Trusted cloud security confidential privacy three-dimensional grade product service system and method
By providing cloud service providers with three-dimensional level product service methods, the problem of inconsistent security, confidentiality and privacy assessment standards in the cloud computing environment is solved, clear security level assessment and dynamic protection are achieved, and user trust and market transparency are enhanced.
Patent Information
- Application Number
- CN202510564329.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-30
- Publication Date
- 2025-08-22
AI Technical Summary
The lack of unified three-dimensional security, confidentiality and privacy rating standards in the existing cloud computing environment, making it difficult for users to objectively compare the security level of cloud service products, and the existing technology is difficult to control costs while ensuring security strength while taking into account user experience needs.
Provide a trusted cloud security confidential privacy three-dimensional product service method, separates the three-dimensional differentiated needs of application development service providers and end users through cloud service providers, configures security modules, combines end-to-end application scenarios, determines the type of cloud service product for users, and deploys dynamic policy adjustment mechanisms, monitors and adapts protection strategies in real time, and provides third-party security audit reports.
It has achieved clear and quantifiable security confidential privacy standards, reduced user selection costs, improved users' trust and security in cloud services, promoted transparent competition in the market, enhanced dynamic security protection capabilities, and solved the problem of opaque matching of traditional cloud services and difficult to trace risks.
Smart Images

Figure CN120528631A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of cloud service technology, and specifically provides a trusted cloud security, confidentiality, and privacy three-dimensional product service system and method. Background Art
[0002] With the rapid development and widespread adoption of cloud computing technology, more and more organizations and individuals are migrating their data and applications to the cloud. Cloud platforms, with their advantages of flexible resource allocation, convenient access, and efficient operations and maintenance, significantly improve IT efficiency and reduce operating costs, becoming a key driving force for the development of modern information technology.
[0003] However, data security and confidentiality and privacy protection in cloud computing environments face many challenges. Although confidential computing and privacy protection technologies can theoretically improve cloud data security and user privacy, in practice, existing cloud computing security technologies still have many shortcomings and cannot achieve the beneficial effects achieved by this invention:
[0004] Existing technologies lack unified standards, making it difficult to quantify the three-dimensional service levels of security, confidentiality, and privacy: The current cloud computing market lacks unified and widely recognized quantitative assessment standards for the confidentiality, privacy, and security levels of cloud service products. This makes it difficult for users to objectively compare the security levels of different cloud services when choosing a service, and existing technologies fail to provide users with a clear basis for selection.
[0005] It is difficult to improve the trust in privacy services using existing technologies. Due to the lack of transparent and quantifiable security level assessment standards, users find it difficult to accurately judge the security capabilities claimed by cloud service providers when choosing cloud services, and there are general concerns about cloud data security and privacy protection. Existing technologies make it difficult to ensure security strength while effectively controlling costs and taking into account users' needs for cloud service performance experience.
[0006] To this end, the present invention provides a trusted cloud security, confidentiality and privacy three-dimensional level product service system and method. Summary of the Invention
[0007] In order to make up for the deficiencies of the prior art, at least one technical problem raised in the background technology is solved.
[0008] The technical solution adopted by the present invention to solve the technical problem is: a trusted cloud security confidentiality privacy three-dimensional level product service method, including the following steps:
[0009] A trusted cloud security, confidentiality and privacy three-dimensional product service method includes the following steps:
[0010] Cloud service providers separate the three-dimensional differentiated needs of application development service providers and end users, and match security-level products to these three-dimensional differentiated needs;
[0011] Cloud service providers configure security modules specifically for security-level products;
[0012] Cloud service providers determine the types of cloud service products for application development service providers and end users based on end-to-end application scenarios;
[0013] Cloud service providers select and match hardware and software confidentiality and privacy for application development service providers and end users based on the security level of the security level products;
[0014] Cloud service providers deploy dynamic policy adjustment mechanisms to monitor abnormal access mechanisms of security-level products in real time, adaptively adjust protection strategies according to level rules, and remotely verify three-dimensional security levels.
[0015] Furthermore, the method of matching the three-dimensional differentiated requirements with safety level products is as follows:
[0016] Divide cloud service data into different security levels, combine the three-dimensional differentiated needs of application development service providers and end users, and achieve matching of security level equipment products.
[0017] Furthermore, the security module includes:
[0018] Trusted cloud root module, trusted cloud kernel module, trusted cloud isolation module, trusted cloud access control module, and trusted cloud verification module.
[0019] Furthermore, the method of deploying the dynamic policy adjustment mechanism is:
[0020] Real-time threat monitoring and response, dynamic security policy adjustment, continuous security monitoring and auditing, proactive defense and threat intelligence;
[0021] Through dynamic policy adjustment mechanism and remote verification of security level, third-party security audit reports are provided to application development service providers and end users.
[0022] Furthermore, the remote verification security level is performed in the following manner:
[0023] Cloud service providers clearly mark the TCDPCU security level product series and DSL security level on their products and services;
[0024] The cloud service provider provides a verifiable security configuration checklist;
[0025] The cloud service provider provides a third-party security audit report;
[0026] Cloud service providers support remote trusted verification;
[0027] Cloud service providers provide real-time security monitoring dashboards;
[0028] Among them, DSL is the data security level and TCDPCU is the trusted cloud security privacy unit.
[0029] Furthermore, the method further comprises the following steps:
[0030] Quantitatively analyze the three-dimensional needs to obtain three-dimensional quantitative indicators, map and analyze the corresponding relationship between the three-dimensional quantitative indicators and the levels, and establish a monitoring matching benchmark library;
[0031] The cloud service provider collects two-way data for demand matching and performs three-dimensional mapping analysis on the two-way data collection to obtain the three-dimensional demand matching degree and determine whether the demand matching is implemented;
[0032] If demand matching is not fully implemented, three-level cross-validation will be conducted in combination with historical data to locate demand mismatch risks and develop a mismatch response mechanism.
[0033] Furthermore, the method of performing three-dimensional mapping analysis on the bidirectional data acquisition is:
[0034] Cloud service providers divide bidirectional data collection into the technical side and the user side. The technical side obtains the technical configuration data of the application development service provider, and the user side obtains the end-user demand data.
[0035] Construct a three-dimensional matching model, input the application development service provider's technical configuration data and end-user demand data, as well as the monitoring and matching benchmark library into the three-dimensional matching model for three-dimensional mapping analysis, and map the application development service provider's technical configuration data and user demand data to the three-dimensional space of confidentiality, privacy, and security corresponding to the monitoring and matching benchmark library;
[0036] The three-dimensional demand matching degree is calculated from the three-dimensional matching model, and the three-dimensional demand matching degree is divided into different demand matching levels.
[0037] Furthermore, the three-dimensional matching model is constructed as follows:
[0038] Data preprocessing module construction: preprocess the technical configuration data of application development service providers and end-user demand data and convert non-numeric data into numerical data;
[0039] Construction of the three-dimensional space mapping module: Determine the data mapping rules and mapping relationships based on the confidentiality, privacy, and security indicator definitions in the monitoring and matching benchmark library;
[0040] Demand matching calculation module construction:
[0041] Based on the constructed three-dimensional mapping space, the numerical data corresponding to the technical configuration data of the application development service provider and the end-user demand data are used as actual values, and the reference values of the three dimensions in the monitoring matching benchmark library corresponding to the actual values in the three-dimensional mapping space are obtained respectively;
[0042] The Euclidean distance between the actual value and the reference value of the three dimensions is calculated to obtain the demand matching degree of the three dimensions;
[0043] The three-dimensional demand matching degree is obtained by performing weighted summation processing on the demand matching degrees of the three dimensions.
[0044] Furthermore, the three-level cross-validation method based on historical data is as follows:
[0045] Indicator verification;
[0046] Compare various indicators in current technical configuration and user needs with indicators in the same or similar scenarios in historical data to identify potential mismatch risk points;
[0047] Dimensional validation;
[0048] Comprehensively consider the performance of each indicator in the three dimensions of confidentiality, privacy, and security, and calculate the difference between the current dimension matching degree and the historical dimension matching degree;
[0049] By calculating the Spearman correlation coefficient of different dimensions, we can analyze the correlation between different dimensions and determine whether the mismatch of a certain dimension affects the matching of other dimensions.
[0050] Scenario verification;
[0051] Compare the demand matching situation in the current scenario with the matching results of similar historical scenarios to assess whether there is any special mismatch risk in the current scenario;
[0052] Based on the results of the three-level cross-validation, potential mismatch risk points are ranked and prioritized;
[0053] Obtain the highest priority risk points and formulate mismatch response mechanism strategies.
[0054] A trusted cloud security, confidentiality and privacy three-dimensional product service system, including the following modules:
[0055] Demand separation module: Cloud service providers separate the three-dimensional differentiated demands of application development service providers and end users, and match the three-dimensional differentiated demands with security-level products;
[0056] Security configuration module: Based on the security level products and corresponding security levels, the cloud service provider configures security modules for security level products;
[0057] Hardware and software selection module: Cloud service providers select and match hardware and software confidentiality and privacy for application development service providers and end users based on the security level of security products;
[0058] Product determination module: Cloud service providers determine cloud service product types for application development service providers and end users based on end-to-end application scenarios;
[0059] Policy deployment module: Cloud service providers deploy dynamic policy adjustment mechanisms to monitor abnormal access mechanisms of security-level products in real time, adaptively adjust protection policies according to level rules, and remotely verify security levels;
[0060] Monitoring quantification module: used to quantitatively analyze three-dimensional requirements to obtain three-dimensional quantitative indicators, map and analyze the corresponding relationship between three-dimensional quantitative indicators and levels, and establish a monitoring matching benchmark library;
[0061] Landing matching module: This module is used by cloud service providers to collect two-way data for demand matching and perform three-dimensional mapping analysis on the two-way data collection to obtain the three-dimensional demand matching degree and determine whether the demand matching has been implemented.
[0062] Verification and response module: If the demand matching is not fully implemented, it is used to perform three-level cross-validation in combination with historical data, locate the demand mismatch risk, and formulate a mismatch response mechanism.
[0063] The beneficial effects of the present invention are as follows:
[0064] 1. Providing a clear three-dimensional service standard for security, confidentiality, and privacy: The DSL3, DSL4, and DSL5 grading system, along with the TCDPCU (Trusted Cloud Security Degree Private Confidential Unit) product line, provides end users and cloud service providers with clear, quantifiable security, confidentiality, and privacy grading standards. This standard covers multiple dimensions, making security capabilities measurable and comparable. It also enhances user choice: Application development service providers and end users can select the most appropriate TCDPCU-grade cloud service based on their data sensitivity, compliance requirements, and budget constraints, comparing it to the DSL grading system. This enhances control and trust in cloud service security. It also promotes transparent competition in the cloud service market: The TCDPCU grading system promotes the establishment of a transparent competition mechanism based on security capabilities in the cloud computing service market. By clearly marking cloud service grading, cloud service providers demonstrate their security capabilities, promote fairer market competition, and drive improvements in the overall security level of the industry.
[0065] 2. Reduce user understanding and selection costs: Compared with complex security certifications and standards, TCDPCU's DSL level standards are simple and easy to understand. Users can quickly understand the differences in security capabilities of different cloud services without professional security knowledge, which reduces the threshold and cost of selecting secure cloud services. It is conducive to enhancing the dynamic security protection capabilities of cloud services. Through real-time threat detection and response, dynamic security policy adjustment, continuous security monitoring and auditing, active defense and threat intelligence zero-trust security architecture applications, strict identity authentication and authorization of users, devices or applications accessing cloud service resources are achieved, and access rights are dynamically evaluated and adjusted to reduce the risk of internal spread and unauthorized access, thereby improving the overall security resilience of cloud services.
[0066] 3. By conducting quantitative analysis on the three-dimensional requirements of confidentiality, privacy, and security and building a monitoring and matching benchmark library, standardized measurement and level mapping of cloud service requirements are achieved. Combined with two-way data collection and three-dimensional mapping analysis on the technical and user sides, abstract requirements are converted into verifiable matching quantitative evaluations, and three matching levels are divided into complete implementation, incomplete implementation, and no implementation at all. For incomplete implementation scenarios, cross-dimensional mismatch risks are located through a three-level cross-validation mechanism of indicator verification, dimension verification, and scenario verification, and a mismatch response mechanism including short-term emergency response and long-term optimization is formulated based on historical data. This solves the problems of opaque matching of traditional cloud service security requirements and difficulty in tracing risks, improves the accuracy of demand matching and dynamic security protection capabilities, and provides cloud service providers with a quantifiable, traceable, and optimizable three-dimensional demand matching technical solution. BRIEF DESCRIPTION OF THE DRAWINGS
[0067] The present invention will be further described below with reference to the accompanying drawings.
[0068] Figure 1 This is a diagram of the security, confidentiality, and privacy unit architecture implemented in the present invention;
[0069] Figure 2 This is a flow chart of the matching and division of the three-dimensional level products of trusted cloud security, confidentiality and privacy provided by the present invention;
[0070] Figure 3 It is a flow chart of the trusted cloud security level product service monitoring method provided by the present invention;
[0071] Figure 4 This is a module diagram of a trusted cloud security, confidentiality and privacy three-dimensional level product service system of the present invention. DETAILED DESCRIPTION
[0072] In order to make the technical means, creative features, objectives and effects achieved by the present invention easier to understand, the present invention is further described below in conjunction with specific implementation methods.
[0073] In the cloud computing service ecosystem, the data security needs of application developers and end users are both interrelated and fundamentally different. Application developers prioritize confidentiality to ensure the security of core data and algorithms for their own commercial interests, while also collecting as much user information as possible for other purposes. End users, on the other hand, are highly concerned about privacy protection to prevent the misuse of personal information. The boundaries and priorities of these two needs often conflict depending on the business scenario. As a technologically neutral third party, cloud service providers, through a systematic, hierarchical service approach based on master and sub-modules, meet the rigid confidentiality and security requirements of application developers while ensuring end users' right to independent control over their privacy. The following seven interlocking steps form a three-dimensional TCDPCU-level service system for trusted cloud security, confidentiality, and privacy: "demand separation - module differentiation - dynamic balance."
[0074] Please refer to Figure 1 The TCDPCU implicitly includes the Trusted Cloud-Grade Universal Subunit (TCDSU), the Trusted Cloud-Grade Confidential Subunit (TCDCU), and the Trusted Cloud-Grade Privacy Subunit (TCDPU). These are all subunits of the Trusted Cloud-Grade Unit (TCDUN) and possess distinct security attributes. Together with the Trusted Cloud-Grade Unit / Trusted Cloud-Grade Management Unit (TCDUN / TCDMU) controlled by the cloud service provider, they form a complete three-dimensional product suite. For simplicity, they are collectively referred to as the TCDPCU.
[0075] Example 1
[0076] See also Figure 2 As shown, a trusted cloud security, confidentiality and privacy three-dimensional product service method according to an embodiment of the present invention includes the following steps:
[0077] Step 1: The cloud service provider separates the three-dimensional differentiated needs of application development service providers and end users, and matches the three-dimensional differentiated needs with security-level products;
[0078] Among them, the three-dimensional differentiated needs are the differentiated needs of application development service providers and end users, including the differences in needs in the three dimensions of confidentiality, privacy, and security:
[0079] It should be explained that application development service providers focus on data confidentiality and security, such as core data encryption and kernel security protection, while end users focus on privacy and security, such as data isolation granularity and access control. Cloud service providers optimize their service products based on the different security needs of application development service providers and end users, providing transparent and tiered services.
[0080] The way to match three-dimensional differentiated needs with safety level products is:
[0081] The cloud service data security level is divided into data security level, trusted cloud unit security level, trusted cloud unit sharing level, trusted cloud unit privacy level, and trusted cloud unit confidentiality level;
[0082] It should be further explained that data security levels are classified according to data security sensitivity in accordance with common international standards, and the data security levels include DSL5 (Top Secret), DSL4 (Confidential), DSL3 (Secret), DSL2 (Internal) and DSL1 (Public);
[0083] Among them, DSL (Data Security Level) refers to the data security level;
[0084] Trusted Cloud Unit Security Level (TCDUNx-TCDUN Security Degree): This refers to the minimum security level of all security mechanism components within the Trusted Cloud Unit (TCDUN), including the Trusted Cloud Root Mechanism Level (TCDKN), Isolation Mechanism Level (TCDIS), Access Control Mechanism Level (TCDAC), Authentication Mechanism Level (TCDCA), and the security level of the shared environment in which they are applied. TCDUNx represents the highest data security level (DSLx) that can actually be supported within the unit.
[0085] Trusted Cloud Unit Sharing Degree (TCDUNshx – TCD Sharing Unit Degree): This refers to the degree to which subunits (TCDSU) within a Trusted Cloud Unit (TCDUN) share data and applications. This also includes non-isolated subunits, such as traditional shared units or TCDUNsh1 units. The degree of sharing is proportional to the security risk; the higher the degree of sharing, the more data and applications are shared, and the higher the security risk.
[0086] Trusted Cloud Unit Privacy Degree (TCDPUx–TCDUN Privacy Degree): This refers to a special trusted cloud unit specifically designed to process and protect privacy-level data. The higher the privacy level, the stricter the restrictions on data sharing and use, which are inversely proportional to the sharing level.
[0087] Trusted Cloud Unit Confidentiality Level (TCDCUx–TCDUN Cnfidentiality Degree): refers to a special trusted cloud unit that is specifically used to perform computing tasks that require confidentiality protection and has a trusted cloud confidentiality level;
[0088] Based on three-dimensional differentiated needs, combined with the three data security levels of DSL3 (secret), DSL4 (confidential), and DSL5 (top secret), we match the corresponding TCDPCU3, TCDPCU4, and TCDPCU5 three-dimensional differentiated needs with security level equipment products;
[0089] It should be explained that the TCDP C U3 product series is designed to support cloud services that meet DSL3 data security requirements, providing enhanced data confidentiality and preliminary privacy protection capabilities. TCDP C U3 products have been optimized for cost-effectiveness, striving to meet basic compliance and security requirements while being compatible with existing trusted computing TPM 2.0 product hardware and software. They are suitable for cloud services in general business scenarios that are cost-sensitive but have certain concerns about data confidentiality and user privacy, such as non-core business system cloud services, internal office system cloud services, and low-sensitivity government information system cloud services. TCDP C U3 products are the core cornerstone for building economical and practical DSL3-level secure cloud services.
[0090] The TCDPCU4 product series is a premium privacy and confidentiality product designed to support cloud services that meet DSL4 data security requirements. Building on the TCDPCU3, it enhances the security strength of both hardware and software. The TCDPCU4 product series' general design goal is to achieve a balance between performance and cost while ensuring high levels of security and privacy. It is suitable for cloud services in core business scenarios that require security and privacy, such as cloud service platforms for core transaction systems in the financial industry, cloud service platforms for core electronic medical records in the healthcare industry, and cloud services for important government information systems. The TCDPCU4 product is a core component for building high-performance, highly secure DSL4-grade cloud services.
[0091] The TCDP C U5 product series is designed to support cloud services that meet DSL5 data security requirements, providing the highest levels of privacy, confidentiality, and security to mitigate security threats such as APT attacks and quantum computing cracking. Prioritizing ultimate security and privacy protection, this product line is suitable for cloud services in top-secret business scenarios with the highest security and privacy requirements, such as core infrastructure control systems, strategic resource management systems, command systems, and intelligence agency data centers. The TCDP C U5 product is the ultimate solution for building DSL5-level cloud services.
[0092] Step 2: Based on the security level product and the corresponding security level, the cloud service provider configures the security module for the security level product;
[0093] Targeted configuration of security modules based on matching security level products;
[0094] The security modules include: Trusted Cloud Root (TCDR) module, Trusted Cloud Kernel (TCDKN) module, Trusted Cloud Isolation (TCDIS) module, Trusted Cloud Access Control (TCDAC) module, and Trusted Cloud Authentication (TCDCA) module;
[0095] It should be explained that the Trusted Cloud Root (TCDR) module is used to establish the hardware and software root of trust and is the cornerstone of the entire trusted cloud security system. Different levels of TCDR modules use hardware and software roots of trust with different security levels.
[0096] Preferably, TCDPCU3 uses an economical TPM2.0 chip, TCDPCU4 uses a dedicated TCDM security chip or an economical HSM, and TCDPCU5 uses a customized quantum security chip and redundant HSM hardware and software cluster to provide hierarchical hardware and software trustworthiness assurance.
[0097] Trusted Cloud Kernel (TCDKN) module: used to enhance the security of the operating system kernel and provide kernel-level security assurance;
[0098] Preferably, different levels of TCDKN modules use different kernel hardening and security extension technologies. For example, TCDPCU3 uses TPM2.0 for kernel security extension, TCDPCU4 uses TCDM hardware and software acceleration and TEE technology, and TCDPCU5 uses dedicated security hardware and software and an optional formally verified microkernel operating system to provide graded kernel security protection capabilities.
[0099] Trusted Cloud Isolation (TCDIS) module: This includes the Trusted Cloud Intranet Isolation (TCDLAN) submodule and the Trusted Cloud Border Isolation (TCDBDR) submodule, which are used to implement internal network isolation and border isolation of cloud services, as well as to ensure network security.
[0100] Preferably, different levels of TCDIS modules use different network isolation technologies. For example, TCDPCU3 provides basic VLAN / ACL and virtual firewall / IDS isolation, TCDPCU4 provides trusted computing / ZTNA / micro-segmentation and virtual WAF / IPS / security situation awareness enhanced isolation, and TCDPCU5 provides the ultimate isolation solution of quantum security encryption / TEE / physical isolation network gatekeeper to build a hierarchical network security isolation system.
[0101] Trusted Cloud Access Control (TCDAC) module: used to implement user identity authentication, authorization management, and access control, enabling secure access to cloud service resources;
[0102] Preferably, different levels of TCDAC modules adopt different access control technologies. For example, TCDPCU3 provides MFA / RBAC / MAC preliminary access control, TCDPCU4 provides biometric MFA / multi-domain access control / UBA / ATI advanced access control, and TCDPCU5 provides zero-trust authentication / dynamic authorization / AI threat detection access control solutions to achieve hierarchical access control strength.
[0103] Trusted Cloud Certification and Authentication (TCDCA) module: used to provide certificate management, encryption algorithm support and security auditing to ensure the trusted authentication of cloud services;
[0104] Preferably, different levels of TCDCA modules adopt different authentication technologies. For example, TCDPCU3 provides internal CA / managed CA basic authentication services, TCDPCU4 provides third-party CA and high-intensity encryption algorithm enhanced authentication services, and TCDPCU5 provides customized quantum security authentication solutions and redundant HSM hardware and software security modules to build a hierarchical trusted authentication system.
[0105] Step 3: The cloud service provider selects and matches hardware and software confidentiality and privacy for application development service providers and end users based on the security level of the security level product;
[0106] The preferred hardware for the TCDPCU3 product for application development service providers is Intel XenBrze / AMD EPYC7001 series CPU, economical TPM2.0 chip and SATA SSD. The user side is equipped with a portable terminal with integrated TPM2.0 to balance cost and basic security.
[0107] TCDPCU3 software selection prioritizes a balance between fundamental security and cost. The TCDPCU3 operating system uses Linux Kernel 4.19 or Windows Server 2019 with a hardened kernel. Virtualization and networking utilize open-source components for basic isolation. TCDPCU3 identity and access management is based on an open-source IAM system with MFA support. Security monitoring relies on open-source log analysis and IDS. Encryption utilizes common algorithms such as AES-256-GCM. Certificate management utilizes internal or hosted CA services, adhering to common security standards.
[0108] TCDPCU4 hardware uses TEE-supported Intel Xen Silver / AMD EPYC7002 series CPUs, dedicated TCDM chips, and NVMe SSDs. Secure terminals are deployed on the end-user side, balancing performance and cost.
[0109] TCDPCU4 software selection enhances security capabilities, with the operating system supporting TEE technology and core security functions integrated into the TCDM chip. TCDPCU4's network and perimeter protection deploys a virtual WAF, IPS, and situational awareness platform. TCDPCU4's identity and access management integrates biometric MFA and strong MFA, introducing UBA and ATI. TCDPCU4 encryption algorithm upgrades mandate the use of third-party CA certificates, support zero-trust architecture components, and reserve space for future upgrades.
[0110] The TCDPCU5 hardware for application development service providers uses quantum security chips and redundant HSM clusters, and the end user side customizes quantum security terminals. The infrastructure adopts an air-gap physical isolation architecture.
[0111] The TCDPCU5 software selection focuses on ultimate security. The operating system is enforced by dedicated security hardware and uses a microkernel system with optional formal verification. The network and perimeter are isolated using dedicated hardware firewalls, IPS, and air gaps, integrated with APT defense systems, and implements zero trust for identity and access management, using quantum-safe authentication and AI / ML threat detection.
[0112] TCDPCU5 encryption uses a quantum-resistant algorithm, combined with a hardware HSM cluster, automatic certificate validity rotation, and 24 / 7 monitoring and response to the TCDPCU5 product's operating status, creating a more secure operating environment for DSL5-level cloud services and ensuring the continued secure and stable operation of cloud services.
[0113] It will be understood by those skilled in the art that selecting and matching hardware and software for application development service providers according to the security level of security products is conducive to achieving layered adaptation of hardware and software resources for confidential computing and user privacy protection of application development service providers.
[0114] Step 4: The cloud service provider determines the cloud service product type for the application development service provider and end user based on the end-to-end application scenario;
[0115] Among them, the end-to-end application scenario refers to the usage scenario corresponding to the two terminals of the application development service provider and the end user;
[0116] It should be explained that in order to support different application scenarios and user needs, the TCDPCU product and service system is further divided into three product types: terminal equipment (TCDPCU-E), cloud server equipment (TCDPCU-S) and cloud service facilities (TCDPCU-I);
[0117] TCDPCU-E (terminal equipment) emphasizes security and ease of use in mobile office scenarios, such as economical security terminals, high-performance security terminals, and quantum security terminals, used to build secure terminal access cloud services;
[0118] TCDPCU-S (Cloud Server Appliance) is suitable for building small and medium-sized cloud platforms or private cloud environments, such as economical cloud servers, high-performance secure cloud servers, and quantum secure cloud servers, and is used to provide computing and storage resources for cloud services.
[0119] TCDPCU-I (Cloud Service Infrastructure) is suitable for building large-scale cloud service infrastructure, such as economical cloud infrastructure, high-performance secure cloud infrastructure, and quantum secure cloud infrastructure. It is used to build and deliver different levels of enterprise-level IaaS, PaaS, and SaaS cloud services.
[0120] Preferably, cloud server equipment (TCDPCU-S) and cloud service facilities (TCDPCU-I) are provided to application development service providers. For example, TCDPCU3-S is used for small and medium-sized private clouds, TCDPCU5-S is used for data centers and cloud service facilities, and TCDPCU4-I is used to build financial / government cloud infrastructure, which can meet the confidential computing needs of application development service providers of different scales.
[0121] Provide terminal devices (TCDPCU-E) for end users, such as TCDPCU3-E suitable for basic privacy protection in mobile office scenarios, and TCDPCU5-E provides quantum security mobile phones for users with high privacy requirements, forming a hardware and software solution covering "terminal-server-infrastructure" and making end-to-end service boundaries explicit.
[0122] The technical solution of this embodiment is as follows: cloud service providers separate the three-dimensional differentiated needs of application development service providers and end users, and match security-grade products to these three differentiated needs. Based on the security-grade products and their corresponding security levels, cloud service providers configure security modules for these products. Cloud service providers select hardware and software for application development service providers based on the security levels of these products. Clear security, confidentiality, and privacy service standards are provided: the DSL3, DSL4, and DSL5 tiers, as well as the TCDPCU product series, provide clear and quantifiable security, confidentiality, and privacy standards for end users and cloud service providers. This standard covers multiple dimensions, making security capabilities measurable and comparable. It also enhances user choice: users can select the most appropriate TCDPCU-grade cloud service based on their data sensitivity, compliance requirements, and budget constraints, comparing it to the DSL tier standards. This enhances control and trust in cloud service security. It also promotes transparent competition in the cloud service market: the TCDPCU tier standards promote the establishment of a transparent competition mechanism based on security capabilities in the cloud computing service market. By clearly marking cloud service tiers, cloud service providers demonstrate their security capabilities, promote fairer market competition, and improve overall security in the industry.
[0123] Example 2
[0124] like Figure 2 As shown, a trusted cloud security confidentiality privacy three-dimensional product service method also includes the following steps:
[0125] Step 5: The cloud service provider deploys a dynamic policy adjustment mechanism to monitor abnormal access mechanisms of security-level products in real time, adaptively adjust protection policies according to level rules, and remotely verify security levels.
[0126] The dynamic policy adjustment mechanism includes:
[0127] S1. Real-time threat monitoring and response;
[0128] It should be explained that the TCDPCU series of security-level products deploy threat detection systems, such as intrusion detection systems (IDS), intrusion prevention systems (IPS), security information and event management (SIEM), security orchestration automation and response (SOAR) systems, and advanced threat detection systems based on artificial intelligence / machine learning (AI / ML). The system can continuously monitor the security situation of the application development service provider's cloud environment, detect and respond to various security threats in real time, and help mitigate security risks;
[0129] S2, dynamic security policy adjustment;
[0130] It should be explained that the TCDPCU security level product supports dynamic adjustment of security policies based on real-time security situation;
[0131] For example, when a cloud service provider detects abnormal traffic or suspicious attacks from an application development service provider, the security system can automatically trigger firewall rule updates and access control policy adjustments. Dynamic security policy adjustment capabilities enable cloud services to respond more flexibly and effectively to evolving network security threats.
[0132] S3, continuous security monitoring and auditing;
[0133] It should be explained that the TCDPCU security-level product series emphasizes the establishment of a security log audit system to record and audit the operating status of cloud services, user behavior, security incidents, etc. Through continuous analysis and monitoring of security logs, potential security issues can be discovered in a timely manner, the root causes of security incidents can be traced, and data support can be provided for subsequent security improvements.
[0134] The higher-level TCDPCU4 / 5 provides advanced security auditing and logging systems, as well as security situation awareness capabilities, which facilitate a more intelligent and comprehensive understanding of the security status of cloud services.
[0135] S4, Active Defense and Threat Intelligence;
[0136] It should be explained that the TCDPCU series, especially the TCDPCU4 and TCDPCU5, can apply active defense and threat intelligence. By integrating advanced threat intelligence (ATI), cloud services can provide early warning of potential security threats and take proactive defense measures.
[0137] In TCDPCU5, an APT defense system is deployed to deal with covert advanced persistent threats;
[0138] S5. Application of zero-trust security architecture;
[0139] It's important to note that both TCDPCU4 and TCDPCU5 incorporate the application of a zero-trust security architecture, emphasizing the principle of "never trust, always verify." Under a zero-trust architecture, any end user, device, or application accessing cloud service resources must undergo strict authentication and authorization, and access rights are dynamically and continuously evaluated and adjusted. This zero-trust security philosophy effectively reduces the risk of internal contamination and unauthorized access, enhancing the overall security resilience of cloud services.
[0140] Provide third-party security audit reports to application development service providers and end users through dynamic policy adjustment mechanisms and remote verification of security levels;
[0141] The remote verification security level is as follows:
[0142] SS1. Cloud service providers clearly identify the TCDPCU security level product series and DSL security level on their products and services;
[0143] Preferably, cloud service providers prominently mark the TCDPCU product series (such as TCDPCU3 / 4 / 5) and its corresponding DSL security level (DSL3 Confidentiality Enhanced, DSL4 Advanced Confidential, DSL5 Extreme Confidential) on product documentation, service interfaces, and physical devices to clearly distinguish the security capability boundaries of different services. This explicit identification helps users quickly identify the confidentiality, privacy protection strength, and applicable scenarios of the service—for example, TCDPCU3 is suitable for basic security of general services, while TCDPCU5 is suitable for extreme protection of top-secret data. This reduces user selection costs, enhances service transparency and trust, and at the same time establishes a unified security level recognition standard for the industry, promoting standardized market competition.
[0144] SS2. The cloud service provider provides a verifiable security configuration checklist;
[0145] Preferably, cloud service providers provide security configuration lists for different TCDPCU product series, including detailed information such as hardware and software selection (such as TPM2.0 chip for TCDPCU3 and quantum security chip for TCDPCU5), core security module technology implementation (such as trusted kernel hardening solution and encryption algorithm suite), and network isolation strategy (such as VLAN division and physical isolation network gatekeeper deployment). The security configuration list is digitally signed or stored on the blockchain. Users and auditing agencies can verify the consistency of the configuration with the declared security level through official channels, ensuring that service delivery is consistent with design standards. This provides a direct basis for compliance audits and risk assessments, solving the problem of opaque and difficult to trace security configuration of traditional cloud services.
[0146] SS3. Cloud service providers provide third-party security audit reports;
[0147] Preferably, cloud service providers regularly entrust qualified third-party organizations (such as CNAS-certified evaluation centers) to conduct comprehensive audits of the security functions, encryption strength, access control mechanisms, etc. of TCDPCU products, and generate audit reports that include compliance assessments (such as compliance with PCI DSS and ISO27001 standards), vulnerability scanning results, and penetration testing conclusions. The reports disclose key security indicators (such as data encryption transmission rate and privileged account control rate) to verify the security capabilities of the service from an independent perspective, make up for the evaluation blind spots caused by insufficient user technical capabilities, enhance service credibility, and especially meet the needs of industries such as finance and government affairs that have mandatory requirements for third-party certification;
[0148] SS4, cloud service providers support remote trusted verification;
[0149] Preferably, cloud service providers open remote verification interfaces (such as trusted reporting interfaces based on TCG standards and REST API security endpoints) through encrypted channels, allowing users or regulatory agencies to verify the security status of cloud services in real time—for example, verifying the integrity of the server boot chain through the PCR value of the hardware and software root of trust (TPM / HSM), and querying the real-time effectiveness of access control policies through APIs. Remote verification technology supports cross-regional and cross-network security capability verification, adapts to multi-cloud architectures and remote office scenarios, ensures that the security configuration of the service has not been tampered with during runtime, and achieves dynamic alignment of the "declared security level" and the "actual operational security level," solving the problem of invisible security status of traditional remote services.
[0150] SS5,Cloud service providers provide real-time security monitoring dashboards;
[0151] Preferably, cloud service providers provide users with a visual, real-time security monitoring dashboard that dynamically displays the security status of TCDPCU services, including but not limited to: data encryption link status (such as the number of SSL / TLS connections and quantum encryption channel utilization), abnormal access event alerts (such as MFA failures and unauthorized access attempts), and security module operation status (such as HSM cluster load and TEE environment integrity). The dashboard supports customizable alert thresholds and notification policies. Users can track the progress of security incident responses in real time and analyze security trends in combination with historical logs to proactively manage the security status of cloud services, improve threat response efficiency, and meet real-time security supervision and business continuity requirements.
[0152] Example 3
[0153] like Figure 4 As shown, a trusted cloud security confidentiality privacy three-dimensional product service method also includes the following steps:
[0154] Step 6: Quantitatively analyze the three-dimensional needs to obtain three-dimensional quantitative indicators, map the three-dimensional quantitative indicators to the corresponding relationship between the levels, and establish a monitoring matching benchmark library;
[0155] Among them, the method of quantitatively analyzing the three-dimensional needs to obtain three-dimensional quantitative indicators is as follows:
[0156] Transform the abstract requirements of confidentiality, privacy, and security into measurable concrete indicators and quantify them numerically, i.e., three-dimensional quantitative indicators;
[0157] It should be explained that confidentiality focuses on the core needs of application development service providers, breaking them down into indicators such as data encryption strength (such as transmission / storage encryption algorithms and key lengths), kernel security technology (such as hardware root of trust type and kernel hardening level), and commercial data isolation solutions (such as logical / physical isolation technologies). Benchmark values are set according to DSL3 / 4 / 5 levels (for example, DSL5 requires quantum-resistant encryption algorithms and physical air-gap isolation).
[0158] Privacy is centered around end-user needs and broken down into indicators such as data isolation granularity (such as RBAC / ABAC / zero-trust authorization), privacy data usage restrictions (such as the proportion of prohibited items collected without necessary data), and sharing transparency (such as log record coverage and evidence storage methods). Different levels of privacy protection strength are clearly defined (for example, DSL5 prohibits any collection of unnecessary privacy data and requires blockchain evidence storage).
[0159] Security, as a universal requirement, is broken down into indicators such as threat response speed (e.g., time to identify abnormal traffic), security audit coverage (e.g., completeness of privileged account operation records), and disaster recovery capabilities (e.g., data recovery time objectives). Technical thresholds are set by level (e.g., DSL5 requires blocking abnormal traffic within 5 seconds and 100% audit log coverage). Through the construction of a three-level indicator system, a quantitative benchmark covering technical implementation, user perception, and risk prevention and control is formed, providing a verifiable measurement basis for security level matching.
[0160] Among them, the mapping analysis method of the correspondence between the three-dimensional quantitative indicators and the grades is as follows:
[0161] With the TCDPCU safety level products as the X-axis and the three-dimensional demand indicators as the Y-axis, a mapping matrix is constructed to determine the threshold value of each technical indicator of each safety level product;
[0162] Those skilled in the art will understand that technical indicators refer to the corresponding technical features in the TCDPCU security level products, such as the kernel security technology and data encryption algorithm in confidentiality;
[0163] For example, TCDPCU3: covers DSL3 level requirements, confidentiality indicators meet basic encryption and logical isolation, privacy indicators meet RBAC permissions and basic shared logs, and security indicator thresholds meet 30-second response and 90% audit coverage.
[0164] TCDPCU5: covers DSL level 5 requirements. Its confidentiality requirements include quantum security chips and physical isolation, privacy requirements include zero-trust authorization and blockchain evidence storage, and security requirements include a 5-second response time and 100% audit coverage.
[0165] Based on the technical indicator thresholds of each security level product and three-dimensional demand indicators, a monitoring matching benchmark library is constructed.
[0166] Step 7: The cloud service provider collects bidirectional data for demand matching and performs three-dimensional mapping analysis on the bidirectional data to obtain the three-dimensional demand matching degree and determine whether the demand matching is implemented;
[0167] Among them, the cloud service provider's two-way data collection method for demand matching is:
[0168] Preferably, the cloud service provider divides the two-way data collection into the technical side and the user side. The technical side obtains the technical configuration data of the application development service provider, and the user side obtains the end-user demand data.
[0169] The technical side collects in real time the hardware configuration (such as TPM chip model and HSM cluster status) and software and security module operation data (such as encryption algorithm configuration and access control policy logs) of the security-grade products used by application development service providers. This data is used to ensure configuration compliance through API interfaces and trusted remote verification technology.
[0170] Provide questionnaires, work order analysis, resource usage logs to collect end-user demand satisfaction, as well as privacy-related behavior data (such as client SDK behavior records, privacy setting modifications, and data subject rights request processing efficiency) and feedback forms as user demand data on the user side;
[0171] Construct a three-dimensional matching model, input the application development service provider's technical configuration data and end-user demand data, as well as the monitoring and matching benchmark library into the three-dimensional matching model for three-dimensional mapping analysis, and map the application development service provider's technical configuration data and user demand data to the three-dimensional space of confidentiality, privacy, and security corresponding to the monitoring and matching benchmark library;
[0172] The three-dimensional matching model is constructed as follows:
[0173] A1. Data preprocessing module construction;
[0174] Among them, the data preprocessing module is constructed as follows:
[0175] Preferably, the technical configuration data of the application development service provider and the end-user demand data are cleaned to remove duplicate, erroneous and incomplete data records;
[0176] For example, in the technical configuration data, if there is repeated entry of hardware equipment information or missing key parameters, corresponding deletion or supplementation will be carried out; invalid feedback consisting of garbled characters or incorrectly formatted text in the user demand data will be eliminated;
[0177] Normalize the numerical data in the application development service provider's technical configuration data and end-user demand data;
[0178] Numerical processing of non-numeric data in the application development service provider's technical configuration data and end-user demand data;
[0179] For example, the numerical data of server response time and data encryption key length are mapped to the interval [0, 1] using the Min-Max normalization method;
[0180] A2. Construction of three-dimensional space mapping module;
[0181] The construction of the three-dimensional mapping module includes: the construction of mapping rules and mapping relationships;
[0182] It needs to be explained that the data mapping rules are determined based on the definition of confidentiality, privacy and security indicators in the monitoring and matching benchmark library;
[0183] For example, if the benchmark library specifies that the selection of a data encryption algorithm at a specific security level is a confidentiality indicator, the encryption algorithm actually used by the application development service provider is mapped to the confidentiality dimension;
[0184] If user demand data involves restrictions on the scope of personal data sharing, it is mapped to the privacy dimension; and data related to the system's ability to detect and defend against external attacks is mapped to the security dimension;
[0185] Map the pre-processed data into the three-dimensional space of confidentiality, privacy and security according to the mapping rules;
[0186] Exemplarily, the mapping relationship of technical configuration data is constructed by mapping data such as hardware root of trust type, encryption algorithm strength, and data storage isolation method to corresponding indicators of the confidentiality dimension;
[0187] Mapping user data access rights control, data sharing record integrity and other data to the privacy dimension;
[0188] Mapping data such as intrusion detection system performance and system vulnerability repair timeliness to security dimensions;
[0189] A3. Construction of demand matching calculation module;
[0190] Based on the constructed three-dimensional mapping space, the numerical data corresponding to the technical configuration data of the application development service provider and the end-user demand data are used as actual values, and the reference values of the three dimensions in the monitoring matching benchmark library corresponding to the actual values in the three-dimensional mapping space are obtained respectively;
[0191] The Euclidean distance between the actual value and the reference value of the three dimensions is calculated to obtain the demand matching degree of the three dimensions;
[0192] The three-dimensional demand matching degree is obtained by weighted summing the demand matching degrees of the three dimensions;
[0193] It should be explained that the weights of the weighted calculation of the three-dimensional demand matching are calculated by the technical indicator thresholds of each security level product; the technical indicator thresholds of each security level product (such as the specific parameter requirements of confidentiality, privacy, and security for DSL3 / 4 / 5) are weighted according to the importance of the indicators to cloud service security. When calculating the three-dimensional space demand matching, the indicator matching within each dimension (such as the encryption algorithm strength under confidentiality, kernel security technology, and other indicators) are first weighted and summed according to the corresponding threshold weights, and then weights are assigned based on the overall importance of the three dimensions (such as setting confidentiality weights of 0.4, privacy weights of 0.3, and security weights of 0.3 based on industry needs). Finally, the comprehensive demand matching is obtained through double weighted summation, which quantifies the degree of matching between technical configuration and user needs with the benchmark library, providing data support for level classification;
[0194] Calculate the three-dimensional demand matching degree from the three-dimensional matching model, and divide the three-dimensional demand matching degree into different demand matching levels;
[0195] Among them, the demand matching level includes complete implementation level, incomplete implementation level, and no implementation level;
[0196] For example, application development service provider A uses the TCDPCU Level 4 cloud service. Its technical configuration "Data Encryption Algorithm" actually uses AES-256 but does not enable TLS1.3. The matching degree with the DSL4 standard requirement of AES-256-GCM+TLS1.3 in the monitoring matching benchmark library is 0.8.
[0197] In terms of kernel security technology, if an application development service provider uses TEE technology but the hardware version is lower than the benchmark requirement, the matching degree is 0.7. Based on the DSL4 confidentiality indicator threshold, the indicator weight ratio is set to 50% each, and the confidentiality dimension matching degree is calculated as follows: confidentiality matching degree = [(0.8\0.5)+(0.7\0.5)] = 0.75;
[0198] A matching degree of ≥0.9 indicates full implementation. For example, a government cloud service deploys quantum-resistant encryption algorithms and quantum security chips in strict accordance with the DSL5 standard, with a matching degree of 0.95, meeting the highest confidentiality requirements.
[0199] A match of 0.6 ≤ or less than 0.9 indicates incomplete implementation. In the example, application development service provider A has a match of 0.75, indicating that the encryption algorithm and kernel security technology partially meet the standards but have room for improvement (e.g., TLS 1.3 is not enabled or the hardware version is insufficient), thus categorizing this as incomplete implementation.
[0200] A matching degree of less than 0.6 indicates a completely unimplemented level: If a cloud service provided by a small or medium-sized manufacturer uses only basic encryption algorithms, resulting in a confidentiality matching degree of 0.5, and does not deploy a hardware root of trust, the security matching degree is 0.4. The weighted matching degree is 0.45, which is far below the DSL3 benchmark and is judged to be completely unimplemented.
[0201] Step 8: If demand matching is not fully implemented, conduct three-level cross-validation based on historical data to identify demand mismatch risks and develop a mismatch response mechanism;
[0202] If demand matching is not fully achieved, historical technical configuration data and user demand data can be obtained from the application development service provider's server logs;
[0203] Conduct three-level cross-validation based on historical technical configuration data and user demand data to identify demand mismatch risks;
[0204] Among them, the three-level cross-validation method to locate mismatch risk is as follows:
[0205] B1. Indicator verification;
[0206] Preferably, various indicators in the current technical configuration and user requirements are compared with indicators in the same or similar scenarios in historical data;
[0207] For example, in the confidentiality dimension, indicators such as the type of data encryption algorithm and key length are compared; in the privacy dimension, indicators such as user data access rights and data sharing scope are compared;
[0208] Use quartiles and isolation forest algorithms to detect whether there are anomalies in the current indicators. If the distribution of a certain indicator differs significantly from historical data, it will be marked as a potential mismatch risk point.
[0209] Those skilled in the art will appreciate that the quartile method determines the normal range by using the quantiles of the data distribution and is applicable to single-dimensional indicators (such as "data encryption key length"). The quartile method calculates the 25th percentile (Q1), 75th percentile (Q3), and interquartile range (IQR = Q3 - Q1) of historical data, using Q1 - 1.5 × IQR and Q3 + 1.5 × IQR as the upper and lower bounds of the abnormal value. If the current indicator value exceeds this range, it is marked as abnormal.
[0210] For example, in a DSL4-level cloud service, the historical key length is 256 bits. The calculated values are Q1 = 256 bits, Q3 = 256 bits, IQR = 0, and the lower bound = 256-0 = 256 bits. If the current detected key length is 192 bits (lower than the lower bound), it means that the baseline requirement is not met and is marked as "Insufficient Encryption Strength" as a mismatch risk point.
[0211] Isolation Forest isolates samples by building a decision tree. Outliers have fewer splits due to their rare feature combinations, making the path shorter. Complex anomalies are identified by calculating anomaly scores (0-1, the closer to 1, the more abnormal).
[0212] Isolation Forest encodes and standardizes multiple indicators (such as "encryption algorithm type + key length + hardware trust root"), then randomly splits features, recursively isolates samples, and finally calculates the anomaly score by integrating the path lengths of multiple trees through a formula;
[0213] B2, Dimension Verification;
[0214] Preferably, the performance of each indicator in the three dimensions of confidentiality, privacy, and security is comprehensively considered, and the difference between the current dimension matching degree and the historical dimension matching degree is calculated;
[0215] Exemplarily, the difference between the current confidentiality dimension matching degree and the historical average confidentiality dimension matching degree is calculated as the difference between the current dimension matching degree and the historical dimension matching degree;
[0216] By calculating the Spearman correlation coefficient of different dimensions, we can analyze the correlation between different dimensions and determine whether the mismatch of a certain dimension affects the matching of other dimensions.
[0217] It should be explained that when analyzing the correlation between different dimensions, the matching degree of each dimension is converted into a rank (a ranking sorted from high to low) to eliminate the dimensionality effect and adapt to non-normal distribution data (such as the unit difference between "threat response time" and "privacy data isolation granularity" in cloud services;
[0218] If the Spearman coefficient between confidentiality and security is 0.8, it indicates that the two dimensions are strongly correlated, indicating that insufficient confidentiality (such as low-level encryption algorithms) is often accompanied by reduced security (such as delayed vulnerability repairs), and there is a mismatch transmission effect between dimensions;
[0219] If the coefficient of privacy and confidentiality is -0.5, which is a moderate negative correlation, it may indicate that excessive confidentiality protection (such as strict data isolation) makes private data inconvenient to use, and a balance between the two configurations is needed;
[0220] By exploring the monotonic correlation between dimensions, we can identify the cross-dimensional impact path of mismatch risk (such as the "confidentiality → security" transmission chain), providing a basis for systematic optimization.
[0221] B3, scenario verification;
[0222] Preferably, the corresponding business scenario is identified based on the current technical configuration and user needs, and similar scenarios are found from historical data. For example, it can be identified as a financial business scenario, a medical business scenario, or an e-commerce business scenario;
[0223] Compare the demand matching situation in the current scenario with the matching results of similar historical scenarios to assess whether there is a special mismatch risk in the current scenario. If so, determine the compliance weight of the scenario;
[0224] For example, in financial business scenarios, the requirements for security and privacy are usually high. If the current matching degree is lower than that of similar historical scenarios, it requires special attention;
[0225] Based on the results of the three-level cross-validation, potential mismatch risk points are ranked and prioritized;
[0226] It should be explained that the three-level cross-validation results are used to sort and prioritize potential mismatch risk points, which requires a comprehensive consideration of the degree of indicator abnormality, the impact of dimension correlation, and the specificity of the scenario;
[0227] The potential mismatch risk points are ranked and prioritized as follows:
[0228] C1. Identify single or multiple indicator combination anomalies (such as substandard key length or missing hardware root of trust) through indicator verification, and quantify the risk value based on the anomaly score;
[0229] C2, Dimension Verification: Analyze cross-dimensional transmission effects (e.g., insufficient confidentiality may lead to decreased security) through the Spearman correlation coefficient. If there is a cross-dimensional transmission effect, take the absolute value of the Spearman correlation coefficient to obtain the scenario dimension value.
[0230] C3. Scenario Verification: Based on the characteristics of business scenarios, technical personnel in this field, based on their experience, make weighted adjustments to risk points that are adapted to the compliance requirements of specific industries to obtain scenario compliance weights.
[0231] Calculate the comprehensive risk score by constructing a risk matrix that includes anomaly scores, scenario dimension values, and scenario compliance weights;
[0232] For example: Risk score = anomaly severity × dimension impact coefficient × scenario compliance weight. Sort by score from high to low, and prioritize high-scoring risk points.
[0233] For example, if quantum security chips are not deployed in DSL5 services or privacy data is excessively collected in financial scenarios, limited resources should be focused on key mismatch issues to achieve efficient and targeted risk management.
[0234] Obtain the highest priority risk points and formulate mismatch response mechanism strategies;
[0235] It should be noted that the mismatch response mechanism includes short-term response measures and long-term response measures;
[0236] For urgent mismatch risks, temporary emergency repair measures are implemented to ensure the normal operation of the system and data security. For example, if a security vulnerability is discovered that causes a decrease in the security dimension match, a security patch is immediately deployed to repair it.
[0237] Conduct root cause analysis on the highest priority risk points, determine the results of the root cause analysis, formulate technical optimization plans, and adjust and improve technical configurations, such as upgrading encryption algorithms and optimizing access control policies.
[0238] The technical solution of this embodiment is: quantitatively analyze the three-dimensional demands to obtain three-dimensional quantitative indicators, map and analyze the correspondence between the three-dimensional quantitative indicators and the levels, and establish a monitoring and matching benchmark library; the cloud service provider collects two-way data for demand matching, and performs three-dimensional mapping analysis on the two-way data collection to obtain the three-dimensional demand matching degree and determine whether the demand matching is implemented; if the demand matching is not fully implemented, a three-level cross-validation is performed in combination with historical data to locate the demand mismatch risk and formulate a mismatch response mechanism; this improves the accuracy of demand matching and dynamic security protection capabilities, and provides cloud service providers with a quantifiable, traceable, and optimizable three-dimensional demand matching technical solution.
[0239] Example 4
[0240] like Figure 4 As shown, a trusted cloud security, confidentiality and privacy three-dimensional product service system includes the following modules:
[0241] Demand separation module: Cloud service providers separate the three-dimensional differentiated demands of application development service providers and end users, and match the three-dimensional differentiated demands with security-level products;
[0242] Security configuration module: Based on the security level products and corresponding security levels, the cloud service provider configures security modules for security level products;
[0243] Hardware and software selection module: Cloud service providers select and match hardware and software confidentiality and privacy for application development service providers and end users based on the security level of security products;
[0244] Product determination module: Cloud service providers determine cloud service product types for application development service providers and end users based on end-to-end application scenarios;
[0245] Policy deployment module: Cloud service providers deploy dynamic policy adjustment mechanisms to monitor abnormal access mechanisms of security-level products in real time, adaptively adjust protection policies according to level rules, and remotely verify security levels;
[0246] Monitoring quantification module: used to quantitatively analyze three-dimensional requirements to obtain three-dimensional quantitative indicators, map and analyze the corresponding relationship between three-dimensional quantitative indicators and levels, and establish a monitoring matching benchmark library;
[0247] Landing matching module: This module is used by cloud service providers to collect two-way data for demand matching and perform three-dimensional mapping analysis on the two-way data collection to obtain the three-dimensional demand matching degree and determine whether the demand matching has been implemented.
[0248] Verification and response module: If the demand matching is not fully implemented, it is used to perform three-level cross-validation in combination with historical data, locate the demand mismatch risk, and formulate a mismatch response mechanism.
[0249] The basic principles, main features, and advantages of the present invention are shown and described above. Those skilled in the art should understand that the present invention is not limited to the foregoing embodiments. The foregoing embodiments and descriptions are merely illustrative of the principles of the present invention. Various changes and modifications may be made to the present invention without departing from the spirit and scope of the present invention. Such changes and modifications are intended to fall within the scope of the present invention. The scope of protection claimed in the present invention is defined by the appended claims and their equivalents.
Claims
1. A trusted cloud security, confidentiality and privacy three-dimensional product service method, characterized by: The steps include: Cloud service providers separate the three-dimensional differentiated needs of application development service providers and end users, and match security-level products to these three-dimensional differentiated needs; Cloud service providers configure security modules specifically for security-level products; Cloud service providers determine the types of cloud service products for application development service providers and end users based on end-to-end application scenarios; Cloud service providers select and match hardware and software confidentiality and privacy for application development service providers and end users based on the security level of the security level products; Cloud service providers deploy dynamic policy adjustment mechanisms to monitor abnormal access mechanisms of security-level products in real time, adaptively adjust protection strategies according to level rules, and remotely verify three-dimensional security levels.
2. A trusted cloud security, confidentiality and privacy three-dimensional product service method according to claim 1, characterized by: The method of matching the three-dimensional differentiated demand with the safety level product is: Divide cloud service data into different security levels, combine the three-dimensional differentiated needs of application development service providers and end users, and achieve matching of security level equipment products.
3. The trusted cloud security, confidentiality and privacy three-dimensional product service method according to claim 1, characterized in that: The security module includes: Trusted cloud root module, trusted cloud kernel module, trusted cloud isolation module, trusted cloud access control module, and trusted cloud verification module.
4. The trusted cloud security, confidentiality and privacy three-dimensional product service method according to claim 1, characterized in that: The method of deploying the dynamic policy adjustment mechanism is: Real-time threat monitoring and response, dynamic security policy adjustment, continuous security monitoring and auditing, proactive defense and threat intelligence; Through dynamic policy adjustment mechanism and remote verification of security level, third-party security audit reports are provided to application development service providers and end users.
5. A trusted cloud security, confidentiality and privacy three-dimensional product service method according to claim 4, characterized in that: The method of remotely verifying the security level is: The cloud service provider clearly identifies the TCDPCU security level product series and DSL security level on its products and services; The cloud service provider provides a verifiable security configuration checklist; The cloud service provider provides a third-party security audit report; Cloud service providers support remote trusted verification; Cloud service providers provide real-time security monitoring dashboards; Among them, DSL is the data security level and TCDPCU is the trusted cloud security privacy unit.
6. The trusted cloud security, confidentiality and privacy three-dimensional product service method according to claim 1, characterized in that: The following steps are also included: Quantitatively analyze the three-dimensional needs to obtain three-dimensional quantitative indicators, map and analyze the corresponding relationship between the three-dimensional quantitative indicators and the levels, and establish a monitoring matching benchmark library; The cloud service provider collects two-way data for demand matching and performs three-dimensional mapping analysis on the two-way data collection to obtain the three-dimensional demand matching degree and determine whether the demand matching is implemented; If demand matching is not fully implemented, three-level cross-validation will be conducted in combination with historical data to locate demand mismatch risks and develop a mismatch response mechanism.
7. A trusted cloud security, confidentiality and privacy three-dimensional product service method according to claim 6, characterized in that: The method of performing three-dimensional mapping analysis on bidirectional data acquisition is: Cloud service providers divide bidirectional data collection into the technical side and the user side. The technical side obtains the technical configuration data of the application development service provider, and the user side obtains the end-user demand data. Construct a three-dimensional matching model, input the application development service provider's technical configuration data and end-user demand data, as well as the monitoring and matching benchmark library into the three-dimensional matching model for three-dimensional mapping analysis, and map the application development service provider's technical configuration data and user demand data to the three-dimensional space of confidentiality, privacy, and security corresponding to the monitoring and matching benchmark library; The three-dimensional demand matching degree is calculated from the three-dimensional matching model, and the three-dimensional demand matching degree is divided into different demand matching levels.
8. A trusted cloud security, confidentiality and privacy three-dimensional product service method according to claim 7, characterized in that: The three-dimensional matching model is constructed as follows: Data preprocessing module construction: preprocess the technical configuration data of application development service providers and end-user demand data and convert non-numeric data into numerical data; Construction of the three-dimensional spatial mapping module: Determine the data mapping rules and mapping relationships based on the definition of confidentiality, privacy, and security indicators in the monitoring and matching benchmark library; Demand matching calculation module construction: Based on the constructed three-dimensional mapping space, the numerical data corresponding to the technical configuration data of the application development service provider and the end-user demand data are used as actual values, and the reference values of the three dimensions in the monitoring matching benchmark library corresponding to the actual values in the three-dimensional mapping space are obtained respectively; The Euclidean distance between the actual value and the reference value of the three dimensions is calculated to obtain the demand matching degree of the three dimensions; The three-dimensional demand matching degree is obtained by performing weighted summation processing on the demand matching degrees of the three dimensions.
9. The trusted cloud security, confidentiality and privacy three-dimensional product service method according to claim 6, characterized in that: The method of performing three-level cross validation in combination with historical data is: Indicator verification; Compare various indicators in current technical configuration and user needs with indicators in the same or similar scenarios in historical data to identify potential mismatch risk points; Dimensional validation; By calculating the Spearman correlation coefficient of different dimensions, we can analyze the correlation between different dimensions and determine whether the mismatch of a certain dimension affects the matching of other dimensions. Scenario verification; Compare the demand matching situation in the current scenario with the matching results of similar historical scenarios to assess whether there is any special mismatch risk in the current scenario; Based on the results of the three-level cross-validation, potential mismatch risk points are ranked and prioritized; Obtain the highest priority risk points and formulate mismatch response mechanism strategies.
10. A trusted cloud security, confidentiality, and privacy three-dimensional product service system, used to implement the trusted cloud security, confidentiality, and privacy three-dimensional product service method according to any one of claims 1 to 9, characterized in that: Includes the following modules: Demand separation module: Cloud service providers separate the three-dimensional differentiated demands of application development service providers and end users, and match the three-dimensional differentiated demands with security-level products; Security configuration module: Based on the security level products and corresponding security levels, the cloud service provider configures security modules for security level products; Hardware and software selection module: Cloud service providers select and match hardware and software confidentiality and privacy for application development service providers and end users based on the security level of security products; Product determination module: Cloud service providers determine cloud service product types for application development service providers and end users based on end-to-end application scenarios; Policy deployment module: Cloud service providers deploy dynamic policy adjustment mechanisms to monitor abnormal access mechanisms of security-level products in real time, adaptively adjust protection policies according to level rules, and remotely verify security levels; Monitoring quantification module: used to quantitatively analyze three-dimensional requirements to obtain three-dimensional quantitative indicators, map and analyze the corresponding relationship between three-dimensional quantitative indicators and levels, and establish a monitoring matching benchmark library; Landing matching module: This module is used by cloud service providers to collect two-way data for demand matching and perform three-dimensional mapping analysis on the two-way data collection to obtain the three-dimensional demand matching degree and determine whether the demand matching has been implemented. Verification and response module: If the demand matching is not fully implemented, it is used to conduct three-level cross-validation in combination with historical data, locate the demand mismatch risk, and formulate a mismatch response mechanism.
Citation Information
Cited By
Internet of Things data secure transmission method and system based on association modeling
CN121000473A
An internet of things data security transmission method and system based on association modeling
CN121000473B
Trusted cloud native security level treatment system and method
CN121585481A
Trusted cloud level standardization framework system and quantitative mapping method
CN121585482A
Automatic and hierarchical trusted cloud level management unit system and method
CN121616244A