Asset access control method and device, equipment and medium

Through a dynamic permission management method based on user historical trust scores, the problem of unreasonable permission allocation in the existing technology is solved, and more flexible and reasonable permission management is achieved.

CN120012149APending Publication Date: 2025-05-16CHINA TELECOM NETWORK SECURITY TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510024876.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-06
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The existing permission management plan adopts a static permission allocation method, and cannot dynamically adjust permissions according to actual needs, and the evaluation strategies and factors for different users are consistent, resulting in unreasonable permission allocation.

Method used

By obtaining the user's historical trust score, determining his credit rating, and selecting the corresponding trust evaluation strategy based on the credit rating, and evaluating the user's trust. Generate decision results based on user trust and target asset trust requirements and dynamically adjust permissions.

Benefits of technology

Improves the rationality and flexibility of permission allocation, ensuring dynamic permission management based on the latest trust assessment results every time you access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120012149A_ABST
    Figure CN120012149A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, in particular to an asset access control method and device, equipment and a medium, and is used for improving the rationality of an access permission distribution mode. The method comprises the following steps: trust evaluation equipment can obtain an access request for accessing a target asset; wherein the access request comprises a user identifier of the access user. The trust evaluation device may query a historical trust score of the access user based on the user identifier, and determine a credit rating of the access user according to the historical trust score. And determining a credibility evaluation strategy corresponding to the access user according to a corresponding relationship between the credit rating and the credibility evaluation strategy. The trust evaluation device can evaluate the trust degree of the access user based on the trust degree evaluation strategy corresponding to the access user to obtain the trust degree of the access user. The trust evaluation device can generate a decision result according to the trust degree of the access user and the trust degree requirement of the target asset. The trust evaluation device may send the decision result.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to a method, device, equipment and medium for controlling asset access. Background Art

[0002] With the increase in the application of business systems, network boundaries are becoming increasingly blurred, access devices are becoming more diverse, and resource exposure is increasing. In order to improve the security of business systems, different access permissions are usually set to manage permissions for devices, users, and applications to improve business security.

[0003] In existing permission management solutions, static permission allocation is usually adopted, and permission adjustment cannot be made dynamically according to actual needs. At the same time, the evaluation strategies and evaluation factors for different users are usually the same.

[0004] Therefore, the permission allocation method of the permission management scheme in the prior art is unreasonable and needs to be improved. Summary of the invention

[0005] The embodiments of the present application provide a method, apparatus, device and medium for controlling asset access, which are used to determine the access rights of a user based on the user's historical trust score, thereby improving the rationality of the permission allocation method.

[0006] In a first aspect, the present application provides a method for controlling asset access, the method comprising: obtaining an access request for accessing a target asset, the access request comprising a user identifier of an accessing user; querying a historical trust score of the accessing user based on the user identifier, and determining a credit rating of the accessing user based on the historical trust score; determining a trust assessment strategy corresponding to the accessing user based on a correspondence between a credit rating and a trust assessment strategy; performing a trust assessment on the accessing user based on the trust assessment strategy corresponding to the accessing user to obtain the trust of the accessing user; generating a decision result based on the trust of the accessing user and the trust requirement of the target asset; and sending the decision result.

[0007] According to this method, the corresponding credit level is determined according to the user's historical trust score, and the user's trust is determined by credit evaluation based on the evaluation strategy corresponding to the credit level. The corresponding access decision result is determined based on the user's trust and the trust requirements of the target asset. Among them, when the user's trust is greater than or equal to the trust requirements of the target asset, the decision result generated is to release the user's access request. When the user's trust is less than the trust requirements of the target asset, the decision result generated is to intercept the user's access request. In other words, every time the user accesses the target asset, the user needs to be trusted, and the evaluation strategy for the user is determined according to the user's historical trust score, that is, different users can correspond to different evaluation strategies, which improves the flexibility of trust evaluation. Furthermore, the access decision result is determined based on the user's trust and the trust requirements of the target asset, so the rationality of the permission allocation method can be improved.

[0008] In a possible embodiment, evaluation results of multiple evaluation factors corresponding to the historical trust scores of the accessing user are obtained; and weights of the multiple evaluation factors are adjusted based on a preset weight adjustment rule and the evaluation results.

[0009] Based on this embodiment, the weights of multiple evaluation factors are dynamically adjusted to improve the accuracy of user trust evaluation.

[0010] In a possible embodiment, the method of performing trust evaluation on the accessing user based on the trust evaluation policy corresponding to the accessing user includes:

[0011] The trust of the accessing user is evaluated based on the trust evaluation strategy corresponding to the accessing user and the weights of the multiple evaluation factors to obtain the trust of the accessing user.

[0012] In a possible embodiment, the multiple evaluation factors include at least one of identity information, Internet Protocol IP, location information, time information, and device security baseline.

[0013] In a possible embodiment, the sensitivity level of the target asset is determined according to the historical activity information and resource security information of the target asset, and the trust requirement of the target asset is determined according to the corresponding relationship between the sensitivity level and the trust requirement.

[0014] Based on this embodiment, the sensitivity level of the target asset is determined based on the historical activity information and resource security information of the target asset, which can improve the accuracy of determining the trust requirements of the target asset, thereby improving the rationality of authority allocation.

[0015] In a second aspect, the present application provides an asset access control device, which includes: a communication module, used to obtain an access request for accessing a target asset, the access request including a user identifier of an accessing user; a processing module, used to query a historical trust score of the accessing user based on the user identifier, and determine the credit level of the accessing user based on the historical trust score; the processing module is also used to determine a trust assessment strategy corresponding to the accessing user based on a correspondence between the credit level and the trust assessment strategy; the processing module is also used to perform a trust assessment on the accessing user based on the trust assessment strategy corresponding to the accessing user, and obtain the trust of the accessing user; the processing module is also used to generate a decision result based on the trust of the accessing user and the trust requirement of the target asset; the communication module is also used to send the decision result.

[0016] In a possible embodiment, the communication module is used to obtain evaluation results of multiple evaluation factors corresponding to the historical trust score of the visiting user; the processing module is also used to adjust the weights of the multiple evaluation factors based on a preset weight adjustment rule and the evaluation results.

[0017] In a possible embodiment, the trust of the visiting user is evaluated based on the trust evaluation strategy corresponding to the visiting user, and the processing module is specifically used to: perform trust evaluation on the visiting user based on the trust evaluation strategy corresponding to the visiting user and the weights of the multiple evaluation factors to obtain the trust of the visiting user.

[0018] In a possible embodiment, the multiple evaluation factors include at least one of identity information, Internet Protocol IP, location information, time information, and device security baseline.

[0019] In a possible embodiment, the processing module is further used to: determine the sensitivity level of the target asset based on the historical activity information and resource security information of the target asset; and determine the trust requirement of the target asset based on the correspondence between the sensitivity level and the trust requirement.

[0020] In a third aspect, the present application provides an electronic device, including:

[0021] A memory for storing program instructions;

[0022] The processor is used to call the program instructions stored in the memory, and execute the steps included in any one of the methods in the first aspect according to the obtained program instructions.

[0023] In a fourth aspect, the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a computer, the computer executes any one of the methods described in the first aspect.

[0024] In a fifth aspect, the present application provides a computer program product, comprising: a computer program code, when the computer program code is run on a computer, the computer executes any one of the methods described in the first aspect.

[0025] The technical effects brought about by the second to fifth aspects and any one of their designs can refer to the technical effects brought about by the corresponding designs in the first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS

[0026] Figure 1 A schematic diagram of an application scenario of an asset access control method provided in an embodiment of the present application;

[0027] Figure 2 A flowchart of a method for controlling asset access provided in an embodiment of the present application;

[0028] Figure 3 A flowchart of another asset access control method provided in an embodiment of the present application;

[0029] Figure 4 A schematic diagram of the structure of a control device for asset access provided in an embodiment of the present application;

[0030] Figure 5 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0031] In order to make the purpose, technical scheme and advantages of the present application clearer, the technical scheme in the embodiment of the present application will be clearly and completely described below in conjunction with the drawings in the embodiment of the present application. Obviously, the described embodiment is only a part of the embodiment of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in the field without making creative work are within the scope of protection of the present application. In the absence of conflict, the embodiments in the present application and the features in the embodiments can be arbitrarily combined with each other. In addition, although the logical order is shown in the flow chart, in some cases, the steps shown or described can be performed in an order different from that here.

[0032] The terms "first" and "second" in the specification and claims of the present application and the above-mentioned drawings are used to distinguish different objects, rather than to describe a specific order. In addition, the term "comprising" and any of their variations are intended to cover non-exclusive protection. For example, a process, method, system, product or device comprising a series of steps or units is not limited to the listed steps or units, but optionally also includes steps or units that are not listed, or optionally also includes other steps or units inherent to these processes, methods, products or devices. "Multiple" in the present application can mean at least two, for example, two, three or more, and the embodiments of the present application are not limited.

[0033] In the technical solution of this application, the collection, dissemination, and use of data are in compliance with the requirements of relevant national laws and regulations.

[0034] Before introducing the asset access control method provided in the embodiment of the present application, for ease of understanding, the scenario in which the embodiment of the present application is applied is first introduced in detail.

[0035] Figure 1 A schematic diagram of an application scenario of an asset access control method provided in an embodiment of the present application. Figure 1 As shown, the application scenario may include a terminal device 101, a trust evaluation device 02 and a server 103, wherein the terminal device 101 and the trust evaluation device 102 are connected via a network, and the trust evaluation device 102 and the server 103 are connected via a network. The trust evaluation device 102 may be used to evaluate the trust of accessing users and to manage the rights of terminal devices. When a user accesses the server 103 through his terminal device 101, he must first pass through the trust evaluation device 102, and the trust evaluation device 102 controls the user's access behavior.

[0036] The terminal device 101 may be, but is not limited to, a smart phone, a tablet computer, a laptop computer, a desktop computer, etc., and this application does not specifically limit this.

[0037] The trust evaluation device 102 may be a processing device for executing the method described in the present application, or may be a processing device in a computer system for executing the method described in the present application, such as a processor or a processing module, etc., which is not specifically limited in the present application.

[0038] Furthermore, based on the application scenario, the method provided by the present application includes: the trust assessment device can obtain an access request for accessing the target asset. The access request includes a user identifier of the accessing user. The trust assessment device can query the historical trust score of the accessing user based on the user identifier, and determine the credit rating of the accessing user based on the historical trust score. The trust assessment policy corresponding to the accessing user is determined based on the correspondence between the credit rating and the trust assessment policy. The trust assessment device can perform a trust assessment on the accessing user based on the trust assessment policy corresponding to the accessing user to obtain the trust of the accessing user. The trust assessment device can generate a decision result based on the trust of the accessing user and the trust requirement of the target asset. The trust assessment device can send the decision result.

[0039] It is understandable that, by adopting this method, the corresponding credit level is determined according to the user's historical trust score, and the user's trust is determined by credit evaluation based on the evaluation strategy corresponding to the credit level. The corresponding access decision result is determined based on the user's trust and the trust requirements of the target asset. Among them, when the user's trust is greater than or equal to the trust requirements of the target asset, the decision result generated is to release the user's access request. When the user's trust is less than the trust requirements of the target asset, the decision result generated is to intercept the user's access request. In other words, every time the user accesses the target asset, the user needs to be trusted, and the evaluation strategy for the user is determined based on the user's historical trust score, that is, different users can correspond to different evaluation strategies, which improves the flexibility of trust evaluation. Furthermore, the access decision result is determined based on the user's trust and the trust requirements of the target asset, so the rationality of the permission allocation method can be improved.

[0040] In addition, based on the above application scenarios, exemplary embodiments of the present application will be described in more detail below. It should be noted that the above application scenarios are only shown to facilitate understanding of the spirit and principles of the present application, and the implementation methods of the present application are not limited in any way. On the contrary, the implementation methods of the present application can be applied to any applicable scenario.

[0041] Figure 2 A flowchart of a method for controlling asset access provided by an embodiment of the present invention. Taking a trust evaluation device as an execution subject as an example, the process may include the following steps:

[0042] S201: A trust evaluation device obtains an access request for accessing a target asset, wherein the access request includes a user identifier of an accessing user.

[0043] In one or more embodiments, the access request for requesting access to the target asset may be triggered by the user according to the access requirement. For example, the user may trigger the target asset access option on the front page of the system through the input device of the terminal device (such as a mouse, keyboard, or touch screen), or trigger the access option in the application program, and when the operation of accessing the target asset option is detected, a corresponding access request for requesting access to the target asset may be generated.

[0044] Optionally, the access request may carry a user ID of the access user. For example, the first two bytes of the access request message are used to represent the user ID of the access user.

[0045] S202: The trust evaluation device queries the historical trust score of the accessing user based on the user identification, and determines the credit level of the accessing user according to the historical trust score.

[0046] The trust evaluation device may obtain multiple historical trust scores of the user based on the user identifier, and use the average of the multiple historical trust scores as the trust score of the user. For example, the average of the historical trust scores of the user within one month may be used as the trust score of the user. In addition, after obtaining the trust score of the user, the trust score may be stored.

[0047] In one or more embodiments, the trust evaluation device may obtain the first correspondence, and determine the historical trust score corresponding to the accessing user according to the first correspondence. The first correspondence may include a correspondence between a user identifier and a historical trust score, and / or a correspondence between a user, a user identifier, and a historical trust score. An example of the first correspondence is shown in Table 1.

[0048] user User ID Trust Rating User 1 01 85 User 2 02 95 User 3 03 90 …… …… ……

[0049] Table 1

[0050] As shown in Table 1, the first correspondence relationship may reflect the correspondence relationship between the user, the user identifier, and the trust score. When it is necessary to determine the trust score corresponding to the user, the trust evaluation device may query the first correspondence relationship shown in Table 1 according to the user identifier of the user to determine the trust score corresponding to the user identifier of the user. For example, if the user identifier is 01, the trust evaluation device may determine that the trust score corresponding to the user is 85.

[0051] Exemplarily, the trust evaluation device may pre-store the first correspondence, that is, the correspondence between the user and the trust score. Alternatively, the trust evaluation device may obtain the first correspondence, that is, the correspondence between the user and the trust score, from a storage device.

[0052] In one or more embodiments, the trust evaluation device may obtain the second correspondence, and determine the credit level corresponding to the trust score of the accessing user according to the second correspondence. The second correspondence may include a correspondence between the trust score and the credit level. An example of the second correspondence is shown in Table 2.

[0053] Trust Rating Credit rating 0-59 One star 60-69 Two Star 70-79 Samsung 80-89 Four Star 90-100 Five Star

[0054] Table 2

[0055] As shown in Table 2, the second correspondence relationship may reflect the correspondence relationship between the trust score and the credit level. When it is necessary to determine the credit level corresponding to the trust score, the trust evaluation device may query the second correspondence relationship shown in Table 1 according to the trust score of the user to determine the credit level corresponding to the trust score of the user. For example, if the trust score of user 1 is 85, the trust evaluation device may determine that the credit level corresponding to user 1 is four stars.

[0056] It is understandable that the specific manner in which the trust assessment device obtains the second corresponding relationship may refer to the specific manner in which the first corresponding relationship is obtained, and will not be described in detail herein.

[0057] S203: The trust evaluation device determines a trust evaluation policy corresponding to the access user according to the correspondence between the credit level and the trust evaluation policy.

[0058] In one or more embodiments, the trust evaluation device may obtain the third correspondence, and determine the trust evaluation policy corresponding to the access user according to the third correspondence. The third correspondence may include a correspondence between a credit rating and a trust evaluation policy, and / or a correspondence between a trust score, a credit rating, and a trust evaluation policy. An example of the third correspondence is shown in Table 3.

[0059]

[0060]

[0061] Table 3

[0062] As shown in Table 3, the third correspondence relationship can reflect the correspondence between the trust score, the credit level, and the trust assessment strategy. When it is necessary to determine the trust assessment strategy corresponding to the credit level, the trust assessment device can query the third correspondence relationship shown in Table 3 according to the user's credit level to determine the trust assessment strategy corresponding to the user's credit level. For example, if the credit level of user 1 is four stars, the trust assessment device can determine that the trust assessment strategy corresponding to user 1 is type 2. Alternatively, the trust assessment device can query the third correspondence relationship shown in Table 3 according to the user's trust score to determine the trust assessment strategy corresponding to the user's trust score. For example, if the trust score of user 1 is 85, the trust assessment device can determine that the trust assessment strategy corresponding to user 1 is type 2.

[0063] In one or more embodiments, different trust evaluation strategies correspond to different evaluation factors. Optionally, the evaluation factor may include at least one of user identity information, Internet protocol IP, location information, time information, and device security baseline. Among them, the user identity information may include user-bound devices, the location information may include login locations, the time information may include login time, and the device security baseline may include device open ports, device running software, and universal serial bus (USB) insertion.

[0064] Illustratively, Table 4 is a correspondence table between a trust evaluation strategy and evaluation factors provided in an embodiment of the present application.

[0065]

[0066]

[0067] Table 4

[0068] As shown in Table 4, when it is necessary to determine the evaluation factors corresponding to the trust evaluation policy, the trust evaluation device can query Table 4 according to the trust evaluation policy to determine the evaluation factors corresponding to the trust evaluation policy. For example, if the trust evaluation policy is type 1, the trust evaluation device can determine that the evaluation factors corresponding to the trust evaluation policy include user-bound device, login location, login time, device open port, device running software, and USB insertion.

[0069] S204: The trust evaluation device performs a trust evaluation on the accessing user based on a trust evaluation policy corresponding to the accessing user to obtain the trust of the accessing user.

[0070] In one or more embodiments, the trust evaluation device can obtain the evaluation results of multiple evaluation factors corresponding to the historical trust score of the accessing user. It is understandable that the historical trust score can be obtained by the scores of multiple evaluation factors and the weights corresponding to the evaluation factors. For example, multiple evaluation factors include: user-bound device, login location, login time, device open ports, device running software, and USB insertion. Among them, the score of the user-bound device is 98 and the weight is 0.2, the score of the login location is 95 and the weight is 0.2, the score of the login time is 94 and the weight is 0.2, the score of the device open port is 93 and the weight is 0.2, the score of the device running software is 60 and the weight is 0.1, and the score of the USB insertion is 60 and the weight is 0.1. The historical trust score and multiple evaluation factors satisfy:

[0071] 98*0.2+95*0.2+94*0.2+93*0.2+92*0.1+60*0.1=91.2.

[0072] That means a historical trust score of 91.2.

[0073] Furthermore, the trust evaluation device may adjust the weights of multiple evaluation factors according to preset weight adjustment rules and evaluation results.

[0074] As an example, the preset weight adjustment rule may be to reduce the weight of the highest-scoring evaluation factor among multiple evaluation factors, and increase the weight of the lowest-scoring evaluation factor among multiple evaluation factors. Taking the above example, the user-bound device has the highest score, and the USB plug-in has the lowest score, then the weight of the user-bound device is reduced, and the weight of the USB plug-in is increased. For example, the weight of the user-bound device may be adjusted from 0.2 to 0.1, and the weight of the USB plug-in may be adjusted from 0.1 to 0.2.

[0075] In one or more embodiments, the trust evaluation device may evaluate multiple evaluation factors of the access user based on the trust evaluation policy corresponding to the access user to obtain evaluation results of the multiple evaluation factors. The trust evaluation device may process the evaluation results of the multiple evaluation factors based on the weights of the multiple evaluation factors of the access user to obtain the trust of the access user.

[0076] S205: The trust evaluation device generates a decision result according to the trust level of the accessing user and the trust level requirement of the target asset.

[0077] In one or more embodiments, the trust assessment device may determine the sensitivity level of the target asset based on the historical activity information and resource security information of the target asset. The trust assessment device may determine the trust requirement of the target asset based on the correspondence between the sensitivity level and the trust requirement.

[0078] Illustratively, Table 5 is a correspondence table between sensitivity levels and trust requirements provided in an embodiment of the present application.

[0079] Asset Type Sensitivity Level Trust Requirements A middle 80 B high 90 C Low 70

[0080] Table 5

[0081] As shown in Table 5, the correspondence table between sensitivity level and trust requirement can reflect the correspondence between asset type, sensitivity level and trust requirement. When it is necessary to determine the trust requirement of the target asset, the trust assessment device can query Table 5 according to the sensitivity level of the target asset to determine the trust requirement of the target asset. For example, if the type of the target asset is A, the trust assessment device can determine that the sensitivity level of the target asset is heavy, and the corresponding trust requirement is 80 points.

[0082] In one or more embodiments, the trust assessment device may generate a corresponding decision result based on the trust of the accessing user and the trust requirement of the target asset. That is, when the trust of the accessing user is greater than or equal to the trust requirement of the target asset, the decision result generated by the trust assessment device may be to allow access. When the trust of the accessing user is less than the trust requirement of the target asset, the decision result generated by the trust assessment device may be to prohibit access.

[0083] S206: The trust evaluation device sends a decision result.

[0084] Optionally, the trust evaluation device may send the decision result to the terminal device. Accordingly, the user may obtain the decision result through the terminal.

[0085] Optionally, the trust evaluation device may send a decision result to the server. Accordingly, the server may provide corresponding services to the terminal device according to the decision result.

[0086] The asset access control method provided by the present application is further described below through Example 1. Among them, Example 1 includes a trust assessment module, a permission policy module and a policy execution module. Among them, the trust assessment module can be used to perform continuous trust assessment on the accessing user based on the identity information, environmental information and other information of the accessing user. The permission policy module can be used to determine whether the user is allowed to access the target asset based on the current trust score of the accessing user and the access requirements of the target asset, and issue the corresponding policy results. The policy execution module can be used to execute the policy issued by the permission policy module. For example, according to the instructions issued by the permission policy module, user access is allowed or denied.

[0087] The specific contents of Example 1 are as follows:

[0088] Figure 3 A flowchart of a method for controlling asset access provided in an embodiment of the present application. Figure 3 As shown, with the terminal device, trust assessment module, authority policy module and policy execution module as the execution subjects, the process includes the following steps:

[0089] S301: The terminal device initiates a target resource access request. Correspondingly, the trust evaluation module receives the target resource access request.

[0090] S302: The trust evaluation module determines the user's credit rating based on the average trust score of the user within one month.

[0091] S303: The authority policy module determines an evaluation policy corresponding to the user's credit rating based on the policy model.

[0092] The policy model may include three levels of policies: high, medium, and low. Among them, the high-level policy corresponds to users with extremely low historical trust, the medium-level policy corresponds to users with average historical trust, and the low-level policy corresponds to users with extremely good historical trust.

[0093] S304, the trust evaluation module dynamically adjusts the weight of the evaluation factor according to the credit evaluation result of the user within one month.

[0094] S305: The trust evaluation module processes the scores of each evaluation factor of the user based on the weight to determine the credit score of the user.

[0095] S306, the trust assessment module dynamically adjusts the sensitivity level of the target asset according to the activity of the target asset within one month and the current security level.

[0096] S307, the authority policy module generates a decision result based on the user's credit score and the minimum credit score corresponding to the sensitivity level of the target asset.

[0097] When the user's credit score is greater than or equal to the minimum credit score corresponding to the sensitivity level of the target asset, the generated decision result is to allow the user's access request. When the user's credit score is less than the minimum credit score corresponding to the sensitivity level of the target asset, the generated decision result is to block the user's access request.

[0098] S308, the policy execution module executes the decision result.

[0099] Based on the same inventive concept, an embodiment of the present application provides a control device for asset access. Figure 4 A schematic diagram of the structure of a control device for asset access provided by an embodiment of the present application is shown. Figure 4 As shown, the device includes a communication module 401 and a processing module 402 .

[0100] The communication module 401 is used to obtain an access request for accessing a target asset, and the access request includes a user identifier of an accessing user. The processing module 402 is used to query the historical trust score of the accessing user based on the user identifier, and determine the credit level of the accessing user based on the historical trust score. The processing module 402 is also used to determine the trust assessment policy corresponding to the accessing user based on the correspondence between the credit level and the trust assessment policy. The processing module 402 is also used to perform a trust assessment on the accessing user based on the trust assessment policy corresponding to the accessing user, and obtain the trust of the accessing user. The processing module 402 is also used to generate a decision result based on the trust of the accessing user and the trust requirement of the target asset. The communication module 401 is also used to send the decision result.

[0101] In a possible embodiment, the communication module 401 is used to obtain the evaluation results of multiple evaluation factors corresponding to the historical trust score of the access user. The processing module 402 is also used to adjust the weights of the multiple evaluation factors based on a preset weight adjustment rule and the evaluation results.

[0102] In a possible embodiment, a trust evaluation is performed on the visiting user based on the trust evaluation strategy corresponding to the visiting user, and the processing module 402 is specifically used to: perform a trust evaluation on the visiting user based on the trust evaluation strategy corresponding to the visiting user and the weights of the multiple evaluation factors to obtain the trust of the visiting user.

[0103] In a possible embodiment, the multiple evaluation factors include at least one of identity information, Internet Protocol (IP), location information, time information, and device security baseline.

[0104] In a possible embodiment, the processing module 402 is further configured to: determine the sensitivity level of the target asset according to the historical activity information and resource security information of the target asset, and determine the trust requirement of the target asset according to the corresponding relationship between the sensitivity level and the trust requirement.

[0105] Based on the same inventive concept, an embodiment of the present application provides an electronic device that can implement the functions of the asset access control device discussed above. Figure 5 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application is shown.

[0106] The electronic device in the embodiment of the present application may include a processor 501. The processor 501 is the control center of the device, and various interfaces and lines can be used to connect various parts of the device, by running or executing instructions stored in the memory 503 and calling data stored in the memory 503. Optionally, the processor 501 may include one or more processing units, and the processor 501 may integrate an application processor and a modem processor, wherein the application processor mainly processes operating systems and application programs, etc., and the modem processor mainly processes wireless communications. It is understandable that the above-mentioned modem processor may not be integrated into the processor 501. In some embodiments, the processor 501 and the memory 503 may be implemented on the same chip, and in some embodiments, they may also be implemented separately on independent chips.

[0107] The processor 501 may be a general-purpose processor, such as a central processing unit (CPU), a digital signal processor, an application-specific integrated circuit, a field programmable gate array or other programmable logic device, a discrete gate or transistor logic device, or a discrete hardware component, and may implement or execute the methods, steps, and logic block diagrams disclosed in the embodiments of the present application. A general-purpose processor may be a microprocessor or any conventional processor, etc. The method steps disclosed in the embodiments of the present application may be directly executed by a hardware processor, or may be executed by a combination of hardware and software modules in the processor.

[0108] In the embodiment of the present application, the memory 503 stores instructions that can be executed by at least one processor 501. The at least one processor 501 can be used to execute the method steps disclosed in the embodiment of the present application by executing the instructions stored in the memory 503.

[0109] The memory 503 is a non-volatile computer-readable storage medium, which can be used to store non-volatile software programs, non-volatile computer executable programs and modules. The memory 503 may include at least one type of storage medium, such as a flash memory, a hard disk, a multimedia card, a card-type memory, a random access memory (Random Access Memory, RAM), a static random access memory (Static Random Access Memory, SRAM), a programmable read-only memory (Programmable Read Only Memory, PROM), a read-only memory (Read Only Memory, ROM), an electrically erasable programmable read-only memory (Electrically Erasable Programmable Read-Only Memory, EEPROM), a magnetic memory, a disk, an optical disk, etc. The memory 503 is any other medium that can be used to carry or store a desired program code in the form of an instruction or data structure and can be accessed by a computer, but is not limited thereto. The memory 503 in the embodiment of the present application can also be a circuit or any other device that can realize a storage function, for storing program instructions and / or data.

[0110] In the embodiment of the present application, the device may further include a communication interface 502 , through which the electronic device may transmit data.

[0111] Optional, can be Figure 5 The processor 501 (or the processor 501 and the communication interface 502) implements Figure 4 The processing module 402 and / or the communication module 401 shown, that is, the actions of the processing module 402 and / or the communication module 401 can be executed by the processor 501 (or the processor 501 and the communication interface 502).

[0112] Based on the same inventive concept, the embodiment of the present application also provides a computer-readable storage medium, which may store instructions. When the instructions are executed on a computer, the computer executes the operation steps provided in the above method embodiment. The computer-readable storage medium may be Figure 5 The memory 503 is shown.

[0113] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that include computer-usable program code.

[0114] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0115] These computer program instructions may also be stored in a computer-readable memory capable of directing a computer or other programmable data processing device to operate in a specific manner, so that the instructions stored in the computer-readable memory produce an article of manufacture comprising an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 A function specified in one or more boxes.

[0116] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for implementing the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0117] Obviously, those skilled in the art can make various changes and modifications to the present application without departing from the spirit and scope of the present application. Thus, if these modifications and variations of the present application fall within the scope of the claims of the present application and their equivalents, the present application is also intended to include these modifications and variations.

Claims

1. A method for controlling asset access, characterized in that: The method comprises: Obtaining an access request for accessing a target asset, wherein the access request includes a user identifier of an accessing user; querying the historical trust score of the accessing user based on the user identifier, and determining the credit rating of the accessing user according to the historical trust score; Determining the trust evaluation strategy corresponding to the access user according to the correspondence between the credit rating and the trust evaluation strategy; Performing a trust evaluation on the access user based on the trust evaluation strategy corresponding to the access user to obtain the trust of the access user; Generate a decision result according to the trust level of the accessing user and the trust level requirement of the target asset; The decision result is sent.

2. The method according to claim 1, characterized in that The method further comprises: Obtaining evaluation results of multiple evaluation factors corresponding to the historical trust scores of the accessing user; Based on the preset weight adjustment rule and the evaluation result, the weights of the multiple evaluation factors are adjusted.

3. The method according to claim 2, characterized in that The method of performing trust evaluation on the access user based on the trust evaluation strategy corresponding to the access user comprises: The trust of the accessing user is evaluated based on the trust evaluation strategy corresponding to the accessing user and the weights of the multiple evaluation factors to obtain the trust of the accessing user.

4. The method according to claim 2 or 3, characterized in that The multiple evaluation factors include at least one of identity information, Internet Protocol (IP), location information, time information, and device security baseline.

5. The method according to claim 1, characterized in that The method further comprises: Determine the sensitivity level of the target asset based on the historical activity information and resource security information of the target asset; The trust requirements of the target assets are determined based on the corresponding relationship between the sensitivity levels and the trust requirements.

6. A control device for asset access, characterized in that: The device comprises: A communication module, used to obtain an access request for accessing a target asset, wherein the access request includes a user identifier of an accessing user; A processing module, configured to query the historical trust score of the accessing user based on the user identification, and determine the credit rating of the accessing user according to the historical trust score; The processing module is further used to determine the trust evaluation strategy corresponding to the access user according to the corresponding relationship between the credit level and the trust evaluation strategy; The processing module is further used to perform a trust evaluation on the accessing user based on the trust evaluation strategy corresponding to the accessing user to obtain the trust of the accessing user; The processing module is further used to generate a decision result according to the trust level of the accessing user and the trust level requirement of the target asset; The communication module is also used to send the decision result.

7. The device according to claim 6, characterized in that The device also includes: A communication module, used to obtain evaluation results of multiple evaluation factors corresponding to the historical trust score of the accessing user; The processing module is further used to adjust the weights of the multiple evaluation factors based on a preset weight adjustment rule and the evaluation result.

8. The device according to claim 7, characterized in that The trust evaluation of the access user is performed based on the trust evaluation strategy corresponding to the access user, and the processing module is specifically used for: The trust of the accessing user is evaluated based on the trust evaluation strategy corresponding to the accessing user and the weights of the multiple evaluation factors to obtain the trust of the accessing user.

9. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program includes program instructions, and when the program instructions are executed by a computer, the computer executes the method according to any one of claims 1 to 5.

10. A computer program product, characterized in that The computer program product comprises: a computer program code, and when the computer program code is run on a computer, the computer is enabled to execute the method according to any one of claims 1 to 5.