Zero trust dynamic access control method, device and computer equipment
By implementing a zero-trust dynamic access control method in the power grid system, dynamically verifying the access rights and transmission information of the terminal equipment, the problem that traditional static verification cannot promptly reflect changes in user attributes is solved, and the security of the power grid system is improved.
Patent Information
- Application Number
- CN202411323162.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-23
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2044-09-23
AI Technical Summary
The identity verification and authorization verification of the access subject in the traditional power grid system are static and cannot promptly reflect changes in the user attributes of the access subject, resulting in security risks in the power grid system and affecting security.
A zero-trust dynamic access control method is provided, which can obtain device identification information and user information in response to operation requests of terminal devices, dynamically verify access permission scope and transmission information, determine risk operation information, and generate access control information based on these information to control the access operation of terminal devices to the power grid system.
Through dynamic verification and risk analysis, abnormal operations in access permissions and transmission information can be identified and dealt with in a timely manner, improving the security of the power grid system and preventing potential security threats.
Smart Images

Figure CN119046910B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer technology, and in particular to a zero-trust dynamic access control method, apparatus, computer equipment, computer-readable storage medium, and computer program product. Background Art
[0002] During the operation of the power grid system, terminal devices can connect to the network and interactively use the functions and services of the power grid system to realize functions such as data exchange, functional operation and service request. Terminal users can access various services provided by the system through the above operations and complete their work tasks efficiently and conveniently. With the development of networking and informatization, the terminals for accessing the power grid system and other operations tend to be more diverse and widely distributed. It is particularly important to ensure the safety and stability of the power grid system.
[0003] In traditional technologies, the identity authentication and authorization verification of access subjects (such as user terminals) are often static, and no verification is performed again after the identity authentication and authorization verification are passed. However, the user attributes of the access subject may change at any time. Traditional simple identity authentication and authorization verification cannot reflect the operations of the access subject in a timely manner, which will cause security risks to the power grid system and is not conducive to improving the security of the power grid system. Summary of the invention
[0004] Based on this, it is necessary to provide a zero-trust dynamic access control method, device, computer equipment, computer-readable storage medium and computer program product that can improve the security of the power grid system in response to the above-mentioned technical problems.
[0005] In a first aspect, the present application provides a zero-trust dynamic access control method, comprising:
[0006] In response to an operation request of a terminal device for a power grid system, acquiring device identification information and user information corresponding to the terminal device;
[0007] In the case where the device identification information and the user information are verified, determining access permission scope information according to the device identification information and the user information;
[0008] When the access permission scope information matches the operation area information corresponding to the operation request, acquiring transmission information between the terminal device and the power grid system;
[0009] Determine first risk operation information according to the access permission range information, and determine second risk operation information according to the transmission information; the first risk operation information is used to characterize an operation with abnormalities in the access permission range; the second risk operation information is used to characterize an operation with abnormalities in the transmission information;
[0010] Dynamically verify the first risk operation information, the second risk operation information and the access duration information of the terminal device to the power grid system to determine access control information for the terminal device; the access control information is used to control the access operation of the terminal device to the power grid system.
[0011] In one embodiment, determining the second risk operation information according to the transmission information includes:
[0012] Acquire storage unit information corresponding to the address information of the transmission information;
[0013] determining the second risk operation information according to the storage unit information and the access permission range information;
[0014] and / or
[0015] Acquiring keyword information in the transmission information;
[0016] Determining confidentiality level information of the transmission information according to the keyword information and the preset mapping relationship;
[0017] The second risk operation information is determined according to the confidentiality level information and the access permission range information.
[0018] In one embodiment, the dynamically verifying the first risk operation information, the second risk operation information, and the access duration information of the terminal device to the power grid system to determine the access control information for the terminal device includes:
[0019] Determining a first risk assessment value according to the first risk operation information and the first weight information within a target time period;
[0020] Determine a second risk assessment value according to the second risk operation information and the second weight information within the target time period;
[0021] determining an evaluation threshold according to the access duration information, the first risk operation information, and the second risk operation information;
[0022] The access control information is determined according to a ratio between a sum of the first risk assessment value and the second risk assessment value and the assessment threshold.
[0023] In one embodiment, determining the access control information according to a ratio between a sum of the first risk assessment value and the second risk assessment value and the assessment threshold value includes:
[0024] Obtain the number of verification failures corresponding to the device identification information and the user information within the target time period;
[0025] Determining a verification risk assessment value according to the number of verification failures and the third weight information;
[0026] Obtaining a sum of the first risk assessment value, the second risk assessment value, and the verification risk assessment value;
[0027] The access control information is determined according to a ratio between the sum and the evaluation threshold.
[0028] In one embodiment, the method further comprises:
[0029] In the case where the verification of the device identification information and the user information fails, sending a verification request to the terminal device, and obtaining the updated device identification information and the updated user information returned by the terminal device;
[0030] Verifying the updated device identification information and the updated user information, and recording the number of verifications;
[0031] When the number of verifications is greater than a preset number threshold, the terminal device is prohibited from accessing the power grid system.
[0032] In one embodiment, determining access permission scope information according to the device identification information and the user information includes:
[0033] Determine the device access permission scope information of the terminal device in a preset device permission database according to the device identification information;
[0034] Determine the user access permission scope information of the terminal device in a preset user permission database according to the user information;
[0035] The device access permission scope information is compared with the user access permission scope information to determine the access permission scope information.
[0036] In a second aspect, the present application also provides a zero-trust dynamic access control device, including:
[0037] An information acquisition module, configured to obtain device identification information and user information corresponding to the terminal device in response to an operation request of the terminal device for the power grid system;
[0038] A scope acquisition module, configured to determine access permission scope information according to the device identification information and the user information when the device identification information and the user information are verified;
[0039] a range verification module, configured to obtain transmission information between the terminal device and the power grid system when the access permission range information matches the operation area information corresponding to the operation request;
[0040] an information analysis module, configured to determine first risk operation information according to the access permission scope information, and to determine second risk operation information according to the transmission information; the first risk operation information is used to characterize an operation with abnormalities in the access permission scope; the second risk operation information is used to characterize an operation with abnormalities in the transmission information;
[0041] An information generation module is used to dynamically verify the first risk operation information, the second risk operation information and the access duration information of the terminal device to the power grid system, and determine the access control information for the terminal device; the access control information is used to control the access operation of the terminal device to the power grid system.
[0042] In a third aspect, the present application further provides a computer device, wherein the computer device comprises a memory and a processor, wherein the memory stores a computer program, and when the computer program is executed by the processor, the steps of the above method are implemented.
[0043] In a fourth aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, wherein the computer program implements the steps of the above method when executed by a processor.
[0044] In a fifth aspect, the present application further provides a computer program product, wherein the computer program product comprises a computer program, and when the computer program is executed by a processor, the steps of the above method are implemented.
[0045] The above-mentioned zero-trust dynamic access control method, apparatus, computer equipment, computer-readable storage medium and computer program product obtain the device identification information and user information corresponding to the terminal device by responding to the operation request of the terminal device to the power grid system, so as to subsequently perform identity authentication based on the device identification information and user information; when the device identification information and user information are verified, the access permission scope information is determined according to the device identification information and user information, so as to accurately analyze the access permission scope of the terminal and the user in combination with the device identification information and user information; when the access permission scope information matches the operation area information corresponding to the operation request, the transmission information between the terminal device and the power grid system is obtained, so as to subsequently perform compliance inspection and risk analysis on the transmission information; first risk operation information is determined according to the access permission scope information, and second risk operation information is determined according to the transmission information, the first risk operation information is used to characterize the existence of abnormal operations in the access permission scope; the second risk operation information is used to characterize the existence of abnormal operations in the transmission information Abnormal operation, thereby analyzing the risk operation between the terminal and the power grid system based on the access permission range information and transmission information, so as to control the access operation of the terminal in combination with the risk operation in the future; dynamically verify the first risk operation information, the second risk operation information and the access duration information of the terminal device to the power grid system, and determine the access control information for the terminal device; the access control information is used to control the access operation of the terminal device to the power grid system, thereby comprehensively analyzing the risk operation and the duration of the terminal's access to the power grid system, evaluating the risk of data interaction between the terminal and the power grid system, and then generating access control information based on the risk assessment results. When the terminal passes the identity authentication and the access permission range meets the range requirements, it can evaluate whether there is a risk operation in the access permission and transmission data, and determine the access control information in combination with the duration of the terminal's access to the system, so as to analyze and screen the risk operations in the interaction process between the terminal and the power grid system, avoid risk operations that threaten the safe and stable operation of the power grid system, and thus improve the security of the power grid system. BRIEF DESCRIPTION OF THE DRAWINGS
[0046] In order to more clearly illustrate the technical solutions in the embodiments of the present application or related technologies, the drawings required for use in the embodiments of the present application or related technical descriptions will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.
[0047] Figure 1 An application environment diagram of a zero-trust dynamic access control method in one embodiment;
[0048] Figure 2 A flowchart of a zero-trust dynamic access control method in an embodiment;
[0049] Figure 3 is a schematic diagram of a trust assessment framework in one embodiment;
[0050] Figure 4 A schematic diagram of a process flow of identity authentication in one embodiment;
[0051] Figure 5 A schematic diagram of a process for determining access permission scope information in an embodiment;
[0052] Figure 6 A flowchart of a zero-trust dynamic access control method in another embodiment;
[0053] Figure 7 It is a structural block diagram of a zero-trust dynamic access control device in one embodiment;
[0054] Figure 8 The figure is a diagram of the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0055] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0056] The zero-trust dynamic access control method provided in the embodiment of the present application can be applied to Figure 1In the application environment shown. Among them, the terminal 102 communicates with the server 104 through the network. The data storage system can store the data that the server 104 needs to process. The data storage system can be integrated on the server 104, or it can be placed on the cloud or other network servers. The server 104 responds to the operation request of the terminal device for the power grid system, and obtains the device identification information and user information corresponding to the terminal device; the server 104 determines the access permission range information according to the device identification information and the user information when the device identification information and the user information are verified; the server 104 obtains the transmission information between the terminal device and the power grid system when the access permission range information matches the operation area information corresponding to the operation request; the server 104 determines the first risk operation information according to the access permission range information, and determines the second risk operation information according to the transmission information; the first risk operation information is used to characterize the operation with abnormal access permission range; the second risk operation information is used to characterize the operation with abnormal transmission information; the server 104 dynamically verifies the first risk operation information, the second risk operation information and the access duration information of the terminal device to the power grid system, and determines the access control information for the terminal device; the access control information is used to control the access operation of the terminal device to the power grid system. The terminal 102 may be, but is not limited to, various personal computers, laptops, smart phones, tablet computers, IoT devices, and portable wearable devices. The IoT devices may be smart speakers, smart TVs, smart air conditioners, smart car devices, projection devices, etc. Portable wearable devices may be smart watches, smart bracelets, head-mounted devices, etc. Head-mounted devices may be virtual reality (VR) devices, augmented reality (AR) devices, smart glasses, etc. The server 104 may be an independent physical server, a server cluster or distributed system consisting of multiple physical servers, or a cloud server that provides cloud computing services.
[0057] In an exemplary embodiment, Figure 2 As shown, a zero-trust dynamic access control method is provided, which is described by taking the method applied to a server as an example, and includes the following steps S202 to S210. Among them:
[0058] Step S202: in response to an operation request of the terminal device for the power grid system, obtaining device identification information and user information corresponding to the terminal device.
[0059] The terminal device may refer to a terminal used by a user to perform business operations (access operations, etc.) on the power grid system.
[0060] The power grid system may refer to a system for managing resources such as power resources (eg, electrical energy).
[0061] The operation request may refer to information used to characterize the operation that the terminal device requests to perform on the power grid system. In practical applications, the operation request may include but is not limited to an access request, a data interaction request, and the like.
[0062] Among them, the device identification information may refer to information used to distinguish / identify different terminal devices. In actual applications, the device identification information may include but is not limited to device identification numbers, pass cards, information tokens, etc.
[0063] Among them, user information can refer to information used to distinguish / identify different users. In actual applications, user information can be used to verify user identity. User information may include but is not limited to user account, password, user identification number, fingerprint, voiceprint and facial features.
[0064] As an example, in order to ensure the security of the power grid system when a user accesses the power grid system through a terminal device, the server can obtain the device identification information and user information corresponding to the terminal device as basic identification information when the terminal device first accesses the power grid system. Then, when the user requests to perform business operations (such as access operations, etc.) to the power grid system through the terminal device, the server can obtain the device identification information and user information corresponding to the terminal device in response to the operation request for the power grid system sent by the user through the terminal device, so as to use the basic identification information to authenticate the identity of the device identification information and user information corresponding to the terminal device.
[0065] Step S204: when the device identification information and the user information are verified, determine the access permission scope information according to the device identification information and the user information.
[0066] The access permission scope information may refer to information representing the operation permissions and data access scope possessed by the terminal device and / or the user.
[0067] As an example, the server can use basic identification information to authenticate the device identification information and user information corresponding to the terminal device. When the device identification information and user information pass the authentication, the server can determine that the terminal device and the user pass the authentication. The server can combine the device identification information and user information to determine the access permission scope information in a preset permission database.
[0068] Step S206: When the access permission range information matches the operation area information corresponding to the operation request, transmission information between the terminal device and the power grid system is obtained.
[0069] The operation area information corresponding to the operation request may refer to information representing the scope of data interaction (such as the location where data is stored, etc.) when the user needs to interact with the power grid system through the terminal device.
[0070] The transmission information may refer to the information transmitted between the user through the terminal device and the power grid system. In practical applications, the transmission information may include the information sent by the terminal device to the power grid system and the information sent by the power grid system to the terminal device.
[0071] As an example, the access permission scope information may represent the operation permission and data interaction scope of the user when the user interacts with the power grid system through the terminal device. The server may compare the access permission scope information with the operation area information corresponding to the operation request. When the area represented by the operation area information corresponding to the operation request is included in the area represented by the access permission scope information, the server may determine that the terminal device meets the preset data interaction requirements. The server may monitor the signal transmission channel for data interaction between the terminal device and the power grid system, and obtain the transmission information between the terminal device and the power grid system.
[0072] Step S208, determining first risk operation information based on the access permission scope information, and determining second risk operation information based on the transmission information; the first risk operation information is used to characterize operations with abnormalities in the access permission scope; the second risk operation information is used to characterize operations with abnormalities in the transmission information.
[0073] Among them, the first risk operation information may refer to information representing operations in which there are abnormalities in access rights and / or data interaction scopes (such as the access rights do not meet the corresponding permission requirements and / or the data interaction scope is not fully included in the area represented by the access rights scope information).
[0074] The second risk operation information may refer to information indicating that there is an abnormal operation in the transmission information.
[0075] As an example, the server can compare the operation authority represented by the access permission range information with the permission requirements of the operation area that the terminal device's operation request needs to access, and / or compare the data interaction range represented by the access permission range information with the operation area that the terminal device's operation request needs to access, to determine whether there is an abnormality in the access permission and / or data interaction range. The server can record the operation with abnormal access permission and / or data interaction range as a first risk operation (or a type of risk operation), and the server can count the occurrence time and frequency of all first risk operations to determine the first risk operation information. The server can also analyze whether the storage location and confidentiality of the transmission information between the terminal device and the power grid system meet the preset data transmission requirements, so as to determine whether there is an abnormality in the transmission information. The server can record the operation with abnormal transmission information as a second risk operation (or a type of second risk operation), and the server can count the occurrence time and frequency of all second risk operations to determine the second risk operation information.
[0076] Step S210, dynamically verify the first risk operation information, the second risk operation information and the access duration information of the terminal device to the power grid system, and determine the access control information for the terminal device; the access control information is used to control the access operation of the terminal device to the power grid system.
[0077] The access duration information may refer to information representing the length of time from when the terminal device accesses the power grid system to when the terminal device disconnects the communication connection with the power grid system.
[0078] Among them, access control information may refer to information used to control the access operation of terminal devices to the power grid system. In actual applications, the access control information may include but does not include information such as allowing terminal devices to access the power grid system or prohibiting terminal devices from accessing the power grid system.
[0079] As an example, the server can dynamically verify and evaluate the first risk operation information, the second risk operation information, and the access duration information of the terminal device to the power grid system detected by the server during the data interaction between the terminal device and the power grid system within a specific time period, and use the first risk operation information, the second risk operation information, and the access duration information as risk assessment considerations to determine the risk assessment result. Then, the server can determine the access control information for the terminal device based on the risk assessment result, and use the access control information to determine whether the terminal device is allowed to access the power grid system.
[0080] In the above-mentioned zero-trust dynamic access control method, by responding to the operation request of the terminal device to the power grid system, the device identification information and user information corresponding to the terminal device are obtained, so that identity authentication is subsequently performed based on the device identification information and user information; when the device identification information and user information are verified, the access permission range information is determined according to the device identification information and user information, so as to accurately analyze the access permission range of the terminal and the user in combination with the device identification information and user information; when the access permission range information matches the operation area information corresponding to the operation request, the transmission information between the terminal device and the power grid system is obtained, so as to subsequently perform compliance inspection and risk analysis on the transmission information; the first risk operation information is determined according to the access permission range information, and the second risk operation information is determined according to the transmission information, so as to analyze the risk between the terminal and the power grid system based on the access permission range information and the transmission information. risk operations, so as to subsequently control the access operations of the terminal in combination with the risk operations; dynamically verify the first risk operation information, the second risk operation information and the access duration information of the terminal device to the power grid system, and determine the access control information for the terminal device; the access control information is used to control the access operations of the terminal device to the power grid system, so as to comprehensively analyze the risk operations and the duration of the terminal's access to the power grid system, evaluate the risk of data interaction between the terminal and the power grid system, and then generate access control information based on the risk assessment results. When the terminal passes the identity authentication and the access permission scope meets the scope requirements, it can evaluate whether there are risk operations in the access permissions and transmitted data, and determine the access control information in combination with the duration of the terminal's access to the system, so as to analyze and screen the risk operations in the interaction process between the terminal and the power grid system, avoid risk operations that threaten the safe and stable operation of the power grid system, and thus improve the security of the power grid system.
[0081] In an exemplary embodiment, determining the second risk operation information based on the transmission information includes: obtaining storage unit information corresponding to the address information of the transmission information; determining the second risk operation information based on the storage unit information and the access permission range information; and / or obtaining keyword information in the transmission information; determining the confidentiality level information of the transmission information based on the keyword information and a preset mapping relationship; determining the second risk operation information based on the confidentiality level information and the access permission range information.
[0082] The address information may refer to information representing the storage location of the transmission information. In practical applications, the address information may include but is not limited to a memory address, a file path, and a hardware address.
[0083] The storage unit information may refer to information representing a location for storing specific data. In practical applications, the storage unit may be used as a basic storage unit.
[0084] The keyword information may refer to information representing words with specific meanings / significances. In practical applications, the keyword information may include but is not limited to keywords.
[0085] The preset mapping relationship may refer to information representing the mapping relationship between keyword information and confidentiality levels.
[0086] The confidentiality level information may refer to information representing the confidentiality level of the transmitted information.
[0087] As an example, in order to determine whether there is an abnormality in the transmission information, for each access operation, the server can obtain the storage unit information corresponding to the address information of the transmission information, and compare the data interaction range represented by the access permission range information with the storage unit information, and determine whether the area represented by the storage unit information is fully included in the data interaction range represented by the access permission range information. When the area represented by the storage unit information is not fully included in the data interaction range represented by the access permission range information, the server can determine that the current access operation is a second risk operation, and the server can determine the second risk operation information based on the occurrence time and number of each second risk operation. In order to determine whether there is an abnormality in the transmission information, the server can also obtain keyword information in the transmission information, and determine the confidentiality level information of the transmission information based on the keyword information and the preset mapping relationship. The server can compare the confidentiality level information and the access permission range information, and determine whether the operation authority represented by the access permission range information can operate the information of the confidentiality level represented by the confidentiality level information. When the terminal device / user does not have the corresponding authority, the server can determine that the current access operation is a second risk operation, and the server can determine the second risk operation information based on the occurrence time and number of each second risk operation.
[0088] In this embodiment, by obtaining storage unit information corresponding to the address information of the transmission information; determining the second risk operation information based on the storage unit information and the access permission range information; and / or obtaining keyword information in the transmission information; determining the confidentiality level information of the transmission information based on the keyword information and a preset mapping relationship; determining the second risk operation information based on the confidentiality level information and the access permission range information, it is possible to analyze the storage location / confidentiality level of the transmission information and match the permission / data interaction range represented by the access permission range information, thereby accurately detecting and screening out risky operations, so that access control information can be subsequently determined in combination with the risk operations, thereby improving the accuracy of the access control information, and further improving the security of the power grid system.
[0089] In some embodiments, the first risk operation information, the second risk operation information and the access duration information of the terminal device to the power grid system are dynamically verified to determine the access control information for the terminal device, including: determining a first risk assessment value based on the first risk operation information and the first weight information within a target time period; determining a second risk assessment value based on the second risk operation information and the second weight information within the target time period; determining an assessment threshold based on the access duration information, the first risk operation information and the second risk operation information; and determining the access control information based on the ratio between the sum of the first risk assessment value and the second risk assessment value and the assessment threshold.
[0090] The target time period may refer to a pre-set time period for analyzing risk operations of terminal devices. In actual applications, the length of the target time period may be flexibly adjusted based on actual needs.
[0091] The first weight information may refer to information representing the degree of influence of the first risk operation on the risk assessment result.
[0092] The first risk assessment value may refer to information representing the degree of influence of the first risk operation on the access control information.
[0093] The second weight information may refer to information representing the degree of influence of the second risk operation on the risk assessment result.
[0094] The second risk assessment value may refer to information representing the degree of influence of the second risk operation on the access control information.
[0095] The assessment threshold may refer to information for generating / calculating risk assessment results.
[0096] As an example, Figure 3 As shown, a schematic diagram of a trust evaluation framework is provided. In order to accurately and reasonably trust evaluate and control the access operation of the terminal device to the power grid system within the target time period (i.e., obtain accurate access control information), the server can count and record the first type of risk operations according to whether the operation area of the access operation within the target time period is within the permission range represented by the permission range information or the non-authorization range, determine the first risk operation information, and combine the evaluation function B of the first type of risk operation according to the first risk operation information and the first weight information β. j , determine the first risk assessment value. The server can also count and record the second type of risk operations according to whether there is an abnormality in the transmission information between the terminal device and the power grid system within the target time period, determine the second risk operation information, and combine the evaluation function C of the second type of risk operation according to the second risk operation information and the second weight information γ. j, determine the second risk assessment value, and then the server can use the timer to obtain the access time information of the terminal device to the power grid system, and accumulate the risk according to the access time information, the number of occurrences of the first risk operation information, and the number of occurrences of the second risk operation information to determine the assessment threshold d N Then, the server can perform a trust assessment based on the ratio between the sum of the first risk assessment value and the second risk assessment value and the assessment threshold, and calculate the risk assessment result. In practical applications, the risk assessment results can be divided into two categories: the first risk assessment result can represent that the risk in the data interaction process between the terminal device and the power grid system is low (such as the terminal device is in a trusted state), and the second risk assessment result can represent that the risk in the data interaction process between the terminal device and the power grid system is high (such as the terminal device is in an untrusted state). The server can compare the risk assessment result with the preset assessment result threshold to determine the access control information. For example, when the risk assessment result is less than the preset assessment result threshold, the server can determine that the terminal device is in a trusted state, otherwise, the server can determine that the terminal device is in an untrusted state.
[0097] In this embodiment, a first risk assessment value is determined based on the first risk operation information and the first weight information within the target time period; a second risk assessment value is determined based on the second risk operation information and the second weight information within the target time period; an assessment threshold is determined based on the access duration information, the first risk operation information, and the second risk operation information; and access control information is determined based on the ratio between the sum of the first risk assessment value and the second risk assessment value and the assessment threshold. The first risk operation information, the second risk operation information, and their respective weights can be used to analyze the degree of influence of the risk operation on access control, and obtain accurate risk assessment results, thereby generating accurate access control information based on the risk assessment results, thereby improving the security of the power grid system.
[0098] In some embodiments, access control information is determined based on the ratio between the sum of the first risk assessment value and the second risk assessment value and the assessment threshold, including: obtaining the number of verification failures corresponding to the device identification information and the user information within the target time period; determining the verification risk assessment value based on the number of verification failures and third weight information; obtaining the sum of the first risk assessment value, the second risk assessment value and the verification risk assessment value; and determining the access control information based on the ratio between the sum and the assessment threshold.
[0099] The number of verification failures may refer to information representing the total number of verification failures when verifying device identification information and user information within a target time period.
[0100] The third weight information may refer to information characterizing the degree of influence of identity authentication failure on the risk assessment result.
[0101] The verification risk assessment value may refer to information that characterizes the degree of impact of identity authentication failure on access control information.
[0102] As an example, Figure 3 As shown, a schematic diagram of a trust evaluation framework is provided. The server can use the device identification information and user information to perform static verification on the terminal device / user to determine the static verification risk. The server can also combine the identity verification results (such as static verification risk) of the terminal device in the target time period to perform risk assessment on the terminal device. The server can obtain the number of verification failures corresponding to the device identification information and user information in the target time period, and combine the identity verification evaluation function A according to the number of verification failures and the third weight information α. j , determine the verification risk assessment value, and then the server can obtain the sum of the first risk assessment value, the second risk assessment value and the verification risk assessment value, and perform a trust assessment based on the ratio between the sum and the assessment threshold, calculate the risk assessment result, and compare the risk assessment result with the preset assessment result threshold to determine the access control information.
[0103] In this embodiment, the number of verification failures corresponding to the device identification information and user information within the target time period is obtained; the verification risk assessment value is determined based on the number of verification failures and the third weight information; the sum of the first risk assessment value, the second risk assessment value and the verification risk assessment value is obtained; and the access control information is determined based on the ratio between the sum and the assessment threshold. This can take into account the impact of identity authentication on the risk assessment results, and determine accurate access control information based on the risk operation and access duration in combination with the identity authentication results, thereby improving the security of the power grid system.
[0104] In some embodiments, the above method also includes: when the verification of device identification information and user information fails, sending a verification request to the terminal device, and obtaining the updated device identification information and updated user information returned by the terminal device; verifying the updated device identification information and updated user information, and recording the number of verifications; when the number of verifications is greater than a preset threshold, prohibiting the terminal device from accessing the power grid system.
[0105] The verification request may refer to information used to represent a server request to obtain device identification information and user information of a terminal device.
[0106] The updated device identification information may refer to the device identification information returned by the terminal device in response to the verification request.
[0107] The updated user information may refer to the user information returned by the terminal device in response to the verification request.
[0108] The number of verification times may refer to information representing the total number of times identity verification is performed on device identification information and user information.
[0109] The preset times threshold may refer to pre-set information used to determine whether the number of verifications meets preset identity authentication requirements.
[0110] As an example, Figure 4 As shown, a schematic diagram of an identity authentication process is provided. When the terminal device is first connected to the power grid system, the server can obtain the device identification information and user information corresponding to the terminal device as basic identification information. Then, when the user requests to perform a business operation (such as an access operation, etc.) to the power grid system through the terminal device, the server can respond to the operation request for the power grid system sent by the user through the terminal device, obtain the device identification information and user information corresponding to the terminal device, and compare the device identification information and user information corresponding to the terminal device with the basic identification information. When the device identification information and user information match the basic identification information, the server can determine that the identity authentication is passed, and the server can operate the terminal device Check of permissions: when the device identification information and user information do not match the basic identification information, the server may determine that the verification of the device identification information and user information has failed. The server may send a verification request to the terminal device, and obtain the updated device identification information and updated user information returned by the terminal device, verify the updated device identification information and updated user information, and record the number of verifications (the verification can be set to 2 at this time). If the verification still fails, the server may request the device identification information and user information for verification again (i.e., repeated verification). When the number of verifications is greater than the preset threshold (e.g., 3 times), the server may block the terminal device and user, i.e., prohibit the terminal device from accessing the power grid system.
[0111] In this embodiment, when the verification of device identification information and user information fails, a verification request is sent to the terminal device, and the updated device identification information and updated user information returned by the terminal device are obtained; the updated device identification information and updated user information are verified, and the number of verifications is recorded; when the number of verifications is greater than a preset threshold, the terminal device is prohibited from accessing the power grid system, and the number of identity authentications can be combined to timely analyze and record the identity authentication situation. When the identity authentication fails for multiple times, the terminal device is prohibited from accessing the power grid system, thereby preventing terminal devices / users with multiple identity authentication failures from threatening the safe and stable operation of the power grid system, thereby improving the security of the power grid system.
[0112] In some embodiments, access permission scope information is determined based on device identification information and user information, including: determining device access permission scope information of the terminal device in a preset device permission database based on the device identification information; determining user access permission scope information of the terminal device in a preset user permission database based on the user information; and comparing the device access permission scope information with the user access permission scope information to determine the access permission scope information.
[0113] The preset device permission database may refer to a database used to record access permissions corresponding to device identification information.
[0114] The device access permission scope information may refer to information representing the operation permission of the terminal device and / or the storage area of the terminal device for interactive data of the power grid system.
[0115] The preset user authority database may refer to a database for recording access authority corresponding to user information.
[0116] The user access permission range information may refer to information representing the user's operation permissions and / or the storage area of the user's interactive data with respect to the power grid system.
[0117] As an example, Figure 5As shown, a flow chart for determining access permission scope information is provided. The server can obtain the access permission and storage area of interactive data of the terminal device in a preset device permission database based on the device identification information, and use the device access permission and storage area of interactive data of the terminal device as the device access permission scope information. The server can also obtain the user's access permission and storage area of interactive data in a preset user permission database based on the user information, and use the user's access permission and storage area of interactive data as the user access permission scope information of the terminal device. The server can then compare the device access permission scope information with the user access permission scope information to determine the access permission scope information. Specifically, the server can use the same operation permission (or access permission) in the device access permission scope information and the user access permission scope information as the operation permission in the access permission scope information, and the server can use the same data interaction area (or data storage area) in the device access permission scope information and the user access permission scope information as the data interaction area in the access permission scope information. Furthermore, the server can also obtain operation application information corresponding to the terminal device's access operation to the power grid system. The operation application information may include a storage area for data to be interacted with. The server can compare the storage area for data to be interacted with in the operation application information and the area represented by the access permission range information, and / or compare the permission requirements corresponding to the storage area for data to be interacted with in the operation application information and the operation permissions contained in the access permission range information to determine whether the access operation exceeds the permission range. When the access operation exceeds the permission range, the server can reject the current access operation and record the current access operation as a risky operation. When the access operation does not exceed the permission range, the server can run the current access operation and enter a data security check (such as analyzing whether there are abnormalities in the transmission information) to facilitate subsequent risk assessment.
[0118] In this embodiment, the device access permission range information of the terminal device is determined in a preset device permission database according to the device identification information; the user access permission range information of the terminal device is determined in a preset user permission database according to the user information; the device access permission range information is compared with the user access permission range information to determine the access permission range information. The device access permission range information and the user access permission range information can be compared to accurately obtain the access permission range information, so as to use the access permission range information to perform a reasonable and accurate risk assessment on the terminal device, thereby avoiding the existence of abnormal terminal devices that threaten the safe and stable operation of the power grid system, thereby improving the security of the power grid system.
[0119] In some embodiments, Figure 6As shown, a flow chart of a zero-trust dynamic access control method is provided. When a terminal device is connected to the power grid, the terminal device and user information that are connected to the power grid for the first time are obtained, and the terminal device and user information that are connected to the power grid for the first time are set as basic identification information. Then, before each operation of the terminal device, the terminal device and user information are obtained again, and the terminal device and user information obtained before each operation are compared with the basic identification information to ensure the consistency of the terminal device and user information during the real-time operation. When the terminal device is connected to the power grid, the terminal device and user information are obtained by static verification. The terminal device and user information can be obtained by information verification such as password, personal identification number, device identification number, or by hardware device information verification such as pass card, information token, or by biometric information verification such as fingerprint, voiceprint, face, etc. During the static verification process, the terminal device and user information are backed up to obtain basic identification information. When the terminal device and user apply for an operation, the terminal device and user information need to be obtained again (the acquisition method is set according to the information obtained by static verification, such as biometric information can be obtained through fingerprint, voiceprint or face recognition, and user information can be confirmed through multiple identification methods); the terminal device and user information obtained again is compared with the basic identification information. If there is a mismatch, it is necessary to repeat the verification until the consistency of the terminal device and user information is met before the operation can be continued. The number of verifications can be set. If the terminal device and user information does not match the basic identification information for more than 3 times, the terminal device and user will be blocked and prohibited from accessing the power grid.
[0120] The server can obtain the access rights of the terminal device in the power Internet of Things based on the information of the terminal device and the user, and obtain the operation rights of the user, that is, obtain the area that the user can access and query in the power Internet of Things, extract the commonly accessed area in combination with the terminal device access rights and the user operation rights, and confirm the authority scope of the terminal device and the user in the power grid. Specifically, the server can divide the authority scope of the terminal device according to the device security level of the terminal device in the power grid system. The security level of the terminal device is based on whether the device model and device identification code of the terminal device are registered in the internal device database of the power grid system. If so, the terminal device has a larger range of access rights. Verify whether the user is an internal staff member of the power grid system based on the user's identity information tag, and verify the user's identity level, and obtain the user's access rights scope in the power grid system based on the user's identity level; combine the overlapping part of the device and user's authority scope as the access rights scope of the terminal device and user in the power grid system this time.
[0121] When the terminal device and the user perform an operation, the server can obtain their operation application information, obtain the various areas in the power Internet of Things involved in the operation based on the operation application information, and evaluate it based on the authority scope of the terminal device and the user in the power grid. If it exceeds the authority scope, the operation application is rejected and recorded as a type of risk operation of the terminal device and the user. When the terminal device and the user submit an operation application, the power grid area that needs to be accessed under the operation is obtained based on the operation application information, that is, the operation area that the terminal device and the user need to access when performing the operation is obtained. According to the access operation instruction issued by the terminal device and the user, the data interaction scope involved in the access operation instruction is obtained, and the data interaction scope is compared with the access permission scope of the terminal device and the user in the power grid system. If it exceeds the access permission scope, it is marked as a type of risk operation.
[0122] When the terminal device and the user are operating, the server can intercept the information data (such as transmission information) output from the terminal device, and extract the storage area corresponding to the information data in the power grid and the confidentiality level of the information data according to the information data. When the storage area involved in the detected information data exceeds the authority of the terminal device and the user; or the confidentiality level of the detected information data is higher than the authority level of the terminal device and the user, the current operation of the terminal device and the user is interrupted and recorded as a second-class risk operation of the terminal device and the user. Specifically, during the operation of the terminal device and the user, the server can monitor the signal transmission channel between the terminal device and the power grid, obtain the data information of the input terminal device based on the monitored signal transmission channel, trace the data information of the input terminal device, extract the address information of the data information, perform addressing operations in the power grid according to the address information of the data information, obtain the storage unit of the address information, that is, the storage unit that sends the information data, and judge whether the storage unit is the storage device of the data information in combination with the storage properties of the storage unit. If the storage unit is a temporary storage unit for the information data, the operation process of obtaining the data information is obtained by querying the storage unit, tracing the actual storage location of the data information, and comparing the actual storage location area with the authority range of the terminal device and the user. If it exceeds the authority range of the terminal device and the user, the current operation of the terminal device and the user is interrupted and recorded as a second-class risk operation of the terminal device and the user. Secondly, the confidentiality of the intercepted data information is tested, the keywords of the data information are extracted, and the confidentiality level of the data information is queried based on the keyword information of the data information. If the confidentiality level of the data information exceeds the authority range of the terminal device and the user, the current operation of the terminal device and the user is interrupted and recorded as a second-class risk operation of the terminal device and the user.
[0123] The server can perform real-time risk assessment on users and terminal devices based on type I risk operations and type II risk operations. When the real-time risk assessment is too high, the terminal device and user are marked as risk units, and the signal connection between the risk and the power grid is interrupted. Specifically, the server can perform dynamic verification based on the real-time operations of the terminal device and the user to improve the reliability and security of the management and control of terminal devices and users connected to the power Internet of Things. Perform real-time risk assessment on terminal devices and users connected to the power grid, record and organize data on identity authentication, type I risk operations, and type II risk operations based on various operations performed by the terminal devices and users during access to the power grid, combine the data for risk assessment, calculate the trust (such as risk assessment results) of the terminal devices and users, and interrupt the connection between the terminal devices and users and the power grid when the trust is lower than the preset value. In the specific implementation, the calculation expression of the risk assessment result can be expressed as:
[0124] .
[0125] Among them, T s can be the risk assessment result of the terminal device and the user, N can be the time when the terminal device is connected to the power grid (such as the access duration information), and the access duration information keyi is updated in real time according to the time when the terminal device is connected to the power grid. α, β, and γ are weighting coefficients, and the sum of α, β, and γ is 1. j is the evaluation function of the identity authentication risk, B j is the evaluation function of the first type of risk, C j is the assessment function of the second type of risk, j is the calculation unit, d N is the evaluation threshold. α, β, and γ can be set and adjusted based on experience, and are generally set to: 0.2, 0.3, and 0.5. When the risk assessment result is lower than 0.2, the terminal device and user are in a trustworthy state. T s It is positively correlated with N, that is, the longer the time N for the terminal equipment to be connected to the power grid, the higher the risk assessment value T of the terminal equipment and the user. s The larger the value (the higher the risk), the longer the access time is, because the access of the terminal device to the power grid involves data transmission between the power grid and the terminal device. The greater the probability of triggering the second type of risk event during the data transmission process (the calculation expression of the risk assessment result shows that the second type of risk calculation weight is the largest), and the greater the risk of the assessment. The time when the terminal device is connected to the power grid can be recorded by a timer; the risk accumulation can be achieved by recording the number of risk operations that occur during the access of the terminal device to the power grid; the server can adjust the assessment threshold in real time based on the timing data of the timer and the risk accumulation result. The calculation expression of the assessment threshold can be expressed as:
[0126] .
[0127] Among them, dN is the evaluation threshold, μ1 is the first allocation coefficient, which is 0.6, μ2 is the second allocation coefficient, which is 0.4, M is the number of risk operations (such as the sum of the number of occurrences of the first type of risk operations and the number of occurrences of the second type of risk operations), N is the time when the terminal device is connected to the power grid, is the normalization parameter.
[0128] In this embodiment, by combining static identity authentication with dynamic identity authentication before each operation, the information of the terminal device and the user is verified by comparison; according to the authority scope of the terminal device and the user, the operation risk of the terminal device and the user is evaluated in combination with the operation application of the terminal device and the user; the security of the information obtained by the terminal device is evaluated according to the data obtained by the terminal device; the security level of the terminal device is evaluated in combination with the operation risk of the terminal device to perform real-time security verification on the terminal device and the user connected to the power grid, and each operation of the terminal device and the user can be authenticated before the operation in real time, and the information of the terminal device and the user is confirmed, so as to improve the verification reliability of the terminal device and the user connected to the power grid. The authority scope is confirmed for each operation request of the terminal device and the user to ensure that the operation of the terminal device and the user meets the authority scope requirements; the information data obtained by the terminal device is traced to obtain the storage area involved in the data information and the confidentiality of the data information; according to the operation risk performed by the terminal device and the user in the process of accessing the power grid and the risk assessment of the data obtained, the terminal device and the user are verified in real time, and the connection between the terminal device and the power grid is managed in combination with the risk assessment of the terminal device and the user, so as to improve the safety and reliability of the power grid operation.
[0129] It should be understood that, although the various steps in the flowcharts involved in the above-mentioned embodiments are displayed in sequence according to the indication of the arrows, these steps are not necessarily executed in sequence according to the order indicated by the arrows. Unless there is a clear explanation in this article, the execution of these steps does not have a strict order restriction, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-mentioned embodiments can include multiple steps or multiple stages, and these steps or stages are not necessarily executed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a part of the steps or stages in other steps.
[0130] Based on the same inventive concept, the embodiment of the present application also provides a zero-trust dynamic access control device for implementing the zero-trust dynamic access control method involved above. The implementation solution provided by the device to solve the problem is similar to the implementation solution recorded in the above method, so the specific limitations in one or more zero-trust dynamic access control device embodiments provided below can refer to the limitations of the zero-trust dynamic access control method above, and will not be repeated here.
[0131] In an exemplary embodiment, Figure 7 As shown, a zero-trust dynamic access control device is provided, including: an information acquisition module 702, a range acquisition module 704, a range verification module 706, an information analysis module 708 and an information generation module 710, wherein:
[0132] The information acquisition module 702 is used to obtain device identification information and user information corresponding to the terminal device in response to an operation request of the terminal device for the power grid system.
[0133] The scope acquisition module 704 is used to determine access permission scope information according to the device identification information and the user information when the device identification information and the user information are verified.
[0134] The scope verification module 706 is used to obtain the transmission information between the terminal device and the power grid system when the access permission scope information matches the operation area information corresponding to the operation request.
[0135] An information analysis module 708 is used to determine first risk operation information according to the access permission scope information, and to determine second risk operation information according to the transmission information; the first risk operation information is used to characterize an operation with abnormalities in the access permission scope; the second risk operation information is used to characterize an operation with abnormalities in the transmission information;
[0136] The information generation module 710 is used to dynamically verify the first risk operation information, the second risk operation information and the access duration information of the terminal device to the power grid system, and determine the access control information for the terminal device; the access control information is used to control the access operation of the terminal device to the power grid system.
[0137] In one of the exemplary embodiments, the information analysis module 708 is specifically used to obtain storage unit information corresponding to the address information of the transmission information; determine the second risk operation information based on the storage unit information and the access permission range information; and / or obtain keyword information in the transmission information; determine the confidentiality level information of the transmission information based on the keyword information and a preset mapping relationship; determine the second risk operation information based on the confidentiality level information and the access permission range information.
[0138] In one of the exemplary embodiments, the information generation module 710 is also specifically used to determine a first risk assessment value based on the first risk operation information and the first weight information within a target time period; determine a second risk assessment value based on the second risk operation information and the second weight information within the target time period; determine an assessment threshold based on the access duration information, the first risk operation information and the second risk operation information; determine the access control information based on the ratio between the sum of the first risk assessment value and the second risk assessment value and the assessment threshold.
[0139] In one of the exemplary embodiments, the information generation module 710 is specifically used to obtain the number of verification failures corresponding to the device identification information and the user information within the target time period; determine a verification risk assessment value based on the number of verification failures and the third weight information; obtain the sum of the first risk assessment value, the second risk assessment value and the verification risk assessment value; and determine the access control information based on the ratio between the sum and the assessment threshold.
[0140] In one of the exemplary embodiments, the above-mentioned device also includes an identity authentication module, which is specifically used to send a verification request to the terminal device when the verification of the device identification information and the user information fails, and obtain the updated device identification information and the updated user information returned by the terminal device; verify the updated device identification information and the updated user information, and record the number of verifications; when the number of verifications is greater than a preset threshold, prohibit the terminal device from accessing the power grid system.
[0141] In one of the exemplary embodiments, the range acquisition module 704 is also specifically used to determine the device access permission range information of the terminal device in a preset device permission database based on the device identification information; determine the user access permission range information of the terminal device in a preset user permission database based on the user information; and compare the device access permission range information with the user access permission range information to determine the access permission range information.
[0142] Each module in the above-mentioned zero-trust dynamic access control device can be implemented in whole or in part by software, hardware and a combination thereof. Each of the above-mentioned modules can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory in the computer device in the form of software, so that the processor can call and execute the operations corresponding to each of the above modules.
[0143] In an exemplary embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as shown in FIG. Figure 8 As shown. The computer device includes a processor, a memory, an input / output interface (Input / Output, referred to as I / O) and a communication interface. Among them, the processor, the memory and the input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store information such as device identification information, user information and access duration information. The input / output interface of the computer device is used to exchange information between the processor and an external device. The communication interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, a zero-trust dynamic access control method is implemented.
[0144] Those skilled in the art will understand that Figure 8 The structure shown in the figure is only a block diagram of a part of the structure related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine certain components, or have a different arrangement of components.
[0145] In one embodiment, a computer device is further provided, including a memory and a processor, wherein a computer program is stored in the memory, and the processor implements the steps in the above method embodiments when executing the computer program.
[0146] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.
[0147] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.
[0148] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with relevant regulations.
[0149] A person of ordinary skill in the art can understand that all or part of the processes in the above-mentioned embodiment method can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to the memory, database or other medium used in the embodiments provided in the present application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in each embodiment provided in this application may include at least one of a relational database and a non-relational database. Non-relational databases may include distributed databases based on blockchains, etc., but are not limited to this. The processor involved in each embodiment provided in this application may be a general-purpose processor, a central processing unit, a graphics processor, a digital signal processor, a programmable logic device, a data processing logic device based on quantum computing, an artificial intelligence (AI) processor, etc., but are not limited to this.
[0150] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0151] The above-described embodiments only express several implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the scope of the present application. It should be pointed out that, for a person of ordinary skill in the art, several variations and improvements can be made without departing from the concept of the present application, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application shall be subject to the attached claims.
Claims
1. A zero-trust dynamic access control method, characterized in that: The method comprises: In response to an operation request of a terminal device for a power grid system, acquiring device identification information and user information corresponding to the terminal device; In the case where the device identification information and the user information are verified, determining access permission scope information according to the device identification information and the user information; When the access permission scope information matches the operation area information corresponding to the operation request, acquiring transmission information between the terminal device and the power grid system; Determine first risk operation information according to the access permission range information, and determine second risk operation information according to the transmission information; the first risk operation information is used to characterize an operation with abnormalities in the access permission range; the second risk operation information is used to characterize an operation with abnormalities in the transmission information; Dynamically verify the first risk operation information, the second risk operation information and the access duration information of the terminal device to the power grid system to determine access control information for the terminal device; the access control information is used to control the access operation of the terminal device to the power grid system.
2. The method according to claim 1, characterized in that The determining the second risk operation information according to the transmission information includes: Acquire storage unit information corresponding to the address information of the transmission information; determining the second risk operation information according to the storage unit information and the access permission range information; and / or Acquire keyword information in the transmission information; Determining confidentiality level information of the transmission information according to the keyword information and the preset mapping relationship; The second risk operation information is determined according to the confidentiality level information and the access permission range information.
3. The method according to claim 1, characterized in that The dynamically verifying the first risk operation information, the second risk operation information, and the access duration information of the terminal device to the power grid system to determine the access control information for the terminal device includes: Determining a first risk assessment value according to the first risk operation information and the first weight information within a target time period; Determine a second risk assessment value according to the second risk operation information and the second weight information within the target time period; determining an evaluation threshold according to the access duration information, the first risk operation information, and the second risk operation information; The access control information is determined according to a ratio between a sum of the first risk assessment value and the second risk assessment value and the assessment threshold.
4. The method according to claim 3, characterized in that The determining the access control information according to the ratio between the sum of the first risk assessment value and the second risk assessment value and the assessment threshold value comprises: Obtain the number of verification failures corresponding to the device identification information and the user information within the target time period; Determining a verification risk assessment value according to the number of verification failures and the third weight information; Obtaining a sum of the first risk assessment value, the second risk assessment value, and the verification risk assessment value; The access control information is determined according to a ratio between the sum and the evaluation threshold.
5. The method according to claim 1, characterized in that The method further comprises: In the case where the verification of the device identification information and the user information fails, sending a verification request to the terminal device, and obtaining the updated device identification information and the updated user information returned by the terminal device; Verifying the updated device identification information and the updated user information, and recording the number of verifications; When the number of verifications is greater than a preset number threshold, the terminal device is prohibited from accessing the power grid system.
6. The method according to claim 1, characterized in that The determining, according to the device identification information and the user information, access permission scope information includes: Determine the device access permission scope information of the terminal device in a preset device permission database according to the device identification information; Determine the user access permission scope information of the terminal device in a preset user permission database according to the user information; The device access permission scope information is compared with the user access permission scope information to determine the access permission scope information.
7. A zero-trust dynamic access control device, characterized in that: The device comprises: An information acquisition module, configured to obtain device identification information and user information corresponding to the terminal device in response to an operation request of the terminal device for the power grid system; A scope acquisition module, configured to determine access permission scope information according to the device identification information and the user information when the device identification information and the user information are verified; a range verification module, configured to obtain transmission information between the terminal device and the power grid system when the access permission range information matches the operation area information corresponding to the operation request; an information analysis module, configured to determine first risk operation information according to the access permission scope information, and to determine second risk operation information according to the transmission information; the first risk operation information is used to characterize an operation with abnormalities in the access permission scope; the second risk operation information is used to characterize an operation with abnormalities in the transmission information; An information generation module is used to dynamically verify the first risk operation information, the second risk operation information and the access duration information of the terminal device to the power grid system, and determine the access control information for the terminal device; the access control information is used to control the access operation of the terminal device to the power grid system.
8. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 6 are implemented.
9. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
10. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Zero-trust dynamic authorization method and device and computer equipment
CN112165461A
Zero-trust boundary-free security access system
CN114205116A