Zero-trust network node dynamic trust degree evaluation and intelligent resource allocation method, equipment and medium

Through continuous dynamic trust evaluation and intelligent resource allocation of zero-trust architecture, the limitations of boundary defense and static trust models in traditional network security are solved, and efficient management and security protection of complex network environments are achieved.

CN120263486AActive Publication Date: 2025-07-04ANHUI UNIV +5

Patent Information

Application Number
CN202510431488.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-08
Publication Date
2025-07-04
Estimated Expiration
2045-04-08

AI Technical Summary

Technical Problem

Traditional network security protection technology relies on boundary defense and static trust models and cannot effectively deal with real-time changes in complex and dynamic network environments, resulting in an expansion of attack surface, unreasonable resource allocation and difficult to prevent internal threats.

Method used

Using a zero-trust architecture, we use continuous dynamic evaluation of node trust, based on behavior and real-time context evaluation, optimize weight parameters using wavelet transformation, particle swarm algorithm and gradient descent method, design trust calculation formulas, and dynamically adjust access control policies and resource allocation.

Benefits of technology

It realizes efficient trust management and reasonable resource allocation for complex network environments, enhances network security and flexibility, prevents internal threats and potential attacks, and meets security needs in dynamic environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120263486A_ABST
    Figure CN120263486A_ABST
Patent Text Reader

Abstract

The invention relates to a zero-trust network node dynamic trust degree evaluation and intelligent resource allocation method, equipment and medium, based on the principle of never trust and continuous verification, continuous information acquisition processing is carried out on all interaction nodes in a zero-trust network environment, a node trust degree calculation model is constructed based on processed data, and the dynamic trust degree evaluation and intelligent resource allocation of the zero-trust network node is realized. Weight parameters are dynamically optimized through a credibility evaluation layer; a dynamic trust threshold is set according to the node trust degree, an access control strategy is adjusted at a decision-making layer, and hierarchical allocation of resources is implemented. In addition, a continuous authentication and anomaly detection mechanism is introduced, node behaviors are monitored in real time, a trust strategy is dynamically adjusted, and abnormal access is limited; based on behaviors, contexts and real-time trust evaluation, refined access control and resource management are realized, internal threats, permission abuse and potential attacks can be effectively prevented, security requirements in a complex dynamic environment are met, and trust management efficiency and resource scheduling rationality are further improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of cyberspace security, and particularly to a method, device and medium for dynamically evaluating the trust degree of zero-trust network nodes and intelligently allocating resources. Background Art

[0002] With the development of technologies such as cloud computing, big data, and the Internet of Things, the number of devices and users in cyberspace has increased sharply, and the security risks in cyberspace have also expanded accordingly. Traditional network security protection technologies mainly rely on boundary defense and static trust models, which gradually show disadvantages in complex and dynamic network environments:

[0003] (1) Limitations of boundary defense: The traditional boundary defense model assumes that nodes within the network are trustworthy, but devices and users within the network may also be controlled by attackers, which provides a breakthrough for attacks.

[0004] (2) Static trust model: Once a user or node passes the initial verification, it is regarded as trustworthy, lacking continuous monitoring and dynamic evaluation of subsequent behaviors, which is prone to internal threats.

[0005] (3) Expansion of the attack surface: Attackers can move laterally through legitimate authenticated nodes, endangering the entire system.

[0006] (4) Unreasonable resource allocation: Lack of a dynamic real-time trust evaluation mechanism, resulting in rigid resource allocation, unable to adjust according to the real-time trust level of nodes, causing waste of resources.

[0007] In the prior art, some studies have tried to introduce a dynamic trust model in network access control. For example: a trust calculation method based on the historical behavior of devices for scoring, but it cannot effectively cope with real-time changes in complex networks, and the weight allocation of the trust degree is dominated by humans, lacking an intelligent optimization mechanism and being difficult to reflect the actual scenario.

[0008] In view of this, this method is proposed in combination with the zero-trust security architecture. The zero-trust architecture is based on the principle of "never trust, always verify", and proposes to continuously and dynamically evaluate the trust degree of nodes, requiring that network access control not only depends on user authentication, but also continuously monitors and adjusts the trust state based on behavior and real-time context evaluation to meet the requirements of complex environments with real-time changes, thereby achieving efficient trust management and reasonable resource allocation. Summary of the Invention

[0009] Aiming at the deficiencies of the prior art, the present invention provides a method, device and medium for dynamically evaluating the trust degree of zero-trust network nodes and intelligent resource allocation, which solves the problem that traditional methods cannot effectively cope with real-time changes in complex networks, and the weight allocation of trust degree is dominated by humans, lacking an intelligent optimization mechanism and being difficult to reflect actual scenarios, that is, aiming to solve the problems of traditional access control relying on static trust evaluation and rigid management. This method proposes to continuously and dynamically evaluate the node trust degree, requiring that network access control not only depends on user authentication, but also continuously and dynamically monitors and adjusts the trust state based on behavior and real-time context evaluation to meet the needs of complex environments with real-time changes, so as to achieve efficient trust management and reasonable resource allocation.

[0010] To solve the above technical problems, the present invention provides the following technical solutions: A method for dynamically evaluating the trust degree of zero-trust network nodes and intelligent resource allocation, including the following steps:

[0011] S1. Collect information on all interaction nodes in the zero-trust network environment;

[0012] S2. After information collection, perform cleaning processing on the data, including denoising, filling and normalization;

[0013] S3. Design a trust degree calculation formula for nodes according to the collected information, and dynamically optimize the weight parameters α, β, γ, η, θ1, θ2, θ3 through the node trust degree evaluation layer based on the processed data;

[0014] S4. Set corresponding trust thresholds according to the trust degree of nodes, dynamically adjust the trust thresholds in the decision layer, and allocate resource hierarchical access control policies.

[0015] Further, in step S1, the collecting information on all interaction nodes in the zero-trust network environment specifically includes: Interaction success rate I i : The statistical ratio of whether data transmission between nodes is successful; Response time R i : The response delay time of communication between nodes; Resource consumption rate C i : The bandwidth, CPU, and storage resources consumed during node access or interaction; Historical behavior credibility A i : The access history of the node and the detection results of abnormal behaviors.

[0016] More specifically, in step S1, it also includes collecting environmental authentication information: using the device management protocol, timestamp, and IP geographical location parsing to obtain device health status, access time, and geographical location information respectively, and adding them to the trustworthiness assessment to further strengthen the idea of multi-factor authentication in the zero-trust architecture. Among them, the device health status: not only verifies the user's identity but also verifies whether the device is in a safe state, that is, whether the latest security patches are installed and whether there is malware; access timing and location: according to the access timing and location, evaluate whether it belongs to a normal access pattern to prevent unauthorized access after stealing the user's identity through phishing.

[0017] Further, in step S2, after information collection, cleaning processing of denoising, filling, and normalization is performed on the data. The specific process includes the following steps:

[0018] S21. Perform denoising processing using wavelet transform, decompose the signal into different frequency domains, and filter out high-frequency noise:

[0019]

[0020] Among them, c(m,n) is the wavelet coefficient, m is the scale parameter, which controls the stretching degree of the wavelet function and corresponds to different frequency bands in the frequency domain, and n is the translation parameter, which determines the position of the wavelet function on the time axis. is the wavelet basis function;

[0021] S22. Fill in missing values and outliers in the data based on the statistics of similar nodes. First, define the similarity metric:

[0022]

[0023] Among them, Node a , Node b represent two network nodes to be compared, x a,i refers to the eigenvalue of node a in the i-th feature dimension, and x b,i refers to the eigenvalue of node b in the i-th feature dimension;

[0024] Then, according to the similarity, select the k most similar nodes from high to low, and use the mean value of the similar nodes to fill in the missing values and then correct the outliers:

[0025]

[0026] Among them, x j is the j-th of the k most similar nodes, and the value range of j is from 1 to k;

[0027] S23. Adopt the Min-max normalization method to normalize all data X iNormalize to the same scale range [0,1], where i = 1,…,k, for better weighted calculation to obtain the normalized data X i ':

[0028]

[0029] Among them, X min ,X max Correspond to the minimum and maximum values of each variable.

[0030] Furthermore, in step S3, the trustworthiness calculation formula of the node is designed according to the collected information, and the weight parameters α, β, γ, η, θ1, θ2, θ3 are dynamically optimized through the node trustworthiness evaluation layer based on the processed data. The specific process includes the following steps:

[0031] S31. Design the node trustworthiness calculation formula according to the collected information:

[0032]

[0033] Among them, σ(·) is a normalization function that normalizes the trust value to the range [0,1], T i ,I i ,R i ,C i ,A i ,E i respectively represent the trustworthiness, interaction success rate, response time, resource consumption rate, historical behavior credibility and current environmental context variables of the node. The non-linear mapping functions f(I i ,R i ), g(C i ,A i ) are the relationship functions between the interaction success rate and the response time and the relationship function between the resource consumption rate and the historical behavior respectively. d(E i ) is the dynamic environment factor, and α, β, γ, η are the weight parameters corresponding to each factor; γ is the basic adjustment parameter used to balance the influence of the molecular weight and the environment factor;

[0034] In addition, the relationship function f(I i ,R i ) between the interaction success rate and the response time:

[0035]

[0036] Among them, θ1, θ2, θ3 are weight coefficients optimized by the algorithm;

[0037] The relationship function g(C i ,A i ) between the resource consumption rate and the historical behavior:

[0038] g(C i ,A i ) = log(1 + C i )·(1 - A i );

[0039] Dynamic environment factor d(E i ):

[0040] d(E i ) = α1·H i + α2·M i + α3·G i ;

[0041] Among them, H i , M i , G i ∈[0,1] are the device health status, access time, and geographical location respectively, and α1, α2, α3 are the weights corresponding to H i , M i , G i ;

[0042] S32. Use the particle swarm optimization algorithm to solve the weights α, β, γ, η in the trust degree calculation formula;

[0043] S33. Use the gradient descent method to solve the weight parameters θ1, θ2, θ3 in the relationship function f(I i , R i ) between the interaction success rate and the response time.

[0044] Furthermore, in step S32, the process of using the particle swarm optimization algorithm to solve the weights α, β, γ, η in the trust degree calculation formula specifically includes the following steps:

[0045] S321. Initialize parameters: Set the number of particles N, the search range is [0,1], and initialize the weight parameters α, β, γ, η and the velocity v of each particle;

[0046] S322. Design the fitness function evaluation, and use the accuracy of the trust evaluation result and the system security as the fitness evaluation criteria:

[0047] Fitness(α, β, γ, η) = λ1·Accuracy(α, β, γ, η) - λ2·Risk(α, β, γ, η);

[0048] Among them, Accuracy(α, β, γ, η) is the trust degree accuracy calculated based on the optimized weights, Risk(α, β, γ, η) is the system security risk, which measures the impact of malicious nodes or attacks, and λ1, λ2 are adjustment coefficients;

[0049]

[0050] Risk = ∑(Abnormal request rate + Failure rate + High - risk behavior frequency);

[0051] Among them, T i True is the true trust level of node i, and T i pred is the predicted trust level of node i, and n is the total number of samples in the validation set (the number of nodes participating in the evaluation);

[0052] S323. Update the global optimal solution and the local optimal solution

[0053] S324. Update the particle velocity:

[0054]

[0055] Among them, ω is the inertia weight, controlling the tendency of the particle to maintain the original velocity, and c1, c2 are the cognitive factor and the social coefficient, respectively controlling the influence of individual experience and group experience, is the local optimal solution, is the global optimal solution, x i is the position of the particle, and r1, r2 are random numbers within the interval [0, 1], used to maintain the population diversity;

[0056] Update the particle position:

[0057] x i+1 = x i + v i+1 ;

[0058] S325. When the fitness value meets the accuracy requirement or the upper limit of the iteration times, output the optimal weight parameters α, β, γ, η.

[0059] Furthermore, in step S33, when using the gradient - descent method to solve the weight parameters θ1, θ2, θ3 in the relationship function f(I i , R i ) of the interaction success rate and the response time, the specific process includes the following steps:

[0060] S331. Collect data: Obtain the historical data of the interaction success rate I i and the response time R i ;

[0061] S332. Define the objective loss function:

[0062] Loss = ∑|T i True-f(I i ,R i )|;

[0063] where T i True is the true trust degree of node i;

[0064] S333. Initialize the weight parameters θ1, θ2, θ3 and the learning rate η;

[0065] S334. Use the gradient descent method to solve and update the weight parameters θ1, θ2, θ3:

[0066]

[0067] where θ k is the k-th weight parameter to be optimized, and k ranges from 1 to 3;

[0068] S334. When the loss function converges or reaches the iteration limit, output the optimal weight parameters θ1, θ2, θ3.

[0069] Furthermore, in step S4, setting the corresponding trust threshold according to the trust degree of the node, performing trust dynamic threshold adjustment in the decision layer, and allocating the resource hierarchical access control policy, the specific process includes the following steps:

[0070] S41. Dynamic threshold setting and access control:

[0071] T threshold = μ·avg(T) + σ·std(T);

[0072] where μ and σ are the average value and standard deviation of threshold adjustment respectively, representing the equilibrium state of all nodes in the current network, avg(T) and std(T) are the average value and standard deviation of the trust degree respectively. By dynamically adjusting these thresholds, the system can ensure real-time adjustment of access permissions and resource allocation according to the network state;

[0073] S42. Input the trust degree T i of each node, adjust the trust degree threshold according to the current network environment and resource allocation requirements and perform resource hierarchical allocation:

[0074] High-trust nodes: If allow the node to access sensitive resources and preferentially allocate high-performance resources;

[0075] Medium-trust nodes: If allow the node to access ordinary resources and restrict some operation permissions;

[0076] Low-trust nodes: If Restrict node access and resume when the trust value returns to the set threshold.

[0077] Through the above technical solutions, the present invention provides a zero-trust network node dynamic trust evaluation and intelligent resource allocation method, device, and medium, which at least have the following beneficial effects:

[0078] 1. The present invention enhances the accuracy of trust evaluation by performing denoising, filling, and normalization cleaning processes on the acquired information data to ensure the accuracy, integrity, and effectiveness of the data during the trust calculation process.

[0079] 2. Design a trust value calculation formula based on node interaction information: interaction success rate, response time, resource consumption rate, and environmental factors. Use intelligent algorithms to determine the weights of each variable, and solve the weights through the trust value calculation formula and intelligent algorithms to achieve dynamic real-time evaluation of node trust, solving the defects of static trust models; use intelligent algorithms to solve weights and automatically adjust with changes in the network environment to achieve adaptive update of intelligent algorithms, avoiding the deficiencies of human dominance, and ensuring that the node evaluation model can adapt to complex and changing network environments.

[0080] 3. The present invention introduces a continuous authentication and anomaly detection mechanism to monitor node behavior in real time, dynamically adjust trust policies and restrict abnormal access, set access control thresholds based on dynamic trust values, and achieve reasonable allocation and secure transfer of resources. Efficient resource allocation and access control improve the flexibility and security of network resource management, as well as the implementation of the zero-trust security principle: strictly follow the zero-trust security concept of "never trust, always verify", continuously and dynamically evaluate all nodes, prevent potential security threats, and enhance the network's security protection capabilities.

[0081] 4. Compared with the traditional static identity authentication-based model, the present invention realizes refined access control and resource management based on behavior, context, and real-time trust evaluation, can effectively prevent internal threats, privilege abuse, and potential attacks, meet the security requirements in complex dynamic environments, and thus improve the efficiency of trust management and the rationality of resource scheduling. BRIEF DESCRIPTION OF THE DRAWINGS

[0082] The drawings described herein are used to provide a further understanding of the present application, form a part of the present application, and the illustrative embodiments and descriptions thereof are used to explain the present application and do not constitute an improper limitation of the present application. In the drawings:

[0083] Figure 1 is a framework diagram of the zero-trust security architecture based on dynamic trust evaluation of the present invention;

[0084] Figure 2 is a flowchart of the present invention using the particle swarm optimization algorithm to solve the parameters α, β, γ, η;

[0085] Figure 3 This is the flowchart for the present invention to solve the parameters θ1, θ2, and θ3 using the gradient descent method;

[0086] Figure 4 This is the flowchart for the dynamic threshold setting and access control of the present invention. Detailed implementation manners

[0087] To make the above objects, features, and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the accompanying drawings and specific implementation manners. Thereby, the implementation process of how the present application uses technical means to solve technical problems and achieve technical effects can be fully understood and implemented accordingly.

[0088] Those of ordinary skill in the art can understand that all or part of the steps in the methods of the above embodiments can be completed by instructing relevant hardware through a program. Therefore, the present application can adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present application can adopt the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk memories, CD-ROMs, optical memories, etc.) containing computer-usable program codes.

[0089] Please refer to Figures 1-4 , which shows a specific implementation manner of this embodiment. Based on the principle of "never trust, continuously verify", the present invention continuously collects information on all interaction nodes in a zero-trust network environment, and performs denoising, filling, and normalization processing on the data to ensure data integrity. Based on the processed data, a node trust degree calculation model is constructed, and the weight parameters are dynamically optimized through the trust degree evaluation layer; a dynamic trust threshold is set according to the node trust degree, the access control policy is adjusted at the decision-making layer, and resource hierarchical allocation is implemented. In addition, the present invention introduces a continuous authentication and anomaly detection mechanism to monitor node behaviors in real time, dynamically adjust trust policies, and restrict abnormal access to ensure system security and flexibility. Compared with the traditional static identity authentication-based mode, the present invention realizes refined access control and resource management based on behaviors, contexts, and real-time trust evaluations, can effectively prevent internal threats, privilege abuses, and potential attacks, meet the security requirements in complex dynamic environments, and thus improve the efficiency of trust management and the rationality of resource scheduling.

[0090] Please refer to Figure 1 , this embodiment proposes a method for dynamic trust degree evaluation and intelligent resource allocation of zero-trust network nodes, and the method includes the following steps:

[0091] S1. Collect information on all interaction nodes in a zero-trust network environment;

[0092] As a preferred embodiment of step S1, in step S1, the information collection of all interaction nodes in the zero-trust network environment specifically includes: interaction success rate I i : The statistical ratio of whether the data transmission between nodes is successful; response time R i : The response delay time of the communication between nodes; resource consumption rate C i : The bandwidth, CPU, and storage resources consumed during the node access or interaction; historical behavior credibility A i : The access history of the node and the detection results of abnormal behaviors;

[0093] In the zero-trust network environment, the success or failure status of each interaction request is recorded by using network access logs respectively. The resource consumption situation is obtained from the resource monitoring module of the node system, the delay time is extracted from the communication protocol, and the response time is recorded, so as to calculate:

[0094] ① Interaction success rate I i :

[0095]

[0096] where N total is the total number of communications between the node and other nodes, and N success is the number of successful times.

[0097] ② Response time R i :

[0098]

[0099] where T i is the response time of the i-th interaction, and N t is the total number of interactions.

[0100] ③ Resource consumption rate C i :

[0101]

[0102] where U i is the resource consumed during the i-th interaction, and N t is the total number of interactions.

[0103] ④ Historical behavior credibility A i : Analyze the past access logs of the node to identify abnormal behaviors, such as excessive failed requests.

[0104] More specifically, step S1 further includes collecting environmental authentication information: using device management protocols, timestamps, and IP geolocation parsing to obtain device health status, access time, and location information respectively, and adding them to the trustworthiness assessment to further strengthen the idea of multi-factor authentication in the zero-trust architecture. Among them, device health status: not only verifies the user's identity, but also verifies whether the device is in a secure state, that is, whether the latest security patches are installed and whether there is malware; access timing and location: based on the timing and location of access, assess whether it belongs to a normal access pattern to prevent unauthorized access after stealing the user's identity through phishing or other means.

[0105] S2. After information collection, perform denoising, filling, and normalization cleaning on invalid and duplicate data;

[0106] As a preferred implementation of step S2, in step S2, after information collection, perform denoising, filling, and normalization cleaning on the data. The specific process includes the following steps:

[0107] S21. Perform denoising using wavelet transform, decompose the signal into different frequency domains, and filter out high-frequency noise:

[0108]

[0109] Among them, c(m,n) is the wavelet coefficient, m is the scale parameter, which controls the stretching degree of the wavelet function and corresponds to different frequency bands in the frequency domain, and n is the translation parameter, which determines the position of the wavelet function on the time axis. is the wavelet basis function;

[0110] S22. Fill in missing values and outliers in the data based on the statistics of similar nodes. First, define the similarity metric:

[0111]

[0112] Among them, Node a ,Node b represent two network nodes to be compared, x a,i refers to the eigenvalue of node a in the i-th feature dimension, and x b,i refers to the eigenvalue of node b in the i-th feature dimension;

[0113] Then, according to the similarity, select the k most similar nodes from high to low ( N is the total number of nodes), and use the mean value of the similar nodes to fill in the missing values and then correct the outliers:

[0114]

[0115] Among them, x jis the j-th among the k most similar nodes, where j ranges from 1 to k;

[0116] S23. Use the Min-max normalization method to normalize all data X i , (i = 1, …, k) to the same scale range, usually [0, 1], for better weighted calculation, and obtain the normalized data X i ':

[0117]

[0118] where X min , X max correspond to the minimum and maximum values of each variable.

[0119] In this embodiment, through these cleaning processes of denoising, filling, and normalization, the data accuracy and effectiveness in the trustworthiness calculation process are ensured to enhance the accuracy of trustworthiness evaluation.

[0120] S3. Design a trustworthiness calculation formula for the node based on the collected information, and dynamically optimize the weight parameters α, β, γ, η, θ1, θ2, θ3 through the node trustworthiness evaluation layer based on the processed data;

[0121] As a preferred implementation manner of step S3, in step S3, the process of designing a trustworthiness calculation formula for the node based on the collected information and dynamically optimizing the weight parameters α, β, γ, η, θ1, θ2, θ3 through the node trustworthiness evaluation layer specifically includes the following steps: The specific process includes the following steps:

[0122] S31. Design a trustworthiness calculation formula for the node according to the collected information:

[0123]

[0124] where σ(·) is a normalization function that normalizes the trust value to the range [0, 1], T i , I i , R i , C i , A i , E i respectively represent the trustworthiness, interaction success rate, response time, resource consumption rate, historical behavior credibility, and current environmental context variable of the node. The non-linear mapping functions f(I i , R i ), g(C i , A i ) are the relationship functions between the interaction success rate and the response time and the relationship function between the resource consumption rate and the historical behavior respectively, d(E i) is the dynamic environmental factor, α, β, η are the weight parameters corresponding to each factor, and γ is the basic adjustment parameter used to balance the influence of the molecular weight and the environmental factor;

[0125] In addition, the relationship function f(I i ,R i ) between the interaction success rate and the response time is as follows:

[0126]

[0127] Among them, θ1, θ2, θ3 are the weight coefficients, which are optimized by the algorithm;

[0128] The relationship function g(C i ,A i ) between the resource consumption rate and the historical behavior is as follows:

[0129] g(C i ,A i ) = log(1 + C i )·(1 - A i );

[0130] The dynamic environmental factor d(E i ) is as follows:

[0131] d(E i ) = α1·H i + α2·A i + α3·G i ;

[0132] Among them, H i ,M i ,G i ∈ [0, 1] are the device health status, access time, and geographical location respectively, and α1, α2, α3 are the weights corresponding to H i ,M i ,G i respectively;

[0133] S32. Use the particle swarm algorithm to solve the weights α, β, γ, η in the trust degree calculation formula;

[0134] More specifically, in step S32, the process of using the particle swarm algorithm to solve the weights α, β, γ, η in the trust degree calculation formula specifically includes the following steps:

[0135] S321. Initialize the parameters: Set the number of particles N, the search range is [0, 1], and initialize the weight parameters α, β, γ, η and the velocity v of each particle;

[0136] S322. Evaluate and design the fitness function, and use the accuracy of the trust evaluation result and the system security as the fitness evaluation criteria:

[0137] Fitness(α, β, γ, η) = λ1·Accuracy(α, β, γ, η) - λ2·Risk(α, β, γ, η);

[0138] Among them, Accuracy(α, β, γ, η) is the trust accuracy calculated based on the optimized weights, Risk(α, β, γ, η) is the security risk of the system, measuring the impact of malicious nodes or attacks, and λ1, λ2 are adjustment coefficients;

[0139]

[0140] Risk = ∑(abnormal request rate + failure rate + high-risk behavior frequency);

[0141] Among them, T i True is the true trust of node i, T i pred is the predicted trust of node i, and n is the total number of samples in the validation set (the number of nodes participating in the evaluation);

[0142] S323. Update the global optimal solution and the local optimal solution

[0143] S324. Update the particle velocity:

[0144]

[0145] Among them, ω is the inertia weight, controlling the tendency of the particle to maintain the original velocity, c1, c2 are the cognitive factor and the social coefficient, respectively controlling the influence of individual experience and group experience, is the local optimal solution, is the global optimal solution, x i is the position of the particle, r1, r2 are random numbers in the interval [0, 1], used to maintain the population diversity;

[0146] Update the particle position:

[0147] x i+1 = x i + v i+1 ;

[0148] S325. When the fitness value meets the accuracy requirement or the upper limit of the iteration times, output the optimal weight parameters α, β, γ, η.

[0149] S33. Use the gradient descent method to solve the weight parameters θ1, θ2, θ3 in the relationship function f(I i , R i ) of the interaction success rate and the response time;

[0150] More specifically, in step S33, when using the gradient descent method to solve the relationship function f(I i ,R i ) of the interaction success rate and the response time, the weight parameters θ1, θ2, θ3 specifically include the following steps:

[0151] S331. Collect data: Obtain the historical data of the interaction success rate I i and the response time R i ;

[0152] S332. Define the objective loss function:

[0153] Loss = ∑|T i True -f(I i ,R i )|;

[0154] where T i True is the true trust degree of node i;

[0155] S333. Initialize the weight parameters θ1, θ2, θ3 and the learning rate η;

[0156] S334. Use the gradient descent method to solve and update the weight parameters θ1, θ2, θ3:

[0157]

[0158] where θ k is the k-th weight parameter to be optimized, and the value of k ranges from 1 to 3;

[0159] S334. When the loss function converges or reaches the iteration limit, output the optimal weight parameters θ1, θ2, θ3.

[0160] In this embodiment, according to the node interaction information: interaction success rate, response time, resource consumption rate, and environmental factors, a trust value calculation formula is designed, the weights of each variable are determined by an intelligent algorithm, and the weights are solved through the trust value calculation formula and the intelligent algorithm to realize the dynamic real-time evaluation of the node trust degree, solving the defects existing in the static trust model; using an intelligent algorithm to solve the weights and automatically adjusting with the change of the network environment to realize the adaptive update of the intelligent algorithm, avoiding the deficiency of human dominance, and ensuring that the node evaluation model can adapt to the complex and changeable network environment.

[0161] S4. According to the trust degree of the node, set the corresponding trust threshold, perform dynamic trust threshold adjustment in the decision layer, and allocate the resource hierarchical access control policy.

[0162] As a preferred embodiment of step S4, in step S4, according to the trust level of the nodes, corresponding trust thresholds are set, dynamic trust threshold adjustment is performed in the decision-making layer, and a resource hierarchical access control policy is allocated. The specific process includes the following steps:

[0163] S41. Dynamic Threshold Setting and Access Control:

[0164] T threshold = μ·avg(T)+σ·std(T);

[0165] Where μ and σ are the average value and standard deviation of threshold adjustment respectively, representing the equilibrium state of all nodes in the current network. avg(T) and std(T) are the average value and standard deviation of the trust level respectively. By dynamically adjusting these thresholds, it can be ensured that the system adjusts the access permissions and resource allocation in real time according to the network state;

[0166] S42. Input the trust level T of each node i , adjust the trust level threshold according to the current network environment and resource allocation requirements and perform hierarchical resource allocation:

[0167] High-trust nodes: If Allow the node to access sensitive resources and preferentially allocate high-performance resources;

[0168] Medium-trust nodes: If Allow the node to access ordinary resources and restrict some operation permissions;

[0169] Low-trust nodes: If Restrict the node's access and resume when the trust level value returns to the set threshold.

[0170] In this embodiment, based on the dynamic trust value, the access control threshold is set to achieve reasonable allocation and secure transfer of resources. The efficient resource allocation and access control improve the flexibility and security of network resource management, as well as the implementation of the zero-trust security principle: strictly following the zero-trust security concept of "never trust, always verify", continuously and dynamically evaluating all nodes to prevent potential security threats and enhancing the network's security protection ability.

[0171] Specifically, the present application also provides an electronic device, including: a memory and a processor. The memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the above-mentioned zero-trust network node dynamic trust level evaluation and intelligent resource allocation method.

[0172] Specifically, the present application further provides a computer-readable storage medium storing a computer program, and when the computer program is executed by a processor, the above-mentioned zero-trust network node dynamic trust degree evaluation and intelligent resource allocation method is implemented.

[0173] In summary, the present invention proposes to continuously and dynamically evaluate the node trust degree, requiring network access control to not only rely on user authentication, but also continuously monitor and adjust the trust state based on behavior and real-time context evaluation to meet the needs of a complex and changing environment in real time, thereby achieving efficient trust management and reasonable resource allocation.

[0174] In the description of this specification, the description with reference to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" means that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.

[0175] The logic and / or steps represented in the flowchart or described in other ways herein, for example, can be considered as a definite sequence list of executable instructions for implementing logical functions, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch instructions from the instruction execution system, apparatus, or device and execute the instructions), or in combination with these instruction execution systems, apparatuses, or devices.

[0176] The above embodiments have introduced the present invention in detail. Specific examples are used herein to elaborate on the principles and embodiments of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.

Claims

1. A method for dynamically evaluating the trust level of zero-trust network nodes and intelligent resource allocation, characterized in that It includes the following steps: S1. Collect information of all interaction nodes in a zero-trust network environment; S2. After information collection, perform cleaning processing on the data, including denoising, filling, and normalization; S3. Design a trust degree calculation formula for nodes according to the collected information, and dynamically optimize weight parameters α, β, γ, η, θ1, θ2, θ3 through the node trust degree evaluation layer based on the processed data; S4. Set corresponding trust thresholds according to the trust degree of nodes, perform dynamic trust threshold adjustment in the decision-making layer, and allocate resource hierarchical access control policies.

2. The zero-trust network node dynamic trust degree evaluation and intelligent resource allocation method according to claim 1, characterized in that: In step S1, the information collection of all interaction nodes in the zero-trust network environment specifically includes: interaction success rate I i : the statistical ratio of whether data transmission between nodes is successful; response time R i : the response delay time of communication between nodes; resource consumption rate C i : the bandwidth, CPU, and storage resources consumed during node access or interaction; historical behavior credibility A i : the access history of the node and the detection results of abnormal behaviors.

3. The zero-trust network node dynamic trust degree evaluation and intelligent resource allocation method according to claim 1, characterized in that: In step S1, the information collection of all interaction nodes in the zero-trust network environment further includes environmental authentication information collection: use the device management protocol, timestamp, and IP geographical location parsing to obtain device health status, access time, and geographical location information respectively, and add them to the trust degree evaluation to further strengthen the idea of multi-factor authentication in the zero-trust architecture. Among them, device health status: not only verify the user identity, but also verify whether the device is in a safe state, that is, whether the latest security patches are installed and whether there is malware; access timing and location: evaluate whether it belongs to a normal access mode according to the access timing and location to prevent unauthorized access after stealing the user identity through phishing.

4. The zero-trust network node dynamic trust degree evaluation and intelligent resource allocation method according to claim 1, characterized in that: In step S2, after information collection, perform cleaning processing on the data, including denoising, filling, and normalization. The specific process includes the following steps: S21. Perform denoising processing using wavelet transform, decompose the signal into different frequency domains, and filter out high-frequency noise: Among them, c(m,n) is the wavelet coefficient, m is the scale parameter that controls the stretching degree of the wavelet function and corresponds to different frequency bands in the frequency domain, and n is the translation parameter that determines the position of the wavelet function on the time axis. is the wavelet basis function; S22. Fill in missing values and outliers in the data based on the statistics of similar nodes. First, define the similarity metric: Among them, Node a , Node b represent two network nodes to be compared, and x a,i refers to the eigenvalue of node a in the i-th feature dimension, and x b,i refers to the eigenvalue of node b in the i-th feature dimension; Then, according to the similarity, select the k most similar nodes from high to low, and use the mean value of the similar nodes to fill in the missing values and further correct the outliers: where x j is the j-th of the k most similar nodes, where j ranges from 1 to k; S23. Adopt the Min-max normalization method to normalize all data X i to the same scale range [0, 1], where i = 1, …, k, for better weighted calculation, and obtain the normalized data X i ': where X min , X max correspond to the minimum and maximum values of the respective variables.

5. The zero-trust network node dynamic trust degree evaluation and intelligent resource allocation method according to claim 1, characterized in that: In step S3, the design of the trust degree calculation formula for nodes according to the collected information and the dynamic optimization of weight parameters α, β, γ, η, θ1, θ2, θ3 through the node trust degree evaluation layer based on the processed data include the following steps: S31. Design a trust degree calculation formula for nodes according to the collected information: Among them, σ(·) is a normalization function that normalizes the trust value to the range of [0, 1], T i , I i , R i , C i , A i , E i respectively represent the trust degree, interaction success rate, response time, resource consumption rate, historical behavior credibility and current environmental context variable of the node. The non-linear mapping functions f(I i , R i ), g(C i , A i ) are the relationship functions between the interaction success rate and the response time and the relationship function between the resource consumption rate and the historical behavior respectively. d(E i ) is the dynamic environment factor, and α, β, γ, η are the weight parameters corresponding to each factor; γ is the basic adjustment parameter used to balance the influence of the molecular weight and the environment factor; In addition, the relationship function f(I i ,R i ) between the interaction success rate and the response time is as follows: where θ1, θ2, θ3 are weight coefficients, which are optimized by algorithms; The relationship function g(C i , A i ) between resource consumption rate and historical behavior: g(C i ,A i ) = log(1 + C i )·(1 - A i ); Dynamic environmental factor d(E i ): d(E i ) = α1·H i + α2·M i + α3·G i ; Among them, H i , M i , G i ∈[0,1] are the device health status, access time, and geographical location respectively. α1, α2, and α3 correspond to H i , M i , G i 's weights respectively; S32. Use the particle swarm algorithm to solve the weights α, β, γ, η in the trust degree calculation formula; S33. Use the gradient descent method to solve for the weight parameters θ1, θ2, and θ3 in the relationship function f(I i ,R i ) of the interaction success rate and response time.

6. The zero-trust network node dynamic trust degree evaluation and intelligent resource allocation method according to claim 5, characterized in that: In step S32, the use of the particle swarm algorithm to solve the weights α, β, γ, η in the trust degree calculation formula includes the following steps: S321. Initialize parameters: set the number of particles N, the search range is [0,1], and initialize the weight parameters α, β, γ, η and velocity v of each particle; S322. Design the fitness function evaluation, and use the accuracy of the trust evaluation result and the system security as the fitness evaluation criteria: Fitness(α,β,γ,η)=λ1·Accuracy(α,β,γ,η)-λ2·Risk(α,β,γ,η); Among them, Accuracy(α,β,γ,η) is the trust accuracy calculated based on the optimized weights, Risk(α,β,γ,η) is the security risk of the system, measuring the impact of malicious nodes or attacks, and λ1,λ2 are adjustment coefficients; Risk = ∑(abnormal request rate + failure rate + high-risk behavior frequency); Among them, T i True is the true trust level of node i, and T i pred is the predicted trust level of node i. n is the total number of samples of the number of nodes participating in the evaluation in the validation set; S323. Update the global optimal solution and the local optimal solution S324. Update the particle velocity: Among them, ω is the inertia weight, which controls the tendency of the particle to maintain its original velocity, and c1 and c2 are the cognitive factor and the social coefficient, respectively controlling the influence of individual experience and group experience. is the local optimal solution, is the global optimal solution, x i is the position of the particle, and r1 and r2 are random numbers within the interval [0, 1], which are used to maintain the diversity of the population. Update the particle position: x i+1 = x i + v i+1 ; S325. Output the optimal weight parameters α,β,γ,η when the fitness value meets the accuracy requirement or the upper limit of the number of iterations.

7. The zero-trust network node dynamic trust level evaluation and intelligent resource allocation method according to claim 5, characterized in that: In step S33, the weight parameters θ1, θ2, θ3 in the relationship function f(I i , R i ) for solving the interaction success rate and response time are obtained by using the gradient descent method. The specific process includes the following steps: S331. Collect data: Obtain the historical data of the interaction success rate I i and the response time R i ; S332. Define the objective loss function: Loss=∑|T i True -f(I i ,R i )|; Among them, T i True is the true trust level of node i; S333. Initialize the weight parameters θ1,θ2,θ3 and the learning rate η; S334. Use the gradient descent method to solve and update the weight parameters θ1,θ2,θ3: where θ k is the k-th weight parameter to be optimized, and k ranges from 1 to 3; S334. Output the optimal weight parameters θ1,θ2,θ3 when the loss function converges or reaches the iteration limit.

8. The zero-trust network node dynamic trust degree evaluation and intelligent resource allocation method according to claim 1, characterized in that: In step S4, according to the trust degree of the node, set the corresponding trust threshold, perform dynamic trust threshold adjustment in the decision layer, and allocate the resource hierarchical access control policy. The specific process includes the following steps: S41. Dynamic threshold setting and access control: T threshold = μ·avg(T) + σ·std(T); Among them, μ and σ are the mean and standard deviation of the threshold adjustment respectively, representing the equilibrium state of all nodes in the current network. avg(T) and std(T) are the mean and standard deviation of the trust degree respectively. By dynamically adjusting these thresholds, the system can be ensured to adjust the access rights and resource allocation in real time according to the network state; S42. Input the trust degree T of each node i , adjust the trust degree threshold according to the current network environment and resource allocation requirements and perform hierarchical resource allocation: High-trust nodes: If allow nodes to access sensitive resources and preferentially allocate high-performance resources; Medium-trust nodes: If Allow nodes to access ordinary resources and restrict some operation permissions; Low-trust nodes: If Node access is restricted and restored when the trust value resumes to the set threshold.

9. An electronic device, characterized in that, Including: A memory and a processor, the memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the zero-trust network node dynamic trust degree evaluation and intelligent resource allocation method according to any one of claims 1-8.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores a computer program, and when the computer program is executed by the processor, it implements the zero-trust network node dynamic trust degree evaluation and intelligent resource allocation method according to any one of claims 1-8.

Citation Information

Patent Citations

  • Zero-trust dynamic access control method based on GBDS user credibility evaluation

    CN115549973A

  • Zero-trust security processing method and system for Internet of Things equipment authentication encryption

    CN116248277A

  • Zero-trust dynamic access control method based on flow identification

    CN116582374A

  • Zero-trust gateway-based application resource dynamic control access method

    CN117278329A

  • Zero-trust security access control method

    CN117436097A

Cited By

  • Trust management method, system and device based on multi-core-node dynamic community

    CN120785517A

  • Self-adaptive security policy generation method and system for zero-trust architecture

    CN120915551A

  • A self-adaptive security policy generation method and system for a zero trust architecture

    CN120915551B