A method for secure information and data sharing based on network security

CN122119954BActive Publication Date: 2026-09-01XIAN JUNCHI KANGDA INFORMATION TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202610221036.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2026-02-24
Publication Date
2026-09-01
Estimated Expiration
2046-02-24

AI Technical Summary

Technical Problem

[0005]为了解决现有技术在CPU计算资源耗尽的极端工况下无法保障信息数据安全共享的可靠性的技术问题,本发明的目的在于提供一种基于网络安全的信息数据安全共享方法,所采用的技术方案具体如下:

Benefits of technology

鉴于现有技术在CPU计算资源耗尽的极端工况下无法保障信息数据安全共享的可靠性的技术问题,本申请提供了一种基于网络安全的信息数据安全共享方法,通过响应于边缘网关处于计算型拥塞状态,触发降级验证模式,获取各个待验证终端的驱动层到达记录集,从而通过物理特征解耦分析得到各待验证终端的硬件约束置信值,进而基于各个待验证终端的硬件约束置信值构建准入控制策略,实现了合法终端与攻击源的有效区分,最终基于准入控制策略配置各个待验证终端的数据共享接入状态。上述技术方案无需依赖大量CPU资源进行解密运算,而是通过轻量级的物理特征分析实现身份验证,打破了极端工况下的防御死锁,既保障了信息数据安全共享的安全性,又确保了合法业务的连续性,提升了数据安全共享的可靠性。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122119954B_ABST
    Figure CN122119954B_ABST
Patent Text Reader

Abstract

This invention relates to the field of network security technology, specifically to a method for secure information and data sharing based on network security. It addresses the technical problem that existing technologies cannot guarantee the reliability of secure information and data sharing under extreme conditions where CPU computing resources are exhausted. The method includes: in response to an edge gateway being in a computational congestion state, triggering a degraded verification mode and obtaining the driver layer arrival record set of each terminal to be verified; for each terminal to be verified, performing physical feature decoupling analysis based on the driver layer arrival record set to obtain a hardware constraint confidence value for the terminal; the hardware constraint confidence value characterizes the degree to which the terminal to be verified is a genuine device subject to physical hardware constraints; constructing an access control policy based on the hardware constraint confidence values ​​of each terminal to be verified, and configuring the data sharing access status of each terminal to be verified based on the access control policy.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and specifically to a method for secure sharing of information and data based on network security. Background Technology

[0002] In virtual power plants and distributed energy control networks, edge gateways are core devices connecting massive numbers of embedded power terminals (such as photovoltaic inverters and energy storage controllers) with upper-level dispatch systems, undertaking the crucial function of power data transmission and interaction. To ensure the confidentiality and integrity of power data during transmission over the public network, existing technologies typically employ encrypted transmission protocols such as Ciphertext-Policy Attribute-Based Encryption (CP-ABE) or Transport Layer Security (TLS). These protocols achieve data security protection through complex cryptographic operations.

[0003] However, in real-world applications, when a computational resource exhaustion attack occurs targeting the edge gateway (such as a massive concurrent encrypted handshake request or replay attack), or when power grid frequency disturbances cause a surge in terminal responses, the gateway's Central Processing Unit (CPU) resources can be rapidly exhausted. Under these conditions, network input / output (I / O) bandwidth often remains available, but the CPU is unable to handle new decryption requests, leading to a defensive deadlock. The gateway is unable to distinguish legitimate terminals from attack sources through decryption, and it struggles to penetrate ciphertext to identify application-layer attacks using traditional defense methods. Dropping all traffic would disrupt legitimate services.

[0004] In summary, under extreme conditions where edge gateway CPU computing resources are exhausted, existing technologies struggle to balance data transmission security and business continuity, and cannot effectively distinguish between legitimate terminals and attack sources, thus affecting the reliability of secure data sharing in virtual power plants and distributed energy control networks. Summary of the Invention

[0005] To address the technical problem that existing technologies cannot guarantee the reliability of secure information and data sharing under extreme conditions where CPU computing resources are exhausted, the present invention aims to provide a secure information and data sharing method based on network security. The specific technical solution adopted is as follows: This application provides a method for secure information and data sharing based on network security, including: In response to the edge gateway being in a computational congestion state, a downgraded verification mode is triggered to obtain the driver layer arrival record set of each terminal to be verified; the driver layer arrival record set includes the arrival time and instruction type identifier of the response data packet of the corresponding terminal to be verified, which is captured by the network card driver layer; For each terminal to be verified, a physical feature decoupling analysis is performed based on the driver layer arrival record set of the terminal to be verified to obtain the hardware constraint confidence value of the terminal to be verified; the hardware constraint confidence value is used to characterize the degree of trust that the terminal to be verified is a real device subject to physical hardware constraints. An admission control policy is constructed based on the hardware constraint confidence values ​​of each terminal to be verified, and the data sharing access status of each terminal to be verified is configured based on the admission control policy.

[0006] The present invention has the following beneficial effects: Given the technical problem that existing technologies cannot guarantee the reliability of secure information and data sharing under extreme conditions where CPU computing resources are exhausted, this application provides a network security-based method for secure information and data sharing. By responding to edge gateways experiencing computational congestion, a downgraded verification mode is triggered to obtain the driver layer arrival record set of each terminal to be verified. Then, through physical feature decoupling analysis, the hardware constraint confidence value of each terminal to be verified is obtained. Based on the hardware constraint confidence values ​​of each terminal to be verified, an access control policy is constructed, effectively distinguishing legitimate terminals from attack sources. Finally, the data sharing access status of each terminal to be verified is configured based on the access control policy. This technical solution does not rely on a large amount of CPU resources for decryption operations, but instead achieves identity verification through lightweight physical feature analysis, breaking the defense deadlock under extreme conditions. It ensures both the security of secure information and data sharing and the continuity of legitimate business, thus improving the reliability of secure data sharing. Attached Figure Description

[0007] To more clearly illustrate the technical solutions and advantages in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0008] Figure 1 This is a flowchart illustrating a method for secure information and data sharing based on network security, provided in one embodiment of the present invention. Figure 2 This is a schematic diagram of the hardware structure of an edge gateway according to an embodiment of the present invention. Detailed Implementation

[0009] To further illustrate the technical means and effects adopted by the present invention to achieve its intended purpose, the following, in conjunction with the accompanying drawings and preferred embodiments, details the specific implementation, structure, features, and effects of a network security-based information data secure sharing method proposed according to the present invention. In the following description, different "one embodiment" or "another embodiment" do not necessarily refer to the same embodiment. Furthermore, specific features, structures, or characteristics in one or more embodiments can be combined in any suitable form.

[0010] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains.

[0011] In all division and logarithmic operations covered in this application, a smoothing mechanism is employed to prevent computer program crashes or invalid values ​​from being generated due to a zero denominator or a zero input. Specifically, a positive correction factor is superimposed on the denominator term of the division operation or the argument term of the logarithmic function. For example, the value is This ensures the robustness and feasibility of the algorithm under extreme conditions.

[0012] The normalization function mentioned in this application Unless otherwise specified, all values ​​are normalized using maximum and minimum values. The maximum and minimum values ​​are preset empirical extreme values ​​derived from a large amount of historical experimental data. If the calculated result exceeds the [0,1] interval, it is restricted to the [0,1] range by a truncation function (i.e., if the result is less than 0, it is taken as 0, and if it is greater than 1, it is taken as 1) to eliminate the influence of outliers on the evaluation index.

[0013] Given the technical problem that existing technologies cannot guarantee the reliability of secure information and data sharing under extreme conditions where CPU computing resources are exhausted, this application provides a network security-based method for secure information and data sharing. By responding to edge gateways experiencing computational congestion, a downgraded verification mode is triggered to obtain the driver layer arrival record set of each terminal to be verified. Then, through physical feature decoupling analysis, the hardware constraint confidence value of each terminal to be verified is obtained. Based on the hardware constraint confidence values ​​of each terminal to be verified, an access control policy is constructed, effectively distinguishing legitimate terminals from attack sources. Finally, the data sharing access status of each terminal to be verified is configured based on the access control policy. This technical solution does not rely on a large amount of CPU resources for decryption operations, but instead achieves identity verification through lightweight physical feature analysis, breaking the defense deadlock under extreme conditions. It ensures both the security of secure information and data sharing and the continuity of legitimate business, thus improving the reliability of secure data sharing.

[0014] The following description, in conjunction with the accompanying drawings, details a specific scheme for a network security-based information data secure sharing method provided by the present invention.

[0015] Please see Figure 1 The diagram illustrates a method flowchart for secure information data sharing based on network security, according to an embodiment of the present invention. The method includes the following steps: Step 101: In response to the edge gateway being in a computational congestion state, trigger the downgrade verification mode and obtain the driver layer arrival record set of each terminal to be verified.

[0016] The driver layer arrival record set includes the arrival time and instruction type identifier of the response data packet of the corresponding terminal to be verified, captured by the network card driver layer.

[0017] The aforementioned computational congestion state refers to a situation where the edge gateway's CPU resources are exhausted due to handling a large number of computational tasks (such as cryptographic operations), but network I / O bandwidth still has surplus. Degraded authentication mode refers to a mode where the edge gateway suspends high-overhead application-layer decryption services and instead achieves terminal authentication through lightweight physical feature detection and analysis. The driver-layer arrival record set can be directly captured by the network interface card (NIC) driver layer. It contains a dataset containing the arrival time of the response data packets from the terminal to be authenticated and the command type identifier. The command type identifier is used to distinguish the type of probe command corresponding to the response data packet.

[0018] In one possible implementation, the edge gateway can monitor its own operational status in real time through the following methods: First, the edge gateway monitors the CPU load and network bandwidth utilization of the edge gateway in real time.

[0019] Among them, CPU load rate is used to characterize the utilization of CPU computing resources. Network bandwidth utilization rate is used to characterize the utilization of network I / O channels, and can be expressed as the ratio of the actual data transmission volume of the network interface per unit time to the maximum transmission capacity.

[0020] In some embodiments, the edge gateway can use a system load monitoring daemon to collect CPU load rate and network bandwidth utilization at a fixed sampling period (e.g., 100ms). CPU load rate can be calculated by reading process scheduling information from the operating system kernel, and network bandwidth utilization can be calculated by statistically analyzing the amount of data sent and received by the network interface and combining this with the interface's rated bandwidth. Real-time monitoring of these two metrics can accurately reflect the gateway's resource occupancy status, providing data support for determining computational congestion.

[0021] When the central processing unit load rate is greater than the first threshold and the network bandwidth utilization rate is less than the second threshold, the edge gateway is determined to be in a computational congestion state.

[0022] The first threshold is a preset CPU load rate safety threshold, used to determine whether CPU resources are exhausted; the second threshold is a preset network bandwidth saturation threshold, used to determine whether there are still spare network I / O channels.

[0023] For example, the first threshold can be set to 90%, and the second threshold can be set to 80%. When the CPU load rate is detected to be greater than 90% and the network bandwidth utilization rate is less than 80%, it indicates that the CPU resources of the edge gateway are severely occupied and cannot meet the needs of computationally intensive tasks such as decryption. However, the network I / O channel still has sufficient capacity for data transmission and reception, which is consistent with the characteristics of computational congestion. This can accurately identify computational congestion scenarios and avoid misjudging other types of congestion, such as network bandwidth exhaustion, as computational congestion, ensuring that the degradation verification mode is triggered only when necessary.

[0024] Then, the application layer decryption tasks of each session in the pending queue are suspended, and each session in the pending queue is marked as pending verification. The terminal corresponding to each session in the pending queue is designated as the terminal to be verified.

[0025] Among them, the pending queue refers to the session queue in the edge gateway that is waiting for application layer decryption and data processing. The application layer decryption task refers to the ciphertext decryption and signature verification operation based on encryption protocols such as CP-ABE or TLS. The pending verification status refers to the status where the session has been established but has not yet passed the authentication and application layer data processing is not performed at this time.

[0026] In some embodiments, upon determining that a computational congestion state has occurred, the gateway scheduler removes the application-layer decryption tasks of all newly inbound sessions from the CPU runtime queue, pausing decryption operations to free up CPU resources. Simultaneously, the edge gateway marks these sessions as pending verification at the application layer and maintains the transport layer connection in an established state, avoiding the need for legitimate terminals to re-establish connections due to connection interruptions and minimizing the impact of service disruptions. Furthermore, the edge gateway extracts the terminal information corresponding to these sessions, designating these terminals as pending verification terminals to prepare for subsequent probing and authentication.

[0027] For example, the terminal to be verified can be an embedded power terminal such as a photovoltaic inverter or an energy storage controller. The arrival time of the drive layer in the record set can be recorded with microsecond-level precision to ensure the accuracy of the data.

[0028] Step 102: For each terminal to be verified, perform physical feature decoupling analysis based on the driver layer arrival record set of the terminal to be verified to obtain the hardware constraint confidence value of the terminal to be verified.

[0029] The hardware constraint confidence value is used to characterize the degree of trust that the terminal to be verified is a real device subject to physical hardware constraints. The larger the hardware constraint confidence value, the higher the trust that the corresponding terminal to be verified is a real physical device.

[0030] The aforementioned physical feature decoupling analysis refers to the process of extracting characteristic parameters that characterize the inherent attributes of the terminal hardware from the driver layer to the record set, and then performing quantitative analysis on the extracted characteristic parameters. Specifically, physical feature decoupling analysis focuses on the characteristics of the terminal being constrained by the power grid and the differences in hardware computing power. By extracting phase features related to power grid synchronization and computing power features related to instruction processing time, the physical authenticity of the terminal is comprehensively evaluated. Since the hardware operation of a real embedded power terminal is subject to the mandatory constraints of the power grid's AC cycle, and its computing power consumption for processing different types of instructions follows a fixed pattern, while software-simulated attack sources do not possess these physical constraints, physical feature decoupling analysis can effectively distinguish between the two scenarios.

[0031] Step 103: Construct an admission control policy based on the hardware constraint confidence values ​​of each terminal to be verified, and configure the data sharing access status of each terminal to be verified based on the admission control policy.

[0032] The access control policy refers to the terminal access rules set based on hardware constraint confidence values, used to determine whether to allow the terminal to be verified to participate in secure information and data sharing. Data sharing access status includes two states: allowed access (i.e., resumption of business data decryption and sharing) and denied access (i.e., discarding business data).

[0033] In one possible implementation, for each terminal to be verified, if the hardware constraint confidence value of the terminal to be verified is greater than or equal to the allow threshold, the terminal to be verified is added to the hardware trust list, and the decryption processing of the service data of the terminal to be verified is resumed, so as to allow the service data of the terminal to be verified to be shared to the upper-layer scheduling system; if the hardware constraint confidence value of the terminal to be verified is less than or equal to the discard threshold, then a rule is configured in the network driver layer to discard the service data of the terminal to be verified.

[0034] The allow threshold is greater than the drop threshold. The allow threshold is the lowest hardware constraint confidence value for determining that the terminal to be verified is a real physical device, while the drop threshold is the highest hardware constraint confidence value for determining that the terminal to be verified is a source of software attacks. A clear judgment interval can be formed when the allow threshold is greater than the drop threshold. The allow and drop thresholds can be adjusted according to the security requirements and network environment of the actual application scenario. For example, the allow threshold can be set to 0.8, and the drop threshold can be set to 0.3. If the hardware constraint confidence value of the terminal to be verified is greater than or equal to the allow threshold, it indicates that the terminal to be verified conforms to the characteristics of a real physical device, and the corresponding session is determined to be a legitimate physical session. At this time, the edge gateway can add the terminal to the hardware trust list and resume the decryption processing of the terminal's service data, allowing its service data to be shared with the upper-layer scheduling system.

[0035] The hardware trust list is a set of kernel-level trusted terminals maintained by the edge gateway, with a preset lifespan (e.g., 5 minutes). Within this lifespan, subsequent packets from the terminal to be verified can skip the downgrade verification process, improving data processing efficiency. Recovery and decryption processing refers to the edge gateway reallocating CPU resources to the session of the terminal to be verified, performing CP-ABE or TLS decryption and signature verification operations on the encrypted data packets in the buffer. The decrypted plaintext data is then delivered to the upper-layer SCADA system through an internal security interface, completing data sharing.

[0036] If the hardware constraint confidence value of the terminal to be verified is less than or equal to the drop threshold, it indicates that the terminal to be verified meets the characteristics of a software attack source, and the corresponding session is determined to be a malware session. At this time, the edge gateway can configure a drop rule for the five-tuple of the session of the terminal to be verified at the network driver layer. Subsequent data packets belonging to the session of the terminal to be verified will be directly dropped at the network card receiver, no longer occupying the CPU and memory resources of the edge gateway, effectively alleviating computational congestion.

[0037] If the hardware constraint confidence value of the terminal to be verified is less than the allow threshold but greater than the discard threshold, it indicates that the characteristics of the terminal to be verified are in an ambiguous zone, possibly caused by extreme network jitter or other abnormal conditions. In this case, the edge gateway can adopt a fault-tolerant strategy to maintain the terminal's pending verification status, not allow it to proceed, wait for the next round of probing for re-authentication, or until the session times out and is disconnected, thus avoiding security risks or service interruptions caused by misjudgment.

[0038] In some embodiments, this application may also continuously monitor the CPU load of the edge gateway. When the CPU load remains below the recovery threshold for a preset period of time, the application exits the downgrade verification mode and clears the hardware trust list.

[0039] The recovery threshold is a CPU load security threshold used to determine whether CPU resources have fallen back to a level capable of handling decryption tasks normally. For example, the recovery threshold can be 70%. The preset duration refers to the minimum time for the CPU load to remain below the recovery threshold. For example, the preset duration can be determined based on the sampling period, such as the duration of 5 sampling periods.

[0040] When the edge gateway detects that the CPU load remains below the recovery threshold for a preset period, it indicates that the edge gateway's computing resources have been fully released and it can normally perform application-layer decryption and signature verification operations. At this point, the edge gateway can automatically exit the downgraded verification mode and resume the decryption-then-verification processing strategy for all new inbound connections. Simultaneously, the edge gateway needs to clear its hardware trust list to avoid security risks arising from terminals on the trust list after resource recovery, ensuring the security of the system after it returns to normal operation.

[0041] Based on the above technical solution, this application can trigger a downgraded verification mode in response to the edge gateway being in a computational congestion state, obtain the driver layer arrival record set of each terminal to be verified, and then obtain the hardware constraint confidence value of each terminal to be verified through physical feature decoupling analysis. Based on the hardware constraint confidence value of each terminal to be verified, an admission control policy is constructed, effectively distinguishing legitimate terminals from attack sources. Finally, the data sharing access status of each terminal to be verified is configured based on the admission control policy. This technical solution does not rely on a large amount of CPU resources for decryption operations, but achieves identity verification through lightweight physical feature analysis, breaking the defense deadlock under extreme conditions. It ensures both the security of information and data sharing and the continuity of legitimate business, improving the reliability of data security sharing.

[0042] As a possible embodiment of this application, step 101 above can be implemented through the following steps: Step 201: In response to the edge gateway being in a computational congestion state, send a sequence of probe commands to each terminal to be verified.

[0043] The probe instruction sequence comprises multiple probe instructions, including input / output instructions and CPU-based instructions. This sequence, consisting of various types of probe instructions, triggers the terminal to be verified to respond to instructions, thereby identifying its hardware characteristics.

[0044] Input / output (I / O) instructions are those that trigger direct memory access or simple I / O bus operations on the terminal. These instructions have extremely low CPU overhead; for example, function code 0x03 in the Modbus-TCP protocol (used to read holding registers). CPU-based instructions require the terminal's CPU to perform multiple arithmetic and logical operations, with a clearly defined computation time. Examples include custom function codes that require the terminal to perform CRC-32 or hash operations on a piece of historical data.

[0045] In one possible implementation, in response to the edge gateway being in a computational congestion state, this application may set a sampling time window, and within the sampling time window, for each terminal to be verified, alternately send input / output commands and central processing unit commands at random time intervals.

[0046] The sampling time window covers multiple AC power cycles of the power grid. The sampling time window refers to the duration of the edge gateway's command detection. The AC power cycle refers to the voltage cycle of the edge gateway's local power supply circuit. This can be achieved through a hardware zero-crossing detector integrated in the power management module, which monitors the voltage waveform of the local power supply circuit in real time with microsecond-level interrupt response speed. This captures the system time of two adjacent zero-crossing points, calculates the time difference, and obtains the AC power cycle. For example, the AC power cycle of a 50Hz power grid is approximately 20ms.

[0047] In some embodiments, the sampling time window setting needs to meet two constraints: first, it must cover multiple complete AC power cycles (e.g., more than 5) to ensure that the terminal's response characteristics under multiple power grid phases can be captured; second, the length of the sampling time window should not be an integer multiple of the AC power cycle to prevent flickering effects, which would prevent the response characteristics of some phases from being collected. For example, when the AC power cycle is 20ms, the sampling time window can be set to a non-integer multiple between 100ms and 120ms, such as 110ms. This duration covers 5 complete 20ms cycles (a total of 100ms) and is not an integer multiple of 20ms, enabling comprehensive and accurate collection of the terminal's response data.

[0048] The random time interval refers to the time difference between the sending of two adjacent probe commands, which can be generated using a random algorithm. Setting a random time interval can prevent attackers from predicting and simulating the sending pattern of probe commands, thereby improving the probe's resistance to attacks.

[0049] After triggering the downgraded verification mode, the edge gateway constructs an adapted probe command sequence based on the type and communication protocol of the terminal to be verified. This probe command sequence alternates between input / output commands and CPU-based commands. By executing these two types of commands differently, the hardware time consumption characteristics of the terminal in processing different types of tasks can be fully exposed. The process of sending the probe command sequence does not consume a large amount of CPU resources, but mainly utilizes the surplus network I / O bandwidth, which is consistent with the resource status under computational congestion.

[0050] Step 202: Capture the response data packets of each terminal to be verified through the packet filtering program of the network card driver layer, record the arrival time of each response data packet and the corresponding instruction type identifier, and form a driver layer arrival record set for each terminal to be verified.

[0051] Packet filtering refers to a program that runs at the network card driver layer and can capture and process data packets before they enter the operating system kernel protocol stack. For example, the Extended Berkeley Packet Filter (eBPF) program can be used. The instruction type identifier is used to distinguish the instruction type of the probe instruction corresponding to the response data packet. For example, the instruction type identifier of input / output instructions can be set to 0, and the instruction type identifier of CPU instructions can be set to 1.

[0052] In some embodiments, the edge gateway can pre-load the eBPF program into the flow control hook or eXpress Data Path (XDP) mount point of the network interface controller. This eBPF program runs in kernel mode, has extremely high execution priority and very low resource overhead, and can run stably even under high CPU load. When a response packet from a terminal to be verified arrives at the gateway's network interface card (NIC) and triggers a hardware interrupt, the eBPF program is immediately triggered. Before the packet enters the kernel protocol stack, it performs operations such as session matching (matching the session 5-tuple of the state to be verified), timestamp recording (reading the high-precision system clock to record the time the packet arrived at the NIC), and instruction type identifier parsing (parseing the packet payload characteristics to determine the corresponding probe instruction type). Subsequently, the eBPF program writes a tuple consisting of the arrival time of each response packet and the instruction type identifier into a kernel circular buffer, which is periodically read and organized by user-space programs to form a driver layer arrival record set for each terminal to be verified.

[0053] Based on the above technical solution, this application can respond to edge gateways experiencing computational congestion by sending a sequence of probe commands, including input / output commands and CPU commands, to each terminal to be authenticated. This effectively triggers the terminal to respond and obtain hardware processing characteristics. Simultaneously, the packet filtering program at the network interface card (NIC) driver layer captures response data packets, avoiding measurement errors caused by operating system protocol stack scheduling delays and ensuring the accuracy of arrival time and command type identification. The driver layer arrival record set obtained by the above technical solution can accurately reflect the hardware response characteristics of the terminal, providing high-quality raw data for subsequent physical feature decoupling analysis. This helps improve the accuracy of hardware constraint confidence value calculation, thereby enhancing the reliability of authentication.

[0054] As a possible embodiment of this application, step 102 above can be implemented through the following steps: Step 301: For each terminal to be verified, perform data cleaning on the driver layer arrival record set of the terminal to be verified to obtain a valid response subset.

[0055] Data cleaning refers to removing background noise data (such as DDoS attack traffic, irrelevant broadcast packets, retransmitted data packets, etc.) from the record set arriving at the driver layer, retaining the valid response data corresponding to the probe commands. The valid response subset refers to the dataset that, after data cleaning, can truly reflect the response of the terminal to the probe commands.

[0056] In one possible implementation, this application can determine the expected arrival window of the response data packet corresponding to each probe command for each terminal to be verified based on the sending time of each probe command sent to the terminal to be verified and the network jitter benchmark. Then, the driver layer arrival record set is cleaned based on the expected arrival window of the response data packet corresponding to each probe command to obtain an effective response subset.

[0057] Among them, the sending time of the probe command refers to the system time when the edge gateway sends the probe command to the terminal to be verified. The network jitter benchmark refers to the standard deviation of network latency counted by the edge gateway during non-congestion periods, which is used to characterize the background noise level of the network environment. This network jitter benchmark can be continuously maintained and updated by the edge gateway under normal operating conditions. The expected arrival window refers to the time interval in which the response data packet corresponding to each probe command is most likely to arrive, which is used to filter valid response data.

[0058] For example, the expected arrival window can be represented as ,in, For the first The time when a probe command is sent. The historical minimum round-trip time for the session corresponding to the terminal to be verified can be obtained by statistically analyzing the minimum round-trip time in the historical communications of that session. This is a tolerance factor, which can be adjusted according to network fluctuations; for example, it can be 3. This serves as a benchmark for network jitter. This is used to address transmission latency fluctuations caused by network jitter, ensuring that valid response data is not misjudged as noise data due to network jitter.

[0059] In some embodiments, the edge gateway traverses each response packet in the driver layer arrival record set and determines whether the arrival time falls within the corresponding expected arrival window. For response packets that fall within the expected arrival window, they are retained as valid data; for response packets that do not fall within any expected arrival window, they are determined to be background noise data and discarded.

[0060] Furthermore, if multiple response packets exist within a given expected arrival window (potentially due to packet retransmission or attacks), the response packet closest to the center of the expected arrival window is retained to avoid interference from retransmitted or attacked data. Through this filtering process, a subset of valid responses, free from background noise and interference, is ultimately obtained.

[0061] Step 302: Determine the phase distribution dispersion based on the effective response subset and the AC cycle of the power grid.

[0062] The phase distribution dispersion characterizes the randomness of the distribution of response data packets' arrival times along the phase of the AC cycle in the power grid. A larger phase distribution dispersion indicates a more random distribution of arrival times, and a lower probability that the terminal is subject to physical constraints from the power grid; conversely, a smaller phase distribution dispersion indicates a more concentrated distribution of arrival times, and a higher probability that the terminal is subject to physical constraints from the power grid.

[0063] In one possible implementation, this application can map the arrival time of each response data packet in the effective response subset to a phase space with the AC cycle of the power grid as the modulus, and statistically analyze the sample distribution probability of each phase interval in the phase space. Then, based on the sample distribution probability of each phase interval in the phase space, the distribution entropy value is calculated to obtain the phase distribution dispersion.

[0064] In this context, phase space refers to the relative phase of each response data packet, which is mapped from the time dimension to the phase dimension [0, 2π) based on the AC cycle of the power grid.

[0065] For example, the relative phase of the response data packet satisfies the following formula: in, To effectively respond to the first subset The relative phase of each response data packet To effectively respond to the first subset The arrival time of each response data packet, For the AC cycle of the power grid, This indicates the modulo operation.

[0066] Subsequently, this application can uniformly divide the phase space [0, 2π) into Phase intervals (e.g.) The number of response data falling into each phase interval is counted, and the proportion of the number of response data packets falling into each phase interval in the effective response subset is calculated to obtain the sample distribution probability of each phase interval.

[0067] For example, the distribution entropy value can be calculated using the Shannon entropy formula, and the phase distribution dispersion satisfies the following formula: in, For phase distribution dispersion, The number of phase intervals, For the first The sample distribution probability of each phase interval, when the sample distribution probability of a certain phase interval... At that time, agreements can be set. This avoids meaningless situations in mathematical calculations.

[0068] in, This characterizes the contribution of the corresponding phase interval to the overall distribution randomness. When the samples are concentrated in a few phase intervals, the majority of the phase intervals... Smaller, corresponding The absolute value is small, so the sum is taken as the negative value. Smaller; when the sample is uniformly distributed across all phase intervals, the value of each phase interval is relatively small. Similar and not zero, corresponding The summation is negative because the absolute value is large. The response time is relatively large. For real embedded terminals subject to the mandatory constraints of the AC power cycle of the power grid, the response time will exhibit statistical clustering due to power grid interruptions, leading to... Smaller; for software attack sources not constrained by the power grid, their response times are randomly distributed, leading to... Larger. Therefore, It can effectively distinguish the phase characteristics of real terminals from those of attack sources, providing key support for the calculation of hardware constraint confidence values.

[0069] Step 303: Determine the computing power processing time difference based on the effective response subset.

[0070] The computing power processing time difference is used to characterize the time difference in processing different types of probe instructions by the terminal under test. It can be represented by the additional time the terminal spends processing CPU-type instructions compared to processing I / O-type instructions. Since the hardware computing power of real embedded terminals has fixed characteristics, the time spent processing CPU-type instructions will be significantly higher than the time spent processing I / O-type instructions. Software-simulated attack sources cannot accurately simulate this time difference. Therefore, this indicator can effectively distinguish between real terminals and attack sources.

[0071] In one possible implementation, this application can divide the effective response subset into a first response time set and a second response time set according to the instruction type identifier, and determine the computing power processing time difference based on the median of the first response time set and the median of the second response time set.

[0072] The first set of response times comprises the arrival times of all response data packets corresponding to input / output instructions in the valid response subset. The second set of response times comprises the arrival times of all response data packets corresponding to CPU-type instructions in the valid response subset. This application can use instruction type identifiers to distinguish the probe instruction type corresponding to the arrival time.

[0073] The median is the value in the middle position after sorting all arrival times in the set from smallest to largest (if the set size is even, the average of the two middle values ​​is taken). Using the median instead of the average value can effectively resist outlier interference caused by network long-tail jitter, ensuring the stability and accuracy of the calculation results.

[0074] For example, the computing power processing time difference satisfies the following formula: in, To handle time differences in computing power, The median of the second response time set. The median of the set of first response times. To find the maximum value function, if Greater than This indicates that the terminal takes longer to process CPU-type instructions than to process I / O instructions. The difference between the two; if Less than or equal to This may be due to abnormal conditions such as network jitter. In this case, Set it to 0 to avoid negative time differences and ensure the reasonableness of the calculation results.

[0075] Step 304: Generate the hardware constraint confidence value of the terminal to be verified based on the phase distribution dispersion and the computing power processing time difference.

[0076] For example, the hardware constraint confidence value satisfies the following formula: in, The hardware constraint confidence value of the terminal to be verified. To handle time differences in computing power, For phase distribution dispersion, The baseline computing power time difference is a preset empirical constant representing the time difference between processing CPU-type instructions and I / O-type instructions in a typical embedded chip. For example, the baseline computing power time difference is 1000μs, used to... Convert to relative difference. To achieve the maximum theoretical entropy, one can... The calculation shows that when the response time is... The entropy value when uniformly distributed within a phase interval This represents the number of phase intervals. The penalty coefficient is used to adjust the degree of penalty imposed on the confidence value by the phase distribution dispersion; for example, it can be 10. The sensitivity coefficient is used to adjust the sensitivity of the phase distribution dispersion to the influence of the confidence value; for example, it can be 2.

[0077] Convert the computing power processing time difference into a relative time difference. The larger the value, the more the terminal's computing power characteristics match those of a real embedded device. The phase distribution dispersion is converted into relative dispersion difference. The larger, that is, the closer This indicates that the stronger the randomness of the phase distribution, the more it conforms to the characteristics of software. The closer to 1, The smaller. Conversely, The smaller the value, the weaker the randomness of the phase distribution. The closer to 0, The larger.

[0078] Hardware constraint confidence values It is an index that combines computing power characteristics and phase characteristics. The larger the value, the more significant the characteristics of the terminal to be verified, which simultaneously possess reasonable computing power time difference (consistent with the computing power characteristics of real terminal hardware) and low-entropy phase distribution (constrained by the physical grid), and the higher the credibility of it as a real physical device. Conversely, the smaller the value, the greater the possibility that the terminal is a source of software attack.

[0079] Based on the above technical solution, this application can obtain an effective subset of responses from each terminal to be verified by cleaning and removing noisy data. It then extracts physical features in two dimensions: phase distribution dispersion and computing power processing time difference. A fusion algorithm is used to generate hardware constraint confidence values, achieving precise quantification of the terminal's physical characteristics. This solution fully utilizes the fundamental differences in physical constraints between real terminals and software attack sources, effectively distinguishing between them and providing a reliable basis for subsequent access control, further enhancing the security and accuracy of data sharing.

[0080] This application also provides a hardware structure diagram of an edge gateway (denoted as edge gateway 20), see [link to diagram]. Figure 2 The edge gateway 20 includes a processor 21, and optionally, a memory 22 connected to the processor 21.

[0081] In the first possible implementation, see Figure 2 The edge gateway 20 also includes a transceiver 23. The processor 21, memory 22, and transceiver 23 are connected via a bus. The transceiver 23 is used to communicate with other devices or communication networks. Optionally, the transceiver 23 may include a transmitter and a receiver. The device in the transceiver 23 used to implement the receiving function can be considered as a receiver, which is used to perform the receiving steps in the embodiments of this application. The device in the transceiver 23 used to implement the transmitting function can be considered as a transmitter, which is used to perform the transmitting steps in the embodiments of this application.

[0082] Based on the first possible implementation method Figure 2 The structural diagram shown can be used to illustrate the structure of the edge gateway involved in the above embodiments.

[0083] in, Figure 2 This can also be illustrated by the system chip in the edge gateway. In this case, the actions performed by the edge gateway can be implemented by the system chip. For details on the specific actions performed, please refer to the above text, which will not be repeated here.

[0084] In implementation, each step of the method provided in this embodiment can be completed by integrated logic circuits in the processor or by instructions in software form. The steps of the method disclosed in the embodiments of this application can be directly manifested as being executed by a hardware processor, or being executed by a combination of hardware and software modules in the processor.

[0085] It should be noted that the order of the above embodiments of the present invention is merely for descriptive purposes and does not represent the superiority or inferiority of the embodiments. The processes depicted in the accompanying drawings do not necessarily require a specific or sequential order to achieve the desired result. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0086] The various embodiments in this specification are described in a progressive manner. The same or similar parts between the various embodiments can be referred to each other. Each embodiment focuses on describing the differences from other embodiments.

Claims

1. A method for secure information and data sharing based on network security, characterized in that, include: In response to the edge gateway being in a computational congestion state, a downgraded verification mode is triggered to obtain the driver layer arrival record set of each terminal to be verified; The driver layer arrival record set includes the arrival time and instruction type identifier of the response data packet of the corresponding terminal to be verified, captured by the network card driver layer; For each terminal to be verified, a physical feature decoupling analysis is performed based on the driver layer arrival record set of the terminal to be verified to obtain the hardware constraint confidence value of the terminal to be verified; the hardware constraint confidence value is used to characterize the degree of credibility of the terminal to be verified as a real device subject to physical hardware constraints. An admission control strategy is constructed based on the hardware constraint confidence values ​​of each terminal to be verified, and the data sharing access status of each terminal to be verified is configured based on the admission control strategy. For each terminal to be verified, a physical feature decoupling analysis is performed based on the driver layer arrival record set of the terminal to be verified to obtain the hardware constraint confidence value of the terminal to be verified, including: For each terminal to be verified, the driver layer arrival record set of the terminal to be verified is cleaned to obtain a valid response subset; Based on the effective response subset and the power grid AC cycle, the phase distribution dispersion is determined; the phase distribution dispersion is used to characterize the randomness of the distribution of the arrival time of the response data packet on the phase of the power grid AC cycle. Based on the effective response subset, the computing power processing time difference is determined; the computing power processing time difference is used to characterize the time difference in processing different types of probe commands by the terminal to be verified; Based on the phase distribution dispersion and the computing power processing time difference, the hardware constraint confidence value of the terminal to be verified is generated. Based on the effective response subset and the AC cycle of the power grid, the phase distribution dispersion is determined, including: The arrival time of each response data packet in the effective response subset is mapped to a phase space modulo the AC cycle of the power grid, and the sample distribution probability of each phase interval in the phase space is statistically analyzed. The distribution entropy is calculated based on the sample distribution probability of each phase interval in the phase space to obtain the phase distribution dispersion. Based on the aforementioned effective response subset, the computing power processing time difference is calculated, including: The valid response subset is divided into a first response time set and a second response time set according to the instruction type identifier; The computing power processing time difference is determined based on the median of the first set of response times and the median of the second set of response times.

2. The information data secure sharing method according to claim 1, characterized in that, The method further includes: Real-time monitoring of the CPU load rate and network bandwidth utilization of the edge gateway; When the central processing unit load rate is greater than the first threshold and the network bandwidth utilization rate is less than the second threshold, the edge gateway is determined to be in a computational congestion state. The application layer decryption tasks of each session in the pending queue are suspended, and each session in the pending queue is marked as pending verification. The terminal corresponding to each session in the pending queue is designated as the terminal to be verified.

3. The information data secure sharing method according to claim 1, characterized in that, In response to the edge gateway being in a computational congestion state, a downgraded authentication mode is triggered to obtain the driver layer arrival record set for each terminal to be authenticated, including: In response to the edge gateway being in a computational congestion state, a sequence of probe instructions is sent to each terminal to be verified; the sequence of probe instructions includes multiple probe instructions, and the instruction types of the probe instructions include input / output instructions and central processing unit instructions; The packet filtering program at the network card driver layer captures the response data packets of each terminal to be verified, records the arrival time of each response data packet and the corresponding instruction type identifier, and forms a driver layer arrival record set for each terminal to be verified.

4. The information data secure sharing method according to claim 3, characterized in that, In response to the edge gateway being in a state of computational congestion, a sequence of probe commands is sent to each terminal to be verified, including: In response to the edge gateway being in a computational congestion state, a sampling time window is set, the length of which covers multiple AC power cycles of the power grid. Within the sampling time window, for each terminal to be verified, input / output commands and central processing unit commands are sent alternately at random time intervals.

5. The information data secure sharing method according to claim 1, characterized in that, For each terminal to be verified, the driver layer arrival record set of the terminal to be verified is cleaned to obtain a valid response subset, including: For each terminal to be verified, the expected arrival window of the response data packet corresponding to each probe command is determined based on the sending time of each probe command sent to the terminal to be verified and the network jitter benchmark. Based on the expected arrival window of the response data packet corresponding to each probe command, the arrival record set of the driver layer is cleaned to obtain a valid response subset.

6. The information data secure sharing method according to claim 1, characterized in that, An admission control policy is constructed based on the hardware constraint confidence values ​​of each terminal to be verified, and the data sharing access status of each terminal to be verified is configured based on the admission control policy, including: For each terminal to be verified, if the hardware constraint confidence value of the terminal to be verified is greater than or equal to the allow threshold, the terminal to be verified is added to the hardware trust list, and the decryption processing of the service data of the terminal to be verified is resumed, so as to allow the service data of the terminal to be verified to be shared to the upper-layer scheduling system. If the hardware constraint confidence value of the terminal to be verified is less than or equal to the discard threshold, then a rule is configured at the network driver layer to discard the service data of the terminal to be verified. Wherein, the allow threshold is greater than the discard threshold; If the hardware constraint confidence value of the terminal to be verified is less than the allow threshold but greater than the discard threshold, a fault-safe strategy is adopted. The fault-safe strategy includes maintaining the terminal to be verified in the unverified state, not allowing it to pass, waiting for the next round of detection cycle to re-authenticate, or until the session times out and is disconnected.

7. The information data secure sharing method according to claim 6, characterized in that, The method further includes: Continuously monitor the CPU load of the edge gateway; When the CPU load remains below the recovery threshold for a preset period of time, the downgrade verification mode is exited and the hardware trust list is cleared.

Citation Information

Patent Citations

  • Terminal-oriented edge zero-trust engine and authentication protection system and method

    CN117061243A

  • Network admission control method, access point, and access controller

    WO2017049580A1