Trusted cloud security confidential privacy level product service system and method
By building a product matching library and a three-dimensional security matrix, screening safety preference products, conducting synergistic effect analysis, and dynamically updating the security matrix, the problem of inadaptability of security level assessment in the existing technology is solved, and dynamic adjustment of security policies and accurate matching of user needs is achieved.
Patent Information
- Application Number
- CN202510586223.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-08
- Publication Date
- 2025-07-18
- Estimated Expiration
- 2045-05-08
AI Technical Summary
The existing technology lacks a dynamic adaptability security level assessment system, has not built a dynamic collaborative analysis mechanism covering the three-dimensional security, confidentiality and privacy, and has not established a technical feature correlation analysis of security, confidentiality and privacy dimensions, so it is difficult for users to understand the correlation between security level and their own needs.
Build a product matching library, extract the three-dimensional security matrix, obtain user privacy hierarchical service needs, filter security preference products, conduct synergistic effect analysis, judge the frequency of technical level improvement, formulate product optimization strategies through dynamic correlation coefficients, and dynamically update the three-dimensional security matrix.
Quantitative evaluation of security capabilities has been achieved, the compatibility between product and user needs has been improved, security strategies have been dynamically adjusted to adapt to real-time threats and user upgrade behaviors, and system security and adaptability have been improved.
Smart Images

Figure CN120342734A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of cloud computing security, and particularly to a trusted cloud security confidential privacy level product service system and method. Background Art
[0002] With the rapid development of cloud computing technology, the demand for trusted cloud security services is increasing day by day. Although the prior art has proposed hierarchical security level evaluation and dynamic calculation methods, there are still many deficiencies.
[0003] A Chinese patent application with the publication number CN118862092A discloses a trusted cloud security level calculation system, including: hierarchically evaluating a cloud computing system, determining the trusted security level of the cloud computing system, dynamically calculating and adjusting the dynamic security level of the cloud computing system, and displaying and proving the trusted security level and dynamic security level of the cloud computing system; this application provides a trusted cloud security mechanism unit level calculation system, making the security level of the cloud computing system visible, credible, and traceable.
[0004] The prior art lacks a dynamically adaptable security level evaluation system and does not construct a dynamic collaborative analysis mechanism covering the three dimensions of security, confidentiality, and privacy; if the dynamic update of the three-dimensional security matrix is achieved through the analysis of the synergistic effect analysis and dynamic correlation coefficient model of the three dimensions of security, confidentiality, and privacy.
[0005] The prior art only focuses on the improvement of the security level in a single dimension and does not establish an association analysis of technical features in the dimensions of security, confidentiality, and privacy. By constructing a requirement matching model, classifying the core features and flexible features, automatically screening the optimal level products, and guiding the collaborative upgrade strategy through dynamic correlation coefficient analysis.
[0006] The security level display of the prior art does not combine the actual application scenario of users and the technical feature reuse rule, making it difficult for users to understand the association between the security level and their own needs; by establishing a three-dimensional security matrix quantization score and dynamic update, clarifying the technical levels of each dimension, and recommending optimal security level products through a requirement matching model. Summary of the Invention
[0007] The purpose of the present invention is to provide a trusted cloud security confidential privacy level product service system and method to solve at least one of the above prior art problems.
[0008] In the first aspect, the present invention provides a trusted cloud security confidential privacy level product service method, including the following steps:
[0009] Step 1: Based on the trusted cloud security confidential privacy level product, construct a product matching library, extract the three-dimensional features of the product matching library, and construct a three-dimensional security matrix;
[0010] Step 2: Obtain the user's current privacy classification service requirements, establish a requirement matching model, and screen for products with a safe and preferred level from the product matching library;
[0011] Step 3: Obtain the number of times of improvement in the technical level of different dimensions in the user's safe and preferred level products, and conduct a synergy effect analysis to determine whether there is a synergistic upgrade effect in the improvement frequency of the technical level of different dimensions. If so, determine whether the synergy effect is significant;
[0012] Step 4: If there is a significant positive correlation, conduct a correlation analysis on the number of times of improvement in the technical level of different dimensions in the safe and preferred level products to obtain a dynamic correlation coefficient. Based on the dynamic correlation coefficient, classify the synergy analysis effect, formulate different product optimization strategies, and dynamically update the three-dimensional security matrix.
[0013] In a second aspect, the present invention provides a trusted cloud security confidential privacy level product service system, including the following modules:
[0014] Feature classification module: Based on the trusted cloud security confidential privacy level products, used to construct a product matching library, extract the three-dimensional features of the product matching library, and construct a three-dimensional security matrix;
[0015] Product optimization module: Used to obtain the user's current privacy classification service requirements, establish a requirement matching model, and screen for products with a safe and preferred level from the product matching library;
[0016] Synergy analysis module: Obtain the number of times of improvement in the technical level of different dimensions in the user's safe and preferred level products, and conduct a synergy effect analysis to determine whether there is a synergistic upgrade effect in the improvement frequency of the technical level of different dimensions. If so, determine whether the synergy effect is significant;
[0017] Optimization and update module: If there is a significant positive correlation, conduct a correlation analysis on the number of times of improvement in the technical level of different dimensions in the safe and preferred level products to obtain a dynamic correlation coefficient. Based on the dynamic correlation coefficient, classify the synergy analysis effect, formulate different product optimization strategies, and dynamically update the three-dimensional security matrix.
[0018] Advantages of the present invention:
[0019] 1. By constructing a product matching library, extract the technical features of the trusted cloud privacy and security levels and the hierarchical core security mechanisms, and build a three-dimensional security matrix according to the quantitative scoring of security protection capabilities, covering the dimensions of security, confidentiality, and privacy. This enables the quantification of security capabilities and the evaluation of product security. Establish a demand matching model based on user requirements, and screen for products with preferred security levels from the product matching library to meet the security requirements of different users in different scenarios. For example, provide suitable TCDPCU-E terminal devices for the mobile office scenario and TCDPCU-S cloud server devices for small and medium-sized cloud platforms to improve the fit between the product and user requirements.
[0020] 2. Obtain the number of times of improvement in the technical levels of different dimensions in the user's preferred security level products for synergy analysis. By comparing the security improvement frequency, confidentiality improvement frequency, privacy dimension improvement frequency, and joint upgrade probability, determine whether there is a synergistic upgrade effect, and use the chi-square statistical test to judge the significance level of the correlation. Understand the user's upgrade behavior pattern to provide data support for product R & D and promotion.
[0021] 3. If there is a significant positive correlation, conduct a correlation analysis to obtain the dynamic correlation coefficient, divide the levels according to the coefficient, and formulate different product optimization strategies. Based on the upgrade probabilities of each dimension under real-time threats, use the entropy weight method to calculate the real-time updated entropy, and combine the quantitative scoring of the three-dimensional security matrix to update the weights to achieve the dynamic update of the three-dimensional security matrix. This enables the product strategy and security matrix to be dynamically adjusted according to real-time threat changes and user upgrade behaviors, improving the system's security and adaptability. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.
[0023] Figure 1 It is a flowchart of a method for providing products and services with trusted cloud security, confidentiality, and privacy levels of the present invention;
[0024] Figure 2 It is a block diagram of a system for providing products and services with trusted cloud security, confidentiality, and privacy levels of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0025] To enable those skilled in the art to better understand the solution of the present invention, the following will clearly and completely describe the technical solution in the embodiments of the present invention in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.
[0026] Embodiment 1
[0027] As Figure 1 shown, a method for providing a trusted cloud security confidential privacy level product service according to an embodiment of the present invention includes the following steps:
[0028] Step 1: Based on the trusted cloud security confidential privacy level product, construct a product matching library, extract the three-dimensional features of the product matching library, and construct a three-dimensional security matrix;
[0029] The construction method of the product matching library is as follows:
[0030] Obtain the trusted cloud privacy security level and the hierarchical core security mechanism, and establish a binding relationship with the trusted cloud product and the product type;
[0031] Based on the binding relationship between the trusted cloud privacy security level and the hierarchical core security mechanism, establish a product matching library;
[0032] Extract technical features based on the trusted cloud privacy security level and the hierarchical core security mechanism of the product matching library, and perform quantitative scoring according to the security protection ability to construct a three-dimensional security matrix;
[0033] It should be noted that the quantitative scoring is set by those skilled in the art based on experience;
[0034] Among them, the three-dimensional security matrix includes the security protection ability score in the security dimension, the confidentiality dimension ability score, and the privacy dimension maintenance ability score;
[0035] It should be noted that the trusted cloud privacy security levels are: DSL3 (Confidentiality Enhanced Privacy Level), DSL4 (Advanced Privacy Confidentiality Level), and DSL5 (Extreme Privacy Confidentiality Level); based on different trusted cloud privacy security levels, there are three products with different security levels: TCDPCU3, TCDPCU4, and TCDPCU5;
[0036] Among them, each security level product also includes different product types to support different application scenarios and user requirements, including: terminal devices (TCDPCU-E), cloud server devices (TCDPCU-S), and cloud service facilities (TCDPCU-I);
[0037] TCDPCU-E emphasizes security and ease of use in the mobile office scenario. For example, economy security terminals, high-performance security terminals, quantum security terminals, etc., are used to build secure terminal access to cloud services;
[0038] TCDPCU-S (cloud server device) is suitable for building small and medium-sized cloud platforms or private cloud environments. For example, economy cloud servers, high-performance security cloud servers, quantum security cloud servers, etc., are used to provide computing and storage resources for cloud services;
[0039] TCDPCU-I (cloud service facility) is suitable for building large-scale cloud service infrastructures. For example, economy cloud infrastructures, high-performance security cloud infrastructures, quantum security cloud infrastructures, etc., are used to build and deliver enterprise-level IaaS, PaaS, and SaaS cloud services of different levels.
[0040] Among them, the hierarchical core security mechanism consists of five key security modules: the trusted root (TCDR) module, the trusted kernel (TCDKN) module, the trusted isolation (TCD IS) module, the trusted access control (TCDAC) module, and the trusted authentication (TCDCA) module;
[0041] Trusted cloud root module: Used to establish a hardware trust root, which is the cornerstone of the entire trusted cloud security system; Trusted cloud root modules of different levels use hardware trust roots with different security levels. For example, TCDPCU3 uses an economy TPM2.0 chip, TCDPCU4 uses a dedicated TCDM security chip or an economy HSM, and TCDPCU5 uses a customized quantum security chip and a redundant HSM hardware cluster to provide hierarchical hardware trust protection;
[0042] Trusted cloud kernel module: Used to enhance the security of the operating system kernel and provide kernel-level security protection; Trusted cloud kernel modules of different levels use different kernel hardening and security extension technologies. For example, TCDPCU3 performs kernel security extension based on TPM2.0, TCDPCU4 is based on TCDM hardware acceleration and TEE technology, and TCDPCU5 is based on dedicated security hardware and an optional formally verified microkernel operating system to provide hierarchical kernel security protection capabilities;
[0043] Trusted Cloud Isolation Module: It includes an internal network isolation sub-module and a boundary isolation sub-module for trusted clouds, which are used to achieve internal network isolation and boundary isolation of cloud services and ensure network security. Different levels of trusted cloud isolation modules adopt different network isolation technologies. For example, TCDPCU3 provides basic VLAN / ACL and virtual firewall / IDS isolation, TCDPCU4 provides trusted computing / ZTNA / micro-isolation and virtual WAF / IPS / enhanced security situation awareness isolation, and TCDPCU5 provides an ultimate isolation solution of quantum security encryption / TEE / physical isolation gateway to build a hierarchical network security isolation system.
[0044] Trusted Cloud Access Control Module: It is used to implement user identity authentication, authorization management, and access control to ensure secure access to cloud service resources. Different levels of trusted cloud access control modules adopt different access control technologies. For example, TCDPCU3 provides preliminary access control of MFA / RBAC / MAC, TCDPCU4 provides advanced access control of biometric MFA / multi-domain access control / UBA / ATI, and TCDPCU5 provides an ultimate access control solution of zero-trust authentication / dynamic authorization / AI threat detection to achieve hierarchical access control intensity.
[0045] Trusted Cloud Verification Module: It is used to provide certificate management, support for encryption algorithms, and security auditing to ensure the trusted authentication of cloud services. Different levels of TCDCA modules adopt different authentication technologies. For example, TCDPCU3 provides basic authentication services of internal CA / managed CA, TCDPCU4 provides enhanced authentication services of third-party CA and high-strength encryption algorithms, and TCDPCU5 provides a customized quantum security authentication solution and redundant HSM hardware security modules to build a hierarchical trusted authentication system.
[0046] Step 2: Obtain the user's current privacy classification service requirements, establish a requirement matching model, and screen for security-optimized level products from the product matching library.
[0047] Based on the security protection ability score, confidentiality dimension ability score, and privacy dimension maintenance ability score of the security dimension in the three-dimensional security matrix, different technical levels are set for the corresponding technical features in the security dimension, confidentiality dimension, and privacy dimension.
[0048] Exemplarily, the technical feature levels are divided into TCD3, TCD4, and TCD5.
[0049] Based on the product matching library, extract the hardware and technical features of the product matching library, and classify the hardware and technical features into core features and flexible features.
[0050] Obtain all the core features of the product matching library and construct a core feature group.
[0051] Obtain all the flexible features of the product matching library and construct a flexible feature group;
[0052] It should be noted that among the hardware and technical features, the hardware includes but is not limited to security products such as TCDPCU3, TCDPCU4, and TCDPCU5, as well as the technical names in the corresponding security modules, such as TPM2.0 and quantum security chips; the technical features include but are not limited to software algorithms in the security modules, such as third-party CAs and high-strength encryption algorithms;
[0053] The core features are the key technologies that directly determine the security level, are deeply bound to the trusted cloud security module, and need to meet the level requirements of DSL3 / 4 / 5. The hardware and technical features in the core features cannot be replaced or upgraded casually;
[0054] The flexible features are the technologies that support the security level but allow optimization within the same level or cross-level compatibility, and can improve the technical level of the core features through software algorithms;
[0055] In some embodiments, by collecting the hardware and technical feature requirements of users, a user requirement group is established;
[0056] Among them, users include application development service providers and end users; the main requirements of application development service providers come from the hardware and technical features in the confidentiality dimension and security dimension; the main requirements of end users come from the hardware and technical features in the privacy dimension and confidentiality dimension;
[0057] Based on the user requirement group, the core feature group, and the flexible feature group, a requirement matching model is established through a clustering algorithm;
[0058] Through the requirement matching model, the hardware and technical features in the user requirement group are matched and analyzed with the core feature group and the flexible feature group to obtain the core features and flexible features of the user requirement group;
[0059] Judge whether all the core features of the user requirement group are in products of the same security level. If so, obtain the security level product corresponding to the user requirement group as the security preferred level product;
[0060] If not all the core features of the user requirement group are in products of the same security level, classify the technical features in the core feature group and the flexible feature group, and filter out the technical features of the user's security dimension, confidentiality dimension, and privacy dimension;
[0061] Filter the technical features of the user's security dimension, confidentiality dimension, and privacy dimension, and eliminate the reused technical features to obtain the technical features of the highest technical level;
[0062] It should be noted that the reused technical features refer to the technical features in the user's security dimension, confidentiality dimension, and privacy dimension that are used to enhance the capabilities of the same dimension and have multiple technical levels;
[0063] Obtain the highest technical levels in different security dimensions, confidentiality dimensions, and privacy dimensions, and compare them with the preset technical levels of the user's requirements respectively;
[0064] If the highest technical levels in different security dimensions, confidentiality dimensions, and privacy dimensions all meet the preset technical levels of the user's requirements, obtain the security level products corresponding to the technical levels as the security preferred level products;
[0065] It should be noted that the cloud service provider provides more precise and transparent level services for users based on the security preferred level products, remotely verifies the security level for users, and provides a trusted security report;
[0066] If not, extract the technical features that do not match the preset technical levels of the user's requirements, remotely verify the security level for users, and send a trusted security report;
[0067] Among them, the trusted security report includes the following parts:
[0068] S1. Clearly mark the TCDPCU series and DSL security levels on the security level products and services;
[0069] S2. Provide a verifiable security configuration list, including specific hardware and technical features;
[0070] S3. Provide a third-party security audit report;
[0071] S4. Support remote trusted verification;
[0072] S5. Provide a real-time security monitoring dashboard;
[0073] It should be noted that through remote communication methods such as the Internet, a security configuration list, an audit report, a remote verification interface, and a monitoring dashboard are provided to remotely verify the security level for users.
[0074] The technical solution of this embodiment is as follows: Based on the trusted cloud security confidentiality and privacy level products, a product matching library is constructed, the three-dimensional features of the product matching library are extracted, and a three-dimensional security matrix is constructed; the current privacy classification service requirements of users are obtained, a requirement matching model is established, and security preferred level products are screened from the product matching library; it is beneficial to improve the matching degree between the product and the user's requirements.
[0075] Embodiment 2
[0076] As Figure 1 shown, a method for trusted cloud security confidentiality and privacy level product services further includes the following steps:
[0077] Step 3: Obtain the number of times of technical level improvement in different dimensions of the user's security preferred level products, and conduct a synergy analysis to determine whether there is a synergistic upgrade effect in the technical level improvement frequencies of different dimensions. If so, determine whether the synergy effect is significant;
[0078] From the historical user data, obtain the number of times of technical level improvement in the security dimension, confidentiality dimension, and privacy dimension of the security preferred level products for all users;
[0079] Based on the number of times of technical level improvement in the security dimension, confidentiality dimension, and privacy dimension of the security preferred level products by users, determine the security improvement frequency, confidentiality improvement frequency, and privacy dimension improvement frequency;
[0080] Mark the security improvement frequency, confidentiality improvement frequency, and privacy dimension improvement frequency as P(S), P(C), and P(A) respectively;
[0081] From the historical user data, obtain the number of times of joint improvement of the technical levels in the security dimension, confidentiality dimension, and privacy dimension, and obtain the joint upgrade probability, marked as P(S∩C∩A);
[0082] Based on the security improvement frequency, confidentiality improvement frequency, privacy dimension improvement frequency, and joint upgrade probability, through comparison and analysis, determine whether there is a synergistic upgrade effect in the technical level improvement frequencies of different dimensions;
[0083] If P(S∩C∩A) > P(S) * P(C) * P(A), it is considered that there is a positive correlation in the technical level improvement frequencies of different dimensions, that is, there is a synergistic upgrade effect in the technical level improvement frequencies of different dimensions;
[0084] If P(S∩C∩A) < P(S) * P(C) * P(A), it is considered that there is a negative correlation in the technical level improvement frequencies of different dimensions, that is, there is no synergistic upgrade effect in the technical level improvement frequencies of different dimensions, and users tend to upgrade in a single dimension;
[0085] If P(S∩C∩A) = P(S) * P(C) * P(A), it is considered that the technical level improvement frequencies of different dimensions are independent and there is no synergy effect;
[0086] If there is a synergy effect, judge the significance level of the correlation through the chi-square statistical test;
[0087] Through the formula: Obtain the chi-square statistic χ 2 , where i, j, and k respectively represent different upgrade states of the security, confidentiality, and privacy dimensions, that is, upgrade or not upgrade, and r, c, and l are the numbers of different states of the security, confidentiality, and privacy dimensions;
[0088] Among them, O ijk represents the observed number of upgrade combinations, that is, the number of times the technical levels in the security dimension, confidentiality dimension, and privacy dimension are improved together. E ijk represents the expected number under the independent hypothesis, that is, the product of the total number of users and P(S)*P(C)*P(A);
[0089] Obtain the chi-square statistic at the significance level value α. If the chi-square statistic of the correlation is higher than the chi-square statistic at the significance level value α, it is considered that there is a significant positive correlation, otherwise it is not considered;
[0090] Step 4: If there is a significant positive correlation, perform a correlation analysis on the number of times the technical levels in different dimensions of the security preferred level products are improved to obtain the dynamic correlation coefficient. Based on the dynamic correlation coefficient, classify the collaborative analysis effect, formulate different product optimization strategies, and dynamically update the three-dimensional security matrix;
[0091] If there is a significant positive correlation, establish a dynamic correlation analysis model to quantify the synergy of the upgrades of the security (S), confidentiality (C), and privacy (P) dimensions from the real-time threat data (t);
[0092] Through the formula: Construct a dynamic correlation analysis model to obtain the dynamic correlation coefficient R(t);
[0093] Among them, P(S∩C∩A|t), P(S|t), P(C|t), and P(A|t) respectively represent the probability of simultaneous upgrades of the three dimensions under real-time threats, the upgrade probability of the security dimension under real-time threats, the upgrade probability of the confidentiality dimension under real-time threats, and the upgrade probability of the privacy dimension under real-time threats;
[0094] It should be noted that the probability of simultaneous upgrades of the three dimensions under real-time threats, the upgrade probability of the security dimension under real-time threats, the upgrade probability of the confidentiality dimension under real-time threats, and the upgrade probability of the privacy dimension under real-time threats are calculated by combining real-time threat data (such as APT attack frequency, quantum threat simulation success rate) to obtain the upgrade probabilities of the security, confidentiality, and privacy dimensions after obtaining the threat data;
[0095] Divide the dynamic correlation coefficient into multiple levels, and formulate different product optimization strategies based on different levels;
[0096] Exemplarily, if the dynamic correlation coefficient > 0.7, it is classified as a high-threat scenario, and the technical features of the TCDPCU5-S quantum security server + physical isolation storage are recommended;
[0097] If the dynamic correlation coefficient < 0.5, it is classified as a low-threat scenario, and TCDPCU4-E + differential privacy optimization is recommended. Users are allowed to extract flexible technical features from the flexible feature group, upgrade the flexible technical features, and achieve the upgrade of the technical level.
[0098] Based on the upgrade probability of the security dimension, the upgrade probability of the confidentiality dimension, and the upgrade probability of the privacy dimension under real-time threats, and calculate the real-time updated entropy of different dimensions through the entropy weight method.
[0099] Obtain the quantization scores of different dimensions corresponding in the three-dimensional security matrix, and use them as the weighted weights for the update calculation of the quantization scores together with the real-time updated entropy.
[0100] Based on the weighted weights for the update calculation of the quantization scores, perform weighted calculation with the quantization scores to obtain the updated scores.
[0101] Based on the updated scores, dynamically update the security protection ability scores of the security dimension, the confidentiality dimension ability scores, and the privacy dimension maintenance ability scores in the three-dimensional security matrix.
[0102] The technical solution of this embodiment is as follows: Obtain the number of times of technical level improvement in different dimensions of the user's security preferred level products, and conduct a synergy analysis to determine whether there is a synergistic upgrade effect in the frequency of technical level improvement in different dimensions. If so, determine whether the synergy effect is significant; if there is a significant positive correlation, conduct a correlation analysis on the number of times of technical level improvement in different dimensions of the security preferred level products to obtain the dynamic correlation coefficient, classify the synergy analysis effect based on the dynamic correlation coefficient, formulate different product optimization strategies, and dynamically update the three-dimensional security matrix to dynamically adjust to real-time threat changes and user upgrade behaviors, improving the system security and adaptability.
[0103] Embodiment III
[0104] As Figure 2 shown, a trusted cloud security confidentiality and privacy level product service system includes the following modules:
[0105] Feature classification module: Based on the trusted cloud security confidentiality and privacy level products, used to construct a product matching library, extract the three-dimensional features of the product matching library, and construct a three-dimensional security matrix.
[0106] The construction method of the product matching library is as follows:
[0107] Obtain the trusted cloud privacy security level and the hierarchical core security mechanism, and establish a binding relationship with the trusted cloud products and product types.
[0108] Based on the binding relationship between the trusted cloud privacy security level and the hierarchical core security mechanism, establish a product matching library.
[0109] Extract technical features based on the trusted cloud privacy security level and the hierarchical core security mechanism of the product matching library, quantify and score according to the security protection capabilities, and construct a three-dimensional security matrix;
[0110] Product optimization module: used to obtain the current privacy classification service requirements of users, establish a requirement matching model, and screen products with the optimal security level from the product matching library;
[0111] Based on the security protection capability score, confidentiality dimension capability score, and privacy dimension maintenance capability score in the three-dimensional security matrix, set different technical levels for the corresponding technical features in the security dimension, confidentiality dimension, and privacy dimension;
[0112] Based on the product matching library, extract the hardware and technical features of the product matching library, and classify the hardware and technical features into core features and flexible features;
[0113] Obtain all the core features of the product matching library and construct a core feature group;
[0114] Obtain all the flexible features of the product matching library and construct a flexible feature group;
[0115] By collecting the hardware and technical feature requirements of users, establish a user requirement group;
[0116] Based on the user requirement group, core feature group, and flexible feature group, establish a requirement matching model through a clustering algorithm;
[0117] Through the requirement matching model, perform matching analysis on the hardware and technical features in the user requirement group with the core feature group and flexible feature group to obtain the core features and flexible features of the user requirement group;
[0118] Judge whether all the core features of the user requirement group are in products of the same security level. If so, obtain the products of the corresponding security level of the user requirement group as products with the optimal security level;
[0119] If not all the core features of the user requirement group are in products of the same security level, classify the technical features in the core feature group and flexible feature group, and screen out the technical features of the user's security dimension, confidentiality dimension, and privacy dimension;
[0120] Filter the technical features of the user's security dimension, confidentiality dimension, and privacy dimension, and eliminate the reused technical features to obtain the technical features of the highest technical level;
[0121] Obtain the highest technical levels in different security dimensions, confidentiality dimensions, and privacy dimensions, and compare them with the preset technical levels of user requirements respectively;
[0122] If the highest technical levels in different security dimensions, confidentiality dimensions, and privacy dimensions all meet the preset technical levels of the user requirements, obtain the security-level products corresponding to the technical levels as the security-preferred level products;
[0123] If not, extract the technical features that do not match the preset technical levels of the user requirements and send a prompt to the user;
[0124] Synergy analysis module: Obtain the number of times of technical level improvement in different dimensions of the user's security-preferred level products, and conduct synergy analysis to determine whether there is a synergistic upgrade effect in the technical level improvement frequencies of different dimensions. If so, determine whether the synergy effect is significant;
[0125] From the historical user data, obtain the number of times of technical level improvement in the security dimension, confidentiality dimension, and privacy dimension of the security-preferred level products for all users;
[0126] Based on the number of times of technical level improvement in the security dimension, confidentiality dimension, and privacy dimension of the security-preferred level products by the user, determine the security improvement frequency, confidentiality improvement frequency, and privacy dimension improvement frequency;
[0127] Mark the security improvement frequency, confidentiality improvement frequency, and privacy dimension improvement frequency as P(S), P(C), and P(A) respectively;
[0128] From the historical user data, obtain the number of times of common technical level improvement in the security dimension, confidentiality dimension, and privacy dimension to obtain the joint upgrade probability, marked as P(S∩C∩A);
[0129] Based on the security improvement frequency, confidentiality improvement frequency, privacy dimension improvement frequency, and joint upgrade probability, through comparison and analysis, determine whether there is a synergistic upgrade effect in the technical level improvement frequencies of different dimensions;
[0130] If P(S∩C∩A) > P(S) * P(C) * P(A), it is considered that there is a positive correlation in the technical level improvement frequencies of different dimensions, that is, there is a synergistic upgrade effect in the technical level improvement frequencies of different dimensions;
[0131] If P(S∩C∩A) < P(S) * P(C) * P(A), it is considered that there is a negative correlation in the technical level improvement frequencies of different dimensions, that is, there is no synergistic upgrade effect in the technical level improvement frequencies of different dimensions, and users tend to upgrade in a single dimension;
[0132] If P(S∩C∩A) = P(S) * P(C) * P(A), it is considered that the technical level improvement frequencies of different dimensions are independent and there is no synergy effect;
[0133] If there is a synergy effect, judge the significance level of the correlation through the chi-square statistical test;
[0134] Through the formula: Obtain the chi-square statistic χ of the correlation 2 , where i, j, and k respectively represent the different upgrade states of the security, confidentiality, and privacy dimensions, that is, upgrade or not upgrade, and r, c, and l are the numbers of different states of the security, confidentiality, and privacy dimensions respectively;
[0135] Among them, O ijk represents the observed number of upgrade combinations, that is, the number of times the technical levels in the security dimension, confidentiality dimension, and privacy dimension are jointly improved. E ijk represents the expected number under the independent hypothesis, that is, the product of the total number of users and P(S)*P(C)*P(A);
[0136] Obtain the chi-square statistic under the significance level value α. If the chi-square statistic of the correlation is higher than the chi-square statistic under the significance level value α, it is considered that there is a significant positive correlation, otherwise it is not considered;
[0137] Optimization and update module: If there is a significant positive correlation, perform a correlation analysis on the number of times the technical levels of different dimensions in the security preferred level products are improved to obtain a dynamic correlation coefficient. Based on the dynamic correlation coefficient, classify the collaborative analysis effect, formulate different product optimization strategies, and dynamically update the three-dimensional security matrix;
[0138] If there is a significant positive correlation, establish a dynamic correlation analysis model to quantify the synergy of the upgrades of the security (S), confidentiality (C), and privacy (P) dimensions from the real-time threat data (t);
[0139] Through the formula: Construct a dynamic correlation analysis model to obtain the dynamic correlation coefficient R(t);
[0140] Among them, P(S∩C∩A|t), P(S|t), P(C|t), and P(A|t) respectively represent the probability of simultaneous upgrade of the three dimensions under real-time threats, the upgrade probability of the security dimension under real-time threats, the upgrade probability of the confidentiality dimension under real-time threats, and the upgrade probability of the privacy dimension under real-time threats;
[0141] Divide the dynamic correlation coefficient into multiple levels and formulate different product optimization strategies based on different levels;
[0142] Based on the upgrade probability of the security dimension under real-time threats, the upgrade probability of the confidentiality dimension under real-time threats, and the upgrade probability of the privacy dimension under real-time threats, calculate the real-time update entropy of different dimensions through the entropy weight method;
[0143] Obtain the corresponding quantitative scores of different dimensions in the three-dimensional security matrix, and use them as the weighted weights for the update calculation of the quantitative scores together with the real-time update entropy;
[0144] The weighted weight based on the updated calculation of the quantitative score is weighted and calculated with the quantitative score to obtain an updated score;
[0145] Based on the updated score, the security protection ability score, the confidentiality dimension ability score, and the privacy dimension maintenance ability score of the security dimension in the three-dimensional security matrix are dynamically updated.
[0146] The above has described an embodiment of the present invention in detail, but the described content is only a preferred embodiment of the present invention and cannot be considered as limiting the scope of implementation of the present invention. All equivalent changes and improvements made according to the scope of the application of the present invention should still fall within the scope covered by the patent of the present invention.
Claims
1. A trusted cloud security confidential privacy level product service method, characterized in that, It includes the following steps: Step 1: Based on the trustworthy cloud security confidential privacy level products, construct a product matching library, extract the three-dimensional features of the product matching library, and construct a three-dimensional security matrix; Step 2: Obtain the user's current privacy classification service requirements, establish a requirement matching model, and screen for products with a secure preferred level from the product matching library; Step 3: Obtain the number of times of technical level improvement in different dimensions of the user's secure preferred level products, and conduct a synergy effect analysis to determine whether there is a synergistic upgrade effect in the frequency of technical level improvement in different dimensions. If so, determine whether the synergy effect is significant; Step 4: If there is a significant positive correlation, conduct a correlation analysis on the number of times of technical level improvement in different dimensions of the secure preferred level products to obtain a dynamic correlation coefficient. Based on the dynamic correlation coefficient, classify the synergy analysis effect, formulate different product optimization strategies, and dynamically update the three-dimensional security matrix.
2. The method for a trusted cloud security confidential privacy level product service according to claim 1, wherein The construction method of the three-dimensional security matrix is as follows: Obtain the trustworthy cloud privacy security level and the hierarchical core security mechanism, and establish a binding relationship with the trustworthy cloud products and product types; Based on the binding relationship between the trustworthy cloud privacy security level and the hierarchical core security mechanism, establish a product matching library; Extract technical features based on the trustworthy cloud privacy security level and the hierarchical core security mechanism of the product matching library, and conduct a quantitative score according to the security protection ability to construct a three-dimensional security matrix.
3. A method for providing a trusted cloud security confidential privacy level product service according to claim 1, characterized in that, The construction method of the secure preferred level products is as follows: Based on the security protection ability scores of the security dimension, the confidentiality dimension ability scores, and the privacy dimension maintenance ability scores in the three-dimensional security matrix, set different technical levels for the corresponding technical features in the security dimension, the confidentiality dimension, and the privacy dimension; Based on the product matching library, extract the hardware and technical features of the product matching library, and divide the hardware and technical features into core features and flexible features to construct a core feature group and a flexible feature group; By collecting the hardware and technical feature requirements of the user, establish a user requirement group; Based on the user requirement group, the core feature group, and the flexible feature group, establish a requirement matching model through a clustering algorithm; Through the requirement matching model, conduct a matching analysis on the hardware and technical features in the user requirement group with the core feature group and the flexible feature group, and screen to obtain products with a secure preferred level.
4. A method for a trusted cloud security confidential privacy level product service according to claim 3, characterized in that, The method of conducting the matching analysis with the core feature group and the flexible feature group is as follows: Judge whether the core features of the user requirement group are all in the products of the same security level. If so, obtain the security level products corresponding to the user requirement group as products with a secure preferred level; If not, conduct a classification process on the technical features in the core feature group and the flexible feature group, conduct a classification matching on the technical features, and screen to obtain products with a secure preferred level.
5. The method for a trusted cloud security confidential privacy level product service according to claim 4, wherein The method of conducting the classification matching is as follows: If the core feature group of the user requirement group is not all in the products of the same security level, conduct a classification process on the technical features in the core feature group and the flexible feature group, and screen to obtain the technical features of the user's security dimension, confidentiality dimension, and privacy dimension; Conduct a filtering process on the technical features of the user's security dimension, confidentiality dimension, and privacy dimension, and eliminate the reused technical features to obtain the technical features of the highest technical level. Obtain the highest technical level in different security dimensions, confidentiality dimensions, and privacy dimensions. If the highest technical levels in different security dimensions, confidentiality dimensions, and privacy dimensions all meet the preset technical level of the user's preset requirements; Obtain the security level products corresponding to the technical level as the security preferred level products.
6. A method for a trusted cloud security confidential privacy level product service according to claim 1, characterized in that, The method of performing the synergy analysis is as follows: Obtain the number of times of technical level improvement in different dimensions of the security preferred level products by all users, and determine the security improvement frequency, confidentiality improvement frequency, and privacy dimension improvement frequency; Obtain the number of times of joint improvement of the technical levels in the security dimension, confidentiality dimension, and privacy dimension to obtain the joint upgrade probability; Based on the security improvement frequency, confidentiality improvement frequency, privacy dimension improvement frequency, and joint upgrade probability, through comparison and analysis, judge whether there is a co-upgrade effect in the technical level improvement frequencies of different dimensions; If the joint upgrade probability is higher than the security improvement frequency, confidentiality improvement frequency, and privacy dimension improvement frequency, it is considered that there is a positive correlation in the technical level improvement frequencies of different dimensions, that is, there is a co-upgrade effect in the technical level improvement frequencies of different dimensions.
7. A method for providing a trusted cloud security confidential privacy level product service according to claim 1, characterized in that, The method of judging whether the synergy effect is significant is as follows: If there is a synergy effect, judge the significance level of the correlation through the chi-square statistical test; Obtain the chi-square statistic under the significance level value α. If the chi-square statistic of the correlation is higher than the chi-square statistic under the significance level value α, it is considered that there is a significant positive correlation.
8. A method for a trusted cloud security encryption privacy level product service according to claim 1, characterized in that, The method of dynamically updating the three-dimensional security matrix is as follows: If there is a significant positive correlation, obtain the real-time update entropy of different dimensions; Obtain the quantization scores of different dimensions corresponding in the three-dimensional security matrix, and use them as the weighted weights for the update calculation of the quantization scores together with the real-time update entropy; Based on the weighted weights for the update calculation of the quantization scores, perform weighted calculation with the quantization scores to obtain the updated scores; Based on the updated scores, dynamically update the security protection ability scores of the security dimension, confidentiality dimension ability scores, and privacy dimension maintenance ability scores in the three-dimensional security matrix.
9. A method for providing a trusted cloud security confidential privacy level product service according to claim 8, characterized in that, The method of obtaining the real-time update entropy of different dimensions is as follows: If there is a significant positive correlation, establish a dynamic correlation analysis model to obtain the upgrade probability of the security dimension under real-time threats, the upgrade probability of the confidentiality dimension under real-time threats, and the upgrade probability of the privacy dimension under real-time threats, and calculate the real-time update entropy of different dimensions by the entropy weight method.
10. A trusted cloud security confidential privacy level product service system for implementing any one of the trusted cloud security confidential privacy level product service methods described in claims 1-9, characterized in that, It includes the following modules: Feature classification module: Based on the trusted cloud security confidentiality and privacy level products, used to construct a product matching library, extract the three-dimensional features of the product matching library, and construct a three-dimensional security matrix; Product optimization module: Used to obtain the current privacy classification service requirements of users, establish a requirement matching model, and screen security preferred level products from the product matching library; Synergy analysis module: Obtain the number of times of technical level improvement in different dimensions of the user's security preferred level products, and perform synergy analysis to judge whether there is a co-upgrade effect in the technical level improvement frequencies of different dimensions. If there is, judge whether the synergy effect is significant; Optimization and update module: If there is a significant positive correlation, perform a correlation analysis on the number of times of technology level improvement in different dimensions of the safety preferred level products to obtain the dynamic correlation coefficient. Based on the dynamic correlation coefficient, classify the collaborative analysis effect, formulate different product optimization strategies, and dynamically update the three-dimensional safety matrix.
Citation Information
Patent Citations
Trusted cloud service selection method based on risk assessment, cloud system, and cloud server
CN107249015A
Network behavior credibility analysis system and processing device
CN115514515A
Credible cloud security level computing system
CN118862092A
Method for fusing optimized network service and dynamically generating protection scheme
CN119945775A
Privacy scoring for cloud services
US9356961B1
Cited By
Trusted cloud native security level treatment system and method
CN121585481A
Trusted cloud level standardization framework system and quantitative mapping method
CN121585482A
Automatic and hierarchical trusted cloud level management unit system and method
CN121616244A
Automated and hierarchical trusted cloud level management unit system and method
CN121616244B
Evolvable credible cloud level computing system and method based on game optimization
CN121644230A