Low-latency interaction platform for trusted data spaces with edge computing fusion

By constructing a hierarchical trusted execution environment and a differentiated key pre-allocation strategy, combined with an elastic federated learning module, the security and latency issues of data interaction in edge computing networks are solved, achieving efficient and secure data interaction management and improving resource utilization.

CN121441913BActive Publication Date: 2026-05-01LINGSHU TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
LINGSHU TECH CO LTD
Filing Date
2025-12-29
Publication Date
2026-05-01

AI Technical Summary

Technical Problem

Existing edge computing data interaction platforms are inadequate in terms of security and latency, and cannot effectively cope with complex network attacks and high latency issues. Furthermore, federated learning schemes lack flexibility, resulting in low resource utilization.

Method used

It provides a trusted data space low-latency interaction platform that integrates edge computing. By building a hierarchical trusted execution environment, a differentiated key pre-distribution strategy, and an elastic federated learning module, it achieves secure and low-latency data interaction management.

Benefits of technology

A hierarchical trusted execution environment was constructed to ensure data security at different processing stages. Through differentiated key pre-allocation strategies and elastic federated learning schemes, key management efficiency and resource utilization were improved, data interaction latency was reduced, and the security and stability of the edge computing network were enhanced.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121441913B_ABST
    Figure CN121441913B_ABST
Patent Text Reader

Abstract

The application discloses a trusted data space low-delay interaction platform fusing edge computing, relates to the technical field of edge computing, and comprises the following steps: constructing a hierarchical trusted execution environment in a target edge computing network based on preset hierarchical rules of the trusted execution environment; constructing a device cooperation relationship graph of the target edge computing network, dividing the device cooperation relationship graph into multiple real-time grades, and configuring a differentiated key pre-allocation strategy for each real-time grade; performing double node screening on network nodes based on behavior characteristic pre-screening and real-time connection performance evaluation, determining a federated learning participating node, and obtaining an elastic federated learning scheme; and integrating the hierarchical trusted execution environment, the differentiated key pre-allocation strategy and the elastic federated learning scheme, and performing low-delay interaction management. The application solves the problem that the prior art cannot effectively cope with the low-delay requirement and security of data interaction in an edge computing network.
Need to check novelty before this filing date? Find Prior Art

Description

A trusted data space low-latency interaction platform integrating edge computing Technical Field

[0001] This application relates to the field of edge computing technology, specifically to a trusted data space low-latency interaction platform that integrates edge computing. Background Technology

[0002] With the development of edge computing technology, its application in various fields is becoming increasingly widespread. However, the existing security protection mechanisms of edge computing data interaction platforms are insufficient to cope with increasingly complex network attacks, and lack effective layered protection and differentiated authentication methods. This results in high security risks to data during transmission and processing, which may lead to data leakage, tampering, and other issues, seriously affecting the normal operation of business.

[0003] On the other hand, the high latency of data interaction makes it unsuitable for some application scenarios with high real-time requirements. Moreover, existing federated learning schemes lack flexibility and cannot be flexibly adjusted according to the actual status and performance of network nodes, resulting in low resource utilization. Summary of the Invention

[0004] This application provides a trusted data space low-latency interaction platform that integrates edge computing, solving the technical problem that existing technologies cannot effectively address the low-latency requirements and security of data interaction in edge computing networks.

[0005] The technical solution to the above-mentioned technical problems in this application is as follows:

[0006] On the one hand, this application provides a trusted data space low-latency interaction platform that integrates edge computing, the platform comprising:

[0007] The environment layering configuration module is used to construct a hierarchical trusted execution environment in the target edge computing network based on preset trusted execution environment layering rules, wherein the network nodes of the target edge computing network include terminal devices, edge gateways and edge servers;

[0008] The differentiated authentication configuration module is used to construct a device collaboration relationship graph of the target edge computing network, divide the network nodes of the target edge computing network into multiple real-time levels based on the device collaboration relationship graph, and configure a differentiated key pre-allocation strategy for each real-time level.

[0009] The elastic federated learning module is used to perform dual node screening of network nodes based on behavioral feature pre-screening and real-time connection performance evaluation, determine the nodes participating in federated learning, and obtain an elastic federated learning scheme by combining the federated learning participating nodes with a preset asynchronous aggregation mechanism.

[0010] The interactive management execution module is used to coordinate and integrate the hierarchical trusted execution environment, the differentiated key pre-allocation strategy, and the elastic federated learning scheme to perform low-latency interactive management.

[0011] This application provides one or more technical solutions, which have at least the following technical effects or advantages:

[0012] This application provides a low-latency interactive platform for trusted data spaces that integrates edge computing. First, it constructs a hierarchical trusted execution environment, enabling network nodes at different levels to operate in their respective suitable trusted environments, ensuring data security at different processing stages. Second, it constructs a device collaboration graph and classifies real-time levels, configuring differentiated key pre-allocation strategies. This helps to flexibly allocate key resources according to the real-time requirements of different nodes, improving the efficiency and security of key management. During data interaction, a secure communication channel is quickly established based on the real-time level, reducing authentication time and lowering data interaction latency. Third, it determines participating nodes in federated learning through dual node screening and obtains a flexible federated learning scheme. Dual node screening comprehensively considers the behavioral characteristics and real-time connection performance of network nodes, enabling more accurate selection of suitable nodes for federated learning. The flexible federated learning scheme's dual aggregation trigger conditions and adaptive asynchronous aggregation mechanism can flexibly adjust the aggregation method according to the actual situation of network nodes, improving resource utilization and reducing the overall low efficiency of federated learning caused by the latency of some nodes. Finally, the interactive management execution module collaboratively integrates the results of the above three modules to perform low-latency interactive management. By organically combining a hierarchical trusted execution environment, a differentiated key pre-allocation strategy, and a resilient federated learning scheme, low latency and security of data interaction in edge computing networks are guaranteed from multiple dimensions.

[0013] Through the above technical solutions, this application effectively solves the problems existing in the prior art and provides strong support for the application of edge computing technology in more fields. Attached Figure Description

[0014] To more clearly illustrate the technical solutions in the embodiments of this application, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the accompanying drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0015] Figure 1 is a schematic diagram of the structure of the trusted data space low-latency interaction platform that integrates edge computing provided in an embodiment of this application.

[0016] The components represented by each number in the attached diagram are explained below:

[0017] Environment layer configuration module 11, differentiated authentication configuration module 12, elastic federated learning module 13, interactive management execution module 14. Detailed Implementation

[0018] This application provides a trusted data space low-latency interaction platform that integrates edge computing, addressing the technical problem that existing technologies cannot effectively meet the low-latency requirements and security of data interaction in edge computing networks.

[0019] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0020] In the description of this application, the terms "first" and "second" are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of indicated technical features. Thus, a feature defined as "first" or "second" may explicitly or implicitly include one or more of the stated features. In the description of this application, "multiple" means two or more, unless otherwise explicitly specified.

[0021] In the description of this application, the term "for example" is used to mean "used as an example, illustration, or description." Any embodiment described as "for example" in this application is not necessarily to be construed as being more preferred or advantageous than other embodiments. The following description is provided to enable any person skilled in the art to make and use this application. Details are set forth in the following description for purposes of explanation. It should be understood that those skilled in the art will recognize that this application can be made without using these specific details. In other instances, well-known structures and processes will not be described in detail to avoid unnecessarily obscuring the description of this application. Therefore, this application is not intended to be limited to the embodiments shown, but is consistent with the broadest scope of the principles and features disclosed in this application.

[0022] As shown in Figure 1, this embodiment of the application provides a low-latency interactive platform for trusted data spaces that integrates edge computing, including:

[0023] The environment layering configuration module 11 is used to construct a hierarchical trusted execution environment in the target edge computing network based on preset trusted execution environment layering rules, wherein the network nodes of the target edge computing network include terminal devices, edge gateways and edge servers;

[0024] In this embodiment, firstly, trusted execution environment (TEE) layering rules are preset based on factors such as the function, data sensitivity, and security requirements of different network nodes. Then, based on these preset TEE layering rules, a hierarchical trusted execution environment is constructed in the target edge computing network. Further, the network nodes of the target edge computing network include terminal devices, edge gateways, and edge servers. Since terminal devices directly interact with users and may store users' sensitive personal information, they are classified as lower-level TEE environments with higher security requirements.

[0025] As an intermediary connecting terminal devices and edge servers, the edge gateway is responsible for forwarding and initial processing of data. Its trusted execution environment has an appropriate level of layer and it has data processing capabilities and security protection capabilities.

[0026] Edge servers undertake more complex data processing and storage tasks and can operate in a higher-level trusted execution environment.

[0027] Specifically, when constructing a hierarchical trusted execution environment, the first step is to collect and analyze information on all network nodes in the target edge computing network. By understanding the hardware configuration, software system, business functions, and data interaction patterns of each node, and combining this with pre-defined trusted execution environment hierarchical rules, a corresponding trusted execution environment level is assigned to each node.

[0028] Meanwhile, to ensure the effectiveness and stability of the tiered trusted execution environment, a dynamic monitoring mechanism is established. This mechanism monitors the operational status of network nodes, data traffic, and security events in real time. If an anomaly is detected in a node, such as signs of data leakage or performance degradation, the trusted execution environment level of that node is adjusted promptly to ensure data security and low-latency interaction across the entire edge computing network.

[0029] The trusted execution environment layering rules include:

[0030] Deploy a minimalist, trusted execution environment at the terminal device layer to perform data desensitization and feature extraction operations;

[0031] Deploy a complete trusted execution environment at the edge gateway layer for performing model inference and federated learning client training, supporting containerized trusted computing tasks;

[0032] Deploy a high-performance, trusted execution environment at the edge server layer for performing federated learning model aggregation and secure multi-party computation coordination;

[0033] Each trusted execution environment is associated with an independent secure memory usage state.

[0034] In this embodiment, firstly, based on the characteristics and needs of different network nodes, different types of trusted execution environments are deployed at the terminal device layer. Since the terminal device layer has limited resources and directly accesses sensitive user data, a simplified trusted execution environment is deployed. This simplified trusted execution environment focuses on performing data desensitization and feature extraction operations, protecting user data privacy while completing necessary data preprocessing without consuming excessive resources. Its independent secure memory usage ensures the security of the data processing process, preventing sensitive data from being leaked or tampered with during processing.

[0035] Secondly, since the edge gateway layer undertakes data forwarding and preliminary processing tasks, it needs to possess certain data processing and security protection capabilities. Therefore, a complete trusted execution environment is deployed at the edge gateway layer. This environment supports containerized trusted computing tasks, enabling the execution of model inference and federated learning client training. Containerization technology isolates different computing tasks, improving system stability and security. Simultaneously, the independent secure memory footprint of the edge gateway layer ensures that data security and integrity remain unaffected during data processing and forwarding.

[0036] Furthermore, because the edge server layer undertakes more complex data processing and storage tasks, such as federated learning model aggregation and secure multi-party computation coordination, a high-performance trusted execution environment (TEX) is deployed. The TEX possesses powerful computing capabilities and security mechanisms, enabling it to efficiently complete large-scale data processing and model training tasks. Independent secure memory occupancy provides reliable security for data processing at the edge server layer, ensuring that data is not illegally accessed or tampered with during complex computations.

[0037] Furthermore, each Trusted Execution Environment (TEX) is associated with an independent secure memory usage status, indicating that the secure memory usage of each TEX is monitored and managed independently during operation.

[0038] Specifically, based on preset trusted execution environment layering rules, the environment layering configuration module is further used for:

[0039] Obtain task planning information for the target edge computing network;

[0040] Based on the task planning information, the occupancy status of the terminal device and the edge gateway is predicted using a pre-built occupancy prediction model to obtain predicted occupancy information. The occupancy prediction model is built based on a regression analysis model.

[0041] The predicted memory usage information is compared with the corresponding safe memory usage status to determine the dynamic unloading node;

[0042] For each of the dynamic uninstallation nodes, a corresponding parent node is matched to construct a dynamic uninstallation pair, and a dynamic uninstallation configuration is defined based on multiple dynamic uninstallation pairs. The dynamic uninstallation configuration includes at least an uninstallation path and a preset uninstallation alternative environment.

[0043] Update the hierarchical trusted execution environment according to the dynamic unloading configuration.

[0044] In this embodiment, firstly, task planning information of the target edge computing network is obtained. This information includes the type, amount, and execution time of tasks to be executed by each node in the network. By analyzing the task planning information, the network load and resource requirements are understood.

[0045] Secondly, based on task planning information and a pre-built memory usage prediction model, the memory usage status of terminal devices and edge gateways is predicted to obtain predicted memory usage information. The memory usage prediction model is built on a regression analysis model, which uses historical data and current task planning information to make relatively accurate predictions about the secure memory usage of terminal devices and edge gateways. For example, the memory usage prediction model can predict the memory usage trend of terminal devices and edge gateways over a future period based on memory usage data from similar tasks in the past, as well as the scale and complexity of the current task.

[0046] Then, the predicted memory usage information is compared with the corresponding secure memory usage status. The secure memory usage status is an independent metric associated with each trusted execution environment, reflecting the upper limit of memory usage allowed for that environment in terms of security. By comparing, if the predicted memory usage information of a terminal device or edge gateway exceeds its corresponding secure memory usage status, then that node is identified as a dynamically offloaded node.

[0047] Next, a corresponding parent node is matched for each dynamic offloading node, constructing a dynamic offloading pair. The parent node undertakes part of the tasks of the dynamic offloading node. For example, when a terminal device is identified as a dynamic offloading node, its corresponding parent node may be an edge gateway; when an edge gateway is identified as a dynamic offloading node, its corresponding parent node may be an edge server. A dynamic offloading configuration is defined based on multiple dynamic offloading pairs. This configuration includes at least an offloading path and a preset offloading alternative environment. The offloading path clarifies the specific method and path by which tasks are transferred from the dynamic offloading node to the parent node, and the preset offloading alternative environment provides a suitable runtime environment for the offloaded tasks.

[0048] Finally, the hierarchical trusted execution environment is updated based on the dynamic offloading configuration. Dynamic offloading transfers some tasks from resource-constrained nodes to higher-level nodes, optimizing resource allocation across the entire edge computing network and improving system stability and security. Simultaneously, the updated hierarchical trusted execution environment better adapts to dynamic network changes, ensuring secure and low-latency data interaction at different processing stages.

[0049] The differentiated authentication configuration module 12 is used to construct a device collaboration relationship graph of the target edge computing network, divide the network nodes of the target edge computing network into multiple real-time levels based on the device collaboration relationship graph, and configure a differentiated key pre-allocation strategy for each real-time level.

[0050] In this embodiment, firstly, a device collaboration relationship graph of the target edge computing network is constructed. The types, functions, and communication relationships of each node in the network are collected. By analyzing and integrating node information, the collaboration relationships between nodes are depicted. For example, this involves identifying terminal devices that frequently interact with specific edge gateways, and edge gateways that have data transmission relationships with edge servers.

[0051] Based on the constructed device collaboration relationship graph, the network nodes of the target edge computing network are divided into multiple real-time levels. Nodes that require real-time response, frequent data interaction, and extremely high latency requirements, such as real-time monitoring equipment and industrial automation control terminals, are classified as high real-time level; while nodes that are relatively insensitive to latency and have a low data interaction frequency, such as sensors that periodically upload data, are classified as low real-time level.

[0052] Secondly, differentiated key pre-allocation strategies are configured for each real-time level. For nodes with high real-time requirements, a fast and efficient key pre-allocation method is adopted to reduce key allocation time and ensure the rapid establishment of secure communication channels. A certain number of keys can be pre-allocated, allowing for rapid encryption and decryption operations when data interaction is needed. For nodes with low real-time requirements, a more complex but secure key pre-allocation strategy is employed, such as dynamically adjusting the number of keys allocated and the update cycle based on the node's usage frequency and security needs.

[0053] Furthermore, when configuring differentiated key pre-allocation strategies, key security and management efficiency must also be considered. Different key storage methods and access permissions should be set for each real-time level node to ensure keys are not illegally obtained. Simultaneously, a key management mechanism should be established to regularly update and back up keys, preventing data security issues due to key leakage or loss.

[0054] By using the above methods, key resources can be flexibly allocated according to the real-time requirements of different nodes, thereby improving the efficiency and security of key management.

[0055] The differentiated authentication configuration module includes:

[0056] An interaction correlation determination unit is used to identify the business dependencies and data interaction patterns among multiple network nodes in the target edge computing network, and to determine the interaction correlation between network nodes.

[0057] The relation edge weight calculation unit is used to obtain the data interaction frequency and real-time requirements between network nodes based on the interaction correlation, and calculate the relation edge weights according to the preset graph construction rules.

[0058] The collaborative relationship graph establishment unit is used to establish the device collaborative relationship graph based on the relationship edge weights and the business dependencies.

[0059] In this embodiment, the first step is to identify the business dependencies and data interaction patterns among multiple network nodes in the target edge computing network. Business dependencies reflect the upstream and downstream relationships between different nodes in the business process. For example, data from a terminal device needs to be processed by an edge gateway before being transmitted to an edge server for storage and analysis, demonstrating the business dependency between the terminal device, the edge gateway, and the edge server. Data interaction patterns include the data transmission direction, transmission frequency, and transmission volume.

[0060] Secondly, based on the interactive relationships, the frequency of data interaction and real-time requirements between network nodes are obtained. The frequency of data interaction can be counted by monitoring the number of data transmissions between nodes within a certain period of time, while the real-time requirements are determined based on the nature of the services carried by the nodes.

[0061] For example, real-time video surveillance services have high requirements for the real-time performance of data transmission, while periodic data acquisition services have relatively lower requirements. The weights of relational edges are calculated according to preset graph construction rules, which can comprehensively consider factors such as data interaction frequency, real-time requirements, and the tightness of business dependencies. For instance, the weights of relational edges between nodes with high data interaction frequency, strong real-time requirements, and close business dependencies will be relatively large.

[0062] Finally, a device collaboration graph is established based on edge weights and business dependencies. Edge weights reflect the tightness of the connections between nodes, while business dependencies clarify the logical relationships between nodes. By integrating information into the graph, the collaboration relationships between various nodes in the target edge computing network are demonstrated, providing a strong basis for subsequently dividing network nodes into multiple real-time levels and configuring differentiated key pre-allocation strategies.

[0063] Furthermore, the execution steps of the differentiated authentication configuration module also include:

[0064] A real-time performance classification unit is used to classify network nodes into multiple real-time performance levels based on the weights of the relationship edges in the device collaboration graph.

[0065] A configuration unit is configured to configure differentiated key update cycles and key pre-allocation quantities for each real-time level, wherein the key update cycle is negatively correlated with the real-time level and the key pre-allocation quantity is positively correlated with the real-time level;

[0066] The trusted remote authentication unit is used to pre-allocate session keys for multiple real-time levels with cooperative relationships and complete trusted remote authentication during the initialization phase of the target edge computing network, in conjunction with the device cooperative relationship graph.

[0067] A secure communication channel establishment unit is used to establish a secure communication channel directly using a pre-allocated session key when data interaction is required, and to periodically rotate and update the key in conjunction with the key update cycle and the number of pre-allocated keys.

[0068] The key update unit is used to identify the affected subgraph range based on the device collaboration relationship graph when a change in the network node of the target edge computing network is detected, and to perform key updates only on devices within the subgraph range.

[0069] In this embodiment, network nodes are first divided into multiple real-time levels based on the edge weights of the device collaboration graph. Nodes with larger edge weights tend to have more frequent data interactions and higher real-time requirements, and are therefore classified as high real-time level; while nodes with smaller edge weights have relatively less data interaction and lower real-time requirements, and are therefore classified as low real-time level.

[0070] Secondly, differentiated key update cycles and key pre-allocation quantities are configured for each real-time level. Since the key update cycle is negatively correlated with the real-time level, nodes with high real-time levels have relatively longer key update cycles. Because high real-time nodes need to quickly establish secure communication channels, frequent key updates would increase communication latency and impact real-time performance. Nodes with low real-time levels, on the other hand, have shorter key update cycles, which improves security and reduces the risk of key leakage. Simultaneously, the key pre-allocation quantity is positively correlated with the real-time level. Nodes with high real-time levels pre-allocate more keys to ensure that secure communication channels can be quickly established using the pre-allocated keys when data interaction is needed, reducing waiting time; nodes with low real-time levels pre-allocate fewer keys to avoid wasting key resources.

[0071] Furthermore, during the initialization phase of the target edge computing network, session keys are pre-assigned to multiple real-time levels with collaborative relationships, and trusted remote authentication is completed, based on the device collaboration relationship graph. The device collaboration relationship graph clarifies the collaborative relationships between nodes and pre-assigns session keys. Simultaneously, trusted remote authentication ensures the authenticity and reliability of the nodes participating in communication, preventing unauthorized nodes from accessing the network.

[0072] Specifically, when data interaction is required, a secure communication channel is established directly using a pre-allocated session key, and the key is periodically rotated and updated based on the key update cycle and the pre-allocated key quantity. This ensures both the timeliness of data interaction and enhances communication security through periodic key updates. For example, when data interaction occurs at nodes with high real-time requirements, the pre-allocated key is quickly used to establish a channel, and updates are performed according to a longer key update cycle; nodes with low real-time requirements rotate the key according to a shorter update cycle.

[0073] When a change in network nodes of the target edge computing network is detected, the affected subgraph range is identified based on the device collaboration relationship graph, and key updates are performed only on devices within that subgraph range. Changes in network nodes may include node addition, removal, or failure. The device collaboration relationship graph can quickly locate the affected nodes and their related collaboration relationships, and key updates are performed on devices within the affected subgraph range, avoiding unnecessary key update operations on the entire network and improving the efficiency of key management.

[0074] The elastic federated learning module 13 is used to perform dual node screening on network nodes based on behavioral feature pre-screening and real-time connection performance evaluation, determine the participating nodes in federated learning, and obtain an elastic federated learning scheme by combining the participating nodes in federated learning with a preset asynchronous aggregation mechanism.

[0075] In this embodiment, a pre-screening based on behavioral characteristics is first performed. Historical behavioral data of each node in the network is collected, such as data upload frequency, data accuracy, and activity level in computation. By analyzing these behavioral characteristics, nodes with good behavioral records, high data quality, and stable computational capabilities are selected. For example, nodes that frequently and accurately upload data and actively participate in computational tasks are given higher priority; while nodes that upload data late, have large data errors, or are not actively participating in computation are initially excluded.

[0076] Secondly, real-time connection performance is evaluated. Based on the pre-screening, the real-time connection performance of the remaining nodes is assessed. Network bandwidth, latency, packet loss rate, and other metrics are monitored to understand the connection stability and data transmission capabilities of the nodes in the current network environment. Nodes with high network bandwidth, low latency, and low packet loss rate are considered to have good real-time connection performance; conversely, they may not be suitable as participating nodes in federated learning.

[0077] The participating nodes in the federated learning process are determined through a dual-node screening method. These selected nodes possess both desirable behavioral characteristics and stable real-time connectivity, enabling efficient data interaction and model training during the federated learning process.

[0078] Then, a flexible federated learning solution is obtained by combining the federated learning participating nodes with a pre-defined asynchronous aggregation mechanism. The asynchronous aggregation mechanism allows participating nodes to complete local model training at different times and upload the training results asynchronously. Once a node completes local training, it can upload its local model parameters to the server for aggregation without waiting for other nodes. The server then dynamically adjusts the global model based on the uploaded model parameters.

[0079] The flexible federated learning scheme can flexibly adjust to the dynamic changes in network nodes. When a new node joins or an existing node leaves, the system can quickly re-select participating nodes and adjust the aggregation mechanism to ensure the efficiency and stability of federated learning. Simultaneously, this scheme can dynamically allocate computing resources based on the real-time status of the network, improving the resource utilization of the entire edge computing network.

[0080] The elastic federated learning module includes:

[0081] The node partitioning unit is used to acquire the behavioral characteristics of network nodes and perform work rhythm analysis, dividing network nodes into rhythm nodes and free nodes.

[0082] The first prediction unit is used to predict the first node availability status of the rhythm node in the next federated learning window based on the working rhythm characteristics of the rhythm node and the current production cycle information.

[0083] The second prediction unit is used to obtain the task planning information of the free node and evaluate the availability status of the free node in the next federated learning window.

[0084] The candidate node set determination unit is used to pre-screen based on the availability status of the first node and the availability status of the second node to determine the candidate node set for federated learning.

[0085] The final node determination unit is used to perform real-time connection performance evaluation on the candidate nodes in the set of candidate nodes for federated learning within a preset time window before the next federated learning window, and select the node that will ultimately participate in federated learning from the set of candidate nodes based on the real-time connection performance evaluation results.

[0086] In this embodiment, firstly, the behavioral characteristics of network nodes are acquired and their work rhythm is analyzed, dividing the network nodes into rhythmic nodes and free nodes. Work rhythm analysis is conducted by long-term monitoring of the network nodes' working time patterns, task execution frequencies, and other behavioral characteristics. Rhythmic nodes typically have relatively fixed working patterns and time patterns, such as periodically executing tasks according to a specific production rhythm; while free nodes have relatively flexible working patterns, without obvious fixed rhythms, and their task execution time and frequency may be affected by various factors.

[0087] Secondly, based on the working rhythm characteristics of the rhythm nodes and combined with the current production cycle information, the availability status of the rhythm nodes in the next federated learning window is predicted. Production cycle information reflects the rhythm and speed of the entire production process; for rhythm nodes, their working status is related to the production cycle. By analyzing the historical working data and current production cycle information of the rhythm nodes, it is predicted whether they are in an available state in the next federated learning window, i.e., whether they have sufficient resources and capabilities to participate in the federated learning task.

[0088] Next, the task planning information of the free node is obtained to assess its availability as a second node in the next federated learning window. The task planning information of the free node includes its task schedule and resource requirements for a future period. By analyzing this information, it is assessed whether the free node has available resources and time to participate in federated learning tasks within the next federated learning window.

[0089] Subsequently, based on the availability status of the first node and the second node, a pre-screening process is performed to determine the candidate node set for federated learning. Rhythm nodes and free nodes that are predicted to be available are included in the candidate node set.

[0090] Finally, within a preset time window before the next federated learning window, real-time connection performance is evaluated on the candidate nodes in the federated learning candidate node set. Based on the real-time connection performance evaluation results, the node that will ultimately participate in federated learning is selected from the candidate node set. Real-time connection performance evaluation can monitor indicators such as network bandwidth, latency, and packet loss rate of the nodes, ensuring that the finally selected node can stably perform data interaction and model training during the federated learning process.

[0091] By using a dual-node screening process, we identified federated learning participants that possess both good behavioral characteristics and stable real-time connection performance, laying the foundation for obtaining a flexible federated learning solution in the future.

[0092] Furthermore, the implementation of the elastic federated learning scheme includes:

[0093] Set up dual aggregation trigger conditions based on the minimum number of participants and the minimum proportion of participants. Count the number of network nodes that submit gradients within a preset timeout threshold. When either the minimum number of participants or the minimum proportion of participants is met, the aggregator is triggered to start working.

[0094] For timeout response nodes that have not submitted gradients within the preset timeout threshold, the corresponding late gradients will be stored in the temporary storage area and marked with the delay time.

[0095] Based on the marked delay time and the intrinsic importance level of the timeout response node, the aggregation level of the late gradient is determined, and the late gradient is adaptively aggregated asynchronously based on the asynchronous aggregation mechanism.

[0096] In this embodiment, a dual aggregation triggering condition is first established based on the minimum number of participants and the minimum participant ratio. The minimum number of participants refers to the number of network nodes submitting gradients within a preset timeout threshold, triggering the aggregator to start working. The minimum participant ratio refers to the proportion of nodes submitting gradients to the total number of nodes participating in federated learning, which also triggers the aggregator. The number of network nodes submitting gradients within the preset timeout threshold is counted, and the aggregator is triggered when either the minimum number of participants or the minimum participant ratio is met. This dual triggering condition ensures that the aggregation process can be initiated under different network environments and node participation conditions, improving the efficiency and stability of federated learning.

[0097] Secondly, for nodes that fail to submit gradients within the preset timeout threshold, the corresponding late gradients are stored in a temporary storage area and marked with a delay time. Various factors in the network may cause some nodes to fail to submit gradients on time, such as network fluctuations or node failures. Storing late gradients in a temporary storage area can prevent gradient loss, and marking the delay time helps in the subsequent proper handling of late gradients.

[0098] Then, the aggregation level of late gradients is determined based on the labeling delay time and the intrinsic importance level of the timeout response nodes. The intrinsic importance level of timeout response nodes can be evaluated based on factors such as their historical performance in federated learning, data quality, and computational power. The longer the labeling delay time, the worse the timeliness of the gradient; the higher the intrinsic importance level, the more important the node's role in federated learning.

[0099] Finally, based on the asynchronous aggregation mechanism, late gradients are adaptively aggregated asynchronously. This mechanism allows nodes to complete local model training and upload gradients at different times, enabling the server to dynamically adjust the global model based on the uploaded gradients. For late gradients, adaptive asynchronous aggregation is performed according to their aggregation level.

[0100] For example, late gradients with higher aggregation levels are given more weight to participate in the global model update; late gradients with lower aggregation levels have their impact on the global model appropriately reduced.

[0101] Specifically, adaptive asynchronous aggregation includes at least the following:

[0102] If the aggregation level is high, then the late gradients are weighted and aggregated in the current federated learning round, wherein the labeling delay time is negatively correlated with the weighted aggregation weight, and the intrinsic importance level is positively correlated with the weighted aggregation weight;

[0103] If the aggregation level is medium, then the late gradient is applied with weighted initialization in the next federated learning round, wherein the labeling delay time is negatively correlated with the weighted initialization application weight, and the intrinsic importance level is positively correlated with the weighted initialization application weight.

[0104] If the aggregation level is low, the late gradient is discarded, and the node characteristics of the network node and the delay time are recorded, and the corresponding behavioral characteristics are updated.

[0105] In this embodiment, firstly, if the aggregation level is high, it indicates that although the late gradient is submitted late, it is still of significant value to the update of the global model due to the high intrinsic importance level of its corresponding timeout response node and the relatively short labeling delay time. When weighting and aggregating it in the current federated learning round, the labeling delay time is negatively correlated with the weighting aggregation weight; that is, the shorter the labeling delay time, the greater the weighting aggregation weight. This is because gradients with shorter delay times have better timeliness and can more accurately reflect the current model training situation. Conversely, the intrinsic importance level is positively correlated with the weighting aggregation weight; the higher the intrinsic importance level, the more crucial the role of the node in federated learning, and the more important its gradient is for the update of the global model, thus receiving a greater weight.

[0106] Secondly, if the aggregation level is medium, it indicates that the importance and timeliness of the late gradient are at a moderate level. In the next federated learning round, it is applied with weighted initialization. Similarly, the latency is negatively correlated with the weighted initialization weight, while the intrinsic importance level is positively correlated with the weighted initialization weight. In the next round, weighted initialization is applied, allowing the late gradient to play a role in the new training round. Simultaneously, weights are reasonably allocated according to its latency and node importance to balance its impact on the global model.

[0107] Finally, if the aggregation level is low, it indicates that the late gradient has little value for updating the global model because the labeling delay time is too long or the intrinsic importance level of the corresponding timeout response node is low. In this case, the late gradient is discarded, and the node characteristics and delay time of the network node are recorded, and the corresponding behavioral features are updated.

[0108] By using adaptive asynchronous aggregation, and handling different situations of late gradients appropriately, the elastic federated learning scheme ensures efficiency and stability under different network conditions.

[0109] The interactive management execution module 14 is used to coordinate and integrate the hierarchical trusted execution environment, the differentiated key pre-allocation strategy, and the elastic federated learning scheme to perform low-latency interactive management.

[0110] In this embodiment of the application, the hierarchical trusted execution environment, the differentiated key pre-allocation strategy, and the elastic federated learning scheme are first analyzed.

[0111] A hierarchical trusted execution environment provides a secure operating space for data interaction, effectively preventing data leakage and malicious attacks.

[0112] The differentiated key pre-allocation strategy ensures the security and timeliness of data communication, with different key update cycles for nodes of different real-time requirements.

[0113] The flexible federated learning scheme can flexibly adjust participating nodes and aggregation mechanisms based on the dynamic changes and real-time status of network nodes, thereby improving resource utilization.

[0114] When performing low-latency interaction management, resources are allocated according to different business needs and network conditions. For services with high real-time requirements, priority is given to ensuring their operation in a hierarchical trusted execution environment, and a secure communication channel is quickly established using pre-allocated keys. Simultaneously, an elastic federated learning scheme is used to select suitable participating nodes, ensuring efficient data interaction and model training.

[0115] Furthermore, when encountering abnormal situations such as network fluctuations or node failures, for example, nodes that fail to update keys in a timely manner due to network fluctuations, the key update cycle is appropriately extended according to the differentiated key pre-allocation strategy, while ensuring security. For nodes that fail, the elastic federated learning scheme will quickly re-select participating nodes and adjust the aggregation mechanism to ensure the stability of federated learning.

[0116] By collaboratively integrating hierarchical trusted execution environments, differentiated key pre-allocation strategies, and elastic federated learning schemes, low-latency, secure, and efficient data interaction is achieved in edge computing networks, providing strong support for a trusted data space that integrates edge computing.

[0117] In summary, compared with existing technologies, this application achieves more efficient, secure and stable data interaction and model training by combining a hierarchical trusted execution environment, a differentiated key pre-allocation strategy and a flexible federated learning scheme.

[0118] In summary, the embodiments of this application have at least the following technical effects:

[0119] This application provides a low-latency interactive platform for trusted data spaces that integrates edge computing. First, it constructs a hierarchical trusted execution environment, enabling network nodes at different levels to operate in their respective suitable trusted environments, ensuring data security at different processing stages. Second, it constructs a device collaboration graph and classifies real-time levels, configuring differentiated key pre-allocation strategies. This helps to flexibly allocate key resources according to the real-time requirements of different nodes, improving the efficiency and security of key management. During data interaction, a secure communication channel is quickly established based on the real-time level, reducing authentication time and lowering data interaction latency. Third, it determines participating nodes in federated learning through dual node screening and obtains a flexible federated learning scheme. Dual node screening comprehensively considers the behavioral characteristics and real-time connection performance of network nodes, enabling more accurate selection of suitable nodes for federated learning. The flexible federated learning scheme's dual aggregation trigger conditions and adaptive asynchronous aggregation mechanism can flexibly adjust the aggregation method according to the actual situation of network nodes, improving resource utilization and reducing the overall low efficiency of federated learning caused by the latency of some nodes. Finally, the interactive management execution module collaboratively integrates the results of the above three modules to perform low-latency interactive management. By organically combining a hierarchical trusted execution environment, a differentiated key pre-allocation strategy, and a resilient federated learning scheme, this application ensures low latency and security of data interaction in edge computing networks from multiple dimensions. Through the above technical solutions, this application effectively solves the problems existing in the prior art and provides strong support for the application of edge computing technology in more fields.

[0120] It should be noted that the order of the embodiments described above is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. Furthermore, the above description focuses on specific embodiments of this specification. Additionally, the processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired results. In some implementations, multitasking and parallel processing are possible or may be advantageous.

[0121] The above description is only a preferred embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the protection scope of this application.

[0122] This specification and accompanying drawings are merely illustrative examples of this application and are intended to cover any and all modifications, variations, combinations, or equivalents within the scope of this application. Clearly, those skilled in the art can make various alterations and modifications to this application without departing from its scope. Therefore, if such modifications and modifications fall within the scope of this application and its equivalents, this application intends to include such modifications and modifications.

Claims

1. A trusted data space low-latency interaction platform integrating edge computing, characterized in that, include: The environment layering configuration module is used to construct a hierarchical trusted execution environment in the target edge computing network based on preset trusted execution environment layering rules. The network nodes of the target edge computing network include terminal devices, edge gateways, and edge servers. The differentiated authentication configuration module is used to construct a device collaboration relationship graph of the target edge computing network, divide the network nodes of the target edge computing network into multiple real-time levels based on the device collaboration relationship graph, and configure a differentiated key pre-allocation strategy for each real-time level. The elastic federated learning module is used to perform dual node screening of network nodes based on behavioral feature pre-screening and real-time connection performance evaluation to determine the nodes participating in federated learning, and combine this with... The system describes a federated learning module that uses nodes and a pre-defined asynchronous aggregation mechanism to obtain an elastic federated learning scheme. An interactive management execution module is used to coordinate and integrate the hierarchical trusted execution environment, the differentiated key pre-allocation strategy, and the elastic federated learning scheme to perform low-latency interactive management. The elastic federated learning module includes: a node partitioning unit, used to acquire the behavioral characteristics of network nodes and perform work rhythm analysis, dividing network nodes into rhythm nodes and free nodes; a first prediction unit, used to predict the first node availability status of the rhythm node in the next federated learning window based on the work rhythm characteristics of the rhythm node and the current production cycle information; and a second prediction unit, used to acquire the tasks of the free nodes. The system includes: a planning information unit to assess the availability of the free node within the next federated learning window; a candidate node set determination unit to pre-screen nodes based on the availability of the first and second nodes to determine a candidate node set for federated learning; and a final node determination unit to perform real-time connection performance evaluation on the candidate nodes in the candidate node set within a preset time window before the next federated learning window, and select the node that will ultimately participate in federated learning from the candidate node set based on the real-time connection performance evaluation results. The execution of the elastic federated learning scheme includes: setting dual aggregation trigger conditions based on the minimum number of participants and the minimum proportion of participants, and statistically analyzing the number of participants within a preset timeout threshold. The number of network nodes intersecting gradients is determined. When either the minimum number of participants or the minimum participant ratio is satisfied, the aggregator is triggered to start working. For timeout response nodes that have not submitted gradients within a preset timeout threshold, the corresponding late gradients are stored in a temporary storage area and marked with a delay time. Based on the marked delay time and the intrinsic importance level of the timeout response node, the aggregation level of the late gradient is determined, and adaptive asynchronous aggregation is performed on the late gradient based on the asynchronous aggregation mechanism: if the aggregation level is high, the late gradient is weighted and aggregated in the current federated learning round, wherein the marked delay time is negatively correlated with the weighted aggregation weight, and the intrinsic importance level is positively correlated with the weighted aggregation weight.If the aggregation level is medium, the late gradient is applied using weighted initialization in the next federated learning round, where the labeling delay time is negatively correlated with the weighted initialization application weight, and the intrinsic importance level is positively correlated with the weighted initialization application weight. If the aggregation level is low, the late gradient is discarded, and the node features of the network node and the delay time are recorded, and the corresponding behavioral features are updated.

2. The trusted data space low-latency interaction platform integrating edge computing as described in claim 1, characterized in that, The trusted execution environment layering rules include: deploying a minimal trusted execution environment at the terminal device layer for performing data desensitization and feature extraction operations; deploying a complete trusted execution environment at the edge gateway layer for performing model inference and federated learning client training, supporting containerized trusted computing tasks; and deploying a high-performance trusted execution environment at the edge server layer for performing federated learning model aggregation and secure multi-party computation coordination; wherein each trusted execution environment is associated with an independent secure memory occupancy state.

3. The trusted data space low-latency interaction platform integrating edge computing as described in claim 1, characterized in that, The environment hierarchical configuration module is further configured to: acquire task planning information of the target edge computing network; predict the occupancy status of the terminal device and the edge gateway based on the task planning information and a pre-built occupancy prediction model, and acquire predicted occupancy information, wherein the occupancy prediction model is constructed based on a regression analysis model; compare the predicted occupancy information with the corresponding secure memory occupancy status to determine dynamic unloading nodes; match a corresponding parent node for each dynamic unloading node, construct a dynamic unloading pair, and define dynamic unloading configurations based on multiple dynamic unloading pairs, wherein the dynamic unloading configuration includes at least an unloading path and a preset unloading alternative environment; and update the hierarchical trusted execution environment according to the dynamic unloading configuration.

4. The trusted data space low-latency interaction platform integrating edge computing as described in claim 1, characterized in that, The differentiated authentication configuration module includes: an interaction correlation determination unit, used to identify the business dependencies and data interaction patterns between multiple network nodes in the target edge computing network, and determine the interaction correlation between network nodes; a relationship edge weight calculation unit, used to obtain the data interaction frequency and real-time requirements between network nodes based on the interaction correlation, and calculate the relationship edge weights according to preset graph construction rules; and a collaborative relationship graph establishment unit, used to establish the device collaborative relationship graph based on the relationship edge weights and the business dependencies.

5. The trusted data space low-latency interaction platform for fusion edge computing as described in claim 4, characterized in that, The differentiated authentication configuration module further includes: a real-time level division unit, used to divide network nodes into multiple real-time levels according to the relation edge weights of the device collaboration relationship graph; a configuration unit, used to configure a differentiated key update cycle and key pre-allocation quantity for each real-time level, wherein the key update cycle is negatively correlated with the real-time level, and the key pre-allocation quantity is positively correlated with the real-time level; a trusted remote authentication unit, used to pre-allocate session keys for multiple real-time levels with collaboration relationships and complete trusted remote authentication in the initialization phase of the target edge computing network, in conjunction with the device collaboration relationship graph; a secure communication channel establishment unit, used to directly establish a secure communication channel using the pre-allocated session keys when data interaction is required, and periodically update the key in rotation with the key update cycle and the key pre-allocation quantity; and a key update unit, used to identify the affected subgraph range based on the device collaboration relationship graph when a change in network nodes of the target edge computing network is detected, and perform key updates only for devices within the subgraph range.

Citation Information

Patent Citations

  • Network security situation early warning method and system based on knowledge graph

    CN119603058A

  • Edge cloud hierarchical collaborative task unloading optimization method fusing federal learning

    CN120567858A