Data processing method and device based on zero trust, equipment and medium
Through interaction between the client and the server in the zero-trust network, the security level is determined based on the operation type and the credentials are allocated, the problem of insufficient data processing reliability in the zero-trust network is solved, and efficient and secure data access control is achieved.
Patent Information
- Application Number
- CN202410008065.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-02
- Publication Date
- 2025-07-04
AI Technical Summary
In the existing zero-trust network, due to the lag and rough control methods of centralized analysis and processing by the zero-trust server, data processing reliability is insufficient.
Through interaction between the zero-trust client and the server, the client carries the operation triggered when sending a data access request. The server determines the security level of the client and allocates credentials based on the operation type, and the client uses the credentials to access the data server.
It realizes timely and accurate data access control, improves the reliability and security of data processing, reduces transmission traffic, and improves processing efficiency and accuracy.
Smart Images

Figure CN120263428A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology. Specifically, it relates to a zero-trust-based data processing method, a zero-trust-based data processing device, an electronic device, and a computer-readable medium. Background Art
[0002] Currently, data access based on the zero-trust network has been promoted and popularized. The zero-trust network refers to establishing secure access control between the access subject (i.e., the party initiating the access) and the access object (i.e., the party being accessed) to improve the security of data access.
[0003] In the related art, a corresponding detection tool is installed on the zero-trust client side, and the data collected by the detection tool is uniformly sent to the zero-trust server. Then, the zero-trust server performs centralized analysis and processing. Furthermore, when the zero-trust server discovers a security problem during centralized analysis and processing, it blocks the data access of the device where the zero-trust client is located.
[0004] It can be seen that there are problems such as lag and rough control methods in the centralized analysis and processing by the zero-trust server in the related art. Therefore, how to improve the reliability of zero-trust-based data processing is an urgent problem to be solved. Summary of the Invention
[0005] The embodiments of this application provide a zero-trust-based data processing method, device, equipment, and medium. The zero-trust-based data processing has high timeliness and fine control granularity, improving the reliability of zero-trust-based data processing.
[0006] In a first aspect, the embodiments of this application provide a zero-trust-based data processing method, which is applied to a zero-trust server. The method includes: if a data access request sent by a zero-trust client is received, obtaining the operation triggered by the zero-trust client from the data access request; determining the security level of the zero-trust client based on the type of the operation; and allocating a credential for the zero-trust client based on the security level of the zero-trust client, so that the zero-trust client can use the credential to access data from a data server.
[0007] Second aspect, an embodiment of the present application provides a zero-trust-based data processing method, which is applied to a zero-trust client. The method includes: if an execution request for a target service is received, obtaining the triggered operation based on the execution request; generating a data access request based on the operation; sending the data access request to a zero-trust server, so that the zero-trust server determines the security level of the zero-trust client based on the type of the operation, and allocates a credential for the zero-trust client based on the security level of the zero-trust client; if the credential sent by the zero-trust server is received, using the credential to access data from a data server to execute the target service.
[0008] Third aspect, an embodiment of the present application provides a zero-trust-based data processing device, which is configured in a zero-trust server. The device includes: an obtaining module, configured to obtain the operation triggered by the zero-trust client from the data access request if a data access request sent by the zero-trust client is received; a determining module, configured to determine the security level of the zero-trust client based on the type of the operation; an allocating module, configured to allocate a credential for the zero-trust client based on the security level of the zero-trust client, so that the zero-trust client uses the credential to access data from a data server.
[0009] Fourth aspect, an embodiment of the present application provides a zero-trust-based data processing device, which is configured in a zero-trust client. The device includes: an obtaining module, configured to obtain the triggered operation based on the execution request if an execution request for a target service is received; a generating module, configured to generate a data access request based on the operation; a sending module, configured to send the data access request to a zero-trust server, so that the zero-trust server determines the security level of the zero-trust client based on the type of the operation, and allocates a credential for the zero-trust client based on the security level of the zero-trust client; an accessing module, configured to use the credential to access data from a data server to execute the target service if the credential sent by the zero-trust server is received.
[0010] Fifth aspect, an embodiment of the present application provides an electronic device, including one or more processors; a memory, configured to store one or more programs, and when the one or more programs are executed by the one or more processors, enabling the electronic device to implement the zero-trust-based data processing method as described above.
[0011] Sixth aspect, an embodiment of the present application provides a computer-readable medium, on which a computer program is stored, and when the computer program is executed by a processor, implementing the zero-trust-based data processing method as described above.
[0012] In a seventh aspect, an embodiment of the present application provides a computer program product, including computer instructions that, when executed by a processor, implement the above-described zero-trust-based data processing method.
[0013] In the technical solution provided by the embodiment of the present application: in zero-trust-based data access, the data access request sent by the zero-trust client carries the operation it triggers. Then, the zero-trust server determines the security situation of the zero-trust client based on the operation type carried in the data access request to determine whether to allocate a credential to it, so as to facilitate the zero-trust client to complete data access based on the allocated credential. That is, associating zero-trust data access with the operation triggered on the zero-trust client side can timely determine the security situation of the zero-trust client, improving the efficiency, accuracy, and security of data access control, etc., and greatly enhancing the reliability of zero-trust-based data processing.
[0014] It should be understood that the above general description and the following detailed description are only exemplary and explanatory, and cannot limit the present application. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] Figure 1 is a schematic diagram of an exemplary implementation environment to which the technical solution of the embodiment of the present application can be applied.
[0016] Figure 2 is a flowchart of a zero-trust-based data processing method shown in an exemplary embodiment of the present application.
[0017] Figure 3 is a flowchart of a zero-trust-based data processing method shown in another exemplary embodiment of the present application.
[0018] Figure 4 is a schematic diagram of matching a reported operation list with a target operation list shown in an exemplary embodiment of the present application.
[0019] Figure 5 is a schematic diagram of a misjudgment caused by a mismatch due to the out-of-sync operations stored in the zero-trust server and the zero-trust client shown in another exemplary embodiment of the present application.
[0020] Figure 6 is a flowchart of a zero-trust-based data processing method shown in another exemplary embodiment of the present application.
[0021] Figure 7 is a schematic diagram of matching a target access list with a candidate access list shown in another exemplary embodiment of the present application.
[0022] Figure 8It is a flowchart of a zero-trust based data processing method shown in an exemplary embodiment of the present application.
[0023] Figure 9 It is a flowchart of a zero-trust based data processing method shown in another exemplary embodiment of the present application.
[0024] Figure 10 It is a flowchart of a zero-trust based data processing method shown in another exemplary embodiment of the present application.
[0025] Figure 11 It is a schematic diagram of an exemplary implementation environment to which the technical solution of the embodiments of the present application can be applied.
[0026] Figure 12 It is a flowchart of a zero-trust based data processing method shown in another exemplary embodiment of the present application.
[0027] Figure 13 It is a block diagram of a zero-trust based data processing device shown in an exemplary embodiment of the present application.
[0028] Figure 14 It is a block diagram of a zero-trust based data processing device shown in an exemplary embodiment of the present application.
[0029] Figure 15 It is a schematic diagram of the structure of a computer system of an electronic device suitable for implementing the embodiments of the present application. Detailed implementation manners
[0030] Here, the exemplary embodiments will be described in detail, and the examples are shown in the drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements. The implementation manners described in the following exemplary embodiments do not represent all implementation manners of the present application. On the contrary, they are only examples of devices and methods that are the same as some aspects of the present application as detailed in the appended claims.
[0031] In the embodiments of the present application, the term "module" or "unit" refers to a computer program with a predetermined function or a part of a computer program, which works together with other related parts to achieve a predetermined goal, and can be fully or partially implemented by using software, hardware (such as a processing circuit or a memory), or a combination thereof. Similarly, one processor (or multiple processors or memories) can be used to implement one or more modules or units. In addition, each module or unit can be a part of the overall module or unit that includes the function of the module or unit.
[0032] The block diagrams shown in the accompanying drawings are merely functional entities and do not necessarily correspond to physically independent entities. That is, these functional entities can be implemented in software form, or implemented in one or more hardware modules or integrated circuits, or implemented in different networks and / or processor devices and / or microcontroller devices.
[0033] The flowcharts shown in the accompanying drawings are only illustrative and do not necessarily include all content and operations / steps, nor do they have to be executed in the described order. For example, some operations / steps can be decomposed, while some operations / steps can be combined or partially combined, so the actual execution order may change according to the actual situation.
[0034] It should be noted that "a plurality of" mentioned in this application means two or more. "And / or" describes the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. The character " / " generally represents an "or" relationship between the associated objects before and after.
[0035] Currently, data access based on the zero-trust network has been promoted and popularized, where the zero-trust network refers to improving the security of data access by establishing secure access control between the access subject (i.e., the party initiating the access) and the access object (i.e., the party being accessed).
[0036] In the related art, corresponding detection tools are installed on the zero-trust client side, and the data collected by the detection tools is uniformly sent to the zero-trust server side, and then the zero-trust server side performs centralized analysis and processing. Furthermore, when the zero-trust server side discovers security problems during centralized analysis and processing, it blocks the data access of the device where the zero-trust client is located. It can be seen that there are problems such as lag and rough control methods in the centralized analysis and processing by the zero-trust server side in the related art.
[0037] Therefore, in order to improve the reliability of zero-trust-based data processing and avoid problems such as lag and rough control methods in the centralized analysis and processing by the zero-trust server side, this application provides a zero-trust-based data processing solution. Please refer to Figure 1 , Figure 1 is a schematic diagram of an implementation environment involved in this application. This implementation environment mainly includes a terminal device 101 and a server 102, and the terminal device 101 and the server 102 can communicate through a wired or wireless network; among them:
[0038] The terminal device 101 is installed with a zero-trust client, and the zero-trust client includes, but is not limited to, verifying whether the user on the terminal device is trustworthy, verifying whether the terminal device is trustworthy, and verifying whether the application is trustworthy, etc.
[0039] Exemplarily, the zero-trust client can be a client of an intelligent office automation system (IOA, Intelligent Office Automation), that is, an IOA client. It can be understood that the IOA client has functions including but not limited to zero-trust office work, virus killing, compliance detection, and vulnerability repair. At the same time, in terms of the security implementation and protection of office work, it has capabilities including but not limited to fact protection, antivirus protection, and security reinforcement such as application entry protection and system underlying protection.
[0040] Exemplarily, the terminal device includes but not limited to a computer, a tablet, a laptop, a smart phone, a smart wearable device, etc.
[0041] The server 102 is installed with a zero-trust server. The zero-trust server performs security scheduling on the service traffic through a policy control engine and authorizes according to the granularity of person-terminal device-application. Among them, the zero-trust server includes but not limited to a user verification module for verifying whether a user is trustworthy, a device verification module for verifying whether a terminal device is trustworthy, and an application verification module for verifying whether an application is trustworthy, etc.
[0042] Exemplarily, the zero-trust server can be a server of an intelligent office automation system, that is, an IOA server.
[0043] Exemplarily, the server can be an independent physical server, or a server cluster or a distributed system composed of multiple physical servers. The server cluster or the distributed system includes cloud servers for providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), and big data and artificial intelligence platforms. There is no limitation here.
[0044] It should be noted that Figure 1 the numbers of the terminal device 101 and the server 102 in are merely illustrative. According to actual needs, there can be any number of terminal devices 101 and servers 102.
[0045] In an embodiment of the present application, the data processing method based on zero trust can be executed interactively by the zero-trust client and the zero-trust server.
[0046] Exemplarily, if the zero-trust client receives an execution request for a target service, it obtains the triggered operation based on the execution request, then generates a data access request based on the operation, and then sends the data access request to the zero-trust server;
[0047] Accordingly, the zero-trust server receives a data access request sent by the zero-trust client, obtains the operation triggered by the zero-trust client from the data access request, then determines the security level of the zero-trust client based on the type of the operation, and then allocates a credential to the zero-trust client based on the security level of the zero-trust client.
[0048] Accordingly, if the zero-trust client receives the credential sent by the zero-trust server, it uses the credential to access data from the data server to execute the target service.
[0049] Figure 1 The technical solutions of the illustrated embodiments can be applied to various scenarios. For example, they can be applied to the online office scenario, which can ensure an efficient and stable remote collaborative office experience and promote the application of zero-trust technology in the digital industry.
[0050] It should be noted that in the specific implementation of this application, when it comes to user-related data, when the embodiments of this application are applied to specific products or technologies, user permission or consent needs to be obtained, and the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions.
[0051] The following elaborates in detail on various implementation details of the technical solutions of the embodiments of this application:
[0052] Please refer to Figure 2 , Figure 2 which is a flowchart of a zero-trust-based data processing method shown in an embodiment of this application. This zero-trust-based data processing method can be executed by the zero-trust server. As Figure 2 shown, this zero-trust-based data processing method includes at least S201 to S203, which are introduced in detail as follows:
[0053] S201, if a data access request sent by the zero-trust client is received, obtain the operation triggered by the zero-trust client from the data access request.
[0054] In the embodiments of this application, after the zero-trust client receives an execution request for a target service, it obtains the operation triggered by the zero-trust client based on the execution request, generates a data access request based on the obtained operation triggered by the zero-trust client, and then sends the data access request to the zero-trust server; accordingly, the zero-trust server receives the data access request sent by the zero-trust client, and then can obtain the operation triggered by the zero-trust client from the data access request.
[0055] In the embodiments of this application, the data access request carries the operation triggered by the zero-trust client, and the operation carried by the data access request refers to the operation / activity triggered by the zero-trust client within the historical time period.
[0056] It can be understood that the historical time period refers to the time period before the current time point, that is, the past time period; for example, if the current time point is set as t2, then the historical time period is [t0, t1), where t0 is earlier than t1, and t1 is earlier than t2.
[0057] In an embodiment of the present application, the operation carried in the data access request may be an operation triggered by the zero-trust client within the most recent historical time period; for example, continuing the foregoing example, if the current time point is set as t2, then the most recent historical time period is [t1, t2), where t1 is earlier than t2.
[0058] In this way, by implementing the optional embodiment, the data access request carries the operation triggered by the zero-trust client within the most recent historical time period, which can better reflect the security situation of the zero-trust client, thereby improving the accuracy of data access control.
[0059] In an embodiment of the present application, the operation carried in the data access request may be an operation selected by the zero-trust client from multiple operations triggered by the zero-trust client within the historical time period, and the selected operation is a sensitive operation related to security.
[0060] That is to say, in the optional embodiment, the operation carried in the data access request is a sensitive operation selected by the zero-trust client from multiple operations triggered by the zero-trust client within the historical time period, which may be all or part of the operations triggered by the zero-trust client within the historical time period.
[0061] Among them, the sensitive operations in the optional embodiment include but are not limited to device firewall change events, sensitive system log trigger events, and sensitive registry detection activities, etc.; in practical applications, the sensitive operations can be flexibly set.
[0062] In this way, by implementing the optional embodiment, the data access request carries the sensitive operations triggered by the zero-trust client within the historical time period, reducing the data volume of the data access request, thereby improving the transmission rate of the data access request, saving transmission traffic, and having high reliability of data access control.
[0063] S202. Determine the security level of the zero-trust client based on the type of the operation.
[0064] In the embodiment of the present application, the zero-trust server obtains the operation triggered by the zero-trust client from the data access request, and then can determine the security level of the zero-trust client based on the type of the operation.
[0065] In the embodiments of the present application, the types of operations include, but are not limited to, the type with undetermined security level and the type with determined security level, etc. Among them, the type with undetermined security level refers to the type where the security situation of the operation cannot be clearly determined temporarily, and this may require waiting for the further execution of subsequent operations, etc. The type with determined security level is contrary to the type with undetermined security level. The type with determined security level refers to the type where the security situation of the operation can be clearly determined, and this does not require waiting for the further execution of subsequent operations, etc.
[0066] In the embodiments of the present application, the security level of the zero-trust client refers to a quantitative representation of the security situation of the zero-trust client.
[0067] In an embodiment of the present application, the process of determining the security level of the zero-trust client based on the type of operation in S202 may include:
[0068] If the operation belongs to the type with undetermined security level, determine that the zero-trust client has a security level equal to or higher than the preset client security level;
[0069] If the operation belongs to the type with determined security level, determine the security level of the zero-trust client based on the security level of the sensitive operation.
[0070] That is, in the alternative embodiment, determining the security level of the zero-trust client based on the type of operation includes two cases:
[0071] Case 1, if the operation belongs to the type with undetermined security level, determine that the zero-trust client has a security level equal to or higher than the preset client security level.
[0072] That is, if the operation belongs to the type with undetermined security level, at this time, the security situation of the operation cannot be determined, so it can be tentatively determined that the zero-trust client is secure, that is, tentatively determine that the zero-trust client has a security level equal to or higher than the preset client security level.
[0073] Case 2, if the operation belongs to the type with determined security level, determine the security level of the zero-trust client based on the security level of the sensitive operation.
[0074] That is, if the operation belongs to the type with determined security level, at this time, the security situation of the operation can be determined, so just determine the security level of the zero-trust client based on the security level of the sensitive operation.
[0075] In this way, by implementing the alternative embodiment, the security level of the zero-trust client can be simply and accurately determined using the type of operation, providing strong support for data access control.
[0076] In an embodiment of the present application, determining the security level of the zero-trust client based on the security level of the sensitive operation in Case 2 includes two cases:
[0077] Case 2.1, if the operation is equal to or higher than the preset operation security level, determine that the zero-trust client has a security level equal to or higher than the preset client security level.
[0078] Case 2.2, if the operation is lower than the preset operation security level, determine that the zero-trust client has a security level lower than the preset client security level.
[0079] That is, in the alternative embodiment for the operation of the security level determination type, the security level of the operation is directly proportional to the security level of the zero-trust client. That is, the higher the security level of the operation, the higher the security level of the zero-trust client. Conversely, the lower the security level of the operation, the lower the security level of the zero-trust client.
[0080] In this way, by implementing the alternative embodiment, for the operation of the security level determination type, the security level of the zero-trust client can be simply and accurately determined using the security level of the security level determination type operation, providing strong support for data access control.
[0081] In an embodiment of the present application, if there are multiple operations carried in the data access request, the security level of the zero-trust client can be determined in parallel based on the type of each operation. At the same time, as long as it is determined based on any one operation that the zero-trust client has a security level lower than the preset client security level, that is, it is determined that the zero-trust client is insecure, then the determination of the security level of the zero-trust client based on the type of operation can be suspended.
[0082] In this way, by implementing the alternative embodiment, taking the determined insecurity of the zero-trust client as the criterion, corresponding security management and control can be carried out in a timely manner, ensuring the security of data access; at the same time, the determination of the security level of the zero-trust client based on the type of operation is executed in parallel, improving the determination efficiency of the security level of the zero-trust client; in addition, after it is determined that the zero-trust client is insecure, the determination of the security level of the zero-trust client based on the type of operation is no longer executed, saving computing resources.
[0083] S203, allocate a credential to the zero-trust client based on the security level of the zero-trust client, so that the zero-trust client can use the credential to access data from the data server.
[0084] In the embodiment of the present application, the zero-trust server determines the security level of the zero-trust client, and then can allocate a credential to the zero-trust client based on the security level of the zero-trust client.
[0085] In the embodiment of the present application, the credential refers to a proof issued by the zero-trust server for the zero-trust client to access the data server, and it can be a ticket.
[0086] In an embodiment of the present application, the process of allocating a credential to a zero-trust client based on the security level of the zero-trust client in S203 may include:
[0087] If the security level of the zero-trust client is equal to or higher than the preset client security level, obtain a credential from the credential storage area and allocate the credential to the zero-trust client;
[0088] If the security level of the zero-trust client is lower than the preset client security level, reject allocating a credential to the zero-trust client.
[0089] That is, in an alternative embodiment, allocating a credential to a zero-trust client based on the security level of the zero-trust client includes two cases:
[0090] Case 1, if the security level of the zero-trust client is equal to or higher than the preset client security level, obtain a credential from the credential storage area and allocate the credential to the zero-trust client.
[0091] That is, if the security level of the zero-trust client is equal to or higher than the preset client security level, at this time the zero-trust client is secure, so a credential can be allocated to the zero-trust client, enabling the zero-trust client to access data from the data server.
[0092] Case 2, if the security level of the zero-trust client is lower than the preset client security level, reject allocating a credential to the zero-trust client.
[0093] That is, if the security level of the zero-trust client is lower than the preset client security level, at this time the zero-trust client is insecure, so a credential cannot be allocated to the zero-trust client, preventing the zero-trust client from accessing data from the data server.
[0094] In this way, by implementing the alternative embodiment, it is possible to simply and accurately determine whether to allocate a credential to a zero-trust client using the security level of the zero-trust client, providing strong support for data access control.
[0095] In an embodiment of the present application, the process of allocating a credential to a zero-trust client in Case 1 may include:
[0096] If the operation belongs to the type with undetermined security level, generate usage restriction information for the credential; where the usage restriction information includes at least one of time restriction and usage times restriction;
[0097] Send the credential and the usage restriction information to the zero-trust client so that the zero-trust client uses the credential based on the usage restriction information.
[0098] That is, in an alternative embodiment, for an operation of the type with undetermined security level, after obtaining a credential from the credential storage area, usage restriction information for the credential may also be generated, and the credential and the usage restriction information for the credential are sent to the zero-trust client; correspondingly, the zero-trust client receives the credential and the usage restriction information for the credential sent by the zero-trust server, and uses the credential in accordance with the usage restriction information for the credential.
[0099] Among them, the usage restriction information for the credential in the alternative embodiment refers to information related to the usage restriction of the credential, which stipulates the usage scope of the credential, and it is invalid to use the credential beyond the usage scope of the credential. The usage restriction information includes, but is not limited to, time restriction and number of uses restriction, etc.; the time restriction refers to that the credential needs to be used within a specified time period, or the maximum duration for which the credential can be used, etc., and the number of uses restriction refers to the maximum number of times the credential can be used.
[0100] In this way, by implementing the alternative embodiment, for an operation of the type with undetermined security level, the usage restriction of the credential assigned thereto is specified, balancing the normal execution of the service and the security of data access control, and at the same time improving the flexibility of credential allocation, which is applicable to many scenarios.
[0101] In an embodiment of the present application, after the process of allocating a credential to the zero-trust client in Case 1, the method may further include:
[0102] If it is detected that the security level corresponding to an operation of the type with undetermined security level is lower than the preset operation security level, or it is detected that the security level corresponding to an operation of the type with determined security level has decreased, then in the verification operation for the credential, control is exerted to make the verification of the credential fail, so as to reject the zero-trust client from accessing data from the data server using the credential.
[0103] That is, in an alternative embodiment, the operation carried in the data access request may be continuously detected. If it is detected that the security level corresponding to an operation of the type with undetermined security level is lower than the preset operation security level, or it is detected that the security level corresponding to an operation of the type with determined security level has decreased, it indicates that the security of the operation has changed, and the operation is insecure, that is, the zero-trust client is insecure at this time. Therefore, control can be exerted in the verification operation for the credential to make the verification of the credential fail, so that the zero-trust client cannot access data from the data server.
[0104] It can be understood that after the zero-trust client obtains the credentials assigned by the zero-trust server, it uses the credentials to access data from the data server. Specifically, the intelligent gateway between the zero-trust client and the data server will initiate a verification operation of the credentials to the zero-trust server, and then the zero-trust server will implement the verification operation of the credentials. After that, when the verification of the credentials passes, the zero-trust client can successfully access data from the data server, and when the verification of the credentials fails, the zero-trust client cannot access data from the data server.
[0105] In this way, by implementing the optional embodiment, after the credentials are assigned to the zero-trust client, the operations carried in the data access request are continuously detected, and when it is detected that the zero-trust client is insecure, the verification of the credentials is timely controlled to fail (which can be simply understood as recycling the credentials), improving the security of data access control and at the same time improving the flexibility of data access control, and being applicable to many scenarios.
[0106] In the embodiment of the present application, the zero-trust server determines the security status of the zero-trust client based on the operation type carried in the data access request sent by the zero-trust client to determine whether to assign credentials to it, so as to facilitate the zero-trust client to complete data access based on the assigned credentials. In this way, the zero-trust data access is associated with the operations triggered on the zero-trust client side, enabling the timely determination of the security status of the zero-trust client, improving the efficiency, accuracy, and security of data access control, etc., and greatly improving the reliability of data processing based on zero trust.
[0107] In an embodiment of the present application, another zero-trust-based data processing method is provided, and this zero-trust-based data processing method can be executed by the zero-trust server. As Figure 3 shown, this zero-trust-based data processing method may further include S301 to S303 after S201 (or S202 or S203).
[0108] In the embodiment of the present application, there are multiple operations carried in the data access request, and the multiple carried operations are arranged in sequence in the target operation list; for example, use E1 to represent the target operation list, E1 = {e1, e2, e3,... en}, where e1, e2, e3,... en are all operations.
[0109] S301 to S303 are introduced in detail as follows:
[0110] S301, obtain the reported operation list corresponding to the zero-trust client from the local operation storage area; wherein, the reported operation list is the zero-trust client's record of multiple operations triggered by the zero-trust client and reported to the zero-trust server.
[0111] In the embodiment of the present application, the local operation storage area refers to the storage area located locally in the zero-trust server for storing operations.
[0112] It can be understood that the zero-trust client will record multiple operations triggered by the zero-trust client to generate a reported operation list, and send the reported operation list to the zero-trust server; correspondingly, the zero-trust server receives the reported operation list sent by the zero-trust client and stores the reported operation list in the local operation storage area.
[0113] In the embodiment of the present application, the zero-trust server can obtain the reported operation list corresponding to the zero-trust client from the local operation storage area; for example, use E2 to represent the reported operation list, E2 = {e1’, e2’, e3’, … en’}, where e1’, e2’, e3’, … en’ are all operations.
[0114] S302, match the reported operation list with the target operation list to obtain a matching result.
[0115] In the embodiment of the present application, after the zero-trust server obtains the reported operation list and the target operation list, it can match the reported operation list with the target operation list to obtain a matching result. Specifically, it is to match the multiple operations included in the reported operation list with the multiple operations included in the target operation list to obtain a matching result.
[0116] For example, continuing with the previous example, please refer to Figure 4 , match E2{e1’, e2’, e3’, … en’} with E1{e1, e2, e3, … en} respectively to obtain a matching result.
[0117] In an embodiment of the present application, the process of matching the reported operation list with the target operation list in S302 to obtain a matching result may include:
[0118] Obtain the first time period corresponding to the operations included in the reported operation list, and obtain the second time period corresponding to the operations included in the target operation list;
[0119] If the first time period and the second time period do not match, synchronize the reported operation list corresponding to the zero-trust client in the local operation storage area so that the first time period corresponding to the operations included in the synchronized reported operation list matches the second time period;
[0120] Match the target operation list with the synchronized reported operation list to obtain a matching result.
[0121] As introduced in the foregoing embodiments, the reported operation list corresponding to the zero-trust client stored in the local operation storage area of the zero-trust server is sent by the zero-trust client. Since sending requires a sending duration, during this sending duration, the zero-trust client may record newly triggered operations. Therefore, the zero-trust server and the zero-trust client are not fully synchronized with respect to the operations triggered by the zero-trust client, and thus there may be a misjudgment phenomenon of matching failure due to the out-of-sync operations stored in the zero-trust server and the zero-trust client.
[0122] For ease of understanding, as Figure 5 shown, the zero-trust client records multiple operations triggered by the zero-trust client in the historical time period [t0, t1] to generate a reported operation list, and sends the reported operation list to the zero-trust server. At time point t2, it records a newly triggered operation. At this time, the zero-trust server stores the reported operation list corresponding to the historical time period [t0, t1] in the local operation storage area, and does not store the reported operation list corresponding to time point t2. The operations stored in the zero-trust server and the zero-trust client are out of sync. The data access request sent by the zero-trust client may carry the operations triggered in the historical time period [t0, t2]. At this time, there is a misjudgment phenomenon of matching failure due to the out-of-sync operations stored in the zero-trust server and the zero-trust client.
[0123] Therefore, in an alternative embodiment, the first time period corresponding to the operations included in the reported operation list can be obtained, and the second time period corresponding to the operations included in the target operation list can be obtained. Then, it is detected whether the first time period and the second time period match, and based on the matching situation of the first time period and the second time period, it is determined whether to match the target operation list with the synchronized reported operation list.
[0124] Among them, in an alternative embodiment, determining whether to match the target operation list with the synchronized reported operation list based on the matching situation of the first time period and the second time period includes two cases:
[0125] Case 1, if the first time period and the second time period do not match, the reported operation list corresponding to the zero-trust client in the local operation storage area is synchronized so that the first time period corresponding to the operations included in the synchronized reported operation list matches the second time period. At this time, the zero-trust server and the zero-trust client are fully synchronized with respect to the operations triggered by the zero-trust client. Therefore, the target operation list can be matched with the synchronized reported operation list.
[0126] For example, assume that the first time period corresponding to the operations included in the reported operation list is [t0, t1], and the second time period corresponding to the operations included in the target operation list is [t0, t2]. Then, synchronize the reported operation list corresponding to the zero-trust client in the local operation storage area so that the first time period corresponding to the operations included in the synchronized reported operation list is [t0, t2], thus matching the second time period [t0, t2]. It can be understood that during synchronization, the operations triggered by the zero-trust client in the historical time period (t1, t2] can be added to the reported operation list corresponding to the zero-trust client in the local operation storage area.
[0127] Case 2, if the first time period and the second time period match, at this time, the zero-trust server and the zero-trust client have been fully synchronized for the operations triggered by the zero-trust client. Therefore, it is only necessary to match the target operation list with the synchronized reported operation list.
[0128] In this way, by implementing the optional embodiment, the comparison of time periods is used to ensure that the zero-trust server and the zero-trust client have been fully synchronized for the operations triggered by the zero-trust client, avoiding the misjudgment phenomenon of matching failure caused by the out-of-synchronization of the operations stored in the zero-trust server and the zero-trust client, and improving the accuracy of data access control.
[0129] S303, detect the zero-trust client and the zero-trust server based on the obtained matching result.
[0130] In the embodiment of the present application, after the zero-trust server obtains the matching result, it can detect the zero-trust client and the zero-trust server based on the obtained matching result.
[0131] In an embodiment of the present application, the process of detecting the zero-trust client and the zero-trust server based on the obtained matching result in S303 may include:
[0132] If the obtained matching result indicates that the target operation list does not match the reported operation list, and there are missing operations in the target operation list, then obtain a detection result indicating that the zero-trust client has been attacked;
[0133] If the obtained matching result indicates that the target operation list does not match the reported operation list, and there are missing operations in the reported operation list, then obtain a detection result indicating that the zero-trust server has been attacked.
[0134] That is, in the optional embodiment, detecting the zero-trust client and the zero-trust server based on the obtained matching result includes two cases:
[0135] Case 1, if the obtained matching result indicates that the target operation list does not match the reported operation list and there are missing operations in the target operation list, then a detection result for indicating that the zero-trust client is under attack is obtained.
[0136] That is, the target operation list does not match the reported operation list and there are missing operations in the target operation list, indicating that the reported operation list of the zero-trust server is complete, while the target operation list of the zero-trust client is not complete. At this time, it may be that the zero-trust client is under attack, resulting in an incomplete target operation list.
[0137] Exemplarily, the zero-trust client being under attack includes, but is not limited to, the zero-trust access service corresponding to the zero-trust client being blindly attacked, resulting in anomalies / failures, etc.; among them, the zero-trust access service can be a service responsible for access-related services.
[0138] Case 2, if the obtained matching result indicates that the target operation list does not match the reported operation list and there are missing operations in the target operation list, then a detection result for indicating that the zero-trust server is under attack is obtained.
[0139] That is, the target operation list does not match the reported operation list and there are missing operations in the reported operation list, indicating that the target operation list of the zero-trust client is complete, while the reported operation list of the zero-trust server is not complete. At this time, it may be that the zero-trust server is under attack, resulting in an incomplete reported operation list.
[0140] Exemplarily, the zero-trust server being under attack includes, but is not limited to, the zero-trust receiving service corresponding to the zero-trust server being blindly attacked, resulting in anomalies / failures, etc.; among them, the zero-trust receiving service can be a service responsible for data reception-related services.
[0141] In this way, by implementing the optional embodiment, the detection result of the zero-trust client being attacked or the detection result of the zero-trust server being attacked can be simply and accurately obtained by comparing the operation lists.
[0142] It should be clear that Figure 2 in the shown embodiment, the security situation of the zero-trust client is detected through the operations carried in the data access request itself (i.e., the operations contained in the target operation list) to allocate credentials to the zero-trust client, while Figure 3 in the shown embodiment, the security situation of the zero-trust client and the security situation of the zero-trust server are detected by comparing the target operation list and the reported operation list.
[0143] It should be noted that Figure 3 for the detailed introduction of S201 to S203 shown, please refer to Figure 2 S201 to S203 shown, which will not be elaborated here.
[0144] In the embodiment of the present application, the zero-trust server realizes the detection of the zero-trust client and the zero-trust server by comparing the operation lists, provides strong support for the security management and control of the zero-trust client and the zero-trust server, and thus improves the security of data access control.
[0145] In an embodiment of the present application, another zero-trust-based data processing method is provided, and this zero-trust-based data processing method can be executed by a zero-trust server. As Figure 6 shown, after S201 (or S202 or S203), this zero-trust-based data processing method may further include S601 to S604.
[0146] S601 to S604 are introduced in detail as follows:
[0147] S601, if the marked data sent by the zero-trust client is received, extract the target access list corresponding to the zero-trust client from the marked data; wherein, the target access list is obtained by the zero-trust client recording the data access initiated by the zero-trust client.
[0148] In the embodiment of the present application, the zero-trust client will record the data access initiated by the zero-trust client to generate a target access list, and generate marked data based on the target access list and send it to the zero-trust server; correspondingly, the zero-trust server receives the marked data sent by the zero-trust client, and extracts the target access list corresponding to the zero-trust client from the marked data.
[0149] In the embodiment of the present application, the target access list includes the data access records initiated by the zero-trust client within the historical time period; for example, use A1 to represent the target access list, A1 = {a1, a2, a3,... an}, where a1, a2, a3,... an are all data access records.
[0150] It can be understood that the historical time period refers to the time period before the current time point, that is, the past time period; for example, assume that the current time point is t2, then the historical time period is [t0, t1), where t0 is earlier than t1, and t1 is earlier than t2.
[0151] In an embodiment of the present application, the data access records included in the target access list may be the data access records initiated by the zero-trust client within the most recent historical time period; for example, continuing the previous example, assume that the current time point is t2, then the most recent historical time period is [t1, t2), where t1 is earlier than t2.
[0152] In this way, by implementing the optional embodiment, the target access list includes the data access records initiated by the zero-trust client in the recent historical time period, which can better reflect the security situation of the zero-trust client, thereby improving the accuracy of data access control.
[0153] It should be clear that the historical time period corresponding to the target access list in the embodiments of the present application and the historical time period corresponding to the target operation list in the foregoing embodiments may be the same or different. In practical applications, it can be flexibly adjusted according to specific application scenarios.
[0154] S602, obtain the candidate access list corresponding to the zero-trust client from the local access record storage area; wherein, the candidate access list is obtained by the zero-trust server recording the data access initiated by the zero-trust client.
[0155] In the embodiments of the present application, the local access record storage area refers to the storage area located locally in the zero-trust server for storing data access records.
[0156] It can be understood that the zero-trust server will record the data access initiated by the zero-trust client to generate a candidate access list and store the candidate access list in the local access record storage area.
[0157] In the embodiments of the present application, the zero-trust server can obtain the candidate access list corresponding to the zero-trust client from the local access record storage area; for example, use A2 to represent the candidate access list, A2 = {a1’, a2’, a3’, … an’}, where a1’, a2’, a3’, … an’ are all data access records.
[0158] S603, match the target access list with the candidate access list to obtain a matching result.
[0159] In the embodiments of the present application, after the zero-trust server obtains the candidate access list and the target access list, it can match the candidate access list with the target access list to obtain a matching result. Specifically, it is to match the multiple data access records contained in the candidate access list with the multiple data access records contained in the target access list to obtain a matching result.
[0160] Illustrate with an example. For example, continuing with the foregoing example, please refer to Figure 7 , match A2{a1’, a2’, a3’, … an’} with A1{a1, a2, a3, … an} respectively to obtain a matching result.
[0161] S604, detect the zero-trust client and the zero-trust server based on the obtained matching result.
[0162] In the embodiment of the present application, the zero-trust server obtains a matching result, and then can detect the zero-trust client and the zero-trust server based on the obtained matching result.
[0163] In an embodiment of the present application, the process of detecting the zero-trust client and the zero-trust server based on the obtained matching result in S604 may include:
[0164] If the obtained matching result indicates that the target access list does not match the candidate access list, and there are missing data access records in the target access list, then a detection result indicating that the zero-trust client is under attack is obtained;
[0165] If the obtained matching result indicates that the target access list does not match the candidate access list, and there are missing data access records in the candidate access list, then a detection result indicating that the zero-trust server is under attack is obtained.
[0166] That is, in the alternative embodiment, detecting the zero-trust client and the zero-trust server based on the obtained matching result includes two cases:
[0167] Case 1, if the obtained matching result indicates that the target access list does not match the candidate access list, and there are missing data access records in the target access list, then a detection result indicating that the zero-trust client is under attack is obtained.
[0168] That is, the target access list does not match the candidate access list, and there are missing data access records in the target access list, indicating that the candidate access list of the zero-trust server is complete, while the target access list of the zero-trust client is not complete. At this time, it may be that the zero-trust client is under attack, resulting in an incomplete target access list.
[0169] Exemplarily, the zero-trust client being under attack includes, but is not limited to, the operation detection module corresponding to the zero-trust client being blindly struck resulting in anomalies / failures, the data reporting module being blindly struck resulting in anomalies / failures, etc.; among them, the operation detection module may be a module responsible for collecting / sending operations triggered by the zero-trust client (i.e., reporting the operation list), and the data reporting module may be a module responsible for sending data access requests (carrying the target operation list).
[0170] Case 2, the obtained matching result indicates that the target access list does not match the candidate access list, and there are missing data access records in the target access list, then a detection result indicating that the zero-trust server is under attack is obtained.
[0171] That is, the target access list does not match the candidate access list, and there are missing data access records in the candidate access list, indicating that the target access list of the zero-trust client is complete, while the candidate access list of the zero-trust server is not complete. In this case, it may be that the zero-trust server has been attacked, resulting in an incomplete candidate access list.
[0172] Exemplarily, the attack on the zero-trust server includes, but is not limited to, the operation receiving module corresponding to the zero-trust server being blindly struck resulting in anomalies / failures, the data receiving module being blindly struck resulting in anomalies / failures, etc.; among them, the receiving module can be a module responsible for receiving the operations triggered by the zero-trust client (i.e., reporting the operation list), and the data receiving module can be a module responsible for receiving the data access requests sent by the zero-trust client (carrying the target operation list).
[0173] In this way, by implementing the optional embodiment, the detection result of the zero-trust client being attacked or the detection result of the zero-trust server being attacked can be easily obtained by comparing the access lists.
[0174] In an embodiment of the present application, the candidate access list can be extracted multiple times and the candidate access list can be obtained. The target access list is respectively matched with the candidate access list. After the number of matching results indicating that the target access list does not match the candidate access list and there are missing data access records in the target access list reaches a preset quantity threshold, it is determined that the zero-trust client has been attacked; similarly, after the number of matching results indicating that the target access list does not match the candidate access list and there are missing data access records in the candidate access list reaches a preset quantity threshold, it is determined that the zero-trust server has been attacked.
[0175] In this way, by implementing the optional embodiment, the detection result of the zero-trust client being attacked or the detection result of the zero-trust server being attacked can be accurately obtained by comparing the access lists multiple times.
[0176] It should be clear that Figure 2 in the illustrated embodiment, the security situation of the zero-trust client is detected through the operations carried in the data access request itself (i.e., the operations contained in the target access list) to allocate credentials to the zero-trust client, while Figure 6 in the illustrated embodiment, the security situation of the zero-trust client and the zero-trust server is detected through the comparison between the target access list and the candidate access list.
[0177] It should be noted that Figure 6 for the detailed introduction of S201 to S203 shown, please refer to Figure 2 S201 to S203 shown, which will not be elaborated here.
[0178] In the embodiment of the present application, the zero-trust server realizes the detection of the zero-trust client and the zero-trust server by comparing the access list, provides strong support for the security management and control of the zero-trust client and the zero-trust server, and further improves the security of data access control.
[0179] It should be noted that Figures 2 to 7 The illustrated embodiment is described from the perspective of the zero-trust server. The following combines Figures 8 to 10 From the perspective of the zero-trust client, the implementation details of the technical solution of the embodiment of the present application are described in detail:
[0180] In an embodiment of the present application, another zero-trust-based data processing method is provided, and this zero-trust-based data processing method can be executed by a zero-trust client. As Figure 8 shown, this zero-trust-based data processing method may include S801 to S804.
[0181] S801 to S804 are introduced in detail as follows:
[0182] S801, if an execution request for a target service is received, obtain the triggered operation based on the execution request.
[0183] In the embodiment of the present application, when the service party has an execution requirement for the target service, the service party can issue an execution request for the target service and send the execution request for the target service to the zero-trust client; correspondingly, the zero-trust client receives the execution request for the target service sent by the service party, and then can obtain the operation triggered by the zero-trust client based on the execution request.
[0184] In an embodiment of the present application, the process of obtaining the triggered operation based on the execution request in S801 may include:
[0185] Select sensitive operations related to security from multiple operations stored in the local operation storage area based on the execution request; among them, the multiple operations are triggered by the zero-trust client.
[0186] Among them, in an alternative embodiment, the local operation storage area refers to the storage area located locally in the zero-trust client for storing operations.
[0187] It can be understood that the zero-trust client will record the multiple operations triggered by the zero-trust client to generate a reported operation list and store the reported operation list in the local operation storage area corresponding to the zero-trust client.
[0188] That is, in an alternative embodiment, the zero-trust client selects sensitive operations related to security from multiple operations stored in the local operation storage area based on an execution request, which may be all or part of the operations triggered by the zero-trust client.
[0189] Among them, sensitive operations in the alternative embodiment include, but are not limited to, device firewall change events, sensitive system log trigger events, and sensitive registry detection activities, etc.; in actual applications, sensitive operations can be flexibly set.
[0190] In this way, by implementing the alternative embodiment, sensitive operations related to security are selected from multiple operations stored in the local operation storage area, providing strong support for the generation of data access requests.
[0191] S802, generate a data access request based on the operation.
[0192] In the embodiment of the present application, the zero-trust client obtains the triggered operations, and then can generate a data access request based on the obtained operations.
[0193] In an embodiment of the present application, if the zero-trust client selects sensitive operations related to security from multiple operations stored in the local operation storage area based on an execution request, correspondingly, the process of generating a data access request based on the operation in S802 may include:
[0194] Generate a data access request based on the sensitive operation.
[0195] That is, in the alternative embodiment, the zero-trust client generates a data access request based on the sensitive operations related to security selected from multiple operations stored in the local operation storage area.
[0196] In this way, by implementing the alternative embodiment, a data access request is generated based on the sensitive operations triggered by the zero-trust client, reducing the data volume of the data access request, thereby improving the transmission rate of the data access request, saving transmission traffic, and having high reliability in data access control.
[0197] S803, send the data access request to the zero-trust server, so that the zero-trust server determines the security level of the zero-trust client based on the type of the operation, and allocates a credential to the zero-trust client based on the security level of the zero-trust client.
[0198] In the embodiments of the present application, a data access request is generated, and then the data access request can be sent to the zero-trust server; correspondingly, the zero-trust server receives the data access request sent by the zero-trust client, determines the security level of the zero-trust client based on the type of operation carried in the data access request, and allocates a credential for the zero-trust client based on the security level of the zero-trust client. For the specific implementation process, please refer to the foregoing embodiments and will not be elaborated here.
[0199] S804, if a credential sent by the zero-trust server is received, use the credential to access data from the data server to execute the target service.
[0200] In the embodiments of the present application, if the zero-trust client receives the credential sent by the zero-trust server, it can use the credential to access data from the data server to execute the target service. On the contrary, if the zero-trust client does not receive the credential sent by the zero-trust server, it cannot access data from the data server to execute the target service.
[0201] In the embodiments of the present application, the zero-trust client carries the operation it triggers in the data access request and sends the data access request to the zero-trust server. Furthermore, the zero-trust server determines the security situation of the zero-trust client based on the type of operation carried in the data access request to determine whether to allocate a credential for it, so as to facilitate the zero-trust client to complete data access based on the allocated credential. In this way, associating the zero-trust data access with the operation triggered on the zero-trust client side can timely determine the security situation of the zero-trust client, improving the efficiency, accuracy, and security of data access control, etc., and greatly improving the reliability of zero-trust-based data processing.
[0202] In an embodiment of the present application, another zero-trust-based data processing method is provided, and this zero-trust-based data processing method can be executed by the zero-trust client. As Figure 9 shown, this zero-trust-based data processing method may further include S901 to S903 before S801.
[0203] S901 to S903 are introduced in detail as follows:
[0204] S901, if a trigger operation is detected, record the triggered operation.
[0205] In the embodiments of the present application, the zero-trust client can detect the trigger of the operation. If a trigger operation is detected, record the triggered operation.
[0206] In an embodiment of the present application, the process of recording the triggered operation when a trigger operation is detected in S901 may include:
[0207] Receive the preset operation record logic sent by the zero-trust server;
[0208] If a triggered operation is detected and the triggered operation meets the preset operation record logic, record the triggered operation.
[0209] That is, in an alternative embodiment, the zero-trust server can set the preset operation record logic / policy, and then the zero-trust server sends the preset operation record logic / policy to the zero-trust client; correspondingly, the zero-trust client receives the preset operation record logic / policy sent by the zero-trust server and records the triggered operation based on the preset operation record logic / policy.
[0210] Among them, in an alternative embodiment, the preset operation record logic / policy refers to the rules for instructing the zero-trust client to record the triggered operation.
[0211] Exemplarily, the preset operation record logic / policy can be to record sensitive operations and not record non-sensitive operations. The scope, type, etc. of sensitive operations are clearly defined in the preset operation record logic / policy so that the zero-trust client can know what sensitive operations are. It can be understood that if the preset operation record logic / policy is to record sensitive operations and not record non-sensitive operations, the selection process of sensitive operations in the foregoing embodiments is not involved.
[0212] In this way, by implementing the alternative embodiment, the zero-trust client records the triggered operation based on the operation record logic / policy set by the zero-trust server, with high flexibility and applicability to many scenarios.
[0213] In an embodiment of the present application, the zero-trust client records the triggered operation including the operation itself and the dynamic and static characteristic information corresponding to the process that triggers the operation.
[0214] In this way, by implementing the alternative embodiment, the zero-trust client makes a complete record of the triggered operation, providing strong support for data access control.
[0215] In an embodiment of the present application, the zero-trust client records the triggered operation including but not limited to system event subscription mechanism, kernel driver hook mechanism, file system filter driver, and process injection, etc.; among them, the system event subscription mechanism can subscribe to information such as registry operations, process start, stop and access, network connection, etc., the kernel driver hook mechanism can obtain information such as keyboard input, windows, etc., the file system filter driver can detect operations on the file system in the terminal device, and inject the security detection module into the memory space of another running application process, etc.
[0216] In this way, by implementing the alternative embodiment, the zero-trust client has multiple recording methods to implement the recording of the triggered operation, and the recording process is simple and highly flexible.
[0217] S902. Generate a reporting operation list based on the recorded operations and store the reporting operation list in the local operation storage area.
[0218] In the embodiment of the present application, the zero-trust client can generate a reporting operation list based on the recorded operations and store the reporting operation list in the corresponding local operation storage area of the zero-trust client.
[0219] In an embodiment of the present application, there are multiple recorded operations; correspondingly, the process of generating a reporting operation list based on the recorded operations in S902 may include:
[0220] Receive the preset operation screening logic sent by the zero-trust server;
[0221] Select the operations that meet the preset operation recording logic from the multiple recorded operations;
[0222] Generate a reporting operation list based on the selected operations.
[0223] That is, in an alternative embodiment, the zero-trust server can set the preset operation screening logic / policy, and then the zero-trust server sends the preset operation screening logic / policy to the zero-trust client; correspondingly, the zero-trust client receives the preset operation screening logic / policy sent by the zero-trust server and records the triggered operations based on the preset operation screening logic / policy.
[0224] Among them, in an alternative embodiment, the preset operation screening logic / policy refers to the rules for instructing the zero-trust client to select operations from the multiple recorded operations.
[0225] Exemplarily, the preset operation screening logic / policy can be to select sensitive operations with anomalies, where the scope of anomalies of sensitive operations is specified in the preset operation screening logic / policy, so that the zero-trust client can know what sensitive operations with anomalies are.
[0226] It can be understood that, in an alternative embodiment, the preset operation screening logic / policy is a further refined logic / policy of the preset operation recording logic / policy in the foregoing embodiment.
[0227] For example, assume that the preset operation recording logic / policy includes firewall rule change operations. When a zero-trust client triggers a firewall rule change operation, the firewall rule change operation needs to be recorded. At the same time, assume that the preset operation screening logic / policy includes suspicious information such as protocol, sensitive ports, incoming (inbound) / outgoing (outbound) traffic, action being allow / deny, and / or application process characteristics (e.g., no digital signature or not in the whitelist) in the firewall rule change operation. When suspicious information such as protocol, sensitive ports, incoming (inbound) / outgoing (outbound) traffic, action being allow / deny, and / or application process characteristics is detected in the firewall rule change operation, it is determined that the firewall rule change operation is abnormal.
[0228] In this way, by implementing the optional embodiment, the zero-trust client selects sensitive operations with anomalies based on the operation screening logic / policy set by the zero-trust server, improving the accuracy of data access control, having high security, and being applicable to many scenarios.
[0229] S903. Send the reported operation list to the zero-trust server so that the zero-trust server stores the reported operation list in the corresponding local operation storage area of the zero-trust server.
[0230] In the embodiment of the present application, the zero-trust client generates a reported operation list and can then send the reported operation list to the zero-trust server. Correspondingly, the zero-trust server receives the reported operation list sent by the zero-trust client and stores the reported operation list in the corresponding local operation storage area of the zero-trust server.
[0231] In an embodiment of the present application, the process of sending the reported operation list to the zero-trust server in S903 may include:
[0232] Send the reported operation list to the zero-trust server regularly or irregularly; or
[0233] Send the reported operation list to the zero-trust server actively or passively.
[0234] That is, in the optional embodiment, the zero-trust client can send the reported operation list to the zero-trust server regularly (i.e., periodically) or irregularly (i.e., non-periodically); the zero-trust client can send the reported operation list to the zero-trust server actively (i.e., triggered when not receiving a reported operation list request sent by the zero-trust server) or passively (i.e., triggered when receiving a reported operation list request sent by the zero-trust server).
[0235] In this way, by implementing the optional embodiments, the zero-trust client has multiple sending methods to realize the sending of the reporting operation list, and the sending process is simple and highly flexible.
[0236] It should be noted that Figure 9 In the illustration, S902 storing the reporting operation list in the local operation storage area and S903 sending the reporting operation list to the zero-trust server can be executed either first or later or simultaneously. At the same time Figure 9 For the detailed introduction of S801 to S804 shown, please refer to Figure 8 S801 to S804 shown, which will not be elaborated here.
[0237] In the embodiment of the present application, the zero-trust client records the operations it triggers, stores them in the local operation storage area, and sends them to the zero-trust server for storage in the local operation storage area, realizing a strong association between the zero-trust network and the operations, providing strong support for data access control; at the same time, the zero-trust server uses the comparison of operations (i.e., the operation list) to realize the detection of the zero-trust client and the zero-trust server, providing strong support for the security management and control of the zero-trust client and the zero-trust server, and enhancing the security of data access control.
[0238] In an embodiment of the present application, another zero-trust-based data processing method is provided, and this zero-trust-based data processing method can be executed by the zero-trust client. As Figure 10 shown, after S804, this zero-trust-based data processing method may further include S1001 to S1003.
[0239] The detailed introduction of S1001 to S1003 is as follows:
[0240] S1001, obtain a target access list; wherein, the target access list includes the data access records initiated by the zero-trust client.
[0241] In the embodiment of the present application, the zero-trust client will record the data access initiated by the zero-trust client to generate a target access list, and store the target access list in the local access record storage area corresponding to the zero-trust client; correspondingly, the zero-trust client can obtain the target access list from the local access record storage area corresponding to the zero-trust client.
[0242] In the embodiment of the present application, the local access record storage area refers to the storage area located locally in the zero-trust client for storing data access records.
[0243] S1002, generate marker data based on the target access list.
[0244] In the embodiment of the present application, the zero-trust client obtains the target access list, and then can generate the marking data based on the target access list.
[0245] S1003. Send the marking data to the zero-trust server, so that the zero-trust server extracts the target access list from the marking data, matches the target access list with the candidate access list of the zero-trust client in the local access record storage area corresponding to the zero-trust server, and detects the security level of the zero-trust client and the security level of the zero-trust server based on the matching result.
[0246] In the embodiment of the present application, the zero-trust client generates the marking data, and then sends the marking data to the zero-trust server; correspondingly, the zero-trust server receives the marking data sent by the zero-trust client, extracts the target access list from the marking data, matches the target access list with the candidate access list of the zero-trust client in the local access record storage area corresponding to the zero-trust server, and detects the security level of the zero-trust client and the security level of the zero-trust server based on the matching result. For the specific implementation process, please refer to the foregoing embodiments and will not be elaborated here.
[0247] In an embodiment of the present application, the process of sending the marking data to the zero-trust server in S1003 may include:
[0248] Send the marking data to the zero-trust server regularly or irregularly; or
[0249] Send the marking data actively or passively.
[0250] That is, in the alternative embodiment, the zero-trust client can send the marking data to the zero-trust server regularly (i.e., periodically) or irregularly (i.e., non-periodically); the zero-trust client can send the marking data actively (i.e., triggered when no marking data request is received from the zero-trust server) or passively (i.e., triggered when a marking data request is received from the zero-trust server).
[0251] In this way, through the implementation of the alternative embodiment, the zero-trust client has multiple sending methods to realize the sending of the marking data, and the sending process is simple and highly flexible.
[0252] It should be noted that Figure 10 For the detailed introduction of S801 to S804 shown, please refer to Figure 8 S801 to S804 shown, and will not be elaborated here.
[0253] In the embodiment of the present application, the zero-trust client sends the tagged data containing the data access record to the zero-trust server. Then, the zero-trust server realizes the detection of the zero-trust client and the zero-trust server by comparing the data access records (i.e., the access list), which provides strong support for the security management and control of the zero-trust client and the zero-trust server, and improves the security of data access control.
[0254] The following details the specific scenarios of the embodiments of the present application:
[0255] Please refer to Figure 11 , which mainly includes an IOA client, an IOA server, an access proxy, an intelligent gateway, and a data server (also called a business server), where:
[0256] The IOA client is a security proxy installed on the terminal device, mainly used to verify whether the user on the terminal device is trustworthy, whether the terminal device is trustworthy, and whether the application is trustworthy, etc.
[0257] The IOA server performs security scheduling on the service traffic through a policy control engine, authorizes according to the granularity of person-terminal device-application, and mainly includes a user verification module for verifying whether the user is trustworthy, a device verification module for verifying whether the terminal device is trustworthy, and an application verification module for verifying whether the application is trustworthy, etc.
[0258] The access proxy intercepts the terminal device traffic through the virtual network card of TUN / TAP (i.e., the virtual network device in the operating system kernel). If the iOA client passes the authentication, it forwards the data access request to the intelligent gateway. If the iOA client does not pass the authentication, it goes through direct connection or interrupts the connection, etc.
[0259] The intelligent gateway is deployed at the entrance of the application and data resources, and is responsible for the verification (i.e., the verification of credentials), authorization, and forwarding of each session request for accessing the data resources.
[0260] The business server stores data resources, and there can be one or more, such as business server A, business server B, and business server C, etc. when there are multiple.
[0261] Please refer to Figure 12 , Figure 12 is a flowchart of a zero-trust-based data processing method shown in an embodiment of the present application. As Figure 12 shown, the zero-trust-based data processing method at least includes S1201 to S1213, which are introduced in detail as follows:
[0262] S1201, the IOA server sends the preset operation logic to the IOA client.
[0263] Optionally, the preset operation logic includes a preset operation recording logic, a preset operation filtering logic, etc.; among them, the preset operation recording logic / strategy includes the scope, type, etc. of sensitive operations, so as to facilitate the IOA client to collect sensitive operations triggered by the IOA client, and the preset operation filtering logic includes the scope of abnormal sensitive operations, so as to facilitate the IOA client to collect sensitive operations with anomalies.
[0264] S1202. The IOA client records the triggered operations and the dynamic and static characteristic information corresponding to the process of the triggered operations according to the received preset operation logic, and obtains system activity data.
[0265] S1203. The IOA client stores the system activity data in the local operation storage area and sends the system activity data to the IOA server.
[0266] S1204. The IOA client stores the received system activity data in the local operation storage area.
[0267] It can be understood that S1201 to S1204 are the processes in which the IOA client continuously collects system activity data and sends the system activity data to the IOA server.
[0268] S1205. If the IOA client receives an execution request for a target service, it obtains system activity data based on the execution request, generates a data access request based on the obtained system activity data, and sends the data access request to the IOA server.
[0269] Optionally, if the IOA client receives an execution request for a target service, it obtains the system activity data obtained in the most recent historical time period from the local operation storage area corresponding to the IOA client based on the execution request.
[0270] S1206. After receiving the data access request sent by the IOA client, if the IOA server detects that the IOA client has data access rights, it obtains the system activity data of the IOA client from the data access request and detects the security level of the IOA client based on the system activity data of the IOA client.
[0271] Among them, if the IOA server detects that the operation contained in the system activity data belongs to the type with undetermined security level, it determines that the IOA client has a security level equal to or higher than the preset client security level.
[0272] Among them, if the IOA server detects that the operation contained in the system activity data belongs to the type with determined security level, it determines the security level of the IOA client based on the security level of the sensitive operation.
[0273] Optionally, determine the security level of the IOA client based on the security level of the sensitive operation, including: if the operation is equal to or higher than the preset operation security level, determine that the IOA client has a security level equal to or higher than the preset client security level; if the operation is lower than the preset operation security level, determine that the IOA client has a security level lower than the preset client security level.
[0274] S1207, if the security level of the IOA client is equal to or higher than the preset client security level, the IOA server obtains a credential from the credential storage area and assigns the credential to the IOA client.
[0275] Optionally, assign a credential to the IOA client, including: if the operation belongs to the security level undetermined type, generate usage restriction information for the credential, where the usage restriction information includes at least one of time restriction and number of times restriction; then send the credential and the usage restriction information to the IOA client so that the IOA client uses the credential based on the usage restriction information.
[0276] Optionally, after assigning a credential to the IOA client, it may further include: if it is detected that the security level corresponding to the operation of the security level undetermined type is lower than the preset operation security level, or it is detected that the security level corresponding to the operation of the security level determined type has decreased, then control the verification of the credential to fail in the verification operation of the credential to reject the IOA client from accessing data from the data server using the credential. That is, in the optional embodiment, although the IOA server assigns a credential to the IOA client, the credential can be recovered to control data access to ensure security.
[0277] Optionally, after assigning a credential to the IOA client, it may further include: if it is detected that the data server is accessed using the credential for non-first time, re-authenticate the IOA client and allow the IOA client to access the data server again after the authentication passes. That is, in the optional embodiment, although the IOA server assigns a credential to the IOA client, the IOA client needs to be multi-authenticated within a specified duration to ensure security. Among them, multi-authentication can be implemented by means of verification codes, etc., and in practical applications, it can be flexibly adjusted according to specific application scenarios.
[0278] It can be understood that if the security level of the IOA client is lower than the preset client security level, the IOA server refuses to assign a credential to the IOA client.
[0279] S1208, if the IOA client receives the credential sent by the IOA server, use the credential to access data from the data server through the access proxy and the intelligent gateway to execute the target service.
[0280] It can be understood that S1205 to S1208 are the processes in which the IOA server allocates credentials to the IOA client based on the system activity data contained in the data access request, so that the IOA client can access data to execute operations.
[0281] S1209, the IOA server obtains the reported operation list corresponding to the IOA client from the local operation storage area, and the reported operation list includes multiple operations.
[0282] As described above, the IOA client continuously collects system activity data and sends it to the IOA server, and the IOA server stores the received system activity data in the local operation storage area.
[0283] S1210, the IOA server matches the reported operation list with the target operation list to obtain a matching result, and performs corresponding management operations based on the matching result.
[0284] It can be understood that the system activity data of the IOA client obtained from the data access request includes a target operation list, and the target operation list includes multiple operations.
[0285] Among them, if the obtained matching result indicates that the target operation list does not match the reported operation list, and there are missing operations in the target operation list, it is determined that the IOA client is under attack.
[0286] Among them, if the obtained matching result indicates that the target operation list does not match the reported operation list, and there are missing operations in the reported operation list, it is determined that the IOA server is under attack.
[0287] Correspondingly, corresponding management operations are adopted for the attacked party.
[0288] It can be understood that S1209 to S1210 are processes that can detect the security status of the IOA client and the IOA server in real time at any time through the comparison between the target operation list and the reported operation list.
[0289] S1211, the IOA client obtains the target access list, the target access list includes the data access records initiated by the IOA client, and generates marker data based on the target access list, and sends the marker data to the IOA server.
[0290] S1212, the IOA server obtains the target access list corresponding to the IOA client from the received marker data, and obtains the candidate access list corresponding to the IOA client from the local access record storage area. The candidate access list is obtained by the IOA server recording the data access initiated by the IOA client.
[0291] In S1213, the IOA server matches the target access list with the candidate access list to obtain a matching result, and performs corresponding management operations based on the matching result.
[0292] Among them, if the obtained matching result indicates that the target access list does not match the candidate access list, and there are missing data access records in the target access list, it is determined that the IOA client is under attack.
[0293] Among them, if the obtained matching result indicates that the target access list does not match the candidate access list, and there are missing data access records in the candidate access list, it is determined that the IOA server is under attack.
[0294] Correspondingly, corresponding management measures are adopted for the attacked party.
[0295] It can be understood that S1211 to S1213 are processes that can detect the security status of the IOA client and the IOA server in real time through the comparison between the target access list and the candidate access list at any time.
[0296] It should be noted that Figure 12 For the detailed introduction of S1201 to S1213 shown, please refer to the foregoing embodiment introduction and will not be elaborated here.
[0297] By implementing the solution of this application, at least the following beneficial effects are achieved:
[0298] (1) The IOA server issues a preset operation logic, and the IOA client continuously detects whether each application in the terminal device triggers a sensitive operation. When the relevant application process performs zero-trust network access, when a data access request is made, it reports the most recently triggered sensitive operation to the IOA server. The IOA server further restricts the access rights of the application process to enterprise resources in combination with the triggering of sensitive events outside the zero-trust network policy.
[0299] On the one hand, compared with the related technology where the IOA client first performs full-scale collection, and then detects whether the applications in the terminal device hit the model or expert rules in this huge amount of full-scale data, and finally issues and executes a disposal action, not only the timeliness of sensitive data collection is improved, the cumbersome operation of detecting from full-scale data is avoided, but also the data access request is associated with the credential distribution. The IOA server can promptly issue and execute a disposal action, avoiding the problem of lag in handling potential abnormal behaviors in the terminal device, and improving the efficiency, accuracy, security, etc. of data access control, ensuring the security of the office environment.
[0300] On the one hand, compared with the related art in which the execution of a disposal action is manually issued to restrict the overall data access of the terminal device or isolate the suspicious terminal device, the IOA server can directly intervene in the suspicious application and can batch issue the execution of the disposal action for the triggered suspicious application, with a finer processing granularity and a simpler processing process, improving the user's office experience.
[0301] (2) In the embodiment of the present application, the IOA client can generate marker data based on the zero-trust access record and send it to the IOA server in a combination of periodic, condition-triggered, randomly generated, and reported manners, so as to be able to detect anomalies in a targeted and timely manner, improving the efficiency, accuracy, security, etc. of data access control and ensuring the security of the office environment.
[0302] Figure 13 It is a block diagram of a zero-trust-based data processing device shown in an embodiment of the present application. As Figure 13 shown, the zero-trust-based data processing device is configured in the zero-trust server and includes:
[0303] An acquisition module 1301, configured to, if a data access request sent by the zero-trust client is received, obtain the operation triggered by the zero-trust client from the data access request;
[0304] A determination module 1302, configured to determine the security level of the zero-trust client based on the type of the operation;
[0305] An allocation module 1303, configured to allocate a credential for the zero-trust client based on the security level of the zero-trust client, so that the zero-trust client can use the credential to access data from the data server.
[0306] In an embodiment of the present application, based on the foregoing solution, the operation is a sensitive operation related to security selected by the zero-trust client from multiple operations triggered by the zero-trust client; the determination module 1302 is specifically configured to:
[0307] If the sensitive operation belongs to the type of undetermined security level, determine that the zero-trust client has a security level equal to or higher than the preset client security level;
[0308] If the sensitive operation belongs to the type of determined security level, determine the security level of the zero-trust client based on the security level of the sensitive operation.
[0309] In an embodiment of the present application, based on the foregoing solution, the determination module 1302 is further specifically configured to:
[0310] If the security level of the zero-trust client is equal to or higher than the preset client security level, obtain a credential from the credential storage area and assign the credential to the zero-trust client;
[0311] If the security level of the zero-trust client is lower than the preset client security level, reject assigning a credential to the zero-trust client.
[0312] In an embodiment of the present application, based on the foregoing solution, the determination module 1302 is further specifically configured as:
[0313] If the operation belongs to the type with undetermined security level, generate usage restriction information for the credential; wherein, the usage restriction information includes at least one of time restriction and times restriction;
[0314] Send the credential and the usage restriction information to the zero-trust client so that the zero-trust client uses the credential based on the usage restriction information.
[0315] In an embodiment of the present application, based on the foregoing solution, the determination module 1302 is further specifically configured as:
[0316] If it is detected that the security level corresponding to the operation of the type with undetermined security level is lower than the preset operation security level, or it is detected that the security level corresponding to the operation of the type with determined security level decreases, then control the verification of the credential to fail in the verification operation for the credential, so as to reject the zero-trust client from accessing data from the data server using the credential.
[0317] In an embodiment of the present application, based on the foregoing solution, multiple operations are carried in the data access request, and the multiple carried operations are arranged in sequence in the target operation list; this zero-trust-based data processing device further includes a first detection module, configured as:
[0318] Obtain the reported operation list corresponding to the zero-trust client from the local operation storage area; wherein, the reported operation list is the zero-trust client's record of multiple operations triggered by the zero-trust client and reported to the zero-trust server;
[0319] Match the reported operation list with the target operation list to obtain a matching result;
[0320] Detect the zero-trust client and the zero-trust server based on the obtained matching result.
[0321] In an embodiment of the present application, based on the foregoing solution, the first detection module is specifically configured as:
[0322] If the obtained matching result indicates that the target operation list does not match the reported operation list, and there are missing operations in the target operation list, a detection result for indicating that the zero-trust client is under attack is obtained;
[0323] If the obtained matching result indicates that the target operation list does not match the reported operation list, and there are missing operations in the reported operation list, a detection result for indicating that the zero-trust server is under attack is obtained.
[0324] In an embodiment of the present application, based on the foregoing solution, the first detection module is specifically configured to:
[0325] Obtain a first time period corresponding to the operations included in the reported operation list, and obtain a second time period corresponding to the operations included in the target operation list;
[0326] If the first time period and the second time period do not match, synchronize the reported operation list corresponding to the zero-trust client in the local operation storage area, so that the first time period corresponding to the operations included in the synchronized reported operation list matches the second time period;
[0327] Match the target operation list with the synchronized reported operation list to obtain a matching result.
[0328] In an embodiment of the present application, based on the foregoing solution, the zero-trust-based data processing device further includes a second detection module, configured to:
[0329] If the marked data sent by the zero-trust client is received, extract the target access list corresponding to the zero-trust client from the marked data; wherein, the target access list is obtained by the zero-trust client recording the data access initiated by the zero-trust client;
[0330] Obtain the candidate access list corresponding to the zero-trust client from the local access record storage area; wherein, the candidate access list is obtained by the zero-trust server recording the data access initiated by the zero-trust client;
[0331] Match the target access list with the candidate access list to obtain a matching result;
[0332] Detect the zero-trust client and the zero-trust server based on the obtained matching result.
[0333] In an embodiment of the present application, based on the foregoing solution, the second detection module is specifically configured to:
[0334] If the obtained matching result indicates that the target access list does not match the candidate access list, and there are missing data access records in the target access list, a detection result for characterizing that the zero-trust client is under attack is obtained;
[0335] If the obtained matching result indicates that the target access list does not match the candidate access list, and there are missing data access records in the candidate access list, a detection result for characterizing that the zero-trust server is under attack is obtained.
[0336] Figure 14 It is a block diagram of a zero-trust based data processing device shown in an embodiment of the present application. As Figure 14 shown, the zero-trust based data processing device is configured in a zero-trust client and includes:
[0337] An acquisition module 1401, configured to, if an execution request for a target service is received, acquire the triggered operation based on the execution request;
[0338] A generation module 1402, configured to generate a data access request based on the operation;
[0339] A sending module 1403, configured to send the data access request to a zero-trust server, so that the zero-trust server determines the security level of the zero-trust client based on the type of the operation, and allocates a credential for the zero-trust client based on the security level of the zero-trust client;
[0340] An access module 1404, configured to, if the credential sent by the zero-trust server is received, access data from a data server using the credential to execute the target service.
[0341] In an embodiment of the present application, based on the foregoing solution, the acquisition module 1401 is specifically configured to:
[0342] Select sensitive operations related to security from multiple operations stored in a local operation storage area based on the execution request; wherein the multiple operations are triggered by the zero-trust client;
[0343] The generating the data access request based on the operation includes:
[0344] Generating a data access request based on the sensitive operation.
[0345] In an embodiment of the present application, based on the foregoing solution, the zero-trust based data processing device further includes a first generation module, configured to:
[0346] If a trigger operation is detected, record the triggered operation;
[0347] Generate a reporting operation list based on the recorded operations, and store the reporting operation list in the local operation storage area; and,
[0348] Send the reporting operation list to the zero-trust server so that the zero-trust server stores the reporting operation list in the local operation storage area corresponding to the zero-trust server.
[0349] In an embodiment of the present application, based on the foregoing solution, the zero-trust-based data processing device further includes a second generation module configured to:
[0350] Obtain a target access list; wherein, the target access list includes data access records initiated by the zero-trust client;
[0351] Generate marking data based on the target access list;
[0352] Send the marking data to the zero-trust server so that the zero-trust server extracts the target access list from the marking data, matches the target access list with the candidate access list of the zero-trust client in the local access record storage area corresponding to the zero-trust server, and detects the security level of the zero-trust client and the security level of the zero-trust server based on the matching result.
[0353] It should be noted that the device provided in the foregoing embodiment and the method provided in the foregoing embodiment belong to the same concept, and the specific manners in which each module and unit perform operations have been described in detail in the method embodiment.
[0354] An embodiment of the present application further provides an electronic device, including: one or more processors; a memory for storing one or more programs, and when the one or more programs are executed by the one or more processors, the electronic device implements the zero-trust-based data processing method as described above.
[0355] Figure 15 It is a schematic structural diagram of a computer system of an electronic device suitable for implementing the embodiments of the present application.
[0356] It should be noted that, Figure 15 The computer system 1500 of the electronic device shown is only an example and should not impose any limitations on the functions and usage scope of the embodiments of the present application.
[0357] Such as Figure 15As shown, computer system 1500 includes a Central Processing Unit (CPU) 1501, which can perform various appropriate actions and processes according to programs stored in Read-Only Memory (ROM) 1502 or programs loaded from storage section 1508 into Random Access Memory (RAM) 1503, such as executing the methods in the above embodiments. In RAM 1503, various programs and data required for system operation are also stored. CPU 1501, ROM 1502, and RAM 1503 are connected to each other via bus 1504. Input / Output (I / O) interface 1505 is also connected to bus 1504.
[0358] The following components are connected to I / O interface 1505: an input section 1506 including a keyboard, a mouse, etc.; an output section 1507 including, for example, a Cathode Ray Tube (CRT), a Liquid Crystal Display (LCD), etc. and speakers, etc.; a storage section 1508 including a hard disk, etc.; and a communication section 1509 including a network interface card such as a LAN (Local Area Network) card, a modem, etc. Communication section 1509 performs communication processing via a network such as the Internet. A drive 1510 is also connected to I / O interface 1505 as needed. A removable medium 1511, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on drive 1510 as needed so that a computer program read from it can be installed into storage section 1508 as needed.
[0359] Specifically, according to an embodiment of the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present application includes a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program includes a computer program for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network via communication section 1509, and / or installed from removable medium 1511. When the computer program is executed by Central Processing Unit (CPU) 1501, various functions defined in the system of the present application are executed.
[0360] It should be noted that the computer-readable medium shown in the embodiments of the present application can be a computer-readable signal medium, a computer-readable storage medium, or any combination of the two. The computer-readable medium can be, for example, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable medium may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), a flash memory, an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present application, the computer-readable medium can be any tangible medium that contains or stores a program, and this program can be used by or in combination with an instruction execution system, apparatus, or device. In the present application, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, in which a computer-readable computer program is carried. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and this computer-readable medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. The computer program contained on the computer-readable medium can be transmitted by any appropriate medium, including but not limited to: wireless, wired, etc., or any suitable combination of the above.
[0361] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. Among them, each block in the flowchart or block diagram can represent a module, a program segment, or a part of code, and the above module, program segment, or part of code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in an order different from that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram or flowchart, as well as the combination of blocks in the block diagram or flowchart, can be implemented by a dedicated hardware-based system for performing the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0362] The units involved in the embodiments described in this application can be implemented in software or in hardware, and the described units can also be provided in a processor. Among them, the names of these units do not constitute a limitation to the unit itself in some cases.
[0363] Another aspect of this application also provides a computer-readable medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the aforementioned zero-trust-based data processing method. The computer-readable medium can be included in the electronic device described in the above embodiments, or can exist alone without being assembled into the electronic device.
[0364] Another aspect of this application also provides a computer program product or a computer program. The computer program product or the computer program includes computer instructions, and the computer instructions are stored in a computer-readable medium. The processor of the computer device reads the computer instructions from the computer-readable medium, and the processor executes the computer instructions, so that the computer device executes the zero-trust-based data processing method provided in the above various embodiments.
[0365] The above content is only a preferred exemplary embodiment of this application and is not used to limit the implementation of this application. Those of ordinary skill in the art can easily make corresponding adaptations or modifications according to the main concept and spirit of this application. Therefore, the protection scope of this application should be subject to the protection scope required by the claims.
Claims
1. A data processing method based on zero trust, characterized in that Applied to the zero-trust server, including: If a data access request sent by the zero-trust client is received, obtain the operation triggered by the zero-trust client from the data access request; Determine the security level of the zero-trust client based on the type of the operation; Allocate a credential for the zero-trust client based on the security level of the zero-trust client, so that the zero-trust client can use the credential to access data from the data server.
2. The method according to claim 1, characterized in that, The operation is a sensitive operation related to security selected by the zero-trust client from multiple operations triggered by the zero-trust client; The determining the security level of the zero-trust client based on the type of the operation includes: If the sensitive operation belongs to the type with undetermined security level, determine that the zero-trust client has a security level equal to or higher than the preset client security level; If the sensitive operation belongs to the type with determined security level, determine the security level of the zero-trust client based on the security level of the sensitive operation.
3. The method according to claim 1, characterized in that The allocating a credential for the zero-trust client based on the security level of the zero-trust client includes: If the security level of the zero-trust client is equal to or higher than the preset client security level, obtain a credential from the credential storage area and allocate the credential to the zero-trust client; If the security level of the zero-trust client is lower than the preset client security level, refuse to allocate a credential for the zero-trust client.
4. The method according to claim 3, characterized in that, The allocating the credential to the zero-trust client includes: If the operation belongs to the type with undetermined security level, generate usage restriction information for the credential; wherein, the usage restriction information includes at least one of time restriction and number of times restriction; Send the credential and the usage restriction information to the zero-trust client, so that the zero-trust client can use the credential based on the usage restriction information.
5. The method according to claim 3, wherein After allocating a credential for the zero-trust client, the method further includes: If it is detected that the security level corresponding to an operation of the type with undetermined security level is lower than the preset operation security level, or it is detected that the security level corresponding to an operation of the type with determined security level decreases, control the verification of the credential to fail in the verification operation of the credential, so as to refuse the zero-trust client to use the credential to access data from the data server.
6. The method according to any one of claims 1 to 5, characterized in that, The operations carried in the data access request are multiple, and the multiple carried operations are arranged in sequence in the target operation list; The method further includes: Obtain the reported operation list corresponding to the zero-trust client from the local operation storage area; wherein, the reported operation list is recorded by the zero-trust client for multiple operations triggered by the zero-trust client and reported to the zero-trust server; Match the reported operation list with the target operation list to obtain a matching result; Detect the zero-trust client and the zero-trust server based on the obtained matching result.
7. The method according to claim 6, wherein The detecting the zero-trust client and the zero-trust server based on the obtained matching result includes: If the obtained matching result indicates that the target operation list does not match the reported operation list, and there are missing operations in the target operation list, a detection result for characterizing that the zero-trust client is under attack is obtained; If the obtained matching result indicates that the target operation list does not match the reported operation list, and there are missing operations in the reported operation list, a detection result for characterizing that the zero-trust server is under attack is obtained.
8. The method according to claim 6, characterized in that, The matching of the reported operation list with the target operation list to obtain a matching result includes: Obtaining a first time period corresponding to the operations included in the reported operation list, and obtaining a second time period corresponding to the operations included in the target operation list; If the first time period and the second time period do not match, synchronize the reported operation list corresponding to the zero-trust client in the local operation storage area so that the first time period corresponding to the operations included in the synchronized reported operation list matches the second time period; Match the target operation list with the synchronized reported operation list to obtain a matching result.
9. The method according to any one of claims 1 to 5, characterized in that, The method further includes: If the marked data sent by the zero-trust client is received, extract the target access list corresponding to the zero-trust client from the marked data; wherein, the target access list is obtained by the zero-trust client recording the data access initiated by the zero-trust client; Obtain the candidate access list corresponding to the zero-trust client from the local access record storage area; wherein, the candidate access list is obtained by the zero-trust server recording the data access initiated by the zero-trust client; Match the target access list with the candidate access list to obtain a matching result; Detect the zero-trust client and the zero-trust server based on the obtained matching result.
10. The method according to claim 9, wherein The detecting the zero-trust client and the zero-trust server based on the obtained matching result includes: If the obtained matching result indicates that the target access list does not match the candidate access list, and there are missing data access records in the target access list, a detection result for characterizing that the zero-trust client is under attack is obtained; If the obtained matching result indicates that the target access list does not match the candidate access list, and there are missing data access records in the candidate access list, a detection result for characterizing that the zero-trust server is under attack is obtained.
11. A data processing method based on zero trust, characterized in that, Applied to a zero-trust client, it includes: If an execution request for a target service is received, obtain the triggered operation based on the execution request; Generate a data access request based on the operation; Send the data access request to the zero-trust server so that the zero-trust server determines the security level of the zero-trust client based on the type of the operation and allocates a credential for the zero-trust client based on the security level of the zero-trust client; If the credential sent by the zero-trust server is received, use the credential to access data from the data server to execute the target service.
12. The method according to claim 11, wherein Obtaining the triggered operation based on the execution request includes: Selecting a sensitive operation related to security from multiple operations stored in the local operation storage area based on the execution request; wherein, the multiple operations are triggered by the zero-trust client; Generating a data access request based on the operation includes: Generating a data access request based on the sensitive operation.
13. The method according to claim 11 or 12, characterized in that, The method further includes: If a triggered operation is detected, recording the triggered operation; Generating a reported operation list based on the recorded operation, and storing the reported operation list in the local operation storage area; and, Sending the reported operation list to the zero-trust server, so that the zero-trust server stores the reported operation list in the corresponding local operation storage area of the zero-trust server.
14. The method according to claim 11 or 12, characterized in that, The method further includes: Obtaining a target access list; wherein, the target access list includes data access records initiated by the zero-trust client; Generating marked data based on the target access list; Sending the marked data to the zero-trust server, so that the zero-trust server extracts the target access list from the marked data, matches the target access list with the candidate access list of the zero-trust client in the corresponding local access record storage area of the zero-trust server, and detects the security levels of the zero-trust client and the zero-trust server based on the matching result.
15. An electronic device, characterized in that, Includes: One or more processors; A memory for storing one or more programs, when the one or more programs are executed by the electronic device, enabling the electronic device to implement the zero-trust-based data processing method according to any one of claims 1 to 14.
16. A computer-readable medium having a computer program stored thereon, characterized in that, The computer program, when executed by a processor, implements the zero-trust-based data processing method according to any one of claims 1 to 14.
17. A computer program product comprising computer instructions, characterized in that, The computer instruction, when executed by a processor, implements the zero-trust-based data processing method according to any one of claims 1 to 14.