Trust evaluation method and device under zero-trust security framework and storage medium

By performing multi-dimensional credibility evaluation on access request messages under the zero-trust security framework and comprehensive evaluation using deep learning models, the problem that trust evaluation technology relies on static rules is solved, achieving higher evaluation accuracy and simpler rule management.

CN120223399APending Publication Date: 2025-06-27PENG CHENG LAB
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510393323.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-31
Publication Date
2025-06-27

AI Technical Summary

Technical Problem

Under the zero-trust security framework, trust evaluation technology mostly relies on static rules, resulting in rules explosion problems and is difficult to update and manage.

Method used

A trust evaluation method is proposed, by receiving access request messages, classifying the data based on the physical meaning of the data, conducting multi-dimensional trustworthiness evaluation, and comprehensive evaluation using a pre-trained network trust evaluation model.

Benefits of technology

It improves the accuracy of trust evaluation, avoids rule explosion problems, simplifies rule updates and management, and can adapt to complex network environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223399A_ABST
    Figure CN120223399A_ABST
Patent Text Reader

Abstract

The invention discloses a trust evaluation method and device under a zero-trust security framework and a storage medium, relates to the technical field of computers, and discloses the trust evaluation method under the zero-trust security framework, and the method comprises the steps: receiving an access request message of a to-be-evaluated user; based on the physical meaning corresponding to the data in the access request message, classifying the data in the access request message to obtain N types of attribute data, N being an integer greater than 1; performing credibility evaluation on the N types of attribute data to obtain credibility scores corresponding to the N types of attribute data; and inputting the credibility scores corresponding to the N types of attribute data into a pre-trained network credibility evaluation model, and evaluating the to-be-evaluated user by the network credibility evaluation model based on the credibility scores corresponding to the N types of attribute data to obtain a network credibility score corresponding to the to-be-evaluated user. The accuracy of trust evaluation is higher, and trust evaluation can be carried out without depending on expert knowledge design rules in related technologies.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular, to a trust evaluation method, device, and storage medium under a zero-trust security framework. Background Art

[0002] Zero-trust security is a new concept of network security architecture, and its core idea is "never trust, always verify". Different from the idea of traditional defense technology to strengthen and protect the boundary, zero-trust security realizes the protection of data assets through technologies such as least-privilege access, continuous verification, and micro-segmentation. And trust evaluation is one of the key technologies to achieve zero-trust security, and its purpose is to dynamically, comprehensively, and finely evaluate the trustworthiness of elements such as the identity, device, and environment of the access request subject.

[0003] The zero-trust security framework is proposed to solve the limitations of traditional network security defense technologies in dealing with modern complex threats. Traditional network security technologies are based on the boundary defense model, which directly establishes trust according to the network location, that is, it is assumed that the enterprise internal network is trustworthy while the external network is not. However, with the increasing complexity of network security threats, the emergence of new attack means such as internal attacks, APT (Advanced Persistent Threat) attacks, and phishing attacks, as well as the popularization of emerging technologies such as cloud computing, mobile office, and Internet of Things, the network boundary has gradually become blurred, and traditional defense technologies have begun to fail.

[0004] However, under the current zero-trust security framework, most trust evaluation technologies rely on static rules, which are prone to the problem of rule explosion and are difficult to update and manage.

[0005] The above content is only used to assist in understanding the technical solution of the present application, and does not represent an admission that the above content is prior art. Summary of the Invention

[0006] The main purpose of the present application is to provide a trust evaluation method, device, and storage medium under a zero-trust security framework, aiming to solve the technical problem that under the current zero-trust security framework, most trust evaluation technologies rely on static rules, are prone to the problem of rule explosion, and are difficult to update and manage.

[0007] To achieve the above object, the present application proposes a trust evaluation method under a zero-trust security framework, and the method includes:

[0008] Receiving an access request message of a user to be evaluated;

[0009] Classifying the data in the access request message based on the physical meaning of the data corresponding to the access request message to obtain N types of attribute data; where N is an integer greater than 1;

[0010] Perform credibility evaluations on the N types of attribute data respectively to obtain the credibility scores corresponding to the N types of attribute data;

[0011] Input the credibility scores corresponding to the N types of attribute data into a pre-trained network trustworthiness evaluation model. The network trustworthiness evaluation model evaluates the user to be evaluated based on the credibility scores corresponding to the N types of attribute data to obtain the network trustworthiness score corresponding to the user to be evaluated.

[0012] In one embodiment, the classifying the data in the access request message based on the physical meaning of the data corresponding thereto to obtain N types of attribute data includes:

[0013] Based on the physical meaning of the data in the access request message, divide the data in the access request message into identity attribute data, network environment attribute data, and physical environment attribute data.

[0014] In one embodiment, the performing credibility evaluations on the N types of attribute data respectively to obtain the credibility scores corresponding to the N types of attribute data includes:

[0015] Based on the identity attribute data and a pre-trained identity credibility evaluation model, evaluate the identity credibility of the user to be evaluated to obtain an identity credibility score;

[0016] Based on the network environment attribute data and a pre-trained network environment credibility evaluation model, evaluate the credibility of the network environment where the user to be evaluated is located to obtain a network environment credibility score;

[0017] Based on the physical environment attribute data and a pre-established physical environment credibility database, evaluate the credibility of the physical environment where the user to be evaluated is located to obtain a physical environment credibility score;

[0018] The inputting the credibility scores corresponding to the N types of attribute data into a pre-trained network trustworthiness evaluation model. The network trustworthiness evaluation model evaluates the user to be evaluated based on the credibility scores corresponding to the N types of attribute data to obtain the network trustworthiness score corresponding to the user to be evaluated includes:

[0019] Input the identity credibility score, the network environment credibility score, and the physical environment credibility score into the network trustworthiness evaluation model. The network trustworthiness evaluation model evaluates the user to be evaluated based on the identity credibility score, the network environment credibility score, and the physical environment credibility score to obtain the network trustworthiness score corresponding to the user to be evaluated.

[0020] In one embodiment, evaluating the identity credibility of the user to be evaluated based on the identity attribute data and a pre-trained identity credibility evaluation model to obtain an identity credibility score includes:

[0021] Determining the identity credibility data of the user to be evaluated based on the identity attribute data;

[0022] Preprocessing the identity credibility data;

[0023] Inputting the preprocessed identity credibility data into the identity credibility evaluation model to obtain the identity credibility score output by the identity credibility evaluation model.

[0024] In one embodiment, determining the identity credibility data of the user to be evaluated based on the identity attribute data includes:

[0025] If the identity attribute data includes a terminal number, using the terminal number to match in a pre-established list of the user's common terminal devices to obtain a first result indicating whether there is a match;

[0026] If the identity attribute data includes the initiation time of an access request, using the initiation time to match in a pre-established user time activity database to obtain a second result indicating the activity level during the period when the access request was initiated;

[0027] If the identity attribute data includes the initiation time and location of an access request, using the initiation time and location to match in a pre-established user location activity database to obtain a third result indicating the activity level at the location where the access request was initiated;

[0028] If the identity attribute data includes biometric authentication information, performing biometric authentication using the biometric authentication information to obtain a fourth result indicating the biometric authentication result;

[0029] If the identity attribute data includes an input password, performing password authentication using the input password to obtain a fifth result indicating the password authentication result;

[0030] If the identity attribute data includes authoritative identity information, performing authentication using the authoritative identity information to obtain a sixth result indicating the authoritative identity authentication result;

[0031] If the identity attribute data includes human-machine verification information, performing authentication using the human-machine verification information to obtain a seventh result indicating the human-machine authentication result;

[0032] If the identity attribute data includes expected information, performing authentication using the expected information to obtain an eighth result indicating the expected authentication result;

[0033] Select at least one of the first result, the second result, the third result, the fourth result, the fifth result, the sixth result, the seventh result, and the eighth result as the identity credibility data of the user to be evaluated.

[0034] In one embodiment, the preprocessing of the identity credibility data includes:

[0035] Unify the type of the identity credibility data into a floating-point type;

[0036] Perform normalization processing on the identity credibility data converted into a floating-point type.

[0037] In one embodiment, the evaluation of the credibility of the network environment where the user to be evaluated is located based on the network environment attribute data and a pre-trained network environment credibility evaluation model to obtain a network environment credibility score includes:

[0038] Based on the network environment attribute data, determine the network environment credibility data of the user to be evaluated;

[0039] Preprocess the network environment credibility data;

[0040] Input the preprocessed network environment credibility data into the network environment credibility evaluation model to obtain the network environment credibility score output by the network environment credibility evaluation model.

[0041] In one embodiment, the determination of the network environment credibility data of the user to be evaluated based on the network environment attribute data includes:

[0042] If the network environment attribute data includes a device brand, use the device brand to perform a match in a pre-established device social credit database to obtain a ninth result representing the device social credit score corresponding to the device brand;

[0043] If the network environment attribute data includes a Trusted Platform Module (TPM) configuration, use the TPM configuration to determine whether the TPM is enabled to obtain a tenth result representing whether the TPM is enabled;

[0044] If the network environment attribute data includes a secure boot configuration, use the secure boot configuration to determine whether the secure boot is enabled to obtain an eleventh result representing whether the secure boot is enabled;

[0045] If the network environment attribute data includes a software vulnerability list, use the software vulnerability list to perform a match in a pre-established software vulnerability information database to obtain a twelfth result representing the vulnerability score corresponding to the software vulnerability list;

[0046] If the network environment attribute data includes a software version number, use the software version number to perform a match in a pre-established software version information database to obtain a thirteenth result representing the software version score corresponding to the software version number;

[0047] If the network environment attribute data includes a security patch list, use the security patch list to perform a match in a pre-established security patch information database to obtain a fourteenth result representing the security patch score corresponding to the security patch list;

[0048] If the network environment attribute data includes communication protocol security information, use the communication protocol security information to determine a fifteenth result representing the communication protocol security assessment result;

[0049] If the network environment attribute data includes the encryption algorithm adopted, use the encryption algorithm to perform a match in a pre-established encryption algorithm database to obtain a sixteenth result representing the encryption algorithm score corresponding to the encryption algorithm;

[0050] If the network environment attribute data includes access network security information, use the access network security information to determine a seventeenth result representing the access network security assessment result;

[0051] Select at least one of the ninth result, the tenth result, the eleventh result, the twelfth result, the thirteenth result, the fourteenth result, the fifteenth result, the sixteenth result, and the seventeenth result as the network environment credibility data of the user to be evaluated.

[0052] In one embodiment, the preprocessing of the network environment credibility data includes:

[0053] Unify the type of the network environment credibility data into a floating-point type;

[0054] Perform normalization processing on the network environment credibility data converted into a floating-point type.

[0055] In one embodiment, the evaluation of the credibility of the physical environment where the user to be evaluated is located based on the physical environment attribute data and a pre-established physical environment credibility database to obtain a physical environment credibility score includes:

[0056] When the physical environment attribute data includes the physical location of the user to be evaluated, use the physical location to perform a match in a pre-established physical environment credibility database to obtain the physical environment credibility score corresponding to the physical location.

[0057] In addition, to achieve the above object, the present application further provides a trust evaluation device under a zero-trust security framework, the device comprising:

[0058] a receiving module, configured to receive an access request message of a user to be evaluated;

[0059] a classification module, configured to classify the data in the access request message based on the physical meaning of the data corresponding in the access request message, to obtain N types of attribute data; where N is an integer greater than 1;

[0060] a credibility scoring module, configured to respectively perform credibility evaluation on the N types of attribute data, to obtain credibility scores corresponding to the N types of attribute data;

[0061] a trust degree evaluation module, configured to input the credibility scores corresponding to the N types of attribute data into a pre-trained network trust degree evaluation model, and the network trust degree evaluation model evaluates the user to be evaluated based on the credibility scores corresponding to the N types of attribute data, to obtain a network trust degree score corresponding to the user to be evaluated.

[0062] In addition, to achieve the above object, the present application further provides a trust evaluation device under a zero-trust security framework, the device comprising: a memory, a processor, and a computer program stored on the memory and executable on the processor, the computer program being configured to implement the steps of the trust evaluation method under the zero-trust security framework as described above.

[0063] In addition, to achieve the above object, the present application further provides a storage medium, the storage medium being a computer-readable storage medium, and a computer program is stored on the storage medium, and when the computer program is executed by a processor, the steps of the trust evaluation method under the zero-trust security framework as described above are implemented.

[0064] In addition, to achieve the above object, the present application further provides a computer program product, the computer program product comprising a computer program, and when the computer program is executed by a processor, the steps of the trust evaluation method under the zero-trust security framework as described above are implemented.

[0065] One or more technical solutions provided by the present application have at least the following technical effects:

[0066] First, the data in the user's access request message is classified according to its physical meaning, so as to subsequently evaluate the user from multiple perspectives. Furthermore, based on the scores obtained from the above multi-dimensional evaluation, a comprehensive evaluation of the user's network trustworthiness is carried out using a network trustworthiness model based on deep learning. This application uses a data-driven approach to learn the trust evaluation logic, with higher accuracy in trust evaluation. Moreover, it can perform trust evaluation without relying on expert knowledge design rules in related technologies, avoiding the rule explosion problem faced by traditional technologies. By updating and training the model in a timely manner, the user's access request can be effectively evaluated. BRIEF DESCRIPTION OF THE DRAWINGS

[0067] The accompanying drawings herein are incorporated into and constitute a part of this specification, showing embodiments consistent with this application, and are used together with the specification to explain the principles of this application.

[0068] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0069] Figure 1 is one of the schematic flowcharts of the trust evaluation method under the zero-trust security framework provided by this application;

[0070] Figure 2 is the second of the schematic flowcharts of the trust evaluation method under the zero-trust security framework provided by this application;

[0071] Figure 3 is the schematic diagram of the overall framework in the trust evaluation method under the zero-trust security framework provided by this application;

[0072] Figure 4 is the schematic diagram of the identity credibility evaluation in the trust evaluation method under the zero-trust security framework provided by this application;

[0073] Figure 5 is the schematic diagram of the network environment credibility evaluation in the trust evaluation method under the zero-trust security framework provided by this application;

[0074] Figure 6 is the schematic diagram of the network trustworthiness evaluation in the trust evaluation method under the zero-trust security framework provided by this application;

[0075] Figure 7 is the schematic diagram of the structure of the trust evaluation device under the zero-trust security framework provided by this application;

[0076] Figure 8It is a schematic structural diagram of a trust evaluation device under the zero-trust security framework provided by this application.

[0077] The realization of the purpose, functional characteristics and advantages of this application will be further described with reference to the accompanying drawings in combination with embodiments. Detailed implementation manners

[0078] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of this application and are not used to limit this application.

[0079] Unless otherwise defined, all technical and scientific terms used in this application have the same meaning as commonly understood by those skilled in the technical field to which this application belongs; the terms used in this application are only for the purpose of describing specific embodiments and are not intended to limit this application; the terms "including" and "having" and any variations thereof in the description of the specification, claims and drawings of this application are intended to cover non-exclusive inclusion.

[0080] In the description of the embodiments of this application, technical terms such as "first" and "second" are only used to distinguish different objects and cannot be understood as indicating or implying relative importance or implicitly indicating the quantity, specific order or primary-secondary relationship of the indicated technical features. In the description of the embodiments of this application, the meaning of "a plurality of" is two or more unless otherwise specifically defined.

[0081] Referring to "embodiments" in this application means that the specific features, structures or characteristics described in combination with the embodiments may be included in at least one embodiment of this application. The appearance of this phrase in various positions in the specification does not necessarily refer to the same embodiment, nor is it an independent or alternative embodiment mutually exclusive with other embodiments. Those skilled in the art explicitly and implicitly understand that the embodiments described in this application can be combined with other embodiments.

[0082] In the description of the embodiments of this application, the term "and / or" is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " in this article generally represents an "or" relationship between the associated objects before and after.

[0083] In order to better understand the technical solutions of this application, the following will be described in detail in combination with the drawings of the specification and specific implementation manners.

[0084] In the related art, in the field of zero-trust security, the following problems still exist in trust evaluation technology:

[0085] 1) Most of the related technologies are targeted at specific scenarios, such as the Internet of Things, etc., and do not have universality;

[0086] 2) The data sources of related trust evaluation technologies are not comprehensive enough to comprehensively evaluate the credibility of elements such as identity, device, and environment;

[0087] 3) Most related technologies rely on static rules, which are prone to the problem of rule explosion and are difficult to update and manage;

[0088] 4) The accuracy of related trust evaluation methods is insufficient.

[0089] In view of the above problems, the present application proposes a trust evaluation method under a zero-trust security framework, aiming to design a trust evaluation method based on deep learning, learn the trust evaluation logic in a data-driven manner, which can achieve high accuracy and does not rely on expert knowledge to design rules, avoiding the problem of rule explosion faced by traditional technologies.

[0090] In addition, the present application can also divide the trust evaluation data sources into three parts: identity credibility evaluation, network environment credibility evaluation, and physical environment credibility evaluation according to the trust evaluation type, apply deep learning algorithms to perform trust evaluations respectively, and then calculate the comprehensive trust evaluation results, which can comprehensively evaluate elements such as the identity, device, and environment of the access subject, and the trust evaluation method has universality.

[0091] It should be noted that the execution subject of the embodiments of the present application can be a computing service device with data processing, network communication, and program running functions, such as a tablet computer, a personal computer, a mobile phone, etc., or an electronic device capable of implementing the above functions, a trust evaluation device under a zero-trust security framework, etc. Hereinafter, taking the trust evaluation device under a zero-trust security framework as an example, the embodiments of the present application and the following embodiments will be described.

[0092] The following specifically describes the embodiments of the present application and the following embodiments.

[0093] The embodiments of the present application provide a trust evaluation method under a zero-trust security framework, referring to Figure 1 , Figure 1 is one of the flow diagrams of the trust evaluation method provided by the present application under a zero-trust security framework, including steps S101 to S104:

[0094] Step S101, receiving an access request message of a user to be evaluated.

[0095] Step S102, classifying the data in the access request message based on the physical meaning of the data corresponding to the access request message to obtain N types of attribute data;

[0096] Wherein, N is an integer greater than 1.

[0097] Step S103: Perform credibility evaluation on the N types of attribute data respectively to obtain the credibility scores corresponding to the N types of attribute data.

[0098] Step S104: Input the credibility scores corresponding to the N types of attribute data into a pre-trained network trustworthiness evaluation model. The network trustworthiness evaluation model evaluates the user to be evaluated based on the credibility scores corresponding to the N types of attribute data to obtain the network trustworthiness score corresponding to the user to be evaluated.

[0099] In some embodiments, the network trustworthiness evaluation model can be pre-trained through the following steps:

[0100] Step S1-1: Prepare data for training the model, generate input data according to the attribute data format, and obtain label data by means of manual scoring, automatic generation of scores, etc., so as to construct a training dataset.

[0101] Step S1-2: Select a deep learning model for network trustworthiness evaluation. Optional deep learning models include but are not limited to DNN (Deep Neural Networks) models, Transformer models, LLM (Large Language Model) models, etc. This model takes attribute data as input and outputs a network trustworthiness score.

[0102] Step S1-3: Use the training dataset to supervise and train the network trustworthiness evaluation model based on deep learning.

[0103] In the related art, trustworthiness evaluation usually relies on pre-set static rules. Specifically, it is necessary to use expert knowledge to design rules to evaluate the trustworthiness of a certain user through these rules, and then decide whether the user can perform access.

[0104] However, in order to perform more accurate evaluation, usually thousands of rules are set for matching. And as the user terminals and network environment conditions are continuously updated and complicated, the difficulty of updating the rules is getting greater and greater, and it is difficult for technicians to update and manage.

[0105] In the embodiment of the present application, a pre-trained network trustworthiness evaluation model is used for network trustworthiness evaluation. By using this data-driven method, technicians no longer need to update and manage numerous evaluation rules. After only training the model with the updated data, it can adaptively evaluate the updated situation, which is convenient for technicians to update and manage.

[0106] In addition, after receiving the access request message of the user to be evaluated, the embodiment of the present application will first classify the data in the access request message based on the physical meaning corresponding to the data in the access request message to obtain N types of attribute data, which is convenient for subsequent credibility evaluation of the N types of attribute data respectively, and then use the network trust degree evaluation model for comprehensive evaluation. This is mainly because there are differences in the trust degree evaluation methods for different attribute data. If they are not distinguished and uniformly processed, the evaluation accuracy is relatively low. The present application uses different attribute data to evaluate the user respectively, and then uses the scores obtained from the above multi-dimensional evaluation to comprehensively evaluate the network trust degree of the user through the network trust degree model, which can effectively improve the accuracy of trust degree evaluation.

[0107] The embodiment of the present application provides a trust evaluation method under a zero-trust security framework. First, the data in the access request message of the user is classified according to the physical meaning, so as to evaluate the user from multiple angles respectively in the follow-up, and then use the scores obtained from the above multi-dimensional evaluation to comprehensively evaluate the network trust degree of the user based on the network trust degree model of deep learning. The present application uses a data-driven method to learn the trust evaluation logic, and the accuracy of trust evaluation is higher. Moreover, it can perform trust evaluation without relying on the rules designed by expert knowledge in related technologies, avoiding the rule explosion problem faced by traditional technologies. By timely updating and training the model, the user can be effectively evaluated when accessing the request.

[0108] Based on the corresponding embodiment in the present application Figure 1 In this embodiment, the same or similar content as the above embodiment can be referred to the above introduction and will not be repeated hereinafter. On this basis, the present application provides a specific implementation manner for classifying the data in the access request message. Please refer to Figure 2 , Figure 2 FIG. is the second flowchart of the trust evaluation method under the zero-trust security framework provided by the present application. The above step S102 includes step S102-1:

[0109] Step S102-1, based on the physical meaning corresponding to the data in the access request message, divide the data in the access request message into identity attribute data, network environment attribute data, and physical environment attribute data.

[0110] It should be noted that the embodiment of the present application only takes the classification into three types of attribute data, namely identity attribute data, network environment attribute data, and physical environment attribute data, for separate evaluation as an example. The N types of attribute data may include more or fewer attribute data, and the present application does not limit this.

[0111] In some embodiments, a specific implementation manner for separately performing credibility evaluation on the N types of attribute data is provided. Such as Figure 2As shown, the above step S103 includes steps S1031 to S1033:

[0112] In step S1031, based on the identity attribute data and a pre-trained identity credibility evaluation model, evaluate the identity credibility of the user to be evaluated to obtain an identity credibility score.

[0113] In some embodiments, the above identity credibility evaluation model can be pre-trained through the following steps:

[0114] In step S2-1, prepare the data for training the model, generate input data according to the attribute data format, and obtain label data by means such as manual scoring and automatic generation of scores, thereby constructing a training dataset.

[0115] In step S2-2, select a deep learning model for identity credibility evaluation. Optional deep learning models include but are not limited to DNN models, Transformer models, LLM models, etc. This model takes attribute data as input and outputs an identity credibility score.

[0116] In step S2-3, use the above training dataset to supervise and train the identity credibility evaluation model based on deep learning.

[0117] In step S1032, based on the network environment attribute data and a pre-trained network environment credibility evaluation model, evaluate the credibility of the network environment where the user to be evaluated is located to obtain a network environment credibility score.

[0118] In some embodiments, the above network environment credibility evaluation model can be pre-trained through the following steps:

[0119] In step S3-1, prepare the data for training the model, generate input data according to the attribute data format, and obtain label data by means such as manual scoring and automatic generation of scores, thereby constructing a training dataset.

[0120] In step S3-2, select a deep learning model for network environment credibility evaluation. Optional deep learning models include but are not limited to DNN models, Transformer models, LLM models, etc. This model takes attribute data as input and outputs a network environment credibility score.

[0121] In step S3-3, use the above training dataset to supervise and train the network environment credibility evaluation model based on deep learning.

[0122] In step S1033, based on the physical environment attribute data and a pre-established physical environment credibility database, evaluate the credibility of the physical environment where the user to be evaluated is located to obtain a physical environment credibility score.

[0123] It should be noted that this application does not limit the order of execution among the above steps S1031, S1032, and S1033, that is, it does not limit the order of using N types of attribute data for credibility evaluation.

[0124] Correspondingly, the above step S104 includes step S104-1:

[0125] Step S104-1, input the identity credibility score, the network environment credibility score, and the physical environment credibility score into the network trustworthiness evaluation model, and the network trustworthiness evaluation model evaluates the user to be evaluated based on the identity credibility score, the network environment credibility score, and the physical environment credibility score, so as to obtain the network trustworthiness score corresponding to the user to be evaluated.

[0126] In some embodiments, a specific implementation manner of the above step S1031 is provided, and the above step S1031 may include:

[0127] Step S1031-1, determine the identity credibility data of the user to be evaluated based on the identity attribute data.

[0128] Step S1031-2, preprocess the identity credibility data.

[0129] Step S1031-3, input the preprocessed identity credibility data into the identity credibility evaluation model to obtain the identity credibility score output by the identity credibility evaluation model.

[0130] In some other embodiments, a specific implementation manner of the above step S1031-1 is provided. The above step S1031-1 may include the following steps:

[0131] 1) If the identity attribute data includes a terminal number, use the terminal number to perform a match in the pre-established list of the user's common terminal devices to obtain a first result indicating whether there is a match;

[0132] It should be noted that the pre-established list of the user's common terminal devices includes the terminal numbers commonly used by the user to be evaluated; when matching, query whether there is a terminal number corresponding to the current access in the list of the user's common terminal devices, determine whether it is a common terminal, and record it as a boolean type.

[0133] 2) If the identity attribute data includes the initiation time of the access request, use the initiation time to perform a match in the pre-established user time activity database to obtain a second result indicating the activity level during the period when the access request is initiated;

[0134] It should be noted that in the pre - established user time activity database, for example, taking <hour> as the time period unit, the active frequency of the user is statistically calculated as the activity level; during matching, by matching the time period in which the access request is initiated, the corresponding activity level is obtained as the second result and recorded as a floating - point number type.

[0135] 3) If the identity attribute data includes the initiation time and location of the access request, then use the initiation time and location to perform matching in the pre - established user location activity database to obtain a third result representing the activity level of the access request initiation location;

[0136] It should be noted that in the pre - established user location activity database, for example, taking <hour - location name> as the unit, the active frequency of the user is statistically calculated as the activity level. For example, the activity level at the restaurant at 12 noon is x, and this location needs to be associated with time; during matching, by matching the time period and location in which the access request is initiated, the corresponding activity level is obtained as the third result and recorded as a floating - point number type.

[0137] 4) If the identity attribute data includes biometric authentication information, then use the biometric authentication information to perform biometric authentication to obtain a fourth result representing the biometric authentication result;

[0138] It should be noted that the above - mentioned fourth result can be recorded as a floating - point number type.

[0139] 5) If the identity attribute data includes an input password, then use the input password to perform password authentication to obtain a fifth result representing the password authentication result;

[0140] It should be noted that the above - mentioned fifth result can be recorded as a floating - point number type.

[0141] 6) If the identity attribute data includes authoritative identity information, then use the authoritative identity information to perform authentication to obtain a sixth result representing the authoritative identity authentication result;

[0142] It should be noted that the above - mentioned sixth result can be recorded as an integer type.

[0143] 7) If the identity attribute data includes human - machine verification information, then use the human - machine verification information to perform authentication to obtain a seventh result representing the human - machine authentication result;

[0144] It should be noted that the above - mentioned seventh result can be recorded as a floating - point number type.

[0145] 8) If the identity attribute data includes expected information, then use the expected information to perform authentication to obtain an eighth result representing the expected authentication result;

[0146] It should be noted that the above eighth result can be recorded as an integer type.

[0147] Select at least one of the first result, the second result, the third result, the fourth result, the fifth result, the sixth result, the seventh result, and the eighth result as the identity credibility data of the user to be evaluated.

[0148] In some other embodiments, a specific implementation manner of the above step S1031-2 is provided. The above step S1031-2 may include the following steps:

[0149] Step S1031-21, uniformly convert the type of the identity credibility data into a floating-point type;

[0150] Step S1031-22, perform normalization processing on the identity credibility data converted into a floating-point type.

[0151] Specifically, the types of the above identity credibility data include boolean type, floating-point type, and integer type. In order to enable normal evaluation after inputting the data into the identity credibility evaluation model, in the embodiments of the present application, the type of the identity credibility data is first uniformly converted into a floating-point type, and then the identity credibility data converted into a floating-point type is normalized to convert the data to the same dimension and eliminate the influence of the dimension and value range differences between different data on the model.

[0152] In some embodiments, a specific implementation manner of the above step S1032 is provided. The above step S1032 may include:

[0153] Step S1032-1, based on the network environment attribute data, determine the network environment credibility data of the user to be evaluated.

[0154] Step S1032-2, perform preprocessing on the network environment credibility data.

[0155] Step S1032-3, input the preprocessed network environment credibility data into the network environment credibility evaluation model to obtain the network environment credibility score output by the network environment credibility evaluation model.

[0156] In some other embodiments, a specific implementation manner of the above step S1032-1 is provided. The above step S1032-1 may include the following steps:

[0157] 1) If the network environment attribute data includes the device brand, use the device brand to perform matching in the pre-established device social credit database to obtain a ninth result representing the device social credit score corresponding to the device brand;

[0158] It should be noted that in the pre-established device social credit database, different device brands and their social credit scores are stored; during matching, the device social credit score matching the device brand is determined as the ninth result and recorded as a floating-point number type.

[0159] 2) If the network environment attribute data includes TPM (Trusted Platform Module) configuration, then use the TPM configuration to determine whether to enable TPM, and obtain the tenth result indicating whether TPM is enabled.

[0160] It should be noted that check whether TPM is enabled, and record the corresponding tenth result as a boolean type.

[0161] 3) If the network environment attribute data includes a secure boot configuration, then use the secure boot configuration to determine whether to enable secure boot, and obtain the eleventh result indicating whether secure boot is enabled.

[0162] It should be noted that check whether secure boot is enabled, and record the corresponding eleventh result as a boolean type.

[0163] 4) If the network environment attribute data includes a software vulnerability list, then use the software vulnerability list to perform matching in the pre-established software vulnerability information database, and obtain the twelfth result indicating the vulnerability score corresponding to the software vulnerability list.

[0164] It should be noted that in the pre-established software vulnerability information database, the severity scores of software vulnerability threats are stored; during matching, the vulnerability score matching the software vulnerability list is determined as the twelfth result and recorded as a floating-point number type.

[0165] 5) If the network environment attribute data includes a software version number, then use the software version number to perform matching in the pre-established software version information database, and obtain the thirteenth result indicating the software version score corresponding to the software version number.

[0166] It should be noted that in the pre-established software version information database, the latest software version information is stored; during matching, the software version score matching the software version number is determined as the thirteenth result and recorded as a floating-point number type.

[0167] 6) If the network environment attribute data includes a security patch list, then use the security patch list to perform matching in the pre-established security patch information database, and obtain the fourteenth result indicating the security patch score corresponding to the security patch list.

[0168] It should be noted that in the pre-established security patch information library, security patch scores are stored, which represent the importance of different security patches; during matching, the security patch score that matches the security patch list is determined as the fourteenth result and recorded as a floating-point type.

[0169] 7) If the network environment attribute data includes communication protocol security information, use the communication protocol security information to determine the fifteenth result representing the communication protocol security assessment result;

[0170] It should be noted that the above fifteenth result can be recorded as a floating-point type.

[0171] 8) If the network environment attribute data includes the encryption algorithm used, use the encryption algorithm to perform matching in the pre-established encryption algorithm database to obtain the sixteenth result representing the encryption algorithm score corresponding to the encryption algorithm;

[0172] It should be noted that in the pre-established encryption algorithm database, different encryption algorithms and their security levels are stored; during matching, the security level that matches the encryption algorithm is determined as the sixteenth result and recorded as a floating-point type.

[0173] 9) If the network environment attribute data includes access network security information, use the access network security information to determine the seventeenth result representing the access network security assessment result;

[0174] It should be noted that the above seventeenth result can be recorded as a floating-point type.

[0175] Select at least one of the ninth result, the tenth result, the eleventh result, the twelfth result, the thirteenth result, the fourteenth result, the fifteenth result, the sixteenth result, and the seventeenth result as the network environment credibility data of the user to be evaluated.

[0176] In some other embodiments, a specific implementation manner of the above step S1032-2 is provided. The above step S1032-2 may include the following steps:

[0177] Step S1032-21, uniformly convert the type of the network environment credibility data into a floating-point type;

[0178] Step S1032-22, perform normalization processing on the network environment credibility data converted into a floating-point type.

[0179] Specifically, the types of the above-mentioned network environment credibility data include boolean type, floating-point type, and integer type. To enable normal evaluation after inputting the data into the network environment credibility evaluation model, in the embodiments of the present application, the types of the network environment credibility data are first uniformly converted into floating-point type, and then the network environment credibility data converted into floating-point type is normalized to convert the data to the same dimension and eliminate the influence of the dimension and value range differences between different data on the model.

[0180] In some embodiments, a specific implementation manner of the above step S1033 is provided. The above step S1033 may include the following steps:

[0181] When the physical environment attribute data includes the physical location where the user to be evaluated is located, use the physical location to perform matching in a pre-established physical environment credibility database to obtain the physical environment credibility score corresponding to the physical location.

[0182] Specifically, in the pre-established physical environment credibility database, different physical locations and their corresponding credibility scores are stored; during matching, determine the credibility score that matches the physical location where the user to be evaluated is located as the corresponding physical environment credibility score.

[0183] Next, an example is used to illustrate the trust evaluation method provided by the embodiments of the present application under the zero-trust security framework.

[0184] Figure 3 is a schematic diagram of the overall framework in the trust evaluation method provided by the present application. As Figure 3 shown, the data sources for trust evaluation are divided into three categories: the identity attribute data of the user, the network environment attribute data, and the physical environment attribute data.

[0185] For the identity attribute data, design an identity credibility evaluation method based on deep learning to calculate the identity credibility of the access subject (Module 1 - Identity Credibility Evaluation);

[0186] For the network environment attribute data, design a network environment credibility evaluation method based on deep learning to calculate the network environment credibility of the access subject (Module 2 - Network Environment Credibility Evaluation);

[0187] For the physical environment attribute data, query the authoritative database to obtain the physical environment credibility of the access subject (Module 3 - Physical Environment Credibility Evaluation).

[0188] Then, design a network trust degree evaluation method based on deep learning, and calculate its network trust degree score according to the identity credibility score, network environment credibility score, and physical environment credibility score of the access subject (Module 4 - Network Trust Degree Evaluation).

[0189] The above modules are specifically described as follows:

[0190] (1) Module 1 - Identity Credibility Assessment:

[0191] The identity credibility assessment module evaluates the credibility of the access subject's identity based on the identity - related information of the access request subject. Figure 4 It is a schematic diagram of identity credibility assessment in the trust assessment method under the zero - trust security framework provided by this application. As Figure 4 shown, the processing flow of this module is as follows:

[0192] Preliminary operations:

[0193] 1) Establish a list of the user's common terminal devices;

[0194] 2) Establish a user time activity database, and count the user's activity frequency in units of <hour>;

[0195] 3) Establish a user location activity database, and count the user's activity frequency in units of <hour - location name>.

[0196] 4) Train the identity credibility assessment model:

[0197] a. Prepare the data for training the model, generate input data according to the attribute data format, and obtain label data by means such as manual scoring and automatic score generation, thereby constructing a training dataset;

[0198] b. Select a deep - learning model for identity credibility assessment. Optional deep - learning models include but are not limited to DNN models, Transformer models, LLM models, etc. This model takes attribute data as input and outputs an identity credibility score;

[0199] c. Supervise and train the deep - learning - based identity credibility assessment model.

[0200] Execution phase:

[0201] Step 1: Collect identity attribute data, including terminal number, the initiation time of the access request, the initiation location of the access request, biometric authentication result, password authentication result, authoritative identity score, human - machine verification score, and expected information verification result.

[0202] Step 2: Obtain identity credibility data:

[0203] 1) According to the terminal number, query the list of the user's common terminal devices, determine whether it is a common terminal, and record it as a boolean value type;

[0204] 2) Query the user time activity database according to the initiation time of the access request to obtain the activity during this period, and record it as a floating-point number type;

[0205] 3) Query and establish the user location activity database according to the initiation time and location of the access request to obtain the activity at this location, and record it as a floating-point number type;

[0206] 4) The biometric authentication result, recorded as a floating-point number type;

[0207] 5) The password authentication result, recorded as a floating-point number type;

[0208] 6) The authoritative identity score, recorded as an integer type;

[0209] 7) The human-machine verification score, recorded as a floating-point number type;

[0210] 8) The expected information verification result, recorded as an integer type.

[0211] Step 3: Data preprocessing. Convert all the identity credibility data obtained in Step 2 into floating-point number types and perform normalization processing.

[0212] Step 4: Identity credibility assessment. Input the data processed in Step 3 into the trained identity credibility assessment model to obtain the identity credibility score.

[0213] (2) Module 2 - Network environment credibility assessment:

[0214] The network environment credibility assessment evaluates the credibility of the network environment where the access subject is located based on the network environment-related information of the access request subject. Figure 5 It is a schematic diagram of the network environment credibility assessment in the trust assessment method under the zero-trust security framework provided by this application. As Figure 5 shown, the processing flow of this module is as follows:

[0215] Preliminary operations:

[0216] 1) Establish a device social credit database to store the device brand and its social credit score;

[0217] 2) Establish a software vulnerability information database to store the severity score of software vulnerability threats;

[0218] 3) Establish a software version information database to record the latest software version information;

[0219] 4) Establish a security patch information database to store the importance score of security patches;

[0220] 5) Establish an encryption algorithm database to store encryption algorithms and their security levels;

[0221] 6) Train the network environment credibility evaluation model:

[0222] a. Prepare the data for training the model, generate input data according to the attribute data format, and obtain label data by means such as manual scoring and automatic generation of scores, so as to construct a training dataset;

[0223] b. Select a deep learning model for network environment credibility evaluation. Optional deep learning models include but are not limited to DNN models, Transformer models, LLM models, etc. This model takes attribute data as input and outputs the network environment credibility score;

[0224] c. Supervise and train the network environment credibility evaluation model based on deep learning.

[0225] Execution phase:

[0226] Step 1: Collect network environment attribute data, including device brand, TPM configuration, secure boot configuration, software vulnerability list, software version number, security patch list, communication protocol security evaluation result, encryption algorithm used, access network security evaluation result.

[0227] Step 2: Obtain network environment credibility data:

[0228] 1) According to the device brand, query the device social credit database to obtain the device social credit score, recorded as a floating-point number type;

[0229] 2) Check whether TPM is enabled, and record the result as a boolean type;

[0230] 3) Check whether secure boot is enabled, and record the result as a boolean type;

[0231] 4) Query the software vulnerability information database to obtain the vulnerability score, recorded as a floating-point number type;

[0232] 5) Query the software version information database to obtain the software version score, recorded as a floating-point number type;

[0233] 6) Query the security patch information database to obtain the security patch score, recorded as a floating-point number type;

[0234] 7) Communication protocol security score, recorded as a floating-point number type;

[0235] 8) Query the encryption algorithm database to obtain the encryption algorithm score, recorded as a floating-point number type;

[0236] 9) Access network security score, recorded as a floating-point number type.

[0237] Step 3: Data preprocessing. Convert the network environment credibility data obtained in Step 2 into floating-point type and perform normalization processing.

[0238] Step 4: Network environment credibility evaluation. Input the data processed in Step 3 into the trained network environment credibility evaluation model to obtain the network environment credibility evaluation score.

[0239] (III) Physical environment credibility evaluation:

[0240] The physical environment credibility evaluation evaluates the credibility of the physical environment where the access subject is located based on the physical environment-related information of the access request subject. The processing flow of this module is as follows:

[0241] Preparation operation: Establish a physical environment credibility database to store physical locations and their corresponding credibility scores.

[0242] Execution stage:

[0243] Step 1: Obtain the physical location where the user is located.

[0244] Step 2: Query the physical environment credibility database to obtain the physical environment credibility score.

[0245] (IV) Module 4 - Network trustworthiness evaluation:

[0246] The network trustworthiness evaluation module comprehensively calculates its network trustworthiness score based on the identity credibility score, network environment credibility score, and physical environment credibility score of the access request subject. Figure 6 It is a schematic diagram of network trustworthiness evaluation in the trust evaluation method under the zero-trust security framework provided by this application. As Figure 6 shown, the processing flow of this module is as follows:

[0247] Preparation operation: Train the network trustworthiness evaluation model:

[0248] a. Prepare the data for training the model, generate input data according to the attribute data format, and obtain label data by means such as manual scoring and automatic generation of scores, so as to construct a training dataset;

[0249] b. Select a deep learning model for network trustworthiness evaluation. Optional deep learning models include but are not limited to DNN models, Transformer models, LLM models, etc. This model takes attribute data as input and outputs the network trustworthiness score;

[0250] c. Supervise and train the deep learning-based network trustworthiness evaluation model.

[0251] Execution stage:

[0252] Step 1: Obtain the identity credibility score, network environment credibility score, and physical environment credibility score from modules 1, 2, and 3 respectively.

[0253] Step 2: Network trustworthiness assessment. Input the data obtained in Step 1 into a trained network trustworthiness assessment model to obtain the network trustworthiness score.

[0254] In the embodiments of the present application, the data sources for trust assessment are divided into three categories: identity, network environment, and physical environment. Trust assessments are performed separately, and further, a comprehensive planned trust score is obtained. An alternative is to not classify the data sources but directly perform trust assessment based on all data sources.

[0255] It should be noted that the above examples are only for understanding the present application and do not constitute a limitation on the trust assessment method under the zero-trust security framework of the present application. Based on this technical concept, more forms of simple transformations are within the protection scope of the present application.

[0256] The present application also provides a trust assessment device under the zero-trust security framework. Figure 7 It is a schematic structural diagram of the trust assessment device provided by the present application under the zero-trust security framework, as Figure 7 shown. The trust assessment device under the zero-trust security framework includes:

[0257] A receiving module 701, configured to receive an access request message of a user to be evaluated;

[0258] A classification module 702, configured to classify the data in the access request message based on the physical meaning of the data corresponding to the access request message to obtain N types of attribute data; where N is an integer greater than 1;

[0259] A credibility score module 703, configured to perform credibility assessment on the N types of attribute data respectively to obtain the credibility scores corresponding to the N types of attribute data;

[0260] A trustworthiness assessment module 704, configured to input the credibility scores corresponding to the N types of attribute data into a pre-trained network trustworthiness assessment model, and the network trustworthiness assessment model is configured to evaluate the user to be evaluated based on the credibility scores corresponding to the N types of attribute data to obtain the network trustworthiness score corresponding to the user to be evaluated.

[0261] The trust evaluation device under the zero-trust security framework provided by this application adopts the trust evaluation method under the zero-trust security framework in the above-mentioned embodiments, and can solve the technical problems that in the current zero-trust security framework, most trust evaluation technologies rely on static rules, which easily lead to the problem of rule explosion and are difficult to update and manage. Compared with the prior art, the beneficial effects of the trust evaluation device under the zero-trust security framework provided by this application are the same as those of the trust evaluation method under the zero-trust security framework provided in the above-mentioned embodiments, and other technical features in the trust evaluation device under the zero-trust security framework are the same as the features disclosed in the method of the above-mentioned embodiments, which will not be elaborated here.

[0262] This application provides a trust evaluation device under the zero-trust security framework. The trust evaluation device under the zero-trust security framework includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the trust evaluation method under the zero-trust security framework in the above-mentioned embodiments.

[0263] Refer to the following Figure 8 , Figure 8 which is a schematic structural diagram of the trust evaluation device under the zero-trust security framework provided by this application, and shows a schematic structural diagram of the trust evaluation device under the zero-trust security framework suitable for implementing the embodiments of this application. The trust evaluation device under the zero-trust security framework in the embodiments of this application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions: tablet computers), PMPs (Portable Media Players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 8 The trust evaluation device shown under the zero-trust security framework is only an example and should not impose any limitations on the functions and usage scope of the embodiments of this application.

[0264] As Figure 8As shown, the trust evaluation device under the zero-trust security framework may include a processing device 801 (such as a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM: Read Only Memory) 802 or the program loaded from the storage device 803 into the random access memory (RAM: Random Access Memory) 804. In the RAM 804, various programs and data required for the operation of the trust evaluation device under the zero-trust security framework are also stored. The processing device 801, the ROM 802, and the RAM 804 are connected to each other through a bus 805. An input / output (I / O) interface 806 is also connected to the bus. Generally, the following systems may be connected to the I / O interface 806: an input device 807 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 808 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 803 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 809. The communication device 809 may allow the trust evaluation device under the zero-trust security framework to communicate with other devices wirelessly or wiredly to exchange data. Although the figure shows a trust evaluation device under the zero-trust security framework with various systems, it should be understood that it is not required to implement or have all the shown systems. More or fewer systems may be implemented or had alternatively.

[0265] In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains program codes for performing the methods shown in the flowcharts. In such an embodiment, the computer program can be downloaded and installed from the network through the communication device, or installed from the storage device 803, or installed from the ROM 802. When the computer program is executed by the processing device 801, the above functions defined in the methods of the embodiments disclosed in the present application are executed.

[0266] The trust evaluation device under the zero-trust security framework provided by this application adopts the trust evaluation method under the zero-trust security framework in the above embodiments, which can solve the technical problems that in the current zero-trust security framework, most trust evaluation technologies rely on static rules, easily lead to the problem of rule explosion, and are difficult to update and manage. Compared with the prior art, the beneficial effects of the trust evaluation device under the zero-trust security framework provided by this application are the same as those of the trust evaluation method under the zero-trust security framework provided in the above embodiments, and other technical features in the trust evaluation device under the zero-trust security framework are the same as the features disclosed in the method of the previous embodiment, which will not be elaborated here.

[0267] It should be understood that the various parts disclosed in this application can be implemented by hardware, software, firmware or a combination thereof. In the description of the above embodiments, specific features, structures, materials or characteristics can be combined in a suitable manner in any one or more embodiments or examples.

[0268] The above is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in this application, and all should be covered by the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.

[0269] This application provides a computer-readable storage medium with computer-readable program instructions (i.e., computer programs) stored thereon, and the computer-readable program instructions are used to execute the trust evaluation method under the zero-trust security framework in the above embodiments.

[0270] The computer-readable storage medium provided by this application can be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, devices, or components, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM) or flash memory, optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this embodiment, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, device, or component. The program code contained on the computer-readable storage medium can be transmitted by any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination of the above.

[0271] The above computer-readable storage medium can be included in a trust evaluation device under a zero-trust security framework; it can also exist independently and not be assembled into a trust evaluation device under a zero-trust security framework.

[0272] The above computer-readable storage medium carries one or more programs. When the one or more programs are executed by a trust evaluation device under a zero-trust security framework, the trust evaluation device under the zero-trust security framework is caused to perform the following steps:

[0273] Receive an access request message from a user to be evaluated;

[0274] Based on the physical meaning of the data corresponding to the access request message, classify the data in the access request message to obtain N types of attribute data; where N is an integer greater than 1;

[0275] Respectively perform credibility evaluations on the N types of attribute data to obtain credibility scores corresponding to the N types of attribute data;

[0276] Input the credibility scores corresponding to the N types of attribute data into a pre-trained network trustworthiness evaluation model, and the network trustworthiness evaluation model evaluates the user to be evaluated based on the credibility scores corresponding to the N types of attribute data to obtain a network trustworthiness score corresponding to the user to be evaluated.

[0277] Computer program code for performing the operations of this application can be written in one or more programming languages or combinations thereof. The above-mentioned programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as an independent software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any kind of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).

[0278] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of this application. In this regard, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks can occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown can actually be executed substantially in parallel, and they can sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as the combination of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0279] The modules described in the embodiments of this application can be implemented in software or in hardware. Among them, the name of the module does not constitute a limitation on the unit itself in some cases.

[0280] The readable storage medium provided by this application is a computer-readable storage medium. The computer-readable storage medium stores computer-readable program instructions (i.e., computer programs) for executing the trust evaluation method under the above zero-trust security framework, which can solve the technical problems that in the current zero-trust security framework, most trust evaluation technologies rely on static rules, easily lead to the problem of rule explosion, and are difficult to update and manage. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided by this application are the same as those of the trust evaluation method under the zero-trust security framework provided by the above embodiments, and will not be elaborated here.

[0281] This application also provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the steps of the trust evaluation method under the zero-trust security framework as described above.

[0282] The computer program product provided by this application can solve the technical problems that in the current zero-trust security framework, most trust evaluation technologies rely on static rules, easily lead to the problem of rule explosion, and are difficult to update and manage. Compared with the prior art, the beneficial effects of the computer program product provided by this application are the same as those of the trust evaluation method under the zero-trust security framework provided by the above embodiments, and will not be elaborated here.

[0283] The above are only some embodiments of this application, and thus do not limit the patent scope of this application. Any equivalent structural transformation made by using the content of the specification and drawings of this application under the technical concept of this application, or any direct / indirect application in other related technical fields, is included in the patent protection scope of this application.

Claims

1. A trust assessment method under a zero-trust security framework, characterized in that: The method comprises: Receive an access request message from a user to be evaluated; Based on the physical meaning corresponding to the data in the access request message, classify the data in the access request message to obtain N types of attribute data; wherein N is an integer greater than 1; Performing credibility evaluation on the N types of attribute data respectively to obtain credibility scores corresponding to the N types of attribute data; The credibility scores corresponding to the N types of attribute data are input into a pre-trained network trust evaluation model, and the network trust evaluation model evaluates the user to be evaluated based on the credibility scores corresponding to the N types of attribute data to obtain the network trust score corresponding to the user to be evaluated.

2. The method according to claim 1, characterized in that The data in the access request message is classified based on the physical meaning corresponding to the data in the access request message to obtain N types of attribute data, including: Based on the physical meaning corresponding to the data in the access request message, the data in the access request message is divided into identity attribute data, network environment attribute data and physical environment attribute data.

3. The method according to claim 2, characterized in that The performing credibility evaluation on the N types of attribute data respectively to obtain credibility scores corresponding to the N types of attribute data includes: Based on the identity attribute data and the pre-trained identity credibility evaluation model, the identity credibility of the user to be evaluated is evaluated to obtain an identity credibility score; Based on the network environment attribute data and a pre-trained network environment credibility evaluation model, the credibility of the network environment where the user to be evaluated is located is evaluated to obtain a network environment credibility score; Based on the physical environment attribute data and a pre-established physical environment credibility database, the credibility of the physical environment of the user to be evaluated is evaluated to obtain a physical environment credibility score; The step of inputting the credibility scores corresponding to the N types of attribute data into a pre-trained network trust evaluation model, and having the network trust evaluation model evaluate the user to be evaluated based on the credibility scores corresponding to the N types of attribute data to obtain the network trust score corresponding to the user to be evaluated, comprises: The identity credibility score, the network environment credibility score and the physical environment credibility score are input into the network trust evaluation model, and the network trust evaluation model evaluates the user to be evaluated based on the identity credibility score, the network environment credibility score and the physical environment credibility score to obtain the network trust score corresponding to the user to be evaluated.

4. The method according to claim 3, characterized in that The step of evaluating the identity credibility of the user to be evaluated based on the identity attribute data and the pre-trained identity credibility evaluation model to obtain an identity credibility score includes: Based on the identity attribute data, determining the identity credibility data of the user to be evaluated; Preprocessing the identity credibility data; The preprocessed identity credibility data is input into the identity credibility evaluation model to obtain the identity credibility score output by the identity credibility evaluation model.

5. The method according to claim 4, characterized in that The step of determining the identity credibility data of the user to be evaluated based on the identity attribute data includes: If the identity attribute data includes a terminal number, the terminal number is used to match the pre-established list of frequently used terminal devices of the user to obtain a first result indicating whether there is a match; If the identity attribute data includes the initiation time of the access request, the initiation time is used to match in a pre-established user time activity database to obtain a second result representing the activity of the time period in which the access request is initiated; If the identity attribute data includes the initiation time and location of the access request, the initiation time and location are used to match in a pre-established user location activity database to obtain a third result representing the activity of the location where the access request was initiated; If the identity attribute data includes biometric authentication information, performing biometric authentication using the biometric authentication information to obtain a fourth result representing the biometric authentication result; If the identity attribute data includes an input password, password authentication is performed using the input password to obtain a fifth result representing a password authentication result; If the identity attribute data includes authoritative identity information, authentication is performed using the authoritative identity information to obtain a sixth result representing an authoritative identity authentication result; If the identity attribute data includes human-machine authentication information, then use the human-machine authentication information to perform authentication to obtain a seventh result representing the human-machine authentication result; If the identity attribute data includes expected information, authentication is performed using the expected information to obtain an eighth result representing the expected authentication result; At least one of the first result, the second result, the third result, the fourth result, the fifth result, the sixth result, the seventh result and the eighth result is selected as the identity credibility data of the user to be evaluated.

6. The method according to claim 4 or 5, characterized in that The preprocessing of the identity credibility data includes: Convert the identity credibility data to a floating point type. Normalize the identity credibility data converted into floating-point type.

7. The method according to claim 3, characterized in that The step of evaluating the credibility of the network environment where the user to be evaluated is located based on the network environment attribute data and a pre-trained network environment credibility evaluation model to obtain a network environment credibility score includes: Determining the network environment credibility data of the user to be evaluated based on the network environment attribute data; Preprocessing the network environment credibility data; The preprocessed network environment credibility data is input into the network environment credibility evaluation model to obtain the network environment credibility score output by the network environment credibility evaluation model.

8. The method according to claim 7, characterized in that The determining, based on the network environment attribute data, the network environment credibility data of the user to be evaluated includes: If the network environment attribute data includes a device brand, the device brand is used to perform a match in a pre-established device social credit database to obtain a ninth result representing a device social credit score corresponding to the device brand; If the network environment attribute data includes a trusted platform module TPM configuration, determining whether to enable the TPM using the TPM configuration, and obtaining a tenth result indicating whether the TPM is enabled; If the network environment attribute data includes a secure boot configuration, determining whether to enable secure boot using the secure boot configuration to obtain an eleventh result indicating whether secure boot is enabled; If the network environment attribute data includes a software vulnerability list, matching the software vulnerability list in a pre-established software vulnerability information database is performed to obtain a twelfth result representing a vulnerability score corresponding to the software vulnerability list; If the network environment attribute data includes a software version number, the software version number is used to match the software version information library established in advance to obtain a thirteenth result representing the software version score corresponding to the software version number; If the network environment attribute data includes a security patch list, matching is performed using the security patch list in a pre-established security patch information library to obtain a fourteenth result representing a security patch score corresponding to the security patch list; If the network environment attribute data includes communication protocol security information, using the communication protocol security information to determine a fifteenth result representing a communication protocol security assessment result; If the network environment attribute data includes an encryption algorithm used, matching the encryption algorithm in a pre-established encryption algorithm database is performed to obtain a sixteenth result representing an encryption algorithm score corresponding to the encryption algorithm; If the network environment attribute data includes access network security information, determining a seventeenth result representing an access network security assessment result using the access network security information; At least one of the ninth result, the tenth result, the eleventh result, the twelfth result, the thirteenth result, the fourteenth result, the fifteenth result, the sixteenth result and the seventeenth result is selected as the network environment credibility data of the user to be evaluated.

9. The method according to claim 7 or 8, characterized in that The preprocessing of the network environment credibility data includes: Convert the type of the network environment credibility data into a floating point type; The network environment credibility data converted into floating point type is normalized.

10. The method according to claim 3, characterized in that The step of evaluating the credibility of the physical environment of the user to be evaluated based on the physical environment attribute data and a pre-established physical environment credibility database to obtain a physical environment credibility score includes: In the case where the physical environment attribute data includes the physical location of the user to be evaluated, the physical location is used to perform a match in a pre-established physical environment credibility database to obtain a physical environment credibility score corresponding to the physical location.

11. A trust assessment device under a zero-trust security framework, characterized in that: The device comprises: A receiving module, used for receiving an access request message from a user to be evaluated; A classification module, configured to classify the data in the access request message based on the physical meaning corresponding to the data in the access request message, to obtain N types of attribute data; wherein N is an integer greater than 1; A credibility scoring module is used to perform credibility evaluation on the N types of attribute data respectively to obtain credibility scores corresponding to the N types of attribute data; The trust evaluation module is used to input the credibility scores corresponding to the N types of attribute data into a pre-trained network trust evaluation model, and the network trust evaluation model evaluates the user to be evaluated based on the credibility scores corresponding to the N types of attribute data to obtain the network trust score corresponding to the user to be evaluated.

12. A trust assessment device under a zero-trust security framework, characterized in that: The device includes: a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the computer program is configured to implement the steps of a trust assessment method under a zero-trust security framework as described in any one of claims 1 to 10.

13. A storage medium, characterized in that: The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by the processor, the steps of the trust assessment method under the zero-trust security framework as described in any one of claims 1 to 10 are implemented.

14. A computer program product, characterized in that The computer program product includes a computer program, and when the computer program is executed by a processor, the steps of the trust assessment method under the zero-trust security framework as described in any one of claims 1 to 10 are implemented.