Method and device for constructing endogenous security os based on intelligent agent and management and control calculation

By constructing an intrinsically secure OS based on intelligent agent and management computing, the response delay and policy lag issues of the security protection system in the IPv6+5G environment in the existing technology are solved. The system achieves anti-tampering and anti-denial-of-service attack of the multi-agent network security operating system, and improves the resilience and security of the system.

CN121644233BActive Publication Date: 2026-05-12SHENZHEN Y& D ELECTRONICS CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
SHENZHEN Y& D ELECTRONICS CO LTD
Filing Date
2026-02-03
Publication Date
2026-05-12

AI Technical Summary

Technical Problem

In the context of "IPv6+5G" integration, the existing security protection system lacks fine-grained protection and dynamic adaptive defense at the agent level, making it difficult to cope with zero-day attacks. Furthermore, traditional security components lack collaborative mechanisms, resulting in high response latency and lagging policy updates, which makes it impossible to effectively defend against high-capacity DDoS attacks.

Method used

We construct an intrinsically secure OS based on intelligent agents and management computing, adopt a hardware root of trust and a microkernel-based underlying security foundation, define hierarchical multi-intelligent agents, establish a multi-agent communication and interaction protocol stack, develop intelligent collaborative scheduling algorithms, integrate proactive defense and passive response mechanisms, and conduct full lifecycle security posture assessments.

Benefits of technology

It achieves anti-tampering and denial-of-service attack protection for computing/data/communication in a multi-agent network security operating system, ensuring system stability, supporting plug-and-play, rapid elastic scaling of resources, dynamic intrusion detection capabilities, recording and tracing security events, and improving the resilience and security of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121644233B_ABST
    Figure CN121644233B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of information security, and relates to an endogenous security OS construction method and device based on intelligent agents and control computing, which comprises the following steps: constructing a bottom-layer security base based on a hardware trusted root and a microkernel; defining and deploying hierarchical and function-specific multi-intelligent agent bodies based on the bottom-layer security base; establishing a multi-agent communication and interaction protocol stack for the multi-intelligent agent bodies; developing an intelligent collaborative scheduling algorithm for multi-objective optimization based on the multi-agent communication and interaction protocol stack; fusing an endogenous security mechanism of active defense and passive response; and performing a full-life-cycle security situation assessment on the endogenous security operating system. Dynamic intrusion detection can be performed, an intrusion detection system (IDS) based on machine learning is deployed, normal behavior patterns of intelligent agents are learned, and abnormal tampering behaviors, DoS attacks, communication abnormalities and the like are identified.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of information security technology, and in particular to a method and apparatus for constructing an intrinsically secure OS based on intelligent agent and control computing. Background Technology

[0002] With the convergence and evolution of new technologies such as 5G, IPv6, IoT, and MEC (Multi-access Edge Computing), massive numbers of terminal devices are accessing the network, forming large-scale machine-type communication (mMTC) scenarios. In the context of "IPv6+5G" convergence, billions of devices are directly exposed to the public network. Without effective security management mechanisms, they are easily exploited by attackers to form large-scale botnets, launch high-capacity DDoS attacks, and seriously threaten the security of core networks and applications.

[0003] Existing security protection systems mostly adopt a centralized protection model, which suffers from high response latency, lagging policy updates, and difficulty in dealing with zero-day attacks. Although traditional security components such as firewalls, WAFs, and log auditing can be deployed at the edge or in the cloud, they lack collaborative mechanisms and cannot achieve fine-grained protection and dynamic adaptive defense at the agent level.

[0004] Therefore, there is an urgent need for a "self-immune" security architecture with autonomous perception, self-repair, and self-defense capabilities, which can realize core functions such as agent integrity verification, anti-tampering, anti-denial-of-service, and secure communication in a distributed environment, thereby improving the resilience and security of the overall system. Summary of the Invention

[0005] To address the aforementioned technical problems, this invention provides a method for constructing an intrinsically secure OS based on intelligent agent and control computing, employing the following technical solution, including the following steps:

[0006] Construct a low-level security foundation based on hardware root of trust and microkernel;

[0007] Based on the aforementioned underlying security foundation, hierarchical and functionally specialized multi-intelligent agents are defined and deployed.

[0008] Establish a multi-agent communication and interaction protocol stack for the aforementioned multi-intelligent agents;

[0009] Based on a multi-agent communication and interaction protocol stack, an intelligent cooperative scheduling algorithm oriented towards multi-objective optimization was developed.

[0010] An intrinsic security mechanism that integrates proactive defense and passive response;

[0011] Conduct a full lifecycle security posture assessment of the intrinsically secure operating system.

[0012] Preferably, the step of constructing a low-level security foundation based on a hardware root of trust and a microkernel specifically includes:

[0013] Implement a full-link measurement startup mechanism based on trusted platform modules;

[0014] The core functions of the operating system are condensed into a secure kernel;

[0015] By leveraging hardware virtualization extensions, hardware-assisted security domain isolation environments can be created at the operating system level for different security components.

[0016] Preferably, the step of defining and deploying hierarchical, functionally specialized multi-intelligent agents based on the underlying security foundation specifically includes:

[0017] Design a three-tiered collaborative intelligent agent organizational architecture comprising activity monitoring agent, host monitoring agent, and network monitoring agent;

[0018] Perform lightweight, containerized encapsulation and deployment of activity monitoring agents, host monitoring agents, and network monitoring agents;

[0019] Inject local autonomous detection capabilities based on behavioral baselines into activity monitoring agents, host monitoring agents, and network monitoring agents.

[0020] Preferably, the step of establishing a multi-agent communication and interaction protocol stack for the multi-intelligent agents specifically includes:

[0021] Develop a secure communication protocol based on national cryptographic algorithms and two-way authentication;

[0022] Implement an asynchronous messaging mechanism based on a publish / subscribe model and a data bus;

[0023] Design a reliable transmission and control mechanism that is resistant to replay and blocking.

[0024] Preferably, the step of developing an intelligent cooperative scheduling algorithm for multi-objective optimization based on a multi-agent communication and interaction protocol stack specifically includes:

[0025] Design a task allocation algorithm based on multidimensional benefit evaluation;

[0026] Construct a conflict resolution mechanism based on game theory and priority;

[0027] Implement a dynamic load balancing algorithm that incorporates global perception and prediction.

[0028] Preferably, the steps of the intrinsic security mechanism that integrates active defense and passive response specifically include:

[0029] Perform continuous measurement and verification of the integrity of the computing environment;

[0030] Deploy intelligent threat hunting and reasoning based on a large security model;

[0031] Construct a closed-loop automated response and strategy self-optimization system.

[0032] Preferably, the step of conducting a full lifecycle security posture assessment of the intrinsically secure operating system specifically includes:

[0033] Establish a multi-dimensional and quantitative security situation assessment indicator system;

[0034] Conduct routine offensive and defensive drills and chaos engineering practices;

[0035] Perform predictive maintenance and resilient scaling of the architecture based on digital twins.

[0036] To address the aforementioned technical problems, this invention also provides an intrinsically secure OS construction device based on intelligent agent and control computing, employing the following technical solution, including:

[0037] Build modules are used to construct a low-level security foundation based on hardware root of trust and a microkernel;

[0038] The deployment module is used to define and deploy hierarchical, functionally specialized multi-intelligent agents based on the underlying security foundation.

[0039] The communication module is used to establish a multi-agent communication and interaction protocol stack for the multi-intelligent agents;

[0040] The scheduling module is used to develop intelligent collaborative scheduling algorithms for multi-objective optimization based on a multi-agent communication and interaction protocol stack.

[0041] The fusion module is used to integrate intrinsic security mechanisms that combine proactive defense and passive response.

[0042] The assessment module is used to conduct a full lifecycle security posture assessment of the intrinsically secure operating system.

[0043] To address the aforementioned technical problems, the present invention also provides a computer device that employs the technical solution described below, comprising a memory and a processor. The memory stores computer-readable instructions, and the processor, when executing the computer-readable instructions, implements the steps of the aforementioned method for constructing an intrinsically secure OS based on intelligent agent and control computing.

[0044] To address the aforementioned technical problems, this invention also provides a computer-readable storage medium that employs the technical solution described below. The computer-readable storage medium stores computer-readable instructions, which, when executed by a processor, implement the steps of the aforementioned method for constructing an intrinsically secure OS based on intelligent agent and control computing.

[0045] Compared with existing technologies, this invention has the following main advantages: Based on a layered trust architecture, an agent self-immunity system, and a secure communication protocol stack, a multi-agent network security operating system is constructed to achieve a computing environment integrity verification system, tamper-proofing of multi-agent agent computing / data / communication, resistance to denial-of-service (DoS) attacks, and leak prevention of data transmission between agents, meeting the high-security requirements of multi-agent collaborative management; a highly reliable microkernel design is adopted to ensure system core stability, and a full-link trust chain from startup to operation is constructed based on a hardware-level root of trust; the SOMN security management protocol adopts a software bus and address, control, and data three-bus interface design to achieve plug-and-play functionality; lightweight technologies such as containerization are used to achieve rapid elastic scaling of resources and solve the compatibility problem between heterogeneous hardware and software; log auditing and tracing are possible, with all agent startup, operation, and communication behaviors recorded in logs, stored using a hash chain (tamper-proof), allowing the management center to trace the root cause of security events through logs; dynamic intrusion detection is possible by deploying a machine learning-based intrusion detection system (IDS) to learn the normal behavior patterns of agents and identify abnormal tampering behaviors, DoS attacks, communication anomalies, etc. Attached Figure Description

[0046] To more clearly illustrate the solutions in this invention, the accompanying drawings used in the description of the embodiments of this invention will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0047] Figure 1 This is a flowchart of an embodiment of the intrinsically secure OS construction method based on intelligent agent and control computing of the present invention;

[0048] Figure 2 This is a schematic diagram of a structure of an embodiment of the intrinsically secure OS construction device based on intelligent agent and control computing of the present invention;

[0049] Figure 3 This is a schematic diagram of another embodiment of the intrinsically secure OS construction device based on intelligent agent and control computing of the present invention;

[0050] Figure 4 yes Figure 3 A schematic diagram illustrating the management and collaborative working principle of multi-agent intelligent agents in the diagram;

[0051] Figure 5 This is a schematic diagram of the structure of an embodiment of the computer device of the present invention. Detailed Implementation

[0052] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains; the terminology used herein in the specification is for the purpose of describing particular embodiments only and is not intended to limit the invention; the terms "comprising" and "having," and any variations thereof, in the specification, claims, and foregoing drawings are intended to cover non-exclusive inclusion. The terms "first," "second," etc., in the specification, claims, or foregoing drawings are used to distinguish different objects and not to describe a particular order.

[0053] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of the invention. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0054] To enable those skilled in the art to better understand the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings.

[0055] It should be noted that the intrinsically secure OS construction method based on intelligent agent and control computing provided in the embodiments of the present invention is generally executed by a server / terminal device, and correspondingly, the intrinsically secure OS construction device based on intelligent agent and control computing is generally set in the server / terminal device.

[0056] It should be understood that the number of terminal devices, networks, and servers is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be used.

[0057] Example 1

[0058] Please refer to Figure 1 The diagram illustrates a flowchart of an embodiment of the intrinsically secure OS construction method based on intelligent agent and control computation of the present invention. The intrinsically secure OS construction method based on intelligent agent and control computation includes the following steps:

[0059] Step S1: Construct a low-level security foundation based on a hardware root of trust and a microkernel.

[0060] In this embodiment, the electronic device (e.g., a server / terminal device) running on the intrinsically secure OS construction method based on intelligent agent and control computing can receive the intrinsically secure OS construction request based on intelligent agent and control computing via wired or wireless connection. It should be noted that the aforementioned wireless connection methods may include, but are not limited to, 3G / 4G / 5G connections, WiFi connections, Bluetooth connections, WiMAX connections, Zigbee connections, UWB (ultra-wideband) connections, and other currently known or future wireless connection methods.

[0061] The purpose of step S1 is to lay an immutable and trustworthy hardware and kernel foundation for the entire intrinsically secure operating system. This is a prerequisite for the trusted execution of all upper-layer security mechanisms, ensuring that the system is in a known secure state from its inception and can resist malicious tampering at the lower level.

[0062] In this embodiment, step S1, constructing a low-level security foundation based on a hardware root of trust and a microkernel, may specifically include the following steps:

[0063] S11, implement a full-link measurement startup mechanism based on the trusted platform module.

[0064] Integrate a Trusted Cryptographic Module (TCM) conforming to Chinese national cryptographic standards or a Trusted Platform Module (TPM) conforming to international standards on the motherboard of the computing node (server, edge device). This module provides protected storage areas (such as the Platform Configuration Register PCR) and cryptographic computing capabilities for storing core metrics and keys.

[0065] The boot sequence is designed and solidified as follows: BIOS / UEFI firmware -> Bootloader (e.g., GRUB) -> Operating system microkernel -> Security service module. Before transferring control to the next level, each stage uses a cryptographic hash algorithm (e.g., SM3, SHA-256) to calculate the hash value of the next level's code and extends this metric into a specific PCR register in the TPM / TCM. The extension operation is defined as follows: ,in This indicates splicing. This operation is irreversible, ensuring that the startup history is recorded completely and tamper-proof.

[0066] After system startup, a remote proof challenge is initiated by the trusted proof service deployed in the security control layer. The node to be proven uses TPM / TCM to sign the current PCR register value and generate reference information. The control layer compares the received reference information with a pre-set, approved golden ratio value. If they match, the node is determined to be trustworthy during startup; if they do not match, it is marked as a compromised node, and an isolation process is triggered.

[0067] The expanded formula for the metric is: .in, : No. The platform configuration register value after phase extension; H() cryptographic hash function (such as SHA-256); PCR values ​​from the previous stage; : No. The hash value of the component being measured in the stage (such as a kernel image); : indicates a splicing operation.

[0068] This formula ensures the continuity of the startup process. Any step ( Any alteration of ) will lead to the final The unpredictable changes in values ​​are thus detected by the remote verification party. It implements cumulative, collision-resistant recording of startup events.

[0069] The purpose of step S11 is to ensure that every step of the operating system, from hardware power-on to kernel loading, has not been tampered with, and to establish a complete chain of trust, providing a reliable starting point for all subsequent security operations.

[0070] S12 condenses the core functions of the operating system into a secure kernel.

[0071] Following the formally verified microkernel design principles of SEL4 and other kernels, the kernel provides only the following basic services: thread (or task) creation and scheduling, virtual address space management, IPC communication primitives, and interrupt and exception handling. All non-core services (such as the file system, network protocol stack, and device drivers) run in user space as independent "service processes".

[0072] The decision-making and enforcement points of security policies (i.e., reference monitors) are built into the microkernel. All access requests to system resources (objects, such as memory pages and ports), whether from user processes or service processes, must undergo mandatory checks by the reference monitor in the kernel. Its design follows three principles: complete arbitration (all requests must pass through it), tamper resistance (its own code and data cannot be modified), and verifiability (its logic is simple enough to be formally verified).

[0073] Using theorem provers such as Isabelle / HOL or Coq, we can mathematically model and formally prove key security attributes of microkernels (such as integrity and confidentiality). For example, we can prove that "a low-integrity process can never write data to a high-integrity process via IPC," thereby theoretically eliminating a certain type of security vulnerability.

[0074] The access control decision function is: ,in, : The final decision result of the access request (allow / deny); F() : Refers to the security policy decision function integrated in the monitor; : The entity that initiates the access request (such as a process or proxy), along with its security attributes (identity ID, security label, role, etc.); The accessed object (such as a file, memory region, or network socket) is accompanied by its security attributes (security label, category, etc.). : The operation to be performed (such as read, write, execute); : The environmental context in which the access occurred (such as time, geographical location, system security status).

[0075] This function is the abstract core of all mandatory access control (MAC) mechanisms. It demonstrates that access control decisions are based on a comprehensive judgment of subject and object attributes and dynamic environment, rather than just a static list of permissions (such as DAC), providing a mathematical model for implementing fine-grained, dynamically adaptive security policies.

[0076] The purpose of step S12 is to condense the core functions of the operating system (process scheduling, memory management, inter-process communication IPC) into a very small, mathematically proven secure kernel, minimizing potential vulnerabilities and acting as the final arbiter for all resource access requests in the system.

[0077] S13 utilizes hardware virtualization extensions to create hardware-assisted security domain isolation environments for different security components at the operating system level.

[0078] Strong isolation based on CPU virtualization: Fully leverage the hardware virtualization support provided by Intel VT-x or AMD-V to create multiple virtual machine monitor layers or directly utilize security zone technology (such as ARM TrustZone). Critical services of the security control layer (such as the policy engine and scheduling hub) run in the highest privilege level and an independent address space, completely isolated from the ordinary application layer and network service layer.

[0079] In practical implementation, the network service layer includes a network service proxy component. This component comprises multiple cooperating proxy components, each responsible for a different function, which can be flexibly combined. The different components are shown in Table 1.

[0080] Table 1

[0081]

[0082] Each security domain is configured with an independent page table through either the Memory Management Unit (MMU) or the Input / Output Memory Management Unit (IOMMU). This ensures that code within one domain cannot directly access or tamper with the memory of another domain. Simultaneously, memory pages containing critical kernel data structures (such as the task queue and IPC message pool) are marked as non-executable (NX bit) to prevent malicious code injected into these data areas from executing.

[0083] Critical I / O paths for network devices, storage devices, etc., are virtualized and abstracted, and DMA operations are redirected to protected memory areas dedicated to each security domain via the IOMMU. This prevents malicious devices or drivers from corrupting the memory of other security domains through DMA attacks.

[0084] Step S13 relies on technologies such as extended page tables, interrupt remapping, and DMA remapping provided by the CPU hardware. Its significance lies in elevating the fundamental security principle of "isolation" from the software logic level to the hardware enforcement level, greatly increasing the difficulty for attackers to perform lateral movement and privilege escalation.

[0085] The purpose of step S13 is to utilize the hardware virtualization extension of modern CPUs to create an isolated and non-interfering execution environment for different security-critical components (such as different intelligent agents and security services) at the operating system level, so as to prevent the entire system from being compromised due to a vulnerability or compromise of a certain component.

[0086] Step S2: Based on the underlying security base, define and deploy hierarchical, functionally specialized multi-intelligent agents.

[0087] The purpose of step S2 is to break down the massive security monitoring and control tasks and assign them to a series of specialized "intelligent agents" distributed across various levels. This achieves decentralized deployment and specialized division of labor for security capabilities, avoids single points of failure, and lays the foundation for fine-grained awareness and rapid response.

[0088] In this embodiment, step S2, defining and deploying hierarchical, functionally specialized multi-intelligent agents based on the underlying security foundation, may specifically include the following steps:

[0089] S21, design a three-tiered collaborative intelligent agent organizational architecture consisting of activity monitoring agent, host monitoring agent, and network monitoring agent.

[0090] The Activity Monitoring Agent (AMA) acts as a perception layer agent, deployed on the finest-grained objects (such as specific processes, network connections, and log files) on each host. Each AMA is dedicated to monitoring one or a specific type of activity (e.g., "SSH login monitoring agent" or "Apache log agent"). It is only responsible for raw data collection and preliminary anomaly filtering based on simple rules, with a single function and extremely low resource consumption.

[0091] The Host Monitoring Agent (HMA) acts as an aggregation layer agent, with one HMA deployed on each host. It serves as the "manager" and "commander" for all AMAs within that host. The HMA is responsible for receiving and aggregating data reported by all AMAs on the local machine, performing cross-activity correlation analysis, and forming a host-level security posture assessment. Simultaneously, it manages the lifecycle of AMAs (startup, shutdown, configuration) and executes control commands from higher layers.

[0092] Network Monitoring Agent (NMA) acts as a decision-making agent, deployed at the core or regional aggregation nodes of the network. NMA aggregates situational information from multiple host Monitoring Agents (HMAs) and combines it with a global view of network traffic to perform cross-host and cross-network threat correlation analysis and assessment. It is the strategist for collaborative defense, responsible for issuing coordinated response instructions to multiple HMAs.

[0093] Data converges from bottom to top, while control commands are executed from top to bottom: AMA (Data Acquisition) → HMA (Local Fusion) → NMA (Global Decision Making). Agents within the same level do not communicate directly laterally; they must coordinate through the agent at the next higher level. This simplifies the communication model and enhances controllability.

[0094] The purpose of step S21 is to clearly define the levels and responsibilities of the agents, form a clear data flow and control flow of "perception-convergence-decision", and achieve three-dimensional security coverage from point to surface.

[0095] S22 enables lightweight, containerized encapsulation and deployment of activity monitoring agents, host monitoring agents, and network monitoring agents.

[0096] The design is lightweight, with each agent process using a streamlined runtime (e.g., written in Rust / Go to reduce memory safety and runtime overhead), and all non-core functional libraries are removed. The AMA's size should be kept under tens of MB, with resident memory usage in the tens of MB range.

[0097] Containerization is employed, using container runtimes such as Docker or Containerd to package each agent and its precise dependencies into an independent container image. Namespaces are used to isolate processes, networks, and file systems, while control groups limit CPU and memory resource quotas. This makes agent deployment, upgrades, and rollbacks as simple and efficient as managing containers.

[0098] Declarative configuration and management are implemented, with each agent designed with a declarative configuration manifest based on YAML or JSON. The manifest defines the agent type, monitoring targets, reporting policies, resource limits, etc. HMA and NMA manage the configuration status of lower-level agents uniformly by reading and distributing these manifest files, achieving configuration as code.

[0099] The purpose of step S22 is to ensure that the agent itself consumes few resources, starts up quickly, has good cross-platform compatibility, and can be flexibly deployed in various heterogeneous environments, from cloud servers to edge IoT devices.

[0100] S23 injects local autonomous detection capabilities based on behavioral baselines into the activity monitoring agent, host monitoring agent, and network monitoring agent.

[0101] In HMA and AMA with complex functions (such as intrusion detection agents), lightweight machine learning models (such as One-Class SVM and Local Anomaly Factor LOF) are integrated. During the "learning period" when the system is running normally, the model automatically learns the normal characteristics of the monitored object (such as a system call sequence or the network traffic pattern of a service) to form a "behavioral baseline".

[0102] During runtime, the agent inputs feature vectors collected in real time into the baseline model to calculate an anomaly score. For example, using the LOF algorithm, the score... Representation Object Compared to it The local density deviation of the nearest neighbor. The higher the score, the more the behavior deviates from the norm.

[0103] The LOF outlier score formula is: .in, : Data points to be evaluated (current behavior feature vector); :point of The set of nearest neighbors; :point The locally accessible density reflects The density of nearby points; :point The local abnormal factor score.

[0104] LOF scores can effectively identify "outliers" whose behavior patterns differ from most of their neighbors, making them ideal for discovering unknown, non-standard, and anomalous behaviors, such as early signs of zero-day attacks.

[0105] A dynamic threshold is set for abnormal scores. When a score exceeds the threshold, the agent can immediately execute a pre-defined primary response action locally (such as generating a high-priority alarm for immediate reporting, or temporarily blocking the network connection of the suspicious process), while awaiting further instructions from its superior. This minimizes detection-response latency.

[0106] The purpose of step S23 is to endow the agent with preliminary local intelligence while ensuring its lightweight nature, so that it can have a certain degree of autonomous detection and response capabilities when disconnected from the superior or facing deterministic threats, thereby improving system resilience.

[0107] Step S3: Establish a multi-agent communication and interaction protocol stack for the multi-intelligent agent.

[0108] The purpose of step S3 is to provide a unified, secure, and high-performance "dialogue language" and "communication network" for the distributed intelligent agents, ensuring that control commands, status data, and alarm information can be transmitted reliably, completely, and promptly between agents. This is the "nervous system" for realizing multi-agent collaboration.

[0109] In this embodiment, step S3, establishing a multi-agent communication and interaction protocol stack for the multi-intelligent agent, may specifically include the following steps:

[0110] S31, to develop a secure communication protocol based on national cryptographic algorithms and two-way authentication.

[0111] Define the SOMN security management protocol. This protocol operates above the transport layer and uses a message header and message body format. The message header includes a sequence number, timestamp, message type, source / destination proxy ID, etc.; the message body is an encrypted payload.

[0112] Each agent is issued a unique X.509 digital certificate upon initialization. The certificate contains the agent ID, public key, and is signed by the control center's private root CA. Before any two agents establish a connection, they must exchange certificates and verify the trustworthiness of each other's certificate signature chain (verifying back to the root CA), as well as whether the certificate is valid or has been revoked. This is a simplified integration of TLS 1.3 or the Chinese national cryptographic protocol TLCP.

[0113] Both communicating parties use a session key negotiated based on certificate exchange (such as ECDHE key exchange) and employ a cryptographic mode that supports authentication, such as SM4 or AES-GCM, to encrypt the message body. In GCM mode, a message authentication code is generated during encryption. The receiver decrypts the message and verifies this MAC, completing decryption and integrity verification in one step.

[0114] The authentication and encryption process is as follows:

[0115] .in, The negotiated session key; One-time use random numbers to prevent replay attacks; : Original message; Additional authentication data (such as message headers); : The encrypted ciphertext; Integrity certification label.

[0116] This operation achieves both encryption and integrity protection within a single algorithmic step, offering high efficiency and strong security. The recipient verifies the encryption by decrypting. This ensures that the message is neither eavesdropped on nor tampered with.

[0117] The purpose of step S31 is to ensure the confidentiality (anti-eavesdropping), integrity (anti-tampering), and authenticity (anti-impersonation) of all communications between agents.

[0118] S32 implements an asynchronous messaging mechanism based on a publish / subscribe model and a data bus.

[0119] Introduce highly available, distributed message queue components, such as Apache Kafka or RabbitMQ clusters, at the management layer. This bus serves as the "data spine" of the system.

[0120] Define a series of logical "topics", such as / alerts / high (high-level alerts), / status / ama / <host_id> (AMA status), / policy / update (policy update). Agents can act as publishers to send messages to specific topics, or as subscribers to topics of interest. When an NMA needs to broadcast a blocking command to all HMAs, it only needs to publish a message once to the / command / block topic, and all HMAs subscribed to that topic will receive it.

[0121] The message bus persistently stores messages on key topics (retaining them for a certain time window). When a new agent joins or an existing agent recovers, it can retrospectively subscribe to historical messages, quickly synchronize the state, and avoid information loss.

[0122] The purpose of step S32 is to decouple the direct dependencies between agents, support flexible communication modes such as one-to-many and many-to-many, improve the scalability and reliability of the system, and is especially suitable for scenarios such as alarm broadcasting and state synchronization.

[0123] S33 is designed with a reliable transmission and control mechanism that is resistant to replay and blocking.

[0124] The SOMN protocol message header contains a globally monotonically increasing sequence number and a high-precision timestamp. The receiver maintains a "sliding window" of processed messages. For a new message, it checks if its sequence number is within the window and has not appeared before, and also checks if the timestamp is within an acceptable time deviation range (e.g., ±30 seconds). Only if both pass is the message accepted, effectively preventing replay attacks.

[0125] Implement priority-based message queues within the agent and on the message bus. Messages are categorized as follows: real-time control commands (highest), alarms (high), status reports (medium), and logs (low). High-priority messages can preempt the processing and transmission resources of low-priority messages, ensuring that critical commands can still be processed promptly even under high system load.

[0126] For critical control commands, a request-acknowledgment model is used. The sender starts a timer after issuing the command; if no application-layer acknowledgment is received from the receiver before the timeout, retransmission is performed using an exponential backoff strategy. Simultaneously, lightweight heartbeat messages are periodically exchanged between upper and lower level agents. If multiple heartbeats are lost consecutively, a connection or peer agent failure is determined, triggering a failover process (see step S6).

[0127] The purpose of step S33 is to cope with complex network environments, ensure that critical control instructions are not lost, not repeated, and not blocked indefinitely due to network latency or agent busyness, and ensure the timeliness and certainty of control.

[0128] Step S4: Develop an intelligent collaborative scheduling algorithm for multi-objective optimization based on a multi-agent communication and interaction protocol stack.

[0129] The role of step S4 is to act as the "scheduling hub" of the system, dynamically and rationally allocate thousands of security monitoring and response tasks to the most suitable intelligent agents for execution, and resolve resource competition and task conflicts between agents, so as to maximize the overall efficiency and resource utilization of the system while ensuring security.

[0130] In this embodiment, step S4, developing an intelligent cooperative scheduling algorithm for multi-objective optimization based on a multi-agent communication and interaction protocol stack, may specifically include the following steps:

[0131] S41, Design a task allocation algorithm based on multidimensional benefit evaluation.

[0132] Maintain a dynamic capability vector for each agent (especially AMA). .in, Success rate of historical mission execution. Current load factor (see step S43). : Semantic matching degree with the task (e.g., whether the agent is specialized in this task type). Network / location proximity to the mission target (reducing communication overhead).

[0133] When it becomes a new task When selecting an agent, each candidate agent is calculated. Expected benefit value : .in, : Weighting coefficients, which correspond to the emphasis on success rate, load balancing, matching degree, and network overhead, respectively, and can be dynamically adjusted; :acting Historical success rate; :acting The current load factor; :acting For the task The matching degree (0 to 1); :acting Execute the task The network overhead normalized value (from 0 to 1).

[0134] This function transforms the task allocation problem into a multi-objective optimization problem. The value comprehensively reflects the "cost-effectiveness" of the agent performing the task. The scheduling center can select... The agent with the highest value, or the agent selected from high-efficiency agents using strategies such as polling or tournament selection, can be chosen to balance fairness and efficiency.

[0135] The scheduling hub (usually located in NMA or a separate scheduling service) maintains real-time profiles of agent capabilities and the system task queue. When a new task arrives, it immediately calculates the availability of each agent based on the aforementioned model. The value is determined, and the allocation is performed.

[0136] The purpose of step S41 is to select one or more optimal execution agents for each newly generated security task (such as "scanning for vulnerabilities in host A" or "deep analysis of traffic from IP X") to ensure that the task is completed efficiently and accurately.

[0137] S42, Construct a conflict resolution mechanism based on game theory and priority.

[0138] The scheduling hub continuously monitors resource requests and task declarations from agents. When a conflict is detected, the conflicting parties (agents or tasks) are modeled as participants in a game. Each participant... There is a set of strategies (such as "continue execution" and "concede and wait") and a payoff function. The function and its task priority Related to task progress.

[0139] The system assigns static priorities (e.g., P0-P3) to each type of task. When a conflict occurs, a preliminary decision is made based on priority: higher-priority tasks unconditionally gain resources or execution rights, while lower-priority tasks are suspended or migrated. This is the simplest and most efficient conflict resolution method.

[0140] When conflicting tasks have the same priority, a utility-based negotiation mechanism is initiated. Drawing inspiration from Nash bargaining, the goal is to find a solution that maximizes the product of utilities for all participants. A simplified implementation involves calculating the utility of each task... In the current conflict resources Marginal utility under The scheduling center tends to prioritize tasks with higher marginal utility by allocating resources to them first. Meanwhile, delayed tasks receive a "compensation point," which increases their priority in subsequent scheduling processes.

[0141] The purpose of step S42 is to conduct fair and efficient arbitration when multiple agents compete for the same scarce resource (such as CPU cores or specific port monitoring rights) or when multiple task logics conflict (such as simultaneously requesting to monitor process P and terminate process P).

[0142] S43 implements a dynamic load balancing algorithm that combines global awareness and prediction.

[0143] Regularly collect data from each agent. Real-time resource utilization (CPU) ,Memory Network I / O Calculate its overall load factor. : .in, :acting The overall load factor; Current CPU, memory, and network I / O utilization; The maximum CPU, memory, and network I / O quota allocated to this agent; Weighting coefficients reflect the sensitivity of different resources to the impact on proxy performance (usually...). Highest).

[0144] It is a normalized comprehensive indicator. The closer the value is to 1, the more saturated the resource utilization; a value exceeding 1 indicates overload. It can reflect the busy / idle status of an agent more comprehensively than a single indicator.

[0145] Periodically check all agents Perform cluster analysis (such as K-means) to identify overloaded clusters, normal clusters, and idle clusters. Set thresholds, such as... For overload, The cluster is currently idle. When both overloaded and idle clusters are detected, a load migration decision is triggered.

[0146] From the overloaded agent, select the task with the lowest migration cost. Migration cost Consider: task data volume, the impact of task interruptions on continuity, and the affinity between the task and the agent. Selection. Low and target idle agent Tasks with high values ​​(see step S41) are migrated. After migration, the load coefficients of the relevant agents are recalculated to form closed-loop control.

[0147] The purpose of step S43 is to monitor the load status of all agents in real time, and prevent some agents from being overloaded while others are idle through intelligent migration tasks, thereby ensuring the overall stability and high throughput of the system.

[0148] Step S5: Inherent security mechanism that integrates active defense and passive response.

[0149] The purpose of step S5 is to transform security from an add-on feature into an inherent and spontaneous attribute of the operating system. Through a series of tightly integrated mechanisms, the system can not only passively respond to known threats, but also proactively detect anomalies, predict risks, and even self-repair after being damaged.

[0150] In this embodiment, step S5, the intrinsic security mechanism that integrates active defense and passive response, may specifically include the following steps:

[0151] S51 performs continuous measurement and verification of the integrity of the computing environment.

[0152] Periodically (e.g., every 5 minutes), calculate the hash value of critical files (proxy binary files, policy files, kernel modules) and compare it with a baseline value stored in secure hardware or a remote trusted service.

[0153] Hooks are implanted in the kernel or security extension modules to monitor critical system call sequences and kernel function call graphs. By comparing these with predefined "normal behavior models," the runtime behavior of advanced malware such as kernel-level rootkits can be detected.

[0154] Each integrity measurement result (file path, hash value, timestamp, verification result) is recorded as a transaction in a lightweight, permission-managed private blockchain or hash chain. The hash of each record is contained within the previous record, forming an immutable chain. This provides highly credible evidence for security auditing and forensics.

[0155] Hash chain formula: .in, : No. The hash value of each block; H(): hash function; The hash value of the previous block; : No. Data recorded in the sub-measure; : splicing operation.

[0156] Any tampering with historical records will cause a change in their hash value, thereby corrupting the hashes of all subsequent blocks, and the tampering will be detected immediately. This achieves tamper-proof and traceable logs.

[0157] When integrity breaches are detected, the system does not simply issue an alert. For repairable components (such as tampered configuration files), it automatically pulls the correct version from the security repository and overwrites it. For core components (such as infected agent binaries), it immediately terminates the process, isolates the host or container from the trusted network, and initiates a clean standby instance takeover process.

[0158] The purpose of step S51 is to extend the trusted boot mechanism of step S1 to the entire runtime, and to perform continuous and silent integrity checks on critical system components (kernel, agent, configuration files) to ensure that they have not been tampered with during operation.

[0159] S52 deploys intelligent threat hunting and reasoning based on a large security model.

[0160] Based on a general open-source model, and using a proprietary massive attack and defense knowledge base (ATT&CK framework, vulnerability descriptions, historical attack and defense cases), device logs, and network traffic metadata, supervised fine-tuning and reinforcement learning are employed to train a dedicated security domain model. This model understands entities (IP addresses, domain names, vulnerability CVE numbers) and relationships (attacks, exploits, and persistence) in the security domain.

[0161] When faced with a series of seemingly loosely connected security events, the dispatch center constructs cue words from the event sequence and contextual information, inputs them into the security model, and requires it to perform thought chain reasoning. For example: Event 1: Host A experiences an abnormal login; Event 2: Host A initiates a large number of SMB connections to internal server B; Event 3: Server B exhibits suspicious PowerShell execution. Please analyze the possible attacker tactics, techniques, and intentions.

[0162] Based on the inference results, the large model automatically reconstructs the attack chain and correlates it with specific tactical phases within the MITRE ATT&CK framework. Then, it can automatically generate or recommend a detailed, multi-product-wide set of action recommendations (playbooks) based on a predefined response playbook library, such as "block the source IP, isolate host A, check sensitive file access records on server B, and search for lateral movement traces." This significantly improves the efficiency of advanced threat analysis and response.

[0163] The purpose of step S52 is to utilize artificial intelligence, especially large security models trained in vertical domains, to perform deep correlation and reasoning on massive amounts of low-value security data, proactively discover hidden threat clues and complex attack chains, and achieve a transformation from "alarm fatigue" to "precision hunting".

[0164] S53, construct a closed-loop automated response and strategy self-optimization system.

[0165] Transform security scenario-based or expert-predefined action scripts into executable workflows. Utilize a low-code / no-code orchestration engine to orchestrate actions such as calling firewall APIs, EDR isolation commands, and backup locking APIs into processes via a graphical drag-and-drop interface. Once a script is triggered, the orchestration engine automatically and sequentially executes these actions, achieving sub-second response times.

[0166] After the automated response is executed, the system does not assume success. A dedicated "verification agent" is activated to check whether the expected results have been achieved (e.g., whether attack traffic has been reduced to zero, whether malicious processes have terminated). The verification results (success / failure / partial success), along with the administrator's manual feedback ("likes" / "dislikes"), serve as reinforcement learning signals.

[0167] The security decision-making process is modeled as a Markov decision process. The system (agent) is in state... Under the current security situation, take action. (Execute a certain response script) and transition to a new state. and receive a reward (Positive rewards come from successful defense and likes, while negative rewards come from business interruptions and dislikes). Through deep reinforcement learning algorithms (such as PPO), the system continuously learns an optimal policy function. This maximizes long-term cumulative rewards. This means the system can gradually learn which response action is most effective and has the least impact on business operations under different situations.

[0168] The purpose of step S53 is to form an automated closed loop of detection, analysis, decision-making, response, and verification, and to optimize its own strategy through feedback learning after each action, so that the system's defense capabilities can evolve dynamically.

[0169] Step S6: Conduct a full lifecycle security posture assessment of the intrinsically secure operating system.

[0170] The purpose of step S6 is to continuously assess the robustness, survivability, and effectiveness of the entire intrinsic security operating system from a macro and dynamic perspective, and to carry out targeted hardening, drills, and optimizations to ensure that the system can maintain its core functions and achieve the high resilience goal of "unbreakable, unparalleled, and recoverable" when facing constantly evolving threats and internal failures.

[0171] In this embodiment, step S6, which involves conducting a full lifecycle security posture assessment of the intrinsically secure operating system, may specifically include the following steps:

[0172] S61, establish a multi-dimensional and quantitative security situation assessment indicator system.

[0173] The core assessment metrics include vulnerability index, threat activity, defense effectiveness, and system resilience metrics.

[0174] Vulnerability Index: Calculated based on asset importance, vulnerability severity, and exploitability, assessing the overall exposure risk of a system. The formula for the vulnerability index is: ,in, The vulnerability index of the system; :assets The weight of business importance; Vulnerability CVSS baseline score; Vulnerability The current availability factor (dynamically adjusted based on whether there is a public exploit and whether it is used in the wild).

[0175] This formula calculates the overall exposure risk of a system based on asset importance, vulnerability severity level, and exploitability, providing a quantitative basis for security posture assessment.

[0176] Threat activity level: Calculated by weighting factors such as the number of alerts per unit time, alert level, and diversity of attack sources.

[0177] Defense effectiveness: Automated response success rate, average detection time, average response time, false alarm / false negative rate.

[0178] System resilience metrics: core service availability, fault recovery time, and data backup integrity.

[0179] The control center dashboard dynamically displays these indicators using heatmaps, topology maps, and trend curves. Indicators from different dimensions can be integrated into a "comprehensive security situation score," with green, yellow, and red levels assigned.

[0180] When a certain indicator deteriorates, the system can automatically correlate and analyze related data. For example, when threat activity increases, it can quickly pinpoint the network segment, the type of attack, and the vulnerability exploited, and display the affected assets and the response measures already implemented.

[0181] The purpose of step S61 is to replace vague "feelings" with quantitative "dashboards," providing managers with a clear and comprehensive view of system safety and health, and providing data support for optimization decisions.

[0182] S62 conducts routine attack and defense drills and chaos engineering practices.

[0183] Build an automated attack simulation platform. The blue team (defender) is the built-in security system; the red team (attacker) is played by the system's built-in "penetration testing agent" or external automated tools. The platform can launch simulated attacks periodically or on demand, with attack scripts covering the entire chain from information gathering and vulnerability exploitation to lateral movement and data leakage.

[0184] During non-core business hours, safely and in a controlled manner inject faults into the system, such as randomly killing a critical agent process, simulating network partitioning, or creating high disk I / O latency. Observe whether the system's monitoring and alarms are timely, whether failover is effective, and whether core business operations are affected.

[0185] After each exercise, a detailed evaluation report is automatically generated, including: attack / failure detection time, response time, whether the handling actions were correct, the scope of business impact, and which aspects failed or were insufficient. Based on the report, the security team and the technical team jointly develop improvement measures and update them into system policies, scripts, or architecture.

[0186] The purpose of step S62 is to proactively and controllably introduce faults and attacks, test the effectiveness of the defense system and the fault tolerance of the system in a real environment, discover defects in advance, and turn "unknown risks" into "known use cases".

[0187] S63 enables predictive maintenance and resilient scaling of the architecture based on digital twins.

[0188] Constructing a digital twin of the security management system: Utilizing the collected full configuration data, topology data, and historical operational data, a digital twin model that maps 1:1 to the real system is built in an offline environment. This model can simulate agent operation, network traffic, attack interactions, and scheduling decisions.

[0189] Prediction and deduction in twins:

[0190] Simulate business growth or large-scale attack and defense drills in a twin, predict the system load at a future point in time, and thus plan resource expansion in advance (such as adding proxy instances).

[0191] Before deploying new security strategies or scheduling algorithms, conduct simulations in a virtual twin to assess their impact on business performance, system load, and security effectiveness, thus avoiding "online trial and error."

[0192] By inputting newly emerging threat intelligence or vulnerability information into the twin, the potential damage path and scope of an attack can be simulated, thereby enabling the development of targeted defense plans and emergency response procedures in advance.

[0193] Based on predicted results or real-time monitored load metrics, and combined with container orchestration platforms such as Kubernetes, automatic horizontal scaling of proxy instances is achieved. When the load increases, new proxy containers are automatically added to the cluster from the resource pool; when the load decreases, instances are automatically scaled down to save resources. This ensures that the system maintains the optimal performance-cost balance under any pressure.

[0194] The purpose of step S63 is to simulate, extrapolate, and predict in the digital world by constructing a virtual mapping of the system, thereby optimizing resources, adjusting strategies, preventing risks, and enabling the system scale to change flexibly as needed.

[0195] The beneficial effects of implementing this embodiment are as follows: Based on a layered trust architecture, an agent's self-immune system, and a secure communication protocol stack, a multi-agent network security operating system is constructed to realize a computing environment integrity verification system, tamper-proofing of multi-agent agents' computing / data / communication, resistance to denial-of-service (DoS) attacks, and leakage prevention of data transmission between agents, meeting the high-security requirements of multi-agent collaborative management; a highly reliable microkernel design is adopted to ensure the stability of the system core, and a full-link trust chain from startup to operation is constructed based on a hardware-level root of trust; the SOMN security management protocol adopts a software bus and address, control, and data three-bus interface design to achieve plug-and-play functionality; lightweight technologies such as containerization are used to achieve rapid elastic scaling of resources and solve the compatibility problem between heterogeneous hardware and software; log auditing and traceability are possible, with all agent startup, operation, and communication behaviors recorded in logs, which are stored using a hash chain (tamper-proof), allowing the management center to trace the root cause of security events through logs; dynamic intrusion detection is possible, deploying a machine learning-based intrusion detection system (IDS) to learn the normal behavior patterns of agents and identify abnormal tampering behaviors, DoS attacks, communication anomalies, etc.

[0196] This invention can be used in a wide variety of general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices. This invention can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform specific tasks or implement specific abstract data types. This invention can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.

[0197] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by instructing related hardware through computer-readable instructions. These computer-readable instructions can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. The aforementioned storage medium can be a non-volatile storage medium such as a magnetic disk, optical disk, or read-only memory (ROM), or random access memory (RAM).

[0198] It should be understood that although the steps in the flowcharts of the accompanying figures are shown sequentially as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the accompanying figures may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.

[0199] Example 2

[0200] Further reference Figure 2 As a response to the above Figure 1 The present invention provides an embodiment of an intrinsically secure OS construction device based on intelligent agent and control computing, which implements the method shown. Figure 1 Corresponding to the method embodiments shown, this device can be specifically applied to various electronic devices.

[0201] like Figure 2 As shown, the intrinsically secure OS construction device 70 based on intelligent agent and control computing described in this embodiment includes: a construction module 71, a deployment module 72, a communication module 73, a scheduling module 74, a fusion module 75, and an evaluation module 76. Wherein:

[0202] Module 71 is used to build a low-level security foundation based on hardware root of trust and microkernel;

[0203] Deployment module 72 is used to define and deploy hierarchical, functionally specialized multi-intelligent agents based on the underlying security base;

[0204] Communication module 73 is used to establish a multi-agent communication and interaction protocol stack for the multi-intelligent agent;

[0205] The scheduling module 74 is used to develop intelligent cooperative scheduling algorithms for multi-objective optimization based on a multi-agent communication and interaction protocol stack.

[0206] Fusion module 75 is used to integrate intrinsic security mechanisms of active defense and passive response;

[0207] Assessment module 76 is used to conduct a full lifecycle security posture assessment of the intrinsically secure operating system.

[0208] The beneficial effects of implementing this embodiment are as follows: Based on a layered trust architecture, an agent self-immunity system, and a secure communication protocol stack, a multi-agent network security operating system is constructed to realize a computing environment integrity verification system, tamper-proofing of multi-agent agent computing / data / communication, resistance to denial-of-service attacks (DoS), and leakage prevention of data transmission between agents, meeting the high-security level requirements of multi-agent collaborative management; a highly reliable microkernel design is adopted to ensure the stability of the system core, and a full-link trust chain from startup to operation is constructed based on a hardware-level root of trust; the SOMN security management protocol adopts a software bus and address, control, and data three-bus interface design to achieve plug-and-play functionality; lightweight technologies such as containerization are used to achieve rapid elastic scaling of resources and solve the compatibility problem between heterogeneous hardware and software; log auditing and traceability are possible, with all agent startup, operation, and communication behaviors recorded in logs, which are stored using a hash chain (tamper-proof), allowing the management center to trace the root cause of security events through logs; dynamic intrusion detection is possible, deploying a machine learning-based intrusion detection system (IDS) to learn the normal behavior patterns of agents and identify abnormal tampering behaviors, DoS attacks, communication anomalies, etc.

[0209] Example 3

[0210] Further reference Figure 3 As a response to the above Figure 1The present invention provides another embodiment of an intrinsically secure OS construction device based on intelligent agent and control computing, which is similar to the method shown. Figure 1 Corresponding to the method embodiments shown, this device can be specifically applied to various electronic devices.

[0211] like Figure 3 As shown, the intrinsically secure OS construction device based on intelligent agent and management computing described in this embodiment includes: a distributed operating system with intrinsic security characteristics built on software-defined networking / software-defined security (SDN / SDS).

[0212] This distributed operating system adopts a highly modular layered architecture, including a security infrastructure layer, a network service layer, a security resource abstraction and management layer, a security control layer, and an application layer. By separating control and data, it achieves complete decoupling of physical hardware, control logic, and security applications, solving the problems of traditional security devices operating independently, inconsistent strategies, and delayed response. It safeguards specific implementation scenarios such as the four-level railway ticketing system and creates a zero-breakthrough defense system.

[0213] This embodiment systematizes and platformizes security management capabilities, aiming to solve fundamental problems commonly found in traditional security construction, such as siloed product stacking, inconsistent strategies, difficulties in linkage, and unverifiable effects, in the context of cloud computing, edge computing, and multi-domain collaboration becoming the norm.

[0214] This distributed operating system is not a single security tool, but rather defined as a collaborative security infrastructure for distributed heterogeneous networks. By building a centralized control plane and a distributed execution plane, it integrates dispersed security capabilities (such as access control, threat detection, and audit verification) into a unified, coordinated, and organic whole. This transforms security from a stack of point-like products into a full-stack product system covering cloud, network, edge, and endpoint. This system aims to provide a closed-loop capability of discovery, orchestration, distribution, verification, and rollback for network objects (links, switches, routers, private network bearers) and system objects (hosts, processes, applications, and data).

[0215] This distributed operating system is a digital chassis that provides underlying support, resource scheduling, service orchestration, and unified management for Security Operations Centers (SOCs), Network Operations Centers (NOCs), situational awareness platforms, and large-scale, complex security operations environments. It is positioned not only as an integration platform for traditional security systems, but also as an advanced computing system and methodology for future intelligent security operations.

[0216] By unifying management, comprehensive abstraction and pooling of heterogeneous resources are achieved: covering physical devices (servers, network devices, security hardware), virtual resources (VMs, containers), security components (IDS / IPS, EDR, probes, sandboxes), etc., and through software definition, various resources are transformed into programmable, schedulable, and orchestratable "security capability units", forming a unified resource view and management entry point.

[0217] It enables efficient collaboration, breaking down security silos: Enabling various security tools to function like applications in an operating system, achieving seamless collaboration based on a unified data bus and resource scheduling mechanism. It supports cross-vendor, cross-protocol, and cross-domain security capability linkage, enabling collaborative defense with a single event triggering multiple responses.

[0218] To be resilient and survivable, the platform itself must possess high availability, high security, self-healing capabilities, and resilience.

[0219] Even under extreme circumstances such as attacks, component failures, or network outages, core functions can still be guaranteed to continue operating, ensuring uninterrupted security operations.

[0220] It supports platform-level security self-immunity mechanisms to detect, isolate, and recover from attacks on itself.

[0221] Figure 4 yes Figure 3 A schematic diagram illustrating the multi-agent intelligent agent management and collaborative working principle. (See diagram below.) Figure 4 As shown, multi-agent intelligent agent systems, through a distributed collaborative architecture, can achieve comprehensive monitoring and efficient management of the entire environment. However, they also face core risks such as the security of the agents themselves (code / data / communication tampering, denial-of-service attacks) and the security of interactions between agents (data leakage, unauthorized injection). This embodiment aims to build a multi-management agent system with high security and strong collaboration, realize the integrity verification of the computing environment, and ensure the overall security and stable operation of the system.

[0222] By establishing a hierarchical multi-agent management architecture, full-dimensional monitoring and management from the host to the network can be achieved; by building an intelligent agent's self-immune system, the security of the intelligent agent's own code, data, and operation process can be guaranteed; by building a secure interaction system, the confidentiality, integrity, and availability of data transmission between agents can be ensured; by designing efficient scheduling algorithms, task collaboration, resource optimization allocation, and conflict resolution between agents can be achieved; and real-time verification of the integrity of the computing environment can be achieved, timely detection, and blocking of security threats can be achieved.

[0223] The beneficial effects of implementing this embodiment are: it enables dynamic intrusion detection, deployment of machine learning-based intrusion detection systems (IDS), learning the normal behavior patterns of intelligent agents, and identifying abnormal tampering behavior, DoS attacks, communication anomalies, etc.

[0224] Example 4

[0225] To address the aforementioned technical problems, embodiments of the present invention also provide a computer device. Please refer to [link / reference needed]. Figure 5 , Figure 5 This is a basic structural block diagram of the computer device in this embodiment.

[0226] The aforementioned computer device 8 includes a memory 81, a processor 82, and a network interface 83 that are interconnected via a system bus. It should be noted that only the computer device 8 with components 81, 82, and 83 is shown in the figure; however, it should be understood that it is not required to implement all the shown components, and more or fewer components can be implemented alternatively. Those skilled in the art will understand that the computer device described herein is a device capable of automatically performing numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes, but is not limited to, microprocessors, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.

[0227] The aforementioned computer devices can be desktop computers, laptops, handheld computers, and cloud servers, among other computing devices. These devices can facilitate human-computer interaction with users through keyboards, mice, remote controls, touchpads, or voice-activated devices.

[0228] The aforementioned memory 81 includes at least one type of readable storage medium, including flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the aforementioned memory 81 may be an internal storage unit of the aforementioned computer device 8, such as the hard disk or memory of the computer device 8. In other embodiments, the aforementioned memory 81 may also be an external storage device of the aforementioned computer device 8, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the computer device 8. Of course, the aforementioned memory 81 may also include both the internal storage unit and its external storage device of the aforementioned computer device 8. In this embodiment, the aforementioned memory 81 is typically used to store the operating system and various application software installed on the aforementioned computer device 8, such as computer-readable instructions for an intrinsically secure OS construction method based on intelligent agent and control computing. In addition, the aforementioned memory 81 can also be used to temporarily store various types of data that have been output or will be output.

[0229] In some embodiments, the processor 82 described above may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chip. The processor 82 is typically used to control the overall operation of the computer device 8. In this embodiment, the processor 82 is used to execute computer-readable instructions stored in the memory 81 or to process data, for example, to execute computer-readable instructions of the intrinsically secure OS construction method based on intelligent agent and control computing.

[0230] The network interface 83 may include a wireless network interface or a wired network interface, which is typically used to establish a communication connection between the computer device 8 and other electronic devices.

[0231] The beneficial effects of implementing this embodiment are: it enables dynamic intrusion detection, deployment of machine learning-based intrusion detection systems (IDS), learning the normal behavior patterns of intelligent agents, and identifying abnormal tampering behavior, DoS attacks, communication anomalies, etc.

[0232] Example 5

[0233] The present invention also provides another embodiment, namely, providing a computer-readable storage medium storing computer-readable instructions that can be executed by at least one processor to cause the at least one processor to perform the steps of the above-described method for building an intrinsically secure OS based on intelligent agent and control computing.

[0234] The beneficial effects of implementing this embodiment are: it enables dynamic intrusion detection, deployment of machine learning-based intrusion detection systems (IDS), learning the normal behavior patterns of intelligent agents, and identifying abnormal tampering behavior, DoS attacks, communication anomalies, etc.

[0235] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods of the various embodiments of the present invention.

[0236] Obviously, the embodiments described above are merely some embodiments of the present invention, not all embodiments. The accompanying drawings show preferred embodiments of the present invention, but do not limit the patent scope of the present invention. The present invention can be implemented in many different forms; rather, these embodiments are provided to provide a more thorough and complete understanding of the disclosure of the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing specific embodiments, or make equivalent substitutions for some of the technical features. Any equivalent structures made using the content of this specification and drawings, directly or indirectly applied to other related technical fields, are similarly within the patent protection scope of this invention.

Claims

1. A method for constructing an intrinsically secure OS based on intelligent agent and control computing, characterized in that, Includes the following steps: Construct a low-level security foundation based on hardware root of trust and microkernel; Based on the aforementioned underlying security foundation, hierarchical and functionally specialized multi-intelligent agents are defined and deployed. Establish a multi-agent communication and interaction protocol stack for the aforementioned multi-intelligent agents; Based on a multi-agent communication and interaction protocol stack, an intelligent cooperative scheduling algorithm oriented towards multi-objective optimization was developed. An intrinsic security mechanism that integrates proactive defense and passive response; Conduct a full lifecycle security posture assessment of the intrinsically secure operating system; The steps for defining and deploying hierarchical, functionally specialized multi-intelligent agents based on the underlying security foundation specifically include: Design a three-tiered collaborative intelligent agent organizational architecture comprising activity monitoring agent, host monitoring agent, and network monitoring agent; Perform lightweight, containerized encapsulation and deployment of activity monitoring agents, host monitoring agents, and network monitoring agents; Inject local autonomous detection capabilities based on behavioral baselines into activity monitoring agents, host monitoring agents, and network monitoring agents; The steps for establishing a multi-agent communication and interaction protocol stack for the multi-intelligent agents specifically include: Develop a secure communication protocol based on national cryptographic algorithms and two-way authentication; Implement an asynchronous messaging mechanism based on a publish / subscribe model and a data bus; Design a reliable transmission and control mechanism that is resistant to replay and blocking.

2. The method for constructing an intrinsically secure OS based on intelligent agent and control computing according to claim 1, characterized in that, The specific steps for constructing a low-level security foundation based on a hardware root of trust and a microkernel include: Implement a full-link measurement startup mechanism based on trusted platform modules; The core functions of the operating system are condensed into a secure kernel; By leveraging hardware virtualization extensions, hardware-assisted security domain isolation environments can be created at the operating system level for different security components.

3. The method for constructing an intrinsically secure OS based on intelligent agent and control computing according to claim 1, characterized in that, The specific steps for developing an intelligent cooperative scheduling algorithm based on a multi-agent communication and interaction protocol stack and oriented towards multi-objective optimization include: Design a task allocation algorithm based on multidimensional benefit evaluation; Construct a conflict resolution mechanism based on game theory and priority; Implement a dynamic load balancing algorithm that incorporates global perception and prediction.

4. The method for constructing an intrinsically secure OS based on intelligent agent and control computing according to claim 1, characterized in that, The specific steps of the intrinsic security mechanism that integrates active defense and passive response include: Perform continuous measurement and verification of the integrity of the computing environment; Deploy intelligent threat hunting and reasoning based on a large security model; Construct a closed-loop automated response and strategy self-optimization system.

5. The method for constructing an intrinsically secure OS based on intelligent agent and control computing according to any one of claims 1 to 4, characterized in that, The specific steps for conducting a full lifecycle security posture assessment of the intrinsically secure operating system include: Establish a multi-dimensional and quantitative security situation assessment indicator system; Conduct routine offensive and defensive drills and chaos engineering practices; Perform predictive maintenance and resilient scaling of the architecture based on digital twins.

6. A device for building an intrinsically secure OS based on intelligent agent and control computing, characterized in that, include: Build modules are used to construct a low-level security foundation based on hardware root of trust and a microkernel; The deployment module is used to define and deploy hierarchical, functionally specialized multi-intelligent agents based on the underlying security foundation. The communication module is used to establish a multi-agent communication and interaction protocol stack for the multi-intelligent agents; The scheduling module is used to develop intelligent collaborative scheduling algorithms for multi-objective optimization based on a multi-agent communication and interaction protocol stack. The fusion module is used to integrate intrinsic security mechanisms that combine proactive defense and passive response. The assessment module is used to perform a full lifecycle security posture assessment of the intrinsically secure operating system. The deployment module is further used for: Design a three-tiered collaborative intelligent agent organizational architecture comprising activity monitoring agent, host monitoring agent, and network monitoring agent; Perform lightweight, containerized encapsulation and deployment of activity monitoring agents, host monitoring agents, and network monitoring agents; Inject local autonomous detection capabilities based on behavioral baselines into activity monitoring agents, host monitoring agents, and network monitoring agents; The communication module is further used for: Develop a secure communication protocol based on national cryptographic algorithms and two-way authentication; Implement an asynchronous messaging mechanism based on a publish / subscribe model and a data bus; Design a reliable transmission and control mechanism that is resistant to replay and blocking.

7. A computer device, characterized in that, The system includes a memory and a processor, wherein the memory stores computer-readable instructions, and the processor executes the computer-readable instructions to implement the steps of the intrinsically secure OS construction method based on intelligent agent and control computing as described in any one of claims 1 to 5.

8. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-readable instructions, which, when executed by a processor, implement the steps of the intrinsically secure OS construction method based on intelligent agent and control computing as described in any one of claims 1 to 5.