Edge computing and distributed zero-trust architecture system and data processing method

By integrating a terminal security agent module and blockchain identity infrastructure into the edge computing device cluster, and combining them with a distributed zero-trust control center, real-time security management of the edge computing network is achieved. This solves the problem of the disconnect between identity authentication and device status, realizes dual-dimensional protection of identity legitimacy and device status, dynamically adjusts permissions, and ensures traceability of security events and network stability.

CN121690774APending Publication Date: 2026-03-17BEIJING ANCHEN INFORMATION TECHNOLOGY CO LTD
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202511918894.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-18
Publication Date
2026-03-17

AI Technical Summary

Technical Problem

Existing edge computing networks suffer from a disconnect between identity authentication and device status management, making them unable to cope with identity impersonation and device tampering. Furthermore, traditional zero-trust architectures lack dynamic permission management, leading to excessive permissions or business interruptions, and making it difficult to trace security incidents.

Method used

By employing a built-in terminal security agent module in an edge computing device cluster, combined with blockchain identity infrastructure and a distributed zero-trust control center, real-time security coefficients are generated by collecting hardware status, software vulnerabilities, and access behavior data. Access policies are dynamically adjusted, and encrypted logs are synchronized to the consortium blockchain for storage, achieving dual-dimensional protection and differentiated control.

Benefits of technology

It effectively resists identity impersonation and device tampering, avoids excessive permissions, ensures traceability of security incidents, reduces latency, and guarantees the stable operation of edge networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121690774A_ABST
    Figure CN121690774A_ABST
Patent Text Reader

Abstract

The invention discloses an edge computing and distributed zero-trust architecture system and a data processing method. The system comprises an edge computing device cluster, a distributed zero-trust control center, an edge security gateway and a block chain identity infrastructure. The edge computing node collects hardware state, vulnerability and behavior data through the terminal security agent module; the block chain identity infrastructure provides distributed identity identification and verifiable credential service; the edge security gateway executes data packet filtering and single packet authentication; and the distributed zero-trust control center calculates a real-time security coefficient and generates a differentiation strategy, and the log is synchronized to the alliance chain for evidence storage. According to the data processing method, security access is realized through access request initiation, single packet authentication, data acquisition, trust evaluation, strategy execution and log evidence storage. According to the method, the edge device state and distributed zero trust are deeply fused, the problems of incomplete identity authentication and static permission control in an edge scene are solved, and the security and traceability of an edge computing network are improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This document relates to the technical field of edge computing and distributed zero-trust architecture, and in particular to an edge computing and distributed zero-trust architecture system and data processing method. Background Technology

[0002] With the widespread adoption of 5G and IoT technologies, edge computing, with its advantages of low latency and high bandwidth, is widely used in industrial control, smart cities, and other fields. However, the dispersed distribution of edge computing nodes and the blurred network boundaries present significant limitations to traditional security technologies. On the one hand, existing edge security solutions largely rely on security chips or packet filtering, failing to link the identity of the accessing entity with the status of the edge device, thus unable to address the combined risks of identity impersonation and device tampering. On the other hand, traditional zero-trust architectures often focus on centralized identity authentication, lacking distributed identity management for edge scenarios, and trust assessment relies on static policies, making it impossible to dynamically adjust permissions based on edge device vulnerabilities or hardware anomalies, easily leading to excessive permission granting or service interruption. Furthermore, edge access logs are mostly stored locally, posing a risk of tampering and making it difficult to trace security incidents after they occur. These problems expose edge computing networks to higher risks of intrusion and data leakage, necessitating a security architecture that integrates edge device status awareness and distributed zero-trust. Summary of the Invention

[0003] This invention provides an edge computing and distributed zero-trust architecture system and data processing method, aiming to solve the above-mentioned problems.

[0004] According to an embodiment of the present invention, an edge computing and distributed zero-trust architecture system is provided, comprising: Edge computing device clusters, distributed zero-trust control centers, edge security gateways, and blockchain identity infrastructure; The edge computing device cluster includes multiple edge computing nodes. Each edge computing node has a built-in terminal security agent module, which is used to collect node hardware status, software vulnerabilities and access behavior data, and encrypt and transmit the data to the distributed zero trust control center. The blockchain identity infrastructure includes distributed identity service nodes and consortium blockchain storage nodes, which are used to generate unique distributed identity identifiers for edge computing nodes and access subjects, store identity identifier documents and public key information, and provide issuance and verification services for verifiable credentials. The edge security gateway is deployed at the connection boundary between the edge computing device cluster and the external network. It is used to receive external access requests and perform packet filtering, single packet authentication and dynamic access control based on the decision instructions of the distributed zero trust control center. The distributed zero-trust control center includes a trust assessment module, a policy generation module, and a log auditing module. The trust assessment module is used to calculate the real-time security coefficient of the access subject by combining edge computing node data and blockchain authentication results. The policy generation module is used to generate differentiated access control policies based on the security coefficient and push them to the edge security gateway. The log auditing module is used to record all access behaviors, authentication results, and policy execution logs and synchronize them to the consortium blockchain storage node for evidence storage.

[0005] According to an embodiment of the present invention, a data processing method for edge computing and distributed zero-trust architecture is provided, comprising: S1. The accessing entity initiates an access request to the edge security gateway through an external terminal, carrying its own distributed identity and the edge computing node information of the access target; S2. The edge security gateway performs single-packet authentication on access requests. After successful authentication, the request information is encrypted and transmitted to the distributed zero-trust control center. S3, the trust assessment module of the distributed zero-trust control center sends a data collection request to the terminal security agent module of the target edge computing node to obtain the node's hardware status, vulnerabilities and behavior data; S4. The trust assessment module combines the authentication results of the access subject returned by the blockchain identity infrastructure to calculate the real-time security coefficient. S5. The policy generation module generates access control policies based on the real-time security coefficient and pushes them to the edge security gateway. S6. The edge security gateway allows or restricts communication between the access subject and the target edge computing node according to the access control policy, and uploads the access behavior log to the log auditing module of the distributed zero trust control center. S7. The log auditing module encrypts the access behavior logs, authentication results, and policy execution records, and then synchronizes them to the consortium blockchain storage node of the blockchain identity infrastructure for evidence storage.

[0006] This invention employs a terminal security proxy module to collect hardware, vulnerability, and behavioral data from edge nodes. Combined with blockchain identity authentication, it constructs a dual-dimensional protection system encompassing both device status and identity legitimacy. This addresses the issues of traditional solutions relying solely on packet filtering and the disconnect between identity and device status, mitigating risks such as identity impersonation and device tampering. Based on real-time security coefficients, differentiated policies are generated, coupled with dynamic port mapping from the edge security gateway. Only necessary ports are temporarily opened, avoiding the excessive permissions or business interruptions associated with traditional static policies, balancing security with edge business flexibility. Security logs are encrypted and synchronized to the consortium blockchain. Relying on the chain structure and access control, data immutability is ensured, and security events are traceable throughout the entire process, resolving the problems of easy tampering and difficulty in tracing traditional local log storage. The edge security gateway processes requests locally, eliminating reliance on centralized nodes and reducing latency. Its distributed architecture aligns with the dispersed deployment of edge nodes, avoiding single points of failure and ensuring stable operation. Attached Figure Description

[0007] To more clearly illustrate the technical solutions in one or more embodiments of this specification or in the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0008] Figure 1 This is a schematic diagram of an edge computing and distributed zero-trust architecture system according to an embodiment of the present invention; Figure 2 This is a flowchart of a data processing method for edge computing and distributed zero-trust architecture according to an embodiment of the present invention. Detailed Implementation

[0009] To enable those skilled in the art to better understand the technical solutions in one or more embodiments of this specification, the technical solutions in one or more embodiments of this specification will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this specification, and not all of the embodiments. Based on one or more embodiments of this specification, all other embodiments obtained by those skilled in the art without creative effort should fall within the protection scope of this document.

[0010] System Implementation Examples According to embodiments of the present invention, an edge computing and distributed zero-trust architecture system is provided. Figure 1 This is a schematic diagram of an edge computing and distributed zero-trust architecture system according to an embodiment of the present invention. Figure 1As shown, an edge computing and distributed zero-trust architecture system according to an embodiment of the present invention specifically includes: Edge computing device clusters, distributed zero-trust control centers, edge security gateways, and blockchain identity infrastructure; The edge computing device cluster includes multiple edge computing nodes. Each edge computing node has a built-in terminal security agent module, which is used to collect node hardware status, software vulnerabilities and access behavior data, and encrypt and transmit the data to the distributed zero trust control center. The terminal security agent module adopts a lightweight design to adapt to the limited computing power and storage resources of edge computing nodes. The data acquisition frequency can be dynamically adjusted according to the node's business load. When the business load is low, the acquisition frequency is increased to ensure data real-time performance, and when the business load is high, the frequency is reduced to avoid consuming too many resources. Encrypted transmission adopts the national cryptographic SM2 algorithm to ensure that the data is not stolen or tampered with during transmission. At the same time, it supports data compression processing to reduce the transmission bandwidth consumption between edge nodes and the control center.

[0011] The terminal security agent module includes a hardware fingerprint collection submodule, a vulnerability scanning submodule, and a behavior monitoring submodule; The hardware fingerprint acquisition submodule is used to extract the CPU serial number, network card MAC address and firmware version information of the edge computing node to generate a unique hardware identifier; This hardware identifier is deeply bound to the physical hardware of the edge computing node. If the CPU serial number, MAC address, or other information is found to be inconsistent with the initial stored value, it is immediately determined to be a hardware tampering risk, triggering a high-risk alarm and synchronizing it to the distributed zero-trust control center. At the same time, the node's external service permissions are suspended until the administrator confirms the device's security.

[0012] The vulnerability scanning submodule is used to periodically scan for vulnerabilities in the node's operating system and applications, and upload the vulnerability level and remediation status to the distributed zero-trust control center. Vulnerability scanning supports custom scanning rules, allowing for the configuration of exclusive scanning templates for different industry scenarios. For discovered vulnerabilities, it automatically matches the remediation solutions in the vulnerability database and pushes them to edge nodes. At the same time, it tracks the remediation progress. Medium and high-risk vulnerabilities that are not remediated on time will trigger secondary alerts, and the security level of the associated access subject will be reduced.

[0013] The behavior monitoring submodule is used to monitor the process startup, port access, and data transmission behavior of nodes, identify abnormal operations, and trigger real-time alarms. Abnormal operation identification employs a machine learning-based behavior baseline model. A baseline is constructed by analyzing historical normal behavior data of edge nodes. When an abnormal process startup path, port access frequency exceeding the baseline threshold, or data transmission destination being an unfamiliar IP is detected, it is immediately marked as an abnormal operation. The alarm information includes details of the abnormal behavior, the time of occurrence, and the associated process ID, facilitating rapid problem localization by administrators.

[0014] The blockchain identity infrastructure includes distributed identity service nodes and consortium blockchain storage nodes, which are used to generate unique distributed identity identifiers for edge computing nodes and access subjects, store identity identifier documents and public key information, and provide issuance and verification services for verifiable credentials. The distributed identity identifier adopts the Decentralized Identifiers (DID) standard format to ensure cross-platform compatibility and support integration with existing identity management systems to achieve cross-system synchronization of identity information. The verifiable credentials contain the identity qualifications, permission scope, and validity period information of the access subject and support credential revocation. When the access subject's qualifications expire, the distributed identity service node can immediately revoke its credentials and synchronize the revocation to the consortium blockchain storage node to prevent expired credentials from being used illegally.

[0015] The edge security gateway is deployed at the connection boundary between the edge computing device cluster and the external network. It receives external access requests and executes packet filtering, single-packet authentication, and dynamic access control based on decision instructions from the distributed zero-trust control center. Specifically, the edge security gateway is used for: Parse the access request data packet and extract the distributed identity, verifiable credentials, counter value, and HMAC value; Packet parsing supports parsing of multiple protocol types such as TCP, UDP, and ICMP. It can automatically filter packets with abnormal formats to avoid invalid packets consuming gateway processing resources. The extracted key information will be temporarily cached locally on the gateway. The cache validity period is consistent with the validity period of the verifiable credentials. It will be automatically cleaned up after expiration to reduce memory usage.

[0016] Query the historical count value corresponding to the distributed identity in the local cache. If the current count value is less than or equal to the historical count value, it is determined to be a replay attack and the request is rejected. Historical counts are stored incrementally and are automatically updated to the current count after each successful authentication. The system also supports a count backup mechanism. After a gateway restart or fault recovery, the latest count can be synchronized from the distributed zero-trust control center to avoid the loss of counts due to gateway failure, which would prevent effective defense against replay attacks.

[0017] The HMAC value is calculated using a pre-set shared key pair with the verifiable credentials and the counter value. If the HMAC value does not match the value in the data packet, the request is rejected. Verifiable credentials are sent to the distributed identity service node of the blockchain identity infrastructure to verify the legality of the user signature and service signature in the credentials. If the verification fails, the request is rejected; if the verification succeeds, the request information is sent to the distributed zero-trust control center to obtain an access decision.

[0018] The distributed zero-trust control center includes a trust assessment module, a policy generation module, and a log auditing module. The trust assessment module is used to calculate the real-time security coefficient of the access subject by combining edge computing node data and blockchain authentication results. The policy generation module is used to generate differentiated access control policies based on the security coefficient and push them to the edge security gateway. The log auditing module is used to record all access behaviors, authentication results, and policy execution logs and synchronize them to the consortium blockchain storage node for evidence storage.

[0019] The trust assessment module is specifically used for: The system obtains the basic trust score of the access subject, which is determined based on the historical authentication records of the distributed identity identifier and the level of verifiable credentials. The historical authentication records include the number of successful authentications and the reasons for authentication failures. The higher the authentication success rate, the higher the basic trust score. The level of verifiable credentials is divided into three levels: Level 1, Level 2, and Level 3. Different levels correspond to different basic score ranges, with Level 1 credentials having the highest basic score and Level 3 credentials having the lowest basic score, ensuring that the basic score matches the identity and qualifications of the access subject.

[0020] Collect hardware status data of edge computing nodes. If there is a risk of hardware tampering or anomaly of critical components, the basic trust score will be deducted. The deduction for hardware tampering risk is greater than that for critical component anomaly. For example, hardware tampering risk will deduct 30%-50% of the basic score, while critical component anomaly will deduct 10%-20%. The deduction is combined with the duration of the risk. The longer the risk lasts, the greater the cumulative deduction will be, until the security level drops to the minimum range, and access will be forcibly denied.

[0021] Based on the vulnerability scan results, if any unpatched vulnerabilities exist, the base trust score will be deducted according to the vulnerability level. Vulnerability levels are divided into high-risk, medium-risk, and low-risk. For each high-risk vulnerability, the base score will be deducted by 20%-40%, for medium-risk vulnerabilities by 10%-20%, and for low-risk vulnerabilities by 5%-10%. If the same vulnerability has been patched, the corresponding deducted score will be automatically restored in the next trust assessment to ensure that the security level can be dynamically improved as vulnerabilities are patched.

[0022] If the behavior monitoring submodule triggers an abnormal operation alarm, the basic trust score will be deducted according to the alarm level. The deduction range corresponding to the alarm level is as follows: 15%-25% for high-risk alarms, 5%-15% for medium-risk alarms, and 1%-5% for low-risk alarms. If the same access subject triggers the same alarm multiple times within 24 hours, only the first deduction will be made or the deduction will be increased according to the cumulative number of times, so as to avoid repeated deductions that may cause the security coefficient to be distorted.

[0023] The deducted score is used as the real-time security coefficient for the accessing entity. After the real-time security coefficient is calculated, a detailed scoring report is generated, including the base score, details of each deduction, and the reasons for the deduction. This report is synchronized to the administrator's terminal, allowing the administrator to trace the key factors affecting the security coefficient and optimize security protection measures accordingly. Simultaneously, the security coefficient is updated every 5 minutes to ensure that the latest security status of the accessing entity and edge nodes is reflected in a timely manner.

[0024] The differentiated access control policies generated by the policy generation module include: When the real-time security level is at its highest range, grant the access subject full operational permissions to the edge computing node, allowing access to all open ports and business data; When the real-time security level is in a high range, grant basic operation permissions to the access subject, restrict access to high-risk ports, and require secondary authentication for sensitive business data; When the real-time security level is in the medium range, only read-only permissions are granted to the access subject, and modification of edge computing node configuration and business data is prohibited. When the real-time security level is at its lowest, all requests from the access subject are rejected, and the distributed identity of the access subject is marked as high-risk and synchronized to the blockchain identity infrastructure.

[0025] By employing the embodiments of the present invention, the following beneficial effects are achieved: By collecting hardware, vulnerability, and behavioral data from edge nodes through a terminal security proxy module and combining it with blockchain identity authentication, a two-dimensional protection system is built to safeguard both device status and identity legitimacy. This addresses the issues of traditional solutions relying solely on packet filtering and the disconnect between identity and device status, mitigating risks such as identity impersonation and device tampering. Differentiated policies are generated based on real-time security coefficients, coupled with dynamic port mapping from the edge security gateway. Only necessary ports are temporarily opened, avoiding the excessive permissions or business interruptions associated with traditional static policies, balancing security with the flexibility of edge services. Security logs are encrypted and synchronized to the consortium blockchain. Relying on the chain structure and access control, data immutability is ensured, and security events are traceable throughout the entire process, solving the problems of easy tampering and difficulty in tracing traditional local log storage. The edge security gateway processes requests locally, eliminating reliance on centralized nodes and reducing latency. Its distributed architecture aligns with the dispersed deployment of edge nodes, avoiding single points of failure and ensuring stable operation.

[0026] Method Implementation Examples According to embodiments of the present invention, a data processing method based on edge computing and a distributed zero-trust architecture is provided. Figure 2 This is a flowchart illustrating a data processing method for edge computing and distributed zero-trust architecture according to an embodiment of the present invention. Figure 2 As shown, a data processing method for edge computing and distributed zero-trust architecture according to an embodiment of the present invention specifically includes: S1. The accessing entity initiates an access request to the edge security gateway through an external terminal, carrying its own distributed identity and the edge computing node information of the access target; External terminals need to have a lightweight security client pre-installed. The client supports automatic detection of terminal security status. If a terminal has security vulnerabilities, the client will prompt the user to fix them. Only after the fix is ​​completed can an access request be initiated. The access request also includes an access timestamp and terminal hardware fingerprint information. The edge security gateway can determine whether the request has timed out by using the timestamp and associate the terminal identity by using the hardware fingerprint to prevent unauthorized access after the terminal has been stolen.

[0027] S2. The edge security gateway performs single-packet authentication on access requests. After successful authentication, the request information is encrypted and transmitted to the distributed zero-trust control center. During single-packet authentication, if any authentication step fails, the edge security gateway will return a rejection response containing the reason for the failure, but will not disclose the specific authentication rules to prevent attackers from inferring the authentication logic through the rejection response. Encrypted transmission uses the TLS 1.3 protocol to ensure the secure transmission of request information between the gateway and the control center. It also supports two-way certificate authentication, requiring the gateway and the control center to verify the legitimacy of each other's certificates to prevent man-in-the-middle attacks.

[0028] S3, the trust assessment module of the distributed zero-trust control center sends a data collection request to the terminal security agent module of the target edge computing node to obtain the node's hardware status, vulnerabilities and behavior data; The data collection request includes a request identifier and a collection scope. The endpoint security agent module only responds to requests with valid request identifiers to prevent unauthorized requests from stealing data. The collection scope can be dynamically adjusted according to the access request type. For example, when the access request is to query business data, the focus is on collecting vulnerability status and data transmission behavior data of edge nodes. When the access request is to modify node configuration, the focus is on collecting hardware status and process behavior data. The data collection response adopts an incremental transmission method, returning only the data that has changed since the last collection to reduce the amount of data transmission.

[0029] S4. The trust assessment module combines the authentication results of the access subject returned by the blockchain identity infrastructure to calculate the real-time security coefficient. The authentication result includes the validity of the distributed identity of the access subject, the status of the verifiable credentials, and the legality of the signature. If the authentication result is invalid, the real-time security coefficient is directly set to the lowest range without further deduction calculation. The security coefficient calculation adopts a weighted algorithm, with the basic trust score accounting for 60%, the edge node hardware status data accounting for 20%, the vulnerability data accounting for 15%, and the behavioral data accounting for 5%, ensuring that the core factors have a greater impact on the security coefficient, while also supporting the adjustment of weight allocation according to business scenarios.

[0030] S5. The policy generation module generates access control policies based on the real-time security coefficient and pushes them to the edge security gateway. Access control policies are encapsulated in JSON format, including policy ID, access subject identifier, target edge node identifier, permission scope, effective time, and expiration time. After receiving the policy, the edge security gateway parses the policy content and caches it. The cached policy is synchronized with the validity period of the security coefficient and automatically expires. Policy push supports breakpoint resume. If the network is interrupted during the push process, only the policy fragments that were not fully transmitted will be re-pushed after the connection is restored, avoiding repeated pushes and wasting bandwidth. The policy generation module synchronizes the policy content to the log audit module as the basis for subsequent audits.

[0031] S6. The edge security gateway allows or restricts communication between the access subject and the target edge computing node according to the access control policy, and uploads the access behavior log to the log auditing module of the distributed zero trust control center. S7. The log auditing module encrypts the access behavior logs, authentication results, and policy execution records, and then synchronizes them to the consortium blockchain storage node of the blockchain identity infrastructure for evidence storage.

[0032] In step S2, before initiating an access request, the accessing entity needs to apply for verifiable credentials from the distributed identity service node of the blockchain identity infrastructure. The specific steps include: The accessing entity submits its identity information to the distributed identity service node; The distributed identity service node verifies the legitimacy of the identity information, generates a unique distributed identity identifier and a public-private key pair, and uploads the distributed identity identifier, identity identifier document and public key to the consortium blockchain storage node; The distributed identity service node generates a verifiable credential based on the access subject's identity information, signs it with the service private key, and returns it to the access subject along with the access subject's private key. The access subject then encrypts and saves the private key through the terminal secure storage module.

[0033] In step S6, when the edge security gateway executes the access control policy, it adopts a dynamic port mapping mechanism: it temporarily opens the corresponding port of the target edge computing node only when the access subject is authenticated and the policy allows it, and closes the port immediately after the access ends. At the same time, it performs end-to-end encryption on the data transmitted between the access subject and the edge computing node.

[0034] A data processing method for edge computing and distributed zero-trust architecture according to an embodiment of the present invention further includes an anomaly response step: when the log auditing module of the distributed zero-trust control center detects that the access behavior does not match the access control policy, or when the edge computing node triggers a high-risk security alarm, it immediately sends an emergency blocking command to the edge security gateway, closes the corresponding access connection, pushes the abnormal event information to the administrator terminal, updates the real-time security coefficient of the access subject, and synchronizes it to the blockchain identity infrastructure tag. The emergency blocking command adopts a priority transmission mechanism, with the highest priority in the gateway processing queue, ensuring that the gateway performs the blocking operation first and reduces the impact of abnormal behavior; the abnormal event information includes the event type, the access subject and edge node involved, the event occurrence time, details of the abnormal behavior, and preliminary handling suggestions. The administrator can receive the information and issue handling commands through the terminal; the real-time security coefficient update of the access subject adopts an emergency deduction method, with a deduction amount of twice that of the normal deduction, and is marked as "deduction caused by abnormal event", which is listed separately in the scoring report for easy traceability by the administrator; the blockchain tag adopts an immutable high-risk event record, including the event ID, event details, and handling results, providing a basis for subsequent security event analysis.

[0035] The consortium chain storage nodes of the blockchain identity infrastructure adopt a consensus mechanism, allowing only distributed identity service nodes and distributed zero-trust control centers to have data write permissions, while other nodes only have data read permissions. Data storage adopts a chain structure, with each block containing the hash value, timestamp, and data digest of the previous block, ensuring that the data cannot be tampered with.

[0036] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, and not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features; and these modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of the present invention.

Claims

1. An edge computing and distributed zero trust architecture system, characterized in that The application relates to an edge computing device cluster, a distributed zero-trust control center, an edge security gateway and a blockchain identity infrastructure. The edge computing device cluster comprises a plurality of edge computing nodes, each of which is internally provided with a terminal security agent module for collecting node hardware state, software vulnerability and access behavior data and transmitting the data to the distributed zero-trust control center in an encrypted manner. The blockchain identity infrastructure comprises a distributed identity service node and an alliance chain storage node, which are used for generating unique distributed identity labels for the edge computing nodes and access subjects, storing identity label documents and public key information, and providing a verifiable credential issuing and verifying service. The edge security gateway is arranged at the connection boundary of the edge computing device cluster and an external network, is used for receiving an external access request, and performs data packet filtering, single packet authentication and dynamic access control based on the decision instruction of the distributed zero-trust control center. The distributed zero-trust control center comprises a trust evaluation module, a policy generation module and a log auditing module. The trust evaluation module is used for combining edge computing node data and blockchain identity verification results to calculate the real-time security coefficient of an access subject. The policy generation module is used for generating a differential access control policy according to the security coefficient and pushing the policy to the edge security gateway.

2. The system of claim 1, wherein, The log auditing module is used for recording all access behaviors, authentication results and policy execution logs and synchronizing the logs to the alliance chain storage node for evidence storage. The terminal security agent module comprises a hardware fingerprint collection sub-module, a vulnerability scanning sub-module and a behavior monitoring sub-module. The hardware fingerprint collection sub-module is used for extracting the CPU serial number, the network card MAC address and the firmware version information of the edge computing node to generate a unique hardware identity. The vulnerability scanning sub-module is used for periodically scanning node operating system vulnerabilities and application program vulnerabilities and uploading vulnerability levels and repair states to the distributed zero-trust control center.

3. The system of claim 1, wherein, The behavior monitoring sub-module is used for monitoring node process startup, port access and data transmission behaviors, identifying abnormal operations and triggering real-time alarms. The edge security gateway is specifically used for: parsing an access request data packet, extracting a distributed identity label, a verifiable credential, a count value and an HMAC value in the data packet, querying a locally cached historical count value corresponding to the distributed identity label, and determining that the request is a replay attack and rejecting the request if the current count value is less than or equal to the historical count value, calculating an HMAC value of the verifiable credential and the count value by using a preset shared key, and rejecting the request if the calculated HMAC value does not match the HMAC value in the data packet, 4. The system of claim 1, wherein, sending the verifiable credential to the distributed identity service node of the blockchain identity infrastructure to verify the legality of a user signature and a service signature in the verifiable credential, rejecting the request if the verification fails, and sending request information to the distributed zero-trust control center to obtain an access decision if the verification is passed. The trust evaluation module is specifically used for: obtaining a basic trust score of an access subject, wherein the basic trust score is determined according to historical authentication records of the distributed identity label and a verifiable credential level, collecting hardware state data of the edge computing node, and deducting the basic trust score if there is a hardware tampering risk or a key component anomaly, and According to the vulnerability scanning result, if there is an unpatched vulnerability, the basic trust score is deducted according to the vulnerability level; If the behavior monitoring submodule triggers an abnormal operation alarm, the basic trust score is deducted according to the alarm level; The score after the above deduction is taken as the real-time security coefficient of the access subject.

5. The edge computing and distributed zero-trust architecture system of claim 1, wherein, The differentiated access control policy generated by the policy generation module includes: When the real-time security coefficient is in the highest interval, the access subject is granted complete operation permission on the edge computing node, allowing access to all open ports and business data; When the real-time security coefficient is in the higher interval, the access subject is granted basic operation permission, access to high-risk ports is limited, and sensitive business data requires secondary authentication; When the real-time security coefficient is in the medium interval, only read-only permission is granted to the access subject, and modification of edge computing node configuration and business data is prohibited; When the real-time security coefficient is in the lowest interval, all requests of the access subject are rejected, and the distributed identity of the access subject is marked as high risk and synchronized to the blockchain identity infrastructure.

6. A data processing method of edge computing and distributed zero trust architecture, applied to the edge computing and distributed zero trust architecture system of any one of claims 1-5, characterized in that, The method comprises the following steps: S1, the access subject initiates an access request to the edge security gateway through an external terminal, carrying its own distributed identity and access target edge computing node information; S2, the edge security gateway performs single package authentication on the access request, and transmits the request information to the distributed zero trust control center after authentication; S3, the trust evaluation module of the distributed zero trust control center sends a data collection request to the terminal security agent module of the target edge computing node to obtain node hardware state, vulnerability and behavior data; S4, the trust evaluation module calculates the real-time security coefficient in combination with the access subject identity verification result returned by the blockchain identity infrastructure; S5, the policy generation module generates an access control policy according to the real-time security coefficient and pushes it to the edge security gateway; S6, the edge security gateway allows or restricts the communication between the access subject and the target edge computing node according to the access control policy, and uploads the access behavior log to the log audit module of the distributed zero trust control center; S7, the log audit module synchronizes the access behavior log, authentication result and policy execution record to the alliance chain storage node of the blockchain identity infrastructure for storage.

7. The data processing method of edge computing and distributed zero trust architecture according to claim 6, characterized in that, Before the access subject initiates the access request in step S2, the access subject needs to apply for a verifiable credential to the distributed identity service node of the blockchain identity infrastructure, and the specific steps include: The access subject submits identity information to the distributed identity service node; The distributed identity service node verifies the legality of the identity information, generates a unique distributed identity and a public-private key pair, and uploads the distributed identity, identity document and public key to the alliance chain storage node; The distributed identity service node generates a verifiable credential based on the identity information of the access subject, signs it with the service private key, and returns it to the access subject together with the private key of the access subject. The access subject encrypts the private key through the terminal security storage module.

8. The data processing method of edge computing and distributed zero trust architecture according to claim 6, characterized in that, In step S6, the edge security gateway adopts a dynamic port mapping mechanism when implementing the access control policy: only when the access subject is authenticated and the policy is allowed, the corresponding port of the target edge computing node is temporarily opened, and the port is closed immediately after the access is completed, while the data transmitted between the access subject and the edge computing node is end-to-end encrypted. 9.The data processing method of edge computing and distributed zero trust architecture of claim 6, wherein, It also includes an abnormal response step: when the log auditing module of the distributed zero-trust control center detects that the access behavior does not match the access control policy, or the edge computing node triggers a high-risk security alarm, it immediately sends an emergency blocking instruction to the edge security gateway, closes the corresponding access connection, and pushes the abnormal event information to the administrator terminal, updates the real-time security coefficient of the access subject, and synchronizes to the blockchain identity infrastructure mark.

10. The data processing method of edge computing and distributed zero trust architecture according to claim 6, characterized in that, The alliance chain storage node of the blockchain identity infrastructure adopts a consensus mechanism, only allows the distributed identity service node and the distributed zero-trust control center to have data writing authority, and other nodes only have data reading authority, data storage adopts a chain structure, each block contains the hash value, timestamp and data digest of the previous block, ensuring that the data cannot be tampered with.

Citation Information

Cited By

  • A method and system for edge mutation triggered digital identity emergency authorization and recovery

    CN122226279A