Internet of Things access control method and device, equipment, storage medium and product
By obtaining network bandwidth requirements and indirect trust evidence data from IoT terminals to calculate scores, and combining this with direct trust evidence data to make network access decisions, the security assessment problem during IoT terminal access is solved, achieving effective network security protection and accurate identification of potential threats.
Patent Information
- Application Number
- CN202511832052.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-05
- Publication Date
- 2026-02-10
AI Technical Summary
Existing technologies cannot effectively assess the reliability of IoT terminals when they are connected, resulting in weak security protection capabilities and risks of privacy leaks and cyberattacks.
By acquiring the network bandwidth requirements and indirect trust evidence data of the terminals to be connected, an indirect trust score is calculated, and combined with direct trust evidence data, a network access decision is made to avoid terminals that exceed the network's carrying capacity and to identify potentially insecure terminals.
It effectively prevents bandwidth overload and network congestion, ensures network security, accurately identifies potentially insecure terminals, and avoids security impacts.
Smart Images

Figure CN121509053A_ABST
Abstract
Description
Technical Field
[0001] This application belongs to the field of Internet of Things (IoT) technology, and in particular relates to an IoT access control method, device, equipment, storage medium, and product. Background Technology
[0002] With the rapid development of Internet of Things (IoT) technology, various physical devices are constantly being connected to the Internet, forming intelligent applications covering multiple key areas such as transportation, healthcare, industrial automation, and emergency response. These IoT terminals collect key information such as situational awareness data and environmental measurement data, providing core contextual support for various scenario-based applications, significantly improving production efficiency and convenience in daily life.
[0003] However, as the scale of IoT device access continues to expand, some terminals have weak security protection capabilities and imperfect identity authentication mechanisms. A large number of smart IoT devices with weak security protection capabilities are exposed to the network, increasing not only the risk of privacy leaks but also the risk of various cyberattacks.
[0004] Therefore, ensuring that the access of terminal devices does not have a security impact on the network in a complex Internet of Things (IoT) environment has become an urgent technical problem to be solved. Summary of the Invention
[0005] This application provides an Internet of Things (IoT) access control method, apparatus, device, storage medium, and product, which can determine the terminal before it accesses the network, thus preventing the terminal from causing security impacts on the network after it accesses the network.
[0006] In a first aspect, embodiments of this application provide an Internet of Things (IoT) access control method, the method comprising: In response to an access request initiated by a terminal to be accessed, obtain the network bandwidth requirements of the terminal to be accessed; When the network bandwidth requirement meets the network bandwidth threshold, obtain indirect trust evidence data of the terminal to be accessed. The indirect trust evidence data includes at least one of performance characteristic behavior data, reliability characteristic behavior data, and security characteristic behavior data. Calculate the indirect trust score of the terminal to be accessed based on indirect trust evidence data; Network access decisions are made based on indirect trust scoring for access requests.
[0007] In one feasible implementation, the method further includes: The indirect trust evidence data is constructed into an indirect trust evidence data matrix. Each row of the indirect trust evidence data matrix represents a type of indirect trust evidence data, and each column represents evidence data within a collection period. Compare any two rows of the indirect trust evidence data matrix, score them according to the size of the evidence data, and obtain the initial judgment matrix; Add the elements of each row in the initial judgment matrix to obtain the row sum of the initial judgment matrix. Based on the row sum of the initial judgment matrix and the total number of rows in the initial judgment matrix, convert the initial judgment matrix into a fuzzy uniform matrix. Add the elements of each row in the fuzzy uniformization matrix to obtain the row sum of the fuzzy uniformization matrix. Based on the row sum of the fuzzy uniformization matrix and the total number of rows in the fuzzy uniformization matrix, convert the fuzzy uniformization matrix into a weight matrix. Based on the weight matrix and the indirect trust evidence data matrix, the indirect trust score of the terminal to be accessed is calculated.
[0008] In one feasible implementation, the method further includes: Obtain the historical indirect trust score of the terminal to be accessed; the historical indirect trust score is calculated based on the indirect trust evidence data collected within the historical period; The total indirect trust score of the terminal to be accessed is calculated based on the historical indirect trust score, the indirect trust score, and the first-time attenuation weight.
[0009] In one feasible implementation, the method further includes: Obtain direct trust evidence data from the terminal to be connected. Direct trust evidence data is a service quality evaluation of the direct interaction between the terminal to be connected and the target resource node in the Internet of Things. Based on the interval between the time of each interaction and the current time, a second time decay weight is assigned to each direct trust evidence data, wherein the interval is inversely proportional to the second time decay weight; The trust level is calculated based on the second time decay weight and direct trust evidence data. The trust score of the terminal to be accessed is obtained by fitting the trust level based on the probability distribution model. The total trust score is calculated based on the direct trust score, indirect trust score, and trust score weights, and the network access decision is made based on the total trust score.
[0010] In one feasible implementation, the method further includes: When the network bandwidth requirement does not meet the network bandwidth threshold, obtain the network bandwidth corresponding to the currently connected IoT terminals; Based on the network bandwidth requirements and the network bandwidth corresponding to the currently connected IoT terminals, calculate the mathematical expectation of the total utility of the IoT. Obtain the expected cost of the currently connected IoT terminals and the expected cost of the terminals to be connected, and calculate the expected total cost of the IoT. Calculate the truncated bandwidth based on the expected total utility and the expected total cost. The network access decision is made based on the truncation bandwidth and network bandwidth threshold.
[0011] In one feasible implementation, the method further includes: Obtain the identifier and matching attribute information of the terminal to be accessed, and obtain the target attribute information from the pre-configured policy information based on the identifier; When the attribute information to be matched and the target attribute information match, the step of obtaining the indirect trust evidence value of the terminal to be accessed is executed; If the attribute information to be matched and the target attribute information do not match, the access request initiated by the terminal to be accessed will be rejected.
[0012] Secondly, embodiments of this application provide an Internet of Things (IoT) access control device, the device comprising: The first acquisition module is used to respond to the access request initiated by the terminal to be accessed and acquire the network bandwidth requirements of the terminal to be accessed. The second acquisition module is used to acquire indirect trust evidence data of the terminal to be accessed when the network bandwidth requirement meets the network bandwidth threshold. The indirect trust evidence data includes at least one of performance characteristic behavior data, reliability characteristic behavior data, and security characteristic behavior data. The calculation module is used to calculate the indirect trust score of the terminal to be accessed based on indirect trust evidence data; The processing module is used to make network access decisions based on indirect trust scores for access requests.
[0013] Thirdly, embodiments of this application provide an electronic device, the device including: a processor, and a memory storing computer program instructions; A processor reads and executes computer program instructions to implement an Internet of Things access control method that achieves any one of the first aspects.
[0014] Fourthly, embodiments of this application provide a computer-readable storage medium storing computer program instructions, which, when executed by a processor, implement an Internet of Things access control method as described in any of the first aspects.
[0015] Fifthly, embodiments of this application provide a computer program product in which instructions, when executed by the processor of an electronic device, cause the electronic device to perform an Internet of Things access control method as described in the first aspect.
[0016] The IoT access control method, apparatus, device, storage medium, and product provided in this application can determine whether the network bandwidth requirement of the terminal to be accessed meets the network bandwidth threshold. If the network bandwidth threshold is not met, the access request initiated by the terminal to be accessed is directly rejected. Therefore, it can prevent the access of terminals that exceed the network carrying capacity from the source, effectively preventing problems in the network environment for terminal security verification caused by bandwidth overload and network congestion due to unrestrained access, which would prevent the terminal from being securely authenticated. When the network bandwidth threshold is met, indirect trust evidence data of the terminal to be accessed is further obtained, and an indirect trust score of the terminal to be accessed is calculated based on the indirect trust evidence data. The access request is then used to make a network access decision based on the indirect trust score. In this way, even when facing a terminal accessing for the first time, an accurate security judgment can be made based on its behavior in other network environments, effectively identifying potentially insecure terminals and preventing the terminal from causing security impact on the network after accessing the network. Attached Figure Description
[0017] To more clearly illustrate the technical solutions of the embodiments of this application, the accompanying drawings used in the embodiments of this application will be briefly introduced below. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0018] Figure 1 A flowchart illustrating an Internet of Things (IoT) access control method according to an embodiment of this application is shown. Figure 2 A flowchart illustrating an IoT access control method according to another embodiment of this application is shown; Figure 3 A flowchart illustrating an IoT access control method according to another embodiment of this application is shown; Figure 4 A flowchart illustrating an IoT access control method according to another embodiment of this application is shown; Figure 5 A schematic diagram of an Internet of Things (IoT) access control process is shown. Figure 6 An XACML format is shown; Figure 7 A schematic diagram of an Internet of Things (IoT) access control process is shown. Figure 8 This application provides a schematic diagram of the structure of an Internet of Things access control device. Figure 9 A schematic diagram of the hardware structure of the electronic device provided in an embodiment of this application is shown. Detailed Implementation
[0019] The features and exemplary embodiments of various aspects of this application will be described in detail below. To make the objectives, technical solutions, and advantages of this application clearer, the application will be further described in detail below with reference to the accompanying drawings and specific embodiments. It should be understood that the specific embodiments described herein are only intended to explain this application and not to limit it. For those skilled in the art, this application can be implemented without some of these specific details. The following description of the embodiments is merely to provide a better understanding of this application by illustrating examples.
[0020] It should be noted that, in this document, relational terms such as "first" and "second" are used merely to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising..." does not exclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.
[0021] It should be noted that the acquisition, storage, use, and processing of data in this application embodiment all comply with the relevant provisions of national laws and regulations.
[0022] It should be noted that in the embodiments of this application, certain software, components, models and other existing solutions in the industry may be mentioned. These should be regarded as exemplary and are only intended to illustrate the feasibility of implementing the technical solution of this application. However, it does not mean that the applicant has used or necessarily used the solution.
[0023] Currently, existing technologies for connecting IoT terminals primarily rely on initially assigning permissions to the device, which remain valid indefinitely as long as the device's identity remains unchanged. However, this method cannot assess the terminal's reliability. Even if the terminal is maliciously compromised, exhibits abnormal behavior, or consistently provides low-quality service, it can still access the network, compromising network security.
[0024] To address the problems of existing technologies, embodiments of this application provide an IoT access control method, apparatus, device, storage medium, and product. By determining whether the network bandwidth requirement of the terminal to be accessed meets the network bandwidth threshold, if the network bandwidth threshold is not met, the access request initiated by the terminal to be accessed is directly rejected. Therefore, it can prevent the access of terminals that exceed the network carrying capacity from the source, effectively preventing problems with the network environment for terminal security verification caused by bandwidth overload and network congestion due to unrestrained access, thus preventing the terminal's security authentication from being impossible. When the network bandwidth threshold is met, indirect trust evidence data of the terminal to be accessed is further obtained, and an indirect trust score of the terminal to be accessed is calculated based on the indirect trust evidence data. The access request is then used to make a network access decision based on the indirect trust score. In this way, even when facing a terminal accessing the network for the first time, an accurate security judgment can be made based on its behavior in other network environments, effectively identifying potentially insecure terminals and preventing the terminal from causing security impacts on the network after accessing the network.
[0025] The following section first introduces an IoT access control method provided in an embodiment of this application.
[0026] Figure 1 This illustration shows a flowchart of an Internet of Things (IoT) access control method according to one embodiment of this application. Figure 1 As shown, the method may include the following steps: S101: In response to an access request initiated by the terminal to be accessed, obtain the network bandwidth requirements of the terminal to be accessed.
[0027] In this embodiment, the access authentication request issued by the embedded IoT terminal is mainly implemented through an authentication network deployed on a cloud computing platform. Therefore, the quality of the authentication network directly affects the efficiency and security of terminal access. Insufficient network bandwidth resources will not only reduce the terminal access efficiency but also disrupt the stable communication environment required for terminal security authentication, leading to authentication timeouts or interruptions, and ultimately preventing the terminal from being securely authenticated. The network bandwidth requirement of the terminal to be accessed is the network transmission rate required by the terminal to complete the expected business.
[0028] In one example, when initiating an access request, the terminal can proactively declare its required bandwidth value or bandwidth level through protocol extension fields. Alternatively, it can query a pre-configured bandwidth database based on the terminal identifier or type to determine the network bandwidth required by the terminal.
[0029] S102: When the network bandwidth requirement meets the network bandwidth threshold, obtain indirect trust evidence data of the terminal to be accessed. The indirect trust evidence data includes at least one of performance characteristic behavior data, reliability characteristic behavior data, and security characteristic behavior data.
[0030] In this embodiment, indirect trust evidence data refers to behavioral data generated by the terminal to be accessed in its historical network communications. Indirect trust evidence data objectively reflects the terminal's behavioral characteristics and trustworthiness in past operations. By analyzing indirect trust evidence data, a trust profile of the terminal can be constructed, providing data analysis basis for access control decisions.
[0031] Furthermore, when the terminal to be connected lacks a direct interaction history with the target resource node, its reliability cannot be assessed based on direct behavioral records. In such cases, by analyzing indirect trust evidence data, the current trust status of the terminal can still be inferred even in the absence of direct trust evidence.
[0032] In one example, indirect trust evidence data includes at least one of performance characteristic behavior data, reliability characteristic behavior data, and security characteristic behavior data.
[0033] The performance characteristic behavior data includes at least one of the following: terminal central processing unit (CPU) utilization, terminal throughput, terminal IP (Internet Protocol) packet transmission delay, IP packet jitter time, IP packet network bandwidth utilization, and IP packet response time.
[0034] Reliability behavior data includes at least one of the following: terminal retransmission rate, terminal IP packet loss rate, connection establishment success rate, and connection establishment latency.
[0035] Security feature behavior data includes at least one of the following: number of unauthorized connections by the terminal, number of times the terminal scans important ports, number of times the terminal attempts to exceed permissions, and number of times the terminal fails to connect.
[0036] In one example, indirect trust evidence data can be at least one of the following: the average value of performance characteristic behavior data over a preset time period, the average value of reliability characteristic behavior data over a preset time period, and the average value of security characteristic behavior data over a preset time period.
[0037] In another example, indirect trust evidence data for the initial terminal can be obtained through network traffic monitoring tools, specialized data collection tools, or data collection tools developed on demand.
[0038] In one example, indirect trust evidence data for the terminal to be connected is only obtained when the network bandwidth requirement of the terminal to be connected is less than or equal to the maximum bandwidth capacity of the embedded IoT server, and greater than or equal to the minimum bandwidth capacity of the embedded IoT server. (1) in, ; This indicates the minimum bandwidth capacity of the embedded IoT server; This indicates the network bandwidth requirement corresponding to terminal i to be connected.
[0039] In another example, when assessing bandwidth requirements, not only the terminal's own bandwidth requirements are considered. Simultaneously, it calculates the total network bandwidth requirement and the total bandwidth already used in the network. If the total bandwidth requirement exceeds the network capacity threshold, the access request is rejected to prevent network overload when multiple devices access the network concurrently, ensuring overall network stability.
[0040] In one example, when the network bandwidth requirement does not meet the network bandwidth threshold, it also includes: Obtain the network bandwidth corresponding to the currently connected IoT terminals.
[0041] In this embodiment, if the original bandwidth requirement of the terminal to be accessed does not meet the preset network bandwidth threshold, directly rejecting access would prevent the reasonable access requirements of the terminal's services from being flexibly responded to, resulting in the network resource utilization efficiency failing to reach its optimal state. To ensure the maximization of the overall benefits of network resources, this application achieves more refined resource management by calculating and truncating bandwidth.
[0042] In one example, a traffic monitoring tool deployed at network nodes can be used to collect real-time data on the network bandwidth currently used by each connected terminal.
[0043] Based on the network bandwidth requirements and the network bandwidth corresponding to the currently connected IoT terminals, calculate the expected total utility of the IoT.
[0044] In this embodiment, based on the network bandwidth requirements and the network bandwidth corresponding to the currently connected IoT terminals, the utility function for each terminal can be calculated first: ,in This represents the server bandwidth acquired by the terminal during the access period. The utility function reflects the urgency of the terminal's bandwidth demand, thus allowing us to calculate the expected total utility of the Internet of Things (IoT) during the access process. (2) in, Represents the expected total utility; i represents the terminal number; Represents the utility function; This represents the access success rate of the i-th terminal under bandwidth B; This represents the resource utilization coefficient of the i-th terminal under bandwidth B; This represents the bandwidth of the i-th terminal.
[0045] Obtain the expected cost of the currently connected IoT terminals and the expected cost of the terminals to be connected, and calculate the expected total cost of the IoT.
[0046] In this embodiment of the application, the expected total overhead is the estimated total resource consumption required by the server to support network operation after the terminal to be connected is connected, including the original expected overhead of the connected terminal and the expected additional overhead of the terminal to be connected.
[0047] In one example, the original expected overhead can be calculated based on the bandwidth usage and data processing volume of the connected terminals.
[0048] In another example, the expected additional overhead can be estimated based on the bandwidth requirements and business complexity of the terminal to be connected.
[0049] Calculate the truncated bandwidth based on the expected total utility and the expected total cost. In this embodiment of the application, the expected service quality of the network is first calculated based on the expected total utility and the expected total cost: (3) in, This represents the mathematical expectation of service quality. This represents the expected value of total utility. This represents the mathematical expectation of the total cost.
[0050] The calculation process of the truncated bandwidth can be transformed into a constrained optimization problem, that is, under the constraints of formula (1), find a network bandwidth that maximizes the mathematical expectation of the quality of service, where the bandwidth that maximizes the mathematical expectation of the quality of service is the truncated bandwidth.
[0051] The network access decision is made based on the truncation bandwidth and network bandwidth threshold.
[0052] In this embodiment of the application, the calculated truncation bandwidth may not meet the constraints of formula (1). In other words, formula (3) has no solution under the constraints of formula (1). At this time, it is necessary to judge the truncation bandwidth and the network bandwidth threshold. If the truncation bandwidth meets the network bandwidth threshold, the access request of the terminal is agreed and the truncation bandwidth is allocated to it. If the truncation bandwidth does not meet the network bandwidth threshold, the access request of the terminal is rejected.
[0053] In this embodiment of the application, for scenarios where the original bandwidth requirement does not meet the threshold, this application obtains the network bandwidth corresponding to the currently connected IoT terminal, calculates the expected total utility of the IoT based on the network bandwidth requirement and the network bandwidth corresponding to the currently connected IoT terminal, and calculates the truncation bandwidth based on the expected total utility and the expected total cost. This avoids directly rejecting terminal access when the original bandwidth requirement does not meet the threshold, thereby improving the efficiency of network resource utilization.
[0054] S103: Calculate the indirect trust score of the terminal to be accessed based on indirect trust evidence data.
[0055] In this embodiment, the indirect trust score is a quantitative processing result of indirect trust evidence data. The higher the score, the higher the credibility of the terminal's historical behavior. The original indirect trust evidence data is fragmented and inconsistent in scale, making it unsuitable for direct decision-making. Furthermore, the indirect trust evidence data may be incomplete. Calculating the indirect trust score of the terminal to be connected based on the indirect trust evidence data can transform the messy indirect trust evidence data into a single indirect trust score, enabling subsequent network access decisions to be made quickly based on the score.
[0056] S104: Make network access decisions based on indirect trust scoring for access requests.
[0057] In this embodiment of the application, the access request is made into a network access decision based on the indirect trust score. In one example, an indirect trust score threshold can be set. When the indirect trust score of the terminal to be accessed is greater than or equal to the indirect trust score threshold, the access request is approved and network resources are allocated. When the indirect trust score is less than the indirect trust score threshold, the access request is rejected.
[0058] In one example, the indirect trust scoring threshold can be dynamically adjusted based on the resource access level. For instance, the indirect trust scoring threshold when the data accessed by the terminal is core business data needs to be higher than the indirect trust scoring threshold when the terminal accesses ordinary sensor data.
[0059] In another example, the indirect trust score threshold can be dynamically adjusted based on the current network environment. If the current network is detected to be in an active period of attack, the indirect trust score threshold can be automatically increased.
[0060] In this embodiment, the system first determines whether the network bandwidth requirement of the terminal to be accessed meets the network bandwidth threshold. If the network bandwidth threshold is not met, the access request initiated by the terminal to be accessed is directly rejected. Therefore, it can prevent terminals that exceed the network carrying capacity from accessing the network from the source, effectively preventing problems in the network environment for terminal security verification caused by bandwidth overload and network congestion due to unrestrained access, thus preventing the terminal from being securely authenticated. If the network bandwidth threshold is met, the system further obtains indirect trust evidence data of the terminal to be accessed, and calculates the indirect trust score of the terminal to be accessed based on the indirect trust evidence data. The system then makes a network access decision based on the indirect trust score. In this way, even when facing a terminal accessing the network for the first time, it can make an accurate security judgment based on its behavior in other network environments, effectively identify potentially insecure terminals, and prevent the terminal from causing security impact on the network after accessing the network.
[0061] Figure 2 A flowchart illustrating an IoT access control method according to another embodiment of this application is shown. Figure 2 As shown above, in the above Figure 1 Based on the illustrated embodiment, one specific implementation of step S103 is as follows: S201: Construct the indirect trust evidence data into an indirect trust evidence data matrix. Each row of the indirect trust evidence data matrix represents a type of indirect trust evidence data, and each column represents evidence data within a collection period.
[0062] In this embodiment of the application, the indirect trust evidence data involves multiple types and multiple collection periods. The scattered data is not conducive to subsequent weight calculation and scoring calculation. By organizing the data into a matrix, the indirect trust evidence data is constructed into an indirect trust evidence data matrix.
[0063] In one example, the indirect trust evidence data matrix is represented as follows: Where E represents the indirect trust evidence data matrix, Let represent the indirect trust evidence data of the i-th type corresponding to the j-th collection period, where n represents the number of indirect trust evidence data types and m represents the number of collection periods.
[0064] In one example, due to different device launch times or abnormal data collection, some indirect trust evidence data may be missing in certain collection periods. To ensure the integrity of the matrix structure, the system uses one of the following methods to complete the data: zero-padding, assigning a value of 0 to missing data; or statistical padding, using the mode or average of the indirect trust evidence data type within the available period.
[0065] In one example, since different types of indirect trust evidence have different dimensions and numerical ranges, in order to eliminate the impact of dimensional differences on subsequent calculations and to make various types of evidence data comparable, all indirect trust evidence data need to be normalized to the interval [0, 1]. The normalization method is as follows: (4) in, This represents the indirect trust evidence data corresponding to the j-th collection period of the i-th type of normalized indirect trust evidence data. This represents the indirect trust evidence data corresponding to the j-th collection period for the i-th type of indirect trust evidence data; This represents the minimum value of this type of indirect trust evidence data across all collection periods; This indicates the maximum value of this type of indirect trust evidence data across all collection periods.
[0066] Therefore, the standardized indirect trust evidence data matrix is as follows: .
[0067] S202: Compare any two rows of the indirect trust evidence data matrix, score them according to the size of the evidence data, and obtain the initial judgment matrix.
[0068] In this embodiment, different types of indirect trust evidence data have varying degrees of impact on terminal credibility. Therefore, pairwise comparisons are needed to determine the relative importance of each type, providing a basis for weight allocation. The initial judgment matrix is a scoring matrix reflecting the relative importance of different types of indirect trust evidence. This initial judgment matrix is obtained by comparing any two rows of the indirect trust evidence data matrix and scoring them according to the size of the evidence data. .
[0069] In one example, when assigning a size rating, a 1-9 scale can be used, where 1 represents equal importance and 9 represents extreme importance. Alternatively, when assigning a size rating, if two pieces of indirect credible evidence are equal, a value of 0.5 is assigned; if indirect credible evidence i is greater than indirect credible evidence j, a value of 1 is assigned; otherwise, a value of 0 is assigned.
[0070] In one example, the scoring can be determined based on the difference, by calculating the proportion of the difference between two rows of data in different collection periods. The larger the difference, the higher the importance score. Alternatively, it can be determined based on the quantity, by counting the number of periods in which one row of data is better than another row of data in multiple collection periods. The higher the proportion of advantageous periods, the higher the importance score.
[0071] To clearly illustrate how this application obtains the initial judgment matrix, a specific example will be used below. For instance, the indirect trust evidence data matrix contains three types of indirect trust evidence data and standardized data from three collection periods. The indirect trust evidence data matrix is as follows: Here, a scoring technique based on quantity is used for explanation. If the indirect trust evidence data for each period in the first row is greater than that in each period in the second row, then it can be scored 9. If the indirect trust evidence data for only two periods in the first row is greater than that in the third row, then it can be scored 7. Comparing the second and third rows, the second row also has two periods where the indirect trust evidence data is greater than that in the third row, so it can be scored 7. Furthermore, considering the reciprocity principle, if the first row scores 9 compared to the second row, then the second row scores 9 compared to the first row. If the score of the first row compared to the third row is 7, then the score of the third row compared to the first row is 1 / 7. Similarly, if the score of the second row compared to the third row is 7, then the score of the third row compared to the second row is 1 / 7. Therefore, the initial judgment matrix is: S203: Add the elements of each row in the initial judgment matrix to obtain the row sum of the initial judgment matrix. Based on the row sum of the initial judgment matrix and the total number of rows in the initial judgment matrix, convert the initial judgment matrix into a fuzzy uniform matrix.
[0072] In this embodiment, the initial judgment matrix may contain logical contradictions. For example, the importance of indirect trust evidence type A may be greater than that of indirect trust evidence type B, and the importance of indirect trust evidence type B may be greater than that of indirect trust evidence type C. However, ultimately, the importance of indirect trust evidence type C may be greater than that of indirect trust evidence type A. This situation may occur because the data collected within a certain period fluctuates, leading to data anomalies and thus logical contradictions.
[0073] In one example, the fuzzy consistency matrix is the matrix after logical consistency correction, where the formula for calculating the fuzzy consistency matrix based on the initial judgment matrix is: (5) in, This represents the row sum of the i-th row in the initial judgment matrix; This represents the score of the i-th type of indirect trust evidence data in the initial judgment matrix compared to the j-th type of indirect trust evidence data; n represents the total number of indirect trust evidence data types.
[0074] (6) in, This represents the score of the i-th indirect trust evidence data type in the fuzzy consistency matrix compared to the j-th indirect trust evidence data type. This represents the row sum of the i-th row in the initial judgment matrix; This represents the row sum and value of the j-th row in the initial judgment matrix; n represents the total number of indirect trust evidence types.
[0075] Therefore, the fuzzy uniformity matrix .
[0076] S204: Add the elements of each row in the fuzzy uniformization matrix to obtain the row sum of the fuzzy uniformization matrix. Based on the row sum of the fuzzy uniformization matrix and the total number of rows in the fuzzy uniformization matrix, convert the fuzzy uniformization matrix into a weight matrix.
[0077] In this embodiment, the weight matrix is a matrix containing weight coefficients for each type of evidence. Each row corresponds to the weight of a type of evidence, representing the proportion of that type's contribution to the indirect trust score. Since the fuzzy consistency matrix reflects the relative importance of each type of indirect trust evidence data, it needs to be further converted into weight coefficients before it can be used for the weighted calculation of the indirect trust score. The weight matrix... The calculation formula is: (7) in, This represents the weight corresponding to the i-th type of indirect trust evidence data; This represents the score of the i-th indirect trust evidence data type in the fuzzy consistency matrix compared to the j-th indirect trust evidence data type; n represents the total number of indirect trust evidence data types.
[0078] S205: Based on the weight matrix and the indirect trust evidence data matrix, calculate the indirect trust score of the terminal to be accessed.
[0079] In this embodiment of the application, the weight matrix clarifies the contribution ratio of the indirect trust evidence data type, and the indirect trust evidence data matrix provides the original behavioral data. By using the weight matrix and the indirect trust evidence data matrix, the indirect trust score of the terminal to be accessed can be obtained.
[0080] In one example, the formula for calculating indirect trust score is: (8) Where F represents the indirect trust score; E represents the indirect trust evidence data matrix; and W represents the weight matrix.
[0081] In one example, the indirect trust score calculated above represents the indirect trust score corresponding to multiple data collection periods. To further improve the accuracy of the indirect trust score, weights can be assigned to different data collection periods to convert the indirect trust scores corresponding to multiple data collection periods into a total indirect trust score for the terminal. The calculation formula is as follows: (9) in, This represents the total indirect trust score of the terminal to be accessed; This represents the indirect trust score corresponding to the j-th collection period; This represents the weight corresponding to the t-th collection period.
[0082] If the indirect trust evidence data is a negative indicator, it can be converted into a positive score where the larger the value, the more credible it is through semantic transformation. For example, subtract the calculated indirect trust score from 1.
[0083] In this embodiment, indirect trust evidence data is constructed into an indirect trust evidence data matrix. Then, any two rows in the indirect trust evidence data matrix are compared, and scores are assigned according to the size of the evidence data to obtain an initial judgment matrix. The relative importance is determined by directly comparing the numerical characteristics of various types of evidence data, so that the weight allocation is based on objective behavioral data, avoiding subjective bias caused by directly determining the weights. Subsequently, through fuzzy consistency transformation processing, possible logical contradictions in the initial judgment matrix are effectively eliminated. Finally, the weight matrix calculated based on the fuzzy consistency matrix can reflect the importance differences of different types of indirect evidence, so that the final indirect trust score can comprehensively and accurately reflect the credibility of the terminal device.
[0084] In one example, to accurately determine the trustworthiness of the terminal, the following is also included: Obtain the historical indirect trust score of the terminal to be accessed; the historical indirect trust score is calculated based on the indirect trust evidence data collected within the historical period.
[0085] In this embodiment, the score is calculated based solely on indirect trust evidence data for the current period. This may be subject to bias due to the randomness of data in a single period, such as network fluctuations causing performance data anomalies. Historical indirect trust scores are calculated based on indirect trust evidence data collected within historical periods. In one example, the historical indirect trust score for each historical period can be calculated using the method described above.
[0086] In one example, after each indirect trust score is calculated, the indirect trust score can be stored in the trust score database according to historical periods.
[0087] The total indirect trust score of the terminal to be accessed is calculated based on the historical indirect trust score, the indirect trust score, and the first-time attenuation weight.
[0088] In this embodiment, recent historical scores reflect the current trust status of the terminal better than long-term scores. As time increases, the trust score becomes less and less trustworthy. The first time decay weight is a coefficient that decreases as the time interval increases. By allocating the first time decay weight, the total indirect trust score can be made to better match the current state of the terminal.
[0089] In one example, the formula for calculating the total indirect trust score is: (10) in, This represents the total indirect trust score; This indicates the weight that decays immediately upon application. Indicates historical indirect trust score; Indicates indirect trust rating; This indicates the sequence number of the current evaluation period.
[0090] In this embodiment of the application, in order to avoid the deviation of indirect trust score assessment caused by the fluctuation of a single behavior, the historical indirect trust score of the terminal to be accessed is obtained, and then the total indirect trust score of the terminal to be accessed is calculated based on the historical indirect trust score, the indirect trust score and the first time decay weight. This ensures that the latest indirect trust evidence data has a key impact on the assessment result, while retaining the indirect trust evidence data as an important reference, thereby improving the accuracy of trust assessment.
[0091] Figure 3 A flowchart illustrating an IoT access control method according to another embodiment of this application is shown. Figure 3 As shown above, in the above Figure 1 Based on the illustrated embodiment, after the network bandwidth requirement meets the network bandwidth threshold, the following is also included: S301: Obtain direct trust evidence data of the terminal to be connected. Direct trust evidence data is a service quality evaluation of the direct interaction between the terminal to be connected and the target resource node in the Internet of Things.
[0092] In this embodiment of the application, the terminal that is not accessing the Internet of Things for the first time has direct interaction records with the target resource node. These records can directly reflect the actual trust performance of the terminal, which can supplement the deficiencies of indirect trust scoring and make the evaluation more comprehensive.
[0093] In one example, direct trust evidence data is a service quality evaluation of the direct interaction between the terminal to be connected and target resource nodes in the Internet of Things (IoT), such as core servers or database nodes. This service quality evaluation can be classified as successful, failed, high-quality, or low-quality interaction. In one example, high-quality or low-quality interaction can be determined by data transmission accuracy.
[0094] S302: Based on the interval between the time of each interaction and the current time, assign a second time decay weight to each direct trust evidence data, wherein the interval is inversely proportional to the second time decay weight.
[0095] In this embodiment, recent direct interaction records are better able to reflect the current service quality level of the terminal than distant records. Based on the interval between the time of each interaction and the current time, a second time decay weight is assigned to each direct trust evidence data to avoid the impact of outdated distant data on the accuracy of the score.
[0096] In one example, the formula for calculating the second time decay weight is: (11) in, This represents the second time decay weight corresponding to the xth direct trust evidence data; Indicates the current time; This indicates the collection time corresponding to the xth direct trust evidence data; This represents the time decay factor.
[0097] S303: Calculate the confidence level based on the second time decay weight and direct trust evidence data.
[0098] In this embodiment of the application, the trust level is the quantitative result of direct trust evidence data after being weighted by a second time decay weight, reflecting the trust level of direct interaction between terminals.
[0099] In one example, by assigning a value of 1 to direct trust evidence data for successful or high-quality interactions and a value of 0 to direct trust evidence data for failed or low-quality interactions, the trust level of successful or high-quality interactions can be calculated as follows: (12) in, This indicates the level of trust in a successful or high-quality interaction. This represents the second time decay weight corresponding to the xth direct trust evidence data; Let x represent the x-th piece of directly trusted evidence; k represents the number of pieces of directly trusted evidence.
[0100] The trust level for failed or low-quality interactions is: (13) in, This indicates the level of trust in a failed or low-quality interaction. This represents the second time decay weight corresponding to the xth direct trust evidence data; Let x represent the x-th piece of directly trusted evidence; k represents the number of pieces of directly trusted evidence.
[0101] S304: The trust level is fitted based on the probability distribution model to obtain the direct trust score of the terminal to be accessed.
[0102] In this embodiment, the trust level only reflects the credibility proportion of historical direct interactions. A probability distribution model is needed to predict the credibility probability of future interactions by the terminal, making the score more valuable for decision-making. In one example, the trust level can be fitted using a Beta probability distribution model. The direct trust score is the mathematical expectation of the Beta distribution, ranging from [0,1], representing the credibility probability of successful future direct interactions by the terminal.
[0103] In one example, the formula for fitting trust level based on the Beta probability distribution model is: (14) in, Indicates device and equipment Direct trust score at the current time t; Represents the mathematical expectation; Indicates A Beta distribution with parameters; This indicates the level of trust in a failed or low-quality interaction. This indicates the level of trust in a successful or high-quality interaction.
[0104] S305: Calculate the total trust score based on the direct trust score, indirect trust score, and trust score weights, and make network access decisions based on the total trust score for access requests.
[0105] In this embodiment, the direct trust score reflects the trustworthiness of direct terminal interactions, while the indirect trust score reflects the trustworthiness of historical behavior. The fusion of these two scores comprehensively assesses the terminal's trustworthiness and improves the accuracy of network access decisions. The proportions of the direct and indirect trust scores can be adjusted by establishing trust score weights.
[0106] In one example, the formula for calculating the total trust score is: (15) in, This represents the overall trust score; Indicates time Indirect trust rating below; Indicates device and equipment In time Direct trust score; Indicates the weight of the trust score; the time difference benchmark for trust assessment.
[0107] In one example, a total trust score threshold can be set. If the calculated total trust score is greater than or equal to the total trust score threshold, the access request initiated by the terminal to be accessed can be approved. If the calculated total trust score is less than the total trust score threshold, the access request initiated by the terminal to be accessed can be rejected.
[0108] In this embodiment of the application, for terminals that are not accessing for the first time, direct trust evidence data of the terminal to be accessed is obtained. Direct trust evidence data originates from the actual interaction process of the terminal and has higher accuracy. This allows the direct trust score calculated based on it to more accurately reflect the real-time trust status of the terminal in the current environment. By weighted and fused with the direct trust score and the indirect trust score, the shortcomings of the indirect trust score are supplemented, and the network access decision is made based on a more comprehensive and accurate total trust score, which further improves the security of IoT access control.
[0109] Figure 4 A flowchart illustrating an IoT access control method according to another embodiment of this application is shown. Figure 4 As shown above, in the above Figure 1 Based on the illustrated embodiment, after the network bandwidth requirement meets the network bandwidth threshold, the following is also included: S401: Obtain the identifier of the terminal to be accessed and the attribute information to be matched, and obtain the target attribute information from the pre-configured policy information based on the identifier.
[0110] In this embodiment of the application, the fact that the bandwidth meets the threshold only indicates that the terminal has the resource conditions to access the network, but it cannot confirm the legitimate identity and permissions of the terminal. It is necessary to verify whether the terminal is an authorized device through attribute verification to prevent unauthorized access and affect network security.
[0111] In one example, the terminal may include the terminal identifier and the attribute information to be matched in the access request.
[0112] In another example, the pre-configured policy information base of the Policy Information Point (PIP) stores pre-configured target attribute information.
[0113] In another example, the attribute information includes at least one of the following: subject attributes, object attributes, and environment attributes. Subject attributes describe the characteristics of the terminal itself, including: device type (e.g., sensor, controller), security level, affiliated organization, role (e.g., administrator device, ordinary terminal), etc.; object attributes describe the characteristics of the accessed resource, including resource identifier, resource type (e.g., data stream, configuration interface), sensitivity level (e.g., public, confidential), etc.; environment attributes describe the context in which the access occurs, including access time, terminal geographical location, current network threat level, etc.
[0114] S402: When the attribute information to be matched and the target attribute information match, perform the step of obtaining the indirect trust evidence value of the terminal to be accessed.
[0115] In this embodiment of the application, when the attribute information to be matched and the target attribute information match, it indicates that the terminal is an authorized and legitimate device. At this time, the step of obtaining the indirect trust evidence value of the terminal to be accessed can be further executed to determine the current indirect trust score of the terminal and decide whether the terminal should join the network.
[0116] In one example, attribute matching means that the attribute information to be matched and the target attribute information meet the preset rules. For example, if it is an exact match, the attribute values must be exactly the same; if it is a fuzzy match, the matching similarity must be greater than the preset threshold.
[0117] For example, the target attribute information is: allow medical monitoring devices with a security level greater than or equal to 2 to access patient data during normal working hours.
[0118] Successful match scenario: The terminal attribute is {role: medical monitoring device, security level: 3}, the requested access is {resource: patient physiological data}, and the environmental attribute is {time: weekday 9:00}, which meets the attribute information matching conditions.
[0119] Matching failure scenario: The terminal attribute is {role: ordinary sensor, security level: 1}, the requested access is {resource: patient physiological data}, and the environmental attribute is {time: weekday 9:00}, which does not meet the attribute information matching conditions.
[0120] S403: If the attribute information to be matched and the target attribute information do not match, reject the access request initiated by the terminal to be accessed.
[0121] In this application embodiment, attribute mismatch indicates that the terminal is an unauthorized and illegal device, such as: the device type is not in the allowed list, or it accesses unauthorized resources. In this case, the access request initiated by the terminal is directly rejected to avoid bringing security risks to the network.
[0122] In another example, a mismatch between the attribute information to be matched and the target attribute information means that any attribute to be matched does not meet the preset matching rules with the target attribute, such as: the terminal type is unauthorized or the access location is outside the specified range.
[0123] In this embodiment of the application, by obtaining the identifier of the terminal to be accessed and the attribute information to be matched, and obtaining the target attribute information from the pre-configured policy information, and by determining whether the attribute information to be matched and the target attribute information match, unauthorized terminals or devices with unauthorized access rights are prevented from accessing the network and causing damage to network security.
[0124] Figure 5 A schematic diagram of an Internet of Things (IoT) access control process is shown, such as... Figure 5 As shown, when IoT terminal 51 requests access to data, its communication data is encapsulated in the standard format of extensible access control markup language (XACML). After receiving the request, policy enforcement point 52 (PEP) first interrupts the access session and forwards the request information to policy decision point 53 (PDP) for security decision-making.
[0125] The policy decision point 53 acquires multi-source data through a multi-source information acquisition process: it obtains the corresponding access control policy document from the policy library 54, where the control policy document is a set of access control rules pre-configured and uniformly managed by the policy management point 55 (PAP) and stored in the policy library 54; it obtains the target attribute information and target environmental condition information from the attribute set 57 and the environmental condition set 58, and sends them to the policy decision point 53; and it requests at least one of the indirect trust evidence data and direct trust evidence data of the terminal from the trust database 59.
[0126] Policy decision point 53 generates an access control decision based on the access control policy document, target attribute information, target environmental condition information, indirect trust evidence data, and direct trust evidence data. Finally, the access control decision result is returned to policy execution point 52. Policy execution point 52 controls whether the terminal accesses the target resource based on the access control decision result. If the request is approved, policy execution point 52 allows the terminal to access the resource. If the request is denied, policy execution point 52 will block access to the information.
[0127] XACML is an Extensible Access Control Markup Language. Figure 6 An XACML format is shown, such as Figure 6 As shown, XACML achieves fine-grained access control configuration through a hierarchy of policy sets, policies, and rules.
[0128] <policyset>A strategy set is a collection of multiple strategies used to combine access strategies for different scenarios. PolicySetID="P": A unique identifier for the policy set (ID is "P"); PolicyCombiningAlgID="Permit-Overrides": Policy combination algorithm. If any policy in the policy set results in "Permit", then the final result of the entire policy set is "Permit". <target>If empty, it means that the scope of the strategy set is defined by the sub-strategy.
[0129] <policy>A strategy is a specific access strategy within a strategy set and is a sub-unit of the strategy set. PolicyID="P1": The unique identifier of this policy (ID is "P1"); RuleCombiningAlgID="Deny-Overrides": Rule combination algorithm. If any rule in this strategy results in "Deny", then the final result of this strategy is rejection.
[0130] <rule>The representation rule is the core execution unit of the strategy, defining the specific allow or deny logic; RuleID="1": The unique identifier of this rule (ID is "1"); Effect="Permit": This rule's effect is to allow (Permit) access; <rule>Internal <target>It is the core of XACML for defining permission scope. Through the three elements of Subject, Resource, and Action, it clarifies what operations a subject can perform on what resources.
[0131] <subjects>Define the permission subject. <subject> IoT_ECG< / subject> The main entity is represented as: IoT_ECG; <subject> Nurse_1< / subject> The subject is: Nurse_1; <resources>Define the target resource. <resource> ECG_Sys< / resource> The target resource is ECG_Sys; <actions>Define the operation behavior. <action> Upload< / action> This indicates that the allowed operation is Upload.
[0132] Figure 7 A schematic diagram of an Internet of Things (IoT) access control process is shown, such as... Figure 7 As shown, S701: User requests access; S702: Determine if the bandwidth is within the range. If not, execute S714 to deny access. If within the range, execute S703 and S706 respectively; S703: Obtain the trust evidence data set; S704: Data processing; S705: Calculate the indirect trust score; S706: The request is intercepted by PED and forwarded to PDP; S707: PDP requests policy from the policy file; S708: PDP requests attributes from PIP; S709: Determine if the attribute policy matches. If not, execute S714 directly to deny access. If they match, execute S710; S710: PDP requests the indirect trust score; S711: PDP calculates the direct trust score; S712: Determine if the overall trust score is less than the threshold; S713: Grant access; S714: Deny access.
[0133] Figure 8 A schematic diagram of the structure of an Internet of Things (IoT) access control device provided in this application is shown. Figure 8 As shown, the IoT access control device 800 provided in this application includes: The first acquisition module 801 is used to obtain the network bandwidth requirements of the terminal to be accessed in response to the access request initiated by the terminal to be accessed. The second acquisition module 802 is used to acquire indirect trust evidence data of the terminal to be accessed when the network bandwidth requirement meets the network bandwidth threshold. The indirect trust evidence data includes at least one of performance characteristic behavior data, reliability characteristic behavior data and security characteristic behavior data. The calculation module 803 is used to calculate the indirect trust score of the terminal to be accessed based on indirect trust evidence data; Processing module 804 is used to make network access decisions based on indirect trust scores for access requests.
[0134] In one example, the calculation module 803 includes: The construction submodule is used to build the indirect trust evidence data into an indirect trust evidence data matrix. Each row of the indirect trust evidence data matrix represents a type of indirect trust evidence data, and each column represents the evidence data within a collection period. The comparison submodule is used to compare any two rows of the indirect trust evidence data matrix, score them according to the size of the evidence data, and obtain the initial judgment matrix. The calculation submodule is used to add the elements of each row in the initial judgment matrix to obtain the row sum of the initial judgment matrix, and convert the initial judgment matrix into a fuzzy uniform matrix according to the row sum of the initial judgment matrix and the total number of rows in the initial judgment matrix. The calculation submodule is also used to add the elements of each row in the fuzzy uniform matrix to obtain the row sum of the fuzzy uniform matrix, and convert the fuzzy uniform matrix into a weight matrix according to the row sum of the fuzzy uniform matrix and the total number of rows in the fuzzy uniform matrix. The calculation submodule is also used to calculate the indirect trust score of the terminal to be accessed based on the weight matrix and the indirect trust evidence data matrix.
[0135] In one example, the IoT access control device 800 also includes: The third acquisition module is used to acquire the historical indirect trust score of the terminal to be accessed; the historical indirect trust score is calculated based on the indirect trust evidence data collected within the historical period. The calculation module is used to calculate the total indirect trust score of the terminal to be accessed based on the historical indirect trust score, the indirect trust score, and the first-time decay weight.
[0136] In one example, the IoT access control device 800 also includes: The fourth acquisition module is used to acquire direct trust evidence data of the terminal to be accessed. Direct trust evidence data is the service quality evaluation of the direct interaction between the terminal to be accessed and the target resource node in the Internet of Things. The processing module is also used to assign a second time decay weight to each direct trust evidence data based on the interval between the time of each interaction and the current time, wherein the interval is inversely proportional to the second time decay weight; The calculation module is also used to calculate the trust level based on the second time decay weight and direct trust evidence data; The calculation module is also used to fit the trust level based on the probability distribution model to obtain the direct trust score of the terminal to be accessed. The calculation module is also used to calculate the total trust score based on the direct trust score, the indirect trust score, and the trust score weight, and to make network access decisions for access requests based on the total trust score.
[0137] In one example, the IoT access control device 800 also includes: The fifth acquisition module is used to acquire the network bandwidth corresponding to the currently connected IoT terminal when the network bandwidth requirement does not meet the network bandwidth threshold. The calculation module is also used to calculate the expected total utility of the Internet of Things (IoT) based on the network bandwidth requirements and the network bandwidth corresponding to the currently connected IoT terminals. The calculation module is also used to obtain the expected cost of the currently connected IoT terminals and the expected cost of the terminals to be connected, and to calculate the expected total cost of the IoT. The calculation module is also used to calculate the truncated bandwidth based on the mathematical expectation of total utility and the mathematical expectation of total cost; The processing module is also used to make network access decisions based on truncation bandwidth and network bandwidth thresholds for access requests.
[0138] In one example, the IoT access control device 800 also includes: The sixth acquisition module is also used to acquire the identifier of the terminal to be accessed and the attribute information to be matched, and to acquire the target attribute information from the pre-configured policy information based on the identifier; The processing module is also used to perform the step of obtaining the indirect trust evidence value of the terminal to be accessed when the attribute information to be matched and the target attribute information are matched; The processing module is also used to reject the access request initiated by the terminal to be accessed when the attribute information to be matched and the target attribute information do not match.
[0139] Figure 9 A schematic diagram of the hardware structure of the electronic device provided in an embodiment of this application is shown.
[0140] An electronic device may include a processor 901 and a memory 902 storing computer program instructions.
[0141] Specifically, the processor 901 may include a central processing unit (CPU), an application specific integrated circuit (ASIC), or one or more integrated circuits that can be configured to implement the embodiments of this application.
[0142] Memory 902 may include mass storage for data or instructions. For example, and not limitingly, memory 902 may include a hard disk drive (HDD), a floppy disk drive, flash memory, optical disk, magneto-optical disk, magnetic tape, or a Universal Serial Bus (USB) drive, or a combination of two or more of these. In one instance, memory 902 may include removable or non-removable (or fixed) media, or memory 902 may be a non-volatile solid-state memory.
[0143] In one instance, memory 902 may be read-only memory (ROM). In one instance, the ROM may be a mask-programmed ROM, a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), an electrically rewritable ROM (EAROM), or flash memory, or a combination of two or more of these.
[0144] Memory 902 may include read-only memory (ROM), random access memory (RAM), disk storage media device, optical storage media device, flash memory device, electrical, optical, or other physical / tangible memory storage device. Therefore, generally, memory includes one or more tangible (non-transitory) computer-readable storage media (e.g., memory devices) encoded with software including computer-executable instructions, and when the software is executed (e.g., by one or more processors), it is operable to perform the operations described with reference to the method according to one aspect of this disclosure.
[0145] The processor 901 implements an Internet of Things (IoT) access control method in the above-described embodiment by reading and executing computer program instructions stored in the memory 902.
[0146] In one example, the electronic device may also include a communication interface 903 and a bus 904. For example, Figure 9 As shown, the processor 901, memory 902, and communication interface 903 are connected through bus 904 and complete communication with each other.
[0147] The communication interface 903 is mainly used to realize communication between various modules, devices, units and / or equipment in the embodiments of this application.
[0148] Bus 904 includes hardware, software, or both, that couples components of an online data traffic metering device together. For example, and not as a limitation, the bus may include an Accelerated Graphics Port (AGP) or other graphics bus, an Extended Industry Standard Architecture (EISA) bus, a Front Side Bus (FSB), a Hyper Transport (HT) interconnect, an Industry Standard Architecture (ISA) bus, an Infinite Bandwidth Interconnect, a Low Pin Count (LPC) bus, a memory bus, a Microchannel Architecture (MCA) bus, a Peripheral Component Interconnect (PCI) bus, a PCI-Express (PCI-X) bus, a Serial Advanced Technology Attachment (SATA) bus, a Video Electronics Standards Association Local (VLB) bus, or other suitable buses, or combinations of two or more of these. Where appropriate, bus 904 may include one or more buses. Although specific buses are described and illustrated in embodiments of this application, this application contemplates any suitable bus or interconnect.
[0149] Furthermore, in conjunction with the IoT access control method described in the above embodiments, this application embodiment can provide a computer storage medium for implementation. The computer storage medium stores computer program instructions; when these computer program instructions are executed by a processor, they implement any of the IoT access control methods described in the above embodiments.
[0150] This application also provides a computer program product, including a computer program that, when executed by a processor, implements any of the IoT access control methods described in the above embodiments.
[0151] It should be clarified that this application is not limited to the specific configurations and processes described above and shown in the figures. For the sake of brevity, detailed descriptions of known methods are omitted here. In the above embodiments, several specific steps are described and shown as examples. However, the method process of this application is not limited to the specific steps described and shown. Those skilled in the art can make various changes, modifications, and additions, or change the order of steps, after understanding the spirit of this application.
[0152] The functional blocks shown in the above block diagram can be implemented as hardware, software, firmware, or a combination thereof. When implemented in hardware, they can be, for example, electronic circuits, application-specific integrated circuits (ASICs), appropriate firmware, plug-ins, function cards, etc. When implemented in software, the elements of this application are programs or code segments used to perform the required tasks. Programs or code segments can be stored on machine-readable media or transmitted over a transmission medium or communication link via data signals carried on a carrier wave. "Machine-readable media" can include any medium capable of storing or transmitting information. Examples of machine-readable media include electronic circuits, semiconductor memory devices, read-only memory (ROM), flash memory, erasable read-only memory (EROM), floppy disks, compact disc read-only memory (CD-ROM), optical disks, hard disks, fiber optic media, radio frequency (RF) links, etc. Code segments can be downloaded via computer networks such as the Internet, intranets, etc.
[0153] It should also be noted that the exemplary embodiments mentioned in this application describe methods or systems based on a series of steps or apparatus. However, this application is not limited to the order of the above steps; that is, the steps can be performed in the order mentioned in the embodiments, or in a different order, or several steps can be performed simultaneously.
[0154] The aspects of this disclosure have been described above with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It should be understood that each block in the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that these instructions, executable via the processor of the computer or other programmable data processing apparatus, enable the implementation of the functions / actions specified in one or more blocks of the flowchart illustrations and / or block diagrams. Such a processor can be, but is not limited to, a general-purpose processor, a special-purpose processor, a special application processor, or a field-programmable logic circuit. It is also understood that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can also be implemented by special-purpose hardware performing the specified functions or actions, or can be implemented by a combination of special-purpose hardware and computer instructions.
[0155] The above are merely specific embodiments of this application. Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of the systems, modules, and units described above can be referred to the corresponding processes in the foregoing method embodiments, and will not be repeated here. It should be understood that the protection scope of this application is not limited thereto. Any person skilled in the art can easily conceive of various equivalent modifications or substitutions within the technical scope disclosed in this application, and these modifications or substitutions should all be covered within the protection scope of this application.< / actions> < / resources> < / subjects> < / target> < / rule> < / rule> < / policy> < / target> < / policyset>
Claims
1. An Internet of Things (IoT) access control method, characterized in that: In response to an access request initiated by a terminal to be accessed, the network bandwidth requirements of the terminal to be accessed are obtained. When the network bandwidth requirement meets the network bandwidth threshold, the indirect trust evidence data of the terminal to be accessed is obtained. The indirect trust evidence data includes at least one of performance characteristic behavior data, reliability characteristic behavior data, and security characteristic behavior data. The indirect trust score of the terminal to be accessed is calculated based on the indirect trust evidence data. The network access decision is made based on the indirect trust score.
2. The method according to claim 1, characterized in that, The calculation of the indirect trust score of the terminal to be accessed based on the indirect trust evidence data includes: The indirect trust evidence data is constructed into an indirect trust evidence data matrix, where each row of the indirect trust evidence data matrix represents one type of indirect trust evidence data, and each column represents evidence data within a collection period. Compare any two rows of the indirect trust evidence data matrix and score them according to the size of the evidence data to obtain an initial judgment matrix; Add the elements of each row in the initial judgment matrix to obtain the row sum of the initial judgment matrix. Then, convert the initial judgment matrix into a fuzzy uniform matrix according to the row sum of the initial judgment matrix and the total number of rows in the initial judgment matrix. The elements of each row in the fuzzy uniformity matrix are summed to obtain the row sum of the fuzzy uniformity matrix. The fuzzy uniformity matrix is then converted into a weight matrix according to the row sum of the fuzzy uniformity matrix and the total number of rows in the fuzzy uniformity matrix. Based on the weight matrix and the indirect trust evidence data matrix, the indirect trust score of the terminal to be accessed is calculated.
3. The method according to claim 2, characterized in that, After calculating the indirect trust score of the terminal to be accessed based on the weight matrix and the indirect trust evidence data matrix, the method further includes: Obtain the historical indirect trust score of the terminal to be accessed; the historical indirect trust score is calculated based on indirect trust evidence data collected within a historical period; Based on the historical indirect trust score, the indirect trust score, and the first time decay weight, the total indirect trust score of the terminal to be accessed is calculated.
4. The method according to claim 1, characterized in that, When the terminal to be accessed is making an access request that is not the first time, after the network bandwidth requirement meets the network bandwidth threshold, the following is also included: Obtain direct trust evidence data of the terminal to be connected, wherein the direct trust evidence data is a service quality evaluation of the direct interaction between the terminal to be connected and the target resource node in the Internet of Things; Based on the interval between the time of each interaction and the current time, a second time decay weight is assigned to each direct trust evidence data, wherein the interval is inversely proportional to the second time decay weight; The trust level is calculated based on the second time decay weight and the direct trust evidence data; The trust level is fitted based on a probability distribution model to obtain the direct trust score of the terminal to be accessed. Based on the direct trust score, the indirect trust score, and the trust score weights, a total trust score is calculated, and a network access decision is made for the access request based on the total trust score.
5. The method according to claim 1, characterized in that, After obtaining the network bandwidth requirements of the terminal to be accessed, the process also includes: When the network bandwidth requirement does not meet the network bandwidth threshold, obtain the network bandwidth corresponding to the currently connected IoT terminal; Based on the network bandwidth requirements and the network bandwidth corresponding to the currently connected IoT terminals, calculate the expected total utility of the IoT. Obtain the expected cost of the currently connected IoT terminals and the expected cost of the terminals to be connected, and calculate the expected total cost of the IoT. Calculate the truncated bandwidth based on the expected total utility and the expected total cost. Based on the truncation bandwidth and the network bandwidth threshold, a network access decision is made for the access request.
6. The method according to claim 1, characterized in that, After the network bandwidth requirement meets the network bandwidth threshold, the following is also included: Obtain the identifier and matching attribute information of the terminal to be accessed, and obtain the target attribute information from the pre-configured policy information based on the identifier; When the attribute information to be matched and the target attribute information match, the step of obtaining the indirect trust evidence value of the terminal to be accessed is executed; If the attribute information to be matched and the target attribute information do not match, the access request initiated by the terminal to be accessed is rejected.
7. An Internet of Things (IoT) access control device, characterized in that, The device includes: The first acquisition module is used to acquire the network bandwidth requirements of the terminal to be accessed in response to the access request initiated by the terminal to be accessed. The second acquisition module is used to acquire indirect trust evidence data of the terminal to be accessed when the network bandwidth requirement meets the network bandwidth threshold. The indirect trust evidence data includes at least one of performance characteristic behavior data, reliability characteristic behavior data, and security characteristic behavior data. The calculation module is used to calculate the indirect trust score of the terminal to be accessed based on the indirect trust evidence data; The processing module is used to make a network access decision on the access request based on the indirect trust score.
8. An electronic device, characterized in that, The device includes: a processor and a memory storing computer program instructions; the processor reads and executes the computer program instructions to implement an Internet of Things access control method as described in any one of claims 1-6.
9. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores computer program instructions, which, when executed by a processor, implement an Internet of Things access control method as described in any one of claims 1-6.
10. A computer program product, characterized in that, When the instructions in the computer program product are executed by the processor of the electronic device, the electronic device performs an Internet of Things access control method as described in any one of claims 1-6.