Zero-trust communication network system and data transmission method

The zero-trust communication network system addresses the increased risks in dynamic network environments by dynamically evaluating and reconfiguring network topology based on trust values, enhancing security and protection capabilities.

CN120321042AActive Publication Date: 2025-07-15INST OF AUTOMATION CHINESE ACAD OF SCI

Patent Information

Application Number
CN202510798951.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-06-16
Publication Date
2025-07-15
Estimated Expiration
2045-06-16

AI Technical Summary

Technical Problem

In the face of cloud computing, Internet of Things and mobile communications, traditional network security architectures have blurred network boundaries and increased dynamic nodes, resulting in a significant increase in the risk of passive impact and active malicious attacks on network systems, users and data.

Method used

The zero-trust communication network system is adopted, and the node trust value is calculated through the trust evaluation module, the control plane is dynamically authorized, the topological reconstruction module reconstructs the network structure, and data transmission is carried out based on the trust value-related information.

Benefits of technology

It improves the security and protection capabilities of the network system, enhances its resistance to malicious attacks, and ensures the reliability and security of data transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120321042A_ABST
    Figure CN120321042A_ABST
Patent Text Reader

Abstract

The invention provides a zero-trust communication network system and a data transmission method, and relates to the technical field of network security, and the system comprises a control plane, a data plane, a trust evaluation module and a topology reconstruction module. The trust evaluation module is used for calculating trust value related information of the target node, wherein the trust value related information of the target node comprises trust values between the target node and all nodes except the target node in the communication network system; the control plane is used for receiving an access request of a target node and determining an authorization condition of the target node to the data plane based on the trust value related information of the target node; and the topology reconstruction module is used for reconstructing the network structure of the communication network system based on the trust value related information of each node in the communication network system. Therefore, the security of the network system is improved, and the protection capability of the network system is enhanced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network security technology, and in particular to a zero-trust communication network system and a data transmission method. Background Art

[0002] With the rapid development of information technology and network security technology, the defects of traditional network security architectures have gradually emerged. In traditional network security architectures, the boundaries are very clear, and network nodes and communication links are mostly static. The security architecture protects the entire system through external security measures such as firewalls and intrusion detection systems. However, with the popularization of cloud computing, the Internet of Things, and mobile communications, the network boundaries have gradually become blurred, the node dynamics have increased significantly, and the ways of interference and infringement have gradually increased. The risks of passive influence and active malicious attacks on network systems, users, data, etc. have increased significantly. In response to this situation, it is necessary to study new network security architectures and self-organizing network technologies in new scenarios and new backgrounds. Summary of the Invention

[0003] The present invention provides a zero-trust communication network system and a data transmission method to solve the defect that the risks of passive influence and active malicious attacks on network systems, users, data, etc. in the prior art have increased significantly, and to achieve the improvement of the security and the enhancement of the protection ability of the network system.

[0004] The present invention provides a zero-trust communication network system, including: A control plane, a data plane, a trust evaluation module, and a topology reconstruction module; Wherein, the trust evaluation module is used to calculate trust value-related information of a target node, and the trust value-related information of the target node includes the trust values between the target node and each node other than the target node in the communication network system; The control plane is used to receive an access request of the target node and determine the authorization situation of the target node for the data plane based on the trust value-related information of the target node; The topology reconstruction module is used to reconstruct the network structure of the communication network system based on the trust value-related information of each node in the communication network system.

[0005] According to a zero-trust communication network system provided by the present invention, the trust evaluation module calculates the trust value-related information of the target node according to the following method: Based on the communication topology-related information of the communication network system and the related information of the target node, determine the trust value-related information of the target node; Among them, the communication topology-related information includes the hardware objective conditions of the communication network system and the graph topology calculation conditions; the related information of the target node includes the importance score of the target node and the interaction behavior score between the target node and each node other than the target node in the communication network system.

[0006] According to a zero-trust communication network system provided by the present invention, the trust evaluation module calculates the trust value-related information of the target node in the following manner: Based on the communication topology-related information of the communication network system, the related information of the target node, and the security mode type of the communication network system, determine the trust value-related information of the target node; Among them, the security mode type is determined based on the information security level and the task objective level of the communication network system.

[0007] According to a zero-trust communication network system provided by the present invention, the trust evaluation module calculates the trust value-related information of the target node in the following manner: Based on the communication topology-related information of the communication network system, the related information of the target node, the security mode type of the communication network system, and time, determine the trust value-related information of the target node.

[0008] According to a zero-trust communication network system provided by the present invention, the topology reconstruction module reconstructs the network structure of the communication network system in the following manner: Based on the trust value-related information of each node in the communication network system, determine the Laplacian matrix of the communication network system; Based on the Laplacian matrix, with the maximum stability margin as the optimization objective, determine the reconstructed network structure.

[0009] The present invention also provides a data transmission method for a zero-trust communication network, which is applied to the zero-trust communication network system as described above, and includes: Based on the trust value-related information of each node in the communication network system, determine the authorization situation of each node for the data plane; Based on the trust value-related information of each node, reconstruct the network structure of the communication network system; Based on the reconstructed network structure and the authorization situation of each node for the data plane, perform data transmission between each node; Among them, the trust value-related information of any node includes the trust value between the any node and each node other than the any node in the communication network system.

[0010] A data transmission method for a zero-trust communication network provided by the present invention, the trust value-related information of each node is calculated according to the following method: Based on the communication topology-related information of the communication network system and the related information of each node, determine the trust value-related information of each node; Wherein, the communication topology-related information includes the hardware objective conditions and graph topology calculation conditions of the communication network system; the related information of any node includes the importance score of the any node and the interaction behavior score of the any node with each node other than the any node in the communication network system.

[0011] A data transmission method for a zero-trust communication network provided by the present invention, the trust value-related information of each node is calculated according to the following method: Based on the communication topology-related information of the communication network system, the related information of each node, and the security mode type of the communication network system, determine the trust value-related information of each node; Wherein, the security mode type is determined based on the information security level and task objective level of the communication network system.

[0012] A data transmission method for a zero-trust communication network provided by the present invention, the trust value-related information of each node is calculated according to the following method: Based on the communication topology-related information of the communication network system, the related information of each node, the security mode type of the communication network system, and time, determine the trust value-related information of each node.

[0013] A data transmission method for a zero-trust communication network provided by the present invention, based on the trust value-related information of each node, reconstruct the network structure of the communication network system, including: Based on the trust value-related information of each node, determine the Laplacian matrix of the communication network system; Based on the Laplacian matrix, with the maximum stability margin as the optimization goal, determine the reconstructed network structure.

[0014] The zero-trust communication network system and data transmission method provided by the present invention, by adopting a zero-trust network architecture, calculate the trust value-related information of each node, determine the authorization situation of the target node for the data plane based on the trust value-related information of the target node, and reconstruct the network structure of the communication network system based on the trust value-related information of each node in the communication network system, thereby improving the security of the network system and enhancing the protection ability of the network system. Brief Description of the Drawings

[0015] To more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the accompanying drawings required for use in the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.

[0016] Figure 1 It is a schematic structural diagram of a zero-trust communication network system provided by the present invention.

[0017] Figure 2 It is a schematic flowchart of a data transmission method for a zero-trust communication network provided by the present invention.

[0018] Figure 3 It is a security network architecture diagram under the zero-trust mechanism provided by the present invention. Detailed implementation manners

[0019] To make the objectives, technical solutions, and advantages of the present invention clearer, the following will clearly and completely describe the technical solutions in the present invention in conjunction with the accompanying drawings in the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Based on the embodiments in the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present invention.

[0020] The following briefly introduces the related technologies of the present invention.

[0021] Zero trust is a new type of network security architecture that emphasizes defaulting to distrust any device or user in the network, adheres to the principle of "never trust, always verify", and adopts multi-level security control strategies to protect network security. It emphasizes security verification and continuous monitoring, and requires the ability to respond and repair any security incident in a timely manner. The zero-trust model provides new ideas and methods for network security and is widely studied and applied.

[0022] The network security architecture based on the zero-trust mechanism has the following key features: setting dynamic directed communication link trust value evaluation; each access and request is based on identity authentication and authorization steps; different data and function request permissions are assigned to different users and nodes; abnormal nodes and abnormal states are discovered by monitoring and detecting the characteristics of real-time network links and nodes; data is encrypted and isolated in layers. In summary, the zero-trust network security architecture evaluates the communication between different nodes through dynamic trust evaluation and identity authentication, and authorizes data and function requests at different levels based on the dynamic evaluation results, that is, sends different data information and opens different data creation, deletion, modification, and query permissions to nodes at different trust levels to protect data from being stolen or tampered with by unqualified and unauthorized access.

[0023] Under the zero-trust architecture, data security transmission and access control are divided into three categories: information sensing and control terminals, communication infrastructure, and cloud platforms. However, due to the strong coupling and overlap in the data transmission process, each node in the zero-trust network system is at risk of identity impersonation and unauthorized services. Therefore, the data security transmission problem in the zero-trust network system is also a dynamic access control problem based on node authentication. If node authentication fails, the node will be excluded from the dynamic network. Among the numerous node join requests to the network, the nodes that pass the node authentication will be able to join the dynamic network system. Therefore, the self-organizing architecture of the network system based on dynamic node authentication becomes the basis of the zero-trust network security architecture.

[0024] A self-organizing network is a special temporary and dynamic wireless network formed by nodes with wireless communication and computing capabilities. Different from traditional network architectures, a self-organizing network does not rely on any pre-established fixed basic communication facilities such as base stations and routers. Each node in the network can send, receive, and forward data. The nodes in a self-organizing network are not fixed, and the communication links are not fixed. A self-organizing network has self-organizing and dynamic characteristics, that is, the nodes in the network can discover the existence of other nodes in the network through queries and requests, and negotiate and configure according to intelligent algorithms to establish and maintain the topological structure of the dynamic network. The topological structure of a self-organizing network changes in real time dynamically. Nodes can apply to join and leave the network at any time, and the relative topological positions of the nodes and the communication links between them will also change in real time. The self-organizing network based on the zero-trust architecture also has the characteristic that the trust evaluation weights of communication links are not fixed on the basis of the traditional self-organizing network.

[0025] Figure 1 It is a schematic structural diagram of the zero-trust communication network system provided by the present invention, as Figure 1 shown. The system includes: A control plane 100, a data plane 110, a trust evaluation module 120, and a topology reconstruction module 130; Among them, the trust evaluation module 120 is used to calculate the trust value-related information of the target node. The trust value-related information of the target node includes the trust values between the target node and each node other than the target node in the communication network system; The control plane 100 is used to receive the access request of the target node and determine the authorization situation of the target node for the data plane 110 based on the trust value-related information of the target node; The topology reconstruction module 130 is used to reconstruct the network structure of the communication network system based on the trust value-related information of each node in the communication network system.

[0026] Specifically, the support system of the zero-trust architecture is called the control plane, and the other parts are called the data plane. The data plane is commanded and configured by the control plane. Requests to access protected resources first pass through the control plane for processing, including authentication and authorization of devices and users.

[0027] Once the control plane completes the check and determines that the request has legitimate authorization, it will dynamically configure the data plane to receive access traffic from the client. Whether the access entity is on the internal network or the external network, authentication is required to access resources.

[0028] In the continuous dynamic access control policy, the access entity needs to be authorized according to its trust status before accessing the trusted area, and continuously monitor its trust dynamics during the access process to dynamically adjust access permissions and achieve secure access control.

[0029] The control plane is the decision-making core of the communication network system. Following the principle of "never trust, always verify", it is responsible for dynamically authorizing all access requests. It includes three logical components: the Policy Engine (PE), Policy Administration (PA), and Policy Enforcement Point (PEP). The PE generates decisions based on trust assessment results and security policies. The PA dynamically configures the policies to the data plane. The PEP is responsible for interacting with users / devices and forwarding requests.

[0030] In the embodiments of this application, all nodes in the communication network system are confirmed and authorized through trust value-related information. The trust value-related information of any node, including the trust values between this node and each node other than this node in the communication network system, helps determine the information level that this node can access and the reliability of transmitted information, etc. The trust assessment module can dynamically calculate the trust values between nodes through multiple dimensional parameters, providing a quantitative basis for the control plane and topology reconstruction. The trust value can be represented by a parameterized adjacency matrix, and the value range of the trust value between nodes is 0 to 1.

[0031] When the target node initiates an access request, the control plane first receives the access request, and combines the trust value-related information provided by the trust assessment module to determine whether to authorize it to access the resources of the data plane.

[0032] For example, if the trust value between the target node and other nodes is lower than the threshold set by the security mode, the control plane will reject its access to sensitive data and only open the basic function permissions.

[0033] The topology reconstruction module can dynamically adjust the network structure based on the trust value-related information and intelligent optimization algorithms to ensure that the system quickly recovers stability when under attack.

[0034] For example, when the trust value between a certain node and other nodes is detected to decrease, the topology reconstruction module can cut off its connection with the core data node and reconstruct the path to bypass potential risk areas.

[0035] It can be understood that in addition to detecting the trust values of each node in the communication network system when the nodes in the communication network system change, a detection period can also be set to regularly detect the trust values of each node in the communication network system, so as to ensure the security of the communication network system.

[0036] The data plane realizes data encryption transmission and access control according to the instructions of the control plane. Its encryption policy can be directly associated with the trust value. For example, high-trust nodes adopt lightweight encryption methods, while low-trust nodes require higher-strength encryption methods. The data plane can dynamically adjust the permissions of each node according to the trust value-related information of each node. For example, when the trust value of a certain node decreases, the data plane can synchronously revoke its key usage permission to ensure that data only flows in trusted paths.

[0037] The zero-trust communication network system provided by the present invention, by adopting a zero-trust network architecture, calculates the trust value-related information of each node, determines the authorization situation of the target node for the data plane based on the trust value-related information of the target node, and reconstructs the network structure of the communication network system based on the trust value-related information of each node in the communication network system, thereby improving the security of the network system and enhancing the protection ability of the network system.

[0038] According to a zero-trust communication network system provided by the present invention, the trust evaluation module calculates the trust value-related information of the target node according to the following method: Based on the communication topology-related information of the communication network system and the related information of the target node, determine the trust value-related information of the target node; Among them, the communication topology-related information includes the hardware objective conditions of the communication network system and the graph topology calculation conditions; the related information of the target node includes the importance score of the target node and the interaction behavior score of the target node with each node other than the target node in the communication network system.

[0039] Specifically, in the embodiments of the present application, the trust evaluation module can dynamically calculate and determine the trust value-related information of the target node by fusing the communication topology-related information and the related information of the target node.

[0040] The communication topology-related information includes the hardware objective conditions of the communication network system and the graph topology calculation conditions.

[0041] The hardware objective conditions of the communication network system may include physical layer indicators such as the link connectivity probability and communication quality (such as bandwidth, latency, bit error rate) of the communication network system, reflecting the stability and reliability of the communication link. For example, the higher the communication quality and the lower the error rate, the higher the trust value.

[0042] The graph topology calculation conditions may include network structure attributes such as node connectivity (obtained from calculations related to graph connectivity), node stability margin (obtained from the calculation of the network topology stability margin), centrality indicators (degree centrality, closeness centrality, betweenness centrality), and graph stability margin. These parameters are quantitatively analyzed through the Laplacian matrix. For example, nodes with high betweenness centrality are assigned higher trust weights because they are on critical communication paths.

[0043] The relevant information of the target node includes the importance score of the target node and the interaction behavior scores of the target node with each node other than the target node in the communication network system. The relevant information of the target node is subjective information, which represents the subjective judgment information generated based on the "interaction" with the other party when there is a direct information connection with the observer and the information and behavior of the other party have a direct impact on the observer, including information links and physical dynamics.

[0044] The importance score of the target node is dynamically adjusted according to the role of the target node in the communication network system (such as critical data source, control node). The interaction behavior score represents the comprehensive score of each node for the other node after communication. For example, if abnormal data is transmitted between nodes, the score of the node for the other node will be dynamically reduced.

[0045] It should be noted that in the embodiments of the present invention, the method for calculating the trust value is not limited. For example, weighted calculation and other methods can be used.

[0046] By quantifying the hardware objective conditions, graph topology calculation conditions, node importance, and node behavior history into trust values, the core goals of dynamic evaluation and continuous verification in the zero-trust architecture are achieved, providing a computable quantitative basis for fine-grained access control and topology optimization in the ad-hoc network environment.

[0047] According to a zero-trust communication network system provided by the present invention, the trust evaluation module calculates the trust value-related information of the target node according to the following method: Based on the communication topology-related information of the communication network system, the relevant information of the target node, and the security mode type of the communication network system, determine the trust value-related information of the target node; Among them, the security mode type is determined based on the information security level and task objective level of the communication network system.

[0048] Specifically, in the embodiment of the present application, the trust evaluation module can dynamically calculate and determine the trust value related information of the target node by integrating the communication topology related information, the target node related information and the security mode type of the communication network system.

[0049] The security mode type can be determined by the information security level of the communication network system (such as public level, confidential level, etc.) and the mission objective level (such as routine mission, important mission, etc.).

[0050] In some implementations, the calculation weight and threshold of the trust value can be determined according to the security mode type. For example, a high security mode can increase the weight of the relevant information of the target node and tighten the trust threshold (such as authorization requires a trust value ≥ 0.9); a low security mode can increase the weight of the information related to the communication topology and relax the threshold (such as authorization requires a trust value ≥ 0.7).

[0051] According to a zero-trust communication network system provided by the present invention, the trust evaluation module calculates the trust value related information of the target node according to the following method: Based on the communication topology related information of the communication network system, the related information of the target node, the security mode type of the communication network system and the time, the trust value related information of the target node is determined.

[0052] Specifically, in an embodiment of the present application, the trust evaluation module can dynamically calculate and determine the trust value related information of the target node by integrating the communication topology related information, the target node related information, the security mode type of the communication network system, and the time.

[0053] In some implementations, the time factor Reflect the dynamic nature of trust value.

[0054] The change of the time factor can be set according to the specific situation. For example, if there is no abnormal behavior between nodes for a long time, the trust value will gradually recover over time (such as linear growth); if malicious behavior is detected, the trust value will instantly return to zero and trigger the isolation mechanism. For another example, if the trust value between nodes gradually decreases over time (such as linear decrease), until the next trust value detection.

[0055] According to a zero-trust communication network system provided by the present invention, the topology reconstruction module reconstructs the network structure of the communication network system according to the following method: Determine a Laplace matrix of the communication network system based on information related to the trust values of each node in the communication network system; Based on the Laplace matrix, the reconstructed network structure is determined with the maximum stability margin as the optimization goal.

[0056] Specifically, the topology reconstruction module in the embodiments of the present invention dynamically adjusts the network structure to maximize the stability margin by fusing trust value-related information and graph theory optimization algorithms.

[0057] The ad hoc network is abstracted as an undirected graph G = (V, E), where V is the set of nodes, E is the set of edges, and the edges represent the communication links between nodes.

[0058] In the case of node attacks as malicious attacks, it is assumed that the attacker can render some nodes ineffective, that is, delete these nodes and their associated edges from the graph. Let the set of attacked nodes be A ∈ V. In the case of link attacks as malicious attacks, the attacker may also disrupt the communication links, that is, delete the edges in the graph. Let the set of attacked edges be B ∈ E.

[0059] The stability margin index is selected as betweenness centrality. The betweenness centrality B(v) of node v refers to the proportion of all shortest paths in the network that pass through node v. If the betweenness centrality of the attacked nodes is relatively high, it may have a greater impact on the network topology.

[0060] During the calculation of the stability margin based on betweenness centrality, let the sum of the betweenness centralities of all nodes be B total , and the sum of the betweenness centralities of the set of attacked nodes A be B A , and define the stability margin S total = 1 - B A / B total , S total ∈ [0, 1], which reflects the degree of influence of the attack on the key nodes of the network. The larger the value, the higher the stability margin.

[0061] It is possible to transform the topologies of multiple ad hoc networks, and then find the topology with the largest stability margin (obtained from betweenness centrality calculation), and change it to the most stable topology structure, thereby ensuring the connectivity of the overall network and more reliable information transmission.

[0062] Figure 2 is a schematic flowchart of the data transmission method for the zero-trust communication network provided by the present invention. As Figure 2 shown, this method is applied to the zero-trust communication network system as described above and includes the following steps: Step 200: Determine the authorization status of each node for the data plane based on the trust value-related information of each node in the communication network system.

[0063] Step 201: Reconstruct the network structure of the communication network system based on the trust value-related information of each node.

[0064] Step 202: Perform data transmission between each node based on the reconstructed network structure and the authorization status of each node for the data plane.

[0065] Among them, the trust value related information of any node includes the trust values between any node and each of the other nodes in the communication network system except the node itself.

[0066] Specifically, the zero-trust communication network system first determines the access rights of each node to the data plane according to the trust values generated by the trust evaluation module.

[0067] In the embodiments of the present application, all nodes in the communication network system are confirmed and authorized through the trust value related information. The trust value related information of any node includes the trust values between the node and each of the other nodes in the communication network system except the node itself. The trust value related information of this node helps to determine the information level that the node can access and the reliability of the transmitted information, etc. The trust evaluation module can dynamically calculate the trust values between nodes through multiple dimensional parameters, providing a quantitative basis for the control plane and topology reconstruction. The trust value can be represented by a parametric adjacency matrix, and the value range of the trust value between nodes is 0 to 1.

[0068] When any node initiates an access request, it is necessary to combine the trust value related information of the node to determine whether to authorize it to access the resources of the data plane.

[0069] For example, if the trust value between the target node and other nodes is lower than the threshold set by the security mode, the control plane will reject its access to sensitive data and only open the basic function permissions.

[0070] After determining the trust value related information of each node, the network structure can also be dynamically adjusted based on the trust value related information and intelligent optimization algorithms to ensure that the system quickly recovers stability when under attack.

[0071] For example, when it is detected that the trust value between a certain node and other nodes decreases, its connection with the core data node can be cut off, and the path can be reconstructed to bypass potential risk areas.

[0072] It can be understood that in addition to detecting the trust values of each node in the communication network system when the nodes in the communication network system change, a detection period can also be set to regularly detect the trust values of each node in the communication network system, so as to ensure the security of the communication network system.

[0073] Then, encryption transmission and access control can be performed according to the reconstructed network structure and the authorization status of each node for the data plane. Its encryption policy can be directly associated with the trust value. For example, high-trust nodes adopt lightweight encryption methods, while low-trust nodes require higher-strength encryption methods. The permissions of each node can be dynamically adjusted according to the trust value related information of each node. For example, when the trust value of a certain node decreases, its key usage permission can be revoked synchronously to ensure that data only flows in trusted paths.

[0074] The data transmission method for a zero-trust communication network provided by the present invention calculates information related to the trust values of each node by adopting a zero-trust network architecture, determines the authorization status of each node for the data plane based on the information related to the trust values of each node, and reconstructs the network structure of the communication network system based on the information related to the trust values of each node in the communication network system. Finally, data transmission is performed between each node, thereby improving the security of the network system and enhancing the protection ability of the network system.

[0075] According to a data transmission method for a zero-trust communication network provided by the present invention, the information related to the trust values of each node is calculated according to the following method: Based on the communication topology-related information of the communication network system and the information related to each node, determine the information related to the trust values of each node; Among them, the communication topology-related information includes the hardware objective conditions of the communication network system and the graph topology calculation conditions; the information related to any node includes the importance score of any node, and the interaction behavior score between any node and each node other than any node in the communication network system.

[0076] Specifically, in the embodiments of the present application, the trust evaluation module can dynamically calculate and determine the information related to the trust values of each node by fusing the communication topology-related information and the information related to each node.

[0077] The communication topology-related information includes the hardware objective conditions of the communication network system and the graph topology calculation conditions.

[0078] The hardware objective conditions of the communication network system may include physical layer indicators such as the link connectivity probability of the communication network system, communication quality (such as bandwidth, delay, bit error rate), etc., reflecting the stability and reliability of the communication link. For example, the higher the communication quality and the lower the error rate, the higher the trust value.

[0079] The graph topology calculation conditions may include network structure attributes such as node connectivity (obtained by relevant calculations of graph connectivity), node stability margin (calculated by network topology stability margin), centrality indicators (degree centrality, closeness centrality, betweenness centrality), and graph stability margin. These parameters are quantitatively analyzed through the Laplacian matrix. For example, nodes with high betweenness centrality are given higher trust weights because they are on critical communication paths.

[0080] For any node, the relevant information of the node includes the importance score of the node and the interaction behavior score between the node and each node other than the node itself in the communication network system. The relevant information of any node is subjective information, which represents the subjective judgment information generated based on the "interaction" with the other party when there is a direct information connection with the observer and the information and behavior of the other party have a direct impact on the observer, including information links and physical dynamics impacts.

[0081] The importance score of any node is dynamically adjusted according to the roles of each node in the communication network system (such as key data sources, control nodes). The interaction behavior score represents the comprehensive score of each node for the other node after communication. For example, if abnormal data is transmitted between nodes, the score of the node for the other node will be dynamically reduced.

[0082] It should be noted that in the embodiments of the present invention, the method for calculating the trust value is not limited. For example, weighted calculation and other methods can be used.

[0083] By quantifying the hardware objective conditions, graph topology calculation conditions, node importance, and node behavior history into trust values, the core goals of dynamic evaluation and continuous verification under the zero-trust architecture are achieved, providing a computable quantitative basis for fine-grained access control and topology optimization in the ad-hoc network environment.

[0084] According to a data transmission method for a zero-trust communication network provided by the present invention, the trust value-related information of each node is calculated according to the following method: Based on the communication topology-related information of the communication network system, the relevant information of each node, and the security mode type of the communication network system, determine the trust value-related information of each node; Among them, the security mode type is determined based on the information security level and task objective level of the communication network system.

[0085] Specifically, in the embodiments of the present application, the trust evaluation module can dynamically calculate and determine the trust value-related information of each node by fusing the communication topology-related information, the relevant information of each node, and the security mode type of the communication network system.

[0086] The security mode type can be jointly determined by the information security level (such as public level, confidential level, etc.) and task objective level (such as regular task, important task, etc.) of the communication network system.

[0087] In some implementation manners, the calculation weight and threshold of the trust value can be determined according to the security mode type. For example, a high security mode can increase the weight of the relevant information of the target node and tighten the trust threshold (such as authorization requires a trust value ≥ 0.9); a low security mode can increase the weight of the communication topology-related information and relax the threshold (such as authorization requires a trust value ≥ 0.7).

[0088] According to a data transmission method for a zero-trust communication network provided by the present invention, the trust value related information of each node is calculated according to the following method: Based on the communication topology related information of the communication network system, the related information of each node, the security mode type of the communication network system, and time, determine the trust value related information of each node.

[0089] Specifically, in the embodiments of the present application, the trust evaluation module can dynamically calculate and determine the trust value related information of each node by fusing the communication topology related information, the related information of each node, the security mode type of the communication network system, and time.

[0090] In some embodiments, the dynamic nature of the trust value can be reflected by a time factor The change situation of the time factor can be set according to the specific situation. For example, if there is no abnormal behavior between nodes for a long time, the trust value gradually recovers over time (such as linear growth); if malicious behavior is detected, the trust value is instantly set to zero and the isolation mechanism is triggered. Another example is that if the trust value between nodes gradually decreases over time (such as linear decrease), until the next trust value detection.

[0091] According to a data transmission method for a zero-trust communication network provided by the present invention, based on the trust value related information of each node, reconstruct the network structure of the communication network system, including:

[0092] Based on the trust value related information of each node, determine the Laplacian matrix of the communication network system; Based on the Laplacian matrix, with the maximum stability margin as the optimization goal, determine the reconstructed network structure. Specifically, the topology reconstruction module in the embodiments of the present invention dynamically adjusts the network structure to maximize the stability margin by fusing the trust value related information and the graph theory optimization algorithm.

[0093] Abstract the ad hoc network as an undirected graph G=(V,E), where V is the node set and E is the edge set, and the edge represents the communication link between nodes.

[0094] In the case of a node attack as a malicious attack, it is assumed that the attacker can make some nodes fail, that is, delete these nodes and their associated edges from the graph. Let the set of attacked nodes be A∈V. In the case of a link attack as a malicious attack, the attacker may also damage the communication link, that is, delete the edges in the graph. Let the set of attacked edges be B∈E.

[0095]

[0096] ​The stability margin index is selected as betweenness centrality. The betweenness centrality B(v) of a node v refers to the proportion of all shortest paths in the network that pass through node v. If the betweenness centrality of the attacked node is relatively high, it may have a greater impact on the network topology.

[0097] In the process of calculating the stability margin based on betweenness centrality, let the sum of the betweenness centralities of all nodes be B total , and the sum of the betweenness centralities of the set A of attacked nodes be B A , and define the stability margin S total = 1 - B A / B total , S total ∈ [0, 1], which reflects the degree of influence of the attack on the key nodes of the network. The larger the value, the higher the stability margin.

[0098] It is possible to transform the topologies of multiple ad hoc networks, and then find the topology with the largest stability margin (calculated from betweenness centrality) and change it to the most stable topology structure, so as to ensure the connectivity of the overall network and more secure information transmission.

[0099] The following further elaborates on the zero-trust communication network system and data transmission method provided by the present invention through embodiments in specific application scenarios.

[0100] Figure 3 This is a security network architecture diagram under the zero-trust mechanism provided by the present invention.

[0101] This embodiment is divided into 4 steps: (1) Network security architecture based on the zero-trust mechanism Zero trust is introduced as a strategy for building a security system. The principle is not to trust any request to access resources, that is, "never trust, always verify". This is an abstract concept, and its implementation requires the guidance of a specific theoretical architecture. The support system of the zero-trust architecture is called the control plane, and other parts are called the data plane. The data plane is commanded and configured by the control plane. Requests to access protected resources first pass through the control plane for processing, including the authentication and authorization of devices and users. Once the control plane completes the inspection and determines that the request has a legitimate authorization, it will dynamically configure the data plane to receive access traffic from this client. Whether the access entity is in the internal network or the external network, it needs to be authenticated to access resources.

[0102] Six basic assumptions are proposed for network connectivity based on the zero-trust architecture, namely, the six key points of untrusted personnel, untrusted devices, untrusted resources, untrusted services, untrusted local connections, and maintaining a secure posture for resource transfer. The NIST architecture contains three core logical components, namely, the Policy Engine (PE), Policy Administration (PA), and Policy Enforcement Point (PEP). Among them, authentication and authorization follow dynamic policies, and the access of a principal (user, device, or application) to a resource (such as a service or data) is only granted during communication. The Policy Enforcement Point (PEP) is responsible for interacting with the principal and forwarding their access requests for resources to the Policy Decision Point (PDP). The Policy Decision Point PDP consists of the Policy Engine PE and the Policy Administration PA. The Policy Engine is responsible for finally determining whether to grant a principal's access to resources, while the Policy Administration controls the communication from the principal to the resource.

[0103] There are always security threats and malicious attackers in the system environment. Users, devices, and networks in the environment are regarded as untrusted, regardless of their network locations. Therefore, the authorization factors for trusted principals will include many aspects such as principal credentials, network location, used devices, and behaviors. As Figure 3 shown, in the continuous dynamic access control policy, the access principal needs to be authorized according to its trust status before accessing the trusted area, and continuously monitor its trust dynamics during the access process to dynamically adjust the access permissions to achieve secure access control.

[0104] The main purpose of the zero-trust architecture is to enable trusted users to obtain reliable information. Then, in the context of a network security system, a specific zero-trust model needs to be constructed. Nodes in an intelligent network security system need to continuously sense external environmental information to make appropriate decisions to ensure their own security. Then, node information perception serves as the input module of the network security system. A large amount of noise and untrusted messages are mixed in the perceived external information. To prevent malicious nodes from tampering with the identified trusted messages, information security needs to be achieved through encryption technology. Identify nodes or network information that requires security authentication in the zero-trust information management platform to ensure that only authorized agents can participate in the information interaction of the system. To transition information security to system security, the execution module needs to design a reasonable controller based on the obtained topology information and node trust value information, etc., so as to meet the performance requirements of the intelligent network security system.

[0105] (2) Construction of a real-time dynamic node and directed communication link trust evaluation model Each intelligent network security system corresponds to an underlying network topology structure, and this topology graph can reflect the connection relationship between nodes. With the improvement of interconnectivity, nodes are no longer isolated units but become part of a complex network system. Considering agents, the topological relationship of the agents is shown in the figure denotes denotes a set of node sets denotes the number of nodes denotes a set of edge sets. Edge denotes a node and node There is a connection between them, and information flows from node to node . If the graph is an undirected graph, then , it should be noted that an undirected graph is a special type of directed graph

[0106] Adjacency matrix , where is the weight of the edge , denotes the set of real numbers. If then , otherwise . Usually, the elements in the adjacency matrix are either 1 or 0. Assume that there are no self-loops in the graph, that is, there is no case where two vertices connected by an edge are the same. The neighbor set of node is defined as , denoting the set of all nodes that transmit information to node . Denote the in-degree matrix as , which is a diagonal matrix. Among them, is the sum of the elements in the th row of the matrix , that is . The Laplacian matrix of the graph , if the graph is an undirected graph, then the Laplacian matrix is a symmetric matrix

[0107] In a zero-trust architecture, each node is an independent entity in a zero-trust environment and needs to be authenticated and authorized to access node information in the intelligent network security system. By default, any device or user is untrusted, and all nodes in the intelligent network security system use trust values for confirmation and authorization. The trust level of a node helps determine the level of information that the node can access and the reliability of the transmitted information, etc. In this embodiment, the Laplacian matrix will be parameterized with trust values, then the connection weight of the edge is no longer , but , where denotes the trust value function related to nodes and , and the range of the trust value is , a node with a trust value of 0 indicates that the node is completely untrusted, and a node with a trust value of 1 indicates that the node is completely trusted. Then the adjacency matrix under the zero-trust architecture .

[0108] In this embodiment, a quantitative analysis of the trust value and influencing factors under the zero-trust architecture are given, which are used to calculate the trust value of the intelligent cluster in different environments and modes. On this basis, in the communication topology network, when a node is maliciously attacked and malicious information is transmitted, the degree of impact on the overall network is parameterized for quantitative calculation. This is used to prove the advantages of the zero-trust architecture in ensuring the security of the communication network.

[0109] In the establishment of the trust value comprehensive evaluation model and the research of the zero-trust information management mechanism, it is necessary to first clarify the definitions of trust and trust value. And through the physical meaning of the trust value, extend it to its definition in the zero-trust information management system. Definition 1: The degree of availability of node information. Definition 2: Parameterized trust, which becomes the trust value. According to the size of the trust value, in cluster control or other execution behaviors, the degree of utilization of information transmitted from other users / systems by a certain user / system. It can also be reflected as a quantitative weighted parameter that needs to be included in the model calculation when confirming the control target. The information sources required for trust value evaluation mainly have two: 1) Observation and perception; 2) Inquiry and communication.

[0110] In a more general case, the calculation of the trust value is directly related to the communication topology. One is the objective hardware conditions, such as the link connectivity probability or communication quality. Obviously, the higher the communication quality and the lower the error rate, the higher the trust value. The other is the conditions related to graph topology calculation, mainly considering the following aspects: 1. Node connectivity (obtained from calculations related to graph connectivity); 2. Node stability margin (obtained from the calculation of the network topology stability margin); 3. Degree centrality, closeness centrality, betweenness centrality, etc.; 4. Graph stability margin.

[0111] Subjective information refers to the information that has a direct information connection with the observer, and the information and behavior of the other party have a direct impact on the observer, including the impact on information links and physical dynamics. At this time, the subjective judgment information generated according to the "interaction" with the other party. It mainly includes: 1. The determination of the identity of the other party's node / network and the determination of the importance level; 2. The comprehensive score of the other party after communicating with the other party's node.

[0112] In addition, the comprehensive trust value system selection made for different information security levels and mission objective levels can be called a mode. For different information security levels and mission objective levels, different modes need to be selected, and the information control degree and control objectives among intelligent clusters are further determined through the mode. The "mode zero trust" is also parameterized and put into the trust value dynamic function for comprehensive calculation.

[0113] In the case where the security level mode is the expression of the trust value becomes:

[0114] Among them, represents at time and the trust value between nodes including the importance of the node / network itself and the subjective score after communication; including network connectivity / connectivity probability, network vulnerability; represents the calculation method.

[0115] (3) Zero-trust ad hoc network topology reconstruction update reference information Quantitatively calculate the impact of a node being attacked and the node transmitting harmful information on the entire network in the communication network. Reasonably parameterize this impact, and then calculate the impact degrees of the intelligent cluster under the zero-trust architecture and the intelligent cluster without a security architecture when affected by network attacks and interference respectively. It intuitively proves the significant role of the zero-trust architecture in the communication security of intelligent clusters.

[0116] Suppose that in the communication topology network of an intelligent cluster, the probability that a node becomes a malicious node due to being attacked and information tampering is , and the probability that this malicious node successfully transmits malicious information to the next connected node is . In the intelligent cluster under the zero-trust architecture, nodes need to perform identity verification during communication, and the probability that a node becomes a malicious node through identity verification is ; the probability that this node successfully transmits malicious information to the next connected node becomes . Obviously:

[0117] Therefore, in theory, the zero-trust architecture greatly reduces the success rate of the spread of faults and error information in the communication network through continuous interrogation and identity verification of node communication.

[0118] Next, a specific topological graph is used to quantitatively calculate the impact degree of malicious information on the network. During the calculation, assume the communication topological graph has nodes, , and the number of information channels of each node is . represents a coefficient related to the spread of malicious information related to the trust value, that is is a function of the trust value. Therefore, in a given communication topological graph, let the number of attacked nodes be , and the number of un-attacked nodes be . The maximum values of the two functions are shown in Table 1.

[0119] When the information topological graph is a tree, and take the maximum values; when the graph is not a tree, there will be information transmission duplicates, that is, the same node may have multiple malicious nodes transmitting information to it. Therefore, the actual and will be less than the calculated values in the table. Here, the less than or equal sign is used to indicate this calculation result.

[0120] Table 1 Influence parameter table of the information topological graph under malicious attack

[0121] In summary, there is the following relationship:

[0122] When , the calculation stops.

[0123] It can be seen that when and are larger, is larger, and decreases faster. The more channels there are for the attacked points, that is is larger, is larger. From the results of theoretical calculations, the zero-trust architecture first greatly reduces , making substantially reduced, and then reduces the impact of malicious information on the overall communication network by curbing the spread of malicious information in the channels.

[0124] In the self-organizing network topology update, intelligent calculations need to be performed based on the impact of malicious information on the overall communication network and the self-organizing network dynamic topology stability correlation coefficient, that is, to ensure that the zero-trust self-organizing network system can achieve the most efficient information output on the basis of security at each moment.

[0125] (4)Secure transmission and decryption of internal data in an ad hoc network based on the zero-trust mechanism Regarding the secure transmission and trusted access control of data in a zero-trust security network system, a series of exploratory studies have been carried out, and a number of good research results have been accumulated. To achieve secure transmission and fine-grained access control under non-trusted relay interference, an interference iterative cancellation algorithm has been proposed, which can maximize the received signal quality of trusted nodes. However, in the case where resource access control is the core, due to the random dynamic changes in the distributed structure of the intelligent network system itself and the characteristics of each interaction node evolving from partial trust to complete distrust, it is easy for untrusted nodes to inject false data and perform unauthorized access control, causing great difficulties in formulating security policies for the intelligent network system. Therefore, in the scenario of an intelligent network system, there are still many basic theoretical issues that need to be deeply studied to achieve secure transmission of heterogeneous data among zero-trust parties and reliable access control. These mainly include: 1) Considering the phased migration characteristics of the data center in a zero-trust intelligent network system and facing the actual requirements of confidentiality, authenticity, integrity, etc. in the full information chain transmission, study the data encryption transmission and processing methods of a weakly centralized lightweight network system. Data encryption can be carried out in the ways of link encryption, node encryption, and end-to-end encryption.

[0126] 2) Facing the data retrieval requirements of nodes in a zero-trust intelligent network system, study the oblivious access control method for data in an adaptive intelligent network system with the principle of maximizing data security and access benefits. According to continuous dynamic trust assessment means, through an assessment model and algorithm, achieve identity-based assessment capabilities, while determining the risks of the network security environment, identifying abnormal behaviors in access requests, and adjusting the assessment results. Ensure that the system can timely adjust access permissions in the face of a constantly changing security environment and user behaviors, without being overly affected by historical data, so as to guarantee the real-time nature of identity control, enhance the flexibility and adaptability of the system, and be applicable to a variety of complex network environments and application scenarios.

[0127] It should be noted that the device embodiments described above are only illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative labor.

[0128] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the essence of the above technical solution, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0129] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and are not intended to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A zero-trust communication network system, characterized in that It includes: A control plane, a data plane, a trust evaluation module, and a topology reconstruction module; Among them, the trust evaluation module is used to calculate trust value-related information of a target node, and the trust value-related information of the target node includes the trust values between the target node and each node other than the target node in the communication network system; The control plane is used to receive an access request from a target node and determine the authorization situation of the target node for the data plane based on the trust value-related information of the target node; The topology reconstruction module is used to reconstruct the network structure of the communication network system based on the trust value-related information of each node in the communication network system.

2. The zero-trust communication network system according to claim 1, wherein The trust evaluation module calculates the trust value-related information of the target node according to the following method: Based on the communication topology-related information of the communication network system and the related information of the target node, determine the trust value-related information of the target node; Among them, the communication topology-related information includes the hardware objective conditions and graph topology calculation conditions of the communication network system; the related information of the target node includes the importance score of the target node and the interaction behavior score between the target node and each node other than the target node in the communication network system.

3. The zero-trust communication network system according to claim 2, wherein The trust evaluation module calculates the trust value-related information of the target node according to the following method: Based on the communication topology-related information of the communication network system, the related information of the target node, and the security mode type of the communication network system, determine the trust value-related information of the target node; Among them, the security mode type is determined based on the information security level and task objective level of the communication network system.

4. The zero-trust communication network system according to claim 3, wherein, The trust evaluation module calculates the trust value-related information of the target node according to the following method: Based on the communication topology-related information of the communication network system, the related information of the target node, the security mode type of the communication network system, and time, determine the trust value-related information of the target node.

5. The zero-trust communication network system according to claim 1, characterized in that, The topology reconstruction module reconstructs the network structure of the communication network system according to the following method: Based on the trust value-related information of each node in the communication network system, determine the Laplacian matrix of the communication network system; Based on the Laplacian matrix, with the maximum stability margin as the optimization goal, determine the reconstructed network structure.

6. A data transmission method for a zero-trust communication network, applied to the zero-trust communication network system according to any one of claims 1 to 5, characterized in that, It includes: Based on the trust value-related information of each node in the communication network system, determine the authorization situation of each node for the data plane; Based on the trust value-related information of each node, reconstruct the network structure of the communication network system; Based on the reconstructed network structure and the authorization situation of each node for the data plane, perform data transmission between each node; Among them, the trust value-related information of any node includes the trust values between the any node and each node other than the any node in the communication network system.

7. The data transmission method of the zero-trust communication network according to claim 6, characterized in that, The trust value-related information of each node is calculated according to the following method: Based on the communication topology-related information of the communication network system and the related information of each node, determine the trust value-related information of each node; Among them, the communication topology related information includes the hardware objective conditions of the communication network system and the graph topology calculation conditions; the related information of any node includes the importance score of the any node, and the interaction behavior score between the any node and each node in the communication network system other than the any node.

8. The data transmission method of the zero-trust communication network according to claim 7, characterized in that, The trust value related information of each node is calculated according to the following method: Based on the communication topology related information of the communication network system, the related information of each node, and the security mode type of the communication network system, determine the trust value related information of each node; Among them, the security mode type is determined based on the information security level and the task objective level of the communication network system.

9. The data transmission method of the zero-trust communication network according to claim 8, wherein The trust value related information of each node is calculated according to the following method: Based on the communication topology related information of the communication network system, the related information of each node, the security mode type of the communication network system, and time, determine the trust value related information of each node.

10. The data transmission method of the zero-trust communication network according to claim 6, characterized in that, Based on the trust value related information of each node, reconstruct the network structure of the communication network system, including: Based on the trust value related information of each node, determine the Laplacian matrix of the communication network system; Based on the Laplacian matrix, with the maximum stability margin as the optimization goal, determine the reconstructed network structure.

Citation Information

Patent Citations

  • Method and device for trust management in block chain-based integrated network

    CN115362443A

  • Wireless sensor network anomaly detection method based on trust value evaluation

    CN117041981A

  • Node identity authentication method of grain block chain traceability system fused with zero trust mechanism

    CN118568752A

  • Mobile ad hoc network continuous authentication system and method based on zero-trust architecture

    CN118612731A

  • A system for trust based attacker detection for manet and method thereof

    IN202021052163A

Cited By

  • Distributed agent dynamic collaboration method and device, computer equipment, storage medium and computer program product

    CN121441958A