A network security processing method, device and equipment
By adjusting security mechanisms and trust mechanisms through trust evaluation, the high overhead of security mechanisms on system performance and resources is resolved, thus achieving cost optimization of network security.
Patent Information
- Application Number
- CN202411048300.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-08-01
- Publication Date
- 2026-01-16
- Estimated Expiration
- 2044-08-01
AI Technical Summary
In existing technologies, security mechanisms incur significant overhead on system performance and resources, leading to increased network costs.
By acquiring the security needs of target users, and combining this with the security and trust mechanisms in the network, a trust assessment is conducted, and the security and trust mechanisms are adjusted to meet the security needs.
It reduces the performance overhead and resource consumption caused by security mechanisms, thus saving network costs.
Smart Images

Figure CN118802357B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of communication technology, and particularly to a network security processing method, device and equipment. BACKGROUND
[0002] At present, with the development of network becoming more and more complex, the security mechanism has higher and higher demand for resources, and brings more and more performance loss to the business. Therefore, under the condition of the great increase of new security requirements and complexity, how to design security and reduce system performance and resource consumption becomes a difficult problem. SUMMARY
[0003] The purpose of the present application is to provide a network security processing method, device and equipment to solve the problem of large overhead of system performance and resources caused by security mechanism.
[0004] To achieve the above purpose, an embodiment of the present application provides a network security processing method, executed by a first device, comprising:
[0005] Obtaining security requirements of a target user;
[0006] According to the security requirements, and the security mechanism and trust mechanism in the network, obtaining a trust evaluation result;
[0007] According to the trust evaluation result, adjusting the security mechanism and / or trust mechanism in the network.
[0008] Optionally, the method further comprises:
[0009] According to the security requirements, determining a key position in the network and a trust mechanism corresponding to the key position;
[0010] Deploying the trust mechanism at the key position.
[0011] Optionally, obtaining the security requirements of the target user comprises:
[0012] In the case that the target user accesses the network, querying a security level of the target user;
[0013] According to the security level, determining the security requirements of the target user.
[0014] Optionally, the trust mechanism comprises:
[0015] A locally stored trust mechanism, and / or a trust mechanism in a trust mechanism resource pool deployed in a second device.
[0016] Optionally, according to the trust evaluation result, adjusting the security mechanism and / or trust mechanism in the network comprises:
[0017] In a case where the trust evaluation result indicates that the current security mechanism and trust mechanism cannot satisfy the security requirement, the security mechanism and / or the trust mechanism in the network are updated until the updated security mechanism and trust mechanism satisfy the security requirement.
[0018] Optionally, the security mechanism and / or the trust mechanism in the network are adjusted according to the trust evaluation result, including:
[0019] In a case where the trust evaluation result indicates that the current security mechanism and trust mechanism exceed the security requirement, the security mechanism and / or the trust mechanism in the network are updated until the updated security mechanism and trust mechanism satisfy the security requirement.
[0020] Optionally, the trust mechanism includes:
[0021] Data consistency sampling and / or behavior consistency checking.
[0022] To achieve the above object, an embodiment of the present application provides a network security processing apparatus, including:
[0023] A first obtaining module is configured to obtain a security requirement of a target user.
[0024] A first processing module is configured to obtain a trust evaluation result according to the security requirement, and a security mechanism and a trust mechanism in a network.
[0025] A second processing module is configured to adjust the security mechanism and / or the trust mechanism in the network according to the trust evaluation result.
[0026] Optionally, the apparatus further includes:
[0027] A third processing module is configured to determine a key position in the network and a trust mechanism corresponding to the key position according to the security requirement.
[0028] A fourth processing module is configured to deploy the trust mechanism at the key position.
[0029] Optionally, the first obtaining module is further configured to:
[0030] In a case where the target user accesses the network, the security level of the target user is queried.
[0031] The security requirement of the target user is determined according to the security level.
[0032] Optionally, the trust mechanism includes:
[0033] A locally stored trust mechanism and / or a trust mechanism in a trust mechanism resource pool deployed in a second device.
[0034] Optionally, the second processing module is further configured to:
[0035] In a case where the trust evaluation result indicates that the current security mechanism and trust mechanism cannot satisfy the security requirement, updating the security mechanism and / or the trust mechanism in the network until the updated security mechanism and trust mechanism satisfy the security requirement.
[0036] Optionally, the second processing module is further configured to:
[0037] In a case where the trust evaluation result indicates that the current security mechanism and trust mechanism exceed the security requirement, updating the security mechanism and / or the trust mechanism in the network until the updated security mechanism and trust mechanism satisfy the security requirement.
[0038] Optionally, the trust mechanism comprises:
[0039] data consistency sampling, and / or, behavior consistency checking.
[0040] To achieve the above object, an embodiment of the present application provides a communication device, comprising a transceiver, a processor, a memory, and a program or instructions stored in the memory and executable on the processor; the processor implements the network security processing method as described above when executing the program or instructions.
[0041] To achieve the above object, an embodiment of the present application provides a readable storage medium, which stores a program or instructions, and the program or instructions are executable on a processor to implement the steps of the network security processing method as described above.
[0042] To achieve the above object, an embodiment of the present application provides a computer program product, which comprises computer instructions, and the computer instructions are executable on a processor to implement the steps of the network security processing method as described above.
[0043] The above technical solutions of the present application have the following beneficial effects:
[0044] The method of the embodiment of the present application can obtain the security requirement of the target user, and then obtain the trust evaluation result by combining the security requirement with the security mechanism and the trust mechanism in the network; and then, the security mechanism and / or the trust mechanism in the network is adjusted according to the obtained trust evaluation result. In this way, by introducing the trust mechanism, the network security is realized by the cooperation of the security mechanism and the trust mechanism, the performance loss and resource consumption caused by the security mechanism are reduced, and the network cost is saved. BRIEF DESCRIPTION OF DRAWINGS
[0045] Figure 1 The flowchart of the network security processing method of the embodiment of the present application;
[0046] Figure 2 A schematic diagram of a module structure of a network security processing apparatus according to an embodiment of the present application;
[0047] Figure 3 A structural diagram of a communication device according to an embodiment of the present application;
[0048] Figure 4 A schematic diagram of a principle of a network security processing method according to an embodiment of the present application. DETAILED DESCRIPTION
[0049] In order to make the technical problems to be solved, technical solutions and advantages of the present application clearer, specific embodiments will be described in detail below with reference to the accompanying drawings.
[0050] It should be understood that the terms "one embodiment" or "an embodiment" as used throughout this specification mean that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment of the present application. Therefore, the appearance of the phrases "in one embodiment" or "in an embodiment" in various places throughout the specification are not necessarily referring to the same embodiment. In addition, these particular features, structures, or characteristics can be combined in any suitable manner in one or more embodiments.
[0051] In various embodiments of the present application, it should be understood that the size of the serial number of the following processes does not mean the order of execution, and the execution order of the processes should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0052] In addition, the terms "system" and "network" are often used interchangeably herein.
[0053] In the embodiments provided in the present application, it should be understood that "B corresponding to A" means that B is associated with A, and B can be determined according to A. However, it should also be understood that the determination of B according to A does not mean that B is determined only according to A, but B can also be determined according to A and / or other information.
[0054] For the convenience of understanding, some contents related to the embodiments of the present application are described as follows:
[0055] In a communication system, the processing of security is usually according to the set target, analysis of security threats, put forward security requirements, develop security solutions, and implement security protection effect. Therefore, in the system, it is necessary to introduce security mechanisms (or can be called security capabilities) in the process of service execution, for example: when a user needs to access the network, it is necessary to enable the security mechanisms such as access authentication on the access and mobility management function (AMF) at the same time, which are bound with communication functions as part of the communication equipment; or when the user's data needs to be transmitted in the network, in order to protect the confidentiality and integrity of the data, it is necessary to use security mechanisms such as Internet Protocol Security (IPSec) on the backhaul link.
[0056] With the evolution of virtualization, security mechanism atomization, etc., security mechanisms also appear in the form of security mechanism resource pools for network use when needed. However, the difficulty of security mechanisms is that security protection capabilities need to be concatenated in the business process, thus causing additional requirements for the execution of the business and resources. With the development of the network becoming more and more complex, the demand of a large number of security mechanisms for resources is also increasing, and the performance loss to the business is also increasing.
[0057] As shown in Figure 1 the network security processing method of the embodiment of the present application is executed by a first device, comprising:
[0058] Step 101, obtaining the security requirements of a target user;
[0059] Step 102, obtaining a trust evaluation result according to the security requirements and the security mechanisms and trust mechanisms in the network;
[0060] Step 103, adjusting the security mechanisms and / or trust mechanisms in the network according to the trust evaluation result.
[0061] In this way, the first device applying the method of the embodiment of the present application will obtain the security requirements of the target user according to steps 101-103, and then obtain the trust evaluation result by combining the security requirements with the security mechanisms and trust mechanisms in the network; and then adjust the security mechanisms and / or trust mechanisms in the network according to the obtained trust evaluation result. In this way, by introducing the trust mechanisms and cooperating with the security mechanisms, the network security is realized, the performance loss and resource overhead caused by the security mechanisms are reduced, and the purpose of saving network cost is achieved.
[0062] The security mechanism and the trust mechanism correspond to one or more services of the target user. In a service execution process, the trust evaluation can be performed by monitoring the security mechanism and the trust mechanism, and a trust evaluation result can be obtained. The trust evaluation result can indicate whether the current security mechanism and the trust mechanism meet the security requirement or exceed the security requirement.
[0063] Here, the monitoring can also be referred to as security monitoring or trust monitoring. Specifically, the trust evaluation includes evaluation of the effect of the security mechanism and evaluation of the result of the trust mechanism. Accordingly, the trust evaluation result can also be reflected in the effect of the security mechanism and the result of the trust mechanism.
[0064] It should also be understood that the security mechanism of the network mainly includes the following types: encryption mechanism, access control mechanism, data integrity mechanism, digital signature mechanism, exchange signature mechanism, notarization mechanism, traffic padding mechanism, routing control mechanism, and the like. The security mechanism can be understood as a security capability, and various types of security mechanisms can be allocated in a security resource pool, and security protection can be performed by scheduling the security resource pool.
[0065] Optionally, in the embodiment, the trust mechanism includes:
[0066] Data consistency sampling and / or behavior consistency checking.
[0067] That is, the trust mechanism is a mechanism for trusting the identity of the user and the data of the user. In addition to the above, the trust mechanism can also include other implementations, which are not listed one by one here.
[0068] Optionally, in the embodiment, the method further includes:
[0069] According to the security requirement, determining a key position in the network and a trust mechanism corresponding to the key position;
[0070] Deploying the trust mechanism at the key position.
[0071] That is, for the security requirement of the target user, the key position in the network and the trust mechanism corresponding to the key position can be determined according to the security requirement, and the trust mechanism can be subsequently deployed at the key position. For example, the target user is user A, and after the first device obtains the security requirement, it is determined that the key position is a backhaul link and the trust mechanism is data consistency sampling. Therefore, a plurality of probes can be deployed at the backhaul link to implement the trust mechanism of data consistency sampling.
[0072] As an optional implementation, in this embodiment, the trust mechanism determined according to the security requirement of the target user can be understood as an initial trust mechanism. Of course, the initial security mechanism can also be explicitly determined according to the security requirement of the target user, and the security mechanism is configured in the network. Then, the first trust mechanism and / or the first security mechanism are adjusted according to the trust evaluation result obtained according to the initial trust mechanism and the initial security mechanism, and after N times of adjustment, the Nth trust mechanism and / or the Nth security mechanism are obtained.
[0073] Optionally, in this embodiment, the trust mechanism includes:
[0074] The trust mechanism stored locally, and / or the trust mechanism in the trust mechanism resource pool deployed in the second device.
[0075] As an optional implementation, in this embodiment, determining the trust mechanism corresponding to the key position includes:
[0076] In the trust mechanism stored locally, or in the trust mechanism resource pool deployed in the second device, the target trust mechanism is queried based on the security requirement.
[0077] That is, the first device stores the trust mechanism locally, and after obtaining the security requirement of the target user, the trust mechanism corresponding to the key position can be further determined in the trust mechanism stored locally. Or, for the second device deployed with the trust mechanism resource pool, the first device initiates a request to the second device after obtaining the security requirement of the target user, and determines the trust mechanism corresponding to the key position in the trust mechanism resource pool.
[0078] In this embodiment, the trust mechanism resource pool is deployed in a specific device, which facilitates pre-configuration of more trust mechanisms to adapt to the diversified security requirements of users, and can reduce the resource occupation of the first device.
[0079] In this embodiment, the security requirement is the security protection requirement of the target user and its business to the network. Optionally, obtaining the security requirement of the target user includes:
[0080] In the case that the target user accesses the network, the security level of the target user is queried;
[0081] According to the security level, the security requirement of the target user is determined.
[0082] The security level can be signed by the target user when registering in the network, or can be applied by the target user before executing a specific business. Moreover, a mapping relationship between the security level and the security requirement is set in advance, so that after the security level of the target user is queried, the security requirement of the target user can be determined according to the queried security level through the mapping relationship.
[0083] In addition, in the above, it is known that after obtaining a trust evaluation result according to a security mechanism and a trust mechanism, the security mechanism and / or the trust mechanism is adjusted according to the trust evaluation result. Alternatively, in this embodiment, adjusting the security mechanism and / or the trust mechanism in the network according to the trust evaluation result comprises:
[0084] In the case where the trust evaluation result indicates that the current security mechanism and the trust mechanism cannot meet the security requirement, the security mechanism and / or the trust mechanism in the network is updated until the updated security mechanism and the trust mechanism meet the security requirement.
[0085] That is, in the case where the trust evaluation result indicates that the current security mechanism and the trust mechanism cannot meet the security requirement, the adjustment is performed for the purpose of meeting the security requirement. Wherein, it can be adjusted once or multiple times, and after each adjustment, the trust evaluation result is reacquired based on the adjusted security mechanism and the trust mechanism to determine whether to adjust again.
[0086] Alternatively, in this embodiment, adjusting the security mechanism and / or the trust mechanism in the network according to the trust evaluation result comprises:
[0087] In the case where the trust evaluation result indicates that the current security mechanism and the trust mechanism exceed the security requirement, the security mechanism and / or the trust mechanism in the network is updated until the updated security mechanism and the trust mechanism meet the security requirement.
[0088] That is, in the case where the trust evaluation result indicates that the current security mechanism and the trust mechanism exceed the security requirement, the adjustment is performed for the purpose of meeting the security requirement. Wherein, it can also be adjusted once or multiple times, and after each adjustment, the trust evaluation result is reacquired based on the adjusted security mechanism and the trust mechanism to determine whether to adjust again.
[0089] Of course, if the trust evaluation result obtained once indicates that the current security mechanism and the trust mechanism cannot meet the security requirement, and the trust evaluation result obtained after adjusting the security mechanism and / or the trust mechanism indicates that the current security mechanism and the trust mechanism exceed the security requirement, further adjustment is still needed. Similarly, if the trust evaluation result obtained once indicates that the current security mechanism and the trust mechanism exceed the security requirement, and the trust evaluation result obtained after adjusting the security mechanism and / or the trust mechanism indicates that the current security mechanism and the trust mechanism cannot meet the security requirement, further adjustment is also needed.
[0090] In addition, in the adjustment process of this embodiment, network efficiency can also be combined to meet the security requirement while achieving higher network efficiency.
[0091] Next, the application of the method of the embodiments of the present application is described below taking the target user A as an example:
[0092] User A is a high-security-level user. When user A enters the network and needs to perform a service, by querying the security level, it is learned that the security requirement of user A is "data is better protected in the network". Therefore, it is determined that the security mechanism is "access authentication + air interface encryption integrity protection + Internet Protocol Security (IPSec) + Transport Layer Security (TLS)", and the key positions of the network (such as the backhaul link and the core network router) and the trust mechanism "data consistency sampling" are determined. In this way, a plurality of probes are deployed at the key positions of the network to implement data consistency sampling. After a period of use, the trust evaluation result "the security risk on the link is small" is obtained through monitoring and trust evaluation, which indicates that the current security mechanism and trust mechanism exceed the security requirement. According to the trust evaluation result, the following adjustments are made: reducing the use of part of the security mechanism, such as the application of IPsec and TLS; and increasing new trust mechanisms, such as adding behavior consistency checking on the link between the UPF and the gNB, such as regularity analysis of user data sending frequency and analysis of commonly used destination addresses of user data sending. After a period of use, the trust evaluation result "user behavior is reliable" is obtained through monitoring and trust evaluation, which indicates that the current security mechanism and trust mechanism still exceed the security requirement. Further adjustments can be made: reducing the frequency of use of the security mechanism, such as extending the duration of the network after each user access authentication; and reducing the frequency of use of the trust mechanism, such as the frequency of data consistency sampling analysis. Conversely, if the trust evaluation result "the user's behavior deviates to a certain extent" is obtained through monitoring and trust evaluation after a period of use, which indicates that the current security mechanism and trust mechanism still do not meet the security requirement, further adjustments can be made: increasing the security mechanism, such as adding the use of a signaling firewall between the UPF and the SMF at the edge of the user; and increasing the trust mechanism, such as adding data consistency sampling between the UPF and the SMF at the edge of the user.
[0093] In summary, the method of the embodiments of the present application, as shown in Figure 4 for the security requirement of the target user, adjusts the security mechanism and / or the trust mechanism through the trust evaluation result of the security or trust monitoring until the security requirement is met, that is, the desired security protection effect is achieved.
[0094] The trust evaluation and trust mechanism are introduced, and the security mechanism and / or the trust mechanism are adjusted in cooperation with the security mechanism to achieve network security, reduce the performance loss and resource overhead caused by the security mechanism, and achieve the purpose of saving network cost.
[0095] As Figure 2 shown in the figure, a network security processing apparatus according to an embodiment of the present application comprises:
[0096] A first obtaining module 210 is configured to obtain a security requirement of a target user.
[0097] A first processing module 220 is configured to obtain a trust evaluation result according to the security requirement and a security mechanism and a trust mechanism in a network.
[0098] A second processing module 230 is configured to adjust the security mechanism and / or the trust mechanism in the network according to the trust evaluation result.
[0099] Optionally, the apparatus further comprises:
[0100] A third processing module is configured to determine a key position in the network and a trust mechanism corresponding to the key position according to the security requirement.
[0101] A fourth processing module is configured to deploy the trust mechanism at the key position.
[0102] Optionally, the first obtaining module is further configured to:
[0103] query a security level of the target user in a case where the target user accesses the network.
[0104] determine the security requirement of the target user according to the security level.
[0105] Optionally, the trust mechanism comprises:
[0106] a locally stored trust mechanism and / or a trust mechanism in a trust mechanism resource pool deployed in a second device.
[0107] Optionally, the second processing module is further configured to:
[0108] update the security mechanism and / or the trust mechanism in the network until the updated security mechanism and trust mechanism satisfy the security requirement in a case where the trust evaluation result indicates that the current security mechanism and trust mechanism cannot satisfy the security requirement.
[0109] Optionally, the second processing module is further configured to:
[0110] update the security mechanism and / or the trust mechanism in the network until the updated security mechanism and trust mechanism satisfy the security requirement in a case where the trust evaluation result indicates that the current security mechanism and trust mechanism exceed the security requirement.
[0111] Optionally, the trust mechanism comprises:
[0112] data consistency sampling, and / or, behavior consistency checking.
[0113] The device obtains a trust evaluation result according to the security mechanism and the trust mechanism in the network, and then adjusts the security mechanism and / or the trust mechanism in the network according to the obtained trust evaluation result. In this way, by introducing the trust mechanism and cooperating with the security mechanism, the network security is realized, the performance loss and resource overhead caused by the security mechanism are reduced, and the purpose of saving network cost is achieved.
[0114] It should be noted that the device applies the network security processing method of the above-mentioned embodiments, and the implementation manner of the method embodiments is applicable to the device, and the same technical effects can also be achieved.
[0115] The communication device of the embodiment of the present application, as shown in Figure 3 the transceiver 310, the processor 300, the memory 320, and the program or instructions stored in the memory 320 and executable on the processor 300; the processor 300 implements the network security processing method described above when executing the program or instructions.
[0116] The transceiver 310 is configured to receive and send data under the control of the processor 300.
[0117] Among them, in Figure 3 , the bus architecture can include any number of interconnected buses and bridges, which are variously linked together by one or more processors represented by the processor 300 and the memory represented by the memory 320. The bus architecture can also link various other circuits such as peripheral devices, voltage stabilizers, and power management circuits, which are well known in the art, and therefore, they will not be further described herein. The bus interface provides an interface. The transceiver 310 can be a plurality of elements, i.e., including a transmitter and a receiver, which provides a unit for communicating with various other devices on a transmission medium. The processor 300 is responsible for managing the bus architecture and general processing, and the memory 320 can store data used by the processor 300 when performing operations.
[0118] A readable storage medium of an embodiment of the present application has a program or instructions stored thereon, which, when executed by a processor, implements the steps of the network security processing method described above and can achieve the same technical effects. To avoid repetition, it will not be described here.
[0119] The processor is the processor in the communication device described in the above embodiments. The readable storage medium includes a computer readable storage medium, such as a computer read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.
[0120] The embodiment of the present application further provides a computer program product, including computer instructions, which, when executed by a processor, implement each process of the network security processing method embodiment shown above and achieve the same technical effects. To avoid repetition, details are not described herein.
[0121] It is further needed to be explained that many functional components described in the specification are referred to as modules, so as to more particularly emphasize their independence in implementation.
[0122] In the embodiment of the present application, a module can be implemented by software, so as to be executed by various types of processors. For example, an identified executable code module can include one or more physical or logical blocks of computer instructions, which can be constructed as objects, processes or functions, for example. However, the executable code of the identified module does not need to be physically located together, but can include different instructions stored in different bits, which, when logically combined, constitute the module and achieve the specified purpose of the module.
[0123] In fact, an executable code module can be a single instruction or many instructions, and can even be distributed on different code segments, in different programs, and across multiple memory devices. Similarly, operational data can be identified within a module, and can be implemented in any appropriate form and organized in any appropriate type of data structure. The operational data can be collected as a single data set, or can be distributed over different locations including over different storage devices, and can at least partially exist only as electronic signals on a system or network.
[0124] When a module can be implemented by software, the module implemented by software can be built into a corresponding hardware circuit by a person skilled in the art without considering the cost, and the hardware circuit includes a conventional very large scale integration (VLSI) circuit or a gate array, and existing semiconductors such as logic chips, transistors or other discrete elements. The module can also be implemented by a programmable hardware device, such as a field programmable gate array, a programmable array logic, a programmable logic device, etc.
[0125] The foregoing exemplary embodiments are described with reference made to the drawings which are provided for the purpose of explanation and illustration and are not intended to limit the scope of the application. Indeed, various modifications and variations that fall within the spirit and scope of the application can become apparent to those skilled in the art upon reading this specification, and it is to be understood that such modifications and variations are intended to fall within the scope of the application. Further, it is to be understood that the phraseology and terminology employed herein are for the purpose of description and explanation and are not intended to be limiting. The use of "including" and "comprising" and variations thereof is meant to encompass the items listed thereafter and equivalents thereof as well as additional items and equivalents thereof. Unless otherwise specified, a range of values includes the beginning and end points of the range and any sub-ranges therebetween.
[0126] The above description is considered that of the preferred embodiments of the application only. Modifications and alterations will occur to others upon reading the preceding description and it is intended to include all such modifications and alterations insofar as they come within the scope of the claims.
Claims
1. A network security processing method characterized by comprising: Implemented by a first device, comprising: obtaining security requirements of a target user; obtaining a trust evaluation result according to the security requirements and security mechanisms and trust mechanisms in a network; adjusting the security mechanisms and / or the trust mechanisms in the network according to the trust evaluation result; the trust mechanisms are mechanisms for trusting user identities and user data.
2. The method of claim 1, wherein, Further comprising: determining key locations in the network and trust mechanisms corresponding to the key locations according to the security requirements; deploying the trust mechanisms at the key locations.
3. The method of claim 1, wherein, The obtaining of the security requirements of the target user comprises: querying a security level of the target user in a case where the target user accesses the network; determining the security requirements of the target user according to the security level.
4. The method of claim 1, wherein, The trust mechanisms comprise: locally stored trust mechanisms and / or trust mechanisms in a trust mechanism resource pool deployed at a second device.
5. The method of claim 1, wherein, The adjusting of the security mechanisms and / or the trust mechanisms in the network according to the trust evaluation result comprises: updating the security mechanisms and / or the trust mechanisms in the network until the updated security mechanisms and / or the trust mechanisms satisfy the security requirements, in a case where the trust evaluation result indicates that the current security mechanisms and / or the trust mechanisms cannot satisfy the security requirements.
6. The method of claim 1, wherein, The adjusting of the security mechanisms and / or the trust mechanisms in the network according to the trust evaluation result comprises: updating the security mechanisms and / or the trust mechanisms in the network until the updated security mechanisms and / or the trust mechanisms satisfy the security requirements, in a case where the trust evaluation result indicates that the current security mechanisms and / or the trust mechanisms exceed the security requirements.
7. The method of claim 1, wherein, The trust mechanisms comprise: data consistency sampling and / or behavior consistency checking.
8. A network security processing device, comprising: Comprising: a first obtaining module configured to obtain security requirements of a target user; a first processing module configured to obtain a trust evaluation result according to the security requirements and security mechanisms and trust mechanisms in a network; a second processing module configured to adjust the security mechanisms and / or the trust mechanisms in the network according to the trust evaluation result; the trust mechanisms are mechanisms for trusting user identities and user data.
9. The apparatus of claim 8, wherein, Further comprising: a third processing module configured to determine key locations in the network and trust mechanisms corresponding to the key locations according to the security requirements; a fourth processing module configured to deploy the trust mechanisms at the key locations.
10. The apparatus of claim 8, wherein, The second processing module is further configured to: update the security mechanisms and / or the trust mechanisms in the network until the updated security mechanisms and / or the trust mechanisms satisfy the security requirements, in a case where the trust evaluation result indicates that the current security mechanisms and / or the trust mechanisms cannot satisfy the security requirements.
11. The apparatus of claim 8, wherein, The second processing module is further configured to: update the security mechanisms and / or the trust mechanisms in the network until the updated security mechanisms and / or the trust mechanisms satisfy the security requirements, in a case where the trust evaluation result indicates that the current security mechanisms and / or the trust mechanisms exceed the security requirements.
12. A communication device comprising: A transceiver, a processor, a memory, and a program or instructions stored on the memory and executable on the processor; wherein the processor implements the network security processing method of any one of claims 1-7 when executing the program or instructions.
13. A readable storage medium, on which a program or instructions are stored, characterized in that, The program or instructions, when executed by the processor, implement the steps of the network security processing method of any one of claims 1-7.
14. A computer program product, characterised in that, Computer instructions, which, when executed by the processor, implement the steps of the network security processing method of any one of claims 1-7.
Citation Information
Patent Citations
Cloud master station service dynamic access control method and system based on zero-trust network
CN115426141A
Zero-trust access control system and method based on network security situation assessment
CN118138295A