Zero-trust-based police service Internet of Things security access method
By adopting a secure access method based on a zero-trust architecture in the police IoT system, the problem of secure access to police IoT terminals is solved, and higher network security and boundary protection are achieved.
Patent Information
- Application Number
- CN202510200770.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-24
- Publication Date
- 2025-05-13
- Estimated Expiration
- Not applicable · inactive patent
AI Technical Summary
The open interaction of police IoT terminals, the boundaries of police IoT protection are blurred, and the traditional border security protection system is difficult to ensure the secure access of police IoT terminals.
The secure access method based on the zero-trust architecture is adopted. By obtaining and verifying the fingerprint information of the police terminal, generating fingerprint identifiers for authorization, performing zero-trust authentication, and generating keys for management through the key generation method, analyzing the device behavior in real time. If an exception is detected, pre-processing is performed, and key events are recorded to form a security log.
Effectively ensures secure access to police IoT terminals, enhances the security of network boundaries, and prevents unauthorized access and potential security threats.
Smart Images

Figure CN119995898A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of smart policing technology, and in particular relates to a zero-trust based police Internet of Things security access method. Background Art
[0002] As a key link in the development of smart policing, the construction of the police Internet of Things has continuously increased the various perception data dimensions of urban social security risk perception on the basis of the original public security video network, playing an important role in supporting the construction and development of smart policing. However, as various police sensor terminals continue to be integrated into the police Internet of Things, its IT architecture is changing from "bounded" to "borderless", and the traditional security boundaries are gradually disintegrating. The security issues of the police Internet of Things have become increasingly prominent, posing a severe challenge to the traditional network security defense system characterized by boundary isolation.
[0003] In view of the problems of open interaction of police IoT terminals, blurred protection boundaries of police IoT, and difficulty in ensuring secure access of police IoT terminals by traditional border security protection systems under the background of the development of police big data, a police IoT secure access method based on zero-trust architecture is proposed. With the IoT terminal identity as the center, lightweight security authentication based on identification is carried out. Based on device fingerprint extraction and police IoT identification public key generation algorithm, lightweight security authentication of police IoT terminals is realized. Summary of the invention
[0004] The purpose of an embodiment of the present invention is to provide a zero-trust based police Internet of Things security access method, aiming to solve the problems raised in the third part of the background technology.
[0005] The embodiment of the present invention is implemented as follows: a zero-trust-based police IoT security access method, the method comprising:
[0006] Obtaining fingerprint information, the fingerprint information is extracted through the police terminal to obtain police comprehensive terminal information;
[0007] Generate a fingerprint identification based on the fingerprint information, verify the fingerprint identification, ensure the credibility of the police terminal through verification, authorize through the fingerprint identification, and perform zero-trust authentication through authorization;
[0008] Obtain the key generation method, generate a key according to the key generation method, and manage the generated key. The private key management method is to encrypt and store it in the police terminal, and the public key management method is to send it to the device key management center;
[0009] Obtain monitoring data and monitoring data analysis results, analyze device behavior in real time through analysis results, perform preprocessing if anomalies are detected, record key events, and form a security log based on the recorded data.
[0010] Preferably, the steps of generating a fingerprint identification according to the fingerprint information, verifying the fingerprint identification, ensuring the credibility of the police terminal through verification, authorizing through the fingerprint identification, and performing zero-trust authentication through authorization specifically include:
[0011] Generate a fingerprint identification according to the fingerprint information, wherein the fingerprint identification includes a physical device identifier and dynamic state information;
[0012] Verify fingerprint identification to ensure the credibility of police terminals;
[0013] Authorization is performed through fingerprint identification, which is used to ensure that each device can only communicate with authorized devices and services in the network, and zero-trust authentication is performed through authorization.
[0014] Preferably, the verification includes transport layer security authentication.
[0015] Preferably, the method for obtaining key generation, generating a key according to the key generation method, managing the generated key, the private key management method is encrypted and stored in the police terminal, and the public key management method is sent to the device key management center, specifically including:
[0016] Obtain a key generation method, wherein the key generation method generates a key using device fingerprint information and a random number generated when the device is connected;
[0017] Generate a key according to a key generation method, wherein the key includes a private key and a public key, and manage the generated key;
[0018] The private key management method is to encrypt and store it in the police terminal, and the public key management method is to send it to the device key management center.
[0019] Preferably, the device key management center is used for subsequent identity authentication and data encryption.
[0020] Preferably, the steps of obtaining monitoring data, obtaining monitoring data analysis results, analyzing device behavior in real time through the analysis results, performing preprocessing if an abnormality is detected, recording key events, and forming a security log based on the recorded data specifically include:
[0021] Obtain monitoring data, wherein the monitoring data is obtained through log data, and obtain monitoring data analysis results;
[0022] Analyze device behavior in real time through analysis results, and if an abnormality is detected, perform preprocessing, including isolation, blocking, and alarming;
[0023] Critical events are recorded, including authentication, authorization, key operations and preprocessing, and a security log is formed based on the recorded data.
[0024] Preferably, the analysis result is used to detect whether there is any abnormal operation.
[0025] The embodiment of the present invention provides a zero-trust based police Internet of Things security access method, which obtains fingerprint information, the fingerprint information is extracted through a police terminal, the police terminal information is obtained, a fingerprint identifier is generated according to the fingerprint information, the fingerprint identifier is verified, the credibility of the police terminal is ensured through verification, authorization is performed through the fingerprint identifier, zero-trust authentication is performed through authorization, a key generation method is obtained, a key is generated according to the key generation method, the generated key is managed, the private key management method is encrypted and stored in the police terminal, the public key management method is sent to the device key management center, monitoring data is obtained, the monitoring data analysis results are obtained, the device behavior is analyzed in real time through the analysis results, if an abnormality is detected, pre-processing is performed, key events are recorded, and a security log is formed according to the recorded data, which solves the problems of open interaction of police Internet of Things terminals, blurred protection boundaries of police Internet of Things, and difficulty in ensuring secure access of police Internet of Things terminals by traditional border security protection systems. BRIEF DESCRIPTION OF THE DRAWINGS
[0026] Figure 1 A flowchart of a zero-trust-based police IoT security access method provided in an embodiment of the present invention;
[0027] Figure 2 A flowchart of the steps of generating a fingerprint identifier based on fingerprint information, verifying the fingerprint identifier, and performing zero-trust authentication through authorization provided by an embodiment of the present invention;
[0028] Figure 3 A flowchart of the steps of obtaining a key generation method provided by an embodiment of the present invention, generating a key according to the key generation method, and managing the generated key;
[0029] Figure 4 A flowchart of the steps of analyzing device behavior in real time through analysis results provided by an embodiment of the present invention, and performing preprocessing if an abnormality is detected; DETAILED DESCRIPTION
[0030] In order to make the purpose, technical solution and advantages of the present invention more clearly understood, the present invention is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present invention and are not intended to limit the present invention.
[0031] It is understood that the terms "first", "second", etc. used in this application may be used herein to describe various elements, but unless otherwise specified, these elements are not limited by these terms. These terms are only used to distinguish a first element from another element. For example, without departing from the scope of this application, a first xx script may be referred to as a second xx script, and similarly, a second xx script may be referred to as a first xx script.
[0032] like Figure 1 As shown, a zero-trust-based police IoT security access method is provided in an embodiment of the present invention, and the method includes:
[0033] S100, obtaining fingerprint information, the fingerprint information is extracted through the police terminal, and the police comprehensive terminal information is obtained, the police comprehensive terminal information includes MAC address, device model, firmware version and serial number.
[0034] In this step, fingerprint information is obtained. The extraction of fingerprint information is based on the hardware and software features of the police terminal device. These features usually include MAC address, device model, firmware version and serial number, etc.
[0035] The MAC address is the network hardware address of the device, which is used to identify each device on the network. The MAC address of each device is unique and does not repeat globally; the device model is a device classification identifier defined by the manufacturer, usually used to distinguish different hardware platforms or device types. Each model represents a specific hardware configuration and performance characteristics; the firmware is the control program between the device hardware and software, and the firmware version number is the identifier of the program, indicating the specific version of the operating system or firmware installed on the device;
[0036] Obtain police comprehensive terminal information. When the police terminal device is started or connected to the network, the system will automatically collect the above information as part of its device fingerprint. With this information, device identity authentication and access control can be performed to ensure that only legitimate devices can access the police IoT system.
[0037] S200, generate a fingerprint identification according to the fingerprint information, verify the fingerprint identification, ensure the credibility of the police terminal through verification, authorize through the fingerprint identification, and perform zero-trust authentication through authorization.
[0038] In this step, a fingerprint identifier is generated based on the fingerprint information. The fingerprint identifier is usually encrypted using a hash algorithm to combine the above information (such as MAC address, device model, etc.) to generate a unique identifier. A common practice is to perform a summary calculation on this information using a hash algorithm such as SHA-256 to obtain a hash value of a fixed length.
[0039] To verify the fingerprint identification, when the device is connected to the network, the system will compare the device's fingerprint identification with the device fingerprint pre-registered in the database. The device fingerprint stored in the database may be securely generated and stored when the device is registered. For example, when the police terminal device is first activated, it will generate and store the fingerprint identification through interaction with the device key management center.
[0040] S300, obtain the key generation method, generate a key according to the key generation method, manage the generated key, the private key management method is to encrypt and store it in the police terminal, and the public key management method is to send it to the device key management center.
[0041] In this step, the key generation method is obtained. Key generation is the process of generating encryption keys based on a certain algorithm and input data. Common key generation methods include symmetric encryption (such as AES) and asymmetric encryption (such as RSA, ECC). In this scheme, key generation usually uses an asymmetric encryption algorithm (such as RSA or ECC) to ensure the uniqueness of the device identity and the security of communication;
[0042] Key management is divided into private key management and public key management. Each key has different storage and management methods. The private key is an important credential bound to the device identity and must be kept strictly confidential and stored securely. Usually, the private key is encrypted and stored in the local storage of the device, and the storage location must have strong protection measures. The public key is used to verify the device identity and can usually be sent to the device key management center through a secure transmission mechanism for centralized management.
[0043] S400, obtaining monitoring data, obtaining monitoring data analysis results, analyzing device behavior in real time through the analysis results, and if an abnormality is detected, performing preprocessing, recording key events, and forming a security log based on the recorded data.
[0044] In this step, monitoring data is obtained. Monitoring data refers to various types of operating information collected from devices, sensors or networks, usually stored in the form of logs, indicators and event data. This data helps to understand the health status, performance and behavior of the device in real time;
[0045] After data collection, the system needs to analyze the data to identify potential security threats or performance issues. The analysis results are based on set rules or machine learning models, which can determine the normal and abnormal behavior of the device;
[0046] When the analysis results detect anomalies, the system needs to respond and process in real time. This process includes the identification, processing and recording of abnormal events.
[0047] like Figure 2As shown, as a preferred embodiment of the present invention, the steps of generating a fingerprint identification according to fingerprint information, verifying the fingerprint identification, ensuring the credibility of the police terminal through verification, authorizing through the fingerprint identification, and performing zero-trust authentication through authorization specifically include:
[0048] S201, generating a fingerprint identification according to fingerprint information, wherein the fingerprint identification includes a physical device identifier and dynamic state information.
[0049] In this step, a fingerprint identifier is generated based on the fingerprint information. The fingerprint identifier is composed of a physical device identifier and dynamic state information to ensure the uniqueness and real-time nature of the device. The fingerprint identifier of each device will change as the state of the device changes, thereby enhancing security and preventing the fingerprint information from being forged or stolen;
[0050] The physical device identifier is a unique identifier of the device at the hardware level, which is used to distinguish different devices. The physical identifier can be used directly to confirm the uniqueness of the device. In addition to the static physical identifier, the dynamic status information provides the characteristics of the device changing during actual operation. This information will change according to the device's behavior, status and environmental changes.
[0051] S202, verifying the fingerprint identification, wherein the verification includes transport layer security authentication, and the credibility of the police terminal is ensured through verification.
[0052] In this step, the fingerprint identification is verified to ensure the credibility of the police terminal, involving multiple authentication levels and methods. Through technologies such as transport layer security authentication (TLS authentication), it can ensure that the terminal identity is verified and data transmission is encrypted during the device communication process to prevent security threats such as man-in-the-middle attacks and data tampering;
[0053] When the police terminal accesses the network, it first generates the fingerprint identification of the device by extracting the fingerprint information. The device transmits the fingerprint identification and related dynamic status information to the device key management center. The verification includes transport layer security authentication. When the device communicates with the key management center, an encrypted channel is first established through the TLS protocol. During the handshake process, the device will provide its digital certificate, and the management center will verify the identity of the device.
[0054] S203, authorization is performed through fingerprint identification, and the authorization is used to ensure that each device in the network can only communicate with authorized devices and services, and zero-trust authentication is performed through authorization.
[0055] In this step, authorization is performed through fingerprint identification. When each device accesses the network, the system will generate a unique fingerprint identification based on the physical identification of the device (such as MAC address, device model, firmware version, etc.). This identification not only includes static device information, but also combines the dynamic status of the device (such as current version, device operating status, etc.), thereby ensuring the uniqueness and accuracy of the device fingerprint at each verification;
[0056] Zero trust authentication through authorization, after authorization through fingerprint identification, the communication between devices and services will be strictly controlled. Only authorized devices can communicate with specific services.
[0057] like Figure 3 As shown, as a preferred embodiment of the present invention, the key generation method is to generate a key according to the key generation method, manage the generated key, the private key management method is to encrypt and store it in the police terminal, and the public key management method is to send it to the device key management center, specifically including:
[0058] S301, obtaining a key generation method, wherein the key generation method generates a key by using device fingerprint information and a random number generated when the device is connected.
[0059] In this step, the key generation method is obtained. The device fingerprint information usually includes the device's MAC address, device model, firmware version, serial number, etc. This information is the unique identifier of each device. The fingerprint information is processed by an encrypted hash algorithm (such as SHA-256) to generate a fixed partial key for the device. Since the fingerprint information is the unique identifier of the device, it can ensure that the key generated for each device is unique;
[0060] When a device is connected, the system will generate a random number for each device. This random number can use a hardware random number generator (HRNG) or a pseudo-random number generator (PRNG). The introduction of random numbers increases the dynamic nature of key generation, so that even if the device is reconnected, the key can remain different.
[0061] S302, generating a key according to a key generation method, wherein the key includes a private key and a public key, and managing the generated key.
[0062] In this step, a key is generated according to the key generation method. The key pair (private key and public key) is generated based on the device fingerprint information and the random number generated when the device is connected. This information, including the unique identification of the device, ensures that the identification of each device is unique. The unique random number generated each time the device is connected increases the unpredictability and security of the key pair generation.
[0063] After the key pair is generated, it needs to be properly stored and managed to ensure security, confidentiality and legitimacy. The private key is very sensitive information and is used for data decryption and identity authentication. To ensure the security of the private key, strict protection measures need to be taken for the storage of the private key. The public key is public and can be used for secure communication and identity authentication with the device. The management method of the public key is relatively simple, but its accuracy and consistency also need to be guaranteed.
[0064] S303, the private key management method is to encrypt and store it in the police terminal, and the public key management method is to send it to the device key management center, which is used for subsequent identity authentication and data encryption.
[0065] In this step, the private key management method is encrypted storage in the police terminal. The private key is the core part of asymmetric encryption and is used to decrypt information or generate digital signatures. In the system, the private key must be highly protected to avoid illegal access or leakage. The key method of private key management is encrypted storage, that is, the private key is stored in the local hardware device of the police terminal and protected by encryption;
[0066] Unlike private keys, public keys are public and can be freely distributed and shared. In the device key management system, the device's public key needs to be securely sent to the device key management center to facilitate subsequent identity authentication and encryption operations.
[0067] like Figure 4 As shown, as a preferred embodiment of the present invention, the steps of obtaining monitoring data, obtaining monitoring data analysis results, analyzing device behavior in real time through the analysis results, performing preprocessing if an abnormality is detected, recording key events, and forming a security log based on the recorded data specifically include:
[0068] S401, obtaining monitoring data, wherein the monitoring data is obtained through log data, and obtaining monitoring data analysis results.
[0069] In this step, monitoring data is obtained. The monitoring data mainly comes from the logs generated during the operation of the device and system. These logs record the behavior, status, errors, events, warnings and other information of the device or system;
[0070] The acquired log data is usually raw, large, and complex, so it needs to be parsed and analyzed. The goal of monitoring data analysis is to discover potential problems such as abnormal behavior, performance bottlenecks, and security threats;
[0071] Obtain monitoring data analysis results, which can be converted into different output formats and specific operations. Based on the analysis results, the system can take corresponding response measures, such as alarm notification, automatic repair or report generation.
[0072] S402, analyzing the device behavior in real time through the analysis results, wherein the analysis results are used to detect whether there is any abnormal operation. If an abnormality is detected, preprocessing is performed, and the preprocessing methods include isolation, blocking and alarm.
[0073] In this step, the device behavior is analyzed in real time through the analysis results. The purpose of real-time analysis of device behavior is to continuously monitor the operating status of the device and promptly detect any abnormal behavior. By obtaining the monitoring data of the device (such as operation logs, system performance, network traffic, etc.), a "normal model" of device behavior can be constructed. Then, by comparing with historical data or set thresholds, the device behavior is analyzed in real time to see if there is any abnormality;
[0074] The system issues anomaly warnings when a device’s behavior deviates from normal patterns, such as unauthorized access, abnormal traffic, and abnormal operations;
[0075] Once the system detects abnormal behavior, the pre-processing mechanism will be activated to reduce potential risks and protect the system. Common pre-processing measures include isolation, blocking and alarm.
[0076] S403, recording key events, including authentication, authorization, key operation and preprocessing, and forming a security log based on the recorded data.
[0077] In this step, key events are recorded, which is crucial to ensure the security of the system, especially when it comes to identity authentication, permission authorization, key management, and exception preprocessing. By fully recording these events, the system can provide a detailed audit trail when security issues arise, and help to promptly discover and respond to potential security risks.
[0078] In one embodiment, a computer device is provided, the computer device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein when the processor executes the computer program, the following steps are implemented:
[0079] Obtaining fingerprint information, the fingerprint information is extracted through the police terminal to obtain police comprehensive terminal information;
[0080] Generate a fingerprint identification based on the fingerprint information, verify the fingerprint identification, ensure the credibility of the police terminal through verification, authorize through the fingerprint identification, and conduct zero-trust authentication through authorization;
[0081] Obtain the key generation method, generate a key according to the key generation method, and manage the generated key. The private key management method is to encrypt and store it in the police terminal, and the public key management method is to send it to the device key management center;
[0082] Obtain monitoring data and monitoring data analysis results, analyze device behavior in real time through analysis results, perform preprocessing if anomalies are detected, record key events, and form a security log based on the recorded data.
[0083] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the processor performs the following steps:
[0084] Obtaining fingerprint information, the fingerprint information is extracted through the police terminal to obtain police comprehensive terminal information;
[0085] Generate a fingerprint identification based on the fingerprint information, verify the fingerprint identification, ensure the credibility of the police terminal through verification, authorize through the fingerprint identification, and conduct zero-trust authentication through authorization;
[0086] Obtain the key generation method, generate a key according to the key generation method, and manage the generated key. The private key management method is to encrypt and store it in the police terminal, and the public key management method is to send it to the device key management center;
[0087] Obtain monitoring data and monitoring data analysis results, analyze device behavior in real time through analysis results, perform preprocessing if anomalies are detected, record key events, and form a security log based on the recorded data.
[0088] It should be understood that, although each step in the flow chart of each embodiment of the present invention is shown in sequence according to the indication of the arrow, these steps are not necessarily performed in sequence according to the order indicated by the arrow. Unless there is a clear explanation in this article, the execution of these steps does not have a strict order restriction, and these steps can be performed in other orders. Moreover, at least a portion of the steps in each embodiment may include a plurality of sub-steps or a plurality of stages, and these sub-steps or stages are not necessarily performed at the same time, but can be performed at different times, and the execution order of these sub-steps or stages is not necessarily performed in sequence, but can be performed in turn or alternately with at least a portion of other steps or sub-steps or stages of other steps.
[0089] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the program can be stored in a non-volatile computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application may include non-volatile and / or volatile memory. Non-volatile memory may include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory may include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).
[0090] The technical features of the above-described embodiments may be arbitrarily combined. To make the description concise, not all possible combinations of the technical features in the above-described embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0091] The above-mentioned embodiments only express several implementation methods of the present invention, and the description thereof is relatively specific and detailed, but it cannot be understood as limiting the scope of the patent of the present invention. It should be pointed out that, for ordinary technicians in this field, several variations and improvements can be made without departing from the concept of the present invention, which all belong to the protection scope of the present invention. Therefore, the protection scope of the patent of the present invention shall be subject to the attached claims.
[0092] The above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the protection scope of the present invention.
Claims
1. A zero-trust-based police IoT security access method, characterized in that: The method comprises: Obtaining fingerprint information, the fingerprint information is extracted through the police terminal to obtain police comprehensive terminal information; Generate a fingerprint identification based on the fingerprint information, verify the fingerprint identification, ensure the credibility of the police terminal through verification, authorize through the fingerprint identification, and perform zero-trust authentication through authorization; Obtain the key generation method, generate a key according to the key generation method, and manage the generated key. The private key management method is to encrypt and store it in the police terminal, and the public key management method is to send it to the device key management center; Obtain monitoring data and monitoring data analysis results, analyze device behavior in real time through analysis results, perform preprocessing if anomalies are detected, record key events, and form a security log based on the recorded data.
2. According to a zero-trust-based police IoT security access method according to claim 1, it is characterized in that: The steps of generating a fingerprint identification according to the fingerprint information, verifying the fingerprint identification, ensuring the credibility of the police terminal through verification, authorizing through the fingerprint identification, and performing zero-trust authentication through authorization specifically include: Generate a fingerprint identification according to the fingerprint information, wherein the fingerprint identification includes a physical device identifier and dynamic state information; Verify fingerprint identification to ensure the credibility of police terminals; Authorization is performed through fingerprint identification, which is used to ensure that each device can only communicate with authorized devices and services in the network, and zero-trust authentication is performed through authorization.
3. According to a zero-trust-based police IoT security access method according to claim 2, it is characterized in that: The verification includes transport layer security authentication.
4. According to claim 2, a zero-trust-based police IoT security access method is characterized in that: The method for obtaining a key generation method generates a key according to the key generation method, manages the generated key, the private key management method is encrypted and stored in the police terminal, and the public key management method is sent to the device key management center, specifically including: Obtain a key generation method, wherein the key generation method generates a key using device fingerprint information and a random number generated when the device is connected; Generate a key according to a key generation method, the key including a private key and a public key, and manage the generated key; The private key management method is to encrypt and store it in the police terminal, and the public key management method is to send it to the device key management center.
5. According to a zero-trust-based police IoT security access method according to claim 4, it is characterized in that: The device key management center is used for subsequent identity authentication and data encryption.
6. According to claim 4, a zero-trust-based police IoT security access method is characterized in that: The steps of obtaining monitoring data, obtaining monitoring data analysis results, analyzing device behavior in real time through the analysis results, performing preprocessing if an abnormality is detected, and recording key events to form a security log based on the recorded data specifically include: Obtain monitoring data, wherein the monitoring data is obtained through log data, and obtain monitoring data analysis results; Analyze device behavior in real time through analysis results, and if an abnormality is detected, perform preprocessing, including isolation, blocking, and alarming; Critical events are recorded, including authentication, authorization, key operations and preprocessing, and a security log is formed based on the recorded data.
7. According to claim 6, a zero-trust-based police IoT security access method is characterized in that: The analysis result is used to detect whether there is abnormal operation.