Cloud Master Station Service Dynamic Access Control Method and System Based on Zero Trust Network
By adopting a dynamic access control method for cloud main station services based on zero-trust network in the power distribution automation main station, the security problems brought about by cloud deployment and new security risks of smart terminals are solved, and a unified identity authentication and dynamic access control system is established to achieve efficient and secure cloud main station service access control.
Patent Information
- Application Number
- CN202210998676.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-08-19
- Publication Date
- 2025-06-20
- Estimated Expiration
- 2042-08-19
AI Technical Summary
The security problems of virtual resource sharing and blurred business system boundaries brought about by the cloud deployment of power distribution automation main stations, the new security risks of smart IoT terminals, the incomplete existing trust system, and the contradiction between the needs of convenient operation and maintenance and security protection requirements.
The dynamic access control method for cloud main station services based on zero-trust network is adopted, and unified identity identification and dynamic access control of users, equipment and services of power distribution main stations are achieved by establishing a zero-trust network authentication basis, continuous trust evaluation and attribute-based cloud main station services dynamic access control technology.
An end-to-end multi-identity authentication, real-time trust evaluation, dynamic access control and authorization system for devices and users has been established, covering the entire business scenarios of cloud, management, edge and end, achieving efficient and secure dynamic access control for cloud main website services, and enhancing the defense capabilities of complex and intelligent penetrating network intrusions.
Smart Images

Figure CN115426141B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the technical field of power distribution network protection, and relates to a method and system for dynamic access control of cloud master station services based on a zero-trust network. Background Art
[0002] With the construction and development of the power Internet of Things, distribution master stations, distribution terminals, and operation and maintenance technologies will all develop towards intelligence and interconnection. The business models, functional positioning, and working methods of each link will become more flexible, open, and efficient compared to the "master station-communication network-terminal" architecture of the traditional distribution monitoring system. For example: the distribution terminal upgrades the edge computing function, low-voltage equipment is widely accessed, edge equipment communication interaction, and the master station system is deployed in the cloud. The current security protection system of the distribution automation system is based on the principles of "security zoning, network dedicating, horizontal isolation, and vertical authentication", forming a deep defense system that spans the production control area and the management information area, covering the master station, communication, terminal, and boundary levels. However, the focus of network security defense is mainly on boundary protection. The security protection system for the cloud deployment of distribution business and the intelligentization of terminals is not yet perfect, and it is difficult to effectively respond to various types of increasingly complex and intelligent penetration network intrusions. Therefore, the current distribution secondary system business security protection has the following technical requirements:
[0003] (1) The cloud deployment of distribution automation master stations brings about security issues such as virtual resource sharing and blurred business system boundaries.
[0004] After the cloud deployment of the distribution automation master station, it has the characteristics of service virtualization, physical / storage resource sharing, centralized data processing, extensive sharing, and multi-party cross-connection. On the one hand, if the isolation measures of the cloud platform's own virtual resources are not in place, it may cause illegal access or information leakage between different applications; on the other hand, the cloud platform's multiple systems and multiple applications increase the probability of vulnerabilities. If the cloud platform does not prevent abnormal behavior, it faces the possibility that attackers can use vulnerabilities to sneak into the system, causing system paralysis or loss of control.
[0005] (2) The development of smart IoT terminals into “hardware platform-based and software APP-based” terminals and the large-scale application of new container technologies as carriers for application software have introduced new security risks.
[0006] On the one hand, the "hardware platformization and software APPization" mostly adopts the Linux operating system, which leads to rapid software iteration, more complex system vulnerabilities, enhanced openness, and reduced attack difficulty. On the other hand, various professional customized APP applications have been developed to support the development of energy interconnection business, mostly using containerized deployment. The containerized deployment of terminal APP improves the perception level and user response ability of the energy Internet, but also brings new risks and challenges to the network security of smart IoT terminals.
[0007] (3) The existing distribution automation trust system is incomplete.
[0008] On the one hand, the existing distribution automation protection solutions mainly focus on boundary protection, emphasizing the security of terminal access. However, in the existing trust system, a unified security authentication system for "people, services, and devices" has not been established, and it cannot meet the security interaction requirements between services, between services and people, between services and devices, and between devices. On the other hand, with the rapid popularization and application of fast protection services such as intelligent distributed feeder automation and distribution network differential protection, the communication method of using plaintext transmission horizontally between intelligent terminals is extremely likely to cause single-point risks to develop into system and network risks. There is a lack of protection for horizontal interactions at the edge side, a lack of identity authentication and data encryption, and there may be identity deception and man-in-the-middle attacks. The existing encryption technology cannot meet the requirements of rapid information encryption and decryption.
[0009] (4) There is a contradiction between the existing security protection requirements and the convenient operation and maintenance needs of front-line operations.
[0010] On the one hand, the operation and maintenance of most existing distribution terminals need to be carried out by on-site workers climbing poles to connect network cables, which poses a great risk to personal safety. On the other hand, the current operation and maintenance control technology based on serial ports cannot meet the operation and maintenance needs of various forms of fragmented IoT terminal devices and end sensing devices, resulting in low work efficiency in terminal inspection, maintenance, debugging, etc.
[0011] To sum up, the main station of the secondary distribution system is gradually evolving towards cloud deployment. By introducing virtualization technology, physical resources are pooled and allocated to users on demand. With the improvement of the mobility, accessibility, and agility of business processes, and the cross-container deployment of user resources, the boundaries of business systems become blurred. The traditional security protection system mainly based on boundary isolation protection can no longer meet the security protection requirements of the main station in the cloud deployment environment. Summary of the Invention
[0012] To solve the deficiencies in the existing technology, this application provides a dynamic access control method for cloud main station services based on the zero-trust network. It studies the digital identity identification technology for unified distribution main station users, devices, and services, and establishes the zero-trust network authentication foundation; studies the continuous trust evaluation technology, converges massive data sources to continuously evaluate the trust of cloud main station service entities and environments, and forms evaluation results; studies the attribute-based dynamic access control technology for cloud main station services, establishes a cloud access security proxy, and realizes dynamic access authorization for distribution main station service access.
[0013] To achieve the above objectives, the present invention adopts the following technical solutions:
[0014] A dynamic access control method for cloud main station services based on the zero-trust network, where the cloud infrastructure security platform realizes the dynamic access control of the cloud main station services based on the zero-trust network;
[0015] The zero-trust network is built based on software-defined perimeter technology for dynamic identity and privilege management and authentication of new business scenarios and new access subjects of the cloud master station;
[0016] The cloud infrastructure security platform includes an identity security management center, a trust continuous assessment center, a dynamic access control center, and a security proxy center;
[0017] The dynamic access control method includes the following steps:
[0018] The identity security management center performs the identification and identity lifecycle management of the subjects of the distribution automation system cloud master station, and conducts fine-grained management and tracking analysis of the authorization policies;
[0019] The trust continuous assessment center continuously conducts access trust assessment based on deep learning algorithms to obtain the trust level of the business access subject and the risk of the environment;
[0020] The dynamic access control center, in combination with the security proxy center, makes dynamic judgments and authorizations on the access trust assessment results.
[0021] The present invention further includes the following preferred solutions:
[0022] Preferably, based on the PKI-based security authentication, and in view of the characteristics of the cloud deployment of the distribution main station business, the zero-trust network combines the device physical fingerprint, user identity, and service characteristics to extend the security perimeter to the identity subject, establish a unified digital identity identifier for users, devices, application programs, and business system entities, regard applications, services, interfaces, and data as business resources, and realize dynamic identity and privilege management and authentication.
[0023] Preferably, the zero-trust network realizes the encrypted transmission of all access traffic based on the national cryptographic algorithm and the TLS protocol. The specific data interaction process is as follows:
[0024] 1) The subject access connects to the secure access gateway, requests to create a secure connection and lists the supported password algorithm combinations, and starts the handshake;
[0025] 2) The secure access gateway selects the encryption algorithm and the three-column algorithm from the password algorithm combinations listed by the access subject and notifies the access subject;
[0026] 3) The secure access gateway sends its digital certificate, which contains the secure access gateway name, the issuing authority name, and the public key of the secure access gateway;
[0027] 4) The access subject verifies the validity of the public key of the secure access gateway;
[0028] 5) The access subject encrypts using the public key of the secure access gateway, generates a random number using the national cryptography algorithm, and sends it to the secure access gateway. The secure access gateway decrypts it using the private key to obtain the random number generated by the access subject.
[0029] 6) Using the random number, both the subject access and the secure access gateway generate a symmetric key for encryption and decryption, and use the symmetric encryption key to encrypt and decrypt the session data.
[0030] Preferably, a continuous trust evaluation model based on deep learning algorithms such as convolutional neural networks, recurrent neural networks, and siamese networks is established to continuously record, analyze, and identify the access subject, context environment, and access habits, dynamically evaluate the trust level of the user, and obtain the trust level of the business access subject and the risk of the environment.
[0031] Preferably, the continuous trust evaluation center generates and maintains a trust library based on the continuous trust evaluation results, providing a decision-making basis for subsequent dynamic access control.
[0032] Preferably, the continuous trust evaluation center also receives the analysis results of the continuous trust evaluation center in the cloud infrastructure security platform, supplements the scenario data required for identity analysis, and thus conducts more accurate risk identification and trust evaluation.
[0033] Preferably, the dynamic access control center establishes an attribute-based dynamic access control model for cloud master station services, realizes continuous measurement of the trust level of the business access subject and the risk of the environment, and dynamically determines whether to authorize.
[0034] Set different risk levels for different functions, and set device and user access permissions according to the principle of minimum privilege.
[0035] Furthermore, the dynamic determination basis is the identity library, permission library, and trust library. The identity library provides the identity attributes of the access subject, the permission library provides the basic permission baseline, and the trust library is continuously maintained by identity analysis through real-time multi-dimensional risk association and trust evaluation.
[0036] Preferably, the security proxy center is based on access request interception technology and a dynamic access control engine, and performs real-time intervention or downgrade processing when there is a risk in the access context environment.
[0037] The present invention also provides a dynamic access control system for cloud master station services based on a zero-trust network, which is used to implement the dynamic access control method for cloud master station services described above.
[0038] The present invention also provides a terminal, including a processor and a storage medium; the storage medium is used to store instructions;
[0039] The processor is used to operate according to the instructions to execute the steps of the method.
[0040] The present invention also provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the steps of the method are implemented.
[0041] Beneficial effects achieved by the present application:
[0042] Starting from the security requirements of the cloud-based deployment of the distribution main station business, the present invention establishes a zero-trust security protection system with continuous identity authentication and dynamic access control as the core, and constructs end-to-end multi-factor identity authentication, real-time trust assessment, dynamic access control and authorization for devices and users based on "cloud, pipe, edge, and terminal", so as to realize the dynamic access control of the cloud main station business based on the zero-trust network.
[0043] (1) Based on the traditional PKI-based security authentication, the present invention combines multi-factor identity identifiers of device physical fingerprints, user identities and service characteristics, covers the entire service scenario of cloud, pipe, edge, and terminal, and converges a large amount of data sources to perform all-round continuous identity identification on the cloud main station business entities.
[0044] (2) The present invention establishes a unified security policy, monitors the east-west data flow between service containers, realizes identity authentication and fine-grained access authorization between services, and automatically adjusts the access policy according to the dynamic changes of access.
[0045] (3) The present invention establishes a unified security authentication center, conducts continuous trust assessment according to the access subject, access object, and access process, dynamically determines and authorizes the assessment results, and forms the dynamic access control ability of the cloud main station business based on attributes. Description of the Drawings
[0046] Figure 1 is the schematic diagram of the method of the present invention;
[0047] Figure 2 is the schematic diagram of the identity security management center of the present invention;
[0048] Figure 3 is the schematic diagram of the zero-trust network encryption transmission of the present invention;
[0049] Figure 4 is the schematic diagram of the continuous trust assessment of the present invention;
[0050] Figure 5 is the schematic diagram of the dynamic access control of the present invention. Detailed Embodiments
[0051] To make the objectives, technical solutions, and advantages of the present invention clearer, the following will clearly and completely describe the technical solutions of the present invention in conjunction with the accompanying drawings in the embodiments of the present invention. The embodiments described in this application are only a part of the embodiments of the present invention, rather than all embodiments. Based on the spirit of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the protection scope of the present invention.
[0052] As Figure 1 shown, Embodiment 1 of the present invention provides a method for dynamic access control of cloud master station services based on a zero-trust network. The cloud infrastructure security platform implements the dynamic access control of the cloud master station services based on the zero-trust network. In a preferred but non-limiting embodiment of the present invention, the zero-trust network is constructed based on software-defined perimeter technology for dynamic identity and permission management and authentication of new business scenarios and new access subjects of the cloud master station;
[0053] The cloud infrastructure security platform includes an identity security management center, a trust continuous assessment center, a dynamic access control center, and a security proxy center;
[0054] The dynamic access control method includes the following steps:
[0055] The identity security management center performs identity and identity lifecycle management of entities such as users, devices, application programs, and business systems of the distribution automation system cloud master station, and performs fine-grained management, tracking, and analysis of authorization policies;
[0056] Identity management realizes the identity and identity lifecycle management of various entities, and permission management performs fine-grained management, tracking, and analysis of authorization policies.
[0057] Based on the PKI-based security authentication of the zero-trust network, in view of the characteristics of the cloud deployment of the distribution main station service, combined with device physical fingerprints, user identities, and service characteristics, the security perimeter is extended to the identity subject, and a unified digital identity identifier is established for entities such as users, devices, application programs, and business systems. Applications, services, interfaces, data, etc. are regarded as business resources to achieve dynamic identity and permission management and authentication, as Figure 2 shown.
[0058] Among them, the identity identifier for a user or device can be obtained through multi-dimensional feature profiling, and the steps are as follows:
[0059] 1) Obtain user profiling data sources: Obtain data information for constructing user profiles from mobile terminals, backend platforms, etc.;
[0060] 2) Calculate user profile similarity: After abstractly analyzing the user profile, construct a model with tags and tag weights, and classify users through similarity calculation;
[0061] 3) Generate user portraits: According to system requirements or application background environment needs, establish representative user portraits for different users respectively;
[0062] 4) Construct device portraits based on device fingerprints and user behaviors of logged-in devices: Use linear regression algorithms to analyze, extract features, and place labels on the collected device behavior data, and finally generate multi-dimensional device behavior portraits, continuously improve the portrait model and optimize the label rule library. The zero-trust network unifies the digital identities of all participating entities in the network. The software-defined perimeter technology replaces broad network access with identity-based fine-grained access, hiding all master station service resources in the cloud, making the access subject unaware of the specific location of the service.
[0063] Such as Figure 3 As shown, the zero-trust network realizes encrypted transmission of all access traffic based on national cryptographic algorithms and the TLS protocol.
[0064] The specific data interaction process is as follows:
[0065] 1) The subject accesses and connects to the secure access gateway, requests to create a secure connection and lists the supported password algorithm combinations, and starts the handshake;
[0066] 2) The secure access gateway selects an encryption algorithm and a triple DES algorithm from the password algorithm combinations listed by the access subject and notifies the access subject;
[0067] 3) The secure access gateway sends its digital certificate, which contains the name of the secure access gateway, the name of the issuing authority, and the public key of the secure access gateway;
[0068] 4) The access subject uses the public key to verify the validity of the public key of the secure access gateway;
[0069] 5) The access subject encrypts a random number generated by using the national cryptographic algorithm with the public key of the secure access gateway and sends it to the secure access gateway. The secure access gateway decrypts it with its private key to obtain the random number generated by the access subject;
[0070] 6) Using the random number, both the subject access and the secure access gateway generate a symmetric key for encryption and decryption, and use the symmetric encryption key to encrypt and decrypt the session data.
[0071] Forward the access request of the subject to the trusted gateway, and only allow traffic from authorized subjects to pass through, which can resist attacks such as loss of user credentials and connection hijacking.
[0072] The trust continuous evaluation center continuously conducts access trust evaluation based on deep learning algorithms to obtain the trust level of the business access subject and the risk of the environment;
[0073] In specific implementation, a continuous trust evaluation model based on deep learning algorithms such as convolutional neural network (CNN) + recurrent neural network (RNN), siamese network, etc. is established to continuously record, analyze, and identify the access subject, context environment, and access habits, dynamically evaluate the user's trust level, and obtain the trust level of the business access subject and the risk of the environment.
[0074] Subject trust has the characteristic of short-term. The continuous trust evaluation model can dynamically adjust the identity trust in the current context according to the authentication strength, risk status, and environmental factors to form a dynamic trust relationship.
[0075] The continuous trust evaluation result generates and maintains a trust library, providing a decision-making basis for subsequent dynamic access control;
[0076] The continuous trust evaluation center also receives the analysis results of the continuous trust evaluation center in the cloud infrastructure security platform, supplements the scenario data required for identity analysis, and thus conducts more accurate risk identification and trust evaluation.
[0077] The dynamic access control center combines with the security proxy center to dynamically determine and authorize the access trust evaluation result.
[0078] Such as Figure 4 and 5 As shown, dynamic access control combines continuous trust evaluation to establish an attribute-based dynamic access control model (ABAC) for cloud main site services, and realizes a flexible access control baseline through the combined authorization of RBAC and ABAC, achieving continuous measurement of the trust level of the business access subject and the risk of the environment and dynamically determining whether to authorize.
[0079] Set different risk levels for different functions, and set device and user access permissions according to the principle of minimum privilege;
[0080] Furthermore, the dynamic determination basis is the identity library, permission library, and trust library. The identity library provides the identity attributes of the access subject, the permission library provides the basic permission baseline, and the trust library is continuously maintained by identity analysis through real-time multi-dimensional risk association and trust evaluation.
[0081] The security proxy center is used to perform real-time intervention or downgrade processing when there is a risk in the access context environment based on the access request interception technology and the dynamic access control engine.
[0082] Embodiment 2 of the present invention provides a dynamic access control system for cloud main site services based on a zero-trust network, and the system is used to implement the dynamic access control method for cloud main site services described above.
[0083] Embodiment 3 of the present invention provides a terminal, including a processor and a storage medium; the storage medium is used to store instructions;
[0084] The processor is configured to operate according to the instructions to perform the steps of the method.
[0085] Example 4 of the present invention provides a computer-readable storage medium, on which a computer program is stored, and when the program is executed by a processor, the steps of the method are implemented.
[0086] In summary, by studying physical entities such as users, devices, application programs, and business systems of the cloud master station of the distribution automation system, the present invention establishes a unified digital identity identifier, regards applications, services, interfaces, data, etc. as business resources, realizes the trustworthy identification of access subjects, designs a multi-dimensional dynamic access control policy, integrates multi-source data attributes such as personnel, devices, networks, data, and working environments, realizes fine-grained dynamic access control authorization for services, applications, and data, balances the permissions and operation security of the access subject and the cloud master station, and through identity identification, abnormal state security monitoring, and dynamic access control, realizes a zero-trust security defense platform to ensure the access security of the distribution cloud master station.
[0087] Through dynamic defense, the security of virtual machines and containers of the cloud master station, the access control and data security of the cloud master station business, the interface security and application security of the cloud master station are protected, and based on the cloud master station security management mechanism covering identity management, dynamic access control, abnormal identification, and risk warning, an active defense architecture of the cloud master station with a zero-trust network model is formed, which can effectively improve the comprehensive defense ability of the cloud master station against various known and unknown feature attack behaviors.
[0088] The present disclosure may be a system, a method, and / or a computer program product. The computer program product may include a computer-readable storage medium having thereon computer-readable program instructions for causing a processor to implement various aspects of the present disclosure.
[0089] A computer-readable storage medium can be a tangible device that can hold and store instructions for use by an instruction execution device. A computer-readable storage medium may be, for example—but not limited to—an electrical storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. More specific examples (a non-exhaustive list) of the computer-readable storage medium include: a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disc (DVD), a memory stick, a floppy disk, a mechanically encoded device, such as a punched card or raised structures in grooves storing instructions thereon, and any suitable combination of the foregoing. The computer-readable storage medium used herein is not construed as an instantaneous signal itself, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagated through a waveguide or other transmission medium (e.g., an optical pulse through an optical fiber cable), or an electrical signal transmitted through a wire.
[0090] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to various computing / processing devices, or downloaded to an external computer or external storage device through a network, such as the Internet, a local area network, a wide area network, and / or a wireless network. The network may include a copper transmission cable, an optical fiber transmission, a wireless transmission, a router, a firewall, a switch, a gateway computer, and / or an edge server. The network adapter or network interface in each computing / processing device receives the computer-readable program instructions from the network and forwards the computer-readable program instructions for storage in the computer-readable storage medium in each computing / processing device.
[0091] The computer program instructions for performing the operations of the present disclosure may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine - related instructions, microcode, firmware instructions, state - setting data, or source code or object code written in any combination of one or more programming languages, including object - oriented programming languages such as Smalltalk, C++, etc., and conventional procedural programming languages such as the "C" language or similar programming languages. The computer - readable program instructions may be executed entirely on the user's computer, partially on the user's computer, executed as a stand - alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via an Internet service provider through the Internet). In some embodiments, by using the state information of the computer - readable program instructions to customize an electronic circuit, such as a programmable logic circuit, a field - programmable gate array (FPGA), or a programmable logic array (PLA), the electronic circuit can execute the computer - readable program instructions to implement various aspects of the present disclosure.
[0092] Aspects of the present disclosure are described herein with reference to the flowcharts and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the present disclosure. It should be understood that each block of the flowcharts and / or block diagrams, and combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer - readable program instructions.
[0093] These computer - readable program instructions can be provided to a processor of a general - purpose computer, a special - purpose computer, or other programmable data - processing apparatus to produce a machine such that the instructions, when executed by the processor of the computer or other programmable data - processing apparatus, create a means for implementing the functions / acts specified in one or more blocks of the flowchart and / or block diagram. These computer - readable program instructions can also be stored in a computer - readable storage medium, which causes a computer, a programmable data - processing apparatus, and / or other devices to operate in a particular manner, so that the computer - readable medium storing the instructions includes a manufacture comprising instructions for implementing various aspects of the functions / acts specified in one or more blocks of the flowchart and / or block diagram.
[0094] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus, or other device, causing a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other device to produce a computer-implemented process such that the instructions executed on the computer, other programmable data processing apparatus, or other device implement the functions / acts specified in one or more boxes of the flowchart and / or block diagram.
[0095] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each box in the flowchart or block diagram may represent a module, a segment of a program, or a portion of an instruction, which contains one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions noted in the boxes may occur out of the order noted in the figures. For example, two consecutive boxes may in fact be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each box in the block diagrams and / or flowcharts, and combinations of boxes in the block diagrams and / or flowcharts, can be implemented by a dedicated hardware-based system that performs the specified functions or acts, or by a combination of dedicated hardware and computer instructions.
[0096] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them. Although the present invention has been described in detail with reference to the above embodiments, those of ordinary skill in the art should understand that: modifications or equivalent replacements can still be made to the specific embodiments of the present invention. Any modification or equivalent replacement that does not depart from the spirit and scope of the present invention shall be covered by the protection scope of the claims of the present invention.
Claims
1. A method for dynamic access control of cloud master station services based on a zero-trust network, where the cloud infrastructure security platform implements the dynamic access control of the cloud master station services based on the zero-trust network, and is characterized in that: The zero-trust network is built based on software-defined perimeter technology for dynamic identity and permission management and authentication of new business scenarios and new access subjects in the cloud master station. Based on the PKI-based security authentication, the zero-trust network extends the security perimeter to the identity subject by combining the device physical fingerprint, user identity, and service characteristics according to the characteristics of the cloud-based deployment of the distribution master station business. The zero-trust network realizes the encrypted transmission of all access traffic based on the national cryptographic algorithm and the TLS protocol. The specific data interaction process is as follows: 1) The subject accesses and connects to the secure access gateway, requests to create a secure connection, lists the supported cryptographic algorithm combinations, and starts the handshake. 2) The secure access gateway selects the encryption algorithm and hash algorithm from the cryptographic algorithm combinations listed by the access subject and notifies the access subject. 3) The secure access gateway sends its digital certificate, which contains the name of the secure access gateway, the name of the issuing authority, and the public key of the secure access gateway. 4) The access subject verifies the validity of the public key of the secure access gateway. 5) The access subject encrypts a random number generated by using the national cryptographic algorithm with the public key of the secure access gateway and sends it to the secure access gateway. The secure access gateway decrypts it with the private key to obtain the random number generated by the access subject. 6) Using the random number, both the subject access and the secure access gateway generate a symmetric key for encryption and decryption, and use the symmetric encryption key to encrypt and decrypt the session data. The cloud infrastructure security platform includes an identity security management center, a trust continuous assessment center, a dynamic access control center, and a security proxy center. The dynamic access control method includes the following steps: The identity security management center conducts the identification and identity lifecycle management of the subjects in the distribution automation system cloud master station, and conducts fine-grained management, tracking, and analysis of the authorization policies. The trust continuous assessment center continuously conducts access trust assessment based on the deep learning algorithm to obtain the trust level of the business access subject and the risk of the environment. The dynamic access control center, in combination with the security proxy center, dynamically determines and authorizes the access trust assessment results.
2. The method for dynamic access control of cloud master station services based on a zero-trust network according to claim 1, characterized in that: The zero-trust network establishes a unified digital identity identifier for users, devices, application programs, and business system entities, regards applications, services, interfaces, and data as business resources, and realizes dynamic identity and permission management and authentication.
3. The method for dynamic access control of cloud master station services based on a zero-trust network according to claim 1, characterized in that: A continuous trust assessment model based on deep learning algorithms of convolutional neural networks, recurrent neural networks, and siamese networks is established to continuously record, analyze, and identify the access subject, context environment, and access habits, dynamically evaluate the trust level of the user, and obtain the trust level of the business access subject and the risk of the environment.
4. The method for dynamic access control of cloud master station services based on a zero-trust network according to claim 1, characterized in that: The trust continuous assessment results of the trust continuous assessment center generate and maintain a trust library, providing a decision-making basis for subsequent dynamic access control.
5. The method for dynamic access control of cloud master station services based on a zero-trust network according to claim 1, characterized in that: The trust continuous assessment center also receives the analysis results of the trust continuous assessment center in the cloud infrastructure security platform to supplement the scenario data required for identity analysis.
6. The method for dynamic access control of cloud master station services based on a zero-trust network according to claim 1, characterized in that: The dynamic access control center establishes an attribute-based cloud master station service dynamic access control model ABAC to continuously measure the trust level of the business access subject and the risk of the environment and dynamically determine whether to authorize.
7. The method for dynamic access control of cloud master station services based on a zero-trust network according to claim 6, characterized in that: In the dynamic access control center, different risk levels are set for different functions, and device and user access permissions are set according to the principle of least privilege. Moreover, dynamic determination is achieved based on the identity library, permission library, and trust library. Among them, the identity library provides the identity attributes of the access subject, the permission library provides the basic permission baseline, and the trust library is continuously maintained by identity analysis through real-time multi-dimensional risk association and trust assessment.
8. The method for dynamic access control of cloud master station services based on a zero-trust network according to claim 1, characterized in that: The security proxy center, based on the access request interception technology and the dynamic access control engine, performs real-time intervention or degradation processing when there are risks in the access context environment.
9. A dynamic access control system for cloud master station services based on a zero-trust network, characterized in that: The system is used to implement the dynamic access control method for the cloud master station service described in any one of claims 1-8.
10. A dynamic access control terminal for cloud master station services based on a zero-trust network, comprising a processor and a storage medium; characterized in that: The storage medium is used to store instructions. The processor is used to operate according to the instructions to execute the steps of the method described in any one of claims 1-8.
11. A computer-readable storage medium, on which a computer program is stored, characterized in that, When the program is executed by the processor, the steps of the method described in any one of claims 1-8 are implemented.