A trusted cloud security confidentiality privacy level product service system and method
By building a product matching library and a three-dimensional security matrix, obtaining user needs, and conducting synergy analysis, the deficiencies in security level assessment in existing technologies are addressed, dynamic collaborative analysis of security, confidentiality, and privacy is achieved, and the security and adaptability of the system are improved.
Patent Information
- Application Number
- CN202510586223.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-08
- Publication Date
- 2025-09-26
- Estimated Expiration
- 2045-05-08
AI Technical Summary
Existing technologies lack a dynamically adaptable security level assessment system, have not built a dynamic collaborative analysis mechanism covering the three dimensions of security, confidentiality, and privacy, and have not established a correlation analysis of technical features in the dimensions of security, confidentiality, and privacy. It is difficult for users to understand the relationship between security levels and their own needs.
Build a product matching library, extract the three-dimensional safety matrix, obtain user needs, conduct synergy analysis, determine the frequency of technology level upgrades, formulate optimization strategies through dynamic correlation coefficients, and realize dynamic updates of the three-dimensional safety matrix.
It achieves quantitative assessment of security capabilities, meets the needs of different user scenarios, improves the fit between products and user needs, system security and adaptability, and provides data support and real-time adjustment capabilities.
Smart Images

Figure CN120342734B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of cloud computing security technology, and in particular to a trusted cloud security confidentiality and privacy level product service system and method. Background Art
[0002] With the rapid development of cloud computing technology, the demand for trusted cloud security services is growing. Although existing technologies have proposed hierarchical security level assessment and dynamic calculation methods, they still have many shortcomings.
[0003] A Chinese patent application with publication number CN118862092A discloses a trusted cloud security level calculation system, including: performing a hierarchical evaluation of a cloud computing system, determining the trusted security level of the cloud computing system, dynamically calculating and adjusting the dynamic security level of the cloud computing system, and displaying and proving the trusted security level and dynamic security level of the cloud computing system; this application provides a trusted cloud security mechanism unit level calculation system, so that the security level of the cloud computing system is visible, trustworthy, and verifiable.
[0004] Existing technologies lack a dynamically adaptable security level assessment system and have not established a dynamic collaborative analysis mechanism covering the three dimensions of security, confidentiality, and privacy. By analyzing the synergistic effect analysis and dynamic correlation coefficient model of the three dimensions of security, confidentiality, and privacy, dynamic updating of the three-dimensional security matrix can be achieved.
[0005] Existing technologies only focus on improving security levels in a single dimension, and have not established correlation analysis of technical features in the dimensions of security, confidentiality, and privacy. By building a demand matching model, core features and flexible features are classified and processed, and the best-level products are automatically screened. Through dynamic correlation coefficient analysis, collaborative upgrade strategies are guided.
[0006] The security level display of existing technologies does not take into account the user's actual application scenarios and technical feature reuse rules, making it difficult for users to understand the relationship between security levels and their own needs. By establishing a three-dimensional security matrix for quantitative scoring and dynamic updating, the technical level of each dimension is clarified, and the preferred security level products are recommended through a demand matching model. Summary of the Invention
[0007] The object of the present invention is to provide a trusted cloud security confidentiality privacy level product service system and method to solve at least one of the above-mentioned existing technical problems.
[0008] In a first aspect, the present invention provides a trusted cloud security confidentiality privacy level product service method, comprising the following steps:
[0009] Step 1: Based on the trusted cloud security confidentiality and privacy level products, build a product matching library, extract the three-dimensional features of the product matching library, and build a three-dimensional security matrix;
[0010] Step 2: Obtain the user's current privacy-graded service needs, establish a demand matching model, and select security-preferred products from the product matching library;
[0011] Step 3: Obtain the number of technical upgrades in different dimensions of the user security priority level products and conduct a synergistic effect analysis to determine whether there is a synergistic upgrade effect in the technical upgrade frequencies of different dimensions. If so, determine whether the synergistic effect is significant.
[0012] Step 4. If there is a significant positive correlation, conduct a correlation analysis on the number of times the technical level is upgraded in different dimensions of the security priority level products to obtain a dynamic correlation coefficient. Based on the dynamic correlation coefficient, classify the synergistic analysis effect, formulate different product optimization strategies, and dynamically update the three-dimensional safety matrix.
[0013] In a second aspect, the present invention provides a trusted cloud security confidentiality privacy level product service system, including the following modules:
[0014] Feature classification module: Based on the trusted cloud security confidentiality privacy level product, it is used to build a product matching library, extract the three-dimensional features of the product matching library, and build a three-dimensional security matrix;
[0015] Product selection module: used to obtain the user's current privacy-graded service needs, establish a demand matching model, and select security-preferred products from the product matching library;
[0016] Synergy Analysis Module: This module obtains the number of technical upgrades in different dimensions of user security priority products and conducts synergy effect analysis to determine whether there is a synergistic upgrade effect in the frequency of technical upgrades in different dimensions. If so, it determines whether the synergistic effect is significant.
[0017] Optimization and update module: If there is a significant positive correlation, a correlation analysis is conducted on the number of times the technical level is upgraded in different dimensions of the security priority level products to obtain a dynamic correlation coefficient. Based on the dynamic correlation coefficient, the synergistic analysis effect is graded, different product optimization strategies are formulated, and the three-dimensional safety matrix is dynamically updated.
[0018] Beneficial effects of the present invention:
[0019] 1. By building a product matching library, extracting the technical characteristics of trusted cloud privacy security levels and graded core security mechanisms, and constructing a three-dimensional security matrix based on the quantitative scoring of security protection capabilities, covering the dimensions of security, confidentiality, and privacy, we can quantify security capabilities and assess product security. A demand matching model is established based on user needs, and products with preferred security ratings are selected from the product matching library to meet the security needs of different users in different scenarios. For example, suitable TCDPCU-E terminal devices are provided for mobile office scenarios, and TCDPCU-S cloud server devices are provided for small and medium-sized cloud platforms, improving the fit between products and user needs.
[0020] 2. Obtain the number of technical upgrades in different dimensions of user security priority products and conduct synergistic effect analysis; determine whether there is a synergistic upgrade effect by comparing the frequency of security upgrades, confidentiality upgrades, privacy dimension upgrades, and the probability of joint upgrades, and use the chi-square statistical test to determine the significance level of the correlation; understand user upgrade behavior patterns and provide data support for product development and promotion.
[0021] 3. If there is a significant positive correlation, a correlation analysis is performed to obtain a dynamic correlation coefficient, which is then used to classify the levels and formulate different product optimization strategies. Based on the upgrade probability of each dimension under real-time threats, the entropy weight method is used to calculate the real-time update entropy, and the weights are updated in combination with the quantitative scoring of the three-dimensional security matrix to achieve dynamic updates of the three-dimensional security matrix. This allows product strategies and security matrices to be dynamically adjusted with real-time threat changes and user upgrade behaviors, thereby improving system security and adaptability. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the technical solutions in the embodiments of the present invention, the following briefly introduces the drawings required for use in the description of the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without creative work.
[0023] Figure 1 It is a flow chart of a trusted cloud security confidentiality privacy level product service method of the present invention;
[0024] Figure 2 It is a module diagram of a trusted cloud security confidentiality privacy level product service system of the present invention. DETAILED DESCRIPTION
[0025] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings in the embodiments of the present invention. Obviously, the embodiments described are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts should fall within the scope of protection of the present invention.
[0026] Example 1
[0027] like Figure 1 As shown, an embodiment of the present invention provides a trusted cloud security confidentiality privacy level product service method, including the following steps:
[0028] Step 1: Based on the trusted cloud security confidentiality and privacy level products, build a product matching library, extract the three-dimensional features of the product matching library, and build a three-dimensional security matrix;
[0029] The product matching library is constructed as follows:
[0030] Obtain trusted cloud privacy security levels and hierarchical core security mechanisms, and establish binding relationships with trusted cloud products and product types;
[0031] Establish a product matching library based on the binding relationship between the trusted cloud privacy security level and the hierarchical core security mechanism;
[0032] Based on the trusted cloud privacy security level and graded core security mechanism of the product matching library, technical features are extracted and quantitatively scored according to security protection capabilities to build a three-dimensional security matrix;
[0033] It should be noted that the quantitative scores are set by those skilled in the art based on their experience;
[0034] The three-dimensional security matrix includes the security protection capability score of the security dimension, the confidentiality dimension capability score, and the privacy dimension maintenance capability score;
[0035] It should be noted that the Trusted Cloud privacy security levels are divided into: DSL3 (Secret Enhanced Privacy), DSL4 (Secret Advanced Privacy), and DSL5 (Secret Ultimate Privacy). Based on different Trusted Cloud privacy security levels, there are three products with different security levels: TCDPCU3, TCDPCU4, and TCDPCU5.
[0036] Each security level also includes different product types to support different application scenarios and user needs, including: terminal equipment (TCDPCU-E), cloud server equipment (TCDPCU-S) and cloud service facilities (TCDPCU-I);
[0037] TCDPCU-E emphasizes security and ease of use in mobile office scenarios, such as economical security terminals, high-performance security terminals, and quantum security terminals, and is used to build secure terminal access cloud services.
[0038] TCDPCU-S (Cloud Server Appliance) is suitable for building small and medium-sized cloud platforms or private cloud environments, such as economical cloud servers, high-performance secure cloud servers, and quantum secure cloud servers, and is used to provide computing and storage resources for cloud services.
[0039] TCDPCU-I (cloud service facility) is suitable for building large-scale cloud service infrastructure, such as economical cloud infrastructure, high-performance secure cloud infrastructure, quantum secure cloud infrastructure, etc., and is used to build and deliver different levels of enterprise-level IaaS, PaaS, and SaaS cloud services.
[0040] The hierarchical core security mechanism consists of five key security modules: the Trusted Root (TCDR) module, the Trusted Kernel (TCDKN) module, the Trusted Isolation (TCDIS) module, the Trusted Access Control (TCDAC) module, and the Trusted Authentication (TCDCA) module.
[0041] Trusted Cloud Root Module: This module is used to establish a hardware root of trust and is the cornerstone of the entire trusted cloud security system. Different levels of trusted cloud root modules utilize hardware roots of trust with varying security levels. For example, the TCDPCU3 uses an economical TPM2.0 chip, the TCDPCU4 uses a dedicated TCDM security chip or an economical HSM, and the TCDPCU5 uses a customized quantum security chip and redundant HSM hardware cluster to provide graded hardware trustworthiness.
[0042] Trusted Cloud Kernel Module: Used to enhance the security of the operating system kernel and provide kernel-level security assurance. Different levels of Trusted Cloud Kernel Modules use different kernel hardening and security extension technologies. For example, TCDPCU3 uses TPM2.0 for kernel security extension, TCDPCU4 uses TCDM hardware acceleration and TEE technology, and TCDPCU5 uses dedicated security hardware and an optional formally verified microkernel operating system to provide graded kernel security protection capabilities.
[0043] Trusted Cloud Isolation Module: This includes the Trusted Cloud Intranet Isolation submodule and the Trusted Cloud Boundary Isolation submodule, which are used to implement internal network isolation and boundary isolation of cloud services to ensure network security. Different levels of Trusted Cloud Isolation Modules use different network isolation technologies. For example, TCDPCU3 provides basic VLAN / ACL and virtual firewall / IDS isolation, TCDPCU4 provides trusted computing / ZTNA / micro-segmentation and virtual WAF / IPS / security situation awareness enhanced isolation, and TCDPCU5 provides the ultimate isolation solution of quantum-safe encryption / TEE / physical isolation network gatekeeper to build a hierarchical network security isolation system.
[0044] Trusted Cloud Access Control Module: This module implements user authentication, authorization management, and access control to ensure secure access to cloud service resources. Different levels of trusted cloud access control modules use different access control technologies. For example, TCDPCU3 provides preliminary access control using MFA / RBAC / MAC, TCDPCU4 provides advanced access control using biometric MFA / multi-domain access control / UBA / ATI, and TCDPCU5 provides an ultimate access control solution with zero-trust authentication / dynamic authorization / AI threat detection to achieve graded access control strength.
[0045] Trusted Cloud Verification Module: This module provides certificate management, encryption algorithm support, and security auditing to ensure trusted authentication of cloud services. Different levels of TCDCA modules use different authentication technologies. For example, TCDPCU3 provides basic authentication services for internal CA / managed CA, TCDPCU4 provides enhanced authentication services for third-party CA and high-strength encryption algorithms, and TCDPCU5 offers customized quantum-safe authentication solutions and redundant HSM hardware security modules to build a hierarchical trusted authentication system.
[0046] Step 2: Obtain the user's current privacy-graded service needs, establish a demand matching model, and select security-preferred products from the product matching library;
[0047] Based on the security protection capability score of the security dimension, the confidentiality dimension capability score, and the privacy dimension maintenance capability score in the three-dimensional security matrix, the corresponding technical features in the security dimension, confidentiality dimension, and privacy dimension are set to different technical levels;
[0048] For example, the technical feature levels are divided into TCD3, TCD4, and TCD5;
[0049] Based on the product matching library, the hardware and technical features of the product matching library are extracted and divided into core features and flexible features;
[0050] Obtain all core features of the product matching library and build a core feature group;
[0051] Obtain all flexible features of the product matching library and build a flexible feature group;
[0052] It should be noted that in the hardware and technical features, hardware includes but is not limited to TCDPCU3, TCDPCU4 and TCDPCU5 security products, as well as the corresponding technology names in the security module, such as TPM2.0 and quantum security chip; technical features include but are not limited to software algorithms in the security module, such as third-party CA and high-strength encryption algorithms;
[0053] Core features are key technologies that directly determine the security level. They are deeply integrated with the trusted cloud security module and must match the DSL3 / 4 / 5 level requirements. The hardware and technical features in the core features cannot be replaced or upgraded at will.
[0054] Flexible features are technologies that support security levels but allow optimization within the same level or cross-level compatibility. Software algorithms can be used to improve the technical level of core features.
[0055] In some embodiments, a user requirement group is established by collecting the user's hardware and technical feature requirements;
[0056] Among them, users include application development service providers and end users. The main requirements of application development service providers come from hardware and technical features in the confidentiality and security dimensions. The main requirements of end users come from hardware and technical features in the privacy and confidentiality dimensions.
[0057] Based on user demand groups, core feature groups and flexible feature groups, a demand matching model is established through clustering algorithms;
[0058] Through the demand matching model, the hardware and technical features in the user demand group are matched and analyzed with the core feature group and the flexible feature group to obtain the core features and flexible features of the user demand group;
[0059] Determine whether the core features of the user demand group are all in the same security level product. If they are, obtain the security level product corresponding to the user demand group as the security priority level product;
[0060] If the core feature groups of the user demand group are not all in the same security level product, the technical features in the core feature group and the flexible feature group are classified and processed to obtain the technical features of the user's security dimension, confidentiality dimension, and privacy dimension;
[0061] Filter the user's security, confidentiality, and privacy technical features, eliminate reused technical features, and obtain the highest-level technical features.
[0062] It should be noted that reused technical features refer to the use of technical features of the user's security dimension, confidentiality dimension, and privacy dimension to enhance the capabilities of the same dimension, and there are multiple technical levels;
[0063] Obtain the highest technical level in different security dimensions, confidentiality dimensions, and privacy dimensions, and compare them with the preset technical level of user requirements;
[0064] If the highest technical levels in different security dimensions, confidentiality dimensions, and privacy dimensions all meet the preset technical levels of user requirements, obtain the security level product corresponding to the technical level as the security preferred level product;
[0065] It should be noted that cloud service providers provide users with more accurate and transparent graded services based on their security priority grade products, remotely verify security levels and provide trusted security reports to users;
[0066] If not, it extracts technical features that do not match the preset technical level of the user's requirements, remotely verifies the security level to the user, and sends a trusted security report;
[0067] The Trusted Security Report includes the following parts:
[0068] S1. Clearly mark the TCDPCU series and DSL security levels on security-level products and services;
[0069] S2. Provide a verifiable security configuration checklist, including specific hardware and technical features;
[0070] S3. Provide third-party security audit reports;
[0071] S4, support remote trusted verification;
[0072] S5. Provide real-time security monitoring dashboard;
[0073] It should be noted that through remote communication methods such as the Internet, security configuration checklists, audit reports, remote verification interfaces and monitoring dashboards are provided to enable users to remotely verify security levels.
[0074] The technical solution of this embodiment is: based on the trusted cloud security confidentiality privacy level products, build a product matching library, extract the three-dimensional features of the product matching library, and build a three-dimensional security matrix; obtain the user's current privacy grading service needs, establish a demand matching model, and screen security preferred level products from the product matching library; this is conducive to improving the fit between products and user needs.
[0075] Example 2
[0076] like Figure 1 As shown, a trusted cloud security confidentiality privacy level product service method also includes the following steps:
[0077] Step 3: Obtain the number of technical upgrades in different dimensions of the user security priority level products and conduct a synergistic effect analysis to determine whether there is a synergistic upgrade effect in the technical upgrade frequencies of different dimensions. If so, determine whether the synergistic effect is significant.
[0078] From historical user data, obtain the number of times all users have upgraded their technical levels in the security, confidentiality, and privacy dimensions of security priority products;
[0079] Determine the frequency of security upgrades, confidentiality upgrades, and privacy upgrades based on the number of times users upgrade the technical levels of the security, confidentiality, and privacy dimensions in the security priority level products;
[0080] The security improvement frequency, confidentiality improvement frequency, and privacy dimension improvement frequency are marked as P(S), P(C), and P(A) respectively;
[0081] From historical user data, we obtain the number of times the technical level in the security dimension, confidentiality dimension, and privacy dimension is jointly improved, and obtain the joint upgrade probability, which is marked as P(S∩C∩A);
[0082] Based on the comparison and analysis of security upgrade frequency, confidentiality upgrade frequency, privacy dimension upgrade frequency and joint upgrade probability, it is determined whether there is a synergistic upgrade effect in the frequency of technology level upgrades in different dimensions;
[0083] If P(S∩C∩A)>P(S)*P(C)*P(A), it is believed that the frequencies of technological level upgrades in different dimensions are positively correlated, that is, there is a synergistic upgrading effect in the frequencies of technological level upgrades in different dimensions;
[0084] If P(S∩C∩A)<P(S)*P(C)*P(A), it is considered that there is a negative correlation between the frequencies of technical level upgrades in different dimensions, that is, there is no synergistic upgrade effect between the frequencies of technical level upgrades in different dimensions, and users tend to upgrade in a single dimension.
[0085] If P(S∩C∩A)=P(S)*P(C)*P(A), then it is considered that the frequency of technical level improvement in different dimensions is independent and there is no synergistic effect;
[0086] If there is a synergistic effect, the significance level of the correlation is determined by the chi-square statistical test;
[0087] By formula: Get the chi-square statistic χ of the correlation 2 , where i, j, and k represent the different upgrade states of security, confidentiality, and privacy dimensions, i.e., upgrade or not upgrade, and r, c, and l represent the number of different states of security, confidentiality, and privacy dimensions, respectively;
[0088] Among them, O ijk represents the number of observed upgrade combinations, i.e., the number of times the technical level in the security dimension, confidentiality dimension, and privacy dimension is jointly improved. E ijk represents the expected number of times under the independence assumption, that is, the product of the total number of users and P(S)*P(C)*P(A);
[0089] Obtain the chi-square statistic under the significance level α. If the chi-square statistic of the correlation is higher than the chi-square statistic under the significance level α, it is considered that there is a significant positive correlation, otherwise it is not considered;
[0090] Step 4: If there is a significant positive correlation, conduct a correlation analysis on the number of technical level upgrades in different dimensions of the security priority level products to obtain a dynamic correlation coefficient. Based on the dynamic correlation coefficient, classify the synergy analysis effect, formulate different product optimization strategies, and dynamically update the three-dimensional safety matrix.
[0091] If there is a significant positive correlation, a dynamic correlation analysis model is established to quantify the synergy of security (S), confidentiality (C), and privacy (P) upgrades based on real-time threat data (t);
[0092] By formula: Construct a dynamic correlation analysis model and obtain the dynamic correlation coefficient R(t);
[0093] Among them, P(S∩C∩A|t), P(S|t), P(C|t), and P(A|t) represent the probability of simultaneous upgrade of the three dimensions under real-time threats, the probability of upgrade of the security dimension under real-time threats, the probability of upgrade of the confidentiality dimension under real-time threats, and the probability of upgrade of the privacy dimension under real-time threats, respectively.
[0094] It should be noted that the probability of simultaneous upgrades in the three dimensions under real-time threats, the probability of upgrades in the security dimension under real-time threats, the probability of upgrades in the confidentiality dimension under real-time threats, and the probability of upgrades in the privacy dimension under real-time threats are calculated by combining real-time threat data (such as APT attack frequency and quantum threat simulation success rate) to obtain the upgrade probabilities of the three dimensions of security, confidentiality, and privacy after obtaining the threat data;
[0095] Divide the dynamic correlation coefficient into multiple levels and formulate different product optimization strategies based on different levels;
[0096] For example, if the dynamic correlation coefficient is greater than 0.7, it is classified as a high-threat scenario, and the technical features of TCDPCU5-S quantum security server + physically isolated storage are recommended;
[0097] If the dynamic correlation coefficient is less than 0.5, it is classified as a low-threat scenario, and TCDPCU4-E+ differential privacy optimization is recommended. This allows users to extract flexible technical features from the flexible feature group and upgrade the flexible technical features to achieve a technical level upgrade.
[0098] Based on the upgrade probability of security dimension under real-time threat, the upgrade probability of confidentiality dimension under real-time threat, and the upgrade probability of privacy dimension under real-time threat, the real-time update entropy of different dimensions is calculated by entropy weight method;
[0099] Obtain the quantitative scores of different dimensions corresponding to the three-dimensional security matrix, and use the real-time updated entropy as the weighted weight for the quantitative score update calculation;
[0100] The weighted weight calculated based on the quantitative score update is added to the quantitative score weighted calculation to obtain the updated score;
[0101] Based on the updated scores, the security protection capability score, confidentiality capability score, and privacy maintenance capability score of the security dimension in the three-dimensional security matrix are dynamically updated;
[0102] The technical solution of this embodiment is: obtain the number of technical level upgrades in different dimensions of user security priority level products, and conduct synergistic effect analysis to determine whether there is a synergistic upgrade effect in the frequency of technical level upgrades in different dimensions. If so, determine whether the synergistic effect is significant; if there is a significant positive correlation, conduct a correlation analysis on the number of technical level upgrades in different dimensions of security priority level products to obtain a dynamic correlation coefficient, grade the synergistic analysis effect based on the dynamic correlation coefficient, formulate different product optimization strategies, and dynamically update the three-dimensional security matrix to dynamically adjust real-time threat changes and user upgrade behaviors to improve system security and adaptability.
[0103] Example 3
[0104] like Figure 2 As shown, a trusted cloud security confidentiality privacy level product service system includes the following modules:
[0105] Feature classification module: Based on the trusted cloud security confidentiality privacy level product, it is used to build a product matching library, extract the three-dimensional features of the product matching library, and build a three-dimensional security matrix;
[0106] The product matching library is constructed as follows:
[0107] Obtain trusted cloud privacy security levels and hierarchical core security mechanisms, and establish binding relationships with trusted cloud products and product types;
[0108] Establish a product matching library based on the binding relationship between the trusted cloud privacy security level and the hierarchical core security mechanism;
[0109] Based on the trusted cloud privacy security level and graded core security mechanism of the product matching library, technical features are extracted and quantitatively scored according to security protection capabilities to build a three-dimensional security matrix;
[0110] Product selection module: used to obtain the user's current privacy-graded service needs, establish a demand matching model, and select security-preferred products from the product matching library;
[0111] Based on the security protection capability score of the security dimension, the confidentiality dimension capability score, and the privacy dimension maintenance capability score in the three-dimensional security matrix, the corresponding technical features in the security dimension, confidentiality dimension, and privacy dimension are set to different technical levels;
[0112] Based on the product matching library, the hardware and technical features of the product matching library are extracted and divided into core features and flexible features;
[0113] Obtain all core features of the product matching library and build a core feature group;
[0114] Obtain all flexible features of the product matching library and build a flexible feature group;
[0115] Establish user demand groups by collecting users' hardware and technical feature requirements;
[0116] Based on user demand groups, core feature groups and flexible feature groups, a demand matching model is established through clustering algorithms;
[0117] Through the demand matching model, the hardware and technical features in the user demand group are matched and analyzed with the core feature group and the flexible feature group to obtain the core features and flexible features of the user demand group;
[0118] Determine whether the core features of the user demand group are all in the same security level product. If they are, obtain the security level product corresponding to the user demand group as the security priority level product;
[0119] If the core feature groups of the user demand group are not all in the same security level product, the technical features in the core feature group and the flexible feature group are classified and processed to obtain the technical features of the user's security dimension, confidentiality dimension, and privacy dimension;
[0120] Filter the user's security, confidentiality, and privacy technical features, eliminate reused technical features, and obtain the highest-level technical features.
[0121] Obtain the highest technical level in different security dimensions, confidentiality dimensions, and privacy dimensions, and compare them with the preset technical level of user requirements;
[0122] If the highest technical levels in different security dimensions, confidentiality dimensions, and privacy dimensions all meet the preset technical levels of user requirements, obtain the security level product corresponding to the technical level as the security preferred level product;
[0123] If not, extract the technical features that do not match the preset technical level of the user's requirements and send a prompt to the user;
[0124] Synergy Analysis Module: This module obtains the number of technical upgrades in different dimensions of user security priority products and conducts synergy effect analysis to determine whether there is a synergistic upgrade effect in the frequency of technical upgrades in different dimensions. If so, it determines whether the synergistic effect is significant.
[0125] From historical user data, obtain the number of times all users have upgraded their technical levels in the security, confidentiality, and privacy dimensions of security priority products;
[0126] Determine the frequency of security upgrades, confidentiality upgrades, and privacy upgrades based on the number of times users upgrade the technical levels of the security, confidentiality, and privacy dimensions in the security priority level products;
[0127] The security improvement frequency, confidentiality improvement frequency, and privacy dimension improvement frequency are marked as P(S), P(C), and P(A) respectively;
[0128] From historical user data, we obtain the number of times the technical level in the security dimension, confidentiality dimension, and privacy dimension is jointly improved, and obtain the joint upgrade probability, which is marked as P(S∩C∩A);
[0129] Based on the comparison and analysis of security upgrade frequency, confidentiality upgrade frequency, privacy dimension upgrade frequency and joint upgrade probability, it is determined whether there is a synergistic upgrade effect in the frequency of technology level upgrades in different dimensions;
[0130] If P(S∩C∩A)>P(S)*P(C)*P(A), it is believed that the frequencies of technological level upgrades in different dimensions are positively correlated, that is, there is a synergistic upgrading effect in the frequencies of technological level upgrades in different dimensions;
[0131] If P(S∩C∩A)<P(S)*P(C)*P(A), it is considered that there is a negative correlation between the frequencies of technical level upgrades in different dimensions, that is, there is no synergistic upgrade effect between the frequencies of technical level upgrades in different dimensions, and users tend to upgrade in a single dimension.
[0132] If P(S∩C∩A)=P(S)*P(C)*P(A), then it is considered that the frequency of technical level improvement in different dimensions is independent and there is no synergistic effect;
[0133] If there is a synergistic effect, the significance level of the correlation is determined by the chi-square statistical test;
[0134] By formula: Get the chi-square statistic χ of the correlation 2 , where i, j, and k represent the different upgrade states of security, confidentiality, and privacy dimensions, i.e., upgrade or not upgrade, and r, c, and l represent the number of different states of security, confidentiality, and privacy dimensions, respectively;
[0135] Among them, O ijk represents the number of observed upgrade combinations, i.e., the number of times the technical level in the security dimension, confidentiality dimension, and privacy dimension is jointly improved. E ijk represents the expected number of times under the independence assumption, that is, the product of the total number of users and P(S)*P(C)*P(A);
[0136] Obtain the chi-square statistic under the significance level α. If the chi-square statistic of the correlation is higher than the chi-square statistic under the significance level α, it is considered that there is a significant positive correlation, otherwise it is not considered;
[0137] Optimization and Update Module: If there is a significant positive correlation, a correlation analysis is conducted on the number of technical level upgrades in different dimensions of the security priority level products to obtain a dynamic correlation coefficient. Based on the dynamic correlation coefficient, the synergy analysis effect is graded, different product optimization strategies are formulated, and the three-dimensional safety matrix is dynamically updated.
[0138] If there is a significant positive correlation, a dynamic correlation analysis model is established to quantify the synergy of security (S), confidentiality (C), and privacy (P) upgrades based on real-time threat data (t);
[0139] By formula: Construct a dynamic correlation analysis model and obtain the dynamic correlation coefficient R(t);
[0140] Among them, P(S∩C∩A|t), P(S|t), P(C|t), and P(A|t) represent the probability of simultaneous upgrade of the three dimensions under real-time threats, the probability of upgrade of the security dimension under real-time threats, the probability of upgrade of the confidentiality dimension under real-time threats, and the probability of upgrade of the privacy dimension under real-time threats, respectively.
[0141] Divide the dynamic correlation coefficient into multiple levels and formulate different product optimization strategies based on different levels;
[0142] Based on the upgrade probability of security dimension under real-time threat, the upgrade probability of confidentiality dimension under real-time threat, and the upgrade probability of privacy dimension under real-time threat, the real-time update entropy of different dimensions is calculated by entropy weight method;
[0143] Obtain the quantitative scores of different dimensions corresponding to the three-dimensional security matrix, and use the real-time updated entropy as the weighted weight for the quantitative score update calculation;
[0144] The weighted weight calculated based on the quantitative score update is added to the quantitative score weighted calculation to obtain the updated score;
[0145] Based on the updated scores, the security protection capability score of the security dimension, the confidentiality dimension capability score, and the privacy dimension maintenance capability score in the three-dimensional security matrix are dynamically updated.
[0146] The above is a detailed description of an embodiment of the present invention. However, the content described is only a preferred embodiment of the present invention and should not be considered to limit the scope of the present invention. All equivalent changes and improvements made within the scope of the present invention should still fall within the scope of the patent coverage of the present invention.
Claims
1. A trusted cloud security confidentiality privacy level product service method, characterized by: The following steps are involved: Step 1: Based on the trusted cloud security confidentiality and privacy level products, build a product matching library, extract the three-dimensional features of the product matching library, and build a three-dimensional security matrix; Step 2: Obtain the user's current privacy-graded service needs, establish a demand matching model, and select security-preferred products from the product matching library; Step 3: Obtain the number of technical upgrades in different dimensions of the user security priority level products and conduct a synergistic effect analysis to determine whether there is a synergistic upgrade effect in the technical upgrade frequencies of different dimensions. If so, determine whether the synergistic effect is significant. Step 4. If there is a significant positive correlation, conduct a correlation analysis on the number of times the technical level is upgraded in different dimensions of the security priority level products to obtain a dynamic correlation coefficient. Based on the dynamic correlation coefficient, classify the synergistic analysis effect, formulate different product optimization strategies, and dynamically update the three-dimensional safety matrix.
2. A trusted cloud security confidentiality privacy level product service method according to claim 1, characterized in that: The three-dimensional safety matrix is constructed as follows: Obtain trusted cloud privacy security levels and hierarchical core security mechanisms, and establish binding relationships with trusted cloud products and product types; Establish a product matching library based on the binding relationship between the trusted cloud privacy security level and the hierarchical core security mechanism; Based on the trusted cloud privacy security level and graded core security mechanism of the product matching library, technical features are extracted, and quantitative scores are given according to security protection capabilities to construct a three-dimensional security matrix.
3. A trusted cloud security confidentiality privacy level product service method according to claim 1, characterized in that: The construction method of the security priority level product is as follows: Based on the security protection capability score of the security dimension, the confidentiality dimension capability score, and the privacy dimension maintenance capability score in the three-dimensional security matrix, the corresponding technical features in the security dimension, confidentiality dimension, and privacy dimension are set to different technical levels; Based on the product matching library, extract the hardware and technical features of the product matching library, divide the hardware and technical features into core features and flexible features, and construct core feature groups and flexible feature groups; Establish user demand groups by collecting users' hardware and technical feature requirements; Based on user demand groups, core feature groups and flexible feature groups, a demand matching model is established through clustering algorithms; Through the demand matching model, the hardware and technical features in the user demand group are matched and analyzed with the core feature group and flexible feature group to screen out products with the preferred security level.
4. A trusted cloud security confidentiality privacy level product service method according to claim 3, characterized in that: The matching analysis method with the core feature group and the flexible feature group is as follows: Determine whether the core features of the user demand group are all in the same security level product. If they are, obtain the security level product corresponding to the user demand group as the security priority level product; If not, classify the technical features in the core feature group and the flexible feature group, classify and match the technical features, and screen out products with the preferred safety grade.
5. A trusted cloud security confidentiality privacy level product service method according to claim 4, characterized in that: The classification matching method is as follows: If the core feature groups of the user demand group are not all in the same security level product, the technical features in the core feature group and the flexible feature group are classified and processed to obtain the technical features of the user's security dimension, confidentiality dimension, and privacy dimension; Filter the user's security, confidentiality, and privacy technical features, eliminate reused technical features, and obtain the highest-level technical features. Obtain the highest technical level in different security dimensions, confidentiality dimensions, and privacy dimensions. If the highest technical level in different security dimensions, confidentiality dimensions, and privacy dimensions all meet the preset user requirement preset technical level; Obtain security level products corresponding to the technical level as security priority level products.
6. A trusted cloud security confidentiality privacy level product service method according to claim 1, characterized in that: The method for performing synergistic effect analysis is: Obtain the number of times all users have upgraded their technical levels in different dimensions of security priority products, and determine the frequency of security upgrades, confidentiality upgrades, and privacy upgrades; Obtain the number of joint upgrades in the security, confidentiality, and privacy dimensions, and obtain the probability of joint upgrades. Based on the comparison and analysis of security upgrade frequency, confidentiality upgrade frequency, privacy dimension upgrade frequency and joint upgrade probability, it is determined whether there is a synergistic upgrade effect in the frequency of technology level upgrades in different dimensions; If the probability of joint upgrade is higher than the frequency of security upgrade, confidentiality upgrade, and privacy dimension upgrade, it is considered that the frequencies of technical level upgrades in different dimensions are positively correlated, that is, there is a synergistic upgrade effect in the frequencies of technical level upgrades in different dimensions.
7. A trusted cloud security confidentiality privacy level product service method according to claim 1, characterized in that: The method for judging whether the synergistic effect is significant is: If there is a synergistic effect, the significance level of the correlation is determined by the chi-square statistical test; Obtain the chi-square statistic under the significance level value α. If the chi-square statistic of the correlation is higher than the chi-square statistic under the significance level value α, it is considered that there is a significant positive correlation.
8. A trusted cloud security encryption privacy level product service method according to claim 1, characterized in that: The method of dynamically updating the three-dimensional safety matrix is as follows: If there is a significant positive correlation, obtain the real-time updated entropy of different dimensions; Obtain the quantitative scores of different dimensions corresponding to the three-dimensional security matrix, and use the real-time updated entropy as the weighted weight for the quantitative score update calculation; The weighted weight calculated based on the quantitative score update is added to the quantitative score weighted calculation to obtain the updated score; Based on the updated scores, the security protection capability score of the security dimension, the confidentiality dimension capability score, and the privacy dimension maintenance capability score in the three-dimensional security matrix are dynamically updated.
9. A trusted cloud security confidentiality privacy level product service method according to claim 8, characterized in that: The real-time updated entropy of different dimensions is obtained as follows: If there is a significant positive correlation, a dynamic correlation analysis model is established to obtain the upgrade probability of the security dimension under real-time threats, the upgrade probability of the confidentiality dimension under real-time threats, and the upgrade probability of the privacy dimension under real-time threats, and the real-time update entropy of different dimensions is calculated using the entropy weight method.
10. A trusted cloud security confidentiality privacy level product service system, used to implement any of the trusted cloud security confidentiality privacy level product service methods described in claims 1-9, characterized in that: Includes the following modules: Feature classification module: Based on the trusted cloud security confidentiality privacy level product, it is used to build a product matching library, extract the three-dimensional features of the product matching library, and build a three-dimensional security matrix; Product selection module: used to obtain the user's current privacy-graded service needs, establish a demand matching model, and select security-preferred products from the product matching library; Synergy Analysis Module: This module obtains the number of technical upgrades in different dimensions of user security priority products and conducts synergy effect analysis to determine whether there is a synergistic upgrade effect in the frequency of technical upgrades in different dimensions. If so, it determines whether the synergistic effect is significant. Optimization and update module: If there is a significant positive correlation, a correlation analysis is conducted on the number of times the technical level is upgraded in different dimensions of the security priority level products to obtain a dynamic correlation coefficient. Based on the dynamic correlation coefficient, the synergistic analysis effect is graded, different product optimization strategies are formulated, and the three-dimensional safety matrix is dynamically updated.
Citation Information
Patent Citations
Credible cloud security level computing system
CN118862092A
Trusted cloud service selection method based on risk assessment, cloud system, and cloud server
CN107249015A
Network behavior credibility analysis system and processing device
CN115514515A