An airborne application dynamic access control method and system based on a zero trust mechanism

By adopting a zero-trust mechanism-based dynamic access control method for airborne applications, the problem of traditional access control methods being unable to prevent attacks is solved, and secure access control of airborne systems in dynamic network environments is achieved, thereby improving the system's trustworthiness and reliability.

CN119885230BActive Publication Date: 2026-01-16XIAN AVIATION COMPUTING TECH RES INST OF AVIATION IND CORP OF CHINA
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411957029.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-12-29
Publication Date
2026-01-16
Estimated Expiration
2044-12-29

AI Technical Summary

Technical Problem

Traditional static access control methods based on network boundaries cannot effectively prevent attackers from bypassing boundary protection to attack airborne applications, leading to information leakage or system failure, and cannot meet the access control requirements of modern airborne systems in dynamic network environments.

Method used

A zero-trust mechanism-based dynamic access control method for airborne applications is adopted. The airborne application open domain/avionics domain log management module receives and standardizes audit logs, uses the airborne message middleware module to classify, store and asynchronously consume log messages, dynamically evaluates application trust values ​​in combination with trust value evaluation rules, and implements access control through the open domain network access control unit.

Benefits of technology

It enables dynamic access control for airborne applications in an open domain network environment, preventing attackers from bypassing boundary protection and improving the trustworthiness and reliability of airborne system application access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119885230B_ABST
    Figure CN119885230B_ABST
Patent Text Reader

Abstract

The application provides an airborne application dynamic access control method based on a zero trust mechanism, relates to the technical field of airborne embedded systems, and establishes a zero trust security authentication framework around the identity information of avionics domain / open domain applications. Based on the minimum authority principle and the dynamic authorization principle, according to the possible changes in the attribute characteristics of devices or applications in physical positions, authentication results, access results, access times, application versions, communication data chains and access frequencies, a closed-loop scheme of identity authentication, dynamic authority granting and behavior auditing is designed by using the identity information of open domain and avionics domain communication parties, so that the continuous authentication and dynamic access control of other aircraft or devices and other entities in the open domain are realized. The method prevents attackers from bypassing the boundary protection to directly attack the airborne application through various means in the environment of the open network boundary, resulting in serious information leakage or system failure. The method improves the credibility and reliability of the access of the airborne system application.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of airborne embedded systems, and particularly provides an airborne application dynamic access control method and system based on a zero-trust mechanism. BACKGROUND

[0002] With the rapid development of information technology, the safety and reliability requirements of airborne systems are increasingly improved. The traditional static access control mode based on network boundaries has been unable to meet the access control requirements of modern airborne systems in dynamic network environments, because network boundaries are becoming increasingly blurred, and attackers in open domains can bypass boundary protection through various means to directly attack airborne applications or systems, which may cause serious information leakage or system failure.

[0003] Therefore, a more advanced and flexible access control mechanism is needed to protect the safety of airborne systems. SUMMARY

[0004] The present application aims to solve the above technical problems, and provides an airborne application dynamic access control method and system based on a zero-trust mechanism, which realizes dynamic access control of airborne application access in an open domain network environment, can prevent attackers from bypassing boundary protection through various means to directly attack airborne applications in an open network boundary environment, and can prevent serious information leakage or system failure. The credibility and reliability of airborne system application access are improved.

[0005] To achieve the above purpose, the present application adopts the following technical solution: an airborne application dynamic access control method based on a zero-trust mechanism, the method comprising:

[0006] S1: configuring corresponding access control strategies in different trust value intervals;

[0007] S2: the airborne application open domain / avionics domain log management module respectively receives the audit logs related to the access entities from the open domain other aircraft and devices, the avionics domain applications and systems, and the open domain network access control module, and respectively standardizes the audit logs;

[0008] S3: the airborne application open domain / avionics domain log management module sends the standardized logs and stores them in the airborne message middleware module according to the message classification;

[0009] S4: asynchronously consuming the classified log messages from the airborne message middleware module, and extracting the key parameters in the log messages;

[0010] S5: dynamically evaluating the trust value of the application according to the key parameters extracted in S4 using the preset trust value evaluation rules or algorithms;

[0011] S6: obtaining the corresponding access policy under the trust value according to the trust value evaluation result obtained in S5 and the access control policy configured in S1;

[0012] S7: sending the corresponding access policy under the trust value obtained in S6 to the open domain network access control unit through the message middleware, and performing access control on the access request according to the access policy by the open domain network access control unit;

[0013] S8: when a new access or a new operation is performed on the application, repeating S2-S7 to complete the continuous dynamic access control of the airborne application.

[0014] The airborne application dynamic access control method based on the zero trust mechanism provided by the application also has the following technical features: the access control policy includes granting of access rights, partial granting of access rights, and denial of access rights; and the access control policy is stored in a structured data format.

[0015] The airborne application dynamic access control method based on the zero trust mechanism provided by the application also has the following technical features: the standardization processing includes pre-processing of log information, cleaning of log information, and unification of data format of log information.

[0016] The airborne application dynamic access control method based on the zero trust mechanism provided by the application also has the following technical features: S7 includes:

[0017] Integrity check on the received policy data;

[0018] Parsing and correctness check on the received policy data;

[0019] Conflict detection and resolution of the parsed policy data;

[0020] Loading and implementing of the policy data.

[0021] Another object of the application is to provide an airborne application dynamic access control system based on a zero trust mechanism, which is used to implement the control method as described in any of the preceding embodiments, and includes:

[0022] The airborne application open domain / avionics domain log management module is used to receive audit logs related to the open domain of other aircraft or equipment and the avionics domain airborne application, and to extract key data, clean useless data, and normalize log format of diversified logs;

[0023] The airborne message middleware module is used to asynchronously receive and process normalized log messages;

[0024] The on-board application trust value evaluation engine module is used for asynchronously consuming the classified audit logs in the message middleware, dynamically evaluating the trust state of the application through a trust value evaluation algorithm in combination with the identity information of the application;

[0025] The on-board application access open domain network access control unit module is used for receiving, verifying, parsing, loading and implementing the access control policy.

[0026] The on-board application policy management module is used for receiving a policy configuration request, parsing, verifying and storing the access control policy, and is responsible for matching the application trust value and the corresponding access control policy.

[0027] The on-board application unified identity management module is used for receiving, standardizing and structuring the application identity information, and supporting the trust value evaluation of the application.

[0028] The on-board application dynamic access control system based on the zero trust mechanism also has the technical features that the key data of the diversified logs includes the on-board application name, the application version, the access time and the aircraft communication data link.

[0029] The on-board application dynamic access control system based on the zero trust mechanism also has the technical features that the on-board application access open domain network access control module includes receiving the latest application access control policy information sent by the on-board application trust value evaluation engine from the on-board message middleware module, and performing integrity verification, parsing, conflict detection and processing, loading and implementation on the policy information.

[0030] The on-board application dynamic access control system based on the zero trust mechanism also has the technical features that the on-board application policy management module includes receiving a policy configuration request sent by the ground crew through a ground configuration management tool, and the policy configuration request contains the access control policies of the application corresponding to different trust values.

[0031] The on-board application dynamic access control system based on the zero trust mechanism also has the technical features that the on-board application policy management module is also used for updating the access policy and notifying the on-board application trust value evaluation engine module of the update message of the access policy.

[0032] Advantages

[0033] The on-board application dynamic access control method and system based on the zero trust mechanism realize the dynamic access control of the on-board application access in the open domain network environment, can prevent attackers from bypassing the boundary protection to directly attack the on-board application through various means in the environment of the open network boundary, and can prevent serious information leakage or system failure. The trustworthiness and reliability of the on-board system application access are improved. Attached Figure Description

[0034] To more clearly illustrate the technical solutions of the embodiments of this disclosure, the drawings used in the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this disclosure. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0035] Fig. 1 This is the airborne application dynamic access control system architecture based on a zero-trust mechanism provided in the embodiments of the present invention;

[0036] Fig. 2 This is a component of the airborne application dynamic access control system based on a zero-trust mechanism provided in the embodiments of the present invention;

[0037] Fig. 3 This is a timing diagram of the airborne application dynamic access control method based on zero trust mechanism provided in an embodiment of the present invention. Detailed Implementation

[0038] The present application will be further described in detail below with reference to the accompanying drawings and embodiments. However, it should be noted that these embodiments are not intended to limit the present application. Equivalent transformations or substitutions in function, method, or structure made by those skilled in the art based on these embodiments are all within the protection scope of the present application.

[0039] In the description of the embodiments of this application, it should be understood that the terms "center", "longitudinal", "lateral", "up", "down", "front", "rear", "left", "right", "vertical", "horizontal", "top", "bottom", "inner", "outer", etc., indicate the orientation or positional relationship based on the orientation or positional relationship shown in the drawings. They are only for the convenience of describing the creation of this application and simplifying the description, and do not indicate or imply that the device or element referred to must have a specific orientation, or be constructed and operated in a specific orientation. Therefore, they should not be construed as limitations on the creation of this application.

[0040] Furthermore, the terms "first," "second," "third," etc., are used for descriptive purposes only and should not be construed as indicating or implying relative importance or implicitly specifying the number of technical features indicated. Therefore, a feature defined with "first," "second," etc., may explicitly or implicitly include one or more of that feature. In the description of this application, unless otherwise stated, "a plurality of" means two or more.

[0041] The terms "mounting", "connection", "connecting" should be understood broadly, for example, it can be fixed connection, or detachable connection, or integral connection; it can be mechanical connection, or electrical connection; it can be direct connection, or indirect connection through intermediate medium, or internal communication of two elements. The specific meaning of the above terms in the application can be understood according to the specific circumstances by those skilled in the art.

[0042] As shown in Figs. 1-3 A method for dynamic access control of onboard application based on zero trust mechanism is provided, and the method comprises the following steps:

[0043] S1: The ground personnel configures the corresponding access control policy under different trust value intervals for each open domain / avionics domain specific application through the configuration tool or command line interface of the onboard policy management module;

[0044] S2: The onboard application open domain / avionics domain log management module respectively receives the audit logs related to the access entity from the open domain other aircraft and equipment, the avionics domain application and system, and the open domain network access control module, and respectively standardizes the audit logs;

[0045] S3: The onboard application open domain / avionics domain log management module sends the standardized logs to the onboard message middleware module and stores them in the module according to the message classification, the message middleware provides high availability and load balancing, and the ability to prevent Dos attacks, to ensure reliable transmission and storage of the logs;

[0046] S4: Asynchronous consumption of the classified log messages from the onboard message middleware module, and extraction of the key parameters in the log messages;

[0047] S5: Dynamic evaluation of the trust value of the application according to the key parameters extracted in S4 using the preset trust value evaluation rules or algorithms;

[0048] S6: Obtain the corresponding access policy under the trust value according to the trust value evaluation result obtained in S5 and the access control policy configured in S1, the policy management module queries the database according to the received trust value and returns the specific access entity access control policy under the trust value to the onboard application trust value evaluation engine, the policy may include the grant, rejection, etc. of access permission;

[0049] S7: Send the corresponding access policy under the trust value obtained in S6 to the open domain network access control unit through the message middleware, and the open domain network access control unit controls the access request according to the access policy;

[0050] S8: When the application is accessed or operated, repeat S2-S7 to complete the continuous dynamic access control of the onboard application.

[0051] In some embodiments, the S1 comprises:

[0052] The ground crew configures the access control policy for each specific application in the airborne system within the preset different trust value intervals through the configuration tool or command window of the airborne strategy management module, and the access control policy includes but is not limited to the granting, partial granting or rejection of access rights, etc. Then the access control policy information configured by the ground crew is stored in a structured data format, so that other system components (such as the airborne application trust value evaluation engine, the open domain network access control unit, etc.) can query and call as needed to realize dynamic access control based on trust value.

[0053] In some embodiments, the S2 comprises:

[0054] The open domain / avionics domain log management module receives audit logs about access entities from different system components through the network interface; the access entities include but are not limited to access subjects, access objects, open domain network access control units, and airborne application trust value evaluation engines, etc. Then the open domain / avionics domain log management module performs preprocessing operations on the received access logs to eliminate redundant information in the logs and ensure the uniqueness and validity of the log data; the preprocessing operations include but are not limited to deduplication processing, timestamp correction, and missing field completion, thereby ensuring the integrity and accuracy of the log data. In addition, it also has a log data cleaning function, which can remove invalid logs in the logs to improve the quality of the log data. Finally, the open domain / avionics domain log management module has a log data format conversion function in the standardization processing stage, which can convert log data in different formats into a unified log format, and the unified log format includes but is not limited to log level, access subject identification, access object, communication data chain, access time, authentication result, access result, etc. Key information fields, so that the subsequent airborne application trust value evaluation engine can use the log data to evaluate the trust value.

[0055] In some embodiments, the S3 comprises:

[0056] The open domain / avionics domain log management module stores the standardized log data into the message middleware, and the message middleware has high availability and load balancing functions to ensure the reliability and stability of the log data in the transmission and storage process. Secondly, the message middleware allows the airborne application trust value evaluation engine and other system modules to consume the log data stored in the message middleware in an asynchronous manner. Finally, the message middleware also has a persistent storage function of log data, which can continue to provide access services for log data after system restart or fault recovery.

[0057] In some embodiments, the S4 comprises:

[0058] The airborne application trust value evaluation engine asynchronously acquires the standardized log data from the message middleware and extracts key parameters therefrom; the key parameters include, but are not limited to, log level, access subject identifier, access object, communication data chain, access time, authentication result, access result, etc. Then, the airborne application trust value evaluation engine analyzes and processes the key parameters extracted from the log data by using preset trust value evaluation rules or algorithms to dynamically evaluate the trust value of the application; finally, the airborne application trust value evaluation engine represents the evaluation result in the form of a numerical value or a level, which serves as the basis for selecting a subsequent access control strategy; the evaluation result can be updated in real time or periodically to reflect the dynamic changes in the application trust value.

[0059] In some embodiments, the access control strategy includes granting of access rights, partial granting of access rights, and denial of access rights; the access control strategy is stored in a structured data format.

[0060] In some embodiments, the policy management module supports the updating capability of the policy. When the access control strategy is changed, including adding, deleting, or modifying the policy, the policy management module automatically notifies the airborne application trust value evaluation engine to update the policy, so as to ensure that the access control strategy used by the airborne application trust value evaluation engine is the latest one.

[0061] In some embodiments, the standardization processing includes pre-processing of log information, cleaning of log information, and unification of data formats of log information.

[0062] In some embodiments, the S7 includes:

[0063] Performing integrity check on the received policy data;

[0064] Performing parsing and correctness check on the received policy data;

[0065] Detecting and resolving conflicts of the parsed policy data;

[0066] Loading and implementing the policy data.

[0067] In the above embodiments, the open domain network access control unit has a data check function when receiving the policy data, which can perform integrity check on the received access control policy data to ensure the integrity of the policy data. Then, the open domain network access control unit also has a policy conflict detection and conflict resolution function when loading the policy to the local execution environment, which can detect and resolve the conflict problems between different policies to ensure the correctness and consistency of policy execution. After verification and conflict resolution, the open domain network access control unit loads the access control policy and implements the access control of the application.

[0068] In some embodiments, a zero-trust mechanism-based dynamic access control system for onboard applications is provided, which is used to implement the control method according to any one of the preceding embodiments, and comprises:

[0069] An onboard application open domain / avionics domain log management module is configured to receive audit logs related to onboard applications in the open domain and the avionics domain from other aircraft or devices in the open domain, and to perform key data extraction, useless data cleaning, and log format normalization processing on the diversified logs.

[0070] An onboard message middleware module is configured to asynchronously receive and process the normalized log messages.

[0071] An onboard application trust value evaluation engine module is configured to asynchronously consume the classified audit logs in the message middleware, dynamically evaluate the trust status of the application by means of a trust value evaluation algorithm, and in combination with the identity information of the application.

[0072] An onboard application access open domain network access control unit module is configured to receive, verify, parse, load, and implement access control policies.

[0073] An onboard application policy management module is configured to receive policy configuration requests, parse, verify, and store access control policies, and is responsible for matching the trust value of the application with the corresponding access control policy.

[0074] An onboard application unified identity management module is configured to receive, standardize, and structure store the identity information of the application, and to support the trust value evaluation of the application.

[0075] In the above embodiments, the main functions of the onboard application open domain / avionics domain log management module include:

[0076] 1) Multi-source log reception. The open domain / avionics domain log management module is mainly responsible for receiving, integrating, cleaning, processing, and storing audit log information from multiple key system modules. These system modules include access subjects (such as open domain devices or applications), access objects (such as onboard applications or resources), onboard application trust value evaluation engines, and open domain network access control units. The logs generated by these modules collectively constitute the data source for trust value evaluation of access entities.

[0077] 2) Standardization of diversified formats. Since the log information and formats of various modules are inconsistent, it is not conducive for the subsequent onboard application trust value evaluation engine to directly utilize the log information to evaluate the trust value of access entities. Therefore, after receiving the audit logs, the onboard application open domain / avionics domain log management module needs to standardize the log information from different sources and in different formats, thereby providing a reliable data basis for subsequent trust evaluation.

[0078] 3) Key data extraction. After receiving and integrating the log information, the open domain / avionics domain log management module uses data processing techniques to remove redundant information and extract key data through data cleaning, standardization, and aggregation operations, providing data support for subsequent trust value evaluation.

[0079] The functions of the airborne message middleware module are described as follows:

[0080] 1) Decoupling of message passing and communication. The message middleware module is a key component in the system architecture, and its design aims to reduce the coupling and complexity of direct communication between modules, and to improve the scalability and flexibility of the system.

[0081] 2) Enhancing business scalability. Each business module communicates with each other by sending or receiving messages to / from the message middleware without the need to establish direct connections or understand the specific implementation details of the other party.

[0082] The specific functions of the airborne application trust value evaluation engine module are described as follows:

[0083] 1) Airborne application log consumption and key parameter extraction. The airborne application trust value evaluation engine module first receives formatted log information from the airborne message middleware. The key parameters contained in these log information are important basis for evaluating the trust status of the application. The airborne application trust value evaluation engine module preprocesses the received log information and extracts the key parameters related to trust evaluation, providing data support for subsequent trust value calculation.

[0084] 2) Trust value evaluation of other aircraft or devices in the open domain. Combined with the application identity information (such as application name, version, data link information, etc.) stored in the database, the airborne application trust value evaluation engine module uses advanced trust value evaluation algorithms to quantitatively evaluate the trust status of the application. This algorithm considers multiple factors, including but not limited to log level, access subject identifier, access object, communication data link, access time, authentication result, access result, etc., to achieve accurate evaluation of the trust status of the application.

[0085] 3) Distribution of evaluation results. After the trust value evaluation is completed, the airborne application trust value evaluation engine module stores the calculated trust value evaluation results in the database. At the same time, it also distributes the trust value and identity information to the airborne policy management module. The airborne policy management module, as a collaborative component of the airborne application trust value evaluation engine, is responsible for matching policy information based on the received trust value and identity information, and returning the access control policy corresponding to the application under the current trust value.

[0086] The specific functions of the open domain network access control module are as follows:

[0087] 1) Receive access control policy. Receive access control policy instructions for open domain devices transmitted by the on-board application trust value evaluation engine.

[0088] 2) Access control policy resolution, conflict resolution, loading and execution. After receiving policy information, the open domain network access control module resolves policies, resolves policy conflicts, updates and applies these policies.

[0089] 3) Continuous monitoring and management of connections. Once the connection is established, the open domain network access control module will monitor the interaction behavior between the open domain device and the on-board device in real time, including data transmission traffic, access frequency, etc. and send the access behavior of the application to the unified open domain / avionics domain log management module in the form of a log to support the continuous trust evaluation of the access entity by the on-board application trust value evaluation engine. Through this mechanism, abnormal activities such as potential attack behavior or improper use of resources can be discovered in time, thereby ensuring the stable operation of the system. The module also has the ability to terminate the connection, when it receives a policy to terminate the connection, it will immediately take action to terminate the corresponding connection to prevent potential security threats from further spreading.

[0090] The specific functions of the on-board application unified identity management module are as follows:

[0091] 1) Identity information reception and standardization processing. The unified identity management module is responsible for receiving and processing application identity information from other modules, first standardizing the received identity information to ensure the uniformity of the format of various types of identity information, facilitating the direct application of subsequent modules. The standardization of identity information includes application name, application belonging device, etc.

[0092] 2) Support for trust value evaluation of access entities. After verification, integration and necessary conversion of identity information, the accuracy, completeness and standardization of identity information are ensured. The subsequent on-board application trust value evaluation engine provides reliable identity data support for the evaluation of open domain application trust value, and provides a solid foundation for access control decision-making.

[0093] The specific functions of the on-board application access policy management module are as follows:

[0094] 1) Responsible for receiving and processing policy configuration requests from ground personnel. Ground personnel configure corresponding policy rules in the policy management module according to the security requirements of the application, which define in detail the security policies that the application should follow in different situations.

[0095] 2) receiving the trust value from the onboard application trust value evaluation engine and matching it with the access control policy. After receiving the trust value, it matches it with the refined set of access control policies stored in the database. The set of policies contains the access control policies that should be applied for the open domain application at different trust value intervals.

[0096] In some embodiments, the onboard application access open domain network access control module comprises receiving the latest application access control policy information sent by the onboard application trust value evaluation engine from the onboard message middleware module, performing integrity verification, conflict detection and processing, loading and implementation on the policy information.

[0097] In some embodiments, the diversified log key data comprises the onboard application name, application version, access time and aircraft communication data link.

[0098] In some embodiments, the onboard application policy management module comprises receiving the policy configuration request sent by the ground crew through the ground configuration management tool, wherein the policy configuration request contains the access control policies of the application corresponding to different trust values.

[0099] In some embodiments, the onboard application policy management module is further used for updating the access policy and notifying the onboard application trust value evaluation engine module of the access policy update message.

[0100] The above only describes the preferred embodiments of the present application and is not intended to limit the present application. Any modifications, equivalent replacements and improvements made within the spirit and principle of the present application shall be included in the protection scope of the present application. The above only describes the preferred embodiments of the present application and is not intended to limit the present application. Any modifications, equivalent replacements and improvements made within the spirit and principle of the present application shall be included in the protection scope of the present application.

Claims

1. An airborne application dynamic access control method based on a zero trust mechanism, characterized in that, The method comprises: S1: configuring corresponding access control policies under different trust value intervals; S2: the airborne application open domain / avionics domain log management module receives audit logs related to the access entity from other aircraft and equipment in the open domain, avionics domain applications and systems, and the open domain network access control module, respectively, and performs standardization processing on the audit logs; S3: the airborne application open domain / avionics domain log management module sends the standardized logs to the airborne message middleware module and stores them in the module according to the message classification; S4: asynchronously consume the classified log messages from the airborne message middleware module and extract the key parameters in the log messages; S5: dynamically evaluate the trust value of the application according to the key parameters extracted in S4 using the preset trust value evaluation rules or algorithms; S6: obtain the corresponding access policy under the trust value according to the trust value evaluation result obtained in S5 and the access control policy configured in S1; S7: send the corresponding access policy under the trust value obtained in S6 to the open domain network access control unit through the airborne message middleware module, and the open domain network access control unit controls the access request according to the access policy; S8: when the application is accessed or operated, repeat S2-S7 to complete the continuous dynamic access control of the airborne application, The S7 comprises: performing integrity check on the received policy data; performing analysis and correctness check on the received policy data; detecting and solving the conflict of the analyzed policy data; loading and implementing the policy data.

2. The method of claim 1, wherein the method further comprises: The access control policy comprises granting of access rights, partial granting of access rights, and denial of access rights; and the access control policy is stored in a structured data format.

3. The method of claim 1, wherein the method further comprises: The standardization processing comprises pre-processing, cleaning, and data format unification of the log information.

4. An on-board application dynamic access control system based on a zero trust mechanism, characterized in that, The system is used to implement the control method according to any one of claims 1-3, comprising: an airborne application open domain / avionics domain log management module for receiving audit logs related to the access entity from other aircraft or equipment in the open domain, avionics domain airborne applications, and performing key data extraction, useless data cleaning, and log format normalization processing on diversified logs; an airborne message middleware module for asynchronously receiving and processing normalized log messages; an airborne application trust value evaluation engine module for asynchronously receiving the classified audit logs in the airborne message middleware module, dynamically evaluating the trust state of the application through a trust value evaluation algorithm combined with the identity information of the application; an airborne application access open domain network access control unit module for receiving, verifying, analyzing, loading, and implementing access control policies; an airborne application policy management module for receiving policy configuration requests, analyzing, verifying, and storing access control policies, and being responsible for matching the trust value of the application with the corresponding access control policy; an airborne application unified identity management module for receiving, standardizing, and structuring the application identity information, supporting the trust value evaluation of the application. The on-board application access open domain network access control module comprises receiving the latest application access control policy information sent by the on-board application trust value evaluation engine from the on-board message middleware module, performing integrity verification, resolution, conflict detection and processing, loading and implementation on the policy information.

5. The system for dynamic access control of on-board applications based on zero trust mechanism as claimed in claim 4 wherein, The key data of the diversified log comprises an on-board application name, an application version, an access time and an aircraft communication data link.

6. The system for dynamic access control of onboard applications based on zero trust mechanism as claimed in claim 4 wherein, The on-board application policy management module comprises receiving a policy configuration request sent by a ground crew through a ground configuration management tool, the policy configuration request containing access control policies of the application corresponding to different trust values.

7. The system for dynamic access control of onboard applications based on zero trust mechanism as claimed in claim 4 wherein, The on-board application policy management module is also used for accessing an update of the access policy and notifying the on-board application trust value evaluation engine module of an update message of the access policy.

Citation Information

Patent Citations

  • Endogenous security defense method, device and equipment of network information system and medium

    CN114978697A

  • Zero-trust secure trusted access method of 5G dual-domain private network

    CN117750467A