Access control method and device, equipment and medium

By identifying multi-dimensional contextual information of terminals and determining risk values, the risk score of access requests is dynamically evaluated, solving the problems of flexibility and accuracy in 5G private network access control and improving the security and flexibility of 5G private networks.

CN121334682APending Publication Date: 2026-01-13CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511506232.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-10-21
Publication Date
2026-01-13

AI Technical Summary

Technical Problem

Existing 5G private network access control methods lack flexibility and accuracy, failing to meet security requirements in complex and dynamic environments.

Method used

By identifying multi-dimensional contextual information of the terminal, the risk value determination model dynamically assesses the risk score of the access request, and performs precise control based on the risk score and pre-configured prevention and control strategies, including secondary authentication and recording access results to optimize the scoring rules.

Benefits of technology

It achieves dynamic, fine-grained, and precise security protection for 5G private network access requests, improving the system's flexibility and controllability, and ensuring security and user experience in complex environments.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121334682A_ABST
    Figure CN121334682A_ABST
Patent Text Reader

Abstract

The invention provides an access control method and device, equipment and a medium, which are used for flexibly and accurately controlling an access request in a 5G private network. In the method, after an access request of a terminal is received, fine-grained multi-dimensional context information related to the access request is identified, and a risk score of the access request is comprehensively determined in combination with multi-dimensional information such as a terminal identity, an equipment state, an access position, a network environment, a user behavior and a resource attribute and a risk value determination model; a target prevention and control strategy suitable for the access request is determined according to the risk score of the access request and the pre-configured corresponding relation between the risk threshold interval and the prevention and control strategy, and the access request is managed and controlled according to the target prevention and control strategy. The access request in the 5G private network is flexibly and accurately managed and controlled, and the security, flexibility and accurate controllability of the 5G private network in a complex and dynamic access environment are guaranteed.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of network security technology, and in particular to an access control method, apparatus, device, and medium. Background Technology

[0002] 5G private networks are the deep integration and application of 5G technology in vertical industries. Relying on the core characteristics of 5G such as high speed, low latency, and high reliability, they provide customized dedicated communication networks for industries such as industry, energy, healthcare, and transportation, meeting the personalized needs of enterprises for data security, business flexibility, and efficiency improvement.

[0003] Currently, access control for access traffic (access requests) in 5G private networks typically employs traditional, static strategies such as IP whitelists. For example, if the IP address involved in the access request is on a pre-configured IP whitelist, access is allowed; otherwise, it is blocked. While simple, this approach lacks flexibility and precision, failing to meet the specific needs of 5G private networks. Therefore, a technical solution that can flexibly and accurately control access requests in 5G private networks is urgently needed. Summary of the Invention

[0004] This application provides an access control method, apparatus, device, and medium for flexibly and accurately controlling access requests in a 5G private network.

[0005] Firstly, this application provides an access control method, the method comprising: The system receives an access request from a terminal and identifies the context information involved in the access request. The context information includes at least one of the following: terminal identity, device status, access location, network environment, user behavior, and resource attributes. Based on the context information and the pre-trained risk value determination model, the risk score of the access request is determined. Based on the risk score, the pre-configured risk threshold range, and the correspondence between prevention and control strategies, the target prevention and control strategy corresponding to the risk threshold range to which the risk score belongs is determined; and the access request is controlled according to the target prevention and control strategy.

[0006] In one possible implementation, determining the risk score of the access request based on the context information and a pre-trained risk value determination model includes: Based on the scoring rules for each preset dimension, the sub-score values ​​of the context information in each preset dimension are determined; Based on the configured weights of the access requests in each preset dimension and each sub-score, a weighted vector for the access requests is obtained. The weighted vector is input into the risk value determination model, and the risk score of the access request is determined based on the output of the risk value determination model.

[0007] In one possible implementation, the weight of the access request in each preset dimension is configured, including: Obtain the context information of the terminal that triggered the access request within the set time window; For each preset dimension, the weight of the access request in that preset dimension is configured based on the context information of that preset dimension within the time window.

[0008] In one possible implementation, the method further includes: If the control result of the access request is to allow it, then record the access result of the access request; Based on the access results, the scoring rules are optimized.

[0009] In one possible implementation, the process of training the risk value determination model includes: Obtain the weighted vector of any sample in the sample set, and the sample weighted vector corresponds to the sample risk score; The risk score of the sample weighted vector is determined by using the risk value to be trained to determine the model. The risk value determination model is trained based on the sample risk score and the identified risk score.

[0010] In one possible implementation, the risk threshold range is related to the business information involved in the access request; and / or, The prevention and control strategy is related to the business information involved in the access request.

[0011] In one possible implementation, the access request is controlled according to the target prevention and control strategy, including: If the target prevention and control strategy is to perform secondary authentication, then the corresponding input box for secondary authentication will be displayed; The secondary authentication result is determined based on the input information received in the input box and the preset reference information; If the secondary authentication result is successful, the access request is allowed; otherwise, the access request is blocked.

[0012] Secondly, this application provides an access control device, the device comprising: The receiving module is used to receive access requests from terminals and identify the context information involved in the access requests. The context information includes at least one of terminal identity, device status, access location, network environment, user behavior, and resource attributes. The determination module is used to determine the risk score of the access request based on the context information and a pre-trained risk value determination model. The control module is used to determine the target control strategy corresponding to the risk threshold range to which the risk score belongs, based on the risk score, the pre-configured risk threshold range and the correspondence between control strategies, and to control the access request according to the target control strategy.

[0013] In one possible implementation, the determining module is specifically used for: Based on the scoring rules for each preset dimension, the sub-score values ​​of the context information in each preset dimension are determined; Based on the configured weights of the access requests in each preset dimension and each sub-score, a weighted vector for the access requests is obtained. The weighted vector is input into the risk value determination model, and the risk score of the access request is determined based on the output of the risk value determination model.

[0014] In one possible implementation, the determining module is specifically used for: Obtain the context information of the terminal that triggered the access request within the set time window; For each preset dimension, the weight of the access request in that preset dimension is configured based on the context information of that preset dimension within the time window.

[0015] In one possible implementation, the control module is further configured to: If the control result of the access request is to allow it, then record the access result of the access request; Based on the access results, the scoring rules are optimized.

[0016] In one possible implementation, the device further includes: The training module is used to obtain the weighted vector of any sample in the sample set, and the weighted vector corresponds to a sample risk score; determine the identification risk score of the weighted vector of the sample through the risk value determination model to be trained; and train the risk value determination model according to the sample risk score and the identification risk score.

[0017] In one possible implementation, the risk threshold range is related to the business information involved in the access request; and / or, The prevention and control strategy is related to the business information involved in the access request.

[0018] In one possible implementation, the control module is specifically used for: If the target prevention and control strategy is to perform secondary authentication, then the corresponding input box for secondary authentication will be displayed; The secondary authentication result is determined based on the input information received in the input box and the preset reference information; If the secondary authentication result is successful, the access request is allowed; otherwise, the access request is blocked.

[0019] Thirdly, this application provides an electronic device comprising at least a processor and a memory, wherein the processor is configured to execute a computer program stored in the memory to implement the steps of any of the methods described in the first aspect.

[0020] Fourthly, this application provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the steps of any of the methods described in the first aspect.

[0021] Fifthly, this application provides a computer program product comprising: computer program code, which, when run on a computer, causes the computer to perform the steps of any of the methods described in the first aspect.

[0022] In this embodiment, after receiving an access request from a terminal, the system can identify the fine-grained, multi-dimensional contextual information involved in the access request. Combining this with multi-dimensional information such as terminal identity, device status, access location, network environment, user behavior, and resource attributes, as well as a risk value determination model, a comprehensive risk score for the access request is determined. Then, based on the risk score of the access request, the correspondence between the pre-configured risk threshold range and the control strategy, a suitable target control strategy for the access request can be determined. According to the target control strategy, the access request is controlled. Based on this, dynamic, fine-grained, precise, and adaptive security protection can flexibly and accurately control access requests in the 5G private network, ensuring the security, flexibility, and precise controllability of the 5G private network in complex and dynamic access environments. Attached Figure Description

[0023] To more clearly illustrate the implementation methods in the embodiments of this application or related technologies, the accompanying drawings used in the description of the embodiments or related technologies will be briefly introduced below. Obviously, the accompanying drawings described below are some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings.

[0024] Figure 1This application provides a schematic diagram of a first access control process according to some embodiments; Figure 2 This application illustrates a second access control process provided by some embodiments; Figure 3 The diagram shows an access control device according to some embodiments of this application; Figure 4 The diagram shows a schematic representation of an electronic device structure provided in some embodiments of this application. Detailed Implementation

[0025] To make the objectives, technical solutions, and advantages of this application clearer, a further detailed description of this application will be provided below with reference to the accompanying drawings. Obviously, the embodiments described in this application are merely some embodiments, not all embodiments. Based on the embodiments in this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0026] It should be noted that the brief descriptions of terms in this application are only for the convenience of understanding the embodiments described below, and are not intended to limit the embodiments of this application. Unless otherwise stated, these terms should be understood in their ordinary and common meaning.

[0027] The terms "first," "second," "third," etc., used in the specification, claims, and accompanying drawings of this application are used to distinguish similar or related objects or entities, and do not necessarily imply a specific order or sequence, unless otherwise specified. It should be understood that such terms are interchangeable where appropriate.

[0028] The terms “comprising” and “having”, and any variations thereof, are intended to cover but not exclude inclusion, for example, a product or device that includes a range of components is not necessarily limited to all of the components that are clearly listed, but may include other components that are not clearly listed or that are inherent to such product or device.

[0029] The term "module" refers to any known or subsequently developed hardware, software, firmware, artificial intelligence, fuzzy logic, or combination of hardware and / or software code that is capable of performing the functions associated with that element.

[0030] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some or all of the technical features therein. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the scope of the technical solutions of the embodiments of this application.

[0031] To flexibly and accurately control access requests, this application provides an access control method, apparatus, device, and medium.

[0032] Example 1: Figure 1 The diagram illustrates a first access control process provided by some embodiments of this application, such as... Figure 1 As shown, the process includes the following steps: S101: Receive an access request from a terminal, identify the context information involved in the access request, and the context information includes at least one of terminal identity, device status, access location, network environment, user behavior, resource attributes, and historical access information.

[0033] The access control method provided in this application is applied to electronic devices, such as personal computers (PCs), mobile terminals, servers, etc., and this application does not specifically limit them.

[0034] To enable flexible and precise control over access to sensitive internal resources of an enterprise after a 5G terminal connects to the 5G private network, this application embodiment can perform access control by collecting relevant multi-dimensional contextual information. Specifically, upon receiving an access request from a terminal, the system can obtain multi-dimensional contextual information related to the access request, such as the terminal's identity, device status, access location, network environment, user behavior, and resource attributes, through the data network authentication, authorization, and accounting (DN-AAA) server deployed by the enterprise.

[0035] The terminal identity may include information such as the terminal's International Mobile Subscriber Identity (IMSI) and International Mobile Equipment Identity (IMEI).

[0036] Device status can include information such as whether the terminal device is trusted (authorized) or disabled. For example, based on a pre-configured employee device whitelist, it can be identified whether the terminal device is on the whitelist. If it is, the device status can be trusted; otherwise, the device status can be disabled. Alternatively, it can also be identified based on a pre-configured employee device blacklist. If it is, the device status can be disabled; otherwise, the device status can be trusted. This application does not specifically limit this.

[0037] The access location can be the location of the base station of the 5G terminal's data network (DN).

[0038] The network environment can include network performance information such as current network latency and bandwidth.

[0039] User behavior can include information about the applications a user accesses and the operations performed on those applications, such as whether the user downloads sensitive data, modifies core data, or frequently logs into applications they do not have permission to access.

[0040] Resource attributes can include information such as whether the resource accessed by the user is sensitive data and whether it has a configured security level.

[0041] In addition, the context information may also include access time (the time the access request was received) collected through the 5G security gateway, as well as the user's historical access behavior within the 5G private network. The context information can be within a set time window (sliding time window). The sliding time window algorithm can retain context information for a period of time (such as one day) and remove expired data. Preprocessing operations such as cleaning invalid data, cleaning duplicate data, and normalizing data can be performed on the context information to integrate it into a unified format; these will not be elaborated further here.

[0042] S102: Based on the context information and the pre-trained risk value determination model, determine the risk score of the access request.

[0043] In one possible implementation, the sub-scores of context information in each preset dimension can be determined based on the scoring rules of each preset dimension. Then, the sub-scores of each preset dimension can be weighted and summed (concatenated) according to the weight of the currently configured access request in each preset dimension and the sub-scores of context information in each preset dimension to obtain a weighted vector of the access request. Finally, the weighted vector can be input into a pre-trained risk value determination model, and the risk score of the access request can be determined according to the output of the risk value determination model.

[0044] The following section describes the process of determining the sub-score values ​​for context information on each preset dimension based on the scoring rules for each preset dimension. This can be achieved by assigning a higher score value to a higher level of risk, and vice versa. Alternatively, a lower score value may indicate a higher level of risk, and vice versa. For ease of understanding, the following explanation uses the example of a higher score value indicating a higher level of risk and a lower score value indicating a lower level of risk to illustrate the access control process provided in this application.

[0045] For example, regarding the device status dimension, when the device status is trusted, the risk of this dimension is considered relatively low, and the sub-score value of this dimension can be lower. Conversely, when the device status is disabled, the risk of this dimension is considered relatively high, and this dimension can be used as a penalty item, with the sub-score value configured to a higher value. The specific score can be flexibly set according to needs, and this application does not impose specific limitations on it.

[0046] Regarding the access location dimension, the risk level is considered relatively low if the base station at the access location is on a pre-configured whitelist, or if the access location is closer to a pre-defined location, such as a corporate campus. In this case, the sub-score for this dimension can be lower. Conversely, if the base station at the access location is not on a pre-configured whitelist, or if the access location is farther from the pre-defined corporate campus (more unfamiliar with the location), the risk level is considered relatively high. In this case, this dimension can be used as a penalty, and its sub-score can be configured to a higher value. Specific scores can be flexibly set according to requirements; this application does not impose specific limitations on this.

[0047] Regarding the network environment dimension, for example, a high network latency indicates a poor network environment. To improve the security of the access process, such as enhancing the security and accuracy of potential data transmission, this dimension can be considered relatively high-risk and can be used as a penalty, with its sub-score set to a higher value. Conversely, a good network environment indicates a relatively low-risk dimension, and its sub-score can be lower. Specific scores can be flexibly set according to requirements, and this application does not impose specific limitations on them.

[0048] Regarding the user behavior dimension, it can be based on the user's historical access behavior within a set time window. If, within the set time window, the user frequently logs into (accesses) applications they do not have permission to access, or is involved in downloading sensitive data or modifying core data, the user behavior is considered high-risk, and this dimension can be used as a penalty item, with its sub-score configured to a higher value. Conversely, the sub-score for this dimension can be lower. The specific score can be flexibly set according to needs, and this application does not impose specific limitations on it.

[0049] Regarding the resource attribute dimension, if a user accesses resources that contain sensitive data or have a high security level, the risk is considered high, and this dimension can be used as a penalty, with its sub-score set to a higher value. Conversely, the sub-score can be lower. Specific scores can be flexibly set according to needs, and this application does not impose specific limitations on them.

[0050] Additionally, if the context information includes access time, for the access time dimension, if the access time falls within a preset working period, the risk is considered low, and the sub-score value of this dimension can be lower. Conversely, if the access time falls outside a working period, the risk is considered high, and this dimension can be used as a penalty item, with the sub-score value of this dimension configured to a higher value.

[0051] The following section describes the process of determining the weight of access requests in each preset dimension.

[0052] In one possible implementation, the weight of each preset dimension can be a pre-configured, static, fixed value. The sum of the weights of all dimensions can be 1, or it can be greater than 1 or less than 1, and can be flexibly set according to requirements. This application does not impose any specific limitations on this.

[0053] To flexibly and accurately manage access requests, the weights of each preset dimension can be configured to be dynamically adjusted and optimized adaptively. Specifically, all context information related to terminals triggering access requests within a set time window can be collected. Then, for each preset dimension, the weight of the access request in that preset dimension can be configured based on the context information within the set time window (e.g., one hour). For example, for the access location dimension, if the access location of the user terminal changes continuously and significantly within the set time window, the dimension can be considered high-risk, and the weight corresponding to the access location can be configured higher (e.g., increasing the preset weight by a certain percentage). Conversely, if the access location of the user terminal does not change significantly within the set time window, the dimension can be considered low-risk, and the weight corresponding to the access location can be configured lower (e.g., decreasing the preset weight by a certain percentage).

[0054] For another example, regarding the user behavior dimension, if a user repeatedly attempts to log in to multiple applications they don't have permission to access within a set time window, or involves repeatedly downloading different sensitive data or modifying multiple core data, this user behavior is considered high-risk, and its corresponding weight can be configured higher. Conversely, if the user behavior within the set time window consists entirely of routine and normal operations, this user behavior can be considered low-risk, and its corresponding weight can be configured lower.

[0055] For another example, regarding the device status dimension, if a user considers a device status to be trustworthy throughout a set time window, then the risk of that device status is considered low, and the weight corresponding to that device status can be configured lower. Conversely, if a user considers a device status to be disabled within a set time window, then the risk of that device status is considered high, and the weight corresponding to that device status can be configured higher.

[0056] For another example, regarding the network environment dimension, if a user considers the network environment to be of low risk when it is consistently good within a set time window, then the weight corresponding to the network environment can be configured lower. Conversely, if a user considers the network environment to be of high risk when it is poor within a set time window, then the weight corresponding to it can be configured higher.

[0057] For another example, regarding the resource attribute dimension, if a user accesses a resource multiple times within a set time window that involves sensitive data, or if it is configured with a high security level, then the risk of this dimension is considered high, and the weight corresponding to the resource attribute can be configured to be higher. Conversely, the weight of this dimension can be configured to be lower.

[0058] For another example, regarding the access time dimension, if all access times within the time window are during working hours, the risk of this dimension is considered low, and the weight corresponding to the access time can be configured to be lower. Conversely, if the access time within the time window is repeatedly located outside of working hours, the risk of this dimension is considered high, and the weight corresponding to the access time can be configured to be higher.

[0059] Once the weights of each preset dimension in this configuration are obtained, the sub-scores of each preset dimension can be weighted and summed (concatenated) according to the weights of each preset dimension in the current configuration and the context information of the access request, to obtain the weighted vector of the access request. Then, the weighted vector can be input into a pre-trained risk value determination model. Based on the output of the risk value determination model, the risk score of the access request can be obtained. This risk score can also be called a dynamic trust value. For example, the risk score is a value between 0 and 100, but this application does not specifically limit it.

[0060] In one possible implementation, the risk value determination model can be based on the random forest algorithm, using the voting results of multiple decision trees to determine the final risk score (risk level), which will not be elaborated further here. The training process of the risk value determination model is described below. The sample set contains multiple sample weighted vectors, each of which can correspond to a label representing the sample's risk score. When training the risk value determination model, any sample weighted vector can be obtained from the sample set and input into the risk value determination model to be trained. Through the trained risk value determination model, the identification risk score of that sample weighted vector is obtained.

[0061] In practice, after determining the identification risk score of the input sample weighted vector, since the sample risk score of the sample weighted vector is pre-saved, the accuracy of the risk value determination model's identification result can be determined by whether the sample risk score matches the identification risk score. If they do not match, it indicates that the identification result of the risk value determination model is inaccurate, and the parameters of the risk value determination model need to be adjusted to train the model.

[0062] In practice, when adjusting the parameters in the risk value determination model, the gradient descent algorithm can be used to backpropagate the gradient of the parameters of the risk value determination model, thereby training the risk value determination model.

[0063] In one possible implementation, the above operation can be performed on each sample weight vector in the sample set, and when the preset convergence condition is met, the risk value is determined to indicate that the model training is complete.

[0064] The preset convergence conditions can include the risk value determining the model from the sample weighted vectors in the sample set, the number of correctly identified sample weighted vectors being greater than a set number, or the number of iterations for training the risk value determining model reaching the set maximum number of iterations. These conditions can be flexibly set in practice and are not specifically limited here.

[0065] In one possible implementation, when training the risk value determination model, the sample weighting vectors in the sample set can be divided into training sample weighting vectors and test sample weighting vectors. The risk value determination model is first trained based on the training sample weighting vectors, and then the reliability of the trained risk value determination model is verified based on the test sample weighting vectors. This will not be elaborated further here.

[0066] S103: Based on the risk score, the pre-configured risk threshold range and the correspondence between prevention and control strategies, determine the target prevention and control strategy corresponding to the risk threshold range to which the risk score belongs; and control the access request according to the target prevention and control strategy.

[0067] In one possible implementation, a personalized security policy can be configured for each service. For example, the applicable risk threshold range and corresponding prevention and control policy for each service can be dynamically configured (adjusted) based on service information such as whether the service is sensitive or frequently accessed. For instance, assuming that for a certain service, the pre-configured initial risk threshold ranges can include three risk threshold ranges: [90, 100], [50, 90], and [0, 50). When the risk score of an access request is in the range [90, 100], it can be considered high risk, and the prevention and control policy can be direct denial of access. When the risk score of an access request is in the range [50, 90), it can be considered medium risk, and the prevention and control policy can be triggering two-factor authentication. When the risk score of an access request is in the range [0, 50), it can be considered low risk, and the prevention and control policy can be allowing normal access.

[0068] Of course, a higher risk score indicates lower risk. For example, an access request with a risk score in the range of [90, 100] is considered low risk, and the control strategy can be to allow normal access. An access request with a risk score in the range of [50, 90) is considered medium risk, and the control strategy can be to trigger two-factor authentication. An access request with a risk score in the range of [0, 50) is considered high risk, and the control strategy is to directly deny access.

[0069] When adjusting risk threshold ranges and corresponding prevention and control strategies based on business information, for example, if a business is frequently accessed or its sensitivity increases, and a higher risk score indicates lower risk, the risk threshold range for low-risk levels can be adjusted to [95, 100]. If the risk score of a business access request is within [95, 100], it is considered low-risk, and the prevention and control strategy is to allow normal access. The risk threshold range for medium-risk levels can be adjusted to [50, 95). If the risk score of a business access request is within [50, 95), it is considered medium-risk, and the prevention and control strategy can be to trigger secondary authentication. Further details are omitted here.

[0070] In one possible implementation, if the target security strategy involves secondary authentication, a corresponding input field for secondary authentication can be displayed. This could be a username / password input field, or a verification code input field, etc., and this application does not specifically limit this. The system can receive and recognize the information entered by the user in the input field, and compare the user's input with preset reference information (such as a correct username, password, or verification code). If the user's input matches the reference information, the secondary authentication is considered successful, and the access request can be allowed. If the user's input does not match the reference information, the secondary authentication is considered unsuccessful, and the access request can be blocked, denying access.

[0071] In one possible implementation, if the final control strategy (control result) for the access request is to allow it, user access to the corresponding service can be permitted based on user role permissions and the principle of least privilege (i.e., users can only obtain the minimum permissions allowed). During the user's access to the corresponding service, some user access behaviors (access results) can be recorded, such as whether they involve downloading sensitive data or modifying core data, which are considered high-risk behaviors. Subsequently, the scoring rules for each dimension can be optimized and updated based on the access results of this access request, so as to enable more flexible and accurate access control in the future. For example, taking the higher the risk score as a sign of higher risk, for the dimension of access location, machine learning models can be used to analyze whether the "access location" is in an unfamiliar area. If the sub-score of this dimension is high, resulting in a high final risk score and triggering secondary authentication, and if the pass rate of secondary authentication is high, and the access behavior within the set time window does not involve any high-risk operations and no corresponding security events occur, then the scoring rules for this dimension can be optimized to appropriately reduce the sub-score when the access location is in an unfamiliar area (reduce the triggering condition of this strategy), and vice versa. This will not be elaborated further here. Alternatively, the access result can be used as information in historical user behavior to determine the risk score of the user's subsequent access requests, which will not be elaborated on here.

[0072] To facilitate understanding, the access control process provided in this application will be explained and illustrated below through a specific embodiment. (See reference...) Figure 2 The process includes the following steps: S201: Receive an access request initiated by the terminal.

[0073] S202: Collect multi-dimensional contextual information involved in the access request. The contextual information includes at least one of the following: terminal identity, device status, access location, network environment, user behavior, and resource attributes.

[0074] S203: Determine the risk score of the access request based on contextual information and the risk value determination model.

[0075] S204: Based on the risk score of the access request, the pre-configured risk threshold range, and the correspondence between prevention and control strategies, dynamically and flexibly determine the target prevention and control strategy corresponding to the risk threshold range to which the risk score belongs. Control the access request according to the target prevention and control strategy.

[0076] S205: If the final control result is to allow the access request, continuously monitor the user's corresponding access behavior and determine whether there are any preset abnormal access behaviors; if so, block the access and trigger a warning. If there are no preset abnormal access behaviors, record the access result, and optimize and update the corresponding scoring rules based on the access result.

[0077] In one possible implementation, the electronic device may include a context information acquisition module, a dynamic trust assessment module, a policy decision module, and a policy execution module. The context information acquisition module can collect multi-dimensional context information related to the access request. The dynamic trust assessment module calculates the risk score of the access request based on the context information, a rule engine (scoring rules), and a machine learning model (risk value determination model). The policy decision module determines the target prevention and control strategy based on the risk score, the correspondence between pre-configured risk threshold ranges and prevention and control strategies. The final decision on whether to allow or block the access request can be generated by the policy decision module, which then sends the final decision to the policy execution module. The policy execution module can be deployed on a 5G security gateway, and it performs corresponding control operations such as allowing access, denying access, rate limiting, and redirection based on the final decision result. Specifically, the policy execution module receives structured policy instructions (final decisions) from the policy decision module, parses the instruction's meaning, and verifies its legality to avoid execution failure due to instruction errors. It can also identify abnormal situations during execution, collect feedback information on the execution results, and return the execution results to the policy decision module.

[0078] This application enables real-time adjustments to control policies through dynamic trust assessment of each access request, resulting in enhanced dynamic adaptability. Simultaneously, dynamic control policies improve user experience while ensuring security, resolving the conflict between "security and efficiency." By obtaining execution results and feeding them back into the logic of control decision optimization, a closed loop is formed, leading to more comprehensive control and continuously improving the accuracy of access control.

[0079] To facilitate understanding, the access control process of this application will be explained below through a specific embodiment. For example, an employee frequently accesses sensitive data, accessing the core system 5 times within 1 hour. Assuming the risk score of their access request is 65 points, a medium-risk level, after triggering secondary authentication, the secondary authentication result is successful. The policy decision module issues a decision to the policy execution module to allow access but restrict data export permissions. The policy execution module grants the access request access to the core system, but restricts its data export permissions, disallowing the operation of exporting data.

[0080] For example, if employee C accesses the system remotely using a registered terminal device, the context acquisition module will find that the access location is unfamiliar and abnormal access behavior occurs within a set time window. The dynamic trust assessment module will then determine the risk score (trust value) to be 40 points, which is a high-risk level. The policy decision module will generate a decision to deny access to the core system, and the policy execution module will directly deny access and report it to the corresponding security center. This will not be elaborated further here.

[0081] In this embodiment, after receiving an access request from a terminal, the system can identify the fine-grained, multi-dimensional contextual information involved in the access request. Combining this with multi-dimensional information such as terminal identity, device status, access location, network environment, user behavior, and resource attributes, as well as a risk value determination model, a comprehensive risk score for the access request is determined. Then, based on the risk score of the access request, the correspondence between the pre-configured risk threshold range and the control strategy, a suitable target control strategy for the access request can be determined. According to the target control strategy, the access request is controlled. Based on this, dynamic, fine-grained, precise, and adaptive security protection can flexibly and accurately control access requests in the 5G private network, ensuring the security, flexibility, and precise controllability of the 5G private network in complex and dynamic access environments.

[0082] Example 2: Based on the same technical concept, this application provides an access control device, see reference. Figure 3 The device includes: The receiving module 301 is used to receive an access request from a terminal and identify the context information involved in the access request. The context information includes at least one of terminal identity, device status, access location, network environment, user behavior, and resource attributes. The determination module 302 is used to determine the risk score of the access request based on the context information and the pre-trained risk value determination model. The control module 303 is used to determine the target control strategy corresponding to the risk threshold range to which the risk score belongs based on the risk score, the correspondence between the pre-configured risk threshold range and the control strategy; and to control the access request according to the target control strategy.

[0083] In one possible implementation, the determining module 302 is specifically used for: Based on the scoring rules for each preset dimension, the sub-score values ​​of the context information in each preset dimension are determined; Based on the configured weights of the access requests in each preset dimension and each sub-score, a weighted vector for the access requests is obtained. The weighted vector is input into the risk value determination model, and the risk score of the access request is determined based on the output of the risk value determination model.

[0084] In one possible implementation, the determining module 302 is specifically used for: Obtain the context information of the terminal that triggered the access request within the set time window; For each preset dimension, the weight of the access request in that preset dimension is configured based on the context information of that preset dimension within the time window.

[0085] In one possible implementation, the control module 303 is further configured to: If the control result of the access request is to allow it, then record the access result of the access request; Based on the access results, the scoring rules are optimized.

[0086] In one possible implementation, the device further includes: The training module 304 is used to obtain the weighted vector of any sample in the sample set, the weighted vector of the sample corresponding to a sample risk score; determine the identification risk score of the weighted vector of the sample through the risk value determination model to be trained; and train the risk value determination model according to the sample risk score and the identification risk score.

[0087] In one possible implementation, the risk threshold range is related to the business information involved in the access request; and / or, The prevention and control strategy is related to the business information involved in the access request.

[0088] In one possible implementation, the control module 302 is specifically used for: If the target prevention and control strategy is to perform secondary authentication, then the corresponding input box for secondary authentication will be displayed; The secondary authentication result is determined based on the input information received in the input box and the preset reference information; If the secondary authentication result is successful, the access request is allowed; otherwise, the access request is blocked.

[0089] Example 3: Based on the same technical concept, this application also provides an electronic device. Figure 4 The present application provides schematic diagrams of the structure of an electronic device according to some embodiments, such as... Figure 4 As shown, the electronic device includes: a processor 401, a communication interface 402, a memory 403, and a communication bus 404, wherein the processor 401, the communication interface 402, and the memory 403 communicate with each other through the communication bus 404. The memory 403 stores a computer program, which, when executed by the processor 401, causes the processor 401 to perform the following steps: The system receives an access request from a terminal and identifies the context information involved in the access request. The context information includes at least one of the following: terminal identity, device status, access location, network environment, user behavior, and resource attributes. Based on the context information and the pre-trained risk value determination model, the risk score of the access request is determined. Based on the risk score, the pre-configured risk threshold range, and the correspondence between prevention and control strategies, the target prevention and control strategy corresponding to the risk threshold range to which the risk score belongs is determined; and the access request is controlled according to the target prevention and control strategy.

[0090] In one possible implementation, the processor 401 is specifically used for: Based on the scoring rules for each preset dimension, the sub-score values ​​of the context information in each preset dimension are determined; Based on the configured weights of the access requests in each preset dimension and each sub-score, a weighted vector for the access requests is obtained. The weighted vector is input into the risk value determination model, and the risk score of the access request is determined based on the output of the risk value determination model.

[0091] In one possible implementation, the processor 401 is specifically used for: Obtain the context information of the terminal that triggered the access request within the set time window; For each preset dimension, the weight of the access request in that preset dimension is configured based on the context information of that preset dimension within the time window.

[0092] In one possible implementation, the processor 401 is further configured to: If the control result of the access request is to allow it, then record the access result of the access request; Based on the access results, the scoring rules are optimized.

[0093] In one possible implementation, the processor 401 is further configured to: Obtain any sample weighted vector in the sample set, and the sample weighted vector corresponds to a sample risk score; determine the identification risk score of the sample weighted vector through the risk value determination model to be trained; train the risk value determination model based on the sample risk score and the identification risk score.

[0094] In one possible implementation, the risk threshold range is related to the business information involved in the access request; and / or, The prevention and control strategy is related to the business information involved in the access request.

[0095] In one possible implementation, the processor 401 is specifically used for: If the target prevention and control strategy is to perform secondary authentication, then the corresponding input box for secondary authentication will be displayed; The secondary authentication result is determined based on the input information received in the input box and the preset reference information; If the secondary authentication result is successful, the access request is allowed; otherwise, the access request is blocked.

[0096] The memory may include random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device. Optionally, the memory may also be at least one storage device located remotely from the aforementioned processor.

[0097] The processors mentioned above can be general-purpose processors, including central processing units, network processors (NPs), etc.; they can also be digital signal processors (DSPs), application-specific integrated circuits, field-programmable gate arrays or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc.

[0098] Example 4: Based on the same technical concept, embodiments of this application provide a computer-readable storage medium storing a computer program executable by an electronic device. When the program is run on the electronic device, the electronic device performs the following steps: The system receives an access request from a terminal and identifies the context information involved in the access request. The context information includes at least one of the following: terminal identity, device status, access location, network environment, user behavior, and resource attributes. Based on the context information and the pre-trained risk value determination model, the risk score of the access request is determined. Based on the risk score, the pre-configured risk threshold range, and the correspondence between prevention and control strategies, the target prevention and control strategy corresponding to the risk threshold range to which the risk score belongs is determined; and the access request is controlled according to the target prevention and control strategy.

[0099] In one possible implementation, determining the risk score of the access request based on the context information and a pre-trained risk value determination model includes: Based on the scoring rules for each preset dimension, the sub-score values ​​of the context information in each preset dimension are determined; Based on the configured weights of the access requests in each preset dimension and each sub-score, a weighted vector for the access requests is obtained. The weighted vector is input into the risk value determination model, and the risk score of the access request is determined based on the output of the risk value determination model.

[0100] In one possible implementation, the weight of the access request in each preset dimension is configured, including: Obtain the context information of the terminal that triggered the access request within the set time window; For each preset dimension, the weight of the access request in that preset dimension is configured based on the context information of that preset dimension within the time window.

[0101] In one possible implementation, the method further includes: If the control result of the access request is to allow it, then record the access result of the access request; Based on the access results, the scoring rules are optimized.

[0102] In one possible implementation, the process of training the risk value determination model includes: Obtain the weighted vector of any sample in the sample set, and the sample weighted vector corresponds to the sample risk score; The risk score of the sample weighted vector is determined by using the risk value to be trained to determine the model. The risk value determination model is trained based on the sample risk score and the identified risk score.

[0103] In one possible implementation, the risk threshold range is related to the business information involved in the access request; and / or, The prevention and control strategy is related to the business information involved in the access request.

[0104] In one possible implementation, the access request is controlled according to the target prevention and control strategy, including: If the target prevention and control strategy is to perform secondary authentication, then the corresponding input box for secondary authentication will be displayed; The secondary authentication result is determined based on the input information received in the input box and the preset reference information; If the secondary authentication result is successful, the access request is allowed; otherwise, the access request is blocked.

[0105] The aforementioned computer-readable storage medium can be any available medium or data storage device that can be accessed by the processor in an electronic device, including but not limited to magnetic storage such as floppy disks, hard disks, magnetic tapes, magneto-optical disks (MO), optical storage such as CDs, DVDs, BDs, HVDs, etc., and semiconductor storage such as ROMs, EPROMs, EEPROMs, non-volatile memory (NAND flash), solid-state drives (SSDs), etc.

[0106] Based on the same technical concept, this application provides a computer program product, which includes computer program code. When the computer program code is run on a computer, it causes the computer to implement the method described in any of the above-described method embodiments applied to electronic devices, which will not be repeated here.

[0107] In the above embodiments, implementation can be achieved, in whole or in part, through software, hardware, firmware, or any combination thereof, or in whole or in part, as a computer program product. The computer program product includes one or more computer instructions, which, when loaded and executed on a computer, generate, in whole or in part, the processes or functions described in the embodiments of this application.

[0108] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0109] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to this application. It should be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0110] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0111] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0112] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. An access control method, characterized in that, The method includes: The system receives an access request from a terminal and identifies the context information involved in the access request. The context information includes at least one of the following: terminal identity, device status, access location, network environment, user behavior, and resource attributes. Based on the context information and the pre-trained risk value determination model, the risk score of the access request is determined. Based on the risk score, the pre-configured risk threshold range, and the correspondence between prevention and control strategies, the target prevention and control strategy corresponding to the risk threshold range to which the risk score belongs is determined; and the access request is controlled according to the target prevention and control strategy.

2. The method according to claim 1, characterized in that, The process of determining the risk score of the access request based on the context information and a pre-trained risk value determination model includes: Based on the scoring rules for each preset dimension, the sub-score values ​​of the context information in each preset dimension are determined; Based on the configured weights of the access requests in each preset dimension and each sub-score, a weighted vector for the access requests is obtained. The weighted vector is input into the risk value determination model, and the risk score of the access request is determined based on the output of the risk value determination model.

3. The method according to claim 2, characterized in that, Configure the weight of the access request in each preset dimension, including: Obtain the context information of the terminal that triggered the access request within the set time window; For each preset dimension, the weight of the access request in that preset dimension is configured based on the context information of that preset dimension within the time window.

4. The method according to claim 2, characterized in that, The method further includes: If the control result of the access request is to allow it, then record the access result of the access request; Based on the access results, the scoring rules are optimized.

5. The method according to claim 2, characterized in that, The process of training the risk value determination model includes: Obtain the weighted vector of any sample in the sample set, and the sample weighted vector corresponds to the sample risk score; The risk score of the sample weighted vector is determined by using the risk value to be trained to determine the model. The risk value determination model is trained based on the sample risk score and the identified risk score.

6. The method according to claim 1, characterized in that, The risk threshold range is related to the business information involved in the access request; and / or, The prevention and control strategy is related to the business information involved in the access request.

7. The method according to claim 1, characterized in that, According to the target prevention and control strategy, the access requests are controlled, including: If the target prevention and control strategy is to perform secondary authentication, then the corresponding input box for secondary authentication will be displayed; The secondary authentication result is determined based on the input information received in the input box and the preset reference information; If the secondary authentication result is successful, the access request is allowed; otherwise, the access request is blocked.

8. An access control device, characterized in that, The device includes: The receiving module is used to receive access requests from terminals and identify the context information involved in the access requests. The context information includes at least one of terminal identity, device status, access location, network environment, user behavior, and resource attributes. The determination module is used to determine the risk score of the access request based on the context information and a pre-trained risk value determination model. The control module is used to determine the target control strategy corresponding to the risk threshold range to which the risk score belongs, based on the risk score, the pre-configured risk threshold range and the correspondence between control strategies, and to control the access request according to the target control strategy.

9. An electronic device, characterized in that, The electronic device includes at least a processor and a memory, the processor being configured to implement the steps of the method as described in any one of claims 1-7 when executing a computer program stored in the memory.

10. A computer-readable storage medium, characterized in that, It stores a computer program that, when executed by a processor, implements the steps of the method as described in any one of claims 1-7.