On-Demand Compression Method, Device, and Equipment for Zero-Trust Network Access Technology
By calculating the correlation degree based on the type and access of data updates in zero-trust network access, and compressing only high-frequency or high-correlation files and strategies, the problem of resource waste in the existing technology is solved, and efficient utilization of computing power and network bandwidth is achieved.
Patent Information
- Application Number
- CN202510147264.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-10
- Publication Date
- 2025-07-04
- Estimated Expiration
- 2045-02-10
AI Technical Summary
In zero-trust network access, the prior art cannot efficiently utilize computing power resources, resulting in unnecessary compression operations wasted resources, especially when transferring files, especially for files that do not require compression, resulting in waste of computing power resources and may exceed the cost of saving network bandwidth resources.
By judging the type and number of data updates, calculating the correlation degree, compressing only high-frequency accessed files and strategies or user-related files, using memory and processor to achieve on-demand compression, including deleting the first compressed files, setting the list to be compressed, and optimizing the compression timing through timing triggers.
It realizes that in zero-trust network access, intelligently saves computing resources, reduces unnecessary compression operations, optimizes the use of network bandwidth resources, and reduces the costs of public cloud platforms.
Smart Images

Figure CN119629255B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer software technology, and particularly to a method, device, and equipment for on-demand compression of zero-trust network access technology. Background Art
[0002] Zero-Trust Network Access (ZTNA) is a new generation of secure access method. Its main feature is to bind user identities with user devices and network service resources, that is, which network resources each user can access on each device is pre-planned, and its granularity can be precise to specific files under a specific domain name.
[0003] For network resources with fixed and frequently accessed content, especially files, they will occupy a large amount of network bandwidth resources. A common method is to compress the files with fixed content (usually mirror files or media files) on the resource server (including standard lossless compression and lossy compression for specific media formats), and then decompress them on the access server, saving network bandwidth resources without causing any impact on the end-user experience.
[0004] In the ZTNA field, all accesses are strictly protected in tunnels, and these tunnels will occupy the network bandwidth resources of the cloud platform, especially when transmitting files.
[0005] However, compressing files, especially using high-compression-rate compression algorithms, will occupy a large amount of computing power resources. If all files are compressed without discrimination, although network bandwidth resources are saved, for files that do not need to be compressed, the extra compression operations will waste computing power resources. On the public cloud platform, unnecessary costs will also be incurred, and it may even exceed the costs saved by saving network bandwidth resources. Summary of the Invention
[0006] This application provides a compression method for zero-trust network access technology, which is characterized by including:
[0007] When there is data update in the system, judge the type of data to be updated to obtain a judgment result;
[0008] When the updated data in the system is a file, when the updated file meets the preset access volume condition, trigger the compression mechanism to compress the updated file;
[0009] When the updated data in the system is a policy or a user, calculate the association degree between the updated policy or user and the file, and judge whether to trigger the compression mechanism to compress the file corresponding to the updated policy or user according to the association degree.
[0010] Optionally, when the updated item in the system is a file, when the updated file meets the preset access volume condition, a compression mechanism is triggered to compress the updated file, including:
[0011] When the updated item in the system is a file, the historical access records of the file are statistically analyzed;
[0012] Based on the statistical result, it is determined whether the file reaches the access volume threshold. If it reaches the access volume threshold, the updated file is compressed; if it does not reach the access volume threshold, compression is abandoned.
[0013] Optionally, the compression method of the zero-trust network access technology is characterized by further including:
[0014] When the updated item in the system is a file, it is retrieved whether there is a prior compressed file for the updated file;
[0015] When there is a prior compressed file for the updated file, the prior compressed file is deleted.
[0016] Optionally, when the updated item in the system is a policy or a user, the correlation degree between the updated policy or user and the file is calculated, and based on the correlation degree, it is determined whether to trigger the compression mechanism to compress the file corresponding to the updated policy or user, including:
[0017] When the updated item in the system is a user or a policy, the correlation degree with each file after the update needs to be calculated;
[0018] Based on the calculation result, it is determined whether the file meets the preset condition of a significant increase in the access probability after the update. If it meets the preset condition of a significant increase in the access probability, the historical access records of the file are statistically analyzed;
[0019] Based on the statistical result, it is determined whether the file reaches the access volume threshold. If it reaches the access volume threshold, the updated file is compressed; if it does not reach the access volume threshold, it is added to the list of files to be compressed, and an initial count value is obtained.
[0020] Optionally, the compression method of the zero-trust network access technology is characterized in that:
[0021] In zero-trust network access, there are three types of data: users, policies, and files. The relationship between users and policies is many-to-many, and the relationship between policies and files is also many-to-many.
[0022] Optionally, based on the calculation result, it is determined whether the file meets the preset condition of a significant increase in the access probability after the update. If it meets the preset condition of a significant increase in the access probability, the historical access records of the file are statistically analyzed, including:
[0023] The preset condition for the significant increase in the access probability is a user-defined threshold, which can be a percentage increase, an absolute increase in quantity, or a combination of both.
[0024] Optionally, according to the statistical results, it is determined whether the file reaches the access volume threshold. If it reaches the access volume threshold, the updated file is compressed. If it does not reach the threshold access volume, it is added to the list to be compressed, and an initial count value is obtained, including:
[0025] After the list to be compressed is completed, a timing trigger is set to traverse the list content to determine whether the high-frequency file threshold is met;
[0026] If the high-frequency file threshold is met, it is taken out from the list to be compressed and compressed immediately. If the high-frequency file threshold is not met, it is considered that the file does not meet the standard within this timing period, and the file count value is decreased by 1;
[0027] After the file count value is decreased by 1, if the count value does not reach zero, it remains in the list to be compressed. If the count value reaches zero, it is removed from the list to be compressed and compression is abandoned.
[0028] The present application also provides a device for the compression method of zero-trust network access technology, characterized in that the device includes:
[0029] A memory, a processor, and a computer program stored on the memory and running on the processor, where the computer program is configured to implement the steps of the on-demand compression method of any one of the zero-trust network access technologies.
[0030] Optionally, the device for the compression method of the zero-trust network access technology is characterized in that:
[0031] The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by the processor, the steps of the on-demand compression method of any one of the zero-trust network access technologies are implemented.
[0032] The present application also provides an electronic device, characterized in that it includes:
[0033] A memory and a processor, and a computer program is stored in the memory. When the processor executes the computer program, the steps of the on-demand compression method of any one of the zero-trust network access technologies are implemented.
[0034] The beneficial effect of the present application is that: the system identifies the types of updated data, applies corresponding judgment criteria, obtains reasonable judgment results for the updated data, intelligently compresses and caches the data that meets the criteria, and saves as much network bandwidth resources as possible with as little computing power as possible. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following briefly introduces the accompanying drawings required in the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on the provided drawings.
[0036] Figure 1 The flowchart showing a demand compression method based on zero trust network access technology disclosed in the present application;
[0037] Figure 2 The relational diagram showing the internal structure of ZTNA disclosed in the present application;
[0038] Figure 3 The flowchart showing the compression of a file when the file is updated disclosed in the present application;
[0039] Figure 4 The flowchart showing the compression of a file when a policy or user is updated disclosed in the present application;
[0040] Figure 5 The flowchart showing the operation of a list to be compressed disclosed in the present application. Detailed implementation manners
[0041] The following will detail various exemplary embodiments, features, and aspects of the present application with reference to the accompanying drawings. The same reference numerals in the drawings denote elements having the same or similar functions. Although various aspects of the embodiments are shown in the drawings, the drawings do not have to be drawn to scale unless otherwise specified.
[0042] Among them, the terms "first" and "second" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" may explicitly or implicitly include one or more of such features. In the description of the present application, "a plurality" means two or more unless otherwise specifically defined.
[0043] The special term "exemplary" herein means "serving as an example, an embodiment, or an illustration". Any embodiment described as "exemplary" here does not have to be construed as superior to or better than other embodiments.
[0044] In addition, to better illustrate the present application, numerous specific details are given in the following detailed implementation manners. Those skilled in the art should understand that the present application can also be implemented without some specific details. In some instances, methods, means, elements, and circuits well-known to those skilled in the art are not described in detail to highlight the gist of the present application.
[0045] This application is a method for on-demand compression of zero-trust network access technology. In this method, the system utilizes the feature that each user in zero-trust network access can only access specific policies and files to obtain the corresponding relationships among all users, policies, and files in the system. When any part of them is updated, the system can determine whether the updated part is a high-frequency file by statistically querying historical access records and calculating file correlation, and immediately compress the high-frequency file to save as much network bandwidth resources as possible with as little computing power as possible.
[0046] As Figure 1 shown, it is a flowchart of a method for on-demand compression of zero-trust network access technology according to an embodiment of this application, which specifically includes the following content:
[0047] S100, when there is data update in the system, determine the type of data to be updated to obtain a judgment result.
[0048] Specifically, the zero-trust network access system includes users, policies, and files. When the updated content is of the file type, its compression trigger mechanism is to determine whether the updated part is a high-frequency file based on historical access records and immediately compress the updated high-frequency file. When the updated content is of the user type or policy type, its compression trigger mechanism is to determine whether the updated part is a high-frequency file based on file correlation and historical access records and immediately compress the updated high-frequency file.
[0049] S200, when the updated content in the system is a file, when the updated file meets the preset access condition, trigger the compression mechanism to compress the updated file.
[0050] Specifically, after the file is updated, the system will delete the compression cache of the file, then statistically analyze its historical access records to determine whether it has an access volume meeting the threshold. If the access volume of this file exceeds the threshold, it is a high-frequency file, and a new version cache will be immediately compressed, otherwise the compression will be directly abandoned.
[0051] S300, when the updated content in the system is a policy or a user, calculate the correlation between the updated policy or user and the file, and determine whether to trigger the compression mechanism to compress the file corresponding to the updated policy or user according to the correlation.
[0052] Specifically, when a policy or user is updated, the system first calculates the correlation between the updated item and the files accessible to this item, and confirms whether the access probability of the accessible files has increased by a certain margin or quantity. When the correlation reaches the growth threshold, the system statistically analyzes its historical access records to determine whether the access volume meets the threshold. If the access volume of this file exceeds the threshold, it is a high-frequency file, and a new version cache is immediately compressed and produced. Those that do not reach the threshold are all added to the list to be compressed, and an initial count value is set.
[0053] Among them, a timing trigger is set to traverse the above list to be compressed. If a certain file in the list meets the conditions of a high-frequency file, it is taken out of the list and immediately compressed. For files that do not meet the conditions of high-frequency files during the traversal, the count value is decreased by 1. If the count value is decreased to 0, the corresponding file will be abandoned for compression and removed from the list.
[0054] To sum up, by analyzing the updated files, it is possible to know whether they were frequently accessed high-frequency files before the update, and immediately compress these high-frequency files with high access rates to produce a new version cache, so as to achieve the purpose of predicting the access trend of large files, pre-compressing high-frequency access files, and saving as much network bandwidth resources as possible with as little computing power as possible.
[0055] Specifically, in a zero-trust network access system, each user can be defined with multiple policies, and the relationship between users and policies is many-to-many. At the same time, a large number of accessible resources are defined in each policy. Here, the resources are simplified to files, and the relationship between policies and files is also many-to-many.
[0056] As Figure 2 shown, the relationship diagram of the internal structure of ZTNA in an embodiment of the present application includes the following content:
[0057] Specifically, three users correspond to two policies, and each policy is associated with two or three files. Finally, Zhang San can access a.iso and b.iso through R & D; Li Si can access a.iso and b.iso through R & D, and access b.iso, c.mp4, and d.mp4 through operation and maintenance; Wang Wu can access b.iso, c.mp4, and d.mp4 through operation and maintenance.
[0058] Among them, it can be found that b.iso can be accessed by all three users, with a correlation of 3 and a relatively high access probability. Taking this as an example, in other application scenarios, with a volume of hundreds of users, dozens of policies, and thousands of files, the zero-trust network access system can quickly calculate how many people each file is corresponding to (i.e., the correlation), and screen out some files with relatively high access probabilities.
[0059] As described above, it is not enough to predict the access probability of a file only based on permissions. After all, a file with a high degree of relevance only indicates a high chance of being accessed, rather than actually being accessed frequently. Moreover, in a zero-trust network access system, users, policies, and files are constantly changing. It is not appropriate to compress immediately when the system is compressed at any time or when users, policies, or files are updated. A relatively "slow" trigger mechanism is needed.
[0060] Specifically, when the updated entity in the system is a file, the historical access records of the file are statistically analyzed. According to the statistical results, it is determined whether the file reaches the access volume threshold. If the access volume threshold is reached, the updated file is compressed; if the access volume threshold is not reached, compression is abandoned.
[0061] Among them, as Figure 3 shown, the flowchart for compressing a file when the file is updated includes the following. When a file in the zero-trust network access system is updated, first, the existing compression cache of the file in the system should be immediately deleted to reduce waste of computing power resources. Then, all historical access records of the file in a recent period of time are retrieved, and based on this record, it is determined whether the file meets the threshold access volume of high-frequency files in the near future.
[0062] If it meets the condition, the file is a high-frequency file, and the system immediately compresses the file and creates a new version of the compression cache; if it does not meet the condition, the file is not a high-frequency file, and the system stores the updated content and directly abandons compression until the file is accessed and then compressed.
[0063] Specifically, when the updated entity in the system is a user or a policy, the relevance between the update and each file needs to be calculated. According to the calculation results, it is determined whether the file meets the preset condition of a significant increase in the access probability after the update. If the preset condition of a significant increase in the access probability is reached, the historical access records of the file are statistically analyzed. According to the statistical results, it is determined whether the file reaches the access volume threshold. If the access volume threshold is reached, the updated file is compressed; if the access volume threshold is not reached, the file is added to the list of files to be compressed, and an initial count value is obtained.
[0064] Among them, as Figure 4As shown in the figure, the flowchart for compressing files when a policy or user is updated includes the following. When a policy or user in the zero-trust network access system is updated, first, the system calculates the degree of association between the updated items and each file to confirm whether this update significantly increases the access probability of some files. Here, "significantly" refers to a definable threshold. For example, a certain file has a 20% increase in access probability during this update, or a certain file has an increase of 100 associations in absolute quantity during this update, or a combination of the above two. If the updated degree of association meets the set threshold, the next judgment will be continued. If the updated degree of association does not meet the set threshold, stop here and do not perform subsequent steps and do not compress.
[0065] Then, query the historical access records for the updated items that meet the threshold, and use this record to judge whether the updated items meet the threshold access volume of high-frequency files recently. If they meet, the updated items are high-frequency files, and the system immediately compresses the updated items and creates a new version of the compressed cache; if they do not meet, the updated items are not high-frequency files, and the system adds the updated items to a list to be compressed and sets an initial count value for the updated items. For example, set the count value to 3.
[0066] Specifically, after the list to be compressed is completed, traverse the content of the list by setting a timing trigger to judge whether it meets the high-frequency file threshold. If it meets the high-frequency file threshold, take it out from the list to be compressed and compress it immediately. If it does not meet the high-frequency file threshold, it is considered that the file does not meet the standard within this timing period, and the count value of the file is decreased by 1. After the count value of the file is decreased by 1, if the count value does not reach zero, it remains in the list to be compressed, and if the count value reaches zero, it is removed from the list to be compressed and compression is abandoned.
[0067] Among them, as Figure 5 shown, the flowchart for the work of the list to be compressed includes the following. First, the system sets a timing trigger. The timing trigger is a mechanism that can automatically trigger and execute specific tasks according to a predetermined time. In this method, the role of the fixed-number trigger is to periodically execute the work of making the system traverse the compression list.
[0068] Then, the system traverses the compression list to judge whether each item in the list meets the high-frequency file threshold. If an item meets the threshold, take it out from the compression list and compress it immediately.
[0069] The list items that do not meet the high-frequency file threshold will be considered by the system as not meeting the standard within this timing period, and the count values of these items will be decreased by 1. Then, check the count values. Those with non-zero count values remain in the list to be compressed and wait for detection in the next cycle. Those with zero count values are removed from the list to be compressed and compression is abandoned.
[0070] An apparatus for an on-demand compression method of a zero-trust network access technology used in the above steps, characterized in that the apparatus includes a memory, a processor, and a computer program stored on the memory and running on the processor, and the computer program is configured to implement the steps of the on-demand compression method of the zero-trust network access technology described in any one of the above contents.
[0071] An electronic device used in the above steps, characterized by including a memory and a processor, and a computer program is stored in the memory, wherein when the processor executes the computer program, the steps of the on-demand compression method of the zero-trust network access technology described in any one of the above contents are implemented.
[0072] The embodiments of the present application have been described above. The above description is exemplary and not exhaustive, and is not limited to the disclosed embodiments. Many modifications and variations are obvious to those of ordinary skill in the art in the technical field without departing from the scope and spirit of the described embodiments. The selection of the terms used herein is intended to best explain the principles of the embodiments, practical applications, or improvements to the technologies in the market, or to enable other ordinary skill in the art in the technical field to understand the embodiments disclosed herein.
Claims
1. A compression method for zero-trust network access technology, characterized in that including: When there is data update in the system, judge the type of data to be updated to obtain a judgment result; When the updated data in the system is a file, when the updated file meets the preset access volume condition, trigger the compression mechanism to compress the updated file; When the updated data in the system is a policy or a user, calculate the correlation degree between the updated policy or user and the file, and judge whether to trigger the compression mechanism to compress the file corresponding to the updated policy or user according to the correlation degree; The judgment of whether the correlation degree triggers the compression mechanism to compress the file corresponding to the updated policy or user includes: When the updated data in the system is a user or a policy, it is necessary to calculate the correlation degree with each file after the update; According to the calculation result, judge whether the file meets the preset condition of a significant increase in the access probability after the update. If the preset condition of a significant increase in the access probability is met, count the historical access records of the file; According to the statistical result, judge whether the file reaches the access volume threshold. If the access volume threshold is reached, compress the updated file. If the access volume threshold is not reached, add it to the list to be compressed and obtain an initial count value.
2. The compression method of the zero-trust network access technology according to claim 1, wherein When the updated data in the system is a file, when the updated file meets the preset access volume condition, trigger the compression mechanism to compress the updated file, including: When the updated data in the system is a file, count the historical access records of the file; According to the statistical result, judge whether the file reaches the access volume threshold. If the access volume threshold is reached, compress the updated file. If the access volume threshold is not reached, abandon the compression.
3. The compression method of the zero-trust network access technology according to claim 2, wherein, It also includes: When the updated data in the system is a file, retrieve whether there is a prior compressed file for the updated file; When there is a prior compressed file for the updated file, delete the prior compressed file.
4. The compression method of the zero-trust network access technology according to claim 1, characterized in that: In zero-trust network access, there are three types of data: users, policies, and files. The relationship between users and policies is many-to-many, and the relationship between policies and files is also many-to-many.
5. The compression method of the zero-trust network access technology according to claim 1, characterized in that, The judgment according to the calculation result of whether the file meets the preset condition of a significant increase in the access probability after the update. If the preset condition of a significant increase in the access probability is met, count the historical access records of the file, including: The preset condition of a significant increase in the access probability is a user-defined threshold, which is a percentage increase, or an absolute increase quantity, or a combination of the above two.
6. The compression method of the zero-trust network access technology according to claim 1, characterized in that, The judgment according to the statistical result of whether the file reaches the access volume threshold. If the access volume threshold is reached, compress the updated file. If the access volume threshold is not reached, add it to the list to be compressed and obtain an initial count value, including: After the list to be compressed is completed, traverse the list content by setting a timing trigger to judge whether it meets the high-frequency file threshold; If the high-frequency file threshold is met, take it out from the list to be compressed and compress it immediately. If the high-frequency file threshold is not met, it is considered that the file does not meet the standard in this timing period, and the count value of the file is decreased by 1; After the count value of the file is decreased by 1, if the count value is not zero, it remains in the list to be compressed. If the count value is zero, it is removed from the list to be compressed and the compression is abandoned.
7. An apparatus for a compression method of a zero-trust network access technology, characterized in that, The device includes: a memory, a processor, and a computer program stored on the memory and running on the processor, the computer program being configured to implement the steps of the compression method of the zero-trust network access technology according to any one of claims 1 to 6.
8. The device for the compression method of the zero-trust network access technology according to claim 7, wherein: the memory is a computer-readable storage medium, and a computer program is stored on the memory, and when the computer program is executed by the processor, the steps of the compression method of the zero-trust network access technology according to any one of claims 1 to 6 are implemented.
9. An electronic device, characterized in that, It includes: a memory and a processor, and a computer program is stored in the memory, wherein when the processor executes the computer program, the steps of the compression method of the zero-trust network access technology according to any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Cloud data management method for user-customized strategy
CN107589910A
Domain name compression method and related product thereof
CN111917899A