Zero-trust core management and control system and method based on user behavior and OSI seven-layer authentication

By constructing an eight-layer full-stack authentication model based on user behavior and OSI seven-layer authentication, the existing zero-trust core control technology has solved the problems of cross-layer protection blind spots and rigid trust assessment under complex network threats. It has achieved real-time response and dynamic adaptation to complex network threats, and improved the accuracy and comprehensiveness of security defense.

CN121262012AActive Publication Date: 2026-01-02SHENZHEN Y& D ELECTRONICS CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202511813413.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-04
Publication Date
2026-01-02
Estimated Expiration
2045-12-04

AI Technical Summary

Technical Problem

Existing zero-trust core management technologies lack the ability to perceive and correlate the full-stack network state of OSI seven layers when facing complex network threats. This allows attackers to carry out malicious operations by forging device information. Furthermore, the trust assessment mechanism is rigid, unable to adapt to dynamic changes, and has weak anomaly identification capabilities, making it difficult to deal with cross-layer coordinated attacks.

Method used

By constructing an eight-layer full-stack authentication model based on user behavior and OSI seven-layer authentication, the features of the OSI seven-layer protocol are transformed into computable vector parameter factors. Combined with user identity and behavior vector information, a three-dimensional trust evidence chain is formed. A state vector similarity algorithm is used for real-time verification and dynamic baseline updates to achieve global trust measurement.

Benefits of technology

It completely eliminates blind spots in cross-level protection, enables real-time response and dynamic adaptation to complex network threats, improves the accuracy and comprehensiveness of security defense, and adapts to the security management needs of dynamic and complex scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121262012A_ABST
    Figure CN121262012A_ABST
Patent Text Reader

Abstract

The invention discloses a zero-trust core management and control system and method based on user behaviors and OSI seven-layer authentication, and relates to the technical field of network security guarantee. The method comprises the steps of converting OSI seven-layer protocol features into computable vector parameter factors, forming a three-dimensional trust evidence chain in combination with user identity and behavior vector information, and realizing zero-trust closed-loop verification by adopting a designed state vector similarity algorithm. According to the invention, a cross-level blind area is eliminated by adopting eight-layer full-stack acquisition of a user behavior + OSI seven-layer protocol, the omnibearing attack resistance is improved, and the defects that an existing security defense system only provides protection for a certain specific function, the security function is single and an overall security protection means is lacked are overcome; oSI seven layers and user behaviors are uniformly converted into computable vectors, credibility quantification is achieved through a similarity algorithm and a corresponding AI recognition model, the defect that the control granularity of an existing level-based automatic judgment system is rough is overcome, and the control precision is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of network security protection technology, and in particular relates to a zero-trust core management system and method based on user behavior and OSI seven-layer authentication. Background Technology

[0002] With the widespread adoption of hybrid cloud, remote work, and IoT technologies, traditional protection models based on clear internal and external network boundaries have gradually become ineffective. Network attacks are showing new characteristics, such as using legitimate identities to penetrate at multiple levels and spreading laterally along the entire network chain.

[0003] Against this backdrop, the core controller, as the central nervous system of the security system, undertakes critical functions such as core business access review, risk identification, policy enforcement, and resource scheduling. Its importance is increasingly prominent, but it also faces severe challenges from the surge in access volume and the increasing complexity of attack methods. While the zero-trust architecture's "never trust, always verify" philosophy points the way to a solution, current mainstream zero-trust core control technologies still have fundamental flaws in practical applications, making it difficult to cope with the increasingly complex threat environment. The core defects of existing technologies profoundly restrict the effectiveness of zero-trust protection: First, traditional solutions are generally limited to two-dimensional authentication of "identity + device", lacking the ability to perceive and correlate the full-stack network status of OSI seven layers. This allows attackers to carry out malicious operations under the guise of holding a legitimate identity by forging device information, hijacking network sessions, etc., creating a blind spot in protection where "the identity is legitimate but the behavior and network status are abnormal". Secondly, existing solutions collect state data for the OSI seven-layer protocol in a fragmented manner, with the protocol states from the physical layer to the application layer isolated from each other. This fails to integrate them into a unified, computable, and traceable chain of trust evidence, making it difficult to detect cross-layer coordinated attacks. Furthermore, the trust assessment mechanism is rigid and static, relying on initial authentication or fixed policies. It cannot continuously adapt to the dynamic changes in user behavior, device status, and network environment, essentially becoming a variant of "one-time authentication, long-term trust." Finally, the anomaly detection capability is weak, and it can only deal with single-point and single-layer alarms. It lacks in-depth analysis of cross-OSI multi-layer linkage with user behavior, which allows attackers to easily bypass detection by using the tactic of "single-layer compliance and multi-layer linkage violation".

[0004] Therefore, how to break down the state silos at different network layers and transform heterogeneous and massive protocol features into computable unified trust parameters in real time to respond to ever-changing threats has become an urgent technical problem to be solved. Summary of the Invention

[0005] The purpose of this invention is to provide a zero-trust core management system and method based on user behavior and OSI seven-layer authentication. By converting the features of the OSI seven-layer protocol into computable vector parameter factors and combining user identity and behavior vector information, a three-dimensional trust evidence chain is formed. A designed state vector similarity algorithm is used to achieve zero-trust closed-loop verification. An eight-layer full-stack trust authentication model based on user behavior and OSI seven-layer network state is adopted, providing proactive defense functions for the core business systems of enterprises and other organizations. It is suitable for the security management of the core business domain computing environment and solves existing problems.

[0006] To solve the above-mentioned technical problems, the present invention is achieved through the following technical solution: As the first aspect provided by this invention, this invention is a zero-trust core management method based on user behavior and OSI seven-layer authentication, comprising the following steps: Step S1: When the terminal initiates a network or application access request, the edge management agent synchronously collects the OSI seven-layer state vector and user behavior vector; Step S2: Encode the vectors using the Word2Vec model, and then normalize the vector data using the Min-Max normalization algorithm; Step S3: Based on historical vector data, the RWKV model is used to automatically learn the normal state threshold range of each layer to construct a three-element dynamic reliable baseline of physical device-transmission network-user behavior. The historical data used to generate the dynamic baseline has a time period of more than 3 months and a sample size of more than 100,000. Step S4: Using an integrated discrimination algorithm, calculate the single-layer similarity using a weighted cosine similarity algorithm, and then calculate the global credibility by weighted summation of the similarities of each layer; Step S5: Assign permissions according to the trust level and execute access authorization according to the corresponding handling measures. The trust level includes high trust, medium trust, low trust and very low trust. Step S6: After successful access, continuously collect real-time vector data and update global credibility. Trigger permission adjustment, alarm or blocking operations based on changes in global credibility. Perform baseline adaptive updates through periodic iteration or emergency iteration. After the iteration is completed, generate an iteration report and store it in the audit log.

[0007] Furthermore, the control method also includes the following steps: After the abnormal terminal is dealt with, the central control node issues instructions on the handling results; If the alert is determined to be a false alarm, the quarantine will be lifted and the trust level will be reset. If it is determined to be a real attack, then isolation will be maintained.

[0008] Furthermore, in step S1, the collected OSI seven-layer state vectors and user behavior vectors include: Collect physical media type, hardware device fingerprint, and device specification compliance vector data at the physical layer; Collect data frame format, MAC address binding relationship, link encryption status, and MAC address change trajectory vector data at the data link layer; Collect source IP address, destination IP address, routing hop count mutation information, IP geolocation, and gateway access frequency vector data at the network layer; Collect vector data on TCP / UDP connection establishment frequency, connection rate fluctuations, port usage compliance, and data transmission volume at the transport layer; Collect session establishment process, session timeout, session reconnection count, and session associated terminal identifier vector data at the session layer; Collect the data encoding format, data compression algorithm, encryption key negotiation process, and data verification result vector data of the presentation layer; Collect API call frequency, API parameter compliance, application permission usage trajectory, and application log exception code vector data at the application layer; Collect user data including mouse / keyboard operation frequency, operation interval, access time, single access duration, high-frequency operation period, permission call order, frequency of sensitive permission usage, and permission request rationality.

[0009] Furthermore, in step S2, the normalization formula used by the Min-Max normalization algorithm is: ; Where X is the original value of a feature term in the OSI seven-layer state vector or user behavior vector, Xmin and Xmax are the minimum and maximum values ​​in the data set of all original values ​​belonging to the same feature term as X, respectively; X* is the value mapped to the interval [0, 1] after normalization.

[0010] Furthermore, in step S4, the algorithm for calculating single-layer similarity and global credibility is as follows: Single-layer similarity: ; Global trustworthiness: Reli Global = ; Where n is the total number of feature vectors collected in each layer; Let i be the i-th eigenvector; The baseline of the i-th eigenvector; The baseline range of the i-th feature vector; Let be the weight of the i-th eigenvector, and satisfy . ; W represents the single-layer similarity for each layer. kLet be the weight coefficients for each layer, and let the weight coefficients satisfy: =1.

[0011] Furthermore, in step S5, the method for assigning permissions based on the trust level includes the following steps: When the trust level is ≥X1, it is judged as high trust, and the user is granted full business permissions of the role, allowing access to all authorized resources; When X2 ≤ Trustworthiness < X1, it is determined to be medium trust, and only basic business functions are open, while access to core databases and sensitive APIs is restricted; When X3 ≤ Trustworthiness < X2, it is judged as low trust, the current session is frozen and reported to the central control node; When 0 ≤ Trustworthiness < X3, it is judged as extremely low trust. The edge control agent directly blocks terminal access, isolates and reports to the central control node. Among them, X1, X2, and X3 are preset values.

[0012] Furthermore, the method for adaptive baseline updates through periodic iterations or emergency iterations is as follows: At a predetermined time each day, the baseline threshold is adjusted periodically based on the newly added vector data from the previous day, with the adjustment range not exceeding 5%. Emergency iteration is triggered when the proportion of newly added terminals exceeds the preset proportion, when the business system is upgraded, or when the network topology changes. The new limit is generated and updated in real time.

[0013] As a second aspect of the present invention, the present invention provides a zero-trust core management system based on user behavior and OSI seven-layer authentication, the management system being used to implement the management method described in the first aspect, the management system comprising: The objects under terminal management include core databases, core network devices, and other core terminal devices; The edge control agent is deployed at the entry point of each core business area to collect OSI seven-layer state vectors and user behavior vectors. It preprocesses the collected vectors, encodes the preprocessed vectors using the Word2Vec model, maps the vector data to the [0,1] interval using the Min-Max normalization algorithm, calculates the single-layer similarity using the weighted cosine similarity algorithm, and calculates the global credibility using weighted summation. Based on the global credibility level, it performs access authorization, permission adjustment, and anomaly blocking. The central control node is used to define trust levels and response measures. It trains a dynamic trust baseline based on historical data using the RWKV model and performs secondary analysis on low-trust and very low-trust events.

[0014] Furthermore, the edge control agent includes: The data acquisition module is used to simultaneously acquire OSI seven-layer state vectors and user behavior vectors; The vector processing module is used to encode and perform Min-Max normalization on the acquired vectors. The trust assessment engine is used to calculate single-layer similarity using a weighted cosine similarity algorithm and to calculate global trustworthiness through weighted summation. The policy execution engine is used to perform access authorization, permission adjustment, and anomaly blocking based on the global trust level; Data caching and synchronization agent, which is used to cache local data and synchronize incremental data to the central control node.

[0015] Furthermore, the central control node includes: The Trust Policy module is used to define trust levels and corresponding actions. The baseline training module is used to train a dynamic trustworthy baseline based on historical data using the RWKV model; the high-risk assessment module is used to perform secondary assessments based on the trust level. The data auditing module is used to store full network vector data, trust assessment logs, and anomaly handling records; The joint response module is used to formulate joint response strategies and distribute them to edge control agents for execution.

[0016] The present invention has the following beneficial effects: This invention establishes an eight-layer full-stack authentication model covering the OSI physical layer, data link layer, network layer, transport layer, session layer, presentation layer, application layer, and user behavior layer. It transforms the characteristics of the seven OSI layers into unified, computable vector parameter factors. Combining user identity and behavior vector information, it forms a three-dimensional trust evidence chain of "physical device - transmission network - user behavior," completely eliminating cross-layer protection blind spots. Through a state vector similarity algorithm, the eight-layer vector data is standardized, and the similarity between the real-time state and the baseline is calculated, achieving a quantitative assessment of trustworthiness. A three-element dynamic trust baseline of "physical device - transmission network - user behavior" is constructed. The baseline can adaptively iterate according to changes in the network environment, evolution of user behavior, and updates in device state, without manual intervention, adapting to dynamic and complex scenarios.

[0017] Of course, any product implementing this invention does not necessarily need to achieve all of the advantages described above at the same time. Attached Figure Description

[0018] To more clearly illustrate the technical solutions of the embodiments of the present invention, the accompanying drawings used in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0019] Figure 1 This is a flowchart of the zero-trust core control method based on user behavior and OSI seven-layer authentication of the present invention. Figure 2 This is a diagram of the full-stack eight-layer zero-trust authentication model of the user + OSI seven-layer architecture. Figure 3 This is a schematic diagram of the zero-trust core control system based on user behavior and OSI seven-layer authentication of the present invention; Figure 4 This is a schematic diagram of the central control node of the present invention; Figure 5 This is a schematic diagram of the edge control agent of the present invention; Figure 6 This is a schematic diagram of the terminal control object of the present invention. Detailed Implementation

[0020] In the following description, specific details such as particular system architectures and techniques are set forth for illustrative purposes and not for limitation, in order to provide a thorough understanding of the embodiments of this application. However, those skilled in the art will understand that this application may also be implemented in other embodiments without these specific details. In other instances, detailed descriptions of well-known systems, apparatuses, circuits, and methods have been omitted so as not to obscure the description of this application with unnecessary detail.

[0021] It should be understood that, when used in this application specification and the appended claims, the term "comprising" indicates the presence of the described features, integrals, steps, operations, elements and / or components, but does not exclude the presence or addition of one or more other features, integrals, steps, operations, elements, components and / or a collection thereof.

[0022] It should also be understood that the term “and / or” as used in this application specification and the appended claims means any combination of one or more of the associated listed items and all possible combinations, and includes such combinations.

[0023] As used in this application specification and the appended claims, the term "if" may be interpreted, depending on the context, as "when," "once," "in response to determination," or "in response to detection." Similarly, the phrase "if determined" or "if detected [the described condition or event]" may be interpreted, depending on the context, as meaning "once determined," "in response to determination," "once detected [the described condition or event]," or "in response to detection [the described condition or event]."

[0024] Furthermore, in the description of this application and the appended claims, the terms "first," "second," "third," etc., are used only to distinguish descriptions and should not be construed as indicating or implying relative importance.

[0025] References to "one embodiment" or "some embodiments" as described in this specification mean that one or more embodiments of this application include a specific feature, structure, or characteristic described in connection with that embodiment. Therefore, the phrases "in one embodiment," "in some embodiments," "in other embodiments," "in still other embodiments," etc., appearing in different parts of this specification do not necessarily refer to the same embodiment, but rather mean "one or more, but not all, embodiments," unless otherwise specifically emphasized. The terms "comprising," "including," "having," and variations thereof mean "including but not limited to," unless otherwise specifically emphasized.

[0026] Example 1: This invention is a zero-trust core control method based on user behavior and OSI seven-layer authentication. It constructs a zero-trust control method with "full-stack authentication - vector modeling - dynamic baseline - continuous evaluation" as its core, including the following steps: Step S1: When the terminal initiates a network or application access request, the edge management agent synchronously collects the OSI seven-layer state vector and user behavior vector; Step S2: Encode the vectors using the Word2Vec model, and then normalize the vector data using the Min-Max normalization algorithm; Step S3: Based on historical vector data, the RWKV model is used to automatically learn the normal state threshold range of the OSI seven layers and the user behavior layer to construct a three-element dynamic trust baseline of physical device-transmission network-user behavior. Step S4: Calculate the single-layer similarity using the weighted cosine similarity algorithm, and then calculate the global credibility by weighted summation of the similarities of each layer; Step S5: Assign permissions based on trust level and execute access authorization; Step S6: After the terminal successfully connects, continuously collect real-time vector data and update the global credibility. Trigger permission adjustment, alarm or blocking operations based on changes in global credibility; perform baseline adaptive updates through periodic iteration or emergency iteration.

[0027] This invention breaks away from the traditional zero-trust two-dimensional authentication framework of "identity + device". By using an eight-layer full-stack authentication model covering the OSI physical layer, data link layer, network layer, transport layer, session layer, presentation layer, application layer, and user behavior layer, it transforms the characteristics of the OSI seven-layer protocol into unified and computable vector parameter factors. Combined with user identity and behavior vector information, it forms a three-dimensional trust evidence chain of "physical device-transmission network-user behavior", completely eliminating blind spots in cross-layer protection.

[0028] Example 2: Please see Figure 1 As shown, this invention is a zero-trust core management method based on user behavior and OSI seven-layer authentication, including the following steps: Step S1: Access Request Trigger and Layer 8 Vector Synchronization Acquisition: When a terminal initiates a network or application access request, the edge management agent detects the request and automatically triggers the Layer 8 full-stack data acquisition module: The OSI Layer 7 state acquisition unit synchronously collects vector data such as physical layer hardware fingerprint, data link layer MAC address, and network layer IP through agents at each layer; the user behavior acquisition unit collects behavioral vector data such as the terminal's current access time and initial operation (e.g., "clicking the login button"), performs preprocessing operations such as missing value filling and fixed-length truncation on the collected raw data, and transmits the vector data to the vector processing module in real time; the terminal is such as an office computer or IoT device, and the access request is such as opening a VPN or logging into a business system; Step S2: Vector Encoding and Standardization: The preprocessed vectors are encoded using the Word2Vec model to address the shortcomings of traditional One-hot encoding, which results in overly sparse data vector matrices as the dimension of the feature space increases, requiring longer-dimensional vectors to represent words, which is detrimental to the computation of deep learning models. Then, the Min-Max normalization algorithm is used to map the vector elements of each layer to the [0,1] interval to eliminate differences in dimensionality, such as the unification of different dimensional parameters like physical layer hardware fingerprint similarity and application layer API call frequency. The standardized vector data is temporarily stored in a time-series database, and vector IDs are generated for subsequent tracing. Step S3: Dynamic Baseline Construction: Based on historical vector data, the RWKV model is used to automatically learn the normal state threshold range of each layer to construct a three-element dynamic reliable baseline of physical device-transmission network-user behavior. The historical data used for generating the dynamic baseline has a time period of more than 3 months and a sample size of more than 100,000. Sufficient time period and sample size are required to ensure the model recognition accuracy. The normal distribution range of each layer vector is output. For example, the hardware fingerprint similarity of the physical layer is ≥95% and the API call frequency deviation of the application layer is ≤20% and is considered normal. Step S4: Trustworthiness Judgment: An integrated judgment algorithm is adopted. The weighted cosine similarity algorithm is used to calculate the similarity of a single layer. The similarity between the actual feature vectors collected in real time and the corresponding baseline vectors is calculated, with a value of 0-100. When the single-layer similarity is <70, the layer is judged to be abnormal. Then, the global trustworthiness is calculated by weighted summation of the similarities of each layer. Step S5: Dynamic permission allocation and access authorization: Permissions are allocated according to the trust level, which includes high trust, medium trust, low trust and very low trust, and access authorization is executed according to the corresponding handling measures; Step S6: Post-Connection Continuous Trust Assessment: After successful connection, continuously collect real-time vector data and update global trustworthiness. Trigger permission adjustments, alarms, or blocking operations based on changes in global trustworthiness. Perform baseline adaptive updates through periodic or emergency iterations. After each iteration, generate an iteration report and store it in the audit log. After successful connection, the Layer 8 full-stack authentication module continuously collects real-time state vectors and user behavior data, such as updating standardized vectors and trustworthiness scores every second. Trustworthiness remains at the corresponding level: Maintain current permissions; Trust level downgraded from high / medium to low: Automatically triggers permission downgrade + local alert; Trust level drops to extremely low: Immediately freeze the session and block access, then report to the central control node; Credibility enhancement: The report is submitted to the central control node for secondary confirmation. Once the confirmation is passed, the credibility is enhanced. Step S7: Anomaly Handling Result Feedback and Terminal Recovery Steps: After handling the abnormal terminal, the central control node issues the handling result instruction; If the alarm is determined to be false (e.g., fingerprint changes have not been updated after terminal hardware repair): the central control node instructs the edge node to release the isolation, reset the terminal's trust level to medium trust, and allow reconnection; If it is determined to be a real attack (such as the terminal being implanted with malicious programs): the central control node instructs the edge nodes to maintain isolation. After the terminal removes the malicious programs and returns to normal, the access process of steps S1-S5 is re-executed. After the terminal regains access, the edge node will focus on monitoring its trustworthiness (e.g., increasing the evaluation frequency to once every 100 milliseconds). After a period of time (e.g., 12 hours) without any abnormalities, the normal evaluation frequency will be restored. Step S8: Dynamic baseline adaptive iteration. The method for adaptively updating the baseline through periodic iteration or emergency iteration is as follows: At a preset time each day, such as 2-4 AM, the central control node initiates a periodic baseline iteration, adjusting the baseline threshold based on the newly added vector data of the previous day. The adjustment range of the baseline threshold does not exceed 5%. For example, the eight-layer vector data of the previous day are synchronized from all edge nodes; the threshold range of the eight-layer normal state is fine-tuned, and the application layer API call frequency fluctuation threshold is adjusted from ±20% to ±18%.

[0029] When the number of newly added terminals exceeds the preset percentage, or when there is a major upgrade of the business system or a change in network topology, an emergency iteration is triggered, and the baseline retraining is completed within 2 hours. If the emergency iteration conditions are triggered, such as adding 200 IoT terminals, accounting for 15% of the original terminals, the central control node will automatically start the emergency iteration, notify all edge nodes to suspend the use of the baseline, and retrain the new baseline. After the training is completed, it will be immediately distributed to the edge nodes, and the edge nodes will resume normal evaluation after updating the baseline. After the baseline iteration is completed, the central control node generates an iteration report and stores it in the audit log. The iteration report includes a comparison of thresholds before and after the iteration, the amount of iteration data, and an evaluation of the iteration effect.

[0030] The system automatically generates and iterates normal threshold ranges through AI models and algorithms to adapt to changes in business and environment without the need for manual maintenance. It provides continuous evaluation and paradigm upgrades, transforming the traditional "single authentication" into a zero-trust "continuous trust evaluation," thus completely closing the zero-trust logic.

[0031] Abandoning the traditional static whitelist mechanism, based on massive historical data, the RWKV model automatically learns and generates eight layers of "normal state threshold ranges" by integrating the efficient parallel training of Transformer and the efficient inference of RNN. It constructs a three-element dynamic trusted baseline of "physical device-transmission network-user behavior". The baseline can adaptively iterate according to changes in network environment, evolution of user behavior and device status updates without manual intervention, and adapt to dynamic and complex scenarios.

[0032] As an embodiment of the present invention, preferably, in step S1, the collected OSI seven-layer state vector and user behavior vector content includes: Collect physical media type, hardware device fingerprint, and device specification compliance vector data at the physical layer; Collect data frame format, MAC address binding relationship, link encryption status, and MAC address change trajectory vector data at the data link layer; Collect source IP address, destination IP address, routing hop count mutation information, IP geolocation, and gateway access frequency vector data at the network layer; Collect vector data on TCP / UDP connection establishment frequency, connection rate fluctuations, port usage compliance, and data transmission volume at the transport layer; Collect session establishment process, session timeout, session reconnection count, and session associated terminal identifier vector data at the session layer; Collect the data encoding format, data compression algorithm, encryption key negotiation process, and data verification result vector data of the presentation layer; Collect API call frequency, API parameter compliance, application permission usage trajectory, and application log exception code vector data at the application layer; Collect user data including mouse / keyboard operation frequency, operation interval, access time, single access duration, high-frequency operation period, permission call order, frequency of sensitive permission usage, and permission request rationality.

[0033] By unifying the OSI seven layers and user behavior into a computable vector, and achieving reliable quantification through similarity algorithms and corresponding AI recognition models, this approach avoids the coarse-grained control shortcomings of existing level-based automatic discrimination systems, improves control accuracy, and breaks through the two-dimensional limitations of identity + device. It adopts an eight-layer full-stack collection method that combines user behavior and the OSI seven-layer protocol to eliminate cross-layer blind spots, enhances all-round attack resistance capabilities, and solves the shortcomings of existing security defense systems that only provide protection for a specific function, have single security functions, and lack overall security protection measures.

[0034] Example 3: like Figure 2 As shown, this invention is a zero-trust core control method based on user behavior and OSI seven-layer authentication, constructing a full-stack eight-layer zero-trust authentication model combining user and OSI seven layers. The model structure is as follows: Figure 2As shown, for different types of dangerous methods, multi-dimensional state vectors are collected in real time at each layer of the OSI protocol stack (from the physical layer to the application layer). These include: the physical layer collecting physical media type and hardware device fingerprints (CPU serial number, motherboard MAC, hard drive unique identifier); the data link layer collecting data frame format and MAC address change trajectories; the network layer collecting IP address and routing hop count mutation information; the transport layer collecting connection rate fluctuations and protocol compliance data; the session layer collecting session establishment / termination procedures and session duration; the presentation layer collecting data encoding format and encryption standards; and the application layer collecting API call frequency and permission usage trajectories. Simultaneously, user behavior vectors (operation habits, time period preferences, resource access sequences) are collected. A state vector similarity algorithm is designed, and after standardizing the eight layers of vector data, the similarity between the real-time state and the baseline is calculated to achieve a quantitative assessment of trustworthiness.

[0035] As an embodiment of the present invention, the preferred full-stack eight-layer zero-trust authentication model of user + OSI seven-layer includes two units: OSI seven-layer state acquisition and encoding unit and user behavior state acquisition and encoding unit.

[0036] A more preferred OSI seven-layer state acquisition and encoding unit: deploys protocol parsing agents at each layer, and collects multi-dimensional state vectors in the order of "physical layer → data link layer → network layer → transport layer → session layer → presentation layer → application layer", and then... Figure 2 Each layer of "feature terms" is transformed into computable vector parameter factors, as detailed below: Physical layer: Data collected includes: physical media type, such as Ethernet, Wi-Fi, hardware device fingerprint, CPU serial number, motherboard MAC address, hard drive unique identifier, BIOS version, device specification compliance, etc., to detect whether there are any signs of hardware tampering or replacement. Encoding method: Physical media type is encoded as a numerical value, such as Ethernet=1, WIFI=2; hardware fingerprint is normalized after using a hash algorithm; compliance is encoded as 0, compliant / 1, non-compliant; Threats to address include hardware attacks, unlocking, hardware address attacks, and physical line interception.

[0037] Data link layer: Data collection includes: parsing data frame formats such as Ethernet frame structure, MAC address binding relationships, link encryption status (e.g., whether SM4 / AES encryption methods are enabled), and MAC address change history (e.g., the number of changes and their sources within the past hour). Encoding method: Frame format is encoded as a numerical value, such as Ethernet frame = 1, PPP frame = 2; MAC change count is normalized; encryption status is encoded as 0, unencrypted / 1, AES encrypted / 2, SM4 encrypted, etc. Countering threats includes: active and passive sniffing attacks, MAC address spoofing, and cracking of wired equivalent encryption.

[0038] Network layer: The data collected includes: source IP address, destination IP address, hop count (e.g., deviation from historical baseline), IP geolocation (e.g., whether it matches the user's frequently used area), gateway access frequency (e.g., whether there are abnormal redirects), etc. Encoding method: IP address is converted into a numerical vector; the ratio of hop count deviation to baseline is normalized; IP geolocation deviation is normalized; access frequency is normalized; IP geolocation deviation can be expressed in kilometers. Threat mitigation: IP attacks, routing attacks, ARP poisoning attacks, MAC flooding, and ICMP attacks, among other threat types.

[0039] Transport layer: Data collected includes: TCP / UDP connection establishment frequency, connection rate fluctuations (e.g., percentage deviation from baseline), port usage compliance (e.g., whether unauthorized high-risk ports are used), and data transmission volume (whether single-session transmission volume exceeds the threshold). Encoding methods: Transmission rate (Mbps) is normalized; protocol compliance is encoded as 0 (compliant) / 1 (non-compliant); port permission is encoded as 0 (authorized) / 1 (unauthorized), etc. Threats to address include: port scanning, DoS attacks, service exhaustion attacks, flag manipulation attacks, and more.

[0040] Session layer: Data collected includes: session establishment process (e.g., whether it conforms to the standard three-way handshake / four-way handshake), session timeout, number of session reconnections (e.g., number of reconnections within 10 minutes), and session associated terminal identifier (e.g., whether there is a shared session across multiple terminals). Encoding method: 0 is used for process compliance (compliant / 1), and 1 is used for non-compliance; session duration (seconds) is normalized; reconnection count is normalized. Threat mitigation: This includes threats such as session hijacking, SYN attacks, and password attacks.

[0041] Presentation layer: The data collected includes: verifying the data encoding format (e.g., whether JSON / XML is compliant), the data compression algorithm (e.g., whether it is an authorized algorithm), the encryption key negotiation process (e.g., whether there is a risk of key leakage), and the data verification results (e.g., whether CRC32 / SHA256 verification passes). Encoding method: Format is encoded as a number (e.g., JSON=1, XML=2, others=3), algorithm type is encoded (e.g., SM4=1, AES=2, ...); verification result is encoded as 0, pass / 1, fail; Countering threats: NetBIOS brute-force attacks, plaintext extraction, and protocol stack attacks, among other threat methods.

[0042] Application layer: Data collected includes: API call frequency (e.g., the number of calls to the login API and data query API per minute), API parameter compliance (e.g., whether there is abnormal parameter injection), application permission usage history (e.g., whether there is unauthorized access to functional modules), and application log error codes (e.g., login failure codes and data reading error codes). Encoding method: Call frequency (times / minute) is normalized; parameter compliance is encoded as 0, compliant / 1, non-compliant; permission trajectory is encoded as a vector (e.g., [1,0,1] represents "authorized - unauthorized - authorized"). Addressing threats: application attacks, cache overflows, malicious code, and malware (such as worms and Trojans).

[0043] As an embodiment of the present invention, preferably, the user behavior collection unit collects user behavior vectors through three methods: terminal proxy, application log parsing, and network traffic analysis, as detailed below: Content collected: User habits: common operation sequences (such as deviations from the fixed process of "login → query → export"), mouse / keyboard operation frequency (whether it matches the user's historical habits), operation interval (fluctuations in the time interval between consecutive operations); Time period preference: access time (whether access occurs outside the user's usual working hours, such as 1-6 am), single access duration (deviation from historical average duration), high-frequency operation time (whether there are high-frequency operations outside of working hours). Permission usage trajectory: permission call order (whether there is an abnormal jump from "low permission to high permission"), frequency of sensitive permission usage (such as the number of times data deletion and batch export permissions are called), and the rationality of permission requests (whether non-business-related permissions are requested temporarily).

[0044] Encoding methods: similarity normalization between the operation sequence and the baseline, time period deviation (number of hours) normalization, and usage frequency (times / hour) normalization. Threat mitigation: Social engineering, flawed policies, spam data mining, spying, email spoofing, and telephone fraud are just some of the threat tactics employed.

[0045] Example 4: Based on Examples 1 to 3, this invention is a zero-trust core management method based on user behavior and OSI seven-layer authentication. In step S2, the normalization formula used by the Min-Max normalization algorithm is: ; Where X is the original value of a feature term in the OSI seven-layer state vector or user behavior vector, Xmin and Xmax are the minimum and maximum values ​​in the data set of all original values ​​belonging to the same feature term as X, respectively; X* is the value mapped to the interval [0, 1] after normalization.

[0046] As an embodiment of the present invention, preferably, the method for allocating permissions according to the trust level in step S5 includes the following steps: When the trust level is ≥85, it is judged as high trust, and the user is granted full business permissions of the role, allowing access to all authorized resources; When the trust level is between 60 and 85, it is considered a medium trust level, and only basic business functions are allowed, while access to the core database and sensitive APIs is restricted. When the trust level is between 30 and 60, it is judged as low trust, the current session is frozen and reported to the central control node, the edge control agent is suspended from access and reported to the central control node for secondary analysis before issuing a disposal instruction. When 0 ≤ Trustworthiness < 30, it is judged as extremely low trust. The edge control agent directly blocks terminal access and isolates it, reports it to the central control node, and notifies the security operation and maintenance team.

[0047] Example 5: Please see Figures 3 to 6 As shown, this invention is a zero-trust core control system based on user behavior and OSI seven-layer authentication. It transforms the features of the OSI seven-layer protocol into computable vector parameter factors, combines user identity and behavior vector information to form a three-dimensional trust evidence chain, and employs a designed state vector similarity algorithm to achieve zero-trust closed-loop verification. The control system is used to implement the control methods provided in Embodiments 1 to 4. The control system includes: The objects under terminal management include core databases, core network devices, and other core terminal devices; The edge control agent is deployed at the entry point of each core business area to collect OSI seven-layer state vectors and user behavior vectors. It preprocesses the collected vectors, encodes the preprocessed vectors using the Word2Vec model, maps the vector data to the [0,1] interval using the Min-Max normalization algorithm, calculates the single-layer similarity using the weighted cosine similarity algorithm, and calculates the global credibility using weighted summation. Based on the global credibility level, it performs access authorization, permission adjustment, and anomaly blocking. The central control node is deployed in the core area of ​​the network to define trust levels and handling measures. It trains a dynamic trust baseline based on historical data using the RWKV model and performs secondary analysis on low-trust and very low-trust events.

[0048] As an embodiment of the present invention, preferably, the control object refers to the terminal equipment in the core area where the core controller performs security control, including various core databases, core network equipment and other core terminal equipment. These core devices are connected to the core controller through a local area network or private network and are subject to the unified management and control of the core controller.

[0049] As an embodiment of the present invention, preferably, the edge control agent is deployed at the entry point of each core business area, supports dynamic expansion, and undertakes functions such as local vector acquisition, real-time trust assessment, low-risk event handling, and continuous status monitoring. It includes: an eight-layer full-stack authentication core data acquisition module, a vector processing module, a real-time trust assessment engine, a local policy execution engine, and a data caching and synchronization agent. Specifically: The data acquisition module is used to synchronously collect OSI seven-layer state vectors and user behavior vectors. The module includes an OSI seven-layer state acquisition unit and a user behavior acquisition unit. It achieves seamless, low-loss acquisition through lightweight proxies. The OSI seven-layer state acquisition unit deploys protocol parsing proxies at each layer, collecting multi-dimensional state vectors in the order of the data auditing module's physical layer → data link layer → network layer → transport layer → session layer → presentation layer → application layer. The user behavior acquisition unit collects user behavior vectors through three methods: terminal proxy, application log parsing, and network traffic analysis. The collected content is as described in Example 3 and the appendix to the specification. Figure 2 As shown; The vector processing module is used to encode and perform Min-Max normalization on the acquired vectors. The trust assessment engine is used to calculate single-layer similarity using a weighted cosine similarity algorithm and to calculate global trustworthiness through weighted summation. The policy execution engine is used to perform access authorization, permission adjustment and anomaly blocking based on the global trust level; it automatically executes access authorization, permission adjustment and anomaly blocking operations according to the centrally issued policies; it also supports the joint prevention and control mechanism based on the central control node linkage and handling module, and realizes comprehensive collaborative control of terminal control objects based on the linkage instructions and corresponding tools provided by the linkage and handling module. Data caching and synchronization agent, which is used to cache local data and synchronize incremental data to the central control node.

[0050] As an embodiment of the present invention, preferably, multi-dimensional state vectors are collected in real time at each layer of the OSI protocol stack (from the physical layer to the application layer), including: physical media and hardware device fingerprints at the physical layer, data frame information and abnormal MAC changes at the data link layer, IP address and routing hop count mutation information at the network layer, connection rate fluctuation information at the transport layer, session establishment, termination, and duration information at the session layer, data format and encryption information at the presentation layer, and API call frequency at the application layer. Combined with user behavior characteristics (operation habits, time preferences, permission usage patterns, etc.), a three-dimensional dynamic trust baseline of physical device-transmission network-user behavior is constructed. Unlike static whitelists or single-factor authentication, the model uses AI learning algorithms to automatically generate normal state threshold ranges for each layer and continuously analyzes and identifies anomalies across eight layers, achieving a paradigm shift from single authentication to continuous trust assessment.

[0051] As an embodiment of the present invention, preferably, the vector processing module transforms the unstructured / semi-structured data collected from eight layers into computable and comparable standardized vectors, providing a unified data foundation for trust assessment. The vector processing module includes: Vector normalization unit: The Min-Max normalization algorithm is used to map vector parameters of different dimensions to the [0,1] interval, eliminating the interference of numerical magnitude differences on the calculation results; vector parameters include API call frequency and connection rate; Vector storage unit: Stores real-time vector data and historical vector data, indexed by terminal ID + timestamp, supports millisecond-level queries, and retains 90 days of historical data for baseline training.

[0052] As an embodiment of the present invention, preferably, the trust assessment engine calculates credibility and identifies anomalies in real time based on a locally stored dynamic baseline, which is generated and distributed by a central control node. The trust assessment engine comprises two sub-modules: single-level similarity calculation and global credibility calculation. Specifically: Single-level similarity calculation submodule: The weighted cosine similarity algorithm is used to calculate the similarity between the real-time standardized vectors of each of the eight layers and the baseline vector. The single-level similarity score ranges from 0 to 100. Global credibility calculation submodule: The global credibility is obtained by weighted summation of each layer. The global credibility score ranges from 0 to 100, and the weight allocation is set according to the degree of risk impact.

[0053] As an embodiment of the present invention, a preferred algorithm for calculating single-layer similarity and global credibility is as follows: Single-layer similarity: ; Global credibility:

[0054] Where n is the total number of feature vectors collected in each layer; Let i be the i-th eigenvector; The baseline of the i-th eigenvector; The baseline range of the i-th feature vector; Let be the weight of the i-th eigenvector, and satisfy . Simi represents the single-layer similarity for each layer, and W is the weight coefficient for each layer, with the weight coefficients satisfying: Among them, the physical layer weight coefficient 15%, data link layer weight coefficient 10%, network layer weight coefficient 15%, transport layer weighting coefficient 10%, Session Layer Weighting Coefficient 4%, representing the layer weight coefficient 4%, application layer weight coefficient 20%, user behavior layer weight coefficient The global credibility is calculated using 22%.

[0055] As an embodiment of the present invention, preferably, the data caching and synchronization proxy module caches local data and incrementally synchronizes it to the central control node, reducing the core network bandwidth pressure, realizing secure data synchronization between the central control node and edge nodes, and ensuring global control consistency. The data caching and synchronization proxy module is used for: Policy and baseline synchronization: The central control node sends the trust level standard, handling measures rules and dynamic baseline to the edge nodes. The synchronization frequency is real-time synchronization of policy changes + timed synchronization of baseline updates. The transmission protocol uses SM2+SM4 for encryption, decryption and signature authentication to avoid data leakage. Vector and log synchronization: Edge nodes incrementally synchronize Layer 8 real-time vector data (once every 5 minutes), trust assessment logs (once every 1 minute), and abnormal event logs (synchronized as soon as they occur) to the central control node, reducing core network bandwidth usage. State synchronization: Every 30 seconds, edge nodes report their own operating status, such as CPU utilization, memory usage, and network bandwidth, to the central control node. The central control node performs load balancing based on the state data, such as migrating tasks from high-load nodes to low-load nodes.

[0056] As an embodiment of the present invention, preferably, the central control node is deployed in the core area of ​​the network and undertakes core functions such as global policy formulation, baseline training and optimization, high-risk event assessment, and data aggregation and auditing. It includes: a trust policy module, a baseline training module, a high-risk assessment module, a data auditing module, and a coordinated response module. Specifically: The Trust Strategy module is used to define trust levels and handling measures. The Trust Strategy module defines eight layers of authentication rules, trust level standards, and handling measure templates. The baseline training module is used to train a dynamic trusted baseline based on historical data using the RWKV model. It also constructs a three-dimensional dynamic trusted baseline for the data auditing module (physical device – transmission network – user behavior data auditing module) based on an AI model, enabling the data auditing module to adaptively iterate as the environment changes. The data auditing module comprises two sub-modules: baseline training and baseline iteration. Baseline Training Submodule: The RWKV model, which combines the efficient parallel training of Transformer with the efficient inference of RNN, is used for trusted baseline threshold training. By inputting historical vector data over a period of time, such as 6 months, it automatically learns the eight layers of data audit modules for normal state threshold baseline data audit modules. Baseline Iteration Submodule: Supports two iteration modes: regular iteration and emergency iteration, to ensure the timeliness of the baseline: Regular iteration: By default, it is from 2:00 to 4:00 a.m. every day. The baseline threshold is fine-tuned based on the newly added vector data of the previous day, with an adjustment range of ≤5%; Emergency iteration: When a preset condition is triggered, the baseline retraining is started immediately and the update is completed within 2 hours. Preset conditions include the proportion of newly added terminals ≥10%, major upgrades to business systems, and changes in network topology. The high-risk assessment module is used for secondary assessment based on trust levels. It receives low / extremely low trust events reported by edge nodes and performs secondary assessment by combining cross-regional data. The high-risk assessment module focuses on low / extremely low trust events that edge nodes cannot independently and accurately determine. By integrating multi-dimensional data resources across regions and the entire network, it achieves a global perspective and deeply correlated secondary assessment of risks. This avoids misjudgments caused by the local perspective of edge control agents and ensures the accuracy, coordination, and completeness of high-risk event handling, serving as a key support for intelligent decision-making in a zero-trust closed loop. The data audit module stores network-wide vector data, trust assessment logs, and anomaly handling records. It aggregates eight layers of network-wide vector data, trust assessment logs, and anomaly handling records, supporting compliance traceability. At the data storage level, a dual mechanism of distributed time-series database and blockchain notarization is employed: the time-series database stores network-wide eight-layer feature vector data in real time (e.g., one record per terminal every 100 milliseconds), trust assessment logs (including credibility calculation process and policy matching logic), and anomaly handling records (including action type, triggering conditions, and execution results), supporting millisecond-level retrieval of TB-level data; blockchain notarization solidifies high-risk assessment conclusions, anomaly handling instructions, and other key operations on the blockchain, ensuring data immutability and traceability, fully meeting compliance requirements for log integrity and authenticity. The joint response module is used to formulate joint response strategies and distribute them to the edge control agent for execution. Specifically, based on the secondary assessment results of the high-risk assessment module, the joint response module, in conjunction with the system's existing security protection tools (such as firewalls, intrusion detection systems, antivirus tools, etc.) and corresponding security maintenance personnel, formulates corresponding joint response strategies and distributes them to the edge control agent for joint execution with the corresponding personnel and tools.

[0057] As an embodiment of the present invention, preferably, in traceability and auditing scenarios, the data auditing module can achieve one-click generation of a complete, three-dimensional evidence chain. For example, when tracing a risk event of a terminal, the administrator can input the terminal ID or time range through a visual interface. The system can automatically associate the terminal's physical layer hardware fingerprint collection records, the vector similarity calculation process at each layer, the basis for determining the credibility level, and the execution trajectory of the abnormal handling actions. Each step is accompanied by a precise timestamp, a snapshot of the original data, and an explanation of the system's decision-making logic, forming a complete evidence chain from data collection to handling, providing irrefutable audit evidence for determining responsibility for security incidents and tracing the source of attacks. At the same time, the center has a built-in compliance analysis engine that can automatically identify compliance shortcomings in logs (such as high-risk events that were not handled in a timely manner, deviations between policy configuration and compliance requirements), generate visual compliance reports, help enterprises complete compliance self-inspections in advance, upgrade auditing work from passive verification to proactive defense, and significantly reduce compliance costs and risks.

[0058] As an embodiment of the present invention, preferably, the trust strategy module includes a trust level classification submodule, a handling measure configuration submodule, and a strategy audit submodule, specifically: The credibility level classification submodule has four preset credibility levels, covering different risk scenarios: High trust: 85-100 points, no anomalies, terminal and behavior fully conform to baseline; Zhongxin: 60-84 points, with minor single-level anomalies and no risk of linkage. Low Trust: 30-59 points, indicating obvious single-level anomalies or low-risk linked anomalies; Extremely low trust: 0-29 points, indicating a serious single-level anomaly or a high-risk linkage anomaly; The action configuration submodule supports binding corresponding action actions to each trust level, and allows administrators to customize and adjust them. High Trust: Grant users full business permissions to their assigned roles, allowing access to all authorized resources without triggering alarms; Zhongxin Trust: Restrict access to sensitive resources such as core databases and high-risk APIs, only open basic business functions, trigger low-level alarms in the data audit module, and only notify end users when the data audit module is triggered; Low Trust: Freeze the current session, force exit the application, prohibit reconnection within 30 minutes, trigger the data audit module's level alarm, and notify the end user and department administrator; Extremely low trust: Block terminal access, prohibit network connection, isolate the terminal from the network, restrict communication with other terminals, trigger high-level alarm of data audit module, notify security operation and maintenance team, and start emergency response; The strategy audit submodule records the history of strategy modifications, such as the modifier, modification time, and modification content, as well as the execution log of the handling measures, including execution time, terminal ID, credibility, and handling result. The logs are stored in the blockchain of the data audit module to ensure immutability and support audit retrieval by time, terminal, and anomaly type.

[0059] A zero-trust core management system and method based on user behavior and OSI seven-layer authentication is proposed. This system establishes an eight-layer full-stack authentication model covering the OSI physical layer, data link layer, network layer, transport layer, session layer, presentation layer, application layer, and user behavior layer. It transforms the characteristics of the OSI seven-layer protocol into unified, computable vector parameter factors. Combined with user identity and behavior vector information, a three-dimensional trust evidence chain is formed between the physical device of the data audit module, the transmission network, and the user behavior data audit module. This completely eliminates cross-layer protection blind spots. Through a state vector similarity algorithm, the eight-layer vector data is standardized, and the similarity between the real-time state and the baseline is calculated, enabling quantitative assessment of trustworthiness. A three-element dynamic trust baseline is constructed for the physical device, transmission network, and user behavior data audit modules. The baseline can adaptively iterate according to changes in the network environment, evolution of user behavior, and updates in device status, without manual intervention, adapting to dynamic and complex scenarios.

[0060] In the description of this specification, references to terms such as "an embodiment," "example," "specific example," etc., indicate that a specific feature, structure, material, or characteristic described in connection with that embodiment or example is included in at least one embodiment or example of the invention. In this specification, illustrative expressions of the above terms do not necessarily refer to the same embodiment or example. Furthermore, the specific features, structures, materials, or characteristics described may be combined in any suitable manner in one or more embodiments or examples.

[0061] The preferred embodiments of the present invention disclosed above are merely illustrative of the invention. These preferred embodiments do not exhaustively describe all details, nor do they limit the invention to the specific implementations described. Clearly, many modifications and variations can be made based on the content of this specification. This specification selects and specifically describes these embodiments to better explain the principles and practical applications of the invention, thereby enabling those skilled in the art to better understand and utilize the invention. The invention is limited only by the claims and their full scope and equivalents.

Claims

1. A zero-trust core control method based on user behavior and OSI seven-layer authentication, characterized in that, Includes the following steps: Step S1: When the terminal initiates a network or application access request, the edge management agent synchronously collects the OSI seven-layer state vector and user behavior vector; Step S2: Encode the vectors using the Word2Vec model, and then normalize the vector data using the Min-Max normalization algorithm; Step S3: Based on historical vector data, the RWKV model is used to automatically learn the normal state threshold range of the OSI seven layers and the user behavior layer to construct a three-element dynamic trust baseline of physical device-transmission network-user behavior. Step S4: Calculate the single-layer similarity using the weighted cosine similarity algorithm, and then calculate the global credibility by weighted summation of the similarities of each layer; Step S5: Assign permissions based on trust level and execute access authorization; Step S6: After the terminal successfully connects, continuously collect real-time vector data and update the global credibility. Trigger permission adjustment, alarm or blocking operations based on changes in global credibility; perform baseline adaptive updates through periodic iteration or emergency iteration.

2. The zero-trust core control method based on user behavior and OSI seven-layer authentication as described in claim 1, characterized in that, The control method further includes: after handling the abnormal terminal, the central control node issues a handling result instruction, the instruction including: If the alert is determined to be a false alarm, the quarantine will be lifted and the trust level will be reset. If it is determined to be a real attack, then isolation will be maintained.

3. The zero-trust core control method based on user behavior and OSI seven-layer authentication as described in claim 1, characterized in that, In step S1, the collected OSI seven-layer state vectors and user behavior vectors include: Collect physical media type, hardware device fingerprint, and device specification compliance vector data at the physical layer; Collect data frame format, MAC address binding relationship, link encryption status, and MAC address change trajectory vector data at the data link layer; Collect source IP address, destination IP address, routing hop count mutation information, IP geolocation, and gateway access frequency vector data at the network layer; Collect vector data on TCP / UDP connection establishment frequency, connection rate fluctuations, port usage compliance, and data transmission volume at the transport layer; Collect session establishment process, session timeout, session reconnection count, and session associated terminal identifier vector data at the session layer; Collect the data encoding format, data compression algorithm, encryption key negotiation process, and data verification result vector data of the presentation layer; Collect API call frequency, API parameter compliance, application permission usage trajectory, and application log exception code vector data at the application layer; Collect user data including mouse / keyboard operation frequency, operation interval, access time, single access duration, high-frequency operation period, permission call order, frequency of sensitive permission usage, and permission request rationality.

4. The zero-trust core control method based on user behavior and OSI seven-layer authentication as described in claim 1, characterized in that, In step S2, the normalization formula used by the Min-Max normalization algorithm is: ; Where X is the original value of a feature term in the OSI seven-layer state vector or user behavior vector, Xmin and Xmax are the minimum and maximum values ​​in the data set of all original values ​​belonging to the same feature term as X, respectively; X* is the value of the normalized original value mapped to the interval [0, 1].

5. The zero-trust core control method based on user behavior and OSI seven-layer authentication as described in claim 1, characterized in that, In step S4, the algorithm for calculating single-layer similarity and global credibility is as follows: Single-layer similarity: ; Global trustworthiness: Reli Global = ; Where n is the total number of feature vectors collected in each layer; Let i be the i-th eigenvector; The baseline of the i-th eigenvector; The baseline range of the i-th feature vector; Let be the weight of the i-th eigenvector, and satisfy . ; W represents the single-layer similarity for each layer. k Let be the weight coefficients for each layer, and let the weight coefficients satisfy . =1.

6. The zero-trust core control method based on user behavior and OSI seven-layer authentication as described in claim 1, characterized in that, In step S5, the method for assigning permissions based on trust level includes the following steps: When the trust level is ≥X1, it is judged as high trust, and the user is granted full business permissions of the role to which he belongs, allowing access to all authorized resources; When X2 ≤ Trustworthiness < X1, it is determined to be medium trust, and only basic business functions are open, while access to core databases and sensitive APIs is restricted; When X3 ≤ Trustworthiness < X2, it is judged as low trust, the current session is frozen and reported to the central control node; When 0 ≤ Trustworthiness < X3, it is judged as extremely low trust. The edge control agent directly blocks terminal access, isolates and reports to the central control node. Among them, X1, X2, and X3 are preset values.

7. The zero-trust core control method based on user behavior and OSI seven-layer authentication as described in claim 1, characterized in that, The method for adaptive baseline updates through periodic iterations or emergency iterations is as follows: The system triggers regular iterations at preset times each day, adjusting the baseline threshold based on the newly added vector data from the previous day, with the adjustment range not exceeding 5%. Emergency iteration is triggered when the proportion of newly added terminals exceeds the preset proportion, when business systems are upgraded, or when network topology changes. The new baseline is updated in real time after training is completed.

8. A zero-trust core control system based on user behavior and OSI seven-layer authentication, characterized in that: The control system is used to implement the control method according to any one of claims 1-7, and the control system includes: The objects under terminal management include core databases, core network devices, and other core terminal devices; The edge control agent is deployed at the entry point of each core business area to collect OSI seven-layer state vectors and user behavior vectors. It preprocesses the collected vectors, encodes the preprocessed vectors using the Word2Vec model, maps the vector data to the [0,1] interval using the Min-Max normalization algorithm, calculates the single-layer similarity using the weighted cosine similarity algorithm, and calculates the global credibility using weighted summation. Based on the global credibility level, it performs access authorization, permission adjustment, and anomaly blocking. The central control node is used to define trust levels and response measures. It trains a dynamic trust baseline based on historical data using the RWKV model and performs secondary analysis on low-trust and very low-trust events.

9. The zero-trust core control system based on user behavior and OSI seven-layer authentication as described in claim 8, characterized in that, The edge control agent includes: The data acquisition module is used to simultaneously acquire OSI seven-layer state vectors and user behavior vectors; The vector processing module is used to encode and perform Min-Max normalization on the acquired vectors. The trust assessment engine is used to calculate single-layer similarity using a weighted cosine similarity algorithm and to calculate global trustworthiness through weighted summation. The policy execution engine is used to perform access authorization, permission adjustment, and anomaly blocking based on the global trust level; Data caching and synchronization agent, which is used to cache local data and synchronize incremental data to the central control node.

10. The zero-trust core control system based on user behavior and OSI seven-layer authentication as described in claim 8, characterized in that, The central control node includes: The Trust Policy module is used to define trust levels and corresponding actions. The baseline training module is used to train a dynamic trustworthy baseline based on historical data using the RWKV model; the high-risk assessment module is used to perform secondary assessments based on the trust level. The data auditing module is used to store full network vector data, trust assessment logs, and anomaly handling records; The joint response module is used to formulate joint response strategies and distribute them to edge control agents for execution.

Citation Information

Patent Citations

  • Zero-trust API gateway dynamic trust evaluation and access control method and system based on machine learning

    CN114465807A

  • Zero-trust security access system based on random forest positioning method

    CN120546929A

  • Identity verification platform

    US20210204116A1

  • Methods for Zero Trust Security with High Quality of Service

    US20210266346A1

  • Dynamic authentication attack detection and enforcement at network, application, and host level

    WO2024263817A1