Terminal access point determination method and device, electronic equipment and storage medium
By building an access situation prediction model and a user trust assessment model, and combining user needs and network situation, we optimize access point selection, addressing the security risks and reduced network performance caused by user terminals selecting the access point with the strongest signal, and achieving higher network security and service quality.
Patent Information
- Application Number
- CN202210083239.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-01-25
- Publication Date
- 2025-10-17
- Estimated Expiration
- 2042-01-25
AI Technical Summary
In the prior art, user terminals select the access point with the strongest signal to access, which leads to the security risk of pseudo base stations, reduced overall network performance and security, and poor network service quality and user experience quality.
By building an access situation prediction model and a user trust assessment model, combined with user needs, network situation and user behavior information, the access situation is predicted and the user trust level is evaluated, thereby optimizing access point selection and ensuring that the access point meets user needs and trust levels.
The accuracy of access point determination is improved, the network service quality and user experience quality are enhanced, and the network security capabilities and user security experience are enhanced.
Smart Images

Figure CN114423007B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the fields of wireless service support and network security, and in particular to a method, device, electronic device, and storage medium for determining a terminal access point. Background Art
[0002] With the development of network technology, authentication and access control technologies have emerged to meet user needs and improve network performance. Access point selection is the core of authentication and access control technology. Access point selection is the process of choosing between several available wireless access points.
[0003] In existing access authentication methods, user terminals often select the access point with the strongest signal strength for access, which poses a security risk of fake base stations. Furthermore, due to different services, the number of terminals connected and the bandwidth usage of different access points will vary. Therefore, if user terminals continue to select the access point with the strongest signal strength according to traditional methods, the overall network throughput and security will be reduced, thereby degrading the network's service quality and user experience. Summary of the Invention
[0004] In view of this, the purpose of this application is to provide a method, device, electronic device, and storage medium for determining a terminal access point. By combining information such as user needs, network status, and user behavior, the method predicts access status and evaluates user trust levels, thereby achieving optimized reasoning for access points. This ensures that the determined access points meet user needs and user trust levels, improves the accuracy of access point determination, effectively enhances the network's service quality and user experience quality, and improves the network's security capabilities and user security experience.
[0005] In a first aspect, an embodiment of the present application provides a method for determining a terminal access point, the method comprising:
[0006] Receiving a service access requirement sent by a target user through a user terminal; wherein the service access requirement includes a target service requirement, a security requirement, and a service quality requirement;
[0007] Determining, based on the location information of the target user, at least one access point within a coverage area corresponding to the location information;
[0008] Use the pre-built access situation prediction model to predict the access situation of each access point and obtain the predicted situation information corresponding to each access point;
[0009] Evaluate the trust level of the target user according to the service access requirements and a pre-built user trust evaluation model to obtain trust level information of the target user;
[0010] According to the trust level information of the target user and the predicted situation information of each access point, a target access point is determined from at least one access point, and the target access point is sent to the user terminal, so that the user terminal accesses the micro-service application through the target access point.
[0011] Further, the access situation prediction model is constructed by the following steps:
[0012] For each historical user accessing the network, the network situation information of the historical user in each historical service access time window is parameterized to obtain network historical situation information associated with the historical user; wherein the network historical situation information associated with the historical user includes user identity description parameters, network security description parameters, network performance description parameters and authentication scheme description parameters;
[0013] The historical access information generated by the historical user under the historical access behavior is obtained;
[0014] The constructed time series analysis model is trained by using the network historical situation information and the historical access information of each historical user, so as to obtain the access situation prediction model.
[0015] Further, the access situation of each access point is predicted by using the pre-constructed access situation prediction model to obtain the predicted situation information corresponding to each access point, including:
[0016] The user behavior portrait is constructed by using the historical access information of each historical user;
[0017] Based on the user behavior portrait, the service access demand and the time information of the target user sending the service access demand through the user terminal, the predicted access behavior information of the target user under the service access demand is determined;
[0018] Based on the predicted access behavior information, the predicted situation information corresponding to each access point is determined by using the access situation prediction model.
[0019] Further, the user trust evaluation model is constructed by the following steps:
[0020] For each historical user accessing the network, the network situation information of the historical user in each historical service access time window is parameterized to obtain network historical situation information associated with the historical user; wherein the network historical situation information associated with the historical user includes user identity description parameters, network security description parameters, network performance description parameters and authentication scheme description parameters;
[0021] obtaining historical access demand of the historical user and access information generated by the historical user in historical access behavior;
[0022] associating the historical access demand of each historical user with the historical access information of the historical user, and calculating behavior deviation degree of each historical user under each historical access information;
[0023] constructing a first correlation analysis sub-model based on the historical access demand, the historical access information and the behavior deviation degree; wherein the first correlation analysis sub-model is used to represent historical access information of each historical user under each historical access demand, and behavior deviation degree of each historical user under different historical access information;
[0024] associating the historical access information of each historical user with network historical situation information, and calculating network situation influence degree of each historical user under each network historical situation information;
[0025] constructing a second correlation analysis sub-model based on the historical access information, the network historical situation information and the network situation influence degree; wherein the second correlation analysis sub-model is used to represent network historical situation information of each historical user under each historical access demand, and network situation influence degree of each historical user under different network historical situation information;
[0026] obtaining the user trust evaluation model based on the first correlation analysis sub-model and the second correlation analysis sub-model.
[0027] Further, according to the business access demand and the pre-constructed user trust evaluation model, the trust level of the target user is evaluated to obtain the trust level information of the target user, including:
[0028] According to each historical business access demand of the target user, the first correlation analysis sub-model in the user trust evaluation model is used to determine the historical access information corresponding to each historical business access demand of the target user, and the behavior deviation degree of the target user under each historical access information;
[0029] According to each historical access information of the target user, the second correlation analysis sub-model in the user trust evaluation model is used to determine the network historical situation information of the target user under each historical access demand, and the network situation influence degree of the target user under each network historical situation information;
[0030] According to the behavior deviation degree of the target user under each historical access information, the network situation influence degree of the target user under each network historical situation information, the trust level information of the target user is determined.
[0031] Further, the determining the target access point from the at least one access point according to the trust level information of the target user and the predicted situation information of each access point comprises:
[0032] judging whether the trust level information of the target user reaches a preset level threshold;
[0033] if yes, integrating the target service requirement, the security requirement and the quality of service requirement of the target user, and taking the access point with the highest comprehensive rating in the multiple access points as the target access point, wherein the comprehensive rating represents a comprehensive rating corresponding to the service, the security capability and the quality of service of each access point;
[0034] if no, sorting each access point according to the security level of each access point, and taking the access point with the highest security level in the multiple access points as the target access point, wherein the security level represents a level corresponding to the configured security measure of each access point.
[0035] Further, after the target access point is determined from the at least one access point according to the trust level information of the target user and the predicted situation information of each access point, the determining method further comprises:
[0036] judging whether the trust level information of the target user reaches a preset level threshold;
[0037] if yes, integrating the target service requirement, the security requirement and the quality of service requirement of the target user, and taking the access scheme with the highest comprehensive rating in the multiple access schemes as the target access scheme, wherein the comprehensive rating represents a comprehensive rating corresponding to the access authentication efficiency and the security protection capability of each access scheme;
[0038] if no, sorting each access scheme according to the access verification strictness of each access scheme, and taking the access scheme with the highest access verification strictness in the multiple access schemes as the target access scheme, wherein the access verification strictness represents the complexity of the verification algorithm of each access scheme, and the attribute, the quantity and the perfection degree of the authentication factor required to be provided by the target user;
[0039] sending the target access scheme to the user terminal, so that the user terminal provides the required authentication information according to the target access scheme.
[0040] In a second aspect, the embodiments of the present application further provide a determination apparatus of a terminal access point, which comprises:
[0041] The service access demand receiving module is configured to receive a service access demand sent by a target user through a user terminal, wherein the service access demand comprises a target service demand, a security demand and a quality of service demand.
[0042] The access point determining module is configured to determine at least one access point within a coverage range corresponding to the location information of the target user based on the location information of the target user.
[0043] The predicted situation information determining module is configured to predict an access situation of each access point by using a pre-constructed access situation prediction model, and obtain predicted situation information corresponding to each access point.
[0044] The trust level information determining module is configured to evaluate a trust level of the target user according to the service access demand and a pre-constructed user trust evaluation model, and obtain trust level information of the target user.
[0045] The target access point determining module is configured to determine a target access point from the at least one access point according to the trust level information of the target user and the predicted situation information of each access point, and send the target access point to the user terminal, so that the user terminal accesses the micro-service application through the target access point.
[0046] In a third aspect, an electronic device is provided, which comprises a processor, a memory and a bus. The memory stores machine readable instructions executable by the processor. When the electronic device is running, the processor communicates with the memory through the bus. The machine readable instructions are executed by the processor to perform the steps of the method for determining a terminal access point as described above.
[0047] In a fourth aspect, a computer readable storage medium is provided, which stores a computer program. When the computer program is run by a processor, the steps of the method for determining a terminal access point as described above are performed.
[0048] The terminal access point determination method provided by the application compares with the determination method in the prior art, by constructing a user trust evaluation model and a network state prediction model, combining user demand, network situation, user behavior and other information, realizing prediction of access situation, evaluation of user trust, realizing access point and access scheme optimization under complex access scene, complex user demand and complex network situation, expanding the traditional authentication framework to the service level, better meeting the security and service quality demand of user access authentication, maximizing network security capability and throughput, and controlling user access to ensure network security. Combining user demand, user trust state and network state multi-dimensional factors, comprehensively considering user habits and behavior characteristics, and realizing access point optimization through a time series analysis model, the method can not only meet the service quality and experience quality demand of users, but also optimize network performance and network security capability, thereby improving the overall service level and security capability of the network.
[0049] In order to make the above objectives, characteristics and advantages of the application more apparent, comprehensible and easy to understand, the following will describe a preferred embodiment in detail, with reference to the accompanying drawings. BRIEF DESCRIPTION OF DRAWINGS
[0050] In order to more clearly illustrate the technical solutions of the embodiments of the application, the following will briefly introduce the drawings needed to be used in the embodiments, and it should be understood that the following drawings only show some of the embodiments of the application, and therefore should not be considered as a limitation to the scope, and for those skilled in the art, other related drawings can also be obtained without creative labor on the basis of these drawings.
[0051] Figure 1 A flowchart of a terminal access point determination method provided by the embodiments of the application;
[0052] Figure 2 A structural diagram of a terminal access point determination device provided by the embodiments of the application;
[0053] Figure 3 A structural diagram of another terminal access point determination device provided by the embodiments of the application;
[0054] Figure 4 A structural diagram of an electronic device provided by the embodiments of the application. DETAILED DESCRIPTION
[0055] To make the purposes, technical solutions, and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application and are not all the embodiments of the present application. The components of the embodiments of the present application described and shown in the drawings herein can be arranged and designed in various different configurations. Therefore, the following detailed description of the embodiments of the present application provided in the drawings is not intended to limit the scope of the claimed present application, but only represents selected embodiments of the present application. Based on the embodiments of the present application, every other embodiment obtained by a person skilled in the art without creative work belongs to the scope of protection of the present application.
[0056] 6G (6th generation wireless systems, the sixth generation of mobile communication technology) network will face the trend of cloud, and will realize intelligent connection and three-dimensional dense coverage connection on the basis of the existing fifth generation mobile communication network. The design of the fifth generation mobile communication network mainly faces three scenes: enhanced mobile broadband, high reliability and low latency, and massive machine type communication, to realize the interconnection of all things between people, things and people. In this case, as the first layer of security for mobile communication network, 5G (5th Generation Mobile Communication Technology, the fifth generation of mobile communication technology) proposes two authentication frameworks, 5G-AKA and EAP-AKA', aiming to provide unified access authentication capability, realize the unification of authentication parameter distribution form, authentication parameter and key parameter generation form, access authentication scene, and authentication framework, and ensure to provide a secure authentication mechanism and process for different types of terminals, and lay a foundation for secure service access.
[0057] Authentication and access control is a concept generated on the basis of traditional access authentication. With the development of network technology, in order to meet the needs of users and improve network performance, authentication and access control technology emerges as the times require. Authentication access point selection and authentication scheme selection are the core links of authentication and access control technology. Authentication access point selection is to select between several available APs, and authentication scheme selection is to select appropriate access authentication protocol and algorithm for users. Authentication and access control can be divided into two orientations, namely user side orientation and network side orientation, the former pays more attention to user demand, and the latter pays more attention to network state. The existing research on access point selection is more inclined to the latter, and the selection of access scheme is more inclined to the former.
[0058] The appeal of heterogeneous network integration has a long history. With the development of wireless communication technology, various heterogeneous and different networks will jointly provide users with ubiquitous interconnection and heterogeneous integrated communication services. With the development of 5G / 6G related technologies, multi-dimensional integration through coverage integration, service integration, user integration, system integration, and system integration between heterogeneous networks can improve network performance and service level, which has become the focus of the industry in recent years. Coverage integration, that is, complementary coverage between heterogeneous networks, expands the overall coverage of the network, making the network scalable. Service integration, that is, providing similar and different network service services while supporting traditional services, realizes the expansion of service capabilities. User integration, that is, providing services using the same user identity (code number), user identity is unique, unified billing, user side on-demand access to services, and network side on-demand scheduling of network resources. System integration, that is, using the same or similar architecture, transmission and switching technology, saving infrastructure construction cost. System integration, that is, heterogeneous networks form a unified whole, provide users with consistent services, and use collaborative resource scheduling, consistent service quality, and seamless roaming between stars and ground.
[0059] Cloud native is a software architecture idea based on cloud infrastructure and a set of methodologies for software development based on the cloud. Microservices (or microservices architecture) is a cloud native architecture method in which a single application is composed of many loosely coupled and independently deployable smaller components or services. Under the trend and background of 6G network cloudization, future network services, and even authentication and access control will be more service-oriented and based on services, that is, users will be provided with selectable authentication through microservices, and access authentication and control according to the type of business the user expects to access.
[0060] According to the above research summary, with the start of 6G research, the current 5G access authentication scheme 5G-AKA and EAP-AKA' have certain single solidification problems, and the scalability is relatively poor, which is difficult to adapt to the access authentication needs of future multi-type terminals. At the same time, 6G networks will face the trend of cloudization, and user access will be more service-oriented. Different service slices will have different quality of service and security requirements; heterogeneous networks will be deeply integrated, and access points will be densely covered. The load and security state of different access points will affect the user's access experience and the network's overall throughput.
[0061] Based on this, the embodiment of the present application provides a terminal access point determination method, which solves the problem that in the prior art, because the user terminal selects the access point with the strongest signal according to the traditional method for access, the user side faces the security risk of pseudo base station, the overall performance and security of the network side are reduced, and the quality of network service and user experience is poor.
[0062] Please refer to Figure 1 , Figure 1A flowchart of a terminal access point determination method provided by an embodiment of the present application is shown in FIG. 1. As shown in FIG. 1, the terminal access point determination method provided by the embodiment of the present application includes the following steps. Figure 1 A terminal access point determination method provided by an embodiment of the present application is shown in FIG. 1. As shown in FIG. 1, the terminal access point determination method provided by the embodiment of the present application includes the following steps.
[0063] In step S101, a service access demand sent by a target user through a user terminal is received.
[0064] It should be noted that the target user refers to a user who currently wants to access a network. The user terminal refers to a mobile terminal used by the user when accessing the network, such as a mobile phone, a computer, a satellite terminal, an Internet of Things device, etc., which is not limited in the present application. The service access demand includes a target service demand, a security demand, and a quality of service demand. Specifically, the target service demand refers to a service that the target user expects to access. The security demand refers to a demand for security in the network, for example, the security demand can include a security demand for an authentication scheme, a security protection capability demand of the network, etc., which is not limited in the present application. The quality of service demand refers to a QoS (Quality of Service) demand, which mainly focuses on the bandwidth demand, the delay demand, and the packet loss rate demand of the service, etc., which is not limited in the present application. As an optional implementation, the service access demand can also include user identity information, for example, the user identity information can include a user-declared identity ID, and user fingerprint information that is not tamperable by the access network side, etc., which is not limited in the present application.
[0065] In response to a click operation of a specific key by the target user through the user terminal, the service access demand sent by the target user through the user terminal is received in the implementation of step S101.
[0066] In step S102, at least one access point in a coverage range corresponding to the location information of the target user is determined based on the location information of the target user.
[0067] It should be noted that the location information refers to the location information of the target user when accessing the network. The coverage range refers to the coverage range of the signal corresponding to the location information. The access point refers to a device for accessing the network by the user terminal of the wireless local area network. Here, the access point can include WiFi, a base station, a satellite, etc., which is not limited in the present application.
[0068] In the implementation of step S102, at least one access point in a coverage range corresponding to the location information of the target user is determined according to the current location information of the target user. Here, since the 6G network access point will achieve dense coverage, a single location of the target user will be covered by different access points, such as WiFi, a base station, a satellite, etc., and all access points in the coverage range corresponding to the location information of the target user are determined according to the location information of the target user.
[0069] S103, predicting the access situation of each access point by using the pre-constructed access situation prediction model, to obtain the prediction situation information corresponding to each access point.
[0070] It should be noted that the access situation refers to the changes of the access point and the network due to the user access when the user accesses the network through the access point. The access situation herein includes the situation of the network and the situation of the access point. As an example, the situation of the access point can be how many users are accessing the access point, the resource occupation of the access point, the average packet loss rate and latency of access through the access point, etc. The situation of the network can include the average packet loss rate and latency, etc. The access situation prediction model is used to predict the comprehensive multi-user access situation information generated in the target service access time window when the target user accesses a certain access point. Specifically, the prediction situation information can also include the situation of the network and the situation of the access point.
[0071] For the above step S103, in specific implementation, after determining the at least one access point, the access situation of each access point is predicted by using the pre-constructed access situation prediction model, to obtain the prediction situation information corresponding to each access point.
[0072] As an optional implementation, the access situation prediction model is constructed by the following steps:
[0073] A: for each historical user accessing the network, parameter extraction is performed on the network situation information of the historical user in each historical service access time window, to obtain the network historical situation information associated with the historical user; wherein the network historical situation information associated with the historical user includes a user identity description parameter, a network security description parameter, a network performance description parameter and an authentication scheme description parameter.
[0074] It should be noted that historical users refer to all users who have accessed the network within the historical time. The historical service access time window refers to the time window in which historical users access services when accessing the network. It can be considered as a time range. For example, a user accesses the network from 20:00 to 21:00 during a certain service access. Therefore, 20:00 to 21:00 is a historical service access time window in the historical information. Network situation information refers to the security situation and performance situation of the network. The security situation can be the frequency of attacks, the security status level of the network to be accessed, and the threats received. The performance situation can be the load, resource status, latency, and packet loss rate of the network or access point. This application does not make specific restrictions on this. Network historical situation information refers to the network situation information associated with historical users when they access the network through an access point within the historical service access time window. Among them, the network historical situation information includes user identity description parameters, network security description parameters, network performance description parameters, and authentication scheme description parameters. User identity description parameters are used to characterize user identities, including the tamper-proof description of user identity information obtained by the access point. Network security description parameters describe the network's security status within a specified time window. Network performance description parameters describe the network's performance within a specified time window. Authentication scheme description parameters describe the performance of different authentication schemes, including computational overhead, bandwidth overhead, and latency overhead. Table 1 shows the parameter definitions for network historical status information.
[0075] Table 1 Parameter definitions of network historical situation information
[0076]
[0077]
[0078] Regarding the above step A, during specific implementation, for each historical user accessing the network, parameters of the network situation information of the historical user in each historical service access time window are extracted to obtain each network historical situation information in Table 1 above.
[0079] B: Obtain the access information generated by the historical user under historical access behavior.
[0080] It should be noted that the historical access behavior refers to the access behavior performed by the historical user after accessing the network through the access point. The access information refers to the access information generated by the historical user when performing the historical access behavior. Specifically, the access information can include a service access start time, a service access duration, an accessed service type, a historical access point, a historical access scheme, an average occupied bandwidth, a peak occupied bandwidth, a threat level of the historical user, etc. The service access start time refers to the start time of the historical user when accessing the target service. The service access duration refers to the duration of the historical user when accessing the target service. The accessed service type refers to the type of the target service accessed by the historical user. The historical access point refers to the access point used by the historical user to access the network. The historical access scheme refers to the access scheme used by the historical user to access the network. The average occupied bandwidth and the peak occupied bandwidth describe the bandwidth occupied by the historical user when accessing the network. The threat level refers to the threat level of the historical user to the network. Specifically, the threat level is calculated according to the sensitive security event record. The threat level is calculated as shown in the following formula:
[0081]
[0082] wherein i represents a security event classification, count(event i ) represents the number of times of occurrence of the security event i, w i represents the threat weight corresponding to the security event i, and threshold is a preset threat level threshold. Obviously, the network side cannot allow the user to perform service access after initiating an explicit and high-risk behavior, so part of the high-risk behaviors (such as uploading a Trojan backdoor) should be assigned to threshold and the user access should be blocked in time. Therefore, the final calculation result of the formula is: if the user initiates an explicit and high-risk behavior, the threat level thereof is threshold; if the threat level of the user is low, the weight calculation is used as the standard; if the user does not initiate an explicit and high-risk behavior, but the comprehensive threat level of the suspected attack event initiated by the user exceeds threshold, the threat level thereof is also assigned to threshold.
[0083] For the above step B, in specific implementation, for each historical user accessing the network, various access information generated by the historical user in the historical access behavior is acquired.
[0084] C: Using the network historical situation information and the historical access information of each historical user, the constructed time series analysis model is trained to obtain the access situation prediction model.
[0085] For the above step C, in specific implementation, the constructed time series analysis model is trained by using the network historical situation information and the historical access information of each historical user, to obtain the access situation prediction model. Specifically, how to train the time series analysis model by using the known parameters is described in detail in the prior art, and will not be repeated here.
[0086] After the access situation prediction model is constructed, the access situation of each access point can be predicted by using the constructed access situation prediction model. For the above step S103, the access situation of each access point is predicted by using the pre-constructed access situation prediction model, to obtain the predicted situation information corresponding to each access point, including:
[0087] In step 1031, a user behavior portrait is constructed by using the historical access information of each historical user.
[0088] It should be noted that the user behavior portrait (User Profile) is user information tagging, that is, after collecting and analyzing the data of the main information such as user social attributes, living habits and consumption behavior, a perfect commercial profile of a user is abstracted. The user behavior portrait provides sufficient information basis, which can quickly find precise user groups and more extensive feedback information such as user demand. Specifically, the user behavior portrait can include the access habits of the user, such as the user habit of accessing which business at which time, and even the bandwidth occupied by the user when accessing the business, which can be described by the user behavior portrait, which is not limited by the present application.
[0089] For the above step 1031, in specific implementation, the user behavior portrait is constructed by using the historical access information of each historical user accessing the network. Specifically, how to construct the user behavior portrait by using the known data of each user is described in detail in the prior art, and will not be repeated here.
[0090] In step 1032, based on the user behavior portrait, the business access demand and the time information of the target user sending the business access demand through the user terminal, the predicted access behavior information of the target user under the business access demand is determined.
[0091] It should be noted that the time information of the target user sending the business access demand through the user terminal refers to the time when the target user requests to access the network on the user terminal, for example, the time information can be 15:30, which is not limited by the present application. The predicted access behavior information refers to the predicted access behavior of the target user under the current business access demand.
[0092] For the above step 1032, in a specific implementation, the predicted access behavior information of the target user under the current service access demand is determined by using the user behavior portrait built in step 1032 and the time information of the target user sending the service access demand through the user terminal. Here, since the user behavior portrait describes the historical user habit of frequently accessing what service in which time period and under what demand, the predicted access behavior information that the target user is likely to perform can be directly predicted based on the service access demand and the time information of the target user sending the service access demand through the user terminal by using the built user behavior portrait. For example, it is known from the user behavior portrait that most historical users generate access behavior information B when sending service access demand A at 15:30, so when the target user sends service access demand A at 15:30, it can be predicted that the predicted access behavior information of the target user under the service access demand is B.
[0093] Step 1033, based on the predicted access behavior information, using the access situation prediction model to determine the predicted situation information corresponding to each access point.
[0094] For the above step 1033, in a specific implementation, the predicted situation information corresponding to each access point is predicted by using the built access situation prediction model. Here, since the access situation prediction model is built based on the network historical situation information and historical access information of the historical user, after the predicted access behavior information of the target user is determined in step 1032, the predicted access behavior information is input into the built access situation prediction model to predict the network situation after the target user accesses each access point, that is, to determine the predicted situation information corresponding to each access point.
[0095] S104, according to the service access demand and the pre-built user trust evaluation model, the trust level of the target user is evaluated, and the trust level information of the target user is obtained.
[0096] It should be noted that the user trust evaluation model refers to a model for evaluating the trust level information of the user. The trust level information refers to the degree to which the target user can be trusted by the network.
[0097] For the above step S104, in a specific implementation, the trust level of the target user is evaluated according to the service access demand sent by the target user through the user terminal and the pre-built user trust evaluation model, so as to obtain the trust level information of the target user.
[0098] As an optional implementation, the user trust evaluation model is built by the following steps:
[0099] a: for each historical user accessing the network, parameter extraction is performed on network situation information of the historical user in each historical service access time window to obtain network historical situation information associated with the historical user; wherein the network historical situation information associated with the historical user comprises a user identity description parameter, a network security description parameter, a network performance description parameter and an authentication scheme description parameter.
[0100] Here, the description of step a can refer to the description of step A and achieve the same technical effects, and thus will not be described here.
[0101] b: obtaining historical access demand of the historical user and access information generated by the historical user in historical access behavior.
[0102] It should be noted that the historical access demand refers to the access demand sent by the user terminal of the historical user when the historical user accesses the network in the historical time, and the historical access demand here can also include historical service demand, historical security demand and historical service quality demand.
[0103] For step b, for each historical user accessing the network, historical access demand of the historical user and access information generated by the historical user in historical access behavior are obtained. Here, the description of obtaining the access information generated by the historical user in the historical access behavior can refer to the description of the access information generated by the historical user in the historical access behavior in step B and achieve the same technical effects, and thus will not be described here.
[0104] c: associating the historical access demand of each historical user with the historical access information of the historical user, and calculating the behavior deviation degree of each historical user in each historical access information.
[0105] It should be noted that the behavior deviation degree refers to the degree of inconsistency between the access demand sent by the user and the generated access behavior.
[0106] For the above step c, in the implementation, for each historical user, the historical access demand and the historical access information of the historical user are associated, and the behavior deviation degree of the historical user under each generated historical access information is calculated according to the historical access demand and the historical access information of the historical user. Here, in the implementation, the access demand and the access information of some historical users are corresponding, for example, the historical access demand of a historical user A is to request access to a service A in a certain behavior mode, and the historical access information of the historical user A also indicates that the historical user A accesses the service A in the conventional behavior mode under the historical access demand, so it is considered that the access demand and the access behavior of the historical user A do not deviate, and the behavior deviation degree is low. However, it is also possible that the historical access demand of a historical user B at a certain time is to request access to a service A, but the historical access information of the historical user B indicates that the historical user B does not access the service A, and may access other services, or performs some operations that do not conform to the conventional behavior mode in the access process, such as port scanning, so it is considered that the access demand and the access behavior of the historical user B deviate, and the behavior deviation degree is high. As an optional implementation, the actual deviation degree of the historical access demand and the historical access behavior of the historical user can be calculated by a preset deviation degree algorithm. The more deviation, the higher the degree of inconsistency between demand and behavior, and the less trusted by the system.
[0107] d: constructing a first correlation analysis sub-model based on the historical access demand, the historical access information and the behavior deviation degree.
[0108] It should be noted that the first correlation analysis sub-model is a correlation analysis model of user demand and user behavior, wherein the first correlation analysis sub-model is used to represent the historical access information of each historical user under each historical access demand, and the behavior deviation degree of each historical user under different historical access information.
[0109] For the above step d, in the implementation, the historical access demand, the historical access information and the behavior deviation degree of each historical user are used to construct the first correlation analysis sub-model, that is, the historical access demand, the historical access information and the behavior deviation degree of each historical user are associated through the identity ID of the historical user, and are stored in the first correlation analysis sub-model in a mapping relationship.
[0110] e: associating the historical access information of each historical user with the network historical situation information, and calculating the network situation influence degree of each historical user under each network historical situation information.
[0111] It should be noted that the network situation influence degree refers to the degree of influence of the user on the network and the access point when accessing the network through the access point.
[0112] For the above step e, in a specific implementation, for each historical user, the historical access information and the network historical situation information of the historical user are associated, and the network situation influence degree of the historical user under each generated network historical situation information is calculated according to the historical access information and the network historical situation information of the historical user. Here, in a specific implementation, for example, a historical user C initiates a DoS (Denial of Service) attack after accessing the network. The DoS attack refers to an intentional attack on the defects of network protocol implementation or a brutal and ruthless depletion of the resources of the attacked object through brute force, aiming to make the target computer or network unable to provide normal service or resource access, so that the target system service system stops responding or even crashes. When the historical user initiates the DoS attack, the resources and performance of the network will be severely reduced, and therefore the influence degree of the historical user on the network will be recorded. Or a historical user D maliciously occupies bandwidth resources to download some files, although the behavior cannot be considered as a network attack, but also affects the network situation. As an optional implementation, the influence degree of the historical user on the network situation can be calculated by a preset network situation influence degree algorithm.
[0113] f: constructing a second correlation analysis sub-model based on the historical access information, the network historical situation information and the network situation influence degree.
[0114] It should be noted that the second correlation analysis sub-model is a correlation analysis model of users and network situation, wherein the second correlation analysis sub-model is used to represent the network historical situation information of each historical user under each historical access demand, and the network situation influence degree of each historical user under different network historical situation information.
[0115] For the above step f, in a specific implementation, the historical access information, the network historical situation information and the network situation influence degree of each historical user are used to construct the second correlation analysis sub-model, that is, the historical access information, the network historical situation information and the network situation influence degree of each historical user are associated through the identity ID of the historical user, and are stored in the second correlation analysis sub-model in a mapping relationship.
[0116] g: obtaining the user trust evaluation model based on the first correlation analysis sub-model and the second correlation analysis sub-model.
[0117] For the above step g, in a specific implementation, the first correlation analysis sub-model and the second correlation analysis sub-model are combined to obtain the user trust evaluation model.
[0118] After the user trust evaluation model is constructed, the trust level of the target user can be evaluated by using the constructed user trust evaluation model. For the above step S104, the trust level of the target user is evaluated according to the business access demand and the pre-constructed user trust evaluation model, and the trust level information of the target user is obtained, including:
[0119] Step 1041, according to each historical business access demand of the target user, the first correlation analysis sub-model in the user trust evaluation model is used to determine the historical access information corresponding to each historical business access demand of the target user, and the behavior deviation degree of the target user under each historical access information.
[0120] For the above step 1041, in specific implementation, since the historical access demand and the historical access information of each historical user in the first correlation analysis sub-model of the user trust evaluation model are associated, the first correlation analysis sub-model can be used to determine the historical access information corresponding to each historical business access demand of the target user based on each historical business access demand of the target user. For example, the same historical access demand as the historical business access demand of the target user can be found in the first correlation analysis sub-model, and the historical access information associated with the historical access demand is determined as the historical access information of the target user under the historical business access demand. For each historical access information of the target user, the behavior deviation degree associated with the historical access information is determined based on the historical access information, and the behavior deviation degree is taken as the behavior deviation degree of the target user.
[0121] Step 1042, according to each historical access information of the target user, the second correlation analysis sub-model in the user trust evaluation model is used to determine the network historical situation information of the target user under each historical access demand, and the network situation influence degree of the target user under each network historical situation information.
[0122] For the above step 1042, in specific implementation, since the historical access information of each historical user and the network historical situation information are associated in the second correlation analysis sub-model in the user trust evaluation model, the second correlation analysis sub-model can be used to determine the network historical situation information corresponding to each historical access information of the target user based on each historical access information of the target user, for example, the same historical access information as the historical access information of the target user can be found in the second correlation analysis sub-model, and the network historical situation information associated with the historical access information is determined as the network historical situation information of the target user under the historical access information. For the network historical situation information of the target user, the network situation influence degree associated with the network historical situation information is determined based on the network historical situation information, and the behavior deviation degree is taken as the network situation influence degree of the target user.
[0123] Step 1043, determining the trust level information of the target user according to the behavior deviation degree of the target user under each historical access information and the network situation influence degree of the target user under each network historical situation information.
[0124] For the above step 1043, in specific implementation, after the behavior deviation degree of the target user under each historical access information and the network situation influence degree of the target user under each network historical situation information are determined, the trust level information of the target user can be determined according to the behavior deviation degree and the network situation influence degree. Specifically, a preset trust level algorithm can be used to determine the trust level information of the target user. Here, the trust level information of the target user is evaluated according to all historical access requirements and all historical access behaviors of the target user, so that the accuracy of trust level information evaluation can be improved.
[0125] S105, determining the target access point from at least one access point according to the trust level information of the target user and the predicted situation information of each access point, and sending the target access point to the user terminal, so that the user terminal accesses the micro-service application through the target access point.
[0126] It should be noted that the target access point refers to the access point used by the target user when accessing the network. The micro-service application refers to the micro-service provided by the Internet platform for the target user.
[0127] For the above step S105, in specific implementation, the target access point is determined from at least one access point according to the trust level information of the target user and the predicted situation information of each access point, and the target access point is sent to the user terminal, so that the user terminal accesses the micro-service application through the selected target access point.
[0128] For the step S105, the target access point is determined from the at least one access point according to the trust level information of the target user and the predicted situation information of each access point, including:
[0129] Step 1051, judging whether the trust level information of the target user reaches a preset level threshold.
[0130] It should be noted that the preset level threshold refers to a preset value, which can also be dynamically adjusted around the preset value, and is a level threshold for judging whether the target user can be trusted.
[0131] For the step 1051, in specific implementation, according to the trust level information of the target user, it is judged whether the trust level information of the target user reaches the preset level threshold, if yes, step 1052 is executed, if no, step 1053 is executed.
[0132] Step 1052, if yes, the target access point is the access point with the highest comprehensive rating in the multiple access points, which is determined according to the target service demand, security demand and quality of service demand of the target user.
[0133] It should be noted that the comprehensive rating represents the comprehensive rating corresponding to the service, security capability and quality of service of each access point. Specifically, the comprehensive rating of the access point can be determined according to the predicted situation information of the access point, for example, the packet loss rate and the low delay in the predicted situation information of the access point can meet the access demand of the user for a specific service and the security protection capability demand of the user, and it is considered that the comprehensive rating of the access point is high.
[0134] For the step 1052, in specific implementation, if the trust level information of the target user reaches the preset level threshold, it is considered that the target user can be trusted by the network, and the access point with the highest comprehensive rating and the most suitable demand of the target user in the multiple access points can be selected as the target access point, which provides the target access point with the optimal comprehensive throughput, the lowest delay and the optimal security capability to meet the demand of the target user.
[0135] Step 1053, if no, each access point is sorted according to the security level of each access point, and the access point with the highest security level in the multiple access points is selected as the target access point.
[0136] It should be noted that the security level represents the level corresponding to the security measures configured on each access point. Specifically, the security level of an access point can be determined based on the security measures configured on the access point. For example, a ground base station may be equipped with many security devices, so the security level of the ground base station access point is considered to be higher. However, a satellite access point has limited resources and cannot deploy a large number of supporting security devices, so the security level of the satellite access point is considered to be lower.
[0137] Regarding step 1053, during specific implementation, if the trust level information of the target user does not reach the preset level threshold, then the target user is considered to be untrustworthy by the network. In this case, each access point is sorted according to its security level, and the access point with the highest security level among the multiple access points is selected as the target access point. The target user is then directed to access an access point with more comprehensive security measures, which will more strictly verify the user's identity.
[0138] As an optional implementation, after the target access point is pushed to the target user, the target access solution needs to be pushed to the target user, so that the target user can provide the information required for the target access solution through the target access point, achieve access authentication, and access the microservice application. According to the determination method provided in this application, after determining the target access point from at least one access point based on the trust level information of the target user and the predicted situation information of each access point, the determination method also includes:
[0139] (1) determining whether the trust level information of the target user reaches a preset level threshold;
[0140] (2) If so, the target user's target business requirements, security requirements, and service quality requirements are comprehensively considered, and the access solution with the highest comprehensive rating among the multiple access solutions is selected as the target access solution.
[0141] Here, the access scheme can be considered as an access authentication algorithm, such as the existing authentication based on the SIM (Subscriber Identity Module, user identification) card, or cross-layer authentication combined with physical layer information, etc., which is not specifically limited in this application. These access authentication algorithms have different algorithm processes and require users to provide different information, so they can be regarded as different access schemes. As an example, if it is a calling service, the access scheme may be authentication based on the SIM card. If network management, network operation and other operations are involved, users need to be highly trusted, and users can be required to perform authentication combined with physical layer information. The comprehensive rating represents the comprehensive rating corresponding to the access authentication efficiency and security protection capabilities of each access scheme. The higher the access authentication efficiency and the higher the security protection capability of the access scheme, the higher the comprehensive rating of the access scheme is considered to be.
[0142] For the above step (2), in the specific implementation, if the trust level information of the target user reaches the preset level threshold, it is considered that the target user can be trusted by the network, and the access scheme with the highest comprehensive evaluation among the multiple access schemes is determined as the target access scheme, that is, the access scheme with the highest access authentication efficiency and the highest security protection capability.
[0143] (3) If not, each access scheme is sorted according to the access verification strictness of each access scheme, and the access scheme with the highest access verification strictness among the multiple access schemes is taken as the target access scheme.
[0144] Here, the access verification strictness represents the complexity of the verification algorithm of each access scheme, as well as the attributes, quantity and perfection degree of the authentication factors required to be provided by the target user.
[0145] For the above step (3), in the specific implementation, if the trust level information of the target user does not reach the preset level threshold, it is considered that the target user cannot be trusted by the network, and the access scheme with the highest access verification strictness among the multiple access schemes is taken as the target access scheme.
[0146] (4) The target access scheme is sent to the user terminal, so that the user terminal provides the required authentication information according to the target access scheme.
[0147] Here, the authentication information refers to the information provided by the user terminal for authentication according to the target access scheme. For example, when the target access scheme is an access scheme with low verification strictness, the authentication information can be the password of the target user, and when the target access scheme is an access scheme with high verification strictness, the authentication information can be the fingerprint or other biological characteristics of the target user.
[0148] For the above step (4), in the specific implementation, after the target access scheme is determined, the target access scheme is sent to the user terminal, and the user terminal can provide the authentication information through the pushed target access scheme to realize the authentication of the target user.
[0149] The method for determining a terminal access point provided in the embodiments of the present application determines at least one access point according to the location information of a target user, and predicts the access situation of each access point by using a pre-constructed access situation prediction model to obtain the prediction situation information corresponding to each access point; the trust level of the target user is evaluated according to the historical service access demand and historical access information of the target user to obtain the trust level information of the target user, and finally the target access point is determined from the at least one access point according to the trust level information of the target user and the prediction situation information of each access point, and the target access point is sent to the user terminal, so that the user terminal accesses the micro-service application through the target access point. The method for determining a terminal access point provided in the present application compares with the determination method in the prior art, by constructing a user trust evaluation model and a network state prediction model, combining user demand, network situation, user behavior and other information, the prediction of the access situation and the evaluation of the user trust are realized, the access point and the access scheme optimization under the complex access scene, complex user demand and complex network situation are realized, the traditional authentication framework is expanded to the service level, the security and service quality demand of the user's access authentication are better met, the network security capability and throughput are maximized, and the user access is controlled to ensure the network security. Combining the user demand, user trust state and network state multi-dimensional factors, comprehensively considering the user habits and behavior characteristics, the access point optimization is performed through a time series analysis model, which not only can meet the service quality and experience quality demand of the user, but also can optimize the network performance and network security capability, so as to improve the overall service level and security capability of the network.
[0150] Please refer to Figure 2 、 Figure 3 , Figure 2 FIG. 1 is a structural schematic diagram of a terminal access point determination device provided in the embodiments of the present application, Figure 3 FIG. 2 is a structural schematic diagram of another terminal access point determination device provided in the embodiments of the present application. As shown in FIG. 2, the determination device 200 comprises: Figure 2
[0151] a service access demand receiving module 201, configured to receive the service access demand sent by a target user through a user terminal; wherein the service access demand comprises target service demand, security demand and service quality demand;
[0152] an access point determination module 202, configured to determine at least one access point in the coverage range corresponding to the location information of the target user based on the location information of the target user;
[0153] a prediction situation information determination module 203, configured to predict the access situation of each access point by using a pre-constructed access situation prediction model to obtain the prediction situation information corresponding to each access point;
[0154] The trust level information determination module 204 is configured to determine the trust level of the target user according to the service access demand and a pre-constructed user trust evaluation model, to obtain the trust level information of the target user.
[0155] The target access point determination module 205 is configured to determine a target access point from at least one access point according to the trust level information of the target user and the predicted situation information of each access point, and send the target access point to the user terminal, so that the user terminal accesses the micro-service application through the target access point.
[0156] Further, as shown in Figure 3 The determination apparatus 200 comprises an access situation prediction model construction module 206, which constructs the access situation prediction model by the following steps:
[0157] For each historical user accessing the network, the network situation information of the historical user in each historical service access time window is parameterized to obtain the network historical situation information associated with the historical user; wherein the network historical situation information associated with the historical user comprises a user identity description parameter, a network security description parameter, a network performance description parameter and an authentication scheme description parameter;
[0158] The historical access information generated by the historical user under the historical access behavior is obtained;
[0159] The constructed time series analysis model is trained by using the network historical situation information and the historical access information of each historical user, to obtain the access situation prediction model.
[0160] Further, when the prediction situation information determination module 203 is configured to predict the access situation of each access point by using the pre-constructed access situation prediction model, to obtain the predicted situation information corresponding to each access point, the prediction situation information determination module 203 is further configured to:
[0161] A user behavior portrait is constructed by using the historical access information of each historical user;
[0162] Based on the user behavior portrait, the service access demand and the time information of the target user sending the service access demand through the user terminal, the predicted access behavior information of the target user under the service access demand is determined;
[0163] Based on the predicted access behavior information, the predicted situation information corresponding to each access point is determined by using the access situation prediction model.
[0164] Further, as shown in Figure 3As shown, the determining apparatus 200 comprises a user trust evaluation model construction module 207, which constructs the user trust evaluation model by the following steps:
[0165] For each historical user accessing the network, the network situation information of the historical user in each historical service access time window is parameterized to obtain network historical situation information associated with the historical user; wherein the network historical situation information associated with the historical user comprises user identity description parameters, network security description parameters, network performance description parameters and authentication scheme description parameters;
[0166] The historical access demand of the historical user and the access information generated by the historical user under the historical access behavior are obtained;
[0167] The historical access demand of each historical user is associated with the historical access information of the historical user, and the behavior deviation degree of each historical user under each historical access information is calculated;
[0168] A first association analysis sub-model is constructed based on the historical access demand, the historical access information and the behavior deviation degree; wherein the first association analysis sub-model is used to represent the historical access information of each historical user under each historical access demand, and the behavior deviation degree of each historical user under different historical access information;
[0169] The historical access information of each historical user is associated with the network historical situation information, and the network situation influence degree of each historical user under each network historical situation information is calculated;
[0170] A second association analysis sub-model is constructed based on the historical access information, the network historical situation information and the network situation influence degree; wherein the second association analysis sub-model is used to represent the network historical situation information of each historical user under each historical access demand, and the network situation influence degree of each historical user under different network historical situation information;
[0171] The user trust evaluation model is obtained based on the first association analysis sub-model and the second association analysis sub-model.
[0172] Further, when the trust level information determining module 204 is used to evaluate the trust level of the target user according to the service access demand and the pre-constructed user trust evaluation model, the trust level information determining module 204 is further used to:
[0173] According to each historical service access demand of the target user, a first correlation analysis sub-model in the user trust evaluation model is used to determine historical access information corresponding to each historical service access demand of the target user and a behavior deviation degree of the target user under each historical access information;
[0174] According to each historical access information of the target user, a second correlation analysis sub-model in the user trust evaluation model is used to determine network historical situation information of the target user under each historical access demand and a network situation influence degree of the target user under each network historical situation information;
[0175] According to the behavior deviation degree of the target user under each historical access information and the network situation influence degree of the target user under each network historical situation information, trust level information of the target user is determined.
[0176] Further, when the target access point is determined from at least one access point according to the trust level information of the target user and the predicted situation information of each access point, the target access point determination module 205 is further used to:
[0177] determine whether the trust level information of the target user reaches a preset level threshold;
[0178] If yes, an access point with the highest comprehensive rating in the multiple access points is taken as the target access point by comprehensively considering the target service demand, the security demand and the service quality demand of the target user, wherein the comprehensive rating represents a comprehensive rating corresponding to the service, the security capability and the service quality index of each access point.
[0179] If no, each access point is sorted according to the security degree of each access point, and an access point with the highest security level in the multiple access points is taken as the target access point, wherein the security level represents a level corresponding to the configured security measure of each access point.
[0180] Further, as shown in Figure 3 the determination apparatus 200 comprises a target access scheme determination module 208, which is used to:
[0181] determine whether the trust level information of the target user reaches a preset level threshold;
[0182] If yes, an access scheme with the highest comprehensive rating in the multiple access schemes is taken as the target access scheme by comprehensively considering the target service demand, the security demand and the service quality demand of the target user, wherein the comprehensive rating represents a comprehensive rating corresponding to the access authentication efficiency and the security protection capability of each access scheme.
[0183] If no, the access schemes are sorted according to the access verification strictness of each access scheme, and the access scheme with the highest access verification strictness in the multiple access schemes is taken as the target access scheme; wherein the access verification strictness represents the complexity of the verification algorithm of each access scheme, and the attribute, quantity and perfection degree of the required authentication factor provided by the target user;
[0184] The target access scheme is sent to the user terminal, so that the user terminal provides the required authentication information according to the target access scheme.
[0185] Please refer to Figure 4 , Figure 4 A structural schematic diagram of an electronic device provided by an embodiment of the present application is shown in FIG. 4. As shown in FIG. 4, the electronic device 400 includes a processor 410, a memory 420 and a bus 430. Figure 4
[0186] The memory 420 stores machine readable instructions executable by the processor 410, and when the electronic device 400 is running, the processor 410 and the memory 420 communicate through the bus 430. When the machine readable instructions are executed by the processor 410, the steps of the terminal access point determination method in the method embodiment shown in FIG. 3 can be performed, which solves the problem that in the prior art, due to the user terminal selecting the access point with the strongest signal according to the traditional method for access, the user side faces the security risk of pseudo base station, the overall performance and security of the network side are reduced, and the network service quality and user experience quality are poor. For specific implementation manners, please refer to the method embodiment, which will not be described here. Figure 1
[0187] The present application also provides a computer readable storage medium, which stores a computer program. When the computer program is run by a processor, the steps of the terminal access point determination method in the method embodiment shown in FIG. 3 can be performed, which solves the problem that in the prior art, due to the user terminal selecting the access point with the strongest signal according to the traditional method for access, the user side faces the security risk of pseudo base station, the overall performance and security of the network side are reduced, and the network service quality and user experience quality are poor. For specific implementation manners, please refer to the method embodiment, which will not be described here. Figure 1 Those skilled in the art can clearly understand that, for the convenience and brevity of description, the specific working process of the system, device and unit described above can refer to the corresponding process in the foregoing method embodiment, which will not be described here.
[0188]
[0189] In several embodiments provided in the present application, it should be understood that the disclosed system, device and method can be implemented in other manners. The described device embodiments are merely schematic, and for example, the division of the units is only a logical function division, and there can be another division manner in actual implementation; for example, a plurality of units or components can be combined or integrated into another system, or some features can be ignored or not executed. In addition, the displayed or discussed mutual couplings or direct couplings or communication connections can be indirect couplings or communication connections through some interfaces, devices or units, and can be electric, mechanical or in other forms.
[0190] The units described as separate components can or can not be physically separate, and the components shown as units can or can not be physical units, i.e., can be located in one place, or can be distributed on a plurality of network units. Some or all of the units can be selected according to actual needs to achieve the purposes of the embodiments.
[0191] In addition, each functional unit in the various embodiments of the present application can be integrated in one processing unit, or each unit can be a physically separate unit, or two or more units can be integrated in one unit.
[0192] If the functions are implemented in the form of software function units and sold or used as independent products, they can be stored in a non-volatile computer readable storage medium executable by a processor. Based on this understanding, the technical solutions of the present application essentially or the parts that make contributions to the prior art or parts of the technical solutions can be embodied in the form of a software product. The computer software product is stored in a storage medium, and includes a plurality of instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application. The aforementioned storage medium includes: a U disk, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, and various media that can store program codes.
[0193] It should be noted that: similar reference numerals and letters in the following drawings represent similar items, and therefore, once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. In addition, the terms "first", "second", "third" and the like are only used to distinguish descriptions, and cannot be understood as indicating or implying relative importance.
[0194] Finally, it should be noted that the above-described embodiments are merely specific embodiments of the present application, which are used to illustrate the technical solutions of the present application, but not to limit the same. The protection scope of the present application is not limited thereto. Although the present application has been described in detail with reference to the foregoing embodiments, it should be understood by those skilled in the art that any skilled person in the art can still modify or easily think of changes to the technical solutions recorded in the foregoing embodiments, or make equivalent replacements to some of the technical features, within the technical scope disclosed by the present application. The modifications, changes or replacements do not make the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A method for determining a terminal access point, characterized in that: The determination method includes: Receiving a service access requirement sent by a target user through a user terminal; wherein the service access requirement includes a target service requirement, a security requirement, and a service quality requirement; Determining, based on the location information of the target user, at least one access point within a coverage area corresponding to the location information; Use the pre-built access situation prediction model to predict the access situation of each access point and obtain the predicted situation information corresponding to each access point; Evaluate the trust level of the target user according to the service access requirements and a pre-built user trust evaluation model to obtain trust level information of the target user; Determining a target access point from at least one access point based on the trust level information of the target user and the predicted situation information of each access point, and sending the target access point to the user terminal, so that the user terminal accesses the microservice application through the target access point; The user trust evaluation model is constructed by the following steps: For each historical user who has accessed the network, parameters of the network status information of the historical user in each historical service access time window are extracted to obtain the historical network status information associated with the historical user; wherein the historical network status information associated with the historical user includes user identity description parameters, network security description parameters, network performance description parameters, and authentication scheme description parameters; Obtain the historical access needs of the historical user and the access information generated by the historical user under the historical access behavior; Associating each historical user's historical access needs with the historical access information of the historical user, and calculating the degree of behavioral deviation of each historical user under each historical access information; Constructing a first association analysis sub-model based on the historical access requirements, the historical access information, and the degree of behavioral deviation; wherein the first association analysis sub-model is used to characterize the historical access information of each historical user under each historical access requirement, and the degree of behavioral deviation of each historical user under different historical access information; Correlate the historical access information of each historical user with the historical network situation information, and calculate the network situation influence degree of each historical user under each historical network situation information; Constructing a second association analysis sub-model based on the historical access information, the historical network situation information, and the network situation influence degree; wherein the second association analysis sub-model is used to characterize the historical network situation information of each historical user under each historical access demand, and the network situation influence degree of each historical user under different historical network situation information; The user trust evaluation model is obtained based on the first association analysis sub-model and the second association analysis sub-model.
2. The determination method according to claim 1, characterized in that The access situation prediction model is constructed by the following steps: For each historical user who has accessed the network, parameters of the network status information of the historical user in each historical service access time window are extracted to obtain the historical network status information associated with the historical user; wherein the historical network status information associated with the historical user includes user identity description parameters, network security description parameters, network performance description parameters, and authentication scheme description parameters; Obtain the historical access information generated by the historical user under historical access behavior; The constructed time series analysis model is trained using the network historical situation information and historical access information of each historical user to obtain the access situation prediction model.
3. The determination method according to claim 2, characterized in that: The method of using a pre-built access situation prediction model to predict the access situation of each access point to obtain predicted situation information corresponding to each access point includes: Use each user's historical access information to build a user behavior profile; Determining predicted access behavior information of the target user under the service access requirement based on the user behavior profile, the service access requirement, and time information of the target user sending the service access requirement through the user terminal; Based on the predicted access behavior information, the access situation prediction model is used to determine the predicted situation information corresponding to each access point.
4. The determination method according to claim 1, characterized in that The step of evaluating the trust level of the target user according to the service access requirement and a pre-built user trust evaluation model to obtain trust level information of the target user includes: According to each historical service access demand of the target user, the first association analysis sub-model in the user trust evaluation model is used to determine the historical access information corresponding to each historical service access demand of the target user, and the degree of behavioral deviation of the target user under each historical access information; Based on each historical access information of the target user, the second association analysis sub-model in the user trust evaluation model is used to determine the target user's network historical situation information under each historical access requirement, and the target user's network situation influence degree under each network historical situation information; The trust level information of the target user is determined according to the behavior deviation degree of the target user under each historical access information and the network situation influence degree of the target user under each historical network situation information.
5. The determination method according to claim 1, characterized in that: The determining a target access point from at least one access point based on the trust level information of the target user and the predicted situation information of each access point includes: Determining whether the trust level information of the target user reaches a preset level threshold; If so, comprehensively considering the target user's target service requirements, security requirements, and service quality requirements, select the access point with the highest comprehensive rating among the multiple access points as the target access point; wherein the comprehensive rating represents the comprehensive rating corresponding to the service services, security capabilities, and service quality indicators of each access point; If not, each access point is sorted according to its security level, and the access point with the highest security level among the multiple access points is used as the target access point; wherein the security level represents the level corresponding to the configured security measures of each access point.
6. The determination method according to claim 1, characterized in that: After determining a target access point from at least one access point based on the trust level information of the target user and the predicted situation information of each access point, the determination method further includes: Determining whether the trust level information of the target user reaches a preset level threshold; If so, then comprehensively considering the target user's target business needs, security needs, and service quality needs, select the access solution with the highest comprehensive rating among the multiple access solutions as the target access solution; wherein the comprehensive rating represents the comprehensive rating corresponding to the access authentication efficiency and security protection capability of each access solution; If not, sorting each access scheme by its access verification strictness, and selecting the access scheme with the highest access verification strictness among the multiple access schemes as the target access scheme; wherein the access verification strictness represents the complexity of the verification algorithm of each access scheme, and the attributes, quantity, and completeness of the authentication factors required to be provided by the target user; The target access solution is sent to the user terminal, so that the user terminal provides required authentication information according to the target access solution.
7. A device for determining a terminal access point, characterized in that: The determining device comprises: A service access requirement receiving module is configured to receive a service access requirement sent by a target user through a user terminal; wherein the service access requirement includes target service requirements, security requirements, and service quality requirements; An access point determination module is configured to determine, based on the location information of the target user, at least one access point within the coverage area corresponding to the location information; The predicted situation information determination module is used to predict the access situation of each access point using a pre-built access situation prediction model to obtain the predicted situation information corresponding to each access point; A trust level information determination module is used to evaluate the trust level of the target user according to the service access requirements and a pre-built user trust evaluation model to obtain the trust level information of the target user; a target access point determination module, configured to determine a target access point from at least one access point based on the trust level information of the target user and the predicted situation information of each access point, and send the target access point to the user terminal, so that the user terminal accesses the microservice application through the target access point; The determining device includes a user trust evaluation model construction module, and the user trust evaluation model construction module constructs the user trust evaluation model through the following steps: For each historical user who has accessed the network, parameters of the network status information of the historical user in each historical service access time window are extracted to obtain the historical network status information associated with the historical user; wherein the historical network status information associated with the historical user includes user identity description parameters, network security description parameters, network performance description parameters, and authentication scheme description parameters; Obtain the historical access needs of the historical user and the access information generated by the historical user under the historical access behavior; Associating each historical user's historical access needs with the historical access information of the historical user, and calculating the degree of behavioral deviation of each historical user under each historical access information; Constructing a first association analysis sub-model based on the historical access requirements, the historical access information, and the degree of behavioral deviation; wherein the first association analysis sub-model is used to characterize the historical access information of each historical user under each historical access requirement, and the degree of behavioral deviation of each historical user under different historical access information; Correlate the historical access information of each historical user with the historical network situation information, and calculate the network situation influence degree of each historical user under each historical network situation information; Constructing a second association analysis sub-model based on the historical access information, the historical network situation information, and the network situation influence degree; wherein the second association analysis sub-model is used to characterize the historical network situation information of each historical user under each historical access demand, and the network situation influence degree of each historical user under different historical network situation information; The user trust evaluation model is obtained based on the first association analysis sub-model and the second association analysis sub-model.
8. An electronic device, characterized in that: include: A processor, a memory, and a bus, wherein the memory stores machine-readable instructions executable by the processor. When the electronic device is running, the processor and the memory communicate via the bus. When the processor runs the machine-readable instructions, the steps of the method for determining a terminal access point according to any one of claims 1 to 6 are executed.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the method for determining a terminal access point according to any one of claims 1 to 6 are executed.
Citation Information
Patent Citations
Wireless local area network user access mode selection method based on satisfaction
CN103369600A
System and method for enhancing security of personal embedded terminal
KR100850362B1