Access control method and system based on zero trust architecture spa technology
By using SPA technology based on zero-trust architecture, combined with user behavior and environment awareness, and dynamically adjusting access control policies, the security protection problem of the power company's business system was solved, and full lifecycle security management was achieved.
Patent Information
- Application Number
- CN202411551386.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-11-01
- Publication Date
- 2025-12-05
- Estimated Expiration
- 2044-11-01
AI Technical Summary
Existing technologies are ineffective in preventing attacks on power company business systems, especially since perimeter security protection devices cannot identify attacks that simulate legitimate operations, leading to data leaks and a lack of zero-trust, full lifecycle security control measures.
Employing SPA technology based on a zero-trust architecture, access control policies are adjusted in real time through user behavior assessment and environment awareness, permissions are dynamically adjusted, and the security of access terminals is monitored in real time, including authentication, behavioral data analysis, environment awareness, and trust value calculation.
It enables real-time risk assessment and dynamic access control for access terminals, effectively preventing illegal activities by legitimate users, minimizing risk intrusion, and ensuring business data security throughout the entire lifecycle.
Smart Images

Figure CN119628866B_ABST
Abstract
Description
Technical Field
[0001] This invention relates to the field of network security technology, and specifically to an access control method and system based on Zero Trust Architecture (SPA) technology. Background Technology
[0002] Currently, power companies typically deploy their services in three tiers: Tier 1, Tier 2, and Tier 3. Each tier has corresponding perimeter security protection devices. However, most services utilize a B / S architecture, meaning the external portal is directly exposed to the internet. Web vulnerabilities make these websites highly susceptible to compromise. Since attacks often mimic legitimate user actions, perimeter security protection devices are ineffective. Furthermore, they can lead to oversights in security and business operations. Numerous data breaches both domestically and internationally demonstrate that existing perimeter security measures are insufficient to meet business security needs.
[0003] Therefore, effective technical solutions are urgently needed to address the most basic issues of business concealment, minimal access control, and real-time continuous security behavior monitoring, in order to effectively prevent business exposure from being targeted by attackers, prevent illegal activities by legitimate users, and achieve zero-trust full business lifecycle security management. Summary of the Invention
[0004] To address the problems existing in the prior art, this invention provides an access control method and system based on Zero Trust Architecture (SPA) technology. The purpose is to assess the security of access terminal requests by combining risk assessment of user behavior with real-time environmental awareness and dynamic policy control. The Zero Trust control center can dynamically adjust permissions or intervene based on the behavior and environmental awareness results. Once a security risk in the access environment occurs, the accessible business data can be adjusted in real time, effectively achieving early warning and handling, and minimizing the harm of risk intrusion.
[0005] To achieve the above objectives, the present invention provides the following technical solution:
[0006] In a first aspect, the present invention provides an access control method based on a zero-trust architecture SPA technology, wherein the zero-trust architecture includes: an access terminal, a trusted console, a trusted environment awareness center, a trusted proxy gateway, and a business data terminal, and the method includes:
[0007] S1, the trusted console receives the service access request sent by the access terminal client and authenticates the access terminal;
[0008] S2, after the authentication of the access terminal is passed, the access control policy of the access terminal is obtained based on the access behavior data of the access terminal;
[0009] S3, based on the access control policy, the trusted console and the access terminal establish SPA single packet authentication, and the trusted proxy gateway calculates the access trust value based on the SPA authentication packet and establishes a data interaction channel.
[0010] S4, the Trusted Environment Awareness Center collects access environment information in real time, dynamically updates the access trust value to adjust the access control policy, and controls the data interaction process between the access terminal and the business data terminal.
[0011] Preferably, step S2, which involves obtaining the access control policy of the access terminal based on its access behavior data, specifically includes:
[0012] If the access terminal is sending an access request for the first time, the user attribute information and access behavior data of the access terminal are obtained to determine the authorization level of the access terminal, and an access control policy is assigned to the access terminal based on the authorization level.
[0013] If the access terminal is not sending an access request for the first time, obtain the historical access behavior data of the current access terminal's users, generate access behavior evaluation data, and formulate the current access control policy for the access terminal based on the access behavior evaluation data.
[0014] Preferably, the step of obtaining the user attribute information and access behavior data of the access terminal to determine the authorization level of the access terminal includes:
[0015] Obtain access traffic data and access behavior data for a preset time period prior to the current time of the access terminal, and perform structured processing on the access behavior data;
[0016] Structured access behavior data is divided into risk information datasets and access content datasets based on text features;
[0017] Map the access traffic data to access ranges and draw trust circles;
[0018] The trust circle is narrowed based on the correlation between the risk information dataset, the access content dataset, and the business access request;
[0019] The trust circle is mapped to a behavioral trust level according to a preset mapping rule, wherein the area of the trust circle corresponds to the level of the behavioral trust level.
[0020] Extract the access user attribute information of the access terminal, and search for the user level of the attribute information in the business system based on the access user identity information;
[0021] The authorization level of the access terminal is obtained by combining the user level and the behavior trust level.
[0022] Preferably, narrowing the trust circle based on the correlation between the risk information dataset, the access content dataset, and the business access request specifically involves:
[0023] The risk rate of the access terminal is obtained based on the risk information dataset.
[0024] Based on the business access request sent by the access terminal, obtain the target business data of the access request, and extract the feature descriptive word vectors of the target business data;
[0025] The accessed content dataset is segmented using a word segmenter to obtain multiple keywords, and these keywords are then converted into multiple keyword vectors.
[0026] Calculate the similarity between the feature description word vectors of the target business data and the keyword vectors of the access content dataset;
[0027] Based on the risk rate and similarity, the radius reduction factor of the trust circle is calculated using the following formula:
[0028]
[0029] Where μ is the radius reduction coefficient, n is the amount of risk data of the access terminal within the preset time period, m is the total number of accesses of the access terminal within the time period, ε is the similarity between the feature description word vector of the target business data and the keyword vector of the access content dataset, and α and β are preset weighting weights.
[0030] Preferably, generating access behavior evaluation data based on the historical access behavior data includes:
[0031] Obtain historical access behavior data of all users who have established data interaction channels with the business data end;
[0032] Extract feature words from any of the historical access behavior data, classify the historical access behavior data according to the feature words, and generate corresponding behavior tags to create a profile of the accessing user;
[0033] Extract common behavioral tags from all users who have established data interaction channels with the business data end;
[0034] Calculate the difference between the behavior tags of the current accessing terminal's user and the shared behavior tags;
[0035] Based on the difference and the current access terminal's authorization level, the access behavior evaluation data of the accessing users of that access terminal is generated.
[0036] Preferably, the trusted environment perception center collects access environment information in real time, including access terminal environment information, user change information, and network environment dynamic information;
[0037] The adjustment of the access control policy includes:
[0038] Based on the access environment information, the Trusted Environment Awareness Center performs data modeling analysis to assess the possibility of access instability and sends the assessment results to the Trusted Console in real time.
[0039] The trusted console adjusts the access control policy based on preset evaluation results and matching rules, and dynamically intervenes in the interaction process.
[0040] Preferably, the dynamic updating of the access trust value includes:
[0041] Historical trust values are extracted from a time sliding window based on a preset adjustment interval;
[0042] Calculate the time decay factor based on the probability of access turbulence.
[0043] The trust value is updated based on the historical trust value and the time decay factor.
[0044] Secondly, the present invention provides an access control system based on zero-trust SPA technology, comprising:
[0045] The authentication module is used to accept business access requests sent by the access terminal, and the trusted console authenticates the access terminal.
[0046] The control policy formulation module is used to obtain the access control policy of the access terminal based on the access behavior data of the access terminal after the authentication of the access terminal is passed.
[0047] The interaction channel establishment module is used to establish SPA single packet authentication between the trusted console and the access terminal based on the access control policy, and the trusted proxy gateway calculates the access trust value based on the SPA authentication packet to establish a data interaction channel.
[0048] The dynamic adjustment module is used by the trusted environment awareness center to collect access environment information in real time, dynamically update the access trust value to adjust the access control policy, and control the data interaction process between the access terminal and the business data terminal.
[0049] Thirdly, the present invention provides an electronic device, comprising:
[0050] Memory, used to store executable instructions;
[0051] When the processor runs the executable instructions stored in the memory, it implements the aforementioned access control method based on a zero-trust architecture SPA technology.
[0052] Fourthly, the present invention provides a computer-readable storage medium storing executable instructions that, when executed by a processor, implement the aforementioned access control method based on a zero-trust architecture SPA technology.
[0053] The access control method and system based on zero-trust SPA technology of the present invention have the following beneficial effects:
[0054] This invention analyzes historical access behavior data of users, assigns different authorization levels to access requests from the same user on different access terminals, and assesses the likelihood of attacks on the current terminal. It also combines access environment information such as access terminal environment information, user change information, and dynamic network environment information to continuously monitor access behavior in real time. Based on a zero-trust technical framework and assisted by SPA technology, it effectively improves the access control strategy for business data, achieving zero-trust full lifecycle security management of business data by addressing three key threats: business exposure, user access control, and continuous business behavior monitoring. Attached Figure Description
[0055] Figure 1 This is a schematic diagram of a zero-trust architecture provided by the present invention;
[0056] Figure 2 This is a flowchart illustrating an access control method based on zero-trust architecture SPA technology according to the present invention.
[0057] Figure 3 This is a structural block diagram of an access control system based on Zero Trust Architecture (SPA) technology according to the present invention. Detailed Implementation
[0058] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.
[0059] First, this embodiment explains the zero-trust architecture. For example... Figure 1 As shown, this embodiment provides a zero-trust architecture framework, including: an access terminal client, a trusted console, a trusted environment awareness center, a trusted proxy gateway, and a business data terminal.
[0060] Using this architecture, the zero-trust access process provided in this embodiment may specifically include:
[0061] One or more zero-trust connection accepting hosts (AHs) come online. These hosts connect to and are authenticated by the controller. However, they do not respond to communications from any other hosts, nor do they respond to non-pre-assigned requests.
[0062] Each newly launched Zero Trust Connection Initiating Host (IH) connects to the Zero Trust Controller and authenticates itself.
[0063] After verifying the Zero Trust Connection Initiating Host (IH), the Zero Trust Controller determines a list of Zero Trust Connection Accepting Hosts (AHs) that can be authorized to communicate with the Zero Trust Connection Initiating Host (IH).
[0064] The Zero Trust Controller notifies the Zero Trust Connection Accepting Host (AH) to accept communication from the Zero Trust Connection Initiating Host (IH) and all optional security policies required for encrypted communication.
[0065] The Zero Trust Controller sends a list of acceptable Zero Trust Connection Initiating Hosts (AHs) and optional security policies to the Zero Trust Connection Initiating Host (IH).
[0066] The Zero Trust Connection Initiating Host (IH) sends a single packet authorization to each Zero Trust Connection Accepting Host (AH) that accepts a connection, and establishes a bidirectional TLS connection with these Zero Trust Connection Accepting Hosts (AH).
[0067] Therefore, in order to achieve secure management of business data in a zero-trust architecture, this invention provides an access control method based on a zero-trust SPA technology, such as... Figure 2 As shown, it includes:
[0068] S1, the trusted console accepts the business access request sent by the access terminal client and performs authentication on the access terminal; authentication is to verify whether the user account used by the access terminal is a legitimate account.
[0069] S2, after the authentication of the access terminal is successful, the access control policy of the access terminal is obtained based on the access behavior data of the access terminal; the access control policy may include blocking access, allowing access, continuing access, allowing and recording, allowing and reviewing, allowing and isolating, and allowing and restricting.
[0070] S3, based on the access control policy, the trusted console and the access terminal establish SPA single packet authentication, and the trusted proxy gateway calculates the access trust value based on the SPA authentication packet and establishes a data interaction channel.
[0071] S4, the Trusted Environment Awareness Center collects access environment information in real time, dynamically updates the access trust value to adjust the access control policy, and controls the data interaction process between the access terminal and the business data terminal.
[0072] Preferably, step S2, which involves obtaining the access control policy of the access terminal based on its access behavior data, specifically includes:
[0073] If the access terminal is sending an access request for the first time, the user attribute information and access behavior data of the access terminal are obtained to determine the authorization level of the access terminal, and an access control policy is assigned to the access terminal based on the authorization level.
[0074] If the access terminal is not sending an access request for the first time, obtain the historical access behavior data of the current access terminal's users, generate access behavior evaluation data, and formulate the current access control policy for the access terminal based on the access behavior evaluation data.
[0075] During user interaction, real-time monitoring policies can dynamically control end-user access to services, allowing or blocking access based on factors such as time, source IP, and user behavior. Access to services can only be granted when all conditions for permission are met.
[0076] For services with higher security requirements, users can be required to perform secondary authentication after completing login authentication, and then perform secondary authentication when using specific services, thus implementing a more flexible access control strategy.
[0077] This method is based on the separation of access terminal and access user. That is, even if a user account that has passed identity authentication is used, it is not necessarily a secure user. Using risky terminals or user accounts that are stolen and used to log in from other ends or intercepted, or forging normal interaction information to confuse the identity authentication process, can also lead to data leakage and attack intrusion.
[0078] Therefore, in this embodiment, after the end user is authenticated, it is necessary to determine the access authorization level of the terminal.
[0079] Preferred options include:
[0080] Determining the authorization level of an access terminal by obtaining its user attribute information and access behavior data includes:
[0081] Obtain access traffic data and access behavior data for a preset time period prior to the current time of the access terminal, and perform structured processing on the access behavior data;
[0082] It should be noted that access traffic data represents the total number of accesses within a preset time period for the access terminal, while access behavior data represents whether the access behavior of the access terminal is compliant or not within the preset time period.
[0083] Structured access behavior data is divided into risk information datasets and access content datasets based on text features;
[0084] It should be noted that the risk information dataset refers to records where the access terminal's previous access history has been marked as risky or has accessed URLs containing risks. For example, if a user visits a domain name that is on a network blacklist, they will receive a warning from their browser or system, informing them of the potential risks of continuing to access the website. When this method is applied to business systems with high confidentiality requirements, it can access the risk databases of the national cyberspace administration, such as the National Information Security Vulnerability Database, management records from online alarm centers, and URL legal certificate information databases, to screen the access terminal's past access records.
[0085] Accessed content datasets refer to the URLs, web page content, data records, etc., that the accessing terminal has visited before.
[0086] Map the access traffic data to access ranges and draw trust circles;
[0087] It should be noted that if the accessing terminal has almost no prior access traffic data, this method adheres to the principle of zero trust, eliminating any potential risks. That is, the trust circle area of the accessing terminal is 0, the terminal's initial access authorization level is low, and access permissions are strictly controlled.
[0088] Attackers typically perform massive web crawling operations to steal data and intrude into networks, resulting in huge amounts of network traffic. However, the content accessed within this traffic covers a wide range of categories. This method verifies the content accessed by the terminal. If the terminal has a large number of previous malicious access records or the accessed content is unrelated to the target data of the current access request, the authorized level for this access will be restricted. Specifically, this embodiment includes the following steps:
[0089] The trust circle is narrowed based on the correlation between the risk information dataset, the access content dataset, and the business access request;
[0090] The trust circle is mapped to a behavior trust level according to a preset mapping rule, wherein the area of the trust circle corresponds to the level of the behavior trust level; the larger the area of the trust circle after association processing, the higher the behavior trust level.
[0091] Extract the access user attribute information of the access terminal, and search for the user level of the attribute information in the business system based on the access user identity information;
[0092] The authorization level of the access terminal is obtained by combining the user level and the behavior trust level.
[0093] Preferably, narrowing the trust circle based on the correlation between the risk information dataset, the access content dataset, and the business access request specifically involves:
[0094] The risk rate of the access terminal is obtained based on the risk information dataset.
[0095] Based on the business access request sent by the access terminal, obtain the target business data of the access request, and extract the feature descriptive word vectors of the target business data;
[0096] It should be noted that the business data stored on the business data side usually comes with category labels and descriptive documents. Based on the category labels and descriptive documents, feature descriptive word vectors of the business data can be extracted.
[0097] In embodiments where business data typically does not contain category labels and descriptive documents, the feature descriptive word vectors of the target business data can also be extracted using the same method as the keyword vector extraction method for access content datasets.
[0098] The accessed content dataset is segmented using a word segmenter to obtain multiple keywords, and these keywords are then converted into multiple keyword vectors.
[0099] It should be noted that the access content dataset contains description documents of multiple access contents. The word segmentation process can employ existing word segmentation techniques; optionally, in this embodiment, jieba technology can be used to perform word segmentation on the documents in the access content dataset.
[0100] Calculate the similarity between the feature description word vectors of the target business data and the keyword vectors of the access content dataset;
[0101] In this embodiment, the similarity is calculated using the cosine similarity formula.
[0102] Based on the risk rate and similarity, the radius reduction factor of the trust circle is calculated using the following formula:
[0103]
[0104] Where μ is the radius reduction coefficient, n is the amount of risk data of the access terminal within the preset time period, m is the total number of accesses of the access terminal within the time period, ε is the similarity between the feature description word vector of the target business data and the keyword vector of the access content dataset, and α and β are preset weighting weights.
[0105] Furthermore, the keyword extraction step for the accessed content dataset in this embodiment includes:
[0106] (1) Clustering algorithm is used to classify each document in the accessed content dataset, and the classification accuracy of each document is determined according to the Euclidean distance from the document to the classification center to which the document belongs.
[0107] (2) For the word segmentation results of each document in the access content dataset, count all high-frequency words of each document.
[0108] (3) Select a high-frequency word, calculate the frequency difference of the high-frequency word in different categories of documents, and the difference in the average distance between the high-frequency word and other high-frequency words in different categories of documents, and obtain the representational ability value of the high-frequency word.
[0109] It should be noted that when the frequency difference of a high-frequency word in different categories of documents is small, that is, when it appears multiple times in multiple categories of documents, it means that the high-frequency word only appears frequently, but cannot distinguish the category of the document, and therefore has poor representation ability. When the difference in the average distance between a high-frequency word and other high-frequency words in different categories of documents is large, it means that the high-frequency word is more prominent than other high-frequency words, and can better represent the content of the document containing the high-frequency word as different from others.
[0110] Optionally, in this embodiment, the average distance / frequency difference can be calculated using variance.
[0111] (4) Repeat step (3) to calculate the representational ability value of all high-frequency words in turn.
[0112] (5) Calculate the keyness of high-frequency words based on the classification accuracy of each document and the representational ability value of high-frequency words in the document.
[0113] (6) Sort all high-frequency words in the same category of documents based on the keyness of the high-frequency words, filter out multiple keywords of the category of documents according to the sorting results, and convert the multiple keywords into multiple keyword vectors.
[0114] The keyword extraction method provided in this embodiment extracts keywords based on document categories. The more prominent a high-frequency word is within a document category, the more likely it is to be a keyword for that category. However, this classification is predicated on the accuracy of the document classification. If a document is on the edge of a category, it indicates that the document's classification boundary is ambiguous, its features are not clearly defined, and it shares common features with documents from multiple categories. Therefore, even if the high-frequency words extracted from this document have high representational power, they are unlikely to represent the overall characteristics of a document category and are far less representative than the high-frequency words from documents at the category center. Therefore, this embodiment uses both the classification accuracy of each document and the representational power value of its high-frequency words as the criteria for measuring the keyness of high-frequency words.
[0115] This method uses client software installed on the access terminal to continuously collect past access information of the terminal. Based on whether the terminal's access behavior is compliant and the correlation between past access and target data, it analyzes and evaluates whether the terminal is secure, effectively preventing the theft of data by forging or stealing the identity of normal users.
[0116] Preferably, generating access behavior evaluation data based on the historical access behavior data includes:
[0117] Obtain historical access behavior data of all users who have established data interaction channels with the business data end;
[0118] In some embodiments, the historical access behavior data may include the amount of data accessed, access time information, web page information browsed before and after sending the access request, etc.
[0119] It should be understood that the users who have established a data interaction channel with the business data terminal are the same users who previously accessed the platform normally.
[0120] Extract feature words from any of the historical access behavior data, classify the historical access behavior data according to the feature words, and generate corresponding behavior tags to create a profile of the accessing user;
[0121] Extract common behavioral tags from all users who have established data interaction channels with the business data end;
[0122] Calculate the difference between the behavior tags of the current accessing terminal's user and the shared behavior tags;
[0123] Based on the difference and the current access terminal's authorization level, the access behavior evaluation data of the accessing users of that access terminal is generated.
[0124] This method, after considering the legitimacy of the access terminal of a legitimate user account, also considers the legitimacy of the user's access behavior for legitimate access terminals. Specifically, using users with normal access as templates, it analyzes the accessing users of the current access terminal and, in conjunction with the user's authorization level, determines whether unauthorized access is being conducted. This allows for the analysis of user access behavior intentions, thereby accurately identifying illegal access behavior by legitimate users.
[0125] Preferably, the trusted environment perception center collects access environment information in real time, including access terminal environment information, user change information, and network environment dynamic information;
[0126] The Trusted Environment Awareness Center collects real-time dynamic information about the access terminal environment, including terminal infection information, virus database update information, and security baseline information.
[0127] Secondly, the Trusted Environment Awareness feature collects information related to changes in user accounts. For example, if an account is authenticated in different regions within a very short time interval, it can be determined that the account has a security risk.
[0128] Finally, the Trusted Environment Awareness Center collects dynamic information about the network environment, which in some embodiments may include dynamic data on abnormal alarms of business system networks, dynamic data on vulnerability monitoring, and dynamic data on attack frequency.
[0129] The adjustment of the access control policy includes:
[0130] Based on the access environment information, the Trusted Environment Awareness Center performs data modeling analysis to assess the possibility of access instability and sends the assessment results to the Trusted Console in real time.
[0131] The trusted console adjusts the access control policy based on preset evaluation results and matching rules, and dynamically intervenes in the interaction process.
[0132] The trusted console can match local dynamic control policy rules based on the access environment results analyzed by the trusted environment awareness center. Once the evaluation result triggers a dynamic control policy rule, the trusted console will issue commands to the trusted proxy gateway to intervene in access permissions in real time. Intervention actions include mandatory two-factor authentication, mandatory password modification, and disconnection of access connections.
[0133] It should be understood that access permissions are granted based on multiple dimensions, including user attributes, environment attributes, operation attributes, and object attributes, according to access environment information. This controls the minimum set of services that a terminal can access; terminals without permission cannot connect at all. This effectively avoids the problem of lateral movement of security risks, such as those encountered with VPNs accessing data center networks.
[0134] Preferably, the dynamic updating of the access trust value includes:
[0135] Historical trust values are extracted from a time sliding window based on a preset adjustment interval;
[0136] The time decay factor is calculated based on the access behavior data of the access terminal; in this embodiment, the formula for calculating the time decay factor is:
[0137]
[0138] Where θ(t) is the time decay factor, riskbehavior t Indicates the number of times the behavior is accessed within time t. t This represents the total number of access actions within time t.
[0139] The trust value is updated based on the historical trust value and the time decay factor.
[0140] In this embodiment, the formula for updating the trust value is:
[0141]
[0142] Among them, T i (i = 1, 2, ..., h) represents the historical trust value, and h is the number of times the time sliding window moves forward.
[0143] It is understandable that as the time interval t increases, the time decay parameter decreases, and at the same time, the weight of historical trust values in the final trust value also gradually decreases.
[0144] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages of other steps.
[0145] Based on the same inventive concept, this application also provides an operating system for implementing the access control method described above. The solution provided by this system is similar to the implementation scheme described in the above method. Therefore, the specific limitations of one or more access control system embodiments based on zero-trust architecture SPA technology provided below can be found in the limitations of the access control method based on zero-trust architecture SPA technology described above, and will not be repeated here.
[0146] like Figure 3 As shown, the present invention also provides an access control system based on zero-trust architecture SPA technology, comprising:
[0147] The authentication module is used to accept business access requests sent by the access terminal, and the trusted console authenticates the access terminal.
[0148] The control policy formulation module is used to obtain the access control policy of the access terminal based on the access behavior data of the access terminal after the authentication of the access terminal is passed.
[0149] The interaction channel establishment module is used to establish SPA single packet authentication between the trusted console and the access terminal based on the access control policy, and the trusted proxy gateway calculates the access trust value based on the SPA authentication packet to establish a data interaction channel.
[0150] The dynamic adjustment module is used by the trusted environment awareness center to collect access environment information in real time, dynamically update the access trust value to adjust the access control policy, and control the data interaction process between the access terminal and the business data terminal.
[0151] It should be noted that the access control system based on Zero Trust Architecture (SPA) technology provided in this embodiment is only an example illustrating the division of the above functional modules. In practical applications, the above functions can be assigned to different functional modules as needed, that is, the internal structure of the system can be divided into different functional modules. Each functional module can be composed of a single execution unit, or two or more execution units can be integrated into one functional module to realize all the functions of that module.
[0152] This invention provides an electronic device, comprising:
[0153] Memory, used to store executable instructions;
[0154] When the processor runs the executable instructions stored in the memory, it implements the aforementioned access control method based on a zero-trust architecture SPA technology.
[0155] This invention also provides a computer-readable storage medium storing executable instructions that, when executed by a processor, implement the aforementioned access control method based on a zero-trust architecture SPA technology.
[0156] Those skilled in the art will understand that the above modules can be implemented in whole or in part through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in a computer device, or stored in the memory of a computer device in software form, so that the processor can call and execute the operations corresponding to each module.
[0157] This invention is not limited to the specific embodiments described above. Any modifications made by those skilled in the art based on the above concept without creative effort are within the scope of protection of this invention.
Claims
1. A method of access control based on a zero trust architecture SPA technique, the zero trust architecture comprising: The application discloses a method for establishing a data interaction channel between an access terminal client, a trusted console, a trusted environment perception center, a trusted proxy gateway and a service data terminal. S1, the trusted console accepts a service access request sent by the access terminal client, and performs identity authentication on the access terminal; S2, after the identity authentication of the access terminal is passed, an access control strategy of the access terminal is acquired based on access behavior data of the access terminal; specifically including: If the access terminal is a first-time access request sender, user attribute information and access behavior data of the access terminal are acquired to determine an authorization level of the access terminal, and an access control strategy is allocated to the access terminal based on the authorization level; If the access terminal is a non-first-time access request sender, historical access behavior data of an access user of the current access terminal is acquired to generate access behavior evaluation data, and a current access control strategy of the access terminal is formulated based on the access behavior evaluation data; The acquisition of the user attribute information and the access behavior data of the access terminal to determine the authorization level of the access terminal includes: Access traffic data and access behavior data of a preset time period before a current time of the access terminal are acquired, and the access behavior data is structured; The structured access behavior data is divided into a risk information data set and an access content data set according to text features; The access traffic data is mapped into an access range to draw a trust circle; The trust circle is reduced based on the correlation between the risk information data set, the access content data set and the service access request; The trust circle is mapped into a behavior trust level according to a preset mapping rule, wherein the area size of the trust circle corresponds to the level of the behavior trust level; Access user attribute information of the access terminal is extracted, and a user level of the attribute information is searched in a service system based on the access user identity information; The authorization level of the access terminal is obtained by combining the user level and the behavior trust level; The reduction of the trust circle based on the correlation between the risk information data set, the access content data set and the service access request specifically includes: The risk rate of the access terminal is acquired according to the risk information data set; Target service data of the access request is acquired based on the service access request sent by the access terminal, and a feature description word vector of the target service data is extracted; A plurality of keywords are acquired by performing word segmentation on the access content data set by using a word segmenter, and the plurality of keywords are converted into a plurality of keyword vectors; Similarity between the feature description word vector of the target service data and the keyword vector of the access content data set is calculated; The radius reduction coefficient of the trust circle is calculated based on the risk rate and the similarity by using the following formula: ; wherein, is a radius reduction factor, is a risk data amount of the access terminal within a preset time period, is a total access number of the access terminal within the time period, is a similarity between a feature description word vector of the target service data and a keyword vector of the access content data set, and is a preset weighting weight; S3, based on the access control strategy, the trusted console establishes an SPA single package authentication with the access terminal, and the trusted proxy gateway calculates an access trust value based on the SPA authentication package to establish a data interaction channel; S4, the trusted environment perception center collects access environment information in real time, dynamically updates the access trust value to adjust the access control strategy, and controls the data interaction process between the access terminal and the service data terminal.
2. The access control method based on the zero-trust architecture SPA technology according to claim 1, characterized in that, The generating access behavior evaluation data based on the historical access behavior data comprises: Obtaining historical access behavior data of all access users who have established data interaction channels with the business data end; Extracting feature words of any historical access behavior data, classifying the historical access behavior data according to the feature words, and generating corresponding behavior labels to profile the access users; Extracting common behavior labels of all access users who have established data interaction channels with the business data end; Calculating the difference between the behavior label of the access user of the current access terminal and the common behavior label; Generating access behavior evaluation data of the access user of the current access terminal based on the difference and the authorized level of the current access terminal.
3. The access control method based on the zero trust architecture SPA technology according to claim 1, characterized in that, The trusted environment perception center collects access environment information in real time, including access terminal environment information, user change information, and network environment dynamic information; The adjusting the access control strategy comprises: Based on the access environment information, the trusted environment perception center performs data modeling analysis to evaluate the access turbulence possibility, and sends the evaluation result to the trusted console in real time; The trusted console adjusts the access control strategy according to the preset evaluation result matching rule, and dynamically intervenes in the interaction process.
4. The access control method based on the zero-trust architecture SPA technology according to claim 3, characterized in that, The dynamically updating the access trust value comprises: Extracting historical trust values in a time sliding window based on a preset adjustment interval; Calculating a time decay factor based on the access turbulence possibility; Updating the trust value according to the historical trust value and the time decay factor.
5. An access control system based on a zero trust architecture SPA technology, characterized in that, Comprise: An identity verification module for accepting a business access request sent by an access terminal, and the trusted console verifies the identity of the access terminal; A control strategy formulation module for obtaining the access control strategy of the access terminal based on the access behavior data of the access terminal after the identity verification of the access terminal is passed; Specifically comprising: If the access terminal is sending an access request for the first time, the user attribute information and access behavior data of the access terminal are obtained to determine the authorized level of the access terminal, and the access control strategy is assigned to the access terminal based on the authorized level; If the access terminal is not sending an access request for the first time, the historical access behavior data of the access user of the current access terminal is obtained to generate access behavior evaluation data, and the current access control strategy of the access terminal is formulated based on the access behavior evaluation data; The obtaining the user attribute information and access behavior data of the access terminal to determine the authorized level of the access terminal comprises: Obtaining access traffic data and access behavior data of a preset time period before the current time of the access terminal, and structurally processing the access behavior data; Dividing the structured access behavior data into a risk information data set and an access content data set according to text features; Mapping the access traffic data to an access range to draw a trust circle; Based on the correlation between the risk information data set, the access content data set, and the business access request, the trust circle is reduced; Mapping the trust circle to a behavior trust level according to a preset mapping rule, wherein the area size of the trust circle corresponds to the level of the behavior trust level; extracting access user attribute information of the access terminal, searching a user level of the attribute information in a service system based on the access user identity information; obtaining an authorization level of the access terminal in combination with the user level and the behavior trust level; the narrowing of the trust circle based on the association between the risk information data set, the access content data set and the service access request is specifically: obtaining a risk rate of the access terminal according to the risk information data set; obtaining target service data of the access request based on the service access request sent by the access terminal, and extracting a feature description word vector of the target service data; performing word segmentation on the access content data set by a word segmenter to obtain a plurality of keywords, and converting the plurality of keywords into a plurality of keyword vectors; calculating the similarity between the feature description word vector of the target service data and the keyword vector of the access content data set; calculating the radius reduction coefficient of the trust circle based on the risk rate and the similarity by using the following formula: ; wherein, is a risk data amount of the access terminal in a preset time period, is a total access number of the access terminal in the time period, is a similarity between a feature description word vector of the target service data and a keyword vector of the access content data set, and is a preset weighting weight; an interaction channel establishment module, configured to establish a SPA single package authentication between the trusted console and the access terminal based on the access control strategy, and to calculate an access trust value by the trusted proxy gateway based on the SPA authentication package to establish a data interaction channel; a dynamic adjustment module, configured to collect access environment information in real time by the trusted environment perception center, to dynamically update the access trust value to adjust the access control strategy, and to control the data interaction process between the access terminal and the service data end.
6. An electronic device, comprising: The electronic device comprises: a memory for storing executable instructions; a processor for running the executable instructions stored in the memory to implement the access control method based on the SPA technology of the zero trust architecture according to any one of claims 1 to 4.
7. A computer-readable storage medium storing executable instructions, wherein the instructions, when executed by a processor, cause the processor to perform operations comprising: The executable instructions are executed by the processor to implement the access control method based on the SPA technology of the zero trust architecture according to any one of claims 1 to 4.
Citation Information
Patent Citations
Secure de-centralized domain name system
CN110537346A
Information security protection system and method and storage medium
CN115001870A