A trust evaluation method, system and related device

By using a centralized trust assessment device and a unified trust assessment model, the problem of differences in trust assessment models between different devices is solved, thereby enabling the establishment of trust relationships between devices and improving security.

CN119276523BActive Publication Date: 2026-02-13HUAWEI TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202310833293.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-06
Publication Date
2026-02-13
Estimated Expiration
2043-07-06

AI Technical Summary

Technical Problem

The use of different trust assessment models by different devices in the network makes it impossible to establish a unified trust relationship, and existing technologies lack a unified trust assessment standard.

Method used

A centralized evaluation device is introduced, and a trust evaluation model is used to evaluate the devices to ensure that devices with different trust evaluation models can establish trust relationships.

Benefits of technology

It enables the establishment of trust relationships between devices using different trust assessment models, thereby improving the security and normal operation of network devices.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119276523B_ABST
    Figure CN119276523B_ABST
Patent Text Reader

Abstract

The application provides a trust evaluation method, system and related device. The method is applied to a trust evaluation system including an evaluation device, a first device and a second device. The first device sends a trust evaluation request including identity information of the second device to the evaluation device, so as to obtain a trust evaluation result of the second device. After receiving the trust evaluation request, the evaluation module obtains trust evaluation data of the second device according to the identity information of the second device. Then, the trust evaluation of the second device is performed according to a trust evaluation model for trust evaluation and the trust evaluation data of the second device, so as to obtain the trust evaluation result of the second device and send the trust evaluation result to the first device, so that the first device determines whether to trust the second device. The trust evaluation of different devices is realized by the centralized evaluation module, the trust evaluation problem between devices using different trust evaluation models can be solved, and a trust relationship between two devices using different trust evaluation models is established.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computer, in particular to a trust evaluation method, system and related equipment. BACKGROUND

[0002] With the diversification of network functions and services, only relying on security authentication cannot meet the requirements of trust between network devices and services. Therefore, the concept of trust evaluation and classification needs to be introduced in future networks, and the management of information interaction between network devices is carried out according to the results of trust evaluation and trust levels.

[0003] In the field of information and communications technology (ICT), trust is that a physical device or object in cyberspace will complete a given task in a specified form, thereby achieving a specified goal. The current trust evaluation has no unified standard, and different manufacturers may use different trust evaluation models for different devices and application scenarios, so the results of trust evaluation differ according to different trust evaluation models. Therefore, how to enable any two devices in the network to establish a trust relationship is a technical problem to be solved. SUMMARY

[0004] The present application provides a trust evaluation method, system and related equipment, which can enable two devices using different trust evaluation models to establish a trust relationship.

[0005] In a first aspect, the present application provides a trust evaluation method, comprising: receiving, by an evaluation device, a trust evaluation request sent by a first device, the trust evaluation request comprising identity information of a second device, the trust evaluation request being used to obtain a trust evaluation result of the second device; then obtaining, by the evaluation device, trust evaluation data of the second device according to the identity information of the second device; performing trust evaluation on the second device according to a trust evaluation model and the trust evaluation data of the second device to obtain the trust evaluation result of the second device; and sending the trust evaluation result of the second device to the first device.

[0006] By deploying a centralized evaluation device capable of trust evaluation in the trust evaluation system, when any two devices in the trust evaluation system need to establish a connection, the evaluation device performs trust evaluation on the devices through the trust evaluation model, so that the devices determine whether to establish a connection according to the trust evaluation result, which can solve the problem of trust evaluation between devices using different trust evaluation models, and enable two devices using different trust evaluation models to establish a trust relationship.

[0007] In a possible implementation, the method further includes: the evaluation device receives and records the registration information of the first device sent by the first device, wherein the registration information of the first device includes identity information of the first device and a trust evaluation model of the first device; and only the result of the trust evaluation performed by using the trust evaluation model of the first device is recognized by the first device. The evaluation data attribute of the first device indicates an attribute of data of the second device required when the trust evaluation of the second device is performed according to the trust evaluation model of the first device.

[0008] The devices in the trust evaluation system all need to send their respective registration information to the evaluation device, and then the evaluation device saves the registration information, for example, the first device and the second device both need to upload the registration information to the evaluation device. In the case that the first device requests to perform the trust evaluation on the second device, the evaluation device can perform the trust evaluation on the second device according to the saved trust evaluation model of the first device and the information of the second device.

[0009] In a possible implementation, the evaluation device performs the trust evaluation on the second device according to the trust evaluation model and the trust evaluation data of the second device to obtain the trust evaluation result of the second device, including: the evaluation device acquires the trust evaluation model of the first device according to the identity information of the first device; then performs the trust evaluation on the second device according to the trust evaluation model of the first device and the trust evaluation data of the second device to obtain the first trust evaluation result of the second device, and takes the first trust evaluation result as the trust evaluation result of the second device; wherein the trust evaluation request includes the identity information of the first device.

[0010] Since only the result of the trust evaluation performed by using the trust evaluation model of the first device is recognized by the first device, in the case that the first device requests to perform the trust evaluation on the second device, only the result of the trust evaluation performed on the second device by using the trust evaluation model of the first device and the trust evaluation data of the second device is accepted by the first device, thereby improving the security of the system and the device.

[0011] In a possible implementation, the registration information of the first device further includes a presentation form of the evaluation result corresponding to the first device, and the presentation form of the evaluation result corresponding to the first device refers to a presentation form of the evaluation result obtained by performing the trust evaluation by using the trust evaluation model of the first device.

[0012] The trust evaluation of the second device according to the trust evaluation model and the trust evaluation data of the second device includes: the evaluation device performing the trust evaluation of the second device according to the trust evaluation model of the second device and the trust evaluation data of the second device, to obtain the second trust evaluation result of the second device; and converting the second trust evaluation result into the evaluation result presentation form corresponding to the first device according to the evaluation result presentation form corresponding to the first device, to obtain the trust evaluation result of the second device.

[0013] The evaluation device can also perform the trust evaluation of the second device according to the trust evaluation model of the second device. Since the trust evaluation model of the second device can be different from the trust evaluation model of the first device, the presentation form of the evaluation result can also be different. For example, the trust evaluation model of the first device is a decision model, and the obtained evaluation result is a trust level; the trust evaluation model of the second device is a numerical model, and the obtained evaluation result is a numerical value. Then, the evaluation device converts the second trust evaluation result into the evaluation result presentation form corresponding to the first device according to the evaluation result presentation form corresponding to the first device, so that the first device can be identified.

[0014] In a possible implementation, the registration information of the first device further includes an evaluation data attribute of the first device, and the evaluation data attribute of the first device indicates the attribute of the data of the second device required when performing the trust evaluation of the second device according to the trust evaluation model of the first device.

[0015] Before the trust evaluation of the second device according to the trust evaluation model of the second device and the trust evaluation data of the second device, the evaluation device further obtains the trust evaluation model of the first device according to the identity information of the first device, and in a case where the trust evaluation data of the second device does not satisfy the evaluation data attribute of the first device, the evaluation device further obtains the trust evaluation model of the second device and the evaluation result presentation form corresponding to the first device, and then performs the trust evaluation of the second device according to the trust evaluation model of the second device.

[0016] In a case where the trust evaluation data of the second device does not satisfy the data required when performing the trust evaluation of the second device according to the trust evaluation model of the first device, the trust evaluation of the second device can be performed according to the trust evaluation model of the second device.

[0017] In a possible implementation, the method further includes: the evaluation device receiving and recording the access control policy of the first device sent by the management device, and the access control policy of the first device indicating the devices that can be accessed by the first device and the devices that can access the first device.

[0018] By configuring the access control policy of the first device, in the case that the first device requests the trust evaluation of other devices, for example, the other devices are the second devices described above, the evaluation device can determine whether the first device can access the second device according to the access control policy of the first device, and in the case that the first device can access the second device, the evaluation device will only perform the trust evaluation on the second device; in the case that the other devices request the trust evaluation of the first device, the evaluation device can also determine whether the other devices can access the first device according to the access control policy of the first device, and in the case that the other devices can access the first device, the evaluation device will only perform the trust evaluation on the first device. By configuring the access control policy, the security of each device in the trust evaluation system can be improved, and the normal operation of each device in the system can be ensured, for example, a device with low security cannot access some important devices in the system, which can prevent the intrusion of these important devices through the device with low security.

[0019] In a possible implementation, the above recording the registration information of the first device includes: the evaluation device sends the registration information of the first device to the management device; the evaluation device receives the registration result of the first device returned by the management device, and the registration result includes agreeing to register or disagreeing to register; and the evaluation device records the registration information of the first device and returns a response message of successful registration to the first device in the case that the registration result is agreeing to register.

[0020] After the device that joins the trust evaluation system sends the registration information to the evaluation module, whether the device can join the trust evaluation system is determined by the management device, and in the case that the management device determines that the device can join the trust evaluation system, the evaluation device will record the registration information of the device. Therefore, it can be prevented that the illegal device joins the trust evaluation system and causes a security risk to other devices in the trust evaluation system.

[0021] In a possible implementation, the above method further includes: the evaluation device receives and records the access control policy of the first device returned by the management device, and the access control policy of the first device is configured by the management device in the case that the registration result is agreeing to register, and the access control policy of the first device indicates the devices that can be accessed by the first device and the devices that can access the first device.

[0022] In the case that the management device determines that a device can join the trust evaluation system, the access control policy of the device is configured, which avoids wasting computing resources.

[0023] In a possible implementation, the acquiring, by the evaluation device, of the trust evaluation data of the second device according to the identity information of the second device comprises: in a case where the evaluation device determines, according to the access control policy of the first device, that the first device can acquire the trust evaluation result of the second device, acquiring the trust evaluation data of the second device according to the identity information of the second device.

[0024] The evaluation module can determine, according to the access control policy of the first device, whether the first device can access the second device, and only when the first device can access the second device, the evaluation module performs the trust evaluation on the second device, thereby avoiding establishing a connection between devices that cannot access each other, and improving the security of the system.

[0025] In a possible implementation, the evaluation device and the management device can be the same device, or can be different devices. It should be understood that if the evaluation device and the management device are the same device, there is no interaction process between the evaluation device and the management device.

[0026] In a second aspect, the present application provides a trust evaluation method, applied to a trust evaluation system comprising an evaluation device, a first device and a second device, wherein the first device sends a trust evaluation request comprising identity information of the second device to the evaluation device, the trust evaluation request being used to acquire a trust evaluation result of the second device; the evaluation device acquires trust evaluation data of the second device according to the identity information of the second device after receiving the trust evaluation request; then the evaluation device performs trust evaluation on the second device according to a trust evaluation model used for trust evaluation and the trust evaluation data of the second device, obtains the trust evaluation result of the second device, and sends the trust evaluation result of the second device to the first device, so that the first device determines whether to establish a connection with the second device according to the trust evaluation result.

[0027] The trust evaluation system can be a system in an Internet of Things scenario, for example, the trust evaluation system is a smart home scenario, and the evaluation device is deployed in a centralized device in the trust evaluation system that can perform calculation according to the trust evaluation model. By implementing the method, when any two devices in the trust evaluation system need to establish a connection, the evaluation device performs trust evaluation on the devices through the trust evaluation model, so that the devices determine whether to establish a connection according to the trust evaluation result, which can solve the problem of trust evaluation between devices using different trust evaluation models, and enable two devices using different trust evaluation models to establish a trust relationship.

[0028] In a possible implementation, the method further includes: the first device sends the registration information of the first device to the evaluation device, and the evaluation device saves the registration information of the first device after receiving the registration information of the first device. The registration information of the first device includes identity information of the first device, a trust evaluation model of the first device, and evaluation data attributes of the first device; the result obtained by performing trust evaluation by using the trust evaluation model of the first device is only recognized by the first device; and the evaluation data attributes of the first device indicate attributes of data of the second device required when performing trust evaluation on the second device according to the trust evaluation model of the first device.

[0029] The devices in the trust evaluation system all need to send their respective registration information to the evaluation device, and then the evaluation device saves the registration information, for example, the first device and the second device both need to upload the registration information to the evaluation device. In the case that the first device requests to perform trust evaluation on the second device, the evaluation device can perform trust evaluation on the second device according to the saved trust evaluation model of the first device and the information of the second device.

[0030] In a possible implementation, the trust evaluation system further includes a management device, and the method further includes: the management device obtains the identity information of the first device, and configures an access control policy of the first device, the access control policy of the first device indicating devices that can be accessed by the first device and devices that can access the first device; and the management device sends the identity information of the first device and the access control policy of the first device to the evaluation device.

[0031] By configuring the access control policy of the first device, in the case that the first device requests to perform trust evaluation on other devices, for example, the other devices are the second device, the evaluation device can determine whether the first device can access the second device according to the access control policy of the first device, and the evaluation device performs trust evaluation on the second device only in the case that the first device can access the second device; in the case that other devices request to perform trust evaluation on the first device, the evaluation device can also determine whether the other devices can access the first device according to the access control policy of the first device, and the evaluation device performs trust evaluation on the first device only in the case that the other devices can access the first device. By configuring the access control policy, the security of each device in the trust evaluation system can be improved, and the normal operation of each device in the system can be ensured, for example, a device with low security cannot access some important devices in the system, and intrusion into the important devices through the device with low security can be prevented.

[0032] In a possible implementation, the trust evaluation system further includes a management device; before the evaluation device saves the registration information of the first device, the trust evaluation system further includes that the evaluation device sends the registration information of the first device to the management device; the management device determines a registration result of the first device according to the registration information of the first device, the registration result including an approval of registration or a disapproval of registration; and the evaluation device receives the registration result of the first device, saves the registration information of the first device, and returns a response message of successful registration to the first device when the registration result is the approval of registration.

[0033] After the devices that join the trust evaluation system send the registration information to the evaluation device, the management device determines whether the devices can join the trust evaluation system, and the evaluation device records the registration information of the devices only when the management device determines that the devices can join the trust evaluation system. Therefore, the trust evaluation system can be prevented from being joined by illegal devices, and the security of other devices in the trust evaluation system can be ensured.

[0034] In a possible implementation, the method further includes that the management device configures an access control policy of the first device when the registration result is the approval of registration, the access control policy of the first device indicating devices that can be accessed by the first device and devices that can access the first device; and the management device sends the access control policy of the first device to the evaluation device.

[0035] The access control policy of a device is configured only when the management device determines that the device can join the trust evaluation system, so that the computing resources are not wasted.

[0036] In a possible implementation, before the evaluation device performs the trust evaluation on the second device according to the trust evaluation model and the trust evaluation data of the second device, the evaluation device further includes that the evaluation device obtains the trust evaluation model of the first device according to the identity information of the first device in the trust evaluation request; and then performs the trust evaluation on the second device according to the trust evaluation model of the first device and the trust evaluation data of the second device, to obtain a first trust evaluation result of the second device, and takes the first trust evaluation result as the trust evaluation result of the second device.

[0037] The result obtained by using the trust evaluation model of the first device to perform the trust evaluation is recognized by the first device, so that the result obtained by using the trust evaluation model of the first device and the trust evaluation data of the second device to perform the trust evaluation on the second device is accepted by the first device when the first device requests to perform the trust evaluation on the second device.

[0038] In a possible implementation, the evaluation device obtains the trust evaluation data of the second device according to the identity information of the second device, including: when the evaluation device determines, according to the access control policy of the first device, that the first device can obtain the trust evaluation result of the second device, the evaluation device obtains the trust evaluation data of the second device according to the identity information of the second device.

[0039] The evaluation device can determine, according to the access control policy of the first device, whether the first device can access the second device, and the evaluation device performs the trust evaluation on the second device only when the first device can access the second device, thereby avoiding establishing a connection between devices that cannot access each other, and improving the security of the system.

[0040] In a possible implementation, the registration information of the first device further includes a presentation form of the evaluation result corresponding to the first device, the presentation form of the evaluation result corresponding to the first device refers to a presentation form of an evaluation result obtained by using the trust evaluation model of the first device to perform the trust evaluation, the evaluation device obtains the trust evaluation model of the first device according to the identity information of the first device, and if the trust evaluation data of the second device does not satisfy the trust evaluation model of the first device, the evaluation device obtains the trust evaluation model of the second device and the presentation form of the evaluation result corresponding to the first device, then performs the trust evaluation on the second device according to the trust evaluation model of the second device and the trust evaluation data of the second device, obtains a second trust evaluation result of the second device, and converts the second trust evaluation result into the presentation form of the evaluation result corresponding to the first device according to the presentation form of the evaluation result corresponding to the first device, to obtain the trust evaluation result of the second device.

[0041] In the case that the trust evaluation data of the second device does not satisfy the trust evaluation model of the first device, the trust evaluation can be performed on the second device by using the trust evaluation model of the second device. Since the trust evaluation model of the second device and the trust evaluation model of the first device can be different, the presentation form of the evaluation result can also be different. For example, the trust evaluation model of the first device is a decision model, and the obtained evaluation result is a trust level, the trust evaluation model of the second device is a numerical model, and the obtained evaluation result is a numerical value. The evaluation device converts the second trust evaluation result into the presentation form of the evaluation result corresponding to the first device according to the presentation form of the evaluation result corresponding to the first device, to obtain the evaluation result of the second device.

[0042] In a possible implementation, the evaluation device and the management device can be the same device, or can be different devices. It should be understood that if the evaluation device and the management device are the same device, there is no interaction process between the evaluation device and the management device.

[0043] In a third aspect, the present application provides a trust evaluation system, comprising an evaluation device, a first device and a second device, wherein: the first device is configured to send a trust evaluation request comprising identity information of the second device to the evaluation device, the trust evaluation request being used to obtain a trust evaluation result of the second device; the evaluation device is configured to obtain trust evaluation data of the second device according to the identity information of the second device after receiving the trust evaluation request; then the evaluation device performs trust evaluation on the second device according to a trust evaluation model used for trust evaluation and the trust evaluation data of the second device, obtains the trust evaluation result of the second device, and sends the trust evaluation result of the second device to the first device, so that the first device determines whether to establish a connection with the second device according to the trust evaluation result.

[0044] In a possible implementation, the trust evaluation system further comprises a management device, the management device is configured to obtain identity information of the first device, and configure an access control policy of the first device, the access control policy of the first device indicating devices that can be accessed by the first device and devices that can access the first device; the management device sends the identity information of the first device and the access control policy of the first device to the evaluation device.

[0045] The devices in the trust evaluation system can implement the operations performed by the corresponding devices in the second aspect and any possible implementation of the second aspect.

[0046] In a fourth aspect, the present application provides a trust evaluation apparatus, comprising a communication module and an evaluation module; wherein the communication module is configured to receive a trust evaluation request comprising identity information of a second device sent by a first device, the trust evaluation request being used to obtain a trust evaluation result of the second device; the evaluation module is configured to obtain trust evaluation data of the second device according to the identity information of the second device; perform trust evaluation on the second device according to a trust evaluation model and the trust evaluation data of the second device, and obtain the trust evaluation result of the second device; and the communication module is further configured to send the trust evaluation result of the second device to the first device.

[0047] In a possible implementation, the communication module is further configured to receive registration information of the first device sent by the first device; and a recording module is configured to record the registration information of the first device; wherein the registration information of the first device comprises identity information of the first device, a trust evaluation model of the first device and an evaluation data attribute of the first device; only the result obtained by using the trust evaluation model of the first device for trust evaluation can be recognized by the first device; and the evaluation data attribute of the first device indicates an attribute of data of the second device required when performing trust evaluation on the second device according to the trust evaluation model of the first device.

[0048] In one possible implementation, the evaluation module is specifically used to: obtain the trust evaluation model of the first device based on the identity information of the first device; the trust evaluation request includes the identity information of the first device; perform a trust evaluation on the second device based on the trust evaluation model of the first device and the trust evaluation data of the second device to obtain a first trust evaluation result of the second device, and use the first trust evaluation result as the trust evaluation result of the second device.

[0049] In one possible implementation, the registration information of the first device also includes the presentation format of the evaluation result corresponding to the first device. The presentation format of the evaluation result corresponding to the first device refers to the presentation format of the evaluation result obtained by using the trust evaluation model of the first device for trust evaluation.

[0050] The evaluation module is specifically used to: perform a trust evaluation on the second device based on the trust evaluation model and trust evaluation data of the second device, and obtain a second trust evaluation result for the second device; and convert the second trust evaluation result into the evaluation result presentation format corresponding to the first device, and obtain a trust evaluation result for the second device.

[0051] In one possible implementation, the registration information of the first device further includes the evaluation data attributes of the first device. These attributes indicate the attributes of the second device's data required when performing a trust evaluation on the second device based on the first device's trust evaluation model; that is, which attribute data of the device the first device's trust evaluation model requires when evaluating a device. The evaluation module is also used to: obtain the first device's trust evaluation model based on the first device's identity information; if the second device's trust evaluation data does not meet the first device's evaluation data attributes, obtain the second device's trust evaluation model and the corresponding evaluation result presentation format for the first device; and then perform a trust evaluation on the second device based on the second device's trust evaluation model.

[0052] In one possible implementation, the communication module is further configured to receive the access control policy of the first device sent by the management device, the access control policy of the first device indicating the devices that the first device can access and the devices that can access the first device; the recording module is further configured to record the access control policy of the first device.

[0053] In one possible implementation, the communication module is further configured to send the registration information of the first device to the management device; receive the registration result of the first device returned by the management device, the registration result including agreement to registration or disagreement to registration; the evaluation module is further configured to send the registration information of the first device to the recording module if the registration result is agreement to registration, so that the recording module records the registration information of the first device; the communication module is further configured to return a registration success response message to the first device.

[0054] In a possible implementation, the access control policy of the first device is configured by the management device when the registration result is an approval of the registration.

[0055] In a fifth aspect, an embodiment of the present application provides a management apparatus, comprising a communication module and a management module, the management module being configured to implement the operations of the management device in the first aspect or any possible implementation manner of the first aspect, and the communication module being configured to receive information or data sent by other devices to the management apparatus.

[0056] In a sixth aspect, an embodiment of the present application provides a computing device, comprising a processor and a memory, the memory being configured to store instructions, and the processor being configured to execute the instructions, when the processor executes the instructions, implementing the method in the first aspect or any possible implementation manner of the first aspect.

[0057] In a seventh aspect, an embodiment of the present application provides a management device, comprising a processor and a memory, the memory being configured to store instructions, and the processor being configured to execute the instructions, when the processor executes the instructions, implementing the method implemented by the management device in the second aspect or any possible implementation manner of the second aspect.

[0058] In an eighth aspect, the present application provides a computer program product, when the computer program product is run on a computing device, causing the computing device to execute the method in the first aspect or any possible implementation manner of the first aspect.

[0059] In a ninth aspect, the present application provides another computer program product, when the computer program product is run on a computing device, causing the computing device to execute the method implemented by the management device in the second aspect or any possible implementation manner of the second aspect.

[0060] In a tenth aspect, the present application provides a computer readable storage medium, the computer readable storage medium storing instructions, when the instructions are run on a server, causing the server to execute the method in the first aspect or any possible implementation manner of the first aspect.

[0061] In an eleventh aspect, the present application provides a computer readable storage medium, the computer readable storage medium storing instructions, when the instructions are run on a server, causing the server to execute the method implemented by the management device in the second aspect or any possible implementation manner of the second aspect. BRIEF DESCRIPTION OF DRAWINGS

[0062] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0063] Figure 1 This is a schematic diagram of a trust assessment system provided in an embodiment of this application;

[0064] Figure 2 This is an interactive schematic diagram of a trust assessment method provided in an embodiment of this application;

[0065] Figure 3 This is a schematic diagram of a trust assessment device provided in an embodiment of this application;

[0066] Figure 4 This is a schematic diagram of a management device provided in an embodiment of this application;

[0067] Figure 5 This is a schematic diagram of a computing device provided in an embodiment of this application. Detailed Implementation

[0068] The technical solutions in this application will now be described with reference to the accompanying drawings.

[0069] like Figure 1 As shown, Figure 1 This is a schematic diagram of a trust assessment system provided in an embodiment of this application. The trust assessment system includes an assessment device, a first device, and a second device. When the first device needs to perform a trust assessment on the second device to determine whether a connection can be established, it sends a trust assessment request to the assessment device. This trust assessment request includes the identity information of the second device, such as its identifier (ID). The trust assessment request is used to obtain the trust assessment result of the second device. After receiving the trust assessment request, the assessment device retrieves the trust assessment data of the second device from a database. Then, the assessment device performs a trust assessment on the second device based on a trust assessment model and the trust assessment data of the second device, obtaining the trust assessment result of the second device. Finally, the assessment device sends the trust assessment result of the second device to the first device.

[0070] The first device and the second device send their respective registration information to the evaluation device after joining the trust evaluation system. The registration information of the first device includes the identity information of the first device, the trust evaluation model of the first device, and the evaluation data attribute of the first device. The result obtained by using the trust evaluation model of the first device to perform trust evaluation is recognized by the first device. The evaluation data attribute of the first device indicates the attribute of the data of the to-be-evaluated device required by the trust evaluation model of the first device in the case of performing trust evaluation on the to-be-evaluated device by using the trust evaluation model of the first device, that is, the attribute of the data required to be provided by the to-be-evaluated device. The registration information of the second device includes the identity information of the second device, the trust evaluation model of the second device, and the evaluation data attribute of the second device. The result obtained by using the trust evaluation model of the second device to perform trust evaluation is recognized by the second device. The evaluation data attribute of the second device indicates the attribute of the data of the to-be-evaluated device required by the trust evaluation model of the second device in the case of performing trust evaluation on the to-be-evaluated device by using the trust evaluation model of the second device. The to-be-evaluated device writes the registration information into a database after obtaining the registration information of the first device and the registration information of the second device.

[0071] Optionally, the registration information further includes device information of the device. The device information of the first device includes one or more of the following information: device role, device function, device ownership, device geographic information, manufacturer, known threat list, social attribute list, trust evaluation model type, and trust measurement method. The device role indicates the role of the device in the trust evaluation system. In the embodiments of the present application, the role includes administrator, member, and guest. The device function indicates the main function of the device. The known threat list includes software vulnerabilities of the device.

[0072] The trust evaluation model type includes a direct trust evaluation model and an indirect trust evaluation model. The trust measurement method includes a numerical measurement method and a decision measurement method. The numerical measurement method refers to that the evaluation result of the trust evaluation model is a numerical value. The decision measurement method refers to that the evaluation result of the trust evaluation model is a trust level, which can directly indicate the trust degree. For example, the trust level includes no trust, low trust, medium trust, high trust, and fully trust. It should be noted that the trust evaluation model type can also be divided into a numerical model and a decision model. The evaluation result of the numerical model is in the form of a numerical value, that is, the result presentation form in the numerical measurement method. The evaluation result of the decision model is in the form of a trust level, that is, the result presentation form in the decision measurement method.

[0073] Exemplarily, in the trust evaluation system composed of devices in a home network, the evaluation device can be a network access point (NAP), such as a router, or other computing devices with storage and computing functions. The first device and the second device can be smart home devices such as a refrigerator, a television, a washing machine, a sweeping robot, and a camera, a smart phone, a projector, a notebook computer, a head-mounted device, and the like, and the administrator can be a smart phone or a notebook computer used by a user in the home network, and the roles of other devices in the home network are members, and the roles of devices of other users when the devices of the other users join the home network are guests.

[0074] It should be understood that the second device also reports the device information of the second device to the evaluation device after joining the trust evaluation system, which will not be described here.

[0075] In a possible implementation, the trust evaluation system further includes a management device; the management device is configured to obtain the identity information of each device in the trust evaluation system, and then configure an access control policy of each device and send the access control policy to the evaluation device. The access control policy of a device is used to indicate devices that can be accessed by the device and devices that can access the device. For example, the control policy of the first device indicates devices that can be accessed by the first device and devices that can access the first device.

[0076] In the embodiments of the present application, the management device and the evaluation device can be the same device or different devices. For example, in the home network, the management device can be the device whose role is the administrator. In the embodiments of the present application, as shown in Figure 1 the trust evaluation system and method provided by the present application are introduced based on the trust evaluation system shown in

[0077] the trust evaluation system shown in Figure 1 the trust evaluation system shown in Figure 2 Figure 2 is an interaction diagram of a trust evaluation method provided by an embodiment of the present application. The trust evaluation method includes S201 to S206.

[0078] S201. The first device sends registration information of the first device to the evaluation device.

[0079] When the first device joins the trust evaluation system, the first device sends the registration information to the evaluation device for registration. The contents of the registration information of the first device and the registration information of the second device are described above and will not be described here. ​

[0080] S202. The evaluation device records the registration information of the first device.

[0081] The evaluation device saves the registration information of the first device after receiving the registration information of the first device.

[0082] In a possible implementation, the first device also sends the registration information to the management device, and the management device configures an access control policy of the first device after receiving the registration information of the first device, where the access control policy of the first device indicates devices that can be accessed by the first device and devices that can access the first device. Then the management device sends the access control policy of the first device to the evaluation device.

[0083] In a possible implementation, the evaluation device sends a registration request to the management device after receiving the registration information of the first device sent by the first device, where the registration request includes the registration information of the first device. The management device determines whether to agree to the registration of the first device according to the registration information of the first device after receiving the registration request. In a case where the management device determines to agree to the registration request of the first device, the management device sends a response message indicating agreement to registration to the evaluation device; in a case where the management device determines to disagree to the registration request of the first device, the management device sends a response message indicating disagreement to registration to the evaluation device. The evaluation device records the registration information of the first device into a database and returns a message indicating registration success to the first device in a case where the response message indicates agreement to registration; and the evaluation device does not record the registration information of the first device and returns a message indicating registration failure to the first device in a case where the response message indicates disagreement to registration.

[0084] The management device configures an access control policy of the first device in a case where the management device determines to agree to the registration of the first device, and then sends the access control policy of the first device to the evaluation device.

[0085] It should be noted that the second device, the evaluation device, and the management device also perform the above operations when the second device joins the trust evaluation system, which will not be described herein again. In addition, the trust evaluation method provided in this application is described by taking the registration success of the first device and the second device as an example.

[0086] S203. The first device sends a trust evaluation request to the evaluation device.

[0087] The trust evaluation request includes identity information of the second device, for example, an ID of the second device, and is used to obtain a trust evaluation result of the second device. That is, the trust evaluation request indicates that the evaluation device performs trust evaluation on the second device and sends the trust evaluation result to the first device.

[0088] S204. The evaluation device obtains trust evaluation data of the second device according to the identity information of the second device.

[0089] The trust evaluation data is related information of the second device, for example, the device information of the second device, and is used for trust evaluation of the second device. After receiving the trust evaluation request sent by the first device, the evaluation device determines whether the first device needs to obtain the trust evaluation result of the second device according to the identity information of the second device in the trust evaluation request. The evaluation device obtains the trust evaluation data of the second device from the database according to the identity information of the second device.

[0090] It should be noted that if the management device configures the access control policy of the first device, the evaluation device determines whether the first device can access the second device according to the access control policy of the first device before obtaining the trust evaluation data of the second device according to the identity information of the second device. If the first device can access the second device, the evaluation device obtains the trust evaluation data of the second device from the database according to the identity information of the second device. It should be understood that in the embodiments of the present application, the first device can access the second device is taken as an example for introduction.

[0091] S205. The evaluation device performs trust evaluation on the second device according to the trust evaluation model and the trust evaluation data of the second device, and obtains a trust evaluation result of the second device.

[0092] After obtaining the trust evaluation data of the second device, the evaluation device performs trust evaluation on the second device according to the trust evaluation model and the trust evaluation data of the second device, and obtains a trust evaluation result of the second device. The trust evaluation model may be the trust evaluation model of the first device, or the trust evaluation model of the second device.

[0093] The following will introduce the schemes in the two cases that the trust evaluation model is the trust evaluation model of the first device and the trust evaluation model is the trust evaluation model of the second device.

[0094] In a possible implementation, the trust evaluation request further includes identity information of the first device. After receiving the trust evaluation request of the first device, the evaluation device obtains the trust evaluation model of the first device from the database according to the identity information of the first device, and obtains the trust evaluation data of the second device from the database according to the identity information of the second device.

[0095] After obtaining the trust evaluation model of the first device and the trust evaluation data of the second device, the evaluation device performs trust evaluation on the second device according to the trust evaluation model of the first device and the trust evaluation data of the second device, and obtains a first trust evaluation result of the second device. Since the first trust evaluation result is determined according to the trust evaluation model of the first device, the first device can identify the presentation form of the trust evaluation result, and therefore the first trust evaluation result is taken as the trust evaluation result of the second device.

[0096] Specifically, if the trust evaluation data of the second device can meet the requirement of the trust evaluation model of the first device for trust evaluation, that is, the trust evaluation data of the second device includes data corresponding to the evaluation data attribute of the first device, it is indicated that the evaluation device can complete the trust evaluation on the second device based on the trust evaluation model of the first device and the trust evaluation data of the second device. The evaluation data attribute of the first device indicates the attribute of the data of the second device required when performing trust evaluation on the second device according to the trust evaluation model of the first device. For example, the evaluation data attribute of the first device includes identity information, security protocol name, manufacturer, and cryptographic algorithm. If the trust evaluation data of the second device includes data of the above attributes of the second device, it is indicated that the trust evaluation on the second device can be completed based on the trust evaluation model of the first device and the trust evaluation data of the second device.

[0097] In the case that the trust evaluation data of the second device can meet the requirement of the trust evaluation model of the first device for trust evaluation, the evaluation device performs trust evaluation on the second device according to the trust evaluation model of the first device and the trust evaluation data of the second device, obtains a first trust evaluation result of the second device, takes the first trust evaluation result as the trust evaluation result of the second device, and sends the trust evaluation result of the second device to the first device. In the case that the trust evaluation data of the second device does not meet the requirement of the trust evaluation model of the first device for trust evaluation, the evaluation device determines that the trust evaluation result is evaluation failure, and returns the trust evaluation result of evaluation failure to the first device.

[0098] In a possible implementation, the registration information of the first device further includes an evaluation result presentation form corresponding to the first device, where the evaluation result presentation form corresponding to the first device refers to the presentation form of the trust evaluation result obtained by performing trust evaluation using the trust evaluation model of the first device. The presentation form of the trust evaluation result includes a numerical value and a trust level. The numerical value refers to a numerical value of the trust evaluation result, and the trust level refers to a trust level of the trust evaluation result, for example, the trust level includes no trust, low trust, medium trust, high trust, and fully trust.

[0099] In a case where the evaluation device determines that the trust evaluation data of the second device does not satisfy the requirement of the trust evaluation model of the first device for trust evaluation, the evaluation device can obtain the trust evaluation model of the second device from the database, and then perform trust evaluation on the second device according to the trust evaluation model of the second device and the trust evaluation data of the second device, to obtain a trust evaluation result of the second device.

[0100] In a case where the evaluation device determines that the trust evaluation data of the second device does not satisfy the requirement of the trust evaluation model of the first device for trust evaluation, if the evaluation device determines that the first device can accept the evaluation result obtained by the trust evaluation model of the second device for trust evaluation, the evaluation device obtains the trust evaluation model of the second device and a presentation form of the evaluation result corresponding to the first device. The evaluation device performs trust evaluation on the second device according to the trust evaluation model of the second device and the trust evaluation data of the second device, to obtain a second trust evaluation result of the second device.

[0101] Since the trust evaluation model of the second device can be different from the trust evaluation model of the first device, the presentation form of the evaluation result can be different, and the first device cannot identify the evaluation result of the trust evaluation model of the second device. For example, the trust evaluation model of the first device is a decision model, and the obtained evaluation result is a trust level. The trust evaluation model of the second device is a numerical model, and the obtained evaluation result is a numerical value. The evaluation device converts the second trust evaluation result into the presentation form of the evaluation result corresponding to the first device according to the presentation form of the evaluation result corresponding to the first device, to obtain the evaluation result of the second device.

[0102] For example, if the trust evaluation model of the first device is a decision model, and the obtained evaluation result is a trust level, the trust level includes no trust, low trust, medium trust, high trust, and fully trust. The trust evaluation model of the second device is a numerical model, and the obtained evaluation result is a numerical value. The conversion relationship between the numerical model and the evaluation result obtained by the decision model can be as shown in Table 1.

[0103] Table 1

[0104]

[0105]

[0106] S206. The evaluation device sends the trust evaluation result of the second device to the first device.

[0107] The evaluation device sends the trust evaluation result of the second device to the first device after obtaining the trust evaluation result of the second device, so that the first device determines whether to establish a connection with the second device according to the trust evaluation result of the second device. For example, in a case where the trust evaluation result of the second device is a trust level below medium trust, the first device determines not to establish a connection with the second device; in a case where the trust evaluation result of the second device is a trust level of medium trust or above medium trust, the first device determines to establish a connection with the second device.

[0108] For the above method embodiments, in order to simply describe, they are all expressed as a series of action combinations, but those skilled in the art should know that the present application is not limited by the order of the described actions, and those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions involved are not necessarily necessary for the present application. Those skilled in the art can think of other reasonable combinations of steps according to the above description, which also belong to the protection scope of the present application. For example, if the above management device and the evaluation device are the same device, there will be no interaction process between the above management device and the evaluation device, and the operations performed by the above management device are performed by the evaluation device.

[0109] The present application also provides a trust evaluation device, as shown in Figure 3 Figure 3 is a schematic diagram of a trust evaluation device provided by an embodiment of the present application. The trust evaluation device is used to implement the operations implemented in the above trust evaluation system; the trust evaluation device 300 includes a communication module 310 and an evaluation module 320. The communication module 310 is configured to receive a trust evaluation request for a second device sent by a first device, the trust evaluation request including identity information of the second device, and the trust evaluation request being used to obtain a trust evaluation result of the second device; the evaluation module 320 is configured to obtain trust evaluation data of the second device according to the identity information of the second device; perform trust evaluation on the second device according to a trust evaluation model and the trust evaluation data of the second device, and obtain the trust evaluation result of the second device. The communication module 310 is further configured to send the trust evaluation result of the second device to the first device.

[0110] ​In a possible implementation, the trust evaluation apparatus 300 further includes a recording module 330. The communication module 310 is further configured to receive registration information of the first device sent by the first device; and the recording module 330 is configured to record the registration information of the first device. The registration information of the first device includes identity information of the first device, a trust evaluation model of the first device, and evaluation data attributes of the first device. The result obtained by performing trust evaluation by using the trust evaluation model of the first device is recognized by the first device. The evaluation data attributes of the first device indicate attributes of data of the second device required when performing trust evaluation on the second device according to the trust evaluation model of the first device.

[0111] When the evaluation module 320 performs trust evaluation on the second device, the evaluation module 320 sends a first query request to the recording module 330, where the first query request includes the identity information of the first device, and the first query request is used to obtain the trust evaluation model of the first device. After obtaining the first query request, the recording module 330 obtains the trust evaluation model of the first device from the database according to the first query request and sends the trust evaluation model to the evaluation module 320. The evaluation module 320 sends a second query request to the recording module 330, where the second query request includes the identity information of the second device, and the second query request is used to obtain the trust evaluation data of the second device. After receiving the second query request, the recording module obtains the trust evaluation data of the second device from the database according to the second query request and sends the trust evaluation data to the evaluation module 320.

[0112] When it is determined that the trust evaluation data of the second device does not meet the requirement of performing trust evaluation according to the trust evaluation model of the first device, the evaluation module 320 sends a third query request to the recording module 330, where the third query request includes the identity information of the first device, and the third query request is used to obtain the evaluation result presentation form corresponding to the first device; the recording module 330 obtains the evaluation result presentation form corresponding to the first device from the database according to the third query request and sends the evaluation result presentation form to the evaluation module 320. The evaluation module 320 further sends a fourth query request to the recording module 330, where the fourth query request includes the identity information of the second device; the fourth query request is used to obtain the trust evaluation model of the second device; and the recording module 330 obtains the trust evaluation model of the second device from the database according to the fourth query request and sends the trust evaluation model to the evaluation module 320. The evaluation module 320 performs trust evaluation on the second device according to the trust evaluation model of the second device and the trust evaluation data of the second device, and obtains a second trust evaluation result of the second device.

[0113] In a possible implementation, the communication module 310 is further configured to receive an access control policy of the first device sent by the management device, where the access control policy of the first device indicates devices that can be accessed by the first device and devices that can access the first device; and the recording module 330 is further configured to record the access control policy of the first device.

[0114] In a possible implementation, the communication module 310 is further configured to send the registration information of the first device to the management device, and receive a registration result of the first device returned by the management device, the registration result including an agreement to register or a disagreement to register; the evaluation module 320 is further configured to, in a case where the registration result is the agreement to register, send the registration information of the first device to the recording module 330, so that the recording module 330 records the registration information of the first device; and the communication module is further configured to return a response message of successful registration to the first device.

[0115] Specifically, the operations performed by the modules in the trust evaluation apparatus 300 can be operations performed by the evaluation device in the above-described embodiments, for example, the communication module 310 performs operations of receiving and sending data by the evaluation device, and the evaluation module 320 is configured to perform trust evaluation on the second device, which will not be described herein again.

[0116] In the embodiments of the present application, if the management device and the evaluation device are different devices, the embodiments of the present application further provide a management apparatus, as shown in Figure 4 , which is a schematic diagram of a management apparatus provided by the embodiments of the present application. Figure 4 The management apparatus 400 includes a management module 410 and a communication module 420. The communication module 420 is configured to receive registration information of a first device, for example, receive registration information sent by the first device or registration information sent by the evaluation device. The management module 410 is configured to configure an access control policy of the first device, and then send the access control policy of the first device to the evaluation device through the communication module 420.

[0117] Optionally, the management module 410 is configured to determine a registration result of the first device according to the registration information of the first device, the registration result including an agreement to register or a disagreement to register; and the communication module 420 is further configured to send the registration result to the evaluation device, and the evaluation device is configured to, in a case where the registration result is the agreement to register, save the registration information of the first device.

[0118] In a case where the management module 410 determines that the device can join the trust evaluation system, the management module 410 is further configured to configure an access control policy of the first device, and the communication module 420 is further configured to send the access control policy of the first device to the evaluation device.

[0119] Specifically, the modules of the management apparatus 400 are configured to perform operations completed by the management device, which will not be described herein again.

[0120] The embodiments of the present application further provide a trust evaluation device, as shown in Figure 5 , which is a schematic diagram of a computing device provided by the embodiments of the present application. Figure 5

[0121] ​The computing device 500 includes one or more processors 510, a communication interface 520, and a memory 530, which are connected to each other by a bus 540, wherein,

[0122] The processor 510 described above can be used to implement the operations performed by the evaluation device in the above method embodiments. The processor 510 implements the method of trust evaluation of the second device can refer to the description in the above method embodiments, and will not be described here.

[0123] The communication interface 520 can be a wired interface or a wireless interface, used for communication with other modules or devices, such as receiving a trust evaluation request, sending a trust evaluation result of the second device to the first device, etc. The wired interface can be an Ethernet interface, a local interconnect network (LIN), etc., and the wireless interface can be a cellular network interface or a wireless local area network interface, etc.

[0124] The memory 530 can be a non-volatile memory, such as a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically EPROM (EEPROM), or a flash memory. The memory 530 can also be a volatile memory, which can be a random access memory (RAM) used as an external cache. By way of example, and not limitation, many forms of RAM can be used, such as a static RAM (SRAM), a dynamic RAM (DRAM), a synchronous DRAM (SDRAM), a double data rate SDRAM (DDR SDRAM), an enhanced SDRAM (ESDRAM), a synchlink DRAM (SLDRAM), and a direct rambus RAM (DR RAM).

[0125] The memory 530 can also be used to store program instructions and data to facilitate the processor 510 to call the program instructions stored in the memory 530 to execute the operation steps of the evaluation device in the above method embodiments. In addition, the computing device 500 can contain more than one processor 510, which can be in the same or different physical packages, and the processor 510 can be one core or more than one core, or each core can be a single core or more than one core.Figure 5 The number of components displayed may be more or less, or there may be different component configurations.

[0126] Bus 540 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. Bus 540 can be divided into address bus, data bus, control bus, etc. For ease of representation, Figure 5 The bus is represented by a single thick line, but this does not mean that there is only one bus or one type of bus.

[0127] It should be noted that the processor 510 mentioned above can be a central processing unit (CPU), or it can include a CPU and other hardware chips. The hardware chips can be of various types. For example, the accelerator card can be any one of the coprocessor chips, including a graphics processing unit (GPU), a tensor processing unit (TPU), a programmable logic device (PLD), a complex programmable logic device (CPLD), a field-programmable gate array (FPGA), or a digital signal processor (DSP). The computing device 500 can include one or more of the above-mentioned hardware chips, or it can include multiple types of the above-mentioned hardware chips. This application embodiment does not make specific limitations.

[0128] Specifically, the specific implementation of various operations performed by the computing device 500 can be referred to the specific operations performed by the evaluation device in the above method embodiment, and will not be repeated here.

[0129] It should be noted that if the aforementioned management module and evaluation module are deployed on different devices, i.e., the management device and evaluation device are not the same device, then this application embodiment also provides another computing device, the structural schematic diagram of which is the same as described above. Figure 5 The structural diagram of the computing device 500 shown is the same, and it is used to perform the operations completed by the management device mentioned above, so it will not be described again here.

[0130] The embodiment of the present application further provides a computer readable storage medium, wherein instructions are stored in the computer readable storage medium, and when the instructions are executed on a processor, the method steps implemented by the evaluation device in the above method embodiment can be implemented. The specific implementation of the processor of the computer readable storage medium in executing the above method steps can refer to the specific operation of the above method embodiment, and will not be described here.

[0131] The embodiment of the present application further provides a computer readable storage medium, wherein instructions are stored in the computer readable storage medium, and when the instructions are executed on a processor, the method steps implemented by the management device in the above method embodiment can be implemented. The specific implementation of the processor of the computer readable storage medium in executing the above method steps can refer to the specific operation of the above method embodiment, and will not be described here.

[0132] In the above embodiments, the description of each embodiment has its own focus, and the parts not described in detail in a certain embodiment can refer to the related description of other embodiments.

[0133] The above embodiments can be realized all or partially by software, hardware, firmware or other any combination. When realized by software, the above embodiments can be realized all or partially in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded or executed on a computer, the flow or function described in the embodiment of the present application is all or partially generated. The computer can be a general-purpose computer, a special-purpose computer, a computer network or other programmable device. The computer instructions can be stored in a computer readable storage medium or transmitted from one computer readable storage medium to another, for example, the computer instructions can be transmitted from one website, computer, server or data center to another website, computer, server or data center through wired (such as coaxial cable, optical fiber, digital subscriber line) or wireless (such as infrared, wireless, microwave, etc.). The computer readable storage medium can be any available medium that can be accessed by a computer or a data storage device such as a server, data center and the like containing one or more available medium collections. The available medium can be a magnetic medium (such as a floppy disk, a hard disk, a magnetic tape), an optical medium or a semiconductor medium. The semiconductor medium can be a solid state drive (SSD).

[0134] The steps in the method embodiment of the present application can be adjusted in sequence, combined or deleted according to actual needs; the modules in the device embodiment of the present application can be divided, combined or deleted according to actual needs.

[0135] The above has carried out the detailed introduction to the embodiment of the application, the principle and implementation mode of the application have been described by applying specific examples in this paper, the above embodiment explanation is only for helping understanding the method of the application and its core idea; at the same time, for the general technical personnel in the art, according to the idea of the application, there will be changes in specific implementation mode and application range, and the above-mentioned, the content of the specification should not be understood as the limitation of the application.

Claims

1. A trust assessment method characterized by, The method comprises the following steps: The evaluation device receives a trust evaluation request sent by a first device, the trust evaluation request being sent by the first device when the first device needs to establish a connection with a second device, the trust evaluation request comprising identity information of the second device, and the trust evaluation request being used to obtain a trust evaluation result of the second device; The evaluation device obtains trust evaluation data of the second device according to the identity information of the second device; The evaluation device performs trust evaluation on the second device according to a trust evaluation model and the trust evaluation data of the second device, obtains the trust evaluation result of the second device, and sends the trust evaluation result of the second device to the first device, so that the first device determines whether to establish a connection relationship with the second device.

2. The method of claim 1, wherein, The method further comprises the following steps: The evaluation device receives registration information of the first device sent by the first device, the registration information of the first device comprising identity information of the first device and a trust evaluation model of the first device; The evaluation device records the registration information of the first device.

3. The method of claim 2, wherein, The evaluation device performs trust evaluation on the second device according to a trust evaluation model and the trust evaluation data of the second device, obtains the trust evaluation result of the second device, and comprises the following steps: The evaluation device obtains the trust evaluation model of the first device according to the identity information of the first device; the trust evaluation request comprises the identity information of the first device; The evaluation device performs trust evaluation on the second device according to the trust evaluation model of the first device and the trust evaluation data of the second device, obtains a first trust evaluation result of the second device, and takes the first trust evaluation result as the trust evaluation result of the second device.

4. The method of claim 2, wherein, The registration information of the first device further comprises a presentation form of an evaluation result corresponding to the first device, the presentation form of the evaluation result corresponding to the first device being a presentation form of an evaluation result obtained by performing trust evaluation by using the trust evaluation model of the first device; The evaluation device performs trust evaluation on the second device according to a trust evaluation model and the trust evaluation data of the second device, obtains the trust evaluation result of the second device, and comprises the following steps: The evaluation device performs trust evaluation on the second device according to the trust evaluation model of the second device and the trust evaluation data of the second device, obtains a second trust evaluation result of the second device; The evaluation device converts the second trust evaluation result into the presentation form of the evaluation result corresponding to the first device according to the presentation form of the evaluation result corresponding to the first device, and obtains the trust evaluation result of the second device.

5. The method of claim 4, wherein, The registration information of the first device further comprises an evaluation data attribute of the first device, the evaluation data attribute of the first device indicating an attribute of data of the second device required when performing trust evaluation on the second device according to the trust evaluation model of the first device; The evaluation device performs trust evaluation on the second device according to a trust evaluation model and the trust evaluation data of the second device, obtains the trust evaluation result of the second device, and further comprises the following steps: The evaluation device obtains a trust evaluation model of the first device according to the identity information of the first device; wherein the trust evaluation request comprises the identity information of the first device; In a case where the trust evaluation data of the second device does not satisfy the evaluation data attribute of the first device, the evaluation device obtains the trust evaluation model of the second device and a presentation form of the evaluation result corresponding to the first device.

6. The method according to any one of claims 3 to 5, characterized in that, The method further comprises: The evaluation device receives and records the access control policy of the first device sent by the management device, and the access control policy of the first device indicates devices that can be accessed by the first device and devices that can access the first device.

7. The method according to any one of claims 3 to 5, characterized in that, The evaluation device records the registration information of the first device, comprising: The evaluation device sends the registration information of the first device to the management device; The evaluation device receives the registration result of the first device returned by the management device, and the registration result comprises an agreement to register or a refusal to register; In a case where the registration result is an agreement to register, the evaluation device records the registration information of the first device and returns a response message of successful registration to the first device.

8. The method of claim 7, wherein, The method further comprises: The evaluation device receives and records the access control policy of the first device returned by the management device, and the access control policy of the first device is configured by the management device in a case where the registration result is an agreement to register, and the access control policy of the first device indicates devices that can be accessed by the first device and devices that can access the first device.

9. The method according to claim 6 or 8, characterized in that, The evaluation device obtains the trust evaluation data of the second device according to the identity information of the second device, comprising: In a case where it is determined according to the access control policy of the first device that the first device can access the second device, the evaluation device obtains the trust evaluation data of the second device according to the identity information of the second device.

10. A trust assessment system, characterized by Comprising an evaluation device, a first device and a second device, wherein: The first device is configured to send a trust evaluation request to the evaluation module, the trust evaluation request being sent by the first device when the first device needs to establish a connection with the second device, the trust evaluation request comprising identity information of the second device, and the trust evaluation request being used to obtain a trust evaluation result of the second device; The evaluation device obtains the trust evaluation data of the second device according to the identity information of the second device; The evaluation device performs trust evaluation on the second device according to a trust evaluation model and the trust evaluation data of the second device, obtains a trust evaluation result of the second device, and sends the trust evaluation result of the second device to the first device; The first device is further configured to determine whether to establish a connection with the second device according to the trust evaluation result of the second device.

11. A trust assessment apparatus, characterized by comprising: Comprising: The communication module is configured to receive a trust evaluation request sent by a first device, the trust evaluation request being sent by the first device when the first device needs to establish a connection with a second device, the trust evaluation request comprising identity information of the second device, and the trust evaluation request being used to obtain a trust evaluation result of the second device. The evaluation module is configured to obtain trust evaluation data of the second device according to the identity information of the second device. The second device is trust evaluated according to a trust evaluation model and the trust evaluation data of the second device, and a trust evaluation result of the second device is obtained. The communication module is further configured to send the trust evaluation result of the second device to the first device, so that the first device determines whether to establish a connection relationship with the second device.

12. A computing device, comprising: The computer program instructions are executed by a computing device, and the computing device implements the method according to any one of claims 1 to 9.

13. A computer-readable storage medium, characterized in that, The computer program instructions are executed by a computing device, and the computing device implements the method according to any one of claims 1 to 9.

Citation Information

Patent Citations

  • Trust evaluation method and device in zero-trust architecture and electronic equipment

    CN116319026A