Distributed identity authentication and access control system based on zero trust

By introducing a zero-trust-based distributed identity authentication and access control mechanism in the identity authentication and access control system, we can monitor and evaluate the user's access behavior and environment in real time, and dynamically adjust access permissions, solving the security risks caused by the existing system's release of all access operation permissions after the user logs in, achieving higher access security and data protection effects.

CN119945773AActive Publication Date: 2025-05-06AVIC CLOUD TELECOM CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510094098.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-21
Publication Date
2025-05-06
Estimated Expiration
2045-01-21

AI Technical Summary

Technical Problem

The existing identity authentication and access control system releases all access operation permissions after the user logs in, making it difficult to effectively ensure access security, which may lead to unauthorized access or data leakage.

Method used

Using a distributed identity authentication and access control system based on zero trust, we use the access permission setting module, identity authentication module, access monitoring module, access monitoring data analysis module, comprehensive access trustworthiness analysis module and access control module to monitor and evaluate the user's access behavior and environment in real time, dynamically adjust access permissions, and ensure continuous identity authentication and real-time access control.

Benefits of technology

Through continuous identity authentication and real-time access control, the risk of data breaches is reduced, access security is improved, and the monitoring and evaluation capabilities of user access behavior and environment are enhanced, effectively protecting data security and Internet service quality.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945773A_ABST
    Figure CN119945773A_ABST
Patent Text Reader

Abstract

The invention discloses a distributed identity authentication and access control system based on zero trust, and particularly relates to the technical field of access control, identity information of a user is authenticated when the user logs in a service internet platform and accesses an item corresponding to a role user advanced permission, the possibility of data leakage is reduced, and the user experience is improved. An access process comprehensive access credibility analysis mechanism is introduced, when the basic data access permission is applied, if the comprehensive access credibility does not conform to the expectation, an interface where a to-be-accessed project is located is directly exited and returned to a previous-level interface of the to-be-accessed project, and if the comprehensive access credibility does not conform to the expectation in a main interface, a service internet platform is directly exited; and when the advanced data access permission is applied, the advanced data access permission of the item to be accessed is issued to the user only when the comprehensive access credibility meets the expectation and the access identity authentication is passed, so that the data exposure risk during the service internet platform access period can be effectively reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of access control technology, and more specifically, to a zero-trust based distributed identity authentication and access control system. Background Art

[0002] With the rapid development of Internet technology, various services are emerging and aggregated through the Internet, forming a service Internet. In recent years, the microservice architecture (MSA) based on the SOA concept has been widely used due to its easy expansion and maintenance. It has been widely used in the service Internet platform and has become the first choice for enterprises to provide services to users and operate within the organization. However, due to the cross-network and cross-domain characteristics of the service Internet, the number of remote service calls and service access scenarios has gradually increased, the scenarios faced by access control have become increasingly complex, and the demand for access control has also increased day by day.

[0003] The existing identity authentication and access control system associates the user's login identity authentication results with the access control policy. When the user successfully logs into the service Internet platform, all access and operation permissions are opened to the user. The user can directly and quickly access the data he needs, which greatly facilitates data query and effectively improves service quality.

[0004] However, there are still some problems with the existing system: the existing system only performs identity authentication when the user logs in to the service Internet platform and releases all access operation permissions after the user logs in to the service Internet platform. The one-time verification mechanism is difficult to completely eliminate the security risks of access or operation behaviors. Unauthorized access or data leakage may occur. It is necessary to introduce a new access control mechanism to further reduce the risk of data leakage. Summary of the invention

[0005] In order to overcome the above-mentioned defects of the prior art, an embodiment of the present invention provides a distributed identity authentication and access control system based on zero trust to solve the problems raised in the above-mentioned background technology.

[0006] To achieve the above objectives, the present invention provides the following technical solution: a distributed identity authentication and access control system based on zero trust, comprising:

[0007] Access permission setting module: build a role access control model to create users with different roles, and assign different data access permissions to each role user;

[0008] Identity authentication module: including login identity authentication and access identity authentication. Login identity authentication is used to authenticate the user's identity information when logging into the service Internet platform, and access identity authentication is used to authenticate the user's identity information when accessing projects corresponding to the role user's advanced permissions;

[0009] Access monitoring module: monitors the user's access behavior on the service Internet platform in real time and generates access logs for backup, extracts real-time access operation data, real-time access network environment data, and real-time access device data and sends them to the access monitoring data analysis module;

[0010] Access monitoring data analysis module: processes the extracted real-time access operation data, real-time access network environment data and real-time access device data to calculate the operation credibility coefficient, network credibility coefficient and device credibility coefficient respectively;

[0011] Comprehensive access credibility analysis module: calculates the comprehensive access credibility index based on the operation credibility coefficient, network credibility coefficient and device credibility coefficient, determines whether the comprehensive access credibility index meets expectations, and sends the judgment result to the access control module;

[0012] Access control module: receives comprehensive access credibility judgment results and identity authentication results and generates access control policies based on them. After the daily access log is generated, it updates the user's access rights in combination with the user's historical access log.

[0013] Database: used to store data information of all modules in the system.

[0014] Preferably, the identity authentication module includes an account registration unit, a login identity authentication unit, an access identity authentication unit and an identity authentication result output unit. The account registration unit generates a login account after the user enters the real name, ID number, email account, strong login password, real-name registered mobile phone number, expected authentication questions and answers, and fingerprint information; the login identity authentication unit is used to perform multi-factor identity authentication on the user and enter the main interface of the service Internet platform after the authentication is passed; the access identity authentication unit authenticates the user's identity information when the user accesses an item corresponding to the advanced permissions of his or her role; the identity authentication result output unit sends the login identity authentication result and the access identity authentication result to the access control module.

[0015] Preferably, the real-time access operation data extracted by the access monitoring module are the number of repeated access applications mfcij for the j-th item at the i-th moment and the duration Tfcij of no-operation access for the j-th item at the i-th moment; the real-time access network environment data extracted by the access monitoring module include the user's network connection speed vai, network bandwidth vbi and delay Tai at the i-th moment; the real-time access device data extracted by the access monitoring module include the firewall false alarm rate αwi at the i-th moment, the number of update differences mai between the operating system version at the i-th moment and the latest operating system version, and the browser encryption strength coefficient εmi at the i-th moment.

[0016] Preferably, the access monitoring data analysis module includes a data receiving unit, an operation credibility analysis unit, a network credibility analysis unit, a device credibility analysis unit and a data output unit. The data receiving unit is used to receive the extracted real-time access operation data, real-time access network environment data and real-time access device data; the operation credibility analysis unit is used to calculate the operation credibility coefficient Xrci at the i-th moment, and the specific formula is: , βmij and βTij are the access application over-limit coefficient and the no-operation stay over-limit coefficient of the j-th project at the i-th time, respectively. The specific calculation formula is as follows: , , mfr, Tfr are the maximum number of repeated visits allowed for the project and the maximum non-operation stay time allowed for the project, respectively, and na is the number of projects; the network credibility analysis unit is used to calculate the network credibility coefficient Xrwi at the i-th moment, and the specific formula is: , vae, vbe, and Tae are the minimum network connection speed allowed for access, the minimum network bandwidth allowed for access, and the maximum delay allowed for access respectively; the device credibility analysis unit is used to calculate the device credibility coefficient Xrsi at the i-th moment, and the specific formula is: ; The data output unit is used to transmit the calculated operation credibility coefficient, network credibility coefficient and device credibility coefficient to the comprehensive access credibility analysis module.

[0017] Preferably, the comprehensive access credibility analysis module includes a data receiving unit, a comprehensive access credibility analysis unit, a comprehensive access credibility judgment unit and a judgment result output unit. The data receiving unit is used to receive the calculated operation credibility coefficient, network credibility coefficient and device credibility coefficient at the i-th moment; the comprehensive access credibility analysis unit is used to calculate the comprehensive access credibility index YFi at the i-th moment. The specific formula is: ; The comprehensive access credibility judgment unit compares the calculated comprehensive access credibility index with the expected value of comprehensive access credibility. If the calculated value is greater than or equal to the expected value of comprehensive access credibility, it meets expectations; if the calculated value is less than the expected value of comprehensive access credibility, it does not meet expectations; the judgment result output unit is used to send the comprehensive access credibility judgment result to the access control module.

[0018] Preferably, the access control module includes an information receiving unit and an access control policy generating unit. The information receiving unit is used to receive the comprehensive access credibility judgment result and the identity authentication result. The access control policy generating unit automatically issues the user role-based data access rights when the login identity authentication is passed and sends an instruction to the access monitoring module to start access monitoring. When applying the basic data access rights, if the comprehensive access credibility does not meet expectations, the user will be directly exited from the interface where the project to be accessed is located and return to the previous level interface of the project to be accessed. If the comprehensive access credibility does not meet expectations on the main interface, the user will be directly exited from the service Internet platform. When applying for advanced data access rights, if the comprehensive access credibility meets expectations and the access identity authentication is passed, the user will be issued with advanced data access rights for the project to be accessed. If the comprehensive access credibility meets expectations but the access identity authentication fails, the user will be directly exited from the service Internet platform.

[0019] Preferably, the access control module further includes a historical access log retrieval unit, a comprehensive access average credibility calculation unit, a user access permission adjustment judgment unit, and a user access permission update unit. The historical access log retrieval unit is used to retrieve the user's historical access log; the comprehensive access average credibility calculation unit summarizes the comprehensive access credibility index that can be calculated from the current day's access log and the historical access log and calculates the comprehensive access average credibility index YFe. The specific formula is: , nb is the data volume of the comprehensive access credibility index; the user access right adjustment judgment unit compares the comprehensive access average credibility index with the comprehensive access credibility expected value, and if the calculated value is greater than or equal to the expected value, the user access right will not be adjusted, otherwise the user's partial advanced data access rights will be frozen until the next access log is generated; the user access right update unit evaluates the importance of the existing advanced data access rights and sorts them from high to low in importance, and calculates the proportion fi of the number of i-th advanced data access rights, and the specific formula is: , nc is the total number of advanced data access permissions, and the difference coefficient θa between the comprehensive access average credibility index YFe and the comprehensive access credibility expected value YFu is calculated. The specific formula is: ,when When the priority order is 1, the high-level data access rights are frozen. When , freeze the access rights of the first and second advanced data in importance, ..., when All advanced data access permissions are frozen.

[0020] Technical effects and advantages of the present invention:

[0021] 1. The present invention sets an identity authentication module to authenticate the user's identity information when logging into the service Internet platform on the one hand, and to authenticate the user's identity information when accessing projects corresponding to the role user's advanced permissions on the other hand, thereby changing the one-time identity authentication into a continuous identity authentication, reducing the possibility of data leakage.

[0022] 2. The present invention sets an access monitoring module to monitor the user's access behavior on the service Internet platform in real time and extract real-time access operation data, real-time access network environment data and real-time access device data, sets an access monitoring data analysis module to process the extracted real-time access operation data, real-time access network environment data and real-time access device data to calculate the operation credibility coefficient, network credibility coefficient and device credibility coefficient respectively, sets a comprehensive access credibility analysis module to calculate the comprehensive access credibility index based on the operation credibility coefficient, network credibility coefficient and device credibility coefficient and judge whether the comprehensive access credibility index meets expectations, and implements the comprehensive access credibility analysis module in the user's access process. The comprehensive access credibility is evaluated when applying basic data access permissions. When the comprehensive access credibility does not meet expectations, the user will be directly exited from the interface where the project to be accessed is located and return to the previous interface of the project to be accessed. If the comprehensive access credibility does not meet expectations on the main interface, the user will be directly exited from the service Internet platform. When applying for advanced data access permissions, when the comprehensive access credibility meets expectations and the access identity authentication passes, the user will be issued with advanced data access permissions for the project to be accessed. When the comprehensive access credibility meets expectations but the access identity authentication fails, the user will be directly exited from the service Internet platform. This can effectively reduce the risk of data exposure during access to the service Internet platform and improve the flexibility and accuracy of security protection.

[0023] 3. The present invention sets an access control module to summarize the comprehensive access credibility index that can be calculated in the access log of the current day and the historical access log and calculate the comprehensive access average credibility index, compare the comprehensive access average credibility index with the expected value of the comprehensive access credibility, and if the calculated value is greater than or equal to the expected value, the user's access rights will not be adjusted; otherwise, some of the user's advanced data access rights will be frozen until the next access log is generated, thereby reducing the losses caused by the theft of important data access rights, and providing a method for freezing advanced data access rights. The lower the credibility, the lower the user's rights, which can effectively protect data security and Internet service quality. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] Figure 1 It is a system structure block diagram of the present invention.

[0025] Figure 2 It is a diagram of the method steps of the present invention. DETAILED DESCRIPTION

[0026] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0027] like Figure 1 The distributed identity authentication and access control system based on zero trust provided by the present embodiment shown includes an access permission setting module, an identity authentication module, an access monitoring module, an access monitoring data analysis module, a comprehensive access credibility analysis module, an access control module and a database. The permission setting module, the identity authentication module and the comprehensive access credibility analysis module are connected to the access control module, and the access monitoring module, the access monitoring data analysis module and the comprehensive access credibility analysis module are connected sequentially, and all modules in the system are connected to the database.

[0028] The access permission setting module constructs a role access control model to create users with different roles, and assigns different data access permissions to each role user;

[0029] It should be specifically noted in this embodiment that the process of building a role-based access control model is a prior art, so the model building process will not be specifically described here.

[0030] What needs to be specifically explained in the present embodiment is that the data access permissions assigned by the access permission setting module to each role user are divided into basic data access permissions and advanced data access permissions. Each role user can directly apply the basic data access permissions when passing the login identity authentication, and can apply the corresponding advanced data access permissions when the comprehensive access credibility assessment meets expectations and the access identity authentication is passed.

[0031] The identity authentication module includes two modes: login identity authentication and access identity authentication. The login identity authentication is used to authenticate the user's identity information when logging into the service Internet platform, and the access identity authentication is used to authenticate the user's identity information when accessing the project corresponding to the role user's advanced permissions;

[0032] Furthermore, the identity authentication module includes an account registration unit, a login identity authentication unit, an access identity authentication unit and an identity authentication result output unit. The account registration unit generates a login account after the user enters the real name, ID number, email account, login strong password, real-name registered mobile phone number, expected authentication questions and answers, and fingerprint information; the login identity authentication unit is used to perform multi-factor identity authentication on the user and enter the main interface of the service Internet platform after the authentication is passed; the access identity authentication unit authenticates the user's identity information when the user accesses the project corresponding to the advanced permissions of the role to which he belongs; the identity authentication result output unit sends the login identity authentication result and the access identity authentication result to the access control module.

[0033] In this embodiment, it should be specifically explained that the specific steps of the login identity authentication unit performing multi-factor authentication on the user are as follows:

[0034] A1. Perform login account and password authentication on the accessing user. If the accessing user enters the correct login account and strong login password, the authentication is passed and the knowledge factor authentication is started.

[0035] A2. Perform knowledge factor authentication on the accessing user, randomly send an expected authentication question that the accessing user entered when registering an account, and if the accessing user enters the correct expected answer, the knowledge factor authentication passes and enters the ownership factor authentication;

[0036] A3. Perform ownership factor authentication on the accessing user, and randomly send a dynamic verification password to the accessing user's email account or mobile phone number. If the accessing user enters the password correctly within the validity period of the verification password, the ownership factor authentication is passed and the biometric factor authentication is entered;

[0037] A4. Perform biometric authentication on the accessing user. When it is detected that the fingerprint information input by the accessing user is consistent with the fingerprint information input when registering the account, the biometric authentication is passed, and the identity authentication is passed.

[0038] It should be specifically explained in this embodiment that the access authentication unit will randomly apply one of the authentication methods of knowledge factor authentication, ownership factor authentication, and biometric factor authentication when authenticating the user.

[0039] The access monitoring module monitors the user's access behavior on the service Internet platform in real time and generates access logs for backup, extracts real-time access operation data, real-time access network environment data and real-time access device data and sends them to the access monitoring data analysis module;

[0040] Furthermore, the real-time access operation data extracted by the access monitoring module are the number of repeated access applications mfcij for the j-th item at the i-th moment and the duration Tfcij of no-operation access for the j-th item at the i-th moment; the real-time access network environment data extracted by the access monitoring module include the user's network connection speed vai, network bandwidth vbi and delay Tai at the i-th moment; the real-time access device data extracted by the access monitoring module include the firewall false alarm rate αwi at the i-th moment, the number of update differences mai between the operating system version at the i-th moment and the latest operating system version, and the browser encryption strength coefficient εmi at the i-th moment.

[0041] In this embodiment, it is specifically necessary to explain that a method for calculating the browser encryption strength coefficient εmi is provided, and the specific formula is: , εai is the key length generated by the encryption algorithm used by the browser at the i-th moment.

[0042] The access monitoring data analysis module processes the extracted real-time access operation data, real-time access network environment data and real-time access device data to calculate the operation credibility coefficient, network credibility coefficient and device credibility coefficient respectively;

[0043] Further, the access monitoring data analysis module includes a data receiving unit, an operation credibility analysis unit, a network credibility analysis unit, a device credibility analysis unit and a data output unit. The data receiving unit is used to receive the extracted real-time access operation data, real-time access network environment data and real-time access device data; the operation credibility analysis unit is used to calculate the operation credibility coefficient Xrci at the i-th moment, and the specific formula is: , βmij and βTij are the access application over-limit coefficient and the no-operation stay over-limit coefficient of the j-th project at the i-th time, respectively. The specific calculation formula is as follows: , , mfr, Tfr are the maximum number of repeated visits allowed for the project and the maximum non-operation stay time allowed for the project, respectively, and na is the number of projects; the network credibility analysis unit is used to calculate the network credibility coefficient Xrwi at the i-th moment, and the specific formula is: , vae, vbe, and Tae are the minimum network connection speed allowed for access, the minimum network bandwidth allowed for access, and the maximum delay allowed for access respectively; the device credibility analysis unit is used to calculate the device credibility coefficient Xrsi at the i-th moment, and the specific formula is: ; The data output unit is used to transmit the calculated operation credibility coefficient, network credibility coefficient and device credibility coefficient to the comprehensive access credibility analysis module.

[0044] The comprehensive access credibility analysis module calculates the comprehensive access credibility index based on the operation credibility coefficient, the network credibility coefficient and the device credibility coefficient, determines whether the comprehensive access credibility index meets expectations, and sends the determination result to the access control module;

[0045] Furthermore, the comprehensive access credibility analysis module includes a data receiving unit, a comprehensive access credibility analysis unit, a comprehensive access credibility judgment unit and a judgment result output unit. The data receiving unit is used to receive the calculated operation credibility coefficient, network credibility coefficient and device credibility coefficient at the i-th moment; the comprehensive access credibility analysis unit is used to calculate the comprehensive access credibility index YFi at the i-th moment. The specific formula is: ; The comprehensive access credibility judgment unit compares the calculated comprehensive access credibility index with the expected value of comprehensive access credibility. If the calculated value is greater than or equal to the expected value of comprehensive access credibility, it meets expectations; if the calculated value is less than the expected value of comprehensive access credibility, it does not meet expectations; the judgment result output unit is used to send the comprehensive access credibility judgment result to the access control module.

[0046] The access control module receives the comprehensive access credibility judgment result and the identity authentication result and generates an access control policy based on the result, and updates the user access rights in combination with the user's historical access log after the access log is generated every day;

[0047] Furthermore, the access control module includes an information receiving unit and an access control policy generating unit. The information receiving unit is used to receive the comprehensive access credibility judgment result and the identity authentication result. The access control policy generating unit automatically issues the role basic data access rights to the user when the login identity authentication is passed and sends an instruction to the access monitoring module to start access monitoring. When applying the basic data access rights, if the comprehensive access credibility does not meet expectations, the user will be directly exited from the interface where the project to be accessed is located and return to the previous level interface of the project to be accessed. If the comprehensive access credibility does not meet expectations on the main interface, the user will be directly exited from the service Internet platform. When applying for advanced data access rights, if the comprehensive access credibility meets expectations and the access identity authentication is passed, the user will be issued with the advanced data access rights for the project to be accessed. If the comprehensive access credibility meets expectations but the access identity authentication fails, the user will be directly exited from the service Internet platform.

[0048] Furthermore, the access control module further includes a historical access log retrieval unit, a comprehensive access average credibility calculation unit, a user access permission adjustment judgment unit, and a user access permission update unit. The historical access log retrieval unit is used to retrieve the user's historical access log; the comprehensive access average credibility calculation unit summarizes the comprehensive access credibility index that can be calculated from the current day's access log and the historical access log and calculates the comprehensive access average credibility index YFe. The specific formula is: , nb is the data volume of the comprehensive access credibility index; the user access right adjustment judgment unit compares the comprehensive access average credibility index with the comprehensive access credibility expected value, and if the calculated value is greater than or equal to the expected value, the user access right will not be adjusted, otherwise the user's partial advanced data access rights will be frozen until the next access log is generated; the user access right update unit evaluates the importance of the existing advanced data access rights and sorts them from high to low in importance, and calculates the proportion fi of the number of i-th advanced data access rights, and the specific formula is: , nc is the total number of advanced data access permissions, and the difference coefficient θa between the comprehensive access average credibility index YFe and the comprehensive access credibility expected value YFu is calculated. The specific formula is: ,when When the priority order is 1, the high-level data access rights are frozen. When , freeze the access rights of the first and second advanced data in importance, ..., when All advanced data access permissions are frozen.

[0049] It should be specifically explained in this embodiment that an access log refers to the result of integrating all access records within a full 24 hours from 0:00 to 24:00.

[0050] The database is used to store data information of all modules in the system.

[0051] It should be specifically noted in this embodiment that the expected values ​​and preset values ​​used are selected based on actual needs and are not limited to specific values ​​here.

[0052] like Figure 2 The distributed identity authentication and access control method based on zero trust provided in this embodiment includes the following steps:

[0053] S1: Build a role-based access control model to create users with different roles and assign different data access permissions to each role user;

[0054] S2: includes two modes: login identity authentication and access identity authentication. Login identity authentication is used to authenticate the user's identity information when logging into the service Internet platform, and access identity authentication is used to authenticate the user's identity information when accessing projects corresponding to the role user's advanced permissions;

[0055] S3: monitors users’ access behaviors on the service Internet platform in real time and generates access logs for backup, extracting real-time access operation data, real-time access network environment data, and real-time access device data;

[0056] S4: respectively processing the extracted real-time access operation data, real-time access network environment data, and real-time access device data to calculate the operation credibility coefficient, the network credibility coefficient, and the device credibility coefficient;

[0057] S5: Calculate a comprehensive access credibility index based on the operation credibility coefficient, the network credibility coefficient, and the device credibility coefficient, and determine whether the comprehensive access credibility index meets expectations;

[0058] S6: Receive the comprehensive access credibility judgment result and identity authentication result and generate access control policy based on it, and update the user access rights in combination with the user's historical access log after the access log is generated every day.

[0059] Finally: The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the protection scope of the present invention.

Claims

1. A distributed identity authentication and access control system based on zero trust, characterized by: include: Access permission setting module: build a role access control model to create users with different roles, and assign different data access permissions to each role user; Identity authentication module: including login identity authentication and access identity authentication. Login identity authentication is used to authenticate the user's identity information when logging into the service Internet platform, and access identity authentication is used to authenticate the user's identity information when accessing projects corresponding to the role user's advanced permissions; Access monitoring module: monitors the user's access behavior on the service Internet platform in real time and generates access logs for backup, extracts real-time access operation data, real-time access network environment data, and real-time access device data and sends them to the access monitoring data analysis module; Access monitoring data analysis module: processes the extracted real-time access operation data, real-time access network environment data and real-time access device data to calculate the operation credibility coefficient, network credibility coefficient and device credibility coefficient respectively; Comprehensive access credibility analysis module: calculates the comprehensive access credibility index based on the operation credibility coefficient, network credibility coefficient and device credibility coefficient, determines whether the comprehensive access credibility index meets expectations, and sends the judgment result to the access control module; Access control module: Receives comprehensive access credibility judgment results and identity authentication results and generates access control policies based on them. After the access log is generated every day, it updates the user's access rights in combination with the user's historical access log.

2. The zero-trust based distributed identity authentication and access control system according to claim 1, characterized in that: The identity authentication module includes an account registration unit, a login identity authentication unit, an access identity authentication unit, and an identity authentication result output unit. The account registration unit generates a login account after the user enters the real name, ID number, email account, login strong password, real-name registered mobile phone number, expected authentication questions and answers, and fingerprint information; the login identity authentication unit is used to perform multi-factor identity authentication on the user and enter the main interface of the service Internet platform after the authentication is passed; the access identity authentication unit authenticates the user's identity information when the user accesses the project corresponding to the advanced authority of the role to which he belongs; The identity authentication result output unit sends the login identity authentication result and the access identity authentication result to the access control module.

3. The zero-trust based distributed identity authentication and access control system according to claim 1, characterized in that: The real-time access operation data extracted by the access monitoring module include the number of repeated access applications mfcij of the j-th item at the i-th moment and the duration of no-operation access Tfcij of the j-th item at the i-th moment; the real-time access network environment data extracted by the access monitoring module include the network connection speed vai, network bandwidth vbi and delay Tai of the user at the i-th moment; The real-time access device data extracted by the access monitoring module includes the firewall false alarm rate αwi at the ith moment, the update difference number mai between the operating system version at the ith moment and the latest operating system version, and the browser encryption strength coefficient εmi at the ith moment.

4. The zero-trust based distributed identity authentication and access control system according to claim 3, characterized in that: The access monitoring data analysis module includes a data receiving unit, an operation credibility analysis unit, a network credibility analysis unit, a device credibility analysis unit and a data output unit. The data receiving unit is used to receive the extracted real-time access operation data, real-time access network environment data and real-time access device data; the operation credibility analysis unit is used to calculate the operation credibility coefficient Xrci at the i-th moment, and the specific formula is: , βmij and βTij are the access application over-limit coefficient and the no-operation stay over-limit coefficient of the j-th project at the i-th time, respectively. The specific calculation formula is as follows: , , mfr, Tfr are the maximum number of repeated visits allowed for the project and the maximum non-operation stay time allowed for the project, respectively, and na is the number of projects; the network credibility analysis unit is used to calculate the network credibility coefficient Xrwi at the i-th moment, and the specific formula is: , vae, vbe, and Tae are the minimum network connection speed allowed for access, the minimum network bandwidth allowed for access, and the maximum delay allowed for access respectively; the device credibility analysis unit is used to calculate the device credibility coefficient Xrsi at the i-th moment, and the specific formula is: ; The data output unit is used to transmit the calculated operation credibility coefficient, network credibility coefficient and device credibility coefficient to the comprehensive access credibility analysis module.

5. The zero-trust based distributed identity authentication and access control system according to claim 1, characterized in that: The comprehensive access credibility analysis module includes a data receiving unit, a comprehensive access credibility analysis unit, a comprehensive access credibility judgment unit and a judgment result output unit. The data receiving unit is used to receive the calculated operation credibility coefficient, network credibility coefficient and device credibility coefficient at the i-th moment; the comprehensive access credibility analysis unit is used to calculate the comprehensive access credibility index YFi at the i-th moment. The specific formula is: ; The comprehensive access credibility judgment unit compares the calculated comprehensive access credibility index with the expected value of comprehensive access credibility. If the calculated value is greater than or equal to the expected value of comprehensive access credibility, it meets expectations; if the calculated value is less than the expected value of comprehensive access credibility, it does not meet expectations; the judgment result output unit is used to send the comprehensive access credibility judgment result to the access control module.

6. The zero-trust based distributed identity authentication and access control system according to claim 1, characterized in that: The access control module includes an information receiving unit and an access control policy generating unit. The information receiving unit is used to receive the comprehensive access credibility judgment result and the identity authentication result. The access control policy generating unit automatically issues the role basic data access rights to the user when the login identity authentication is passed and sends instructions to the access monitoring module to start access monitoring. When applying the basic data access rights, if the comprehensive access credibility does not meet the expectations, the user will be directly exited from the interface where the project to be accessed is located and return to the upper-level interface of the project to be accessed. If the comprehensive access credibility does not meet the expectations on the main interface, the user will be directly exited from the service Internet platform. When applying for advanced data access rights, if the comprehensive access credibility meets the expectations and the access identity authentication is passed, the user will be issued the advanced data access rights of the project to be accessed. If the comprehensive access credibility meets the expectations but the access identity authentication fails, the user will be directly exited from the service Internet platform.

7. The zero-trust based distributed identity authentication and access control system according to claim 1, characterized in that: The access control module also includes a historical access log retrieval unit, a comprehensive access average credibility calculation unit, a user access right adjustment judgment unit, and a user access right update unit. The historical access log retrieval unit is used to retrieve the user's historical access log; the comprehensive access average credibility calculation unit summarizes the comprehensive access credibility index that can be calculated from the current day's access log and the historical access log and calculates the comprehensive access average credibility index YFe. The specific formula is: , nb is the data volume of the comprehensive access credibility index; the user access right adjustment judgment unit compares the comprehensive access average credibility index with the comprehensive access credibility expected value, and if the calculated value is greater than or equal to the expected value, the user access right is not adjusted; otherwise, some of the user's advanced data access rights are frozen until the next access log is generated; The user access permission updating unit evaluates the importance of the existing advanced data access permissions and sorts them from high to low in importance, and calculates the proportion fi of the number of i-th advanced data access permissions. The specific formula is: , nc is the total number of advanced data access permissions, and the difference coefficient θa between the comprehensive access average credibility index YFe and the comprehensive access credibility expected value YFu is calculated. The specific formula is: ,when When the priority order is 1, the high-level data access permissions are frozen. When , freeze the access rights of the first and second advanced data in importance, ..., when All advanced data access permissions are frozen.

Citation Information

Patent Citations

  • Security micro-service architecture based on zero-trust access strategy and implementation method

    CN112765639A

  • Internet of vehicles access control method based on zero trust mechanism

    CN114567473A

  • Zero-trust single packet authentication system and method based on distributed identity

    CN116388989A

  • User trust measurement method and system in zero-trust network environment

    CN116455668A

  • Method and system to detect discrepancy in infrastructure security configurations from translated security best practice configurations in heterogeneous environments

    WO2017177077A2