Network switch hardware security protection system based on dynamic encryption
By employing dynamic encryption and adaptive strategies, the problems of easily cracked keys and inaccurate threat identification in traditional network switches are solved, achieving efficient security protection for network switches and improving network security and transmission efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- SHAANXI UNIV OF CHINESE MEDICINE
- Filing Date
- 2026-03-18
- Publication Date
- 2026-04-14
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The static encryption mechanism of traditional network switches cannot adapt to dynamic network changes, making keys easy to crack, threat location inaccurate, and encryption strategies unable to be adjusted according to network area differences, resulting in security risks and resource waste.
The network switch hardware security protection system based on dynamic encryption captures data packet characteristics in real time through a dynamic encryption key generation component, an encryption difference analysis component, a security threat location component, and an adaptive encryption strategy component. It performs three-dimensional difference assessment and threat probability density map generation to achieve adaptive encryption strategy adjustment.
It enhances the security and adaptability of encryption keys, accurately locates network threat areas, optimizes encryption strategies, improves network security and transmission efficiency, and avoids resource waste.
Smart Images

Figure CN121864501A_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security protection technology, specifically to a network switch hardware security protection system based on dynamic encryption. Background Technology
[0002] With the rapid development of network technology, network switches, as the core hub for data transmission, directly impact the stable operation of the entire network system due to their hardware security capabilities. Currently, traditional network switches rely heavily on static encryption mechanisms for security protection. These mechanisms typically use fixed encryption keys and rarely consider the dynamic characteristics of the network during actual operation, resulting in keys that lack adaptability to complex network environments.
[0003] In real-world network transmission, the transmission time interval and load capacity of data packets fluctuate constantly with changes in network traffic, and different types of network protocols also generate data packets with differentiated characteristics. Traditional static encryption methods cannot capture these dynamic changes in real time, and the generated encryption keys always maintain a fixed pattern. Once the key is maliciously cracked, attackers can steal or tamper with network data for an extended period of time, posing a serious threat to network security.
[0004] Traditional network security systems often rely on single network parameters or simple log analysis for threat localization, making it difficult to effectively correlate anomalies in encryption keys with information such as network topology and switch port configurations. When key discrepancies occur, the system cannot quickly and accurately pinpoint the physical network area where the anomaly occurs, leading to delayed threat response and further expanding the scope of security risks.
[0005] Regarding encryption policy adjustments, traditional systems typically employ a uniform policy configuration approach, neglecting the differences in threat probabilities across different network areas. For areas with high threat probabilities, a uniform encryption policy may fail to provide sufficient security protection; conversely, for areas with low threat probabilities, excessive encryption measures can increase network transmission burden, reduce data transmission efficiency, and waste network resources. These issues make traditional network switch hardware security systems ill-suited to meet today's complex and ever-changing network security needs. Summary of the Invention
[0006] The purpose of this invention is to provide a network switch hardware security protection system based on dynamic encryption to solve the problems mentioned in the background art.
[0007] To achieve the above objectives, the present invention provides a network switch hardware security protection system based on dynamic encryption, the system comprising: Dynamic encryption key generation component: Based on the historical traffic patterns and real-time data packet characteristics of the network switch, a dynamic encryption model is constructed. The transmission time interval, load capacity and protocol identifier of the current data packet are captured in real time, and a temporary encryption key value is output through the dynamic encryption model. Encryption Difference Analysis Component: Performs a three-dimensional difference assessment on the temporary encryption key value and the pre-stored baseline key value. The three-dimensional difference assessment includes temporal consistency deviation, entropy fluctuation, and sequence pattern similarity, generating a set of key-level difference indicators. Security threat location component: Input the key-level difference index set into the network topology mapping system, combine it with switch port configuration parameters and network segmentation identifiers to generate a threat probability density map of the security threat propagation path and locate abnormal network physical areas; Adaptive encryption strategy component: Configures encryption strategy parameters based on the threat probability density map, including enabling multi-layer encryption protocols for high-probability threat areas and performing key refresh operations on neighboring network nodes.
[0008] Preferably, the dynamic encryption key generation component specifically includes: Historical traffic pattern analysis: Multi-dimensional analysis and processing of historical traffic data from network switches, including using adaptive window function decomposition to extract packet size distribution characteristics, establishing a correspondence matrix between protocol type and transmission rate through protocol correlation analysis, and using dynamic warping algorithm to align transmission time interval patterns under different network conditions. Dynamic encryption model construction: The processed historical traffic data is input into the hybrid key generation network, which includes a recursive prediction unit based on the traffic trend curve to generate the basic key prediction value, a fully connected network with an embedded entropy adjustment mechanism to correct the prediction deviation caused by protocol changes, and a feature compensator to dynamically adjust the generation weights according to the characteristics of the real-time captured data packets. The heterogeneous data capture unit deployed at the edge synchronously acquires jitter parameters of transmission time intervals, distribution statistics of load capacity, and category labels of protocol identifiers.
[0009] Preferably, the calculation of the temporary encryption key value includes performing: Adaptive smoothing based on network traffic status eliminates measurement errors caused by background noise; The correlation characteristics of transmission time interval, load capacity and protocol identifier are fused by a spatiotemporal feature integration algorithm; The output includes a temporary encryption key value within the normal fluctuation range, which is dynamically updated according to the network load status.
[0010] Preferably, the encryption difference analysis component specifically includes: Timing consistency deviation calculation: The temporary encryption key value is compared with the base key value point by point using a sliding time window. A dynamic alignment algorithm is used to correct the asynchronously sampled key sequence. The cumulative deviation within each window is calculated to generate a timing deviation vector. Entropy fluctuation detection: Calculate the information entropy of the key sequence of temporary value and base value, calculate the entropy ratio, extract the fluctuation index of each sequence segment, and construct the entropy fluctuation vector; Sequence pattern similarity assessment: Based on the structural comparison algorithm, the distance distribution between the temporary value and the reference key sequence is matched, the phase difference of the sequence mutation point is calculated, the divergence value of the pattern consistency is quantized, and a similarity vector is generated; Key-level difference index set generation: The temporal deviation vector, entropy fluctuation vector, and similarity vector are fused by tensor, and scale differences are eliminated through feature weighted normalization. The output is a second-order difference index set with the network node timestamp difference type as the dimension.
[0011] Preferably, the entropy fluctuation detection specifically includes: In the entropy analysis phase, the corresponding entropy components in the temporary and base key sequences are first extracted. Multi-scale entropy analysis is used to divide the frequency band of each group of entropy signals and extract the distribution characteristics within the preset sensitive entropy interval. The sensitive entropy interval is selected to cover the entropy range of typical network attacks. After extraction, the entropy density of the temporary and base data within the sensitive entropy interval is quantified and calculated. Based on the relative change of the two, the fluctuation index of each segment of entropy is extracted. The entropy fluctuation results of all segments are summarized to construct the entropy fluctuation vector.
[0012] Preferably, in the sequence pattern similarity assessment, the structural comparison algorithm uses a distance metric algorithm to perform position matching on the set of mutation points in the two sequences and identify phase differences.
[0013] Preferably, the security threat location component specifically includes: Network topology modeling: Construct a topology diagram of the connection relationship between switch nodes based on the network segmentation identifier, label the link delay parameters between each node, overlay the traffic constraints of the virtual private network access point on the topology diagram, and generate a networked topology model including the delay matrix and the node bandwidth matrix. Threat propagation simulation: The key-level difference index set is mapped to the corresponding nodes in the network topology model; threat propagation simulation is performed based on the graph computing engine. The calculation of threat propagation simulation includes calculating the attenuation factor of threat traffic based on node delay parameters, capturing cross-regional threat association characteristics through a multi-head attention mechanism, and simulating the diffusion path of threat traffic in the topology network using a random walk method. Probability density generation: Statistically analyze the frequency of threat traffic occurrence on each link during simulated propagation, calculate the threat traffic retention probability value by combining link delay parameters, generate a threat probability density map covering the entire network, and mark the set of suspicious links whose probability values exceed the preset threat retention probability threshold; Physical region location: Perform spatial clustering analysis on the threat probability density map to identify threat probability clusters; delineate the physical boundaries of abnormal networks based on network segment identifiers and switch node connections.
[0014] Preferably, the security threat localization component further includes outputting suspicious node identifiers and a main threat propagation path. The suspicious node identifiers are based on network nodes connected by a set of suspicious links, binding network nodes to actual switch ports to form a set of suspicious node identifiers, indicating potential threat sources or affected terminals. The main threat propagation path is obtained by recording the node paths and their order experienced in each round of propagation during the threat diffusion process simulated by random walks. Among all simulated paths, the frequency of occurrence of each path is counted, and the path sequence with the highest cumulative frequency is selected as the main threat propagation path. The output main threat propagation path sequence is a structured and ordered list of nodes.
[0015] Preferably, the adaptive encryption strategy component specifically includes: When the threat probability value of a certain area in the threat probability density map exceeds the preset threat residence probability threshold, an encryption mode switching command is sent to the switch to which the area belongs, and the encryption algorithm strength is increased to several times the original strength. At the same time, the key sequence real-time tracking mode is enabled to capture key change events, and a temporary event detector is deployed on the edge side to record abnormal key fragments. Key refresh operation execution: Apply multi-mode key refresh to the nearest network node with the largest change in threat probability gradient in the threat probability density map.
[0016] Preferably, the multi-mode key refresh includes injecting multi-band test signals through a controllable key generator, calculating the theoretical response key spectrum based on a networked topology model and a delay matrix, recording the response of each node after the test signal injection to obtain the measured response key spectrum, calculating the difference distance between the theoretical response key spectrum and the measured response key spectrum, comparing the difference distance between the measured key spectrum and the theoretical key spectrum, calculating the percentage of abnormal node offset, and marking abnormal node as a key abnormal associated node when the percentage of abnormal node offset exceeds a second threshold.
[0017] Compared with the prior art, the beneficial effects of the present invention are: The dynamic encryption key generation component can construct a dynamic encryption model based on the historical traffic patterns and real-time packet characteristics of the network switch. It captures the transmission time interval, load capacity, and protocol identifier of the current packet in real time to output a temporary encryption key value. This approach breaks the limitation of fixed keys in traditional static encryption mechanisms, allowing the encryption key to be adjusted in real time as the network operates dynamically. This ensures the key is highly adapted to the actual network operating state, effectively avoiding the risk of being easily cracked due to a long-term fixed key. It improves the security and adaptability of the key itself, thereby enhancing the encryption protection capabilities of the network switch during data transmission.
[0018] The encryption difference analysis component employs a three-dimensional difference assessment approach, comparing the temporary encryption key value with the pre-stored baseline key value across three dimensions: temporal consistency deviation, entropy fluctuation, and sequence pattern similarity, generating a set of key-level difference indicators. Compared to traditional single-dimensional key difference detection, this multi-dimensional assessment method can more comprehensively and accurately capture differences between keys, leaving no stone unturned in identifying any potential key anomalies. This provides richer and more reliable evidence for subsequent security threat assessment, reducing false positives or false negatives caused by incomplete single-dimensional analysis, and making key anomaly monitoring more detailed and accurate.
[0019] The security threat localization component inputs a set of key-level difference indicators into the network topology mapping system and combines this with switch port configuration parameters and network segmentation identifiers to generate a threat probability density map, thereby locating abnormal network physical areas. This component effectively correlates key anomaly information with network topology and device configuration information, transforming abstract key difference data into an intuitive threat probability distribution image. This helps administrators quickly and clearly identify network physical areas with security threats, changing the traditional threat localization approach which relies on single pieces of information, resulting in vague and delayed localization. It buys valuable time for timely and targeted security measures, effectively curbing the further spread of security threats within the network.
[0020] The adaptive encryption strategy component configures encryption strategy parameters based on the threat probability density map, enabling multi-layered encryption protocols for high-probability threat areas and performing key refresh operations on neighboring network nodes. This differentiated encryption strategy configuration method abandons the drawbacks of traditional uniform encryption strategies, and can flexibly adjust protection measures according to the threat probability of different network areas. For high-threat probability areas, multi-layered encryption protocols provide stronger security protection against potential high-intensity attacks; for neighboring network nodes, timely key refresh operations can prevent threat spread, while avoiding the waste of network resources and reduced transmission efficiency caused by over-encryption of low-threat areas. It balances network security with the efficiency of network data transmission, achieving a balance between security protection and transmission efficiency, making the entire network switch's security protection system more efficient and reasonable. Attached Figure Description
[0021] Figure 1 This is a timing diagram of the network switch hardware security protection system based on dynamic encryption as described in this invention; Figure 2 A flowchart for calculating the temporary encryption key value; Figure 3 This is a flowchart for entropy fluctuation detection. Detailed Implementation
[0022] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0023] Please see Figure 1This invention provides a network switch hardware security protection system based on dynamic encryption. The system includes: a dynamic encryption key generation component responsible for capturing network data packet transmission time intervals, load capacity, and protocol identifiers in real time, and outputting a temporary encryption key value based on a dynamic encryption model constructed from historical traffic patterns; an encryption difference analysis component performing a three-dimensional difference assessment of the temporary encryption key value and a pre-stored baseline key value, including temporal consistency deviation, entropy fluctuation, and sequence pattern similarity analysis, generating a set of key-level difference indicators; a security threat location component inputting the difference indicators into a network topology mapping system, combining switch port configuration parameters and network segmentation identifiers, simulating threat propagation paths and generating a threat probability density map to locate abnormal network physical areas; and an adaptive encryption strategy component dynamically adjusting the encryption strategy according to the threat probability density map, such as enabling multi-layer encryption protocols or implementing key refresh operations for high-probability threat areas. The entire system is deployed in the network switch through hardware integration, achieving real-time and adaptive security protection.
[0024] Example 1: See Figure 2 Historical traffic pattern analysis, serving as the data preparation stage for building a dynamic encryption model, processes the massive amounts of historical traffic data accumulated by network switches during their normal operation cycles. This data, with data packets as the basic unit, includes fields such as timestamps, source and destination addresses, payload size, and protocol type. Multi-dimensional analysis first focuses on the data packet size distribution characteristics, employing an adaptive window function decomposition method. Unlike fixed-length window partitioning, this method dynamically adjusts the span of the analysis window based on changes in traffic rate. Shorter windows are used during high-traffic periods to capture detailed fluctuations, while longer windows are used during low-traffic periods to smooth random noise and extract macroscopic trends. The window function itself uses functions with low sidelobes, such as the Hanning window or Blackman window, to reduce spectral leakage, thereby more accurately separating the periodic and bursty components in the data packet size sequence. Protocol correlation analysis aims to uncover the intrinsic relationship between protocol type and transmission rate. It uses statistical methods to calculate the average rate, peak rate, and rate variance of different protocols (such as TCP, UDP, and ICMP) within a specific time window, forming a correspondence matrix. The rows of this matrix represent protocol types, and the columns represent different time granularities or network states. The matrix elements store rate statistics, providing a basis for subsequent models to understand the impact of protocol behavior on key stability. The introduction of dynamic warping algorithms addresses the misalignment problem of transmission time interval patterns under different network states. For example, during the high-load state of a weekday day, the time interval pattern of data packet arrivals may be stretched or compressed on the time axis compared to the low-load state at night. Dynamic warping algorithms find an optimal curved path to align the time series under different states, allowing pattern comparisons to be performed on a common time reference, thereby extracting more fundamental interval features that are relatively independent of network state.
[0025] The construction of the dynamic encryption model is the core of the entire key generation process, and its carrier is a computational structure designed as a hybrid key generation network. This network is not a single model, but a composite system in which multiple functional units work together. The recursive prediction unit based on the traffic trend curve is the time-series processing module. It is usually implemented by a long short-term memory network or a gated recurrent unit. This unit receives preprocessed historical traffic time-series data, learns the evolution of traffic in the time dimension, including periodic fluctuations, long-term trends, and short-term burst characteristics. Its output is a basic key prediction value inferred based on historical patterns. This value reflects the theoretical evolution path of the key under the condition of no sudden interference. Fully connected networks with embedded entropy adjustment mechanisms are responsible for handling the uncertainties introduced by dynamic changes in protocols. Changes in protocol identifiers often mean abrupt changes in data flow characteristics (such as packet size distribution and transmission intervals), which directly affect the randomness (entropy) of key sequences. Fully connected networks use protocol type labels and their related statistical characteristics (from the protocol correlation analysis matrix) as additional inputs, and calculate an entropy adjustment amount through one or more nonlinear transformations. This adjustment amount is used to correct the basic key prediction values generated by the recursive prediction unit, so that it can adapt to the entropy jumps brought about by protocol switching. The feature compensator integrates the features of real-time captured data packets to achieve final fine-tuning of key generation. It synchronously receives real-time data from heterogeneous data capture units deployed at the edge, including jitter parameters of transmission time intervals, load capacity distribution statistics, and category labels of protocol identifiers. The feature compensator maintains a dynamic weight matrix internally, which updates the contribution weight of each feature to the final key value in real time according to the current network load status. For example, under high load conditions, the jitter parameter of transmission time intervals may be given a higher weight because network congestion may have a greater impact on timing characteristics. By weightedly fusing real-time features with intermediate key values that have undergone recursive prediction and entropy adjustment, the feature compensator outputs the final temporary encryption key value.
[0026] In the specific calculation process of the temporary encryption key value, adaptive smoothing based on network traffic status is a crucial preliminary step. This process aims to eliminate minor fluctuations in the key value caused by network background noise. Adaptive smoothing typically employs Kalman filtering or its variants. This algorithm treats key value generation as a dynamic system, comprising two stages: state prediction and measurement update. It predicts the current key state based on a historical key value evolution model, and then combines this prediction with real-time measurements of the noisy raw key characteristics. By calculating the Kalman gain, it optimally combines the predicted and measured values, thus outputting a smoothed key estimate that more closely approximates the true state, effectively suppressing short-term random interference. Following closely behind is the spatiotemporal feature integration algorithm, which is responsible for fusing three different dimensions of features—transmission time interval, load capacity, and protocol identifier—into a unified and highly discriminative feature representation. This algorithm borrows the idea of convolutional neural networks in image processing to simultaneously capture spatial local correlations, but adapts it to time series and attribute sequences in this application. The algorithm designs a one-dimensional convolutional kernel that slides along the time dimension to extract local patterns of transmission time intervals. At the same time, it processes the load capacity sequence and the protocol identifier sequence transformed by the embedding layer through different convolutional channels. Then, the feature maps extracted from each channel are concatenated, and then dimensionality reduction and integration are performed through a fully connected layer to generate a comprehensive spatiotemporal feature vector. This vector fully expresses the correlation characteristics of the current network data packets in time and feature space. The final output temporary encryption key value is designed to include a normal fluctuation range. This range is not fixed but is determined by historical statistics and the current network status. For example, the moving average and standard deviation of the key value over a period of time can be calculated and the current value can be compared with them. Allowing it to fluctuate within a range of several times the standard deviation above and below the mean is considered a normal operating range. The update mechanism of the temporary encryption key value is closely tied to the network load status. The update event can be driven by the arrival of data packets or based on a fixed time interval. However, the length of the time interval will be dynamically adjusted according to the current network load. When the load is high, the update is more frequent to cope with the rapidly changing network environment, while when the load is low, the update frequency is appropriately reduced to save computing resources.
[0027] Heterogeneous data capture units deployed at the edge are the physical foundation for real-time feature acquisition. These units are typically integrated near the port processors or network interface cards of network switches as software agents or dedicated hardware probes to achieve packet loss-free capture or line-rate sampling. Jitter parameter capture for transmission intervals requires high-precision timestamps, relying on the switch's hardware clock or a system clock synchronized with a precision time protocol. The capture unit records precise timestamps when packets arrive at or leave a specific port, calculates the time interval between consecutive packets, and calculates statistics for this interval sequence in real time, such as the standard deviation, root mean square deviation, or more complex jitter metrics like packet delay variation within the most recent time window. Load capacity distribution statistics are achieved through real-time statistical aggregation of the load length of each packet. The capture unit maintains a sliding window, recording the size of several recent packets and dynamically calculating the average, median, maximum, minimum, and histogram distribution of these sizes, thereby sensing real-time changes in data flow load characteristics. Extraction of protocol identifier category labels is relatively straightforward, typically achieved by parsing specific fields in the Ethernet frame header or IP header of the data packet. The capture unit maps the parsed protocol type to a predefined category label. All the captured raw data undergoes initial filtering and aggregation to reduce the amount of data transmitted to the core processing unit, and is then sent to the dynamic encryption model for further processing via the switching backplane or a dedicated management bus. The operation of the entire dynamic encryption key generation component relies on the hardware resources of the underlying switch, including application-specific integrated circuits or field-programmable gate arrays for packet capture, central processing units or graphics processing units for model calculation, and high-speed memory for storing historical model parameters and real-time data. Its software implementation typically employs a multi-threaded or event-driven architecture to ensure that tasks such as data capture, model inference, and key output can be executed concurrently to meet the real-time requirements of network data processing.
[0028] Example 2: See Figure 3The cryptographic difference analysis component receives a sequence of temporary cryptographic key values from the dynamic cryptographic key generation component and compares it with a baseline key value sequence pre-stored in a secure storage area. This baseline key value typically originates from historical key data of the system under known security conditions or an initial key issued by an authoritative institution. Its core analytical task is to quantify the deviation between the temporary key and the baseline key through a three-dimensional difference assessment: temporal consistency deviation, entropy fluctuation, and sequence pattern similarity. The final output is a structured set of key-level difference indicators. The temporal consistency deviation calculation aims to evaluate the alignment and cumulative deviation between the temporary key sequence and the baseline key sequence in the time dimension. This calculation process begins with the application of a sliding time window. The system sets a configurable-length window that slides along the time axis, moving a fixed step each time, thereby segmenting the continuous key sequence into a series of overlapping or non-overlapping segments. Within each time window, the temporary key sequence and the base key sequence need to be compared point by point. However, due to the possibility of slight asynchronous sampling issues during key generation, direct comparison will introduce errors. Therefore, a dynamic alignment algorithm is required for correction. This algorithm essentially finds the optimal correspondence path between the two sequences, compensating for the bending and stretching effects of the sequences on the time axis, thus allowing sequence points with similar shapes but phase differences to be correctly matched. After the alignment operation is completed, the system calculates the absolute difference or squared difference of each pair of matching points within the window, and accumulates and sums or calculates their average value as the cumulative deviation for that window. As the window slides continuously, a series of cumulative deviations constitute a temporal deviation vector. This vector clearly reflects the trend of key deviation evolution over time, where higher peaks usually correspond to periods when the key sequence exhibits significant anomalies.
[0029] Entropy fluctuation detection assesses the changes in randomness of a key sequence from an information theory perspective, analyzing both temporary and baseline key sequences. The first step is calculating information entropy, which measures the uncertainty or randomness of the sequence. For each analysis window in the key sequence, the system calculates its information entropy value, resulting in entropy curves for both the temporary and baseline sequences over time. The entropy ratio is calculated for comparison; it's the quotient of the temporary and baseline sequence entropy values within the same time window. A ratio close to 1 indicates comparable randomness, while a significant deviation from 1 indicates anomalies. A more advanced step in the entropy analysis phase is multi-scale entropy analysis. This method doesn't just calculate entropy on a single time scale; instead, it divides the key sequence into frequency bands, generating multiple new sequences at different scales through a coarse-grained process. Then, it calculates the entropy value at each scale, capturing the complexity features of the sequence from microscopic to macroscopic levels. Extracting the distribution characteristics within a pre-defined sensitive entropy range is a crucial step. This sensitive range is pre-defined based on in-depth research into known network attack behaviors. These attacks typically leave "fingerprints" on the key entropy values, causing them to fall within a specific range. The system focuses on data points whose entropy values for temporary and baseline sequences fall within this sensitive range and calculates their densities separately—the proportion of data points within this range to the total number of points. Based on the relative changes in these two values, the system can extract fluctuation indicators for each segment of entropy. For example, it can calculate the relative difference or ratio between the density of the temporary sequence and the density of the baseline sequence within the sensitive range. Finally, the system summarizes the entropy fluctuation indicators of all analyzed segments in chronological order, forming an entropy fluctuation vector. This vector characterizes the intensity and distribution of abnormal fluctuations in key randomness.
[0030] Sequence pattern similarity assessment focuses on identifying similarities and differences in the overall shape and structural features of key sequences. Its core lies in comparing the shape of the sequences, not just point-by-point values. The foundation of this method is matching the distance distribution between temporary values and the reference key sequence using a structural comparison algorithm. This algorithm employs distance metrics, such as dynamic time warping distance, which effectively handles the nonlinear deformation of time series on the time axis, calculating the shortest matching path and its cumulative distance between the two sequences. This distance value itself can serve as a measure of the overall difference between the sequences. Calculating the phase difference of sequence mutation points represents a deeper level of analysis. Mutation points are points in the sequence where the slope changes abruptly or the values jump, typically corresponding to network state transitions or the occurrence of anomalous events. The system uses mutation point detection algorithms to extract the sets of mutation point locations from both the temporary and reference sequences, and then attempts to match the points in the two sets. For each pair of matched mutation points, the positional difference on the time axis is calculated; this difference is the phase difference, reflecting whether similar event patterns occur earlier or later. The divergence value for quantifying pattern consistency is a process of synthesizing the above comparison results into a scalar index. The divergence value may combine the characteristics of the overall distance distribution and the statistics of the phase difference at the mutation point, thereby generating a similarity vector that reflects the degree of similarity in the shapes of the two sequences.
[0031] The generation of the key-level difference index set is the fusion and standardization stage of the three-dimensional evaluation results. It integrates the time-series deviation vector from the calculation of time-series consistency deviation, the entropy fluctuation vector from the detection of entropy fluctuation, and the similarity vector from the evaluation of sequence pattern similarity. Tensor fusion is the integration method used. This method treats the three vectors as features of different dimensions and combines them into a higher-dimensional data structure—a tensor—through tensor operations. This tensor can simultaneously retain the interaction information between the three-dimensional features. Since the three vectors of time-series deviation, entropy fluctuation, and similarity may have different dimensions and numerical ranges, direct fusion will cause the feature with the larger numerical range to dominate the entire index. Therefore, feature weighted normalization must be performed to eliminate scale differences. The normalization process usually includes two steps: first, each vector is normalized by min-max scaling or Z-score, transforming its value to the [0,1] interval or a standard distribution with a mean of 0 and a variance of 1; then, appropriate weights are assigned to each feature according to its contribution to anomaly detection in historical data or domain knowledge, and weighted processing is performed to highlight the contribution of key features. Ultimately, the system outputs a set of second-order difference indicators with dimension 1. This set is a structured data cube that can clearly show the specific values of various difference indicators at different network nodes and at different time points, providing accurate and multi-dimensional input data for the security threat location component.
[0032] Example 3: The security threat localization component is responsible for transforming the abstract indicators generated by encryption difference analysis into a spatial visualization of the specific threat locations and propagation paths in the network. The component uses a set of key-level difference indicators as its core input. This set is structured data containing multi-dimensional information such as temporal deviations, entropy fluctuations, and pattern similarities. The component maps this data onto a real network topology to simulate the potential spread of threats and ultimately generates a threat probability density map that identifies high-risk areas. Its internal operation can be divided into four closely linked stages: network topology modeling, threat propagation simulation, probability density generation, and physical area localization.
[0033] Network topology modeling is the first step in building the foundational environment for analysis. Its goal is to create a digital map that accurately reflects the actual network connectivity. The modeling process begins by dividing the network into logical regions based on network segmentation identifiers (e.g., VLAN IDs, IP subnets), and identifying all switch nodes and terminal device nodes within each region. The connections between nodes are determined by reading the switch's MAC address table, spanning tree protocol status information, or neighbor discovery data collected by network management protocols (such as SNMP). In the initial topology map, each link needs to be labeled with its link delay parameters. These parameters can be measured using active probing tools (e.g., ping, bidirectional active measurement protocols) or obtained from historical statistics in the network management system's performance database. Furthermore, modern enterprise networks typically include Virtual Private Network (VPN) access points, which introduce traffic policies and security constraints. These constraints need to be overlaid as attributes onto the corresponding nodes in the topology map. The final generated network topology model is a weighted graph data structure containing two key matrices: a delay matrix, which is a symmetric matrix and a mathematical representation used to quantify the transmission delay between network nodes. Assuming the network topology contains n nodes, the delay matrix D is an n×n square matrix, and its mathematical expression is:
[0034] Where D represents the entire delay matrix, n represents the total number of nodes in the network topology model, and the elements... This represents the communication delay between node i and node j; if there is no direct connection between the nodes, its value can be set to infinity. The node bandwidth matrix records the available bandwidth capacity of the links between each node and its neighboring nodes, providing a resource constraint basis for subsequent simulation of traffic propagation. Specifically, in the context of a threat propagation model, this refers to the delay in the transmission of threat impact from node i to node j.
[0035] The threat propagation simulation phase is a crucial step in transforming abstract difference indicators into concrete network behaviors. This phase maps the values in the key-level difference indicator set to the corresponding nodes in the network topology model. Each node's difference indicator value is initialized as its "threat strength" or "anomaly degree." Simulation execution relies on a high-performance graph computing engine capable of iterative computation on large-scale topology graphs. The threat propagation inference computation process involves multiple physical mechanisms. First, a threat traffic attenuation factor is calculated based on inter-node latency parameters. This factor simulates the phenomenon that threat intensity weakens with increasing distance as it spreads in the network; a node receiving a threat from a neighboring node experiences attenuation as link latency increases according to a certain pattern. A core computational step is capturing cross-regional threat association features through a multi-head attention mechanism. This mechanism is integrated into a graph neural network, allowing each node to simultaneously monitor the threat strength information of multiple neighboring nodes and assign different attention weights when updating its own state, thereby learning complex threat association patterns that span different network regions. Using a random walk method to simulate the diffusion path of threat traffic in the topology network is a means of achieving path tracing. This process starts with nodes that have been mapped with high difference index values, releasing a large number of virtual "threat particles". Each particle walks randomly in the topology graph according to a preset transition probability (e.g., it tends to propagate to links with low latency and high bandwidth), and each walk path is recorded.
[0036] The probability density generation phase involves statistical analysis of numerous random walk simulation results, aiming to transform discrete path information into continuous threat distribution probabilities. The system counts the frequency with which each network link is traversed across all simulated propagation paths; a higher frequency indicates a greater likelihood of threat propagation through that link. Then, it calculates the dwell probability of threat traffic on that link by combining the link's latency parameter. A fundamental consideration is that links with higher latency may cause threat traffic to remain on the link for a longer period, thus increasing the risk exposure probability of that link. Dwell Probability The calculation can be synthesized based on the following relations:
[0037] in: This represents the probability of a threat residing on links i and j. This represents the frequency with which the link is traversed in the random walk simulation. This is the delay parameter of the link, and the function f is a monotonically increasing function of delay, used to characterize the enhancing effect of delay on the dwell probability. This is achieved by calculating the delay parameter of all links in the network. The system can generate a threat probability density map covering the entire network. This map is typically overlaid on the topology map in the form of a heatmap, with color intensity indicating probability levels. The system sets a preset threat residency probability threshold and marks all links with probability values exceeding this threshold, forming a set of suspicious links. These links are potential risk channels that require close monitoring.
[0038] Physical area localization is the final step in transforming the probability map into security decisions. This step performs spatial clustering analysis on the generated threat probability density map, using clustering algorithms such as DBSCAN or K-means to group links and nodes with high probability values in the topology map, identifying clusters of threat probabilities. The DBSCAN algorithm is particularly suitable for this scenario because it can discover clusters of arbitrary shapes and filter out low-probability areas as noise points. Based on network segment identifiers and switch node connections, the system delineates the boundaries of the identified threat clusters. For example, if a threat cluster is entirely within a VLAN or IP subnet, the boundary of that subnet is defined as the abnormal network physical boundary. If the threat spans multiple segments, it may be necessary to determine a minimum physical area containing all affected segments, such as a cabinet or wiring closet, based on the actual physical connection locations of the switch ports. Ultimately, the output of the security threat localization component is a report that clearly defines the geographical location and boundaries of the abnormal area, while also including the set of suspicious links and the main trends in threat propagation, providing direct spatial basis for the accurate response of the adaptive encryption strategy component.
[0039] Example 4: The generation process of suspicious node identifiers begins by parsing the set of suspicious links marked on the threat probability density map. Each link marked as suspicious connects two network nodes. The system traverses this set of suspicious links, extracting the end nodes associated with all links in the set, forming a preliminary list of suspicious nodes. However, this preliminary list may contain duplicate nodes because a node may connect to multiple suspicious links, so deduplication is required. The next crucial step is to bind these network node identifiers to the physical ports of the actual switches. This binding operation is achieved by querying the MAC address table, Address Resolution Protocol (ARP) cache, or Simple Network Management Protocol (SMMP) management information base of the switch. For example, if the IP address of a suspicious node is 192.168.1.105, the system will query the core switch to determine the specific physical port corresponding to the MAC address of that IP address, such as the GigabitEthernet1 / 0 / 24 port of the core switch Cisco_Switch_01. After the binding is completed, the final set of suspicious node identifiers is formed. This set is usually organized in tabular form. Each entry not only contains the logical identifier of the node (such as IP address, device hostname), but also clearly marks its corresponding physical location information (such as switch name, port number, rack number), and includes a threat probability value inherited from the threat probability density map. This set directly indicates the potential threat source or the terminal device that has already been affected. For a more intuitive demonstration, let's assume a suspicious node identifier set generated after a certain analysis, as shown in Table 1.
[0040] Table 1: Set of Suspicious Node Identifiers
[0041] The construction of the main threat propagation path relies on a large amount of simulated path data generated by the random walk method used in the threat propagation simulation phase. The random walk simulation releases a large number of virtual particles from initial high-threat-probability nodes, each particle moving through the network topology according to certain transition probability rules. The system completely records all node paths traversed by each virtual particle in each round of propagation and their strict sequence. This path data is temporarily stored in an in-memory database or cache. Path records typically use data structures such as stacks or linked lists to ensure the order of node sequences is maintained. For example, a path might be recorded as: [Source_IP: 192.168.1.220]->[Switch_IP: 172.16.1.1]->[Server_IP: 10.10.10.5]. After all simulation rounds are completed, the system counts the frequency of all recorded paths. This counting process is implemented using a hash table to improve efficiency. The key of the hash table is the string representation of the path (e.g., a string formed by connecting node IPs with arrows), and the value is the number of times that path appears. The system iterates through all paths, accumulating the frequency of each unique path. Finally, the algorithm selects the path sequence with the highest cumulative frequency, identifying it as the main threat propagation path in this simulation. This path represents the most likely spread route of the threat under the current network environment and key difference indicators. The output threat propagation main path is a structured, ordered list of nodes. Each element in the list contains not only the node's identifier (usually an IP address) but also timestamp information, indicating the relative or absolute time when the threat arrived at that node. For example, a single output main path might look like this: [{node: 192.168.1.220, timestamp: T0}, {node: 172.16.1.1, timestamp: T0+ΔT1}, {node: 10.10.10.5, timestamp: T0+ΔT1+ΔT2}]. This ordered list clearly shows the path of the threat's gradual spread from the originating node to critical assets, providing direct decision-making basis for blocking threat propagation.
[0042] The combination of suspicious node identifiers and the main threat propagation path constitutes the core content output by the security threat localization component. These elements transform the abstract threat probability field into concrete network entities and action routes. Upon receiving this information, the network security management platform can immediately highlight suspicious node icons on the high-frequency network topology map and mark the main threat propagation path with a prominent directed line. Administrators can quickly locate the physical location (e.g., port 24 of Cisco_Switch_01 in rack 03 of area A in the data center) and perform operations such as traffic mirroring, tightening access control list policies, or temporary isolation of that port. Simultaneously, by analyzing the main threat propagation path, administrators can predict the threat's next target, thereby proactively deploying enhanced protection measures on key nodes ahead of the path (such as core servers).
[0043] Example 5: When the system detects that the threat probability value of a specific area in the threat probability density map (e.g., corresponding to an IP subnet or a group of ports served by a specific switch) is consistently higher than a preset threshold, it automatically sends an encryption mode switching command to the network switch managing that area. This command is typically transmitted via modern network management protocols such as NETCONF or RESTCONF. The command payload contains specific configuration parameters, and the execution process involves increasing the encryption algorithm strength of the affected link or port to several times its original strength. For example, if the basic encryption configuration uses a 128-bit AES algorithm, it may switch to 256-bit AES or enable an elliptic curve-based encryption suite. Simultaneously, the system enables a real-time key sequence tracking mode on the relevant switch. This mode is achieved by deploying a lightweight monitoring agent in kernel space or on a dedicated security chip. This agent continuously captures and records every key fragment or key update event generated by the key generator, and records these events along with a system clock stamp in a protected circular buffer. To capture transient anomalies, transient event detectors are deployed at the network edge (such as access switches or protected server network cards). These detectors are equipped with rule-based engines that can identify anomalous segments in the key sequence that do not conform to expected patterns, such as key duplication, excessively short key cycles, or the detection of calls from unknown cryptographic libraries. Once an anomaly is identified, the detector immediately captures a segment of the key sequence before and after that point in time, along with relevant contextual information, and generates a timestamped log event, which is then sent to the security information and event management system for further in-depth analysis.
[0044] Key refresh is another proactive defense mechanism of this component, targeting neighboring network nodes whose threat probability gradients show the most significant changes in the threat probability density map. The threat probability gradient characterizes the drastic change in threat probability within the topology space; high gradient regions typically indicate rapid threat spread or convergence, thus becoming key areas for key refresh. The system applies a complex operation called multi-mode key refresh to these target nodes, designed to verify the integrity of the key distribution path and reset potentially compromised keys. The multi-mode key refresh process begins by injecting a series of multi-band test signals into the target node and surrounding links via a controllable key generator. These test signals are not real production data, but rather predefined key challenge values or pseudo-random sequences with specific patterns, transmitted on different logical channels or frequency bands to simulate various network loads and interaction patterns. Simultaneously with the injection of test signals, the system calculates a theoretical response key spectrum based on the existing network topology model and delay matrix. This theoretical spectrum predicts the standard key response sequence that each node should return upon receiving the test signal under ideal, interference-free conditions.
[0045] The system records the actual responses of each network node in real time after the test signal is injected, forming a measured response key spectrum. Recording is performed by probes deployed at key nodes or mirror ports of switches, ensuring the capture of raw, unprocessed response data. Then, the core algorithm calculates the difference distance between the theoretical and measured response key spectra. This distance calculation may employ a combination of metrics, such as comparing the Hamming distance between two response sequences to measure bit differences, or calculating the root mean square error of their corresponding values to assess overall deviation. A crucial judgment step is comparing the difference distance between the measured and theoretical key spectra and calculating the percentage of anomalous node offset for each node. This percentage is typically expressed as the ratio of the measured difference distance to an acceptable baseline difference distance. The system internally sets a second threshold; when the percentage of anomalous node offset for a node consistently exceeds this second threshold, the node is marked as a key anomalous associated node. The marking operation triggers a series of subsequent actions. For example, it may immediately initiate a forced key update for the node, resetting its key synchronization state with other nodes in the network; or, if the abnormal indicators are extremely high, the system may suggest that the network management system isolate the node's port and generate a high-priority alarm to notify the security administrator for manual intervention. The operation of the entire adaptive encryption strategy component embodies a closed-loop control logic. It senses threats in the network, locates risks through algorithmic analysis, and ultimately dynamically improves the local defense strength of the network by adjusting the basic parameters of encrypted communication, thus forming a continuously evolving, dynamic security protection system that adapts to changes in the threat environment.
[0046] It should be noted that, in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus.
[0047] Although embodiments of the invention have been shown and described, it will be understood by those skilled in the art that various changes, modifications, substitutions and alterations can be made to these embodiments without departing from the principles and spirit of the invention, the scope of which is defined by the appended claims and their equivalents.
Claims
1. A network switch hardware security protection system based on dynamic encryption, characterized in that, include: Dynamic encryption key generation component: Based on the historical traffic patterns and real-time data packet characteristics of the network switch, a dynamic encryption model is constructed. The transmission time interval, load capacity and protocol identifier of the current data packet are captured in real time, and a temporary encryption key value is output through the dynamic encryption model. Encryption Difference Analysis Component: Performs a three-dimensional difference assessment on the temporary encryption key value and the pre-stored baseline key value. The three-dimensional difference assessment includes temporal consistency deviation, entropy fluctuation, and sequence pattern similarity, generating a set of key-level difference indicators. Security threat location component: Input the key-level difference index set into the network topology mapping system, combine it with switch port configuration parameters and network segmentation identifiers to generate a threat probability density map of the security threat propagation path and locate abnormal network physical areas; Adaptive encryption strategy component: Configures encryption strategy parameters based on the threat probability density map, including enabling multi-layer encryption protocols for high-probability threat areas and performing key refresh operations on neighboring network nodes.
2. The network switch hardware security protection system based on dynamic encryption according to claim 1, characterized in that, The dynamic encryption key generation component specifically includes: Historical traffic pattern analysis: Multi-dimensional analysis and processing of historical traffic data from network switches, including using adaptive window function decomposition to extract packet size distribution characteristics, establishing a correspondence matrix between protocol type and transmission rate through protocol correlation analysis, and using dynamic warping algorithm to align transmission time interval patterns under different network conditions. Dynamic encryption model construction: The processed historical traffic data is input into the hybrid key generation network, which includes a recursive prediction unit based on the traffic trend curve to generate the basic key prediction value, a fully connected network with an embedded entropy adjustment mechanism to correct the prediction deviation caused by protocol changes, and a feature compensator to dynamically adjust the generation weights according to the characteristics of the real-time captured data packets. The heterogeneous data capture unit deployed at the edge synchronously acquires jitter parameters of transmission time intervals, distribution statistics of load capacity, and category labels of protocol identifiers.
3. The network switch hardware security protection system based on dynamic encryption according to claim 2, characterized in that, The calculation of the temporary encryption key value includes the following steps: Adaptive smoothing based on network traffic status eliminates measurement errors caused by background noise; The correlation characteristics of transmission time interval, load capacity and protocol identifier are fused by a spatiotemporal feature integration algorithm; The output includes a temporary encryption key value within the normal fluctuation range, which is dynamically updated according to the network load status.
4. A network switch hardware security protection system based on dynamic encryption according to claim 1, characterized in that, The encrypted difference analysis component specifically includes: Timing consistency deviation calculation: The temporary encryption key value is compared with the base key value point by point using a sliding time window. A dynamic alignment algorithm is used to correct the asynchronously sampled key sequence. The cumulative deviation within each window is calculated to generate a timing deviation vector. Entropy fluctuation detection: Calculate the information entropy of the key sequence of temporary value and base value, calculate the entropy ratio, extract the fluctuation index of each sequence segment, and construct the entropy fluctuation vector; Sequence pattern similarity assessment: Based on the structural comparison algorithm, the distance distribution between the temporary value and the reference key sequence is matched, the phase difference of the sequence mutation point is calculated, the divergence value of the pattern consistency is quantized, and a similarity vector is generated; Key-level difference index set generation: The temporal deviation vector, entropy fluctuation vector, and similarity vector are fused by tensor, and scale differences are eliminated through feature weighted normalization. The output is a second-order difference index set with the network node timestamp difference type as the dimension.
5. A network switch hardware security protection system based on dynamic encryption according to claim 4, characterized in that, The entropy fluctuation detection specifically includes: In the entropy analysis phase, the corresponding entropy components in the temporary and base key sequences are first extracted. Multi-scale entropy analysis is used to divide the frequency band of each group of entropy signals and extract the distribution characteristics within the preset sensitive entropy interval. The sensitive entropy interval is selected to cover the entropy range of typical network attacks. After extraction, the entropy density of the temporary and base data within the sensitive entropy interval is quantified and calculated. Based on the relative change of the two, the fluctuation index of each segment of entropy is extracted. The entropy fluctuation results of all segments are summarized to construct the entropy fluctuation vector.
6. A network switch hardware security protection system based on dynamic encryption according to claim 4, characterized in that, In the sequence pattern similarity assessment, the structural comparison algorithm uses a distance metric algorithm to match the locations of mutation points in the two sequences and identify phase differences.
7. A network switch hardware security protection system based on dynamic encryption according to claim 1, characterized in that, The security threat location component specifically includes: Network topology modeling: Construct a topology diagram of the connection relationship between switch nodes based on the network segmentation identifier, label the link delay parameters between each node, overlay the traffic constraints of the virtual private network access point on the topology diagram, and generate a networked topology model including the delay matrix and the node bandwidth matrix. Threat propagation simulation: The key-level difference index set is mapped to the corresponding nodes in the network topology model; threat propagation simulation is performed based on the graph computing engine. The calculation of threat propagation simulation includes calculating the attenuation factor of threat traffic based on node delay parameters, capturing cross-regional threat association characteristics through a multi-head attention mechanism, and simulating the diffusion path of threat traffic in the topology network using a random walk method. Probability density generation: Statistically analyze the frequency of threat traffic occurrence on each link during simulated propagation, calculate the threat traffic retention probability value by combining link delay parameters, generate a threat probability density map covering the entire network, and mark the set of suspicious links whose probability values exceed the preset threat retention probability threshold; Physical region location: Perform spatial clustering analysis on the threat probability density map to identify threat probability clusters; delineate the physical boundaries of abnormal networks based on network segment identifiers and switch node connections.
8. A network switch hardware security protection system based on dynamic encryption according to claim 7, characterized in that, The security threat localization component also includes outputs including suspicious node identifiers and threat propagation main paths. The suspicious node identifiers are based on network nodes connected by a set of suspicious links. The network nodes are bound to actual switch ports to form a set of suspicious node identifiers, indicating potential threat sources or affected terminals. The threat propagation main path is obtained by recording the node paths and their order in each round of propagation during the threat diffusion process simulated by random walks. Among all simulated paths, the frequency of occurrence of each path is counted, and the path sequence with the highest cumulative frequency is selected as the threat propagation main path. The output threat propagation main path sequence is a structured and ordered list of nodes.
9. A network switch hardware security protection system based on dynamic encryption according to claim 1, characterized in that, The adaptive encryption strategy component specifically includes: When the threat probability value of a certain area in the threat probability density map exceeds the preset threat residence probability threshold, an encryption mode switching command is sent to the switch to which the area belongs, and the encryption algorithm strength is increased to several times the original strength. At the same time, the key sequence real-time tracking mode is enabled to capture key change events, and a temporary event detector is deployed on the edge side to record abnormal key fragments. Key refresh operation execution: Apply multi-mode key refresh to the nearest network node with the largest change in threat probability gradient in the threat probability density map.
10. A network switch hardware security protection system based on dynamic encryption according to claim 9, characterized in that, The multi-mode key refresh includes injecting multi-band test signals through a controllable key generator, calculating the theoretical response key spectrum based on a networked topology model and delay matrix, recording the response of each node after the test signal injection to obtain the measured response key spectrum, calculating the difference distance between the theoretical response key spectrum and the measured response key spectrum, comparing the difference distance between the measured key spectrum and the theoretical key spectrum, calculating the percentage of abnormal node offset, and marking abnormal node offset nodes as key abnormal associated nodes when the percentage of abnormal node offset exceeds a second threshold.