Mobile office security access method, device and equipment based on zero-trust network

Through a secure access method based on zero-trust network, using application isolation and secure channel enhancement processes for identity authentication and risk assessment, the security challenges of the mobile office environment are solved and in-depth security control of mobile office applications is achieved.

CN120301696APending Publication Date: 2025-07-11AGRICULTURAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510689787.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-27
Publication Date
2025-07-11

AI Technical Summary

Technical Problem

Traditional security policies cannot meet the security needs of mobile office environments and face challenges such as data breaches, cyber attacks and device loss.

Method used

Using a secure access method based on zero-trust network, identity authentication and access channel management are performed by applying isolated processes and secure channel enhancement processes, and data risk assessment is performed using a pre-trained intelligent risk assessment model to obtain execution strategies to handle interactive behavior.

Benefits of technology

It improves the security of mobile office, increases the difficulty of cracking by separating user identity authentication steps, and analyzes user behavior in real time to identify abnormal behaviors, effectively identifying security threats.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120301696A_ABST
    Figure CN120301696A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a mobile office security access method, device and equipment based on a zero-trust network. The method comprises the steps that under the condition that a mobile terminal starts a target application, the target application is operated in an isolated mode through an application isolation process; when the target application performs external network office access, identity authentication and access channel management are performed by using the secure channel enhancement process; acquiring any data interacted by the target application, and performing risk assessment on the acquired data by using a pre-trained intelligent risk assessment model to obtain a risk assessment result; and obtaining a corresponding execution strategy according to a risk assessment result, and processing the interaction according to the execution strategy. Based on this, user identity authentication is divided into two independent process steps through an application isolation process and a security channel enhancement process, the cracking difficulty is increased, in addition, user behaviors can be analyzed in real time and abnormal behaviors can be recognized by using an intelligent risk assessment model, and thus security threats are effectively recognized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments of the present application relate to the technical field of network data access, and in particular, to a mobile office secure access method, device, and equipment based on a zero-trust network. Background Art

[0002] With the popularization of mobile devices and the prevalence of remote work models, more and more enterprises adopt mobile office methods to improve the flexibility and productivity of employees.

[0003] However, the mobile office environment faces many security challenges, including data leakage, network attacks, and device loss. Traditional security policies can no longer meet the security requirements of mobile office, so a more advanced and flexible secure access method is needed to protect the data and resources of enterprises. Summary of the Invention

[0004] The embodiments of the present application provide a mobile office secure access method, device, and equipment based on a zero-trust network to meet the need for a more advanced and flexible secure access method in mobile office.

[0005] In a first aspect, the embodiments of the present application provide a mobile office secure access method based on a zero-trust network. The method includes:

[0006] When the target application is started on the mobile terminal, the target application is isolated and run by using an application isolation process;

[0007] When the target application accesses the external network for office work, identity authentication and access channel management are performed by using a secure channel enhancement process;

[0008] Collect any data interacted by the target application, and use a pre-trained intelligent risk assessment model to perform a risk assessment on the collected data to obtain a risk assessment result;

[0009] Obtain a corresponding execution policy according to the risk assessment result, and process the current interaction according to the execution policy.

[0010] In a second aspect, the embodiments of the present application provide a mobile office secure access device based on a zero-trust network. The device includes:

[0011] An isolation module, configured to isolate and run the target application by using an application isolation process when the target application is started on the mobile terminal;

[0012] A channel management module, configured to perform identity authentication and access channel management by using a secure channel enhancement process when the target application accesses the external network for office work;

[0013] A risk assessment module, configured to collect any data interacted with by a target application, and use a pre-trained intelligent risk assessment model to perform risk assessment on the collected data to obtain a risk assessment result;

[0014] A policy allocation and processing module, configured to obtain a corresponding execution policy according to the risk assessment result, and process the current interaction according to the execution policy.

[0015] Thirdly, an embodiment of the present application further provides an electronic device, which includes:

[0016] One or more processors;

[0017] A storage device, configured to store one or more programs,

[0018] When the one or more programs are executed by the one or more processors, the one or more processors implement the mobile office secure access method based on a zero-trust network provided in any embodiment of the present application.

[0019] Fourthly, an embodiment of the present application further provides a computer-readable storage medium, on which a computer program is stored, and characterized in that when the program is executed by a processor, it implements the mobile office secure access method based on a zero-trust network provided in any embodiment of the present application.

[0020] In the technical solution of the embodiment of the present application, when the target application is started on the mobile side, the target application is isolated and run by using an application isolation process; when the target application accesses the external network for office work, an identity authentication and access channel management are performed by using a secure channel enhancement process; any data interacted with by the target application is collected, and a pre-trained intelligent risk assessment model is used to perform risk assessment on the collected data to obtain a risk assessment result; a corresponding execution policy is obtained according to the risk assessment result, and the current interaction is processed according to the execution policy. Based on this, through the application isolation process and the secure channel enhancement process, the user identity authentication is divided into two independent process steps, increasing the cracking difficulty. In addition, by using the intelligent risk assessment model, user behaviors can be analyzed in real time to identify abnormal behaviors, thereby effectively identifying security threats. BRIEF DESCRIPTION OF THE DRAWINGS

[0021] Figure 1 It is a schematic flowchart of the mobile office secure access method based on a zero-trust network provided in Embodiment 1 of the present application;

[0022] Figure 2 It is a schematic architecture diagram of application isolation provided in Embodiment 1 of the present application;

[0023] Figure 3 It is a schematic architecture diagram of a secure channel enhancement process provided in Embodiment 1 of the present application;

[0024] Figure 4 A schematic diagram of the overall architecture of the LSTM-AE model provided for the first embodiment of the present application;

[0025] Figure 5 A schematic diagram of the structure of a mobile office secure access device based on the zero-trust network provided for the second embodiment of the present application;

[0026] Figure 6 A schematic diagram of the structure of an electronic device provided for the third embodiment of the present application. Detailed implementation manners

[0027] The present application will be further described in detail below with reference to the accompanying drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the present application, rather than limiting the present application. In addition, it should be noted that, for the sake of convenience of description, only parts related to the present application are shown in the accompanying drawings instead of all structures.

[0028] Embodiment 1

[0029] Figure 1 A flowchart of the mobile office secure access method based on the zero-trust network provided for the first embodiment of the present application. As Figure 1 shown, the mobile office secure access method based on the zero-trust network provided in this embodiment can be applied to a mobile office secure access platform based on the zero-trust network carried on a device with data processing capabilities such as a computer, and can cooperate with some application software to achieve a better experience. Specifically, it can include the following steps:

[0030] Step 101: When the target application is started on the mobile device, use the application isolation process to isolate and run the target application.

[0031] In this step, the mobile device refers to the terminal used by the user for mobile office, such as a mobile phone, a tablet, a laptop, etc. Generally, there are various office software that can be marked as the target application.

[0032] It should be noted that the software can be custom-marked by the user, or some common office software can be initially marked.

[0033] When any of the marked target applications is detected to be started, the application isolation process can be used to isolate and run the target application. Specifically, the architecture of the application isolation process can refer to Figure 2 , Figure 2 A schematic diagram of the architecture of an application isolation provided for the first embodiment of the present application.

[0034] As Figure 2As shown, the application isolation process is provided with an information collection module and a basic service module. Among them, the information collection module is provided with a login page, a session management page, a verification page, and a security settings page. These pages are used for human-computer interaction with users to collect the user identity information of the users.

[0035] In addition, the basic service module integrates functions such as data communication, exception handling, resource isolation, and tunnel management to achieve data communication.

[0036] Specifically, in this step, the information collection module can be used to obtain the user identity information and conduct a preliminary verification on the user identity information. In the case where the verification is passed, the basic service module is used to allocate an access channel for the target application so that the target application can perform inter-application interaction and external network interaction through the access channel.

[0037] It should be noted that the information collection module provides pages such as login, verification, session management, and security settings for users. The process implements various human-computer interaction mechanisms. By collecting the user's biometric features (fingerprint recognition, face recognition, voiceprint recognition, etc.) or hardware keys (USB security keys, smart cards, etc.), it ensures the accuracy and integrity of the user identity to prove that it is a human rather than a machine, preventing automated attacks and completing the preliminary verification.

[0038] In the basic service module, the data communication sub-module provides a secure communication pipeline, enabling necessary interaction between different application programs while ensuring the confidentiality and integrity of the data; the resource isolation sub-module allocates and restricts the resources that the mobile office application can use; the exception handling sub-module is used to detect and timely handle exceptions such as application crashes and resource exhaustion to ensure the stability and fairness of the system; the tunnel management sub-module is used to manage the parameter configuration and running status of the network tunnel to achieve access control of network resources.

[0039] In addition, the tunnel in this step is the access channel, which is used as the channel for interacting with other applications or the external network.

[0040] In step 102, when the target application conducts external network office access, the security channel enhancement process is used for identity authentication and access channel management.

[0041] In this step, external network office access refers to the data interaction between the target application and the external network, which is generally achieved through the target object accessing the external network. The target object can be an application, an interface, a service, data, etc.

[0042] Specifically, the architecture of the security channel enhancement process can refer to Figure 3 , Figure 3 which is a schematic diagram of the architecture of a security channel enhancement process provided in Embodiment 1 of this application.

[0043] As Figure 3 shown, the security channel enhancement process is provided with a data proxy module and a control center module; among them, the data proxy module is provided with functions such as network configuration, resource management, connection answering, traffic forwarding, etc., and the control center module is provided with functions such as module recharge, identity authentication, encrypted communication, tunnel start and stop, etc.

[0044] Specifically, in this step, the data proxy module can be used to monitor and forward the data and required resources interacted by the target application; obtain the user identity information logged in the target application, use the control center module to authenticate the user identity information, and encrypt the data or resources to be forwarded in the case of successful authentication; according to the forwarding requirements, use the control center module to control the start and stop of the access channel.

[0045] It should be noted that in the data proxy module, the network configuration is responsible for managing and configuring the network settings of the security channel to ensure the smooth progress of communication; the resource management is responsible for handling the resource updates related to the security channel, such as security policies, certificates, etc., and performing necessary maintenance tasks; the connection listening is responsible for waiting for connection requests from mobile terminals; the traffic forwarding is responsible for forwarding the communication traffic data packets between the mobile office application and the zero-trust security gateway.

[0046] This process initializes and resets the modules in the security channel when needed to restore their normal state (module reset); at the same time, it provides the zero-trust gateway with encrypted user identity information for identity authentication interaction (identity authentication); the encrypted communication is responsible for encrypting the communication data to protect the confidentiality of the data (encrypted communication); and manages the start and stop of the secure communication tunnel to ensure that the tunnel is available when needed and can be safely closed when not needed (tunnel start and stop).

[0047] Step 103: Collect any data interacted by the target application, and use a pre-trained intelligent risk assessment model to assess the risk of the collected data to obtain a risk assessment result.

[0048] In this step, the collected data can be analyzed and processed to obtain the user behavior sequence reflected by the data; the user behavior sequence is input into the pre-trained intelligent risk assessment model to obtain the risk assessment result output by the intelligent risk assessment model.

[0049] Among them, in the process of obtaining the user behavior sequence, the user identity identifier can be screened and analyzed from the collected data, and at least one access subject can be determined according to the identity identifier; obtain the independent files of each access subject, sort them according to the time stamp of the log, and generate a complete behavior sequence according to the independent files.

[0050] Specifically, when collecting data, data anonymization technology can be used to ensure that the collected data such as device attributes, operation records, traffic packets, and permission identifiers do not contain any personally identifiable information, thereby protecting user privacy. At the same time, differential privacy technology is used to add appropriate noise to the data to balance the relationship between data availability and individual privacy, so as to prevent the leakage of individual information during the data analysis process.

[0051] Then, the identity identifiers of the analysis targets are screened from the collected data to obtain independent files for each access subject, and they are sorted according to the time stamps of the logs to generate a complete behavior sequence. Specifically, it includes four steps:

[0052] Data cleaning: Define a subset of attribute fields, and use methods such as deletion and filling to uniformly process dirty data such as missing values, invalid values, and inaccurate values in various structured logs.

[0053] Data standardization: In order to convert the format and structure of the data into a form that is convenient for subsequent association and processing, unify the formats of all log files, and perform statistical calculations, abstraction, and generalization on field data to standardize character-type and numerical-type data.

[0054] Sequence recombination: Associate multi-source data according to the identity identifier, construct complete end-to-end behavior records of network connections, resource requests, application accesses, and business operations from the session dimension, and encode the behavior sequence vectors.

[0055] Data compression: In order to ensure the speed of behavior analysis, data compression and other methods are used to minimize the data as much as possible without destroying the data integrity.

[0056] In addition, the intelligent risk assessment model is a long short-term memory neural network that constructs a neural network in an incremental manner. When training, the long short-term memory neural network (Long Short-Term Memory, LSTM) can be used to construct a neural network in an incremental manner. By adding memory units, selectively forget the irrelevant parts in the previous state, and at the same time selectively output the relevant parts in the state to future time stages. The auto-encoder (Auto-Encoder, AE) is an unsupervised learning model that includes two parts: an encoder and a decoder, and data annotation is not required for the identification of abnormal scenarios.

[0057] In this embodiment, the encoder and decoder of the AE are constructed based on the LSTM, and the overall architecture of the LSTM-AE model is as Figure 4 shown, Figure 4 which is a schematic diagram of the overall architecture of an LSTM-AE model provided in Embodiment 1 of this application.

[0058] For the sequence data X, first, the high-dimensional original sequence data is reduced in dimension and compressed through an encoding layer, enabling the LSTM model to learn the most informative features. Then, through a decoding layer, the latent variables in the hidden layer are restored to the initial dimension, generating an expression as close as possible to its original input from the dimension-reduced encoding to obtain a reconstructed sequence. The overall error and local error of the sequence before and after reconstruction are compared to determine the outliers.

[0059] The loss function of the model includes the reconstruction error L of the encoder MSE , the classification error L of the detection model cross-entropy and the regularization term L regularization , which are specifically expressed as:

[0060] L loss = λ1L MSE + λ2L cross-entropy + L regularization

[0061] where λ1 and λ2 are hyperparameters used to balance the importance of different parts of the loss function; L MSE refers to the difference between the original input sequence and the low-dimensional sequence output by the encoder, which is measured using the Mean Squared Error (MSE), calculating the average of the squares of the differences between the input and output. The goal is to minimize the reconstruction error of the encoder and decoder as much as possible to retain more features of the original input sequence; L cross-entropy refers to the difference between the classification result of the detection model and the actual label of the sequence, which is measured using the Cross-Entropy Loss. The goal is to enable the detection model to identify abnormal sequences as accurately as possible to ensure the reliability and accuracy of the model; L regularization is used to promote the model to learn more generalized feature representations and improve the performance of the detection model.

[0062] Through model analysis, the detected network threats are classified into three levels: low, medium, and high according to their severity. Based on the risk level, the policy engine can perform trust assessment on abnormal behaviors in the network and actively respond to changes in network parameters before the threats have an impact.

[0063] In addition, the model of this embodiment can adapt to changes in the network environment and attack methods through continuous learning and updating, effectively reducing the situations of false alarms and missed detections, and having a higher accuracy rate.

[0064] Step 104: Obtain the corresponding execution policy according to the risk assessment result, and process this interaction according to the execution policy.

[0065] In this step, the risk assessment results include the risk levels of each abnormal behavior; for any target abnormal behavior, according to the mapping relationship between the abnormal behavior, the risk level, and the execution policy, determine the execution policy of the target abnormal behavior at the corresponding risk level.

[0066] It should be noted that in this embodiment, the mobile office application is connected to the zero-trust gateway by applying the isolation process and the secure channel enhancement process. In the zero-trust security gateway, the typical and atypical behaviors of the access subjects in the network are modeled, and by defining such baselines, untrusted events, potential threats, and attack behaviors in the network are detected.

[0067] The means of the dual-process enhanced authentication for accessing the zero-trust security gateway in this embodiment connects the mobile office application to the zero-trust security gateway by applying the isolation process and the secure channel enhancement process, ensuring that all access requests must undergo strict authentication and authorization, and realizing in-depth security control of the mobile office application.

[0068] In this embodiment, when the target application is started on the mobile side, the target application is isolated and run by using the application isolation process; when the target application accesses the external network for office work, the secure channel enhancement process is used for identity authentication and access channel management; any data interacted by the target application is collected, and the collected data is risk-assessed by using a pre-trained intelligent risk assessment model to obtain risk assessment results; the corresponding execution policy is obtained according to the risk assessment results, and this interaction is processed according to the execution policy. Based on this, by applying the application isolation process and the secure channel enhancement process, the user identity authentication is divided into two independent process steps, increasing the cracking difficulty. In addition, by using the intelligent risk assessment model, the user behavior can be analyzed in real time to identify abnormal behaviors, thereby effectively identifying security threats.

[0069] Embodiment 2

[0070] Figure 5 This is a schematic structural diagram of a mobile office secure access device based on a zero-trust network provided in Embodiment 2 of the present application. The mobile office secure access device based on the zero-trust network provided in the embodiments of the present application can execute the mobile office secure access method provided in any embodiment of the present application, and has the corresponding functional modules and beneficial effects of the execution method. The device can be implemented in software and / or hardware ways, such as Figure 5 As shown, the mobile office secure access device based on the zero-trust network specifically includes: an isolation module 501, a channel management module 502, a risk assessment module 503, and a policy allocation and processing module 504.

[0071] Among them,

[0072] An isolation module, which is used to isolate and run a target application by using an application isolation process when the target application is launched on a mobile device;

[0073] A channel management module, which is used to perform identity authentication and access channel management by using a secure channel enhancement process when the target application accesses external network for office work;

[0074] A risk assessment module, which is used to collect any data interacted by the target application and perform risk assessment on the collected data by using a pre-trained intelligent risk assessment model to obtain a risk assessment result;

[0075] A policy allocation and processing module, which is used to obtain a corresponding execution policy according to the risk assessment result and process this interaction according to the execution policy.

[0076] Embodiment III

[0077] Figure 6 The following is a schematic structural diagram of an electronic device provided in Embodiment III of this application. As Figure 6 shown, the electronic device includes a processor 610, a memory 620, an input device 630, and an output device 640; the number of processors 610 in the electronic device can be one or more. Figure 6 Here, one processor 610 is taken as an example; the processor 610, the memory 620, the input device 630, and the output device 640 in the electronic device can be connected through a bus or other means. Figure 6 Here, connection through a bus is taken as an example.

[0078] The memory 620, as a computer-readable storage medium, can be used to store software programs, computer-executable programs, and modules, such as program instructions / modules corresponding to the mobile office security access method based on the zero-trust network in the embodiments of the present invention. The processor 610 executes various functional applications and data processing of the electronic device by running the software programs, instructions, and modules stored in the memory 620, that is, implements the above-mentioned mobile office security access method based on the zero-trust network:

[0079] When the target application is launched on a mobile device, isolate and run the target application by using an application isolation process;

[0080] When the target application accesses external network for office work, perform identity authentication and access channel management by using a secure channel enhancement process;

[0081] Collect any data interacted by the target application and perform risk assessment on the collected data by using a pre-trained intelligent risk assessment model to obtain a risk assessment result;

[0082] Obtain a corresponding execution policy according to the risk assessment result and process this interaction according to the execution policy.

[0083] Furthermore, the application isolation process is provided with an information collection module and a basic service module;

[0084] Isolate and run the target application by using the application isolation process, including:

[0085] Use the information collection module to obtain the user identity information and perform a preliminary verification on the user identity information;

[0086] In the case of successful verification, use the basic service module to allocate an access channel for the target application, so that the target application can perform inter-application interaction and external network interaction through the access channel.

[0087] Furthermore, the secure channel enhancement process is provided with a data proxy module and a control center module;

[0088] Perform identity authentication and access channel management by using the secure channel enhancement process, including:

[0089] Use the data proxy module to monitor and forward the data and required resources for the interaction of the target application;

[0090] Obtain the user identity information logged in the target application, use the control center module to authenticate the user identity information, and encrypt the data or resources that need to be forwarded in the case of successful authentication;

[0091] According to the forwarding requirement, use the control center module to control the start and stop of the access channel.

[0092] Furthermore, use a pre-trained intelligent risk assessment model to perform a risk assessment on the collected data to obtain a risk assessment result, including:

[0093] Analyze and process the collected data to obtain the user behavior sequence reflected by the data;

[0094] Input the user behavior sequence into the pre-trained intelligent risk assessment model to obtain the risk assessment result output by the intelligent risk assessment model.

[0095] Furthermore, analyze and process the collected data to obtain the user behavior sequence reflected by the data, including:

[0096] Screen and analyze the user identity identifiers from the collected data, and determine at least one access subject according to the identity identifiers;

[0097] Obtain the independent files of each access subject, sort them according to the time stamps of the logs, and generate a complete behavior sequence according to the independent files.

[0098] Furthermore, the intelligent risk assessment model is a long short-term memory neural network that constructs a neural network in an incremental manner.

[0099] Further, the risk assessment result includes the risk level of each abnormal behavior;

[0100] Obtain the corresponding execution policy according to the risk assessment result, including:

[0101] For any target abnormal behavior, determine the execution policy of the target abnormal behavior at the corresponding risk level according to the mapping relationship between the abnormal behavior, the risk level, and the execution policy.

[0102] The memory 620 may mainly include a program storage area and a data storage area. Among them, the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created according to the use of the terminal, etc. In addition, the memory 620 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, a flash memory device, or other non-volatile solid-state storage devices. In some instances, the memory 620 may further include a memory remotely set relative to the processor 610, and these remote memories may be connected to the electronic device through a network. Examples of the above network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0103] Embodiment 4

[0104] Embodiment 4 of the present application further provides a storage medium containing computer-executable instructions, and the computer-executable instructions are used to execute a mobile office security access method based on a zero-trust network when executed by a computer processor. The method includes:

[0105] When starting a target application on the mobile side, use the application isolation process to isolate and run the target application;

[0106] When the target application accesses the external network for office work, use the secure channel enhancement process for identity authentication and access channel management;

[0107] Collect any data interacted by the target application, and use a pre-trained intelligent risk assessment model to perform risk assessment on the collected data to obtain a risk assessment result;

[0108] Obtain the corresponding execution policy according to the risk assessment result, and process the current interaction according to the execution policy.

[0109] Further, the application isolation process is provided with an information collection module and a basic service module;

[0110] Using the application isolation process to isolate and run the target application includes:

[0111] Use the information collection module to obtain the user identity information and perform preliminary verification on the user identity information;

[0112] When the verification is passed, the basic service module is used to allocate an access channel for the target application, so that the target application can perform inter-application interaction and external network interaction through the access channel.

[0113] Furthermore, the secure channel enhancement process is provided with a data proxy module and a control center module;

[0114] The secure channel enhancement process is used for identity authentication and access channel management, including:

[0115] The data proxy module is used to monitor and forward the data and required resources interacted by the target application;

[0116] The user identity information logged in the target application is obtained, and the control center module is used to authenticate the user identity information. When the authentication is passed, the data or resources to be forwarded are encrypted;

[0117] According to the forwarding requirement, the control center module is used to control the start and stop of the access channel.

[0118] Furthermore, the collected data is used for risk assessment by a pre-trained intelligent risk assessment model to obtain a risk assessment result, including:

[0119] The collected data is analyzed and processed to obtain the user behavior sequence reflected by the data;

[0120] The user behavior sequence is input into the pre-trained intelligent risk assessment model to obtain the risk assessment result output by the intelligent risk assessment model.

[0121] Furthermore, the collected data is analyzed and processed to obtain the user behavior sequence reflected by the data, including:

[0122] The identity identifier of the user is screened and analyzed from the collected data, and at least one access subject is determined according to the identity identifier;

[0123] The independent file of each access subject is obtained, sorted according to the time stamp of the log, and a complete behavior sequence is generated according to the independent file.

[0124] Furthermore, the intelligent risk assessment model is a long short-term memory neural network that constructs a neural network in an incremental manner.

[0125] Furthermore, the risk assessment result includes the risk level of each abnormal behavior;

[0126] The corresponding execution policy is obtained according to the risk assessment result, including:

[0127] For any target abnormal behavior, determine the execution policy of the target abnormal behavior at the corresponding risk level according to the mapping relationship between the abnormal behavior, the risk level, and the execution policy.

[0128] Of course, for a storage medium containing computer-executable instructions provided in the embodiments of the present application, the computer-executable instructions are not limited to the above method operations, and can also execute relevant operations in the mobile office security access method based on a zero-trust network provided in any embodiment of the present application.

[0129] From the above description of the implementation manners, those skilled in the art can clearly understand that the present application can be implemented by means of software and necessary general-purpose hardware. Of course, it can also be implemented by hardware, but in many cases, the former is a better implementation manner. Based on such an understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. The computer software product can be stored in a computer-readable storage medium, such as a floppy disk, a read-only memory (ROM), a random access memory (RAM), a flash memory (FLASH), a hard disk, or an optical disc of a computer, and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods of the various embodiments of the present application.

[0130] It should be noted that in the embodiments of the above search device, the various units and modules included are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be realized; in addition, the specific names of the functional units are only for the convenience of mutual distinction and do not limit the protection scope of the present application.

[0131] Note that the above is only the preferred embodiment of the present application and the applied technical principle. Those skilled in the art will understand that the present application is not limited to the specific embodiments here, and various obvious changes, re-adjustments, and substitutions can be made by those skilled in the art without departing from the protection scope of the present application. Therefore, although the present application has been described in detail through the above embodiments, the present application is not limited to the above embodiments. Without departing from the concept of the present application, more other equivalent embodiments can be included, and the scope of the present application is determined by the scope of the appended claims.

Claims

1. A mobile office secure access method based on a zero-trust network, characterized in that, The method includes: When the target application is launched on the mobile device, isolating and running the target application by using an application isolation process; When the target application accesses the external network for office work, performing identity authentication and access channel management by using a secure channel enhancement process; Collecting any data interacted by the target application, and using a pre-trained intelligent risk assessment model to perform risk assessment on the collected data to obtain a risk assessment result; Obtaining a corresponding execution policy according to the risk assessment result, and processing the current interaction according to the execution policy.

2. The method according to claim 1, characterized in that, The application isolation process is provided with an information collection module and a basic service module; The isolating and running the target application by using the application isolation process includes: Obtaining user identity information by using the information collection module, and performing preliminary verification on the user identity information; When the verification is passed, using the basic service module to allocate an access channel for the target application, so that the target application performs inter-application interaction and external network interaction through the access channel.

3. The method according to claim 1, characterized in that, The secure channel enhancement process is provided with a data proxy module and a control center module; The performing identity authentication and access channel management by using the secure channel enhancement process includes: Using the data proxy module to monitor and forward the data and required resources interacted by the target application; Obtaining the user identity information logged in the target application, using the control center module to authenticate the user identity information, and encrypting the data or resources to be forwarded when the authentication is passed; Controlling the start and stop of the access channel by using the control center module according to the forwarding requirement.

4. The method according to claim 1, wherein The using a pre-trained intelligent risk assessment model to perform risk assessment on the collected data to obtain a risk assessment result includes: Analyzing and processing the collected data to obtain a user behavior sequence reflected by the data; Inputting the user behavior sequence into a pre-trained intelligent risk assessment model to obtain the risk assessment result output by the intelligent risk assessment model.

5. The method according to claim 4, wherein The analyzing and processing the collected data to obtain a user behavior sequence reflected by the data includes: Screening and analyzing the user identity identifier from the collected data, and determining at least one access subject according to the identity identifier; Obtaining the independent file of each access subject, sorting according to the time stamp of the log, and generating a complete behavior sequence according to the independent file.

6. The method according to claim 4, wherein The intelligent risk assessment model is a long short-term memory neural network that constructs a neural network in an incremental manner.

7. The method according to claim 1, wherein The risk assessment result includes the risk levels of each abnormal behavior; The obtaining a corresponding execution policy according to the risk assessment result includes: For any target abnormal behavior, determining the execution policy of the target abnormal behavior at the corresponding risk level according to the mapping relationship between the abnormal behavior, the risk level and the execution policy.

8. A mobile office security access device based on a zero-trust network, characterized in that, The device includes: An isolation module, configured to isolate and run the target application by using an application isolation process when the target application is launched on the mobile device; A channel management module, configured to perform identity authentication and access channel management by using a secure channel enhancement process when the target application accesses the external network for office work; A risk assessment module, configured to collect any data interacted with the target application, and use a pre-trained intelligent risk assessment model to perform risk assessment on the collected data to obtain a risk assessment result; A policy allocation and processing module, configured to obtain a corresponding execution policy according to the risk assessment result, and process the current interaction according to the execution policy.

9. An electronic device, characterized in that, Comprising: One or more processors; A storage device, configured to store one or more programs, When the one or more programs are executed by the one or more processors, the one or more processors implement the mobile office secure access method based on a zero-trust network according to any one of claims 1-7.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by a processor, it implements the mobile office secure access method based on a zero-trust network according to any one of claims 1-7.