IP Library Granted Patent US 11,374,969
Granted Patent B2
US 11,374,969 · App. 17/298,610 · Granted Jun 28, 2022

Quantitative selection of secure access policies for edge computing system

Inventors: Jie Tang (Chengdu, CN); Hong Wen (Chengdu, CN); Huanhuan Song (Chengdu, CN); Feiyi Xie (Chengdu, CN); Yi Chen (Chengdu, CN)
Assignee: UNIVERSITY OF ELECTRONIC SCIENCE AND TECHNOLOGY OF CHINA
H04L63/1466G06N3/0454H04L63/1416H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,374,969
App. No.
17/298,610
Granted
Jun 28, 2022
Kind
B2
Abstract

A quantitative method for the security access strategy selection of the edge computing terminals includes the following steps: S1. Quantifying and ranking the security risks according to the terminals and data application requirements under the edge computing system. S1. Quantifying and ranking the security risks according to the terminals and data application requirements under the edge computing system. S2. Calculating the security quantification value of terminal and data application. S3. Giving the weight coefficients for the security risk protection of the security access strategies for the terminal and data in the edge computing side. S4. Give the corresponding value of each security strategy to the corresponding terminal and data security protection. S5. Select the corresponding algorithm according to the data set in S4 to select the security strategies.

Claims (217)

1. A cooperative computational method for an edge computing system, comprising the following steps:

1) according to security risks and application requirements of a terminal and a data application under the edge computing system, quantifying the security risks as shown in table 1:

TABLE 1

quantifying the security risks of the terminal and the data application

in the edge computing system

quantification value of security risks

0-2

2-4

4-6

6-8

8-10

system risk

very low

low

medium

high

very high

destructive force

very weak

weak

medium

strong

very strong

vulnerability

very low

low

medium

high

very high

wherein,

for an attack on the terminal selected from the group consisting of a permission attack, a data storage and encryption attack, a loophole threat and a remote control, the security risks of the terminal and the data application are quantified from three aspects of the system risks, the destructive force, and the vulnerability; a quantification value of the security risks for each of the attack is determined by experience, or by expert assessment, and in response to s kinds of threats, an evaluation matrix is written as:

A

=

{

a

1

1

a

2

1

a

3

1

a

1

2

a

2

2

a

3

2

a

1

s

a

2

s

a

3

s

}

,

(

1

)

wherein with t=1, 2, 3 and v=1, 2, . . . s, a t v is the quantification value of the security risks of the terminal under the attack, and is determined according to Table 1;

2) calculating the quantification value W i of the security risks on a i-th terminal of k terminals or the data application as follows:

W

i

=

{

w

1

i

,

w

2

i

,

w

s

i

,

}

(

i

=

1

,

2

,

k

)

wherein

w

v

i

=

t

=

1

3

a

t

v

v

=

1

s

t

=

1

3

a

t

v

(

i

=

1

,

2

,

k

;

v

=

1

,

2

,

,

s

)

,

(

2

)

3) according to p security strategies on an edge side, calculating the evaluation matrix as follows:

B

=

{

b

1

1

b

2

1

b

p

1

b

1

2

b

2

2

b

p

2

b

1

s

b

2

s

b

p

s

}

;

(

3

)

4) after applying the p security strategies to the i-th terminal or the data application, calculating a security protection quantification value as follows:

Z i =W i ·B={Z 1 i Z 2 i . . . Z j i . . . Z p i },( i= 1,2, . . . k;j= 1,2, . . . p )  (4),

wherein Z j i is the security protection quantification value after applying a j-th security strategy to the i-th terminal or the data application;

5) in response to a single security strategy, selecting the single security strategy based on a maximum value of Z j i , (i=1, 2, . . . k; j=1, 2, . . . p); and

in response to a combination of two or more security strategies, using a machine learning method and a deep learning algorithm to select the combination of two or more security strategies based on the security protection quantification value in Eq. (4).

2. The method of claim 1 , wherein a connection between edge computing devices and the terminals is either a wireless connection or a wired connection.

3. The method of claim 1 , wherein the security strategies adopted by edge computing devices and the number of the security strategies are determined according to security requirements of the network system.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 28, 2022
From: WANG, SIJING
To: UNIVERSITY OF ELECTRONIC SCIENCE AND TECHNOLOGY OF CHINA
Reel/Frame 059407/0373 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 31, 2021
From: TANG, JIE; WEN, HONG; SONG, HUANHUAN; XIE, FEIYI; CHEN, YI
To: UNIVERSITY OF ELECTRONIC SCIENCE AND TECHNOLOGY OF CHINA
Reel/Frame 056499/0299 →
Priority Claims (1)
CN 201910622251.6 · Jul 11, 2019 · national
Continuity (1)
Related Publication 20210392163A1 · Dec 16, 2021