A method for building a secure service chain based on data tags

By adopting a data tag-based security service chain construction method in cross-network and cross-domain data exchange, binding user data, tag attributes and security service chains is solved, and the need for security inspection and security control is difficult to meet the needs of security inspection and security control in the existing technology is realized, dynamic expansion of security protection capabilities and accurate data exchange are achieved, and security and credibility are improved.

CN119814280BActive Publication Date: 2025-05-23NO 30 INST OF CHINA ELECTRONIC TECH GRP CORP
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510294967.3
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-03-13
Publication Date
2025-05-23
Estimated Expiration
2045-03-13

AI Technical Summary

Technical Problem

The prior art is difficult to meet the needs of security inspection and security control in cross-network and cross-domain data exchange, cannot dynamically expand security protection capabilities, and cannot accurately control data flow and exchange.

Method used

The security service chain construction method based on data tags is adopted to bind the three parts of user data, tag attributes and security service chain, define the security detection process through an extensible service chain, and add trustworthy measurement and signature protection mechanisms in the registration, call and judgment of security detection services.

Benefits of technology

It has achieved dynamic expansion of security protection capabilities, accurate data exchange and security problems solved in the entire process of service, improved the credibility and security of security services, and met the requirements of adaptability, efficiency, strong control and security of cross-network exchange security processing.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119814280B_ABST
    Figure CN119814280B_ABST
Patent Text Reader

Abstract

The present invention discloses a method for constructing a security service chain based on data tags, and relates to the field of network security technology. The method for constructing a security service chain based on data tags of the present invention establishes an integrated binding data tag with data as the center, takes the tag data attribute as the matching factor, defines the security detection process with an extensible service chain, and adds a trusted measurement and signature protection mechanism in the registration, calling, and judgment process of the security detection service, thereby improving the credibility and security of the security service, realizing the dynamic expansion of security protection capabilities, accurate data exchange, and security issues of the full-process execution of services.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a method for constructing a security service chain based on data tags. Background Art

[0002] The statements in this section merely provide background information related to the present disclosure and may not constitute prior art.

[0003] At present, cross-network and cross-domain data exchange involves the use of different network systems and different business systems. With the continuous development of various information systems, the types of data exchanged across domains are diverse. According to the business type, it is mainly divided into files, formatted data, video, audio, database and other types. At the same time, network attack technology is constantly developing, and the security threats faced are also increasing. This has led to the fact that fixed-capability security inspection methods can no longer meet the security protection needs of cross-network and cross-domain data exchange. It is necessary to be able to adjust the security protection function in a timely manner according to the security threats faced, increase security protection measures, and ensure the safe operation of cross-network and cross-domain data exchange.

[0004] Cross-network and cross-domain data security processing mainly includes two aspects: security inspection and security control. Security inspection uses various detection technologies to ensure that data protocols and content are legal and compliant, such as virus detection, content inspection, and protocol filtering. Security control is to control data flow and exchange based on data-centric exchange strategies. However, if a one-size-fits-all or customized security inspection and exchange control method is adopted, it will not be able to meet the diverse cross-domain exchange applications of different network systems and different business data.

[0005] Currently, dynamic expansion of security capabilities can be achieved through NFV and service chain construction; for data exchange control, attribute-based data flow and exchange control can be performed based on data tags. However, both technologies are used in different scenarios or different products. For cross-network and cross-domain security processing needs, there is no unified integrated solution that can solve both security checks and security controls. Summary of the invention

[0006] The purpose of the present invention is to provide a method for building a security service chain based on data tags to meet the requirements of cross-network and cross-domain security inspection and security control, and to meet the requirements of adaptability, efficiency, strong control and security of cross-network exchange security processing, so as to solve the following problems:

[0007] 1) In response to the different security protection requirements of diversified data and the evolving security attack threats, the security protection capability has the ability to dynamically expand;

[0008] 2) In the face of security issues of different network systems, the security services provided by the system need to be enhanced to prevent problems such as fake service calls, tampering of the call process, and fake execution results;

[0009] 3) Cross-network information networks involve different network systems and different businesses. In addition to ensuring the compliance of data content, it is also necessary to accurately control various attributes such as data source, scope of knowledge, time control, etc. to achieve accurate flow and exchange during data exchange.

[0010] In response to the above problems, the present invention proposes a data tag-based security service chain construction method that establishes an integrated bound data tag with data as the center, uses tag data attributes as matching factors, defines the security detection process with an extensible service chain, and adds trusted metrics and signature protection mechanisms during the registration, call, and judgment of security detection services, thereby improving the credibility and security of security services, achieving dynamic expansion of security protection capabilities, and solving security issues in the accurate exchange of data and the entire service process.

[0011] The technical solution of the present invention is as follows:

[0012] A method for constructing a security service chain based on data tags, comprising:

[0013] Generate an integrated binding data tag corresponding to the original data content to be transmitted according to the integrated binding data tag format; the integrated binding data tag format includes: user data, tag attributes and security service chain; the user data is the original data content to be transmitted; the tag attributes include data version number, application category, security level, sending / receiving unit, timestamp, extensible field and tag summary; the security service chain is based on security policy configuration, including security service sequence, security service execution time, security service signature information, security service key information measurement value and execution sequence rule;

[0014] Call the security service chain and execute each security service according to the security service sequence. During the execution process, compare the key information measurement values ​​of the security service to ensure the reliability of the security service. Write the execution results of each security service into the security service chain and perform signature protection.

[0015] Two-level exchange control verification is performed based on tag attributes. If the two-level verification passes and the security service chain execution result is compliant, data flow is allowed, otherwise it is blocked and an alarm is issued.

[0016] Furthermore, the extensible field supports custom extension according to business requirements and is used to store additional control attributes.

[0017] Furthermore, the security service includes: virus scanning, content filtering, and signature verification.

[0018] Furthermore, the security service key information measurement value is a key information hash value of the security service, including a service version number, configuration parameters and a signature public key.

[0019] Furthermore, the construction of the security service chain includes:

[0020] Establish a security service resource pool and a third-party service resource pool, and register security services through the service bus;

[0021] Orchestrate security service chains based on data types and security policies.

[0022] Furthermore, the calling security service chain includes:

[0023] Verify the integrity and signature authenticity of the security service chain based on registered security services and orchestrated security service chains;

[0024] Call the registered security services according to the security service sequence, and compare the key information measurement values ​​of the security services during the security service execution to ensure the service is trustworthy;

[0025] The execution results of each security service are written into the security service chain and signed for protection.

[0026] Furthermore, the two-stage switching control verification includes:

[0027] First level verification: verify the integrity of data payload and tag content through hashing algorithm;

[0028] Second level verification: Verify the legitimacy of data source, data attributes, and data destination based on exchange control policies and data exchange permissions.

[0029] Furthermore, the construction of the security service resource pool and the third-party service resource pool includes:

[0030] Based on the security function extension mechanism of the security service chain, the service-oriented concept is adopted to service various heterogeneous security functions and establish a security service resource pool;

[0031] By integrating third-party security services through functional extension, a third-party service resource pool is established; the third-party service resource pool can be dynamically expanded.

[0032] Furthermore, the final judgment is made based on the security service execution results, signature verification and integrity check results; non-compliant data is discarded or blocked, and the judgment log is recorded.

[0033] Furthermore, the construction of the security service chain supports multi-domain collaboration, identifies data sources and destinations through tag attributes, and achieves precise control of cross-network and cross-domain data exchange.

[0034] Compared with the prior art, the present invention has the following beneficial effects:

[0035] At present, the existing technology can realize dynamic security expansion based on the service chain or classify and carry out related security processing based on data tags, but they are all applied in different scenarios or different products, and there is no unified integrated solution. The present invention innovatively proposes an integrated binding data tag to bind the three major parts of user data, tag attributes and security service chain, effectively combining the security check and exchange control elements: fine-grained data exchange control can be performed based on tag attributes, and dynamic expansion of security capabilities can be achieved based on the security service chain. The integrated binding data tag allows security checks and security controls to be executed concurrently, greatly improving processing efficiency. At the same time, combined with cryptographic technology, the tags, service registrations, calls, and results are signed and integrity protected to prevent important judgment information from being tampered with, greatly improving the security of the security service itself, and meeting the requirements of adaptability, efficiency, strong control and security of cross-network exchange security processing. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] Figure 1 It is a schematic diagram of the fusion of security inspection and exchange control;

[0037] Figure 2 This is a schematic diagram of integrated binding data tags;

[0038] Figure 3 A schematic diagram of the security enhancement design for the security service chain. DETAILED DESCRIPTION

[0039] It should be noted that relational terms such as "first" and "second" are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.

[0040] The features and performance of the present invention are further described in detail below in conjunction with the embodiments.

[0041] Embodiment 1

[0042] First of all, it should be noted that cross-network and cross-domain data security processing mainly includes two aspects: security checking and security control. The present invention innovatively integrates the two functions based on an integrated binding data tag. The security check is based on the security service chain in the tag for dynamic expansion and security detection, and the security control is based on the attributes in the tag for precise matching control.

[0043] For details, please refer to Figure 1 , a method for constructing a security service chain based on data tags, specifically comprising the following steps:

[0044] Generate an integrated binding data tag corresponding to the original data content to be transmitted according to the integrated binding data tag format; the integrated binding data tag format includes: user data, tag attributes and security service chain; the user data is the original data content to be transmitted; the tag attributes include data version number, application category, security level, sending / receiving unit, timestamp, extensible field and tag summary; the security service chain is based on security policy configuration, including security service sequence (security service is detection service), security service execution time, security service signature information, security service key information measurement value and execution sequence rule;

[0045] Call the security service chain and execute each security service according to the security service sequence. During the execution process, compare the key information measurement values ​​of the security service to ensure the reliability of the security service. Write the execution results of each security service into the security service chain and perform signature protection.

[0046] Two-level exchange control verification is performed based on tag attributes. If the two-level verification passes and the security service chain execution result is compliant, data flow is allowed, otherwise it is blocked and an alarm is issued.

[0047] See also Figure 2 ,It should be noted that in this embodiment, in order to organically combine the two functions of ,dynamic expansion of security services and refined exchange control, an ,integrated binding data tag is innovatively designed ,which includes three parts: user data, tag attributes and ,security service chain;

[0048] Among them, user data is the original data content to be transmitted, and security checks are performed on the user data according to the security service sequence in the security service chain;

[0049] The tag attributes mainly include data version number, application category, security level, sending / receiving unit, timestamp, extensible field and tag summary; the security level is the data level in the figure (full name is data security level); the sending / receiving unit includes the sender, sending unit, receiver and receiving unit in the figure; the timestamp includes the sending time and receiving time in the figure; the extension field is reserved and supports custom extension according to business needs, which is used to store additional control attributes; the tag summary is to prevent the tag from being tampered with during the transmission process and improve the security and credibility of the tag;

[0050] The security service chain configures the security policy and writes relevant information such as the security service required for the data, the security service execution time, and the service signature into the integrated binding data security tag.

[0051] In this embodiment, specifically, the security service includes: virus scanning, content filtering, signature verification, etc.

[0052] In this embodiment, specifically, the security service key information measurement value is a key information hash value of the security service, including a service version number, configuration parameters, and a signature public key.

[0053] In this embodiment, specifically, the construction of the security service chain includes:

[0054] Establish a security service resource pool and a third-party service resource pool, and register security services through the service bus;

[0055] Orchestrate security service chains based on data types and security policies.

[0056] In this embodiment, specifically, the calling of the security service chain includes:

[0057] Verify the integrity and signature authenticity of the security service chain based on registered security services and orchestrated security service chains;

[0058] Call the registered security services according to the security service sequence, and compare the key information measurement values ​​of the security services during the security service execution to ensure the service is trustworthy;

[0059] The execution results of each security service are written into the security service chain and signed for protection.

[0060] In this embodiment, specifically, the two-stage switching control verification includes:

[0061] First-level verification: The integrity of the data payload and label content is verified through a hash algorithm. That is, a hash algorithm is used to generate an integrity check value for the data payload and label content. During the data exchange process, each control point verifies the integrity check value to achieve integrity protection.

[0062] Second-level verification: Verify the legitimacy of data sources, data attributes, and data destinations based on exchange control policies and data exchange permissions; that is, in the process of cross-network and cross-domain data exchange, tag attributes (i.e., control attributes) can be used as the core elements for the formulation of exchange control policies and data exchange permission policies. By identifying and extracting tag attributes such as the network domain, sender, recipient, sending unit, receiving unit, level, and scope of knowledge, and comparing and matching them with the exchange control policy and exchange permission policy, data flow control based on data security tags can be achieved.

[0063] In this embodiment, specifically, the construction of the security service resource pool and the third-party service resource pool includes:

[0064] Based on the security function extension mechanism of the security service chain, the service-oriented concept is adopted to service various heterogeneous security functions and establish a security service resource pool;

[0065] By integrating third-party security services through functional extension, a third-party service resource pool is established; the third-party service resource pool can be dynamically expanded; each security service is registered through the service bus before scheduling, and only the successfully registered security services will be scheduled.

[0066] In this embodiment, specifically, a final judgment is made based on the security service execution results, signature verification and integrity check results; discard or block operations are performed on non-compliant data, and a judgment log is recorded.

[0067] In this embodiment, specifically, the construction of the security service chain supports multi-domain collaboration, identifies the source and destination of data through tag attributes, and realizes precise control of cross-network and cross-domain data exchange.

[0068] In this embodiment, it should be noted that the security function extension mechanism based on the security service chain adopts a service-oriented design concept, encapsulates various security functions into services, flexibly and efficiently arranges and schedules corresponding security services for processing according to different data types, and makes exchange legitimacy judgments based on the service execution results.

[0069] The core of service orchestration, service scheduling, and service execution is the security service chain, which is the "process sheet" output by service orchestration, the "baton" of the service call process, and the "physical examination sheet" of the service execution results. The security of the security service chain itself is of vital importance, which is mainly reflected in the following aspects:

[0070] (1) It is necessary to address the risk of the security service chain output by service orchestration being forged or tampered with.

[0071] (2) It is necessary to address the issue of whether the security services executed during the service call process are trustworthy.

[0072] (3) The need to solve the problem of anti-counterfeiting of service execution results.

[0073] Therefore, if Figure 3 As shown, the present invention is based on the security enhancement design of the security service chain. By using cryptographic technology to enhance the security of the entire process of service orchestration, service scheduling and service execution, a security service chain is constructed. It can effectively prevent problems such as service call fraud, call process tampering, and execution result fraud, and can make the execution of various security functions processed in parallel more secure and reliable.

[0074] Embodiment 2

[0075] Embodiment 2 further implements a method for constructing a secure service chain based on data tags proposed in Embodiment 1, and proposes a cross-network and cross-domain data exchange security processing system based on data tags, including: a service orchestration module, a service scheduling module and a security judgment module.

[0076] Among them, the service orchestration module establishes multiple service chains based on various data security processing strategies. Each service chain contains one or more different types of data security processing services and serial or parallel execution sequences. After the service orchestration is completed, the security service chain is output, and the key information measurement values ​​of the security service in the service registration process are recorded together for comparison of the execution process, and the integrity and authenticity of the generated security service chain are protected.

[0077] During the execution of the data exchange task, the service scheduling module identifies the data type and executes the corresponding security service chain. First, it verifies the integrity and authenticity of the security service chain and calls the security service. During the call, the measurement value of the security service is compared to verify the credibility of the security service. After the service call is completed, the security service will write the inspection or processing results back to the security service chain and perform integrity protection, and "stamp" the execution results of this service. The service scheduling module monitors the execution of the security service chain. After all security services are executed, the execution results are uniformly checked and verified to prevent the execution process from being bypassed and the execution results from being forged.

[0078] The security judgment module performs final comparison, analysis and judgment based on the execution results of the security check, signature verification, integrity check, etc., to decide whether the data content has passed the security check and whether it is legal and compliant, discard non-compliant data and block its passage.

[0079] The above-mentioned embodiments only express the specific implementation methods of the present application, and the descriptions thereof are relatively specific and detailed, but they cannot be understood as limiting the protection scope of the present application. It should be pointed out that, for ordinary technicians in this field, several variations and improvements can be made without departing from the technical solution concept of the present application, and these all belong to the protection scope of the present application.

[0080] This background section is provided to generally present the context of the invention, and the work of the presently named inventors, the work to the extent described in this background section, and aspects of this section that did not constitute prior art at the time of application are neither explicitly nor implicitly admitted to be prior art to the present invention.

Claims

1. A method for constructing a secure service chain based on data tags, characterized in that: include: Generate an integrated binding data tag corresponding to the original data content to be transmitted according to the integrated binding data tag format; The integrated binding data tag format includes: user data, tag attributes and security service chain; the user data is the original data content to be transmitted; the tag attributes include data version number, application category, security level, sending / receiving unit, timestamp, extensible field and tag summary; the security service chain is based on security policy configuration, including security service sequence, security service execution time, security service signature information, security service key information measurement value and execution sequence rule; Call the security service chain and execute each security service according to the security service sequence. During the execution process, compare the key information measurement values ​​of the security service to ensure the reliability of the security service. Write the execution results of each security service into the security service chain and perform signature protection. Two-level exchange control verification is performed based on tag attributes. If the two-level verification passes and the security service chain execution result is compliant, data flow is allowed, otherwise it is blocked and an alarm is issued.

2. According to the method for constructing a secure service chain based on data tags according to claim 1, it is characterized in that: The extensible field supports custom extension according to business requirements and is used to store additional control attributes.

3. According to the method for constructing a secure service chain based on data tags in claim 1, it is characterized in that: The security services include: virus scanning, content filtering, and signature verification.

4. According to the method for constructing a secure service chain based on data tags in claim 1, it is characterized in that: The security service key information measurement value is a key information hash value of the security service, including a service version number, configuration parameters, and a signature public key.

5. According to the method for constructing a secure service chain based on data tags in claim 1, it is characterized in that: The construction of the security service chain includes: Establish a security service resource pool and a third-party service resource pool, and register security services through the service bus; Orchestrate security service chains based on data types and security policies.

6. A method for constructing a secure service chain based on data tags according to claim 5, characterized in that: The calling security service chain includes: Verify the integrity and signature authenticity of the security service chain based on registered security services and orchestrated security service chains; Call the registered security services according to the security service sequence, and compare the key information measurement values ​​of the security services during the security service execution to ensure the service is trustworthy; The execution results of each security service are written into the security service chain and signed for protection.

7. The method for constructing a secure service chain based on data tags according to claim 1, characterized in that: The two-stage switching control verification includes: First level verification: verify the integrity of data payload and tag content through hashing algorithm; Second level verification: Verify the legitimacy of data source, data attributes, and data destination based on exchange control policies and data exchange permissions.

8. The method for constructing a secure service chain based on data tags according to claim 5, characterized in that: The construction of the security service resource pool and the third-party service resource pool includes: Based on the security function extension mechanism of the security service chain, the service-oriented concept is adopted to service various heterogeneous security functions and establish a security service resource pool; By integrating third-party security services through functional extension, a third-party service resource pool is established; the third-party service resource pool can be dynamically expanded.

9. The method for constructing a secure service chain based on data tags according to claim 1, characterized in that: Make a final judgment based on the results of security service execution, signature verification, and integrity check; discard or block non-compliant data and record the judgment log.

10. The method for constructing a secure service chain based on data tags according to claim 1, characterized in that: The construction of the security service chain supports multi-domain collaboration, identifies the source and destination of data through label attributes, and realizes precise control of cross-network and cross-domain data exchange.

Citation Information

Patent Citations

  • An information security sharing exchange method and system based on a data security label

    CN109635583A

  • Service chain construction method, service access method, related device, equipment and medium

    CN117155599A