Zero-trust dynamic access control method and device based on role attributes and user portraits
By calculating the historical trust value, real-time trust value and user portrait trust value of the access subject, and combining the environmental security value, the permission threshold and permission set are dynamically adjusted, the problem of insufficient static and granularity of the authorization mechanism in the existing access control model is solved, and fine-grained permission management and dynamic response are achieved, improving system security and flexibility.
Patent Information
- Application Number
- CN202510702517.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-28
- Publication Date
- 2025-08-15
AI Technical Summary
When facing the needs of dynamic, security and flexibility, the authorization mechanism is too static and not granular enough, and ignores environmental and behavioral factors, resulting in weak identification and response capabilities for malicious access behavior.
By calculating the historical trust value, real-time trust value and user portrait trust value of the access subject, combined with the environmental security value, the permission threshold and permission set are dynamically adjusted, and fine-grained permission allocation and dynamic adjustment are achieved.
It realizes fine-grained resource management in complex environments, improves system security and flexibility, can detect abnormal access behaviors in a timely manner and dynamically adjust trust values, and improves sensitivity and response speed to malicious behaviors.
Smart Images

Figure CN120498810A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of information security technology, and specifically relates to a zero-trust dynamic access control method and device based on role attributes and user portraits. Background Art
[0002] With the rapid development of the Internet of Things, cloud computing, and artificial intelligence technologies, the scale and complexity of network systems have increased significantly. The frequency of user-resource interactions has increased, and the importance of data and privacy protection has also increased. However, traditional access control models have exposed many shortcomings when faced with the demands of dynamism, security, and flexibility.
[0003] Existing discretionary access control (DAC), mandatory access control (MAC), role-based access control (RBAC), and attribute-based access control (ABAC) all suffer from overly static authorization mechanisms. For example, the RBAC model assigns fixed roles to users, preventing user permissions from dynamically changing based on behavior or trust, leading to the risk of over-authorization or under-authorization.
[0004] Most access control models offer relatively coarse permission management granularity, particularly in complex environments, and are unable to meet the demands of fine-grained resource management. RBAC relies on the granularity of roles, and while ABAC offers a degree of dynamism, it lacks the ability to integrate user behavior analysis.
[0005] Traditional models often ignore the environmental security status and historical behavior patterns of the access subject, such as geographic location, device environment, or operation logs. This leads to weak identification and response capabilities for malicious access behaviors, and a lack of real-time monitoring and dynamic adjustment mechanisms for illegal access behaviors. As a result, users can accumulate trust points or bypass security mechanisms through abnormal operations, posing potential threats to system resources.
[0006] In summary, the existing access control model exposes the problems of overly static authorization mechanism, insufficient granularity, neglect of environment and behavior, and low sensitivity to illegal behavior when facing the needs of dynamism, security and flexibility. Therefore, it is necessary to develop a new zero-trust dynamic access control method and device based on role attributes and user portraits to solve the existing problems. Summary of the Invention
[0007] The purpose of the present invention is to provide a zero-trust dynamic access control method and device based on role attributes and user portraits to solve the above problems.
[0008] To achieve the above objectives, the present invention provides the following technical solution: a zero-trust dynamic access control method based on role attributes and user profiles, comprising:
[0009] Calculate the historical trust value and real-time trust value based on the historical trust mechanism of the access subject, generate a user profile and calculate the user profile trust value to obtain the comprehensive trust value of the access subject;
[0010] By accessing the environment and calculating the environment security value, all permissions for accessing the resource are determined, a permission set is generated, and the permission thresholds of each permission in the permission set are traversed. Permissions with a comprehensive trust value greater than the threshold are retained in the permission set. If the comprehensive trust value is less than the permission threshold, the permission is deleted from the permission set and the permission combination is updated;
[0011] Calculate the authority value and decision value of the authority in the authority set, make a decision, judge the relationship between the comprehensive trust value and the decision value of each authority, and retain the authority with a comprehensive trust value greater than the decision value in the set;
[0012] If the permission set meets the set conditions, the user role is activated and the access operations within the obtained permission set can be performed; otherwise, the access operation fails;
[0013] Record the user's operation behavior during the access process, adjust the upper limit of the trust value based on the access performance, use it as a reference for calculating the historical trust value, and update the permission threshold.
[0014] Preferably, the calculating of the historical trust value according to the historical trust mechanism of the access subject includes:
[0015] When a user first obtains access to a resource, a real-time trust value TD is generated based on the user's real-time behavior. Real-time , the first historical trust value TD at this time history =TD Real-time ;
[0016] When it is not the first visit, TD overall The value of and the historical trust value upper limit p are stored in the historical trust behavior array. The calculation method of the historical trust value is shown in the following formula:
[0017] t[i][1]=λ·min(TD overall , p)
[0018] Among them, λ is the historical behavior control parameter, TD overall It represents the comprehensive trust value of the access subject, and p represents the upper limit of the trust value after punishment, which is used to limit TD overall The value range of
[0019] The rows and columns of the historical trust behavior array of each access subject are set to fixed values n and m;
[0020] Maintain a historical trust behavior array t[n][m] for each access subject;
[0021] Set the historical trust value attenuation coefficient W(u). The formula is as follows:
[0022]
[0023] Where W(u) represents the attenuation coefficient of the historical trust value of the access subject, u represents the subscript of the current array element, v represents the subscript of the last element in the array, and ζ represents an arbitrarily small positive number used to adjust the range of historical trust attenuation;
[0024] The historical trust value of the access subject is obtained by summing the product of the historical trust value elements of the access subject in the historical trust behavior array and the corresponding attenuation coefficient. The calculation method of the attenuated historical trust value is shown in the following formula:
[0025]
[0026] When the historical trust array is full, that is, the number of visits by the access subject reaches the size of the trust value array row number n, the first x elements are weighted averaged and the average is stored at the first position of the array. The positions of the remaining elements are moved forward by x-1 as the historical trust credentials of the access subject.
[0027] Preferably, the calculation of the real-time trust value includes:
[0028] Read the access subject log and access behavior information to obtain the attribute table belonging to the access subject, pre-process the data in the access subject attribute table, and digitize the nominal attribute values in the attribute table; normalize the data; convert the feature values into values in the range of 0 to 1; h represents the basic element in the access subject attribute set, that is, the value of a single attribute, h min and h max are the minimum and maximum values of the attribute, respectively, h new Indicates the latest value of the attribute after normalization. The formula for calculating the attribute value normalization is as follows:
[0029]
[0030] After preprocessing the access subject attribute data, the identity attribute h is obtained i , identity attribute value set H = {h1, h2, ..., h n}, divide the identity attribute set into l classes, l≤n, H≥H1∪H2∪…∪H l , H1={h1,h2,…,h i},…,H l ={h j , h j+1 ,…,hn}, 1≤i<j<n, the calculation formula of the access subject trust component based on logistic regression is as follows:
[0031]
[0032] Among them, z i Represents the i-th attribute category H i The trust weight, h k Represents the i-th attribute category H i The kth attribute value, v i is the trust component calculation process of the i-th attribute classification, a k Indicates h k The corresponding weight, f k Represents classification H i The trust component calculation process of the k-th attribute classification;
[0033] Find l trust components z1, z2, ..., z l Then, the weighted harmonic mean is calculated; where b i For the set H i The formula for the real-time trust value of the access subject is as follows:
[0034]
[0035] Preferably, generating a user profile and calculating a user profile trust value includes:
[0036] Extract effective features from the access subject's past behavior and attributes to generate user profiles, and analyze user behavior patterns and characteristics to assess their trustworthiness;
[0037] Each dimension of the user portrait corresponds to a behavior evaluation factor θ and a weight w. The behavior evaluation factor θ has three evaluation values:
[0038]
[0039] The behavioral evaluation factor for each dimension of the user portrait is determined based on the degree of deviation between the current behavioral data and the historical behavioral data. For each dimension of the user portrait, the historical data within a certain time range is recorded.
[0040] T={t1,t2,t3,...,t n-1}
[0041] Among them, T is the historical set of login time of the generated access subject, symbol t i Indicates the login time;
[0042] Normalize the current user login deviation t:
[0043]
[0044] Among them, t′ is the standardized t, μ is the average value of the login duration, and σ is the standard deviation of the login duration;
[0045] Set a general upper limit Δt1 and a maximum upper limit Δt2 for the deviation degree. If t′ ≤ Δt1, it is considered that the deviation degree between the current behavior and the historical behavior is small, and the corresponding behavior evaluation factor is set to 1;
[0046] If Δt1 < t′ ≤ Δt2, the deviation degree between the current behavior and the historical behavior is within the set range, and the corresponding behavior evaluation factor is set to 0.5;
[0047] If t′ > Δt2, the deviation between the current behavior and the historical behavior is too large, and the corresponding behavior evaluation factor is set to 0;
[0048] Add the behavior evaluation factors of each dimension of the user profile according to the weight ratio to generate the user's behavior trust value TD portrait :
[0049]
[0050] Among them, n is the dimension of the behavior characteristics, θ i is the behavior evaluation factor of each dimension of the user profile, and w i is the weight of each dimension of the user profile;
[0051] The calculation formula for the dynamically updated user profile trust value is as follows:
[0052]
[0053] Among them, represents the user profile trust value of the current cycle, γ is the cycle behavior factor, indicating the offset of the user's behavior in the current cycle from the behavior habit in the previous cycle, and γ ∈ [0, 1].
[0054] Preferably, the obtaining of the comprehensive trust value of the access subject includes:
[0055] The calculation formula for the comprehensive trust value TD overall is as follows:
[0056] TD overall = εTD history + ηTD portrait [[ID=5�]]+ ξTD Real-time
[0057] Among them, ε represents the weight of the historical trust value, ξ represents the weight of the real-time trust value, and η represents the weight of the user profile trust value.
[0058] Preferably, calculating the environmental security value by accessing the environment includes:
[0059] Environmental safety value PE includes: geographical location safety, equipment environment safety;
[0060] The calculation formula for the geographical location safety EV is as follows:
[0061]
[0062] Where D is the weight factor of the geographical location security, which is determined by the frequency of network security issues at the geographical location. t is the time interval between the last visit and the current visit. pv is the total number of visits within time t. f is the frequency of geographical location changes within time t. tm is the number of historical visits to the location.
[0063] The calculation formula for the equipment environment safety degree DE is as follows:
[0064]
[0065] Where d represents the weight factor of historical security, v represents the historical average update frequency of the device, and y represents the update frequency of the device. The parameter representing the update frequency of the historical security score, e represents the weight factor of the security configuration factor, and UF represents the security configuration factor of the device;
[0066] The calculation formula for the device's security configuration factor UF is as follows:
[0067]
[0068] Where n represents the number of device security configuration factors, c i represents the score of the i-th security configuration factor, max(c1, c2, ..., c n ) represents the maximum value of all security configuration factor scores;
[0069] The calculation formula of environmental safety value is as follows:
[0070] PE=EV+DE
[0071] The authority thresholds include:
[0072] The trust value is divided into several equal continuous intervals, and the endpoint values of each interval are recorded as Q = {q1, q2, ..., q m},q m Represents the permission threshold, and this set is the initial trust threshold. The interval of each interval is represented by D. Then, 2k intervals are set for each initial threshold, which are recorded as Set a marker value for each interval Where i∈{[-k,k],Z}, k is an integer parameter used to control the number of intervals divided around the initial permission threshold, and i is the interval index, indicating the relative position of a specific interval; The initial value is 0. hour, The value is increased by 1; another cumulative access count S is set to indicate that the threshold is modified once after S accesses without dangerous operations. The dynamic adjustment algorithm of the permission threshold is shown in the following formula. After the adjustment, the new permission threshold is saved in the array:
[0073]
[0074] q′ m Indicates the new permission threshold after adjustment;
[0075] Generating the permission set includes: the permission set X is represented by the following formula:
[0076] X={x1,x2,...,x n}
[0077] Among them, x1,x2,...,x n Represents each permission in the permission set, and n represents the number of permissions;
[0078] The permission set is dynamically updated based on the real-time status of the comprehensive trust value and the permission threshold. i The corresponding threshold is q m , for each permission x in X i , the update rule formula is as follows:
[0079]
[0080] Among them, X′ is the updated permission set, x′ i is the i-th permission in the set, o∈[0,n].
[0081] Preferably, the calculation of permission values and decision values for the permissions in the permission set and the decision-making judgment include:
[0082] Calculate the permission value PN, use the midpoint of each permission threshold interval of the set X′ to represent the permission value PN and save it to the permission value set Q:
[0083] Q={q′1, q′2,..., q′ o}
[0084] q′ i The midpoint of the permission threshold interval of the i-th permission in the set is used to represent the permission value PN;
[0085] The decision value P is calculated based on the environmental safety value PE and the authority value PN. The formula is as follows:
[0086]
[0087] Among them, PE represents the environmental security value, PN represents the permission value for applying for a certain permission, and w1 and w2 represent weight parameters respectively;
[0088] The relationship between the comprehensive trust value and the decision value of each authority is determined, and the authority with a comprehensive trust value greater than the decision value is retained in the set;
[0089] If you judge TD overall The value of is higher than the decision value generated by the access subject's application. The user role is activated through the access subject's application, and the user role is granted permissions that are less than or equal to the permission value.
[0090] Preferably, if the permission set meets the set conditions, activating the user role includes:
[0091] If the permission set is not empty, the access subject will be granted at least one permission; otherwise, it will not be able to access.
[0092] Preferably, recording the user's operational behavior during the access process, adjusting the upper limit of the trust value according to the access performance, using it as a reference for calculating the historical trust value, and updating the threshold of the authority include:
[0093] Update the permission threshold. When the access subject accesses for the first time, the initial permission threshold G is calculated based on the access subject's identity type and the security of the device and environment. The formula is as follows;
[0094] G=f(U,PE)
[0095] Where f() is the threshold adjustment policy function, U is the user identity type, and PE is the environmental security value;
[0096] Check the subject's historical trust behavior array and use the upper limit of the trust value in the last row of the array as the new initial value;
[0097] Record user operations and use the penalty mechanism to adjust the upper limit of the trust value. When an illegal operation is detected, the upper limit of the trust value is calculated and set through the penalty function, and the value is recorded in the array t[n][2]. The penalty function is as follows:
[0098]
[0099] Among them, p represents the upper limit of the new trust value of the access subject, p′ represents the upper limit of the trust value of the current access subject's target permission; C represents the penalty coefficient, which ranges from 0 to 1; R represents the number of levels contained in the illegal operation, n represents the number of illegal operations that occurred, and r i Indicates the severity of the i-th illegal operation;
[0100] If no illegal behavior occurs, the upper limit of the trust value gradually increases, but always remains below the initial value. The growth rate of the upper limit of the trust value increases with the number of consecutive times n without illegal behavior, but the growth rate will gradually slow down. The function is as follows:
[0101]
[0102] Where a is the decay rate, a∈[0,1], φ is the penalty reduction factor, t is the time variable, and n is the number of consecutive times no violation occurs within t time.
[0103] The present invention further provides a zero-trust dynamic access control device based on role attributes and user profiles, comprising:
[0104] Trust server, used to calculate the user's historical trust value, real-time trust value and user profile trust value, and generate a comprehensive trust value;
[0105] The permission server is used to dynamically adjust the permission threshold and maintain the permission set;
[0106] A decision server is used to calculate a decision value based on an environmental security value and an authority value;
[0107] Behavioral analysis server, used to generate user profiles and evaluate behavioral patterns;
[0108] Audit server, used to record user operation behavior and calculate environmental security value.
[0109] The technical effects and advantages of the present invention are as follows: The zero-trust dynamic access control method and device based on role attributes and user portraits, by introducing user portraits and environmental security value elements, introduces user portraits and environmental security values on the basis of the traditional ABAC model, and realizes fine-grained and high flexibility of permission allocation through dynamic trust evaluation. This application is used for dynamic adjustment and precise management of resource access rights in complex environments, combined with the dynamic adjustment mechanism of trust values, to achieve fine-grained control and dynamic allocation of access rights; the trust server comprehensively evaluates the user's historical trust value, real-time trust value and user portrait trust value, and calculates the decision value according to the permission threshold and environmental security value to dynamically adjust the user's permissions; simulation experiments show that this application is superior to traditional access control models in terms of dynamic permission allocation, illegal access prevention and permission escape control, and can effectively improve the security and flexibility of the system; by introducing user portraits and environmental security values, combined with the dynamic adjustment mechanism of trust values, real-time dynamic management of user permissions is achieved. , avoiding the static problem of the traditional model authorization mechanism; through the dynamic comparison of the comprehensive trust value and the permission threshold, it can adjust the permission set in real time according to the changes in user behavior, thereby realizing the refinement of permission allocation and meeting the needs of resource management in complex environments; using the audit server to record the user's operation log and environmental parameters, combined with the dynamic trust evaluation system, it can timely detect abnormal access behavior, and dynamically adjust the user's trust value upper limit through the penalty mechanism, thereby improving the system's sensitivity and response speed to malicious behavior; through the evaluation of geographic location security and equipment environment security, the model can comprehensively consider the user's access environment, restrict high-risk environments, and improve the overall security of access control; using the penalty mechanism, it can dynamically adjust the trust value upper limit, and implement strict real-time response and punishment strategies according to the user's behavior pattern, which not only effectively limits the threat of malicious behavior to system resources, but also gradually restores the trust value when there is no violation, thereby balancing security and user experience. BRIEF DESCRIPTION OF THE DRAWINGS
[0110] Figure 1 Schematic diagram of the access control process of the present invention;
[0111] Figure 2 It is a structural schematic diagram of the device of the present invention;
[0112] Figure 3 A relationship diagram showing the influence of illegal behavior and upper limit of trust value in the method of the present invention;
[0113] Figure 4 A graph showing the relationship between the continuous absence of illegal behavior and the upper limit of the trust value according to the method of the present invention;
[0114] Figure 5 A comparison chart of the permissions and trust values of different access devices according to the method of the present invention;
[0115] Figure 6A comparison chart of the authority and trust values of the method of the present invention and other models;
[0116] Figure 7 A comparison chart of the permission adjustment time during illegal operations using the method of the present invention and other models;
[0117] Figure 8 A comparison chart of the permission escape rates of the method of the present invention and other models during illegal operations; DETAILED DESCRIPTION
[0118] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0119] The present invention provides Figure 2 A zero-trust dynamic access control device based on role attributes and user profiles, as shown in FIG, includes:
[0120] It consists of trust server, authority server, decision server, behavior analysis server, and audit server;
[0121] The trust server is the "core" of the dynamic trust evaluation system. When an access subject makes an access, the trust server will calculate a comprehensive trust value for it based on its historical trust value, real-time trust value, and user profile trust value, and assign it a role based on the access subject's comprehensive trust value and permission set.
[0122] The permission server dynamically adjusts permission thresholds, updates permission sets, calculates permission values, maintains role lists, and generates resource decision trees.
[0123] The decision server calculates the decision value based on the access subject's permission value and environmental security value, and determines whether the access subject's application is approved based on the corresponding relationship between the comprehensive trust value of the access subject's role and the decision value.
[0124] The behavior analysis server analyzes the user's behavior operations, measures the degree of deviation between the access subject's historical behavior and current behavior, generates a user profile, and calculates the user profile trust value through the trust server; it is used to generate user profiles and evaluate behavior patterns.
[0125] The audit server is responsible for recording and storing all access requests and access decision results. It collects information about geographic location, access device environment, etc. for auditing and analysis, calculates environmental security values, and saves them in a secure storage system for subsequent decision-making.
[0126] The present invention further provides Figure 1 、 Figure 3 、 Figure 4 、 Figure 5 、 Figure 6 、 Figure 7 、 Figure 8 A zero-trust dynamic access control method based on role attributes and user profiles, as shown in , includes:
[0127] S01. When an access subject initiates an access request to an IoT resource, the model calculates the historical trust value and real-time trust value based on the access subject's historical trust mechanism, generates a user profile, and calculates the user profile trust value to obtain the access subject's comprehensive trust value.
[0128] S02. The model calculates the environmental security value based on the user's access environment, determines all permissions involved in accessing the resource, generates a permission set, completes initialization, and traverses the permission thresholds of each permission in the permission set. Permissions with a comprehensive trust value greater than the threshold are retained in the set. If the comprehensive trust value is less than the threshold of a certain permission, the permission is deleted from the set and the permission set is updated.
[0129] S03. Calculate the authority value and decision value for the authority in the set, make a decision, and judge the relationship between the comprehensive trust value and the decision value of each authority. Keep the authority with a comprehensive trust value greater than the decision value in the set;
[0130] S04, if If the user role is activated, the user can perform the access operations within the permission set obtained. Otherwise, the user access operation fails.
[0131] S05. The model records the user's operational behavior throughout the entire access process, adjusts the upper limit of the trust value based on the access performance, uses it as a reference for calculating the historical trust value, and updates the permission threshold;
[0132] S01 includes the following steps:
[0133] S011. First, calculate the historical trust value. When a user first obtains access to a resource, the trust calculation model will generate a real-time trust value TD based on the user's real-time behavior. Real-time , the first historical trust value TD at this time history =TD Real-time When it is not the first visit, after each visit, the TD overall The value of and the historical trust value upper limit p are stored in the historical trust behavior array. The following is the calculation method of the historical trust value:
[0134] t[i][1]=λ·min(TD overall ,p))(1)
[0135] Among them, λ is the historical behavior control parameter, TD overall It represents the comprehensive trust value of the access subject, and p represents the upper limit of the trust value after punishment, which is used to limit TD overall The value range of
[0136] To save resources on the trust server, the rows and columns of each access subject's historical trust behavior array are set to fixed values n and m. The trust server maintains a historical trust behavior array t[n][m] for each access subject. t[n][1], i.e., the first column of the array, records the trust value calculated by the model after the access subject's historical application for access. t[n][2], i.e., the second column of the array, records the access subject's single historical behavior parameters, using the format of "historical trust value upper limit / penalty record". In the penalty record, if there is a penalty record, it is recorded as 1, and if there is no penalty record, it is recorded as 0. t[n][3], i.e., the access environment parameters of the access subject in the third column of the array.
[0137] In access control systems, there are cases where users maliciously gain trust points. Once these malicious users obtain sufficiently high trust points, they may exploit these trust points to conduct malicious access. Such behavior will pose a greater security threat and risk to the resources within the system. To avoid this, the historical trust value decay coefficient W(u) is introduced to reduce the impact of historical access data on current access. The specific formula is as follows:
[0138]
[0139] Among them, W(u) is the attenuation coefficient of the access subject's historical trust value, u is the current array element index, v is the last element index of the array, and ζ is an arbitrarily small positive number used to adjust the range of historical trust attenuation. The weight of the user's historical trust will decrease with the increase in the number of visits.
[0140] The historical trust value of the access subject is obtained by summing the product of the historical trust value elements of the access subject in the historical trust behavior array and the corresponding attenuation coefficient. Formula (3) is the calculation method of the attenuated historical trust value:
[0141]
[0142] When the trust value shows a continuous downward trend, it indicates that the access subject may have the intention to violate the law. In this case, if the normal record of the trust value cannot provide protection, the trust value should be quickly reduced to avoid security risks. If the historical trust array contains k consecutive elements with a downward trend, the specific value of k is determined by experts. The values of these k consecutive elements in the array are replaced with the minimum value among them, providing a reliable reference for the calculation of the trust value.
[0143] When the historical trust array is filled, that is, the number of visits by the access subject reaches the size of the trust value array row number n, since the earlier the access record, the lower the effectiveness, the array will take a weighted average of the first x elements and store the average at the first position of the array. The positions of the remaining elements are moved forward by x-1 as the historical trust credentials of the access subject.
[0144] S012. Calculate the real-time trust value. When the access subject accesses the model, the trust server obtains the attribute table of the access subject by reading the access subject log, access behavior and other information, which contains various types of information about the access subject. When calculating the access subject trust value, first pre-process the data in the access subject attribute table and digitize the nominal attribute values in the attribute table. Since the value ranges of the attributes in the access subject attribute table are different, features with larger values will reduce the role of features with smaller values in the calculation process. Therefore, it is necessary to normalize the data and convert the feature values into values within the range of 0 to 1. h represents the basic element in the access subject attribute set - the value of a single attribute, h min and h max are the minimum and maximum values of the attribute, respectively, h new Indicates the latest value of the attribute after standardization. The formula is the attribute value standardization calculation method:
[0145]
[0146] After preprocessing the access subject attribute data, the identity attribute h is obtained i , identity attribute value set H = {h1, h2, ..., h n}, first divide the identity attribute set into l classes, l≤n, H≥H1∪H2∪…∪H l , H1={h1,h2,…,h i},…,H l ={h j , h j+1 ,…,h n}, 1≤i<j<n, the calculation method of the access subject trust component based on logistic regression is shown in the formula:
[0147]
[0148] Among them, z i Represents the i-th attribute category H i The trust weight, h k Represents the i-th attribute category H i The kth attribute value, v i is the trust component calculation process of the i-th attribute classification, a k Indicates h k The corresponding weight, f k Represents classification Hi The trust component calculation process of the k-th attribute classification;
[0149] Find l trust components z1, z2, ..., z l Then, the weighted harmonic mean is calculated; where b i For the set H i The calculation method of the real-time trust value of the access subject is as shown in the formula:
[0150]
[0151] S013 calculates the user portrait trust value. The behavior analysis server can extract effective features from the past behavior and attributes of the access subject to generate a user portrait. The user portrait trust value is calculated by the trust server, and its trustworthiness is evaluated by analyzing the user's behavior pattern and characteristics. The abnormality and security of the user's behavior and attribute characteristics are analyzed based on the user's previous behavior habits, and abnormal users and abnormal behaviors of users are dynamically identified. Different from the historical trust value, the user portrait extracts the characteristics of the user's historical behavior, and focuses more on analyzing the degree of deviation between the user's current behavior and historical behavior. It can determine whether the user's current behavior is abnormal compared with the previous behavior; the user portrait contains information such as the login behavior, network behavior, operation behavior and other behaviors of the access subject; the login behavior records the login method, login time, login duration, login device, login IP and other data of the access subject. The network behavior records the upstream and downstream traffic, TCP connection density and other data of the access subject; the operation behavior records the name of the resource visited, historical operations and other data;
[0152] Each dimension of the user portrait corresponds to a behavior evaluation factor θ and a weight w. The behavior evaluation factor θ has three evaluation values:
[0153]
[0154] The behavioral evaluation factor for each dimension of the user portrait is determined based on the degree of deviation between the current behavioral data and the historical behavioral data. For each dimension of the user portrait, the historical data within a certain time range is recorded.
[0155] T={t1,t2,t3,...,t n-1} (8)
[0156] Among them, T is the historical set of login time of the generated access subject, symbol t i Indicates the login time;
[0157] Normalize the current user login deviation t:
[0158]
[0159] Where t′ is the standardized t, μ is the mean login time, and σ is the standard deviation of login time;
[0160] Set a general upper limit Δt1 and a maximum upper limit Δt2 for the degree of deviation. If t′≤Δt1, it is considered that the deviation between the current behavior and the historical behavior is small, and the corresponding behavior evaluation factor is set to 1. If Δt1<t′≤Δt2, the deviation between the current behavior and the historical behavior is within a certain range, and the corresponding behavior evaluation factor is set to 0.5. If t′>Δt2, the deviation between the current behavior and the historical behavior is too large, and the corresponding behavior evaluation factor is set to 0;
[0161] Add the behavioral evaluation factors of each dimension of the user portrait according to the weight ratio to generate the user's behavioral trust value TD portrait :
[0162]
[0163] Among them, n is the dimension of behavioral characteristics, θ i is the behavioral evaluation factor for each dimension of user portrait, w i The weight of each dimension of the user portrait;
[0164] The trust value of a user profile will constantly change. Access subjects usually have multiple access behaviors. The following formula is the dynamically updated user profile trust value formula:
[0165]
[0166] in, is the user portrait trust value of the current cycle, γ is the cycle behavior factor, which represents the offset between the user’s behavior in the current cycle and the behavior habits in the previous cycle, γ∈[0,1].
[0167] S014. Calculate the comprehensive trust value. The set of permissions that the access subject can execute and whether the access can be successful are determined by the comprehensive trust value. The comprehensive trust value TD overall The calculation method is shown in the formula:
[0168] TD overall =εTD history +ηTD portrait +ξTD Real-time (12)
[0169] Among them, ε is the weight of the historical trust value, ξ is the weight of the real-time trust value, and η is the weight of the user portrait trust value.
[0170] S02 includes the following steps:
[0171] S021. Calculate the environmental security value. The environmental security value PE consists of two parts: geographic location security and device environment security. The geographic location security EV compares the security of the current access subject's location with the areas frequently visited before, while the device environment security compares the security of the device currently used with the devices frequently used before to determine whether the security status of the currently visited area and device has changed compared to before. The calculation method of geographic location security EV is shown as follows:
[0172]
[0173] Where D is the weight factor of the geographic location security, which is determined by the frequency of network security issues at that geographic location. t is the time interval between the last visit and the current visit. pv is the total number of visits within time t. f represents the frequency of geographic location changes within time t. tm represents the number of historical visits to that location.
[0174] The calculation method of equipment environment safety degree DE is shown as follows:
[0175]
[0176] Among them, d is the weight factor of historical security, v represents the historical average update frequency of the device, and y represents the update frequency of the device. It is the adjustment parameter for the update frequency of the historical security score, the weight factor of the e security configuration factor, and UF is the security configuration factor of the device, which indicates whether the security configuration of the device is reasonable.
[0177] The calculation method for the device's security configuration factor UF is as follows:
[0178]
[0179] Where n is the number of device security configuration factors, c i is the score of the i-th security configuration factor. The higher the score, the safer the configuration. max(c1, c2, ..., c n ) represents the maximum value of all security configuration factor scores;
[0180] The following formula is the calculation formula for the environmental safety value:
[0181] PE=EV+DE(16)
[0182] S022. Calculate the authority threshold, authority threshold q mIt is calculated by the permission server and represents the minimum trust value required to obtain permission in the system. The setting of the permission threshold is very critical. Too high or too low a threshold may cause problems with system security and stability. The trust value is divided into several equal continuous intervals, and the endpoint values of each interval are recorded as Q = {q1, q2, ..., q m}, this set is the initial trust threshold, the interval of each interval is represented by D, and then 2k intervals are set for each initial threshold, recorded as Set a marker value for each interval Where i∈{[-k, k], Z}, k is an integer parameter used to control the number of intervals divided around the initial permission threshold, and i is the interval index, indicating the relative position of a specific interval; The initial value is 0. hour, The value increases by 1. In addition, a cumulative access count S is set to indicate that the threshold is modified once after S accesses without dangerous operations. The value of S is set together with the initial permission threshold at the system initialization. The following formula gives the dynamic adjustment algorithm for the permission threshold. After adjustment, the new permission threshold is saved in the array:
[0183]
[0184] q m It represents the new permission threshold after adjustment. The algorithm adjusts the permission threshold appropriately according to the distribution of the access subject's trust value. During the adjustment process, if the access subject's trust value is too low, it should be regarded as a dangerous operation. The trust value of all dangerous operations obtained by the trust algorithm is 0. The access subject with too high trust value can directly obtain the low threshold permission. Therefore, only the subject trust value in q is considered. m Non-dangerous operations and legal operations that are denied within a certain range nearby.
[0185] S023. Generate a permission set. The permission set X represents the set of all available permissions granted to the access subject in a specific environment. It is a set consisting of a series of permissions. Each permission represents a specific operation that the access subject can perform or the ability to access resources. The permission set is represented as follows:
[0186] X={x1,x2,...,x n} (17)
[0187] Among them, x1, x2, ..., x n are the individual permissions in the permission set, and n is the number of permissions.
[0188] The permission set is dynamically updated based on the real-time status of the comprehensive trust value and the permission threshold. i The corresponding threshold is qm , for each permission x in X i , the update rules are as follows:
[0189]
[0190] Among them, X′ is the updated permission set, x′ i is the i-th permission in the set, o∈[0,n].
[0191] S03 includes the following steps:
[0192] S031. Calculate the permission value PN as a reference for decision making. Use the midpoint of each permission threshold interval of the set X′ to represent the permission value PN and save it to the permission value set Q:
[0193] Q={q′1, q′2,..., q′ o} (19)
[0194] q′ i The midpoint of the permission threshold interval of the i-th permission in the set is used to represent the permission value PN.
[0195] S032. Calculate the decision value P. This value is generated by the decision server and is calculated from the environmental security value PE and the permission value PN. It represents the reference value for the final decision on whether to approve or reject the access request, and is used to comprehensively evaluate the security of the permission application for a specific resource.
[0196] The formula is as follows:
[0197]
[0198] Among them, PE represents the environmental safety value, PN represents the permission value for applying for a certain permission, w1 and w2 are weight parameters, representing the weights of the environmental safety value and the permission value, respectively, which are used to adjust the impact of each factor on the comprehensive evaluation;
[0199] S033. Determine the relationship between the comprehensive trust value and the decision value of each authority, and retain the authority whose comprehensive trust value is greater than the decision value in the set;
[0200] If the model determines TD overall The value of is higher than the decision value generated by the access subject's application. The user role is activated through the access subject's application, and the user role is granted permissions that are less than or equal to the permission value.
[0201] S04 includes the following steps:
[0202] As long as the permission set is not empty, the access subject will be granted at least one permission, otherwise, it will not be able to access.
[0203] S05 includes the following steps:
[0204] S051. Update the permission threshold. When the access subject accesses the model for the first time, the initial permission threshold is calculated based on the access subject's identity type and the device and environment security. Here, the environmental security value PE is used to measure the device and environment security.
[0205] G=f(U,PE)(27)
[0206] Among them, f() is the threshold adjustment strategy function. The specific adjustment strategy is given by experts according to the actual situation. U is the user identity type and PE is the environmental security value.
[0207] S052. In subsequent visits, the trust server checks the subject's historical trust behavior array and uses the trust value upper limit of the last row of the array as the new initial value; as the system runs and events occur, if malicious behavior continues to occur, the system will gradually lower the node's trust value upper limit; conversely, if no malicious behavior occurs, the system may gradually increase the node's trust value upper limit; however, the higher the trust level of the user, the greater the harm caused to the object resource by malicious access. In order to prevent this from happening, the node's trust value upper limit is set not to exceed its initial original value.
[0208] S053. Record user operations and use the penalty mechanism to adjust the upper limit of the trust value. When an illegal operation is detected, the upper limit of the trust value is calculated and set through the penalty function, and the value is recorded in the array t[n][2]. The penalty function is as follows:
[0209]
[0210] Among them, p is the upper limit of the new trust value of the access subject, and p′ represents the upper limit of the trust of the current access subject's target permission. C is the penalty coefficient, which represents the system's penalty for illegal operations. The value range is between 0 and 1. The greater the penalty, the greater the value of C. Illegal operations are divided into 5 levels from low to high: lowest, lower, medium, higher, and highest. R represents the number of levels of illegal operations, n is the number of illegal operations that occurred, and r i is the severity of the i-th illegal operation.
[0211] If no illegal behavior occurs, the upper limit of the trust value gradually increases to indicate that the punishment is weakened, but it always remains below the initial value. The growth rate of the upper limit of the trust value should increase with the number of consecutive times n without any violation, but the growth rate will gradually slow down. The function is as follows:
[0212]
[0213] Where a is the decay rate, a∈[0,1], φ is the penalty reduction factor, t is the time variable, and n is the number of consecutive times no violation occurs within t time.
[0214] Finally, it should be noted that the above is only a preferred embodiment of the present invention and is not intended to limit the present invention. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art can still modify the technical solutions described in the aforementioned embodiments or make equivalent substitutions for some of the technical features therein. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the scope of protection of the present invention.
Claims
1. A zero-trust dynamic access control method based on role attributes and user profiles, characterized by: include: Calculate the historical trust value and real-time trust value based on the historical trust mechanism of the access subject, generate a user profile and calculate the user profile trust value to obtain the comprehensive trust value of the access subject; By accessing the environment and calculating the environment security value, we can determine all permissions for accessing the resource, generate a permission set, and traverse the permission thresholds of each permission in the permission set. Calculate the permission value and decision value of the permissions in the permission set and make decisions; If the permission set meets the set conditions, the user role is activated; Record the user's operation behavior during the access process, adjust the upper limit of the trust value based on the access performance, use it as a reference for calculating the historical trust value, and update the permission threshold.
2. A zero-trust dynamic access control method based on role attributes and user profiles according to claim 1, characterized in that: The calculation of the historical trust value according to the historical trust mechanism of the access subject includes: When a user first obtains access to a resource, a real-time trust value TD is generated based on the user's real-time behavior. Real-time , the first historical trust value TD at this time history =TD Real-time ; When it is not the first visit, TD overall The value of and the historical trust value upper limit p are stored in the historical trust behavior array. The calculation method of the historical trust value array t is shown in the following formula: t[i][1]=λ·min(TD overall ,p) Among them, λ is the historical behavior control parameter, TD overall It represents the comprehensive trust value of the access subject, and p represents the upper limit of the trust value after punishment, which is used to limit TD overall The value range of The rows and columns of the historical trust behavior array of each access subject are set to fixed values n and m; Maintain a historical trust behavior array t[n][m] for each access subject; Set the historical trust value attenuation coefficient W(u). The formula is as follows: Where W(u) represents the attenuation coefficient of the historical trust value of the access subject, u represents the subscript of the current array element, v represents the subscript of the last element in the array, and ζ represents an arbitrarily small positive number used to adjust the range of historical trust attenuation; The historical trust value of the access subject is obtained by summing the product of the historical trust value elements of the access subject in the historical trust behavior array and the corresponding attenuation coefficient. The calculation method of the attenuated historical trust value is shown in the following formula: When the historical trust array is full, that is, the number of visits by the access subject reaches the size of the trust value array row number n, the first x elements are weighted averaged and the average is stored at the first position of the array. The positions of the remaining elements are moved forward by x-1 as the historical trust credentials of the access subject.
3. A zero-trust dynamic access control method based on role attributes and user profiles according to claim 2, characterized in that: The calculation of the real-time trust value includes: Read the access subject log and access behavior information to obtain the attribute table belonging to the access subject, pre-process the data in the access subject attribute table, and digitize the nominal attribute values in the attribute table; normalize the data; convert the feature values into values in the range of 0 to 1; h represents the basic element in the access subject attribute set, that is, the value of a single attribute, h min and h max are the minimum and maximum values of the attribute, respectively, h new Indicates the latest value of the attribute after normalization. The formula for calculating the attribute value normalization is as follows: After preprocessing the access subject attribute data, the identity attribute h is obtained i , identity attribute value set H = {h1, h2, ..., h n }, divide the identity attribute set into l classes, l≤n, H≥H1∪H2∪…∪H l , H1={h1,h2,…,h i },…,H l ={h j , h j+1 ,…,h n }, 1≤i<j<n, the calculation formula of the access subject trust component based on logistic regression is as follows: Among them, z i Represents the i-th attribute category H i The trust weight, h k Represents the i-th attribute category H i The kth attribute value, v i is the trust component calculation process of the i-th attribute classification, a k Indicates h k The corresponding weight, f k Represents classification H i The trust component calculation process of the k-th attribute classification; Find l trust components z1, z2, ..., z l Then, the weighted harmonic mean is calculated; where b i For the set H i The formula for the real-time trust value of the access subject is as follows:
4. A zero-trust dynamic access control method based on role attributes and user profiles according to claim 3, characterized in that: Generating a user profile and calculating a user profile trust value includes: Extract effective features from the access subject's past behavior and attributes to generate user profiles, and analyze user behavior patterns and characteristics to assess their trustworthiness; Each dimension of the user portrait corresponds to a behavior evaluation factor θ and a weight w. The behavior evaluation factor θ has three evaluation values: The behavioral evaluation factor for each dimension of the user portrait is determined based on the degree of deviation between the current behavioral data and the historical behavioral data. For each dimension of the user portrait, the historical data within a certain time range is recorded. T={t1,t2,t3,...,t n-1 } Among them, T is the historical set of login time of the generated access subject, symbol t i Indicates the login time; Normalize the current user login deviation t: Where t′ is the standardized t, μ is the mean login time, and σ is the standard deviation of login time; Set a general upper limit Δt1 and a maximum upper limit Δt2 for the degree of deviation. If t′≤Δt1, it is considered that the degree of deviation between the current behavior and the historical behavior is small, and the corresponding behavior evaluation factor is set to 1; If Δt1<t′≤Δt1, the deviation between the current behavior and the historical behavior is within the set range, and the corresponding behavior evaluation factor is set to 0.5; If t′>Δt2, the current behavior deviates too much from the historical behavior, and the corresponding behavior evaluation factor is set to 0; Add the behavioral evaluation factors of each dimension of the user portrait according to the weight ratio to generate the user's behavioral trust value TD portrait : Among them, n is the dimension of behavioral characteristics, θ i is the behavioral evaluation factor for each dimension of user portrait, w i The weight of each dimension of the user portrait; The formula for calculating the dynamically updated user profile trust value is as follows: in, represents the trust value of the user portrait in the current cycle, γ is the cycle behavior factor, which represents the offset between the user's behavior in the current cycle and the behavioral habits in the previous cycle, γ∈[0,1].
5. A zero-trust dynamic access control method based on role attributes and user profiles according to claim 4, characterized in that: The comprehensive trust value of the access subject includes: Comprehensive trust value TD overall The calculation formula is as follows: TD overall =εTD history +ηTD portrait +ξTD Real-time Among them, ε represents the weight of the historical trust value, ξ represents the weight of the real-time trust value, and η represents the weight of the user portrait trust value.
6. The zero-trust dynamic access control method based on role attributes and user profiles according to claim 1 is characterized by: Calculating the environment security value by accessing the environment includes: Environmental safety value PE includes: geographical location safety, equipment environment safety; The calculation formula for the geographical location safety EV is as follows: Where D is the weight factor of the geographical location security, which is determined by the frequency of network security issues at the geographical location. t is the time interval between the last visit and the current visit. pv is the total number of visits within time t. f is the frequency of geographical location changes within time t. tm is the number of historical visits to the location. The calculation formula for the equipment environment safety degree DE is as follows: Where d represents the weight factor of historical security, v represents the historical average update frequency of the device, and y represents the current update frequency of the device. The parameter that controls the update frequency of the historical security score, e represents the weight factor of the security configuration factor, and UF represents the security configuration factor of the device. The calculation formula for the device's security configuration factor UF is as follows: Where n represents the number of device security configuration factors, c i represents the score of the i-th security configuration factor, max(c1, c2, ..., c n ) represents the maximum value of all security configuration factor scores; The calculation formula of environmental safety value is as follows: PE=EV+DE The authority thresholds include: The trust value is divided into several equal continuous intervals, and the endpoint values of each interval are recorded as Q = {q1, q2, ..., q m },q m Represents the permission threshold, and this set is the initial trust threshold. The interval of each interval is represented by D. Then, 2k intervals are set for each initial threshold, which are recorded as Set a marker value for each interval Where i∈{[-k, k], Z}, k is an integer parameter used to control the number of intervals divided around the initial permission threshold, and i is the interval index, indicating the relative position of a specific interval; The initial value is 0. hour, The value is increased by 1; another cumulative access count S is set to indicate that the threshold is modified once after S accesses without dangerous operations. The dynamic adjustment algorithm of the permission threshold is shown in the following formula. After the adjustment, the new permission threshold is saved in the array: q′ m Indicates the new permission threshold after adjustment; Generating the permission set includes: the permission set X is represented by the following formula: X={x1,x2,...,x n } Among them, x1, x2, ..., x n Represents each permission in the permission set, and n represents the number of permissions; The permission set is dynamically updated based on the real-time status of the comprehensive trust value and the permission threshold. i The corresponding threshold is q m , for each permission x in X i , the update rule formula is as follows: Among them, X′ is the updated permission set, x′ i is the i-th permission in the set, o∈[0,n].
7. The zero-trust dynamic access control method based on role attributes and user profiles according to claim 1 is characterized by: The calculation of the permission value and the decision value for the permissions in the permission set and the decision-making judgment include: Calculate the permission value PN, use the midpoint of each permission threshold interval of the set X′ to represent the permission value PN and save it to the permission value set Q: Q={q′1,q′2,...,q′ o } q′ i The midpoint of the permission threshold interval of the i-th permission in the set is used to represent the permission value PN; The decision value P is calculated based on the environmental safety value PE and the authority value PN. The formula is as follows: Among them, PE represents the environmental security value, PN represents the permission value for applying for a certain permission, and w1 and w2 represent weight parameters respectively; The relationship between the comprehensive trust value and the decision value of each authority is determined, and the authority with a comprehensive trust value greater than the decision value is retained in the set; If you judge TD overall The value of is higher than the decision value generated by the access subject's application. The user role is activated through the access subject's application, and the user role is granted permissions that are less than or equal to the permission value.
8. The zero-trust dynamic access control method based on role attributes and user profiles according to claim 1 is characterized by: If the permission set meets the set conditions, activating the user role includes: If the permission set is not empty, the access subject will be granted at least one permission; otherwise, it will not be able to access.
9. The zero-trust dynamic access control method based on role attributes and user profiles according to claim 1 is characterized by: The recording of the user's operation behavior during the access process, adjusting the upper limit of the trust value based on the access performance, using it as a reference for calculating the historical trust value, and updating the threshold of the permission include: Update the permission threshold. When the access subject accesses for the first time, the initial permission threshold G is calculated based on the access subject's identity type and the security of the device and environment. The formula is as follows; G=f(U,PE) Where f() is the threshold adjustment policy function, U is the user identity type, and PE is the environmental security value; Check the subject's historical trust behavior array and use the upper limit of the trust value in the last row of the array as the new initial value; Record user operations and use the penalty mechanism to adjust the upper limit of the trust value. When an illegal operation is detected, the upper limit of the trust value is calculated and set through the penalty function, and the value is recorded in the array t[n][2]. The penalty function is as follows: Among them, p represents the upper limit of the new trust value of the access subject, p represents the upper limit of the trust value of the current access subject's target permission; C represents the penalty coefficient, which ranges from 0 to 1; R represents the number of levels contained in the illegal operation, n represents the number of illegal operations that occurred, and r i Indicates the severity of the i-th illegal operation; If no illegal behavior occurs, the upper limit of the trust value gradually increases, but always remains below the initial value. The growth rate of the upper limit of the trust value increases with the number of consecutive times n without illegal behavior, but the growth rate will gradually slow down. The function is as follows: Where a is the decay rate, a∈[0,1], φ is the penalty reduction factor, t is the time variable, and n is the number of consecutive times no violation occurs within t time.
10. A zero-trust dynamic access control device based on role attributes and user portraits, characterized by: include: Trust server, used to calculate the user's historical trust value, real-time trust value and user profile trust value, and generate a comprehensive trust value; The permission server is used to dynamically adjust the permission threshold and maintain the permission set; A decision server is used to calculate a decision value based on an environmental security value and an authority value; Behavioral analysis server, used to generate user profiles and evaluate behavioral patterns; Audit server, used to record user operation behavior and calculate environmental security value.