Equipment cross-domain authorization method and device, computer equipment and storage medium
By using a cross-domain trust migration model and federated learning technology, the problems of trust fragmentation and static authorization in cross-domain authorization of IoT devices are solved, realizing trust transfer and dynamic authorization between devices in heterogeneous networks, thereby improving network security and the rationality of access control.
Patent Information
- Application Number
- CN202511572585.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-10-30
- Publication Date
- 2026-02-24
AI Technical Summary
Existing cross-domain authorization methods for IoT devices lack flexibility, suffer from trust gaps, authentication delays, and static authorization issues, and cannot effectively respond to real-time risks. Furthermore, the transmission of privacy data violates data compliance requirements.
The cross-domain trust migration model maps the trust characteristics of devices in the source network domain to the target network domain. It calculates the trust value of the target domain by combining environmental risk factors, dynamically adjusts the scope of resource access, and updates the model parameters through federated learning, thereby realizing the transfer of trust and flexible authorization between devices in heterogeneous networks.
It improves the flexibility and security of cross-domain authorization for IoT devices, reduces trust fragmentation and static authorization issues, enhances the rationality of access control and network security, and adapts to changes in trust relationships between devices in different network domains.
Smart Images

Figure CN121567368A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of Internet of Things (IoT) technology, and in particular to a method, apparatus, computer device, computer-readable storage medium, and computer program product for cross-domain device licensing. Background Technology
[0002] With the continuous advancement of information technology, the Internet of Things (IoT) has been widely applied and rapidly developed. The scale of IoT devices is constantly expanding, covering various scenarios from homes to offices, and has greatly changed people's lifestyles and work habits. The development of the IoT relies on efficient and secure communication between devices and effective management of these devices.
[0003] As IoT device applications diversify, devices often need to switch between different network domains, such as from a home network to an office network. However, current cross-domain authorization methods suffer from a lack of flexibility. Summary of the Invention
[0004] Therefore, it is necessary to provide a method, apparatus, computer device, computer-readable storage medium, and computer program product that can flexibly authorize cross-domain licensing of devices in response to the above-mentioned technical problems.
[0005] Firstly, this application provides a method for cross-domain authorization of devices, including:
[0006] In response to a device accessing a target network domain, the source domain trust features of the device in the source network domain are mapped to the trust feature space of the target network domain. Based on the mapped trust features and the environmental risk factors of the target network domain, the target domain trust value of the device in the target network domain is obtained through a pre-trained cross-domain trust transfer model.
[0007] Based on the target domain trust value, the resource access range of the device in the target network domain is determined, and the resources within the resource access range are authorized to the device.
[0008] In one embodiment, the step of obtaining the cross-domain trust migration model includes:
[0009] Obtain the model gradient parameters uploaded by multiple network domains associated with the central server; the model gradient parameters are the model gradient parameters of the device trust evaluation model pre-trained in each of the network domains, and the device trust evaluation model is trained based on the device interaction features under each of the network domains;
[0010] Gradient aggregation is performed on the gradient parameters of the models in multiple network domains to obtain a trained cross-domain trust transfer model.
[0011] In one embodiment, after authorizing the device with the resources within the resource access range, the method further includes:
[0012] Obtain the behavior monitoring results of the device under the target network domain;
[0013] Based on the behavior monitoring results, the resource access range of the device under the target network domain is updated, and the resources within the updated resource access range are authorized to the device.
[0014] In one embodiment, the method further includes:
[0015] The behavior monitoring results and authorization logs are sent back to the source network domain to trigger incremental training of the device trust assessment model in the source network domain and to obtain the updated model gradient parameters of the device trust assessment model in the source network domain.
[0016] The model parameters of the cross-domain trust transfer model are updated based on the updated model gradient parameters.
[0017] In one embodiment, updating the resource access range of the device under the target network domain based on the behavior monitoring results, and authorizing the device with resources within the updated resource access range, includes:
[0018] If the behavior monitoring results indicate the presence of a preset risky behavior, the target domain trust value is updated.
[0019] If the updated trust value of the target domain is less than a preset trust threshold, the resource access range of the device in the target network domain is reduced, and the resources within the reduced resource access range are authorized to the device.
[0020] In one embodiment, updating the target domain trust value when the behavior monitoring result indicates the presence of a preset risky behavior includes:
[0021] When the behavior monitoring results indicate the presence of a preset risky behavior, a trust value decay coefficient and the duration of the risk are obtained; the trust value decay coefficient is positively correlated with the risk level of the preset risky behavior.
[0022] The updated target domain trust value is obtained based on the target domain trust value, the trust value decay coefficient, and the risk duration.
[0023] In one embodiment, authorizing the device with resources within the resource access range includes:
[0024] A network port opening instruction matching the resource access range is generated and sent to the gateway device of the target network domain; the network port opening instruction is used to instruct the gateway device of the target network domain to open network ports matching the resource access range.
[0025] Secondly, this application also provides a device cross-domain licensing apparatus, comprising:
[0026] The trust value acquisition module is used to respond to the device accessing the target network domain by mapping the source domain trust features of the device in the source network domain to the trust feature space of the target network domain. Based on the mapped trust features and the environmental risk factors of the target network domain, the target domain trust value of the device in the target network domain is obtained through a pre-trained cross-domain trust transfer model.
[0027] The resource authorization module is used to determine the resource access range of the device in the target network domain based on the target domain trust value, and to authorize the device with resources within the resource access range.
[0028] Thirdly, this application also provides a computer device, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps of the method described in the first aspect.
[0029] Fourthly, this application also provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the steps of the method described in the first aspect.
[0030] Fifthly, this application also provides a computer program product, including a computer program that, when executed by a processor, implements the steps of the method described in the first aspect.
[0031] The aforementioned cross-domain authorization method, apparatus, computer device, computer-readable storage medium, and computer program product, in response to a device accessing a target network domain, map the source domain trust features of the device in the source network domain to the trust feature space of the target network domain. Based on the mapped trust features and environmental risk factors of the target network domain, a pre-trained cross-domain trust migration model is used to obtain the target domain trust value of the device in the target network domain. Then, based on the target domain trust value, the resource access range of the device in the target network domain is determined, and resources within the resource access range are authorized to the device. Based on the above-mentioned mapping of source domain trust features to the target network domain and the determination of the target domain trust value in conjunction with environmental risk factors, the trust migration and authorization problem when IoT devices cross domains can be effectively solved, enabling trust transfer between heterogeneous networks and improving the flexibility of cross-domain authorization. In the above steps, determining the resource access range and authorizing corresponding resources based on the target domain trust value allows for granting reasonable resource access permissions based on the device's trust status in the target network domain, improving the rationality and security of access control, reducing problems such as trust fragmentation and static authorization in traditional solutions, and enhancing network security. Attached Figure Description
[0032] To more clearly illustrate the technical solutions in the embodiments of this application or related technologies, the drawings used in the description of the embodiments of this application or related technologies will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other related drawings can be obtained based on these drawings without creative effort.
[0033] Figure 1 This is an application environment diagram of a device cross-domain authorization method in one embodiment;
[0034] Figure 2 This is a flowchart illustrating a cross-domain authorization method for devices in one embodiment;
[0035] Figure 3 This is a flowchart illustrating the steps of obtaining a cross-domain trust migration model in one embodiment;
[0036] Figure 4 This is a flowchart illustrating the cross-domain trust federation migration and dynamic authorization method for IoT devices in another embodiment;
[0037] Figure 5 This is a schematic diagram of the cross-domain trust migration process in another embodiment;
[0038] Figure 6 This is a structural block diagram of a device cross-domain authorization device in one embodiment;
[0039] Figure 7 This is an internal structural diagram of a computer device in one embodiment. Detailed Implementation
[0040] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative and not intended to limit the scope of this application.
[0041] It should be noted that the terms "comprising" and "having," and any variations thereof, as used in this application, are intended to cover non-exclusive inclusion. The term "multiple" as used in this application refers to two or more.
[0042] The cross-domain authorization method for devices provided in this application can be applied to, for example... Figure 1 In the application environment shown, device 102 can communicate with central server 104 and target domain 106 via the network; central server 104 can also communicate with target domain 106 via the network. Device 102 and central server 104 can also communicate with other domains via the network. When device 102 accesses target domain 106, central server 104 responds to the access request by device 102 to target domain 106 by mapping the source domain trust features of device 102 in the source domain to the trust feature space of target domain 106. Based on the mapped trust features and the environmental risk factors of target domain 106, central server 104 obtains the target domain trust value of device 102 in target domain 106 through a pre-trained cross-domain trust migration model. Based on the target domain trust value, central server 104 determines the resource access range of device 102 in target domain 106 and authorizes the resources within the resource access range to device 102. Among them, device 102 can be, but is not limited to, various personal computers, laptops, smartphones, tablets, drones, low-altitude aircraft, IoT devices, and portable wearable devices. IoT devices can be smart speakers, smart TVs, smart air conditioners, smart in-vehicle devices, projection devices, etc. Portable wearable devices can be smartwatches, smart bracelets, head-mounted devices, etc. Head-mounted devices can be virtual reality (VR) devices, augmented reality (AR) devices, smart glasses, etc. The central server 104 can be a standalone physical server, a server cluster or distributed system composed of multiple physical servers, or a cloud server providing cloud computing services.
[0043] In one exemplary embodiment, such as Figure 2 As shown, a cross-domain authorization method for devices is provided, which can be applied to... Figure 1Taking the central server 104 as an example, the explanation includes the following steps S202 to S204. Wherein:
[0044] Step S202: In response to the device accessing the target network domain, the source domain trust features of the device in the source network domain are mapped to the trust feature space of the target network domain. Based on the trust features obtained from the mapping and the environmental risk factors of the target network domain, the target domain trust value of the device in the target network domain is obtained through a pre-trained cross-domain trust transfer model.
[0045] Among them, devices can refer to Internet of Things (IoT) devices, such as smart home appliances in a home network domain and smart terminals in an office environment. Devices can access and obtain authorization between different network domains.
[0046] The source domain can refer to the network area where the device is located before accessing a new domain. For example, when a device switches from a home network to an office network, the home network becomes the source domain, and the device has corresponding trust characteristics in that domain. Similarly, when a device switches from an office network to a home network, the office network becomes the source domain. Source domain trust characteristics can refer to features within the source domain used to describe the trust status of the device. For example, when the source domain is a home network, dynamic indicators such as device authentication success rate, communication encryption strength, and frequency of abnormal behavior can be collected in real time, along with static attributes such as device type and firmware version, processed to obtain characteristics that reflect the degree of trust the device has in the source domain. Similarly, when the source domain is an office network, environmental risk data such as the proportion of vulnerable devices, blacklisted IPs, and threat intelligence can be collected, and then features can be extracted to obtain the characteristics. For instance, after identifying a device, the central server can search for the corresponding source domain trust characteristics of the device from the pre-stored trust characteristics of each device under the source domain. Alternatively, after identifying a device, the central server can initiate a trust characteristic acquisition request for the source domain where the device resides, thereby obtaining the device's source domain trust characteristics.
[0047] The target network domain can refer to a new network area that the device requests to access. For example, when a device switches from a home network to an office network, the office network is the target network domain; or when a device switches from an office network to a home network, the home network is the target network domain.
[0048] The trust feature space can refer to the space formed by the features used to measure the trust level of devices in the target network domain. The source domain trust features need to be mapped to this space so that trust assessment can be performed in the target network domain.
[0049] Among them, environmental risk factors can be used to reflect the network environment security risks in the target network domain.
[0050] Among them, the cross-domain trust migration model can refer to a pre-trained model deployed in a central server, which combines the source domain trust features with the target network domain environment risk factors to output the trust value of the device in the target network domain, thus solving the trust transfer problem between heterogeneous networks.
[0051] The target domain trust value can be a numerical value obtained through a cross-domain trust migration model, which represents the degree of trust of a device in the target network domain and serves as the basis for determining the scope of resource access for the device in the target network domain.
[0052] For example, when a device requests access to a target network domain, the central server can first extract the source domain trust features of the device in the source network domain. These features can be obtained by collecting various dynamic indicators and static attributes of the device in the source network domain and processing them through feature extraction.
[0053] Then, these source domain trust features are projected onto the target network domain's trust feature space using linear transformation matrices and other methods, enabling trust value evaluation within the target network domain environment. Simultaneously, environmental risk factors for the target network domain are obtained, such as by calculating the proportion of vulnerable devices. Finally, the mapped and aligned trust features and environmental risk factors are input into a pre-trained cross-domain trust transfer model. The model performs internal calculations and outputs the device's target domain trust value within the target network domain. For example, in a scenario where an IoT device switches from a home network to an office network, trust features of the device in the home domain, such as device authentication success rate and frequency of abnormal behavior, are extracted, processed, and mapped onto the office network's trust feature space. Combined with the proportion of vulnerable devices in the office network, this data is input into the cross-domain trust transfer model to obtain the device's target domain trust value within the office network.
[0054] Step S204: Based on the target domain trust value, determine the resource access range of the device in the target network domain, and authorize the device with the resources within the resource access range.
[0055] The resource access range can refer to the range of resources that a device is allowed to access in the target network domain, as determined by the target domain trust value. For example, different trust value ranges for the target domain trust value of a device can correspond to different resource access ranges. For instance, a trust value range representing full trust corresponds to opening all resources, while a trust value range representing conditional trust corresponds to opening only basic applications.
[0056] For example, the central server can determine the resource access range matched by the target domain trust value according to pre-defined policy matching rules. The higher the target domain trust value, the larger the matched resource access range may be. The central server determines the device's resource access range in the target network domain according to the policy matching rules, and authorizes the corresponding resources to the device according to the resource access range. For example, assuming the target domain trust value is A, and the policy matching rules match its resource access range as open resources a, b, and c, then the central server authorizes resources a, b, and c to the device.
[0057] In the aforementioned cross-domain authorization method, the central server responds to a device's access to the target network domain by mapping the device's source domain trust features in the source network domain to the target network domain's trust feature space. Based on the mapped trust features and the target network domain's environmental risk factors, a pre-trained cross-domain trust migration model is used to obtain the device's target domain trust value in the target network domain. Then, the central server determines the device's resource access range in the target network domain based on the target domain trust value and authorizes the device with resources within that range. Based on the mapping of source domain trust features to the target network domain and the determination of the target domain trust value using environmental risk factors, this method effectively solves the trust migration and authorization problems when IoT devices cross domains, enabling trust transfer between heterogeneous networks and improving the flexibility of cross-domain authorization. The steps described above, which determine the resource access range and authorize corresponding resources based on the target domain trust value, allow for reasonable resource access permissions based on the device's trust status in the target network domain, improving the rationality and security of access control, reducing trust fragmentation and static authorization issues in traditional solutions, and enhancing network security.
[0058] In one exemplary embodiment, such as Figure 3 As shown, the steps for obtaining the cross-domain trust migration model include steps S302 to S304. Wherein:
[0059] Step S302: Obtain the model gradient parameters uploaded by multiple network domains associated with the central server; the model gradient parameters are the model gradient parameters of the pre-trained device trust evaluation model in each network domain, and the device trust evaluation model is trained based on the device interaction features under each network domain.
[0060] Step S304: Perform gradient aggregation on the model gradient parameters of multiple network domains to obtain the trained cross-domain trust transfer model.
[0061] The central server is responsible for collecting and aggregating model gradient parameters uploaded from multiple network domains to generate global model parameters. Model gradient parameters refer to the gradient parameters calculated during the training process of pre-trained device trust assessment models in each network domain. These parameters reflect the direction and magnitude of parameter updates during training and are aggregated at the central server to update the global model, resulting in a trained cross-domain trust transfer model. Device trust assessment models are models trained based on local device interaction features for each network domain. They are used to assess the trust level of devices within that domain. In federated learning, each network domain participates in the construction of the global model by training this model and uploading its gradient parameters. Gradient aggregation refers to the process of summarizing and merging model gradient parameters uploaded from multiple network domains. By aggregating these gradient parameters, the parameters of the cross-domain trust transfer model are updated, enabling it to better adapt to different network domain situations.
[0062] For example, each network domain collects the interaction characteristics of devices locally, and then uses these characteristics to train a device trust assessment model. During training, each network domain calculates the gradient parameters of the device trust assessment model and uploads them to the central server. After receiving the model gradient parameters uploaded by multiple network domains, the central server aggregates these gradient parameters. After aggregation, new model parameters are generated, thus obtaining the trained cross-domain trust transfer model.
[0063] In this embodiment, a cross-domain trust transfer model is obtained through federated learning. Each network domain only uploads the model's gradient parameters, not the original data, thus protecting the data privacy of each network domain and complying with data compliance requirements. By training the model using device interaction features from multiple network domains, the cross-domain trust transfer model can better adapt to the characteristics of different network domains, improving the model's generalization ability and accuracy, and thereby enhancing the reliability and stability of cross-domain trust transfer.
[0064] After the device is authorized and successfully accesses the target network domain, the device can be adjusted in real time. In an exemplary embodiment, after authorizing the device with resources within the resource access range, the method further includes: obtaining the device's behavior monitoring results under the target network domain; updating the device's resource access range under the target network domain based on the behavior monitoring results; and authorizing the device with resources within the updated resource access range.
[0065] Among them, the behavior monitoring results can refer to the results obtained after monitoring the behavior of the device in the target network domain, which are used to determine whether the device behavior poses a risk.
[0066] For example, within the target network domain, the behavior of devices can be monitored in real time using behavioral analysis models or related monitoring tools deployed in the network, and behavioral monitoring results can be obtained. After the central server obtains the behavioral monitoring results, if the behavioral monitoring results indicate that the device has risky behavior, it updates the device's resource access scope in the target network domain according to preset rules; and re-authorizes the resources within the updated resource access scope to the device.
[0067] In this embodiment, the central server obtains the monitoring results of the device's behavior in the target network domain in real time and updates the device's resource access range accordingly, thereby realizing the dynamic adjustment of device access permissions. It can respond promptly to real-time risks of the device in the target network domain. Compared with the static authorization method, it improves the flexibility and security of access control and better protects the resource security of the target network domain.
[0068] In an exemplary embodiment, the cross-domain authorization method may further include: transmitting behavior monitoring results and authorization logs back to the source network domain to trigger incremental training of the device trust assessment model in the source network domain, and obtaining the updated model gradient parameters of the device trust assessment model in the source network domain; and updating the model parameters of the cross-domain trust migration model according to the updated model gradient parameters.
[0069] The authorization log refers to a log that records information related to a device obtaining authorization in the target network domain. This log may include authorization time, authorization level, accessed resources, etc., and is used to provide feedback on the device's authorization status. Incremental training refers to further training the model using new data based on an existing model to update the model parameters and better adapt it to new data and tasks. In this embodiment, the device trust assessment model in the source network domain undergoes incremental training based on the returned behavior monitoring results and the authorization log.
[0070] For example, the central server sends back the device's behavior monitoring results and authorization logs in the target network domain to the source network domain. Upon receiving this information, the source network domain uses it as new data to input into the device trust assessment model for incremental training. Through incremental training, the model learns the device's behavior information in the target network domain, thereby updating the model parameters. After training is complete, the updated model gradient parameters of the device trust assessment model are obtained. The source network domain uploads the updated model gradient parameters to the central server. The central server updates the model parameters of the cross-domain trust migration model based on the updated model gradient parameters to adjust the parameters of the cross-domain trust migration model so that it can better reflect changes in the trust relationship between devices in different network domains.
[0071] In this embodiment, closed-loop optimization of the device trust assessment model is achieved by sending behavior monitoring results and authorization logs back to the source network domain and triggering incremental training. This allows the device trust assessment model in the source network domain to be updated based on the device's behavior in the target network domain, improving the accuracy of the model's device trust assessment. Furthermore, the cross-domain trust transfer model is updated based on the updated model gradient parameters in the source network domain, enabling the cross-domain trust transfer model to continuously adapt to the dynamic changes in trust relationships between devices in different network domains, thus improving the adaptability and reliability of the entire cross-domain trust transfer and authorization system.
[0072] In an exemplary embodiment, based on the behavior monitoring results, the resource access range of the device in the target network domain is updated, and the resources within the updated resource access range are authorized to the device. This includes: updating the target domain trust value when the behavior monitoring results indicate the existence of a preset risky behavior; and reducing the resource access range of the device in the target network domain when the updated target domain trust value is less than a preset trust threshold, and authorizing the resources within the reduced resource access range to the device.
[0073] The preset risky behavior refers to pre-defined device behaviors that are considered potentially threatening to network security or network resources, i.e., high-risk behaviors. The trust threshold can be a boundary used to determine whether the trust value of the target domain needs to be adjusted. When the updated trust value of the target domain is less than this boundary, the resource access range of the device will be reduced.
[0074] For example, the central server analyzes the behavior monitoring results. If the analysis determines that a device exhibits a preset risky behavior, it can update the device's target domain trust value according to preset rules. The updated target domain trust value is compared with a preset trust threshold. If it is less than the trust threshold, the device's resource access range in the target network domain is reduced according to a preset policy, and the resources within the reduced resource access range are reauthorized to the device.
[0075] In this embodiment, when the behavior monitoring results indicate the presence of a preset risky behavior, the target domain trust value is updated. Furthermore, if the updated target domain trust value is less than a preset trust threshold, the device's resource access range within the target network domain is reduced, and then resources within the reduced access range are authorized to the device. These operations provide rules for updating the target domain trust value and adjusting the resource location range when a device exhibits risky behavior. This makes the dynamic authorization mechanism more robust, enabling dynamic adjustment of the resource access range based on the risk of the device's real-time behavior. This precise dynamic access control improves the security of resources within the target network domain.
[0076] In an exemplary embodiment, when the behavior monitoring results indicate the presence of a preset risky behavior, updating the target domain trust value includes: obtaining a trust value decay coefficient and a risk duration when the behavior monitoring results indicate the presence of a preset risky behavior; the trust value decay coefficient is positively correlated with the risk level of the preset risky behavior; and obtaining the updated target domain trust value based on the target domain trust value, the trust value decay coefficient, and the risk duration.
[0077] The trust value decay coefficient can be used to calculate the trust value update of the target domain. It is positively correlated with the risk level of the preset risk behavior. That is, the higher the risk level, the larger the trust value decay coefficient, and the faster the trust value of the target domain decays.
[0078] For example, when the central server determines that a device exhibits a preset risky behavior, it can determine the level of that risky behavior based on a behavioral risk analysis model and obtain a corresponding trust value decay coefficient based on the risk level; simultaneously, it records the duration of the risky behavior. For instance, if it detects that a device is downloading a sensitive file, the behavior is judged to have a high risk level, a larger trust value decay coefficient is obtained, and the duration from the detection of the behavior is recorded. Then, according to a preset exponential decay formula, the target domain trust value, the trust value decay coefficient, and the risk duration are substituted into the formula to calculate the updated target domain trust value.
[0079] This embodiment illustrates the method for updating the target domain trust value. The target domain trust value is updated by using a trust value decay coefficient and risk duration related to the risk level. This allows the adjustment of the trust value to more accurately reflect the risk level of device behavior. This precise trust value update mechanism provides a more reasonable basis for dynamically adjusting the scope of resource access, further enhancing the scientificity and effectiveness of the dynamic authorization mechanism and improving the security of network resources.
[0080] In an exemplary embodiment, the preset exponential decay formula in the above embodiments can be as follows:
[0081]
[0082] in, The updated target domain trust value; Trust value for the target domain; Trust value decay coefficient (value determined based on behavioral risk level, e.g., when the risk level is high) ); t represents the duration of the risk (in minutes).
[0083] In an exemplary embodiment, granting access to resources within the resource access range to a device includes: generating a network port opening instruction that matches the resource access range and sending it to a gateway device in the target network domain; the network port opening instruction is used to instruct the gateway device in the target network domain to open network ports that match the resource access range.
[0084] The network port open instruction refers to a command generated by the central server and sent to the gateway device in the target network domain. This command instructs the gateway device to open network ports matching its resource access scope, thereby controlling access to device resources. The gateway device can be any device in the target network domain responsible for network access and data forwarding. Upon receiving the network port open instruction, it opens the corresponding network ports as required by the instruction, thus managing access to device resources.
[0085] For example, the central server generates corresponding network port opening instructions based on the determined device resource access range. For instance, if the resource access range is limited to internet access only (ports 80 / 443), then instructions to open ports 80 and 443 are generated. These instructions are then sent to the gateway device in the target network domain. Upon receiving the instructions, the gateway device opens the corresponding network ports as required, thereby controlling device resource access and ensuring that the device can only access resources permitted within the specified access range.
[0086] In another example, a policy executor can be deployed in an embedded security zone (such as ARM TrustZone) on the gateway device. The central server can directly send the target domain trust value to the policy executor. Policy executors in different domains can configure different trust values to match resource policies locally. The executor in the target domain determines the authorized trust level and resource access scope corresponding to the target domain trust value through local policies, and then dynamically switches network ports based on the authorized trust level (e.g., only opening ports 80 / 443 for zero trust level). In this embodiment, by deploying a local policy executor, different policy execution rules can be configured for different domains. The central server only needs to pass the target domain trust value after cross-domain trust migration to the policy executor, and the policy executor can automatically implement the locally configured resource authorization policy. Different domains can configure personalized resource authorization policies according to their characteristics, improving the flexibility of cross-domain authorization.
[0087] This embodiment clarifies the specific implementation method of authorizing resources to devices. By controlling the gateway device to open corresponding network ports, precise control over device resource access is achieved, ensuring the security and rationality of resource access. This authorization method based on network port control is easy to implement and manage, improves the efficiency and accuracy of authorization policy execution, and provides a reliable means for cross-domain authorization of IoT devices.
[0088] Traditional cross-domain authentication schemes for IoT devices suffer from the following problems: trust fragmentation, requiring repeated authentication when devices switch between home and office networks, resulting in significant authentication delays; static authorization, with fixed access permissions, failing to respond to real-time risks; and privacy leakage, as the cross-domain transfer of raw behavioral data violates data compliance requirements. To address these issues, in an exemplary embodiment, such as... Figure 4 As shown, this application also provides a cross-domain trust federated migration and dynamic authorization method for IoT devices. It aggregates trust features from multiple domain devices through federated learning, trains a cross-domain trust migration model, and when a device connects to a new domain, extracts its source domain trust features and inputs them into the model, outputting the initial trust value of the target domain. It dynamically matches authorization strategies based on the trust value range and updates the local trust model based on the closed-loop feedback of the authorization results. Specifically, it may include:
[0089] Step 1: Perform cross-domain trust migration using a cross-domain trust migration model, such as... Figure 5 As shown, the central server responds to a device's access to the target network domain by mapping the device's source domain trust features in the source network domain to the target network domain's trust feature space. Based on the mapped trust features and the target network domain's environmental risk factors, the central server obtains the device's target domain trust value in the target network domain through a pre-trained cross-domain trust transfer model.
[0090] Specifically, the first step is to align features through the feature alignment layer in the cross-domain trust migration model, thereby aligning the source domain trust features of the device in the source network domain. Through linear transformation matrix The feature space projected onto the target network domain can be calculated using the following formula:
[0091]
[0092] in, The trust features obtained from the mapping; The source domain trust features are heterogeneous to the target network domain, therefore feature mapping is required; This is the bias matrix.
[0093] Then, obtain the environmental risk factors of the target domain. In this embodiment, environmental risk factors It can be obtained by calculating the percentage of vulnerable devices in the target network domain, with a value range of (0, 1).
[0094] Next, the mapped and aligned trust features are... Environmental risk factors Concatenation, or merging, into a single vector. This concatenated vector is then input into a 3-layer Transformer encoder in the cross-domain trust transfer model to learn cross-domain trust relationships; the target domain trust value is output through the fully connected layer of the model. (like Figure 5 The initial trust value). Here, cross-domain trust relationship can refer to the correlation or dependency relationship between device trust status, trust characteristics and environmental risks between different network domains (source network domain and target network domain) learned by the model; through the learned cross-domain trust relationship, the cross-domain trust transfer model can combine the environmental characteristics of the target network domain and dynamically adjust the weight of the source domain features, so that the output target domain trust value inherits the device historical information of the source network domain and adapts to the actual risk scenario of the target domain.
[0095] The steps of federated trust modeling (for various local domains, such as home domains and office domains) include: First, data collection is performed on each local domain. For example, home domain devices need to collect dynamic indicators such as device authentication success rate, communication encryption strength, and frequency of abnormal behavior in real time; office domain devices need to collect environmental risk data such as the proportion of vulnerable devices, blacklisted IPs, and threat intelligence. Then, feature extraction is performed on the collected data. For example, static attributes such as device type and firmware version are embedded and vectorized (e.g., device type is mapped to an 8-dimensional vector), and dynamic device behavior data is normalized to the [0, 1] interval to obtain source domain trust features (e.g., home domain trust features, office domain trust features, etc.). Next, federated training is performed. Each domain trains a device trust evaluation model locally using a lightweight Transformer model; each domain only uploads the model gradient parameters to the central server (a federated aggregation server can be configured separately in the central server for federated training); the central server adds Gaussian noise (standard deviation σ=0.1) and aggregates the gradients to generate global model parameters and distribute them. A cross-domain trust transfer model is generated in the central server.
[0096] Step two: Implement dynamic authorization through the dynamic authorization policy engine. Based on the target domain trust value, determine the device's resource access scope within the target network domain, and authorize the device with resources within that scope. Obtain the device's behavior monitoring results within the target network domain; based on these results, update the device's resource access scope within the target network domain, and authorize the device with resources within the updated scope.
[0097] Specifically, based on the target domain trust value, the resource access scope of the device in the target network domain is determined, and the policy matching rules can be shown in the table below:
[0098]
[0099] After determining the resource access scope of the device in the target network domain according to the policy matching rules in the table above, the resources within the resource access scope are authorized to the device.
[0100] Then, a real-time adjustment mechanism is implemented to obtain the device's behavior monitoring results within the target network domain; based on the behavior monitoring results, the device's resource access scope within the target network domain is updated. For example, when the detected behavior monitoring results indicate high-risk behavior (such as downloading sensitive files), the target domain trust value is updated according to the following exponential decay formula:
[0101]
[0102] in, The updated target domain trust value; Trust value for the target domain; Trust value decay coefficient (value determined based on behavioral risk level, e.g., when the risk level is high) ); t represents the duration of the risk (in minutes).
[0103] If the updated target domain trust value is less than the preset trust threshold, the device's resource access range in the target network domain is reduced, and the resources within the reduced resource access range are authorized to the device. In other words, after updating the target domain trust value, if the trust value falls below the threshold, authorization downgrade is automatically triggered. The threshold can be determined based on the boundary values of the trust value range in the table above.
[0104] Step 3: Implement the terminal execution strategy and feedback.
[0105] Deploy a policy executor in the embedded security zone (such as ARM TrustZone) on the gateway device of the target network domain to dynamically open and close network ports according to the authorization level (e.g., only open ports 80 / 443 for zero trust level).
[0106] Then, behavioral data such as interception events and authorization logs from the behavior monitoring results can be sent back to the local model; triggering incremental training and generating new gradient parameters to participate in federated aggregation.
[0107] In one example, a mathematical model is used as an analogy to illustrate the learning principle of transfer models, demonstrating the change in trust values during cross-domain migration. This could be seen in scenarios where IoT devices switch from home networks to office networks, such as an employee's home tablet accessing the company network to access the financial system.
[0108] Trust transfer phase: Extracting trust features from the family domain Office network environment risk factors: vulnerable devices account for 10% ( ); transfer model output, .
[0109] The mathematical model used in the example of the transfer learning principle is as follows:
[0110]
[0111] Wherein, the coefficient can be (Trainable parameters); This is the source domain trust value (e.g., a home network score of 0.7).
[0112] Initial authorization: → Grant "Conditional Trust" level (access to printers, email, etc.).
[0113] Dynamic adjustment: The tablet attempts to download financial documents → Behavioral analysis model detects anomalies (high risk level). Trust value update in the first minute: (As the risk persists, the trust value continues to decrease); Authorization downgrade: Switch to "Internet access only" → Block file downloads.
[0114] Federated Feedback: Intercepting events upload gradients → Global model update → New parameters generated in the next generation.
[0115] The above embodiments construct local device trust models in the source and target network domains respectively, aggregate model parameters through a federated learning framework, and when a device accesses the target network domain, extract its source domain trust features, input them into the cross-domain migration model, output an initial trust value, match a dynamic authorization policy level according to the initial trust value, execute resource access control on the device, and update the local trust evaluation model based on the closed-loop feedback of the authorization result. This application creates a "feature alignment-Transformer migration" model to solve the trust transmission problem in heterogeneous networks and protects privacy through federated learning. At the same time, this application designs a dynamic authorization mechanism driven by real-time decay of trust value to achieve fine-grained access control and a lightweight implementation of zero-trust architecture in IoT scenarios.
[0116] It should be understood that although the steps in the flowcharts of the embodiments described above are shown sequentially according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless explicitly stated herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some steps in the flowcharts of the embodiments described above may include multiple steps or multiple stages. These steps or stages are not necessarily completed at the same time, but can be executed at different times. The execution order of these steps or stages is not necessarily sequential, but can be performed alternately or in turn with other steps or at least some of the steps or stages in other steps. It is understood that the steps in different embodiments can be freely combined as needed, and all non-contradictory solutions formed by such combinations are within the scope of protection of this application.
[0117] Based on the same inventive concept, this application also provides a device cross-domain licensing apparatus for implementing the aforementioned device cross-domain licensing method. The solution provided by this apparatus is similar to the implementation described in the above method; therefore, the specific limitations in one or more device cross-domain licensing apparatus embodiments provided below can be found in the limitations of the device cross-domain licensing method described above, and will not be repeated here.
[0118] In one exemplary embodiment, such as Figure 6 As shown, a cross-domain device authorization device 900 is provided, including: a trust value acquisition module 901 and a resource authorization module 902, wherein:
[0119] The trust value acquisition module 901 is used to respond to the device accessing the target network domain by mapping the source domain trust features of the device in the source network domain to the trust feature space of the target network domain. Based on the trust features obtained by mapping and the environmental risk factors of the target network domain, the target domain trust value of the device in the target network domain is obtained through a pre-trained cross-domain trust transfer model.
[0120] The resource authorization module 902 is used to determine the resource access range of the device in the target network domain based on the target domain trust value, and to authorize the device with the resources within the resource access range.
[0121] In an exemplary embodiment, the above-mentioned cross-domain authorization device further includes a model acquisition module, which is used to acquire model gradient parameters uploaded by multiple network domains associated with the central server respectively; the model gradient parameters are the model gradient parameters of the pre-trained device trust evaluation model in each network domain, and the device trust evaluation model is trained based on the device interaction features under each network domain; the model gradient parameters of multiple network domains are aggregated to obtain a trained cross-domain trust transfer model.
[0122] In an exemplary embodiment, the device cross-domain authorization device further includes a real-time adjustment module, which is used to obtain the behavior monitoring results of the device in the target network domain; update the resource access range of the device in the target network domain according to the behavior monitoring results, and authorize the device with resources within the updated resource access range.
[0123] In an exemplary embodiment, the above-mentioned cross-domain authorization device further includes a model parameter update module, which is used to send the behavior monitoring results and authorization logs back to the source network domain to trigger incremental training of the device trust assessment model in the source network domain and obtain the updated model gradient parameters of the device trust assessment model in the source network domain; and update the model parameters of the cross-domain trust transfer model according to the updated model gradient parameters.
[0124] In an exemplary embodiment, the real-time adjustment module is further configured to update the target domain trust value when the behavior monitoring results indicate the presence of a preset risky behavior; and to reduce the resource access range of the device in the target network domain when the updated target domain trust value is less than a preset trust threshold, and to authorize the device with resources within the reduced resource access range.
[0125] In an exemplary embodiment, the real-time adjustment module is further configured to obtain a trust value decay coefficient and a risk duration when the behavior monitoring results indicate the presence of a preset risky behavior; the trust value decay coefficient is positively correlated with the risk level of the preset risky behavior; and an updated target domain trust value is obtained based on the target domain trust value, the trust value decay coefficient, and the risk duration.
[0126] In an exemplary embodiment, the resource authorization module 902 is further configured to generate a network port opening instruction that matches the resource access scope and send it to the gateway device of the target network domain; the network port opening instruction is used to instruct the gateway device of the target network domain to open network ports that match the resource access scope.
[0127] Each module in the aforementioned cross-domain authorization device can be implemented entirely or partially through software, hardware, or a combination thereof. These modules can be embedded in or independent of the processor in the computer device in hardware form, or stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to each module.
[0128] In one exemplary embodiment, a computer device is provided, which may be a server, and its internal structure diagram may be as follows: Figure 7As shown, this computer device includes a processor, memory, input / output (I / O) interfaces, and a communication interface. The processor, memory, and I / O interfaces are connected via a system bus, and the communication interface is also connected to the system bus via the I / O interfaces. The processor provides computing and control capabilities. The memory includes non-volatile storage media and internal memory. The non-volatile storage media stores the operating system, computer programs, and databases. The internal memory provides the environment for the operating system and computer programs stored in the non-volatile storage media to run. The I / O interfaces are used for exchanging information between the processor and external devices. The communication interface is used for communicating with external terminals via a network connection. When the computer program is executed by the processor, it implements a cross-domain authorization method for the device.
[0129] Those skilled in the art will understand that Figure 7 The structure shown is merely a block diagram of a portion of the structure related to the present application and does not constitute a limitation on the computer device to which the present application is applied. Specific computer devices may include more or fewer components than those shown in the figure, or combine certain components, or have different component arrangements.
[0130] In one embodiment, a computer device is also provided, including a memory and a processor, wherein the memory stores a computer program, and the processor executes the computer program to implement the steps in the above method embodiments.
[0131] In one embodiment, a computer-readable storage medium is provided having a computer program stored thereon that, when executed by a processor, implements the steps in the above method embodiments.
[0132] In one embodiment, a computer program product is provided, including a computer program that, when executed by a processor, implements the steps in the above method embodiments.
[0133] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, data stored, data displayed, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of the relevant data must comply with relevant regulations.
[0134] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments can be implemented by a computer program instructing related hardware. The computer program can be stored in a non-volatile computer-readable storage medium, and when executed, it can include the processes of the embodiments of the above methods. Any references to memory, databases, or other media used in the embodiments provided in this application can include at least one of non-volatile memory and volatile memory. Non-volatile memory can include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory can include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can take many forms, such as Static Random Access Memory (SRAM) or Dynamic Random Access Memory (DRAM). The databases involved in the embodiments provided in this application may include at least one type of relational database and non-relational database. Non-relational databases may include, but are not limited to, blockchain-based distributed databases. The processors involved in the embodiments provided in this application may be general-purpose processors, central processing units, graphics processing units, digital signal processors, programmable logic devices, quantum computing-based data processing logic devices, artificial intelligence (AI) processors, etc., and are not limited to these.
[0135] The technical features of the above embodiments can be combined in any way. For the sake of brevity, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this application.
[0136] The embodiments described above are merely illustrative of several implementation methods of this application, and while the descriptions are specific and detailed, they should not be construed as limiting the scope of this patent application. It should be noted that those skilled in the art can make various modifications and improvements without departing from the concept of this application, and these all fall within the protection scope of this application. Therefore, the protection scope of this application should be determined by the appended claims.
Claims
1. A method for cross-domain authorization of devices, characterized in that, The method includes: In response to a device accessing a target network domain, the source domain trust features of the device in the source network domain are mapped to the trust feature space of the target network domain. Based on the mapped trust features and the environmental risk factors of the target network domain, the target domain trust value of the device in the target network domain is obtained through a pre-trained cross-domain trust transfer model. Based on the target domain trust value, the resource access range of the device in the target network domain is determined, and the resources within the resource access range are authorized to the device.
2. The method according to claim 1, characterized in that, The steps for obtaining the cross-domain trust migration model include: Obtain the model gradient parameters uploaded by multiple network domains associated with the central server; the model gradient parameters are the model gradient parameters of the device trust evaluation model pre-trained in each of the network domains, and the device trust evaluation model is trained based on the device interaction features under each of the network domains; Gradient aggregation is performed on the gradient parameters of the models in multiple network domains to obtain a trained cross-domain trust transfer model.
3. The method according to claim 1, characterized in that, After authorizing the device to access the resources within the resource access range, the method further includes: Obtain the behavior monitoring results of the device under the target network domain; Based on the behavior monitoring results, the resource access range of the device under the target network domain is updated, and the resources within the updated resource access range are authorized to the device.
4. The method according to claim 3, characterized in that, The method further includes: The behavior monitoring results and authorization logs are sent back to the source network domain to trigger incremental training of the device trust assessment model in the source network domain and to obtain the updated model gradient parameters of the device trust assessment model in the source network domain. The model parameters of the cross-domain trust transfer model are updated based on the updated model gradient parameters.
5. The method according to claim 3, characterized in that, The step of updating the resource access range of the device under the target network domain based on the behavior monitoring results, and authorizing the device with resources within the updated resource access range, includes: If the behavior monitoring results indicate the presence of a preset risky behavior, the target domain trust value is updated. If the updated trust value of the target domain is less than a preset trust threshold, the resource access range of the device in the target network domain is reduced, and the resources within the reduced resource access range are authorized to the device.
6. The method according to claim 5, characterized in that, When the behavior monitoring results indicate the presence of a preset risky behavior, updating the target domain trust value includes: When the behavior monitoring results indicate the presence of a preset risky behavior, a trust value decay coefficient and the duration of the risk are obtained; the trust value decay coefficient is positively correlated with the risk level of the preset risky behavior. The updated target domain trust value is obtained based on the target domain trust value, the trust value decay coefficient, and the risk duration.
7. The method according to any one of claims 1 to 6, characterized in that, The step of authorizing the device with resources within the resource access range includes: A network port opening instruction matching the resource access range is generated and sent to the gateway device of the target network domain; the network port opening instruction is used to instruct the gateway device of the target network domain to open network ports matching the resource access range.
8. A device cross-domain authorization device, characterized in that, The device includes: The trust value acquisition module is used to respond to the device accessing the target network domain by mapping the source domain trust features of the device in the source network domain to the trust feature space of the target network domain. Based on the mapped trust features and the environmental risk factors of the target network domain, the target domain trust value of the device in the target network domain is obtained through a pre-trained cross-domain trust transfer model. The resource authorization module is used to determine the resource access range of the device in the target network domain based on the target domain trust value, and to authorize the device with resources within the resource access range.
9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method according to any one of claims 1 to 7.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7.
11. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by a processor, it implements the steps of the method according to any one of claims 1 to 7.