Method and device for constructing secure and trusted functional component
By identifying the security requirements and encapsulation decision factors of the target system, dynamically matching the encapsulation mode and combining it with standardized interfaces and routing rules, the problem of the solidified security mechanism encapsulation mode in the existing technology is solved. This achieves high adaptability and high security of secure and trustworthy functional components, reduces development and maintenance costs, and supports highly available and real-time trusted construction.
Patent Information
- Application Number
- CN202511069007.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-31
- Publication Date
- 2025-12-09
AI Technical Summary
The encapsulation mode of security mechanisms in existing technologies is relatively rigid, lacking the ability to dynamically adapt to the number of participants, external decision-making requirements, and the degree of shielding of mechanism details. This results in poor adaptability of secure and trustworthy functional components, insufficient security, high development and maintenance costs, and an inability to support the requirements for highly available and real-time trusted construction.
By identifying the security requirements of the target system, key encapsulation decision factors such as the number of participants, whether external decision-making is introduced, and the degree of mechanism detail shielding are extracted. Pre-defined encapsulation modes such as black box, segmentation, window, or abstraction are dynamically matched, and standardized interfaces and routing rules are combined to achieve efficient integration of secure and reliable functional components.
It achieves a precise match between the encapsulation mode of security mechanisms and system requirements, improves the adaptability and security of secure and trustworthy functional components, reduces development and maintenance costs, and supports the requirements for highly available and real-time trusted construction.
Smart Images

Figure CN121098531A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular to a method and apparatus for constructing secure and trusted functional components. Background Technology
[0002] With the rapid development of information technology, cybersecurity threats are becoming increasingly diverse and complex, and traditional passive defense methods are no longer sufficient to meet the demands of dynamic attacks and complex business scenarios. In key areas such as industrial control systems, the Internet of Things, and zero-trust architectures, the requirements for security and trustworthiness have significantly increased, necessitating proactive immune mechanisms to achieve dynamic protection and real-time trusted verification. To address this challenge, my country has proposed an independent cybersecurity system, the core concept of which is to separate secure computing from business computing and achieve dynamic trusted assurance through independently operating security monitoring processes.
[0003] Currently, existing security mechanisms typically employ a single encapsulation and integration model, such as black-box encapsulation or segmented encapsulation. However, this single model is relatively rigid and lacks the dynamic adaptability to the number of participants, external decision-making requirements, and the degree of shielding of mechanism details. It cannot solve the matching problem between the encapsulation model of the security mechanism and system requirements, resulting in poor adaptability, insufficient security, and high development and maintenance costs for the constructed secure and trusted functional components. Consequently, it cannot effectively support the requirements for high availability and high real-time trusted construction. Summary of the Invention
[0004] In view of the above problems, this application provides a method and apparatus for constructing secure and trusted functional components. The main purpose is to achieve a precise match between the encapsulation mode of the security mechanism and the system requirements, improve the adaptability and security of the constructed secure and trusted functional components, reduce development and maintenance costs, and effectively support the requirements for trusted construction with high availability and high real-time performance.
[0005] To solve the above-mentioned technical problems, this application proposes the following solution:
[0006] In a first aspect, this application provides a method for constructing a secure and trusted functional component, the method comprising:
[0007] Identify the required target security mechanisms based on the security requirements of the target system;
[0008] Based on the mechanism type of the target security mechanism, the encapsulation decision factors corresponding to the target security mechanism are determined. The encapsulation decision factors include the number of participants, whether external decision-making is introduced, and whether mechanism details are hidden.
[0009] determine a target packaging mode in preset packaging modes according to the packaging decision factor, the preset packaging modes including black box packaging, segmented packaging, window packaging and abstract packaging, and the target packaging mode including at least any one of the black box packaging, the segmented packaging, the window packaging and the abstract packaging;
[0010] standardize the target security mechanism according to the target packaging mode to form a secure and trusted functional component with a unified interface;
[0011] integrate the packaged secure and trusted functional component into the target system through routing rules.
[0012] In a second aspect, the present application provides a secure and trusted functional component construction apparatus, which comprises:
[0013] an identifying unit configured to identify a target security mechanism required according to security requirements of a target system;
[0014] a first determining unit configured to determine a packaging decision factor corresponding to the target security mechanism based on a mechanism type of the target security mechanism obtained by the identifying unit, the packaging decision factor including a number of participants, whether to introduce external decision and whether to shield mechanism details;
[0015] a second determining unit configured to determine a target packaging mode in preset packaging modes according to the packaging decision factor obtained by the first determining unit, the preset packaging modes including black box packaging, segmented packaging, window packaging and abstract packaging, and the target packaging mode including at least any one of the black box packaging, the segmented packaging, the window packaging and the abstract packaging;
[0016] a packaging unit configured to standardize the target security mechanism according to the target packaging mode obtained by the second determining unit to form a secure and trusted functional component with a unified interface;
[0017] an integrating unit configured to integrate the packaged secure and trusted functional component obtained by the packaging unit into the target system through routing rules.
[0018] In order to achieve the above-mentioned purpose, according to a third aspect of the present application, a storage medium is provided, which comprises a stored program, wherein the storage medium controls a device where the storage medium is located to execute the secure and trusted functional component construction method of the first aspect when the program is running.
[0019] In order to achieve the above-mentioned purpose, according to a fourth aspect of the present application, a processor is provided, which is used to run a program, wherein the program executes the secure and trusted functional component construction method of the first aspect when the program is running.
[0020] By the above technical solution, the safe and reliable functional component construction method and device provided by the application is that when it is necessary to construct a safe and reliable functional component, first, the target security mechanism required is identified according to the security requirement of the target system, then the packaging decision factors corresponding to the target security mechanism are determined based on the mechanism type of the target security mechanism, the packaging decision factors include the number of participants, whether to introduce external decision, and whether to shield mechanism details, then the target packaging mode is determined in the preset packaging mode according to the packaging decision factors, the preset packaging mode includes black box packaging, segmented packaging, window packaging and abstract packaging, the target packaging mode at least includes any one of the black box packaging, the segmented packaging, the window packaging and the abstract packaging, the target security mechanism is packaged according to the target packaging mode, a safe and reliable functional component with a unified interface is formed, and finally the packaged safe and reliable functional component is integrated into the target system through routing rules. The technical solution provided by the application is based on the security requirement of the target system, the packaging decision factors of the number of participants, whether to introduce external decision, and whether to shield mechanism details are identified, the target packaging mode is dynamically matched in the black box packaging, the segmented packaging, the window packaging and the abstract packaging, the safe and reliable functional component with a unified interface is formed through standardized packaging, and the safe and reliable functional component is directly integrated into the target system combined with the routing rules, a dynamic packaging decision mechanism is constructed, the limitation of the traditional single packaging mode is broken, the accurate matching of the packaging mode of the security mechanism and the system requirement is realized, the adaptability and safety of the constructed safe and reliable functional component are improved, the development and maintenance cost is reduced, and the high availability and high real-time reliability of the trusted construction requirement is effectively supported.
[0021] The above description is only a summary of the technical solution of the application. In order to enable the technical means of the application to be more clearly understood, the specific embodiments of the application can be implemented according to the content of the description, and in order to enable the above and other purposes, characteristics and advantages of the application to be more obvious and easy to understand, the following specific embodiments of the application are described. BRIEF DESCRIPTION OF DRAWINGS
[0022] By reading the detailed description of the preferred embodiments below, various other advantages and benefits will become apparent to those of ordinary skill in the art. The drawings are only for the purpose of illustrating the preferred embodiments and are not considered to be limiting on the application. Moreover, the same reference symbols are used throughout the drawings to represent the same components. In the drawings:
[0023] Figure 1 A safe and reliable functional component construction method flowchart provided by an embodiment of the application is shown;
[0024] Figure 2 Another safe and reliable functional component construction method flowchart provided by an embodiment of the application is shown;
[0025] Figure 3 A component block diagram of a secure and trusted function component construction device provided by an embodiment of the present application is shown;
[0026] Figure 4 A component block diagram of another secure and trusted function component construction device provided by an embodiment of the present application is shown;
[0027] Figure 5 A schematic diagram of a secure and trusted function component packaging mode provided by an embodiment of the present application is shown. DETAILED DESCRIPTION
[0028] Exemplary embodiments of the present application will be described herein below with reference to the accompanying drawings. Although exemplary embodiments of the present application are shown in the drawings, it should be understood that the present application can be implemented in various forms and should not be limited by the embodiments set forth herein. Rather, these embodiments are provided so that the present application can be more thoroughly understood and so that the scope of the present application can be accurately conveyed to those skilled in the art.
[0029] Currently, the security mechanism in the prior art is usually packaged and integrated in a single mode, such as black box packaging, segmented packaging, etc. However, this single mode is relatively rigid, lacks dynamic adaptation capability for the number of participants, external decision-making demand, and shielding degree of mechanism details, and cannot solve the matching problem between the packaging mode of the security mechanism and the system demand, resulting in poor adaptability, insufficient security, high development and maintenance costs, and other problems of the secure and trusted function component, which cannot effectively support the trusted construction demand of high availability and high real-time performance.
[0030] The inventors have found that the security demand of a target system can be identified and key packaging decision factors such as the number of participants, whether to introduce external decision-making, the shielding degree of mechanism details, etc. can be extracted, and preset packaging modes such as black box, segmentation, window, or abstraction can be dynamically matched, and the efficient integration of secure and trusted function components can be realized in combination with standardized interfaces and routing rules. In this way, the limitations of traditional single packaging modes can be broken through, the system can adjust the packaging strategy in real time according to the system demand, the dynamic adaptation capability and security of the secure and trusted function component can be significantly improved, the development complexity can be reduced through interface unification and protocol compatibility, the development and maintenance costs can be reduced, and the trusted construction demand of high availability and high real-time performance can be effectively supported.
[0031] Based on the above considerations, the embodiment of the present application provides a secure and trusted function component construction method, which can realize the precise matching of the encapsulation mode of the security mechanism and the system requirements, improve the adaptability and security of the constructed secure and trusted function component, reduce the development and maintenance cost, and effectively support the trusted construction requirements of high availability and high real-time performance. The execution subject of the embodiment can be a specific module or component that actually executes the security monitoring process, security mechanism or business logic in the core platform of the autonomous trusted computing system. The specific execution steps are as shown in Figure 1 include:
[0032] 101. According to the security requirements of the target system, identify the required target security mechanism.
[0033] In this step, the target system refers to the running environment of the business computing task that needs to apply the security monitoring process, including but not limited to industrial control systems, Internet of Things, zero-trust architecture, etc. By analyzing the business scenario of the target system, the security requirements are determined, including security, real-time performance, compatibility and other key attributes. Specifically, the security requirements can be determined in combination with the resource subject of the business scenario and the purpose of the resource subject, the resource subject is used to represent the key resources that need to be protected or managed in the business scenario, and the purpose is used to represent the function of the resource subject in the business scenario. The security requirements are refined into specific security functions, such as data encryption, identity authentication, etc.
[0034] A mechanism library is constructed in advance according to all the security mechanisms required by the target system, and corresponding security attributes are defined for each security mechanism, such as access control, intrusion detection, data integrity verification, etc. The target security mechanism can be matched in the mechanism library in combination with the corresponding attributes of the security requirements.
[0035] 102. Based on the mechanism type of the target security mechanism, determine the encapsulation decision factors corresponding to the target security mechanism.
[0036] Among them, the encapsulation decision factors include the number of participants, whether to introduce external decision, and whether to shield the mechanism details.
[0037] Due to the differences in the functional characteristics, collaboration requirements and technical implementation of different mechanism types, these differences directly determine the core decision factors that need to be concerned in the packaging process, i.e., packaging decision factors. In this step, the packaging decision factors include the number of participants, whether to introduce external decision-making, and whether to shield mechanism details. The number of participants determines whether the security mechanism is a single-party mechanism or a multi-party mechanism when the security mechanism is packaged as a standardized component. For example, local encryption algorithms usually involve only a single system or user, while distributed identity authentication and cross-system data synchronization involve multiple participants and require a phased process. Whether to introduce external decision-making determines whether the security mechanism requires external system or third-party service decision input when the security mechanism is packaged as a standardized component. For example, static encryption algorithms do not require external input, while threat intelligence-based intrusion detection and policy dynamic adjustment require external decision-making, such as real-time attack databases and user behavior analysis. Whether to shield mechanism details determines whether the security mechanism needs to be isolated to hide its details when it is packaged as a standardized component. For example, log recording and audit tracking need to expose some implementation details for monitoring, while cryptographic algorithms and hardware-level security modules need to completely hide implementation details to prevent reverse engineering.
[0038] By counting the number of entities (such as users, devices, and servers) involved in the mechanism type of the target security mechanism, it is determined whether multi-stage verification or distributed collaboration is needed, thereby determining the number of participants. According to whether the business requirements corresponding to the mechanism type of the target security mechanism require dynamic invocation of external decision-making interfaces, it is determined whether external decision-making is needed. By analyzing the transparency requirements of the mechanism type of the target security mechanism, it is determined whether mechanism details need to be shielded. Based on this, the packaging decision factors corresponding to the target security mechanism are obtained.
[0039] 103. Determine the target packaging mode in the preset packaging modes according to the packaging decision factors.
[0040] The preset packaging modes include black box packaging, segmented packaging, window packaging, and abstract packaging, and the target packaging mode at least includes any one of black box packaging, segmented packaging, window packaging, and abstract packaging.
[0041] In this step, black box packaging, segmented packaging, window packaging, and abstract packaging are implemented in a message-driven manner. The packaged component provides one or more message input / output interfaces and format requirements for the message input / output interfaces to the outside. The logic of the internal security mechanism of the component is dispersed in different modules, and the security mechanism logic is triggered to execute in sequence through the propagation of messages between modules. The specific description and implementation are as follows: Black box packaging is to put the packaging object into a black box for overall packaging, such as Figure 5As shown in Figure 5-a, black-box encapsulation is the most basic encapsulation pattern, often used for encapsulating algorithm components. When implementing black-box encapsulation, the formats of input and output messages can be defined separately according to the data requirements of the security mechanism's input and output. The black box provides interfaces for message input and output. When using it, the user inputs messages conforming to the input message format into the black box, receives the black box's output messages, and performs subsequent operations. Furthermore, the input and output messages of the security mechanism can be added to the input and output messages as extension items (this also applies to other encapsulation mechanisms).
[0042] Segmented encapsulation is an encapsulation pattern for security functions that are executed in stages, such as... Figure 5 As shown in Figure 5-b, component functionality is encapsulated into multiple black boxes. These black boxes can access different components at different stages, allowing the component mechanisms within each black box to collaboratively implement security functions. This approach is often used for encapsulating security protocols. During segmented encapsulation, the input and output message formats for each segment black box are defined according to the input and output data requirements of different functional segments of the security mechanism. The security monitoring process of calling the security mechanism is itself a message transmission process. When calling the security mechanism, at the locations where each segment of the security mechanism needs to be executed, input and output modules adapted to that segment are added, allowing messages to pass through all segments of the security mechanism in sequence during transmission, completing the entire security mechanism.
[0043] Window encapsulation is a method of encapsulating security mechanisms that require external decision-making assistance, such as... Figure 5 As shown in Figure 5-c, this involves setting up one or more window flows within the component. When using the component at a higher level, an additional window module needs to be provided to access the window location to support the external decision-making process. During window encapsulation implementation, the input and output message formats can be defined first according to the input and output data requirements of the security mechanism. Then, based on the data requirements of the security mechanism during decision-making and the format of the decision result, the input and output message formats of the decision window are defined. The message routing process within the window encapsulation is from the input module to the window front-end module, then to the window back-end module, and finally to the output module. When using this security mechanism, the decision module connects between the window front-end module and the window back-end module, thus forming a complete message path from the security mechanism's input module to the output module.
[0044] Abstraction and encapsulation are used to provide a unified interface to the upper layers, shielding them from the technical details of the underlying mechanisms, such as... Figure 5The general security function is realized by two-layer encapsulation. The components are divided into an abstract layer and a mechanism layer. The mechanism layer operates the security mechanism, and the abstract layer realizes the format conversion between the standard input / output messages and the mechanism layer messages, which is used to adapt the standard component interface with non-standard components. When the abstract encapsulation is implemented, the abstract layer and the mechanism layer can be developed in parallel. The abstract layer provides a coarse-grained, objectified abstract layer message format interface according to the application requirements, and the mechanism layer determines the input / output message format according to the mechanism's own strategy and return information. Then, in the abstract layer module, the conversion from the abstract layer input message to the mechanism layer input message is realized at the input end, and the conversion from the mechanism layer output message to the abstract layer output message is realized at the output end. Finally, the abstract layer input conversion part is connected between the encapsulation component entrance and the mechanism layer message entrance, and the abstract layer output conversion part is connected between the mechanism layer message exit and the encapsulation component exit, thus completing the abstract encapsulation.
[0045] It should be noted that whether to use black box encapsulation or segmented encapsulation depends on the "number of participants" in the encapsulation decision factors, i.e. single-party mechanism uses black box encapsulation, and multi-party mechanism uses segmented encapsulation. On this basis, whether to use window encapsulation depends on whether to introduce external decision in the encapsulation decision factors. Whether to use abstract encapsulation depends on whether to shield the mechanism details in the encapsulation decision factors. According to the actual needs of the above-mentioned encapsulation, multiple encapsulation modes can be combined as the final target encapsulation mode to realize the functional decoupling and dynamic expansion of the finally constituted trusted functional components.
[0046] For example, when the number of participants is single, if no external decision is introduced and the mechanism details are not shielded, the black box encapsulation is determined as the target encapsulation mode, if the external decision is introduced and the mechanism details are not shielded, the window encapsulation is determined as the target encapsulation mode, and if the number of participants is single, the external decision is introduced and the mechanism details are shielded, the superimposed encapsulation combination of window encapsulation and abstract encapsulation is determined as the target encapsulation mode. When the number of participants is multi, if no external decision is introduced and the mechanism details are not shielded, the segmented encapsulation is determined as the target encapsulation mode, if the external decision is introduced and the mechanism details are not shielded, the superimposed encapsulation combination of segmented encapsulation and window encapsulation is determined as the target encapsulation mode, and if the external decision is introduced and the mechanism details are shielded, the superimposed encapsulation combination of segmented encapsulation, window encapsulation and abstract encapsulation is determined as the target encapsulation mode.
[0047] 104. Standardize the target security mechanism according to the target encapsulation mode to form a secure trusted functional component with a unified interface.
[0048] In this step, a unified interface specification is predefined to ensure that the encapsulated secure and trusted function component can be called through a standard protocol. If the target encapsulation mode involves black box encapsulation, the implementation details of the security mechanism are encapsulated as a binary module, and only the input and output interfaces are retained. If the target encapsulation mode involves segmented encapsulation, the multi-stage verification process is split into independent components and executed in series through segmented interfaces. If the target encapsulation mode involves window encapsulation, an external decision entry is reserved in the interface to support runtime parameter adjustment. If the target encapsulation mode involves abstract encapsulation, different protocols are compatible through abstract classes or middleware to achieve seamless integration of heterogeneous systems.
[0049] 105. Integrate the encapsulated secure and trusted function component into the target system through routing rules.
[0050] In this step, according to the network topology and business logic of the target system, corresponding routing rules are formulated. For example, the access path and forwarding logic of the secure and trusted function component in the target system are defined in the interface specification in step 104, that is, the access path and forwarding logic are deployed to the target system as standardized format routing rules, so that the secure and trusted function component is integrated into the target system.
[0051] Based on the above Figure 1 , it can be seen that the secure and trusted function component construction method provided by the present application is based on the security requirements of the target system, and through the identification of the number of participants, whether to introduce external decision, and whether to shield the encapsulation decision factors of mechanism details, the target encapsulation mode is dynamically matched in black box encapsulation, segmented encapsulation, window encapsulation and abstract encapsulation, and the secure and trusted function component with a unified interface is formed through standardized encapsulation, and is directly integrated into the target system combined with routing rules, a dynamic encapsulation decision mechanism is constructed, which breaks through the limitation of traditional single encapsulation mode, realizes the precise matching of the encapsulation mode of the security mechanism and the system requirements, improves the adaptability and security of the constructed secure and trusted function component, reduces the high development and maintenance cost, and effectively supports the trusted construction requirements of high availability and high real-time performance.
[0052] Further, the preferred embodiment of the present application is a detailed description of the process of constructing a secure and trusted function component based on the above Figure 1 , and the specific steps are as shown in Figure 2 , including:
[0053] 201. Determine the business scenario of the target system and identify the resource subject corresponding to the business scenario and the use of the resource subject.
[0054] Among them, the resource subject is used to represent the key resources that need to be protected or managed in the business scenario, and the use is used to represent the function of the resource subject in the business scenario.
[0055] In this step, according to the business scenario of the target system, its corresponding business scenario is determined. The business scenario is used to describe the business process of the target system. For example, in the cooperative pursuit scene of the public security bureau and the traffic bureau, the business process includes: AI model training, data transmission, inference execution, result return. The resource subject refers to the key resources that need to be protected or managed in the business scenario, such as data, computing resources, network resources, etc. For example, the data can be an AI model, pursuit data, and inference result; the computing resource can be the training ability of server A and the inference ability of server B; the network resource can be the communication channel between server A and B. The use refers to the function of the resource subject in the business scenario, which needs to be defined in combination with the security requirements. For example, the AI model is used for inference of the pursuit task, which needs to ensure its integrity and confidentiality, and the communication channel is used for transmitting pursuit data, which needs to prevent tampering and eavesdropping.
[0056] 202. Determine the security requirements based on the resource subject and the use.
[0057] In this step, the security requirements of the target system can be further determined through the determination of the resource subject and the use. For example, data integrity: the trigger condition is that the resource subject is data and the use involves integrity protection (such as AI model needs to prevent tampering), and its security requirement can be to use data binding / unbinding components. Access control: the trigger condition is that the resource subject is a computing resource and the use involves permission management (such as only allowing server A to call the model), and its security requirement is to deploy an eBPF isolation component. Confidentiality: the trigger condition is that the resource subject is a communication channel and the use involves data encryption (such as transmission of pursuit data), and its security requirement can be to use a key exchange component.
[0058] It should be noted that when determining the security requirements, the corresponding priority of the security requirements can also be further set. The priority can be set in combination with the business scenario, that is, one business scenario corresponds to the priority of one security requirement, for example, in the AI pursuit scene, the priority of the security requirement is: data integrity > confidentiality > access control. Specifically, the sensitivity and business dependency of the resource subject can be scored, for example, the sensitivity of the AI model is 5 / 5 and the sensitivity of the communication channel is 4 / 5. High-priority requirements need to be met, such as data integrity. Low-priority requirements can be dynamically adjusted, such as access control can be configured through a policy.
[0059] 203. Match the target security mechanism in the preset mechanism library according to the attribute corresponding to the security requirement.
[0060] Among them, the mechanism library is constructed according to the security mechanisms required by all business scenarios of the target system.
[0061] In this step, since the target system can be used for one business scenario or multiple business scenarios, a mechanism library can be constructed in combination with the security mechanisms required by all business scenarios involved. The security mechanisms can be classified, for example, algorithm components: such as AES encryption, SHA-256 hashing (black box encapsulation). Protocol components: such as data binding / unbinding protocols (segment encapsulation). Driver components: such as TCM device drivers (abstract encapsulation). Add an attribute tag to each security mechanism, which is used to match with security requirements. When the attributes of the security requirements are determined, the corresponding security mechanisms can be screened in the mechanism library based on the attribute tags to obtain the target security mechanism.
[0062] 203、Extract the target typical characteristics corresponding to the mechanism type of the target security mechanism.
[0063] It should be noted that before this step, it also includes: extracting the typical characteristics corresponding to the mechanism type of each security mechanism from the mechanism library; obtaining the trigger conditions corresponding to each encapsulation mode in the preset encapsulation mode; and constructing a feature-condition mapping rule according to the logical association between the typical characteristics and the trigger conditions.
[0064] Since the mechanism library contains all the security mechanisms required by the target system for all business scenarios, the typical characteristics of each security mechanism in the mechanism library can be extracted, which is an inherent attribute of the security mechanism itself, used to describe its function, collaboration requirements and technical characteristics, such as the number of participants, whether external decision is needed, etc. The typical characteristics are input attributes, which are metadata of each security mechanism in the mechanism library, used to describe what the mechanism is. By extracting the typical characteristics, it can be determined that the mechanism type of the security mechanism itself has which characteristics. The trigger condition is a decision factor for selecting which encapsulation, which is used to determine which encapsulation mode is suitable for the current mechanism. The trigger condition is an output rule, which is the "judgment basis" for encapsulation mode selection, used to determine which encapsulation mode is suitable for the current mechanism. For example, black box encapsulation: few participants, no external decision required, need to completely shield details. Segment encapsulation: multi-stage protocol, need to be executed in stages. Window encapsulation: need external decision support. Abstract encapsulation: cross-platform compatibility, need to shield technical details.
[0065] Since the typical characteristics are input attributes, used to describe "what the mechanism is", and the trigger condition is an output rule, which is the "judgment basis" for encapsulation mode selection, used to determine which encapsulation mode is suitable for the current mechanism, i.e. there is a clear logical association between the two, by mapping this logical association, a mapping rule between the typical characteristics and the trigger conditions can be constructed, i.e. a feature-condition mapping rule is obtained. The feature-condition mapping rule is used to determine the corresponding trigger condition through the typical characteristics.
[0066] In this step, after the target typical feature corresponding to the mechanism type of the target security mechanism is extracted, the target trigger condition corresponding to the target typical feature can be determined according to the feature-condition mapping rule.
[0067] 205、Based on the target typical feature, the target trigger condition corresponding to the target typical feature is dynamically matched in the feature-condition mapping rule, and the target trigger condition is taken as the encapsulation decision factor corresponding to the target security mechanism.
[0068] In this step, by referring to the feature-condition mapping rule, the target trigger condition matching the target typical feature can be found. Since the trigger condition is the decision factor of each encapsulation mode, the target trigger condition can be taken as the encapsulation decision factor corresponding to the target security mechanism for subsequent use.
[0069] 206、According to the encapsulation decision factor, the target encapsulation mode is determined in the preset encapsulation mode.
[0070] This step combines the description of step 103 in the above method, and the same content will not be repeated here. It should be noted that, in combination with the number of participants, whether to introduce external decision and whether to shield mechanism details, the specific execution process of determining the target encapsulation mode in the preset encapsulation mode is as follows: if the number of participants is single, no external decision is introduced, and the mechanism details are not shielded, the black box encapsulation is determined as the target encapsulation mode; if the number of participants is single, the external decision is introduced, and the mechanism details are not shielded, the window encapsulation is determined as the target encapsulation mode; if the number of participants is single, the external decision is introduced, and the mechanism details are shielded, the combination of window encapsulation and abstract encapsulation is determined as the target encapsulation mode; if the number of participants is multiple, no external decision is introduced, and the mechanism details are not shielded, the segmented encapsulation is determined as the target encapsulation mode; if the number of participants is multiple, the external decision is introduced, and the mechanism details are not shielded, the combination of segmented encapsulation and window encapsulation is determined as the target encapsulation mode; if the number of participants is multiple, the external decision is introduced, and the mechanism details are shielded, the combination of segmented encapsulation, window encapsulation and abstract encapsulation is determined as the target encapsulation mode.
[0071] 207、According to the target encapsulation mode, the target security mechanism is standardized encapsulated to form a security and trusted functional component with a unified interface.
[0072] This step combines the description of step 104 in the above method, and the same content will not be repeated here.
[0073] 208、The encapsulated security and trusted functional component is integrated into the target system through routing rules.
[0074] This step combines the description of step 105 in the above method, and the same content will not be repeated here.
[0075] It should be noted that the specific implementation process of integrating the encapsulated secure and trusted function component into the target system through the routing rule is as follows: obtaining the interface specification corresponding to the unified interface; defining the access path and forwarding logic of the secure and trusted function component in the target system in the interface specification; deploying the access path and forwarding logic as the routing rule in the standardized format to the target system, so as to integrate the secure and trusted function component into the target system.
[0076] In this step, the interface specification is obtained by using tools such as Swagger and Postman to automatically generate interface documents. The access path is defined in the interface specification, that is, the access path is divided according to the function of the secure and trusted function component, to ensure that the path is clear and easy to maintain. The forwarding logic is defined according to the architecture of the target system (such as microservices and gateways), including load balancing, service discovery, routing matching, etc. The routing rule is dynamically updated through service registration and discovery to adapt to system expansion and component changes. The standardized format such as YAML / JSON is adopted to ensure the cross-platform compatibility of the routing rule. The routing rule is written into the configuration file of the target system, which is suitable for fixed scenarios. The routing rule is dynamically issued through the configuration center to support hot updating.
[0077] Further, as an implementation of the method embodiment described above Figures 1-2 The embodiment of the present application provides a secure and trusted function component construction device. The device is used to realize the accurate matching of the encapsulation mode of the security mechanism and the system requirement, improve the adaptability and security of the constructed secure and trusted function component, reduce the development and maintenance cost, and effectively support the trusted construction requirement of high availability and high real-time performance. The embodiment of the device corresponds to the foregoing method embodiment. For ease of reading, the details in the foregoing method embodiment will not be described one by one in this embodiment, but it should be clear that the device in this embodiment can correspondingly realize all the contents in the foregoing method embodiment. Specifically, as shown in Figure 3 The device comprises:
[0078] The identification unit 31 is configured to identify the required target security mechanism according to the security requirement of the target system.
[0079] The first determination unit 32 is configured to determine the encapsulation decision factor corresponding to the target security mechanism based on the mechanism type of the target security mechanism obtained by the identification unit 31. The encapsulation decision factor includes the number of participants, whether to introduce external decision, and whether to shield the mechanism details.
[0080] The second determining unit 33 is used to determine a target packaging mode in a preset packaging mode based on the packaging decision factors obtained by the first determining unit 32. The preset packaging modes include black-box packaging, segmented packaging, window packaging, and abstract packaging. The target packaging mode includes at least one of the black-box packaging, segmented packaging, window packaging, and abstract packaging.
[0081] The encapsulation unit 34 is used to standardize the encapsulation of the target security mechanism according to the target encapsulation mode obtained by the second determining unit 33, so as to form a secure and reliable functional component with a unified interface.
[0082] Integration unit 35 is used to integrate the encapsulated secure and trusted functional components obtained by encapsulation unit 34 into the target system through routing rules.
[0083] Furthermore, such as Figure 4 As shown, the second determining unit 33 is specifically used for,
[0084] If the number of participants is unilateral, no external decision-making is introduced, and the mechanism details are not hidden, then the black-box encapsulation determines the target encapsulation mode;
[0085] If the number of participants is unilateral, the external decision-making is introduced, and the mechanism details are not hidden, then the window encapsulation is determined as the target encapsulation mode;
[0086] If the number of participants is unilateral, the external decision-making is introduced, and the mechanism details are hidden, then the superimposed encapsulation combination formed by the window encapsulation and the abstract encapsulation is determined as the target encapsulation mode.
[0087] Furthermore, such as Figure 4 As shown, the second determining unit 33 is also used for,
[0088] If there are multiple participants, without introducing external decisions and without shielding the mechanism details, then the segmented encapsulation determines the target encapsulation mode;
[0089] If there are multiple participants, external decision-making is introduced, and the mechanism details are not hidden, then the superimposed encapsulation combination of the segmented encapsulation and the window encapsulation is determined as the target encapsulation mode.
[0090] If there are multiple participating parties, external decision-making is introduced, and the mechanism details are hidden, then the superimposed encapsulation combination consisting of segmented encapsulation, window encapsulation, and abstract encapsulation is determined as the target encapsulation mode.
[0091] Furthermore, such as Figure 4As shown, the identification unit 31 comprises:
[0092] An identification module 311 is configured to determine a business scenario of the target system, and identify a resource subject corresponding to the business scenario and a use corresponding to the resource subject, the resource subject being used to represent a key resource that needs to be protected or managed in the business scenario, and the use being used to represent a function of the resource subject in the business scenario;
[0093] A determination module 312 is configured to determine the security requirement based on the resource subject and the use obtained by the identification module 311.
[0094] A first matching module 313 is configured to match the target security mechanism in a preset mechanism library according to an attribute corresponding to the security requirement obtained by the determination module 312, the mechanism library being constructed according to security mechanisms required by all business scenarios of the target system.
[0095] Further, as shown in the figure, Figure 4 The apparatus further comprises:
[0096] An extraction unit 36 is configured to extract, before the first determination unit 32, a typical feature corresponding to a mechanism type of each security mechanism from the mechanism library;
[0097] An acquisition unit 37 is configured to acquire a trigger condition corresponding to each encapsulation mode in the preset encapsulation mode;
[0098] A construction unit 38 is configured to construct the feature-condition mapping rule according to a logical association between the typical feature obtained by the extraction unit 36 and the trigger condition obtained by the acquisition unit 37;
[0099] The first determination unit 32 comprises:
[0100] An extraction module 321 is configured to extract a target typical feature corresponding to a mechanism type of the target security mechanism;
[0101] A second matching module 322 is configured to dynamically match a target trigger condition corresponding to the target typical feature in the feature-condition mapping rule based on the target typical feature obtained by the extraction module 321, and take the target trigger condition as the encapsulation decision factor corresponding to the target security mechanism.
[0102] Further, as shown in the figure, Figure 4 The integration unit 35 comprises:
[0103] An acquisition module 351 is configured to acquire an interface specification corresponding to the unified interface;
[0104] Configuration module 352 is used to define the access path and forwarding logic of the secure and trusted functional component in the target system in the interface specification obtained by acquisition module 351;
[0105] Integration module 353 is used to take the access path and forwarding logic obtained by configuration module 352 as the routing rules in a standardized format and deploy them to the target system, so as to integrate the security and trust function components into the target system.
[0106] Furthermore, embodiments of this application also provide a storage medium for storing a computer program, wherein the computer program, when running, controls the device where the storage medium is located to execute the above-described... Figures 1-2 The method for constructing secure and trusted functional components as described in [the document].
[0107] Furthermore, embodiments of this application also provide a processor for running a program, wherein the program executes the above-described... Figures 1-2 The method for constructing secure and trusted functional components as described in [the document].
[0108] In the above embodiments, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0109] It is understood that the relevant features in the above methods and apparatus can be referenced interchangeably. Furthermore, the terms "first," "second," etc., in the above embodiments are used to distinguish between embodiments and do not represent the superiority or inferiority of any particular embodiment.
[0110] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, devices, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here.
[0111] The algorithms and displays provided herein are not inherently related to any particular computer, virtual system, or other device. Various general-purpose systems can also be used in conjunction with the teachings herein. The required structure for constructing such systems is apparent from the above description. Furthermore, this application is not directed to any particular programming language. It should be understood that the content of this application described herein can be implemented using various programming languages, and the above description of specific languages is for the purpose of disclosing the best mode of implementation of this application.
[0112] In addition, the memory may include non-permanent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.
[0113] Those skilled in the art will appreciate that embodiments of the application can be readily used as software, hardware, or a combination of software and hardware. In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0114] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks.
[0115] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks.
[0116] The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks. Figure 1 Figure 1 The computer program instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer implemented process such that the instructions which execute on the computer or other programmable apparatus provide steps for implementing the functions specified in the flowchart block or blocks.
[0117] In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory.
[0118] The memory can include non-persistent memory and / or persistent memory, such as flash memory, read-only memory (ROM), and / or volatile or non-volatile random access memory (RAM), among others. The memory is an example of computer-readable media.
[0119] Computer-readable media includes permanent and non-permanent, movable and non-movable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible to a computing device. According to the definition herein, computer-readable media does not include transitory media such as modulated data signals and carriers.
[0120] It should also be noted that the terms "comprising", "containing", or any other variant thereof are intended to cover a non-exclusive inclusion, such that a process, method, article or apparatus that comprises a list of elements does not only include those elements, but can also include other elements not expressly listed or inherent to such process, method, article or apparatus. Without more limitations, the element defined by the statement "comprising a" does not exclude the presence of additional identical elements in the process, method, article or apparatus that includes the element.
[0121] Those skilled in the art will appreciate that embodiments of the present application can be provided as a method, system or computer program product. Accordingly, the present application can take the form of an entirely hardware embodiment, an entirely software embodiment or an embodiment combining software and hardware aspects. Furthermore, the present application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROMs, optical storage devices, etc.) containing computer usable program code.
[0122] The above merely provides embodiments of the present application and is not intended to limit the present application. Various modifications and changes can be made to the present application by those skilled in the art. Any modification, equivalent replacement, improvement, etc. made within the spirit and principles of the present application shall be included in the scope of the claims of the present application.
Claims
1. A method for constructing a secure and reliable functional component, characterized in that, The method includes: Identify the required target security mechanisms based on the security requirements of the target system; Based on the mechanism type of the target security mechanism, the encapsulation decision factors corresponding to the target security mechanism are determined. The encapsulation decision factors include the number of participants, whether external decision-making is introduced, and whether mechanism details are hidden. Based on the aforementioned encapsulation decision factors, a target encapsulation mode is determined from the preset encapsulation modes. The preset encapsulation modes include black-box encapsulation, segmented encapsulation, window encapsulation, and abstract encapsulation. The target encapsulation mode includes at least one of the following: black-box encapsulation, segmented encapsulation, window encapsulation, and abstract encapsulation. The target security mechanism is standardized and encapsulated according to the target encapsulation pattern to form a secure and trusted functional component with a unified interface. The encapsulated secure and trusted functional components are integrated into the target system through routing rules.
2. The method according to claim 1, characterized in that, Determining the target packaging mode from preset packaging modes based on the aforementioned packaging decision factors includes: If the number of participants is unilateral, no external decision-making is introduced, and the mechanism details are not hidden, then the black-box encapsulation determines the target encapsulation mode; If the number of participants is unilateral, the external decision-making is introduced, and the mechanism details are not hidden, then the window encapsulation is determined as the target encapsulation mode; If the number of participants is unilateral, the external decision-making is introduced, and the mechanism details are hidden, then the superimposed encapsulation combination formed by the window encapsulation and the abstract encapsulation is determined as the target encapsulation mode.
3. The method according to claim 2, characterized in that, The method further includes: If there are multiple participants, without introducing external decisions and without shielding the mechanism details, then the segmented encapsulation determines the target encapsulation mode; If there are multiple participants, external decision-making is introduced, and the mechanism details are not hidden, then the superimposed encapsulation combination of the segmented encapsulation and the window encapsulation is determined as the target encapsulation mode. If there are multiple participating parties, external decision-making is introduced, and the mechanism details are hidden, then the superimposed encapsulation combination consisting of segmented encapsulation, window encapsulation, and abstract encapsulation is determined as the target encapsulation mode.
4. The method according to claim 1, characterized in that, Based on the security requirements of the target system, identify the necessary target security mechanisms, including: The business scenario of the target system is determined, and the resource subject corresponding to the business scenario and the purpose corresponding to the resource subject are identified. The resource subject is used to characterize the key resources that need to be protected or managed in the business scenario, and the purpose is used to characterize the function of the resource subject in the business scenario. The security requirements are determined based on the resource entity and its intended use; The target security mechanism is matched in a preset mechanism library based on the attributes corresponding to the security requirements. The mechanism library is constructed based on the security mechanisms required for all business scenarios of the target system.
5. The method according to claim 4, characterized in that, Before determining the encapsulation decision factors corresponding to the target security mechanism based on the mechanism type of the target security mechanism, the method further includes: Extract typical features corresponding to the mechanism type of each security mechanism from the mechanism library; Obtain the trigger conditions corresponding to each of the preset encapsulation modes; The feature-condition mapping rule is constructed based on the logical association between the typical features and the triggering conditions; The mechanism type based on the target security mechanism determines the encapsulation decision factors corresponding to the target security mechanism, including: Extract the typical characteristics of the target corresponding to the mechanism type of the target security mechanism; Based on the typical characteristics of the target, the corresponding target triggering conditions are dynamically matched in the feature-condition mapping rule, and the target triggering conditions are used as the encapsulation decision factors corresponding to the target security mechanism.
6. The method according to any one of claims 1-5, characterized in that, The encapsulated secure and trusted functional components are integrated into the target system via routing rules, including: According to the interface specification corresponding to the unified interface; The interface specification defines the access path and forwarding logic of the secure and trusted functional components in the target system; The access path and the forwarding logic are configured as routing rules in a standardized format and deployed to the target system to integrate the secure and trusted functional components into the target system.
7. A device for constructing secure and reliable functional components, characterized in that, The device includes: The identification unit is used to identify the required target security mechanisms based on the security requirements of the target system. The first determining unit is used to determine the encapsulation decision factors corresponding to the target security mechanism based on the mechanism type of the target security mechanism obtained by the identification unit. The encapsulation decision factors include the number of participants, whether external decision-making is introduced, and whether mechanism details are hidden. The second determining unit is used to determine a target packaging mode in a preset packaging mode based on the packaging decision factors obtained by the first determining unit. The preset packaging modes include black-box packaging, segmented packaging, window packaging, and abstract packaging. The target packaging mode includes at least one of the black-box packaging, segmented packaging, window packaging, and abstract packaging. The encapsulation unit is used to standardize and encapsulate the target security mechanism according to the target encapsulation mode obtained by the second determining unit, forming a secure and trusted functional component with a unified interface. An integration unit is used to integrate the encapsulated secure and trusted functional components obtained by the encapsulation unit into the target system through routing rules.
8. The apparatus according to claim 7, characterized in that, The second determining unit is specifically used for, If the number of participants is unilateral, no external decision-making is introduced, and the mechanism details are not hidden, then the black-box encapsulation determines the target encapsulation mode; If the number of participants is unilateral, the external decision-making is introduced, and the mechanism details are not hidden, then the window encapsulation is determined as the target encapsulation mode; If the number of participants is unilateral, the external decision-making is introduced, and the mechanism details are hidden, then the superimposed encapsulation combination formed by the window encapsulation and the abstract encapsulation is determined as the target encapsulation mode; If there are multiple participants, without introducing external decisions and without shielding the mechanism details, then the segmented encapsulation determines the target encapsulation mode; If there are multiple participants, external decision-making is introduced, and the mechanism details are not hidden, then the superimposed encapsulation combination of the segmented encapsulation and the window encapsulation is determined as the target encapsulation mode. If there are multiple participating parties, external decision-making is introduced, and the mechanism details are hidden, then the superimposed encapsulation combination consisting of segmented encapsulation, window encapsulation, and abstract encapsulation is determined as the target encapsulation mode.
9. A storage medium, characterized in that, The storage medium includes a stored program, wherein, when the program is executed, it controls the device where the storage medium is located to perform the secure and trusted functional component construction method as described in any one of claims 1 to 6.
10. A processor, characterized in that, The processor is used to run a program, wherein the program executes the secure and trusted functional component construction method as described in any one of claims 1 to 6.