Resource acquisition method and zero-trust access control device
By using zero-trust access control devices in multiple branches, analyzing resource access requirements and determining data resource acquisition solutions, the high network latency problem of devices in different geographical locations in data interaction is solved, and resource sharing and utilization efficiency is improved.
Patent Information
- Application Number
- CN202111442374.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2021-11-30
- Publication Date
- 2025-06-27
- Estimated Expiration
- 2041-11-30
AI Technical Summary
In multiple branches, when devices in different geographical locations interact, there is a problem that the network delay is high and the data they need cannot be quickly obtained in real time, which reduces the efficiency of resource sharing.
Provide a resource acquisition method and a zero-trust access control device. By acquiring the resource access requirements of the resource requirements device, analyzing and determining the data resource acquisition plan, applying for data resources from the data resource server, so that the data resource server provides data resources to the resource requirements device based on the data resource acquisition plan.
By optimizing the data resource acquisition solution, it reduces network latency, improves resource sharing efficiency, and improves resource utilization efficiency, so that data resource servers and resource demand equipment in different regions can share data resources.
Smart Images

Figure CN114116638B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technologies, and particularly to a resource acquisition method and a zero-trust access control device. Background Art
[0002] Currently, when multiple branches (such as a group including multiple subsidiaries) conduct internal resource sharing, data resource interaction is required between branch structures in different geographical locations, that is, off-site interaction of data resources.
[0003] However, when devices in different geographical locations perform data interaction and the amount of data to be interacted is large, there are problems such as high network latency and inability to obtain required data in real time and quickly, which reduces the efficiency of resource sharing, fails to effectively utilize the resources within the group, and reduces the resource utilization efficiency. Summary of the Invention
[0004] Therefore, this application provides a resource acquisition method and a zero-trust access control device to solve the problem of how to reduce network latency and improve resource sharing efficiency.
[0005] To achieve the above object, a first aspect of this application provides a resource acquisition method, which is characterized in that it is applied to a zero-trust access control device. The zero-trust access control device is respectively connected to a resource demand device and a data resource server, and includes:
[0006] Obtain the resource access demand of the resource demand device;
[0007] Analyze the resource access demand to determine a data resource acquisition plan;
[0008] Apply to the data resource server for data resources according to the data resource acquisition plan, so that the data resource server provides data resources for the resource demand device based on the data resource acquisition plan. The data resource server and the resource demand device are in different regions.
[0009] In some specific implementations, the resource access demand includes data to be analyzed;
[0010] Analyzing the resource access demand to determine a data resource acquisition plan includes:
[0011] Use a multivariate cubic regression algorithm to analyze the data to be analyzed to obtain analysis result data;
[0012] Determine a data resource acquisition plan based on the analysis result data.
[0013] In some specific implementations, the data to be analyzed includes at least one of: access user account, access permission, access source address, resource target address, and access duration.
[0014] In some specific implementations, the resource access requirements further include: evaluation parameters;
[0015] Based on the analysis result data, determine a data resource acquisition plan, including:
[0016] Evaluate the analysis result data based on the evaluation parameters to determine a data resource acquisition plan.
[0017] In some specific implementations, evaluating the analysis result data based on the evaluation parameters to determine a data resource acquisition plan includes:
[0018] Perform a matching degree analysis on the analysis result data based on the evaluation parameters to obtain a to-be-confirmed plan that matches the evaluation parameters;
[0019] Judge whether the to-be-confirmed plan that matches the evaluation parameters meets the preset evaluation conditions;
[0020] In the case where it is determined that the to-be-confirmed plan that matches the evaluation parameters meets the preset evaluation conditions, use the to-be-confirmed plan that matches the evaluation parameters as the data resource acquisition plan.
[0021] In some specific implementations, before using the to-be-confirmed plan that matches the evaluation parameters as the data resource acquisition plan in the case where it is determined that the to-be-confirmed plan that matches the evaluation parameters meets the preset evaluation conditions, it further includes:
[0022] In the case where it is determined that the to-be-confirmed plan that matches the evaluation parameters does not meet the preset evaluation conditions, judge whether the current iteration count of the matching degree analysis is the maximum iteration count;
[0023] In the case where it is determined that the current iteration count is not the maximum iteration count, update the current iteration count;
[0024] Based on the updated iteration count, perform supervised learning on the evaluation parameters and the analysis result data to obtain a learning result;
[0025] Based on the learning result, continue to execute the step of performing a matching degree analysis on the analysis result data based on the evaluation parameters to obtain a to-be-confirmed plan that matches the evaluation parameters.
[0026] In some specific implementations, the evaluation parameters include at least one of: confidentiality rate, response delay rate, and access success rate.
[0027] In some specific implementations, evaluating the analysis result data based on the evaluation parameters to determine a data resource acquisition plan includes:
[0028] Obtain the data resource acquisition plan using the following formula:
[0029]
[0030] Among them, MinZ k represents the value corresponding to the data resource acquisition scheme in the k-th iteration; i represents the first dimension, j represents the second dimension, t represents the third dimension, where i ∈ [1, m], j ∈ [1, n], t ∈ [1, p], and m, n, and p respectively represent the maximum values of the dimensions; represents the access success rate at the k-th iteration, is the response delay rate at the k-th iteration, is the confidentiality rate at the k-th iteration; C Gmax represents the maximum access success rate, E Gmin represents the minimum response delay rate, W Gmin represents the minimum confidentiality rate; represents the value corresponding to the data to be analyzed; represents the value corresponding to the analysis result data at the k-th iteration; represents the value corresponding to the analysis result data before iteration.
[0031] In some specific implementations, according to the updated number of iterations, supervised learning is performed on the evaluation parameters and the analysis result data to obtain the learning result, including:
[0032] The following formula is used to determine the learning result, which includes: the corresponding value of the evaluation parameter when the number of iterations is the (k + 1)-th time, and the value corresponding to the analysis result data when the number of iterations is the (k + 1)-th time, where k represents the number of iterations and k is an integer greater than or equal to 1;
[0033]
[0034]
[0035] Among them, μ represents the iteration weight, represents the corresponding value of the evaluation parameter when the number of iterations is the (k + 1)-th time, represents the access success rate when the number of iterations is the (k + 1)-th time, represents the response delay rate when the number of iterations is the (k + 1)-th time, represents the confidentiality rate when the number of iterations is the (k + 1)-th time, represents the value corresponding to the analysis result data when the number of iterations is the k-th time, represents the enhancement factor when the number of iterations is the (k + 1)-th time;
[0036] Among them, the enhancement factor can be implemented using a recurrent excitation function, and the recurrent excitation function is obtained according to the following formula:
[0037]
[0038] Among them, represents the value of the recursive excitation function in the (k + 1)-th iteration loop; C Gmax represents the historical maximum access success rate, E Gmin represents the historical minimum data delay rate, W Gmin represents the historical minimum confidentiality rate; represents the value corresponding to the analysis result data in the k-th iteration; represents the value corresponding to the analysis result data when no iteration is performed.
[0039] To achieve the above object, a zero-trust access control device is provided in the second aspect of the present application. The zero-trust access control device is respectively connected to a resource demand device and a data resource server. The zero-trust access control device includes:
[0040] An acquisition module, configured to acquire the resource access demand of the resource demand device;
[0041] An analysis module, configured to analyze the resource access demand to determine a data resource acquisition plan;
[0042] An application module, configured to apply to the data resource server for data resources according to the data resource acquisition plan, so that the data resource server provides data resources for the resource demand device based on the data resource acquisition plan. The data resource server and the resource demand device are in different regions.
[0043] In the resource acquisition method and the zero-trust access control device of the present application, by acquiring the resource access demand of the resource demand device, the demand of the resource demand device for data resources is clarified; by analyzing the resource access demand, a data resource acquisition plan is determined, so that the data resource acquisition plan can match the resource access demand, improving the acquisition efficiency of data resources; by applying to the data resource server for data resources according to the data resource acquisition plan, the data resource server provides data resources for the resource demand device based on the data resource acquisition plan, enabling the data resource server and the resource demand device in different regions to share data resources, improving the resource sharing efficiency, and enhancing the resource utilization efficiency. BRIEF DESCRIPTION OF THE DRAWINGS
[0044] The drawings are used to provide a further understanding of the embodiments of the present disclosure and constitute a part of the specification. They are used to explain the present disclosure together with the embodiments of the present disclosure and do not constitute a limitation to the present disclosure. By describing the detailed exemplary embodiments with reference to the drawings, the above and other features and advantages will become more obvious to those skilled in the art. In the drawings:
[0045] Figure 1 Shows a schematic flowchart of a resource acquisition method provided by an embodiment of the present application.
[0046] Figure 2 A schematic flowchart showing the resource acquisition method provided by another embodiment of the present application.
[0047] Figure 3 A block diagram showing the components of the zero-trust access control device provided by an embodiment of the present application.
[0048] Figure 4 A block diagram showing the components of the resource acquisition system provided by an embodiment of the present application.
[0049] Figure 5 A flowchart showing the working method of the resource acquisition system provided by an embodiment of the present application.
[0050] Figure 6 A schematic diagram showing a multi-layer neural network in an embodiment of the present application.
[0051] Figure 7 A schematic diagram showing that evaluation parameters are stored in the form of three-dimensional vectors in an embodiment of the present application.
[0052] Figure 8 A schematic flowchart showing the method for determining the data resource acquisition scheme in the implementation of the present application. Detailed Description of the Specific Embodiment
[0053] The following will describe the specific embodiments of the present application in detail with reference to the accompanying drawings. It should be understood that the specific embodiments described herein are only for the purpose of illustrating and explaining the present application, and are not intended to limit the present application. For those skilled in the art
[0054] the present application can be implemented without some of these specific details. The following description of the embodiments is only to provide a better understanding of the present application by showing examples of the present application.
[0055] To make the purpose, technical solutions and advantages of the present application clearer, the embodiments of the present application will be further described in detail below with reference to the accompanying drawings.
[0056] With the rapid development of zero trust, zero trust represents a new generation of network security protection concept. The key lies in breaking the default "trust". In a nutshell, it is "continuous verification, never trust". By default, it does not trust anyone, device, or system inside or outside the enterprise network. It rebuilds the trust foundation of access control based on identity authentication and authorization, thus ensuring the credibility of identities, devices, applications, and links. Based on the zero-trust principle, it can guarantee three "securities" for the office system: terminal security, link security, and access control security. For zero trust, it shows more obvious advantages and more powerful functions in the actual application process. The rapid and continuous development of the cross-border and cross-domain operator office system and method based on zero trust is of great significance.
[0057] Figure 1 The flowchart shows the resource acquisition method provided by an embodiment of the present application. This method can be applied to a zero-trust access control device, which is respectively connected to a resource demand device and a data resource server.
[0058] As Figure 1 shown, the resource acquisition method includes but is not limited to the following steps.
[0059] Step S101, obtain the resource access demand of the resource demand device.
[0060] Among them, the resource access demand is used to represent the demand information of the data resources that the resource demand device needs to obtain. For example, the resource demand device can be a certain remote terminal or a terminal device used by a subsidiary within a certain group. The above are only examples of the types of resource demand devices, which can be specifically set according to actual needs. Other types of resource demand devices not mentioned are also within the protection scope of the present application and will not be elaborated here.
[0061] The resource demand device needs to access the data resources on a remote server (such as a data resource server). Therefore, it needs to generate a resource access demand based on the data resource identifier and send the resource access demand to the remote server so that the remote server can learn the demand information of the resource demand device.
[0062] Step S102, analyze the resource access demand to determine the data resource acquisition plan.
[0063] By analyzing the resource access demand, an analysis result is generated. This analysis result represents information such as the access path and access interface that the resource demand device needs to pass through during the process of obtaining the data resources stored on the remote server. Then, a data resource acquisition plan is generated based on this analysis result, and through this data resource acquisition plan, the resource demand device can quickly and accurately obtain the data resources it needs.
[0064] Step S103: Apply for data resources from the data resource server according to the data resource acquisition plan.
[0065] Among them, the data resource server and the resource - demand device are in different regions. For example, the data resource server and the resource - demand device are in different countries or different cities, etc.
[0066] After obtaining the data resource acquisition plan, the data resource server can clarify the transmission path of the data resources based on the data resource acquisition plan, and use this transmission path to transmit the data resources to the resource - demand device as soon as possible, facilitating the resource - demand device to obtain the data resources it needs.
[0067] In this embodiment, by obtaining the resource access requirements of the resource - demand device, the requirements of the resource - demand device for data resources are clarified; by analyzing the resource access requirements, a data resource acquisition plan is determined, enabling the data resource acquisition plan to match the resource access requirements, improving the acquisition efficiency of data resources; applying for data resources from the data resource server according to the data resource acquisition plan, so that the data resource server can provide data resources for the resource - demand device based on the data resource acquisition plan, enabling the data resource server and the resource - demand device in different regions to share data resources, improving the resource sharing efficiency, and enhancing the utilization efficiency of resources.
[0068] Figure 2 The flowchart of the resource acquisition method provided by another embodiment of the present application is shown. This method can be applied to a zero - trust access control device, which is respectively connected to a resource - demand device and a data resource server.
[0069] As Figure 2 shown, the resource acquisition method includes but is not limited to the following steps.
[0070] Step S201: Obtain the resource access requirements of the resource - demand device.
[0071] Among them, the resource access requirements include data to be analyzed. The data to be analyzed includes at least one of: access user account, access permission, access source address, resource target address, and access duration.
[0072] For example, the access source address may include: the network address of the resource - demand device, and / or, device identification information of the resource - demand device, etc., to quickly obtain the location information of the resource - demand device. The resource target address may include the network address of the data resource server, or the network address of the zero - trust access control device, etc. Through the forwarding of the zero - trust access control device, the data resource server can obtain the resource access requirements sent by the resource - demand device.
[0073] Step S202: Analyze the data to be analyzed using a multivariate cubic regression algorithm to obtain analysis result data.
[0074] A simple linear regression algorithm has only one eigenvalue. Usually, there are multiple eigenvalues in a linear regression algorithm, and some even have thousands or tens of thousands of eigenvalues. In a multiple linear regression algorithm, there are multiple features, and each feature has a linear relationship with the output result, only the coefficients of the linear relationships are different. Correspondingly, in a multivariate cubic regression algorithm, multiple eigenvalues are used and a cubic regression method is adopted to analyze the data to be analyzed to improve the analysis accuracy of the data to be analyzed.
[0075] Step S203: Determine a data resource acquisition plan based on the analysis result data.
[0076] Among them, the analysis result data can represent the verification result of at least one of the confidentiality rate, response delay rate, and access success rate in the evaluation parameters, so that the obtained data resource acquisition plan can meet the requirements of evaluation parameters in different dimensions and improve the accuracy of the data resource acquisition plan.
[0077] Step S204: Apply for data resources from the data resource server according to the data resource acquisition plan.
[0078] It should be noted that step S204 in this embodiment is the same as step S103 in the previous embodiment, and will not be elaborated here.
[0079] In this embodiment, by analyzing the data to be analyzed using a multivariate cubic regression algorithm to obtain analysis result data, the analysis result data can represent the acquisition method of the data resources expected to be obtained by the resource demand device. Then, based on the analysis result data, a data resource acquisition plan is determined to improve the acquisition speed of the data resources. According to the data resource acquisition plan, data resources are applied for from the data resource server, so that the data resource server can provide data resources for the resource demand device based on the data resource acquisition plan, enabling data resource servers and resource demand devices in different regions to share data resources, improving the resource sharing efficiency, and enhancing the utilization efficiency of the resources.
[0080] Another possible implementation manner is provided in the embodiment of the present application. Among them, the resource access requirement further includes: evaluation parameters. Determining a data resource acquisition plan based on the analysis result data in step S203 includes: evaluating the analysis result data based on the evaluation parameters to determine a data resource acquisition plan.
[0081] Among them, the evaluation parameters include at least one of a confidentiality rate, a response delay rate, and an access success rate.
[0082] The confidentiality rate represents the security of data resources. For example, whether the data resources are encrypted, etc., to ensure the security of data resources during transmission and use. The response delay rate represents the ratio between the response delay time of the data resource server to the data resource requested by the resource demand device and the preset response time;
[0083] The access success rate represents the ratio of whether the resource demand device successfully obtains the data resources it needs from the data resource server. For example, the access success rate can be the ratio between the number of times the data resources are successfully obtained and the number of times the data resources are accessed.
[0084] Evaluating the analysis result data using different evaluation parameters can evaluate the analysis result data from different dimensions to determine whether the analysis result data meets the requirements of the evaluation parameters. Furthermore, when it is determined that the requirements of the evaluation parameters are met, a data resource acquisition plan can be obtained, so that according to this data resource acquisition plan, the data resources required by the resource demand device can be obtained quickly and accurately.
[0085] In some specific implementations, evaluating the analysis result data based on the evaluation parameters to determine the data resource acquisition plan includes: performing a matching degree analysis on the analysis result data based on the evaluation parameters to obtain a to-be-confirmed plan that matches the evaluation parameters; determining whether the to-be-confirmed plan that matches the evaluation parameters meets the preset evaluation conditions; and when it is determined that the to-be-confirmed plan that matches the evaluation parameters meets the preset evaluation conditions, using the to-be-confirmed plan that matches the evaluation parameters as the data resource acquisition plan.
[0086] Among them, performing a matching degree analysis on the analysis result data based on the evaluation parameters is to use different evaluation parameters to match the analysis result data with the to-be-confirmed plan, thereby obtaining multiple to-be-confirmed plans with different matching degrees; then, screening the to-be-confirmed plans with different matching degrees to obtain the to-be-confirmed plan that matches the evaluation parameters; and when it is determined that the to-be-confirmed plan with the optimal matching degree meets the preset evaluation conditions, obtaining the business resource acquisition plan.
[0087] So that the finally obtained data resource acquisition plan can meet the corresponding requirements of the analysis result data (i.e., the resource access requirements of the resource demand device), improving the accuracy of the data resource acquisition plan.
[0088] In some specific implementations, before determining the to-be-confirmed solution that matches the evaluation parameter as the data resource acquisition solution when it is determined that the to-be-confirmed solution that matches the evaluation parameter meets the preset evaluation conditions, it further includes: when it is determined that the to-be-confirmed solution that matches the evaluation parameter does not meet the preset evaluation conditions, determining whether the current iteration count for the matching degree analysis is the maximum iteration count; when it is determined that the current iteration count is not the maximum iteration count, updating the current iteration count; based on the updated iteration count, performing supervised learning on the evaluation parameter and the analysis result data to obtain a learning result; based on the learning result, continuing to execute the step of performing matching degree analysis on the analysis result data based on the evaluation parameter to obtain the to-be-confirmed solution that matches the evaluation parameter.
[0089] Among them, the matching degree of the to-be-confirmed solution can be processed through multiple iterations. When it is determined that the current iteration count is not the maximum iteration count, the current iteration count is updated (for example, incrementing the iteration count by one, or processing the iteration count according to preset conditions to obtain the updated iteration count, etc.).
[0090] Furthermore, different iteration counts are used to perform supervised learning on the evaluation parameter and the analysis result data to obtain a learning result, so that the device can obtain the ability of autonomous learning and ensure the accuracy of the learning result.
[0091] In some specific implementations, evaluating the analysis result data based on the evaluation parameter to determine the data resource acquisition solution includes:
[0092] The data resource acquisition solution is obtained using the following formula:
[0093]
[0094] Among them, MinZ k represents the value corresponding to the data resource acquisition solution for the k-th iteration; i represents the first dimension, j represents the second dimension, t represents the third dimension, where i ∈ [1, m], j ∈ [1, n], t ∈ [1, p], and m, n, p respectively represent the maximum values of the dimensions; represents the access success rate for the k-th iteration, is the response delay rate for the k-th iteration, is the confidentiality rate for the k-th iteration; C Gmax represents the maximum access success rate, E Gmin represents the minimum response delay rate, W Gmin represents the minimum confidentiality rate; represents the value corresponding to the data to be analyzed; represents the value corresponding to the analysis result data for the k-th iteration; represents the value corresponding to the analysis result data before iteration.
[0095] Through multiple superposition processes for the access success rate, response latency rate, and confidentiality rate, and then multiple iteration processes, the obtained analysis result data can meet the requirements of evaluation parameters in different dimensions, improving the accuracy of the analysis result data.
[0096] In some specific implementations, according to the updated number of iterations, supervised learning is performed on the evaluation parameters and the analysis result data to obtain a learning result, including: determining the learning result using the following formulas (2) and (3).
[0097] Among them, the learning result includes: the corresponding value of the evaluation parameter when the number of iterations is the (k + 1)-th time, and the corresponding value of the analysis result data when the number of iterations is the (k + 1)-th time, where k represents the number of iterations, and k is an integer greater than or equal to 1;
[0098]
[0099]
[0100] Among them, μ represents the iteration weight, represents the corresponding value of the evaluation parameter when the number of iterations is the (k + 1)-th time, represents the access success rate when the number of iterations is the (k + 1)-th time, represents the response latency rate when the number of iterations is the (k + 1)-th time, represents the confidentiality rate when the number of iterations is the (k + 1)-th time, represents the corresponding value of the analysis result data when the number of iterations is the k-th time, represents the enhancement factor when the number of iterations is the (k + 1)-th time.
[0101] In some specific implementations, the enhancement factor can be implemented using a recurrent excitation function, and the recurrent excitation function is obtained according to the following formula:
[0102]
[0103] Among them, represents the value of the (k + 1)-th iteration recurrent excitation function; C Gmax represents the historical maximum access success rate, E Gmin represents the historical minimum data latency rate, W Gmin represents the historical minimum confidentiality rate; represents the corresponding value of the analysis result data at the k-th iteration; represents the corresponding value of the analysis result data before iteration.
[0104] By using a cyclic recursive activation function as a reinforcement factor, the corresponding values of the evaluation parameters in different numbers of iterations obtained by calculation can be made more accurate, so that the learning result can better reflect the demand of the resource - requiring device for data resources after multiple iterations, ensuring the accuracy of the learning result.
[0105] Figure 3 The block diagram showing the components of the zero - trust access control device provided by the embodiments of the present application is presented. For the specific implementation of this zero - trust access control device, reference can be made to the relevant descriptions in the above - mentioned method embodiments, and repeated parts will not be elaborated. It should be noted that the specific implementation of the device in this embodiment is not limited to the above embodiments, and other unmentioned embodiments are also within the protection scope of this device.
[0106] As Figure 3 shown, the zero - trust access control device 300 includes the following modules.
[0107] An acquisition module 301, configured to acquire the resource access requirements of the resource - requiring device.
[0108] An analysis module 302, configured to analyze the resource access requirements to determine a data resource acquisition plan.
[0109] An application module 303, configured to apply to the data resource server for data resources according to the data resource acquisition plan, so that the data resource server provides data resources for the resource - requiring device based on the data resource acquisition plan, and the data resource server and the resource - requiring device are in different regions.
[0110] In this embodiment, by using the acquisition module to acquire the resource access requirements of the resource - requiring device, the demand of the resource - requiring device for data resources is clarified; the analysis module is used to analyze the resource access requirements to determine a data resource acquisition plan, so that the data resource acquisition plan can match the resource access requirements, improving the acquisition efficiency of data resources; the application module is used to apply to the data resource server for data resources according to the data resource acquisition plan, so that the data resource server provides data resources for the resource - requiring device based on the data resource acquisition plan, enabling the data resource server and the resource - requiring device in different regions to share data resources, improving the resource sharing efficiency, and enhancing the utilization efficiency of resources.
[0111] It is worth mentioning that each module involved in this embodiment is a logical module. In practical applications, a logical unit can be a physical unit, a part of a physical unit, or a combination of multiple physical units. In addition, to highlight the innovative part of the present application, units not closely related to solving the technical problems proposed by the present application are not introduced in this embodiment, but this does not mean that there are no other units in this embodiment.
[0112] Figure 4 The block diagram showing the components of the resource acquisition system provided by the embodiments of the present application is as follows. As Figure 4 shown, the zero-trust based business processing system includes the following devices.
[0113] A data resource server 410, a zero-trust access control device 420, and a resource demand device 430.
[0114] Among them, the data resource server 410 and the resource demand device 430 are in different regions. The zero-trust access control device 420 is mainly used to obtain the resource access requirements of the resource demand device 430; analyze the resource access requirements to determine a data resource acquisition plan; and apply to the data resource server 410 for data resources according to the data resource acquisition plan, so that the data resource server 410 provides data resources for the resource demand device 430 based on the data resource acquisition plan.
[0115] The zero-trust access control device 420 may include: a zero-trust access control and protection engine 421 and a zero-trust gateway 422. The resource demand device 430 may include: an internal group access device 431, a group dedicated line access device 432, a subsidiary company device 433, a merged company device 434, and a cooperative company device 435.
[0116] It should be noted that the data resource server 410 may be a device for storing data resources. For example, an enterprise server, a Web server, an SSH server, etc., which can respond to the acquisition or analysis requests of the data resources fed back by the zero-trust access control device 420, so that the resource demand device 430 can obtain the data resources it needs.
[0117] Figure 5 The flowchart showing the working method of the resource acquisition system provided by the embodiments of the present application is as follows. As Figure 5 shown, the working method of the resource acquisition system specifically includes the following steps.
[0118] Step S501, the resource demand device 430 sends a resource access request to the zero-trust access control device 420.
[0119] Among them, the resource access requirements include: data to be analyzed and evaluation parameters. The evaluation parameters include at least one of: the confidentiality rate, the response delay rate, and the access success rate. This resource access request is used to request data resources from the data resource server 410.
[0120] Step S502, after receiving the resource access request, the zero-trust access control device 420 analyzes the data to be analyzed therein, obtains analysis result data, and determines a data resource acquisition plan based on the analysis result data.
[0121] Among them, the data to be analyzed may include at least one of: the accessed user account, access permissions, access source address (for example, any one of the addresses of the internal group access device 431, the group dedicated line access device 432, the subsidiary device 433, the acquired company device 434, and the collaborative company device 435), the resource target address (for example, the address of the data resource server 410, etc.), and the access duration.
[0122] For example, the zero-trust access control device 420 uses multiple methods such as multi-layer neural networks, matrix decomposition, and multivariate cubic regression algorithms to analyze the data to be analyzed, determine the optimal data resource acquisition plan, and based on this data resource acquisition plan, enable the resource demand device 430 to obtain the data resources it needs.
[0123] Figure 6 It is a schematic diagram of the multi-layer neuron network in the embodiment of this application. As Figure 6 shown, in the process of each iteration processing, it is necessary to perform iteration and processing on the response delay rate E, confidentiality rate W, and access success rate C in turn according to strategies such as multi-layer neural networks, matrix decomposition, and multivariate cubic regression (that is, migrate to the positions of the solid sphere where each solid line is located as Figure 6 shown) to obtain the optimal data resource acquisition plan.
[0124] Among them, the confidentiality rate W (= the unencrypted traffic of the internal group resource access analyzed / the total unencrypted traffic of the internal group resource access analyzed), the response delay rate E (= the ineffective occupation time of the internal group resource analysis per unit time / the total unit time), the access success rate C (= the number of successful internal group resource accesses analyzed / the total number of internal group resource accesses analyzed). The output includes: pre-recommended information on the data resource acquisition plan.
[0125] Step S503, the zero-trust access control and protection engine 421 and the zero-trust gateway 422 in the zero-trust access control device 420 apply for data resources from the data resource server 410 according to the data resource acquisition plan.
[0126] Step S504, the data resource server 410 feeds back the data resources corresponding to the data resource acquisition plan to the zero-trust gateway 422 or the zero-trust access control and protection engine 421.
[0127] Step S505, the zero-trust gateway 422 or the zero-trust access control and protection engine 421 feeds back the obtained data resources to the resource demand device 430 based on the data resource acquisition plan.
[0128] Specifically, there may also be a router or an access cloud server between the zero-trust gateway 422 and the resource demand device 430 (Figure 4 (not shown in the figure), through the forwarding of a router or access to a cloud server, so that resource demand devices 430 in different geographical locations can obtain the data resources they need.
[0129] For example, through the forwarding of different routers or access to a cloud server, internal access devices 431 within the group, dedicated line access devices 432 within the group, subsidiary devices 433, acquired company devices 434, and collaborating company devices 435 can respectively obtain the data resources they need to achieve data sharing within the group.
[0130] In this embodiment, by analyzing the data to be analyzed in the resource access demand, an optimal data resource acquisition scheme is obtained, so that the resource demand device 430 can obtain the data resources it needs in a timely manner, improving the sharing efficiency of the data resources.
[0131] In some specific implementations, step S502 can also be implemented in the following manner to obtain a data resource acquisition scheme.
[0132] 1) Preprocess the parameters input into the multi-layer neural network.
[0133] For example, when K is equal to 0, the parameters input into the multi-layer neural network include: the data to be analyzed (for example, access user account, access permission, access source address (for example, any one of the addresses of internal access device 431 within the group, dedicated line access device 432 within the group, subsidiary device 433, acquired company device 434, and collaborating company device 435), resource target address (for example, the address of data resource server 410, etc.), and access duration, etc.) and evaluation parameters (for example, at least one of confidentiality rate W, response delay rate E, and access success rate C).
[0134] When K is not equal to 0, the parameters input into the multi-layer neural network include: the confidentiality rate of the k-th iteration access success rate response delay rate and multivariate cubic regression data etc., where k ∈ [0, 1,..., 50].
[0135] Use the multivariate cubic regression algorithm to analyze the data to be analyzed, and after multiple iterative processes of the multi-layer neural network, obtain the analysis result data. This analysis result data can be expressed by formula (5) as:
[0136]
[0137] Wherein, i represents the first dimension, j represents the second dimension, and t represents the third dimension, where i ∈ [1, m], j ∈ [1, n], t ∈ [1, p], and m, n, and p respectively represent the maximum values of the dimensions; is the access success rate at the k-th iteration; represents the response delay rate at the k-th iteration; represents the confidentiality rate at the k-th iteration; represents the value corresponding to the data to be analyzed; represents the value corresponding to the analysis result data at the k-th iteration; l2 represents the regression coefficient.
[0138] It can be understood that through the calculation of the multivariate cubic regression algorithm, the value of is between (0, 1).
[0139] Figure 7 shows a schematic diagram of storing the evaluation parameters in the form of three-dimensional vectors in the embodiments of the present application. Among them, in combination with Figure 7 the storage space shown, in this embodiment, the evaluation parameters (for example, the confidentiality rate W, the response delay rate E, and the access success rate C) are stored in the form of different three-dimensional vectors.
[0140] Further, based on the evaluation parameters, the data to be analyzed is analyzed to obtain a data resource acquisition scheme. Figure 8 shows a schematic flowchart of the method for determining the data resource acquisition scheme in the embodiments of the present application. As Figure 8 shown, the method includes the following steps.
[0141] Step S801, perform a matching degree analysis on the analysis result data based on the evaluation parameters to obtain a to-be-confirmed scheme that matches the evaluation parameters.
[0142] In this embodiment, the matching degree analysis is to obtain a to-be-confirmed scheme that matches the evaluation parameters by using deep learning. It can be understood that the to-be-confirmed scheme corresponding to the resource access request migrates in the direction of the optimal evaluation parameters and analysis result data to obtain the analysis result data that matches the evaluation parameters. Specifically, step S801 can be obtained according to formula (1):
[0143]
[0144] Wherein, MinZ k represents the value corresponding to the data resource acquisition scheme at the k-th iteration; i represents the first dimension, j represents the second dimension, t represents the third dimension, where i ∈ [1, m], j ∈ [1, n], t ∈ [1, p], and m, n, and p respectively represent the maximum values of the dimensions; represents the access success rate at the k-th iteration, is the response delay rate at the k-th iteration, is the confidentiality rate at the k-th iteration; C Gmax represents the historical maximum access success rate, E Gmin represents the historical minimum response delay rate, W Gmin represents the historical minimum confidentiality rate; represents the value corresponding to the data to be analyzed; represents the value corresponding to the analysis result data at the k-th iteration; represents the value corresponding to the analysis result data before iteration.
[0145] Step S802, determine whether the to-be-confirmed solution matching the evaluation parameter meets the preset evaluation condition.
[0146] Among them, the preset evaluation condition can be determined by formula (6):
[0147]
[0148] Among them, represents the product probability of the access success rate at the k-th iteration;
[0149] represents the product probability of the confidentiality rate at the k-th iteration;
[0150] represents the product probability of the response delay rate at the k-th iteration;
[0151] represents the access success rate at the k-th iteration;
[0152] is the response delay rate at the k-th iteration;
[0153] represents the confidentiality rate at the k-th iteration;
[0154] represents the value corresponding to the said data to be analyzed;
[0155] represents the value corresponding to the analysis result data at the k-th iteration.
[0156] It should be noted that in the case where it is determined that the to-be-confirmed solution matching the evaluation parameter meets the preset evaluation condition, step S805 is executed; otherwise, step S803 is executed.
[0157] Step S803, determine whether the current iteration count for the matching degree analysis has reached the maximum iteration count.
[0158] In the case where it is determined that the current iteration count has reached the maximum iteration count, step S805 is executed; otherwise, step S804 is executed.
[0159] It is understandable that the current iteration count for the matching degree analysis is the iteration count for the matching degree analysis in step S801. This iteration count can be adaptively set according to the actual application.
[0160] Step S804: Update the current iteration count, and based on the updated iteration count, perform supervised learning on the evaluation parameters and the analysis result data to obtain a learning result.
[0161] Among them, the learning result may include: the corresponding value of the evaluation parameter when the iteration count is the (k + 1)-th time, and the value of the analysis result data when the iteration count is the (k + 1)-th time.
[0162] In one implementation, the corresponding value of the evaluation parameter when the iteration count is the (k + 1)-th time can be calculated using formula (2) and formula (3)
[0163]
[0164]
[0165] Among them, μ represents the iteration weight;
[0166] represents the corresponding value of the evaluation parameter when the iteration count is the (k + 1)-th time, represents the access success rate when the iteration count is the (k + 1)-th time, represents the response delay rate when the iteration count is the (k + 1)-th time, represents the confidentiality rate when the iteration count is the (k + 1)-th time, represents the value of the analysis result data corresponding to the k-th iteration count, represents the enhancement factor when the iteration count is the (k + 1)-th time;
[0167] Among them, the enhancement factor can be implemented using a recurrent excitation function, and the recurrent excitation function is obtained according to formula (4):
[0168]
[0169] Among them, represents the value of the recurrent excitation function for the (k + 1)-th iteration; C Gmax represents the historical maximum access success rate, E Gmin represents the historical minimum data delay rate, W Gmin represents the historical minimum confidentiality rate; represents the value of the analysis result data corresponding to the k-th iteration; represents the value of the analysis result data corresponding to when there is no iteration.
[0170] It should be noted that after step S804 is executed, step S801 still needs to be continued. Further, based on the learning result and the evaluation parameter, the matching degree analysis of the analysis result data is performed here, so that the to-be-confirmed solution with the optimal matching degree is more accurate.
[0171] Step S805, use the to-be-confirmed solution with the optimal matching degree as the data resource acquisition solution.
[0172] In this embodiment, by combining multiple algorithms such as the multivariate cubic regression algorithm, deep learning, and supervised learning, the resource access requirements sent by the resource demand device 430 are dynamically and deeply analyzed to obtain a data resource acquisition solution, and the data resource acquisition solution is used to obtain the data resources required by the resource demand device 430, so that the resource demand device 430 can quickly and accurately obtain the data resources, which can reduce the response delay rate, improve the confidentiality rate of the data, and improve the access efficiency of the data.
[0173] It can be understood that the above embodiments are only exemplary embodiments adopted to illustrate the principle of the present application. However, the present application is not limited thereto. For those of ordinary skill in the art, various modifications and improvements can be made without departing from the spirit and essence of the present application, and these modifications and improvements are also regarded as the protection scope of the present application.
Claims
1. A resource acquisition method, characterized in that, Applied to a zero-trust access control device, the zero-trust access control device is respectively connected to a resource demand device and a data resource server, and includes: Obtain the resource access demand of the resource demand device; Analyze the resource access demand to determine a data resource acquisition plan; Apply for data resources from the data resource server according to the data resource acquisition plan, so that the data resource server provides data resources for the resource demand device based on the data resource acquisition plan, and the data resource server and the resource demand device are in different regions; The resource access demand includes data to be analyzed; The analyzing the resource access demand to determine a data resource acquisition plan includes: analyzing the data to be analyzed by using a multivariate cubic regression algorithm to obtain analysis result data; determining the data resource acquisition plan according to the analysis result data; The resource access demand further includes: evaluation parameters; The determining the data resource acquisition plan according to the analysis result data includes: evaluating the analysis result data based on the evaluation parameters to determine the data resource acquisition plan; The evaluating the analysis result data based on the evaluation parameters to determine the data resource acquisition plan includes: Obtain the data resource acquisition plan by using the following formula: Among them, MinZ k represents the value corresponding to the data resource acquisition scheme in the k-th iteration; i represents the first dimension, j represents the second dimension, t represents the third dimension, where i ∈ [1, m], j ∈ [1, n], t ∈ [1, p], and m, n, and p respectively represent the maximum values of the dimensions; represents the access success rate at the k-th iteration, is the response delay rate at the k-th iteration, is the confidentiality rate at the k-th iteration; C Gmax represents the maximum access success rate, E Gmin represents the minimum response delay rate, W Gmin represents the minimum confidentiality rate; represents the value corresponding to the data to be analyzed; represents the value corresponding to the analysis result data at the k-th iteration; represents the value corresponding to the analysis result data before iteration.
2. The method according to claim 1, wherein The data to be analyzed includes at least one of an access user account, access permissions, an access source address, a resource target address, and an access duration.
3. The method according to claim 1, wherein The evaluating the analysis result data based on the evaluation parameters to determine the data resource acquisition plan includes: Perform a matching degree analysis on the analysis result data based on the evaluation parameters to obtain a to-be-confirmed plan that matches the evaluation parameters; Judge whether the to-be-confirmed plan that matches the evaluation parameters meets a preset evaluation condition; When it is determined that the to-be-confirmed plan that matches the evaluation parameters meets the preset evaluation condition, use the to-be-confirmed plan that matches the evaluation parameters as the data resource acquisition plan.
4. The method according to claim 3, wherein Before the step of using the to-be-confirmed plan that matches the evaluation parameters as the data resource acquisition plan when it is determined that the to-be-confirmed plan that matches the evaluation parameters meets the preset evaluation condition, further includes: When it is determined that the to-be-confirmed plan that matches the evaluation parameters does not meet the preset evaluation condition, judge whether the current iteration number of the matching degree analysis is the maximum iteration number; When it is determined that the current iteration number is not the maximum iteration number, update the current iteration number; Perform supervised learning on the evaluation parameters and the analysis result data according to the updated iteration number to obtain a learning result; According to the learning result, continue to execute the step of performing a matching degree analysis on the analysis result data based on the evaluation parameters to obtain a to-be-confirmed plan that matches the evaluation parameters.
5. The method according to any one of claims 1 to 4, characterized in that The evaluation parameters include at least one of a confidentiality rate, a response delay rate, and an access success rate.
6. The method according to claim 4, wherein Supervising and learning the evaluation parameters and the analysis result data according to the updated number of iterations to obtain a learning result, including: Determining the learning result by using the following formula, where the learning result includes the corresponding value of the evaluation parameter when the number of iterations is the (k + 1)-th time, and the corresponding value of the analysis result data when the number of iterations is the (k + 1)-th time, k represents the number of iterations, and k is an integer greater than or equal to 1; Among them, μ represents the iteration weight, represents the corresponding value of the evaluation parameter when the iteration number is the (k + 1)-th time, represents the access success rate when the iteration number is the (k + 1)-th time, represents the response delay rate when the iteration number is the (k + 1)-th time, represents the confidentiality rate when the iteration number is the (k + 1)-th time, represents the value corresponding to the analysis result data when the iteration number is the k-th time, represents the enhancement factor when the iteration number is the (k + 1)-th time; Among them, the enhancement factor is implemented by a cyclic recursive activation function, and the cyclic recursive activation function is obtained according to the following formula: Among them, represents the value of the recursive excitation function in the (k + 1)-th iteration loop; C Gmax represents the historical maximum access success rate, E Gmin represents the historical minimum data delay rate, W Gmin represents the historical minimum confidentiality rate; represents the value corresponding to the analysis result data in the k-th iteration; represents the value corresponding to the analysis result data before iteration.
7. A zero-trust access control device, which is respectively connected to a resource demand device and a data resource server, and the zero-trust access control device includes: An acquisition module configured to acquire the resource access demand of the resource demand device; An analysis module configured to analyze the resource access demand to determine a data resource acquisition plan; An application module configured to apply for data resources from the data resource server according to the data resource acquisition plan, so that the data resource server provides data resources for the resource demand device based on the data resource acquisition plan, and the data resource server and the resource demand device are in different regions; Among them, the resource access demand includes data to be analyzed; Analyzing the resource access demand to determine a data resource acquisition plan includes: analyzing the data to be analyzed by using a multivariate cubic regression algorithm to obtain analysis result data; determining the data resource acquisition plan according to the analysis result data; The resource access demand further includes: evaluation parameters; Determining the data resource acquisition plan according to the analysis result data includes: evaluating the analysis result data based on the evaluation parameters to determine the data resource acquisition plan; Evaluating the analysis result data based on the evaluation parameters to determine the data resource acquisition plan includes: Obtaining the data resource acquisition plan by using the following formula: Among them, MinZ k represents the value corresponding to the data resource acquisition scheme in the k-th iteration; i represents the first dimension, j represents the second dimension, t represents the third dimension, where i ∈ [1, m], j ∈ [1, n], t ∈ [1, p], and m, n, p respectively represent the maximum values of the dimensions; represents the access success rate at the k-th iteration, is the response delay rate at the k-th iteration, is the confidentiality rate at the k-th iteration; C Gmax represents the maximum access success rate, E Gmin represents the minimum response delay rate, W Gmin represents the minimum confidentiality rate; represents the value corresponding to the data to be analyzed; represents the value corresponding to the analysis result data at the k-th iteration; represents the value corresponding to the analysis result data before iteration.
Citation Information
Patent Citations
Method, device and system for acquiring monitoring data
CN112437086A
Database fine-grained access control method based on zero-trust architecture
CN113051602A