Trusted management and control network platform construction method and device, electronic equipment and storage medium

By building a trusted management and control network platform, the problem of existing information security systems being unable to prevent external attacks and internal vulnerabilities has been solved. Dynamic and proactive security protection has been achieved, enhancing network security and data transmission reliability, and improving system compatibility and operational efficiency.

CN120934918APending Publication Date: 2025-11-11SHENZHEN Y& D ELECTRONICS CO LTD

Patent Information

Application Number
CN202511466863.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-14
Publication Date
2025-11-11

AI Technical Summary

Technical Problem

Existing information security systems are unable to effectively prevent external attacks and internal vulnerabilities, cannot predict future attacks, and cannot fundamentally solve operating system security problems, leading to data leaks and unauthorized access.

Method used

Construct a trusted management and control network platform, including basic security architecture and trusted foundation, multi-dimensional trusted verification and dynamic access control, intelligent boundary protection and deep detection system, unified secure communication tunnel and cross-domain transmission guarantee, standardized security function interfaces and collaborative protocols, and continuous trust assessment and automated operation and management closed loop, forming a dynamic and proactive security protection mechanism.

Benefits of technology

It enhances the overall security of the network, ensures the confidentiality and integrity of data transmission, improves the compatibility and collaboration of the system, realizes intelligent security operation, reduces the cost of manual intervention, and provides comprehensive security protection.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120934918A_ABST
    Figure CN120934918A_ABST
Patent Text Reader

Abstract

The invention belongs to the field of network security, and relates to a trusted management and control network platform construction method and device, electronic equipment and a storage medium, the method comprises the following steps: constructing a basic security architecture and a trusted base, the basic security architecture being used for providing a unified root of trust and a management core for collaborative operation of upper security components; based on the basic security architecture and the trusted base, implementing multi-dimensional trusted verification and dynamic access control; an intelligent boundary protection and depth detection system is deployed and is used for constructing an intelligent, three-dimensional and self-adaptive security defense line at the boundary of each region of the network, and various known and unknown threats can be identified and blocked; constructing a unified secure communication tunnel and a cross-domain transmission guarantee; defining and realizing a standardized security function interface and a collaboration protocol; and a continuous trust evaluation and automatic operation management and control closed loop is established. The overall security is enhanced, the secure transmission of data is ensured, the compatibility and collaboration of the system are improved, and the security operation intelligence is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security technology, and in particular to a method, apparatus, electronic device, and storage medium for constructing a trusted management network platform. Background Technology

[0002] Most current information security systems consist mainly of firewalls, intrusion detection, and virus prevention.

[0003] Conventional security measures only defend the network layer (IP), blocking unauthorized users and access from the perimeter to prevent external attacks. A typical example is the IP / MAC binding security policy adopted for terminal network access, where attackers bypass security checks by forging legitimate IP and MAC addresses to carry out malicious activities. Lack of control over the source end (client machine) of access users allows for the unrestricted sharing of information resources. For example, to facilitate daily maintenance, a series of high-risk applications, including FTP services, file servers, and WebSQL, are often self-built. Attackers can easily obtain weak passwords through brute-force attacks and dictionary attacks, gaining unauthorized access to business systems, such as identity impersonation and privilege escalation. Insecure operating systems lead to numerous vulnerabilities in application systems, which cannot be fundamentally resolved. Blocking methods capture the characteristic information of hacker attacks and virus intrusions, but this information is delayed and cannot scientifically predict future attacks and intrusions, nor can it prevent operational-level problems. Summary of the Invention

[0004] To address the aforementioned technical problems, this invention provides a method for constructing a trusted management and control network platform, employing the following technical solution, including the following steps: Construct a basic security architecture and a trusted foundation, wherein the basic security architecture is used to provide a unified root of trust and management core for the collaborative operation of upper-layer security components; Based on the aforementioned basic security architecture and trusted foundation, multi-dimensional trusted verification and dynamic access control are implemented. Deploy an intelligent boundary protection and deep detection system to build an intelligent, three-dimensional, and adaptive security defense line at the boundaries of various network areas, capable of identifying and blocking various known and unknown threats; Construct a unified secure communication tunnel and cross-domain transmission guarantee to ensure that data remains confidential and intact throughout the entire network transmission process, especially when crossing different trust domains; Define and implement standardized security function interfaces and collaboration protocols to solve data communication problems between heterogeneous security components through standardized protocols; Establish a closed loop of continuous trust assessment and automated operation and management to transform security protection from a static, passive model to a dynamic, proactive model based on continuous monitoring and automated response.

[0005] Preferably, the step of constructing a basic security architecture and a trusted foundation, wherein the basic security architecture provides a unified root of trust and a management core for the collaborative operation of upper-layer security components, specifically includes: Construct a three-layer architecture consisting of a computing power management and control network, a control network, and a service network; A SQY20 cryptographic service system based on national cryptographic algorithms is deployed on the three-layer architecture of computing power management network, control network and business network; Build a centralized security management and control center platform.

[0006] Preferably, the steps of implementing multi-dimensional trusted verification and dynamic access control based on the basic security architecture and the trusted base specifically include: Define and implement a trust verification model that integrates four elements: user / permission trust, device trust, application trust, and network communication trust. Establish a whitelist access mechanism based on door-knocking authentication; After a terminal connects, it undergoes continuous trust assessment through a security agent. Once a decrease in the terminal's trustworthiness is detected, the manageable application firewall performs dynamic permission adjustments or blocking operations.

[0007] Preferably, the steps of deploying the intelligent boundary protection and deep detection system to build an intelligent, three-dimensional, and adaptive security defense line at the boundaries of various network areas, capable of identifying and blocking various known and unknown threats, specifically include: Deploy manageable application firewalls at the boundaries of each security domain and configure access control rules for IP addresses, ports, protocols, and user identities; Integrate and enable multiple security modules on the border firewall, including web application protection, abnormal packet attack defense, scanning attack defense, DOS / DDOS attack protection, brute-force attack prevention, weak password protection, and compromised host protection; Establish a unified endpoint security configuration baseline, and enforce detection and control of service requests initiated by the endpoint through the downstream firewall. Control elements include the endpoint's hardware information, operating system version, patch status, and antivirus software status.

[0008] Preferably, the steps of constructing a unified secure communication tunnel and cross-domain transmission guarantee to ensure that data maintains confidentiality and integrity throughout the entire network transmission process, especially when crossing different trust domains, specifically include: Deploy end-to-end trusted VPN communication equipment; Optimize the software and accelerate the hardware of the terminal access controller and the secure communication platform at all levels to reduce the performance loss caused by encryption and decryption. By utilizing a secure isolation and information exchange system, a controlled data exchange channel is established at key cross-domain nodes such as the external access area of ​​the central office.

[0009] Preferably, the step of defining and implementing standardized security function interfaces and collaboration protocols to solve data communication problems between heterogeneous security components through standardized protocols specifically includes: Define the YD-SOMN software bus and object identifier ID; Define a family of security control protocols; Define a multi-parameter organizational model for the execution of security functions.

[0010] Preferably, the step of establishing a continuous trust assessment and automated operation management closed loop to transform security protection from a static, passive mode to a dynamic, proactive mode based on continuous monitoring and automated response specifically includes: The auth.devCheck interface can be used to perform integrity checks on the device's operating environment periodically or triggered automatically. Through the security management and control center platform, data from multiple sources such as network traffic monitoring, host intrusion detection, log auditing, and situational awareness are aggregated to establish a comprehensive security situation view; To achieve automated orchestration and lifecycle management of security policies.

[0011] To address the aforementioned technical problems, the present invention also provides a trusted management and control network platform construction device, which adopts the following technical solution, including: The building module is used to build the basic security architecture and trusted foundation. The basic security architecture provides a unified root of trust and management core for the collaborative operation of upper-layer security components. The access control module is used to implement multi-dimensional trusted verification and dynamic access control based on the basic security architecture and the trusted base. The deployment module is used to deploy an intelligent boundary protection and deep detection system, which is used to build an intelligent, three-dimensional, and adaptive security defense line at the boundaries of various network areas, capable of identifying and blocking various known and unknown threats; The protection module is used to build a unified secure communication tunnel and cross-domain transmission protection to ensure that data remains confidential and intact throughout the entire network transmission process, especially when crossing different trust domains. Standardization modules are used to define and implement standardized security function interfaces and collaboration protocols, and to solve data communication problems between heterogeneous security components through standardized protocols. The closed-loop module is used to establish a closed loop of continuous trust assessment and automated operation and management, transforming security protection from a static and passive mode to a dynamic, proactive mode based on continuous monitoring and automated response.

[0012] To address the aforementioned technical problems, the present invention also provides an electronic device that employs the technical solution described below, comprising a memory and a processor. The memory stores computer-readable instructions, and the processor executes the computer-readable instructions to implement the steps of the aforementioned trusted management network platform construction method.

[0013] To address the aforementioned technical problems, the present invention also provides a computer-readable storage medium, which employs the technical solution described below. The computer-readable storage medium stores computer-readable instructions, which, when executed by a processor, implement the steps of the aforementioned trusted management network platform construction method.

[0014] Compared with the prior art, the present invention has the following main advantages: (1) Enhanced overall security: The basic security architecture and trusted foundation provide a unified root of trust for upper-layer components, thus consolidating the security foundation from the source. Multi-dimensional trusted verification and dynamic access control strictly screen access entities to prevent unauthorized access. Intelligent boundary protection and deep detection system build a multi-layered defense line to effectively identify and block various threats and ensure the security of all areas of the network. (2) Ensures secure data transmission: The unified secure communication tunnel and cross-domain transmission guarantee mechanism ensure that the confidentiality and integrity of data are not compromised throughout the entire network transmission process, especially when crossing trusted domains, thus avoiding the risk of data leakage and tampering; (3) Improved system compatibility and collaboration: Standardized security function interfaces and collaboration protocols solve the data communication problem between heterogeneous security components, enabling different components to seamlessly connect and collaborate efficiently, thereby improving the overall security protection performance; (4) Intelligent security operation has been achieved: continuous trust assessment and automated operation management closed loop, which transforms security protection from static passive to dynamic proactive. Through continuous monitoring and automated response, security threats can be dealt with in a timely manner, reducing the cost of manual intervention, improving the efficiency and accuracy of security operation, and providing comprehensive and sustainable security protection for the stable operation of the network platform. Attached Figure Description

[0015] To more clearly illustrate the solutions in this invention, the accompanying drawings used in the description of the embodiments of this invention will be briefly introduced below. Obviously, the drawings described below are some embodiments of this invention. For those skilled in the art, other drawings can be obtained from these drawings without creative effort.

[0016] Figure 1 This is a flowchart of an embodiment of the trusted management network platform construction method of the present invention; Figure 2 This is a control network architecture diagram used in the trusted management network platform construction method of the present invention; Figure 3 This is a diagram of the secure and trusted management platform architecture used in the trusted management network platform construction method of the present invention; Figure 4 This is a diagram of the YD-SOMN bus architecture used in the trusted management network platform construction method of the present invention; Figure 5 This is a schematic diagram of the YD-SOMN security management protocol family used in the trusted management network platform construction method of the present invention; Figure 6 This is a flowchart of the integrity check of the device's operating environment used in the trusted management network platform construction method of the present invention; Figure 7 This is a diagram of the security management computing architecture used in the trusted management network platform construction method of the present invention; Figure 8 This is a schematic diagram of the structure of an embodiment of the trusted management network platform construction device of the present invention; Figure 9 This is a schematic diagram of the structure of an embodiment of the electronic device of the present invention. Detailed Implementation

[0017] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the art to which this invention pertains; the terminology used herein in the specification is for the purpose of describing particular embodiments only and is not intended to limit the invention; the terms "comprising" and "having," and any variations thereof, in the specification, claims, and foregoing drawings are intended to cover non-exclusive inclusion. The terms "first," "second," etc., in the specification, claims, or foregoing drawings are used to distinguish different objects and not to describe a particular order.

[0018] In this document, the term "embodiment" means that a particular feature, structure, or characteristic described in connection with an embodiment may be included in at least one embodiment of the invention. The appearance of this phrase in various places throughout the specification does not necessarily refer to the same embodiment, nor is it a separate or alternative embodiment mutually exclusive with other embodiments. It will be explicitly and implicitly understood by those skilled in the art that the embodiments described herein can be combined with other embodiments.

[0019] To enable those skilled in the art to better understand the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings.

[0020] It should be noted that the trusted management network platform construction method provided in the embodiments of the present invention is generally executed by a server / terminal device, and correspondingly, the trusted management network platform construction device is generally set in the server / terminal device.

[0021] It should be understood that the number of terminal devices, networks, and servers is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be used.

[0022] Example 1 Please refer to Figure 1 The flowchart illustrates an embodiment of the trusted management network platform construction method of the present invention. The trusted management network platform construction method includes the following steps: Step S1: Construct a basic security architecture and a trusted foundation. The basic security architecture is used to provide a unified root of trust and management core for the collaborative operation of upper-layer security components.

[0023] In this embodiment, the electronic device (e.g., a server / terminal device) on which the trusted management network platform construction method runs can receive the trusted management network platform construction request via a wired or wireless connection. It should be noted that the aforementioned wireless connection methods may include, but are not limited to, 3G / 4G / 5G connections, WiFi connections, Bluetooth connections, WiMAXX connections, Zigbee connections, UWB (ultra-wideband) connections, and other currently known or future-developed wireless connection methods.

[0024] In this embodiment, step S1 further includes the following steps: S11 constructs a three-layer architecture consisting of a computing power management and control network, a control network, and a service network.

[0025] Software-defined networking (SDN) is used to separate the network control plane from the data plane, and resource virtualization is used to achieve logical isolation and on-demand allocation of physical resources. The network is logically divided into three relatively independent but closely coordinated planes: a three-layer architecture of computing power management network, control network, and service network.

[0026] SDN-based control and forwarding separation: A centralized SDN controller is deployed on top of the physical network infrastructure (routers, switches). This controller constitutes the core network control component of the computing power management and control network.

[0027] The SDN controller communicates with all network devices via a southbound interface (such as the penFLW protocol) and globally abstracts the topology and state of the entire network. Unlike traditional networks where each device makes independent decisions, it uniformly calculates and distributes flow tables to lower-layer network devices based on security policies.

[0028] Network devices (which constitute the underlying bearer of the service network) are only responsible for performing high-speed data forwarding according to flow tables, thus becoming a pure data plane.

[0029] Logical network slicing is achieved through virtualization: By utilizing network function virtualization, the functions of traditional physical security devices (such as firewalls and intrusion detection systems) are software-based to form virtual security function components.

[0030] The SDN controller works in conjunction with these virtualization technologies to dynamically create multiple logically independent virtual networks on a unified physical infrastructure.

[0031] The computing power management network is instantiated as a dedicated virtual control network for communication between the SDN controller and the security management platform, ensuring that management traffic is isolated from business traffic.

[0032] The control network is instantiated as a secure service chain virtual network. The SDN controller uses precise flow table rules to direct the service traffic that needs to be inspected to virtual security components (such as vFirewall, vIDS) in this network for processing, forming the execution spine.

[0033] The service network, after security policies allow it, is a virtual network that forwards pure business data. Its path is strictly defined by SDN flow tables to ensure that data is transmitted in a controlled pipeline.

[0034] Automated orchestration and policy coordination: The security management platform (located in the computing power management network) acts as the highest decision-making layer, converting advanced security policies (such as access from the terminal area must be detected by WAF) into specific network instructions and issuing them to the SDN controller.

[0035] The SDN controller acts as a translator and execution coordinator, automatically orchestrating security policies into specific network configurations and security service chain deployment instructions, enabling the linkage between the control network and the service network.

[0036] By leveraging SDN to achieve centralized intelligent control and flexible traffic scheduling, and virtualization to achieve elastic abstraction and logical isolation of resources, three logical planes are clearly separated and constructed on the physical layer network, each with its own responsibilities and closely cooperating through standard interfaces, thereby achieving the decoupling and re-integration of security and business.

[0037] Figure 2This is a control network architecture diagram used in the trusted management network platform construction method of the present invention. (See diagram below.) Figure 2 As shown, the control network, as the execution layer of "three-layer defense supported by a central hub", implements three-layer protection of communication network, regional boundary and computing environment with the support of security management platform, including four types of security protection capabilities: protection, detection, recovery and response.

[0038] The control network includes a core controller, a network controller, a host controller, a manageable firewall, and a network access control controller.

[0039] The core controller, deployed as a "sentinel" at the front end of the database server, is used for semi-structured protection of the server, security monitoring of the database / business system, and security auditing.

[0040] The network controller monitors and audits network devices in a bypass manner. It adopts a decentralized collaborative parallel computing architecture to enable plug-and-play network computing nodes. At the same time, it supports the execution of policy configurations for mainstream routing and switching devices, mainstream firewalls and other security devices.

[0041] The host controller provides access control mechanisms for resources such as business terminals and application servers. It can restrict access channels based on IP, port, MAC address and user permissions, filter request behavior, and execute the access channel permission check. If it matches, it is allowed; otherwise, it is locked.

[0042] This manageable firewall is used to enforce access control at regional boundaries. It has real-time security monitoring and rapid response capabilities, including packet filtering, stateful inspection, application defense, and network access control. It also features intrusion detection, traffic auditing, and integrated penetration testing toolsets.

[0043] Trusted and secure VPN communication devices are used for secure communication network security and secure cross-domain network access. Furthermore, with the support of SQY20 cryptographic services, they ensure the confidentiality, integrity, and non-repudiation of data transmission, while also preventing network intrusion through communication network monitoring.

[0044] The network access control unit is deployed at the business terminal access network to enable trusted access for business terminals (terminals, self-service devices, OA terminals, etc.) and to realize trusted operation of various managed network systems.

[0045] Step S11 separates the computing power management network, control network, and service network into a three-layer architecture, thereby decoupling and re-integrating security and services, and improving the flexibility and maintainability of the architecture.

[0046] S12 deploys the SQY20 cryptographic service system based on national cryptographic algorithms on a three-layer architecture of computing power management network, control network, and business network.

[0047] First, we need to build a public key infrastructure (PKI) system based on Chinese cryptographic algorithms, including deploying hardware cryptographic machines and managing the entire lifecycle of digital certificates.

[0048] Hardware cryptographic machine deployment: The core hardware cryptographic machine is deployed in a separate, physically isolated cryptographic service area. This device incorporates a chip certified by the State Cryptography Administration to generate and securely store the root key (Rt Key) and perform high-strength national cryptographic algorithms (such as SM2 for asymmetric encryption and signatures, SM3 for hashing, and SM4 for symmetric encryption). All core cryptographic operations are performed internally in the hardware, ensuring that the keys are never leaked.

[0049] Digital Certificate Lifecycle Management: This system deploys a Certificate Authority (CA) server, a Registration and Audit Center (RA) server, and a Lightweight Directory Access Protocol (LDAP) directory server. Protected by a cryptographic machine, the CA server issues X.509-formatted digital certificates to various entities within the platform (users, servers, network devices, and security devices). This system automates the entire lifecycle management of certificates, from application, auditing, issuance, distribution, storage, renewal to revocation, providing each entity with a unique and unforgeable "digital identity card."

[0050] Secondly, it provides a standardized cryptographic service interface: The SQY20 system provides a unified and standardized cryptographic service API interface. All other components within the platform (such as the security management platform, application server, and terminal agent) initiate service calls to the SQY20 system through a secure network channel when they need to perform cryptographic operations.

[0051] For example, when two components need to establish secure communication, they request each other's digital certificates from SQY20 and use the SM2 algorithm provided by SQY20 for authentication and session key negotiation. During data transmission, SQY20's SM4 algorithm is used for data encryption, and the SM3 algorithm generates a hash value to ensure integrity.

[0052] Then, two-way authentication and mandatory control based on digital certificates are implemented. For example, before a business terminal (such as a ticketing terminal) accesses the network, its built-in smart key (UKey) (which internally stores the user certificate and device certificate issued by SQY20) must first perform two-way authentication with the network access device (such as an access controller) based on SM2 certificates. The terminal verifies the legitimacy of the access device, and the access device also verifies the legitimacy of the terminal and the user.

[0053] Authentication will only succeed if both parties' certificates are verified and the certificate chain can be traced back to the trusted root certificate of SQY20. This mechanism achieves "no access without authorization," completely blocking any entity without a legitimate "identity card" from entering the system.

[0054] By establishing a root of trust through national cryptographic hardware, issuing and managing digital identities in batches through a standardized PKI system, empowering the entire network with high-strength cryptographic capabilities through a unified cryptographic service API, and finally using two-way certificate authentication technology to force all interactions to take place between trusted entities, a trusted management and control architecture based on cryptography and centered on identity is realized.

[0055] The purpose of step S12 is to provide a unified digital identity for all entities (users, devices, and applications) on the entire platform as the starting point for trust; to ensure the confidentiality, integrity, and non-repudiation of data transmission through cryptographic technology; and to form a trusted root for the entire network, thus constructing a closed-loop cryptographic security protection network.

[0056] S13, build a centralized security management and control center platform.

[0057] First, data collection and modeling of the entire network are carried out based on the YD-SOMN protocol.

[0058] The security management and control center platform has a built-in YD-SOMN protocol stack, which uses its data bus as a unified data pipeline to continuously collect data such as status, performance, and security events reported by all security components (firewalls, intrusion detection systems, endpoint agents, etc.).

[0059] The platform utilizes this real-time and historical data to internally build and maintain a digital twin model that fully maps to the physical network. This model not only includes static data such as network topology and asset information, but also dynamically reflects the security status, policy configuration, and traffic relationships of entities, achieving a digital mirroring of all assets.

[0060] Secondly, the platform performs automated orchestration and simulation verification of the policies. It provides a graphical policy editing interface, allowing security administrators to define high-level security objectives (such as isolating infected hosts). The automated policy orchestration engine translates these objectives into a specific, executable sequence of low-level instructions. Before issuing the instructions, the orchestration engine performs simulations in a digital twin model to predict the impact of policy execution on business connectivity and system performance, ensuring the accuracy and effectiveness of the policies and avoiding false positives or business interruptions.

[0061] Then, coordinated linkage and closed-loop management based on unified commands are carried out. After the simulation verification is successful, the orchestration engine uses the YD-SOMN control bus to send standardized commands (such as calling the sec.cmd.run interface to execute blocking actions) in parallel to multiple related security components (such as notifying the network controller to adjust routes, instructing the firewall to update rules, and commanding the terminal agent to isolate files).

[0062] After each component completes its execution, its result status is fed back to the control center via the data bus. The platform compares the real-time status with the expected target, forming an automated security closed loop of perception-decision-execution-verification, thereby realizing digital management of the entire lifecycle of the security mechanism.

[0063] Figure 3 This is a diagram of the secure and trusted management platform architecture used in the trusted management network platform construction method of this invention. (See diagram below.) Figure 3 As shown, the security management and control center platform is the "security brain" of the entire network and the computing power management and control network. Based on the SQY20 cryptographic service system, it grants trust and authorization to users, operating devices, applications and critical information resources of the managed network system, and supports proactive identification, proactive measurement and proactive confidential storage, so as to achieve trustworthy data information processing and trustworthy system service resources under the policy support of the security management and control platform.

[0064] Formulate "security policies, strategies, and security objectives" for the entire network; among them, network control, application control, host control, and client access control including but not limited to ticket terminals, automatic vending terminals, and turnstiles, correspond to the security zones agreed upon by the three-layer defense, including secure computing environments, network area boundaries, and secure communication networks, and implement local / domain "security control measures supported by security objectives" deployment and collaborative work.

[0065] Network security management is layered, including physical layer management, link layer management, network layer management, transport layer management, and application layer management; network security management is graded according to user operations, data security, threat incidents, and information asset exposure vulnerability incidents.

[0066] Furthermore, it achieves the separation of the control layer and the data layer, forming three relatively independent planes: the control network, the business network, and the data network, thus constructing an automated security defense architecture that can be automatically orchestrated, managed, and layered.

[0067] The security management and control center platform is highly integrated with network devices, enabling each network element node to serve as an execution point for security policies and become part of the security protection system. This allows security to perceive network and business changes, and enables security protection to detect and follow up on network changes in a timely manner.

[0068] The network security trusted management and control system, through the YD-SOMN security interface protocol, enables the security management and control platform to achieve efficient collaboration and close linkage of security devices in multiple dimensions such as system management, security management, and audit management. Furthermore, it can embed the security devices deployed in the triple defense (such as application firewalls, intrusion detection, secure communication components, etc.), the security mechanisms and security services set up, into network devices such as routers and switches, forming a high degree of coupling between security and business, realizing resource sharing and automatic balancing, and collaborative operation of security and business.

[0069] At the same time, at the system architecture level, security is enabled to perceive and adapt to the network, and to promote automated security operation and protection capabilities.

[0070] The security management center platform uses the YD-SOMN security management protocol as its "nerve network" to automatically orchestrate security policies under the support of security policies and objectives. It also works in conjunction with "network management, application management, and host management" in various distributed security domains to achieve network collaboration. Furthermore, it provides digital management of the enterprise network system across dimensions such as security policies, organization, personnel, equipment, assets, events, communications, operations, and passwords, enabling full lifecycle digital management of security mechanisms such as business continuity and compliance.

[0071] Step S2: Based on the basic security architecture and trusted foundation, implement multi-dimensional trusted verification and dynamic access control.

[0072] In this embodiment, step S2 further includes the following steps: S21 defines and executes a trust verification model based on four elements: user / permission trust, device trust, application trust, and network communication trust.

[0073] First, define and implement user / permission trust (T_user). Use two-factor authentication (such as UKey + PIN code) to ensure the legitimacy of user identity and permissions. Users must insert a personal smart key (UKey) issued by the SQY20 cryptographic system and enter the correct PIN code to complete dual verification of knowledge (PIN code) and possession (UKey).

[0074] During the authentication process, the trusted proxy on the terminal extracts the user's digital certificate from the UKey and sends it to the authentication server (such as an access controller) over the network. The server uses the SQY20 CA root certificate to verify the authenticity and validity of the user certificate and check its bound permission roles. Only when the certificate is valid and the permissions comply with the policy is the user's identity recognized as trusted.

[0075] Next, define and implement device trust (T_device). Through a trusted management agent deployed on the terminal, collect hardware information that cannot be easily tampered with, such as the device's hardware serial number, CPU model, motherboard information, and network card MAC address.

[0076] The agent uses the national cryptographic SM3 hash algorithm to calculate this information and generate a unique, strongly associated device fingerprint (hardware hash). This fingerprint, along with the device digital certificate (stored in the device UKey), is reported during access authentication.

[0077] The security control center compares the received device fingerprints with the pre-set trusted device list baseline and verifies the legality of the device certificates to ensure that the connected devices are legitimate assets that have been registered and authorized and whose hardware environment has not been tampered with.

[0078] Then define and implement the collaboration between application trust (T_app) and network communication trust (T_net).

[0079] Trusted Application (T_app): The trusted agent scans the list of processes running on the terminal and the applications installed, calculates their digital signatures or file hashes, and compares them with the application whitelist policy issued by the security control center. Only applications with valid signatures, compliant versions, and within the whitelist are allowed to run and access the network, thereby preventing the execution of malware or unauthorized applications.

[0080] Trusted Network Communication (T_net): After passing the first three verifications, all communication between the terminal and the business system will be required to pass through a trusted VPN tunnel. The terminal agent will automatically establish a connection with the secure communication platform, using the key allocated by the SQY20 system, and based on national cryptographic algorithms (such as SM4) to encrypt and protect the integrity of the communication data throughout the process, ensuring that the link is not eavesdropped on or tampered with.

[0081] This model verifies users through digital certificates and biometrics (PIN), verifies devices through device fingerprints and digital certificates, verifies applications through digital signatures / hash whitelists, and finally ensures communication through a VPN tunnel using national cryptographic algorithms. This enforces comprehensive trustworthiness of access terminals and precisely extends the security defense line to every source of access.

[0082] S22, Construct a whitelist access mechanism based on door-knocking authentication.

[0083] A trusted management agent app is deployed on the terminal side to work in conjunction with the access controller, implementing a door-to-door authentication mechanism where authentication precedes connection. The authentication factors are combined information fingerprints: IP address, MAC address, time, and location.

[0084] Step S22 reverses the traditional network connection order, making high-strength authentication the only prerequisite for network layer connection, thereby achieving default rejection at the network layer.

[0085] First, authentication triggering and door-knocking data packet generation are performed: when a terminal device attempts to access the network, the trusted management agent APP deployed on it will first block its normal TCP / IP connection request.

[0086] Subsequently, the proxy app will collect four core factors: the terminal's IP address, MAC address, current precise timestamp, and geographical location data provided by the built-in security chip or GPS / base station information.

[0087] The proxy app uses a pre-installed device certificate private key issued by the SQY20 system to digitally sign this combined information (IP + MAC + time + location) to form a structured, tamper-proof door-knocking authentication request data packet.

[0088] Authentication and dynamic policy distribution: This "knock-on" packet is sent to the access controller at the network boundary. At this point, a TCP connection has not yet been established between the terminal and the controller; only a specific authentication data packet is transmitted at the network layer.

[0089] Upon receiving the packet, the access controller performs rigorous verification: integrity verification is performed by using the public key of the device certificate corresponding to the terminal to verify the digital signature and ensure that the information has not been tampered with; timeliness verification is performed by checking the timestamp to prevent replay attacks (such as when the data packet is intercepted and resent); and legitimacy verification is performed by comparing the IP, MAC, and location information with the pre-registered legitimate information.

[0090] Only after all verifications pass will the access controller determine that the terminal is trustworthy. Subsequently, the controller will issue a temporary, time-limited ACL rule to the connected network switch (which can be done via SNMP or API) to add the terminal's MAC and IP addresses to a dynamic whitelist, allowing it to establish TCP connections with specific business servers.

[0091] Connection establishment and session maintenance: Only after the whitelist takes effect can the terminal's initial TCP connection request (such as a TCPSYN packet) be allowed by the network device, thus successfully establishing a connection and starting normal business communication.

[0092] Throughout the session, the trusted agent periodically sends keep-alive heartbeat messages to the admission controller. Once the session ends or the heartbeat times out, the admission controller automatically removes the endpoint from the whitelist, revokes the corresponding ACL rules, and revoks its network access permissions.

[0093] S23: After a terminal connects, it undergoes continuous trust assessment through its security agent. Once a decrease in the terminal's trustworthiness is detected, the manageable application firewall performs dynamic permission adjustments or blocking operations.

[0094] This transforms one-time access trust into dynamic trust scoring based on continuous behavior monitoring, and enables real-time, dynamic adjustment of permissions through automated policy execution points. Its implementation is an automated closed loop consisting of perception, decision-making, and execution. First, continuous multi-source data awareness and trust assessment are performed: the security agent on the endpoint runs continuously, collecting various behavioral data uninterruptedly throughout the entire endpoint session. This data includes system behavior data, network behavior data, and environmental integrity data.

[0095] System behavior: Monitor changes in the process tree, system call sequence, registry, or critical system files to detect the presence of malware behavior patterns.

[0096] Network Behavior: Analyze the destination IP, port, protocol, and traffic patterns of network connection requests to determine whether there are suspicious activities such as port scanning, lateral movement within the intranet, or communication with malicious C&C servers.

[0097] Environment integrity: Periodically recalculate the hardware hash (devPidHash) and application whitelist hash (devNetHash), and compare them with the baseline values ​​at the time of admission to detect whether the runtime environment has been tampered with.

[0098] This data is reported to the security management center platform in real time or near real time via the YD-SOMN protocol. The platform's embedded trust assessment engine calculates a dynamic trust score for each online terminal based on predefined security policies and machine learning models.

[0099] Secondly, policy-based real-time risk decision-making and instruction generation are performed: the security control center platform compares the dynamic trust score of the terminal with the preset risk threshold. Once it is found that the trust score of a terminal drops below the warning threshold (for example, suspicious network sniffing behavior is detected), or a specific risk rule is triggered (for example, an attempt to access an unauthorized database port), the decision engine will immediately determine that the trustworthiness of the terminal has decreased.

[0100] The engine then automatically generates specific control instructions based on the pre-set scripts. For example, for medium-risk situations, it generates instructions to restrict access permissions, allowing only essential business operations; for high-risk situations, it directly generates instructions to immediately block the session.

[0101] Then, low-latency collaborative linkage and policy execution are carried out: the generated instructions are sent to the relevant policy execution points in parallel and synchronously through the YD-SOMN security control protocol family.

[0102] The instruction is sent to the manageable application firewall nearest to the terminal, requiring it to immediately update the ACL rules to block all traffic of the terminal IP or limit its access scope.

[0103] The instruction is also sent to the network controller simultaneously, causing it to discard the traffic from the terminal MAC / IP on the SDN switch.

[0104] The instruction may also be sent to the terminal agent itself, ordering it to isolate suspicious processes or disconnect its network.

[0105] This mechanism of multi-point synchronous execution ensures that the total response time (Trespnse) from detecting a risk to completing control is extremely short, so that threats can be isolated before the attacker completes vulnerability exploitation and data theft (i.e., the attack breakthrough time Tbreach), achieving the security goal of Trespnse < Tbreach.

[0106] Step S3, deploy an intelligent boundary protection and deep detection system to build an intelligent, three-dimensional, and adaptive security defense line at the boundaries of each network area, capable of identifying and blocking various known and unknown threats.

[0107] In this embodiment, step S3 further includes the steps of: S31, deploy a manageable application firewall at the boundary of each security domain, and configure access control rules for IP addresses, ports, protocols, and user identities.

[0108] Step S31 goes beyond the traditional five-tuple firewall policy, strongly binds the network identity with the user identity, and realizes centralized, automated, and dynamic management of policies. Its implementation is a multi-level and integrated control process: First, perform real-time binding of identity and IP and policy generation: When the terminal passes the "four-factor" authentication and "knock authentication", its user identity (from the CN field or attribute field of the digital certificate) will be real-time bound with the IP address it obtains on the security control center platform and recorded in the dynamic session table.

[0109] Security administrators do not need to face complex IP addresses on the control platform, but define high-level access policies based on user roles (such as "ticket seller", "system administrator") and business applications (such as "ticket query", "database maintenance") (for example: "Allow the 'ticket seller' role to access the 'ticket query' application during working hours").

[0110] The policy engine of the platform will automatically "translate" these business language policies into specific underlying ACL rules that are precise to the source IP, destination IP, destination port, and transport protocol.

[0111] Secondly, policy dynamic distribution based on the YD-SOMN protocol: The generated refined ACL rules are sent to the manageable application firewalls at the boundaries of the target areas in real time and accurately through the YD-SOMN security control protocol family.

[0112] This process is automated. For example, when a "conductor" terminal is successfully authenticated and obtains an IP, the policy will be immediately sent to the firewall in front of the business service area, allowing its source IP to access a specific port (such as TCP 443) of the ticket query server. When the user logs off or the session times out, the management platform will immediately trigger a policy revocation instruction to delete the corresponding rules from the firewall, realizing the immediate recovery of permissions.

[0113] Then, context-based enforcement and session monitoring are carried out: The manageable application firewalls deployed at the boundaries serve as the final policy enforcement points, performing deep packet inspection on all passing data packets. It not only checks IPs and ports but also analyzes application layer protocols (such as HTTP) to verify the legality of sessions.

[0114] The policy enforcement points of the firewall will strictly enforce access control according to the sent rules. Any connection attempt that does not conform to the rules, whether from an unauthorized IP or accessing an unopened port, will be directly discarded and a security log will be generated.

[0115] At the same time, the firewall feeds back network traffic and session status to the security management center in real time. Through correlation analysis, the center can promptly detect abnormal behaviors (such as a "conductor" terminal suddenly attempting to connect to the database port) and can immediately issue a temporary "block" instruction to the firewall through the YD-SOMN protocol to achieve dynamic permission adjustment.

[0116] S32. Integrate and enable multiple security modules such as Web application protection, abnormal packet attack defense, scanning attack defense, DOS / DDOS attack protection, brute force cracking prevention, weak password protection, and compromised host protection on the boundary firewall.

[0117] Step S32 is to upgrade the boundary firewall from a static packet filtering device to an intelligent security platform integrating multiple detection engines, with behavior analysis capabilities and global threat intelligence. Its implementation depends on deep integration and linkage analysis: First, perform deep integration of network layer and application layer protection: Abnormal packet and scanning defense: At the network layer, the built-in engine of the firewall will detect based on protocol specification compliance and traffic behavior modeling. It can identify and discard malformed packets and fragmented attack packets that do not conform to the TCP / IP RFC standard, and can detect port scanning and network probing behaviors in real time by analyzing the rate of connection requests and the target port distribution pattern, and automatically temporarily block the source IP.

[0118] Web Application Protection: At the application layer, the WAF module acts as a reverse proxy, deeply analyzing HTTP / HTTPS traffic. It performs bidirectional inspection of every web request and response using a predefined rule base (targeting known attacks such as SQL injection and XSS) and a machine learning-based anomaly detection model (targeting business logic vulnerabilities and unknown threats). It can identify malicious commands hidden within seemingly legitimate requests, thus effectively defending against application-layer attacks targeting web servers.

[0119] Secondly, resource protection and credential security protection are implemented, including DOS / DDOS protection, brute-force attack prevention, and weak password protection.

[0120] DOS / DDOS Protection: The firewall establishes a normal traffic model through traffic baseline self-learning technology. When a large number of requests far exceeding the baseline are detected heading towards a specific target, a multi-layered cleaning mechanism is activated: first, traffic from known malicious IPs is filtered through an IP reputation database; second, connection rates are limited through traffic shaping; and finally, suspected attack traffic is challenged and verified to ensure that business bandwidth is not exhausted.

[0121] Brute-force attack and weak password protection: This module works in conjunction with the identity authentication system. When the firewall detects multiple failed login attempts from the same source IP address to a specific service (such as SSH, RDP, or login interface) within a short period, it identifies it as a brute-force attack and automatically adds the IP address to the blacklist or triggers a CAPTCHA. Simultaneously, it can detect whether common weak passwords are used in login requests and block such requests in real time, recording them as security events.

[0122] Then, intelligent analysis and compromised host handling are performed, including compromised host protection.

[0123] Compromised Host Protection: This is a concentrated manifestation of adaptive capabilities. The firewall not only relies on its own detection but also receives global threat intelligence from the security management center platform. For example, when the endpoint EDR detects malware on a host, or the network IDS discovers that an internal IP address is communicating with an external C&C server, this information is synchronized to the firewall in real time via the YD-SOMN protocol.

[0124] Upon receiving intelligence, the firewall will immediately focus on monitoring or directly block all outbound and lateral traffic from the compromised host at the boundary to prevent data leakage and internal spread. Simultaneously, it can also report suspicious outbound activities detected by itself to the control center, providing data for global situational awareness and forming a closed loop.

[0125] S33 establishes a unified endpoint security configuration baseline and enforces detection and control over service requests initiated by the endpoint through the downstream firewall. Control elements include the endpoint's hardware information, operating system version, patch status, and antivirus software status.

[0126] Step S33 involves treating the terminal's security status as a dynamic and mandatory access control attribute, and setting the execution point at the network boundary to enable the network layer to perceive and respond to the terminal's health status. This is implemented as a closed-loop process collaboratively completed by the terminal agent, the control center, and the boundary firewall. First, real-time collection and reporting of the environmental context are performed: The trusted management agent APP deployed on the business terminal acts as a continuously running "health monitor," periodically (or before each important business request) collecting the terminal's environmental information. This includes: Operating system version and patch information: Check whether critical security patches (such as KB numbers) are installed.

[0127] Antivirus software status: Verifies whether the specified antivirus process is running and whether the virus database is the latest version.

[0128] Security configuration: Check if the firewall is enabled and if there are any insecure shares, etc.

[0129] Hardware and software list: Compared with the initial network access, are there any unauthorized hardware changes or software installations?

[0130] The agent encapsulates this environment context data into a standard format (such as JSN) through interfaces in the YD-SOMN public service protocol family (such as evn.getItemAll) and reports it to the security management center platform in real time.

[0131] Secondly, baseline compliance dynamic matching and policy generation are performed: The security management center platform predefines a unified endpoint security configuration baseline, which exists in the form of executable policies (e.g., "Patch KB5005565 must be installed" and "Antivirus software virus database age must not exceed 24 hours").

[0132] The platform dynamically matches and verifies the compliance of real-time data reported by terminals against preset baselines. Based on the verification results, the platform calculates and maintains a dynamic security status label for each terminal, such as "compliant", "risky", or "violation".

[0133] When a terminal is in a "risk" or "violation" status, the platform's policy engine will immediately generate a temporary access control policy for that terminal's IP address. The core content of this policy is: "Deny access to the core business area by this IP address".

[0134] Then, the network boundary enforces the policy and blocks services: This dynamically generated policy is immediately distributed to the manageable application firewall in the area where the terminal is located (downstream area) through the YD-SOMN security control protocol suite.

[0135] As the final point of policy enforcement, the firewall, upon receiving the instruction, immediately creates a high-priority blocking rule in its access control list (ACL). When the "unauthorized terminal" attempts to initiate a TCP connection to the ticketing server, its data packets are dropped by the firewall before reaching the server.

[0136] End users will receive an "Access Denied" message, and the terminal agent will simultaneously display an alert, notifying the user to perform security repairs (such as installing system updates). Only after the terminal has repaired the problem, resubmitted its environment information, and its status has been verified by the platform to be "compliant" will the control center send a command to the firewall via the YD-SOMN protocol to revoke the blocking rule and restore its business access permissions.

[0137] By employing an automated pipeline of "terminal self-inspection and reporting -> central dynamic evaluation -> boundary enforcement," the security and health of terminals are creatively and strongly linked to network access permissions. This enables the network boundary to "identify terminal health status" and "authorize on demand," eliminating the possibility of "sick" terminals accessing core business resources from the network root node. This is a crucial step in building an endogenous security immune system.

[0138] Step S4: Construct a unified secure communication tunnel and cross-domain transmission guarantee to ensure that data remains confidential and intact throughout the entire network transmission process, especially when crossing different trust domains.

[0139] In this embodiment, step S4 further includes the following steps: S41, deploy end-to-end trusted VPN communication equipment.

[0140] By deploying dedicated hardware and deeply integrating national cryptographic algorithms, a transparent and secure data transmission channel, fully protected by cryptographic technology, can be constructed between any two network areas. Its implementation is a systematic application of cryptographic engineering, as detailed below: First, dedicated hardware is deployed and integrated with national cryptographic algorithms: Dedicated, trusted, and secure VPN communication devices (usually hardware security gateways) are deployed at key network boundaries in the railway bureau's wide area network, including the uplink area (connecting headquarters), the downlink area (connecting various stations), and the cryptographic service area. These devices have built-in cryptographic chips certified by the State Cryptography Administration.

[0141] These VPN devices register and issue their device certificates with the SQY20 cryptographic service system during manufacturing or initialization. Afterward, all secure communication between VPN devices is built upon the root of trust provided by SQY20.

[0142] The device integrates a suite of national cryptographic algorithms, using the SM2 algorithm for asymmetric encryption and digital signatures, the SM3 algorithm for data integrity verification, and the SM4 algorithm for symmetric encryption, ensuring that all cryptographic operations comply with national standards and are highly efficient and secure.

[0143] Secondly, a certificate-based two-way authentication and tunnel establishment process is implemented: When communication needs to be established (for example, when the VPN gateway in the lower-level station area needs to communicate with the VPN gateway in the upper-level station area), both parties will perform a strict two-way authentication process based on SM2 digital certificates. Each party must verify the authenticity and validity of the other party's device certificate, confirming that it was issued by a trusted SQY20 CA and has not been revoked.

[0144] After successful authentication, both parties use the SM2 algorithm to negotiate a key, dynamically generating a one-time session key. This key is used only for this communication session, and all subsequent data encryption and decryption will use this key. The negotiation process itself is also encrypted, ensuring forward key security.

[0145] Then, real-time encryption and integrity verification of the data are performed: After the tunnel is established, all business data flowing through the VPN device (whether from the terminal or the server) is processed in real time at the sending end. Encryption: The original data packets (IP packets) are encrypted using the SM4 session key. Encapsulation and Signing: The encrypted data is encapsulated in a new IP packet, and a hash value is generated using the SM3 algorithm. This hash value is then digitally signed using the local device's SM2 private key and appended to the data packet.

[0146] After receiving the data packet, the VPN device at the receiving end first verifies the digital signature using the peer's SM2 public key to confirm that the data source is authentic and has not been tampered with (integrity and non-repudiation). After successful verification, it decrypts the data using the negotiated SM4 session key, recovers the original data packet, and forwards it to the target server or terminal.

[0147] S42 optimizes the software and accelerates the hardware of the terminal access controller and various levels of secure communication platforms, reducing the performance loss caused by encryption and decryption.

[0148] First, hardware cryptographic acceleration and dedicated chip offloading are implemented: In trusted and secure VPN communication equipment and terminal access controllers, hardware acceleration cards for national cryptographic algorithms or dedicated chips with cryptographic operation instruction sets are integrated. This hardware is specifically designed to perform complex mathematical operations using algorithms such as SM2, SM3, and SM4.

[0149] The most CPU-intensive processes—asymmetric encryption (SM2), symmetric encryption / decryption (SM4), and hash calculation (SM3)—are offloaded from the device's general-purpose CPU to dedicated hardware. This can result in performance improvements of tens or even hundreds of times, significantly reducing latency in encrypted data transmission and enhancing the device's ability to handle concurrent VPN tunnels and SSL connections, ensuring line-speed data forwarding performance when a massive number of terminals access the device.

[0150] Then, multi-core parallel processing and connection reuse are performed at the software level: the software stack of the trusted management agent APP and communication platform on the terminal is deeply optimized. Lock-free queues, thread pools, and multi-core parallel processing technologies are adopted to distribute network I / O, data encryption and encapsulation, and other tasks to multiple CPU cores for parallel processing, making full use of the computing power of modern multi-core processors.

[0151] Then, intelligent traffic identification and selective encryption strategies are implemented: a deep packet inspection engine is deployed in the secure communication platform to intelligently identify traffic. Based on predefined strategies, the system can differentiate between different types of data streams.

[0152] S43 utilizes a secure isolation and information exchange system to establish controlled data exchange channels at key cross-domain nodes such as the external access area of ​​the central office.

[0153] First, physical isolation and dedicated hardware ferry are implemented: Deploy a secure isolation and information exchange system, the core of which is a dedicated hardware device containing two independent host systems that are connected to a high-security zone (such as the ticket intranet) and a low-security zone (such as the external access zone). The two are connected through a dedicated non-TCP / IP physical channel (such as a custom bus or reflective memory), and usually adopt a unidirectional transmission hardware design.

[0154] Next, protocol stripping and content reconstruction are performed: When data needs to be transferred from the low-security zone to the high-security zone, the external host of the gateway will first completely terminate all network connections from the outside (such as TCP sessions and HTTP requests). Subsequently, it performs deep content inspection and virus scanning on the received application layer data (such as database query statements and file content).

[0155] Then, content filtering and access control based on strict policies are implemented: During data transfer, the system performs content-level filtering according to strict policies issued by the security management center. For example, rules can be set to allow only database query commands containing specific keywords to pass through, or to block all outbound data packets containing sensitive information such as ID card numbers and bank card numbers.

[0156] Step S5: Define and implement standardized security function interfaces and collaboration protocols to solve data communication problems between heterogeneous security components through standardized protocols.

[0157] In this embodiment, step S5 further includes the following steps: S51 defines the YD-SOMN software bus and object identifier ID.

[0158] like Figure 4 The diagram shown illustrates the YD-SOMN bus architecture used in the trusted management network platform construction method of this invention. The YD-SOMN protocol defines a software bus structure, including an address bus, a control bus, and a data bus. The address bus uses object identifiers (IDs) to uniformly encode all network security objects. The ID encoding rule is a tree structure, and its global uniqueness is guaranteed by the hierarchical structure.

[0159] ID numeric name formula: ID = {root}.{parent node}.{child node}..., for example: 1.2.156.112.

[0160] The ID is the object identifier, a dot-separated sequence of integers. The root, parent, and child nodes represent different levels in a predefined naming tree, ensuring unambiguous object identification. The numeric name value is a positive integer greater than 0 and less than 16,000,000.

[0161] Implementation of a three-bus architecture for the software bus: Address Bus: Implement a global ID registry within the protocol stack. Each security object (such as a firewall, a user account, or a security policy) is assigned a unique ID by the control center upon creation, based on its type, region, and instance number. For example, 1.2.156.112.3.25 might represent "Beijing Railway Bureau - Ticketing System - Firewall - Device No. 25". All addressing within the system is based on this ID.

[0162] Control Bus: Implemented as a message routing and coordination engine. It is responsible for managing the interaction sequence between components, such as ensuring the order of "request-response"; performing permission checks to verify whether a component has the right to call the functions of another component; and monitoring the component status and triggering recovery processes when a component fails.

[0163] Data Bus: Defines a unified message encapsulation format. Data is classified into two categories: "Events" and "Configuration," each using different serialization formats. Event data uses URIs to identify its type for easy classification and processing; configuration data uses a well-structured YAML format to describe the system's target state.

[0164] ID allocation and management mechanism: This is achieved through a centrally authorized, hierarchical ID allocation system. First, a top-level naming tree is predefined, for example, the root node is assigned to "Railway", and its child nodes are assigned to various railway bureaus and business systems.

[0165] When a new security device or user needs to connect, the management platform assigns an unused ID code to it sequentially under the corresponding branch of the naming tree, based on its affiliation. This tree structure and centralized allocation mechanism technically guarantee the uniqueness of each ID across the entire network, enabling any object to be unambiguously located and addressed, laying the foundation for subsequent "plug and play" functionality.

[0166] S52 defines a family of security control protocols.

[0167] Define a security control protocol family, whose data format refers to the MDbus model, including: Address field (1 byte): identifies the target device or functional module; Function code (1 byte): defines the operation to be performed (e.g., 1-scan, 4-block, 6-allow); Data field (N bytes): carries the specific parameters of the operation; Error checking: ensures the accuracy of data transmission.

[0168] Figure 5 This is a schematic diagram of the YD-SOMN security management protocol family used in the trusted management network platform construction method of the present invention. Figure 5 As shown, the YD-SOMN-CM security management protocol family manages the lifecycle of the Security Assessment Object (TOE), defines security policies and functions, and organizes and schedules these functions. The Px interface in the diagram serves as a key interaction channel between different modules within the protocol family, responsible for transmitting security policies and issuing execution commands, ensuring collaborative work among modules and achieving consistent security control. MD (Management Data) is the foundational information set for platform operation, encompassing data such as device status and user permissions, providing a basis for security decisions. SNMP (Simple Network Management Protocol) is used for monitoring and managing network devices, ensuring stable operation by collecting device information and setting parameters. CMIP (Common Management Information Protocol) offers more powerful functionality, providing richer management features and higher security, suitable for comprehensive management in complex network environments. These elements work together to construct an efficient, reliable, and trustworthy network platform security management system.

[0169] 1) Security assessment objects (TOEs) include, but are not limited to, SDCN secure communication network; DCN data communication; SOS secure operation system; SMD secure intermediary device; SWS secure workstation; SDA security device adapter; SD security device; NE network unit, wherein SOS, SDA, and SMD are interconnected using the SOMN security management protocol suite.

[0170] 2) Steps for implementing digital control over the security policies and strategies, organization, personnel, equipment, assets, events, communications, operations, passwords, and other dimensions involved in the security assessment object (TOE). 3) F interface: The F interface is applied at the f reference point and is used to enable the workstation (SWS) to connect with physical elements including SOSF and SMF through a secure communication network. It supports the following information interfaces, including configuration information interface, device configuration interface, basic information interface, alarm information interface, and information reporting interface.

[0171] SMF: Security devices with interfaces conforming to the SOMN architecture, including firewalls; IDS / IPS; vulnerability scanning devices, security auditing, and security agents, etc.; SDAF: Security Controller. System status information interface, including configuration information, status information, security information, fault information, and business information. Read / write SMIB interface: Interface for reading and writing security policies.

[0172] 4) P interface, including registration interface, security authentication interface, event management interface; and interfaces for filtering, merging, and combining event handling methods; interfaces for extracting events; and interfaces that provide real-time and non-real-time methods for providing other subsystems with various security events that have occurred or are occurring in the system; as well as authorization interface and security service interface.

[0173] The security authentication interfaces include authentication request interfaces, authentication sequence generation interfaces, authentication sequence issuance interfaces, simple authentication interfaces, challenge-response authentication interfaces, X.509 one-way authentication interfaces, X.509 two-way authentication interfaces, data integrity protection interfaces, data signing interfaces, and encryption interfaces.

[0174] 5) Such as the integrity detection interface, used to perform integrity checks on the device's operating environment, including hardware, system and software services, etc. Hardware or peripheral changes are not allowed, system replacement is not allowed, application software upgrades, updates and releases are not allowed, etc.

[0175] Integrity authentication interfaces include hardware configuration integrity, operating system integrity, and software system integrity. Integrity detection interface formats include integrity request formats and integrity response formats.

[0176] Figure 6 This is a flowchart illustrating the integrity check of the device's operating environment used in the trusted management network platform construction method of this invention. Figure 6As shown, this process involves interaction between the device, the device agent, and the master control unit. The device agent collects device integrity data, including hardware information, operating system information, and software information. The master control unit encrypts the integrity data (hardware, operating system, and software information) and submits integrity authentication requests (encrypted environment information), etc.

[0177] S53 defines a multi-parameter organizational model for the execution of security functions.

[0178] Define a multi-parameter organization model for security function execution. Its core data structure is represented in JSN format in the interface request and includes the following key fields: "actin": The action performed (such as "scan" or "block").

[0179] "target": The target object of the action (such as "Device", "IPv4-Net").

[0180] "args": Parameters for the action (such as target IP and port).

[0181] "func": Security function type (such as "Ids" - intrusion detection).

[0182] "cmmand_id": The specific command or tool executed.

[0183] "Prfile": The security policy file on which it is based.

[0184] The purpose of step S53 is to service and interface security capabilities, enabling upper-layer applications to call various underlying security functions in a unified and standardized manner; this greatly simplifies the integration of the Security Operations Automation (SAR) process and shortens the response time to security incidents.

[0185] Step S6: Establish a closed loop of continuous trust assessment and automated operation management to transform security protection from a static, passive mode to a dynamic, proactive mode based on continuous monitoring and automated response.

[0186] In this embodiment, step S6 further includes the following steps: S61 performs integrity checks on the device's operating environment periodically or triggered by the auth.devCheck interface.

[0187] Baseline Establishment and Hash Calculation: During the initial trusted access of the terminal, the trusted management agent on it will collect a list in three dimensions: hardware list, including CPU model / serial number, memory information, hard disk serial number, network card MAC address, etc.; system list, including operating system kernel version, list of running system services, security software processes, etc.; software list, including the name, version, path and digital signature information of all installed applications.

[0188] The agent uses the national cryptographic SM3 hash algorithm to calculate the corresponding baseline hash values ​​for the three lists: devPidHash (hardware), devFirewrkHash (system), and devNetHash (software). These baseline values ​​are securely transmitted to the security management center platform and stored as the integrity measurement baseline for the terminal.

[0189] Periodic Measurement and Reporting: During terminal operation, the Trusted Management Agent periodically (e.g., every 5 minutes) or after a triggered event (e.g., detecting a new process startup or software installation) re-collects the above three lists and calculates new hash values ​​in real time using the same SM3 algorithm.

[0190] The proxy uses the auth.devCheck interface in the YD-SOMN protocol to encapsulate the three newly calculated hash values ​​in a JSN request and report it to the security control center. This process constitutes a continuous health check of the endpoint environment.

[0191] Comparison and dynamic response: After receiving the integrity report, the security control center will immediately compare the real-time hash value reported by the terminal with the pre-stored baseline hash value.

[0192] The adjudication logic is very simple and strict: any inconsistency means a breach of integrity. For example: a mismatch in devPidHash may mean that hardware has been replaced (such as the addition of an unauthorized network card). A mismatch in devFirewrkHash may mean that system services have been tampered with or critical system files have been replaced. A mismatch in devNetHash may mean that unauthorized software has been installed or that legitimate software has been infected by malware.

[0193] Once a mismatch is detected, the control center will immediately and significantly lower the dynamic trust score of the terminal. It can also issue instructions to network devices or terminal agents via the YD-SOMN-CL protocol according to the preset policy, such as restricting their network access permissions or forcing them to go offline for repair.

[0194] S62, through the security management center platform, aggregates multi-source data from network traffic monitoring, host intrusion detection, log auditing, and situational awareness to establish a comprehensive security situation view.

[0195] First, perform multi-source data standardization aggregation and unified modeling: As a data hub, the security control center platform receives various alarms and logs from the network side (traffic sensors, firewalls), host side (EDR, logs), and security devices (IDS, WAF) through the YD-SOMN data bus. All data is normalized into a unified format (such as using standard threat intelligence formats like STIX) at the entrance and mapped into a unified attack chain model.

[0196] Then, perform correlation analysis and situation determination based on the attack chain: The built-in security analysis engine of the platform (combining a rule engine and a machine learning model) performs correlation analysis on the aggregated standardized data. It no longer treats individual alarms as independent events but attempts to restore the complete attack chain.

[0197] Then, perform pre-set response script-driven automated linkage handling: For the advanced threats determined above, security administrators have pre-arranged linkage response scripts on the platform. The scripts are a series of "IF-THEN" statements that clearly define the response actions and execution objects.

[0198] S63, implement automated orchestration and life cycle management of security policies.

[0199] The security control center platform uses the YD-SOMN protocol as the "nervous system", and according to the security situation and business requirements, performs automated orchestration and dynamic optimization of security policies in the triple defense system. The configuration data is sent down in Yaml format through the data bus.

[0200] Figure 7 This is the security control computing system architecture diagram used in the construction method of the trusted control network platform of the present invention. As Figure 7 shown, the computing power network framework has an overall architecture with the horizontal integration of the "management network - control network - service network or cloud-edge technology integration, and the vertical penetration of the 'triple defense system supported by one center' architecture, and the use of 'trusted, manageable, and controllable' active defense network security" as the main body. This computing power network uses SD-WAN to form a deterministic network, achieving network visualization, path visualization, fault visualization, and on-demand scheduling of the computing power network. At the same time, the security control computing system consists of a "4-horizontal 2-vertical" command layer, management network, control network, service access network; and a two-vertical system structure of 6 major security capabilities and trusted password services.

[0201] Implementing this embodiment has the beneficial effects that: (1) Enhanced overall security: The basic security architecture and trusted foundation provide a unified root of trust for upper-layer components, thus consolidating the security foundation from the source. Multi-dimensional trusted verification and dynamic access control strictly screen access entities to prevent unauthorized access. Intelligent boundary protection and deep detection system build a multi-layered defense line to effectively identify and block various threats and ensure the security of all areas of the network. (2) Ensures secure data transmission: The unified secure communication tunnel and cross-domain transmission guarantee mechanism ensure that the confidentiality and integrity of data are not compromised throughout the entire network transmission process, especially when crossing trusted domains, thus avoiding the risk of data leakage and tampering; (3) Improved system compatibility and collaboration: Standardized security function interfaces and collaboration protocols solve the data communication problem between heterogeneous security components, enabling different components to seamlessly connect and collaborate efficiently, thereby improving the overall security protection performance; (4) Intelligent security operation has been achieved: continuous trust assessment and automated operation management closed loop, which transforms security protection from static passive to dynamic proactive. Through continuous monitoring and automated response, security threats can be dealt with in a timely manner, reducing the cost of manual intervention, improving the efficiency and accuracy of security operation, and providing comprehensive and sustainable security protection for the stable operation of the network platform.

[0202] This invention can be used in a wide variety of general-purpose or special-purpose computer system environments or configurations. Examples include: personal computers, server computers, handheld or portable devices, tablet devices, multiprocessor systems, microprocessor-based systems, set-top boxes, programmable consumer electronics, network PCs, minicomputers, mainframe computers, and distributed computing environments including any of the above systems or devices. This invention can be described in the general context of computer-executable instructions, such as program modules, that are executed by a computer. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform specific tasks or implement specific abstract data types. This invention can also be practiced in distributed computing environments where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.

[0203] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by instructing related hardware through computer-readable instructions. These computer-readable instructions can be stored in a computer-readable storage medium. When the program is executed, it can include the processes of the embodiments of the above methods. The aforementioned storage medium can be a non-volatile storage medium such as a magnetic disk, optical disk, or read-only memory (RM), or random access memory (RAM).

[0204] It should be understood that although the steps in the flowcharts of the accompanying figures are shown sequentially as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the accompanying figures may include multiple sub-steps or multiple stages. These sub-steps or stages are not necessarily completed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the sub-steps or stages of other steps.

[0205] Example 2 Further reference Figure 8 As a response to the above Figure 1 The present invention provides an embodiment of a trusted management and control network platform construction device, which implements the method shown. Figure 1 Corresponding to the method embodiments shown, this device can be specifically applied to various electronic devices.

[0206] like Figure 8 As shown, the trusted management and control network platform construction device 70 described in this embodiment includes: a construction module 71, an access control module 72, a deployment module 73, a security module 74, a standardization module 75, and a closed-loop module 76. Wherein: Module 71 is used to build a basic security architecture and a trusted foundation. The basic security architecture provides a unified root of trust and management core for the collaborative operation of upper-layer security components. The access control module 72 is used to implement multi-dimensional trusted verification and dynamic access control based on the basic security architecture and the trusted base; Deployment module 73 is used to deploy an intelligent boundary protection and deep detection system, which is used to build an intelligent, three-dimensional and adaptive security defense line at the boundaries of various network areas, capable of identifying and blocking various known and unknown threats; The protection module 74 is used to build a unified secure communication tunnel and cross-domain transmission protection to ensure that data remains confidential and intact throughout the entire network transmission process, especially when crossing different trust domains. Standardization module 75 is used to define and implement standardized security function interfaces and collaboration protocols, and to solve the data communication problem between heterogeneous security components through standardized protocols. The closed-loop module 76 is used to establish a closed loop for continuous trust assessment and automated operation and control, which transforms security protection from a static and passive mode to a dynamic, proactive mode based on continuous monitoring and automated response.

[0207] The beneficial effects of implementing this embodiment are: enhanced overall security, guaranteed secure data transmission, improved system compatibility and collaboration, and intelligent security operation.

[0208] Example 3 To address the aforementioned technical problems, embodiments of the present invention also provide an electronic device. Please refer to [link / reference needed]. Figure 9 , Figure 9 This is a basic structural block diagram of the electronic device in this embodiment.

[0209] The aforementioned electronic device 8 includes a memory 81, a processor 82, and a network interface 83 that are interconnected via a system bus. It should be noted that only the electronic device 8 with components 81, 82, and 83 is shown in the figure; however, it should be understood that it is not required to implement all the shown components, and more or fewer components can be implemented alternatively. Those skilled in the art will understand that the electronic device described herein is a device capable of automatically performing numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes, but is not limited to, microprocessors, application-specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.

[0210] The aforementioned electronic devices can be computing devices such as desktop computers, laptops, handheld computers, and cloud servers. These electronic devices can interact with users via keyboards, mice, remote controls, touchpads, or voice-activated devices.

[0211] The aforementioned memory 81 includes at least one type of readable storage medium, including flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory), random access memory (RAM), static random access memory (SRAM), read-only memory (RM), electrically erasable programmable read-only memory (EEPRM), programmable read-only memory (PRM), magnetic memory, magnetic disk, optical disk, etc. In some embodiments, the aforementioned memory 81 may be an internal storage unit of the aforementioned electronic device 8, such as the hard disk or memory of the electronic device 8. In other embodiments, the aforementioned memory 81 may also be an external storage device of the aforementioned electronic device 8, such as a plug-in hard disk, smart media card (SMC), secure digital (SD) card, flash card, etc., equipped on the electronic device 8. Of course, the aforementioned memory 81 may also include both internal storage units and external storage devices of the aforementioned electronic device 8. In this embodiment, the aforementioned memory 81 is typically used to store the operating system and various application software installed on the aforementioned electronic device 8, such as computer-readable instructions for a trusted management network platform construction method. In addition, the aforementioned memory 81 can also be used to temporarily store various types of data that have been output or will be output.

[0212] In some embodiments, the processor 82 described above may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chip. The processor 82 is typically used to control the overall operation of the electronic device 8. In this embodiment, the processor 82 is used to execute computer-readable instructions stored in the memory 81 or to process data, for example, to execute computer-readable instructions for the trusted management network platform construction method described above.

[0213] The aforementioned network interface 83 may include a wireless network interface or a wired network interface, which is typically used to establish communication connections between the aforementioned electronic device 8 and other electronic devices.

[0214] The beneficial effects of implementing this embodiment are: enhanced overall security, guaranteed secure data transmission, improved system compatibility and collaboration, and intelligent security operation.

[0215] Example 4 The present invention also provides another embodiment, namely, providing a computer-readable storage medium storing computer-readable instructions that can be executed by at least one processor to cause the at least one processor to perform the steps of the trusted management network platform construction method described above.

[0216] The beneficial effects of implementing this embodiment are: enhanced overall security, guaranteed secure data transmission, improved system compatibility and collaboration, and intelligent security operation.

[0217] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as RM / RAM, magnetic disk, optical disk) and includes several instructions to cause a terminal device (which may be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods of the various embodiments of the present invention.

[0218] Obviously, the embodiments described above are merely some embodiments of the present invention, not all embodiments. The accompanying drawings show preferred embodiments of the present invention, but do not limit the patent scope of the present invention. The present invention can be implemented in many different forms; rather, these embodiments are provided to provide a more thorough and complete understanding of the disclosure of the present invention. Although the present invention has been described in detail with reference to the foregoing embodiments, those skilled in the art can still modify the technical solutions described in the foregoing specific embodiments, or make equivalent substitutions for some of the technical features. Any equivalent structures made using the content of this specification and drawings, directly or indirectly applied to other related technical fields, are similarly within the patent protection scope of this invention.

Claims

1. A method for constructing a trusted management and control network platform, characterized in that, Includes the following steps: Construct a basic security architecture and a trusted foundation, wherein the basic security architecture is used to provide a unified root of trust and management core for the collaborative operation of upper-layer security components; Based on the aforementioned basic security architecture and trusted foundation, multi-dimensional trusted verification and dynamic access control are implemented. Deploy an intelligent boundary protection and deep detection system to build an intelligent, three-dimensional, and adaptive security defense line at the boundaries of various network areas, capable of identifying and blocking various known and unknown threats; Construct a unified secure communication tunnel and cross-domain transmission guarantee to ensure that data remains confidential and intact throughout the entire network transmission process, especially when crossing different trust domains; Define and implement standardized security function interfaces and collaboration protocols to solve data communication problems between heterogeneous security components through standardized protocols; Establish a closed loop of continuous trust assessment and automated operation and management to transform security protection from a static, passive model to a dynamic, proactive model based on continuous monitoring and automated response.

2. The method for constructing a trusted management and control network platform according to claim 1, characterized in that, The steps of constructing the basic security architecture and trusted foundation, wherein the basic security architecture provides a unified root of trust and management core for the collaborative operation of upper-layer security components, specifically include: Construct a three-layer architecture consisting of a computing power management and control network, a control network, and a service network; A SQY20 cryptographic service system based on national cryptographic algorithms is deployed on the three-layer architecture of computing power management network, control network and business network; Build a centralized security management and control center platform.

3. The method for constructing a trusted management and control network platform according to claim 1, characterized in that, The steps for implementing multi-dimensional trusted verification and dynamic access control based on the aforementioned basic security architecture and trusted foundation specifically include: Define and implement a trust verification model that integrates four elements: user / permission trust, device trust, application trust, and network communication trust. Establish a whitelist access mechanism based on door-knocking authentication; After a terminal connects, it undergoes continuous trust assessment through a security agent. Once a decrease in the terminal's trustworthiness is detected, the manageable application firewall performs dynamic permission adjustments or blocking operations.

4. The method for constructing a trusted management and control network platform according to claim 1, characterized in that, The aforementioned deployment of the intelligent boundary protection and deep detection system, used to build an intelligent, three-dimensional, and adaptive security defense line at the boundaries of various network areas, capable of identifying and blocking various known and unknown threats, specifically includes the following steps: Deploy manageable application firewalls at the boundaries of each security domain and configure access control rules for IP addresses, ports, protocols, and user identities; Integrate and enable multiple security modules on the border firewall, including web application protection, abnormal packet attack defense, scanning attack defense, DOS / DDOS attack protection, brute-force attack prevention, weak password protection, and compromised host protection; Establish a unified endpoint security configuration baseline, and enforce detection and control of service requests initiated by the endpoint through the downstream firewall. Control elements include the endpoint's hardware information, operating system version, patch status, and antivirus software status.

5. The method for constructing a trusted management and control network platform according to claim 1, characterized in that, The steps for constructing a unified secure communication tunnel and cross-domain transmission guarantee to ensure that data maintains confidentiality and integrity throughout the entire network transmission process, especially when crossing different trust domains, specifically include: Deploy end-to-end trusted VPN communication equipment; Optimize the software and accelerate the hardware of the terminal access controller and the secure communication platform at all levels to reduce the performance loss caused by encryption and decryption. By utilizing a secure isolation and information exchange system, a controlled data exchange channel is established at key cross-domain nodes such as the external access area of ​​the central office.

6. The method for constructing a trusted management and control network platform according to claim 1, characterized in that, The steps of defining and implementing standardized security function interfaces and collaboration protocols to solve data communication problems between heterogeneous security components through standardized protocols specifically include: Define the YD-SOMN software bus and object identifier ID; Define a family of security control protocols; Define a multi-parameter organizational model for the execution of security functions.

7. The method for constructing a trusted management and control network platform according to any one of claims 1 to 6, characterized in that, The steps for establishing a continuous trust assessment and automated operation management closed loop to transform security protection from a static, passive mode to a dynamic, proactive mode based on continuous monitoring and automated response specifically include: The auth.devCheck interface can be used to perform integrity checks on the device's operating environment periodically or triggered automatically. Through the security management and control center platform, data from multiple sources such as network traffic monitoring, host intrusion detection, log auditing, and situational awareness are aggregated to establish a comprehensive security situation view; To achieve automated orchestration and lifecycle management of security policies.

8. A trusted management and control network platform construction device, characterized in that, include: The building module is used to build the basic security architecture and trusted foundation. The basic security architecture provides a unified root of trust and management core for the collaborative operation of upper-layer security components. The access control module is used to implement multi-dimensional trusted verification and dynamic access control based on the basic security architecture and the trusted base. The deployment module is used to deploy an intelligent boundary protection and deep detection system, which is used to build an intelligent, three-dimensional, and adaptive security defense line at the boundaries of various network areas, capable of identifying and blocking various known and unknown threats; The protection module is used to build a unified secure communication tunnel and cross-domain transmission protection to ensure that data remains confidential and intact throughout the entire network transmission process, especially when crossing different trust domains. Standardization modules are used to define and implement standardized security function interfaces and collaboration protocols, and to solve data communication problems between heterogeneous security components through standardized protocols. The closed-loop module is used to establish a closed loop of continuous trust assessment and automated operation and management, transforming security protection from a static and passive mode to a dynamic, proactive mode based on continuous monitoring and automated response.

9. An electronic device, characterized in that, The system includes a memory and a processor, wherein the memory stores computer-readable instructions, and the processor executes the computer-readable instructions to implement the steps of the trusted management network platform construction method as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer-readable instructions, which, when executed by a processor, implement the steps of the trusted management network platform construction method as described in any one of claims 1 to 7.

Citation Information

Patent Citations

  • Trusted computing platform system based on dual-system architecture

    CN116796332A

  • Method and electronic equipment for constructing compliance capability of trusted control network based on Thevenin ring PDCA (Packet Data Convergence Analysis)

    CN117938489A

  • Structured protection system and method based on trusted control calculation

    CN118713847A

  • Software-defined-network-based cloud-edge collaborative defense system and method for unknown attacks

    WO2025194680A1

Cited By

  • Parallel computing and distributed network access risk management and control device and management and control method

    CN121098643A

  • Safe and trusted host access risk management and control system and method based on distributed management and control

    CN121193542A

  • Security and trust host access risk management system and method based on collection and distribution management

    CN121193542B

  • Security communication platform and method constructed based on security control and trusted network connection

    CN121217484A

  • Method and device for constructing network security management and control platform, electronic equipment and storage medium

    CN121486099A