Zero-trust communication network system and data transmission method
Through trust assessment and topology reconstruction under the zero-trust architecture, the network structure is dynamically adjusted, which solves the security risk problems of traditional network security architecture in dynamic network environments and achieves higher security and protection capabilities.
Patent Information
- Application Number
- CN202510798951.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-16
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2045-06-16
AI Technical Summary
When faced with scenarios such as cloud computing, the Internet of Things, and mobile communications, traditional network security architectures have blurred network boundaries and increased node dynamics, resulting in a significantly increased risk of network systems, users, and data being passively affected and actively attacked by malicious attacks.
A zero-trust communication network system is adopted. The trust value-related information of the node is calculated through the trust evaluation module, and the authorization status is determined by the control plane. The topology reconstruction module dynamically adjusts the network structure and uses the Laplace matrix to optimize the network stability margin.
It improves the security and protection capabilities of the network system, enhances the ability to resist malicious attacks, and ensures the reliability and security of data transmission.
Smart Images

Figure CN120321042B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of network security technology, and in particular to a zero-trust communication network system and a data transmission method. Background Art
[0002] With the rapid development of information technology and network security, the flaws of traditional network security architectures have gradually become apparent. In traditional network security architectures, boundaries are clearly defined, network nodes and communication links are mostly static, and the security architecture protects the entire system through perimeter security measures such as firewalls and intrusion detection systems. However, with the widespread adoption of cloud computing, the Internet of Things, and mobile communications, network boundaries are becoming increasingly blurred, node dynamics are significantly increasing, and the methods of interference and intrusion are increasing. This has significantly increased the risk of both passive impacts and active malicious attacks on network systems, users, and data. To address this situation, it is necessary to research new network security architectures and ad hoc networking technologies for these new scenarios and contexts. Summary of the Invention
[0003] The present invention provides a zero-trust communication network system and data transmission method to address the defects in the prior art that the risk of network systems, users, data, etc. being passively affected and actively attacked is significantly increased, thereby improving the security of the network system and enhancing the protection capability.
[0004] The present invention provides a zero-trust communication network system, comprising:
[0005] Control plane, data plane, trust assessment module and topology reconstruction module;
[0006] The trust evaluation module is used to calculate the trust value related information of the target node, and the trust value related information of the target node includes the trust value between the target node and each node in the communication network system other than the target node;
[0007] The control plane is used to receive an access request from a target node and determine authorization status of the target node for the data plane based on trust value related information of the target node;
[0008] The topology reconstruction module is used to reconstruct the network structure of the communication network system based on the trust value related information of each node in the communication network system.
[0009] According to a zero-trust communication network system provided by the present invention, the trust evaluation module calculates the trust value related information of the target node according to the following method:
[0010] Determining trust value-related information of the target node based on the communication topology-related information of the communication network system and the relevant information of the target node;
[0011] Among them, the communication topology related information includes the hardware objective conditions and graph topology calculation conditions of the communication network system; the relevant information of the target node includes the importance score of the target node, and the interaction behavior score between the target node and each node in the communication network system other than the target node.
[0012] According to a zero-trust communication network system provided by the present invention, the trust evaluation module calculates the trust value related information of the target node according to the following method:
[0013] Determining trust value-related information of the target node based on communication topology-related information of the communication network system, relevant information of the target node, and a security mode type of the communication network system;
[0014] The security mode type is determined based on the information security level and mission target level of the communication network system.
[0015] According to a zero-trust communication network system provided by the present invention, the trust evaluation module calculates the trust value related information of the target node according to the following method:
[0016] Based on the communication topology related information of the communication network system, the related information of the target node, the security mode type of the communication network system, and time, the trust value related information of the target node is determined.
[0017] According to a zero-trust communication network system provided by the present invention, the topology reconstruction module reconstructs the network structure of the communication network system according to the following method:
[0018] Determining a Laplace matrix of the communication network system based on information related to trust values of respective nodes in the communication network system;
[0019] Based on the Laplace matrix, the reconstructed network structure is determined with the maximum stability margin as the optimization goal.
[0020] The present invention also provides a data transmission method for a zero-trust communication network, which is applied to the zero-trust communication network system as described above, comprising:
[0021] Determining authorization status of each node for a data plane based on trust value related information of each node in the communication network system;
[0022] Reconstructing the network structure of the communication network system based on the trust value related information of each node;
[0023] Based on the reconstructed network structure and the authorization status of each node for the data plane, data transmission between each node is performed;
[0024] The trust value related information of any node includes the trust value between the arbitrary node and each node in the communication network system except the arbitrary node.
[0025] According to a data transmission method for a zero-trust communication network provided by the present invention, the trust value-related information of each node is calculated according to the following method:
[0026] Determining trust value information of each node based on the communication topology information of the communication network system and the information of each node;
[0027] Among them, the communication topology related information includes the hardware objective conditions and graph topology calculation conditions of the communication network system; the relevant information of any node includes the importance score of the arbitrary node, and the interaction behavior score between the arbitrary node and each node in the communication network system except the arbitrary node.
[0028] According to a data transmission method for a zero-trust communication network provided by the present invention, the trust value-related information of each node is calculated according to the following method:
[0029] Determining trust value-related information of each node based on the communication topology-related information of the communication network system, the relevant information of each node, and the security mode type of the communication network system;
[0030] The security mode type is determined based on the information security level and mission target level of the communication network system.
[0031] According to a data transmission method for a zero-trust communication network provided by the present invention, the trust value-related information of each node is calculated according to the following method:
[0032] Based on the communication topology related information of the communication network system, the related information of the respective nodes, the security mode type of the communication network system, and time, the trust value related information of the respective nodes is determined.
[0033] According to a data transmission method of a zero-trust communication network provided by the present invention, based on the trust value related information of each node, the network structure of the communication network system is reconstructed, including:
[0034] Determining a Laplace matrix of the communication network system based on the trust value related information of each node;
[0035] Based on the Laplace matrix, the reconstructed network structure is determined with the maximum stability margin as the optimization goal.
[0036] The zero-trust communication network system and data transmission method provided by the present invention adopt a zero-trust network architecture, calculate the trust value-related information of each node, determine the authorization status of the target node for the data plane based on the trust value-related information of the target node, and reconstruct the network structure of the communication network system based on the trust value-related information of each node in the communication network system, thereby improving the security of the network system and enhancing the protection capability of the network system. BRIEF DESCRIPTION OF THE DRAWINGS
[0037] In order to more clearly illustrate the technical solutions in the present invention or the prior art, a brief introduction is given below to the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0038] Figure 1 It is a structural diagram of the zero-trust communication network system provided by the present invention.
[0039] Figure 2 It is a flow chart of the data transmission method of the zero-trust communication network provided by the present invention.
[0040] Figure 3 This is a diagram of the secure network architecture under the zero-trust mechanism provided by the present invention. DETAILED DESCRIPTION
[0041] To make the objectives, technical solutions, and advantages of the present invention more clear, the technical solutions of the present invention will be clearly and completely described below in conjunction with the accompanying drawings. Obviously, the embodiments described are only some of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts shall fall within the scope of protection of the present invention.
[0042] The following is a brief introduction to the related technologies of the present invention.
[0043] Zero Trust is a new network security architecture that emphasizes default distrust of any device or user on the network, adhering to the principle of "never trust, always verify." It employs a multi-layered security control strategy to protect network security. It emphasizes security verification and continuous monitoring, and requires timely response and remediation of any security incidents. The Zero Trust model offers new insights and approaches to network security and is widely researched and applied.
[0044] A network security architecture based on zero-trust mechanisms has the following key features: dynamic trust value assessments for directed communication links; each access and request is based on identity authentication and authorization steps; different data and function request permissions are assigned to different users and nodes; abnormal nodes and abnormal states are detected by monitoring and detecting real-time network link and node characteristics; and data is encrypted and isolated in layers. In summary, a zero-trust network security architecture evaluates communications between different nodes through dynamic trust assessment and identity authentication. Based on the dynamic assessment results, data and function requests are authorized at different levels. This means that different data information is sent to nodes at different trust levels, and different data addition, deletion, modification, and query permissions are granted, protecting data from being stolen or tampered with by unqualified and unauthorized access.
[0045] In a zero-trust architecture, data security transmission and access control are divided into three categories: information sensing and control terminals, communication infrastructure, and cloud platforms. However, due to the strong coupling and overlap of data transmission processes, every node in a zero-trust network system is subject to the risk of identity impersonation and unauthorized services. Therefore, the issue of data security transmission in a zero-trust network system is also a dynamic access control issue based on node authentication. Failure of node authentication excludes the node from the dynamic network. However, among the numerous node joining requests, nodes that pass node authentication are allowed to join the dynamic network system. Therefore, the self-organizing architecture of the network system based on dynamic node authentication becomes the foundation of the zero-trust network security architecture.
[0046] An ad hoc network (AMN) is a temporary, dynamic, and specialized wireless network composed of nodes equipped with wireless communication and computing capabilities. Unlike traditional network architectures, AMNs do not rely on any pre-established fixed communication infrastructure, such as base stations or routers. Every node in the network can send, receive, and forward data. AMNs have flexible nodes and flexible communication links. AMNs are self-organizing and dynamic, meaning that nodes can discover other nodes through queries and requests, negotiate configurations based on intelligent algorithms, and establish and maintain a dynamic network topology. The topology of an AMN changes dynamically in real time. Nodes can apply to join and leave the network at any time, and the relative topological positions of nodes and the communication links between them also change in real time. AMNs based on a zero-trust architecture build on the strengths of traditional AMNs by also having flexible trust evaluation weights for communication links.
[0047] Figure 1 This is a schematic diagram of the structure of the zero-trust communication network system provided by the present invention. Figure 1 As shown, the system includes:
[0048] Control plane 100, data plane 110, trust assessment module 120 and topology reconstruction module 130;
[0049] The trust evaluation module 120 is used to calculate the trust value related information of the target node, and the trust value related information of the target node includes the trust value between the target node and each node other than the target node in the communication network system;
[0050] The control plane 100 is used to receive an access request from a target node and determine the authorization status of the target node for the data plane 110 based on the trust value related information of the target node;
[0051] The topology reconstruction module 130 is used to reconstruct the network structure of the communication network system based on the trust value related information of each node in the communication network system.
[0052] Specifically, the supporting system of a zero-trust architecture is called the control plane, while the remaining components are called the data plane. The data plane is directed and configured by the control plane. Requests to access protected resources are first processed by the control plane, including device and user authentication and authorization.
[0053] Once the control plane completes the inspection and determines that the request is legitimate and authorized, it will dynamically configure the data plane to accept access traffic from the client. Regardless of whether the access subject is on the internal network or the external network, authentication is required before access to resources.
[0054] In a continuous dynamic access control strategy, the access subject needs to be authorized based on its trust status before accessing the trusted area, and its trust dynamics are continuously monitored during the access process so that access rights can be dynamically adjusted to achieve secure access control.
[0055] The control plane is the decision-making core of the communication network system. Adhering to the principle of "never trust, always verify," it is responsible for dynamically authorizing all access requests. It comprises three logical components: the Policy Engine (PE), Policy Administration (PA), and Policy Enforcement (PEP). The PE makes decisions based on trust assessment results and security policies. The PA dynamically configures policies to the data plane. The PEP is responsible for interacting with users and devices and forwarding requests.
[0056] In an embodiment of the present application, all nodes in the communication network system are confirmed and authorized through trust value-related information. The trust value-related information of any node includes the trust value between the node and each node other than the node in the communication network system. The trust value-related information of the node helps determine the level of information that the node can access and the reliability of the transmitted information. The trust evaluation module can dynamically calculate the trust value between nodes through multiple dimensional parameters, providing a quantitative basis for the control plane and topology reconstruction. The trust value can be represented by a parameterized adjacency matrix, and the trust value between nodes ranges from 0 to 1.
[0057] When the target node initiates an access request, the control plane first receives the access request and, based on the trust value information provided by the trust evaluation module, determines whether to authorize it to access the resources of the data plane.
[0058] For example, if the trust value between the target node and other nodes is lower than the threshold set by the security mode, the control plane will deny it access to sensitive data and only open basic function permissions.
[0059] The topology reconstruction module can dynamically adjust the network structure based on trust value-related information and intelligent optimization algorithms to ensure that the system can quickly recover and stabilize when attacked.
[0060] For example, when it is detected that the trust value between a node and other nodes is reduced, the topology reconstruction module can cut off its connection with the core data node and reconstruct the path to bypass the potential risk area.
[0061] It can be understood that in addition to performing trust value detection on each node in the communication network system when the nodes in the communication network system change, the communication network system can also set a detection cycle to perform regular trust value detection on each node in the communication network system to ensure the security of the communication network system.
[0062] The data plane implements encrypted data transmission and access control according to instructions from the control plane. Its encryption strategy can be directly linked to trust values. For example, high-trust nodes use lightweight encryption, while low-trust nodes require stronger encryption. The data plane can dynamically adjust the permissions of each node based on its trust value. For example, if a node's trust value decreases, the data plane can simultaneously revoke its key usage permissions, ensuring that data flows only within trusted paths.
[0063] The zero-trust communication network system provided by the present invention adopts a zero-trust network architecture, calculates the trust value-related information of each node, determines the authorization status of the target node for the data plane based on the trust value-related information of the target node, and reconstructs the network structure of the communication network system based on the trust value-related information of each node in the communication network system, thereby improving the security of the network system and enhancing the protection capability of the network system.
[0064] According to a zero-trust communication network system provided by the present invention, the trust evaluation module calculates the trust value related information of the target node according to the following method:
[0065] Determining trust value information of the target node based on communication topology information of the communication network system and relevant information of the target node;
[0066] Among them, the communication topology related information includes the hardware objective conditions of the communication network system and the graph topology calculation conditions; the target node related information includes the importance score of the target node and the interaction behavior score between the target node and each node in the communication network system except the target node.
[0067] Specifically, in the embodiment of the present application, the trust evaluation module may dynamically calculate and determine the trust value related information of the target node by fusing the communication topology related information and the target node related information.
[0068] Communication topology related information includes the hardware objective conditions of the communication network system and the graph topology calculation conditions.
[0069] The objective hardware conditions of a communication network system can include physical layer indicators such as link connectivity probability and communication quality (such as bandwidth, latency, and bit error rate), reflecting the stability and reliability of the communication link. For example, higher communication quality and lower error rates indicate a higher trust value.
[0070] Graph topology calculation conditions can include network structural properties such as node connectivity (derived from graph connectivity-related calculations), node stability margin (derived from network topology stability margin), centrality metrics (degree centrality, closeness centrality, betweenness centrality), and graph stability margin. These parameters are quantitatively analyzed using the Laplace matrix. For example, nodes with high betweenness centrality are given higher trust weights because they are located on critical communication paths.
[0071] The target node's relevant information includes its importance score and the scores of its interactions with other nodes in the communication network. This information is subjective, representing subjective judgments generated by interactions with other nodes that have a direct information connection with the observer and directly impact them, including both information links and physical dynamics.
[0072] The importance score of a target node is dynamically adjusted based on its role in the communication network system (e.g., key data source, control node). The interaction score represents the overall score each node assigns to its counterpart after communication. For example, if abnormal data is transmitted between nodes, the node's score for the counterpart will be dynamically lowered.
[0073] It should be noted that the embodiment of the present invention does not limit the method for calculating the trust value. For example, the trust value may be calculated using a weighted method.
[0074] By quantifying hardware objective conditions, graph topology calculation conditions, node importance and node behavior history into trust values, the core goals of dynamic evaluation and continuous verification under the zero-trust architecture are achieved, providing a computable quantitative basis for fine-grained access control and topology optimization in self-organizing network environments.
[0075] According to a zero-trust communication network system provided by the present invention, the trust evaluation module calculates the trust value related information of the target node according to the following method:
[0076] Determining trust value information of the target node based on communication topology information of the communication network system, information related to the target node, and a security mode type of the communication network system;
[0077] Among them, the security mode type is determined based on the information security level and mission target level of the communication network system.
[0078] Specifically, in an embodiment of the present application, the trust evaluation module can dynamically calculate and determine the trust value related information of the target node by integrating the communication topology related information, the target node related information, and the security mode type of the communication network system.
[0079] The security mode type can be determined by the information security level of the communication network system (such as public level, confidential level, etc.) and the mission objective level (such as routine mission, important mission, etc.).
[0080] In some implementations, the trust value calculation weight and threshold can be determined based on the security mode type. For example, a high-security mode can increase the weight of information related to the target node and tighten the trust threshold (e.g., authorization requires a trust value ≥ 0.9); a low-security mode can increase the weight of information related to the communication topology and relax the threshold (e.g., authorization requires a trust value ≥ 0.7).
[0081] According to a zero-trust communication network system provided by the present invention, the trust evaluation module calculates the trust value related information of the target node according to the following method:
[0082] Based on the communication topology related information of the communication network system, the related information of the target node, the security mode type of the communication network system and time, the trust value related information of the target node is determined.
[0083] Specifically, in an embodiment of the present application, the trust evaluation module can dynamically calculate and determine the trust value related information of the target node by integrating the communication topology related information, the target node related information, the security mode type of the communication network system and time.
[0084] In some implementations, the time factor Reflect the dynamic nature of trust value.
[0085] The time factor can be configured to adapt to specific scenarios. For example, if there is no abnormal behavior between nodes for a long period of time, the trust value will gradually recover over time (e.g., linear growth). If malicious behavior is detected, the trust value will instantly return to zero and the isolation mechanism will be triggered. Another example is if the trust value between nodes gradually decreases over time (e.g., linearly), it will continue until the next trust value check.
[0086] According to a zero-trust communication network system provided by the present invention, the topology reconstruction module reconstructs the network structure of the communication network system according to the following method:
[0087] Determining a Laplace matrix of the communication network system based on information related to trust values of each node in the communication network system;
[0088] Based on the Laplace matrix, the reconstructed network structure is determined with the maximum stability margin as the optimization goal.
[0089] Specifically, the topology reconstruction module in the embodiment of the present invention dynamically adjusts the network structure to maximize the stability margin by integrating trust value related information with a graph theory optimization algorithm.
[0090] The ad hoc network is abstracted as an undirected graph G=(V,E), where V is the node set, E is the edge set, and the edges represent the communication links between nodes.
[0091] In the case of a node attack, the attacker can disable some nodes, that is, delete these nodes and their associated edges from the graph. Let the set of attacked nodes be A∈V. In the case of a link attack, the attacker can also destroy communication links, that is, delete edges in the graph. Let the set of attacked edges be B∈E.
[0092] The stability margin indicator chosen is betweenness centrality. The betweenness centrality B(v) of a node v refers to the proportion of all shortest paths in the network that pass through node v. If the betweenness centrality of the attacked node is high, it may have a significant impact on the network topology.
[0093] In the calculation process of the stability margin based on betweenness centrality, let the sum of all node betweenness centralities be B total , the sum of the betweenness centrality of the attacked node set A is B A , define the stability margin S total =1-B A / B total , S total ∈[0,1], reflects the impact of the attack on key nodes of the network. The larger the value, the higher the stability margin.
[0094] The topology of multiple ad hoc networks can be transformed, and then the topology with the largest stability margin (calculated by betweenness centrality) can be found and changed to the most stable topology structure, thereby ensuring the connectivity of the overall network and more secure information transmission.
[0095] Figure 2 This is a flow chart of the data transmission method of the zero-trust communication network provided by the present invention, such as Figure 2 As shown, the method is applied to the zero-trust communication network system as described above, and includes the following steps:
[0096] Step 200: Based on the trust value related information of each node in the communication network system, determine the authorization status of each node for the data plane.
[0097] Step 201: Reconstruct the network structure of the communication network system based on the trust value related information of each node.
[0098] Step 202: Based on the reconstructed network structure and the authorization status of each node for the data plane, data transmission is performed between each node.
[0099] The trust value related information of any node includes the trust value between the any node and each node other than the any node in the communication network system.
[0100] Specifically, the zero-trust communication network system first determines the access rights of each node to the data plane based on the trust value generated by the trust assessment module.
[0101] In an embodiment of the present application, all nodes in the communication network system are confirmed and authorized through trust value-related information. The trust value-related information of any node includes the trust value between the node and each node other than the node in the communication network system. The trust value-related information of the node helps determine the level of information that the node can access and the reliability of the transmitted information. The trust evaluation module can dynamically calculate the trust value between nodes through multiple dimensional parameters, providing a quantitative basis for the control plane and topology reconstruction. The trust value can be represented by a parameterized adjacency matrix, and the trust value between nodes ranges from 0 to 1.
[0102] When any node initiates an access request, it is necessary to combine the trust value-related information of the node to determine whether it is authorized to access the data plane resources.
[0103] For example, if the trust value between the target node and other nodes is lower than the threshold set by the security mode, the control plane will deny it access to sensitive data and only open basic function permissions.
[0104] After determining the trust value related information of each node, the network structure can be dynamically adjusted based on the trust value related information and the intelligent optimization algorithm to ensure that the system quickly recovers to stability when under attack.
[0105] For example, when it is detected that the trust value between a certain node and other nodes decreases, the connection between the certain node and the core data node can be cut off, and the path can be reconfigured to bypass the potential risk area.
[0106] It can be understood that, in addition to the case where the nodes of the communication network system change, the communication network system can also perform trust value detection of each node, and set a detection period to periodically perform trust value detection of each node in the communication network system, thereby ensuring the security of the communication network system.
[0107] Then, the encrypted transmission and access control can be performed according to the reconfigured network structure and the authorization of each node to the data plane. The encryption strategy can be directly associated with the trust value, for example, a high-trust node adopts a lightweight encryption method, and a low-trust node needs a higher strength encryption method. The permissions of each node can be dynamically adjusted according to the trust value related information of each node, for example, when the trust value of a certain node decreases, the key usage permission of the certain node can be revoked synchronously to ensure that data only circulates in a trusted path.
[0108] The data transmission method of the zero-trust communication network provided by the application improves the security of the network system and enhances the protection capability of the network system.
[0109] According to the data transmission method of the zero-trust communication network provided by the application, the trust value related information of each node is calculated in the following manner:
[0110] Based on the communication topology related information of the communication network system and the related information of each node, the trust value related information of each node is determined.
[0111] The communication topology related information includes the hardware objective conditions and the graph topology calculation conditions of the communication network system, and the related information of any node includes the importance score of the any node and the interaction behavior score of the any node and each node in the communication network system except the any node.
[0112] Specifically, in the embodiment of the application, the trust evaluation module can dynamically calculate and determine the trust value related information of each node by fusing the communication topology related information and the related information of each node.
[0113] Communication topology related information includes the hardware objective conditions of the communication network system and the graph topology calculation conditions.
[0114] The objective hardware conditions of a communication network system can include physical layer indicators such as link connectivity probability and communication quality (such as bandwidth, latency, and bit error rate), reflecting the stability and reliability of the communication link. For example, higher communication quality and lower error rates indicate a higher trust value.
[0115] Graph topology calculation conditions can include network structural properties such as node connectivity (derived from graph connectivity-related calculations), node stability margin (derived from network topology stability margin), centrality metrics (degree centrality, closeness centrality, betweenness centrality), and graph stability margin. These parameters are quantitatively analyzed using the Laplace matrix. For example, nodes with high betweenness centrality are given higher trust weights because they are located on critical communication paths.
[0116] For any node, the relevant information includes its importance score and the interaction scores between it and every node in the communication network system. The relevant information for any node is subjective information, representing subjective judgments generated based on the interaction with the observer, who has a direct information connection and whose information and behavior have a direct impact on the observer, including both information links and physical dynamics.
[0117] The importance score of any node is dynamically adjusted based on its role in the communication network system (e.g., key data source, control node). The interaction score represents the overall score each node assigns to its counterpart after communication. For example, if abnormal data is transmitted between nodes, the node's score for the other node will be dynamically lowered.
[0118] It should be noted that the embodiment of the present invention does not limit the method for calculating the trust value. For example, the trust value may be calculated using a weighted method.
[0119] By quantifying hardware objective conditions, graph topology calculation conditions, node importance and node behavior history into trust values, the core goals of dynamic evaluation and continuous verification under the zero-trust architecture are achieved, providing a computable quantitative basis for fine-grained access control and topology optimization in self-organizing network environments.
[0120] According to a data transmission method for a zero-trust communication network provided by the present invention, the trust value related information of each node is calculated according to the following method:
[0121] Determining trust value information of each node based on information related to the communication topology of the communication network system, information related to each node, and a security mode type of the communication network system;
[0122] Among them, the security mode type is determined based on the information security level and mission target level of the communication network system.
[0123] Specifically, in an embodiment of the present application, the trust evaluation module can dynamically calculate and determine the trust value related information of each node by integrating the communication topology related information, the related information of each node, and the security mode type of the communication network system.
[0124] The security mode type can be determined by the information security level of the communication network system (such as public level, confidential level, etc.) and the mission objective level (such as routine mission, important mission, etc.).
[0125] In some implementations, the trust value calculation weight and threshold can be determined based on the security mode type. For example, a high-security mode can increase the weight of information related to the target node and tighten the trust threshold (e.g., authorization requires a trust value ≥ 0.9); a low-security mode can increase the weight of information related to the communication topology and relax the threshold (e.g., authorization requires a trust value ≥ 0.7).
[0126] According to a data transmission method for a zero-trust communication network provided by the present invention, the trust value related information of each node is calculated according to the following method:
[0127] Based on the communication topology related information of the communication network system, the related information of each node, the security mode type of the communication network system and time, the trust value related information of each node is determined.
[0128] Specifically, in an embodiment of the present application, the trust evaluation module can dynamically calculate and determine the trust value related information of each node by integrating the communication topology related information, the related information of each node, the security mode type of the communication network system and time.
[0129] In some implementations, the time factor Reflect the dynamic nature of trust value.
[0130] The time factor can be configured to adapt to specific scenarios. For example, if there is no abnormal behavior between nodes for a long period of time, the trust value will gradually recover over time (e.g., linear growth). If malicious behavior is detected, the trust value will instantly return to zero and the isolation mechanism will be triggered. Another example is if the trust value between nodes gradually decreases over time (e.g., linearly), it will continue until the next trust value check.
[0131] According to a data transmission method for a zero-trust communication network provided by the present invention, the network structure of the communication network system is reconstructed based on information related to the trust value of each node, including:
[0132] Determine the Laplace matrix of the communication network system based on the trust value related information of each node;
[0133] Based on the Laplace matrix, the reconstructed network structure is determined with the maximum stability margin as the optimization goal.
[0134] Specifically, the topology reconstruction module in the embodiment of the present invention dynamically adjusts the network structure to maximize the stability margin by integrating trust value related information with a graph theory optimization algorithm.
[0135] The ad hoc network is abstracted as an undirected graph G=(V,E), where V is the node set, E is the edge set, and the edges represent the communication links between nodes.
[0136] In the case of a node attack, the attacker can disable some nodes, that is, delete these nodes and their associated edges from the graph. Let the set of attacked nodes be A∈V. In the case of a link attack, the attacker can also destroy communication links, that is, delete edges in the graph. Let the set of attacked edges be B∈E.
[0137] The stability margin indicator chosen is betweenness centrality. The betweenness centrality B(v) of a node v refers to the proportion of all shortest paths in the network that pass through node v. If the betweenness centrality of the attacked node is high, it may have a significant impact on the network topology.
[0138] In the calculation process of the stability margin based on betweenness centrality, let the sum of all node betweenness centralities be B total , the sum of the betweenness centrality of the attacked node set A is B A , define the stability margin S total =1-B A / B total , S total ∈[0,1], reflects the impact of the attack on key nodes of the network. The larger the value, the higher the stability margin.
[0139] The topology of multiple ad hoc networks can be transformed, and then the topology with the largest stability margin (calculated by betweenness centrality) can be found and changed to the most stable topology structure, thereby ensuring the connectivity of the overall network and more secure information transmission.
[0140] The following further illustrates the zero-trust communication network system and data transmission method provided by the present invention through embodiments in specific application scenarios.
[0141] Figure 3 This is a diagram of the secure network architecture under the zero-trust mechanism provided by the present invention.
[0142] This embodiment is divided into 4 steps:
[0143] (1) Network security architecture based on zero trust mechanism
[0144] Zero trust was introduced as a strategy for building secure systems. Its principle is to distrust any request to access resources, that is, "never trust, always verify." This is an abstract concept, and its implementation requires the guidance of a specific theoretical architecture. The supporting system of the zero trust architecture is called the control plane, and the other parts are called the data plane. The data plane is commanded and configured by the control plane. Requests to access protected resources are first processed by the control plane, including device and user authentication and authorization. Once the control plane completes the check and determines that the request is legally authorized, it dynamically configures the data plane to receive access traffic from the client. Regardless of whether the access subject is on the internal network or the external network, authentication is required to access resources.
[0145] Based on the Zero Trust architecture, six fundamental assumptions are made about network connectivity: untrusted personnel, untrusted devices, untrusted resources, untrusted services, untrusted local connections, and the need to maintain a secure posture during resource transfer. The NIST architecture includes three core logical components: the Policy Engine (PE), Policy Administration (PA), and Policy Enforcement (PEP). Authentication and authorization follow dynamic policies, and access to resources (services, data, etc.) by subjects (users, devices, or applications) is granted only during communication. The Policy Enforcement (PEP) is responsible for interacting with subjects and forwarding their resource access requests to the Policy Decision Plan (PDP). The Policy Decision Plan (PDP) consists of the Policy Engine (PE) and the Policy Administration (PA). The Policy Engine is responsible for the final decision on whether to grant resource access to a given subject, while Policy Administration controls communication from subjects to resources.
[0146] Security threats and malicious attackers are always present in the system environment. Users, devices, and networks in the environment are considered untrusted, regardless of their network location. Therefore, the authorization factors of a trusted subject will include many aspects such as the subject's credentials, network location, the device used, and behavior. Figure 3 As shown in the figure, in the continuous dynamic access control strategy, the access subject needs to be authorized according to its trust status before accessing the trusted area, and its trust dynamics are continuously monitored during the access process so as to dynamically adjust the access rights and achieve secure access control.
[0147] The primary purpose of a zero-trust architecture is to enable trusted users to obtain reliable information. Therefore, within the context of a network security system, a specific zero-trust model needs to be constructed. Nodes in an intelligent network security system must continuously perceive external environmental information in order to make appropriate decisions and ensure their own security. Node information perception serves as the input module for the network security system. This perceived external information is mixed with a significant amount of noise and untrusted messages. To prevent malicious nodes from tampering with identified trusted messages, encryption technology is required to achieve information security. The zero-trust information management platform identifies nodes or network information requiring security authentication to ensure that only authorized agents can participate in system information interactions. To transition from information security to system security, the execution module must design a rational controller based on acquired topological information and node trust value information to achieve the performance requirements of the intelligent network security system.
[0148] (2) Construction of real-time dynamic node and directed communication link trust evaluation model
[0149] Each intelligent network security system corresponds to an underlying network topology, which reflects the connection relationship between nodes. With the improvement of connectivity, nodes are no longer isolated units, but become part of a complex network system. agents, and the topological relationship of the agents is represented by the graph express, Represents a set of nodes, Indicates the number of nodes, Represents a set of edges. Representation node and nodes There is a connection between nodes, and information is transmitted from the nodes Flow Node If the figure is an undirected graph, then ,It is worth noting that an undirected graph is a special type of directed graph.
[0150] Adjacency Matrix ,in It's the edge The weight of represents the set of real numbers. If but ,otherwise . Usually the adjacency matrix The elements in are either 1 or 0. Assume that there are no self-loops in the graph, that is, no two vertices connected by an edge are the same. The neighbor set of , indicating all nodes The set of nodes that transmit information. The in-degree matrix is represented as , which is a diagonal matrix. Among them, is a matrix Middle The sum of the row elements, that is The Laplacian matrix of the graph , if the picture is an undirected graph, then the Laplace matrix It is a symmetrical array.
[0151] In a zero-trust architecture, each node is an independent entity in a zero-trust environment and needs to be authenticated and authorized before it can access node information in the intelligent network security system. By default, no device or user is trustworthy. All nodes in the intelligent network security system use trust values for confirmation and authorization. The trust level of a node helps determine the level of information the node can access and the reliability of the transmitted information. In this embodiment, the trust value is used to parameterize the Laplace matrix, so the edge connection weight is no longer , but ,in Representation and Node and The trust value function is related to the trust value range. , a node with a trust value of 0 indicates that the node is completely untrusted, and a node with a trust value of 1 indicates that the node is completely trustworthy. Then the adjacency matrix under the zero trust architecture is .
[0152] This example provides a quantitative analysis of trust values and influencing factors within a zero-trust architecture, used to calculate trust values for intelligent clusters in different environments and modes. Furthermore, within a communication topology network, the impact of a malicious attack on a node and the transmission of malicious information is parameterized and quantitatively calculated. This demonstrates the advantages of a zero-trust architecture in ensuring communication network security.
[0153] In establishing a comprehensive trust value assessment model and researching zero-trust information management mechanisms, we must first clarify the definitions of trust and trust value. Furthermore, by leveraging the physical meaning of trust value, we can extend its definition within a zero-trust information management system. Definition 1: The degree to which node information can be utilized. Definition 2: Parameterized trust, known as trust value. The trust value determines the degree to which a user / system utilizes information transmitted from other users / systems during cluster control or other execution activities. This can also be reflected in the quantitative weighted parameters that need to be incorporated into model calculations when confirming control objectives. Trust value assessment primarily comes from two sources: 1) observation and perception; 2) inquiry and communication.
[0154] In more general cases, the calculation of trust values is directly related to the communication topology. One factor is objective hardware conditions, such as link connectivity probability or communication quality. Obviously, the higher the communication quality and the lower the error rate, the higher the trust value. The other factor is conditions related to graph topology calculation, mainly considering the following aspects:
[0155] 1. Node connectivity (calculated from graph connectivity);
[0156] 2. Node stability margin (calculated from the network topology stability margin);
[0157] 3. Degree centrality, closeness centrality, betweenness centrality, etc.;
[0158] 4.Graph stability margin.
[0159] Subjective information refers to the information that has a direct connection with the observer, and the other party's information and behavior have a direct impact on the observer, including information links and physical dynamics. At this time, based on the "interaction" with the other party, subjective judgment information is generated. It mainly includes:
[0160] 1. Determine the identity and importance of the other party's node / network;
[0161] 2. Comprehensive score of the other party after communicating with the other node.
[0162] Furthermore, the comprehensive trust value system chosen for different information security levels and mission objectives can be called a model. Different models are selected for different information security levels and mission objectives. The degree of information control and control objectives between intelligent clusters are further determined by the model. "Model Zero Trust" is also parameterized and integrated into the trust value dynamic function for comprehensive calculation.
[0163] In security level mode In the case of , the expression of the trust value becomes:
[0164]
[0165] in, express Node at the moment and The trust value between Including the importance of the node / network itself and the subjective score after communication; Including network connectivity / connectivity probability, network vulnerability; Indicates the calculation method.
[0166] (3) Zero Trust Ad Hoc Network Topology Reconstruction Update Reference Information
[0167] The team quantitatively calculated the impact of a node attack and the transmission of harmful information on the entire communication network. This impact was parameterized appropriately, and the impact of network attacks and interference on smart clusters operating under a zero-trust architecture was calculated, compared to smart clusters without a security architecture. This intuitively demonstrated the significant role of zero-trust architecture in ensuring secure communication in smart clusters.
[0168] Assume that in the communication topology network of the intelligent cluster, the probability that a node becomes a malicious node due to attack or information tampering is , the probability that the malicious node successfully transmits the malicious information to the next node connected to it is In a smart cluster under a zero-trust architecture, nodes need to be authenticated when communicating. The probability of a node becoming a malicious node through authentication is ; The probability that the node successfully transmits the malicious information to the next node connected to it becomes . Obviously:
[0169]
[0170] Therefore, in theory, the zero-trust architecture greatly reduces the success rate of faults and erroneous information propagating in the communication network by continuously querying and authenticating node communications.
[0171] Next, we will use a specific topology diagram to quantitatively calculate the impact of malicious information on the network. In the calculation, it is assumed that the communication topology diagram There are nodes, , the number of information paths per node is . represents a coefficient related to the trust value and the spread of malicious information, that is, is a function of the trust value. Therefore, in a given communication topology, let the number of nodes attacked be , the number of nodes that have not been attacked is , the maximum values of the two functions are shown in Table 1.
[0172] When the information topology is a tree, and Take the maximum value; when the graph is not a tree, information transmission will be repeated, that is, the same node may have multiple malicious nodes transmitting information to it, so the actual and The less than or equal to sign is used here to indicate the result of the calculation.
[0173] Table 1 Parameters of information topology affected by malicious attacks
[0174]
[0175] In summary, there is the following relationship:
[0176]
[0177] When , the calculation stops.
[0178] Therefore, when and are larger, is larger, decreases faster. The more paths the attacked point has, i.e. is larger, is larger. According to the results of theoretical calculation, the zero-trust architecture first greatly reduces , so that is greatly reduced, and then reduces the impact of malicious information on the overall communication network through the suppression effect of the path propagation of malicious information.
[0179] In the self-organizing network topology update, intelligent calculation needs to be carried out according to the impact of malicious information on the overall communication network and the self-organizing network dynamic topology stability correlation coefficient, i.e. to ensure that the zero-trust self-organizing network system at each moment can realize the most efficient information output on the basis of security.
[0180] (4) Zero-trust mechanism-based internal data encryption and decryption transmission of self-organizing network
[0181] A series of exploratory researches have been carried out on the security transmission and trusted access control of zero-trust security network system data, and a batch of good research results have been accumulated. In order to realize secure transmission and fine-grained access control under the interference of non-trust relay, an interference iterative elimination algorithm is proposed, which can maximize the reception signal quality of trust nodes. However, in the case of resource access control as the core, due to the characteristics of the intelligent network system itself distributed structure random dynamic change, each interactive node from partial trust to complete distrust, it is easy to lead to the injection of false data by untrusted nodes and unauthorized access control, which causes great difficulty in formulating the security policy of intelligent network system. Therefore, in the intelligent network system scene, to realize the secure transmission and access reliable control of zero-trust heterogeneous data of all parties, there are still many basic theoretical problems to be further studied. Mainly including:
[0182] 1) In light of the phased migration characteristics of zero-trust intelligent network system data centers and the practical requirements for confidentiality, authenticity, and integrity of full information chain transmission, research is conducted on data encryption transmission and processing methods for weakly centralized lightweight network systems. Data encryption can be achieved through link encryption, node encryption, and end-to-end encryption.
[0183] 2) To address the data retrieval needs of zero-trust intelligent network system nodes, we research a forgetful access control method for adaptive intelligent network system data, based on the principles of data security and maximizing access efficiency. Based on continuous dynamic trust assessment, we implement identity-based assessment capabilities through evaluation models and algorithms. This approach simultaneously assesses network security risks, identifies abnormal access requests, and adjusts the assessment results. This ensures that the system can adjust access permissions in a timely manner in response to evolving security environments and user behaviors, without being overly influenced by historical data. This ensures real-time identity control, enhances system flexibility and adaptability, and is applicable to a variety of complex network environments and application scenarios.
[0184] It should be noted that the device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of the modules may be selected based on actual needs to achieve the objectives of the present embodiment. Persons of ordinary skill in the art can understand and implement the present embodiment without inventive effort.
[0185] Through the above description of the embodiments, those skilled in the art will clearly understand that each embodiment can be implemented using software plus a necessary general-purpose hardware platform, or of course, hardware. Based on this understanding, the essence of the above technical solution, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, a magnetic disk, or an optical disk, and includes a number of instructions for causing a computer device (such as a personal computer, server, or network device) to execute the methods described in each embodiment or certain portions of the embodiments.
[0186] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the various embodiments of the present invention.
Claims
1. A zero-trust communication network system, characterized in that: include: Control plane, data plane, trust assessment module and topology reconstruction module; The trust evaluation module is used to calculate the trust value related information of the target node, and the trust value related information of the target node includes the trust value between the target node and each node in the communication network system other than the target node; The control plane is used to receive an access request from a target node and determine authorization status of the target node for the data plane based on trust value related information of the target node; The topology reconstruction module is used to reconstruct the network structure of the communication network system based on the trust value related information of each node in the communication network system; The trust evaluation module calculates the trust value related information of the target node according to one of the following methods: Method 1: Determine the trust value related information of the target node based on the communication topology related information of the communication network system and the related information of the target node; The communication topology related information includes the hardware objective conditions and graph topology calculation conditions of the communication network system; the target node related information includes the importance score of the target node and the interaction behavior score between the target node and each node in the communication network system other than the target node; Method 2: Determine the trust value related information of the target node based on the communication topology related information of the communication network system, the related information of the target node, and the security mode type of the communication network system; Wherein, the security mode type is determined based on the information security level and the mission target level of the communication network system; Method three: Determine the trust value related information of the target node based on the communication topology related information of the communication network system, the related information of the target node, the security mode type of the communication network system, and time.
2. The zero-trust communication network system according to claim 1, characterized in that The topology reconstruction module reconstructs the network structure of the communication network system according to the following method: Determining a Laplace matrix of the communication network system based on information related to trust values of respective nodes in the communication network system; Based on the Laplace matrix, the reconstructed network structure is determined with the maximum stability margin as the optimization goal.
3. A data transmission method for a zero-trust communication network, applied to the zero-trust communication network system according to any one of claims 1 or 2, characterized in that: include: Determining authorization status of each node for a data plane based on trust value related information of each node in the communication network system; Reconstructing the network structure of the communication network system based on the trust value related information of each node; Based on the reconstructed network structure and the authorization status of each node for the data plane, data transmission between each node is performed; The trust value related information of any node includes the trust value between the arbitrary node and each node in the communication network system except the arbitrary node.
4. The data transmission method of the zero-trust communication network according to claim 3, characterized in that The trust value related information of each node is calculated according to the following method: Determining trust value information of each node based on the communication topology information of the communication network system and the information of each node; Among them, the communication topology related information includes the hardware objective conditions and graph topology calculation conditions of the communication network system; the relevant information of any node includes the importance score of the arbitrary node, and the interaction behavior score between the arbitrary node and each node in the communication network system except the arbitrary node.
5. The data transmission method of the zero-trust communication network according to claim 4, characterized in that: The trust value related information of each node is calculated according to the following method: Determining trust value-related information of each node based on the communication topology-related information of the communication network system, the relevant information of each node, and the security mode type of the communication network system; The security mode type is determined based on the information security level and mission target level of the communication network system.
6. The data transmission method of the zero-trust communication network according to claim 5, characterized in that: The trust value related information of each node is calculated according to the following method: Based on the communication topology related information of the communication network system, the related information of the respective nodes, the security mode type of the communication network system, and time, the trust value related information of the respective nodes is determined.
7. The data transmission method of a zero-trust communication network according to claim 3, characterized in that: Reconstructing the network structure of the communication network system based on the trust value related information of each node includes: Determining a Laplace matrix of the communication network system based on the trust value related information of each node; Based on the Laplace matrix, the reconstructed network structure is determined with the maximum stability margin as the optimization goal.
Citation Information
Patent Citations
Method and device for trust management in block chain-based integrated network
CN115362443A
Mobile ad hoc network continuous authentication system and method based on zero-trust architecture
CN118612731A