An evolvable game-based optimization trusted cloud level calculation system and method

By using a game-theoretic optimization approach, antagonistic pairs in cloud services are identified, adversarial gradients are calculated, and weights are redistributed. This solves the problems of dynamic adaptability and foresight in existing technologies for trustworthy cloud level assessment, and achieves optimized allocation of security resources and stability of assessment results.

CN121644230BActive Publication Date: 2026-06-26WUHAN TRUSTED CLOUD TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
WUHAN TRUSTED CLOUD TECH CO LTD
Filing Date
2026-01-29
Publication Date
2026-06-26

AI Technical Summary

Technical Problem

Existing trusted cloud rating assessment methods fail to reflect the dynamic security status of cloud services, lack the ability to predict future security risk trends, and lack a systematic and adaptive weight evolution framework, resulting in assessment results that are out of sync with the actual security situation.

Method used

A game-theoretic optimization approach is adopted to obtain static and dynamic weight vectors, identify antagonistic pairs, calculate adversarial gradients, redistribute weights and perform sensitivity projection, establish policy combinations, and generate a trust level improvement path.

Benefits of technology

It enables optimized allocation of security resources for cloud services, enhances the dynamic adaptability and foresight of assessments, provides clear potential for level upgrades, and ensures the stability and implementability of security strategies.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121644230B_ABST
    Figure CN121644230B_ABST
Patent Text Reader

Abstract

The application relates to the technical field of computer system evaluation, and particularly discloses an evolvable and reliable cloud level calculation system and method based on game optimization; the method comprises the following steps: in the first stage, a pair comparison matrix is established based on the theory of trusted computing dependency tree and the analytic hierarchy process to generate a static weight vector; in the second stage, multi-source threat data is collected through an AI model, a double comparison matrix is constructed through double-dimension labeling classification, and a dynamic weight vector is output; through game theory, an antagonistic pair of core security mechanisms is identified, an antagonistic gradient and the dynamic weight vector are calculated, a weight convergence interval and a level promotion upper bound are predicted, and an optimal weight evolution path is generated; the system is used for realizing an evolvable and reliable cloud level calculation method based on game optimization; and the application is favorable for improving the adaptability and predictability of cloud security evaluation and providing a decision basis for cloud service security optimization.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of computer system evaluation technology, and specifically to an evolvable trustworthy cloud rating system and method based on game-theoretic optimization. Background Technology

[0002] With the widespread adoption and in-depth application of cloud computing technology, the security and trustworthiness of cloud services have become core considerations for users when choosing cloud service providers. Trusted cloud rating, as a key indicator for measuring the overall security level of cloud services, directly relates to the effectiveness of security strategies and the rationality of resource allocation through the scientific validity and accuracy of its calculation method.

[0003] In existing technologies for trusted cloud level assessment, a typical approach is a static assessment model based on expert knowledge. This model establishes an assessment system based on core security elements such as trusted computing infrastructure, access control, and auditing mechanisms, and assigns fixed weights to each. The determination of these weights relies heavily on expert experience, leading to a disconnect between the assessment results and real-time security posture, failing to reflect the true and dynamic security status of cloud services.

[0004] Another type of improvement attempt to introduce dynamic indicators, adjusting some evaluation parameters by collecting real-time data such as vulnerability information and attack logs. However, dynamic adjustment is often limited to local parameters and lacks a framework for systematically and adaptively evolving the weights of core security mechanisms from a system-wide perspective. Secondly, existing methods usually focus on passively responding to threats that have already occurred, lacking the ability to predict future security risk trends and, based on this prediction, to proactively plan the path for improving trust levels.

[0005] Therefore, this invention provides an evolvable trustworthy cloud rating system and method based on game theory optimization. Summary of the Invention

[0006] The purpose of this invention is to provide an evolvable, game-theoretic optimization-based trusted cloud rating system and method to address the aforementioned background problems.

[0007] The objective of this invention can be achieved through the following technical solutions:

[0008] An evolvable, game-theoretic optimization-based method for calculating the trust level of a cloud platform includes the following steps:

[0009] Obtain the execution strategy formulated by the Trusted Cloud Level Management Unit, extract the weight transformation samples of all core security mechanisms under the trigger of the strategy, identify the antagonistic pairs of the weight transformation samples, and extract the local offset features and adversarial benefit features of each antagonistic pair;

[0010] The adversarial gradient of the antagonistic pair is calculated based on the local offset and adversarial gain features, and the dynamic weight vector is reconstructed based on the adversarial gradient.

[0011] Based on dynamic weight vectors and local offset samples, weight redistribution sensitivity projection is performed, and the output weight convergence interval and corresponding confidence level can improve the upper bound.

[0012] Establish a strategy combination, perform a feasibility evaluation on the strategy combination based on the weight convergence interval, determine the weight evolution path based on the evaluation results, and extract the optimal weight vector based on the weight evolution path.

[0013] An evolvable, game-theoretic optimization-based trusted cloud computing system includes the following modules:

[0014] Feature extraction module: Based on the execution strategy formulated by the Trusted Cloud Level Management Unit, extract weight transformation samples of all core security mechanisms triggered by the strategy, identify antagonistic pairs of weight transformation samples, and extract local offset features and adversarial benefit features of each antagonistic pair;

[0015] Vector Reconstruction Module: Calculates the adversarial gradient of antagonistic pairs based on local offset and adversarial gain features, and reconstructs dynamic weight vectors based on the adversarial gradient;

[0016] Convergence analysis module: Based on dynamic weight vector and local offset samples, perform weight redistribution sensitivity projection, output weight convergence interval and corresponding confidence level, which can improve the upper bound.

[0017] The optimal selection module is used to establish a strategy combination, perform a feasibility evaluation on the strategy combination based on the weight convergence interval, determine the weight evolution path based on the evaluation results, and extract the optimal weight vector based on the weight evolution path.

[0018] The beneficial effects of this invention are:

[0019] The first phase, based on trusted computing dependency tree theory and the analytic hierarchy process (AHP), generates static weight vectors driven by expert knowledge, providing an evaluation benchmark that conforms to the inherent security architecture of cloud services. The second phase introduces an AI model to perform natural language parsing and labeling of unstructured threat intelligence from multiple sources, constructing a dual strategic and tactical comparison matrix to generate dynamic weight vectors that respond to real-time threat environments. This fusion of static and dynamic weights helps the trusted cloud level assessment retain the stability based on security theory while possessing dynamic adaptability to changes in the external threat landscape.

[0020] By monitoring weight transformation samples after strategy execution, the system can automatically identify antagonistic pairs that exhibit significant negative correlations among core security mechanisms. This helps reflect the inherent trade-offs when prioritizing security resources are limited. Calculating the adversarial gradient by analyzing the local offset and adversarial benefit characteristics of each antagonistic pair quantifies the intensity and direction of dynamic competition. Gradient information provides data-driven support for weight redistribution, facilitating the system's ability to balance competing security mechanisms and optimize security resource allocation.

[0021] A sensitive projection model for weight redistribution is constructed. Taking static weights, dynamic weights, and historical offset samples as input, the model predicts a weight convergence interval for each core security mechanism by simulating the uncertainties in future weight change paths. This facilitates a shift in trust level management from passive response to proactive planning. Based on the interval and the pre-defined weight-level mapping relationship, the upper bound of trust level improvement for each mechanism and the entire cloud service is quantified. This provides cloud service providers with clear and quantifiable potential for trust level improvement, enhancing the foresight and predictability of their security efforts.

[0022] A large number of candidate strategy combinations are generated through discrete sampling, and their feasibility is assessed. The assessment includes calculating the benefit-cost ratio of each combination and adjusting the risk premium of strategies related to high-conflict mechanisms based on dynamic conflict intensity weights, thereby generating a strategy priority sequence. The system uses gradient descent to plan a multi-step adjustment scheme from the current weight to the target weight, which helps reduce system oscillations or strategy conflicts caused by sudden weight changes, achieving stability in the safe strategy adjustment process and feasibility in actual operation. Attached Figure Description

[0023] The invention will now be further described with reference to the accompanying drawings.

[0024] Figure 1 This is a flowchart of an evolvable, game-theoretic optimization-based trusted cloud rating calculation method according to the present invention;

[0025] Figure 2 This is a flowchart of the continuous evolution analysis performed in this invention;

[0026] Figure 3 This is a functional block diagram of an evolvable, game-theoretic optimization-based trusted cloud rating calculation system in this invention. Detailed Implementation

[0027] The technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of the present invention.

[0028] Example 1: Please refer to Figure 1 As shown, this invention is an evolvable, game-theoretic optimization-based method for calculating the trust level of a cloud, comprising a first stage and a second stage:

[0029] S1. The first-stage cloud service provider establishes a pairwise comparison matrix and outputs a weight vector based on the trusted computing dependency tree theory.

[0030] Among them, the cloud service provider uses the trusted computing dependency tree theory to establish a pairwise comparison matrix to calculate the quantized weight value as follows:

[0031] In some embodiments, the Trusted Computing Dependency Tree (TCDT) theory includes five core security mechanisms: Trusted Computing Dependency Root (TCDR), Trusted Computing Dependency Knowledge (TCDKN), Trusted Computing Dependency Isolation (TCDIS), Access Control (AC), and Authentication Audit (CA).

[0032] It should be noted that the trusted computing dependency root is the hardware or software component that is unconditionally trusted in the cloud service system startup chain.

[0033] Trusted computing relies on knowledge, which is the benchmark value for trust measurement in cloud service systems, such as a list of known software hash values;

[0034] Trusted computing dependency isolation is a mechanism for isolating computing resources in different security domains within a cloud service system.

[0035] Access control refers to the mechanism by which users or processes have access permissions to resources in a cloud service system.

[0036] Authentication auditing is a mechanism that verifies user identity and records system activity to provide traceability;

[0037] Based on the 1-9 scale rule of the Analytic Hierarchy Process (AHP), professionals in this field assign values ​​to the relative importance of the five core security mechanisms in pairs, and establish a pairwise comparison matrix.

[0038] It should be noted that a scale of "1" indicates that the two mechanisms are equally important; a scale of "9" indicates that one mechanism is absolutely more important than the other; for example, if a person skilled in the art considers the TCDIS mechanism to be "significantly important" relative to the TCDAC mechanism, then a value of 5 will be assigned to the corresponding position in the pairwise comparison matrix.

[0039] The pairwise comparison matrix is ​​standardized, and the consistency is checked based on the standardized pairwise comparison matrix to obtain the consistency ratio.

[0040] The consistency ratio is compared with a preset consistency ratio threshold. If the consistency ratio is lower than or equal to the preset consistency ratio threshold, it indicates that the pairwise comparison matrix has the expected consistency, and a weight vector W is established.

[0041] If the consistency ratio is higher than the preset consistency ratio threshold, it indicates that there is a logical contradiction in the pairwise comparison matrix. The cloud service system will prompt professionals in this field to re-examine the core security mechanism and reassign values ​​until the expected consistency is achieved.

[0042] It should be noted that the weight vector W contains five elements, each corresponding to a weight value for one of the five core security mechanisms, and the sum of all weight values ​​is 1. For example, the calculated weight vector is: ;

[0043] In some embodiments, a level vector representing the current security level in the current cloud server system is obtained through the Trusted Cloud Level Calculation Framework;

[0044] The level vector and weight vector are summed to output the weight vector of the current cloud server system.

[0045] S2. In the second stage, an AI model is built to obtain threat analysis data from cloud services. The AI ​​model is used to parse the threat analysis data and perform labeling and classification. Based on the classification results, a dual comparison matrix is ​​dynamically established, and a two-dimensional dynamic weight vector is output.

[0046] The method for building AI models and obtaining threat analysis data from cloud services through natural language processing algorithms is as follows:

[0047] S201. Set the data source to obtain threat analysis data;

[0048] Preferably, unstructured security intelligence is automatically ingested through global data sources, including: vulnerability databases (NISTNVD), security bulletins on GitHub (an open-source community platform), and threat analysis data obtained from public network security communities;

[0049] It should be noted that threat analysis data includes: vulnerability reports, technical attack logs, etc.

[0050] S202. Construct an AI model to perform two-dimensional labeling and classification of threat analysis data;

[0051] The threat analysis data is processed by building an AI (artificial intelligence) model using natural language algorithms and combined with the knowledge graph of TCDT (Trusted Computing Dependency Tree Theory) to perform two-dimensional tagging and classification on each piece of unstructured threat intelligence.

[0052] The two-dimensional labeling classification includes functional domain classification and technical domain classification.

[0053] It should be noted that the functional domain classification is based on the TCDCSM (Trusted Cloud Dependent Computing Security Mechanism) framework, mapping threat intelligence to one of the five core security mechanisms. For example, if a vulnerability report about virtual machine escape describes an attack whose ultimate goal is to compromise the isolation mechanism, then the vulnerability report will be classified under the TCDIS (Trusted Computing Dependent Isolation) tag.

[0054] Based on the IS (Technology Area) classification system, threat intelligence is mapped to one of the four major technology areas, including virtualization (IS.Virt), networking (IS.Net), storage (IS.Storage), and computing (IS.Compute). For example, if the same vulnerability report shows an attack that occurs at the virtualization layer, it will be classified under the IS.Virt tag.

[0055] The dual comparison matrix includes a strategic comparison matrix and a tactical comparison matrix.

[0056] S203. Based on threat analysis data with dual-dimensional labeling classification, a strategic comparison matrix and a tactical comparison matrix are dynamically established to realize the establishment of dual comparison matrices and perform dynamic weight processing to obtain a dual-dimensional dynamic weight vector.

[0057] Among them, based on threat analysis data with dual-dimensional labeling classification, a strategic comparison matrix and a tactical comparison matrix are dynamically established. The method for establishing the dual comparison matrix and performing dynamic weight calculation is as follows:

[0058] In some embodiments, the system uses a dynamic AHP matrix to quantify threat intelligence under each functional domain label (corresponding to the five core security mechanisms) and technical domain label (corresponding to the four technical fields);

[0059] The quantitative indicators include: threat frequency (F), severity coefficient (S), and trend coefficient (T).

[0060] It should be noted that threat frequency refers to the number of similar threat events occurring per unit of time; the severity coefficient is based on a standardized score mapping to the 0-10 range using the Common Vulnerability Scoring System (CVSS); and the trend coefficient is obtained by calculating the average of the recent threat quantity growth rate over a sliding window.

[0061] The dynamic AHP matrix generation unit algorithm assigns weights to different quantitative indicators, such as threat frequency weights. Set the severity coefficient weight to 0.5. Set the trend coefficient weight to 0.3. Set the value to 0.2, and use the weighted summation formula ( Calculate the overall threat value for each tag, and automatically generate two orthogonal judgment matrices based on the overall threat value:

[0062] Strategic Judgment Matrix: Based on five core security mechanisms, a 5x5 matrix is ​​constructed, with matrix elements... The value is determined through a comparison mechanism. With mechanism The overall threat value ratio is assigned according to the 1-9 scale rule of AHP. For example, if the overall threat value of TCDIS is 3 times that of TCDAC, and the ratio falls into the preset slightly important range, then the corresponding matrix element is assigned the value 3.

[0063] Tactical Judgment Matrix: Construct a 4x4 matrix with four technical fields as rows and columns. Matrix elements. The value is determined through a comparison mechanism. With mechanism The overall threat value ratio is calculated and assigned a value according to the 1-9 scale rule of AHP, and is generated based on the overall threat value comparison results of different technical fields;

[0064] Calculate the eigenvectors: For each judgment matrix (strategic judgment matrix, tactical judgment matrix), calculate the maximum eigenvalue and the corresponding eigenvector, and normalize the eigenvectors to obtain the strategic weight vector and tactical weight vector respectively.

[0065] Calculate the consistency ratio of each matrix. If the consistency ratio is lower than or equal to a preset threshold (e.g., 0.1), the matrix is ​​considered to have the expected consistency, and the output weight vector is valid.

[0066] If the consistency ratio exceeds the limit, the system will automatically log and use the last valid weight vector, while triggering an alarm signal to prompt that the data source needs to be checked.

[0067] For example, a strategic weight vector, such as:

[0068] }

[0069] Tactical weight vector, for example:

[0070] {IS.Virt:0.5,IS.Net:0.15,IS.Storage:0.25,IS.Compute:0.1};

[0071] If the matrix has the expected consistency, the strategic weight vector (e.g., TCDIS:0.4) and tactical weight vector (e.g., IS.Virt:0.5) are output by solving the eigenvector corresponding to the largest eigenvalue and normalizing it.

[0072] S3. The Trusted Cloud Level Management Unit performs decision deduction on the weight vectors output from the first and second stages, formulates the execution strategy for cloud services, and conducts continuous evolution analysis.

[0073] Preferably, the Trusted Cloud Level Management Unit performs decision deduction on the weight vectors output from the first and second stages to formulate the cloud service execution strategy in the following way:

[0074] The Trusted Cloud Level Management Unit (TCDMU) receives the static weight vector generated in the first phase based on expert knowledge:

[0075] W={TCDIS:0.417,TCDAC:0.265,TCDR:0.105,TCDKN:0.055,CA:0.158};

[0076] And the second phase uses AI-generated two-dimensional weight vectors (including strategic weights such as {TCDIS:0.4, TCDAC:0.3, TCDR:0.15, CA:0.1, TCDKN:0.05} and tactical weights such as {IS.Virt:0.5%, IS.Net:0.15, IS.Storage:0.25, IS.Compute:0.1}).

[0077] By determining resource allocation priorities through macro-strategic decision-making simulations (e.g., prioritizing the allocation of approximately 40% of the security budget to upgrade the isolation mechanism level), and by refining technical implementation paths through micro-tactical decision-making simulations (e.g., prioritizing the deployment of critical applications migrating from ordinary VMs to TCDIS4 confidential VMs based on the high-risk weight of virtualization layer 0.5), hierarchical and categorized executable cloud service security optimization strategies are generated.

[0078] Example 2: Please refer to Figure 2 As shown, this invention is an evolvable, game-theoretic optimization-based method for calculating the trust level of a cloud, wherein S3 performs continuous evolutionary analysis and includes the following steps:

[0079] S4. Based on the execution strategy formulated by the Trusted Cloud Level Management Unit, extract the weight transformation samples of all core security mechanisms under the policy trigger, identify the antagonistic pairs of weight transformation samples, and extract the local offset features and adversarial benefit features of each antagonistic pair.

[0080] Among them, the method for extracting weight transformation samples of all core security mechanisms triggered by the execution strategy formulated by the Trusted Cloud Level Management Unit is as follows:

[0081] In some embodiments, after executing the policy, the Trusted Cloud Level Management Unit (TCDMU) continuously monitors and records the strategic weight vector dynamically generated by the second-stage AI model to form a weight transformation sample set.

[0082] The weight transformation sample set includes a baseline weight vector and N time-series weight vectors.

[0083] It should be noted that the strategic weight vector of the last stable state before the policy is triggered is marked as the baseline weight vector. The strategic weight vectors collected over N consecutive monitoring periods (e.g., every minute or every hour) after the strategy is triggered are labeled as a time-series weight vector sequence. , , This refers to the numbering of time series points within the monitoring period. The time point representing the first monitoring period, The time point representing the Nth monitoring cycle;

[0084] Preferably, N≥30 to meet the statistical significance requirement;

[0085] The method for identifying antagonistic pairs of weight-transformed samples is as follows:

[0086] In some embodiments, the cloud service system analyzes the weight transformation sample set based on game theory principles to identify antagonistic pairs between core security mechanisms;

[0087] It should be noted that antagonistic pairs refer to two core security mechanisms that exhibit a significant negative correlation and competition in dynamic weight changes. That is, the increase in the weight of one mechanism is often accompanied by the decrease in the weight of the other mechanism, reflecting the inherent trade-off of cloud service systems in dynamically scheduling security priorities under limited resources.

[0088] The cloud service system iterates through all core security mechanism pairs (such as TCDIS-AC, TCDR-CA, etc.), and for each mechanism pair ( The extraction mechanism extracts the weight value sequence at N time points ( ;

[0089] By calculating the sliding window Pearson correlation coefficient of the weight value sequence (the window size can be set to 5 to 10 periods), if the average value of the correlation coefficient is less than the preset negative threshold (such as -0.6), the mechanism pair is determined to be a significant antagonistic pair.

[0090] Preferably, the average correlation coefficient for each antagonistic pair , as the basic measure of its antagonistic strength;

[0091] The method for determining the local offset features and adversarial gain features for each identified antagonistic pair under the output policy trigger is as follows:

[0092] In some embodiments, for each identified antagonistic pair (i,j), the cloud service system calculates local offset features and adversarial gain features to quantify the adversarial dynamics triggered by the strategy:

[0093] The local offset feature is calculated using the weighted offset equation: Calculate the absolute weight offset of core security mechanisms i and j from the baseline weight to the last time point (tN). , ;

[0094] Through the formula: The net offset is calculated. ;

[0095] Net offset As a local offset feature;

[0096] It should be noted that, Positive values ​​indicate a shift in the game towards a direction favorable to core security mechanism i, while negative values ​​indicate a shift towards a direction favorable to mechanism j. The absolute value represents the intensity of the offset;

[0097] Based on the dynamic assessment in the second phase, the average comprehensive threat value of core security mechanisms i and j in the current threat environment is obtained. and ;

[0098] The payoff values ​​of core security mechanisms i and j are calculated by constructing a system of payoff equations. and ;

[0099] Preferably, the method for constructing the system of benefit equations is as follows: ;

[0100] Through the formula: Calculate the benefit values ​​of core security mechanisms i and j and The difference in returns ;

[0101] Use the difference in returns as a characteristic of counter-returns;

[0102] It should be noted that, if A value greater than 0 indicates that, from a global security perspective, weight rebalancing is generally beneficial; conversely, there is room for optimization.

[0103] S5. Calculate the adversarial gradient of the antagonistic pair based on the local offset and adversarial gain features, and reconstruct the dynamic weight vector based on the adversarial gradient.

[0104] The adversarial gradient of the antagonistic pair is calculated based on local offset and adversarial gain characteristics as follows:

[0105] In some embodiments, the cloud service system maintains M sliding time windows (e.g., window size K = 10 monitoring periods) and stores the net offset of M sliding time window antagonistic pairs (i,j). and the difference in returns ;

[0106] Preferably, M=50;

[0107] Construct a difference in payoffs for M sliding time window antagonistic pairs (i,j). Profit difference sequence and net offset The offset sequence;

[0108] Calculate the variance of the offset sequence across all sliding windows. variance of the difference in returns series ;

[0109] calculate and variance The sum of the variances The ratio of the variance to the total variance is used to calculate the offset weight. The ratio of the total value to the total value is used to calculate the revenue weight;

[0110] It should be noted that features with larger variance indicate more drastic recent changes and are given higher weight in gradient calculation; for example, if the antagonistic pair of isolation mechanisms (TCDIS) and access control (AC) has recently changed significantly, then the features with larger variance will be given higher weight in gradient calculation. For 0.08 If the value is 0.02, then the offset weight = 0.8 and the benefit = 0.2, and the gradient calculation naturally biases towards local offset features;

[0111] The net offset of the Mth sliding window The product of the corresponding offset weights is used to calculate the difference in revenue for the Mth sliding window. Multiply the product with the corresponding reward weight, then sum the results of the two multiplications to obtain the adversarial gradient. ;

[0112] The method for constructing the weight vector of the dynamic conflict intensity of each antagonistic pair based on the adversarial gradient is as follows:

[0113] In some embodiments, the cloud service system first calculates the absolute conflict strength of each antagonistic pair (i,j). ;

[0114] in Indicates adversarial gradient The absolute value of the gradient direction information is converted into a pure non-negative intensity value. The magnitude of the value reflects the intensity of the dynamic competition between the antagonists in the current situation.

[0115] For each core security mechanism i (i.e., TCDR, TCDKN, TCDIS, AC, CA), aggregate the conflict strengths of all relevant antagonistic pairs to obtain the total conflict strength of a single core security mechanism. ;

[0116] For example, the total conflict intensity is obtained. The method is as follows: The calculation formula is as follows: , where j iterates through all mechanisms that have an antagonistic relationship with the core security mechanism i; if a mechanism does not participate in any antagonistic pair, then Set to a preset minimum value (e.g., 1e-6) to reduce division by zero errors;

[0117] For all core security mechanisms The total conflict intensity is obtained by summing the results. ;

[0118] For each core security mechanism i, calculate the weight component of core security mechanism i in the dynamic conflict intensity weight vector (i.e., calculate the total conflict intensity). Total value of conflict intensity The proportion of ( ) is normalized;

[0119] Based on the weight components of the core security mechanism i in the dynamic conflict intensity weight vector, the dynamic conflict intensity weight vector is established: , a weight vector used to reflect the overall conflict intensity of the current mechanisms in antagonistic interactions;

[0120] For example, suppose the system currently has two antagonistic pairs: TCDIS-AC (where | |=0.7) and TCDR-CA (its | If |=0.4), then:

[0121] TCDIS conflict intensity =0.7 (antagonistic only to AC);

[0122] AC conflict intensity =0.7 (antagonistic to TCDIS);

[0123] TCDR conflict intensity =0.4 (antagonistic to CA);

[0124] CA Conflict Intensity =0.4 (antagonistic to TCDR);

[0125] TCDKN conflict intensity =0 (no antagonistic pair);

[0126] The total conflict intensity S = 0.7 + 0.7 + 0.4 + 0.4 + 0 = 2.2; after normalization, the dynamic weight vector is:

[0127] Finally, all weights are fine-tuned so that the total weights are 1.

[0128] Example 3: Please refer to Figure 2 As shown, this invention provides an evolvable, game-theoretic optimization-based method for calculating the trust level of a cloud, which further includes the following steps:

[0129] S6. Based on dynamic weight vector and local offset samples, perform weight redistribution sensitivity projection, output weight convergence interval and corresponding confidence level, which can improve the upper bound.

[0130] The weight vector generated in the first stage is marked as a static weight vector;

[0131] A sensitive projection model for weight redistribution is constructed based on the time series prediction algorithm (ARIMA model) and the Monte Carlo simulation algorithm. The static weight vector generated in the first stage, the dynamic weight vector generated in the second stage, and the local offset sample set are used as inputs to the sensitive projection model, and the weight convergence interval is output.

[0132] Preferably, the method for constructing the sensitivity projection model is as follows:

[0133] S601. Construct a historical weight sequence based on the input of the sensitivity projection model;

[0134] Preferably, the projection model constructs a historical weight sequence for each core security mechanism i, which is composed of three parts: the static weight values ​​in the static weight vector serve as the baseline starting point;

[0135] The sequence of weight values ​​of the core security mechanism i from the N temporal weight vectors extracted in S4;

[0136] The dynamic weight values ​​in the dynamic weight vector serve as reference points for the current dynamic weights;

[0137] S602. Based on the historical weight sequence, the ARIMA model is used to fit the weight of each mechanism and predict the weight base trajectory for the next P periods.

[0138] S603. Based on the weighted basic trajectory, the Monte Carlo simulation method is used to introduce a random disturbance term to simulate the uncertainty in the weight redistribution process and output the weight convergence interval.

[0139] It should be noted that the variance of the random disturbance term is determined by the variance of the net offset calculated in S4 and the weight components of the core security mechanism i in the dynamic weight vector:

[0140] The cloud service system performs Z Monte Carlo simulations (e.g., Z=1000 times), each simulation generating a weight change path for the next P periods; statistical distribution analysis is performed on the weight values ​​of all Z simulation results at each future time point t, and the quantile interval with a confidence level of 95% is taken as the weight fluctuation range at that time point t.

[0141] Preferably, the weight convergence interval is the steady-state region of the weight fluctuation range within the next P cycles; that is, the lower limit of the weight fluctuation range in the last Q cycles (e.g., Q=5 cycles) is taken as the lower limit of the acceptable weight interval, and the upper limit of the upper limit is taken as the upper limit of the acceptable weight interval; thus, the acceptable weight interval of each core security mechanism i is obtained, i.e., the weight convergence interval.

[0142] S604. Based on the weight convergence interval, construct the weight-level mapping relationship to determine the upper bound of the confidence level.

[0143] For example, the weight-rank mapping relationship can be constructed as follows:

[0144] Trust Level 1: The weight of core security mechanism i is ≥ ( That is, a mechanism weight of 0.1 is sufficient to meet the minimum requirements for Level 1.

[0145] Trust Level 2: The weight of core security mechanism i is ≥ ( =0.12, meaning that to upgrade from level 1 to level 2, the weight needs to increase by at least 0.02).

[0146] Trust Level 3: The weight of core security mechanism i is ≥ ( That is, to upgrade from level 2 to level 3, the weight needs to increase by at least 0.02).

[0147] Trust Level 4: The weight of core security mechanism i is ≥ ( =0.16, meaning that to upgrade from level 3 to level 4, the weight needs to increase by at least 0.02).

[0148] Trust Level 5: The weight of core security mechanism i is ≥ ( =0.18, meaning that to upgrade from level 4 to level 5, the weight needs to increase by at least 0.02).

[0149] It should be further explained that the above The minimum weight increment for level upgrade (i.e., the weight difference between adjacent levels) is uniformly set to 0.02, which is obtained through historical threat data statistics to achieve the universality of the mapping relationship;

[0150] The way to increase the upper bound by predicting and outputting the corresponding confidence level is as follows:

[0151] For each core security mechanism i, the upper bound of its trust level improvement is calculated as follows:

[0152] Calculate the difference between the current weight and the upper limit of the acceptable weight range. ;

[0153] Based on the weight-rank mapping relationship, calculate Maximum number of level increases supported The upper limit that can be increased in credibility level. ;

[0154] Preferred, ,in This is the floor function;

[0155] For example, if the current weight of the TCDIS mechanism is 0.40, the upper limit of the acceptable weight range is 0.48. =0.02, then =0.08, =4, indicating that the trust level of the TCDIS mechanism has the potential to be improved by a maximum of 4 levels;

[0156] Preferably, the minimum value among the escalable upper bounds of all core security mechanisms of the cloud service system is taken as the overall trust level escalation upper bound of the entire cloud service system, which is used to ensure the robustness of the level escalation scheme.

[0157] S7. Establish a strategy combination, perform a feasibility evaluation on the strategy combination based on the weight convergence interval, determine the weight evolution path based on the evaluation results, and extract the optimal weight vector based on the weight evolution path.

[0158] The strategy combination is established as follows: the strategy combination refers to the scheme of assigning different weight values ​​to the core security mechanism, and each scheme satisfies the constraints of each mechanism in the weight convergence interval determined in S6.

[0159] The cloud service system generates a candidate strategy combination set through discrete sampling: for each core security mechanism i, K weight values ​​are sampled at a fixed step size (e.g., 0.01) within the weight convergence interval, and invalid combinations with all weight values ​​not equal to 1 are excluded to form a candidate strategy combination set. Each strategy combination is a five-dimensional weight vector, which corresponds to the five core security mechanisms.

[0160] The method for evaluating the feasibility of strategy combinations based on the weight convergence interval is as follows:

[0161] Obtain the resource consumption required for the cloud service system to implement each strategy combination, as well as the current trust level value;

[0162] Based on the weight-level mapping relationship in S6, each strategy combination is mapped to a trust level value;

[0163] Calculate the difference between the current trust level value and the existing trust level value to obtain the trust benefit value;

[0164] The resource consumption value and the credible benefit value are dimensionless, and the ratio of the credible benefit value to the resource consumption value for each strategy combination is calculated to obtain the benefit-cost ratio.

[0165] The strategy combinations are sorted in descending order of their benefit-cost ratio; the higher the benefit-cost ratio, the greater the level improvement brought by the unit of resource input.

[0166] Based on the dynamic conflict intensity weight vector in S5, risk premium adjustment is performed on strategy portfolios involving high conflict intensity mechanisms to generate an adjusted strategy priority sequence.

[0167] The method for outputting the final weight evolution path is as follows:

[0168] In some embodiments, the cloud service system generates a weight evolution path based on a policy priority sequence and using a progressive optimization approach.

[0169] It should be noted that the weight evolution path is a time-series weight adjustment plan that reflects a smooth transition from the current weight vector to the target weight vector.

[0170] The specific generation method is as follows:

[0171] Select the top P policy combinations (e.g., P=3) from the policy priority sequence as the phase objectives; for each phase objective, use gradient descent to determine the optimal transition path:

[0172] With the goal of minimizing adjustment costs and maximizing transition stability, a multi-step adjustment scheme for calculating the current weights to the target weights under constraints is constructed.

[0173] The weight change in each adjustment step must satisfy the following constraints:

[0174] Constraint 1: The single-step weight change is less than or equal to the preset maximum allowable change threshold;

[0175] Constraint 2: The direction of weight change in adjacent steps remains consistent;

[0176] Generate a weight evolution path with T time points based on a multi-step adjustment scheme. ,in As the current weight, The final target weight;

[0177] For example, the evolution path is as follows: in the first week, the focus is on increasing the TCDIS weight (from 0.40 to 0.45), and in the second week, the AC and CA weights are adjusted simultaneously (AC from 0.25 to 0.23, CA from 0.15 to 0.17), gradually approaching the target vector;

[0178] The recommended weight vector is output in the following way:

[0179] In some embodiments, the cloud service system base policy priority sequence constructs an optimal weight vector based on the final target weight.

[0180] Example 4: Please refer to Figure 3 As shown, this invention is an evolvable, game-theoretic optimization-based trusted cloud level computing system, comprising the following modules:

[0181] Static analysis module: Used by cloud service providers in the first phase to establish pairwise comparison matrices and output weight vectors based on the trusted computing dependency tree theory;

[0182] Dynamic Analysis Module: Used in the second stage to build AI models, acquire threat analysis data from cloud services, parse the threat analysis data through the AI ​​model for labeling and classification, dynamically establish a dual comparison matrix based on the classification results, and output a two-dimensional dynamic weight vector;

[0183] Strategy formulation module: The Trusted Cloud Level Management Unit performs decision deduction on the weight vectors output from the first and second phases, formulates the execution strategy for cloud services, and conducts continuous evolution analysis;

[0184] Feature extraction module: Based on the execution strategy formulated by the Trusted Cloud Level Management Unit, extract weight transformation samples of all core security mechanisms triggered by the strategy, identify antagonistic pairs of weight transformation samples, and extract local offset features and adversarial benefit features of each antagonistic pair;

[0185] Vector Reconstruction Module: Calculates the adversarial gradient of antagonistic pairs based on local offset and adversarial gain features, and reconstructs dynamic weight vectors based on the adversarial gradient;

[0186] Convergence analysis module: Based on dynamic weight vector and local offset samples, perform weight redistribution sensitivity projection, output weight convergence interval and corresponding confidence level, which can improve the upper bound.

[0187] The optimal selection module is used to establish a strategy combination, perform a feasibility evaluation on the strategy combination based on the weight convergence interval, determine the weight evolution path based on the evaluation results, and extract the optimal weight vector based on the weight evolution path.

[0188] The foregoing has provided a detailed description of one embodiment of the present invention, but this description is merely a preferred embodiment and should not be construed as limiting the scope of the invention. All equivalent variations and modifications made within the scope of the present invention should still fall within the scope of the present invention.

Claims

1. An evolvable, game-theoretic optimization-based method for calculating the trust level of a cloud, characterized in that: Includes the following steps: Obtain the execution policy formulated by the Trusted Cloud Level Management Unit, extract the weight transformation samples of all core security mechanisms under the policy trigger, and identify the antagonistic pairs of the weight transformation samples; The core security mechanisms mentioned above are the five core security mechanisms in the Trusted Computing Dependency Tree Theory: Trusted Computing Dependency Root, Trusted Computing Dependency Knowledge, Trusted Computing Dependency Isolation, Access Control, and Authentication Audit. The antagonistic pair refers to a pair of mechanisms in which two core security mechanisms exhibit a negatively correlated competitive relationship during dynamic weight changes. Extract the local offset features and adversarial gain features for each antagonistic pair; including: for each identified antagonistic pair (i,j), calculate the absolute weight offset of core security mechanism i and mechanism j from the baseline weight to the weight of the last time point tN, and take the difference as the local offset feature; based on dynamic evaluation, obtain the average comprehensive threat value of core security mechanisms i and j in the current threat environment. and The core security mechanisms i and j are multiplied by their respective absolute weight offsets to obtain their benefit values, and the difference between the benefit values ​​is calculated as the adversarial benefit feature. The adversarial gradient of the antagonistic pair is calculated based on local offset and adversarial gain features, and the dynamic weight vector is reconstructed based on the adversarial gradient; wherein, the adversarial gradient is obtained by weighted summation based on the local offset and adversarial gain features of the sliding time window. Sensitive projection for weight redistribution based on dynamic weight vectors and local offset samples outputs weight convergence intervals and corresponding confidence levels, which can improve the upper bound. Specifically, a sensitive projection model for weight redistribution is constructed based on time series prediction algorithms and Monte Carlo simulation algorithms. The static weight vector generated in the first stage, the dynamic weight vector generated in the second stage, and the local offset sample set are used as inputs to the sensitive projection model, and the weight convergence interval is output. A strategy combination is established, and a feasibility evaluation is performed on the strategy combination based on the weight convergence interval. The weight evolution path is determined based on the evaluation results, and the optimal weight vector is extracted based on the weight evolution path. Here, the strategy combination refers to the scheme of assigning different weight values ​​to the core security mechanism, and each scheme satisfies the constraint of each mechanism in the weight convergence interval. The cloud service system generates a time series form of weight adjustment plan based on the strategy priority sequence and adopts the idea of ​​incremental optimization as the weight evolution path.

2. The method for calculating the trust level of a cloud based on game theory optimization according to claim 1, characterized in that: The execution strategy is obtained as follows: In the first phase, cloud service providers establish pairwise comparison matrices and output static weight vectors based on the trusted computing dependency tree theory. The second stage involves building an AI model to obtain threat analysis data from cloud services, parsing the threat analysis data using the AI ​​model for labeling and classification, dynamically establishing a dual comparison matrix based on the classification results, and outputting a two-dimensional dynamic weight vector. The two-dimensional dynamic weight vector includes: strategic weight vector and tactical weight vector; The label-based classification includes functional domain-based classification and technical domain-based classification. The strategic weight vector is the weight vector for the corresponding functional domain dimension classification, and the tactical weight vector is the weight vector for the corresponding technical domain dimension classification. The Trusted Cloud Level Management Unit performs decision deduction on the weight vectors output from the first and second phases to formulate the execution strategy for cloud services.

3. The method for calculating the trust level of a cloud based on game theory optimization according to claim 2, characterized in that: The method for outputting the two-dimensional dynamic weight vector is as follows: Configure a data source to acquire threat analysis data; Threat analysis data is categorized using two-dimensional tagging. Based on threat analysis data with dual-dimensional labeling classification, a strategic comparison matrix and a tactical comparison matrix are dynamically established. The dual comparison matrix is ​​then dynamically weighted to obtain a dual-dimensional dynamic weight vector.

4. The method for calculating the trust level of a cloud based on game theory optimization according to claim 1, characterized in that: The method for reconstructing the dynamic weight vector is as follows: For each core security mechanism, the conflict intensity of all related antagonistic pairs is aggregated to obtain the total conflict intensity of the single core security mechanism; The total conflict intensity is obtained by summing the total conflict intensity of all core security mechanisms. Calculate the weight components of a single core security mechanism i in the dynamic conflict intensity weight vector and perform normalization processing; Based on the weight components of the core security mechanism i in the dynamic conflict intensity weight vector, a weight vector for dynamic conflict intensity is established.

5. The method for calculating the trust level of a cloud based on game theory optimization according to claim 1, characterized in that: The method for outputting the weight convergence interval is as follows: Based on the input of the sensitivity projection model, a historical weight sequence is constructed; Fit each mechanism weight based on historical weight sequences and predict the weight base trajectory for future cycles; Based on the weighted basic trajectory, the Monte Carlo simulation method is used to introduce a random perturbation term to simulate the uncertainty in the weight redistribution process and output the weight convergence interval.

6. An evolvable game-theoretic optimization-based trusted cloud rating calculation system, used to implement the evolvable game-theoretic optimization-based trusted cloud rating calculation method according to any one of claims 1-5, characterized in that: Includes the following modules: Feature extraction module: Based on the execution strategy formulated by the Trusted Cloud Level Management Unit, extract weight transformation samples of all core security mechanisms under the triggering of the strategy, and identify antagonistic pairs of weight transformation samples; wherein, the core security mechanisms are the five core security mechanisms in the Trusted Computing Dependency Tree Theory: Trusted Computing Dependency Root, Trusted Computing Dependency Knowledge, Trusted Computing Dependency Isolation, Access Control, and Authentication Audit; the antagonistic pair refers to a pair of mechanisms in which two core security mechanisms exhibit a negatively correlated competitive relationship during dynamic weight changes; Extract the local offset features and adversarial gain features for each antagonistic pair; including: for each identified antagonistic pair (i,j), calculate the absolute weight offset of core security mechanism i and mechanism j from the baseline weight to the weight of the last time point tN, and calculate the difference as the local offset feature; based on dynamic evaluation, obtain the average comprehensive threat values ​​Si and Sj of core security mechanisms i and j in the current threat environment, and multiply them by the corresponding absolute weight offset to obtain the gain values ​​of core security mechanisms i and j, and calculate the difference of the gain values ​​as the adversarial gain feature; Vector Reconstruction Module: Calculates the adversarial gradient of the antagonistic pair based on local offset and adversarial gain features, and reconstructs the dynamic weight vector based on the adversarial gradient; wherein, the adversarial gradient is obtained by weighted summation based on the local offset and adversarial gain features of the sliding time window. Convergence Analysis Module: Based on dynamic weight vectors and local offset samples, a weight redistribution sensitivity projection is performed, outputting the weight convergence interval and the corresponding confidence level upper bound. Specifically, a weight redistribution sensitivity projection model is constructed based on time series prediction algorithms and Monte Carlo simulation algorithms. The static weight vector generated in the first stage, the dynamic weight vector generated in the second stage, and the local offset sample set are used as inputs to the sensitivity projection model, and the weight convergence interval is output. The optimal selection module is used to establish a strategy combination, perform a feasibility evaluation on the strategy combination based on the weight convergence interval, determine the weight evolution path based on the evaluation results, and extract the optimal weight vector based on the weight evolution path. Among them, strategy combination refers to the scheme of assigning different weight values ​​to the core security mechanism, and each scheme satisfies the constraint of each mechanism in the weight convergence interval; The method for determining the weight evolution path is as follows: the cloud service system generates a time-series weight adjustment plan based on the policy priority sequence and adopts the idea of ​​incremental optimization, which serves as the weight evolution path.

Citation Information

Patent Citations

  • Credible cloud security level computing system

    CN118862092A

  • Trusted cloud security confidential privacy level product service system and method

    CN120342734A