intelligently cluster frequently communicating nodes into the same partition, minimize cross-partition communication, reduce network bandwidth consumption and communication latency during the group learning process, and optimize the resource utilization of the entire distributed system.

[0065] This method enhances the terminal access security authentication capabilities of each node in a 5G network containing multiple Downward User Plane Function (UPF) nodes through a decentralized swarm learning framework.

[0066] In a P2P network, the shared content is the model's gradient, weights, and other parameters, while in a DAG main chain network, the shared content is the model's hash proof, rather than the original business traffic data, in order to protect data privacy and achieve network lightweighting.

[0067] The global agent monitors the macroscopic state of the network and makes decisions on global repartitioning or authorizing local distribution. Multiple partition agents, bound to partitions, execute specific node migration operations to optimize the internal structure of the partition based on the local state of their respective partitions after receiving instructions.

[0068] One or more partitioned subchains, characterized by processing high-frequency terminal authentication log recording; and a DAG main chain, characterized by being used only to receive and record hash proofs of the global model generated by the off-chain P2P network, thereby securely anchoring and notarizing the final state of the group learning process.

[0069] It should be understood that the sequence number of each step in the above embodiments does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0070] The above embodiments are in Figure 2 Based on the method shown, each step will be discussed in detail. To facilitate understanding of the complete execution process, the overall method flow will be discussed below with reference to an embodiment.

[0071] Initialization: Deploy the initial security authentication model on each sunken UPF node.

[0072] Real-time authentication: Business traffic from distributed terminals (such as photovoltaic inverters) reaches the sinking UPF to which they belong.

[0073] The EDP module within UPF extracts the behavioral feature vector of the traffic in real time.

[0074] The feature vector is sent to the DSA module in the MEC control plane. The DSA module uses the current security model to perform reasoning and determine the legality of the action.

[0075] If authentication is successful, the EDP module will allow the traffic; if authentication fails, it will block or isolate the traffic and log the process.

[0076] Group learning-based model co-evolution: Local training: Each UPF node periodically uses local data to train its DSA model.

[0077] Intra-partition aggregation: After training is complete, all UPF nodes within the same partition submit their model updates to the leader node of that partition. The leader then completes the first-level aggregation locally, generating the "partition consensus model".

[0078] Inter-regional P2P fusion: The leader nodes of each region exchange their respective "regional consensus models" in a dedicated P2P network and execute the global fusion algorithm locally to jointly calculate the next generation of "global model".

[0079] Global consensus anchoring (on-chain): One or more leader nodes publish the hash value of the final generated global model to the DAG main chain as a trusted timestamp and consensus proof for the entire network.

[0080] Model Enhancement: All UPF nodes learn of new model releases by monitoring the DAG main chain. Subsequently, based on the metadata recorded on the main chain, they download the complete global model data from the leader P2P network and integrate it into their own local models, completing a collaborative evolution.

[0081] This invention provides a power generation side management system, including: multiple distributed power generation terminal devices, an edge data plane processing module, a dynamic security authentication module, and a directed acyclic graph group learning module; Among them, the distributed generation terminal equipment is used to collect and transmit business traffic data on the generation side; The edge data plane processing module is used to receive the service traffic data transmitted by the corresponding distributed generation terminal equipment, extract features from the service traffic data, and execute access control policies based on the authentication results. The dynamic security authentication module is used to receive the business traffic characteristics extracted by the edge data plane processing module and to perform real-time assessment of the legality of the access behavior of distributed generation terminal equipment. The directed acyclic graph group learning module is used to achieve collaborative optimization of model parameters of various dynamic security authentication modules; The power generation management system enhances service security access based on the aforementioned 5G network distributed service security access enhancement method.

[0082] In the above embodiments, the descriptions of each embodiment have their own emphasis. Parts not detailed or described in a particular embodiment can be referred to in the relevant descriptions of other embodiments. Unless otherwise specified or in conflict with logic, the terminology and / or descriptions between different embodiments are consistent and can be referenced interchangeably. Technical features in different embodiments can be combined to form new embodiments based on their inherent logical relationships.

[0083] The above embodiments are only used to illustrate the technical solutions of the present invention, and are not intended to limit it. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included within the protection scope of the present invention.

Claims

1. A method for enhancing secure access to distributed services in a 5G network, implemented based on a secure access system, the secure access system comprising: The distributed terminal, edge data plane processing module, dynamic security authentication module, and directed acyclic graph population learning module are characterized by a security access enhancement method comprising: The distributed terminal transmits service traffic data to the corresponding edge data plane processing module; The edge data plane processing module extracts features from the service traffic data; The optimized dynamic security authentication module determines the access authentication security of the service traffic data based on the extracted features; The model parameters of the dynamic security authentication module are optimized using a directed acyclic graph population learning module.

2. The 5G network distributed service security access enhancement method according to claim 1, characterized in that, The directed acyclic graph (DAG) swarm learning module includes a global agent, a regional agent, a DAG main chain, and UPF nodes. The model parameters of the dynamic security authentication module are optimized through the DAG swarm learning module, including: The global agent partitions each UPF node, and the partitioned agent elects the corresponding partition leader in the corresponding partition UPF node. Each partition leader obtains the model parameters of the dynamic security authentication module of each UPF node in the corresponding partition, and performs the first-level aggregation of the model parameters to obtain the partition consensus model parameters in the corresponding partition. Each partition leader obtains the partition consensus model parameters sent by other partition leaders, and performs a second-level aggregation of the partition consensus model parameters of each partition to obtain the global model parameters; The partition leader publishes the metadata corresponding to the global model parameters to the directed acyclic graph main chain for notarization; wherein, the metadata includes hash value, version number and P2P address; When new global model parameters exist in the directed acyclic graph main chain, each UPF node downloads the global model parameters based on the metadata of the directed acyclic graph main chain and updates the model parameters of the dynamic security authentication module to optimize the dynamic security authentication module.

3. The 5G network distributed service security access enhancement method according to claim 2, characterized in that, The directed acyclic graph (DAG) population learning module further includes sub-chains; the global agent partitions each UPF node, including: The global agent partitions each UPF node based on the load of the sub-chains corresponding to each partition, the communication overhead and computational load of each partition leader.

4. The 5G network distributed service security access enhancement method according to claim 2, characterized in that, Each partition leader obtains the model parameters of the dynamic security authentication module of each UPF node within its corresponding partition, and performs a first-level aggregation of the model parameters, including: The partition leader weights and aggregates the model parameters of the dynamic security authentication module of each UPF node in the corresponding partition to obtain the partition consensus model parameters.

5. The 5G network distributed service security access enhancement method according to claim 2, characterized in that, Before performing the second-level aggregation of the partition consensus model parameters for each partition, the following is also included: After each partition leader receives a preset number of partition consensus model parameters sent by other partition leaders, a second-level aggregation is performed; in this process, the partition consensus model parameters of each partition are transmitted through a P2P network.

6. The 5G network distributed service security access enhancement method according to claim 2, characterized in that, The updated model parameters of the dynamic security authentication module include: Each UPF node merges the global model parameters with the local model parameters according to a preset ratio; Incremental training is performed using the fused model parameters and local data to obtain the updated model parameters for the dynamic security authentication module.

7. The 5G network distributed service security access enhancement method according to claim 1, characterized in that, The edge data plane processing module performs feature extraction on the service traffic data, including: Feature extraction is performed on the service traffic data using P4 or eBPF programmable data surfaces; wherein the extracted features include basic features, time-series features, and shallow load features.

8. The 5G network distributed service security access enhancement method according to claim 1, characterized in that, The access authentication security includes successful authentication and authentication failure; After determining the access authentication security of the service traffic data, the process also includes: If authentication is successful, the service traffic data is forwarded through the flow table; If authentication fails, the service traffic data is blocked through the access control list, and an anomaly alarm log is generated; wherein, the anomaly alarm log includes traffic data characteristics and timestamps.

9. The 5G network distributed service security access enhancement method according to claim 8, characterized in that, After blocking the business traffic data through the access control list, the following is also included: Within a preset time period, the business traffic data initiated by the distributed terminal is monitored. If authentication fails again, a security alarm is immediately triggered, and the terminal is temporarily isolated.

10. A power generation-side management system, characterized in that, include: Multiple distributed generation terminal devices, edge data plane processing module, dynamic security authentication module, and directed acyclic graph group learning module; The distributed generation terminal equipment is used to collect and transmit business traffic data on the generation side. The edge data plane processing module is used to receive the service traffic data transmitted by the corresponding distributed generation terminal equipment, extract features from the service traffic data, and execute access control policies based on the authentication results. The dynamic security authentication module is used to receive the business traffic characteristics extracted by the edge data plane processing module and to perform real-time assessment of the legality of the access behavior of distributed generation terminal equipment. The directed acyclic graph group learning module is used to achieve collaborative optimization of model parameters of various dynamic security authentication modules; The power generation-side management system implements enhanced service security access based on the 5G network distributed service security access enhancement method according to any one of claims 1 to 9.