A dynamic key agreement method and system
Patent Information
- Application Number
- CN202611256061.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2026-08-19
- Publication Date
- 2026-09-29
AI Technical Summary
[0004]这种检测方法中入侵检测与密钥协商相互分离,密钥更新时机的选择依赖固定周期或预设阈值,无法根据协商过程本身的实时行为特征进行自适应调节
1、本发明通过直接采集链路层确认帧的硬件时间戳,提取包含间隔抖动、计算停顿指纹及响应构造节奏的微节奏向量,将不可见的硬件处理特征转化为可计算的行为指纹,实现了链路层微观时序的内生感知,为预共享密钥或简易密钥交换提供了内生的身份验证能力,从根本上解决了密钥泄露后被中间人冒用的风险;
Smart Images

Figure CN122845119A_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of network security technology, and in particular relates to a dynamic key negotiation method and system. Background Technology
[0002] In small to medium-sized internal network environments, office terminals, operation terminals, data servers, dedicated cryptographic devices, and other equipment communicate via Ethernet links. The communicating parties need to periodically perform key negotiation to update the session key in order to ensure the confidentiality and integrity of data transmission.
[0003] In existing dynamic key negotiation schemes, threat awareness typically relies on a stand-alone intrusion detection system. This intrusion detection system is deployed in a bypass or connected in series within the network. After detecting abnormal behavior through characteristic analysis of network traffic, it triggers a key update or session blocking via an alarm signal.
[0004] In this detection method, intrusion detection and key negotiation are separated. The timing of key updates depends on a fixed period or a preset threshold, and cannot be adaptively adjusted according to the real-time behavioral characteristics of the negotiation process itself. When the network environment experiences normal drift or minor anomalies, the fixed threshold is often unable to distinguish between normal fluctuations and real attacks. It is very easy for the response to be delayed due to the threshold being set too wide, giving attackers enough time to complete key theft or session hijacking. Alternatively, if the threshold is set too strict, false alarms will occur frequently, causing unnecessary interruptions to normal business communication. Summary of the Invention
[0005] The purpose of this invention is to solve one of the above-mentioned technical problems and provide a dynamic key negotiation method and system.
[0006] To achieve the above objectives, the technical solution adopted by the present invention is as follows: A dynamic key negotiation method includes the following steps: The hardware timestamp sequence of link layer confirmation frames during multiple historical security key negotiation processes is collected, and the micro-rhythm vector of each historical negotiation process is extracted. The micro-rhythm vector is used to characterize the link layer temporal behavior pattern of each historical security key negotiation interaction process. Based on the micro-rhythm vectors from multiple historical negotiation processes, a macro-rhythm profile of the communication peer is established; the macro-rhythm profile is used to characterize the normal fluctuation range of the link layer interaction timing and the correlation distribution pattern among multiple features. During real-time key negotiation, the hardware timestamp sequence of the link layer confirmation frames of the current negotiation process is collected, and the current micro-rhythm vector is extracted. The current micro-rhythm vector is compared with the macro-rhythm profile to calculate multi-dimensional quantitative indicators; these indicators are used to characterize the degree of temporal deviation of the current micro-rhythm vector. Threat confidence is calculated based on multi-dimensional quantitative indicators; threat confidence is used to characterize the degree of risk of the current negotiation being subjected to a man-in-the-middle attack. Based on the numerical range of the threat confidence level, implement a graded response strategy that matches the threat level.
[0007] In some embodiments of the present invention, the extraction of the micro-rhythm vector for each historical negotiation process includes: Discretize the arrival time difference of adjacent acknowledgment frames in the hardware timestamp sequence, calculate the Shannon entropy value of the discrete probability distribution, and obtain the message arrival interval jitter characteristics. The number of occurrences, maximum duration, and relative position distribution of each silent period on the normalized negotiation time axis of the hardware timestamp sequence without data arrival are detected to obtain computational pause fingerprint features. When the key negotiation response message is transmitted in fragments of multiple link layer frames, the frame interval variation coefficient and first-order autocorrelation coefficient are calculated based on the frame interval sequence at the arrival time of each fragment frame to obtain the response construction rhythm characteristics. The message arrival interval jitter feature, the calculation pause fingerprint feature, and the response construction rhythm feature are combined in a preset order to generate a micro-rhythm vector.
[0008] In some embodiments of the present invention, establishing a macro rhythm profile of the communication peer includes: Kernel density estimation is performed on the sample values collected during the security negotiation phase for each micro-rhythm component to obtain the probability density function, and the tolerance domain boundary of each micro-rhythm component is determined based on the preset quantile to construct the tolerance domain model. Based on the micro-rhythm vector of multiple historical security key negotiations, the correlation coefficient and covariance matrix between each micro-rhythm component are calculated, and a correlation matrix model is constructed. Record the timestamps of multiple historical security key negotiations, calculate the mean and standard deviation of adjacent negotiation time intervals, determine the lower limit of the prediction interval based on the mean and standard deviation, and construct a negotiation interval stability model. A macro-rhythm profile is constructed based on the tolerance domain model, the correlation matrix model, and the negotiation interval stability model.
[0009] In some embodiments of the present invention, the tolerance domain boundary includes an upper bound and a lower bound. Establishing a macro rhythm profile of the communication peer further includes: For each micro-rhythm component, maintain an exponentially weighted moving average for the lower and upper bounds of the tolerance domain; After each security key negotiation update, the actual tolerance domain boundary is updated to a weighted sum of the new boundary value and the historical moving average by a preset smoothing coefficient, thus constructing a trend tracking model.
[0010] In some embodiments of the present invention, the negotiation method further includes the following steps: During real-time key negotiation, determine whether the threat confidence level of the current negotiation is less than a preset security threshold; When the threat confidence level is less than the preset security threshold, the micro-rhythm vector of the current negotiation is included in the sample pool; When the sample pool reaches the preset capacity, the sample pool is replaced with samples of equal probability using the reservoir sampling algorithm to maintain the fixed capacity of the sample pool. The tolerance zone boundary in the macro rhythm profile is recalculated based on the updated sample pool, and the exponentially weighted moving average of the tolerance zone boundary is updated based on the trend-following model.
[0011] In some embodiments of the present invention, the multi-dimensional quantitative indicators include single-point deviation, joint deviation, and interval anomaly; the multi-dimensional quantitative indicators are calculated as follows: Each feature component in the current micro-rhythm vector is compared with the fluctuation boundary of the corresponding tolerance domain model to calculate the single-point deviation degree used to characterize the single-point out-of-bounds amplitude. Based on the correlation matrix model, the degree of joint offset of the current micro-rhythm vector relative to the overall historical micro-rhythm vector samples is calculated to obtain the joint deviation. Based on the negotiation interval stability model, the degree of abnormality of the current negotiation initiation time relative to the historical negotiation frequency is calculated to obtain the interval abnormality degree.
[0012] In some embodiments of the present invention, threat confidence is calculated based on multi-dimensional quantitative indicators, including: The basic score is obtained by weighting and summing the single-point deviation, joint deviation, and interval anomaly based on preset weights. Obtain the context identifier corresponding to the current negotiation process; the context identifier includes at least one of the following: continuous anomaly identifier, first communication identifier, or untrusted period identifier; the continuous anomaly identifier is used to indicate whether the basic scores of the most recent consecutive negotiations have all exceeded the preset anomaly judgment threshold; the first communication identifier is used to indicate whether the macro rhythm profile of the communication peer is not stored locally; the untrusted period identifier indicates whether the current negotiation initiation time is in a preset high-risk period; Threat confidence is obtained by adjusting the base score based on contextual identifiers.
[0013] In some embodiments of the present invention, implementing a graded response strategy that matches the threat level includes: The threat confidence level is compared sequentially with a preset first threshold, a second threshold, and a third threshold; wherein the first threshold is less than the second threshold; and the second threshold is less than the third threshold. When the threat confidence level is less than the first threshold, the session key generated in this negotiation is allowed to take effect, and the macro rhythm profile is updated. When the threat confidence level is greater than or equal to the first threshold and less than the second threshold, the session key is allowed to take effect and implicit challenge verification is performed. The implicit challenge verification uses the newly generated session key to encrypt the preset challenge data, sends the encryption result to the peer in the first application data packet, and verifies the response data returned by the peer. When the threat confidence level is greater than or equal to the second threshold and less than the third threshold, the session key is temporarily suspended and out-of-band verification is performed. When the threat confidence level is greater than or equal to the third threshold, all key materials generated in this negotiation are discarded, and subsequent negotiation requests are blocked.
[0014] In some embodiments of the present invention, implicit challenge verification is performed, including: The initiator generates a random number, encrypts and authenticates the random number using a new session key, and appends the generated ciphertext and authentication tag to the extended field of the first application data packet before sending it to the responder. Wait for the responder to echo the decrypted random number within the preset waiting time; Upon receiving a correct response, the communication is confirmed to be secure and the verification process ends. When an error is echoed or a timeout occurs, the threat confidence level is raised to the preset blocking level, the key is discarded, and subsequent negotiation requests are blocked.
[0015] Some embodiments of the present invention further provide a dynamic key negotiation protection system, which is deployed in a network security device in a communication link, comprising: The profile building module is used to collect the hardware timestamp sequence of link layer confirmation frames during multiple historical security key negotiations, extract the micro-rhythm vector of each historical negotiation process, and build a macro-rhythm profile of the communication peer based on the micro-rhythm vector of multiple historical negotiation processes. The real-time monitoring module is used to collect the hardware timestamp sequence of the link layer confirmation frames of the current negotiation process and extract the current micro-rhythm vector during the real-time key negotiation process. The deviation calculation module is used to compare the current micro-rhythm vector with the macro-rhythm profile and calculate multi-dimensional quantitative indicators. The fusion judgment module is used to calculate threat confidence based on multi-dimensional quantitative indicators; The tiered response module is used to execute tiered response strategies that match the threat level based on the numerical range in which the threat confidence level falls.
[0016] The beneficial effects of this invention are as follows: 1. This invention directly collects the hardware timestamps of the link layer confirmation frames and extracts a micro-rhythm vector containing interval jitter, calculation pause fingerprints, and response construction rhythm. It transforms the invisible hardware processing features into computable behavioral fingerprints, realizes the intrinsic perception of the micro-temporal sequence of the link layer, and provides intrinsic authentication capabilities for pre-shared keys or simplified key exchanges, fundamentally solving the risk of key leakage and misuse by man-in-the-middle. 2. This invention uses kernel density estimation to construct a tolerance domain model, combines it with reservoir sampling to maintain a fixed-capacity safe sample pool, and tracks long-term changes in the tolerance domain boundary through exponentially weighted moving average. It only absorbs safe samples to update the profile, smoothly absorbs normal drift such as equipment aging, and maintains high sensitivity to sudden changes in attacks. This enables the dynamic evolution and adaptive updating of the behavioral baseline profile in long-term operation. 3. This invention quantifies the degree of deviation from three dimensions: single-point deviation, joint deviation, and interval anomaly. Single-point deviation detects isolated anomalies, Mahalanobis distance identifies multi-feature collaborative offsets, and interval anomaly capture frequency is accelerated. On this basis, a context factor is introduced to adjust the basic score, avoiding the one-sidedness that may be caused by a single indicator or isolated judgment, and improving the accuracy and reliability of threat assessment. 4. This invention implements a four-level progressive handling based on threat confidence, so that the handling intensity is precisely matched with the threat level. When the threat level is low, communication availability is maintained at the lowest cost. When the threat level increases, the verification strength is progressively enhanced. When an attack is confirmed, the key is blocked from taking effect, thus achieving a dynamic balance between security and availability.
[0017] Other features and advantages of the invention will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the invention. The objects and other advantages of the invention may be realized and obtained by means of the structures pointed out in the description, claims and drawings. Attached Figure Description
[0018] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the specific embodiments of the present invention will be described in detail below with reference to the accompanying drawings. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0019] Figure 1 This is a flowchart of a dynamic key negotiation method; Figure 2 This is a schematic diagram of a dynamic key negotiation system. Detailed Implementation
[0020] To make the objectives, technical solutions, and advantages of this application clearer, the application is described and illustrated below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application. All other embodiments obtained by those skilled in the art based on the embodiments provided in this application without inventive effort are within the scope of protection of this application.
[0021] It should be noted that the terminology used herein is for the purpose of describing particular implementations only and is not intended to limit the exemplary implementations according to this application. As used herein, unless the context clearly indicates otherwise, the singular form is also intended to include the plural form. Furthermore, it should be understood that the terms “comprising” and “having”, and any variations thereof, are intended to cover non-exclusive inclusion, for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such process, method, product, or apparatus.
[0022] In existing small and medium-sized internal network environments such as government agencies and research institutes, office terminals, operation terminals, data servers, and dedicated cryptographic devices communicate via Ethernet links. Both parties need to periodically perform key negotiation to update session keys to ensure the confidentiality and integrity of data transmission.
[0023] In existing dynamic key negotiation schemes, threat awareness typically relies on a separately deployed intrusion detection system. This system is deployed in bypass mode or connected in series within the network. After detecting abnormal behavior through network traffic feature analysis, it triggers a key update or session blocking via an alarm signal. In this approach, intrusion detection and key negotiation are separated, which has the following drawbacks: 1. Threat perception and key negotiation are poorly coupled. The alarm results of intrusion detection systems are usually binary judgments, lacking characterization and quantitative mapping of attack types and threat levels, and the response strategies are relatively simple. 2. The timing of key updates depends on a fixed period or a preset threshold, and cannot be adaptively adjusted according to the real-time behavioral characteristics of the negotiation process itself. 3. Link-layer attack behaviors exhibit observable changes in micro-timing indicators such as confirmation frame sending rhythm and response latency. However, existing solutions have limited ability to detect link-layer threats and mainly rely on upper-layer traffic analysis, making it difficult to capture the timing anomalies introduced by man-in-the-middle attacks at the lower layer. 4. In small and medium-sized internal network environments, the conditions for deploying a complete public key infrastructure are often limited. When the two parties use pre-shared keys or simplified key exchange, once the pre-shared key is leaked, there is a lack of inherent authentication methods. A middleman can establish an independent encrypted channel to eavesdrop or tamper with the data without being detected.
[0024] Therefore, there is an urgent need to provide a dynamic key negotiation method that can embed a threat perception mechanism into the key negotiation process, utilize the link-layer timing characteristics of the negotiation interaction to construct behavioral benchmarks and monitor deviations in real time, and realize real-time perception and graded blocking of man-in-the-middle attacks.
[0025] Where there is no conflict, the embodiments and features in the embodiments of the present invention can be combined with each other.
[0026] The technical solution of the present invention will be described in detail below with reference to specific embodiments and accompanying drawings.
[0027] As attached Figure 1 - Appendix Figure 2 As shown in the illustrative embodiment of the dynamic key negotiation method of the present invention, the method can be applied to the edge network environment of a smart park, and is used to detect man-in-the-middle attack threats in real time during the key negotiation process between various terminals and edge computing nodes in the park, and to perform graded handling according to the degree of threat.
[0028] In this embodiment, the smart park deployed using the dynamic key negotiation method integrates two core scenarios: security monitoring and business office.
[0029] The park is equipped with at least front-end sensing devices, office terminals, edge network infrastructure, and central-side equipment.
[0030] The front-end sensing devices include high-definition network cameras (supporting H.265 encoding), access control controllers, intrusion detectors, and other security monitoring equipment. These devices continuously collect video streams and sensor data, which are then uploaded to the park's video management server (VMS) or intelligent analysis server via the edge network.
[0031] Office terminals include employees' desktop computers, laptops, IP phones, and wireless access points (APs) for daily document processing, email sending and receiving, video conferencing, and other business-related tasks.
[0032] Edge network infrastructure mainly includes edge computing gateways, lightweight aggregation switches, industrial-grade Ethernet switches, and network-attached storage (NAS). Edge computing gateways are deployed in the low-voltage rooms of various buildings or at the aggregation nodes of the campus, providing near-field computing, protocol conversion, and local data processing capabilities, while also serving as the endpoint for key negotiation.
[0033] The central side includes the campus data center, which is equipped with core switches, authentication servers (such as RADIUS), video management servers, and file servers.
[0034] In this embodiment, the two communicating parties are referred to as the initiator and the responder. The initiator can be a security camera, an office terminal, or an edge computing gateway, and the responder can be an edge computing gateway, a video management server, or a file server.
[0035] Typical communication links include: The link between the camera and the edge gateway (key negotiation before encrypted transmission of the video stream); The link between office terminals and file servers (encrypted access to office documents); The link between the edge gateway and the central server (cross-subnet data aggregation).
[0036] The two ends communicate via a standard Ethernet link, with the link layer conforming to the IEEE 802.3 standard. The initiator and responder perform key negotiation at regular intervals according to the security policy to update the session key.
[0037] The negotiation cycle can be flexibly set according to the scenario. For example, in a security monitoring scenario, the camera and the edge gateway can be set to update the session key every 90 minutes to prevent the video stream from being stolen or tampered with by a man-in-the-middle.
[0038] In business office scenarios, office terminals and file servers can be set to update every 120 minutes.
[0039] In administrative office areas where data is highly sensitive, the time can be reduced to 60 minutes.
[0040] During key negotiation, the initiator and responder each generate a temporary key pair based on the SM2 elliptic curve algorithm. After exchanging public keys, they each execute the SM2 key exchange protocol to calculate a shared key. This shared key is then processed by a key derivation function based on the SM3 cryptographic hash algorithm and used as the session key. This invention does not involve improvements to the aforementioned key negotiation protocol and cryptographic algorithm itself. Instead, it utilizes the timing data of acknowledgment frames generated at the link layer during the negotiation interaction process to achieve threat perception. The hardware network interface controller (NIC) of the edge computing gateway can directly provide microsecond-level precision acknowledgment frame arrival timestamps, without relying on upper-layer operating system scheduling, thus ensuring the accuracy of feature collection.
[0041] This dynamic key negotiation method is divided into a profile building phase and a real-time verification phase. The profile building phase is executed in a secure network environment (e.g., during the initialization of a new system in a campus, or within a maintenance window after manual confirmation by a security administrator that no attacks exist), establishing a behavioral baseline for each communication peer, known as a macro-rhythm profile. The real-time verification phase is executed synchronously during each key negotiation process, using the macro-rhythm profile to evaluate the current negotiation behavior, determine whether there are attack threats, and take tiered measures.
[0042] The profile construction phase is performed during device network initialization or within a network maintenance window confirmed by the security administrator. During this phase, the communication environment is deemed secure and trustworthy, and there is no possibility of man-in-the-middle attacks.
[0043] The method includes the following steps.
[0044] S1: Collect the hardware timestamp sequence of link layer confirmation frames during multiple historical security key negotiation processes, and extract the micro-rhythm vector for each historical negotiation process. The micro-rhythm vector is used to characterize the link layer temporal behavior pattern of each historical security key negotiation interaction process.
[0045] In this embodiment of the application, historical security key negotiation refers to key negotiation interaction performed in a network environment where the security administrator has confirmed that there is no attack threat, and the interaction process is regarded as a benchmark sample of normal communication.
[0046] A data link layer acknowledgment frame is an immediate feedback signal sent directly by hardware after a data frame is successfully received in the IEEE 802.3 standard. It includes ACK acknowledgment frames, and their arrival timing can reflect the physical interaction characteristics of the two communicating parties.
[0047] Hardware timestamp sequences refer to the ordered set of arrival times of acknowledgment frames recorded by the network interface controller (NIC) with microsecond-level precision. Unlike timestamps recorded by the operating system software, hardware timestamps are not affected by operating system scheduling delays and interrupt handling jitter.
[0048] The micro-rhythm vector is a feature vector composed of three dimensions: message arrival interval jitter feature, computation pause fingerprint feature, and response construction rhythm feature. It is used to transform the micro-behavioral patterns of the key negotiation interaction process into a quantifiable numerical representation.
[0049] For example, in a smart park security monitoring scenario, the initiator is a high-definition network camera, and the responder is an edge computing gateway. During security initialization, the camera and gateway perform 50 rounds of complete SM2 key negotiation. In each round of negotiation, the camera reads the arrival timestamp of the acknowledgment frame from its local NIC, obtaining, for example, [t1, t2, t3, ..., t...]. nThe arrival time sequence of [v1, v2, v3, ..., v] is used to calculate message arrival interval jitter features, pause fingerprint features, and response construction rhythm features. These three are combined into the micro-rhythm vector V=[v1, v2, v3, ..., v] for this round of negotiation. m After 50 rounds of negotiation, a total of 50 micro-rhythm vector samples were obtained.
[0050] S2: Based on the micro-rhythm vectors from multiple historical negotiation processes, a macro-rhythm profile of the communication peer is established. This macro-rhythm profile characterizes the normal fluctuation range of link-layer interaction timing and the correlation distribution patterns among multiple features.
[0051] In this embodiment, the macro-rhythm profile is a personalized normal behavior reference system for the communication peer constructed based on micro-rhythm vector samples obtained through multiple security negotiations.
[0052] The macro-rhythm profile includes a tolerance domain model obtained by statistical modeling of each micro-rhythm component, a correlation matrix model between micro-rhythm components, a stability model of adjacent negotiation time intervals, and a trend tracking model that tracks long-term changes in the tolerance domain boundary.
[0053] The tolerance domain model is used to define the reasonable fluctuation range of each feature in normal interactions, providing a statistical benchmark for deviation judgment. The correlation matrix model is used to describe the association structure between multiple features, making the detection of collaborative anomalies possible.
[0054] The negotiation interval stability model is used to characterize the temporal regularity of negotiation occurrences and identify abnormal changes in negotiation frequency. The trend tracking model is used to ensure that the profile boundary evolves smoothly with normal changes in the network environment and device status, avoiding misjudgments caused by gradual environmental changes.
[0055] S3: During real-time key negotiation, collect the hardware timestamp sequence of the link layer confirmation frames of the current negotiation process and extract the current micro-rhythm vector.
[0056] In this embodiment, the real-time key negotiation process refers to the key negotiation interaction that the communicating parties periodically perform according to the security policy after the system is put into normal operation. The current micro-rhythm vector refers to the feature vector extracted from the currently ongoing key negotiation process that is consistent with the structure of the historical security negotiation micro-rhythm vector, and is used for comparison with the macro-rhythm profile.
[0057] Specifically, the execution entity of this step is the edge computing gateway, and its implementation method includes: during the real-time key negotiation process, the edge computing gateway extracts the current micro-rhythm vector from the arrival timestamp of the confirmation frame of the current negotiation in the same way as in step S1.
[0058] In one implementation, the real-time monitoring module resides in a lightweight container on the edge gateway to ensure low-latency processing. In another implementation, the real-time monitoring module runs as a kernel module within the edge gateway's Linux operating system, directly accessing the network interface card (NIC) registers to obtain timestamps.
[0059] S4: Compare the current micro-rhythm vector with the macro-rhythm profile to calculate multi-dimensional quantitative indicators. These multi-dimensional quantitative indicators characterize the degree of temporal deviation of the current micro-rhythm vector.
[0060] In this embodiment of the application, the multi-dimensional quantitative index refers to a set of indicators that quantify the degree of deviation of the current micro-rhythm vector from the macro-rhythm profile from three dimensions: single-point deviation, joint deviation, and interval anomaly. It is used to comprehensively characterize the difference between the current negotiation behavior and the normal benchmark.
[0061] Specifically, the execution entity of this step is an edge computing gateway, and its implementation includes: for each component in the current micro-rhythm vector, comparing its current observation value with the corresponding tolerance range interval to calculate the single-point deviation; based on the covariance matrix in the correlation matrix model, calculating the Mahalanobis distance from the current micro-rhythm vector to the mean vector of the historical safe micro-rhythm vector set to obtain the joint deviation; obtaining the actual time interval between the current negotiation and the previous negotiation, comparing it with the lower limit of the prediction interval of the negotiation interval stability model to calculate the interval anomaly.
[0062] In one implementation, the deviations of the three dimensions can be calculated in parallel to reduce processing time. In another implementation, the deviations can be calculated sequentially in the order of single-point deviation, joint deviation, and interval anomaly, so that subsequent calculations can be terminated early if a serious anomaly is detected at some intermediate step.
[0063] S5: Calculate threat confidence based on multi-dimensional quantitative indicators.
[0064] In this embodiment of the application, the threat confidence level is a continuous value in the range [0,1], which is used to characterize the risk level of the current negotiation being attacked by a man-in-the-middle attack. The higher the value, the greater the possibility of being attacked.
[0065] In this embodiment of the application, the threat confidence level is obtained by weighted fusion of multi-dimensional quantitative indicators and adjusted using context factors, taking into account the cumulative effect of historical anomalies, the status of communication relationship establishment, and the time risk background.
[0066] Specifically, this step is executed by an edge computing gateway, and its implementation includes: summing the single-point deviations of each micro-rhythm component according to preset weights to obtain a weighted sum of single-point deviations; summing the weighted sum of single-point deviations, joint deviations, and interval anomalies according to preset weights to obtain a base score; acquiring continuous anomaly identifiers, first communication identifiers, and untrusted period identifiers; and accumulating and amplifying the baseline context factor based on the enhancement coefficients corresponding to each identifier to obtain a context factor; and multiplying the base score by the context factor and truncating it to obtain the threat confidence level.
[0067] In one implementation, the three identifiers of the context factor are combined using an OR logic, and the base score is amplified immediately when any identifier is true. In another implementation, the three identifiers are weighted and accumulated to produce differentiated amplification effects based on different identifier combinations.
[0068] S6: Based on the numerical range of the threat confidence level, implement a graded response strategy that matches the threat level.
[0069] In this embodiment, the graded response strategy refers to triggering response actions of different intensities based on different numerical ranges of threat confidence, so that the response intensity matches the threat level and establishes a dynamic balance between security and communication availability.
[0070] Specifically, the execution entity of this step is an edge computing gateway, and its implementation method includes: comparing the threat confidence level with a first threshold, a second threshold, and a third threshold in sequence.
[0071] In one implementation, the three thresholds can be set to 0.3, 0.6, and 0.9, respectively. In another implementation, the thresholds can be dynamically adjusted according to the sensitivity of the communication scenario. For example, a stricter threshold (0.25, 0.55, 0.85) can be used for security monitoring scenarios, while a relatively lenient threshold (0.35, 0.65, 0.95) can be used for office scenarios.
[0072] In this embodiment, by embedding a threat perception mechanism into the key negotiation process, behavioral benchmarks are constructed using the link-layer timing characteristics of the negotiation interaction, and deviations are monitored in real time to achieve real-time perception and graded blocking of man-in-the-middle attacks. A micro-rhythm vector is constructed by extracting the arrival interval jitter of the link-layer confirmation frames, calculating pause fingerprints, and constructing rhythms from response fragmentation. In a secure environment, a macro-rhythm profile of the communication peer is established based on multiple negotiation samples. This ensures that the additional processing nodes and computational load introduced by man-in-the-middle attacks produce detectable deviations in the timing characteristics of the negotiation interaction, thereby achieving intrinsic security perception of the negotiation process in small to medium-sized internal networks lacking a central trust anchor. By calculating multi-dimensional quantitative indicators between the current negotiation micro-rhythm vector and the macro-rhythm profile, and fusing and adjusting them to obtain a continuous threat confidence level, graded actions matching the threat level are executed based on the confidence level interval. When the threat level is low, communication availability is maintained and verification is completed in a seamless manner. When the threat level increases, the verification strength is progressively enhanced. When an attack is confirmed, the key is blocked from taking effect, thus establishing a dynamic balance between security and communication availability that matches the threat level.
[0073] In some embodiments of the present invention, the method for extracting the micro-rhythm vector of each historical negotiation process includes the following steps.
[0074] Discretize the arrival time difference of adjacent acknowledgment frames in the hardware timestamp sequence, calculate the Shannon entropy value of the discrete probability distribution, and obtain the message arrival interval jitter characteristics.
[0075] In this embodiment of the application, the arrival time difference between adjacent confirmation frames refers to the difference between two adjacent timestamps in the timestamp sequence, reflecting the time interval between the arrival of the confirmation frames.
[0076] Discretization refers to dividing continuous time intervals into equal-length intervals according to a preset time granularity, and statistically analyzing the frequency distribution within each interval.
[0077] Shannon entropy is an indicator used in information theory to measure the uncertainty of information. Its calculation formula is as follows: H = -Σp_i × log(p_i).
[0078] Where p_i represents the probability of each discrete interval, and the higher the entropy value, the more dispersed the distribution and the weaker the regularity.
[0079] p_i represents the proportion of data points falling into the i-th interval out of the total number of data points.
[0080] log(p_i) performs a non-linear transformation on the probability. The lower the probability of an event (i.e., the more "unexpected"), the greater its information content log(p_i).
[0081] H measures the degree of uncertainty or disorder in a probability distribution.
[0082] The number of occurrences, maximum duration, and relative position distribution of each silent period on the normalized negotiation time axis in the hardware timestamp sequence of consecutive silent periods without data arrival are detected to obtain computational pause fingerprint features.
[0083] In this embodiment of the application, the silent period refers to a time window in which no acknowledgment frame arrives for several consecutive check time slices during the waiting response period, and the cumulative duration exceeds the preset silent threshold. It occurs because the peer device suspends sending acknowledgment frames during the execution of cryptographic operations.
[0084] The normalized negotiation timeline refers to normalizing the total duration of the entire waiting response period to the [0,1] interval, which is used to mark the relative occurrence position of each silent period in the negotiation process.
[0085] The computation pause fingerprint feature consists of three sub-features: the number of occurrences of the silent period, the maximum duration, and the relative position distribution, which are used to reflect the computational load characteristics of the peer device.
[0086] When the key negotiation response message is transmitted in fragments of multiple link layer frames, the frame interval variation coefficient and the first-order autocorrelation coefficient are calculated based on the frame interval sequence at the arrival time of each fragment frame to obtain the response construction rhythm characteristics.
[0087] In this embodiment of the application, link layer frame fragmentation refers to the process by which the responder splits the key negotiation response message into multiple fragmented frames and sends them sequentially when the data volume of the key negotiation response message exceeds the maximum transmission unit (MTU) of the link layer.
[0088] A frame interval sequence is a sequence of time differences between the arrival times of adjacent fragmented frames.
[0089] The coefficient of variation is the ratio of the standard deviation to the mean, used to measure the relative dispersion of data. The formula is: CV = σ / μ.
[0090] Where σ (standard deviation) represents the dispersion of the arrival time interval between adjacent fragment frames, i.e. the fluctuation of the interval duration; μ (mean) represents the average level of the arrival time interval between adjacent fragment frames, i.e. the average interval duration.
[0091] The first-order autocorrelation coefficient is the linear correlation coefficient between adjacent frame intervals, used to measure the autocorrelation characteristics of a sequence. The calculation formula is: r=Σ[(x_i-μ)(x_{i+1}-μ)] / Σ(x_i-μ)².
[0092] Here, r is used to measure the degree of linear correlation between two adjacent data points, and its value is between [-1, 1].
[0093] x_i represents the i-th data point in the sequence arranged in chronological order.
[0094] x_{i+1} represents the next data point in the sequence immediately following x_i.
[0095] μ represents the arithmetic mean of all data points in the sequence.
[0096] The message arrival interval jitter feature, the calculation pause fingerprint feature, and the response construction rhythm feature are combined in a preset order to generate a micro-rhythm vector.
[0097] In this embodiment of the application, the preset order refers to the pre-agreed feature arrangement order, which ensures that the extracted micro-rhythm vectors are consistent in dimension each time, which is convenient for subsequent statistical modeling and vector comparison.
[0098] In this embodiment, the timing data of the link layer acknowledgment frame is decomposed into three dimensions: message arrival interval jitter, computation pause fingerprint, and response construction rhythm. These are then combined into a structured micro-rhythm vector, enabling precise quantification and capture of the timing disturbances introduced by man-in-the-middle attacks at the link layer. Through complementary detection of these three features, the message arrival interval jitter reflects the degree of disturbance to the acknowledgment stream timing by the attacking device; the computation pause fingerprint reflects abnormal changes in the peer's computational load; and the response construction rhythm reflects whether the hardware sending rhythm has been replaced by software processing. This comprehensively depicts the timing traces left by the attack behavior at the link layer from multiple perspectives, improving the accuracy and reliability of threat perception.
[0099] In some embodiments of the present invention, step S1 specifically includes the following steps.
[0100] S101: Collect link layer interaction timing data.
[0101] Specifically, the initiator and responder perform 50 rounds of complete key negotiation interactions in a secure environment.
[0102] For each round of negotiation, the initiating party obtains the arrival timestamp of the link layer acknowledgment frame from its local network interface controller. The timestamp accuracy is in the microsecond range (s). The acknowledgment frame is an immediate feedback signal sent by the link layer after successful reception of a data frame. It is directly driven by hardware and can most directly reflect the physical interaction characteristics of the communicating parties. The initiating party saves the arrival timestamps of the acknowledgment frames collected in each round in chronological order to obtain the arrival time sequence of the acknowledgment frames for that round of negotiation.
[0103] S102: Extract the micro-rhythm vector of a single negotiation.
[0104] Specifically, for each round of negotiation, the initiator extracts the following three dimensions of features from the confirmation frame arrival time sequence collected in step S101, and combines them in a fixed order to form the micro-rhythm vector of that negotiation.
[0105] (1) Jitter characteristics of message arrival interval.
[0106] The period from the moment the initiator sends the key negotiation request message to the moment the initiator fully receives the key negotiation response message is called the response waiting period. During the response waiting period, the arrival times of each acknowledgment frame are arranged in chronological order, and the time difference between two adjacent arrival times is calculated to obtain the time interval sequence.
[0107] The time interval sequence is discretized according to a preset time granularity. The time granularity can be set to 1ms. Specifically, the range of time interval values is divided into continuous equal-length intervals according to this time granularity. The number of time intervals falling within each interval is counted to obtain the frequency distribution of each discrete interval, from which the discrete probability distribution is calculated. The Shannon entropy value is then calculated for this probability distribution; the resulting entropy value is the message arrival interval jitter characteristic.
[0108] In normal communication, the protocol stack processing path of the peer device is fixed, the arrival rhythm of confirmation frames is regular, the values of each time interval are relatively concentrated, and the Shannon entropy value is low. After a man-in-the-middle attack device enters the link, its store-and-forward and queue waiting operations introduce additional random delays, disrupting the original regular arrival rhythm, causing the time interval distribution to become more dispersed, and the Shannon entropy value to increase significantly.
[0109] (2) Calculate the pause fingerprint features.
[0110] During the response waiting period, continuously monitor data arrival events at the link layer. Divide the response waiting period into consecutive small time slices with the smallest resolution unit of timestamps as the inspection granularity, and check whether an acknowledgment frame arrives in each time slice one by one. When no acknowledgment frames arrive for several consecutive time slices, and the cumulative duration of these time slices exceeds a preset silence threshold, this continuous period without data arrival is recorded as a silence period. The silence threshold can be set to 5ms. In another optional method, the silence threshold can be calibrated based on the cryptographic operation performance of the peer device, for example, by measuring the response time after sending a standard test message.
[0111] For all the silent periods detected in this round of negotiations, the following three statistics were extracted: the total number of silent periods, the maximum duration of all silent periods, and the relative position distribution of each silent period on the negotiation timeline.
[0112] The relative position is determined as follows: the total duration of the entire waiting response period is normalized to the interval [0, 1], and the normalized coordinate value of the midpoint of each silent period within this interval is taken as its relative position. When the number of silent periods detected in this round is less than the preset number, the relative positions of the missing parts are filled with preset placeholder values (for example); when the number exceeds the preset number, the first preset number are taken. The preset number can be set to 3.
[0113] Under normal circumstances, the computation time for the peer to perform SM2 elliptic curve key exchange operations is relatively stable, and the number, duration, and location of silent periods are consistent across different rounds. Man-in-the-middle attacks require additional cryptographic operations, the computation time of which is added to the normal pauses, leading to an increase in the number of silent periods, abnormal pause durations, or shifts in their location.
[0114] (3) Response to the rhythmic characteristics of construction.
[0115] When the data volume of the key negotiation response message exceeds the maximum transmission unit (MTU) of the link layer, the responder splits it into multiple fragmented frames and sends them sequentially. The initiator records the arrival time of each fragmented frame, arranges them in chronological order, and calculates the frame interval between the arrival times of adjacent fragmented frames to obtain a frame interval sequence. Based on the frame interval sequence, the frame interval variation coefficient (the ratio of standard deviation to mean) and the first-order autocorrelation coefficient (the linear correlation coefficient between adjacent frame intervals) are calculated, and both together constitute the response construction rhythm characteristics.
[0116] When the response message does not need to be sent in fragments, i.e. the frame interval sequence is empty, the frame interval variation coefficient and autocorrelation coefficient are both set to a value of 0.
[0117] In a normal device, the hardware DMA controller and MAC layer send data fragments mechanically, with almost a fixed frame interval, resulting in a low coefficient of variation and a high autocorrelation coefficient. In a man-in-the-middle attack, data reception, buffering, and retransmission are completed at the software level. Influenced by operating system scheduling, the frame intervals exhibit random jitter, leading to an increased coefficient of variation and a decreased autocorrelation coefficient.
[0118] The features of the above three dimensions are combined into a vector in a fixed order to obtain the micro-rhythm vector of this negotiation.
[0119] In some embodiments of the present invention, the method for establishing a macro rhythm profile of the communication peer includes the following steps.
[0120] Kernel density estimation is performed on the sample values collected during the security negotiation phase for each micro-rhythm component to obtain the probability density function. Based on the preset quantile, the tolerance domain boundary of each micro-rhythm component is determined, and a tolerance domain model is constructed.
[0121] In this embodiment, kernel density estimation is a non-parametric density estimation method that does not require the data to follow a specific distribution pattern. It estimates the probability density function by smoothly weighting the sample points using a kernel function. The kernel function is usually a Gaussian kernel, and the bandwidth parameter can be determined by the Silverman rule.
[0122] The tolerance domain boundary includes an upper limit and a lower limit, which are used to define the reasonable fluctuation range of each micro-rhythm component in normal interaction.
[0123] Preset quantiles refer to the cumulative probability thresholds used to determine the boundaries of the tolerance region. The first preset quantile corresponds to the lower bound of the tolerance region, and the second preset quantile corresponds to the upper bound of the tolerance region.
[0124] Specifically, this step is executed by an edge computing gateway, and its implementation includes: extracting the sample value of each component in the micro-rhythm vector during the security negotiation phase; estimating the probability density function of the component under normal conditions using a kernel density estimation method, with a Gaussian kernel selected as the kernel function and the bandwidth parameter determined by the Silverman rule; and integrating from negative infinity based on the obtained probability density function to find the point where the cumulative probability reaches the first preset quantile as the lower bound of the tolerance region, and continuing to integrate until the cumulative probability reaches the second preset quantile as the upper bound of the tolerance region.
[0125] Based on the micro-rhythm vectors from multiple historical security key negotiations, the correlation coefficients and covariance matrices between each micro-rhythm component are calculated, and a correlation matrix model is constructed.
[0126] In this embodiment of the application, the correlation coefficient refers to the measure of the degree of linear correlation between two random variables. The Pearson correlation coefficient is usually used, and its value range is [-1, 1].
[0127] The covariance matrix is a symmetric matrix composed of the covariances between each pair of micro-rhythm components. The diagonal elements are the variances of each component, and the off-diagonal elements are the covariances of the corresponding two components. It is used to describe the joint variation relationship between multiple features.
[0128] Specifically, this step is executed by an edge computing gateway, and its implementation includes: calculating the Pearson correlation coefficient between each pair of components based on 50 secure micro-rhythm vector samples to form a correlation matrix; and converting the correlation matrix into a covariance matrix by combining the standard deviation of each component in the secure samples.
[0129] Record the timestamps of multiple historical security key negotiations, calculate the mean and standard deviation of adjacent negotiation time intervals, determine the lower limit of the prediction interval based on the mean and standard deviation, and construct a negotiation interval stability model.
[0130] In this embodiment of the application, the adjacent negotiation time interval refers to the time difference between two adjacent key negotiation times.
[0131] The lower bound of the prediction interval refers to the lower boundary of the normal negotiation interval determined based on the statistical characteristics of historical intervals, and is used to identify abnormal accelerations in the negotiation frequency.
[0132] Specifically, this step is executed by an edge computing gateway, and its implementation includes: recording the timestamps of 50 rounds of security negotiation, arranging them in chronological order, calculating the time interval between two adjacent negotiations to obtain an interval sequence; calculating the mean μ and standard deviation σ of this interval sequence. Subtracting twice the standard deviation from the mean is used as the lower limit T_low of the prediction interval, i.e., T_low = μ - 2σ.
[0133] A macro-rhythm profile is constructed based on the tolerance domain model, the correlation matrix model, and the negotiation interval stability model.
[0134] In this embodiment of the application, this step combines the three sub-models into a complete macro rhythm profile. The profile is stored in association with the counterpart identifier, providing a complete benchmark reference for subsequent real-time comparison.
[0135] In this embodiment, a tolerance domain model is constructed using kernel density estimation. This eliminates the need to presuppose that the data follows a specific distribution pattern and can adaptively fit probability density curves based on actual samples, making the definition of normal fluctuation ranges more closely reflect the complex distribution characteristics of real network environments. By constructing a correlation matrix model, the collaborative changes among multiple features are taken into account, making joint anomaly detection possible. Furthermore, by constructing a negotiation interval stability model, the negotiation frequency patterns in the time dimension are transformed into quantifiable prediction intervals, supplementing the detection dimension of temporal features from a frequency perspective. These three sub-models work together to form a multi-dimensional and comprehensive characterization of the normal behavior of the communication peer, improving the detection coverage and accuracy of man-in-the-middle attacks.
[0136] In some embodiments of the present invention, the tolerance domain boundary includes an upper bound and a lower bound.
[0137] The establishment of a macro rhythm profile of the communication peer further includes...
[0138] For each micro-rhythm component, maintain an exponentially weighted moving average for the lower and upper bounds of the tolerance domain.
[0139] After each security key negotiation update, the actual tolerance domain boundary is updated to a weighted sum of the new boundary value and the historical moving average by a preset smoothing coefficient, thus constructing a trend tracking model.
[0140] Specifically, the method for constructing the macro-rhythm profile is as follows: After completing 50 rounds of security negotiation, a unique macro-rhythm profile is constructed for each responder. This profile is stored in association with the identifier information of the peer, which can be a MAC address or device identifier (such as an edge gateway serial number or camera ID). When the initiator communicates with multiple different peers (e.g., an edge gateway negotiating with 20 cameras simultaneously), a separate macro-rhythm profile is established and maintained for each peer, and these profiles are independent of each other.
[0141] Among them, the tolerance domain model is used to define the reasonable fluctuation range of each micro-rhythm component in normal interaction.
[0142] For each component in the micro-rhythm vector, 50 sample values are extracted during the safety negotiation phase. The probability density function of this component under normal conditions is estimated using a kernel density estimation method. A Gaussian kernel is chosen as the kernel function, and the bandwidth parameter is determined using the Silverman rule. Based on the obtained probability density function, integration is performed starting from negative infinity to find the point where the cumulative probability reaches the first preset quantile, which is then used as the lower bound of the tolerance region. Continue integrating until the cumulative probability reaches the second preset quantile, which serves as the upper bound of the tolerance region. .
[0143] The first preset quantile can be set to 2%, and the second preset quantile can be set to 98%. Taking this value as an example, the tolerance range covers approximately 96% of the data in the normal sample, excluding extreme outliers while covering the vast majority of normal fluctuations. In scenarios with higher security levels (such as core data center areas), the quantiles can be adjusted to 1% and 99% to obtain a tolerance range with a higher coverage ratio.
[0144] The correlation matrix model is used to describe the cooperative change relationship between various micro-rhythm components.
[0145] Based on 50 safe micro-rhythm vector samples, the Pearson correlation coefficients between each pair of components were calculated. This forms a correlation matrix. The standard deviations of each component in the safe samples are then combined. and ,based on Convert the correlation matrix into a covariance matrix. The covariance matrix is used to subsequently calculate the Mahalanobis distance to comprehensively evaluate the overall offset level of the current vector in the multidimensional feature space.
[0146] The negotiation interval stability model is used to characterize the temporal pattern of normal key negotiation.
[0147] Record the timestamps of 50 rounds of security negotiation, arrange them chronologically, and calculate the time interval between two adjacent negotiations to obtain an interval sequence. Calculate the mean of this interval sequence. and standard deviation The lower limit of the prediction interval is the mean minus twice the standard deviation. ,Right now A man-in-the-middle attacker could initiate multiple negotiations in a short period to probe key materials, resulting in a significantly shortened actual interval. This model is used to identify such anomalies.
[0148] Trend-following models are used to achieve long-term smooth evolution of the tolerance domain boundary.
[0149] Lower bound of the tolerance domain for each micro-rhythm component and the upper bound of the tolerance domain Each sample maintains an exponentially weighted moving average. During initial construction, the moving average is directly set as the initial tolerance boundary. In subsequent operation, when a new safe sample is added to the sample pool and triggers a recalculation of the tolerance boundary, resulting in a new boundary value, the actual boundary value used is updated to a weighted combination of the new boundary value and the historical moving average, using a smoothing coefficient.
[0150] Specifically, let the lower bound moving average before the update be... The upper bound moving average is If the candidate lower bound obtained from this recalculation is L' and the candidate upper bound is U', then the lower bound that actually takes effect after the update is... and the Upper Realm They are determined by the following formulas respectively: ; .
[0151] After the update is complete, and Store them separately in the moving average variable (i.e., let...) , This serves as the historical baseline for the next update. L' and U' are only used in this weighted calculation and are not stored separately.
[0152] in, The preset smoothing coefficient typically ranges from 0.05 to 0.10, and can be set to 0.08. It should be noted that a smaller smoothing coefficient allows for slow tracking of normal drift caused by device aging (such as camera crystal oscillator drift) and gradual changes in the network environment (such as changes in background traffic due to the addition of a new Wi-Fi AP in the campus), while maintaining high sensitivity to sudden temporal changes caused by attacks.
[0153] In some embodiments of the present invention, the method further includes the following steps.
[0154] During real-time key negotiation, it is determined whether the threat confidence level of the current negotiation is less than a preset security threshold.
[0155] In this embodiment of the application, the preset security threshold refers to the threshold used to determine whether the current negotiation can be regarded as a secure sample. It usually corresponds to the first threshold in the hierarchical handling strategy, that is, the upper limit of the threshold for allowing the key to take effect and update the profile.
[0156] When the threat confidence level is less than the preset security threshold, the micro-rhythm vector of the current negotiation is included in the sample pool.
[0157] In this embodiment of the application, the sample pool refers to a collection used to store historical security negotiation micro-rhythm vector samples, which is the data source for the construction and updating of macro-rhythm profiles.
[0158] When the sample pool reaches the preset capacity, the reservoir sampling algorithm is used to replace the samples in the sample pool with equal probability in order to maintain the fixed capacity of the sample pool.
[0159] In this embodiment of the application, the reservoir sampling algorithm is a random sampling algorithm that maintains a fixed-capacity sample pool in a data flow scenario. It can ensure that the sample pool is an unbiased sampling of historical samples, and that each sample has an equal probability of being retained, regardless of the order in which the samples arrive.
[0160] Specifically, this step is executed by an edge computing gateway, and its implementation includes: the sample pool capacity is fixed at a preset value, which can be set to 200. When the sample pool is full and a new sample needs to be added, a reservoir sampling algorithm is used for equal-probability replacement. The specific algorithm is as follows: for the nth arriving sample (n>200), a probability of 200 / n is used to determine whether to replace a randomly selected old sample in the sample pool with a new sample.
[0161] The tolerance zone boundary in the macro rhythm profile is recalculated based on the updated sample pool, and the exponentially weighted moving average of the tolerance zone boundary is updated based on the trend-following model.
[0162] Specifically, this step is performed by an edge computing gateway, and its implementation includes: re-estimating the kernel density based on the updated sample pool to calculate a new tolerance domain boundary. The actual tolerance domain boundary is then updated to a weighted sum of the new boundary value and the historical moving average, according to the smoothing coefficient of the trend-following model.
[0163] In this embodiment of the application, by constructing a strict security access mechanism and a scientific water storage sampling strategy, dynamic and secure updates of the macro rhythm profile are achieved. This not only prevents attackers from evading detection by polluting training data, but also ensures that the profile can adapt to the normal evolution of the network and devices in the long term, thus maintaining the long-term security of the system.
[0164] In one embodiment of this application, the macro-rhythm profile is incrementally updated during system operation according to the following rules: the micro-rhythm vector of a real-time negotiation is only included in the sample pool when the threat confidence of a real-time negotiation is less than a first threshold, so as to prevent attackers from gradually polluting the baseline model by constructing slow abnormal responses.
[0165] The sample pool capacity is fixed at a preset value, which can be set to 200. When the sample pool is full and new samples need to be added, a reservoir sampling algorithm is used for equal-probability replacement, ensuring that the sample pool consists of unbiased sampling of historically safe samples. Thus, the profile retains the memory of the early safety baseline while gradually incorporating normal changes in the environment and equipment.
[0166] In addition, when significant changes occur to the peer device (such as camera firmware upgrades or edge gateway hardware replacements) or when an administrator manually triggers a reset, the sample pool of the peer device can be cleared and the profile building phase can be re-executed. This re-execution should be carried out in a secure network environment.
[0167] In some embodiments of the present invention, the multi-dimensional quantitative indicators include single-point deviation, joint deviation, and interval anomaly.
[0168] The method for calculating multi-dimensional quantitative indicators includes the following steps.
[0169] Each feature component in the current micro-rhythm vector is compared with the fluctuation boundary of the corresponding tolerance domain model to calculate the single-point deviation degree used to characterize the single-point out-of-bounds amplitude.
[0170] In this embodiment of the application, the single-point deviation refers to the degree of deviation of each micro-rhythm component independently relative to the boundary of the corresponding tolerance domain. When the component value falls within the tolerance domain, the deviation is zero. When it exceeds the boundary, the deviation is the ratio of the exceedance amplitude to the historical extreme value.
[0171] Specifically, this step is executed by an edge computing gateway, and its implementation includes: for each component in the current micro-rhythm vector, comparing its current observation value with the corresponding tolerance domain interval [L, U] in the tolerance domain model. When the current observation value falls within the tolerance domain, the single-point deviation is zero. When it is below the lower bound of the tolerance domain, the single-point deviation is the ratio of the magnitude of the deviation below the lower bound to the distance from the lower bound to the historical minimum observation value. When it is above the upper bound of the tolerance domain, the single-point deviation is the ratio of the magnitude of the deviation above the upper bound to the distance from the historical maximum observation value to the upper bound.
[0172] Based on the correlation matrix model, the degree of joint offset of the current micro-rhythm vector relative to the overall historical micro-rhythm vector samples is calculated to obtain the joint deviation.
[0173] In this embodiment, the joint deviation refers to the overall offset level of the current micro-rhythm vector in the multidimensional feature space, which is evaluated by Mahalanobis distance, taking into account the correlation and scale difference between each micro-rhythm component.
[0174] Specifically, this step is executed by an edge computing gateway, and its implementation includes: using the covariance matrix in the profile to calculate the Mahalanobis distance from the current micro-rhythm vector to the mean vector of the historical safe micro-rhythm vector set; comparing the Mahalanobis distance with a preset quantile threshold of the Mahalanobis distance of the historical safe samples to obtain the normalized joint deviation.
[0175] Based on the negotiation interval stability model, the degree of abnormality of the current negotiation initiation time relative to the historical negotiation frequency is calculated to obtain the interval abnormality degree.
[0176] In this embodiment of the application, the interval anomaly refers to the degree of deviation of the current negotiation interval from the historical negotiation interval pattern, and is used to identify the behavior of abnormally accelerating negotiation frequency in a short period of time.
[0177] Specifically, this step is executed by an edge computing gateway, and its implementation includes: obtaining the actual time interval between the current negotiation and the previous negotiation; comparing the actual time interval with the lower limit of the prediction interval of the negotiation interval stability model; when the actual time interval is less than the lower limit of the prediction interval, using the proportion of the shortening amount to the lower limit of the prediction interval as the interval anomaly degree; otherwise, setting it to zero.
[0178] In this embodiment, by integrating anomaly indicators from three dimensions—single-point, joint, and interval—a comprehensive and refined characterization of key negotiation behavior is achieved. This multi-dimensional quantitative evaluation mechanism can effectively identify complex threats, including covert channels and slow attacks, significantly improving the depth and breadth of threat perception.
[0179] In one embodiment of this application, during the real-time verification phase, after the system is put into normal operation, the initiator synchronously executes the following real-time verification process each time a key negotiation occurs.
[0180] Extract the current micro-rhythm vector.
[0181] During real-time key negotiation, the initiator uses the exact same method as the steps described above for extracting historical micro-rhythm vectors, extracting the current micro-rhythm vector from the arrival timestamp of the current negotiation confirmation frame, denoted as... .
[0182] Calculate the deviation at a single point.
[0183] For the current micro-rhythm vector For each component in the dataset, its current observation value is... The component is compared with the corresponding tolerance region interval [L, U] in the tolerance region model.
[0184] when At that time, the component performed normally, with a single-point deviation. .
[0185] when When this occurs, it indicates that the component has exceeded the downward limit, indicating a deviation. ,in This is the minimum observed value of this component in the historical security negotiation sample.
[0186] when When this occurs, it indicates that the component has exceeded the upward limit, indicating a deviation. ,in This represents the maximum observed value of this component in the historical security negotiation sample.
[0187] and During the profile construction phase, samples are extracted and stored from security samples. After calculating the deviation of each component in the micro-rhythm vector, the single-point deviation corresponding to each component is obtained. .
[0188] The above calculation normalizes the out-of-bounds magnitude relative to historical extremes: slight out-of-bounds errors produce small deviations, while severe distortions produce deviations close to or even exceeding the historical extremes. The degree of deviation helps to distinguish the degree of abnormality later.
[0189] Calculate the joint deviation.
[0190] Using the covariance matrix in the portrait Calculate the current micro-rhythm vector To the historical safe micro-rhythm vector set mean vector Mahalanobis distance Mahalanobis distance takes into account the correlation and scale differences between features, and the cooperative offset that occurs in combinations of highly correlated components will be amplified.
[0191] Will Divide by the preset quantile threshold of the Mahalanobis distance of historical safe samples The normalized joint deviation is obtained. .when Time to take . The 95th percentile of the Mahalanobis distance from historical safe samples can be used. When a historically rare overall shift occurs in the cooperative pattern, the Mahalanobis distance exceeds the quantile threshold, and the joint deviation increases sharply.
[0192] Calculate the interval anomaly rate.
[0193] Obtain the actual time interval between this negotiation and the previous negotiation. Read the lower bound of the prediction interval from the negotiation interval stability model. .
[0194] when When the interval is normal, the degree of interval abnormality is... ;when Time, Interval Anomaly The more severe the shortening, the better. The closer .
[0195] In some embodiments of the present invention, the method for calculating threat confidence based on multi-dimensional quantitative indicators includes the following steps.
[0196] The basic score is obtained by weighting and summing the single-point deviation, joint deviation, and interval anomaly based on preset weights.
[0197] In this embodiment of the application, the basic score refers to the weighted sum of deviation information from three dimensions—single-point deviation, joint deviation, and interval anomaly—into a unified value, reflecting the overall deviation level of the current negotiation behavior relative to the normal benchmark.
[0198] Specifically, this step is executed by an edge computing gateway, and its implementation includes: summing the single-point deviations of each micro-rhythm component according to preset weights to obtain a weighted sum of single-point deviations; and summing the weighted sum of single-point deviations, joint deviations, and interval anomalies according to preset weights to obtain a basic score.
[0199] Obtain the context identifier corresponding to the current negotiation process.
[0200] The context identifier includes at least one of the following: continuous anomaly identifier, first communication identifier, or untrusted period identifier.
[0201] Among them, the continuous anomaly flag indicates whether the basic scores of the most recent consecutive negotiations have all exceeded the preset anomaly judgment threshold. The first communication flag indicates whether the macro rhythm profile of the communication peer is not stored locally. The untrusted period flag indicates whether the current negotiation initiation time is within a preset high-risk period.
[0202] In this embodiment of the application, the continuous anomaly identifier is a Boolean identifier used to characterize whether the basic scores of the most recent consecutive negotiations all exceed the preset anomaly judgment threshold, reflecting the persistence characteristics of the attack.
[0203] The first communication identifier is a Boolean identifier used to characterize whether the macro rhythm profile of the communication peer is not stored locally, reflecting cognitive uncertainty.
[0204] The non-trust period identifier is a Boolean identifier used to characterize whether the current negotiation initiation time is within a preset high-risk period, reflecting the risk background in the time dimension.
[0205] Specifically, this step is executed by an edge computing gateway, and its implementation includes: checking whether the basic scores of the most recent consecutive negotiations have all exceeded a preset anomaly judgment threshold to determine a continuous anomaly identifier; checking whether the macro rhythm profile of the peer is stored locally to determine the first communication identifier; and checking whether the current time is within a preset high-risk period to determine an untrusted period identifier.
[0206] Threat confidence is obtained by adjusting the base score based on contextual identifiers.
[0207] Specifically, this step is executed by an edge computing gateway, and its implementation includes: based on a baseline value, accumulating and amplifying each context identifier and its enhancement coefficient to obtain a context factor; multiplying the baseline score by the context factor and truncating the result to obtain the threat confidence level.
[0208] In this embodiment, the context factor refers to the adjustment coefficient that amplifies or keeps the base score unchanged based on the context identifier. When there is no high-risk situation, the factor is the baseline value and the base score is not amplified; when there is a high-risk situation, the amplification effect is superimposed accordingly.
[0209] In this embodiment, by introducing a context-aware and dynamic adjustment mechanism, the threat assessment model is endowed with logical reasoning capabilities, enabling it to make comprehensive judgments in combination with environmental factors. This significantly improves the system's actual defense capabilities in complex scenarios while reducing the false alarm rate.
[0210] In one embodiment of this application, calculating threat confidence specifically includes the following steps.
[0211] First, calculate the baseline score. Then, calculate the single-point deviation of each micro-rhythm component. According to preset weights Weighted summation yields the weighted sum of single-point deviations. .
[0212] The weighting of each component is set as follows: message arrival interval jitter feature weight 0.25, each of the features included in the calculation of pause fingerprint (number of silent periods, maximum duration, and relative position distribution) weight 0.15, and each of the features included in the response construction rhythm (coefficient of variation and autocorrelation coefficient) weight 0.15.
[0213] Will Joint deviation and interval anomaly The base score is obtained by weighting and summing the results according to preset weights. .in, a , b , c These are all weighting coefficients. An example of weighting settings is shown below: , , This allocation makes single-component anomalies and multivariate synergistic anomalies the main components of the score, with interval anomalies serving as a supplement.
[0214] Next, calculate the context factor. Obtain the following three Boolean identifiers, each set to a value when the condition is true. Otherwise take : Continuous anomaly flag If recently consecutive Basic score for the second negotiation If all exceed the preset anomaly detection threshold of 0.4, then This reflects the persistence of the attack.
[0215] First communication identifier If the macro rhythm profile of the peer is not stored locally (e.g., the device is joining the network for the first time or the profile has been reset), then This reflects cognitive uncertainty. In a smart park, this indicator is triggered by newly connected cameras or temporary visitor devices.
[0216] Untrusted period identifier If the current negotiation is initiated during a pre-set high-risk period (e.g., early morning) Click to Points of vulnerability in park security during off-peak hours or outside of office hours: This reflects the risk context over time.
[0217] Each icon corresponds to a preset enhancement factor: , , Context factors When no high-risk situations exist, all three indicators are [missing information]. , Do not amplify the base score; when one or more high-risk situations exist, The amplification effects are superimposed.
[0218] Finally, the base score is multiplied by the context factor, and the product is summed. The smaller of the two values is used to obtain the threat confidence level. . It represents a continuous value in the interval [0, 1]. The higher the value, the greater the possibility of being attacked by a man-in-the-middle.
[0219] In some embodiments of the present invention, the method for implementing a graded response strategy that matches the threat level includes the following steps.
[0220] The threat confidence level is compared sequentially with a preset first threshold, a second threshold, and a third threshold. The first threshold is less than the second threshold; the second threshold is less than the third threshold.
[0221] It should be noted that the first threshold, the second threshold, and the third threshold are three dividing points used to divide the continuous values of threat confidence into four intervals, corresponding to four threat levels: normal, slightly abnormal, highly suspicious, and very likely to be attacked.
[0222] When the threat confidence level is less than the first threshold, the session key generated in this negotiation is allowed to take effect, and the macro rhythm profile is updated.
[0223] Specifically, this step is executed by an edge computing gateway, and its implementation includes: allowing the session key generated in this negotiation to take effect immediately; adding the current micro-rhythm vector to the sample pool; and triggering incremental updates of each sub-model of the profile.
[0224] Understandably, this step corresponds to the first level of handling, determining that the negotiation behavior is normal, and continuously optimizing the behavioral benchmark while confirming safety.
[0225] When the threat confidence level is greater than or equal to the first threshold and less than the second threshold, the session key is allowed to take effect and implicit challenge verification is performed.
[0226] In this embodiment, implicit challenge verification uses a new session key to encrypt a challenge random number and embeds it in the application data packet. Without adding extra rounds of message interaction, it completes the secondary confirmation of the peer's identity and key in a seamless manner based on basic trust.
[0227] Understandably, this step corresponds to the second level of processing, which determines that there is a minor anomaly and adopts a trust-then-verify strategy to complete the secondary confirmation in a seamless manner while maintaining communication availability.
[0228] Specifically, this step is executed by an edge computing gateway, and its implementation includes: allowing the session key to take effect; the initiator generates a random number, encrypts and authenticates the random number using the new session key, and appends the generated ciphertext and authentication tag to the extended field of the first application data packet and sends it to the responder. The system waits for the responder to echo the decrypted random number within a preset waiting time; if a correct echo is received, communication security is confirmed; if the echo is incorrect or a timeout occurs, the threat confidence level is raised to a preset blocking level and the process is transferred to Level 4 handling.
[0229] When the threat confidence level is greater than or equal to the second threshold and less than the third threshold, the session key is temporarily suspended and out-of-band verification is performed.
[0230] In this embodiment of the application, out-of-band verification refers to using an existing trust anchor independent of the current negotiation message for identity authentication, and enabling more prudent verification methods when there is a high degree of doubt.
[0231] Understandably, this step corresponds to the third level of handling, where the negotiation is deemed highly suspicious, and a strategy of temporarily suspending activation and conducting secondary verification is adopted to prevent the use of suspicious keys.
[0232] Specifically, this step is executed by an edge computing gateway, and its implementation includes: temporarily suspending the validity of the session key generated in this negotiation. The initiator generates a random number and sends it to the responder via a verification request message independent of the current negotiation message. The responder calculates the message authentication code using the old session key generated by both parties in the previous negotiation that has not yet expired and returns it. The initiator performs a comparison and verification within a preset waiting time. If the verification passes, the new session key is allowed to take effect, but the current micro-rhythm vector is multiplied by a decay factor and included in the profile update. If the verification fails or times out, it proceeds to the fourth level of processing.
[0233] When the threat confidence level is greater than or equal to the third threshold, all key materials generated in this negotiation are discarded, and subsequent negotiation requests are blocked.
[0234] It should be noted that this step corresponds to the fourth level of response, which determines that there is a high probability of a man-in-the-middle attack and takes decisive blocking measures.
[0235] Specifically, this step is executed by the edge computing gateway, and its implementation includes: immediately discarding all key materials generated in this negotiation and not enabling them; sending a negotiation termination notification message to the peer; adding the peer's identification information to the local temporary blocking list and refusing to process any subsequent negotiation requests initiated by the peer for a preset blocking duration; triggering a security alarm event and reporting key information such as the attack time, peer identification, and threat confidence value to the campus network security management center.
[0236] In this embodiment, a four-level hierarchical handling mechanism is constructed to achieve adaptive adjustment of defense intensity. This mechanism avoids business interruption caused by excessive defense, while completing high-intensity identity verification in the low-risk stage through implicit challenges and out-of-band verification, maximizing the balance between network security and business continuity.
[0237] In some embodiments of the present invention, the method for performing implicit challenge verification includes the following steps.
[0238] The initiator generates a random number, encrypts and authenticates the random number using a new session key, and appends the generated ciphertext and authentication tag to the extended field of the first application data packet before sending it to the responder.
[0239] In this embodiment, the extended field refers to the field reserved in the application data packet for carrying additional authentication information, which does not affect the transmission of normal business data.
[0240] Specifically, the execution entity of this step is the edge computing gateway (as the initiator), and its implementation includes: the initiator generates a random number, encrypts and authenticates the random number with a new session key using the GCM working mode of the SM4 block cipher algorithm, and attaches the generated ciphertext and authentication tag to the extended field of the first application data packet and sends it to the responder.
[0241] Wait for the responder to return the decrypted random number within the preset waiting time.
[0242] Upon receiving a correct response, confirm that communication is secure and end the verification process.
[0243] When an error is echoed or a timeout occurs, the threat confidence level is raised to the preset blocking level, the key is discarded, and subsequent negotiation requests are blocked.
[0244] In this embodiment, a correct response means that the random number responded to by the responder is exactly the same as the random number originally generated by the initiator. An incorrect response means that the random number responded to by the responder is inconsistent with the original random number.
[0245] In this embodiment, by seamlessly embedding an implicit challenge mechanism into the application data stream, the system's ability to resist man-in-the-middle attacks is greatly enhanced without sacrificing user experience. In particular, it provides crucial security protection during the vulnerable window period when the key has just been negotiated and the risk has not been completely eliminated.
[0246] In one embodiment of this application, performing graded processing specifically includes the following steps.
[0247] Threat confidence With the first threshold Second threshold and the third threshold Compare in turn, according to The appropriate level of action is taken within the specified interval. The three thresholds can be set as follows: , , .
[0248] Level 1: When If the negotiation is successful, the session key generated in this negotiation is allowed to take effect immediately, and the current micro-rhythm vector is added to the sample pool, triggering incremental updates to each sub-model of the profile.
[0249] Level Two: When If a minor anomaly is detected, a "trust first, verify later" strategy is adopted: the session key is allowed to take effect, but an implicit challenge verification is embedded in the first application data packet after it takes effect.
[0250] The specific method is as follows: The initiator generates a 32-bit random number, encrypts and authenticates the random number using the SM4 block cipher algorithm in GCM mode with a new session key, and appends the generated ciphertext and authentication tag to the extended field of the first application data packet before sending it to the responder. Upon receiving the packet, the responder decrypts and authenticates it using the same key, and echoes the decrypted random number in the extended field of the next response message. The initiator waits for the echo within a preset waiting time (e.g., 300ms). If a correct echo is received, the communication is confirmed secure, and the verification ends; if the echo is incorrect or times out (including cases where the responder does not support extended field parsing, resulting in no echo), the threat confidence level is directly set to 0.9 and the process is moved to Level 4 handling. This method does not add any additional message interaction rounds and is completely transparent to the user.
[0251] Level 3: When If the negotiation is deemed highly suspicious, a "delayed activation, secondary verification" strategy is adopted: the session key generated in this negotiation is temporarily suspended, and out-of-band verification is initiated using the existing trust anchors between the two parties.
[0252] The specific procedure is as follows: The initiator generates a 32-bit random number and sends it to the responder via a verification request message independent of the current negotiation message. This verification request can be encrypted using an old session key, or the random number can be sent in plaintext (in which case integrity and authentication are only guaranteed by the message authentication code). The responder uses the old session key generated in the previous negotiation and which has not yet expired, and calculates the message authentication code on the random number using the SM3 cryptographic hash algorithm before returning it. The initiator then performs a comparison and verification using the same key and algorithm within a preset waiting time (e.g., 500ms).
[0253] If the verification passes, the new session key will be allowed to take effect. However, given the high anomaly in this negotiation, the micro-rhythm vector will be multiplied by a decay factor of 0.2 and then included in the profile update. If the verification fails or times out, the threat confidence level will be directly set to 0.9 and the process will proceed to Level 4.
[0254] Level 4: When If it is determined that a man-in-the-middle attack is highly likely, blocking measures will be taken directly.
[0255] Specifically, this includes: immediately discarding all key materials generated during this negotiation and not enabling them; sending a negotiation termination notification message to the other party; adding the other party's identification information to the local temporary blocking list and refusing to process any subsequent negotiation requests initiated by the other party for a preset blocking duration (e.g., 10 minutes); triggering a security alarm event and reporting key information such as the attack time, the other party's identification, and the threat confidence value to the park's network security management center (usually deployed on the data center side), while also displaying the alarm in real time on the park management platform's operation and maintenance dashboard.
[0256] The above four levels of response progressively strengthen as the threat level increases: Level 1 continuously optimizes the profile while confirming security; Level 2 implicitly completes secondary verification based on basic trust; Level 3 activates independent trust anchors for careful verification when there is high suspicion; and Level 4 decisively blocks attacks upon confirmation. This achieves a dynamic balance between security and communication availability that matches the real-time threat level.
[0257] As attached Figure 2 As shown, some embodiments of the present invention further provide a dynamic key negotiation protection system, which is deployed in a network security device in a communication link. Specifically, it can be deployed on the edge computing gateway, video management server, or core switch side in a smart park edge network, and is implemented collaboratively by a processor, network interface controller, and storage medium.
[0258] The system includes: a profile construction module, a real-time monitoring module, a deviation calculation module, a fusion judgment module, and a graded handling module.
[0259] The profile construction module is used to collect the arrival timestamps of link layer confirmation frames from multiple key negotiations between communicating parties in a secure network environment (e.g., during the campus initialization and configuration phase). It extracts a micro-rhythm vector composed of message arrival interval jitter features, calculation pause fingerprint features, and response construction rhythm features. Then, it uses the micro-rhythm vectors from multiple secure negotiations to construct a macro-rhythm profile that includes a tolerance domain model, a correlation matrix model, a negotiation interval stability model, and a trend tracking model. The extraction and construction methods are the same as in the above embodiments.
[0260] The real-time monitoring module is used during real-time key negotiation to obtain the arrival timestamp of the confirmation frame from the local network interface controller. It then extracts the current micro-rhythm vector in the same way as the profile building module and passes it to the deviation calculation module. In smart park scenarios, this module resides in a lightweight container or kernel module of the edge gateway to ensure low-latency processing.
[0261] The deviation calculation module is used to calculate the single-point deviation, joint deviation, and interval anomaly based on the current micro-rhythm vector and the counterpart macro-rhythm profile read from the storage medium. The calculation method is the same as in the above embodiment.
[0262] The fusion judgment module receives the three types of deviation degrees output by the deviation calculation module, weights and sums the single-point deviation degrees of each component, and then fuses them with the joint deviation degree and the interval anomaly degree according to preset weights to obtain a basic score. The basic score is then adjusted based on context factors determined by continuous anomaly identifiers, first communication identifiers, and non-trust period identifiers, outputting the threat confidence level within the interval [0, 1]. The fusion and adjustment methods are the same as in the above embodiment.
[0263] The tiered response module is used to execute tiered response actions based on the comparison results of threat confidence with the first, second, and third thresholds: when The key is allowed to take effect and the profile is updated at that time; when The key is allowed to take effect and the implicit challenge verification is triggered at that time; when Temporarily suspend key activation and trigger out-of-band verification; when The key is discarded, negotiation is blocked, and the alarm is reported to the park's security management platform.
[0264] It should be noted that the functional division between the above modules is only for clearly illustrating the technical solution of the present invention. In actual implementation, each module can be implemented by executing different program segments on the same processor, or it can be merged or split as needed, all of which do not depart from the protection scope of the present invention. In smart park deployment, the above system can run in a containerized manner on the Linux operating system of the edge gateway, using DPDK or AF_XDP technology to directly capture the timestamp of the acknowledgment frame from the network card to ensure microsecond-level ( s) precision.
[0265] Finally, it should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. The same or similar parts between the various embodiments can be referred to each other.
[0266] The above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them; although the present invention has been described in detail with reference to preferred embodiments, those skilled in the art should understand that modifications can still be made to the specific implementation of the present invention or equivalent substitutions can be made to some technical features without departing from the spirit of the technical solutions of the present invention, and all such modifications and substitutions should be covered within the scope of the technical solutions claimed in the present invention.
Claims
1. A dynamic key negotiation method, characterized in that, Includes the following steps: Collect the hardware timestamp sequence of link layer confirmation frames during multiple historical security key negotiations, and extract the micro-rhythm vector of each historical negotiation process; The micro-rhythm vector is used to characterize the link-layer timing behavior pattern of each historical security key negotiation interaction process; Based on the micro-rhythm vectors of multiple historical negotiation processes, a macro-rhythm profile of the communication peer is established. The macro-rhythm profile is used to characterize the normal fluctuation range of the link layer interaction timing and the correlation distribution pattern among multiple features; During real-time key negotiation, the hardware timestamp sequence of the link layer confirmation frames of the current negotiation process is collected, and the current micro-rhythm vector is extracted. The current micro-rhythm vector is compared with the macro-rhythm profile to calculate multi-dimensional quantitative indicators; The multi-dimensional quantitative indicators are used to characterize the temporal deviation of the current micro-rhythm vector; Threat confidence is calculated based on the aforementioned multi-dimensional quantitative indicators; the threat confidence is used to characterize the degree of risk of the current negotiation being subjected to a man-in-the-middle attack. Based on the numerical range of the threat confidence level, a graded handling strategy matching the threat level is implemented.
2. The dynamic key negotiation method according to claim 1, characterized in that, The extraction of the micro-rhythm vector for each historical negotiation process includes: Discretize the arrival time difference of adjacent confirmation frames in the hardware timestamp sequence, calculate the Shannon entropy value of the discrete probability distribution, and obtain the message arrival interval jitter feature. The number of occurrences, maximum duration, and relative position distribution of each silent period on the normalized negotiation time axis of the hardware timestamp sequence without data arrival are detected to obtain the calculation pause fingerprint features. When the key negotiation response message is transmitted in fragments of multiple link layer frames, the frame interval variation coefficient and the first-order autocorrelation coefficient are calculated based on the frame interval sequence at the arrival time of each fragment frame to obtain the response construction rhythm characteristics. The message arrival interval jitter feature, the calculated pause fingerprint feature, and the response construction rhythm feature are combined in a preset order to generate the micro-rhythm vector.
3. The dynamic key negotiation method according to claim 1, characterized in that, The establishment of the macro rhythm profile of the communication peer includes: Kernel density estimation is performed on the sample values collected during the security negotiation phase for each micro-rhythm component to obtain the probability density function, and the tolerance domain boundary of each micro-rhythm component is determined based on the preset quantile to construct the tolerance domain model. Based on the micro-rhythm vector of multiple historical security key negotiations, the correlation coefficient and covariance matrix between each micro-rhythm component are calculated, and a correlation matrix model is constructed. Record the timestamps of multiple historical security key negotiations, calculate the mean and standard deviation of adjacent negotiation time intervals, determine the lower limit of the prediction interval based on the mean and standard deviation, and construct a negotiation interval stability model. The macro-rhythm profile is constructed based on the tolerance domain model, the correlation matrix model, and the negotiation interval stability model.
4. The dynamic key negotiation method according to claim 3, characterized in that, The tolerance domain boundary includes an upper bound and a lower bound. The establishment of the macro rhythm profile of the communication peer further includes: For each micro-rhythm component, maintain an exponentially weighted moving average for the lower and upper bounds of the tolerance domain; After each security key negotiation update, the actual tolerance domain boundary is updated to a weighted sum of the new boundary value and the historical moving average by a preset smoothing coefficient, thus constructing a trend tracking model.
5. The dynamic key negotiation method according to claim 4, characterized in that, The negotiation method further includes: During the real-time key negotiation process, it is determined whether the threat confidence level of the current negotiation is less than a preset security threshold. When the threat confidence level is less than the preset security threshold, the currently negotiated micro-rhythm vector is included in the sample pool; When the sample pool reaches the preset capacity, the samples in the sample pool are replaced with equal probability using a reservoir sampling algorithm to maintain the fixed capacity of the sample pool. The tolerance zone boundary in the macro-rhythm profile is recalculated based on the updated sample pool, and the exponentially weighted moving average of the tolerance zone boundary is updated based on the trend tracking model.
6. The dynamic key negotiation method according to claim 3, characterized in that, The multi-dimensional quantitative indicators include single-point deviation, joint deviation, and interval anomaly; the calculated multi-dimensional quantitative indicators include: Each feature component in the current micro-rhythm vector is compared with the fluctuation boundary of the corresponding tolerance domain model to calculate the single-point deviation degree used to characterize the single-point out-of-bounds amplitude. Based on the aforementioned correlation matrix model, the degree of joint offset of the current micro-rhythm vector relative to the overall historical micro-rhythm vector samples is calculated to obtain the joint deviation. Based on the aforementioned negotiation interval stability model, the degree of abnormality of the current negotiation initiation time relative to the historical negotiation frequency is calculated to obtain the interval abnormality degree.
7. The dynamic key negotiation method according to claim 6, characterized in that, The calculation of threat confidence based on the multi-dimensional quantitative indicators includes: The single-point deviation, the joint deviation, and the interval anomaly are weighted and summed based on preset weights to obtain a basic score; Obtain the context identifier corresponding to the current negotiation process; the context identifier includes at least one of the following: continuous anomaly identifier, first communication identifier, or untrusted period identifier; the continuous anomaly identifier is used to indicate whether the basic scores of the most recent consecutive negotiations have all exceeded a preset anomaly judgment threshold; the first communication identifier is used to indicate whether the macro rhythm profile of the communication peer is not stored locally; the untrusted period identifier is used to indicate whether the current negotiation initiation time is in a preset high-risk period. The threat confidence level is obtained by adjusting the base score based on the context identifier.
8. The dynamic key negotiation method according to claim 1, characterized in that, The implementation of a graded response strategy that matches the threat level includes: The threat confidence level is compared sequentially with a preset first threshold, a second threshold, and a third threshold; the first threshold is less than the second threshold; the second threshold is less than the third threshold. When the threat confidence level is less than the first threshold, the session key generated in this negotiation is allowed to take effect, and the macro rhythm profile is updated; When the threat confidence level is greater than or equal to the first threshold and less than the second threshold, the session key is allowed to take effect, and implicit challenge verification is performed; When the threat confidence level is greater than or equal to the second threshold and less than the third threshold, the session key is temporarily suspended and out-of-band verification is performed. When the threat confidence level is greater than or equal to the third threshold, all key materials generated in this negotiation are discarded, and subsequent negotiation requests are blocked.
9. The dynamic key negotiation method according to claim 8, characterized in that, The implicit challenge verification includes: The initiator generates a random number, encrypts and authenticates the random number using a new session key, and appends the generated ciphertext and authentication tag to the extended field of the first application data packet before sending it to the responder. Wait for the responder to echo the decrypted random number within a preset waiting time; Upon receiving a correct response, the communication is confirmed to be secure and the verification process ends. When an error is echoed or a timeout occurs, the threat confidence level is raised to a preset blocking level, the key is discarded, and subsequent negotiation requests are blocked.
10. A dynamic key negotiation protection system, characterized in that, Network security devices deployed in communication links include: The profile building module is used to collect the hardware timestamp sequence of link layer confirmation frames during multiple historical security key negotiations, extract the micro-rhythm vector of each historical negotiation process, and build a macro-rhythm profile of the communication peer based on the micro-rhythm vector of multiple historical negotiation processes. The real-time monitoring module is used to collect the hardware timestamp sequence of the link layer confirmation frames of the current negotiation process and extract the current micro-rhythm vector during the real-time key negotiation process. The deviation calculation module is used to compare the current micro-rhythm vector with the macro-rhythm profile and calculate multi-dimensional quantitative indicators. The fusion judgment module is used to calculate threat confidence based on the multi-dimensional quantitative indicators. The tiered response module is used to execute a tiered response strategy that matches the threat level based on the numerical range in which the threat confidence level falls.