A Trusted Execution Region Verification Method and System Based on a Global Resolution Architecture

By setting trust prefixes and real-time monitoring frequency for each running area, generating real-time monitoring logs and performing layered verification, identifying and handling abnormal servers, the problem of inability to promptly discover that the server is transferred to untrusted areas in the existing technology is solved, and data security and system stability are improved.

CN119691745BActive Publication Date: 2025-07-25WANGGEN TECH (QINGDAO) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411646169.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-11-18
Publication Date
2025-07-25
Estimated Expiration
2044-11-18

AI Technical Summary

Technical Problem

The existing identification resolution technology cannot meet the needs of increasingly complex network environments and continuously improving data security and compliance, and cannot promptly detect the potential security risks of servers being accidentally transferred to untrusted areas.

Method used

By setting a trust prefix for each running area, determining several running trust areas, and setting real-time monitoring frequency for each area, generating real-time monitoring logs, performing hierarchical verification, identifying exception servers, intercepting exception data, and notifying relevant personnel to handle the problem.

Benefits of technology

It realizes effective supervision of trust operation areas, timely discovers and handles potential security risks, improves data security and system stability, and ensures the security of cross-border data transmission and sharing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119691745B_ABST
    Figure CN119691745B_ABST
Patent Text Reader

Abstract

The present invention provides a method and system for verifying a trusted operating area based on a global parsing architecture, including: setting corresponding trust prefixes for each operating area respectively, determining a number of trusted operating areas, and setting corresponding real-time monitoring frequencies respectively. Based on the real-time monitoring frequencies, updating the real-time monitoring logs corresponding to each trusted operating area, analyzing the real-time operating status of the corresponding trusted operating area according to the real-time monitoring logs, performing hierarchical verification on each real-time operating status respectively, determining the operating exception information of the corresponding trusted operating area, tracking the operating exception information in the corresponding trusted operating area, determining the abnormal server, obtaining the historical working data of the corresponding abnormal server in the real-time monitoring logs, identifying the abnormal cause of the corresponding abnormal information and performing corresponding data interception and notification reminders. By viewing the area where the current server is running in real time, it is possible to timely discover whether the server is in a normal running position.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of anomaly supervision, and particularly relates to a method and system for verifying a trusted operating area based on a global resolution architecture. Background Art

[0002] Currently, most enterprises use the identification and resolution system to manage data security. Whether it is an enterprise involved in global supply chain management or a technology enterprise with a distributed data center, this system can timely understand whether the server is within the trusted operating area at different time points, ensuring the security and compliance of key business data. For enterprises involved in sensitive information processing, such as financial institutions and healthcare enterprises, this system can effectively prevent the non-compliant use of prefixes, providing a solid guarantee for the data security of enterprises and avoiding huge economic losses and reputation risks caused by data leakage or illegal access. The identification and resolution system has four functions: identification, resolution, information management, and security authentication, meeting the higher requirements of manufacturing application support, conforming to the needs of the transformation and upgrading of intelligent manufacturing, and being an important support for solving important issues such as information security, controllability, and shareability in the development and application of manufacturing, and an important infrastructure for the transformation and upgrading of manufacturing.

[0003] However, with the development of technology, the data volume of various enterprises is continuously increasing and the demand for information sharing is becoming increasingly urgent, and the requirements for data security and compliance are gradually increasing. The Handle identification and resolution technology has emerged, providing a unified identification and positioning method for information resources worldwide. However, with the increasingly complex network environment and continuous increase in security threats, simple identification and resolution can no longer meet the requirements for data security.

[0004] Therefore, the present invention provides a method and system for verifying a trusted operating area based on a global resolution architecture. Summary of the Invention

[0005] A method and system for verifying a trusted operating area based on a global resolution architecture according to the present invention can timely discover whether the server is in a normal operating position by real-time viewing the area where the current server is running. If the server is accidentally transferred to an untrusted area, measures can be immediately taken to prevent potential security risks and ensure the stable operation of the system.

[0006] The present invention provides a method for verifying a trusted operating area based on a global resolution architecture, including:

[0007] Step 1: Set corresponding trust prefixes for each operating area respectively, determine a number of operating trusted areas, and set corresponding real-time monitoring frequencies for each of the operating trusted areas;

[0008] Step 2: Update the real-time monitoring log corresponding to each running trust area based on the real-time monitoring frequency, analyze the real-time running status of the corresponding running trust area according to the real-time monitoring log, and display it;

[0009] Step 3: Perform hierarchical verification on each real-time running status respectively, determine the running exception information of the corresponding running trust area, track the running exception information in the corresponding running trust area, and determine the abnormal server;

[0010] Step 4: Obtain the historical working data of the corresponding abnormal server from the real-time monitoring log, identify the abnormal cause corresponding to the abnormal information, and perform corresponding data interception and notification reminder.

[0011] In an implementable manner,

[0012] The said Step 1 includes:

[0013] Step 11: Obtain the security development level corresponding to each running area respectively, set the corresponding trust prefix for the corresponding running area according to the security development level, determine several running trust areas, classify the running trust areas according to the trust prefix, and determine several running trust areas corresponding to each security development level;

[0014] Step 12: Configure the initial monitoring frequency for the corresponding running trust area based on the security development level, obtain the number of servers corresponding to each running trust area respectively, sort the running trust areas based on the number of servers, obtain the last running trust area at the end of the sorting, and regard the last initial monitoring frequency corresponding to the last running trust area as the minimum threshold of the monitoring frequency;

[0015] Step 13: Calculate the quantity ratio between the servers and non-servers included in each running trust area respectively, add the corresponding service weight to the corresponding running trust area according to the quantity ratio, and use the service weight and the minimum threshold of the monitoring frequency to correct the corresponding initial monitoring frequency to obtain the real-time monitoring frequency corresponding to each running trust area.

[0016] In an implementable manner,

[0017] It further includes:

[0018] Obtain the server addition / subtraction data and non-server addition / subtraction data corresponding to each running trust area respectively;

[0019] Calculate the real-time quantity ratio of the corresponding running trust area according to the server addition / subtraction data and non-server addition / subtraction data;

[0020] Synchronously correct the corresponding real-time monitoring frequency according to the real-time quantity ratio and the minimum value of frequency monitoring.

[0021] In an implementable manner,

[0022] Step 2 includes:

[0023] Step 21: Perform running data sampling on the corresponding running trust area based on the real-time monitoring frequency to obtain sampled running data, and determine the log level of the corresponding running trust area based on the trust prefix corresponding to each running trust area;

[0024] Step 22: Perform dimensionality reduction processing on each sampled running data respectively to obtain the running key information corresponding to the running trust area, construct corresponding timestamps according to the real-time monitoring frequency, combine the log level and the running key information corresponding to each running trust area with the corresponding timestamps, and generate real-time monitoring logs corresponding to each running trust area;

[0025] Step 23: Perform real-time analysis on the real-time monitoring logs, determine several running process characteristics corresponding to the running trust area, determine the overall running rule of the corresponding running trust area based on the running rule corresponding to each running process characteristic, and determine the latest log data corresponding to the running trust area according to the real-time monitoring logs;

[0026] Step 24: Input the latest log data into the corresponding overall running rule for rule matching, construct the real-time running state corresponding to the running trust area according to the rule matching result, and input it into the corresponding terminal for display respectively.

[0027] In an implementable manner,

[0028] Step 3 includes:

[0029] Step 31: Determine the server change information corresponding to the running trust area according to the real-time monitoring logs, determine the server distribution information corresponding to the running trust area at each supervision moment, map the real-time running state corresponding to each supervision moment in the server distribution information, and obtain the server running information corresponding to each server at different supervision moments;

[0030] Step 32: Generate the running negotiation trajectory of the corresponding server in the corresponding running trust area according to the server running information, determine the trust operable trajectory corresponding to each running trust area according to the trust prefix corresponding to each running trust area, verify whether each running negotiation trajectory exceeds the corresponding trust operable trajectory respectively, and determine the abnormal running trust area containing running abnormal information;

[0031] Step 33: Adjust the real-time monitoring frequency of the abnormal operation trust area to the high-frequency monitoring frequency, collect the high-frequency operation data of the abnormal operation trust area, find several pieces of associated data corresponding to the operation abnormal information in the high-frequency operation data, trace each piece of associated data respectively, and determine the abnormal server corresponding to each piece of associated data;

[0032] Step 34: Obtain the specified negotiation track corresponding to each abnormal server respectively, determine the out-of-track negotiation range corresponding to the abnormal server, and determine the out-of-track negotiation content corresponding to the abnormal server, find the corresponding abnormal server in the abnormal operation trust area, and mark the corresponding out-of-track negotiation range and out-of-track negotiation content.

[0033] In an implementable manner,

[0034] It further includes:

[0035] Determine the out-of-track negotiation object corresponding to the abnormal server according to the out-of-track negotiation range corresponding to each abnormal server;

[0036] Estimate the accepted content of the out-of-track negotiation object according to the out-of-track negotiation content, and judge the influence degree of the accepted content on the corresponding abnormal operation area;

[0037] When the influence degree is higher than the security level, construct interference content according to the accepted content and transmit it to the corresponding out-of-track negotiation object.

[0038] In an implementable manner,

[0039] The said step 4 includes:

[0040] Step 41: Find the abnormal real-time monitoring log corresponding to the abnormal operation trust area containing the abnormal server, extract the historical working data corresponding to the abnormal server from the abnormal real-time monitoring log, and divide the historical working data into system sub-data, application sub-data and access sub-data;

[0041] Step 42: Identify the service function change information corresponding to the abnormal server according to the system sub-data, identify the service function management change information corresponding to the abnormal server according to the application sub-data, and identify the service negotiation change information corresponding to the abnormal server according to the access sub-data;

[0042] Step 43: Determine the cause of the exception corresponding to each abnormal server based on the service function change information, the service function management change information, and the service negotiation change information corresponding to the abnormal server, generate a corresponding coping strategy according to the cause of the exception, and use the coping strategy for data interception and notification reminder.

[0043] In an implementable manner,

[0044] It further includes:

[0045] Obtain the management terminal corresponding to the abnormal operation trust area, generate corresponding notification text and reminder method according to the coping strategy, and transmit them to the management terminal for notification reminder.

[0046] The present invention provides a trust operation area verification system based on a global resolution architecture, including:

[0047] An effective supervision module, used to set corresponding trust prefixes for each operation area respectively, determine several operation trust areas, and set corresponding real-time monitoring frequencies for each of the operation trust areas;

[0048] A log analysis module, used to update the real-time monitoring log corresponding to each operation trust area based on the real-time monitoring frequency, analyze the real-time operation status of the corresponding operation trust area according to the real-time monitoring log, and display it;

[0049] An abnormal verification module, used to perform hierarchical verification on each of the real-time operation statuses respectively, determine the operation abnormal information corresponding to the operation trust area, and track the operation abnormal information in the corresponding operation trust area to determine the abnormal server;

[0050] An abnormal processing module, used to obtain the historical working data of the corresponding abnormal server in the real-time monitoring log, identify the cause of the abnormality corresponding to the abnormal information, and perform corresponding data interception and notification reminder.

[0051] In an implementable manner,

[0052] The effective supervision module includes:

[0053] A trust configuration unit, used to obtain the security development level corresponding to each operation area respectively, set corresponding trust prefixes for the corresponding operation areas according to the security development level, determine several operation trust areas, and classify the operation trust areas according to the trust prefixes to determine several operation trust areas corresponding to each security development level;

[0054] A frequency initial setting unit, configured to configure an initial monitoring frequency for a corresponding running trust region based on the security development level, respectively obtain the number of servers corresponding to each running trust region, sort the running trust regions based on the number of servers, obtain the last running trust region at the end of the sorting, and regard the last initial monitoring frequency corresponding to the last running trust region as the minimum threshold of the monitoring frequency;

[0055] A frequency determination unit, configured to respectively calculate the quantity ratio between the servers and non-servers included in each running trust region, add corresponding service weights to the corresponding running trust regions according to the quantity ratio, and use the service weights and the minimum threshold of the monitoring frequency to correct the corresponding initial monitoring frequency to obtain the real-time monitoring frequency corresponding to each running trust region.

[0056] The achievable beneficial effects of the above technical solution are as follows: In order to verify the specific running conditions of the trusted running regions, the present invention provides a strong guarantee for information sharing and the security of the architecture. First, in order to demarcate the trusted running regions from other regions, corresponding trust prefixes are set for each running region, and different real-time monitoring frequencies are set for different running trust regions, which can not only achieve data monitoring but also adjust the frequency according to the actual situation of the running trust regions to avoid the phenomenon of supervision failure. Then, the running trust regions are monitored according to the real-time monitoring frequency to generate corresponding real-time monitoring logs, and the real-time running status of the running trust regions is determined according to the real-time monitoring logs. The running anomaly information of the running trust regions is determined by hierarchical verification of the real-time running status, and the abnormal servers are traced. In order to avoid losses caused by data leakage, abnormal identification is performed on the abnormal servers, data interception is performed according to their abnormal reasons, and relevant personnel are notified to handle it in time, which improves the effective supervision of the running trust regions and enhances the security of the running trust regions.

[0057] Other features and advantages of the present invention will be described in the following description, and part of them will be obvious from the description or understood by implementing the present invention. The objectives and other advantages of the present invention can be achieved and obtained through the structures specifically pointed out in the written description and the drawings.

[0058] The technical solution of the present invention will be further described in detail below through the drawings and embodiments. Description of the Drawings

[0059] The drawings are used to provide a further understanding of the present invention, and constitute a part of the description. They are used together with the embodiments of the present invention to explain the present invention, and do not constitute a limitation to the present invention. In the drawings:

[0060] Figure 1Schematic diagram of the working process of a trust operation area verification method based on a global resolution architecture in an embodiment of the present invention;

[0061] Figure 2 Schematic diagram of the composition of a trust operation area verification system based on a global resolution architecture in an embodiment of the present invention. Specific embodiments

[0062] The following describes the preferred embodiments of the present invention with reference to the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention, and are not used to limit the present invention.

[0063] Embodiment 1

[0064] This embodiment provides a trust operation area verification method and system based on a global resolution architecture, as Figure 1 shown, including:

[0065] Step 1: Set corresponding trust prefixes for each operation area respectively, determine a number of operation trust areas, and set corresponding real-time monitoring frequencies for each of the operation trust areas;

[0066] Step 2: Update the real-time monitoring log corresponding to each operation trust area based on the real-time monitoring frequency, analyze the real-time operation status of the corresponding operation trust area according to the real-time monitoring log, and display it;

[0067] Step 3: Perform hierarchical verification on each of the real-time operation statuses respectively, determine the operation abnormal information of the corresponding operation trust area, track the operation abnormal information in the corresponding operation trust area, and determine the abnormal server;

[0068] Step 4: Obtain the historical working data of the corresponding abnormal server in the real-time monitoring log, identify the abnormal cause corresponding to the abnormal information, and perform corresponding data interception and notification reminder.

[0069] In this example, the trust prefix represents an identifier used to distinguish the trust area and the non-trust area, and also represents different trust areas. The trust prefixes include: TEEA (used to identify all applications or modules related to the trusted execution environment), SEC_ (indicating security-related functions or modules), TEE_ (used to identify APIs or functions related to TEE), and SCT_ (a module representing the security context, usually used to describe the context management in the EE);

[0070] In this example, the operation area represents a specified area, such as: City A, Community B, Room C;

[0071] In this example, the operation trust area means that legal data activities can be carried out within this operation trust area;

[0072] In this example, the real-time monitoring frequency corresponding to each running trust area is different;

[0073] In this example, the running exception information represents the information presented when an exception occurs in a running trust area;

[0074] In this example, the real-time monitoring log represents the log generated when supervising the work of a running trust area with a 24-hour cycle. Moreover, one running trust area corresponds to one real-time monitoring log, and the real-time monitoring log is in a continuously updated state;

[0075] In this example, the trust running area verification method and system based on the global resolution architecture of the present invention, as a basic module of the Handle identification resolution technology, has a wide and important scope of application. The trust running area verification method and system of the global resolution architecture can provide unified security standards and verification mechanisms for institutions in different countries and regions, ensure the security of cross-border data transmission and sharing, break information barriers, and promote global economic cooperation and cultural exchanges;

[0076] In this example, when an abnormal situation is detected, notifying the user by email can enable relevant personnel to quickly understand the severity and urgency of the problem. Users can take timely measures, such as activating the emergency plan, notifying the technical team for handling, etc., to avoid the further expansion of the problem;

[0077] In this example, the purpose of hierarchical verification is: 1. Monitoring the server running area can effectively prevent unauthorized access. If the server appears outside the trust running area, it is very likely to have suffered a malicious attack or been illegally transferred. Timely detection of such abnormal situations can prevent attackers from further invading the system and protect the security of sensitive data and services;

[0078] 2. Based on the records of abnormal situations, potential security risk points can be analyzed, and then the security policy can be adjusted and improved. For example, strengthening access control for specific areas, adding identity verification mechanisms, etc., to improve the overall security of the system.

[0079] Working principle and beneficial effects of the above technical solution: In order to verify the specific operating conditions of the trusted operating area, the present invention provides a strong guarantee for information sharing and the security of the architecture. First, in order to demarcate the trusted operating area from other areas, a corresponding trust prefix is set for each operating area, and different real-time monitoring frequencies are set for different operating trusted areas, which can not only achieve data monitoring but also adjust the frequency according to the actual situation of the operating trusted area to avoid the phenomenon of supervision failure. Then, the operating trusted area is monitored according to the real-time monitoring frequency, and the corresponding real-time monitoring log is generated. The real-time operating state of the operating trusted area is determined according to the real-time monitoring log. The operating exception information of the operating trusted area is determined by hierarchical verification of the real-time operating state, and the abnormal server is traced. In order to avoid losses caused by data leakage, abnormal identification is performed on the abnormal server, and data interception is performed according to its abnormal cause and relevant personnel are notified to handle it in time, which improves the effective supervision of the operating trusted area and enhances the security of the operating trusted area.

[0080] Embodiment 2

[0081] Based on Embodiment 1, for the method for verifying a trusted operating area based on a global resolution architecture, Step 1 includes:

[0082] Step 11: Obtain the corresponding security development level of each operating area respectively, set a corresponding trust prefix for the corresponding operating area according to the security development level, determine a number of operating trusted areas, classify the operating trusted areas according to the trust prefix, and determine a number of operating trusted areas corresponding to each security development level;

[0083] Step 12: Configure an initial monitoring frequency for the corresponding operating trusted area based on the security development level, obtain the number of servers corresponding to each operating trusted area respectively, sort the operating trusted areas based on the number of servers, obtain the last operating trusted area at the end of the sorting, and regard the corresponding initial monitoring frequency of the last operating trusted area as the minimum threshold of the monitoring frequency;

[0084] Step 13: Calculate the quantity ratio between the servers and non-servers included in each operating trusted area respectively, add a corresponding service weight to the corresponding operating trusted area according to the quantity ratio, and correct the corresponding initial monitoring frequency by using the service weight and the minimum threshold of the monitoring frequency to obtain the real-time monitoring frequency corresponding to each operating trusted area.

[0085] In this example, the minimum threshold of the monitoring frequency means that the set monitoring frequency cannot be lower than this value;

[0086] In this example, the security development level represents the current security level of the operating area;

[0087] In this example, the service weight is related to the number of servers. The more servers there are, the more likely data leakage is to occur, and thus the greater the service weight.

[0088] The working principle and beneficial effects of the above technical solution: Since different running trust regions have different running attributes, when monitoring different running trust regions, corresponding monitoring frequencies should be set according to their actual needs. First, set the corresponding trust prefix according to the security development level of the running region, then configure the corresponding initial monitoring frequency for the running trust region in combination with the security development level of each running trust region, then construct the corresponding service weight in combination with the ratio of the number of servers to non - servers in each running trust region, and at the same time set the minimum threshold of the monitoring frequency according to the actual situation. Finally, correct the initial monitoring frequency according to the service weight and the minimum threshold of the monitoring frequency to obtain the real - time monitoring frequency of each running trust region. By setting the monitoring frequency and trusted running regions for specific prefixes, it is possible to record and determine whether the current service is running in the trusted region in the follow - up, improving system security.

[0089] Embodiment 3

[0090] Based on Embodiment 2, the method for verifying a trusted running region based on a global resolution architecture further includes:

[0091] Obtain the server addition / subtraction data and non - server addition / subtraction data corresponding to each of the running trust regions respectively;

[0092] Calculate the real - time quantity ratio of the corresponding running trust region according to the server addition / subtraction data and non - server addition / subtraction data;

[0093] Synchronously correct the corresponding real - time monitoring frequency according to the real - time quantity ratio and the minimum value of the frequency monitoring.

[0094] The working principle and beneficial effects of the above technical solution: Since the number of servers and non - servers in the running trust region is constantly changing, adjusting the real - time monitoring frequency according to its change can ensure the effectiveness of monitoring and achieve synchronous monitoring.

[0095] Embodiment 4

[0096] Based on Embodiment 1, in the method for verifying a trusted running region based on a global resolution architecture, step 2 includes:

[0097] Step 21: Sample the running data of the corresponding running trust region based on the real - time monitoring frequency to obtain sampled running data, and determine the log level of the corresponding running trust region based on the trust prefix corresponding to each running trust region;

[0098] Step 22: Perform dimensionality reduction processing on each of the sampled operation data to obtain the operation key information corresponding to the operation trust region, construct corresponding timestamps according to the real-time monitoring frequency, and combine the log level and the operation key information corresponding to each operation trust region with the corresponding timestamps to generate the real-time monitoring log corresponding to each operation trust region;

[0099] Step 23: Analyze the real-time monitoring log in real time to determine several operation process characteristics corresponding to the operation trust region, determine the overall operation rule corresponding to the operation trust region based on the operation rules corresponding to each operation process characteristic, and determine the latest log data corresponding to the operation trust region according to the real-time monitoring log;

[0100] Step 24: Input the latest log data into the corresponding overall operation rule for rule matching, and construct the real-time operation status corresponding to the operation trust region according to the rule matching result and input it into the corresponding terminal for display respectively.

[0101] In this example, the log level represents the importance of the log, including: DEBUG, INFO, WARNING, ERROR, CRITICAL;

[0102] In this example, the dimensionality reduction processing means eliminating the redundancy in the sampled operation data and reducing the dimension of the sampled operation data by one degree;

[0103] In this example, the operation key information represents the information that determines the state of the operation trust region in the operation trust region;

[0104] In this example, the expression of the real-time monitoring log is: [timestamp]-[log level]-[operation key information].

[0105] Working principle and beneficial effects of the above technical solution: Data sampling is performed on the running trusted area according to the set real-time monitoring frequency, the collected data is dimensionally reduced to determine the key running information of the running trusted area. At the same time, the log level of the running trusted area is determined according to the trust prefix of the running trusted area, and a corresponding timestamp is constructed according to the real-time monitoring frequency. Further, the log level and the key running information are combined with the timestamp to construct the real-time monitoring log of the running trusted area. Then, the real-time monitoring log is further analyzed to generate the running process characteristics of the running trusted area. The overall running law of the running trusted area is constructed based on the running process characteristics. The overall running law is used to analyze the latest log data, and the real-time running state of the running trusted area is generated according to the result of the law analysis. In this way, the latest log data can be analyzed at each timestamp, so as to obtain the real-time running state corresponding to the running trusted area at different moments, effectively avoiding the interference of time delay and achieving the purpose of synchronous monitoring.

[0106] Embodiment 5

[0107] Based on Embodiment 1, for the method for verifying a trusted running area based on a global resolution architecture, Step 3 includes:

[0108] Step 31: Determine the server change information corresponding to the running trusted area according to the real-time monitoring log, determine the server distribution information corresponding to the running trusted area at each supervision moment, and map the real-time running state corresponding to each supervision moment in the server distribution information to obtain the server running information corresponding to each server at different supervision moments;

[0109] Step 32: Generate the running negotiation trajectory of the corresponding server in the corresponding running trusted area according to the server running information, determine the trusted executable trajectory corresponding to each running trusted area according to the trust prefix corresponding to each running trusted area, and respectively verify whether each running negotiation trajectory exceeds the corresponding trusted executable trajectory to determine the abnormal running trusted area containing running abnormal information;

[0110] Step 33: Adjust the real-time monitoring frequency of the abnormal running trusted area to the high-frequency monitoring frequency, collect the high-frequency running data of the abnormal running trusted area, find several pieces of associated data corresponding to the running abnormal information in the high-frequency running data, and respectively trace the origin of each piece of associated data to determine the abnormal server corresponding to each piece of associated data;

[0111] Step 34: Obtain the specified negotiation trajectory corresponding to each of the abnormal servers respectively, determine the scope of deviant negotiation corresponding to the abnormal server, and determine the content of deviant negotiation corresponding to the abnormal server. Search for the corresponding abnormal server in the abnormal operation trust area, and mark the corresponding scope of deviant negotiation and content of deviant negotiation.

[0112] In this instance, the server change information includes: server switching mode, server switch, server addition, server reduction, server failure;

[0113] In this instance, the supervision time is related to the corresponding real-time supervision frequency;

[0114] In this instance, the server operation information represents the information generated when the server is working;

[0115] In this instance, the operation negotiation trajectory represents the footprint generated when the operation trust area negotiates with other servers or non-servers during the operation process;

[0116] In this instance, the high-frequency monitoring frequency represents the process of highly frequent supervision of the abnormal operation trust area;

[0117] In this instance, the associated data represents the data related to the operation abnormal information in the abnormal operation trust area;

[0118] In this instance, the specified negotiation trajectory represents the negotiation trajectory presented by the abnormal server when it is in a normal working state;

[0119] In this instance, the content of deviant negotiation represents the content of data exchange or information exchange between the abnormal server and the insecure server or insecure non-server.

[0120] The working principle and beneficial effects of the above technical solution: In order to quickly identify whether a server is abnormal and quickly locate the servers that already have abnormalities, determine the server change information of the operation trust area according to the real-time monitoring log, determine the server distribution information at each supervision time, and further combine the corresponding real-time operation status to determine the server operation information presented by a server at different supervision times. Then, based on the server operation information, determine the operation negotiation trajectory of the server in the operation trust area, determine the abnormal servers by analyzing the legality of the operation negotiation trajectory, and at the same time determine its scope of deviant negotiation and content of deviant negotiation according to its specified negotiation trajectory and mark them in the corresponding operation trust area. It is possible to supervise multiple abnormal servers simultaneously, achieving quick identification, quick positioning, and effectively avoiding data leakage.

[0121] Embodiment 6

[0122] Based on Embodiment 5, the method for verifying a trusted operating area based on a global resolution architecture further includes:

[0123] Determine the object of deviation negotiation for each abnormal server according to the scope of deviation negotiation corresponding to each abnormal server;

[0124] Estimate the accepted content of the object of deviation negotiation according to the content of deviation negotiation, and judge the degree of influence of the accepted content on the corresponding abnormal operating area;

[0125] When the degree of influence is higher than the security level, construct interference content according to the accepted content and transmit it to the corresponding object of deviation negotiation.

[0126] The working principle and beneficial effects of the above technical solution: When data or information has been leaked, prevent the object of deviation negotiation from obtaining effective content, establish interference content based on the content it has received, and then use the interference content to destroy the content it has received, minimizing the risk of leakage.

[0127] Embodiment 7

[0128] Based on Embodiment 1, in the method for verifying a trusted operating area based on a global resolution architecture, Step 4 includes:

[0129] Step 41: Search for the abnormal real-time monitoring log corresponding to the abnormal operating trust area containing the abnormal server, extract the historical working data corresponding to the abnormal server from the abnormal real-time monitoring log, and divide the historical working data into system sub-data, application sub-data, and access sub-data;

[0130] Step 42: Identify the service function change information corresponding to the abnormal server according to the system sub-data, identify the service function management change information corresponding to the abnormal server according to the application sub-data, and identify the service negotiation change information corresponding to the abnormal server according to the access sub-data;

[0131] Step 43: Determine the abnormal cause corresponding to each abnormal server according to the service function change information, the service function management change information, and the service negotiation change information corresponding to each abnormal server, generate a corresponding countermeasure according to the abnormal cause, and use the countermeasure for data interception and notification reminder.

[0132] In this example, the service function change information refers to the information generated when the abnormal server adds or reduces service functions, the service function management change information refers to the information generated when the management terminal performs different management on the abnormal server, and the service negotiation change information refers to the information generated when the abnormal server negotiates with other servers or non-servers;

[0133] In this example, the countermeasures include two parts: data interception and notification reminder.

[0134] The working principle and beneficial effects of the above technical solution: When an abnormal server has appeared in the running trusted area, extract the historical working data of the abnormal server from its abnormal real-time monitoring log, and then identify various change information of the abnormal server, so as to determine the cause of the abnormality of the abnormal server. Finally, generate corresponding countermeasures for data interception and notification reminder, and perform further interception processing on the leaked data or information, and minimize the risk of data leakage through multiple safeguards.

[0135] Embodiment 8

[0136] Based on Embodiment 7, the method for verifying a trusted running area based on a global resolution architecture further includes:

[0137] Obtain the management terminal corresponding to the abnormal running trusted area, and generate corresponding notification text and reminder method according to the countermeasure and transmit them to the management terminal for notification reminder.

[0138] The working principle and beneficial effects of the above technical solution: Manage and remind different abnormal running trusted areas differently, which is convenient for managers to make decisions as soon as possible.

[0139] Embodiment 9

[0140] This embodiment provides a system for verifying a trusted running area based on a global resolution architecture, as Figure 2 shown, including:

[0141] An effective supervision module, which is used to set corresponding trust prefixes for each running area, determine a number of running trusted areas, and set corresponding real-time monitoring frequencies for each of the running trusted areas;

[0142] A log analysis module, which is used to update the real-time monitoring log corresponding to each running trusted area based on the real-time monitoring frequency, analyze the real-time running status of the corresponding running trusted area according to the real-time monitoring log and display it;

[0143] An abnormal verification module, which is used to perform hierarchical verification on each of the real-time running statuses, determine the running abnormal information of the corresponding running trusted area, and trace the running abnormal information in the corresponding running trusted area to determine the abnormal server;

[0144] An abnormal processing module, which is used to obtain the historical working data of the corresponding abnormal server in the real-time monitoring log, identify the cause of the abnormality corresponding to the abnormal information and perform corresponding data interception and notification reminder.

[0145] In this example, the trust prefix represents an identifier used to distinguish between trusted and untrusted regions, and also represents different trusted regions. The trust prefixes include: TEEA (used to identify all applications or modules related to the trusted execution environment), SEC_ (representing security-related functions or modules), TEE_ (used to identify APIs or functions related to the TEE), and SCT_ (a module representing the security context, usually used to describe context management in the EE);

[0146] In this example, the running region represents a specified region, such as: City A, Community B, Room C;

[0147] In this example, the running trusted region means that legal data activities can be carried out within this running trusted region;

[0148] In this example, the real-time monitoring frequency corresponding to each running trusted region is different;

[0149] In this example, the running exception information represents the information presented when an exception occurs in a running trusted region;

[0150] In this example, the real-time monitoring log represents the log generated when supervising the work of a running trusted region in a 24-hour cycle, and one running trusted region corresponds to one real-time monitoring log, and the real-time monitoring log is in a continuously updated state;

[0151] In this example, the trust running region verification method and system based on the global resolution architecture of the present invention, as a basic module of the Handle identification resolution technology, has a wide and important scope of use. The trust running region verification method and system of the global resolution architecture can provide unified security standards and verification mechanisms for institutions in different countries and regions, ensure the security of cross-border data transmission and sharing, break information barriers, and promote global economic cooperation and cultural exchanges;

[0152] In this example, when an abnormal situation is detected, notifying the user by email can enable relevant personnel to quickly understand the severity and urgency of the problem. Users can take timely measures, such as activating the emergency plan, notifying the technical team for handling, etc., to avoid the problem from further expanding;

[0153] In this example, the purpose of hierarchical verification is: 1. Monitoring the server running region can effectively prevent unauthorized access. If the server appears outside the trusted running region, it is very likely to have been attacked maliciously or illegally transferred. Discovering such abnormal situations in a timely manner can prevent attackers from further invading the system and protect the security of sensitive data and services;

[0154] 2. Based on the records of abnormal situations, potential security risk points can be analyzed, and then security policies can be adjusted and improved. For example, strengthening access control for specific areas, adding identity authentication mechanisms, etc., to improve the overall security of the system.

[0155] The working principle and beneficial effects of the above technical solution: In order to verify the specific operating conditions of the trusted operating area, the present invention provides a strong guarantee for information sharing and the security of the architecture. First, in order to demarcate the trusted operating area from other areas, a corresponding trust prefix is set for each operating area, and different real-time monitoring frequencies are set for different operating trusted areas, which can not only achieve data monitoring but also adjust the frequency according to the actual situation of the operating trusted area to avoid the phenomenon of supervision failure. Then, the operating trusted area is monitored according to the real-time monitoring frequency to generate corresponding real-time monitoring logs. The real-time operating status of the operating trusted area is determined based on the real-time monitoring logs. The operating abnormal information of the operating trusted area is determined by hierarchical verification of the real-time operating status, and the abnormal server is traced. In order to avoid losses caused by data leakage, abnormal identification is performed on the abnormal server, and data interception is carried out according to its abnormal cause and relevant personnel are notified to handle it in a timely manner, improving the effective supervision of the operating trusted area and enhancing the security of the operating trusted area.

[0156] Embodiment 10

[0157] Based on Embodiment 9, for the trust operating area verification system based on the global resolution architecture, the effective supervision module includes:

[0158] A trust configuration unit, which is used to respectively obtain the security development level corresponding to each operating area, set a corresponding trust prefix for the corresponding operating area according to the security development level, determine a number of operating trusted areas, and classify the operating trusted areas according to the trust prefix, and determine a number of operating trusted areas corresponding to each security development level;

[0159] A frequency initial setting unit, which is used to configure an initial monitoring frequency for the corresponding operating trusted area based on the security development level, respectively obtain the number of servers corresponding to each operating trusted area, sort the operating trusted areas based on the number of servers, obtain the last operating trusted area at the end of the sorting, and regard the last initial monitoring frequency corresponding to the last operating trusted area as the minimum threshold of the monitoring frequency;

[0160] A frequency determination unit is configured to calculate the quantity ratio between the servers and non-servers included in each of the operation trust regions respectively, add corresponding service weights to the corresponding operation trust regions according to the quantity ratio, and correct the corresponding initial monitoring frequencies by using the service weights and the minimum monitoring frequency threshold, so as to obtain the real-time monitoring frequency corresponding to each of the operation trust regions.

[0161] In this instance, the minimum monitoring frequency threshold indicates that the set monitoring frequency cannot be lower than this value.

[0162] In this instance, the secure development level represents the current security level of the operation region.

[0163] In this instance, the service weight is related to the number of servers. The more servers there are, the more likely data leakage will occur, and thus the greater the service weight.

[0164] The working principle and beneficial effects of the above technical solution: Since different operation trust regions have different operation attributes, corresponding monitoring frequencies should be set according to their actual requirements when monitoring different operation trust regions. First, set corresponding trust prefixes according to the secure development level of the operation region, then configure corresponding initial monitoring frequencies for the operation trust regions in combination with the secure development level of each operation trust region, then construct corresponding service weights in combination with the quantity ratio of servers and non-servers in each operation trust region, and at the same time set the minimum monitoring frequency threshold according to the actual situation. Finally, correct the initial monitoring frequencies according to the service weights and the minimum monitoring frequency threshold to obtain the real-time monitoring frequency of each operation trust region. By setting the monitoring frequency and the trusted operation region for a specific prefix, it is possible to record and determine whether the current service is running in the trusted region in the subsequent process, improving the system security.

[0165] Obviously, those skilled in the art can make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if these modifications and variations of the present invention fall within the scope of the claims of the present invention and their equivalent technologies, the present invention is also intended to include these changes and modifications.

Claims

1. A trust operation area verification method based on a global parsing architecture, characterized in that Including: Step 1: Set corresponding trust prefixes for each operating area, determine a number of operating trust areas, and set corresponding real-time monitoring frequencies for each of the operating trust areas; Step 2: Update the real-time monitoring logs corresponding to each of the operating trust areas based on the real-time monitoring frequencies, analyze the real-time operating status of the corresponding operating trust areas according to the real-time monitoring logs, and display them; Step 3: Perform hierarchical verification on each of the real-time operating statuses, determine the operating exception information of the corresponding operating trust area, track the operating exception information in the corresponding operating trust area, and determine the abnormal server; Step 4: Obtain the historical working data of the corresponding abnormal server from the real-time monitoring logs, identify the abnormal causes corresponding to the abnormal information, and perform corresponding data interception and notification reminders; The said Step 1 includes: Step 11: Obtain the corresponding security development level of each operating area respectively, set corresponding trust prefixes for the corresponding operating areas according to the security development level, determine a number of operating trust areas, and classify the operating trust areas according to the trust prefixes, and determine a number of operating trust areas corresponding to each security development level; Step 12: Configure the initial monitoring frequency for the corresponding operating trust area based on the security development level, obtain the number of servers corresponding to each of the operating trust areas respectively, sort the operating trust areas based on the number of servers, obtain the last operating trust area at the end of the sorting, and regard the last initial monitoring frequency corresponding to the last operating trust area as the minimum threshold of the monitoring frequency; Step 13: Calculate the quantity ratio between the servers and non-servers included in each of the operating trust areas respectively, add corresponding service weights to the corresponding operating trust areas according to the quantity ratio, and use the service weights and the minimum threshold of the monitoring frequency to correct the corresponding initial monitoring frequencies to obtain the real-time monitoring frequencies corresponding to each of the operating trust areas.

2. The trust operation area verification method based on the global resolution architecture according to claim 1, characterized in that It also includes: Obtain the server addition / deletion data and non-server addition / deletion data corresponding to each of the operating trust areas respectively; Calculate the real-time quantity ratio corresponding to the corresponding operating trust area according to the server addition / deletion data and non-server addition / deletion data; Synchronously correct the corresponding real-time monitoring frequency according to the real-time quantity ratio and the minimum threshold of the monitoring frequency.

3. The method for verifying a trusted operating region based on a global resolution architecture according to claim 1, wherein The said Step 2 includes: Step 21: Perform sampling of operating data for the corresponding operating trust area based on the real-time monitoring frequency to obtain sampled operating data, and determine the log level of the corresponding operating trust area based on the trust prefix corresponding to each operating trust area; Step 22: Perform dimensionality reduction processing on each of the sampled operating data respectively to obtain the operating key information of the corresponding operating trust area, construct corresponding timestamps according to the real-time monitoring frequency, combine the log level and the operating key information corresponding to each operating trust area with the corresponding timestamps to generate the real-time monitoring logs corresponding to each operating trust area. Step 23: Analyze the real-time monitoring log in real time, determine several operation process features corresponding to the running trust region, determine the overall operation rule corresponding to the running trust region based on the operation rule corresponding to each operation process feature, and determine the latest log data corresponding to the running trust region according to the real-time monitoring log; Step 24: Input the latest log data into the corresponding overall operation rule for rule matching, construct the real-time operation state corresponding to the running trust region according to the rule matching result, and input it into the corresponding terminal for display respectively.

4. The trust operation area verification method based on the global resolution architecture according to claim 1, characterized in that The said Step 3 includes: Step 31: Determine the server change information corresponding to the running trust region according to the real-time monitoring log, determine the server distribution information corresponding to the running trust region at each supervision moment, map the real-time operation state corresponding to each supervision moment in the server distribution information, and obtain the server operation information corresponding to each server at different supervision moments; Step 32: Generate the operation negotiation track of the corresponding server in the corresponding running trust region according to the server operation information, determine the trust operable track corresponding to each running trust region according to the trust prefix corresponding to each running trust region, verify whether each operation negotiation track exceeds the corresponding trust operable track respectively, and determine the abnormal running trust region containing operation abnormal information; Wherein, the operation negotiation track represents the footprint generated when the running trust region negotiates with other servers or non-servers during the operation process, Step 33: Adjust the real-time monitoring frequency of the abnormal running trust region to the high-frequency monitoring frequency, collect the high-frequency operation data of the abnormal running trust region, find several associated data corresponding to the operation abnormal information in the high-frequency operation data, trace each associated data respectively, and determine the abnormal server corresponding to each associated data; Step 34: Obtain the specified negotiation track corresponding to each abnormal server respectively, determine the deviated negotiation range corresponding to the abnormal server, and determine the deviated negotiation content corresponding to the abnormal server, find the corresponding abnormal server in the abnormal running trust region, and mark the corresponding deviated negotiation range and deviated negotiation content; Wherein, the specified negotiation track represents the negotiation track presented when the abnormal server is in the normal working state.

5. The method for verifying a trusted operating area based on a global resolution architecture according to claim 4, wherein It also includes: Determine the deviated negotiation object corresponding to the abnormal server according to the deviated negotiation range corresponding to each abnormal server; Estimate the accepted content of the deviated negotiation object according to the deviated negotiation content, and judge the influence degree of the accepted content on the corresponding abnormal running trust region; Wherein, the deviated negotiation content represents the content of data exchange or information exchange between the abnormal server and the insecure server or insecure non-server; When the influence degree is higher than the security degree, construct interference content according to the accepted content and transmit it to the corresponding deviated negotiation object.

6. The trust operation area verification method based on the global resolution architecture according to claim 1, characterized in that The said Step 4 includes: Step 41: Search for the abnormal real-time monitoring log corresponding to the abnormal running trust area containing the abnormal server, extract the historical working data corresponding to the abnormal server from the abnormal real-time monitoring log, and divide the historical working data into system sub-data, application sub-data, and access sub-data; Step 42: Identify the service function change information corresponding to the abnormal server according to the system sub-data, identify the service function management change information corresponding to the abnormal server according to the application sub-data, and identify the service negotiation change information corresponding to the abnormal server according to the access sub-data; Step 43: Determine the abnormal cause corresponding to the abnormal server according to the service function change information, the service function management change information, and the service negotiation change information corresponding to each abnormal server, generate a corresponding countermeasure according to the abnormal cause, and use the countermeasure for data interception and notification reminder.

7. The trust operation area verification method based on a global resolution architecture according to claim 6, wherein It also includes: Obtain the management terminal corresponding to the abnormal running trust area, generate a corresponding notification text and reminder method according to the countermeasure, and transmit them to the management terminal for notification reminder.

8. A trust operation area verification system based on a global resolution architecture, characterized in that, It includes: An effective supervision module, which is used to set corresponding trust prefixes for each running area, determine several running trust areas, and set corresponding real-time monitoring frequencies for each of the running trust areas; A log analysis module, which is used to update the real-time monitoring log corresponding to each running trust area based on the real-time monitoring frequency, analyze the real-time running status of the corresponding running trust area according to the real-time monitoring log, and display it; An abnormal verification module, which is used to perform hierarchical verification on each of the real-time running statuses, determine the running abnormal information corresponding to the running trust area, track the running abnormal information in the corresponding running trust area, and determine the abnormal server; An abnormal handling module, which is used to obtain the historical working data corresponding to the abnormal server in the real-time monitoring log, identify the abnormal cause corresponding to the abnormal information, and perform corresponding data interception and notification reminder; The effective supervision module includes: A trust configuration unit, which is used to obtain the security development level corresponding to each running area respectively, set corresponding trust prefixes for the corresponding running areas according to the security development level, determine several running trust areas, and classify the running trust areas according to the trust prefixes, and determine several running trust areas corresponding to each security development level; A frequency initial setting unit, which is used to configure the initial monitoring frequency for the corresponding running trust area based on the security development level, obtain the number of servers corresponding to each running trust area respectively, sort the running trust areas based on the number of servers, obtain the last running trust area at the end of the sorting, and regard the last initial monitoring frequency corresponding to the last running trust area as the minimum threshold of the monitoring frequency; A frequency determination unit is configured to calculate, respectively, the quantity ratio between the servers and non-servers included in each of the running trust regions, add corresponding service weights to the corresponding running trust regions according to the quantity ratio, and correct the corresponding initial monitoring frequencies by using the service weights and the minimum monitoring frequency threshold, so as to obtain the real-time monitoring frequency corresponding to each of the running trust regions.

Citation Information

Patent Citations

  • Log monitoring method and device, computer equipment and storage medium

    CN114398239A

  • Unified monitoring management platform

    CN115766417A