Cloud service comprehensive security management system based on multi-layer protection architecture
By adopting a multi-layer protection architecture in cloud service security protection, combining multi-factor identity authentication, classification detection and cross-protection knowledge graph, the problem of insufficient single-layer protection in the existing technology is solved, efficient and dynamic security protection is achieved, and the security of cloud access is improved.
Patent Information
- Application Number
- CN202510245613.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-04
- Publication Date
- 2025-05-09
- Estimated Expiration
- 2045-03-04
AI Technical Summary
The existing cloud service security protection methods are mainly focused on single-layer protection, lacking intelligent interactive joint protection, and cannot adapt to different malicious attack processes and quickly cut off access.
A cloud service comprehensive security management system based on a multi-layer protection architecture is adopted, and multi-level and multi-dimensional security detection and protection are achieved through multi-factor identity authentication, classification detection, cross-protection knowledge graph and dynamic strategy regulation.
It improves the security of cloud access, realizes personalized and dynamic security protection, can effectively deal with various malicious attacks, and ensures the stable operation of the cloud service system.
Smart Images

Figure CN119788412B_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of cloud service security, and in particular relates to a cloud service comprehensive security management system based on a multi-layer protection architecture. Background Art
[0002] In order to ensure the security of cloud services, various security protection methods and systems have emerged. At present, cloud service security protection methods mainly include data access interface protection and intrusion detection and analysis; for example, the Chinese patent application with publication number CN113206818A discloses a cloud server security protection method and system, which determines the comprehensive protection configuration parameters by considering the protection label of the data access interface to be protected and its related configuration parameters, thereby realizing the protection of the data access interface; the Chinese patent application with publication number CN115622790A discloses a cloud service security protection method, which constructs protection objects and network objects based on the cloud service platform, identifies intrusion attack tendencies through the analysis of intrusion logs, and generates intrusion analysis reports; However, the patent application with publication number CN113206818A mainly focuses on the protection of data access interfaces, lacks comprehensive consideration of other security levels, determines protection strategies through pre-set protection labels and configuration parameters, and lacks dynamic adjustment and adaptive capabilities. Although the patent application with publication number CN115622790A can identify intrusion attack tendencies through analysis of intrusion logs, its processing process is relatively complicated. It takes a certain amount of time from obtaining intrusion logs to generating intrusion analysis reports, and cannot achieve real-time response and rapid processing. In addition, this method mainly relies on the analysis of intrusion logs, and may have problems of false positives and false negatives.
[0003] The above existing technologies have the following problems: most of the existing technologies adopt a single-layer protection, which is very easy to be hacked. In addition, the existing multi-layer protection method is just a simple accumulation of multi-layer protection strategies and one-way protection, lacking intelligent interactive joint protection strategies and feedback adjustments, and unable to adapt to different malicious attack processes and quickly cut off access to malicious attacks. For this reason, the present invention provides a cloud service comprehensive security management system based on a multi-layer protection architecture. Summary of the invention
[0004] In view of the shortcomings of the prior art, the present invention proposes a cloud service comprehensive security management system based on a multi-layer protection architecture. The system performs access login through an interactive module, verifies user identity using a multi-factor identity authentication unit, and classifies and marks the access users with security levels through a classification detection unit. The system selects a suitable access detection path through an access path selection unit according to the access user type, security level and access requirements. Specifically, for whitelisted users, a first identity access token is directly generated and access is authorized. For first-time access users, anomaly detection is performed through the built-in first detection path. After the detection passes, a second identity access token is generated and access is authorized. If the detection fails, the security policy is called for adjustment until the detection passes or access is denied. For blacklisted users, the access requirements are first evaluated through an access requirement evaluation model. When the evaluation score is higher than the threshold, the second detection path is selected for multi-layer protection screening. After all are passed, a fourth identity access token is generated and access is authorized, otherwise access is directly denied. The present invention combines knowledge graph technology to construct a cross-protection knowledge graph, realizes multi-layer cross-protection, and improves the security of cloud access.
[0005] To achieve the above object, the present invention provides the following technical solutions:
[0006] A cloud service comprehensive security management system based on a multi-layer protection architecture, including: a multi-layer protection module, an access control module, and an interaction module;
[0007] The multi-layer protection module includes a multi-factor identity authentication unit, a classification detection unit, a multi-layer protection unit and an access token unit; the identity information registration and login and access requirement input are performed through the interaction module, and the identity authentication is performed through the multi-factor identity authentication unit according to the logged-in identity information. When the identity authentication is passed, the access user type is obtained through the classification detection unit and the access identity security level is marked; the access control module includes an access path selection unit and a policy control unit;
[0008] The access user type, access identity security level and access requirement are input into the access path selection unit, and the access detection path selection is performed through the cross-protection knowledge graph configured by the multi-layer protection unit. When the access user type is a whitelist user, the access requirement is directly input into the access token unit to construct a first identity access token; when the access user type is a first-time access user, the first detection path built into the cross-protection knowledge graph in the multi-layer protection unit is selected by the access path selection unit to perform access anomaly detection. When the access anomaly detection passes, the access requirement is input into the access token unit to construct a second identity access token. When the access anomaly detection fails, the corresponding security protection policy is called through the policy control unit to adjust the access anomaly. When the access anomaly detection passes after adjustment, a third identity access token is constructed. When the access anomaly detection fails or it is a malicious access, the corresponding access requirement is directly rejected.
[0009] Specifically, the multi-layer protection module also includes an access authorization unit;
[0010] When the access user type is a blacklist user, the access demand is evaluated and judged through the configured access demand evaluation model. When the judgment is passed, the second detection path built into the cross-protection knowledge graph in the multi-layer protection unit is selected through the access path selection unit. When all the detection nodes in the second detection path are passed, the fourth identity access token is constructed through the access token unit. When any node in the second detection path fails to pass the detection or the evaluation judgment, the corresponding access demand is directly rejected through the policy control unit, and access feedback is performed through the interactive module;
[0011] The generated first identity access token, second identity access token, third identity access token, and fourth identity access token are input into the access authorization unit for verification. When the verification passes, the corresponding access requirement is authorized, otherwise the access is denied.
[0012] Specifically, the steps of obtaining the access user type and marking the access identity security level include:
[0013] A1. Obtain historical user login and multi-identity authentication information, access demand information, access frequency, the number of abnormal access and malicious attack access, the length of a single access, and the abnormal access frequency information of the access device, and pre-process the acquired data;
[0014] A2. Input the pre-processed user identity and access data into the comprehensive fuzzy evaluation model to obtain the corresponding user security access evaluation score , represents the k-th user identity security access evaluation score;
[0015] A3. Set the score threshold for the third-level security access assessment and ,when When , the corresponding user is assumed to be a whitelist user, and the identity security level is the first security level. When , the corresponding user is assumed to be a primary blacklist user, and the identity security level is the second security level; when When , the corresponding user is assumed to be a medium-level blacklist user, and the identity security level is the third security level. , the corresponding user is assumed to be a malicious attack user, and the identity security level is the fourth security level.
[0016] Specifically, the step of obtaining the access user type and marking the access identity security level also includes:
[0017] A4. Input the obtained pre-processed user identity, access data, and corresponding security access assessment score and identity security level into the entity extraction model for keyword extraction to obtain the [user identity, access information, identity security level] triple information;
[0018] A5. Input the triplet information into the graph database, obtain the historical access user identity security level database, and configure the historical access user identity security level database and the comprehensive fuzzy evaluation model to the login verification interface;
[0019] A6. Obtain the identity information of the registered login user and the historical access information of the corresponding access device in real time, and use the comprehensive fuzzy evaluation model configured in the login verification interface to evaluate and obtain the security access evaluation score of the real-time access user;
[0020] A7. According to the real-time user identity information and the corresponding security access assessment score, the access user type of the corresponding access user is obtained and the identity type is marked by matching the model and the configured historical access user identity security level database. If the corresponding historical access user cannot be matched, the user is a first-time access user.
[0021] A8. For first-time users, the access consent form is configured to obtain the historical access information and abnormal access mark information of the device used by the first-time user.
[0022] Specifically, the cross-protection knowledge graph configured by the multi-layer protection unit includes a first-level verification node, a second-level control node, a third-level protection detection node, a fourth-level security encryption node, and a fifth-level access data storage node;
[0023] The first-level verification node includes an identity authentication sub-node and a verification classification sub-node; the second-level control node includes an access control sub-node;
[0024] The three-level protection detection node includes a protection detection sub-node, a protection strategy sub-node and a verification and authorization sub-node; the protection detection sub-node includes a boundary protection layer, an application security layer, an intrusion detection layer, and a terminal security layer, and the boundary protection layer, the application security layer, the intrusion detection layer, and the terminal security layer all have built-in security detection score thresholds; the protection strategy sub-node includes an emergency strategy layer and a security audit layer; the verification and authorization sub-node includes an access token verification layer and an access authorization layer;
[0025] The fourth-level security encryption node includes a data security layer sub-node; the fifth-level access data storage node includes a bottom-level access data sub-node.
[0026] Specifically, the connection relationship between each node in the cross-protection knowledge graph is:
[0027] The identity authentication subnode in the first-level verification node is connected to the verification classification subnode, the verification classification subnode is connected to the second-level control node, the second-level control node connection has a first detection path and a second detection path built in, the second-level control node is connected to the protection detection subnode in the third-level protection detection node through the built-in path information, and is directly connected to the protection strategy subnode and the verification authorization subnode;
[0028] The emergency strategy layer in the protection strategy subnode in the three-level protection detection node and the boundary protection layer, application security layer, intrusion detection layer, and terminal security layer in the protection detection subnode are all connected, and the security audit layer and the boundary protection layer, application security layer, intrusion detection layer, and terminal security layer in the protection detection subnode are also connected;
[0029] The protection detection subnode in the third-level protection detection node is connected to the access token verification layer in the verification and authorization subnode; the access token verification layer is connected to the access authorization layer; the access authorization layer is connected to the fourth-level security encryption node; the fourth-level security encryption node is connected to the fifth-level access data storage node and the second-level control node.
[0030] Specifically, the first detection path includes any three of the parallel boundary protection layer, application security layer, intrusion detection layer, terminal security layer and emergency strategy layer; the second detection path includes the serially connected boundary protection layer, application security layer, intrusion detection layer, terminal security layer and emergency strategy layer, and security audit layer;
[0031] The workflow steps of the cross-protection knowledge graph include:
[0032] B1. Acquire real-time access user identity information and access requirement information, perform identity authentication and corresponding identity type classification through the identity authentication sub-node and the verification classification sub-node, and obtain the corresponding access user type and corresponding historical access data information;
[0033] B2. When the corresponding access user type is a whitelist user, the kth user access information sensitivity score is obtained through the evaluation algorithm according to the corresponding user's access requirement information. ;
[0034] B3. Set the sensitivity score threshold ,when Less than or equal to When the user identity basic information, access requirement information and configuration access validity period information are directly input into the access token verification layer through the control of the access control sub-node to construct and verify the access identity token. When the verification is passed, the access authorization layer is used to perform access authorization, and the underlying access data sub-node is accessed and interacted with through the authorization information and the verified access identity token.
[0035] B4. When the verification fails, the access process is adjusted by calling the emergency policy corresponding to the emergency policy layer through the access control sub-node. If the verification passes after adjustment, the B3 process is repeated for access interaction. If the verification fails after adjustment, the corresponding user is marked as access abnormal, and the corresponding user is removed from the whitelist users. The identity security level of the corresponding access user at the current moment is reconfirmed through the A1 to A3 processes, and added to the corresponding identity security level node.
[0036] Specifically, the workflow steps of the cross-protection knowledge graph also include:
[0037] B5. When Greater than , the access control subnode calls the first detection path to detect the input user identity basic information and access requirement information. When the detection in the first detection path is passed, the corresponding user identity basic information, access requirement information and configured access validity period information are input into the access token verification layer, and the B3 and B4 processes are repeated to reconfirm the access interaction and identity security level;
[0038] B6. If the detection of the first detection path fails, the emergency strategy in the emergency strategy layer is called through the access control subnode to adjust the layer that failed the detection. If the detection in the first detection path passes after adjustment, the B5 process is repeated to reconfirm the access interaction and identity security level. If the detection in the first detection path fails after adjustment, the access request at the current moment is directly rejected, and the corresponding user identity security level is reconfirmed.
[0039] B7. When the corresponding access user type is a primary blacklist user and Less than or equal to When the access control sub-node calls the first detection path to detect the input user identity basic information and access requirement information, when the detection in the first detection path is passed, the corresponding user identity basic information, access requirement information and configuration access valid time period information are input into the access token verification layer to construct and verify the identity token, and when the verification passes, the B3 process is repeated to perform access interaction.
[0040] Specifically, the workflow steps of the cross-protection knowledge graph also include:
[0041] B8. If the identity token fails to be verified, repeat B4 to adjust the identity token. If the verification passes after adjustment, repeat B7 to perform access interaction.
[0042] B9. If the verification fails after adjustment, the primary blacklist user will be marked, and the current access user identity security level will be evaluated and confirmed. The corresponding path will be re-called for access interaction according to the current access user identity security level;
[0043] B10. When the detection in the first detection path fails, the emergency strategy in the emergency strategy layer is called through the access control subnode to adjust the layer that failed the detection. When it passes after adjustment, the B7-B9 process is repeated to perform access interaction or new identity security level confirmation and new access detection path selection;
[0044] B11. If the adjustment fails, the current access request will be rejected directly, and a new identity security level confirmation and a new access detection path selection will be performed.
[0045] Specifically, the workflow steps of the cross-protection knowledge graph also include:
[0046] B12. When the corresponding access user type is a primary blacklist user and Greater than When the first detection path passes but the identity token verification fails, the emergency policy in the emergency policy layer is called through the access control subnode to adjust the identity token. If the verification passes, the B8 process is repeated for access interaction. If it fails, the current user's access request is directly rejected, and a new identity security level confirmation and a new access detection path selection are performed;
[0047] B13. When the corresponding access user type is an intermediate blacklist user, the second detection path and the security protection library built in the security audit layer are called through the access control subnode to detect the input user identity basic information and access requirement information. When the detection passes and the identity token verification passes, authorized interactive access is performed, and the accessed data information is encrypted and transmitted through the data security layer subnode;
[0048] B14. When one of the second detection path detection or identity token verification fails, the corresponding user is identified as a malicious attack user and access is directly denied, and the user is added to the historical access user identity security level database;
[0049] B15. When the corresponding access user type is a malicious attack user, directly reject the corresponding access request;
[0050] B16. When the corresponding access user type is a first-time access user, and The size of Less than or equal to When the whitelist user access interaction process is repeated, Greater than When , the primary blacklist user access interaction process is repeated;
[0051] B17, B1-B16 process verification passed and Greater than The data accessed by the accessing user is encrypted and interacted with through the data security layer sub-node.
[0052] Compared with the prior art, the present invention has the following beneficial effects:
[0053] In view of the deficiencies in the prior art, the present invention uses a multi-factor identity authentication unit and a classification detection unit to perform accurate identity authentication and security level marking on access users, thereby ensuring the initial security of access; the access path selection unit intelligently selects the access detection path according to the user type and security level, thereby realizing personalized and dynamic security protection; especially for first-time access users and blacklisted users, the system adopts the cross-protection knowledge graph in the multi-layer protection unit, and performs multi-level and multi-dimensional anomaly detection and security assessment through the first detection path and the second detection path, thereby ensuring the security of access requests; at the same time, the policy control unit can call the corresponding security protection strategy in real time according to the detection results, adjust or reject abnormal access, forming a closed-loop security management mechanism, effectively responding to various malicious attacks, and ensuring the stable operation of the cloud service system. BRIEF DESCRIPTION OF THE DRAWINGS
[0054] Figure 1 This is a module diagram of a cloud service integrated security management system based on a multi-layer protection architecture according to Embodiment 1 of the present invention;
[0055] Figure 2 This is a cross-protection knowledge graph architecture diagram of Example 1 of the present invention;
[0056] Figure 3 This is the corresponding unit workflow diagram of the cloud service comprehensive security management system based on the multi-layer protection architecture according to Example 2 of the present invention. DETAILED DESCRIPTION
[0057] Example 1
[0058] See also Figure 1 , an embodiment provided by the present invention: a cloud service integrated security management system based on a multi-layer protection architecture, comprising: a multi-layer protection module, an access control module and an interaction module;
[0059] The multi-layer protection module is used to construct a multi-layer protection strategy to protect the working status of the cloud service in real time; the multi-layer protection module includes a multi-factor identity authentication unit, a classification detection unit, a multi-layer protection unit, an access token unit and an access authorization unit;
[0060] The multi-factor identity authentication unit is used to verify the user identity and the registration and login of the user identity through multiple authentication methods; further, in this embodiment, the multiple authentication methods include user name / password, SMS verification code, and biometrics;
[0061] The classification detection unit is used to obtain the current access user type and mark the primary access security level according to the user request information and registration information through the configured whitelist database and matching classification algorithm. The current access user type includes whitelist users, first-time access users and blacklist users;
[0062] Furthermore, in this embodiment, the steps of obtaining the access user type and marking the access identity security level include:
[0063] A1. Obtain historical user login and multi-identity authentication information, access demand information, access frequency, the number of abnormal access and malicious attack access, the length of a single access, and the abnormal access frequency information of the access device, and pre-process the acquired data;
[0064] A2. Input the pre-processed user identity and access data into the comprehensive fuzzy evaluation model to obtain the corresponding user security access evaluation score , represents the k-th user identity security access evaluation score;
[0065] A3. Set the score threshold for the third-level security access assessment and ,when When , the corresponding user is assumed to be a whitelist user, and the identity security level is the first security level. When , the corresponding user is assumed to be a primary blacklist user, and the identity security level is the second security level; when When , the corresponding user is assumed to be a medium-level blacklist user, and the identity security level is the third security level. When , the corresponding user is assumed to be a malicious attack user, and the identity security level is the fourth security level;
[0066] Furthermore, in this embodiment, whitelist users are users who have no access anomalies and malicious attacks during n access processes, primary blacklist users are users who have low-frequency access anomalies but no malicious attacks during n access processes, intermediate blacklist users are users who have high-frequency access anomalies and potential malicious attack intentions during n access processes, and malicious attack users are users who have carried out malicious attacks during n access processes.
[0067] A4. Input the obtained pre-processed user identity, access data, and corresponding security access assessment score and identity security level into the entity extraction model for keyword extraction to obtain the [user identity, access information, identity security level] triple information;
[0068] A5. Input the triplet information into the graph database, obtain the historical access user identity security level database, and configure the historical access user identity security level database and the comprehensive fuzzy evaluation model to the login verification interface;
[0069] A6. Obtain the identity information of the registered login user and the historical access information of the corresponding access device in real time, and use the comprehensive fuzzy evaluation model configured in the login verification interface to evaluate and obtain the security access evaluation score of the real-time access user;
[0070] A7. According to the identity information of the real-time access user and the corresponding security access assessment score, the access user type of the corresponding access user is obtained and the identity type is marked through the matching model and the configured historical access user identity security level database. If the corresponding historical access user cannot be matched, it is a first-time access user;
[0071] A8. For first-time users, the access consent form is configured to obtain the historical access information and abnormal access mark information of the device used by the first-time user.
[0072] The process first ensures the accuracy and security of user identity through multiple authentication methods such as username / password, SMS verification code and biometrics; secondly, the classification detection unit uses the whitelist database and matching classification algorithm to quickly identify and mark the access user type, thereby improving the efficiency and accuracy of access control; in particular, by obtaining and preprocessing historical user login and multi-identity authentication information, combined with data such as access requirements, access frequency, abnormal access and malicious attack times, the information is input into the comprehensive fuzzy evaluation model to obtain the user's security access evaluation score; a three-level security access evaluation score threshold is set to divide users into whitelist users, primary blacklist users, intermediate blacklist users and malicious attack users, thereby achieving fine-grained security management; further, a historical access user identity security level database is constructed through an entity extraction model and a graph database to ensure the integrity and traceability of the data; the identity information and historical access information of registered and logged-in users are obtained in real time, and a comprehensive fuzzy evaluation model is used for real-time evaluation, and the historical database is combined for matching and marking to ensure the real-time and accuracy of the system; for first-time users, the device historical access information and abnormal access tag information are obtained by configuring the access consent form, thereby further enhancing the security of the system and the trust of users.
[0073] The multi-layer protection unit is used to construct a cross-protection knowledge graph based on the boundary protection layer, application security layer, intrusion detection layer, data security layer, security audit layer, terminal security layer and emergency strategy layer in combination with the knowledge graph, and perform multi-layer protection screening and anomaly detection on the input user needs;
[0074] Furthermore, the boundary protection layer in this embodiment has a built-in firewall; the application security layer is used to protect Web applications from common attacks, such as SQL injection and XSS; the intrusion detection layer is used for intrusion detection and threat intelligence analysis; the data security layer is used to encrypt, store and transmit sensitive data; the security audit layer is used to collect and manage the security logs of the system, identify potential security issues, and use the identified security issues to build a security protection library; the terminal security layer is used to detect and remove malware and protect terminal devices; the emergency strategy layer is used to build an emergency strategy library to provide real-time security solution strategies for problems detected by the boundary protection layer, application security layer, intrusion detection layer, data security layer, security audit layer and terminal security layer.
[0075] Furthermore, the cross-protection knowledge graph configured by the multi-layer protection unit in this embodiment includes a first-level verification node, a second-level control node, a third-level protection detection node, a fourth-level security encryption node, and a fifth-level access data storage node;
[0076] The first-level verification node includes an identity authentication sub-node and a verification classification sub-node; the second-level control node includes an access control sub-node;
[0077] The three-level protection detection node includes a protection detection sub-node, a protection strategy sub-node and a verification authorization sub-node; the protection detection sub-node includes a boundary protection layer, an application security layer, an intrusion detection layer, and a terminal security layer, and the boundary protection layer, the application security layer, the intrusion detection layer, and the terminal security layer all have built-in security detection score thresholds. When the corresponding security detection score is greater than the security detection score threshold of the corresponding layer, the security detection of the corresponding layer is passed;
[0078] The protection strategy sub-node includes an emergency strategy layer and a security audit layer; the verification and authorization sub-node includes an access token verification layer and an access authorization layer;
[0079] The fourth-level security encryption node includes a data security layer sub-node; the fifth-level access data storage node includes a bottom-level access data sub-node.
[0080] For further information, see Figure 2 , the connection relationship between the nodes in the cross-protection knowledge graph in this embodiment is:
[0081] The identity authentication subnode in the first-level verification node is connected to the verification classification subnode, the verification classification subnode is connected to the second-level control node, the second-level control node connection has a first detection path and a second detection path built in, the second-level control node is connected to the protection detection subnode in the third-level protection detection node through the built-in path information, and is directly connected to the protection strategy subnode and the verification authorization subnode;
[0082] Furthermore, in this embodiment, the identity authentication subnode corresponds to the multi-factor identity authentication unit; the verification classification subnode corresponds to the classification detection unit; the secondary control node corresponds to the access control module; the protection detection subnode corresponds to the multi-layer protection unit; the protection policy subnode corresponds to the policy control unit; the access path selection unit selects the path information through the configured first detection path and the second detection path;
[0083] The emergency strategy layer in the protection strategy subnode in the three-level protection detection node and the boundary protection layer, application security layer, intrusion detection layer, and terminal security layer in the protection detection subnode are all connected, and the security audit layer and the boundary protection layer, application security layer, intrusion detection layer, and terminal security layer in the protection detection subnode are also connected;
[0084] The protection detection subnode in the third-level protection detection node is connected to the access token verification layer in the verification and authorization subnode; the access token verification layer is connected to the access authorization layer; the access authorization layer is connected to the fourth-level security encryption node; the fourth-level security encryption node is connected to the fifth-level access data storage node and the second-level control node.
[0085] Further, in this embodiment, the access token verification layer corresponds to the access token unit; the access authorization layer corresponds to the access authorization unit; the data security layer subnode corresponds to the data security layer; the bottom access data subnode is used for the storage of access data in the cloud service;
[0086] The process first forms a comprehensive protection system through the collaborative work of the boundary protection layer, application security layer, intrusion detection layer, data security layer, security audit layer, terminal security layer and emergency strategy layer; each layer of the boundary protection layer, application security layer, intrusion detection layer and terminal security layer has a built-in security detection score threshold to ensure the accuracy and reliability of the security detection results of each layer; secondly, through the identity authentication sub-node and verification classification sub-node of the first-level verification node, accurate verification and classification of user identity are achieved to ensure the initial security of access requests; the second-level control node realizes intelligent path selection through the built-in first detection path and second detection path, improving the flexibility and adaptability of the system; the protection strategy sub-node and verification authorization sub-node in the third-level protection detection node, combined with the emergency strategy layer and security audit layer, realize real-time adjustment of detection results and dynamic update of security policies; the access token verification layer and access authorization layer ensure the legitimacy and security of access requests, and the data security layer sub-node and the underlying access data sub-node ensure the encrypted storage and transmission of data, further improving the security of data.
[0087] Further, in this embodiment, the first detection path includes any three of the parallel boundary protection layer, application security layer, intrusion detection layer, terminal security layer and emergency strategy layer; the second detection path information includes the serially connected boundary protection layer, application security layer, intrusion detection layer, terminal security layer and emergency strategy layer, and security audit layer;
[0088] The workflow steps of the cross-protection knowledge graph include:
[0089] B1. Acquire real-time access user identity information and access requirement information, perform identity authentication and corresponding identity type classification through the identity authentication sub-node and the verification classification sub-node, and obtain the corresponding access user type and corresponding historical access data information;
[0090] B2. When the corresponding access user type is a whitelist user, the kth user access information sensitivity score is obtained through the evaluation algorithm according to the corresponding user's access requirement information. ;
[0091] B3. Set the sensitivity score threshold ,when Less than or equal to When the user identity basic information, access requirement information and configuration access validity period information are directly input into the access token verification layer through the control of the access control sub-node to construct and verify the access identity token. When the verification is passed, the access authorization layer is used to perform access authorization, and the underlying access data sub-node is accessed and interacted with through the authorization information and the verified access identity token.
[0092] B4. When the verification fails, the access control subnode calls the emergency policy corresponding to the emergency policy layer to adjust the access process. If the verification passes after the adjustment, the B3 process is repeated for access interaction. If the verification fails after the adjustment, the corresponding user is marked as abnormal, and the corresponding user is removed from the whitelist users. The identity security level of the corresponding access user at the current moment is reconfirmed through the A1 to A3 processes and added to the corresponding identity security level node;
[0093] B5. When Greater than , the access control subnode calls the first detection path to detect the input user identity basic information and access requirement information. When the detection in the first detection path is passed, the corresponding user identity basic information, access requirement information and configured access validity period information are input into the access token verification layer, and the B3 and B4 processes are repeated to reconfirm the access interaction and identity security level;
[0094] Furthermore, in the present embodiment, the detection layer of the first detection path is selected by accessing the user access information and the detection function of the corresponding layer, and matching is performed through a matching algorithm to obtain the detection layers with the top three matching degrees for detection.
[0095] B6. If the detection of the first detection path fails, the emergency strategy in the emergency strategy layer is called through the access control subnode to adjust the layer that failed the detection. If the detection in the first detection path passes after adjustment, the B5 process is repeated to reconfirm the access interaction and identity security level. If the detection in the first detection path fails after adjustment, the access request at the current moment is directly rejected, and the corresponding user identity security level is reconfirmed.
[0096] B7. When the corresponding access user type is a primary blacklist user and Less than or equal to When the access control sub-node calls the first detection path to detect the input user identity basic information and access requirement information, when the detection in the first detection path is passed, the corresponding user identity basic information, access requirement information and configuration access valid time period information are input into the access token verification layer to construct and verify the identity token, and when the verification passes, the B3 process is repeated to perform access interaction.
[0097] B8. If the identity token fails to be verified, repeat B4 to adjust the identity token. If the verification passes after adjustment, repeat B7 to perform access interaction.
[0098] B9. If the verification fails after adjustment, the primary blacklist user will be marked, and the current access user identity security level will be evaluated and confirmed. The corresponding path will be re-called for access interaction according to the current access user identity security level;
[0099] B10. When the detection in the first detection path fails, the emergency strategy in the emergency strategy layer is called through the access control subnode to adjust the layer that failed the detection. When it passes after adjustment, the B7-B9 process is repeated to perform access interaction or new identity security level confirmation and new access detection path selection;
[0100] B11. If the adjustment fails, the current access request will be rejected directly, and a new identity security level confirmation and a new access detection path selection will be performed;
[0101] B12. When the corresponding access user type is a primary blacklist user and Greater than When the first detection path passes but the identity token verification fails, the emergency policy in the emergency policy layer is called through the access control subnode to adjust the identity token. If the verification passes, the B8 process is repeated for access interaction. If it fails, the current user's access request is directly rejected, and a new identity security level confirmation and a new access detection path selection are performed;
[0102] B13. When the corresponding access user type is an intermediate blacklist user, the second detection path and the security protection library built in the security audit layer are called through the access control subnode to detect the input user identity basic information and access requirement information. When the detection passes and the identity token verification passes, authorized interactive access is performed, and the accessed data information is encrypted and transmitted through the data security layer subnode;
[0103] B14. When one of the second detection path detection or identity token verification fails, the corresponding user is identified as a malicious attack user and access is directly denied, and the user is added to the historical access user identity security level database;
[0104] B15. When the corresponding access user type is a malicious attack user, directly reject the corresponding access request;
[0105] B16. When the corresponding access user type is a first-time access user, and The size of Less than or equal to When the whitelist user access interaction process is repeated, Greater than When , the primary blacklist user access interaction process is repeated;
[0106] B17, B1-B16 process verification passed and Greater than The data accessed by the accessing user is encrypted and interacted with through the data security layer sub-node.
[0107] This process ensures that different types of user requests can be properly and securely handled through multi-level security verification and dynamic adjustment mechanisms. For whitelist users, the user's access information sensitivity score is obtained through an evaluation algorithm. When the access information sensitivity score is less than or equal to the sensitivity score threshold, access token verification and authorization are directly performed to ensure fast access for high-trust users. When the access information sensitivity score is greater than the sensitivity score threshold, the first detection path is called for multi-layer detection to ensure the security of high-sensitivity requests. For primary blacklist users, multi-layer detection is performed through the first detection path to ensure that access requests from low-trust users are strictly verified. When the identity token verification fails, the emergency strategy is called for adjustment to ensure the flexibility and security of the system. For intermediate blacklist users, detection is performed through the second detection path and the security audit layer to ensure that access requests from high-risk users are most strictly verified. When the detection or identity token verification fails, it is directly identified as a malicious attack user and access is denied to ensure the security of the system. For users who launch malicious attacks, the corresponding access requests are directly rejected to ensure that the system is not affected by malicious attacks. In addition, the system makes dynamic adjustments through the emergency strategy layer when the detection fails, ensuring the flexibility and robustness of the system. The data security layer encrypts and transmits the corresponding access data of access users who have passed the verification and have high sensitivity scores, ensuring the security and privacy of the data. The underlying access data sub-node is used to store access data in cloud services, ensuring the integrity and traceability of the data. In summary, the multi-layer protection unit effectively improves the overall security of the system and user trust and reduces security risks through multi-level and multi-dimensional security verification and dynamic adjustment mechanisms. And through the construction and application of knowledge graphs, it realizes intelligent analysis and processing of user requests, ensuring the efficiency and security of the system.
[0108] The access token unit is used to generate a dynamic access token for data access based on user requests that have been screened by whitelist users and multi-layer protection units;
[0109] The access authorization unit is used to verify the dynamic access token corresponding to the access request and authorize the access request after the verification, otherwise the access is denied;
[0110] The access control module is used to regulate the user's access rights, access paths and protection strategies for cloud service resources; the access control module includes an access path selection unit and a strategy regulation unit;
[0111] The access path selection unit is used to select an access path and control access authorization according to the classification result of the classification detection unit;
[0112] The policy control unit is used to call the security protection policy to the corresponding protection layer for security protection through a matching algorithm according to the abnormal access result obtained by the multi-layer protection unit;
[0113] The interaction module is used for user registration and login and provides an interaction interface between the user and the system for parameter configuration and access request.
[0114] Example 2
[0115] See also Figure 3 Another embodiment provided by the present invention is a workflow of a corresponding unit of a cloud service integrated security management system based on a multi-layer protection architecture, including:
[0116] First, the user inputs the access login and access requirements through the interactive module, and the identity is authenticated through the multi-factor identity authentication unit according to the login identity information. After the identity is authenticated, the user is classified through the classification detection unit, the user type is obtained, and the access identity security level is marked;
[0117] Second, the access user type, access identity security level and access requirements are input into the access path selection unit to select an access detection path. When the access user type is a whitelist user, the access requirement is directly input into the access token unit to construct a first identity access token, and the first identity access token is input into the access authorization unit for verification. When the verification passes, access authorization is performed. When the access user type is a first-time access user, the first detection path built into the cross-protection knowledge graph in the multi-layer protection unit is selected by the access path selection unit, and access anomaly detection is performed on the input access requirement. When the access anomaly detection passes, the access requirement is input into the access token unit to construct a second identity access token, and the second identity access token is input into the access authorization unit for verification. When the verification passes, access authorization is performed. When the access anomaly detection fails, the detected access anomaly is fed back to the policy control unit, the corresponding security protection policy is called, and the access anomaly adjustment is performed. When the access anomaly detection passes after adjustment, the corresponding access requirement is input into the access token unit, a third identity access token is constructed, and access risk marking and access authorization are verified.
[0118] If the access anomaly detection fails after adjustment or the access is malicious, the corresponding access request will be directly rejected, and the corresponding first-time access user will be fed back to the classification detection unit and added to the access blacklist;
[0119] Third, when the access user type is a blacklist user, the access demand is evaluated through the configured access demand evaluation model to obtain the access information sensitivity score. When the access information sensitivity score is less than or equal to the sensitivity score threshold, the second detection path built into the cross-protection knowledge graph in the multi-layer protection unit is selected through the access path selection unit. When all the detection nodes in the second detection path are passed, the corresponding user access demand is input into the access token unit and the access authorization unit to construct and verify the fourth identity access token and perform access authorization. When any node in the second detection path fails to pass the detection, the corresponding access demand is directly rejected through the policy control unit;
[0120] Furthermore, the access demand evaluation model in this embodiment is constructed by an evaluation algorithm and is used to obtain the access information sensitivity score of the corresponding user according to the user's access demand information;
[0121] Fourth, when the access information sensitivity score is greater than the sensitivity score threshold, the access request is directly rejected and access feedback is provided through the interactive module.
[0122] The embodiments of the present invention are described above in conjunction with the accompanying drawings, but the present invention is not limited to the above-mentioned specific implementation modes, which are merely illustrative rather than restrictive. Under the guidance of the present invention, ordinary technicians in the field may also change, modify, replace and modify the above-mentioned embodiments without departing from the scope of protection of the purpose of the present invention and the claims, and all of these are within the protection of the present invention.
[0123] If the disclosed technical solution involves personal information, the product using the disclosed technical solution has clearly informed the personal information processing rules and obtained the individual's voluntary consent before processing the personal information. If the disclosed technical solution involves sensitive personal information, the product using the disclosed technical solution has obtained the individual's separate consent before processing the sensitive personal information, and at the same time meets the "explicit consent" requirement. For example, on personal information collection devices such as cameras, clear and prominent signs are set to inform that the personal information collection scope has been entered and personal information will be collected. If the individual voluntarily enters the collection scope, it is deemed that he or she agrees to the collection of his or her personal information; or on the device that processes personal information, when the personal information processing rules are notified by obvious signs / information, the individual's authorization is obtained through pop-up information or by asking the individual to upload his or her personal information; among them, the personal information processing rules may include information such as the personal information processor, the purpose of personal information processing, the processing method, and the type of personal information processed.
Claims
1. A cloud service integrated security management system based on a multi-layer protection architecture, characterized by: include: Multi-layer protection module, access control module and interaction module; The multi-layer protection module includes a multi-factor identity authentication unit, a classification detection unit, a multi-layer protection unit and an access token unit; the identity information registration and login and access requirement input are performed through the interaction module, and the identity authentication is performed through the multi-factor identity authentication unit according to the logged-in identity information. When the identity authentication is passed, the access user type is obtained through the classification detection unit and the access identity security level is marked; the access control module includes an access path selection unit and a policy control unit; The access user type, access identity security level and access requirement are input into the access path selection unit, and the access detection path selection is performed through the cross-protection knowledge graph configured by the multi-layer protection unit. When the access user type is a whitelist user, the access requirement is directly input into the access token unit to construct a first identity access token; when the access user type is a first-time access user, the first detection path built into the cross-protection knowledge graph in the multi-layer protection unit is selected by the access path selection unit to perform access anomaly detection. When the access anomaly detection passes, the access requirement is input into the access token unit to construct a second identity access token. When the access anomaly detection fails, the corresponding security protection policy is called through the policy control unit to adjust the access anomaly. When the access anomaly detection passes after adjustment, a third identity access token is constructed. When the access anomaly detection fails or it is a malicious access, the corresponding access requirement is directly rejected.
2. The cloud service integrated security management system based on a multi-layer protection architecture as claimed in claim 1, characterized in that: The multi-layer protection module also includes an access authorization unit; When the access user type is a blacklist user, the access demand is evaluated and judged through the configured access demand evaluation model. When the judgment is passed, the second detection path built into the cross-protection knowledge graph in the multi-layer protection unit is selected through the access path selection unit. When all the detection nodes in the second detection path are passed, the fourth identity access token is constructed through the access token unit. When any node in the second detection path fails to pass the detection or the evaluation judgment, the corresponding access demand is directly rejected through the policy control unit, and access feedback is performed through the interactive module; The generated first identity access token, second identity access token, third identity access token, and fourth identity access token are input into the access authorization unit for verification. When the verification passes, the corresponding access requirement is authorized, otherwise the access is denied.
3. The cloud service integrated security management system based on a multi-layer protection architecture as claimed in claim 2, characterized in that: The steps of obtaining the access user type and marking the access identity security level include: A1. Obtain historical user login and multi-identity authentication information, access demand information, access frequency, the number of abnormal access and malicious attack access, the length of a single access, and the abnormal access frequency information of the access device, and pre-process the acquired data; A2. Input the pre-processed user identity and access data into the comprehensive fuzzy evaluation model to obtain the corresponding user security access evaluation score , represents the k-th user identity security access evaluation score; A3. Set the score threshold for the third-level security access assessment and ,when When , the corresponding user is assumed to be a whitelist user, and the identity security level is the first security level. When , the corresponding user is assumed to be a primary blacklist user, and the identity security level is the second security level; when When , the corresponding user is assumed to be a medium-level blacklist user, and the identity security level is the third security level. , the corresponding user is assumed to be a malicious attack user, and the identity security level is the fourth security level.
4. The cloud service integrated security management system based on a multi-layer protection architecture as claimed in claim 3, characterized in that: The step of obtaining the access user type and marking the access identity security level also includes: A4. Input the obtained pre-processed user identity, access data, and corresponding security access assessment score and identity security level into the entity extraction model for keyword extraction to obtain the [user identity, access information, identity security level] triple information; A5. Input the triplet information into the graph database, obtain the historical access user identity security level database, and configure the historical access user identity security level database and the comprehensive fuzzy evaluation model to the login verification interface; A6. Obtain the identity information of the registered login user and the historical access information of the corresponding access device in real time, and use the comprehensive fuzzy evaluation model configured in the login verification interface to evaluate and obtain the security access evaluation score of the real-time access user; A7. According to the identity information of the real-time access user and the corresponding security access assessment score, the access user type of the corresponding access user is obtained and the identity type is marked through the matching model and the configured historical access user identity security level database. If the corresponding historical access user cannot be matched, it is a first-time access user; A8. For first-time users, the access consent form is configured to obtain the historical access information and abnormal access mark information of the device used by the first-time user.
5. The cloud service integrated security management system based on a multi-layer protection architecture as claimed in claim 4, characterized in that: The cross-protection knowledge graph configured by the multi-layer protection unit includes a first-level verification node, a second-level control node, a third-level protection detection node, a fourth-level security encryption node, and a fifth-level access data storage node; The first-level verification node includes an identity authentication sub-node and a verification classification sub-node; the second-level control node includes an access control sub-node; The three-level protection detection node includes a protection detection sub-node, a protection strategy sub-node and a verification and authorization sub-node; the protection detection sub-node includes a boundary protection layer, an application security layer, an intrusion detection layer, and a terminal security layer, and the boundary protection layer, the application security layer, the intrusion detection layer, and the terminal security layer all have built-in security detection score thresholds; the protection strategy sub-node includes an emergency strategy layer and a security audit layer; the verification and authorization sub-node includes an access token verification layer and an access authorization layer; The four-level security encryption node includes a data security layer subnode; The five-level access data storage node includes a bottom-level access data sub-node.
6. The cloud service integrated security management system based on a multi-layer protection architecture as claimed in claim 5, characterized in that: The connection relationship between the nodes in the cross-protection knowledge graph is: The identity authentication subnode in the first-level verification node is connected to the verification classification subnode, the verification classification subnode is connected to the second-level control node, the second-level control node has a first detection path and a second detection path built in, the second-level control node is connected to the protection detection subnode in the third-level protection detection node, and is directly connected to the protection strategy subnode; The emergency strategy layer in the protection strategy subnode in the three-level protection detection node and the boundary protection layer, application security layer, intrusion detection layer, and terminal security layer in the protection detection subnode are all connected, and the security audit layer and the boundary protection layer, application security layer, intrusion detection layer, and terminal security layer in the protection detection subnode are also connected; The protection detection subnode in the third-level protection detection node is connected to the access token verification layer in the verification and authorization subnode; the access token verification layer is connected to the access authorization layer; the access authorization layer is connected to the fourth-level security encryption node; The fourth-level security encryption node is connected to the fifth-level access data storage node and the second-level control node.
7. The cloud service integrated security management system based on a multi-layer protection architecture as claimed in claim 6, characterized in that: The first detection path includes any three of the parallel boundary protection layer, application security layer, intrusion detection layer, terminal security layer and emergency strategy layer; the second detection path includes the serially connected boundary protection layer, application security layer, intrusion detection layer, terminal security layer and emergency strategy layer, and security audit layer; The workflow steps of the cross-protection knowledge graph include: B1. Acquire real-time access user identity information and access requirement information, perform identity authentication and corresponding identity type classification through the identity authentication sub-node and the verification classification sub-node, and obtain the corresponding access user type and corresponding historical access data information; B2. When the corresponding access user type is a whitelist user, the kth user access information sensitivity score is obtained through the evaluation algorithm according to the corresponding user's access requirement information. ; B3. Set the sensitivity score threshold ,when Less than or equal to When the user identity basic information, access requirement information and configuration access validity period information are directly input into the access token verification layer through the control of the access control sub-node to construct and verify the access identity token. When the verification is passed, the access authorization layer is used to perform access authorization, and the underlying access data sub-node is accessed and interacted with through the authorization information and the verified access identity token. B4. When the verification fails, the access process is adjusted by calling the emergency policy corresponding to the emergency policy layer through the access control sub-node. If the verification passes after adjustment, the B3 process is repeated for access interaction. If the verification fails after adjustment, the corresponding user is marked as access abnormal, and the corresponding user is removed from the whitelist users. The identity security level of the corresponding access user at the current moment is reconfirmed through the A1 to A3 processes, and added to the corresponding identity security level node.
8. The cloud service integrated security management system based on a multi-layer protection architecture as claimed in claim 7, characterized in that: The workflow steps of the cross-protection knowledge graph also include: B5. When Greater than , the access control subnode calls the first detection path to detect the input user identity basic information and access requirement information. When the detection in the first detection path is passed, the corresponding user identity basic information, access requirement information and configured access validity period information are input into the access token verification layer, and the B3 and B4 processes are repeated to reconfirm the access interaction and identity security level; B6. If the detection of the first detection path fails, the emergency strategy in the emergency strategy layer is called through the access control subnode to adjust the layer that failed the detection. If the detection in the first detection path passes after adjustment, the B5 process is repeated to reconfirm the access interaction and identity security level. If the detection in the first detection path fails after adjustment, the access request at the current moment is directly rejected, and the corresponding user identity security level is reconfirmed. B7. When the corresponding access user type is a primary blacklist user and Less than or equal to When the access control sub-node calls the first detection path to detect the input user identity basic information and access requirement information, when the detection in the first detection path is passed, the corresponding user identity basic information, access requirement information and configuration access valid time period information are input into the access token verification layer to construct and verify the identity token, and when the verification passes, the B3 process is repeated to perform access interaction.
9. The cloud service integrated security management system based on a multi-layer protection architecture as claimed in claim 8, characterized in that: The workflow steps of the cross-protection knowledge graph also include: B8. If the identity token fails to be verified, repeat B4 to adjust the identity token. If the verification passes after adjustment, repeat B7 to perform access interaction. B9. If the verification fails after adjustment, the primary blacklist user will be marked, and the current access user identity security level will be evaluated and confirmed. The corresponding path will be re-called for access interaction according to the current access user identity security level; B10. When the detection in the first detection path fails, the emergency strategy in the emergency strategy layer is called through the access control subnode to adjust the layer that failed the detection. When it passes after adjustment, the B7-B9 process is repeated to perform access interaction or new identity security level confirmation and new access detection path selection; B11. If the adjustment fails, the current access request will be rejected directly, and a new identity security level confirmation and a new access detection path selection will be performed.
10. The cloud service integrated security management system based on a multi-layer protection architecture as claimed in claim 9, characterized in that: The workflow steps of the cross-protection knowledge graph also include: B12. When the corresponding access user type is a primary blacklist user and Greater than When the first detection path passes but the identity token verification fails, the emergency policy in the emergency policy layer is called through the access control subnode to adjust the identity token. If the verification passes, the B8 process is repeated for access interaction. If it fails, the current user's access request is directly rejected, and a new identity security level confirmation and a new access detection path selection are performed; B13. When the corresponding access user type is an intermediate blacklist user, the second detection path and the security protection library built in the security audit layer are called through the access control subnode to detect the input user identity basic information and access requirement information. When the detection passes and the identity token verification passes, authorized interactive access is performed, and the accessed data information is encrypted and transmitted through the data security layer subnode; B14. When one of the second detection path detection or identity token verification fails, the corresponding user is identified as a malicious attack user and access is directly denied, and the user is added to the historical access user identity security level database; B15. When the corresponding access user type is a malicious attack user, directly reject the corresponding access request; B16. When the corresponding access user type is a first-time access user, and The size of Less than or equal to When the whitelist user access interaction process is repeated, Greater than When , the primary blacklist user access interaction process is repeated; B17, B1-B16 process verification passed and Greater than The data accessed by the accessing user is encrypted and interacted with through the data security layer sub-node.
Citation Information
Patent Citations
Cloud server security protection method and system
CN113206818A
Cloud service security protection method
CN115622790A
Network abnormal user detection method, device and equipment based on knowledge graph
CN111949803A
Security protection method and device, electronic equipment and storage medium
CN117134926A