A network access processing method, wireless broadband terminal and system

By employing multi-dimensional perception, intent parsing, and dynamic policy adjustment, the system addresses the issues of low operational efficiency and lagging security protection in static network access control, achieving intelligent and adaptive network access management and improving network resource utilization and security.

CN121985396BActive Publication Date: 2026-08-25SHENZHEN XINSIDA ELECTRONIC TECH CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202610132027.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-01-30
Publication Date
2026-08-25
Estimated Expiration
2046-01-30

AI Technical Summary

Technical Problem

Existing network access control methods rely on static policy management, resulting in a large workload for operation and maintenance, lagging security protection, low resource utilization, and an inability to adapt to changes in device traffic and fluctuations in service priorities.

Method used

By employing multi-dimensional perception and information collection, intent parsing and policy binding, security assessment and policy correction, and traffic self-learning and elastic scheduling, an intelligent closed loop of perception-parsing-execution-optimization is constructed to achieve dynamic and adaptive network access control.

Benefits of technology

It enhances the automation level of network management, the initiative of security defense, and the flexibility of resource allocation, improves operation and maintenance efficiency and resource utilization, and enables rapid detection and automatic containment of internal threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121985396B_ABST
    Figure CN121985396B_ABST
Patent Text Reader

Abstract

The application discloses a network access processing method, wireless broadband terminal and system, and particularly relates to the technical field of network access, which comprises the following steps: a multi-dimensional perception and information collection step, which collects multi-dimensional context information of equipment and reports the information; an intention analysis and policy binding step, which infers the business intention of the equipment based on the information and automatically generates and issues a fine-grained network policy; a security evaluation and policy correction step, which continuously monitors the security state of the equipment and automatically triggers policy correction according to dynamic scoring; a traffic self-learning and elastic scheduling step, which analyzes and predicts the traffic mode of the equipment and dynamically adjusts the network bandwidth resource quota thereof; and a session termination and resource cleaning step, which automatically cleans relevant policies and recycles resources after the equipment is offline. The application realizes a fundamental change from static configuration to dynamic scheduling based on intention and context by constructing an intelligent closed loop, and significantly improves the automation, security and resource utilization efficiency of network access.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network access technology, and more specifically, to a network access processing method, a wireless broadband terminal, and a system. Background Technology

[0002] With the rapid development of the Internet of Things (IoT), BYOD (By-Oriented Development), and the Industrial Internet, the types and numbers of devices connected to networks are becoming increasingly diverse, ranging from traditional personal computers and servers to various sensors, cameras, smart terminals, and specialized industrial equipment. This has transformed the network environment of enterprises and operators from a relatively closed and homogeneous system to a highly open and heterogeneous complex system. Against this backdrop, achieving efficient, secure, and intelligent network access control has become a key challenge in ensuring smooth business operations and effective utilization of network resources.

[0003] Currently, mainstream network access control methods primarily rely on identity-based static policy management. Typical techniques include IEEE 802.1X-based authentication, MAC address-based access control lists (ACLs) binding, and assigning fixed virtual local area networks (VLANs) and bandwidth quotas to devices after successful authentication. These traditional methods have gradually revealed significant shortcomings in practical applications: First, policy configuration heavily relies on manual operation by network administrators, requiring detailed network policies (such as VLANs, ACLs, and QoS) to be pre-defined for each device type or role. Faced with a massive and diverse number of access devices, this model leads to a heavy workload, low efficiency, and is prone to security vulnerabilities or network failures due to configuration errors. Second, policies are fixed once issued, lacking dynamic adjustment capabilities. They cannot perceive real-time security status changes after device access (e.g., whether the device is infected with malware or has unpatched high-risk vulnerabilities), nor can they understand the device's true business intent and behavioral patterns, resulting in lagging security protection and an inability to flexibly allocate resources based on business priorities. Finally, static resource allocation methods (such as fixed bandwidth) cannot adapt to the tidal changes in device traffic and fluctuations in service priorities, which can easily lead to network resources being congested during peak hours and idle during off-peak hours, resulting in low overall utilization.

[0004] Therefore, existing technologies urgently need a network access processing method that can overcome the limitations of static configuration and achieve intelligent perception, dynamic strategy generation, and adaptive adjustment. Summary of the Invention

[0005] To overcome the above-mentioned deficiencies of the prior art, embodiments of the present invention provide a network access processing method, a wireless broadband terminal, and a system.

[0006] To achieve the above objectives, the present invention provides the following technical solution: A network access processing method includes the following steps: Multi-dimensional perception and information collection: When a device initiates a network access request, the network access control point collects the device's traditional authentication information as well as multi-dimensional context information such as device type, claimed access purpose, device basic status, access time and location, and sends the information to the central policy controller. Intent parsing and policy binding: The central policy controller infers the service intent of the device based on the received multi-dimensional context information, and based on the inferred service intent, matches and generates the corresponding fine-grained network policy from the preset policy template library, binds the network policy with the device's unique identifier, and sends it to the policy execution point in the network. Security assessment and policy correction: After a device is connected to the network, its security status is continuously monitored and a dynamic security health score is generated. When the security health score is lower than a preset threshold, the policy correction process is automatically triggered to generate and issue a corrected network policy to adjust the network access permissions of the device. Traffic self-learning and elastic scheduling: Analyze the historical service traffic generated by the device to build a resource profile; based on the resource profile and the prediction of the device's future traffic, dynamically adjust the network bandwidth resource quota allocated to the device; Session termination and resource cleanup steps: When a device is detected to be offline, the central policy controller is notified, and the controller instructs the relevant network nodes to clean up all dynamic policies issued to the device and reclaim the network resources they occupy.

[0007] Specifically, in the multidimensional perception and information acquisition step, acquiring and sending multidimensional context information specifically includes: By using a pre-installed data acquisition agent on the managed device, local information is automatically collected and structured information objects are generated in accordance with a unified data model; For devices that cannot install an agent, the access control point indirectly obtains the device type information by sending LLDP extended messages or custom probe messages and analyzing their responses. The access control point sends the encapsulated authentication information and multidimensional context information data packet to the northbound RESTful API interface of the central policy controller through a TLS-based secure channel.

[0008] Specifically, the intent parsing and policy binding also includes an online feedback optimization process, which specifically includes: After the device is connected and communication begins, its actual business mode vector Q is extracted through traffic analysis; The matching degree R between the initial inferred intent description P of the computing device and the actual business pattern vector Q is determined based on the size of the intersection of the key feature sets extracted from P and Q, and the consistency indicator function between the traffic destination and the intent claim target. Based on the matching degree R, a dynamic decay update algorithm with a forgetting factor is used to update the confidence degree C of the device's intent resolution. When the confidence level C remains below the confidence threshold within a preset observation time window W, an optimization learning process is triggered. The process includes: correcting the intent mapping rule base, or adding the context information X that generates low-confidence inferences and the actual business model as new sample pairs to the incremental learning queue of the machine learning model for training.

[0009] Specifically, in the security assessment and strategy correction steps, generating a dynamic security health score involves the following steps: Maintain an initial score S for each device and subscribe to a real-time event stream from the security information and event management system; When a security incident occurs, the score S is deducted based on the predefined event weight and event severity coefficient to obtain the updated security health score S(t). Security incidents include at least the detection of unauthorized processes, the existence of known high-risk vulnerabilities, and the occurrence of abnormal external connections; S(t) is updated periodically.

[0010] Specifically, the traffic self-learning and elastic scheduling steps, which involve dynamically adjusting based on predictions of future traffic, include: Maintain a traffic prediction model for a device or group of devices. The model uses the historical traffic pattern fingerprint time series of the device as the training set. The fingerprint includes bandwidth value, application type distribution vector and traffic entropy feature. In each scheduling decision cycle, the latest L time window traffic pattern fingerprints of the device are input into the model to obtain the predicted traffic trajectory Ť for the next K windows and its confidence score. Active preheating mode: When the predicted trajectory shows that the device has a confidence level greater than the preset standard to enter the critical business state within the next m windows, and the overall network utilization is lower than the safety threshold, a pre-upgrade decision is triggered, and the enhanced bandwidth quota is dynamically calculated and allocated in advance based on the predicted bandwidth peak. Predictive load balancing mode: When the predicted trajectory shows that a device will enter a long period of business silence and the confidence level meets the standard, a more persistent resource reclamation strategy is triggered to perform predictive global load balancing across devices.

[0011] Specifically, the traffic prediction model supports online learning and calibration; After each prediction period ends, the model predictions are compared with the actual observations. If the prediction deviation continues to exceed the tolerance range, the corresponding historical sequence and actual value data pairs are added to the circular buffer. The model periodically samples data from the circular buffer for incremental training to adapt to gradual or abrupt changes in device traffic patterns.

[0012] Specifically, the session termination and resource cleanup steps include the following atomic operations: Query the device-policy mapping table to obtain a list of globally unique identifiers for all policies issued to offline devices; Send a batch policy deletion command to all relevant network devices that are on record. The command is an OpenFlow Flow-Mod message, the command is DELETE, and the matching field is the MAC address of the device. Send a DHCP-Release request to the IP address management system to release the IP address lease assigned to the device.

[0013] A network access processing wireless broadband terminal, comprising: Context-aware agent is used to collect the device attributes and declared business intent of the terminal, and format them into a standard data model for reporting to the network control plane; The policy execution adapter is used to receive and parse network policy instructions based on business intent issued by the network controller, convert them into configurations that can be recognized by the terminal, and drive the execution of its network protocol stack. The state coordination unit is used to provide the necessary terminal runtime data interface to the network-side security and performance monitoring components, and to allow the network side to perform in-depth inspection of its network traffic; The connection lifecycle manager manages the entire process of a terminal from network access authentication and session persistence to offline disconnection, and coordinates resource cleanup and state synchronization when offline.

[0014] A network access processing system includes the following modules: The multi-dimensional information perception and acquisition module is deployed at the network access control point to collect and upload the device's identity authentication information and multi-dimensional context information when the device is connected. The intelligent intent parsing and policy generation module is deployed in the central policy controller. It is used to infer the device's service intent based on the received information and automatically generate and bind fine-grained device-specific network policies based on the intent. The dynamic monitoring and adaptive optimization module is used to continuously assess the security status of the device while it is online to trigger policy correction, and dynamically schedule its network bandwidth resources based on its traffic pattern self-learning and prediction results. The policy lifecycle management module is used to monitor device offline events and automatically trigger the cleanup of related policies and the global reclamation of network resources for the device.

[0015] The technical effects and advantages of this invention are as follows: This invention effectively overcomes the inherent defects of traditional static access control models by constructing an intelligent closed loop of perception-analysis-execution-optimization. It upgrades network access control from identity-based, one-off, and fixed policy allocation to context- and intent-based, lifecycle-driven, and dynamically adaptive refined intelligent governance. This fundamentally improves the automation level of network management, the proactiveness and real-time nature of security defense, and the flexibility and utilization of resource allocation.

[0016] The beneficial effects of this invention are mainly reflected in the following four aspects: First, it significantly improves operational efficiency and reliability by automatically generating and binding fine-grained policies through multi-dimensional perception and intent parsing, avoiding tedious and error-prone manual configuration. Second, a continuous and proactive security defense system has been built, which enables rapid detection and automatic containment of internal threats through real-time security assessment and dynamic policy correction. Third, it enables refined and elastic scheduling of network resources. Based on traffic self-learning and prediction mechanisms, it enables resources such as bandwidth to be dynamically adjusted according to actual business needs, ensuring the experience of critical services while improving the overall efficiency of the resource pool. Fourth, it endows the system with the ability to evolve and optimize itself. By introducing mechanisms such as intention feedback learning and online calibration of predictive models, the system can continuously improve as the network environment and business models change, and its intelligence level is constantly improved. Attached Figure Description

[0017] Figure 1 This is a flowchart of the method of the present invention. Detailed Implementation

[0018] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0019] like Figure 1 As shown, the steps of a network access processing method are as follows: Step 1: Multidimensional Perception and Information Acquisition When a new device attempts to access the network, it initiates a connection request to the network access control point (such as a switch or wireless controller). The access control point not only collects the device's traditional authentication information (such as MAC address and 802.1X certificate), but also gathers multi-dimensional contextual information about the device through proxies or probes, including: Device type (such as sensor, camera, industrial computer), claimed purpose of access (obtained through device reporting or pre-registration information), basic device status (such as operating system version, list of installed patches), current time, physical access port location, etc.

[0020] The specific implementation method is as follows: Data Collection Agent: A lightweight data collection agent is pre-installed on the managed device. Upon device startup, the agent automatically collects local information and generates a structured information object following a unified data model (such as one based on the YANG model definition). For example, it generates a JSON-formatted data packet. Network probes: For devices that cannot install agents (such as simple IoT sensors), access control points indirectly obtain basic information such as device type by sending probe messages of specific protocols (such as LLDP extended messages or custom UDP discovery packets) and analyzing their responses, or by cooperating with the gateways they are connected to.

[0021] Information Upload: The access control point sends the encapsulated device authentication information and multidimensional context information data packet to the northbound RESTful API interface of the central policy controller (e.g., POST / api / v1 / device context) through a secure channel (such as the NETCONF protocol based on TLS).

[0022] This information will be encapsulated and sent to the central policy controller.

[0023] Step 2: Intent parsing and policy binding: After receiving the information, the central policy controller performs the following steps: First, the claimed access purpose of the device is correlated with the device type, access location, time, etc., to infer its true business intent (e.g., "The temperature sensor in the east area of ​​the building intends to upload data to cloud platform A").

[0024] Then, based on the parsed intent, the policy matching engine automatically generates an initial, fine-grained network policy by combining it with a pre-set policy template library (such as "IoT sensor template" and "visitor terminal template").

[0025] The specific implementation method is as follows: Intent parsing module: Embeds a parser based on a rule engine (such as Drools) or a lightweight machine learning model (such as a text classifier). The parser loads a set of predefined intent mapping rules.

[0026] Through reasoning via rule chains, a structured intent object is ultimately output.

[0027] An online feedback-based parsing optimization mechanism is introduced to construct a closed-loop learning process that feeds back the policy execution results to the intent inference model. The specific optimization process is as follows: Intent-Traffic Matching Observation: After the device connects and begins communication, the traffic analyzer (see step four) performs in-depth analysis of the actual network traffic generated by the device to extract its actual business mode vector Q. Vector Q includes, but is not limited to: the main communication destination IP set, port protocol combination, traffic cycle characteristics, etc. At the same time, the initial inferred intent description P of the device (e.g., "Upload data to cloud platform A") is obtained from the output of the intent parsing module. Calculate the matching score and update the confidence score: Define a matching score function R to quantify the consistency between the inferred intent P and the actual business model Q. For example, a calculation method based on feature overlap can be used: ; in, This is a matching degree function used to quantify the consistency between the inferred intent P and the actual business model Q. and These represent the sets of key features (such as target server domain name and protocol type) extracted from intent P and traffic pattern Q, respectively. Represents a set and Size of the intersection and Weighting coefficients ( + = 1). It is an indicator function based on whether the traffic destination matches the claimed intent target (1 if they match, 0 otherwise). An intent resolution confidence score C is maintained for each device, and this confidence score is dynamically decayed and updated based on the matching degree R. ; in, The updated intent parsing confidence score. The confidence level for intent parsing before the update. Forgetting factor (0 < < 1), used to balance the impact of historical confidence levels with the latest observations; Triggering optimization learning: Continuously monitor the confidence level C. When the confidence level C of a certain device or a class of devices (with similar multidimensional contextual information) remains below the confidence threshold within a preset observation window W... (For example When the value is 0.7, the optimization learning process is triggered: For rule-based parsers: A "low confidence alert" log is automatically generated, prompting the administrator to check the mapping relationship between the context information of the device (or this type of device) and the initial inferred intent P. The administrator can then modify or supplement the intent mapping rule base accordingly.

[0028] For parsers based on machine learning models: The contextual information that led to the low-confidence inference will be used. The observed business model Q is used as a new training sample. This is added to the model's incremental learning queue. The model is periodically fine-tuned using new samples, so that subsequent samples have similar learning outcomes. The intention inference of the new equipment is more inclined to produce and The intention .

[0029] Closed-loop effectiveness: Through the above process, the intent resolution module can continuously learn from the actual operating state of the network, constantly narrowing the gap between "inferred intent" and "actual behavior." This enables the system not only to achieve automated initial policy binding, but also to become more accurate over long-term operation, dynamically adapting to new business scenarios and device behavior patterns, thus realizing the self-evolution of the intelligence level of network access policies.

[0030] Strategy Template Library: A collection of strategy templates stored in a database. Each template is a JSON or YAML file that defines the variables of the strategy elements.

[0031] Policy generation and binding: The policy matching engine replaces variables in the intent object (such as TARGET PLATFORM IP) with real values ​​retrieved from the network resource database (such as 10.10.10.100). Then, it generates a specific device-specific policy configuration instruction set and simultaneously distributes it to the device's access switch and network core router / firewall via a southbound interface protocol (such as OpenFlow or P4Runtime). Policies are bound using the device ID (MAC address) as a unique matching key.

[0032] This policy not only includes traditional VLANs and ACLs, but also an initial bandwidth limit, a list of allowed server addresses, and necessary traffic coloring tags. This policy is automatically bound to the device's unique identifier (such as a MAC address) and distributed to access control points and relevant policy enforcement points in the network (such as firewalls and gateways).

[0033] Step 3: Security Assessment and Strategy Adjustment After the device successfully connects to the network, it enters the monitoring phase: Network security status assessment services continuously evaluate online devices either periodically or through event-triggered mechanisms. The assessment content is based on data obtained from endpoint detection and response systems and vulnerability scanners, including: The assessment includes checking for unauthorized processes running on the device, the presence of known high-risk vulnerabilities, and abnormal CPU / memory usage. The results form a dynamic security health score; the specific process is as follows: Data Acquisition and Scoring: The security assessment service subscribes to real-time event streams from the security information and event management system. A dynamic score S (initial value 100) is maintained for each device. The scoring algorithm calculates in real time based on a predefined threat weight table. ; in, Rate the safety and health status at the current moment. The safety and health score for the previous moment. Weights are assigned to different security events (such as unauthorized processes, high-risk vulnerabilities, and abnormal external links). For example, unauthorized processes have a weight of -15, high-risk vulnerabilities have a weight of -25, and abnormal external links have a weight of -30. This is a severity rating for security incidents, set according to different incident types and actual circumstances; the rating is updated every minute. Correction strategy and triggering: Two preset thresholds: warning threshold ( =70) and isolation threshold ( =50); The strategy correction module listens for score update events: when Trigger "Restriction" remediation. Select a "Restrict Access" template from the remediation policy library (e.g., allow access only to the patch server and DNS), generate a new policy, and issue the new ACL to the firewall through the controller to replace the original policy; when Trigger "Isolation" correction. The module immediately generates a highest-priority flow table entry, sends it to the access switch, redirects all traffic from that device to a dedicated isolation VLAN (such as VLAN 999), and notifies the administrator; Real-time delivery: All corrective policies are delivered via a message queue (such as Kafka) that publishes a "policy update" event. Policy enforcement points in the network (such as SDN switches and next-generation firewalls) subscribe to this topic and, upon receiving instructions relevant to themselves, complete the policy update or insertion within seconds.

[0034] The policy correction module monitors this score in real time. When the score falls below a preset security threshold (for example, when a device is detected to be infected with a virus), the policy correction process is immediately triggered. This process automatically downgrades or isolates the access permissions in the device's initial policy based on the severity of the security incident (for example, correcting it from "access to the production database" to "access to the security patch server only"), and distributes the corrected policy in real time to achieve rapid containment of threats.

[0035] Step 4: Traffic Self-Learning and Elastic Scheduling During normal device communication, the following steps are performed: The network traffic analyzer continuously learns and analyzes the service traffic patterns generated by the device, identifying peak service periods, periodicity, and critical service flows (such as real-time video surveillance streams) versus non-critical service flows (such as firmware downloads). Based on the learned patterns, the resource scheduling engine builds a "resource profile" for the device; specifically, this is implemented as follows: Traffic Feature Learning: A traffic analyzer deployed on the core gateway (e.g., developed based on DPDK) performs deep packet inspection (DPI) and metadata extraction on device traffic. It records the following features in 5-minute intervals and forms a time series: Traffic quintuples (source / destination IP, port, protocol); average / peak bandwidth; application type (identified by signature, such as RTSP, HTTP); traffic burstiness and periodicity (detected by Fourier analysis); this data is stored as a traffic pattern fingerprint for each device.

[0036] To achieve a scheduling evolution from passive response to proactive assurance, a future traffic pattern prediction mechanism based on time series forecasting is introduced, building upon traffic feature learning. By performing deep learning on device traffic pattern fingerprints, short-term traffic demand is predicted, providing a forward-looking decision-making basis for resource scheduling. The specific optimization process is as follows: Prediction Model Building and Training: Maintain an independent traffic prediction model for each device or for each group of devices with similar traffic patterns. The model uses historical "traffic pattern fingerprint" time-series data of devices as the training set. Each fingerprint data point contains multiple feature dimensions, such as the bandwidth value at time t. Distribution vector of main application types Flow entropy (Used to characterize suddenness) etc. Model The learning objective (which can be achieved using a Transformer time series predictor or a lightweight spatiotemporal graph network) is to construct fingerprint sequences from the past L time windows. Predicted sequences for the next K time windows The mapping relationship, where = ( , , The model minimizes the loss function between the predicted and observed values. (e.g., using smoothed mean absolute percentage error (sMAPE) for training): ; in The loss function for the prediction model is the smoothed mean absolute percentage error, where K is the number of future time windows to be predicted. The summation index ranges from 0 to K-1, where t is the current time. The traffic pattern fingerprint vector (including bandwidth, application type distribution, traffic entropy, etc.) predicted by the model at time t+i. This is the flow pattern fingerprint vector observed at time t+i. Let the magnitude of the vector be . It is a very small constant used to prevent the denominator from being zero; Real-time prediction and confidence assessment: At the beginning of each scheduling decision cycle, the system inputs the latest L time window traffic pattern fingerprints of the device into the corresponding prediction model. To obtain the predicted traffic trajectory for the next K windows. At the same time, the model outputs the confidence score of this prediction. The score is calculated based on the uncertainty estimate within the model or the accuracy backtesting of the most recent predictions.

[0037] Fusion of predictive information and resource profiles: predictable traffic trajectories This will be integrated with the resource profiles subsequently built in the previous steps to generate a dynamic, forward-looking resource profile. Specifically, based on the original static profile {state label, typical bandwidth range, list of key applications, probability of time period}, two dynamic fields, predicted state sequence and prediction confidence score, will be added. For example, if the predicted trajectory shows that the device's bandwidth demand will continuously exceed the typical range of its data upload period within the next 15 minutes, the forward-looking profile will mark this period as a predicted congestion period and attach a confidence score. .

[0038] Predictive-based elastic scheduling decision-making: The resource scheduling engine introduces predictive decision factors on top of the original matching rules; the decision logic is upgraded to dual-mode judgment. Active warm-up mode: When the predicted trajectory This shows that within the next m time windows ( The device has a high degree of confidence ( ) Entering a critical business state (e.g. If the current overall network utilization is below the security threshold, a pre-upgrade decision is immediately triggered. Enhanced resource quotas are allocated in advance before actual equipment demand arrives, ensuring zero-wait time when services start. The amount of resources to be pre-upgraded... Calculated dynamically based on predicted values: ; in This refers to the amount of resources required for the pre-upgrade. This represents the predicted bandwidth value from the current time t to time t+m-1. For safety factor ( ), This is the current quota.

[0039] Predictive load reduction mode: When the predicted trajectory display device will enter a long period of business silence (such as multiple consecutive windows) (close to zero), and confidence level With sufficient power, a more aggressive and sustained resource reclamation strategy can be implemented to more effectively allocate the released resources to other devices that are in the predicted peak period, thereby achieving predictive global load balancing across devices. Online Model Learning and Calibration: Predictive Models Online learning is supported. At the end of each prediction period, when the actual traffic data... When available, compared with the predicted value Compare them. If prediction biases consistently exceed the tolerance range and the confidence score... In cases of artificially inflated values, the model is triggered to perform immediate fine-tuning. New data pairs (text{historical sequence}, text{actual value}) for fine-tuning are added to a circular buffer, and the model is periodically sampled from the buffer for incremental training to ensure that it can adapt to gradual or abrupt changes in device traffic patterns.

[0040] Resource profiling: The resource scheduling engine analyzes traffic pattern fingerprints from the past 24 hours and uses clustering algorithms (such as K-means) to classify typical device states, such as "business inactivity period," "data upload period," and "video streaming period." A resource profile is created for each state, including: {state label, typical bandwidth range, list of key applications, and probability of the time period}. Elastic scheduling decision and execution: The scheduling engine monitors the current traffic of the device in real time and matches it with the resource profile; Degradation decision: If the current traffic characteristics match the "business quiet period" and the overall network utilization is >80%, then a "temporary rate limiting policy" (such as reducing the bandwidth quota to 50% of the basic limit) will be generated, which will be valid for 30 minutes. Upgrade Decision: If the DPI identifies traffic as belonging to a "critical application list" (such as video streaming), or predicts that a device is about to enter its historical "peak period," and the overall network utilization is <60%, a "temporary enhancement policy" (such as increasing the bandwidth quota to 200% of the base) is generated, valid until the end of the predicted peak period. The decision result calls the controller via a REST API, and the controller issues the corresponding QoS policy (such as modifying the Meter table or Queue configuration) to the access switches.

[0041] During off-peak hours or when devices are performing non-critical operations, their bandwidth quota limits are automatically reduced to free up resources for other devices. When critical business operations are predicted or detected to begin (such as devices in a smart factory starting production instructions), or when the overall network load is low, their bandwidth quotas are automatically and temporarily increased to ensure a smooth service experience. This scheduling is performed dynamically at the minute or even second level and ensures that it always occurs within the global resource pool managed by the policy controller to avoid resource conflicts.

[0042] Step 5: Session Termination and Resource Cleanup When a device disconnects from the network and a preset keep-alive timeout period has elapsed, the access control point notifies the central policy controller. The controller instructs all relevant network nodes to automatically clean up all dynamic policies issued to that device, reclaim the logical resources they occupy (such as IP addresses and policy entries), and archive the device's full lifecycle log for this access (including intent resolution records, security events, and resource usage) for auditing and model optimization.

[0043] The specific implementation method is as follows: Offline Detection and Notification: Access switches detect device offline status through link state detection (such as port DOWN events) or neighbor discovery protocols (such as NDP / ARP timeouts). The control agent on the switch starts a configurable delay timer (e.g., 30 seconds to prevent brief disconnections), and after the timeout, sends a standard Device-Offline-Notification message to the central controller, containing the device ID and offline timestamp. Global policy cleanup: After receiving the notification, the controller's policy lifecycle management module performs the following atomic operations: Query the device-policy mapping table to obtain a list of globally unique identifiers for all policies issued to this device; Send batch policy deletion commands to all relevant network devices (switches, firewalls) that are on record (e.g., OpenFlow's Flow-Mod message, command DELETE, matching field is the MAC address of the device). Send a DHCP-Release request to the IP Address Management (IPAM) system to release the device's IP address lease; In the controller's internal database, the device's status is marked as "offline," and the log archiving process is triggered. Log archiving: The controller compresses and transfers all log entries related to the device (stored locally or in a distributed log system) to a cold storage layer of an object storage system (such as compatible storage).

[0044] A network access processing wireless broadband terminal, comprising: The context-aware agent is responsible for automatically collecting multi-dimensional static attributes and dynamic claims of the local machine, including device type, hardware fingerprint, software version, security basis, and user-claimed business intent. This information is formatted into a standard data model and proactively, on demand, or periodically reported to the network control plane via a secure connection, providing accurate source data for intent resolution on the network side. The policy enforcement adapter receives and parses intent-based, fine-grained policy instructions (such as structured JSON or YAML format) issued by the network controller, and transforms them into specific configuration parameters recognizable by the terminal's operating system or hardware. Subsequently, it drives the terminal's network protocol stack, firewall rules, or traffic shaping queues to apply these policies in real time, ensuring that all inbound and outbound traffic from the terminal strictly complies with the network-defined access control, bandwidth limits, and quality of service requirements. The state coordination unit provides an open and secure local interface, allowing network-deployed security probes or performance collectors to acquire necessary runtime data (such as process lists and resource utilization). Simultaneously, its network traffic can be directed to a deep detection system on the network side for analysis, enabling terminals to seamlessly participate in the global network security posture assessment and resource profiling learning process, achieving dynamic adaptation of terminal behavior to network policies. The connection lifecycle manager oversees the entire process from access authentication and session persistence to graceful offline. In addition to handling standard connection and authentication protocols, it is also aware of application-layer state and user intent. When the network connection is abnormally interrupted or the user actively disconnects, it attempts to send offline notifications or state synchronization messages to the network. Upon receiving a connection termination command from the network, it coordinates the various components within the terminal to release network resources in an orderly manner and clear session state, ensuring that the offline process does not affect user experience or the consistency of network policies.

[0045] A network access processing system, comprising the following modules: The multi-dimensional information perception and acquisition module is responsible for performing dual information capture when a device initiates an access request. It not only completes the traditional authentication of device identity (such as MAC address and certificate), but also collects multi-dimensional context information such as device type, claimed access purpose, operating system status, and physical port location through lightweight proxy or active probe technology. It then securely and systematically encapsulates and uploads this information to the central controller, providing a comprehensive and accurate raw data foundation for intelligent decision-making. The intelligent intent parsing and policy generation module receives multi-dimensional information from the perception module and uses an embedded rule engine or machine learning model to infer and parse the device's true business intent. Subsequently, based on the parsed intent, it automatically matches and instantiates a pre-configured policy template library to generate a device-specific network configuration containing fine-grained policies such as VLANs, ACLs, and bandwidth limits. This configuration is then distributed to all execution points across the network through a standardized interface, achieving automated and precise policy binding. The dynamic monitoring and adaptive optimization module includes two core sub-functions: the security status monitoring sub-module assesses the security health of devices in real time and automatically triggers policy corrections (such as restricting access or isolating) when the score deteriorates, thus achieving proactive security defense; the resource scheduling sub-module analyzes the historical traffic of devices and predicts future demand, dynamically adjusting their bandwidth resource quotas (predictive upgrades / downgrades), ensuring the experience of critical services while achieving global elastic optimization and efficient utilization of network resources; The policy lifecycle management module is responsible for managing the entire process from policy generation to expiration, ensuring the cleanliness of system resources and the consistency of policies. It monitors device offline events and automatically triggers commands to clear all dynamic policies issued to that device on all relevant nodes in the network and reclaim logical resources such as IP addresses after the device disconnects. Simultaneously, it organizes and archives logs throughout the device's lifecycle, providing data support for system auditing, problem tracing, and continuous model optimization.

[0046] The above formulas are all dimensionless calculations. Dimensionless calculations can be performed using various methods such as standardization, which will not be elaborated here. The formulas are derived from software simulations based on a large amount of collected data, and the preset parameters in the formulas can be set by those skilled in the art according to the actual situation.

[0047] The above embodiments can be implemented, in whole or in part, by software, hardware, firmware, or any other combination thereof. When implemented using software, the above embodiments can be implemented, in whole or in part, as a computer program product. The computer program product includes one or more computer instructions or computer programs. When the computer instructions or computer programs are loaded or executed on a computer, all or part of the processes or functions described in the embodiments of this application are generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable device. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another. For example, the computer instructions can be transmitted from one website, computer, server, or data center to another website, computer, server, or data center via wired or wireless (e.g., infrared, wireless, microwave, etc.) means. The computer-readable storage medium can be any available medium that a computer can access or a data storage device such as a server or data center that includes one or more sets of available media. The available medium can be a magnetic medium (e.g., floppy disk, ATA hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium. The semiconductor medium can be a solid-state ATA hard disk.

[0048] It should be understood that in the various embodiments of this application, the order of the above-mentioned processes does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.

[0049] Those skilled in the art will recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.

[0050] In the several embodiments provided in this application, it should be understood that the disclosed systems, apparatuses, and methods can be implemented in other ways. For example, the apparatus embodiments described above are merely illustrative; for instance, the division of units is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be through some interfaces; the indirect coupling or communication connection between apparatuses or units may be electrical, mechanical, or other forms.

[0051] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment, depending on actual needs.

[0052] In addition, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit.

[0053] If the aforementioned functions are implemented as software functional units and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or a portion of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable ATA hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.

[0054] The above description is merely a specific embodiment of this application, but the scope of protection of this application is not limited thereto. Any variations or substitutions that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the scope of protection of this application. Therefore, the scope of protection of this application should be determined by the scope of the claims.

Claims

1. A network access processing method, characterized in that, Includes the following steps: Multi-dimensional perception and information collection: When a device initiates a network access request, the network access control point collects the device's traditional authentication information as well as multi-dimensional context information such as device type, claimed access purpose, device basic status, access time and location, and sends the information to the central policy controller. Intent parsing and policy binding: The central policy controller infers the service intent of the device based on the received multi-dimensional context information, and based on the inferred service intent, matches and generates the corresponding fine-grained network policy from the preset policy template library, binds the network policy with the device's unique identifier, and sends it to the policy execution point in the network. Security assessment and policy correction: After a device is connected to the network, its security status is continuously monitored and a dynamic security health score is generated. When the security health score is lower than a preset threshold, the policy correction process is automatically triggered to generate and issue a corrected network policy to adjust the network access permissions of the device. Traffic self-learning and elastic scheduling: Analyze the historical business traffic generated by the device to build resource profiles; Based on resource profiles and predictions of future device traffic, the network bandwidth resource quota allocated to devices is dynamically adjusted. Session termination and resource cleanup steps: When a device is detected to be offline, the central policy controller is notified, and the controller instructs the relevant network nodes to clean up all dynamic policies issued to the device and reclaim the network resources they occupy. The intent parsing and policy binding also includes an online feedback optimization process, specifically including: After the device is connected and communication begins, its actual business mode vector Q is extracted through traffic analysis; The matching degree R between the initial inferred intent description P of the computing device and the actual business pattern vector Q is determined based on the size of the intersection of the key feature sets extracted from P and Q, and the consistency indicator function between the traffic destination and the intent claim target. Based on the matching degree R, a dynamic decay update algorithm with a forgetting factor is used to update the confidence degree C of the device's intent resolution. When the confidence level C is consistently below the confidence threshold within the preset observation time window W, an optimization learning process is triggered. The process includes: correcting the intent mapping rule base, or adding the context information X that generates low-confidence inference and the actual business model as new sample pairs to the incremental learning queue of the machine learning model for training. The traffic self-learning and elastic scheduling steps, specifically including dynamic adjustments based on predictions of future traffic, include: Maintain a traffic prediction model for a device or group of devices. The model uses the historical traffic pattern fingerprint time series of the device as the training set. The fingerprint includes bandwidth value, application type distribution vector and traffic entropy feature. In each scheduling decision cycle, the latest L time window traffic pattern fingerprints of the device are input into the model to obtain the predicted traffic trajectory Ť for the next K windows and its confidence score. Active preheating mode: When the predicted trajectory shows that the device has a confidence level greater than the preset standard to enter the critical business state within the next m windows, and the overall network utilization is lower than the safety threshold, a pre-upgrade decision is triggered, and the enhanced bandwidth quota is dynamically calculated and allocated in advance based on the predicted bandwidth peak. Predictive load balancing mode: When the predicted trajectory shows that a device will enter a long period of business silence and the confidence level meets the standard, a more persistent resource reclamation strategy is triggered to perform predictive global load balancing across devices.

2. The network access processing method according to claim 1, characterized in that, The multidimensional perception and information acquisition step specifically includes acquiring and sending multidimensional context information, including: By using a pre-installed data acquisition agent on the managed device, local information is automatically collected and structured information objects are generated in accordance with a unified data model; For devices that cannot install an agent, the access control point indirectly obtains the device type information by sending LLDP extended messages or custom probe messages and analyzing their responses. The access control point sends the encapsulated authentication information and multidimensional context information data packet to the northbound RESTful API interface of the central policy controller through a TLS-based secure channel.

3. The network access processing method according to claim 1, characterized in that, In the aforementioned security assessment and strategy correction steps, the generation of a dynamic security health score specifically involves: Maintain an initial score S for each device and subscribe to a real-time event stream from the security information and event management system; When a security incident occurs, the score S is deducted based on the predefined event weight and event severity coefficient to obtain the updated security health score S(t). Security incidents include at least the detection of unauthorized processes, the existence of known high-risk vulnerabilities, and the occurrence of abnormal external connections; S(t) is updated periodically.

4. The network access processing method according to claim 1, characterized in that, The traffic prediction model supports online learning and calibration; After each prediction period ends, the model predictions are compared with the actual observations. If the prediction deviation continues to exceed the tolerance range, the corresponding historical sequence and actual value data pairs are added to the circular buffer. The model periodically samples data from the circular buffer for incremental training to adapt to gradual or abrupt changes in device traffic patterns.

5. The network access processing method according to claim 1, characterized in that, The session termination and resource cleanup steps specifically include the following atomic operations: Query the device-policy mapping table to obtain a list of globally unique identifiers for all policies issued to offline devices; Send a batch policy deletion command to all relevant network devices that are on record. The command is an OpenFlow Flow-Mod message, the command is DELETE, and the matching field is the MAC address of the device. Send a DHCP-Release request to the IP address management system to release the IP address lease assigned to the device.

6. A wireless broadband terminal applied to the network access processing method according to any one of claims 1-5, characterized in that, include: Context-aware agent is used to collect the device attributes and declared business intent of the terminal, and format them into a standard data model for reporting to the network control plane; The policy execution adapter is used to receive and parse network policy instructions based on business intent issued by the network controller, convert them into configurations that can be recognized by the terminal, and drive the execution of its network protocol stack. The state coordination unit is used to provide the necessary terminal runtime data interface to the network-side security and performance monitoring components, and to allow the network side to perform in-depth inspection of its network traffic; The connection lifecycle manager manages the entire process of a terminal from network access authentication and session persistence to offline disconnection, and coordinates resource cleanup and state synchronization when offline.

7. A system applied to the network access processing method according to any one of claims 1-5, characterized in that, Includes the following modules: The multi-dimensional information perception and acquisition module is deployed at the network access control point to collect and upload the device's identity authentication information and multi-dimensional context information when the device is connected. The intelligent intent parsing and policy generation module is deployed in the central policy controller. It is used to infer the device's service intent based on the received information and automatically generate and bind fine-grained device-specific network policies based on the intent. The dynamic monitoring and adaptive optimization module is used to continuously assess the security status of the device while it is online to trigger policy correction, and dynamically schedule its network bandwidth resources based on its traffic pattern self-learning and prediction results. The policy lifecycle management module is used to monitor device offline events and automatically trigger the cleanup of related policies and the global reclamation of network resources for the device.

Citation Information

Patent Citations

  • Intention-driven network management system and method

    CN114167760A

  • Dynamic adaptive network traffic management system and method

    CN118055024A

  • Real-time monitoring and protection method and system for security data of Internet of Things

    CN121309112A