Micro-isolation system and method based on service awareness in zero-trust environment
By using a micro-isolation system based on business perception in a zero-trust environment, using multiple attribute characteristics such as microservice type, business characteristics and network characteristics, an authorization strategy model is established, which solves the problem of difficult to achieve dynamic hierarchical adaptive access control in the existing technology, and realizes fine-grained permission management and system security and controllability.
Patent Information
- Application Number
- CN202311729783.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-15
- Publication Date
- 2025-06-17
AI Technical Summary
It is difficult for the prior art to realize dynamic hierarchical adaptive access control based on microservice trust and business scenario security characteristics in a zero-trust environment.
A service-aware micro-isolation system based on service perception in a zero-trust environment is proposed. Through micro-service business traffic perception and policy association, the verification logic and resource system are isolated, and only micro-services within the permission scope are allowed to exchange data. Using multi-attribute characteristics such as microservice types, business characteristics and network characteristics, an authorization policy model is established to achieve fine-grained permission management.
It realizes fine-grained permission management for microservices in a zero-trust environment, ensuring that only microservices within the scope of authorization can exchange data, and improves the security and controllability of the system.
Smart Images

Figure BDA0004609796130000021 
Figure BDA0004609796130000022 
Figure BDA0004609796130000031
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of zero-trust security, and in particular, to a micro-segmentation system and method based on service awareness in a zero-trust environment. Background Art
[0002] The central idea of zero-trust security is that an enterprise should not automatically trust anyone / thing inside or outside the enterprise, and should verify anyone / thing attempting to access the enterprise system before authorization. Similar to the idea of a whitelist with a minimum set of permissions, any entity such as an IP, host, ID, etc. without authorization or an unknown authorization path is denied access.
[0003] At the implementation level, "zero trust" requires an enterprise to determine whether to trust a user / host / application requesting access to a specific scope of the enterprise based on conditions such as the user, the location of the user, and other data, using micro-segmentation and fine-grained boundary rules.
[0004] Therefore, how to implement dynamic hierarchical adaptive access control based on microservice trust levels and service scenario security features is an issue that needs to be addressed currently. Summary of the Invention
[0005] To address the deficiencies in the prior art, the present application proposes a micro-segmentation system and method based on service awareness in a zero-trust environment. By means of microservice traffic awareness and policy association, the verification logic and the resource system are isolated, and only microservices within the permitted scope are allowed to perform data exchange. An authorization policy model is established using multi-attribute characteristics such as microservice type, service characteristics, and network characteristics to achieve fine-grained permission management.
[0006] The technical solution adopted by the present invention is as follows:
[0007] A micro-segmentation system based on service awareness in a zero-trust environment includes three units: a zero-trust engine, a zero-trust execution agent, and a microservice node;
[0008] The zero-trust engine filters services at the network protection boundary, extracts service context information, and generates service access data objects;
[0009] There are several zero-trust execution agents, and each zero-trust execution agent is signal-connected to the zero-trust engine; the zero-trust execution agent transmits service awareness data to the zero-trust engine, and accepts the policies issued by the zero-trust engine, and the zero-trust execution agent executes the policies; the zero-trust execution agent publishes service basic data to the service bus; each zero-trust execution agent is signal-connected to a microservice node, responsible for obtaining microservice status information, and issuing resource access policies.
[0010] Further, the access data object is represented as {S-ID, user, S-parameter, action}, which are the microservice identifier, the affiliated user, the microservice parameter, and the network behavior respectively.
[0011] Further, the zero-trust engine, the zero-trust execution agent, and the microservice nodes are all connected to the service bus.
[0012] A micro-segmentation method based on service awareness in a zero-trust environment includes the following steps:
[0013] Step 1: The zero-trust policy engine filters the services at the network protection boundary and extracts service context information.
[0014] Step 2: The zero-trust policy engine performs hierarchical authorization on the access data object according to the zero-trust least privilege principle.
[0015] Step 3: The zero-trust execution agent performs service awareness, real-time monitors and tracks the permission usage records, real-time monitors the interaction behaviors between microservices, real-time updates the permission policies that reach the threshold, and sends them to the zero-trust execution agent through an encryption algorithm to open the corresponding access permissions.
[0016] Further, the method for performing hierarchical authorization on the access data object is: performing least privilege authorization on the access data object, that is, performing hierarchical authorization on the microservice business data L1, the call relationship L2, and the control instruction L3 respectively. The authorization levels are divided into P1, P2, and P3, and a security scope is set for each level.
[0017] Further, the hierarchical authorization process is as follows:
[0018] Step 2.1: Perform preliminary permission calculation based on the microservice parameter and the network behavior to obtain the initial permission P0. According to the access relationship between microservices, obtain the initial security matrix, which is expressed as:
[0019]
[0020] where r m,n represents the access relationship between the m-th microservice and the n-th microservice in the matrix;
[0021] Step 2.2: Extract the microservice parameter from the access data object and perform hierarchical authorization; that is, judge the security scope according to the business characteristics and network characteristics of the microservice, trim the permissions that exceed the security scope, and keep the permissions within the security scope to form the access permission matrix X t , which is expressed as follows:
[0022]
[0023] Among them, P1, P2, and P3 are the access permissions corresponding to the microservices respectively.
[0024] Furthermore, when the network behavior of the microservice changes in step 3, the permissions of the terminal need to be dynamically changed. The process is as follows:
[0025] Step 3.1: Deploy a traffic monitoring device in the core switch to perform business perception on the traffic of all microservices and form microservice access logs;
[0026] Step 3.2: Set a system access threshold and perform threshold judgment; the corresponding relationships between the access threshold, authorization type, permission level, and network behavior are as follows:
[0027] Authorization type Permission level Access threshold Action list L1 P1 F1 Actions for adding, deleting, modifying, and querying business data L2 P2 F2 RPC method, event-driven method L3 P3 F3 Power-on / off control instruction, status control instruction, privilege escalation control
[0028] The calculation method of the access threshold is:
[0029]
[0030] Among them, α is the positive weight, indicating that the operation is within the threshold range, and β is the negative weight, indicating that the operation is not within the threshold range; A i is the score value of the i-th compliant operation; B i is the deduction value of the i-th illegal operation, where i = 1, 2, 3;
[0031] Step 3.3: The permission update data is encrypted and transmitted through a combined public key;
[0032] Step 3.4: Update the permission data. The update data packet is:
[0033] update = {S-ID s → S-ID t : P s → P t : action},
[0034] indicating that under the action of the access behavior action, the access permission of the microservice S-ID s to the microservice S-ID t changes from P s to P t ;
[0035] Encryption transmission: ciphertext
[0036] The zero-trust execution agent decrypts the data:
[0037] This change will be reflected in the permission matrix, where r g is the g-th public key, and R gis the g-th private key, and c is the ciphertext.
[0038] Further, the microservice access log formed in step 3.1 is expressed as:
[0039] {Time1→Time2:S-ID1→S-ID2:action},
[0040] indicating that during the time from Time1 to Time2, the microservice S-ID1 to S-ID2 had an access behavior identified as aciton.
[0041] Further, the key generation method in step 3.3 is as follows:
[0042] Take an elliptic curve y p on the finite field F 2 = (x 2 + ax + b) mod p, with parameters T = {a, b, G, n, p}, where p is a prime number, a and b are integers on F p On the elliptic curve cryptosystem, the key management system generates a public and private key pair as (r i , R i ).
[0043] Advantages of the present invention:
[0044] The present invention isolates the verification logic and the resource system by means of microservice business traffic perception and policy association, and only allows microservices within the authorized scope to perform data exchange. By using multi-attribute characteristics such as microservice type, business characteristics, and network characteristics, an authorization policy model is established to achieve fine-grained permission management. Brief Description of the Drawings
[0045] Figure 1 is a flowchart of a microservice isolation system based on business perception in a zero-trust environment.
[0046] Figure 2 is an architecture diagram of a microservice isolation system based on business perception in a zero-trust environment. Detailed Embodiments
[0047] In order to make the objectives, technical solutions, and advantages of the present invention clearer, the present invention will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not used to limit the present invention.
[0048] Combined with the attached Figure 1 and 2, the present invention proposes a micro - isolation system based on business awareness in a zero - trust environment. The system can perform dynamic hierarchical adaptive access control according to the microservice trust level and the security characteristics of the business scenario. The system includes three units: a zero - trust engine, a zero - trust execution agent, and a microservice node. Among them, the zero - trust engine filters the business at the network protection boundary, extracts business context information, generates business access data objects, and the access data objects are represented as {S - ID, user, S - parameter, action}, which are the microservice identifier, the affiliated user, the microservice parameters (business type, status), and the network behavior respectively.
[0049] There are several zero - trust execution agents, and each zero - trust execution agent is signal - connected to the zero - trust engine. Among them, the zero - trust execution agent transmits business awareness data to the zero - trust engine, accepts the policies issued by the zero - trust engine, and executes the policies by the zero - trust execution agent; the zero - trust execution agent publishes the business basic data to the business bus.
[0050] Each zero - trust execution agent is signal - connected to a microservice node, responsible for obtaining microservice status information and issuing resource access policies; and the zero - trust engine, the zero - trust execution agent, and the microservice node are all connected to the business bus.
[0051] Based on the above - mentioned micro - isolation system, the present invention also proposes a micro - isolation method based on business awareness in a zero - trust environment. This method specifically includes three steps:
[0052] Step 1: The zero - trust policy engine filters the business at the network protection boundary, extracts business context information, and the information includes the microservice identifier, the affiliated user, the microservice parameters (type, status), and the network behavior, and generates business access data objects {S - ID, user, S - parameter, action}.
[0053] Step 2: The zero - trust policy engine performs hierarchical authorization on the access data objects according to the zero - trust principle of least privilege. Specifically: perform least - privilege authorization on the access data objects, that is, perform hierarchical authorization on the microservice business data (L1), the call relationship (L2), and the control instruction (L3) respectively. The authorization levels are divided into: P1, P2, P3, and a corresponding security scope is set for each level. The security scope is the set of access instances corresponding to each level.
[0054] Step 3: The zero - trust execution agent performs business awareness, real - time monitors and tracks the permission usage records, real - time monitors the interaction behaviors between microservices, makes real - time changes to the permission policies that reach the threshold, and sends them to the zero - trust execution agent through an encryption algorithm to open the corresponding access permissions.
[0055] In this embodiment, in combination with Figure 2, the hierarchical authorization process in Step 2 above is as follows:
[0056] Step 2.1: Perform preliminary permission calculation based on microservice parameters and network behavior to obtain the initial permission P0. The initial permission ensures that the system is in a secure state. In specific implementation, based on the controllability and trustworthiness of the microservice during initial deployment, determine the initial access policy that meets the security conditions. The initial security matrix is as follows:
[0057]
[0058] Among them, r m,n represents the access relationship between the m-th microservice and the n-th microservice in the matrix.
[0059] Step 2.2: Extract microservice parameters from the access data object and perform hierarchical authorization. At the same time, judge the security scope according to the business characteristics and network characteristics of the microservice, trim the permissions that exceed the security scope, and keep the permissions within the security scope. Specific permission allocation examples are as follows:
[0060]
[0061] Among them, X t is the access permission matrix, and P1, P2, and P3 are the access permissions corresponding to the microservices respectively.
[0062] The permission policy update in Step 3 above is that when the network behavior of the microservice changes, the permissions of the terminal need to be dynamically changed, specifically as follows:
[0063] Step 3.1: Perform business perception. Deploy a traffic monitoring device in the core switch to perceive the traffic of all microservices and form a microservice access log, the format of which is:
[0064] {Time1→Time2:S-ID1→S-ID2:action},
[0065] indicating that during the time from Time1 to Time2, the microservice S-ID1 to S-ID2 had an access behavior identified as aciton.
[0066] Step 3.2: Perform threshold judgment. Set the system access threshold, and its format is shown in the following table:
[0067]
[0068]
[0069] Among them, the access threshold is the score of the action list behavior, and the specific calculation is as follows:
[0070]
[0071] Among them, α is the positive weight, indicating that the operation is within the threshold range, and β is the negative weight, indicating that the operation is not within the threshold range; A i is the score value of the i-th compliant operation; B i is the deduction value of the i-th illegal operation, where i = 1, 2, 3.
[0072] Step 3.3: Generate the permission update key. The permission update data is encrypted and transmitted through the combined public key to ensure data consistency. The specific key generation method is as follows:
[0073] According to the combined public key algorithm, take an elliptic curve y on the finite field Fp 2 =(x 2 +ax + b) mod p, and the parameters are T = {a, b, G, n, p}, where p is a prime number, a and b are integers on F p , G is the base point of the additive group on the elliptic curve, and n is the order of the group based on G. For the elliptic curve cryptosystem, the key management system generates a public key and private key pair as (r i , R i ).
[0074] Step 3.4: Update the permission data. The update data packet is:
[0075] update = {S-ID s →S-ID t :P s →P t :action},
[0076] indicating that under the action of the access behavior action, the access permission of the microservice S-ID s to S-ID t changes from P s to P t .
[0077] Encrypted transmission: The ciphertext
[0078] The zero-trust execution agent decrypts the data:
[0079] This change will be reflected in the permission matrix. r g is the g-th public key, R g is the g-th private key, and c is the ciphertext.
[0080] The above embodiments are only used to illustrate the design concept and features of the present invention, and the purpose is to enable those skilled in the art to understand the content of the present invention and implement it accordingly. The protection scope of the present invention is not limited to the above embodiments. Therefore, all equivalent changes or modifications made according to the principles and design concepts disclosed by the present invention are within the protection scope of the present invention.
Claims
1. A micro - isolation system based on business awareness in a zero - trust environment, characterized in that, It includes three units: a zero-trust engine, a zero-trust execution agent, and a microservice node; The zero-trust engine filters services at the network protection boundary, extracts service context information, and generates service access data objects; There are several zero-trust execution agents, and each zero-trust execution agent is signal-connected to the zero-trust engine; The zero-trust execution agent transmits service perception data to the zero-trust engine, accepts the policies issued by the zero-trust engine, and executes the policies by the zero-trust execution agent; The zero-trust execution agent publishes service basic data to the service bus; Each zero-trust execution agent is signal-connected to a microservice node, responsible for obtaining microservice status information and issuing resource access policies.
2. The micro - isolation system based on business awareness in a zero - trust environment according to claim 1, characterized in that, The access data object is represented as {S-ID, user, S-parameter, action}, which are microservice identifier, affiliated user, microservice parameter, and network behavior respectively.
3. The micro - isolation system based on business awareness in a zero - trust environment according to claim 1, characterized in that, The zero-trust engine, the zero-trust execution agent, and the microservice node are all connected to the service bus.
4. A micro - isolation method based on business awareness in a zero - trust environment, characterized in that, Based on the microservice isolation system based on service perception in a zero-trust environment described in claim 1, the implementation method is as follows: Step 1: The zero-trust policy engine filters services at the network protection boundary and extracts service context information; Step 2: The zero-trust policy engine performs hierarchical authorization on the access data object according to the zero-trust least privilege principle, Step 3: The zero-trust execution agent performs service perception, real-time monitors and tracks the permission usage records, real-time monitors the interaction behaviors between microservices, real-time updates the permission policies that reach the threshold, and sends them to the zero-trust execution agent through an encryption algorithm to open the corresponding access permissions.
5. The micro - isolation method based on business awareness in a zero - trust environment according to claim 4, characterized in that, The method for performing hierarchical authorization on the access data object is: perform least privilege authorization on the access data object, that is, perform hierarchical authorization on microservice business data L1, call relationship L2, and control instruction L3 respectively. The authorization levels are divided into P1, P2, and P3, and a security range is set for each level.
6. The micro - isolation method based on business awareness in a zero - trust environment according to claim 5, characterized in that, The process of the hierarchical authorization is as follows: Step 2.1: Perform preliminary permission calculation based on microservice parameters and network behavior to obtain the initial permission P0. According to the access relationship between microservices, obtain the initial security matrix, which is expressed as: where r m,n represents the access relationship between the m-th microservice and the n-th microservice in the expression matrix; Step 2.2: Extract microservice parameters from the accessed data object and perform hierarchical authorization; that is, judge the security scope according to the business characteristics and network characteristics of the microservice, trim the permissions that exceed the security scope, and maintain the permissions within the security scope to form an access permission matrix X t , which is expressed as follows: Among them, P1, P2, and P3 are the access permissions corresponding to the microservices respectively.
7. The micro - isolation method based on business awareness in a zero - trust environment according to claim 5 or 6, characterized in that, In step 3, the permission policy update is that when the network behavior of the microservice changes, the permissions of the terminal need to be dynamically changed. The process is as follows: Step 3.1: Deploy a traffic monitoring device in the core switch to perform service perception on the traffic of all microservices and form microservice access logs; Step 3.2: Set the system access threshold and perform threshold judgment; the corresponding relationship between the access threshold, authorization type, permission level, and network behavior is as follows: The calculation method of the access threshold is: Among them, α is the positive weight, indicating that the operation is within the threshold range, and β is the negative weight, indicating that the operation is not within the threshold range; A i is the score value of the i-th compliant operation; B i is the deduction value of the i-th illegal operation, where i = 1, 2, 3; Step 3.3: The permission update data is encrypted and transmitted through a combined public key; Step 3.4: Update the permission data, and the update data packet is: update = {S-ID s → S-ID t :P s → P t :action}, Indicates that under the action of access behavior action, microservice S-ID s to microservice S-ID t The access permission of s is changed from P t ; Encrypted transmission: ciphertext Zero Trust Enforcement Agent decrypts data: This change will be reflected in the permission matrix, r g is the g-th public key, R g is the g-th private key, and c is the ciphertext.
8. A micro - isolation method based on service awareness in a zero - trust environment according to claim 7, characterized in that, The microservice access log formed in step 3.1 is expressed as: {Time1→Time2:S-ID1→S-ID2:action}, It indicates that within the time period from Time1 to Time2, the microservices S-ID1 to S-ID2 have an access behavior labeled as action.
9. A micro - isolation method based on service awareness in a zero - trust environment according to claim 7, characterized in that, The method for generating the key in Step 3.3 is as follows: Take an elliptic curve y over the finite field F p =(x 2 +ax + b) mod p, with parameters T = {a, b, G, n, p}, where p is a prime number, a and b are integers in F 2 , G is the base point of the additive group on the elliptic curve, and n is the order of the group with G as the base point. For the cryptosystem based on the elliptic curve, the key management system generates a public-private key pair as (r p , R i ). i )
Citation Information
Cited By
Network micro-isolation protection method, system and equipment based on zero-trust architecture
CN121462316A