Private network dynamic access control method and system

By using an attention-based multimodal feature fusion model and multidimensional risk assessment, a real-time risk score is generated, solving the problems of real-time threat perception and fine-grained policy adjustment in dynamic access control of private networks. This achieves efficient and flexible access control, improving the security and response speed of private network networks.

CN121261998APending Publication Date: 2026-01-02GUANGZHOU TRUSTMO INFORMATION SYST CO LTD

Patent Information

Application Number
CN202511649991.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-11-12
Publication Date
2026-01-02

AI Technical Summary

Technical Problem

Existing dynamic access control technologies for private networks are insufficient in terms of real-time threat perception capabilities, dynamic adjustment of fine-grained access control policies, and adaptability to multiple service scenarios. In particular, traditional access control methods cannot effectively cope with real-time network threats in complex and ever-changing security risk scenarios.

Method used

A multimodal feature fusion model based on an attention mechanism is adopted, combined with a multidimensional risk assessment model and a weighted aggregation algorithm, to generate a real-time risk score. By dynamically generating access control policies, a deep correlation between the static attributes and dynamic behavioral characteristics of devices is achieved, thereby improving the accuracy and interpretability of access risk perception.

Benefits of technology

It significantly improves the accuracy and interpretability of risk perception for private network access, enables fine-grained access control policy generation, can quickly respond to changes in security posture in high-risk scenarios, and enhances the response speed and execution reliability of private network access control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121261998A_ABST
    Figure CN121261998A_ABST
Patent Text Reader

Abstract

The invention discloses a private network dynamic access control method and system, and relates to the technical field of network security and access control. The method comprises the following steps: acquiring equipment behavior data and network flow data in a private network, performing feature construction, and generating equipment trust features and network behavior features; and carrying out multi-dimensional risk assessment model training based on the equipment trust features and the network behavior features, carrying out real-time risk assessment on access requests or entities in the private network through the trained multi-dimensional risk assessment model, and generating a real-time risk score through a weighted aggregation function. According to the invention, through the multi-modal feature fusion model based on an attention mechanism, deep association of static attributes and dynamic behavior features of equipment is realized, and a real-time risk score is generated in combination with a multi-dimensional risk assessment model and a weighted aggregation algorithm. The limitation that in traditional access control, the evaluation dimension is single, the static strategy lags behind, and dynamic threats cannot be reflected is effectively overcome, and the accuracy and interpretability of private network access risk perception are remarkably improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of network security and access control technology, and in particular to a method and system for dynamic access control of private networks. Background Technology

[0002] When managing dynamic access control on a private network, ensuring network security, isolation, and transmission efficiency are paramount. Only by achieving efficient and flexible access control can the needs of diverse service scenarios be better met. Traditional dynamic access control methods typically rely on static access control lists (ACLs) for permission verification. This approach has limitations in dealing with real-time network threats, especially in complex and ever-changing security risk scenarios, and its adaptability needs improvement. With the development of private network technology, some new solutions have been proposed, such as methods combining NAT and L2TP technologies, which achieve encrypted data transmission and service isolation through dynamically adjusting tunnel policies. However, these technologies have limited ability to detect real-time threats, and the scope of dynamic adjustment is mainly focused on NAT mapping and tunnel configuration, failing to fully consider fine-grained access control requirements.

[0003] Furthermore, in recent years, technical solutions incorporating the zero-trust security concept have gradually gained attention. These solutions establish trusted monitoring models by collecting device information and network slice data in real time and adjust the monitoring frequency based on daily risk factors. However, this approach focuses more on trusted verification of device access and lacks dynamic access control between different services within the private network. Additionally, its dynamic adjustments are primarily reflected in the monitoring frequency rather than directly targeting the access control policies themselves, which may affect response speed and accuracy in high-risk scenarios.

[0004] The above situation indicates that existing private network dynamic access control technologies still have room for improvement in terms of real-time threat awareness capabilities, dynamic adjustment of fine-grained access control policies, and adaptability to multiple service scenarios. Summary of the Invention

[0005] To address the shortcomings of existing technologies, this invention provides a method and system for dynamic access control of private networks. By using a multimodal feature fusion model based on an attention mechanism, it achieves a deep correlation between static attributes and dynamic behavioral characteristics of devices. Combined with a multi-dimensional risk assessment model and a weighted aggregation algorithm, it generates real-time risk scores, effectively overcoming the limitations of traditional access control, such as single assessment dimensions, outdated static policies, and inability to reflect dynamic threats. This significantly improves the accuracy and interpretability of risk perception for private network access.

[0006] In a first aspect, the present invention provides a method for dynamic access control of a private network, comprising: S100: Collect device behavior data and network traffic data within the private network and construct features to generate device trust features and network behavior features; S200: A multi-dimensional risk assessment model is trained based on device trust characteristics and network behavior characteristics. The trained multi-dimensional risk assessment model is used to conduct real-time risk assessment of access requests or entities within the private network, and a real-time risk score is generated through a weighted aggregation function. S300: Transform the generated real-time risk score into specific, executable access control policies; S400 executes dynamically generated access control policies and continuously provides feedback for optimization.

[0007] Optionally, S100 further includes: Collect equipment attribute data using an equipment information acquisition device; Network traffic packets flowing through key network nodes are collected in real time using network probes, and deep packet inspection is performed on the net payload of network data packets to extract data packet content features; the network traffic packets include network traffic data. The sampling frequency of the network probe is adaptively adjusted according to the dynamic changes in network traffic.

[0008] Optionally, S100 further includes: Device trust features are constructed based on the preprocessed device attribute data to quantitatively assess the security, compliance, and credibility of historical behavior of each device within the private network; Network behavior features are constructed based on preprocessed network traffic data to characterize the communication patterns, traffic characteristics, and abnormal behaviors between devices within the private network. Both the device trust features and the network behavior features are stored in vector form.

[0009] Optionally, S200 further includes: The device trust features and network behavior features are deeply fused; the deep fusion adopts a fusion model based on an attention mechanism, and dynamically assigns weights according to the device trust features and network behavior features to generate a high-dimensional vector representation; The generated high-dimensional vector representation is input into the multi-dimensional risk assessment model for training. The trained multi-dimensional risk assessment model is then used to perform real-time risk assessment on each access request or each active entity within the private network, generating a set of risk indicators. A real-time risk score is generated by weighted summation of the risk indicator set using a weighted aggregation function; the real-time risk score is an integer value between 0 and 100.

[0010] Optionally, step S300 is used to convert the real-time risk score obtained in step S200 into an executable access control policy; the access control policy can respond in real time to changes in the security posture and risk level within the private network, including: Risk levels are classified based on the real-time risk score, including no risk, low risk, medium risk, and high risk. Each risk level is associated with a predefined basic access control policy; Based on the business isolation requirements and security compliance requirements of the private network, the basic access control policy is refined to generate detailed policy rules; The refined policy rules are then subjected to conflict detection and priority sorting to generate a dynamic access control policy rule set.

[0011] Optionally, the basic access control policy includes: When assessed as risk-free, resources within the access permission scope are permitted. When assessed as low risk, resources within the access permission scope are permitted, but access is subject to bandwidth restrictions, re-authentication, and access logging. When assessed as medium risk, access to designated isolation areas and communication with designated security management systems to issue instructions or upload logs are permitted only. When assessed as high risk, immediately terminate all existing sessions, reject all subsequent access requests, and issue flow table rules through the network control system to logically isolate the device to a predefined isolation VLAN or security domain, while simultaneously sending a highest priority alarm to the security management platform.

[0012] Optionally, the basic access control policy is refined by combining the business isolation requirements and security compliance requirements of the private network, generating refined policy rules, including: Data resources and services within the private network are classified into security levels according to their business value, sensitivity, and compliance requirements. These security levels include public resources, internal resources, sensitive resources, and core resources. Furthermore, differentiated access constraints are preset for resources of different security levels. Based on risk level and resource security level, fine-grained access rules for device-resource matching are generated. These fine-grained access rules include strengthening monitoring and auditing, implementing session encryption or restricting the scope of operation for low-risk devices accessing sensitive resources, allowing medium-risk devices to access non-core resources only during specific time periods and enabling multi-factor authentication, and restricting the scope of resources and operation types that the device can access based on its role and the security domain it belongs to. Based on factors such as access time, geographical location, and network status, the fine-grained access rules for device-resource matching are contextualized to obtain refined policy rules.

[0013] Optionally, the step of performing conflict detection and priority ranking on the refined policy rules to generate a dynamic access control policy rule set includes: The conflict detection uses a rule tree-based conflict detection algorithm to traverse all generated policy rules and identify whether there are rule conflicts. Once a conflict is detected, the system will arbitrate according to a preset conflict resolution strategy. The priority ranking is used to assign a priority to each rule based on the importance, risk level, and business criticality of the strategy; The dynamic access control policy rule set contains all access control instructions that need to be issued to private network devices.

[0014] Optionally, S400 includes the step of: The generated dynamic access control policy rule set is distributed to each policy enforcement point within the private network through a secure and reliable communication channel; After receiving and loading the policy rule set, the policy enforcement point immediately executes all network access requests flowing through its control node; The system will continuously monitor the execution effect and collect access logs, security event alerts and user feedback information generated from policy execution points; When the number of denied legitimate access requests increases abnormally, the risk assessment model can be iteratively trained or the policy template library can be updated based on the collected access logs, security event alerts, and user feedback.

[0015] Secondly, the present invention also provides a private network dynamic access control system, which applies a private network dynamic access control method as described above. The system includes a data acquisition and feature construction module, a risk assessment module, a policy generation module, and a policy execution and feedback module. The data acquisition and feature construction module is used to collect device behavior data and network traffic data within the private network and perform feature construction to generate device trust features and network behavior features. The risk assessment module is used to train a multi-dimensional risk assessment model based on device trust characteristics and network behavior characteristics. The trained multi-dimensional risk assessment model is used to conduct real-time risk assessment of access requests or entities within the private network, and a real-time risk score is generated through a weighted aggregation function. The policy generation module is used to convert the generated real-time risk score into a specific, executable access control policy. The policy execution and feedback module is used to execute dynamically generated access control policies and continuously provide feedback for optimization.

[0016] Compared with the prior art, the present invention has the following advantages and beneficial effects: 1. By constructing a multi-dimensional, high-real-time data acquisition and feature extraction mechanism, we comprehensively aggregate device attribute data and network traffic data within the private network. Based on deep packet inspection, time-series alignment, and data preprocessing technologies, we generate high-quality device trust features and network behavior features. This effectively solves the problems of single data source, incomplete feature construction, and insufficient real-time performance in traditional solutions, providing a comprehensive, accurate, and timely data foundation for subsequent risk assessment.

[0017] 2. By using a multimodal feature fusion model based on an attention mechanism, a deep correlation and adaptive weighting of static attributes and dynamic behavioral features of devices are achieved. Combined with a multi-dimensional risk assessment model and a weighted aggregation algorithm, accurate real-time risk scores are generated. This effectively overcomes the limitations of traditional access control, such as single assessment dimensions, lagging static policies, and inability to reflect dynamic threats, and significantly improves the accuracy and interpretability of private network access risk perception.

[0018] 3. By combining real-time risk scoring with business resource classification and environmental context information, refined and contextualized access control policies based on risk levels are generated. With the help of conflict detection and priority ranking mechanisms, a consistent and reliable dynamic policy rule set is constructed, which effectively solves the problems of rigid traditional access control policies that are difficult to adapt to complex business scenarios and compliance requirements of private networks, and realizes true dynamic authorization and the principle of least privilege.

[0019] 4. By real-time secure distribution and distributed execution of policy rule sets, combined with continuous monitoring and closed-loop feedback mechanisms, an integrated adaptive access control system of "decision-execution-optimization" is constructed, which effectively improves the response speed and execution reliability of private network access control policies. At the same time, it can continuously iterate and optimize risk assessment models and policy rules based on actual operating results, significantly enhancing the sustainability and resilience of the overall security protection of the private network. Attached Figure Description

[0020] Figure 1 This is a flowchart illustrating a dynamic access control method for private networks.

[0021] Figure 2 This is a block diagram of a private network dynamic access control system. Detailed Implementation

[0022] The technical solution of the present invention will be clearly and completely described below with reference to the embodiments. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of the present invention. It should be noted that relational terms such as "first" and "second" are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations.

[0023] Example 1 Please see Figure 1 This invention provides a method for dynamic access control in a private network, comprising the following steps: S100: Collect device behavior data and network traffic data within the private network and construct features to generate device trust features and network behavior features; S200: A multi-dimensional risk assessment model is trained based on device trust characteristics and network behavior characteristics. The trained multi-dimensional risk assessment model is used to conduct real-time risk assessment of access requests or entities within the private network, and a real-time risk score is generated through a weighted aggregation function. S300: Transform the generated real-time risk score into specific, executable access control policies; S400 executes dynamically generated access control policies and continuously provides feedback for optimization.

[0024] Specifically, S100 is used to comprehensively and accurately acquire real-time status information of devices and network activities within the private network, and transform it into structured features for subsequent analysis and evaluation. This process has extremely high requirements for data integrity, real-time performance, and accuracy; any missing or delayed data may affect the accuracy of subsequent risk assessment and the timeliness of strategy generation. The process includes the following steps: S110. Deploy a dedicated device information collection device within the private network, and monitor and collect the attribute data of all connected devices in the private network in real time according to the set collection frequency; the device attribute data includes device serial number, MAC address, private network IP address, device configuration information, etc.; the device information collection device securely transmits the collected device attribute data to the central processing unit based on the Secure Sockets Layer protocol.

[0025] S120. Deploy network probes at key network nodes (e.g., core switches, routers, security gateways) of the private network to capture all network data packets flowing through these nodes in real time and extract network traffic metadata, including source IP address, destination IP address, source port number, destination port number, protocol type, etc. Furthermore, the network probes perform deep packet inspection on the payload of network data packets to extract packet content characteristics; for example, monitoring for specific malicious signatures, abnormal protocol fields, or suspicious application-layer behavior patterns in the network data packets. The sampling frequency of the network probes can be adaptively adjusted according to dynamic changes in network traffic, increasing to once per millisecond during high-traffic or high-risk periods and decreasing to once per second during low-traffic periods to balance sampling accuracy and system load. The collected network traffic data is transmitted through a dedicated data bus and anonymized and de-identified before being stored to protect user privacy requirements.

[0026] S130. The collected device attribute data and network traffic data are timestamped to unify the time base of all data. This timestamping can be achieved through linear interpolation or nearest neighbor interpolation. Next, duplicate fields in the device attribute data and network traffic data are removed to reduce redundancy. Then, missing fields in the device attribute data and network traffic data are supplemented. The supplementation rules can be based on historical mean filling, recent valid value filling, or prediction filling based on machine learning models. Statistical methods (e.g., the three-standard-deviation rule) are used to identify and mark outliers in the device attributes, and these outliers are corrected, isolated, or removed. Finally, the data from heterogeneous data sources is converted into a unified structured format and subjected to numerical normalization to eliminate dimensional differences between different features, facilitating subsequent processing by machine learning models.

[0027] S140. Construct device trust features based on the preprocessed device attribute data to quantitatively evaluate the security, compliance, and credibility of historical behavior of each device within the private network; the device trust features include device authentication strength, device compliance, historical security event records, behavioral deviation degree, and device vulnerability status; The device authentication strength refers to the strength of the authentication method used when the device is connected. The device compliance refers to whether the port opening status, service operation status, and system log auditing strategy meet the security specifications. The historical security event record is a record of whether the device has been detected with malicious files or suffered denial-of-service attacks in the past period of time; The behavioral deviation is the degree of deviation between the device's current behavior pattern and its historical normal behavior pattern. The device vulnerability status is assessed by evaluating the number and severity of known security vulnerabilities in the device based on the Common Vulnerabilities and Exposures (CVE) database and internal vulnerability scan results.

[0028] These constructed device trust features are stored in the form of feature vectors, each vector corresponding to a private network device and associated with a unique device ID and timestamp.

[0029] S150. Construct network behavior features for the preprocessed network traffic data to characterize the communication patterns, traffic characteristics, and possible abnormal behaviors between devices within the private network; the network behavior features include connection mode features, abnormal traffic mode features, protocol violations, abnormal request features, and data packet content features. The connection mode characteristics include the connection frequency, connection duration, number of sessions, and round-trip time of data packets between the source IP and destination IP. The traffic anomaly pattern characteristics include the ratio of uplink to downlink traffic, average packet size, and data transmission rate; The aforementioned protocol violations include known protocol communication on non-standard ports, incorrect protocol field formats, and abuse of specific protocols. The abnormal request characteristics are the number of failed authentication attempts for a specific service and a large number of network requests for non-existent resources within a short period of time. The data packet content features are identified through deep packet inspection to determine whether the data packet contains sensitive information, such as credit card numbers, personal identification information, or malicious payloads.

[0030] These constructed network behavior features are also stored in the form of feature vectors, and associated with unique connection IDs and timestamps.

[0031] Specifically, step S200 includes the following steps: S210. To comprehensively characterize the security of private network entities and their behaviors, the device trust features and network behavior features are deeply fused. This deep fusion process is not merely a simple concatenation; it also considers the heterogeneity of the two modal features, differences in information density, and potential correlations between them. First, the device trust features and network behavior features are dimensionally aligned and standardized to eliminate differences in units and numerical ranges. Then, an attention-based fusion model is used to dynamically assign weights based on the device trust features and network behavior features. Specifically, when the device's trust level is low (e.g., there are serious vulnerabilities), the weight of the device trust features is less than the weight of the network behavior features, and the model pays more attention to subtle anomalies in network behavior. When the trust level of the network behavior features is low, the weight of the network behavior features is less than the weight of the device trust features, thereby reducing the impact of untrusted data caused by device failure or network untrustworthiness. Finally, the dynamic weights are fused into a high-dimensional vector representation. This high-dimensional vector representation simultaneously contains the device's static security attributes and dynamic network behavior pattern information, providing a more comprehensive and richer input for subsequent risk assessment. It's important to note that the core logic of weight allocation is to prioritize features that better reflect the real-time threat state under different feature reliability scenarios. Reducing the weight of a device when its trust level is low does not mean ignoring device risks, but rather using network behavior features as a dynamic observation window to more accurately determine whether static risks have transformed into actual threats. Reducing the weight of network behavior features when their trust level is low leverages the static stability of device trust features to ensure the basic accuracy of risk assessment when dynamic information is unreliable.

[0032] S220. The generated high-dimensional vector representation is input into a multi-dimensional risk assessment model for training. The trained multi-dimensional risk assessment model is used to perform real-time risk assessment on each access request or each active entity within the private network, generating a set of risk indicators. The set of risk indicators includes security vulnerability risk, abnormal behavior risk, compliance risk, and threat exposure risk. The security vulnerability risk is used to assess the likelihood of a device or application being attacked by a vulnerability. The abnormal behavior risk is used to assess the degree of deviation between the current network behavior and historical normal patterns. The compliance risk is used to assess whether the device or user behavior violates the security policy and compliance requirements of the private network. The threat exposure risk is used to assess the potential threat exposure surface caused by improper network configuration or lack of security protection.

[0033] S230. To simplify the multi-dimensional risk assessment results into a single, operable numerical indicator, a weighted aggregation function is used to sum the risk indicator set to generate a real-time risk score; the real-time risk score is an integer value between 0 and 100; the expression of the weighted aggregation function is: ; In the formula, This indicates a real-time risk score. Indicates the number of risk dimensions. Indicates the first The weights of each risk dimension, Indicates the first The assessment values ​​for each risk dimension, among which, To score the risk of security vulnerabilities, Assess the risk of behavioral abnormalities. For compliance risk scoring, Threat exposure risk scoring. The real-time risk score reflects the overall risk score of the current device or access behavior, providing a quantitative basis for subsequent policy generation.

[0034] Specifically, step S300 is used to convert the real-time risk score obtained in step S200 into an executable access control policy; the access control policy can respond in real time to changes in the security posture and risk level within the private network to ensure that access permissions always match the trust level, including the following steps: S310. Risk levels are determined based on the real-time risk score, including no risk, low risk, medium risk, and high risk. When the real-time risk score is between 0 and the low-risk threshold, it is assessed as no risk; when the real-time risk score is between the low-risk threshold and the medium-risk threshold, it is assessed as low risk; when the real-time risk score is between the medium-risk threshold and the high-risk threshold, it is assessed as medium risk; when the real-time risk score is greater than the high-risk threshold, it is assessed as high risk. Each risk level is associated with a predefined basic access control policy. When assessed as no risk, all resources within the normal access permission range are allowed. When assessed as low risk, access to all resources within the normal access permission range is allowed, but constraints are imposed, such as limiting bandwidth, enabling more frequent re-authentication, or logging all access logs for auditing purposes. When assessed as medium risk, all access is denied by default, but exceptional access is allowed, such as allowing access only to designated isolation zones, or allowing communication with designated security management systems to issue instructions or upload logs. When assessed as high risk, all existing sessions are immediately terminated, all subsequent access requests are denied, and the device is logically isolated to a predefined isolation VLAN or security domain, while sending the highest priority alarm to the security management platform.

[0035] S320. After the basic access control policy is determined, in order to achieve more granular access control, it is necessary to refine the basic access control policy by combining the business isolation requirements and security compliance requirements of the private network, and generate refined policy rules; including the following steps: S321. Data resources and services within the private network are classified into security levels according to their business value, sensitivity, and compliance requirements. These security levels include public resources, internal resources, sensitive resources, and core resources. Furthermore, based on the principle of least privilege and business needs, differentiated access constraints are preset for resources of different security levels. For example, public resources may require no authentication or only basic network layer access control. Internal resources require domain account authentication, and access from external visitor devices can be restricted or monitored, limiting large-scale downloads. Sensitive resources require mandatory multi-factor authentication, and access behavior (especially read operations) is recorded and monitored, with alerts for abnormal downloads. Core resources require mandatory multi-factor authentication, allowing access only to specific device tag sets, restricting access to only specific time periods and trusted network areas, strictly limiting high-risk operations (such as batch deletion and data export), or requiring secondary approval for write operations. Simultaneously, all access sessions for this type of resource are fully encrypted and logged with complete audit logs.

[0036] S322. Based on risk level and resource security level, generate fine-grained access rules for device-resource matching; for example, for low-risk devices accessing sensitive resources, monitoring and auditing should be strengthened, session encryption should be implemented, or the scope of operation should be restricted; for medium-risk devices, access to non-core resources should only be allowed during specific time periods, and multi-factor authentication should be enabled; in addition, the scope of resources that can be accessed and the types of operations can be further constrained according to the device role (such as employee devices, visitor devices, and maintenance devices) and its security domain.

[0037] S323. Based on environmental factors such as access time, geographical location, and network status, the fine-grained access rules for device-resource matching are contextualized to obtain refined policy rules. For example, when access is initiated outside of working hours or from an untrusted geographical location, even if the risk rating is low, the authentication strength should be increased or some high-risk operations should be temporarily restricted. At the same time, if the network detects that it is under attack or there is abnormal traffic, the security policy level of all accesses should be temporarily increased globally.

[0038] S330. Perform conflict detection and priority sorting on the refined policy rules to generate a dynamic access control policy rule set. The conflict detection uses a rule tree-based conflict detection algorithm to traverse all generated policy rules and identify whether there are rule conflicts. Once a conflict is detected, the system will arbitrate according to a preset conflict resolution policy to ensure the uniqueness and determinism of the dynamic access control policy rule set. The priority sorting is used to assign priority to each rule according to the importance, risk level, and business criticality of the policy. For example, a denial policy triggered by high risk has a higher priority than an allow policy triggered by low risk. The dynamic access control policy rule set contains all access control instructions that need to be issued to the private network devices. Each instruction clearly specifies the access subject, access object, operation type, risk level, and policy action (e.g., allow, deny, alarm, isolate).

[0039] Specifically, S400 is used to apply the dynamic access control policy rule set to the actual private network environment and regulate network access behavior in real time, including the following steps: S410. The generated dynamic access control policy rule set is distributed to each policy execution point within the private network through a secure and reliable communication channel. The policy execution points include hardware firewalls, security gateways, intrusion prevention systems (IPS), and terminal access control agents. The policy distribution adopts an incremental update mechanism. When there is a high-risk or urgent policy update, the system will actively push the new policy to the relevant execution points to ensure that the new policy takes effect in real time.

[0040] After receiving and loading the policy rule set, the S420 policy execution point immediately makes real-time judgments on all network access requests flowing through its control node. The request matching process combines policy priority and the longest matching principle: the system compares the access request with the policy rule conditions. If a "deny" rule is matched (e.g., a medium-risk device attempts to access the core database), the request is immediately blocked and a detailed denial log is generated. If a "allow" rule is matched (e.g., a low-risk device accesses public resources), the request is allowed. If a request matches multiple policies, arbitration is performed according to the conflict resolution mechanism preset in S330. All execution actions are associated with the original policy ID and real-time risk score to ensure that the operation is auditable and traceable.

[0041] S430. The system will continuously monitor the execution effect of step S420, collect access logs, security event alarms and user feedback information generated from policy execution points; when the number of denied legitimate access requests increases abnormally, it may indicate that the current dynamic access control policy rule set is too strict or that the risk assessment model has misjudged. Therefore, it can be used for iterative training of the risk assessment model and updating of the policy template library to ensure that the private network dynamic access control system has the ability to learn adaptively and continuously optimize.

[0042] Example 2 Please see Figure 2 The present invention also provides a private network dynamic access control system, which applies a private network dynamic access control method as described above. The system includes a data acquisition and feature construction module, a risk assessment module, a policy generation module, and a policy execution and feedback module. The data acquisition and feature construction module is used to collect device behavior data and network traffic data within the private network and perform feature construction to generate device trust features and network behavior features. The risk assessment module is used to train a multi-dimensional risk assessment model based on device trust characteristics and network behavior characteristics. The trained multi-dimensional risk assessment model is used to conduct real-time risk assessment of access requests or entities within the private network, and a real-time risk score is generated through a weighted aggregation function. The policy generation module is used to convert the generated real-time risk score into a specific, executable access control policy. The policy execution and feedback module is used to execute dynamically generated access control policies and continuously provide feedback for optimization.

[0043] All content not described in detail in this specification is prior art known to those skilled in the art, and the model parameters of each electrical appliance are not specifically limited; conventional equipment can be used. Electrical control components not mentioned in this technical solution are not shown in the figures because they are prior art, and will not be described further here.

[0044] The above description is merely a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of the present invention should be included within the protection scope of the present invention.

Claims

1. A method for dynamic access control on a private network, characterized in that, Including the following steps: S100: Collect device behavior data and network traffic data within the private network and construct features to generate device trust features and network behavior features; S200: A multi-dimensional risk assessment model is trained based on device trust characteristics and network behavior characteristics. The trained multi-dimensional risk assessment model is used to conduct real-time risk assessment of access requests or entities within the private network, and a real-time risk score is generated through a weighted aggregation function. S300: Convert the generated real-time risk score into an executable access control policy; S400 executes dynamically generated access control policies and continuously provides feedback for optimization.

2. The method for dynamic access control of a private network according to claim 1, characterized in that: The S100 further includes: Collect equipment attribute data using an equipment information acquisition device; Network traffic packets flowing through key network nodes are collected in real time using network probes, and deep packet inspection is performed on the net payload of network data packets to extract data packet content features; the network traffic packets include network traffic data. The sampling frequency of the network probe is adaptively adjusted according to the dynamic changes in network traffic.

3. The method for dynamic access control of a private network according to claim 2, characterized in that: The S100 further includes: Device trust features are constructed based on the preprocessed device attribute data to quantitatively assess the security, compliance, and credibility of historical behavior of each device within the private network; Network behavior features are constructed based on preprocessed network traffic data to characterize the communication patterns, traffic characteristics, and abnormal behaviors between devices within the private network. Both the device trust features and the network behavior features are stored in vector form.

4. The method for dynamic access control of a private network according to claim 2, characterized in that: The S200 further includes: The device trust features and network behavior features are deeply fused; the deep fusion adopts a fusion model based on an attention mechanism, and dynamically assigns weights according to the device trust features and network behavior features to generate a high-dimensional vector representation; The generated high-dimensional vector representation is input into the multi-dimensional risk assessment model for training. The trained multi-dimensional risk assessment model is then used to perform real-time risk assessment on each access request or each active entity within the private network, generating a set of risk indicators. A real-time risk score is generated by weighted summation of the risk indicator set using a weighted aggregation function; the real-time risk score is an integer value between 0 and 100.

5. The method for dynamic access control of a private network according to claim 3, characterized in that: Specifically, S300 is as follows: Risk levels are classified based on the real-time risk score, including no risk, low risk, medium risk, and high risk. Each risk level is associated with a predefined basic access control policy; Based on the business isolation requirements and security compliance requirements of the private network, the basic access control policy is refined to generate detailed policy rules; The refined policy rules are then subjected to conflict detection and priority sorting to generate a dynamic access control policy rule set.

6. The method for dynamic access control of a private network according to claim 5, characterized in that: The basic access control policy includes: When assessed as risk-free, resources within the access permission scope are permitted. When assessed as low risk, resources within the access permission scope are permitted, but access is subject to bandwidth restrictions, re-authentication, and access logging. When assessed as medium risk, access to designated isolation areas and communication with designated security management systems to issue instructions or upload logs are permitted only. When assessed as high risk, immediately terminate all existing sessions, reject all subsequent access requests, and issue flow table rules through the network control system to logically isolate the device to a predefined isolation VLAN or security domain, while simultaneously sending a highest priority alarm to the security management platform.

7. The method for dynamic access control of a private network according to claim 5, characterized in that: The basic access control policy is refined based on the business isolation requirements and security compliance requirements of the private network, generating detailed policy rules, including: Data resources and services within the private network are classified into security levels according to their business value, sensitivity, and compliance requirements. These security levels include public resources, internal resources, sensitive resources, and core resources. Furthermore, differentiated access constraints are preset for resources of different security levels. Based on risk level and resource security level, fine-grained access rules for device-resource matching are generated. These fine-grained access rules include strengthening monitoring and auditing, implementing session encryption or restricting the scope of operation for low-risk devices accessing sensitive resources, allowing medium-risk devices to access non-core resources only during specific time periods and enabling multi-factor authentication, and restricting the scope of resources and operation types that the device can access based on its role and the security domain it belongs to. Based on factors such as access time, geographical location, and network status, the fine-grained access rules for device-resource matching are contextualized to obtain refined policy rules.

8. The method for dynamic access control of a private network according to claim 5, characterized in that: The step of performing conflict detection and priority ranking on the refined policy rules to generate a dynamic access control policy rule set includes: The conflict detection uses a rule tree-based conflict detection algorithm to traverse all generated policy rules and identify whether there are rule conflicts. Once a conflict is detected, the system will arbitrate according to a preset conflict resolution strategy. The priority ranking is used to assign a priority to each rule based on the importance, risk level, and business criticality of the strategy; The dynamic access control policy rule set contains all access control instructions that need to be issued to private network devices.

9. A method for dynamic access control of a private network according to claim 8, characterized in that: The S400 includes the following steps: The generated dynamic access control policy rule set is distributed to each policy enforcement point within the private network through a secure and reliable communication channel; After receiving and loading the policy rule set, the policy enforcement point immediately executes all network access requests flowing through its control node; The system will continuously monitor the execution effect and collect access logs, security event alerts and user feedback information generated from policy execution points; When the number of denied legitimate access requests increases abnormally, the risk assessment model is iteratively trained or the policy template library is updated based on the collected access logs, security event alerts, and user feedback.

10. A private network dynamic access control system, which applies the private network dynamic access control method as described in any one of claims 1-9 above, wherein the system includes a data acquisition and feature construction module, a risk assessment module, a policy generation module, and a policy execution and feedback module; The data acquisition and feature construction module is used to collect device behavior data and network traffic data within the private network and perform feature construction to generate device trust features and network behavior features. The risk assessment module is used to train a multi-dimensional risk assessment model based on device trust characteristics and network behavior characteristics. The trained multi-dimensional risk assessment model is used to conduct real-time risk assessment of access requests or entities within the private network, and a real-time risk score is generated through a weighted aggregation function. The policy generation module is used to convert the generated real-time risk score into a specific, executable access control policy. The policy execution and feedback module is used to execute dynamically generated access control policies and continuously provide feedback for optimization.

Citation Information

Patent Citations

  • Enterprise-level network access control system based on dynamic authentication

    CN120415765A

  • Network security multi-mode intelligent detection system and method

    CN120498904A

  • Multi-tenant zero-trust security system based on micro segmentation

    CN120567697A

  • Security access control method based on zero-trust model

    CN120880710A

  • Contextual zero trust network access (ZTNA) based on dynamic security posture insights

    US20220210173A1

Cited By

  • ABAC dynamic risk assessment method and device based on improved MLP and electronic equipment

    CN121456677A

  • Secure endogenous and cognitive self-evolution intelligent network control method and system

    CN121690861A

  • Computer network big data security protection method

    CN121907576A

  • A message sampling method, device and related equipment

    CN122420149A