Edge computing cooperative terminal device security access and data encryption transmission system

By constructing a terminal access authentication unit, an edge node collaborative control unit, and a data encryption transmission unit, the problem of imperfect collaborative management and control architecture in edge computing is solved. This enables full-domain scheduling and control of distributed edge clusters and global core key management, dynamically adjusts security policies, and improves the security and reliability of edge computing.

CN122179189APending Publication Date: 2026-06-09BEIJING GUOKE DATA SECURITY TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
BEIJING GUOKE DATA SECURITY TECHNOLOGY CO LTD
Filing Date
2026-03-17
Publication Date
2026-06-09

AI Technical Summary

Technical Problem

In edge computing, existing technologies suffer from imperfect collaborative management architecture design for edge nodes, making it impossible to achieve full-domain scheduling and management of distributed edge clusters and conflict-free synchronization of management policies. Furthermore, global core key management and global instruction verification are subject to centralized limitations, and there is no dynamic adjustment mechanism for security policies under node collaboration.

Method used

The system constructs a terminal access authentication unit, an edge node collaborative control unit, a data encryption transmission unit, and an edge security monitoring unit. Through two-way identity authentication, distributed edge collaborative cluster construction, threshold secret sharing algorithm, and threshold signature mechanism, it achieves collaborative scheduling and unified management among edge nodes, distributed storage of global control commands, and dynamic adjustment of security policies.

Benefits of technology

It enables collaborative scheduling and unified management among edge nodes, adapts to distributed deployment characteristics, completes distributed security management of global core keys, dynamically adjusts security policies, adapts to abnormal scenarios, and improves the security and reliability of edge computing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122179189A_ABST
    Figure CN122179189A_ABST
Patent Text Reader

Abstract

This invention relates to the field of terminal device security technology, specifically to a secure access and encrypted data transmission system for edge computing collaborative terminal devices. It includes: a terminal access authentication unit; an edge node collaborative control unit; and a data encrypted transmission unit. This invention constructs a distributed edge collaborative cluster, achieving node collaborative management and control through node initialization, point-to-point networking, and heartbeat detection and load balancing scheduling; it assigns exclusive permission identifiers and transmission channels to legitimate terminals, encapsulates management policies as CRDT objects, and achieves conflict-free policy synchronization through a distributed consistency synchronization protocol, adapting to distributed edge computing deployment; it uses a threshold secret sharing algorithm to split and distribute the master private key for storage and verification updates, and combines threshold signatures and Lagrange interpolation algorithms to achieve distributed verification of global control commands; it dynamically adjusts management policies based on monitored anomaly information, realizing distributed secure management of global keys and linked policy adjustments.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of terminal device security technology, and more specifically, to a terminal device secure access and data encryption transmission system for edge computing collaboration. Background Technology

[0002] Edge computing has become the mainstream application architecture due to its distributed architecture. Massive distributed access of terminal devices has become the norm, and the frequency of data interaction between the end and the edge has increased significantly. The security protection requirements for secure access of terminal devices and encrypted data transmission have also become key considerations for the practical application of edge computing technology.

[0003] In existing technologies, relevant patents have researched and explored aspects such as secure access and node collaboration in edge computing. For example, invention patent CN201910155324.5 discloses a node access and node authentication method based on edge computing. This access method includes: receiving an authentication master key and public parameters sent by a key generation server; sending identity identification information to the main edge computing node and the key generation server; receiving partial private key information generated by the key generation server based on the authentication master key, public parameters, and identity identification information; calculating a first public-private key based on the public parameters, identity identification information, and partial private key information, and sending the first public-private key to the main edge computing node; receiving a secret share signed by the main edge computing node based on the first public-private key, and using the secret share as a credential for access authentication. For example, invention patent CN202511723524.8 discloses an abnormal transaction identification method, device, and electronic device based on edge node collaboration. The method includes: receiving an encrypted transaction feature vector transmitted from the base device, generating a transaction request based on the encrypted transaction feature vector, sending the transaction request to multiple neighboring edge nodes, receiving the collaborative verification results of the transaction request from multiple neighboring edge nodes based on a preset consensus algorithm, using a gradient boosting decision tree model to identify abnormal transactions based on the collaborative verification results of all neighboring edge nodes, and executing the transaction request when the transaction identification result indicates that the transaction is a normal transaction, and feeding back the transaction execution result to the base device.

[0004] Despite the design advantages of the above technical solutions, they also have the following technical defects: First, the collaborative management and control architecture of edge nodes is not perfect, failing to achieve full-domain scheduling and control of distributed edge clusters and conflict-free synchronization of management and control policies, and cannot adapt to the core characteristics of distributed deployment of edge computing: Invention patent CN201910155324.5 only relies on the main edge computing node to complete the access authentication of a single node, without building a distributed edge collaborative cluster, without load balancing scheduling and unified management and control mechanism between nodes, and without synchronous design of management and control policies for access permissions and transmission channels; Invention patent CN202511723524.8's edge node collaboration is limited to the request verification stage of abnormal transaction identification, which is a collaborative design for local scenarios, without a full-domain edge node scheduling and control system, and does not involve the synchronization and unified management of various management and control policies. Secondly, the centralized design of global core key management and global command verification suffers from limitations and lacks a dynamic adjustment mechanism for security policies based on node collaboration. Patent CN201910155324.5 relies on a centralized key generation server to manage the authentication master key, without distributing and splitting the core key for storage, and also lacks a distributed verification process for global commands based on node collaboration. Patent CN202511723524.8 lacks a verification design for global control commands; its node collaboration results are only used for transaction identification and judgment, without linkage with security policy adjustments, and cannot dynamically adapt relevant control policies based on scenario anomalies. Therefore, we propose an edge computing collaborative terminal device secure access and data encryption transmission system. Summary of the Invention

[0005] The purpose of this invention is to provide a secure access and encrypted data transmission system for edge computing collaborative terminal devices, in order to solve the problems mentioned in the background art, such as imperfect collaborative management and control architecture design of edge nodes, failure to achieve full-domain scheduling and control of distributed edge clusters and conflict-free synchronization of management and control policies, inability to adapt to the core characteristics of distributed deployment of edge computing, centralized limitations in the management of global core keys and verification of global instructions, and lack of dynamic adjustment mechanism for security policies under node collaboration.

[0006] To address the aforementioned technical problems, the present invention aims to provide a secure access and encrypted data transmission system for edge computing collaborative terminal devices, comprising: The terminal access authentication unit performs two-way identity authentication on the terminal device, binds the unique hardware identifier of the terminal device with the identity authentication credential, completes the legality verification of the terminal device, and synchronizes the legal terminal information that has passed the verification to the edge node collaborative control unit. An edge node collaborative control unit constructs a distributed edge collaborative cluster to achieve collaborative scheduling and unified management among edge nodes. Based on the legitimate terminal information synchronized by the terminal access authentication unit, the edge node collaborative control unit allocates corresponding terminal access permissions and data transmission channels. It encapsulates the access permission and data transmission channel management policies into conflict-free replication data type CRDT objects, and uses a distributed consistency synchronization protocol to achieve conflict-free merging and state synchronization of policy copies across edge nodes. The edge node collaborative control unit uses a threshold secret sharing algorithm to split the global control instruction master private key into multiple fragment private keys, which are distributed and stored in the secure storage area of ​​the trusted execution environment of each edge node. It also performs validity verification and dynamic updates of the fragment private keys according to preset conditions. The edge node collaborative control unit uses a threshold signature mechanism to perform distributed verification of the global control instruction. Upon successful verification, the instruction execution permission is unlocked and distributed to each edge node. Simultaneously, based on the abnormal information reported by the edge security monitoring unit, the edge node collaborative control unit adjusts the terminal access permission and data transmission channel management policies. The data encryption transmission unit performs encryption processing and integrity verification on the data transmitted between the terminal device and the edge node, and between the edge nodes, based on the data transmission channel and control strategy allocated by the edge node collaborative control unit. The edge security monitoring unit monitors terminal access behavior and data transmission traffic in accordance with the terminal access permissions and data transmission channel control policies of the edge node collaborative control unit, and reports abnormal access and abnormal transmission behavior information to the edge node collaborative control unit.

[0007] As a further improvement to this technical solution, the terminal access authentication unit includes an identity information collection module, a two-way authentication module, a hardware identifier binding module, a legitimacy verification module, and a legitimacy information synchronization module, wherein: The identity information collection module collects the identity authentication credentials of the terminal device; The two-way identity verification module performs two-way identity authentication on the terminal device; The hardware identifier binding module binds the unique hardware identifier of the terminal device with the identity authentication credential; The legitimacy verification module performs legitimacy verification on terminal devices that have completed binding and two-way identity authentication; The legitimate information synchronization module synchronizes the verified legitimate terminal information to the edge node collaborative control unit.

[0008] As a further improvement to this technical solution, the edge node collaborative control unit includes a cluster construction and scheduling management module, a channel permission allocation and synchronization module, a master private key shard storage module, a shard private key verification and update module, a global command distributed verification module, and an anomaly linkage strategy adjustment module, wherein: The cluster construction and scheduling management module constructs a distributed edge collaborative cluster to achieve collaborative scheduling and unified management among edge nodes. The channel permission allocation and synchronization module allocates terminal access permissions and data transmission channels according to the legitimate terminal information, and encapsulates and synchronizes access permission and data transmission channel management strategies. The master private key fragment storage module splits and distributes the fragmented private keys of the global control instruction master private key; The fragment private key verification and update module completes the validity verification and dynamic update of the fragment private key; The global command distributed verification module completes the distributed verification of global control commands, permission unlocking, and command issuance; The abnormal linkage strategy adjustment module adjusts the terminal access permissions and data transmission channel control strategies based on abnormal information.

[0009] As a further improvement to this technical solution, the cluster construction and scheduling management module includes a node initialization submodule, a cluster networking submodule, a node status acquisition submodule, and a load balancing scheduling submodule, wherein: The node initialization submodule assigns a unique node identifier generated based on a hardware unique identifier to each edge node in the cluster, and completes the initialization configuration of the network communication parameters and computing resource baseline parameters of the edge nodes. The cluster networking submodule establishes point-to-point communication links between edge nodes based on a distributed node discovery protocol, and constructs a distributed edge collaborative cluster. The node status acquisition submodule collects real-time operational status data of each edge node, including CPU utilization, memory usage, and network bandwidth utilization, through a fixed-period heartbeat detection mechanism. The load balancing scheduling submodule coordinates terminal access requests based on the running status data collected by the node status acquisition submodule, thereby achieving unified management and load balancing of edge nodes within the cluster.

[0010] As a further improvement to this technical solution, the channel permission allocation and synchronization module includes a permission channel allocation submodule, a CRDT policy encapsulation submodule, and a distributed policy synchronization submodule, wherein: The permission channel allocation submodule allocates an access permission identifier generated based on the hash of the unique identifier of the terminal device hardware to each legitimate terminal according to the legitimate terminal information synchronized by the terminal access authentication unit, as well as a dedicated data transmission channel. The CRDT policy encapsulation submodule encapsulates the access permission identifier generated by the permission channel allocation submodule and the control policy corresponding to the dedicated data transmission channel into a conflict-free replication data type policy object; The distributed policy synchronization submodule is based on a distributed consistency synchronization protocol, which synchronizes conflict-free replicated data type policy objects to all edge nodes in the cluster, thereby achieving conflict-free merging and state synchronization of local policy replicas on each edge node.

[0011] As a further improvement to this technical solution, the process of splitting and distributing the global control instruction master private key using the threshold secret sharing algorithm in the master private key fragment storage module includes the following steps: S23.1 Define the global control command master private key Select a cryptographic standard finite field and set the unlock master private key. The minimum number of fragmented private keys required is a threshold value. ,in , This represents the total number of edge nodes in the distributed edge collaboration cluster. S23.2, Based on the master private key Constructing a secret shared polynomial This polynomial is uniquely indexed at each edge node. The calculation result at that point is used to determine the sharding private key of the corresponding edge node. ,in ; S23.3, Transfer the fragmented private key and corresponding edge node index Bind them and write them to the trusted execution environment secure storage area of ​​each edge node.

[0012] As a further improvement to this technical solution, the process of the fragmented private key verification and dynamic update module performing fragmented private key validity verification and dynamic update includes the following steps: S24.1 Calculate the fragmented private key using a cryptographic hash algorithm. hash value ,Will With fragmented private keys The baseline hash value is synchronized and pre-stored when stored in the secure storage area of ​​the trusted execution environment. Perform a comparison to complete the fragmented private key. Validation of effectiveness; S24.2, Verify the validity of the fragmented private key. Without reconstructing the global control command master private key Under the premise of secure storage area in trusted execution environment of edge nodes, cryptographically secure random numbers are generated. , and the original shard private key Perform an XOR operation to generate a new fragment private key. ; S24.3 Calculate the new fragment private key using a cryptographic hash algorithm. hash value The pre-stored base hash value Updated to This completes the dynamic update of the fragmented private key.

[0013] As a further improvement to this technical solution, the global instruction distributed verification module uses a threshold signature mechanism to complete the distributed verification and execution of global control instructions, including the following steps: S25.1 Calculate global control commands using a cryptographic hash algorithm. hash value to the holder of the fragment private key Or new shard private key Edge nodes send hash values ; S25.2, Each edge node receives the hash value Subsequently, based on the fragmented private key stored in the secure storage area of ​​the trusted execution environment of this node... Or new shard private key Public-key cryptography algorithm is used to generate fragmented signatures. And return; S25.3 Collect valid fragment signatures returned by edge nodes When a valid fragment signature The number reaches the threshold At that time, the complete signature was reconstructed using the Lagrange interpolation algorithm. ; S25.4, Using the master private key of the global control command The paired public key is for the complete signature. Verification will be performed; once verification is successful, global control commands will be unlocked. Grant execution permissions and grant global control commands It is distributed to all edge nodes within the distributed edge collaboration cluster.

[0014] As a further improvement to this technical solution, the data encryption transmission unit includes a data encryption module, a data integrity verification module, and a transmission adaptation module, wherein: The transmission adaptation module adapts the data transmission links between the terminal device and the edge node, and between the edge nodes, based on the data transmission channels and management strategies allocated by the edge node collaborative control unit. The data encryption module performs encryption processing on the data transmitted between the terminal device and the edge node, and between the edge nodes, based on the data transmission channel and control strategy allocated by the edge node collaborative control unit. The data transmission integrity verification module performs integrity verification on the data transmission between the terminal device and the edge node, and between the edge nodes, based on the data transmission channel and control strategy allocated by the edge node collaborative control unit.

[0015] As a further improvement to this technical solution, the edge security monitoring unit includes a security policy acquisition module, an access behavior monitoring module, a transmission traffic monitoring module, and an abnormal information reporting module, wherein: The security policy acquisition module acquires the terminal access permissions and data transmission channel control policies of the edge node collaborative control unit; The access behavior monitoring module monitors terminal access behavior according to the terminal access permission and data transmission channel control policy; The transmission traffic monitoring module monitors the data transmission traffic according to the terminal access permissions and data transmission channel control policy; The abnormal information reporting module reports the detected abnormal access and abnormal transmission behavior information to the edge node collaborative control unit.

[0016] Compared with the prior art, the beneficial effects of the present invention are as follows: 1. This invention constructs a distributed edge collaborative cluster, completes the initial configuration of edge nodes and the establishment of point-to-point communication links, collects node operating status through a heartbeat detection mechanism and implements load balancing scheduling to achieve collaborative scheduling and unified management among edge nodes; at the same time, it assigns exclusive access permission identifiers and data transmission channels to legitimate terminals, encapsulates management policies into conflict-free replication data type CRDT objects, and completes conflict-free merging and state synchronization of policy replicas of each edge node through a distributed consistency synchronization protocol, adapting to the distributed deployment characteristics of edge computing; 2. This invention employs a threshold secret sharing algorithm to split the global control command master private key into fragmented private keys, which are then distributed and stored in the secure storage area of ​​the trusted execution environment of each edge node. This completes the validity verification and dynamic update of the fragmented private keys, achieving distributed secure management of the global core key. Simultaneously, a threshold signature mechanism combined with the Lagrange interpolation algorithm is used to complete the distributed verification of the global control command. After successful verification, the command is unlocked and issued, achieving node collaborative verification of the global control command. Furthermore, based on the abnormal access and abnormal transmission behavior information reported by the edge security monitoring unit, the terminal access permissions and data transmission channel control strategies are dynamically adjusted, achieving linkage adjustment between security policies and edge node monitoring results. Attached Figure Description

[0017] Figure 1 This is a schematic diagram of the system framework of the present invention; The meanings of the labels in the diagram are as follows: 1. Terminal access authentication unit; 11. Identity information collection module; 12. Two-way identity verification module; 13. Hardware identifier binding module; 14. Legality verification module; 15. Legal information synchronization module; 2. Edge node collaborative control unit; 21. Cluster construction and scheduling management module; 22. Channel permission allocation and synchronization module; 23. Master private key sharded storage module; 24. Shard private key verification and update module; 25. Global command distributed verification module; 26. Anomaly linkage strategy adjustment module; 3. Data encryption transmission unit; 31. Data encryption module; 32. Transmitted data integrity verification module; 33. Transmission adaptation module; 4. Edge security monitoring unit; 41. Security policy acquisition module; 42. Access behavior monitoring module; 43. Transmission traffic monitoring module; 44. Abnormal information reporting module. Detailed Implementation

[0018] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention.

[0019] like Figure 1 As shown, this embodiment provides a secure access and encrypted data transmission system for edge computing collaborative terminal devices, including: Terminal access authentication unit 1 performs two-way identity authentication on terminal devices, binds the unique hardware identifier of the terminal device with the identity authentication credential, completes the legality verification of the terminal device, and synchronizes the legally verified terminal information to the edge node collaborative control unit 2; terminal access authentication unit 1 includes an identity information collection module 11, a two-way identity verification module 12, a hardware identifier binding module 13, a legality verification module 14, and a legal information synchronization module 15, wherein: In this embodiment, the identity information collection module 11 collects the identity authentication credentials of the terminal device. The collection process adopts a dual approach of hardware-level reading and software-level verification to prevent the collected information from being tampered with by the software layer. The specific operation is as follows: The data collected includes: 1) the authentication credentials of the terminal device, including the digital certificate pre-configured by the terminal that conforms to cryptographic standards, the device-specific access symmetric key, and the terminal access authorization token granted by the user; 2) the unique hardware identifier of the terminal device, which is selected as a fixed, tamper-proof, and globally unique hardware feature identifier in the terminal device, specifically including the device MAC address, CPU serial number, and motherboard unique factory identifier. These identifiers are all stored in the terminal hardware registers and cannot be modified by software. Data acquisition implementation: The hardware unique identifier in the terminal hardware register is read directly through the hardware driver layer interface, and the pre-configured identity authentication credentials are extracted through the terminal secure communication interface. During the acquisition process, the format of each type of information is checked to ensure that the information is in a compliant original data format without any missing or garbled characters. Data output: The collected hardware unique identifier and identity authentication credential are integrated, packaged into a unified format identity information data packet, and after adding a data collection timestamp and format verification code, it is transmitted to the two-way identity verification module 12.

[0020] In this embodiment, the two-way authentication module 12 performs two-way authentication on the terminal device, enabling two-way identity verification between the terminal device and the terminal access authentication unit 1, and between the terminal access authentication unit 1 and the terminal device. This avoids security vulnerabilities such as counterfeit authentication terminals and terminal identity hijacking that exist in the one-way authentication mode, and provides the hardware identifier binding module 13 with verified and compliant identity information. The specific implementation is as follows: Based on the Public Key Infrastructure (PKI) system, two-way authentication is carried out. First, the identity information data packet transmitted by the identity information collection module 11 is received. The terminal digital certificate is extracted and its validity is verified in sequence, including the legality of the certificate signature, whether the certificate validity period is within the preset valid range, and whether the certificate is not revoked. After the terminal digital certificate is verified, the two-way authentication module 12 generates a random cryptographic challenge code, encrypts it with the terminal public key, and sends it to the terminal device. After receiving it, the terminal device signs the challenge code with its own private key and returns it. The two-way authentication module 12 verifies the validity of the challenge code signature with the terminal public key, thus completing the authentication of the terminal device. Subsequently, in response to the authentication request initiated by the terminal device, the two-way authentication module 12 sends its own valid digital certificate and a random cryptographic challenge code to the terminal device. After the terminal device completes the validity verification of the digital certificate of the terminal access authentication unit 1, it verifies the signature of the challenge code through the public key of the terminal access authentication unit 1, thus completing the authentication of the terminal device's access authentication unit 1. After both-way authentications are successful, the identity information data packet with the verification success identifier is transmitted to the hardware identifier binding module 13. If the verification in either direction fails, the access request of the terminal is directly rejected, and the verification failure log is recorded in real time. The log content includes terminal abnormal information, specific reasons for verification failure, and operation timestamp.

[0021] In this embodiment, the hardware identifier binding module 13 binds the unique hardware identifier of the terminal device with the identity authentication credential. This is used to achieve a strong association between the physical hardware identity of the terminal device and the digital identity credential, ensuring that the two form a unique one-to-one relationship and eliminating the security risk of identity authentication credential being reused across devices. This provides the legality verification module 14 with the terminal identity information after binding. The specific implementation is as follows: The system receives the verified identity information data packet transmitted by the two-way authentication module 12, accurately extracts the unique hardware identifier and authentication credential of the terminal device, and performs a joint hash operation on the unique hardware identifier using the SHA-256 cryptographic hash algorithm to generate a fixed-length unique hardware hash value. This hash processing avoids the risk of information leakage caused by storing the original hardware identifier in plaintext. A one-to-one binding relationship between the unique hardware hash value and the authentication credential is established, and an anti-tampering timestamp and a digital signature of the terminal access authentication unit 1 are added to this binding relationship. The binding relationship is temporarily stored in the local trusted storage area of ​​the terminal access authentication unit 1, and the binding information data packet containing the unique hardware hash value, authentication credential, and binding relationship identifier is transmitted to the legality verification module 14.

[0022] In this embodiment, the legitimacy verification module 14 performs legitimacy verification on the terminal device that has completed binding and two-way identity authentication. It is used to conduct a multi-dimensional comprehensive review of the terminal identity information that has completed the binding of hardware identifier and identity credential, accurately determine the access legitimacy of the terminal device, and provide compliant and valid legitimate terminal information to the legitimate information synchronization module 15. The specific implementation is as follows: Receive the binding information data packet transmitted by the hardware identifier binding module 13, and extract the hardware unique hash value, identity authentication credential and binding relationship identifier from it; Simultaneously, a comprehensive legality verification is conducted according to preset verification rules, encompassing three dimensions: First, a uniqueness verification of the binding relationship is performed, checking whether the same hardware unique hash value or identity authentication credential exists in the local trusted storage area of ​​the terminal access authentication unit 1, to prevent duplicate binding and identity credential misuse; second, a secondary verification of the validity of the identity authentication credential is performed, re-checking the validity period of the digital certificate, the matching of the access symmetric key with the terminal device, and the scope and current validity of the access authorization token; third, a completeness verification of the binding information is performed, confirming that the binding information data packet has no missing information fields or tampering traces, and verifying the matching of the hash value with the original hardware unique identifier; after all three dimensions of verification pass, the terminal device is determined to be a legitimate access terminal, and a legitimate terminal information data packet containing basic terminal device information, hardware unique hash value, identity authentication credential summary, and access permission application identifier is generated and transmitted to the legitimate information synchronization module 15. Furthermore, if any dimension of the verification fails, the terminal is directly identified as an illegal terminal, its access request is rejected, and an illegal access log is recorded in real time. The log includes terminal abnormal information, the specific reason for the verification failure, the operation timestamp, and the subsequent authentication process is immediately terminated.

[0023] In this embodiment, the legitimate information synchronization module 15 synchronizes the verified legitimate terminal information to the edge node collaborative control unit 2. This enables secure and conflict-free distributed synchronization of legitimate terminal information to the edge node collaborative control unit 2, ensuring that all edge nodes of the edge node collaborative control unit 2 can obtain consistent legitimate terminal information. This provides a unified and accurate basis for the edge node collaborative control unit 2 to allocate terminal access permissions and configure dedicated data transmission channels. The specific implementation is as follows: The system receives legitimate terminal information data packets transmitted by the legitimacy verification module 14 and, strictly following the distributed data synchronization specifications of the edge node collaborative control unit 2, standardizes and simplifies the data packets, retaining only core information such as the terminal's legitimate identifier, unique hardware hash value, identity authentication credential digest, and access permission application identifier. This reduces the amount of synchronized data while ensuring the integrity of the identity information, thereby improving the information synchronization efficiency in distributed scenarios. Furthermore, it uses the same encryption algorithm as the edge node collaborative control unit 2 to encrypt the encapsulated legitimate terminal information, preventing the information from being stolen or tampered with during transmission. Meanwhile, based on the distributed consistency synchronization protocol, the encrypted legitimate terminal information is synchronized to the local trusted storage area of ​​all edge nodes in the edge node collaborative control unit 2, ensuring that the legitimate terminal information copies of each edge node are conflict-free and completely consistent in state; Finally, after completing the information synchronization with all edge nodes, a synchronization completion receipt is generated. The receipt includes the number of synchronized nodes, the synchronization completion time, and the information verification code. The receipt is temporarily stored in the local trusted storage area of ​​the terminal access authentication unit 1 to achieve full-link traceability of the legitimate terminal information synchronization process.

[0024] Edge Node Collaborative Control Unit 2 constructs a distributed edge collaborative cluster to achieve collaborative scheduling and unified management among edge nodes. Based on the legitimate terminal information synchronized by Terminal Access Authentication Unit 1, Edge Node Collaborative Control Unit 2 allocates corresponding terminal access permissions and data transmission channels. It encapsulates access permission and data transmission channel management policies into conflict-free replication data type CRDT objects, and uses a distributed consistency synchronization protocol to achieve conflict-free merging and state synchronization of policy copies across edge nodes. Edge Node Collaborative Control Unit 2 uses a threshold secret sharing algorithm to split the global control command master private key into multiple fragmented private keys, which are distributed and stored in the secure storage area of ​​the trusted execution environment of each edge node. It also performs validity verification and dynamic updates of the fragmented private keys according to preset conditions. Edge Node Collaborative Control Unit 2 uses a threshold signature mechanism to complete distributed verification of global control commands. Upon successful verification, the command execution permission is unlocked and distributed to each edge node. Simultaneously, it monitors the abnormal information reported by Edge Security Monitoring Unit 4. The edge node collaborative control unit 2 is the core control hub of the entire edge computing collaborative terminal device secure access and data encryption transmission system. It coordinates the construction and scheduling of distributed edge collaborative clusters, the precise allocation of access permissions and data transmission channels for legitimate terminals, the conflict-free distributed synchronization of control policies, the secure distributed management of global keys, the trusted verification of global control commands, and the dynamic policy adjustment in abnormal scenarios. Vertically, it connects the terminal access authentication unit 1, the data encryption transmission unit 3, and the edge security monitoring unit 4. Horizontally, it realizes the collaborative linkage and unified control of various edge nodes. All functions are designed based on the characteristics of heterogeneous, nearby deployment, low-latency interaction, and distributed operation of edge computing nodes. All configuration parameters, execution operations, and status data are stored in real time in its own global trusted control library, realizing full-process traceability, verification, and rollback, providing core control support for the stable operation, efficient collaboration, and full-link security protection of the entire system. The edge node collaborative control unit 2 includes a cluster construction and scheduling management module 21, a channel permission allocation and synchronization module 22, a master private key shard storage module 23, a shard private key verification and update module 24, a global command distributed verification module 25, and an anomaly linkage strategy adjustment module 26, wherein: In this embodiment, the cluster construction and scheduling control module 21 constructs a distributed edge collaborative cluster to achieve collaborative scheduling and unified management among edge nodes. The cluster construction and scheduling control module 21 includes a node initialization submodule, a cluster networking submodule, a node status acquisition submodule, and a load balancing scheduling submodule, wherein: The node initialization submodule assigns a unique node identifier, generated based on a hardware-unique identifier, to each edge node within the cluster. It also initializes and configures the network communication parameters and computing resource baseline parameters of the edge nodes, achieving standardized and normalized initialization of all edge nodes within the cluster. This lays a unified configuration foundation for subsequent cluster networking and unified management. Hardware-level unique node identifier allocation avoids node identity conflicts, and standardized parameter configuration ensures communication compatibility and quantifiable resource management across edge nodes. All initialization operations are completed within a trusted execution environment on the edge nodes, preventing configuration information from being tampered with. The specific implementation is as follows: Unique Node Identifier Generation: Extract three types of immutable hardware unique identifiers from the edge node: the motherboard's unique factory identifier, the network card's physical MAC address, and the CPU serial number, all permanently stored in the hardware registers. Use the SHA-256 cryptographic hash algorithm to perform a joint hash operation on these three hardware identifiers, generating a 256-bit fixed-length unique node identifier. This identifier is globally unique and serves as the unique identity of the edge node within the distributed edge collaboration cluster; it cannot be tampered with, copied, or forged. After generation, the unique node identifier is bound to the hash digest of the original hardware identifier and stored in the edge node's trusted execution environment secure storage area.

[0025] Basic parameter initialization is categorized into two types: network communication parameters and computing resource baseline parameters. Standardized initialization configuration of edge nodes is completed. All parameters are customized based on the actual hardware configuration of the edge nodes and the actual needs of edge computing services. After configuration, they are stored via hardware-level write and cannot be arbitrarily modified at the software layer. Network communication parameters include the node's static network IP address, dedicated point-to-point communication port, standard data transmission protocol (TCP / IP), maximum data transmission packet length, data retransmission threshold, communication timeout, and multicast discovery address. Computing resource baseline parameters include the number of CPU cores, total physical memory capacity, virtual memory activation threshold, network bandwidth uplink / downlink baseline threshold, disk I / O read / write baseline threshold, and computing resource occupancy warning threshold.

[0026] Full initialization verification: Dual verification is performed on edge nodes that have completed node identifier allocation and parameter initialization. First, the uniqueness of node identifiers is verified by checking whether there are identical node identifiers in the global trusted management library to avoid duplication. Second, the validity of configuration parameters is verified by checking the compliance of network communication parameters and the matching of computing resource baseline parameters with the actual hardware configuration to ensure that the parameters are error-free and complete.

[0027] Verification result feedback and receipt synchronization: For edge nodes that pass verification, a node initialization completion receipt is generated. The receipt includes a unique node identifier, a hash digest of the original hardware identifier, a network communication parameter configuration table, a computing resource baseline parameter configuration table, and an initialization completion timestamp. The receipt is encrypted after being digitally signed by the edge node and synchronized to the cluster scheduling sub-library of the global trusted management library of the edge node collaborative control unit 2. For edge nodes that fail verification, the specific reason for the verification failure is fed back in real time (such as duplicate node identifier, parameter mismatch with hardware, etc.), and a re-initialization process is triggered until the verification passes.

[0028] The cluster networking submodule, based on a distributed node discovery protocol, establishes point-to-point communication links between edge nodes, constructs a distributed edge collaborative cluster, and achieves decentralized networking among edge nodes after initialization. It uses a standardized distributed node discovery protocol to quickly discover and verify the identity of neighboring nodes, and uses encrypted point-to-point communication links to achieve secure communication between nodes. Ultimately, it forms a dynamically scalable, link-monitorable, and topology-synchronizable distributed edge collaborative cluster, adapting to the characteristics of distributed edge node deployment. The specific implementation is as follows: Node discovery protocol loading and configuration: Send networking instructions to all edge nodes that have passed initialization verification. Each edge node automatically loads the Gossip distributed node discovery protocol (a decentralized node discovery protocol specifically for edge computing scenarios) and uniformly configures the core node discovery parameters, including multicast sending address, multicast listening port, node discovery message sending period (default 5 seconds), maximum number of adjacent node connections, and message signature verification rules.

[0029] Node discovery message interaction and identity verification: Each edge node sends a node discovery message to a designated multicast address at a preset period. This node discovery message contains its own unique node identifier, static IP address, dedicated point-to-point communication port, hardware configuration summary, initialization completion timestamp, and the message is accompanied by the edge node's own digital signature to ensure that the message is not tampered with during transmission. After receiving the discovery message sent by the neighboring node, the edge node first verifies the legality of the message's digital signature. After the signature verification is successful, it checks whether the node identifier in the message has been registered in the local node information table. If not registered, it extracts the neighboring node's core information for temporary storage and returns a node confirmation message (also containing its own core information and digital signature) to the neighboring node, completing the two-way identity verification.

[0030] Encrypted point-to-point communication link establishment: After the two-way message confirmation is completed between adjacent nodes, a TLS1.3 encrypted point-to-point communication link is established based on the TCP / IP protocol. The link is encrypted using an asymmetric encryption algorithm to ensure the confidentiality and integrity of all communication data between nodes. After the link is established, the link communication status is detected in real time, a link status identifier (connected / disconnected) is generated, and synchronized to the local node information table.

[0031] Decentralized distributed cluster construction: Once all initialized edge nodes in the network have completed neighbor node discovery, two-way identity verification, and the establishment of encrypted point-to-point communication links, a decentralized distributed edge collaboration cluster is automatically formed. The cluster has no central node, and each edge node has equal status, enabling it to independently complete local operations and collaborate with neighboring nodes.

[0032] Cluster topology generation and real-time synchronization: The cluster networking submodule integrates information such as the identifier, network location, link relationship, and link status of all nodes based on the local node information tables of each edge node to generate a global cluster node topology map. The topology map is encrypted and synchronized to the secure storage area of ​​the trusted execution environment of all edge nodes in the cluster, and is also stored in the cluster scheduling sub-library of the global trusted management library. When nodes are added, taken offline, or fail in the cluster, the local node information tables of each node will be updated in real time, triggering a dynamic refresh of the global cluster node topology map to ensure that the topology information of all nodes in the cluster is highly consistent.

[0033] The node status acquisition submodule uses a fixed-period heartbeat detection mechanism to collect real-time operational status data such as CPU utilization, memory usage, and network bandwidth utilization of each edge node. This submodule acts as the "state-aware nerve" of the distributed edge collaborative cluster. Through a standardized heartbeat detection mechanism, it achieves real-time, accurate, and continuous collection of the core operational status of all edge nodes within the cluster. Data cleaning and smoothing ensure the accuracy of the status data, and threshold monitoring provides timely warnings of abnormal node states. This provides the subsequent load balancing scheduling submodule with accurate and effective node load data. The specific implementation is as follows: Heartbeat detection global parameter configuration: The node status acquisition submodule sends unified heartbeat detection configuration parameters to all edge nodes in the cluster. All parameters can be flexibly adjusted according to the cluster size and business needs. These parameters include the fixed period for sending heartbeat packets (default 10 seconds), the timeout period for receiving heartbeat packets (set to 1.5 times the heartbeat period), the threshold for the number of consecutive abnormal heartbeats (default 3 times), the heartbeat packet data format specification, and digital signature requirements. The configuration parameters are synchronized to the trusted execution environment of each edge node.

[0034] Standardized heartbeat generation and transmission: Each edge node collects its own core operating status data in the local trusted execution environment at a preset fixed period to generate a standardized heartbeat packet. The heartbeat packet contains a unique node identifier, the current instantaneous CPU utilization rate, the CPU average utilization rate over 5 minutes, the real-time physical memory utilization rate, the virtual memory enable status and utilization rate, the real-time uplink / downlink utilization rate of network bandwidth, the communication status of all point-to-point links, and the heartbeat packet generation timestamp. After the heartbeat packet is generated, an edge node digital signature is added, and it is sent to the node status collection submodule in real time through an encrypted point-to-point communication link.

[0035] Heartbeat Packet Verification and Data Cleaning: The node status acquisition submodule receives heartbeat packets from each edge node in real time. First, it performs dual validity verification: verifying the legality of the digital signature of the heartbeat packet and verifying the validity of the node identifier. Heartbeat packets with invalid signatures or non-existent node identifiers are directly discarded. For heartbeat packets that pass verification, the running status data is extracted and data cleaning and smoothing are performed. Abnormal extreme value data caused by network jitter and instantaneous hardware fluctuations are removed. The moving average method is used to smooth the same type of data for three consecutive heartbeat cycles to eliminate data fluctuations and ensure the accuracy and stability of the status data.

[0036] Status data classification, storage, and traceability: The cleaned and valid operational status data is classified and organized according to unique node identifiers, and written to the node status data table of the cluster scheduling sub-database of the global trusted management and control library in real time. The data table is updated incrementally according to timestamps, and the full amount of node status data for the most recent 7 days is automatically retained. It supports precise retrieval and historical data traceability by node identifier, time range, and indicator type.

[0037] Node status threshold monitoring and anomaly early warning: Real-time threshold monitoring of stored node status data is performed. For three core indicators, such as CPU 5-minute average utilization, physical memory real-time utilization, and network bandwidth average utilization, preset early warning thresholds are set (default 80%). When any core indicator of a node exceeds the early warning threshold for three consecutive heartbeat cycles, or when a state such as continuous heartbeat packet timeout or link disconnection occurs, node status anomaly early warning information is immediately generated. The early warning information includes node identifier, abnormal indicator type, abnormal value, and abnormal occurrence timestamp. It is synchronized to the load balancing scheduling submodule and the global trusted management library to achieve real-time perception and early warning of node status.

[0038] The load balancing scheduling submodule coordinates terminal access requests based on the operational status data collected by the node status acquisition submodule. This enables unified management and load balancing of edge nodes within the cluster, achieving optimal allocation of computing and network resources for edge nodes. It avoids single-node overload or resource idleness, ensuring low-latency response to terminal access requests. Simultaneously, it achieves unified management and high availability of cluster nodes. All scheduling operations follow preset rules, and scheduling results are fully synchronized and traceable. The specific implementation is as follows: Core load metric extraction and normalization: From the node status data table of the global trusted management and control library, three types of core load metrics are extracted in real time: CPU 5-minute average utilization, physical memory real-time utilization, and network bandwidth average utilization (arithmetic mean of uplink and downlink utilization) for each edge node. Simultaneously, the three types of indicators are normalized, mapping the actual values ​​of each indicator to the [0,1] interval, eliminating the differences in indicator dimensions, and providing a unified quantitative basis for the calculation of the comprehensive load value. The normalization calculation formula is as follows: ; In the formula: This represents the normalized value of the index, with a range of [0,1]. This indicates the actual value collected for the indicator; This indicates the preset minimum threshold for this indicator (default 0). This indicates the preset maximum threshold for this indicator (default 100%).

[0039] Quantitative calculation of node comprehensive load value: Differentiated load weights are assigned to the three normalized core load metrics. The weights are set based on the resource requirements of edge computing services, with CPU utilization as the default weight. Physical memory usage weight Average network bandwidth utilization weight All weights sum to 1 and can be flexibly adjusted according to business type; the comprehensive load value of each edge node is calculated using a weighted summation algorithm, and the calculation formula is as follows: ; In the formula: Indicates the first The combined load value of each edge node, with a value range of [0,1]; Indicates the first Normalized value of CPU utilization of each edge node; Indicates the first The normalized value of memory usage of each edge node; Indicates the first The normalized value of bandwidth utilization of each edge node.

[0040] The lower the overall load value, the higher the node's idle time, and the more terminal access requests it can handle.

[0041] Legitimate Terminal Access Request Parsing and Validity Verification: Receive legitimate terminal access requests synchronized by Terminal Access Authentication Unit 1 in real time, parse the core information in the request, including the legitimate terminal identifier, hardware unique identifier hash value, access service type, data transmission bandwidth, and computing resource requirements; simultaneously verify the validity of the legitimate terminal identifier in the request, check whether the identifier has been registered in the global trusted management database, directly reject invalid identifiers and forged requests, and record the rejection reason, request information, and timestamp in the scheduling anomaly log.

[0042] Weighted round-robin algorithm for precise load balancing scheduling: Based on the comprehensive load value of each edge node, a weighted round-robin load balancing scheduling algorithm is used to allocate access requests. The core scheduling rule is: access requests are preferentially allocated to the edge node with the lowest comprehensive load value; if multiple nodes have the same comprehensive load value, they are sorted a second time according to their hardware performance (number of CPU cores, total physical memory capacity), and the node with better performance is given priority; if the terminal access request has specific bandwidth and computing resource requirements, the scheduling will match the node with the resource capacity to meet the requirements, ensuring that the node resources are adapted to the terminal service requirements.

[0043] End-to-end synchronization and implementation of scheduling results: After scheduling is completed, a standardized scheduling result package is generated, which includes the terminal's legal identifier, the unique identifier of the allocated edge node, the scheduling timestamp, the node's current comprehensive load value, the terminal access resource allocation threshold (bandwidth, computing), and the terminal access permission range. After the result package is digitally signed by the edge node collaborative control unit 2, it is encrypted and synchronized to the allocated edge node and the terminal access authentication unit 1. At the same time, the allocated edge node is triggered to reserve the corresponding resources to complete the implementation of the scheduling instructions.

[0044] Dynamic management and fault tolerance of cluster nodes: Real-time dynamic management and control are implemented for all edge nodes in the cluster. A comprehensive load overload threshold is set (default 0.9). When the comprehensive load value of a node exceeds the threshold for three consecutive heartbeat cycles, the allocation of new terminal access requests to it is suspended until the load value falls back below the threshold. If a node experiences abnormal states such as heartbeat packet timeout, link disconnection, or hardware failure, it is immediately marked as unavailable, removed from the scheduling node pool, and no access requests are allocated. The abnormal information is also synchronized to the global trusted management and control library. When the abnormal node recovers and completes the status verification, the unavailable state is automatically removed, and it is reinstated into the scheduling node pool, thus achieving fault tolerance and high availability of the cluster.

[0045] Standardized Management and Data Support for Scheduling Logs: A standardized scheduling log table is established in the cluster scheduling sub-library of the global trusted management and control library. This table records all scheduling information for all terminal access requests in real time, including request reception time, terminal legal identifier, access service type, allocation node identifier, scheduling result, node load status during scheduling, and log generation timestamp. The log table supports multi-dimensional retrieval and querying by terminal identifier, node identifier, time range, and service type. It automatically retains scheduling logs for the most recent 30 days, providing accurate and comprehensive data support for cluster scheduling strategy optimization, node operation status analysis, and fault diagnosis.

[0046] In this embodiment, the channel permission allocation and synchronization module 22 allocates terminal access permissions and data transmission channels according to legitimate terminal information, and encapsulates and synchronizes access permission and data transmission channel control policies; the channel permission allocation and synchronization module 22 includes a permission channel allocation submodule, a CRDT policy encapsulation submodule, and a distributed policy synchronization submodule, wherein: The permission channel allocation submodule, based on the legitimate terminal information synchronized by the terminal access authentication unit 1, assigns an access permission identifier generated from the hash of the terminal device's unique hardware identifier, and a dedicated data transmission channel to each legitimate terminal. This achieves a precise one-to-one allocation of legitimate terminal access permissions and data transmission channels. The access permission identifier generated from the hash of the unique hardware identifier strongly binds the terminal's physical identity to its digital access permissions. The dedicated virtual data transmission channel isolates and controls terminal communication, preventing permission misuse and channel misuse, and ensuring the controllability of terminal access and data transmission. The specific implementation is as follows: Receiving and verifying legitimate terminal information: Receive legitimate terminal information packets synchronized by terminal access authentication unit 1 in real time, extract core content such as the unique identifier hash value of the terminal hardware, basic terminal information, and legitimacy verification receipt within the packet; verify the validity of the information packet, including verifying the digital signature of the information packet and checking the uniqueness of the unique identifier hash value of the terminal hardware, to ensure that the information packet is legitimate, tamper-proof, and valid data. If the verification fails, subsequent allocation operations are rejected and an exception log is recorded.

[0047] Access permission identifier generation and permission level binding: Based on the unique identifier hash value of the terminal hardware The SHA-256 cryptographic hash algorithm is used for secondary hashing, and a strategy is combined to generate timestamps. (UTC second-level timestamp) Generate a 256-bit fixed-length, globally unique access permission identifier. The formula is as follows: ; This identifier is strongly bound to the terminal's physical identity, and the introduction of a timestamp avoids the risk of identifier duplication in extreme scenarios. Furthermore, based on the terminal's business type and access requirements, the access permission identifier is bound to a corresponding hierarchical access permission level, divided into three levels (…). Different levels correspond to clearly defined access ranges and operation permissions for edge node resources, and the permission levels and access permission identifiers form a one-to-one correspondence.

[0048] Dedicated virtual data transmission channel allocation and parameter configuration: Each legitimate terminal is assigned an independent, dedicated virtual data transmission channel. These channels are implemented using virtual port isolation, and each channel corresponds to a unique channel identifier. With communication port number Based on terminal permission level Configure the maximum transmission bandwidth threshold for the channel. The formula is as follows: ; In the formula, Set as the base bandwidth threshold (default 10Mbps). Bandwidth coefficient for permission level (Level 1 permission) Level 2 permissions Level 3 permissions This ensures that the service transmission needs of high-privilege terminals are met; Simultaneously configure other channel control parameters (data transmission protocol, encryption algorithm adaptation type, connection timeout, etc.), and all parameters are related to... The binding forms a complete configuration information.

[0049] Permission-channel mapping relationship establishment and storage: A five-dimensional mapping relationship table is established, consisting of terminal hardware unique identifier hash value, access permission identifier, permission level, dedicated channel identifier, and channel configuration parameters. This table serves as the core control basis for terminal access and data transmission. After encrypting the mapping relationship table, it is stored in the permission channel sub-library of the global trusted control library of the edge node collaborative control unit 2, and synchronized to the local cache of the permission channel allocation sub-module, which facilitates rapid data extraction for subsequent policy encapsulation.

[0050] Allocation result feedback: Generate a terminal permission and channel allocation completion receipt, which includes... , , , The system will encrypt and synchronize the receipt with the terminal access authentication unit 1, along with the channel configuration parameters, and simultaneously send it to the corresponding legitimate terminal to complete the allocation and notification of permissions and channels.

[0051] The CRDT policy encapsulation submodule encapsulates the access permission identifier generated by the permission channel allocation submodule and the control policy corresponding to the dedicated data transmission channel into a conflict-free replication data type policy object. This avoids policy conflicts caused by network latency and node heterogeneity during subsequent distributed synchronization. At the same time, it adds an anti-tampering mechanism to the policy object to ensure the integrity of the policy during storage and transmission. The specific implementation is as follows: Core content extraction of control strategy: Extract the core content of the five-dimensional mapping table from the local cache of the permission channel allocation submodule, integrate it to generate a personalized control strategy for each legitimate terminal, and the single terminal control strategy includes the core elements— , , , And channel configuration parameters, permission effective / expiration time, channel access control rules, and data transmission control rules.

[0052] CRDT Data Structure Selection and Object Definition: We select the OR-Set ordered set type CRDT data structure for policy encapsulation. This structure has the inherent characteristics of conflict-free merging and monotonically increasing. The structured definition formula of the CRDT policy object is as follows: ; In the formula: For CRDT strategy objects; Add a collection to the policy to store all valid control policy entries. Each entry should have the following format: ,in For strategy unique ID, For access control rules, For channel control rules; Remove the set for the policy and store only the invalid policies. with expiration timestamp This enables policy-based soft deletion. The metadata layer stores the basic attributes and security identifiers of policy objects.

[0053] Strategy object metadata layer construction and anti-tampering processing: Metadata layer Includes policy object version number Generate timestamps Digital signature Integrity check code The formula for calculating the integrity check code is as follows: ; Employs the dedicated private key of the edge node collaborative control unit 2 right Perform digital signature, generate and will Write This layer provides a basis for validity verification during subsequent synchronization processes.

[0054] CRDT policy object validity verification: for the encapsulated... Perform integrity and compliance verification, and check Are the strategy entries complete? and Check for match and logical conflicts in the policy rules; after successful verification, The permission channel sub-library is stored in the global trusted management library and awaits distributed synchronization. If the verification fails, a re-encapsulation process is triggered.

[0055] The distributed policy synchronization submodule, based on a distributed consistency synchronization protocol, synchronizes conflict-free replicated policy objects to all edge nodes within the cluster. This enables conflict-free merging and state synchronization of local policy copies on each edge node. Through a standardized process of "master node initiation - slave node verification - conflict-free merging - result feedback," it ensures that the local policy copies of all edge nodes within the cluster are completely consistent with the policy objects in the core management database, achieving globally unified execution of permission and channel control policies. The specific implementation is as follows: Distributed consensus synchronization protocol loading and master node election: Load the Raft distributed consensus synchronization protocol onto all edge nodes in the cluster, and determine the master synchronization node through the Raft election mechanism. (The rest are from the synchronization node) When the master node fails, a re-election is automatically triggered.

[0056] Master node policy object extraction and synchronization message generation: Extract verified data from the global trusted management library. Integration , , Generate an encrypted synchronization message. The message is encrypted using the AES-256-GCM algorithm and contains a policy-unique ID (generated based on "terminal hardware hash + creation timestamp + version number"). Private key signing and message generation timestamp; broadcast to all nodes via encrypted point-to-point links within the cluster. .

[0057] Synchronize message reception and validity verification from the node: After receiving the message, the following core verification steps are executed in sequence: verify Digital signature: using The pre-distributed public key verifies the signature; the formula is a message, and if the equation is true, the verification is successful. verify Integrity: Recalculate the message hash and match it with... If the hash values ​​are completely identical and there are no signs of tampering, the comparison is successful. verify Validity: It must be a positive integer and not lower than the current lowest version number of the cluster, excluding invalid scenarios with version numbers of 0 or negative numbers; after successful verification, it will enter the policy merging stage, and if the verification fails, an exception receipt will be directly sent back.

[0058] Conflict-free merging and updating of local strategy copies: The latest policy object received With local legacy copy Merge according to OR-Set rules, for entries with the same strategy. Operation priority is higher The operation ensures that effective strategies are preserved in the event of conflicts; the merging formula is as follows: ; In the formula: For set union operations, ensure that all valid strategies are retained and all invalid strategies are eliminated; The final CRDT policy object after merging is from the node. The local management policy copy is generated by merging the old local copy with the latest received policy object without any conflicts. This refers to the local legacy CRDT policy object. The addition set stores all policy entries currently in effect locally. Each policy entry is identified by a globally unique policy ID and records core information such as the terminal hardware identifier hash value, permission control rules, and channel control rules. This indicates the latest CRDT policy object received. Add a collection to store the master synchronization node. The latest effective policy items issued, item format and completely consistent; This refers to the local legacy CRDT policy object. The removal set stores only the globally unique policy ID and expiration timestamp of expired policy entries, which is used to mark policies that need to be deactivated, and realize soft deletion (without physically deleting historical records, which facilitates auditing and rollback). This indicates the latest CRDT policy object received. The removal set stores the master synchronization node. The latest failure policy ID and failure timestamp, entry format and completely consistent; This indicates the latest CRDT policy object received. The metadata layer contains the version number of the merged strategy object. Integrity check code Digital signature Generate timestamps and other metadata for subsequent policy synchronization verification, version management and security auditing; and and All entries are merged using the unique policy ID as the index to avoid confusion of policy entries. After merging, update the metadata layer version number using the following formula: ; in: express Local policy version number; express The latest version number carried; Indicates the updated version number after the merge; This indicates the maximum possible value for the version number, ensuring that the version number does not overflow. After the merger Store to A trusted execution environment secure storage area serves as the basis for local control.

[0059] Synchronization result feedback and success determination: After the merge is completed, a synchronization completion receipt will be generated and sent back to [the relevant authority / organization]. ; The synchronization is considered successful when the number of valid completed receipts meets the following formula: ; In the formula, To effectively meet the required number of reply slips, This represents the total number of nodes in the cluster. The threshold for successful synchronization (default 0.9), and Upon successful synchronization, an announcement is generated and broadcast to all nodes.

[0060] Abnormal retransmission and policy completion: for synchronization failures , A maximum of 3 directed retransmissions will be initiated; if the retransmission still fails, the node will be marked as abnormal, and a directed synchronization will be initiated after the node recovers; newly added nodes will automatically request synchronization upon joining the network. Latest Complete the strategy completion.

[0061] Full recording of the synchronization process: Identifier, synchronization initiation time, ,each Synchronization results and other information are written to the policy synchronization log table in the global trusted management library to achieve full-process traceability.

[0062] In this embodiment, the master private key fragment storage module 23 splits and distributes the fragmented private keys of the global control instruction master private key; the process of the master private key fragment storage module 23 splitting and distributing the global control instruction master private key using a threshold secret sharing algorithm includes the following steps: S23.1 Define the global control command master private key Select a cryptographic standard finite field and set the unlock master private key. The minimum number of fragmented private keys required is a threshold value. ,in , The total number of edge nodes in the distributed edge collaborative cluster provides a standardized cryptographic foundation for the subsequent construction of the secret sharing polynomial, as specifically implemented below: Global control command master private key Definition: Define the master private key for global control commands. For cryptographic standard finite fields 2048 random numbers within, It is generated solely by the edge node collaborative control unit 2 in a trusted execution environment and is not leaked to any edge node or external component.

[0063] Cryptographic Standard Finite Field Selection: Selecting a Prime Finite Field As the fundamental field of cryptographic operations, To satisfy the requirement of a safe prime number of 2048 bits ( , (Also a prime number), all operations in a finite field follow the modulo operator. Calculation rules.

[0064] Threshold Dynamic settings: Set the master private key for unlocking. The minimum number of fragmented private keys required is a threshold value. ,in Threshold value The calculation formula is: ; in: This indicates the master private key for unlocking global control commands. Minimum number of private keys required for fragmentation (threshold value); This indicates the rounding up operation.

[0065] Based on the total number of cluster nodes Dynamically calculate threshold value Guarantee the maximum allowed Even if one edge node fails or goes offline, it can still be accessed through the remaining... The master private key is reconstructed from fragmented private keys; at the same time, at least [number] fragmented private keys are required. Only through collaboration among multiple edge nodes can the master private key be reconstructed, preventing a few nodes from colluding to leak the master private key.

[0066] Finally, SHA-256 hash digest finite field modulus Threshold value Total number of cluster nodes The key management sub-library is synchronized to the global trusted control library of the edge node collaborative control unit 2.

[0067] S23.2, Based on the master private key Constructing a secret shared polynomial This polynomial is uniquely indexed at each edge node. The calculation result at that point is used to determine the sharding private key of the corresponding edge node. ,in By using Shamir threshold secret sharing polynomial interpolation, the master private key is... The security is embedded in a polynomial, and then the fragmented private key for each edge node is generated through polynomial evaluation, realizing the core security features of "fragmented distributed storage and threshold reconstruction and restoration". The specific implementation is as follows: First, based on the master private key Build Sub-secret shared polynomial The polynomial satisfies (that is, when) At that time, the polynomial result is exactly the master private key. Its standard formula is: ; In the formula: express Sub-secret shared polynomial; This represents the master private key for global control commands; Representing a finite field A randomized 2048-bit non-zero coefficient (all coefficients are non-zero); Represents a polynomial variable; Modulus Calculation.

[0068] The computational logic of this polynomial is based on... The constant term is randomly generated. Construct a polynomial with non-zero coefficients to ensure And any The complete polynomial can be reconstructed from a point using Lagrange interpolation, and fewer than [a certain number of points] can be used. A single point cannot yield any information about... Valid information.

[0069] Subsequently, a unique index is assigned to each edge node within the distributed edge collaboration cluster. ,in , They are distinct positive integers, and their values ​​range from 1 to 2. , After being bound to the unique node identifier of the edge node, it is stored in the global trusted management library to ensure a one-to-one correspondence between the sharded private key and the edge node.

[0070] Finally, the unique index of each edge node Substitute the secret shared polynomial Calculate polynomials in Model at the location The result was determined to be the shard private key of the corresponding edge node. The calculation formula is: ; In the formula: Indicates the first The sharded private key of each edge node; Indicates the first A unique index for each edge node; The above formula is for indexing nodes. As a polynomial input, through the modulus The fragmented private key is obtained through computation. Each node corresponds to a unique And any indivual The polynomial can be reconstructed using Lagrange interpolation. In order to restore the master private key It fully complies with the core security characteristics of threshold secret sharing.

[0071] S23.3, Transfer the fragmented private key and corresponding edge node index The fragmented private keys are bound and written to the secure storage area of ​​the trusted execution environment of each edge node, completing the distributed secure storage of the fragmented private keys. Through hardware-level secure storage and integrity verification mechanisms, the storage security and immutability of the fragmented private keys are ensured, providing a reliable foundation for subsequent fragmented private key verification, updates, and master private key reconstruction. The specific implementation is as follows: First, the first Sharding private keys of each edge node With corresponding unique index Bind and encapsulate as The formatted bound data packet includes an integrity checksum. The formula used to verify the integrity of bound data packets during storage and transmission is as follows: ; In the formula: This represents the SHA-256 integrity checksum of the bound data packet; This refers to the SHA-256 cryptographic hash algorithm; It is a big-endian byte stream concatenation operator.

[0072] The formula will and After the byte streams are concatenated, a checksum is generated using the SHA-256 algorithm. If the bound data packet is tampered with during storage or transmission, the checksum will not match, thus enabling rapid verification of data integrity.

[0073] Then, each bound data packet is sent via a TLS 1.3 encrypted point-to-point communication link within the cluster to the corresponding edge node's hardware-level trusted execution environment (such as Intel SGX or ARM TrustZone), and written to its secure storage area. The trusted execution environment has hardware-level anti-tampering and anti-theft features to ensure the security of the fragmented private key. It can only be accessed within the trusted environment of this node and cannot be obtained by external processes or other nodes.

[0074] Subsequently, after each edge node completes the binding data packet writing, a storage completion receipt is generated. ,in for SHA-256 hash value, The storage completion timestamp is used; after the receipt is digitally signed by the edge node, it is encrypted and synchronized to the key management sub-library of the global trusted control library of the edge node collaborative control unit 2, so as to realize the full-process traceability of the storage status of the fragmented private key.

[0075] Finally, after receiving all receipts, the edge node collaborative control unit 2 verifies the validity of the digital signature of each receipt. To ensure consistency with the pre-stored shard private key hash values, if there are edge nodes with missing receipts or failed verification, a redistribution and storage process will be triggered until all shard private keys are stored and verified.

[0076] Understandably, compared to traditional distributed storage solutions, this step employs a triple security mechanism of "sharded private key + node index" binding storage + trusted hardware execution environment + integrity verification, which solves the problems of easy leakage and tampering of sharded private keys. At the same time, it achieves full-process traceability of key storage through receipt synchronization, thereby improving the reliability of key management.

[0077] In this embodiment, the fragment private key verification and update module 24 completes the validity verification and dynamic update of the fragment private key; the process of the fragment private key verification and update module 24 performing the fragment private key validity verification and dynamic update includes the following steps: S24.1 Calculate the fragmented private key using a cryptographic hash algorithm. hash value ,Will With fragmented private keys The baseline hash value is synchronized and pre-stored when stored in the secure storage area of ​​the trusted execution environment. Perform a comparison to complete the fragmented private key. Validation of the fragment private key is used for quick verification. To check whether the storage has been tampered with or leaked during the storage process, a lightweight hash comparison mechanism is used to achieve efficient validity verification, providing a reliable validity prerequisite for subsequent dynamic updates of the fragmented private key. The specific implementation is as follows: First, the SHA-256 cryptographic hash algorithm is explicitly used as the verification algorithm for the first... The fragmented private key stored on each edge node Calculate hash value The calculation formula is: ; Then, the fragmented private key is extracted from the secure storage area of ​​the trusted execution environment on the edge node. Synchronize the pre-stored base hash value during storage The baseline hash value is generated and pre-stored by the master private key fragment storage module 23 in step S23.3, and the formula is: ; Then, the hash value calculated in real time Compared with the pre-stored baseline hash value Perform a byte-by-byte comparison: If Then determine the fragmented private key. Unaltered and undisclosed, verification passed; if Then determine the fragmented private key. There is a risk of tampering or leakage. If the verification fails, an abnormal alarm will be triggered and the alarm information will be synchronized to the global trusted management library of the edge node collaborative control unit 2.

[0078] Finally, the verification result (pass / fail), verification timestamp, and comparison hash value are synchronized to the key management sub-library of the global trusted management library to achieve full traceability of the verification process.

[0079] S24.2, Verify the validity of the fragmented private key. Without reconstructing the global control command master private key Under the premise of secure storage area in trusted execution environment of edge nodes, cryptographically secure random numbers are generated. , and the original shard private key Perform an XOR operation to generate a new fragment private key. Thus, without reconstructing the global control command master private key. Under the premise of ensuring that the fragmented private key is dynamically updated, the cryptographic risks of using the same fragmented private key for a long time are avoided, while ensuring that the updated fragmented private key is guaranteed. The refactoring property of threshold secret sharing is still satisfied, and the specific implementation is as follows: First, filter out the fragmented private keys that have been verified in S24.1. Update operations are only performed on valid fragment private keys; for fragment private keys that fail to be verified, the update process is terminated directly and an abnormal alarm is triggered to avoid security risks caused by invalid updates.

[0080] Then, cryptographically secure random numbers are generated through the secure storage area of ​​the trusted execution environment at the edge node. , To match the original shard private key A true random number of equal length (2048 bits) is generated only within the trusted execution environment of this edge node and will never be leaked to external components or other nodes. After generation, it is only used for this update operation.

[0081] Subsequently, within the trusted execution environment of the edge node, cryptographically secure random numbers are... With the original shard private key Perform a bitwise XOR operation to generate a new fragment private key. The formula for the XOR operation is: .

[0082] The above formula uses an XOR operation to evaluate the original fragment private key. Perform masking to generate a new fragment private key. Due to the invertibility of the XOR operation ( ),and Stored only in the trusted execution environment of the corresponding edge node, without obtaining Under the premise that it is impossible to pass reduction Meanwhile, the update process did not involve the master private key. Any reconstruction operation fully satisfies the requirement of "not reconstructing the global control instruction master private key". The core requirement of "".

[0083] S24.3 Calculate the new fragment private key using a cryptographic hash algorithm. hash value The pre-stored base hash value Updated to This process involves dynamically updating the sharded private key, updating the hash base of the new sharded private key, and synchronizing the verification base to the new sharded private key. This provides a new benchmark for subsequent verification of the validity of the sharded private key and achieves a closed loop for the entire sharded private key update process. The specific implementation is as follows: First, the SHA-256 cryptographic hash algorithm is used to update the new fragment private key. Calculate hash value The calculation formula is: ; In the formula: Indicates the new shard private key The SHA-256 hash value.

[0084] Then, the baseline hash value pre-stored in the secure storage area of ​​the trusted execution environment of the edge node is... Update to the new shard private key hash value The updated formula is: ; In the formula: This represents the updated base hash value; Indicates the new shard private key The hash value.

[0085] Then, the new shard private key Write to the secure storage area of ​​the trusted execution environment on the edge node, overwriting the original shard private key. At the same time, the updated base hash value will be... The key management sub-library of the global trusted control library of the edge node collaborative control unit 2 is synchronized to replace the original base hash value. .

[0086] Finally, a shard private key update completion receipt is generated, which includes the unique node identifier of the edge node and the original shard private key. Hash value New shard private key Hash value The updated timestamp is encrypted and synchronized to the global trusted management library after being digitally signed by the edge node, thus achieving full traceability of the update process.

[0087] In this embodiment, the global command distributed verification module 25 completes the distributed verification, permission unlocking, and command issuance of global control commands. The process of global command distributed verification module 25 completing the distributed verification and execution of global control commands using a threshold signature mechanism includes the following steps: S25.1 Calculate global control commands using a cryptographic hash algorithm. hash value to the holder of the fragment private key Or new shard private key Edge nodes send hash values This provides a unified verification benchmark for the generation of fragment signatures at subsequent edge nodes, and simultaneously transmits them through an encrypted channel. Distribute the signatures to each edge node to ensure the consistency and security of the signature generation baseline. The specific implementation is as follows: First, the SHA-256 cryptographic hash algorithm was selected as the instruction digest generation algorithm for global control instructions. Perform hash operations to calculate the instruction hash value. The calculation formula is: ; In the formula: Indicates global control commands The SHA-256 hash value is a 256-bit fixed-length binary string; This represents the raw data of global control commands, including core information such as command type, target object, execution parameters, and effective time.

[0088] Since subsequent fragmented signature generation, complete signature reconstruction, and verification are all based on finite fields Modular exponentiation ( (2048-bit safe prime modulus), in 256-bit binary string form It cannot be directly used in calculations and needs to be converted into a valid large integer within a finite field (the converted integer is still denoted as ). (To maintain symbol consistency), the specific conversion rules are as follows: 256-bit binary string Convert to decimal integer in big-endian order, denoted as: The range of values ​​is ; right Execution Module The operation yields the hash value after finite field adaptation: ; If after conversion (0 cannot participate in modular exponentiation), then in the global control instructions Append a fixed padding value of 0x01 to the end of the original data, re-execute the SHA-256 hash operation and the above conversion steps, and ensure the final result is correct. satisfy And with finite fields It is compatible with the operation rules.

[0089] Then, the edge node collaborative control unit 2 transmits the finite-domain adapted instruction hash value through the TLS 1.3 encrypted point-to-point communication link within the cluster. Directly sent to all holders of fragmented private keys within the distributed edge collaboration cluster. Or new shard private key Edge nodes; during the transmission process Encryption protection is implemented to prevent theft or tampering during transmission.

[0090] Finally, the edge node receives... Then, it is temporarily stored in the secure storage area of ​​its trusted execution environment to provide input for the subsequent generation of fragmented signatures, while recording the received timestamp and synchronizing it to the instruction verification sub-library of the global trusted control library.

[0091] S25.2, Each edge node receives the hash value Subsequently, based on the fragmented private key stored in the secure storage area of ​​the trusted execution environment of this node... Or new shard private key Public-key cryptography algorithm is used to generate fragmented signatures. And return it to avoid the private key being leaked. The specific implementation is as follows: First, each edge node receives the instruction hash value after finite field adaptation issued by S25.1. Retrieve the stored fragmented private key from its own trusted execution environment's secure storage area. Or the updated new shard private key This ensures that access to the private key is limited to the trusted execution environment, preventing external leakage.

[0092] Then, select based on finite field Discrete logarithmic cryptography algorithms, using fragmented private keys or As the key, the instruction hash value Perform signature calculations to generate fragmented signatures. The core calculation formula is: ; Or the updated formula: ; In the formula: Representing a finite field The original generator, and the master private key Public key The generators used for generation are consistent; Subsequently, the edge nodes will generate fragment signatures. and its own unique node identifier Node index (The index used in the calculation of Lagrange coefficients in S25.3 is consistent with that used in the calculation of Lagrange coefficients) It is encapsulated into a signed data packet; it is returned to the global instruction distributed verification module 25 through an encrypted communication link. Before returning, the signed data packet is digitally signed to ensure the integrity and legality of the returned data.

[0093] S25.3 Collect valid fragment signatures returned by edge nodes When a valid fragment signature The number reaches the threshold At that time, the complete signature was reconstructed using the Lagrange interpolation algorithm. The core security feature of threshold signatures is that they only appear when the threshold is reached. Only then can a valid instruction signature be reconstructed. The specific implementation is as follows: First, the global instruction distributed verification module 25 collects the fragmented signatures returned by each edge node. Each signature undergoes preliminary validity verification, including verifying the legitimacy of the node's identity, the validity of the signature format, and hash matching, to filter out the set of valid sharded signatures. ,in This represents the current number of valid signatures.

[0094] Then, determine the number of valid signatures. Has the threshold been reached? Threshold value The threshold value is completely consistent with that defined by the master private key fragment storage module 23, and the calculation formula is as follows: ; like If the edge node fails to return a signature, the request will continue to wait for the edge node to return a signature, or the timeout mechanism will be triggered to re-initiate a request to the edge node that has not returned a signature after the timeout. like Then select the first one. One valid fragment signature and its corresponding edge node unique index Proceed to the signature reconstruction stage.

[0095] Next, based on the Lagrange interpolation algorithm, using the selected... Individual signature With index Reconstruction yields global control instructions. Full signature The complete signature reconstruction formula is: ; Among them, the Lagrange coefficient The calculation formula is: ; In the above formula for Lagrange coefficients, Denominator In a finite field The modular inverse, rather than ordinary integer division, is used, and the specific rules are as follows: Modular inverse definition: For a finite field Non-zero elements within (here) ,and (Because the node index is unique), its modulo inverse. satisfy: ; Right now and The product in the modulus The modulo inverse is equal to 1 and is the only legal way to perform division in a finite field.

[0096] Modular inverse solution method: The extended Euclidean algorithm, which is conventional in this field, is used for solution. This algorithm can compute a finite field in polynomial time. It can be implemented using modular inverses and requires only basic number theory operations, without the need for additional dedicated hardware.

[0097] Operational constraints: All intermediate results during the calculation process must be modulo 1. The operation ensures that the result always falls within the finite field. The range of legal values Internally, to avoid numerical overflow or calculation failure.

[0098] In the formula: Indicates the selected first Fragment signatures of each edge node; Indicates the first The Lagrange coefficients corresponding to each fragment signature are only valid in the finite field. Internally valid; Indicates the first A unique index for each edge node; Indicates the first The unique index of each edge node ( That is, exclude the current number (number of nodes) This represents a series of multiplication operations. This means that all operations are performed on a 2048-bit safe prime modulus. Executed within a finite field.

[0099] Finally, the reconstructed complete signature The set of node indices participating in the signature, and the threshold value. The instruction verification sub-library of the global trusted management library of the edge node collaborative control unit 2 is synchronized to provide a complete signature basis for subsequent public key verification.

[0100] S25.4, Using the master private key of the global control command The paired public key is for the complete signature. Verification will be performed; once verification is successful, global control commands will be unlocked. Grant execution permissions and grant global control commands The command is distributed to all edge nodes within the distributed edge collaboration cluster to ensure secure execution. The specific implementation is as follows: First, extract the master private key for global control commands. Paired public keys ,and ,in, Representing a finite field Generators; This represents the master private key for global control commands; Represents a 2048-bit secure prime modulus. Public key. Pre-distribute to all edge nodes.

[0101] Then, using the public key For complete signature With instruction hash value The core verification formula is as follows: ; In the formula: This indicates an equality verification operation; if the equality is true, the verification passes.

[0102] Cryptographic equivalence derivation: Full signature From step S25.3 The equivalent derivation of the following is based on the Shamir threshold secret sharing and discrete logarithmic cryptography principles, obtained by reconstructing valid fragment signatures: Master private key Refactoring properties that satisfy Shamir threshold secret sharing: ; in For Lagrange coefficients, For the first to participate in the reconstruction The sharded private key of each edge node; The complete signature reconstruction formula can be derived as follows: ; Public Key Therefore, substituting the public key into the right side of the verification formula yields: ; This result is consistent with the complete signature. They are completely equivalent, therefore the formula can be verified. If valid, it can effectively verify the legitimacy of a complete signature.

[0103] If verification fails, then the global control command is determined. If the signature is forged, altered, or invalid, the instruction issuance process will be terminated immediately, triggering a security alarm: the verification failure information, the unique identifier of the instruction, and the identifier of the node involved in the reconstruction will be synchronized to the security alarm sub-library of the global trusted management library, and the abnormal event will be reported to the edge security monitoring unit 4. At the same time, the node involved in generating the invalid fragment signature will be marked and its subsequent permission to participate in the signature reconstruction will be restricted. If the verification is successful, the edge node collaborative control unit 2 will unlock the global control command. Grant execution permissions and generate an instruction execution unlock token, which includes a unique instruction identifier, a verification timestamp, and a full signature. Abstract and other information.

[0104] Finally, the edge node collaborative control unit 2 will send global control commands. The unlock token is sent to all edge nodes in the distributed edge collaboration cluster via an encrypted broadcast channel. After receiving the token, each edge node verifies its validity and then executes the corresponding instruction (such as adjusting terminal access permissions, updating data transmission channel policies, etc.). The execution results are then synchronized to the global trusted management library, enabling full traceability and auditability of the instruction execution process.

[0105] In this embodiment, the abnormal linkage strategy adjustment module 26 adjusts the terminal access permission and data transmission channel control strategy based on the abnormal information.

[0106] Specifically, the anomaly linkage strategy adjustment module 26 receives and parses the anomaly information reported by the edge security monitoring unit 4. The anomaly linkage strategy adjustment module 26 is used to extract the core elements of the anomaly, providing accurate input for subsequent risk classification and strategy adjustment. The specific implementation is as follows: First, the abnormal linkage strategy adjustment module 26 receives abnormal information packets reported by the edge security monitoring unit 4 through the TLS1.3 encrypted channel in real time. The information packets include the abnormal type, abnormal terminal identifier, abnormal behavior details, abnormal occurrence time, and number of affected terminals / nodes.

[0107] Then, the integrity of the abnormal information packet is verified by calculating the checksum using the SHA-256 cryptographic hash algorithm. The verification formula is as follows: ; In the formula: The SHA-256 integrity checksum representing the abnormal information packet; Indicates the exception type; Indicates an abnormal terminal identifier; Indicates details of the abnormal behavior; Indicates the timestamp of the exception occurrence; Indicates the number of affected terminals / nodes; This refers to the SHA-256 cryptographic hash algorithm; It is a big-endian byte stream concatenation operator.

[0108] After successful verification, extract the core elements, specifically including: exception type. (Such as terminal identity spoofing, data out-of-bounds access, abnormal traffic transmission, edge node communication interruption), abnormal terminal identifiers Time of occurrence of abnormality Number of terminals affected This provides basic data for subsequent classification and adjustment; if the verification fails, the abnormal information packet is discarded and an abnormal log is recorded.

[0109] Furthermore, the anomaly linkage strategy adjustment module 26 quantifies and classifies the parsed anomaly information. The anomaly linkage strategy adjustment module 26 is used to convert qualitative anomalies into quantitative risk levels. This provides an objective basis for strategy adjustments and avoids misjudgments caused by subjective judgment. The specific implementation is as follows: First, pre-defined weights and scores are assigned to different anomaly dimensions, and the anomaly level is calculated. The grading formula is: ; In the formula: This indicates the level of abnormality, with a value range of [1,5]. The higher the value, the higher the risk level. This indicates the rounding up operation; Indicates the weight of the exception type (default value is 0.5); The score indicates the type of anomaly (identity spoofing = 5, outbound access = 4, abnormal traffic = 3, communication anomaly = 2). Indicates the weight of the duration of the anomaly (default value is 0.3); The score indicates the duration of the abnormality (>10 minutes = 5, 5-10 minutes = 4, 1-5 minutes = 3, <1 minute = 2). Indicates the weight of the scope of influence (default value is 0.2); The score indicates the scope of impact (single terminal = 2, multiple terminals = 3, cluster scope = 5).

[0110] This formula quantifies the risk level by summing the anomaly type, duration, and scope of impact according to preset weights. It highlights the core impact of the anomaly type while also taking into account the actual harm caused by the duration and scope of the anomaly, providing a precise and objective basis for subsequent strategy adjustments.

[0111] Subsequently, the abnormal level was determined. With the core elements of the anomaly ( , , , The policy management sub-library of the global trusted control library of the edge node collaborative control unit 2 is bound and stored to provide a unified parameter basis for subsequent policy matching.

[0112] In addition, the abnormal linkage strategy adjustment module 26 adjusts according to the abnormality level. The module 26, which matches and executes adjustments to terminal access permissions and data transmission channel control policies, and uses anomaly linkage policy adjustment module 26, is used to precisely adjust the access permissions and channel rules of the corresponding terminals according to the quantified risk level, so as to achieve refined security control. The specific implementation is as follows: First, according to the anomaly level Abnormal terminal identifier It matches the preset hierarchical adjustment strategy, and the core matching rule is: like (Low risk): Tighten the terminal data transmission bandwidth to 50% of the original threshold, retain the original read permissions, and do not affect the terminal's basic services; like (Medium risk): Revoke the terminal's data write permission, retain only read-only permission, and restrict the channel access range to prevent the risk from spreading; like (High Risk): Immediately block terminal access, shut down the dedicated data transmission channel, add the terminal to the cluster blacklist, and completely block the source of risk.

[0113] Then, adjust the terminal access permission level. With data transmission channel configuration Encapsulated as standardized policy adjustment instructions, the instructions include , Adjust the effective date After being digitally signed by the edge node collaborative control unit 2, the instruction is sent to the channel permission allocation and synchronization module 22. Upon receiving the instruction, the channel permission allocation and synchronization module 22 updates the corresponding CRDT policy object. The updated formula is: ; ; ; ; In the formula: This represents the updated CRDT policy object; This indicates that the new strategy adds a set; This indicates that the old strategy is being removed from the set; This indicates the updated metadata; Indicates a unique ID for the strategy; This indicates the adjusted access permission level; This indicates the adjusted channel configuration; This represents the union operation of sets; Indicates the policy version number; The new strategy is added to the add set using the above formula, and the old strategy is marked as the remove set. The set union operation is used to achieve conflict-free merging. At the same time, the version number is updated to ensure the uniqueness of the strategy, which is fully compatible with the CRDT strategy synchronization mechanism of the channel permission allocation synchronization module 22.

[0114] Subsequently, the channel permission allocation synchronization module 22 synchronizes the updated permissions using the Raft distributed consistency synchronization protocol. Synchronize to all edge nodes within the cluster to complete the conflict-free merging of local policy replicas and ensure that the policy state of each edge node is consistent.

[0115] Finally, the abnormal linkage strategy adjustment module 26 will adjust the results (including...) Original strategy information, new strategy information, adjustment time, and anomaly level. The policy management sub-library of the global trusted control library of the edge node collaborative control unit 2 is synchronized to the edge security monitoring unit 4, and the adjustment completion receipt is fed back to the edge security monitoring unit 4, forming a complete security closed loop of "monitoring-analysis-adjustment-synchronization-feedback".

[0116] The data encryption transmission unit 3, based on the data transmission channel and control strategy allocated by the edge node collaborative control unit 2, performs encryption processing and integrity verification on the transmitted data between the terminal device and the edge node, and between edge nodes. The data encryption transmission unit 3 includes a data encryption module 31, a transmitted data integrity verification module 32, and a transmission adaptation module 33, wherein: In this embodiment, the data encryption module 31 performs encryption processing on the data transmitted between the terminal device and the edge node, and between the edge nodes, according to the data transmission channel and control strategy allocated by the edge node collaborative control unit 2, to ensure data confidentiality. At the same time, it adapts to the channel bandwidth and protocol characteristics to avoid encryption redundancy. The specific implementation is as follows: First, based on the channel control strategy, the encryption algorithm is selected: the terminal-edge node link uses the AES-256-GCM symmetric encryption algorithm, and the edge node-edge node link uses the TLS1.3 encryption protocol. Then, the transmitted data The encryption operation is performed using the following formula: ; In the formula: This represents the encrypted data; This represents the original transmitted data; This indicates the channel-specific symmetric key (and the channel identifier). (Binding, assigned by edge node collaborative control unit 2); This indicates a one-time random number (generated encrypted each time to avoid replay attacks); This indicates the AES-256-GCM encryption algorithm.

[0117] Then, the encrypted data The data is sent to the corresponding transmission link, and the encryption algorithm type and key identifier are recorded and synchronized to the transmission data integrity verification module 32.

[0118] In this embodiment, the data integrity verification module 32 performs integrity verification on the data transmitted between the terminal device and the edge node, and between the edge nodes, based on the data transmission channel and control strategy allocated by the edge node collaborative control unit 2, to ensure data integrity. The specific implementation is as follows: First, the SHA-256 cryptographic hash algorithm is used to hash the original transmitted data. Or encrypted data Calculate integrity check code The calculation formula is: ; Or the encrypted verification formula: ; In the formula: This represents the SHA-256 hash value of the transmitted data; Indicates the original / encrypted data transmitted; This represents the SHA-256 cryptographic hash algorithm.

[0119] Then, the verification code or The checksum is appended to the end of the transmitted data and sent along with the data. After receiving the data, the receiving end recalculates the checksum and compares it with the appended checksum. If they match, the verification is successful and the data is received normally. If they do not match, the data is determined to have been tampered with, triggering the retransmission mechanism (up to 3 times). If the retransmission fails, an alarm is triggered. Finally, the verification results are synchronized to the global trusted management library of the edge node collaborative control unit 2 to achieve traceability of the integrity of transmitted data.

[0120] In this embodiment, the transmission adaptation module 33 adapts the data transmission links between the terminal device and the edge node, and between the edge nodes, according to the data transmission channels and management strategies allocated by the edge node collaborative control unit 2. The specific implementation is as follows: First, extract the dedicated data transmission channel identifier for the corresponding terminal / node from the global trusted management library of the edge node collaborative control unit 2. Communication port Bandwidth threshold Transmission protocol type Connection timeout ; Then, based on the extracted channel parameters, dedicated transmission links are established between the terminal device and the edge node, and between the edge nodes: the terminal-edge node link uses a TCP long connection with port binding. Bandwidth limit is Edge node-to-edge node links select either TCP point-to-point or UDP multicast connections based on the policy. Subsequently, the link connectivity status is monitored in real time. If the link is disconnected, it will automatically reconnect (up to 3 times). If the reconnection fails, an abnormal alarm will be triggered and synchronized to the edge node collaborative control unit 2. Finally, the link adaptation results (channel identifier) ​​are... The link status and adaptation parameters are synchronized to the data encryption module 31 and the data integrity verification module 32, providing a configuration basis for subsequent encryption and verification.

[0121] Edge security monitoring unit 4 monitors terminal access behavior and data transmission traffic according to the terminal access permission and data transmission channel control policies of edge node collaborative control unit 2, and reports abnormal access and abnormal transmission behavior information to edge node collaborative control unit 2. Edge security monitoring unit 4 includes a security policy acquisition module 41, an access behavior monitoring module 42, a transmission traffic monitoring module 43, and an abnormal information reporting module 44, wherein: In this embodiment, the security policy acquisition module 41 acquires the terminal access permissions and data transmission channel control policies of the edge node collaborative control unit 2, ensuring that the monitoring rules are completely consistent with the policies of the edge node collaborative control unit 2, and avoiding false alarms or missed alarms due to policy asynchrony. The specific implementation is as follows: First, the security policy acquisition module 41 retrieves the latest terminal access permission and data transmission channel control policies from the permission channel sub-library of the global trusted control library of the edge node collaborative control unit 2. The policies include terminal identifiers. Access permission level Exclusive passage signage Channel bandwidth threshold Permission activation / expiration time ; Then, the obtained policy is subjected to integrity verification, and the policy check code is calculated using the SHA-256 hash algorithm. The formula is: ; After successful verification, the policy is cached in the local trusted storage area, and the policy version number is recorded. It keeps the policy version synchronized with the edge node collaborative control unit 2; if the verification fails, it will re-fetch the policy until the verification passes. Subsequently, the caching strategy is synchronized to the access behavior monitoring module 42 and the transmission traffic monitoring module 43 to provide a unified baseline rule for subsequent monitoring.

[0122] In this embodiment, the access behavior monitoring module 42 monitors terminal access behavior according to the terminal access permission and data transmission channel control policy, identifies anomalies such as unauthorized access and illegal access, and ensures that access behavior complies with the control policy. Specifically, the implementation is as follows: First, the access behavior monitoring module 42 obtains the terminal access permission policy from the security policy acquisition module 41 and extracts the terminal identifier. Access permission level Permission effective time Exclusive passage signage ; Then, the terminal access requests are monitored in real time, and the access behavior is verified in multiple dimensions: Permission matching verification: Verify whether the operation permissions of the access terminal match the permissions of the user terminal. If a low-privilege terminal attempts to perform a write operation, it is considered an unauthorized access exception. Channel matching verification: Verifies whether the access terminal is using a dedicated channel. If the access channel does not match the IDch, it is determined to be an illegal channel access anomaly. Time validity verification: Verify whether the access time is within the specified range. If the access time is outside the validity period within the specified range, it will be judged as an access timeout exception. Frequent access verification: Count the number of times a terminal accesses the network within 1 minute. If the number of accesses exceeds the threshold (default 5 times), it is judged as an abnormal frequent access. Subsequently, the abnormal access behavior information (abnormal type, The data (access time, exception details) is temporarily stored in the local cache to provide input for the exception information reporting module 44.

[0123] In this embodiment, the transmission traffic monitoring module 43 monitors the data transmission traffic according to the terminal access permissions and data transmission channel control policies, identifies abnormal traffic, out-of-bounds transmission, and other behaviors, and ensures that the transmission behavior complies with the control policies. The specific implementation is as follows: First, the transmission traffic monitoring module 43 obtains the data transmission channel policy from the security policy acquisition module 41 and extracts the exclusive channel identifier. Bandwidth threshold Transmission protocol type Access Scope ; Then, the transmission traffic within the channel is monitored in real time, and the traffic is verified from multiple dimensions: Bandwidth Exceedance Check: Calculate the real-time bandwidth of the channel. ,like If so, it is determined to be an abnormality of bandwidth exceeding the limit; Protocol matching verification: Verifies whether the transport protocol is compatible with... If they are consistent, it is determined that the transmission is an illegal protocol error; Access Scope Validation: Verifies whether the target object for the transmitted data is within the specified range. If the range is exceeded, it is considered an out-of-bounds transmission error. Abnormal traffic verification: Statistically analyze the size / frequency of data packets per unit time. If a large number of small packets or oversized packets appear, it is determined to be abnormal traffic transmission. Subsequently, the abnormal transmission behavior information (abnormal type, The data (transmission time, exception details) is temporarily stored in the local cache to provide input for the exception information reporting module 44.

[0124] In this embodiment, the anomaly information reporting module 44 reports the detected abnormal access and abnormal transmission behavior information to the edge node collaborative control unit 2, triggering policy adjustment, as specifically implemented as follows: First, the exception information reporting module 44 extracts the temporarily stored exception information from the local cache and encapsulates it into a standardized exception information package. ,in It is an exception type. This is an identifier for an abnormal terminal. This is an abnormal channel identifier. For details of the anomaly, This is the timestamp of the exception occurrence. This represents the number of affected terminals / nodes. Then, the packet is encrypted using the TLS 1.3 encryption protocol, and the integrity check code is calculated. The formula is: ; In the formula, This represents the SHA-256 integrity checksum of the exception information packet.

[0125] Subsequently, the information packet is reported to the edge node collaborative control unit 2 via an encrypted point-to-point link, and a response is awaited: if no response is received within 10 seconds, the process will retrieve up to 3 times; if the retry fails, the information will be temporarily stored and re-reported after the link is restored. Finally, the reporting results (success / failure, reporting time, and anomaly summary) are synchronized to the local log library of the edge security monitoring unit 4 to achieve full traceability of the anomaly reporting process.

[0126] Those skilled in the art will understand that the process of implementing all or part of the steps of the above embodiments can be carried out by hardware or by a program instructing the relevant hardware.

[0127] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely preferred examples and are not intended to limit the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the claimed invention.

Claims

1. A secure access and encrypted data transmission system for edge computing collaborative terminal devices, characterized in that, include: Terminal access authentication unit (1) performs two-way identity authentication on terminal devices, binds the unique hardware identifier of terminal devices with identity authentication credentials, completes the legality verification of terminal devices, and synchronizes the legal terminal information that has passed the verification to the edge node collaborative control unit (2). The edge node collaborative control unit (2) constructs a distributed edge collaborative cluster to realize collaborative scheduling and unified management and control among edge nodes. The edge node collaborative control unit (2) allocates corresponding terminal access permissions and data transmission channels according to the legitimate terminal information synchronized by the terminal access authentication unit (1), encapsulates the access permission and data transmission channel management policies into conflict-free replication data type CRDT objects, and realizes conflict-free merging and state synchronization of policy replicas of each edge node through a distributed consistency synchronization protocol. The edge node collaborative control unit (2) uses a threshold secret sharing algorithm to split the global control instruction master private key into multiple fragment private keys, distributes them to the secure storage area of ​​the trusted execution environment of each edge node, and completes the validity verification and dynamic update of the fragment private keys according to preset conditions. The edge node collaborative control unit (2) uses a threshold signature mechanism to complete the distributed verification of global control commands. After the verification is successful, the command execution permission is unlocked and sent to each edge node. At the same time, based on the abnormal information reported by the edge security monitoring unit (4), the terminal access permission and data transmission channel management strategy are adjusted. The data encryption transmission unit (3) performs encryption processing and integrity verification on the data transmitted between the terminal device and the edge node, and between the edge nodes, according to the data transmission channel and control strategy allocated by the edge node collaborative control unit (2). Edge security monitoring unit (4) monitors terminal access behavior and data transmission traffic according to the terminal access permission and data transmission channel control strategy of edge node collaborative control unit (2), and reports abnormal access and abnormal transmission behavior information to edge node collaborative control unit (2).

2. The edge computing collaborative terminal device secure access and data encryption transmission system according to claim 1, characterized in that, The terminal access authentication unit (1) includes an identity information collection module (11), a two-way authentication module (12), a hardware identifier binding module (13), a legality verification module (14), and a legal information synchronization module (15), wherein: The identity information collection module (11) collects the identity authentication credentials of the terminal device; The two-way authentication module (12) performs two-way authentication on the terminal device; The hardware identifier binding module (13) binds the unique hardware identifier of the terminal device with the identity authentication credential; The legitimacy verification module (14) performs legitimacy verification on the terminal device that has completed binding and two-way identity authentication; The legitimate information synchronization module (15) synchronizes the verified legitimate terminal information to the edge node collaborative control unit (2).

3. The edge computing collaborative terminal device secure access and data encryption transmission system according to claim 2, characterized in that, The edge node collaborative control unit (2) includes a cluster construction and scheduling management module (21), a channel permission allocation and synchronization module (22), a master private key shard storage module (23), a shard private key verification and update module (24), a global instruction distributed verification module (25), and an abnormal linkage strategy adjustment module (26), wherein: The cluster construction and scheduling control module (21) constructs a distributed edge collaborative cluster to realize collaborative scheduling and unified control among edge nodes; The channel permission allocation and synchronization module (22) allocates terminal access permissions and data transmission channels according to the legitimate terminal information, and encapsulates and synchronizes access permission and data transmission channel control strategies. The master private key fragment storage module (23) splits and distributes the fragment private keys of the global control instruction master private key; The fragment private key verification and update module (24) completes the validity verification and dynamic update of the fragment private key; The global instruction distributed verification module (25) completes the distributed verification of global control instructions, permission unlocking and instruction issuance; The abnormal linkage strategy adjustment module (26) adjusts the terminal access permission and data transmission channel control strategy according to the abnormal information.

4. The edge computing collaborative terminal device secure access and data encryption transmission system according to claim 3, characterized in that, The cluster construction and scheduling management module (21) includes a node initialization submodule, a cluster networking submodule, a node status acquisition submodule, and a load balancing scheduling submodule, wherein: The node initialization submodule assigns a unique node identifier generated based on a hardware unique identifier to each edge node in the cluster, and completes the initialization configuration of the network communication parameters and computing resource baseline parameters of the edge nodes. The cluster networking submodule establishes point-to-point communication links between edge nodes based on a distributed node discovery protocol, and constructs a distributed edge collaborative cluster. The node status acquisition submodule collects real-time operational status data of each edge node, including CPU utilization, memory usage, and network bandwidth utilization, through a fixed-period heartbeat detection mechanism. The load balancing scheduling submodule coordinates terminal access requests based on the running status data collected by the node status acquisition submodule, thereby achieving unified management and load balancing of edge nodes within the cluster.

5. The edge computing collaborative terminal device secure access and data encryption transmission system according to claim 4, characterized in that, The channel permission allocation and synchronization module (22) includes a permission channel allocation submodule, a CRDT policy encapsulation submodule, and a distributed policy synchronization submodule, wherein: The permission channel allocation submodule allocates an access permission identifier generated based on the hash of the unique identifier of the terminal device hardware to each legitimate terminal according to the legitimate terminal information synchronized by the terminal access authentication unit (1), as well as a dedicated data transmission channel. The CRDT policy encapsulation submodule encapsulates the access permission identifier generated by the permission channel allocation submodule and the control policy corresponding to the dedicated data transmission channel into a conflict-free replication data type policy object; The distributed policy synchronization submodule is based on a distributed consistency synchronization protocol, which synchronizes conflict-free replicated data type policy objects to all edge nodes in the cluster, thereby achieving conflict-free merging and state synchronization of local policy replicas on each edge node.

6. The edge computing collaborative terminal device secure access and data encryption transmission system according to claim 5, characterized in that, The process by which the master private key fragment storage module (23) uses a threshold secret sharing algorithm to split and distribute the global control instruction master private key includes the following steps: S23.1 Define the global control command master private key Select a cryptographic standard finite field and set the unlock master private key. The minimum number of fragmented private keys required is a threshold value. ,in , This represents the total number of edge nodes in the distributed edge collaboration cluster. S23.2, Based on the master private key Constructing a secret shared polynomial This polynomial is uniquely indexed at each edge node. The calculation result at that point is used to determine the sharding private key of the corresponding edge node. ,in ; S23.3, Transfer the fragmented private key and corresponding edge node index Bind them and write them to the trusted execution environment secure storage area of ​​each edge node.

7. The edge computing collaborative terminal device secure access and data encryption transmission system according to claim 6, characterized in that, The process of the fragment private key verification and update module (24) performing fragment private key validity verification and dynamic update includes the following steps: S24.1 Calculate the fragmented private key using a cryptographic hash algorithm. hash value ,Will With fragmented private keys The baseline hash value is synchronized and pre-stored when stored in the secure storage area of ​​the trusted execution environment. Perform a comparison to complete the fragmented private key. Validation of effectiveness; S24.2, Verify the validity of the fragmented private key. Without reconstructing the global control command master private key Under the premise of secure storage area in trusted execution environment of edge nodes, cryptographically secure random numbers are generated. , and the original shard private key Perform an XOR operation to generate a new fragment private key. ; S24.3 Calculate the new fragment private key using a cryptographic hash algorithm. hash value The pre-stored base hash value Updated to This completes the dynamic update of the fragmented private key.

8. The edge computing collaborative terminal device secure access and data encryption transmission system according to claim 7, characterized in that, The global instruction distributed verification module (25) uses a threshold signature mechanism to complete the distributed verification and execution of global control instructions, including the following steps: S25.1 Calculate global control commands using a cryptographic hash algorithm. hash value to the holder of the fragment private key Or new shard private key Edge nodes send hash values ; S25.2, Each edge node receives the hash value Subsequently, based on the fragmented private key stored in the secure storage area of ​​the trusted execution environment of this node... Or new shard private key Public-key cryptography algorithm is used to generate fragmented signatures. And return; S25.3 Collect valid fragment signatures returned by edge nodes When a valid fragment signature The number reaches the threshold At that time, the complete signature was reconstructed using the Lagrange interpolation algorithm. ; S25.4, Using the master private key of the global control command The paired public key is for the complete signature. Verification will be performed; once verification is successful, global control commands will be unlocked. Grant execution permissions and grant global control commands It is distributed to all edge nodes within the distributed edge collaboration cluster.

9. The edge computing collaborative terminal device secure access and data encryption transmission system according to claim 1, characterized in that, The data encryption transmission unit (3) includes a data encryption module (31), a data integrity verification module (32), and a transmission adaptation module (33), wherein: The data encryption module (31) performs encryption processing on the data transmitted between the terminal device and the edge node, and between the edge nodes, according to the data transmission channel and control strategy allocated by the edge node collaborative control unit (2); The data transmission integrity verification module (32) performs integrity verification on the data transmission between the terminal device and the edge node, and between the edge nodes, based on the data transmission channel and control strategy allocated by the edge node collaborative control unit (2). The transmission adaptation module (33) adapts the data transmission links between the terminal device and the edge node, and between the edge nodes, according to the data transmission channels and management strategies allocated by the edge node collaborative control unit (2).

10. The edge computing collaborative terminal device secure access and data encryption transmission system according to claim 1, characterized in that, The edge security monitoring unit (4) includes a security policy acquisition module (41), an access behavior monitoring module (42), a transmission traffic monitoring module (43), and an abnormal information reporting module (44), wherein: The security policy acquisition module (41) acquires the terminal access permissions and data transmission channel control policies of the edge node collaborative control unit (2); The access behavior monitoring module (42) monitors the terminal access behavior in accordance with the terminal access permission and data transmission channel control strategy; The transmission traffic monitoring module (43) monitors the data transmission traffic according to the terminal access permission and data transmission channel control strategy; The abnormal information reporting module (44) reports the detected abnormal access and abnormal transmission behavior information to the edge node collaborative control unit (2).

Citation Information

Patent Citations

  • A node access and node authentication method based on edge computing

    CN109861828A

  • Abnormal transaction identification method and device based on edge node collaboration, and electronic equipment

    CN121481727A