Risk perception and control method and device based on zero-trust strategy

By adopting a risk perception and control method based on a zero-trust strategy in the government external network, the problem of lack of authentication mechanism and security control in the access area of ​​the government external network is solved, and effective control of illegal users and unsafe terminals is achieved, and network security is improved.

CN120017389APending Publication Date: 2025-05-16GUANGDONG PLANNING & DESIGNING INST OF TELECOMM
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510201857.8
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-21
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

The existing government affairs external network lacks a network access authentication mechanism and terminal security control system in the network access area, resulting in a significant increase in the risk of illegal users or unsafe terminals accessing government affairs external networks, threatening network security.

Method used

The risk perception and control method based on the zero-trust strategy is adopted, and the risk perception information is detected when the user accesses the target application, and inputs it into the preset zero-trust trustworthy scoring model for calculation, determines the user's trustworthy scoring results, and determines the access control policy based on the preset trustworthy scoring threshold information, and performs secure access control operations.

Benefits of technology

An authentication mechanism for network access has been established, which reduces the security risks of illegal users or unsafe terminals accessing government external networks and improves the overall security and stability of government external networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017389A_ABST
    Figure CN120017389A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of network security, and discloses a risk perception and management and control method and device based on a zero-trust policy, and the method comprises the steps: obtaining risk perception information corresponding to a user when the user is detected to access a target application, inputting the risk perception information into a preset zero-trust credible scoring model for calculation, and obtaining a target application; and obtaining a credibility scoring result corresponding to the user output by the zero-credibility credibility scoring model, obtaining preset credibility scoring threshold information, determining an access control strategy for the user according to the credibility scoring threshold information and the credibility scoring result, and executing a security access control operation on the user based on the access control strategy. Visibly, by implementing the invention, a network access authentication mechanism can be established, the security risk that illegal users or unsafe terminals access the government affair extranet is reduced, and the security and reliability of the government affair extranet can be globally improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a risk perception and control method and device based on a zero-trust strategy. Background Art

[0002] In today's digital age, the application of digital government e-government continues to develop in depth, and has become a key support force for government departments at all levels to achieve efficient operation, innovate management models, and optimize the quality of public services. With the continuous emergence of cutting-edge technologies and emerging applications such as the new generation of mobile communications, the Internet of Things, cloud computing, and big data, government service objects are becoming more and more Internet-oriented, application methods are becoming more mobile, and service needs are becoming more diverse. These significant trends have brought both new opportunities and many challenges for digital government to promote the standardized, intensive, and scientific development of e-government. In particular, as the business carried by the government extranet becomes increasingly complex, ensuring the stable operation of the network and the safe development of business has become increasingly important for the government extranet.

[0003] However, at present, the government extranets in some cities and prefectures across the country have obvious defects in the network access area. On the one hand, the network access authentication mechanism is missing, and the access terminals of various access units may have system vulnerabilities, no anti-virus software installed, and other security risks. Moreover, they can access the Internet or business private network at will without authentication, which greatly increases the risk of illegal users or unsafe terminals accessing the government extranet, posing a potential threat to network security. On the other hand, the lack of a complete terminal security management and control system makes it difficult to effectively ensure the overall security and stability of the government extranet. Therefore, it is particularly important to propose a technical solution that can improve the security of the government extranet in a global manner. Summary of the invention

[0004] The present invention provides a risk perception and control method and device based on a zero-trust strategy, which can improve the security of government extranets globally.

[0005] In order to solve the above technical problems, the first aspect of the present invention discloses a risk perception and control method based on a zero-trust strategy, the method comprising:

[0006] When it is detected that a user accesses a target application, risk perception information corresponding to the user is obtained;

[0007] Inputting the risk perception information into a preset zero-trust trusted scoring model for calculation, and obtaining a trusted scoring result corresponding to the user output by the zero-trust trusted scoring model;

[0008] Acquire preset trust score threshold information, determine an access control policy for the user according to the trust score threshold information and the trust score result, and perform a security access control operation on the user based on the access control policy.

[0009] As an optional implementation, in the first aspect of the present invention, when it is detected that a user accesses a target application, obtaining risk perception information corresponding to the user includes:

[0010] When it is detected that a user accesses a target application, user access perception information corresponding to the user is obtained, wherein the user access perception information includes user behavior perception information, terminal environment perception information, and network environment perception information;

[0011] Analyze the user access perception information to determine at least one risk event corresponding to the user access perception information and a risk characterization coefficient corresponding to each risk event;

[0012] For each of the risk events, determine whether the risk table integral coefficient corresponding to the risk event meets the preset risk determination condition, and when the risk table integral coefficient corresponding to the risk event meets the risk determination condition, determine that the risk event is a target risk event;

[0013] According to each of the target risk events, risk perception information corresponding to the user is determined, and the risk perception information includes at least one of a user behavior risk event, a terminal environment risk event, and a network environment risk event.

[0014] As an optional implementation manner, in the first aspect of the present invention, determining the access control policy for the user according to the trust score threshold information and the trust score result includes:

[0015] Determine a plurality of credible score threshold ranges according to the credible score threshold information, and determine a target credible score threshold range to which the credible score result belongs within each of the credible score threshold ranges;

[0016] Establishing a logical connection between the client and the server, and generating an access credential for the user based on the logical connection;

[0017] An access control policy for the user is determined based on the logical connection, the access credential, and the target trust score threshold range.

[0018] As an optional implementation manner, in the first aspect of the present invention, performing a security access control operation on the user based on the access control policy includes:

[0019] Determine the network type of the user accessing the target application, the network type including the Internet type or the government extranet type;

[0020] When the network type includes the Internet type, performing a first security check on the user through a metropolitan area network boundary to obtain a first security check result;

[0021] When the network type includes the government extranet type, controlling the user's access to the government extranet according to the access control policy and proxy encryption through a zero-trust security gateway, and performing a second security check on the user through the metropolitan area network boundary to obtain a second security check result;

[0022] The user is controlled to access the target application according to the first security detection result or the second security detection result.

[0023] As an optional embodiment, in the first aspect of the present invention, the method further comprises:

[0024] Before the user accesses the target application, the service port of the target application is hidden based on the application proxy to achieve network invisibility of the target application;

[0025] Detecting a single-packet authentication request sent by the user through a preset zero-trust client, and performing a single-packet verification on the user based on the single-packet authentication request to obtain a verification result;

[0026] When the verification result meets the preset verification pass condition, the business forwarding port corresponding to the target application is opened to the user through the zero-trust security gateway, and the business forwarding port is used for the user to access the service port of the target application.

[0027] As an optional embodiment, in the first aspect of the present invention, the method further comprises:

[0028] When it is detected that the user downloads the target data in the target application through the service forwarding port, determining the user authority of the user and the data authority of the target data;

[0029] Determine whether the user authority and the data authority match, and when the user authority and the data authority match, encrypt and encapsulate the target data to obtain a data encryption package corresponding to the target data, wherein the data encryption package includes the target data, data identification information corresponding to the target data, and a destination address;

[0030] Sending the data encryption package to the zero-trust security gateway, decrypting the data encryption package through the zero-trust security gateway, and performing data verification according to the data authentication information to obtain a verification result;

[0031] When the data verification result meets the preset data verification pass condition, the target data is forwarded to the user according to the destination address through the zero-trust security gateway.

[0032] As an optional embodiment, in the first aspect of the present invention, the method further comprises:

[0033] When it is detected that a target service is published in the target application, determining a service type of the target service, wherein the service type includes a public service type or a sensitive service type;

[0034] When the service type of the target service includes the sensitive service type, determining an access permission condition corresponding to the target service, the access permission condition including at least one of a terminal condition, a user identity condition, and a network condition;

[0035] Generate a restricted access control policy for the target service according to the access permission condition, and publish the target service in the target application based on the restricted access control policy;

[0036] When the service type of the target service includes the public service type, the target service is released in the target application based on a preset full-range release and launch principle.

[0037] A second aspect of the present invention discloses a risk perception and control device based on a zero-trust strategy, the device comprising:

[0038] An acquisition module, used to acquire risk perception information corresponding to a user when it is detected that the user accesses a target application;

[0039] A calculation module, used for inputting the risk perception information into a preset zero-trust trusted scoring model for calculation, and obtaining a trusted scoring result corresponding to the user output by the zero-trust trusted scoring model;

[0040] The acquisition module is further used to acquire preset trustworthy score threshold information;

[0041] A determination module is used to determine an access control policy for the user according to the trust score threshold information and the trust score result, and perform a security access control operation on the user based on the access control policy.

[0042] As an optional implementation, in the second aspect of the present invention, when the acquisition module detects that the user accesses the target application, the manner in which the risk perception information corresponding to the user is acquired specifically includes:

[0043] When it is detected that a user accesses a target application, user access perception information corresponding to the user is obtained, wherein the user access perception information includes user behavior perception information, terminal environment perception information, and network environment perception information;

[0044] Analyze the user access perception information to determine at least one risk event corresponding to the user access perception information and a risk characterization coefficient corresponding to each risk event;

[0045] For each of the risk events, determine whether the risk table integral coefficient corresponding to the risk event meets the preset risk determination condition, and when the risk table integral coefficient corresponding to the risk event meets the risk determination condition, determine that the risk event is a target risk event;

[0046] According to each of the target risk events, risk perception information corresponding to the user is determined, and the risk perception information includes at least one of a user behavior risk event, a terminal environment risk event, and a network environment risk event.

[0047] As an optional implementation, in the second aspect of the present invention, the determination module determines the access control policy for the user according to the trust score threshold information and the trust score result, specifically including:

[0048] Determine a plurality of credible score threshold ranges according to the credible score threshold information, and determine a target credible score threshold range to which the credible score result belongs within each of the credible score threshold ranges;

[0049] Establishing a logical connection between the client and the server, and generating an access credential for the user based on the logical connection;

[0050] An access control policy for the user is determined based on the logical connection, the access credential, and the target trust score threshold range.

[0051] As an optional implementation, in the second aspect of the present invention, the manner in which the determination module performs the security access control operation on the user based on the access control policy specifically includes:

[0052] Determine the network type of the user accessing the target application, the network type including the Internet type or the government extranet type;

[0053] When the network type includes the Internet type, performing a first security check on the user through a metropolitan area network boundary to obtain a first security check result;

[0054] When the network type includes the government extranet type, controlling the user's access to the government extranet according to the access control policy and proxy encryption through a zero-trust security gateway, and performing a second security check on the user through the metropolitan area network boundary to obtain a second security check result;

[0055] The user is controlled to access the target application according to the first security detection result or the second security detection result.

[0056] As an optional implementation, in the second aspect of the present invention, the device further includes:

[0057] A hiding module, used for hiding the service port of the target application based on an application proxy before the user accesses the target application to achieve network invisibility of the target application;

[0058] A detection module, used to detect a single-packet authentication request sent by the user through a preset zero-trust client, and perform a single-packet verification on the user based on the single-packet authentication request to obtain a verification result;

[0059] An opening module is used to open the business forwarding port corresponding to the target application to the user through the zero-trust security gateway when the verification result meets the preset verification pass condition, and the business forwarding port is used for the user to access the service port of the target application.

[0060] As an optional implementation, in the second aspect of the present invention, the detection module is further used to determine the user authority of the user and the data authority of the target data when detecting that the user downloads the target data in the target application through the service forwarding port;

[0061] The device also includes:

[0062] A judgment module, used to judge whether the user authority and the data authority match, and when the user authority and the data authority match, encrypt and encapsulate the target data to obtain a data encryption package corresponding to the target data, wherein the data encryption package includes the target data, data identification information corresponding to the target data, and a destination address;

[0063] A sending module, used for sending the data encryption package to the zero-trust security gateway, decrypting the data encryption package through the zero-trust security gateway, and performing data verification according to the data authentication information to obtain a verification result;

[0064] A forwarding module is used to forward the target data to the user according to the destination address through the zero-trust security gateway when the data verification result meets the preset data verification pass condition.

[0065] As an optional implementation, in the second aspect of the present invention, the determination module is further used to determine the service type of the target service when it is detected that the target service is published in the target application, and the service type includes a public service type or a sensitive service type;

[0066] The determination module is further configured to determine, when the service type of the target service includes the sensitive service type, an access permission condition corresponding to the target service, wherein the access permission condition includes at least one of a terminal condition, a user identity condition, and a network condition;

[0067] The device also includes:

[0068] A generating module, used for generating a restricted access control policy for the target service according to the access permission condition;

[0069] A publishing module, used for publishing the target service in the target application based on the restricted access control policy;

[0070] The publishing module is further configured to publish the target service in the target application based on a preset full-range publishing and online principle when the service type of the target service includes the public service type.

[0071] The third aspect of the present invention discloses another risk perception and control device based on a zero-trust strategy, the device comprising:

[0072] A memory storing executable program code;

[0073] a processor coupled to the memory;

[0074] The processor calls the executable program code stored in the memory to execute the risk perception and control method based on zero trust strategy disclosed in the first aspect of the present invention.

[0075] The fourth aspect of the present invention discloses a computer storage medium, which stores computer instructions. When the computer instructions are called, they are used to execute the risk perception and control method based on the zero trust strategy disclosed in the first aspect of the present invention.

[0076] Compared with the prior art, the embodiments of the present invention have the following beneficial effects:

[0077] In an embodiment of the present invention, when a user is detected accessing a target application, the risk perception information corresponding to the user is obtained, the risk perception information is input into a preset zero-trust trusted scoring model for calculation, and the trusted scoring result corresponding to the user output by the zero-trust trusted scoring model is obtained, and the preset trusted scoring threshold information is obtained, and the access control policy for the user is determined based on the trusted scoring threshold information and the trusted scoring result, and a secure access control operation is performed on the user based on the access control policy. It can be seen that the implementation of the present invention can establish an authentication mechanism for network access, reduce the security risks of illegal users or unsafe terminals accessing the government extranet, and can improve the security and reliability of the government extranet globally. BRIEF DESCRIPTION OF THE DRAWINGS

[0078] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.

[0079] Figure 1 It is a flow chart of a risk perception and control method based on a zero-trust strategy disclosed in an embodiment of the present invention;

[0080] Figure 2 It is a flow chart of another risk perception and control method based on zero trust strategy disclosed in an embodiment of the present invention;

[0081] Figure 3 It is a structural schematic diagram of a risk perception and control device based on a zero-trust strategy disclosed in an embodiment of the present invention;

[0082] Figure 4 It is a structural schematic diagram of another risk perception and control device based on zero trust strategy disclosed in an embodiment of the present invention;

[0083] Figure 5 It is a structural schematic diagram of another risk perception and control device based on zero trust strategy disclosed in an embodiment of the present invention. DETAILED DESCRIPTION

[0084] In order to enable those skilled in the art to better understand the scheme of the present invention, the technical scheme in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.

[0085] The terms "first", "second", etc. in the specification and claims of the present invention and the above-mentioned drawings are used to distinguish different objects rather than to describe a specific order. In addition, the terms "including" and "having" and any variations thereof are intended to cover non-exclusive inclusions. For example, a process, method, device, product or end including a series of steps or units is not limited to the listed steps or units, but may optionally include steps or units that are not listed, or may optionally include other steps or units inherent to these processes, methods, products or ends.

[0086] Reference to "embodiments" herein means that a particular feature, structure, or characteristic described in conjunction with the embodiments may be included in at least one embodiment of the present invention. The appearance of the phrase in various places in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment that is mutually exclusive with other embodiments. It is explicitly and implicitly understood by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0087] The present invention discloses a risk perception and control method and device based on a zero-trust strategy, which can establish a network access authentication mechanism, reduce the security risk of illegal users or unsafe terminals accessing the government extranet, and improve the security and reliability of the government extranet in a global manner. The following are detailed descriptions.

[0088] Embodiment 1

[0089] See also Figure 1 , Figure 1 This is a flow chart of a risk perception and control method based on a zero-trust strategy disclosed in an embodiment of the present invention. Figure 1 The described risk perception and control method based on zero trust strategy can be applied to a risk perception and control device based on zero trust strategy, and the risk perception and control device based on zero trust strategy can be constructed based on zero trust security architecture. Specifically, the risk perception and control device based on zero trust strategy can include an intelligent server or intelligent platform for implementing zero trust dynamic protection for target applications. The intelligent server includes a local server or a cloud server, which is not limited in the embodiments of the present invention. Figure 1 As shown, the risk perception and control method based on the zero trust strategy may include the following operations:

[0090] 101. When it is detected that a user accesses a target application, the risk perception information corresponding to the user is obtained.

[0091] In an embodiment of the present invention, optionally, the target application may include a smart application. Specifically, the smart application includes but is not limited to one-stop service, one-network management, collaborative office and other digital urban management applications. In the overall architecture of the smart city zero trust, the smart application can be separated from the front and back ends based on the microservice architecture. The smart application (front end) is responsible for the interface display of the application, that is, the application page seen by the user from the client, and the smart application (back end) is responsible for the business logic processing of the application, such as API interface, data, etc. For the scenario where the front and back ends of the smart application are separated, the hierarchical management and control of the front and back ends of the smart application can be achieved through trusted access agents and trusted API agents.

[0092] In the embodiment of the present invention, the front-end and back-end of the smart application can be optionally constructed based on the zero-trust security architecture and the design principles of the zero-trust technology of the smart city. The overall zero-trust architecture of the smart city should include content modules such as risk perception, zero-trust policy engine, zero-trust policy management, and zero-trust policy execution points, and realize zero-trust dynamic protection through docking with smart applications, identity management and access control. Identity management and access control is a platform for managing natural persons and application systems, and manages the organizations, roles, positions, identities, accounts, permissions, authentications, etc. of personnel in various dimensions throughout their life cycle.

[0093] In an embodiment of the present invention, optionally, the risk perception information corresponding to the user may include risk perception information of multiple aspects such as user behavior, terminal environment, and network environment during the user's access to the target application, which is not limited by the present invention.

[0094] 102. Input the risk perception information into a preset zero-trust trusted scoring model for calculation, and obtain a trusted scoring result corresponding to the user output by the zero-trust trusted scoring model.

[0095] In an embodiment of the present invention, optionally, the risk perception information can be input into a preset zero-trust trusted scoring model for calculation. Specifically, the risk perception information can be input into a zero-trust policy engine. The zero-trust policy engine is used for trusted assessment when a user accesses an application. The zero-trust policy engine aggregates risk events such as user behavior, terminal environment, and network environment, calculates the user's trusted score based on the zero-trust trusted scoring model, obtains the trusted score result corresponding to the user output by the zero-trust trusted scoring model, and sends the trusted score result to the zero-trust policy management, which is not limited by the present invention.

[0096] 103. Obtain preset trust score threshold information, determine an access control policy for the user based on the trust score threshold information and the trust score result, and perform a security access control operation on the user based on the access control policy.

[0097] In an embodiment of the present invention, optionally, the preset trust score threshold information may include multiple trust score threshold ranges, and the access control policy for the user can be determined based on the trust score threshold information and the trust score result. Specifically, the zero trust policy management receives the user's trust score from the zero trust policy engine, determines the access control policy based on the trust score threshold, and sends the access control policy to the corresponding zero trust policy execution point for execution, which is not limited by the present invention.

[0098] It can be seen that implementation Figure 1 The described risk perception and control method based on zero-trust strategy can obtain the risk perception information corresponding to the user when it is detected that the user accesses the target application, input the risk perception information into the preset zero-trust trusted scoring model for calculation, obtain the trusted scoring result corresponding to the user output by the zero-trust trusted scoring model, obtain the preset trusted scoring threshold information, and determine the access control policy for the user based on the trusted scoring threshold information and the trusted scoring result, and perform security access control operations on the user based on the access control policy, so as to establish a network access authentication mechanism, reduce the security risks of illegal users or insecure terminals accessing the government extranet, and improve the security and reliability of the government extranet globally.

[0099] Embodiment 2

[0100] See also Figure 2 , Figure 2 This is a flow chart of a risk perception and control method based on a zero-trust strategy disclosed in an embodiment of the present invention. Figure 2 The described risk perception and control method based on zero trust strategy can be applied to a risk perception and control device based on zero trust strategy, and the risk perception and control device based on zero trust strategy can be constructed based on zero trust security architecture. Specifically, the risk perception and control device based on zero trust strategy can include an intelligent server or intelligent platform for implementing zero trust dynamic protection for target applications. The intelligent server includes a local server or a cloud server, which is not limited in the embodiments of the present invention. Figure 2 As shown, the risk perception and control method based on the zero trust strategy may include the following operations:

[0101] 201. When it is detected that a user accesses a target application, user access perception information corresponding to the user is obtained.

[0102] In an embodiment of the present invention, optionally, the user access perception information may include user behavior perception information, terminal environment perception information and network environment perception information. Specifically, the user behavior perception information may include login behavior, operation behavior, etc. when the user accesses the target application, the terminal environment perception information may include device software status, device hardware status, device positioning information, etc., and the network environment perception information may include network type information, network connection status, network protocol information, etc., which are not limited by the present invention.

[0103] 202. Analyze the user access perception information to determine at least one risk event corresponding to the user access perception information and a risk representation coefficient corresponding to each risk event.

[0104] In the embodiment of the present invention, optionally, the risk event may include one or more combinations of user behavior risk events, terminal environment risk events, and network environment risk events, wherein user behavior risk events may include one or more combinations of abnormal login events, abnormal operation events, and abnormal behavior pattern events, terminal environment risk events may include one or more combinations of abnormal device security status events, abnormal device hardware events, and abnormal terminal location events, and network environment risk events may include one or more combinations of abnormal network connection events, abnormal network traffic events, and abnormal network protocol events; taking user behavior risk events as an example, abnormal login behavior: such as logging into the same account multiple times in different geographical locations in a short period of time, for example, an account logs in from two cities far apart within a few minutes, which may be a sign of account theft; frequent logins during non-working hours or non-habitual times, if one A user usually only uses the system between 9:00 and 17:00 on weekdays, but a large number of logins occur in the early morning, which may pose a risk; abnormal operation behavior: a large number of repeated operations on a certain function may be a malicious attack or an automated script performing brute force cracking operations, such as constantly trying to change the password in a short period of time or frequently submitting the same form content; functions or data beyond the access rights, for example, an ordinary user frequently tries to access sensitive data that only administrators can view, such as system configuration files or other users' private information; abnormal behavior patterns: inconsistent with previous operating habits, if the user usually completes the business process step by step in sequence, but suddenly skips key steps or reverses the operation, there may be security risks; abnormal operation speed, for example, normal users need a certain amount of time to read and enter information when filling out a form, but if a complex form is completed instantly, it may be an automated tool.

[0105] In an embodiment of the present invention, optionally, the risk characterization coefficient corresponding to each risk event can represent the risk level or danger degree of the risk event. The higher the risk characterization coefficient, the higher the risk level, which is not limited in the present invention.

[0106] 203. For each risk event, determine whether the risk table integral coefficient corresponding to the risk event meets the preset risk determination conditions. When the risk table integral coefficient corresponding to the risk event meets the risk determination conditions, determine that the risk event is a target risk event.

[0107] In an embodiment of the present invention, optionally, for each risk event, it is determined whether the risk table integral coefficient corresponding to the risk event meets a preset risk determination condition, for example, it is determined whether the risk table integral coefficient corresponding to the risk event is greater than a preset risk threshold. When the risk table integral coefficient corresponding to the risk event meets the risk determination condition, the risk event is determined to be a target risk event, that is, an event that affects the user's trust.

[0108] 204. Determine risk perception information corresponding to the user based on each target risk event.

[0109] In the embodiment of the present invention, optionally, the risk perception information may include at least one of a user behavior risk event, a terminal environment risk event, and a network environment risk event.

[0110] 205. Input the risk perception information into a preset zero-trust trusted scoring model for calculation, and obtain a trusted scoring result corresponding to the user output by the zero-trust trusted scoring model.

[0111] 206. Obtain preset trust score threshold information, determine an access control policy for the user according to the trust score threshold information and the trust score result, and perform a security access control operation on the user based on the access control policy.

[0112] In the embodiment of the present invention, for other descriptions of step 205 and step 206, please refer to the detailed description of step 102 and step 103 in the first embodiment, and the embodiment of the present invention will not be repeated.

[0113] It can be seen that implementation Figure 2The described risk perception and control method based on zero trust strategy can obtain the user access perception information corresponding to the user when it is detected that the user accesses the target application, analyze the user access perception information, determine at least one risk event corresponding to the user access perception information and the risk characterization coefficient corresponding to each risk event, and for each risk event, determine whether the risk table integral coefficient corresponding to the risk event meets the preset risk determination condition. When the risk table integral coefficient corresponding to the risk event meets the risk determination condition, the risk event is determined to be a target risk event. According to each target risk event, the risk perception information corresponding to the user is determined, and it can be determined based on user behavior, terminal and network environment. Risk perception information, improve the accuracy and comprehensiveness of determining risk perception information, and then improve the accuracy and reliability of calculating user trust scores, input risk perception information into the preset zero trust trust score model for calculation, and obtain the trust score result corresponding to the user output by the zero trust trust score model, obtain the preset trust score threshold information, and determine the access control policy for the user based on the trust score threshold information and the trust score result, and perform security access control operations on the user based on the access control policy, which can establish a network access authentication mechanism, reduce the security risks of illegal users or insecure terminals accessing the government extranet, and can improve the security and reliability of the government extranet globally.

[0114] In an optional embodiment, determining the access control policy for the user according to the trust score threshold information and the trust score result may include the following operations:

[0115] Determine multiple credible score threshold ranges according to the credible score threshold information, and determine a target credible score threshold range to which the credible score result belongs within each credible score threshold range;

[0116] Establish a logical connection between the client and the server, and generate the user's access credentials based on the logical connection;

[0117] Determine access control policies for users based on logical connections, access credentials, and target trust score threshold ranges.

[0118] In this optional embodiment, optionally, multiple trusted score threshold ranges can be determined based on the trusted score threshold information, each trusted score threshold range can correspond to a different security level or degree of trust, and accordingly, each trusted score threshold range can correspond to a different access control policy, and the target trusted score threshold range to which the trusted score result belongs can be determined within each trusted score threshold range, which is not limited in this embodiment.

[0119] In this optional embodiment, optionally, a logical connection is established between the client and the server, and the user's access credentials are generated based on the logical connection. Specifically, zero trust policy management can be used to establish a logical connection between the client and the server, which is responsible for generating credentials for the client to access the server, and then determining the access control policy for the user based on the logical connection, access credentials and target trust score threshold range, and sending the access control policy to the corresponding zero trust policy execution point for execution, which is not limited in this embodiment.

[0120] It can be seen that the implementation of this optional embodiment can determine multiple trusted score threshold ranges based on the trusted score threshold information, and determine the target trusted score threshold range to which the trusted score result belongs within each trusted score threshold range, establish a logical connection between the client and the server, and generate the user's access credentials based on the logical connection, and determine the access control policy for the user based on the logical connection, access credentials and target trusted score threshold range. This can improve the accuracy and reliability of determining the access control policy for the user, thereby improving the accuracy and efficiency of access control for users, reducing the security risks of illegal users or unsafe terminals accessing the government extranet, and can improve the security and reliability of the government extranet globally.

[0121] In another optional embodiment, performing a security access control operation on a user based on an access control policy may include the following operations:

[0122] Determine the network type of the user accessing the target application, which may include the Internet type or the government extranet type;

[0123] When the network type includes an Internet type, performing a first security check on the user through a metropolitan area network boundary to obtain a first security check result;

[0124] When the network type includes the government extranet type, the user's access to the government extranet is controlled by the zero-trust security gateway according to the access control policy and proxy encryption, and the second security detection is performed on the user through the metropolitan area network boundary to obtain the second security detection result;

[0125] The user's access to the target application is controlled according to the first security detection result or the second security detection result.

[0126] In this optional embodiment, the zero-trust policy execution point can be responsible for the secure access control of user access to smart applications. The zero-trust policy execution point obtains the access control policy from the zero-trust policy management and executes specific control actions to ensure the user's secure access to applications and data. The zero-trust policy execution point can include a policy execution point deployed on the application side, which implements trusted access control of application functions through application modification; the zero-trust policy execution point can also include a policy execution point deployed on the network side, which implements trusted access control of applications through user access rights.

[0127] In this optional embodiment, optionally, on the application side, the network type of the user's access to the target application can be determined, and the network type can include an Internet type or a government extranet type. When the network type includes the Internet type, a first security check is performed on the user through the metropolitan area network boundary to obtain a first security check result. When the network type includes the government extranet type, the user's access to the government extranet can be controlled by the zero-trust security gateway according to the access control policy and proxy encryption. That is, the zero-trust security gateway performs access control according to the policy issued by the zero-trust management platform and accesses the government application through proxy encryption, and when accessing the same-level business or the local Internet exit, a second security check is performed on the user through the metropolitan area network boundary to obtain a second security check result. The user's access to the target application is controlled according to the first security check result or the second security check result, that is, the multi-network switching function can be realized, and the network isolation of the Internet and the government extranet is realized. Only one of the Internet and the government extranet is allowed to be connected at the same time. This is not limited in this embodiment.

[0128] It can be seen that implementing this optional embodiment can determine the network type of the user's access to the target application, and the network type includes the Internet type or the government extranet type. When the network type includes the Internet type, a first security check is performed on the user through the metropolitan area network boundary to obtain a first security check result. When the network type includes the government extranet type, the user's access to the government extranet is controlled by the zero-trust security gateway according to the access control policy and proxy encryption method, and a second security check is performed on the user through the metropolitan area network boundary to obtain a second security check result. The user's access to the target application is controlled according to the first security check result or the second security check result, which can realize the multi-network switching function, realize the network isolation of the Internet and the government extranet, improve the security of access to the government extranet, and reduce the risk of virus penetration.

[0129] In another optional embodiment, the risk perception and control method based on the zero trust strategy may also include the following operations:

[0130] Before the user accesses the target application, the service port of the target application is hidden based on the application proxy to achieve network invisibility of the target application;

[0131] Detect the single-packet authentication request sent by the user through the preset zero-trust client, and perform single-packet verification on the user based on the single-packet authentication request to obtain the verification result;

[0132] When the verification result meets the preset verification pass conditions, the business forwarding port corresponding to the target application is opened to the user through the zero-trust security gateway. The business forwarding port is used for users to access the service port of the target application.

[0133] In this optional embodiment, optionally, on the network side, the service port of the target application can be hidden based on the application proxy before the user accesses the target application to achieve network invisibility of the target application. Specifically, by closing the service port by default, the service achieves network invisibility and cannot be connected or scanned from the network. If the service needs to be used, the authentication message is sent to the server through a specific client. After the server authenticates the message, it will open the relevant service to the IP address.

[0134] In this optional embodiment, optionally, when a user of a government extranet terminal needs to use the government extranet, it is necessary to send a unique SPA (Single Packet Authorization) single packet authentication request through the executed zero-trust client, detect the single packet authentication request sent by the user through the preset zero-trust client, and perform single packet verification on the user based on the single packet authentication request to obtain a verification result. When the verification result meets the preset verification pass condition, the business forwarding port corresponding to the target application is opened to the user through the zero-trust security gateway. The business forwarding port is used for the user to access the service port of the target application, and access authentication and security checks are implemented for user terminals accessing the government extranet to ensure that the identity of the accessed personnel is legal, the accessed terminal has security protection capabilities, and cannot carry viruses to access the government extranet, to ensure that only legal and compliant terminals can access services within the corresponding authority scope, which is not limited in this embodiment.

[0135] In this optional embodiment, optionally, on the network side, it may also include an Internet access area and a 5G wireless access area, wherein the Internet access area is the only exit for the e-government extranet to connect to the Internet, and office personnel can access the e-government extranet through this area to conduct government affairs; the 5G wireless access area is the interface for equipment to access through 5G technology, and office personnel access the e-government extranet through mobile terminal equipment in a 5G wireless access manner; law enforcement personnel access the e-government extranet through 5G access equipment in a 5G wireless access manner, upload the data, sound, image, and video collected by the terminal equipment to the business platform, and realize two-way mutual access between the terminal equipment and the business system, which is not limited in this embodiment.

[0136] It can be seen that the implementation of this optional embodiment can hide the service port of the target application based on the application proxy before the user accesses the target application to achieve network invisibility of the target application, detect the single-packet authentication request sent by the user through the preset zero-trust client, and perform single-packet verification on the user based on the single-packet authentication request to obtain a verification result. When the verification result meets the preset verification pass condition, the business forwarding port corresponding to the target application is opened to the user through the zero-trust security gateway. The business forwarding port is used for the user to access the service port of the target application, which can achieve network invisibility of the government extranet service port, allow users to access services after access authentication and security checks are completed, ensure that only legal and compliant terminals can access services within the corresponding authority scope, and improve the network security and reliability of the government extranet.

[0137] In another optional embodiment, the risk perception and control method based on the zero trust strategy may also include the following operations:

[0138] When it is detected that a user downloads target data in a target application through a service forwarding port, user permissions of the user and data permissions of the target data are determined;

[0139] Determine whether the user authority and the data authority match. When the user authority and the data authority match, encrypt and encapsulate the target data to obtain a data encryption package corresponding to the target data. The data encryption package includes the target data, data identification information corresponding to the target data, and the destination address;

[0140] The data encryption package is sent to the zero-trust security gateway, the data encryption package is decrypted by the zero-trust security gateway, and the data is verified according to the data identification information to obtain the verification result;

[0141] When the data verification result meets the preset data verification pass conditions, the target data is forwarded to the user according to the destination address through the zero-trust security gateway.

[0142] In this optional embodiment, optionally, when it is detected that a user downloads target data in a target application through a business forwarding port, the user's user rights and the data rights of the target data are determined, and it is judged whether the user rights and the data rights match. When the user rights match the data rights, the target data is encrypted and encapsulated to obtain a data encryption package corresponding to the target data. The data encryption package may include the target data, data identification information corresponding to the target data, and the destination address. The data encryption package is sent to a zero-trust security gateway. Specifically, a trusted API agent can be deployed between a smart application (front-end) and a smart application (back-end). Based on the principle of separation of business and data, the smart application is separated and transformed to achieve trusted access control of the smart application (back-end); through the application proxy, the real address and port of the business system are protected and hidden, and only the address and port of the zero-trust security gateway are provided to the outside. For users, all business system access requests are directed to the zero-trust security gateway, and proxy access is performed on the application to achieve application hiding, reduce the application attack surface, and prevent government applications from being scanned, attacked, or injected.

[0143] In this optional embodiment, optionally, the data encryption package can be decrypted by the zero-trust security gateway, and the data can be verified according to the data identification information to obtain a verification result. When the data verification result meets the preset data verification pass condition, the target data is forwarded to the user according to the destination address through the zero-trust security gateway. Specifically, after obtaining the user's request, the client will use encryption technology to encrypt and encapsulate the data packet to ensure the security of the identification information and business data during the transmission process. The encapsulated data packet will be sent to the zero-trust security gateway through the HTTPS encrypted tunnel. The zero-trust security gateway will perform integrity verification on the data, and after verification and decryption, it will be forwarded according to the destination address decrypted from the data packet. The client cannot access the business system before completing zero-trust authentication and authorization. After zero-trust authentication and authorization, the business system can be accessed through the application proxy capability, which is not limited in this embodiment.

[0144] It can be seen that the implementation of this optional embodiment can determine the user's user rights and the data rights of the target data when it is detected that the user downloads the target data in the target application through the business forwarding port, and judge whether the user rights and data rights match. When the user rights match the data rights, the target data is encrypted and encapsulated to obtain a data encryption package corresponding to the target data, and the data encryption package is sent to the zero-trust security gateway. The data encryption package is decrypted by the zero-trust security gateway, and the data is verified according to the data identification information to obtain a verification result. When the data verification result meets the preset data verification pass condition, the target data is forwarded to the user according to the destination address through the zero-trust security gateway, which can achieve data isolation of the government extranet, reduce the risk of data leakage in the government extranet, and improve the data protection capability and data security of the government extranet.

[0145] In another optional embodiment, the risk perception and control method based on the zero trust strategy may also include the following operations:

[0146] When it is detected that the target service is published in the target application, determining the service type of the target service, where the service type includes a public service type or a sensitive service type;

[0147] When the service type of the target service includes a sensitive service type, determining an access permission condition corresponding to the target service, where the access permission condition includes at least one of a terminal condition, a user identity condition, and a network condition;

[0148] Generate a restricted access control policy for the target service according to the permitted access conditions, and publish the target service in the target application based on the restricted access control policy;

[0149] When the service type of the target service includes a public service type, the target service is released in the target application based on a preset full-range release and launch principle.

[0150] In this optional embodiment, optionally, the service type of the target service may include a public service type or a sensitive service type, wherein, when the service type of the target service includes a sensitive service type, the access permission condition corresponding to the target service is determined, and the access permission condition may include at least one of a terminal condition, a user identity condition, and a network condition. A restricted access control policy for the target service is generated according to the access permission condition, and the target service is published in the target application based on the restricted access control policy. The restricted access control policy may specifically limit one or more combinations of the accessible scope, accessible users, and accessible terminals of the target service. When the service type of the target service includes a public service type, the target service is published in the target application based on a preset full-range publication and online principle. This embodiment does not make any limitation.

[0151] In this optional embodiment, optionally, the hierarchical and decentralized management scheme is retained, and the scope of distribution management is added on this basis. Users can click on the published business system through the business portal and automatically jump to the business system interface. Users can search and find by entering the business system name through the business resource navigation search window.

[0152] It can be seen that the implementation of this optional embodiment can determine the business type of the target business when it is detected that the target business is published in the target application. When the business type of the target business includes a sensitive business type, determine the access permission conditions corresponding to the target business, the access permission conditions include at least one of terminal conditions, user identity conditions and network conditions, generate a restricted access control policy for the target business according to the access permission conditions, and publish the target business in the target application based on the restricted access control policy. When the business type of the target business includes a public business type, based on the preset full-range release and online principle, the target business is published in the target application, which can dynamically control the release scope of different types of services, improve the accuracy of service release, and improve the security and reliability of user access to services.

[0153] Embodiment 3

[0154] See also Figure 3 , Figure 3 Schematic diagram of a risk perception and control device based on zero trust strategy disclosed in an embodiment of the present invention. Figure 3 The described risk perception and control device based on zero trust strategy can be constructed based on zero trust security architecture. Specifically, the risk perception and control device based on zero trust strategy can include an intelligent server or intelligent platform for implementing zero trust dynamic protection for target applications. The intelligent server includes a local server or a cloud server, which is not limited in the embodiments of the present invention. Figure 3 As shown, the risk perception and control device based on the zero trust strategy may include:

[0155] The acquisition module 301 is used to acquire the risk perception information corresponding to the user when it is detected that the user accesses the target application;

[0156] The calculation module 302 is used to input the risk perception information into a preset zero-trust trusted scoring model for calculation, and obtain a trusted scoring result corresponding to the user output by the zero-trust trusted scoring model;

[0157] The acquisition module 301 is also used to obtain preset trustworthy score threshold information;

[0158] The determination module 303 is used to determine the access control policy for the user according to the trust score threshold information and the trust score result, and perform a security access control operation on the user based on the access control policy.

[0159] It can be seen that implementation Figure 3 The described risk perception and management device based on zero-trust strategy can obtain the risk perception information corresponding to the user when it detects that the user accesses the target application, input the risk perception information into the preset zero-trust trusted scoring model for calculation, obtain the trusted scoring result corresponding to the user output by the zero-trust trusted scoring model, obtain the preset trusted scoring threshold information, and determine the access control policy for the user based on the trusted scoring threshold information and the trusted scoring result, and perform security access control operations on the user based on the access control policy. It can establish a network access authentication mechanism, reduce the security risks of illegal users or unsafe terminals accessing the government extranet, and can improve the security and reliability of the government extranet globally.

[0160] In an optional embodiment, if Figure 4 As shown, when the acquisition module 301 detects that a user accesses a target application, the specific method of acquiring the risk perception information corresponding to the user includes:

[0161] When it is detected that a user accesses a target application, the user access perception information corresponding to the user is obtained, where the user access perception information includes user behavior perception information, terminal environment perception information, and network environment perception information;

[0162] Analyze the user access perception information to determine at least one risk event corresponding to the user access perception information and a risk characterization coefficient corresponding to each risk event;

[0163] For each risk event, determine whether the risk table integral coefficient corresponding to the risk event meets the preset risk determination conditions. When the risk table integral coefficient corresponding to the risk event meets the risk determination conditions, determine that the risk event is a target risk event;

[0164] According to each target risk event, the risk perception information corresponding to the user is determined, and the risk perception information includes at least one of user behavior risk events, terminal environment risk events and network environment risk events.

[0165] It can be seen that implementation Figure 4The described risk perception and control device based on zero trust strategy can obtain the user access perception information corresponding to the user when it is detected that the user accesses the target application, analyze the user access perception information, determine at least one risk event corresponding to the user access perception information and the risk characterization coefficient corresponding to each risk event, and for each risk event, determine whether the risk table integral coefficient corresponding to the risk event meets the preset risk determination condition. When the risk table integral coefficient corresponding to the risk event meets the risk determination condition, the risk event is determined to be a target risk event. According to each target risk event, the risk perception information corresponding to the user is determined, and it can be determined based on user behavior, terminal and network environment. Risk perception information, improve the accuracy and comprehensiveness of determining risk perception information, and then improve the accuracy and reliability of calculating user trust scores, input risk perception information into the preset zero trust trust score model for calculation, and obtain the trust score result corresponding to the user output by the zero trust trust score model, obtain the preset trust score threshold information, and determine the access control policy for the user based on the trust score threshold information and the trust score result, and perform security access control operations on the user based on the access control policy, which can establish a network access authentication mechanism, reduce the security risks of illegal users or insecure terminals accessing the government extranet, and can improve the security and reliability of the government extranet globally.

[0166] In another optional embodiment, Figure 4 As shown, the specific manner in which the determination module 303 determines the access control policy for the user according to the trust score threshold information and the trust score result includes:

[0167] Determine multiple credible score threshold ranges according to the credible score threshold information, and determine a target credible score threshold range to which the credible score result belongs within each credible score threshold range;

[0168] Establish a logical connection between the client and the server, and generate the user's access credentials based on the logical connection;

[0169] Determine access control policies for users based on logical connections, access credentials, and target trust score threshold ranges.

[0170] It can be seen that implementation Figure 4The described risk perception and management device based on zero-trust strategy can determine multiple trusted score threshold ranges according to trusted score threshold information, and determine the target trusted score threshold range to which the trusted score result belongs within each trusted score threshold range, establish a logical connection between the client and the server, and generate the user's access credentials according to the logical connection, and determine the access control policy for the user according to the logical connection, access credentials and target trusted score threshold range. This can improve the accuracy and reliability of determining the access control policy for the user, thereby improving the accuracy and efficiency of user access control, reducing the security risks of illegal users or unsafe terminals accessing the government extranet, and can improve the security and reliability of the government extranet globally.

[0171] In yet another optional embodiment, Figure 4 As shown, the specific manner in which the determination module 303 performs a security access control operation on the user based on the access control policy includes:

[0172] Determine the network type of the user accessing the target application, which may include the Internet type or the government extranet type;

[0173] When the network type includes an Internet type, performing a first security check on the user through a metropolitan area network boundary to obtain a first security check result;

[0174] When the network type includes the government extranet type, the user's access to the government extranet is controlled by the zero-trust security gateway according to the access control policy and proxy encryption, and the second security detection is performed on the user through the metropolitan area network boundary to obtain the second security detection result;

[0175] The user's access to the target application is controlled according to the first security detection result or the second security detection result.

[0176] It can be seen that implementation Figure 4 The described risk perception and control device based on zero-trust strategy can determine the network type of user access to the target application, and the network type includes Internet type or government extranet type. When the network type includes Internet type, a first security check is performed on the user through the metropolitan area network boundary to obtain a first security check result. When the network type includes the government extranet type, the user's access to the government extranet is controlled by the zero-trust security gateway according to the access control policy and proxy encryption method, and a second security check is performed on the user through the metropolitan area network boundary to obtain a second security check result. The user's access to the target application is controlled according to the first security check result or the second security check result, which can realize multi-network switching function, realize network isolation between the Internet and the government extranet, improve the security of access to the government extranet, and reduce the risk of virus penetration.

[0177] In yet another optional embodiment, Figure 4As shown, the risk perception and control device based on the zero trust strategy may also include:

[0178] A hiding module 304 is used to hide the service port of the target application based on the application proxy before the user accesses the target application to achieve network invisibility of the target application;

[0179] The detection module 305 is used to detect the single-package authentication request sent by the user through the preset zero-trust client, and perform a single-package verification on the user based on the single-package authentication request to obtain a verification result;

[0180] The opening module 306 is used to open the business forwarding port corresponding to the target application to the user through the zero-trust security gateway when the verification result meets the preset verification pass condition. The business forwarding port is used for the user to access the service port of the target application.

[0181] It can be seen that implementation Figure 4 The described risk perception and control device based on zero-trust strategy can hide the service port of the target application based on the application proxy before the user accesses the target application to achieve network invisibility of the target application, detect the single-packet authentication request sent by the user through a preset zero-trust client, and perform single-packet verification on the user based on the single-packet authentication request to obtain a verification result. When the verification result meets the preset verification pass condition, the business forwarding port corresponding to the target application is opened to the user through the zero-trust security gateway. The business forwarding port is used for the user to access the service port of the target application, which can achieve network invisibility of the government extranet service port, allow users to access services after access authentication and security checks are completed, ensure that only legal and compliant terminals can access services within the corresponding authority scope, and improve the network security and reliability of the government extranet.

[0182] In yet another optional embodiment, Figure 4 As shown, the detection module 305 is also used to determine the user authority of the user and the data authority of the target data when it is detected that the user downloads the target data in the target application through the service forwarding port;

[0183] The risk perception and control device based on the zero trust strategy may also include:

[0184] The judging module 307 is used to judge whether the user authority and the data authority match. When the user authority and the data authority match, the target data is encrypted and encapsulated to obtain a data encryption package corresponding to the target data. The data encryption package includes the target data, data identification information corresponding to the target data, and a destination address;

[0185] The sending module 308 is used to send the data encryption package to the zero-trust security gateway, decrypt the data encryption package through the zero-trust security gateway, and perform data verification according to the data identification information to obtain a verification result;

[0186] The forwarding module 309 is used to forward the target data to the user according to the destination address through the zero-trust security gateway when the data verification result meets the preset data verification pass condition.

[0187] It can be seen that implementation Figure 4 The described risk perception and control device based on zero-trust strategy can determine the user's user rights and the data rights of the target data when detecting that the user is downloading the target data in the target application through the business forwarding port, and judge whether the user rights and data rights match. When the user rights match the data rights, the target data is encrypted and encapsulated to obtain a data encryption package corresponding to the target data, and the data encryption package is sent to the zero-trust security gateway. The data encryption package is decrypted by the zero-trust security gateway, and the data is verified according to the data identification information to obtain the verification result. When the data verification result meets the preset data verification pass condition, the target data is forwarded to the user according to the destination address through the zero-trust security gateway, which can realize data isolation of the government extranet, reduce the risk of data leakage in the government extranet, and improve the data protection capability and data security of the government extranet.

[0188] In yet another optional embodiment, Figure 4 As shown, the determination module 303 is further used to determine the service type of the target service when it is detected that the target service is published in the target application, and the service type includes a public service type or a sensitive service type;

[0189] The determination module 303 is further configured to determine, when the service type of the target service includes a sensitive service type, an access permission condition corresponding to the target service, where the access permission condition includes at least one of a terminal condition, a user identity condition, and a network condition;

[0190] The risk perception and control device based on the zero trust strategy may also include:

[0191] A generating module 310, for generating a restricted access control policy for a target service according to the access permission conditions;

[0192] A publishing module 311, used to publish a target service in a target application based on a restricted access control policy;

[0193] The publishing module 311 is further used to publish the target service in the target application based on a preset full-range publishing and going online principle when the service type of the target service includes a public service type.

[0194] It can be seen that implementation Figure 4The described risk perception and control device based on zero-trust strategy can determine the business type of the target business when it detects that the target business is published in the target application. When the business type of the target business includes a sensitive business type, it can determine the corresponding access conditions of the target business, and the access conditions include at least one of terminal conditions, user identity conditions and network conditions. A restricted access control policy for the target business is generated according to the access conditions, and the target business is published in the target application based on the restricted access control policy. When the business type of the target business includes a public business type, the target business is published in the target application based on the preset full-range release and online principle. It can dynamically control the release scope of different types of businesses, improve the accuracy of business release, and improve the security and reliability of user access to the business.

[0195] Embodiment 4

[0196] See also Figure 5 , Figure 5 FIG. 1 is a schematic diagram of the structure of another risk perception and control device based on a zero-trust strategy disclosed in an embodiment of the present invention. Figure 5 As shown, the risk perception and control device based on the zero trust strategy may include:

[0197] A memory 401 storing executable program codes;

[0198] a processor 402 coupled to the memory 401;

[0199] The processor 402 calls the executable program code stored in the memory 401 to execute the steps in the risk perception and control method based on the zero trust strategy described in the first embodiment of the present invention or the second embodiment of the present invention.

[0200] Embodiment 5

[0201] An embodiment of the present invention discloses a computer storage medium, which stores computer instructions. When the computer instructions are called, they are used to execute the steps of the risk perception and control method based on the zero trust strategy described in Embodiment 1 or Embodiment 2 of the present invention.

[0202] Embodiment 6

[0203] An embodiment of the present invention discloses a computer program product, which includes a non-transitory computer-readable storage medium storing a computer program, and the computer program is operable to enable a computer to execute the steps in the risk perception and control method based on the zero trust strategy described in Example 1 or Example 2.

[0204] The device embodiments described above are only illustrative, wherein the modules described as separate components may or may not be physically separated, and the components displayed as modules may or may not be physical modules, i.e., they may be located in one place, or they may be distributed on multiple network modules. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this embodiment. Those of ordinary skill in the art may understand and implement it without creative work.

[0205] Through the specific description of the above embodiments, those skilled in the art can clearly understand that each implementation method can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the above technical solution can be essentially or partly contributed to the prior art in the form of a software product, and the computer software product can be stored in a computer-readable storage medium, and the storage medium includes a read-only memory (ROM), a random access memory (RAM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), a one-time programmable read-only memory (OTPROM), an electronically erasable rewritable read-only memory (EEPROM), a compact disc (CD-ROM) or other optical disc storage, magnetic disk storage, magnetic tape storage, or any other computer-readable medium that can be used to carry or store data.

[0206] Finally, it should be noted that the risk perception and control method and device based on zero-trust strategy disclosed in the embodiment of the present invention discloses only the preferred embodiment of the present invention, which is only used to illustrate the technical solution of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, ordinary technicians in this field should understand that it is still possible to modify the technical solutions recorded in the aforementioned embodiments, or to replace some of the technical features therein by equivalents. However, these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the various embodiments of the present invention.

Claims

1. A risk perception and control method based on zero trust strategy, characterized in that: The method comprises: When it is detected that a user accesses a target application, risk perception information corresponding to the user is obtained; Inputting the risk perception information into a preset zero-trust trusted scoring model for calculation, and obtaining a trusted scoring result corresponding to the user output by the zero-trust trusted scoring model; Acquire preset trust score threshold information, determine an access control policy for the user according to the trust score threshold information and the trust score result, and perform a security access control operation on the user based on the access control policy.

2. The risk perception and control method based on zero trust strategy according to claim 1 is characterized in that: When detecting that a user accesses a target application, obtaining risk perception information corresponding to the user includes: When it is detected that a user accesses a target application, user access perception information corresponding to the user is obtained, wherein the user access perception information includes user behavior perception information, terminal environment perception information, and network environment perception information; Analyze the user access perception information to determine at least one risk event corresponding to the user access perception information and a risk characterization coefficient corresponding to each risk event; For each of the risk events, determine whether the risk table integral coefficient corresponding to the risk event meets the preset risk determination condition, and when the risk table integral coefficient corresponding to the risk event meets the risk determination condition, determine that the risk event is a target risk event; According to each of the target risk events, risk perception information corresponding to the user is determined, and the risk perception information includes at least one of a user behavior risk event, a terminal environment risk event, and a network environment risk event.

3. The risk perception and control method based on zero trust strategy according to claim 1 or 2 is characterized in that: The determining, according to the trust score threshold information and the trust score result, an access control policy for the user includes: Determine a plurality of credible score threshold ranges according to the credible score threshold information, and determine a target credible score threshold range to which the credible score result belongs within each of the credible score threshold ranges; Establishing a logical connection between the client and the server, and generating an access credential for the user based on the logical connection; An access control policy for the user is determined based on the logical connection, the access credential, and the target trust score threshold range.

4. The risk perception and control method based on zero trust strategy according to claim 3 is characterized in that: The performing a security access control operation on the user based on the access control policy includes: Determine the network type of the user accessing the target application, the network type including the Internet type or the government extranet type; When the network type includes the Internet type, performing a first security check on the user through a metropolitan area network boundary to obtain a first security check result; When the network type includes the government extranet type, controlling the user's access to the government extranet according to the access control policy and proxy encryption through a zero-trust security gateway, and performing a second security check on the user through the metropolitan area network boundary to obtain a second security check result; The user is controlled to access the target application according to the first security detection result or the second security detection result.

5. The risk perception and control method based on zero trust strategy according to claim 4 is characterized in that: The method further comprises: Before the user accesses the target application, the service port of the target application is hidden based on the application proxy to achieve network invisibility of the target application; Detecting a single-packet authentication request sent by the user through a preset zero-trust client, and performing a single-packet verification on the user based on the single-packet authentication request to obtain a verification result; When the verification result meets the preset verification pass condition, the business forwarding port corresponding to the target application is opened to the user through the zero-trust security gateway, and the business forwarding port is used for the user to access the service port of the target application.

6. The risk perception and control method based on zero trust strategy according to claim 5 is characterized in that: The method further comprises: When it is detected that the user downloads the target data in the target application through the service forwarding port, determining the user authority of the user and the data authority of the target data; Determine whether the user authority and the data authority match, and when the user authority and the data authority match, encrypt and encapsulate the target data to obtain a data encryption package corresponding to the target data, wherein the data encryption package includes the target data, data identification information corresponding to the target data, and a destination address; Sending the data encryption package to the zero-trust security gateway, decrypting the data encryption package through the zero-trust security gateway, and performing data verification according to the data authentication information to obtain a verification result; When the data verification result meets the preset data verification pass condition, the target data is forwarded to the user according to the destination address through the zero-trust security gateway.

7. The risk perception and control method based on zero trust strategy according to any one of claims 3 to 6, characterized in that: The method further comprises: When it is detected that a target service is published in the target application, determining a service type of the target service, wherein the service type includes a public service type or a sensitive service type; When the service type of the target service includes the sensitive service type, determining an access permission condition corresponding to the target service, the access permission condition including at least one of a terminal condition, a user identity condition, and a network condition; Generate a restricted access control policy for the target service according to the access permission condition, and publish the target service in the target application based on the restricted access control policy; When the service type of the target service includes the public service type, the target service is released in the target application based on a preset full-range release and launch principle.

8. A risk perception and control device based on zero trust strategy, characterized in that: The device comprises: An acquisition module, used to acquire risk perception information corresponding to a user when it is detected that the user accesses a target application; A calculation module, used for inputting the risk perception information into a preset zero-trust trusted scoring model for calculation, and obtaining a trusted scoring result corresponding to the user output by the zero-trust trusted scoring model; The acquisition module is further used to acquire preset trustworthy score threshold information; A determination module is used to determine an access control policy for the user according to the trust score threshold information and the trust score result, and perform a security access control operation on the user based on the access control policy.

9. A risk perception and control device based on zero trust strategy, characterized in that: The device comprises: A memory storing executable program code; a processor coupled to the memory; The processor calls the executable program code stored in the memory to execute the risk perception and control method based on the zero trust strategy as described in any one of claims 1-7.

10. A computer storage medium, characterized in that: The computer storage medium stores computer instructions, which, when called, are used to execute the risk perception and control method based on the zero-trust strategy as described in any one of claims 1-7.