Fttr-based internal and external network cooperative access control and security isolation system, method, device and medium

By using a three-dimensional dynamic role model and master-slave gateways in the FTTR network, the problem of lack of real-time protection for new device access and accidental damage to normal services during anomaly handling is solved, achieving real-time protection, low false alarm rate and transparent isolation.

CN122316801APending Publication Date: 2026-06-30TECHNICOLOR (CHINA) TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
TECHNICOLOR (CHINA) TECH CO LTD
Filing Date
2026-06-01
Publication Date
2026-06-30

AI Technical Summary

Technical Problem

In existing FTTR networks, new equipment access lacks real-time protection, and abnormal handling can easily damage normal services, making it difficult to achieve effective isolation without interrupting services.

Method used

A three-dimensional dynamic role model is adopted to determine device behavior based on device access location, type and time window. Through the collaborative work of master and slave gateways, anomalies are identified by sliding time window and weighted deviation, and port isolation and spoofed response are performed.

Benefits of technology

It enables instant protection for new device access, reduces false alarm rate, maintains transparent operation of normal business, and achieves isolation and data protection without attackers noticing without increasing hardware costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122316801A_ABST
    Figure CN122316801A_ABST
Patent Text Reader

Abstract

This application discloses a system, method, device, and medium for collaborative access control and security isolation between internal and external networks based on FTTR. The system includes: a main gateway establishing a three-dimensional dynamic role model for access devices based on physical access location, device type, and time window; receiving access behavior information reported by the secondary gateway, determining dimensional matching, and triggering a deviation flag when a mismatch occurs; using a sliding time window to weightedly sum the deviation flags to obtain a weighted deviation degree, and calculating the deviation density; triggering an anomaly determination when the weighted deviation degree exceeds a first threshold and the deviation density is greater than a second threshold; issuing port isolation commands and spoofing configuration files to the corresponding secondary gateway; the secondary gateway modifying the port PVID to classify the device into a shadow VLAN, and returning a protocol success response to subsequent access within it. This application provides real-time protection upon access, requires no historical data, achieves closed-loop isolation without the attacker's awareness, and does not increase the processing burden on the main gateway.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of FTTR security technology, specifically to a system, method, device, and medium for collaborative access control and security isolation between internal and external networks based on FTTR. Background Technology

[0002] FTTR achieves high-speed network coverage throughout the home via fiber optic connections between a main gateway and secondary gateways distributed throughout the rooms. In a typical home network setup, the main gateway serves as the sole exit point for both internal and external networks, while each secondary gateway provides regional wireless access. All access devices operate on the same local area network (LAN) plane and communicate with each other by default. In this network architecture, if IoT devices within the home network are controlled by malware or a remote attacker, they can access other devices within the same LAN or upload stolen data to the external internet.

[0003] Existing technologies require several days to several weeks of data accumulation to build a reliable behavioral profile, during which time newly connected devices lack effective protection. In addition, slow probing behavior by attackers at a low rate may gradually be accepted as normal by the profiling system, leading to missed detections.

[0004] Therefore, existing technologies have long faced a contradiction between the need for immediate protection that takes effect as soon as new devices are connected and the reliance on historical data accumulation, as well as a contradiction between effective isolation and not interrupting normal business and not exposing defensive intentions during anomaly handling. Summary of the Invention

[0005] This application aims to propose a collaborative access control and security isolation system, method, device, and medium for internal and external networks based on FTTR. Through a three-dimensional dynamic role model and a master-slave separation isolation deception architecture, it solves two problems: the protection vacuum period when new devices are connected, and the network outage and accidental damage and exposure of defense intentions during anomaly handling.

[0006] To achieve the above objectives, this application provides an FTTR-based collaborative access control and security isolation system for internal and external networks, including a master gateway and at least one slave gateway. The master gateway is used to establish a three-dimensional dynamic role model for access devices. This model determines the physical access location based on the slave gateway port the device accesses, determines the device type based on the device's MAC address prefix or DHCP request field, and sets a time window based on the device type and access time. The master gateway receives device access behavior information reported by the slave gateways and determines whether the current access behavior matches the three-dimensional dynamic role model in terms of physical access location, device type, and time window. If any dimension does not match, a deviation flag of the corresponding type is triggered based on the mismatched dimension. Each deviation flag corresponds to a preset weight value. The system uses a sliding time window of preset length to accumulate deviations. It then performs a weighted summation of deviation markers within the sliding time window to obtain a weighted deviation. The ratio of the number of occurrences of deviation markers within the sliding time window to the window length is calculated as the deviation density. When the weighted deviation exceeds a first preset threshold and the deviation density is greater than a second preset threshold, an anomaly detection is triggered. After triggering the anomaly detection, a port isolation command and a spoofing configuration file are sent to the slave gateway connected to the access device. The slave gateway receives the port isolation command and the spoofing configuration file. Based on the port isolation command, it modifies the PVID of the corresponding port and assigns the access device to a shadow VLAN. Based on the spoofing configuration file, it returns a protocol success response to subsequent access requests from the access device within the shadow VLAN.

[0007] Optionally, the weighted deviation is calculated as follows: each deviation marker corresponds to a preset deviation event type, and the deviation event type is determined by the mismatch dimension that triggers the deviation marker; wherein, physical access location mismatch corresponds to accessing an unexpected target, time window mismatch corresponds to accessing during an inactive time period, and device type mismatch corresponds to an abnormal traffic pattern; when multiple dimensions mismatch simultaneously, multiple corresponding deviation markers are triggered, and each deviation marker has its own preset weight value; the weighted deviation is the sum of the weight values ​​corresponding to all deviation markers within the sliding time window.

[0008] Optionally, the successful protocol response includes: returning SYN+ACK for TCP connection requests, returning 200 OK for HTTP requests, returning an A record resolution pointing to the virtual IP address for DNS queries, and returning Echo Reply for ICMP requests.

[0009] Preferably, when the gateway returns a successful protocol response, it generates a dynamic virtual MAC address and uses the dynamic virtual MAC address to send a response to the access device; wherein, the dynamic virtual MAC address is generated based on the current time window value, the device identifier, and the gateway ID, and the current time window value is the sequence number of the time window to which the current time belongs or a discretized value of the window start time.

[0010] Optionally, the secondary gateway is further configured to determine that shadow VLAN resources are insufficient when the number of allocated shadow VLANs reaches a preset maximum threshold, and to reclaim the shadow VLAN ID that has not been used for the longest time and clear all virtual MAC address mappings within that VLAN.

[0011] Optionally, the main gateway is further configured to calculate a recovery confidence score after detecting that the access device's behavior has returned to normal. The recovery confidence score is calculated based on the continuous duration during which the device has not triggered a deviation flag within a preset observation window. When the recovery confidence score is greater than a recovery threshold and the duration exceeds a preset duration, a state rollback instruction is sent to the secondary gateway. The secondary gateway is further configured to restore the port PVID to the original VLAN ID according to the state rollback instruction.

[0012] This application also provides a method for collaborative access control and security isolation between internal and external networks based on FTTR, used to implement any of the methods described above, applied to a system including a master gateway and at least one slave gateway, the method comprising: The main gateway establishes a three-dimensional dynamic role model for the access devices. This model determines the physical access location based on the slave gateway port the device connects to, the device type based on the device's MAC address prefix or DHCP request field, and sets a time window based on the device type and access time. The main gateway receives device access behavior information reported by the slave gateways and determines whether the current access behavior matches the three-dimensional dynamic role model in terms of physical access location, device type, and time window. If any dimension does not match, a deviation marker of the corresponding type is triggered based on the mismatched dimension. Each deviation marker corresponds to a preset weight value. The main gateway accumulates the deviation using a preset length sliding time window and applies the deviation within the sliding time window. The deviation markers are weighted and summed to obtain a weighted deviation degree. The ratio of the number of occurrences of the deviation markers within the sliding time window to the window length is calculated as the deviation density. When the weighted deviation degree exceeds a first preset threshold and the deviation density is greater than a second preset threshold, an anomaly determination is triggered. After triggering the anomaly determination, the main gateway sends a port isolation command and a spoofing configuration file to the slave gateway connected to the access device. The slave gateway receives the port isolation command and the spoofing configuration file. The slave gateway modifies the PVID of the corresponding port according to the port isolation command and assigns the access device to the shadow VLAN. According to the spoofing configuration file, the slave gateway returns a protocol success response to subsequent access requests from the access device within the shadow VLAN.

[0013] Optionally, the weighted deviation is calculated as follows: each deviation marker corresponds to a preset deviation event type, and the deviation event type is determined by the mismatch dimension that triggers the deviation marker; wherein, physical access location mismatch corresponds to accessing an unexpected target, time window mismatch corresponds to accessing during an inactive time period, and device type mismatch corresponds to an abnormal traffic pattern; when multiple dimensions mismatch simultaneously, multiple corresponding deviation markers are triggered, and each deviation marker has its own preset weight value; the weighted deviation is the sum of the weight values ​​corresponding to all deviation markers within the sliding time window.

[0014] This application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor, when executing the program, implements any of the methods described above.

[0015] This application also provides a computer-readable storage medium having a computer program stored thereon that, when executed by a processor, implements any of the methods described above.

[0016] The FTTR-based collaborative access control and security isolation system, method, device, and medium for internal and external networks provided in this application have the following beneficial effects: First, because it adopts a three-dimensional dynamic role model based on physical access location, device type and time window, and the information required for model building can be obtained when the device is first connected, without the need for historical traffic statistics or machine learning training, new devices are equipped with protection capabilities as soon as they are connected, which helps to eliminate security vacuum periods. Second, by introducing a time window dimension and combining weighted deviation degree and deviation density dual threshold judgment, different access expectations can be given to devices at different times, avoiding false alarms caused by normal work and rest fluctuations. At the same time, filtering short-term occasional deviations by the deviation density threshold helps to achieve a lower false alarm rate. Third, the architecture of separating the main gateway's decision-making and scheduling, and the local execution of PVID isolation and lightweight protocol response by the slave gateway is adopted. The main gateway does not handle abnormal traffic, and the slave gateway only returns a protocol layer success response without performing deep packet inspection. This helps to achieve closed-loop isolation without the attacker's awareness, and the main gateway's processor load is low. Fourth, the gateway returns a successful protocol response within the shadow VLAN and optionally generates a dynamic virtual MAC address, making it impossible for attackers to perceive that the area has been isolated. Real data is not leaked, which helps to achieve a defense effect that combines transparent isolation with attack behavior recording. Attackers find it difficult to detect the isolation status in a short period of time. Attached Figure Description

[0017] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0018] Figure 1 A schematic block diagram of an internal and external network collaborative access control and security isolation system based on FTTR provided in the embodiments of this application; Figure 2 A flowchart illustrating the FTTR-based collaborative access control and security isolation method for internal and external networks provided in this application embodiment; Figure 3 This is a schematic diagram of the anomaly detection and deception-isolation separation architecture provided in the embodiments of this application; Figure 4 This is a schematic diagram of a home FTTR network topology provided in Embodiment 1 of this application. Detailed Implementation

[0019] Before providing a further detailed description of the embodiments of this application, the nouns and terms involved in the embodiments of this application will be explained, and the nouns and terms involved in the embodiments of this application shall be interpreted as follows.

[0020] (1) The three-dimensional dynamic role model in this application refers to the expected model of device behavior composed of three dimensions: physical access location, device type and time window.

[0021] (2) In this application, the shadow VLAN refers to a virtual local area network used to isolate abnormal devices. The VLAN is configured to local loopback mode only, and access to real devices in the home network and the Internet is prohibited.

[0022] (3) In this application, the successful response of the protocol refers to returning a successful status response that conforms to the protocol specification without completing the actual application layer business, so that the device that initiated the request believes that the request has been processed normally.

[0023] Unless otherwise defined, all technical and scientific terms used in the embodiments of this application have the same meaning as commonly understood by one of ordinary skill in the art. The terminology used in the embodiments of this application is for the purpose of describing the embodiments of this application only and is not intended to limit this application.

[0024] To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings. The described embodiments should not be regarded as limitations on this application. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0025] like Figure 1As shown, this application provides an internal / external network collaborative access control and security isolation system based on FTTR, including a master gateway and at least one slave gateway. The master gateway is used to establish a three-dimensional dynamic role model for access devices. The three-dimensional dynamic role model determines the physical access location based on the slave gateway port through which the device accesses, determines the device type based on the device's MAC address prefix or DHCP request field, and sets a time window based on the device type and access time. The system receives device access behavior information reported by the slave gateway and determines whether the current access behavior matches the three-dimensional dynamic role model in the three dimensions of physical access location, device type, and time window. When any dimension does not match, a deviation flag of the corresponding type is triggered according to the mismatched dimension. Each deviation flag corresponds to a preset weight value. A weighted deviation is obtained by weighting and summing the deviation markers within the sliding time window, and calculating the ratio of the number of occurrences of deviation markers within the sliding time window to the window length as the deviation density. When the weighted deviation exceeds a first preset threshold and the deviation density is greater than a second preset threshold, an anomaly determination is triggered. After triggering the anomaly determination, a port isolation command and a spoofing configuration file are sent to the slave gateway connected to the access device. The slave gateway receives the port isolation command and the spoofing configuration file; modifies the PVID of the corresponding port according to the port isolation command, and assigns the access device to a shadow VLAN; according to the spoofing configuration file, returns a protocol success response to subsequent access requests from the access device within the shadow VLAN. Figure 3As shown, the complete timing of the anomaly judgment and deception-isolation separation architecture of this system includes the following stages: (1) Normal communication stage: The abnormal device (controlled IoT device) sends data packets (such as requests to access other devices on the intranet or the Internet) to the connected slave gateway; the slave gateway forwards the received data packets to the master gateway and simultaneously reports the device access behavior information (including source MAC, target IP, protocol type, timestamp, etc.) to the master gateway; (2) Anomaly detection stage: The master gateway verifies the current access behavior according to the three-dimensional dynamic role model; when any dimension does not match, a deviation mark is triggered, and the weighted deviation degree and deviation density are accumulated within the sliding time window. When both thresholds are exceeded, the main gateway determines that the device is an abnormal device and generates a spoofing profile (containing the protocol type to be responded to and the corresponding successful response template); (3) Command issuance stage: The main gateway issues two types of commands to the slave gateway connected to the abnormal device through a proprietary control protocol: ① Set-Port-PVID (port isolation command, carrying the target port number and shadow VLAN ID); ② Set-Spoofing-Profile (spoofing profile issuance command, carrying protocol response rules); (4) Isolation spoofing stage: After receiving the command, the slave gateway modifies the PVID of the corresponding port and assigns the port to the shadow VLAN; for ARP requests, the slave gateway returns the dynamic virtual MAC address; for TCP, HTTP, DNS, ICMP and other requests, it returns a protocol successful response according to the spoofing profile; thereafter, subsequent requests from the abnormal device are no longer forwarded to the main gateway, but are only responded to locally by the slave gateway in the shadow VLAN. Since the main gateway is only responsible for judgment and scheduling, and the slave gateway performs isolation and lightweight response locally, the processor load of the main gateway is low, the slave gateway does not need deep packet parsing, and the overall system can achieve transparent decoupling without increasing hardware costs.

[0026] In a preferred embodiment, the weighted deviation is calculated as follows: each deviation marker corresponds to a preset deviation event type, which is determined by the mismatch dimension that triggers the deviation marker. Specifically, a physical access location mismatch corresponds to accessing an unexpected target, a time window mismatch corresponds to accessing during an inactive time period, and a device type mismatch corresponds to an abnormal traffic pattern. When multiple dimensions mismatch simultaneously, multiple corresponding deviation markers are triggered, each with its own preset weight value. The weighted deviation is the sum of the weight values ​​corresponding to all deviation markers within the sliding time window. This allows deviations in different dimensions to have different risk weights, more accurately reflecting the degree of abnormality in behavior.

[0027] In another preferred embodiment, the protocol success response includes returning SYN+ACK for TCP connection requests, 200 OK for HTTP requests, an A record resolution pointing to the virtual IP address for DNS queries, and Echo Reply for ICMP requests. By aggregating communication protocols covering the vast majority of devices in a home network, basic network activity of devices can be maintained within a shadow VLAN.

[0028] In another preferred embodiment, when the gateway returns a successful protocol response, it generates a dynamic virtual MAC address and uses the dynamic virtual MAC address to send a response to the access device. The dynamic virtual MAC address is generated based on the current time window value, the device identifier, and the gateway ID. The current time window value is either the sequence number of the time window to which the current time belongs or a discretized value of the window's start time. Because the MAC address changes with the time window, attackers cannot detect a fixed MAC address pattern when performing ARP scans at different times, making it difficult to identify the deception environment.

[0029] Preferably, in order to ensure that the limited VLAN resources of the slave gateway can be reused and to support concurrent anomaly handling of multiple devices, the slave gateway is also used to determine that the shadow VLAN resources are insufficient when the number of allocated shadow VLANs reaches a preset maximum threshold, and to reclaim the shadow VLAN ID that has not been used for the longest time and clear all virtual MAC address mappings in that VLAN.

[0030] Furthermore, the primary gateway is also used to calculate a recovery confidence score after detecting that the access device's behavior has returned to normal. The recovery confidence score is calculated based on the continuous duration during which the device has not triggered a deviation flag within a preset observation window. When the recovery confidence score is greater than a recovery threshold and the duration exceeds a preset duration, a state rollback command is sent to the secondary gateway. The secondary gateway is also used to restore the port PVID to its original VLAN ID according to the state rollback command. This rollback mechanism enables the device to automatically exit the isolation state after its behavior recovers, reducing the impact on normal communication.

[0031] like Figure 2As shown, this application also provides a method for collaborative access control and security isolation between internal and external networks based on FTTR, applied to a system including a master gateway and at least one slave gateway. The method includes: the master gateway establishing a three-dimensional dynamic role model for the access device; the three-dimensional dynamic role model determines the physical access location based on the slave gateway port accessed by the device, determines the device type based on the device's MAC address prefix or DHCP request field, and sets a time window based on the device type and access time; the master gateway receives device access behavior information reported by the slave gateway, and determines whether the current access behavior matches the three-dimensional dynamic role model in the three dimensions of physical access location, device type, and time window; when any dimension does not match, a deviation flag of the corresponding type is triggered according to the mismatched dimension; wherein, each deviation flag corresponds to a preset weight value; the master gateway... The main gateway uses a sliding time window of preset length to accumulate deviations. It then performs a weighted summation of deviation markers within the sliding time window to obtain a weighted deviation. The ratio of the number of occurrences of deviation markers within the sliding time window to the window length is calculated as the deviation density. When the weighted deviation exceeds a first preset threshold and the deviation density is greater than a second preset threshold, an anomaly detection is triggered. After triggering the anomaly detection, the main gateway sends a port isolation command and a spoofing configuration file to the slave gateway connected to the access device. The slave gateway receives the port isolation command and the spoofing configuration file. Based on the port isolation command, the slave gateway modifies the PVID of the corresponding port and assigns the access device to a shadow VLAN. Based on the spoofing configuration file, the slave gateway returns a protocol success response to subsequent access requests from the access device within the shadow VLAN. The steps of this method correspond to those of the system described above, and the technical effects will not be elaborated further.

[0032] In a preferred embodiment, the weighted deviation is calculated as follows: each deviation marker corresponds to a preset deviation event type, which is determined by the mismatch dimension that triggers the deviation marker; wherein, physical access location mismatch corresponds to accessing an unexpected target, time window mismatch corresponds to accessing during an inactive time period, and device type mismatch corresponds to an abnormal traffic pattern; when multiple dimensions mismatch simultaneously, multiple corresponding deviation markers are triggered, each deviation marker having its own preset weight value; the weighted deviation is the sum of the weight values ​​corresponding to all deviation markers within the sliding time window.

[0033] This application also provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that the processor implements the above-described method when executing the program.

[0034] This application also provides a computer-readable storage medium storing a computer program, characterized in that the program, when executed by a processor, implements the above-described method. This storage medium can be used for firmware upgrades of a master gateway or a slave gateway. The technical solution of this application will be clearly and completely described below with reference to the accompanying drawings and specific embodiments. In actual deployment, an applicable solution can be selected according to the network topology. The described embodiments are only a part of the embodiments of this application, and not all of them.

[0035] Example 1: Figure 4 The illustration shows a home FTTR network topology in Embodiment 1 of this application. A main gateway (such as a Huawei OptiXstar K662c) is connected via fiber optic cable to multiple secondary gateways (such as Huawei OptiXstar K662d) installed in areas such as the living room and bedrooms. A smart camera, acting as an access device, is connected to a port of the secondary gateway in the living room; its physical access location is uniquely determined by the secondary gateway identifier and port number corresponding to that port.

[0036] The main gateway establishes a 3D dynamic role model for the camera: the physical access location is the living room, the gateway is port 2, the device type is camera (identified by the OUI organization unique identifier of the MAC address), and the time window is 24 hours a day (00:00-24:00) (because cameras usually need to be online 24 hours a day).

[0037] After receiving access behavior information reported by the secondary gateway, the main gateway checks the matching status of each dimension. When any dimension does not match, a corresponding deviation flag is triggered according to the mismatch dimension: physical access location mismatch corresponds to accessing an unexpected target (weight 0.4), time window mismatch corresponds to accessing during an inactive time period (weight 0.3), and device type mismatch corresponds to an abnormal traffic pattern (weight 0.3). For example, when a camera attempts to access the main gateway's management interface after being attacked (which is an unexpected target), a deviation flag for physical access location mismatch is triggered.

[0038] A 10-minute sliding time window is used. The weighted deviation is calculated by summing the deviation markers within the window. Simultaneously, the ratio of the number of deviation marker occurrences to the window length is calculated as the deviation density. An anomaly is triggered when the weighted deviation exceeds a first preset threshold of 2.0 and the deviation density is greater than a second preset threshold of 0.2 times / minute. Example: If the camera experiences 3 position mismatches (weighted deviation = 3 × 0.4 = 1.2) and 2 time mismatches (weighted deviation = 2 × 0.3 = 0.6) within 10 minutes, the total weighted deviation = 1.8 < 2.0, and no anomaly is triggered. If another position mismatch occurs (weighted deviation increases by 0.4 to 2.2) and the total number of deviations reaches 6 (deviation density = 0.6 times / minute), the dual threshold conditions are met, and an anomaly is triggered.

[0039] The primary gateway sends port isolation commands and spoofing configuration files to the secondary gateway. Successful protocol responses include: SYN+ACK for TCP connection requests, 200 OK for HTTP requests, an A record resolution pointing to the virtual IP address for DNS queries, and Echo Reply for ICMP requests. The secondary gateway modifies the PVID of the corresponding port according to the port isolation commands, assigns the camera to the shadow VLAN, and dynamically generates a virtual MAC address based on the current time window value, device identifier, and secondary gateway ID to respond.

[0040] When the number of allocated shadow VLANs reaches the preset maximum threshold, the gateway determines that resources are insufficient, reclaims the least used shadow VLAN ID, and clears all virtual MAC address mappings within that VLAN. After the camera behavior returns to normal, the main gateway calculates the recovery confidence based on the continuous duration within a preset observation window during which deviation markers have not been triggered. When the recovery confidence is greater than 0.85 and lasts for more than 30 minutes, it sends a status rollback command to the secondary gateway, which restores the port PVID to the original VLAN ID. If the main gateway fails, the secondary gateway's local policy can temporarily allow or directly block access, synchronizing logs after the main gateway recovers. When a link is lost, the secondary gateway caches the most recent deviation markers and discards them after a timeout.

[0041] This embodiment achieves beneficial effects such as instant protection for new device access (eliminating security vacuum periods), low false alarm rate (time window combined with dual thresholds to filter occasional deviations), attacker-unawareness (protocol success response combined with dynamic virtual MAC address), low load on the main gateway (master-slave separation architecture), and automatic fallback.

[0042] Example 2: The main gateway establishes a 3D dynamic role model for the access device, and uses a dual threshold of weighted deviation degree and deviation density to trigger anomaly detection. The detection logic and weight design are the same as in Example 1. The main gateway issues port isolation commands and spoofing configuration files, and the protocol success response content is the same as in Example 1. The remaining steps are also the same as in Example 1, the only difference being that this example does not include shadow VLAN resource reclamation and state rollback mechanisms. By omitting dynamic MAC, resource reclamation, and rollback, it can still achieve immediate protection for new devices (without historical data) and attacker-unaware isolation (maintaining successful protocol layer responses), and the computational overhead from the gateway is lower, making it suitable for scenarios with limited computing power or low requirements for MAC randomness.

[0043] Based on the above technical solution, this application can achieve the following beneficial effects: (1) A three-dimensional role model is established based on the physical location, device type and access time that can be obtained upon first access, without the need for historical traffic statistics or machine learning training, which helps to eliminate the security vacuum period after the new device is accessed; (2) By introducing the time window dimension and combining the weighted deviation degree and deviation density dual threshold judgment, different access expectations can be given to the device at different times, avoiding false alarms caused by normal work and rest fluctuations. At the same time, the deviation density threshold filters out short-term occasional deviations and controls the false alarm rate at an extremely low level. (3) The main gateway determines the scheduling, and the slave gateway performs PVID isolation and lightweight protocol response locally. The main gateway does not handle abnormal traffic, and the slave gateway only returns a protocol layer success response without performing deep packet inspection. When hundreds of devices are online, the CPU utilization rate of the main gateway is about ten percent, which helps to achieve closed-loop isolation without the attacker's awareness. (4) The gateway returns a protocol success response within the shadow VLAN and optionally generates a dynamic virtual MAC address, making it impossible for attackers to perceive that it has been isolated and real data is not leaked. Usually, attackers will not be able to detect it for several hours or even one or two days, which helps to achieve a defense effect of transparent decoupling and attack behavior recording. (5) The state rollback mechanism allows the device to automatically exit isolation after its behavior returns to normal, which helps to reduce the long-term impact on normal communication; The above descriptions are merely embodiments of this application. Commonly known technical solutions or characteristics are not described in detail here. It should be noted that those skilled in the art can make various modifications and improvements without departing from the technical solution of this application. These modifications and improvements should also be considered within the scope of protection of this application, and will not affect the effectiveness of the application or the practicality of the patent. The scope of protection claimed in this application should be determined by the content of its claims, and the specific embodiments described in the specification can be used to interpret the content of the claims.

Claims

1. An FTTR-based internal and external network cooperative access control and security isolation system, characterized in that, Includes a main gateway and at least one slave gateway; The main gateway is used to establish a three-dimensional dynamic role model for the access device. The three-dimensional dynamic role model determines the physical access location based on the slave gateway port through which the device accesses, determines the device type based on the device's MAC address prefix or DHCP request field, and sets a time window based on the device type and access time. It receives device access behavior information reported by the slave gateway and determines whether the current access behavior matches the three-dimensional dynamic role model in three dimensions: physical access location, device type, and time window. When any dimension does not match, a deviation marker of the corresponding type is triggered according to the mismatched dimension. Each deviation marker corresponds to a preset weight value. A preset length sliding time window is used to accumulate the deviation degree. The deviation markers within the sliding time window are weighted and summed to obtain a weighted deviation degree. The ratio of the number of occurrences of deviation markers within the sliding time window to the window length is calculated as the deviation density. When the weighted deviation degree exceeds a first preset threshold and the deviation density is greater than a second preset threshold, an anomaly determination is triggered. After triggering the anomaly determination, a port isolation command and a deception configuration file are sent to the slave gateway connected to the access device. The gateway is configured to receive the port isolation command and the spoofing configuration file; modify the PVID of the corresponding port according to the port isolation command, and assign the access device to the shadow VLAN; and return a protocol success response to subsequent access requests from the access device within the shadow VLAN according to the spoofing configuration file.

2. The system of claim 1, wherein, The weighted deviation is calculated as follows: each deviation marker corresponds to a preset deviation event type, which is determined by the mismatch dimension that triggers the deviation marker; wherein, physical access location mismatch corresponds to accessing an unexpected target, time window mismatch corresponds to accessing during an inactive time period, and device type mismatch corresponds to an abnormal traffic pattern; when multiple dimensions mismatch simultaneously, multiple corresponding deviation markers are triggered, and each deviation marker has its own preset weight value; the weighted deviation is the sum of the weight values ​​corresponding to all deviation markers within the sliding time window.

3. The system of claim 1, wherein, Successful responses to the protocol include: returning SYN+ACK for TCP connection requests, returning 200 OK for HTTP requests, returning an A record resolution pointing to the virtual IP address for DNS queries, and returning Echo Reply for ICMP requests.

4. The system of claim 1 or 3, wherein, When the gateway returns a successful protocol response, it generates a dynamic virtual MAC address and uses the dynamic virtual MAC address to send a response to the access device. The dynamic virtual MAC address is generated based on the current time window value, the device identifier, and the gateway ID. The current time window value is the sequence number of the time window to which the current time belongs or a discretized value of the window start time.

5. The system of claim 1, wherein, The gateway is also used to determine that shadow VLAN resources are insufficient when the number of allocated shadow VLANs reaches a preset maximum threshold, and to reclaim the shadow VLAN ID that has not been used for the longest time and clear all virtual MAC address mappings in that VLAN.

6. The system of claim 1, wherein, The main gateway is also used to calculate the recovery confidence score after detecting that the access device behavior has returned to normal. The recovery confidence score is calculated based on the continuous duration during which the device has not triggered a deviation flag within a preset observation window. When the recovery confidence score is greater than the recovery threshold and the duration exceeds the preset duration, a state rollback instruction is sent to the slave gateway. The slave gateway is also used to restore the port PVID to the original VLAN ID according to the state rollback instruction.

7. A method for FTTR-based internal and external network collaborative access control and security isolation, characterized in that, Applied to a system including a master gateway and at least one slave gateway, the method includes: The main gateway establishes a three-dimensional dynamic role model for the access device. The three-dimensional dynamic role model determines the physical access location based on the access port of the device to the secondary gateway, determines the device type based on the device MAC address prefix or DHCP request field, and sets a time window based on the device type and access time. The main gateway receives device access behavior information reported by the secondary gateway, and determines whether the current access behavior matches the three-dimensional dynamic role model in three dimensions: physical access location, device type, and time window. When any dimension does not match, a deviation flag of the corresponding type is triggered according to the mismatched dimension. Each deviation flag corresponds to a preset weight value. The main gateway uses a sliding time window of a preset length to accumulate the deviation. It performs a weighted summation on the deviation markers within the sliding time window to obtain a weighted deviation. It also calculates the ratio of the number of occurrences of the deviation markers within the sliding time window to the window length as the deviation density. When the weighted deviation exceeds a first preset threshold and the deviation density is greater than a second preset threshold, an anomaly determination is triggered. After triggering an anomaly detection, the main gateway sends a port isolation command and a deception configuration file to the slave gateway connected to the access device. The port isolation command and spoofing configuration file are received from the gateway; The gateway modifies the PVID of the corresponding port according to the port isolation instruction, and assigns the access device to the shadow VLAN; The gateway, based on the spoofing configuration file, returns a protocol success response to subsequent access requests from the access device within the shadow VLAN.

8. The method of claim 7, wherein, The weighted deviation is calculated as follows: each deviation marker corresponds to a preset deviation event type, which is determined by the mismatch dimension that triggers the deviation marker; wherein, physical access location mismatch corresponds to accessing an unexpected target, time window mismatch corresponds to accessing during an inactive time period, and device type mismatch corresponds to an abnormal traffic pattern; when multiple dimensions mismatch simultaneously, multiple corresponding deviation markers are triggered, and each deviation marker has its own preset weight value; the weighted deviation is the sum of the weight values ​​corresponding to all deviation markers within the sliding time window.

9. An electronic device comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the method as described in claim 7 or 8.

10. A computer-readable storage medium having stored thereon a computer program, characterized in that, When the program is executed by the processor, it implements the method as described in claim 7 or 8.