Network access control method and device, equipment and storage medium
By combining subjective and objective weighting methods, and using access frequency and trust score to estimate the coefficient of variation and conflict coefficient, the comprehensive weight of trust assessment factors is dynamically generated, solving the problem of inaccurate trust assessment in existing technologies and achieving precision and adaptability of network access control.
Patent Information
- Application Number
- CN202511964145.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-12-24
- Publication Date
- 2026-02-24
AI Technical Summary
Existing network access control methods suffer from several problems in trust assessment, including the subjective weighting method being highly subjective, the objective weighting method ignoring business importance, and the inability to update weights online adaptively, leading to inaccurate trust assessment results.
By combining subjective and objective weighting methods, and using the number of visits and trust scores to estimate the coefficient of variation and the coefficient of conflict, the comprehensive weight of the trust assessment factor is dynamically generated, enabling online adaptive updates.
It improves the accuracy of trust assessment and the precision of network access control, and can adapt to changes in business data to achieve accurate trust assessment of access subjects.
Smart Images

Figure CN121567460A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technology, and in particular to a network access control method, apparatus, device, and storage medium. Background Technology
[0002] In network security access control scenarios, to ensure the security of network access, it is usually necessary to perform trust assessments on the accessing entities. Only accessing entities that are assessed as trustworthy are authorized to access the corresponding network resources. For example, when the access control system receives a network resource access request, it first obtains the values of all lower-level assessment factors (without lower-level assessment factors) through terminal reporting and database queries. Then, it quantifies the scores of all lower-level assessment factors and combines the quantified scores to obtain the scores of the higher-level assessment factors. Finally, it combines the scores of all higher-level assessment factors to obtain the total trust score. If the total trust score exceeds the trust score threshold, the access is allowed; otherwise, the access is denied.
[0003] Currently, when synthesizing trust scores for multiple evaluation factors, it is usually necessary to assign corresponding weights to each factor. The rationality of the weighting directly affects the accuracy of the trust score. Mainstream weighting methods include subjective weighting and objective weighting. Subjective weighting methods rely on expert scores, directly utilizing or calculating the weights of each factor, such as direct weighting, analytic hierarchy process (AHP), and pecking order diagrams. Objective weighting methods, on the other hand, rely on actual data, analyzing factors such as data volatility and correlation to calculate the weights of each factor, such as entropy methods, independence weighting, information content weighting, and CRITIC weighting.
[0004] However, while the subjective weighting method considers the business importance of different evaluation factors and does not rely on data samples, it is subjective and ignores the objective data distribution and correlation of the factors. The objective weighting method, while free from subjective human intervention and focusing only on data distribution and correlation, requires sample data and cannot reflect the business importance of factors. Furthermore, once the weights are determined using either the subjective or objective weighting method, they remain unchanged during business processing, or require periodic restarts for adjustments and updates. This lack of an online adaptive update mechanism makes it unable to adapt to changes in business data. Summary of the Invention
[0005] In view of this, the purpose of this application is to provide a network access control method, apparatus, device, and storage medium capable of accurately assessing the trust of the access subject (i.e., the target client), thereby making the trust assessment results more accurate and achieving precise network access control. The specific solution is as follows:
[0006] In a first aspect, this application discloses a network access control method, applied to an access control system, comprising:
[0007] Receive network resource access requests sent by the target client, and determine the trust assessment factors used to assess the trust level of the target client, as well as the current trust score corresponding to each trust assessment factor;
[0008] Determine the target number of accesses corresponding to the current network resource access request, and estimate the coefficient of variation of each of the trust evaluation factors based on the target number of accesses and the current trust score;
[0009] The conflict coefficients of each trust evaluation factor are estimated based on the target number of visits and the current trust score, and the objective weights corresponding to each trust evaluation factor are determined based on the conflict coefficients and the coefficient of variation.
[0010] Obtain the subjective weight corresponding to each trust assessment factor, and merge the subjective weight with the corresponding objective weight to obtain the comprehensive weight of each trust assessment factor; the subjective weight is the weight assigned to different trust assessment factors using the subjective weighting method.
[0011] The total trust score is obtained by summing the products of all the comprehensive weights and the corresponding current trust scores. If the total trust score exceeds a preset threshold, the target client is allowed to access the target network resources. If the total trust score does not exceed the preset threshold, the target client is prohibited from accessing the target network resources.
[0012] Optionally, determining the trust assessment factors used to assess the trust level of the target client, and the current trust score corresponding to each trust assessment factor, includes:
[0013] The access information carried in the network resource access request is matched with a preset database to obtain a matching result; the preset database is used to record the mapping relationship between different access information and corresponding trust evaluation factors and trust scores.
[0014] Based on the matching results, trust assessment factors are determined for assessing the trust level of the target client, and the current trust score corresponding to each trust assessment factor is determined.
[0015] Optionally, estimating the coefficient of variation of each of the trust assessment factors based on the target number of visits and the current trust score includes:
[0016] The historical average value corresponding to the last resource access request is updated using the target access count and the current trust score to obtain the updated average value;
[0017] The historical variance corresponding to the previous resource access request is updated using the target access count, the current trust score, the historical mean, and the updated mean to obtain the updated variance;
[0018] The coefficient of variation of each of the trust assessment factors is estimated based on the updated variance and the updated mean.
[0019] Optionally, estimating the conflict coefficient of each of the trust evaluation factors based on the target number of visits and the current trust score includes:
[0020] The sum of historical trust scores corresponding to the last resource access request is updated using the current trust score corresponding to each of the trust evaluation factors to obtain the updated sum of trust scores.
[0021] The current trust score corresponding to each of the trust evaluation factors is used to update the sum of squared historical trust scores corresponding to the previous resource access request, so as to obtain the updated sum of squared trust scores.
[0022] The current trust score corresponding to any two of the trust evaluation factors is used to update the product sum of the historical trust scores corresponding to the previous resource access request, so as to obtain the updated product sum of trust scores.
[0023] The correlation coefficient between the two trust evaluation factors is calculated based on the sum of the updated trust scores, the sum of squares of the updated trust scores, the sum of products of the updated trust scores, and the target number of visits for any two of the trust evaluation factors.
[0024] The conflict coefficient of the corresponding trust assessment factor is calculated based on all the correlation coefficients corresponding to a single trust assessment factor.
[0025] Optionally, determining the objective weight corresponding to a single trust assessment factor based on the conflict coefficient and the coefficient of variation includes:
[0026] Calculate the product of the conflict coefficient and the coefficient of variation corresponding to a single trust assessment factor to obtain the coefficient product result;
[0027] The objective weight of each trust assessment factor is calculated based on the product of the coefficients corresponding to all the trust assessment factors.
[0028] The formula for calculating the objective weight is:
[0029] ;
[0030] In the formula, This represents the objective weight. This represents the product of the coefficients corresponding to any current trust assessment factor. This represents the product of the coefficients corresponding to the other trust assessment factors.
[0031] Optionally, the formula for calculating the overall weight of a single trust assessment factor is as follows:
[0032] ;
[0033] In the formula, This represents the comprehensive weight corresponding to any current trust assessment factor. This represents the objective weight corresponding to any current trust assessment factor. This represents the subjective weight corresponding to any current trust assessment factor. These are preset parameters;
[0034] Accordingly, the formula for calculating the total trust score is:
[0035] ;
[0036] In the formula, This represents the total trust score. This represents the current trust score corresponding to any current trust assessment factor.
[0037] Optionally, after determining the target number of accesses corresponding to the current network resource access request, the method further includes:
[0038] Determine whether the target access count is 1;
[0039] If the target access count is greater than 1, then the step of estimating the coefficient of variation of each of the trust evaluation factors based on the target access count and the current trust score is triggered;
[0040] If the target number of visits is 1, then obtain the subjective weights corresponding to each of the trust evaluation factors, calculate the sum of the products of all the subjective weights and the corresponding current trust scores to obtain the target trust score, and determine whether the target trust score exceeds a preset threshold.
[0041] If the target trust score exceeds the preset threshold, the target client is allowed to access the target network resources;
[0042] If the target trust score does not exceed the preset threshold, the target client is prohibited from accessing the target network resources.
[0043] Secondly, this application discloses a network access control device, applied to an access control system, comprising:
[0044] The request receiving module is used to receive network resource access requests sent by the target client;
[0045] The first determining module is used to determine the trust assessment factors used to assess the trust level of the target client, and the current trust score corresponding to each trust assessment factor.
[0046] The second determining module is used to determine the target number of accesses corresponding to the current network resource access request;
[0047] The first estimation module is used to estimate the coefficient of variation of each of the trust evaluation factors based on the target number of visits and the current trust score;
[0048] The second estimation module is used to estimate the conflict coefficient of each of the trust evaluation factors based on the target number of visits and the current trust score.
[0049] The third determining module is used to determine the objective weight corresponding to a single trust evaluation factor based on the conflict coefficient and the variation coefficient;
[0050] The first calculation module is used to obtain the subjective weight corresponding to a single trust assessment factor, and to fuse the subjective weight with the corresponding objective weight to obtain the comprehensive weight of the single trust assessment factor; the subjective weight is the weight assigned to different trust assessment factors using the subjective weight method.
[0051] The second calculation module is used to calculate the sum of the products of all the comprehensive weights and the corresponding current trust scores to obtain the total trust score;
[0052] An access control module is configured to allow the target client to access the target network resources if the total trust score exceeds a preset threshold, and to prohibit the target client from accessing the target network resources if the total trust score does not exceed the preset threshold.
[0053] Thirdly, this application discloses an electronic device, including a processor and a memory; wherein, when the processor executes a computer program stored in the memory, it implements the aforementioned network access control method.
[0054] Fourthly, this application discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the aforementioned network access control method.
[0055] As can be seen, this application is applied to an access control system. When a network resource access request is received from a target client, the system first determines the trust evaluation factors used to assess the trust level of the target client, as well as the current trust score corresponding to each trust evaluation factor. Then, it determines the target access count corresponding to the current network resource access request, and estimates the coefficient of variation of each trust evaluation factor based on the target access count and the current trust score. Next, it estimates the conflict coefficient of each trust evaluation factor based on the target access count and the current trust score, and determines the objective weight corresponding to a single trust evaluation factor based on the conflict coefficient and the coefficient of variation. Then, it obtains the subjective weight corresponding to a single trust evaluation factor, and merges the subjective weight with the corresponding objective weight to obtain the comprehensive weight of a single trust evaluation factor. Finally, it calculates the sum of the products of all comprehensive weights and the corresponding current trust scores to obtain the total trust score. If the total trust score exceeds a preset threshold, the target client is allowed to access the target network resource; if the total trust score does not exceed the preset threshold, the target client is prohibited from accessing the target network resource. This application first determines the trust assessment factors and corresponding trust scores used to evaluate the current client. Then, it calculates the coefficient of variation and conflict coefficient of each trust assessment factor based on the number of accesses by the current client to obtain the subjective weight of each factor. The subjective weight and objective weight are then integrated to obtain the comprehensive weight of each factor. That is, the weight of a single factor combines both subjective and objective weights, and the objective weight is dynamically generated in real time based on the coefficient of variation and conflict coefficient. In this way, the importance of the business is taken into account, while the objective distribution of the actual data of different assessment factors is also taken into account. This enables accurate trust assessment of the access subject (i.e., the target client), making the trust assessment results more accurate and thus achieving precise network access control. Attached Figure Description
[0056] To more clearly illustrate the technical solutions in the embodiments of this application or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of this application. For those skilled in the art, other drawings can be obtained based on the provided drawings without creative effort.
[0057] Figure 1 This is a flowchart of a network access control method disclosed in this application;
[0058] Figure 2 This is a flowchart of a specific network access control method disclosed in this application;
[0059] Figure 3This is a schematic diagram of the structure of a network access control device disclosed in this application;
[0060] Figure 4 This is a structural diagram of an electronic device disclosed in this application. Detailed Implementation
[0061] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this application, and not all embodiments. Based on the embodiments of this application, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.
[0062] This application discloses a network access control method, applied to an access control system. See also... Figure 1 As shown, the method includes:
[0063] Step S11: Receive a network resource access request sent by the target client, and determine the trust assessment factors used to assess the trust level of the target client, as well as the current trust score corresponding to each trust assessment factor.
[0064] It should be noted that the network access control scheme proposed in this application is specifically applied to the access control system. When the system receives a network resource access request sent by any client (for example, an employee initiates an access request to the company's human resources system), it can first determine the trust assessment factor for assessing the trust level of the current client based on the access information carried in the access request (such as employee type, employee length of service, type of device used, type of operating system of device, location of access, network connection type, etc.), and then determine the trust score corresponding to each trust assessment factor.
[0065] It should be noted that in network access control scenarios, when trust assessment of the access subject (such as a client) is required, the trust assessment factors involved can typically be divided into three types: user information, device information, and environmental information. Each type of trust assessment factor can also contain multiple sub-assessment factors. User information refers to information about the person initiating the access request and the account they are using, such as user type, user status, account type, and account status. Device information refers to the device information that initiated the access request, such as device type and operating system type. Environmental information refers to the environmental information of the access request initiator and the initiating device, such as geographical location and network type.
[0066] Specifically, determining the trust assessment factors used to evaluate the trust level of the target client, and the current trust score corresponding to each trust assessment factor, may include: matching the access information carried in the network resource access request with a preset database to obtain a matching result; the preset database is used to record the mapping relationship between different access information and the corresponding trust assessment factors and trust scores; and determining the trust assessment factors used to evaluate the trust level of the target client, and the current trust score corresponding to each trust assessment factor, based on the matching result. In a specific implementation, the first trust assessment factor for user information type specifically includes N sub-assessment factors such as user type, user status, user tenure, and account type. When the access control system receives a network resource access request from any client, it first matches the access information carried in the request (such as user type, user status, user tenure, account type, etc.) with the preset database to query the assessment factor (including sub-assessment factors) corresponding to the current access request, and simultaneously queries the value (i.e., trust score) corresponding to each sub-assessment factor. It should be noted that the value (i.e., trust score) corresponding to each sub-assessment factor is a quantified percentage score. For example, for the sub-evaluation factor of user type, if the user type information is a full-time employee, the trust score is 100 after querying; if it is an outsourced employee, the corresponding trust score is 50. For the sub-evaluation factor of user length of service, if the length of service is less than 1 month, the trust score is 20 after querying; if the length of service is more than 5 years, the trust score is set to 100; if the length of service is between 1 month and 5 years, the trust score can increase linearly with the length of service (but not exceeding 100).
[0067] Step S12: Determine the target number of accesses corresponding to the current network resource access request, and estimate the coefficient of variation of each of the trust evaluation factors based on the target number of accesses and the current trust score.
[0068] In this embodiment, after determining the trust assessment factor used by the arc to assess the trust level of the target client and the corresponding current trust score, the number of all network resource access requests initiated by the current target client can be counted to determine the target access count k corresponding to the current network resource access request (that is, how many times the target client initiated the current access request). Then, based on the target access count k and the aforementioned current trust score (denoted as...), (where N is the total number of all sub-evaluation factors under the first trust evaluation factor) Estimate the coefficient of variation (CV, which is a statistic that measures the dispersion of a set of data) for each trust evaluation factor (such as the first trust evaluation factor of user information type, the second trust evaluation factor of device information type, and the third trust evaluation factor of environmental information type).
[0069] Specifically, estimating the coefficient of variation of each trust evaluation factor based on the target access count and the current trust score may include: updating the historical mean corresponding to the previous resource access request using the target access count and the current trust score to obtain an updated mean; updating the historical variance corresponding to the previous resource access request using the target access count, the current trust score, the historical mean, and the updated mean to obtain an updated variance; and estimating the coefficient of variation of each trust evaluation factor based on the updated variance and the updated mean. In this embodiment, the coefficient of variation of each trust evaluation factor can be estimated by iteratively updating the historical mean and historical variance corresponding to the previous resource access request; wherein, the formula for calculating the updated mean is:
[0070] ;
[0071] In the formula, The historical trust score corresponding to the i-th sub-evaluation factor when the target client first initiates a resource access request. This represents the current trust score corresponding to the i-th sub-evaluation factor when the k-th network resource access request is initiated. Let be the historical mean of the i-th sub-evaluation factor when the (k-1)-th network resource access request is initiated (i.e., the previous resource access request). This is the updated mean of the i-th sub-evaluation factor when the k-th network resource access request is initiated.
[0072] In obtaining Then, the historical variance can be updated using the Welford method (an algorithm for calculating the mean and variance of a series) to obtain the updated variance. The specific calculation formula is as follows:
[0073] ;
[0074] In the formula, Let be the historical variance of the i-th sub-evaluation factor when the (k-1)-th network resource access request is initiated (i.e., the previous resource access request). This represents the updated variance of the i-th sub-evaluation factor when the k-th network resource access request is initiated.
[0075] Furthermore, based on the updated variance and the updated mean Estimate the coefficient of variation of the i-th sub-evaluation factor The specific calculation formula is as follows:
[0076] .
[0077] Step S13: Estimate the conflict coefficient of each trust evaluation factor based on the target number of visits and the current trust score, and determine the objective weight corresponding to each trust evaluation factor based on the conflict coefficient and the coefficient of variation.
[0078] In this embodiment, the target number of visits k and the current trust score (such as the trust scores of all sub-evaluation factors under the first trust evaluation factor) can also be used as the basis. ), respectively estimate the conflict coefficient of each trust assessment factor.
[0079] Specifically, estimating the conflict coefficient of each trust evaluation factor based on the target access count and the current trust score may include: updating the sum of historical trust scores corresponding to the previous resource access request using the current trust score corresponding to each trust evaluation factor to obtain an updated sum of trust scores; updating the sum of squares of historical trust scores corresponding to the previous resource access request using the current trust score corresponding to each trust evaluation factor to obtain an updated sum of squares of trust scores; updating the sum of products of historical trust scores corresponding to the previous resource access request using the current trust scores corresponding to any two trust evaluation factors to obtain an updated sum of products of trust scores; calculating the correlation coefficient between the corresponding two trust evaluation factors based on the updated sum of trust scores, the updated sum of squares of trust scores, the updated sum of products of trust scores, and the target access count; and calculating the conflict coefficient of the corresponding trust evaluation factor based on all the correlation coefficients corresponding to a single trust evaluation factor. In this embodiment, the conflict coefficient of each sub-evaluation factor under the trust evaluation factor can be calculated through the following steps: Step 1: Update the sum of historical trust scores and the sum of squared historical trust scores of the i-th sub-evaluation factor in sequence to obtain the updated sum of trust scores and the updated sum of squared trust scores; wherein the formula for calculating the updated sum of trust scores is:
[0080] ;
[0081] In the formula, This is the sum of historical trust scores corresponding to the previous resource access request (i.e., k-1 access requests). This is the sum of trust scores corresponding to the current network resource access requests (i.e., k access requests) (i.e., the sum of updated trust scores).
[0082] Next, the updated sum of squared trust scores is calculated using the following formula:
[0083] ;
[0084] In the formula, This is the sum of squared historical trust scores corresponding to the previous resource access request (i.e., the k-1 access requests). This is the sum of squared trust scores corresponding to the current network resource access requests (i.e., k access requests) (i.e., the updated sum of squared trust scores).
[0085] Step 2: Update the sum of the products of sub-evaluation factor i and all other sub-evaluation factors j. The specific update formula is as follows:
[0086] ;
[0087] In the formula, It is the sum of the products of historical trust scores corresponding to the previous resource access request (i.e., k-1 access requests). It is the sum of the trust scores corresponding to the current network resource access requests (i.e., k access requests) (i.e., the sum of the updated trust scores).
[0088] Step 3: Calculate the correlation coefficient between the current sub-evaluation factor i and all other sub-evaluation factors j. The specific calculation formula is as follows:
[0089] .
[0090] Step 4: Calculate the correlation coefficient between any two sub-evaluation factors to obtain the correlation coefficient matrix:
[0091] .
[0092] Step 5: Based on all correlation coefficients corresponding to each individual sub-evaluation factor i The conflict coefficient of this sub-evaluation factor is calculated using the following formula:
[0093] ;
[0094] In the formula, Indicates the correlation coefficient Take the absolute value. Let be the conflict coefficient of the current i-th sub-evaluation factor.
[0095] Specifically, determining the objective weight corresponding to a single trust evaluation factor based on the conflict coefficient and the coefficient of variation may include: calculating the product of the conflict coefficient and the coefficient of variation corresponding to a single trust evaluation factor to obtain a coefficient product result; and calculating the objective weight of each trust evaluation factor based on the coefficient product results corresponding to all trust evaluation factors. In this embodiment, the conflict coefficient corresponding to the i-th sub-evaluation factor may be calculated first. and the coefficient of variation The product of the coefficients yields the result of the coefficient product. The specific calculation formula is as follows:
[0096] ;
[0097] Next, based on the product of the coefficients of all sub-evaluation factors in the first trust evaluation factor (including... and The objective weight of a single sub-evaluation factor (such as sub-evaluation factor i) is calculated using the following formula:
[0098] ;
[0099] In the formula, This represents the objective weight. This represents the product of the coefficients corresponding to the current sub-evaluation factor i. This represents the product of the coefficients corresponding to the other sub-evaluation factors j.
[0100] Step S14: Obtain the subjective weight corresponding to a single trust assessment factor, and fuse the subjective weight with the corresponding objective weight to obtain the comprehensive weight of the single trust assessment factor; the subjective weight is the weight assigned to different trust assessment factors using the subjective weight method.
[0101] In this embodiment, the subjective weighting method can be used to assign initial weights (i.e., subjective weights) to different sub-evaluation factors. For example, subjective weights can be assigned to N sub-evaluation factors under the first trust evaluation factor. Then subjective weight With the corresponding objective weights The factors are then fused to obtain the combined weight of each trust assessment factor. The specific calculation formula is as follows:
[0102] ;
[0103] In the formula, This represents the comprehensive weight corresponding to the current sub-evaluation factor i. This represents the objective weight corresponding to the current sub-evaluation factor. This represents the subjective weight corresponding to the current sub-evaluation factor i. These are preset parameters;
[0104] Step S15: Calculate the sum of the products of all the comprehensive weights and the corresponding current trust scores to obtain the total trust score. If the total trust score exceeds a preset threshold, the target client is allowed to access the target network resources. If the total trust score does not exceed the preset threshold, the target client is prohibited from accessing the target network resources.
[0105] In this embodiment, the total trust score corresponding to the N sub-evaluation factors under each trust evaluation factor can be calculated first. The specific calculation formula is as follows:
[0106] ;
[0107] In the formula, This represents the total trust score. This represents the current trust score corresponding to the current sub-evaluation factor i.
[0108] Similarly, the same processing procedure is applied to the second trust assessment factor (i.e., the assessment factor for device information type) and the third trust assessment factor (i.e., the assessment factor for environmental information type) to obtain the total trust score corresponding to each trust assessment factor. Then, the three total trust scores are integrated (using the same weighted fusion method as this solution, i.e., dynamically generating corresponding weights for different trust assessment factors using a combination of subjective and objective weighting methods). Finally, an integrated total trust score is obtained. Then, it is determined whether the total trust score exceeds a preset threshold, for example, whether it exceeds the trust score threshold required to access the human resources system. If so, the resource access request is allowed; otherwise, it is rejected. The target network resources for access include, but are not limited to, files, folders, websites, etc.
[0109] It is understandable that the above example uses network access control with two levels of evaluation factors. If there are more levels, the same authorization rules can be used for access control operations at each level.
[0110] By using the above-mentioned online adaptive update method, the weights of each evaluation factor can be automatically updated based on changes in the distribution of evaluation factor data in various aspects of users, devices, and environment (such as changes in organizational personnel information, device iteration updates, device access system installation and uninstallation, etc.). This makes the distribution of evaluation factor data closer to the actual distribution in the operating environment, resulting in more accurate trust evaluation results and thus improving the precision of network access control.
[0111] As can be seen, the embodiments of this application first determine the trust assessment factors and corresponding trust scores used to evaluate the current client, and then calculate the coefficient of variation and conflict coefficient of each trust assessment factor in combination with the number of accesses of the current client to obtain the subjective weight of a single factor. Then, the subjective weight and the objective weight are integrated to obtain the comprehensive weight of a single factor. That is, the weight of a single factor combines both subjective and objective weights, and the objective weight is dynamically generated in real time based on the coefficient of variation and the conflict coefficient. In this way, the importance of the business is taken into account, while the objective distribution of the actual data of different assessment factors is also taken into account. This enables accurate trust assessment of the access subject (i.e., the target client), making the trust assessment results more accurate, thereby achieving precise network access control.
[0112] This application discloses a specific network access control method, applied to an access control system. See also... Figure 2 As shown, the method includes:
[0113] Step S21: Receive a network resource access request sent by the target client, and determine the trust assessment factors used to assess the trust level of the target client, as well as the current trust score corresponding to each trust assessment factor.
[0114] Step S22: Determine the target access count corresponding to the current network resource access request, and determine whether the target access count is 1.
[0115] In this embodiment, after determining the target access count k corresponding to the current network resource access request, it is determined whether the target access count k is 1.
[0116] Step S23: If the target access count is 1, obtain the subjective weights corresponding to each trust evaluation factor, calculate the sum of the products of all subjective weights and the corresponding current trust scores to obtain the target trust score, and determine whether the target trust score exceeds a preset threshold.
[0117] In this embodiment, if the target number of visits k=1, the trust score corresponding to each sub-evaluation factor i can be directly calculated using subjective weights. The specific calculation formula is as follows:
[0118] ;
[0119] In the formula, This represents the subjective weight corresponding to the current sub-evaluation factor i (i.e. (any weight in the)
[0120] Next, the trust scores corresponding to all sub-evaluation factors i are calculated. The scores are accumulated to obtain a target trust score, and then it is determined whether the target trust score exceeds a preset threshold. It should be noted that if the target number of visits k ≠ 1, the process can directly jump to step S12 above.
[0121] Step S24: If the target trust score exceeds the preset threshold, the target client is allowed to access the target network resources.
[0122] Step S25: If the target trust score does not exceed the preset threshold, then the target client is prohibited from accessing the target network resources.
[0123] For more detailed processing procedures of steps S21, S24, and S25, please refer to the corresponding content disclosed in the foregoing embodiments, which will not be repeated here.
[0124] As can be seen, when receiving a network resource access request, this application embodiment will adopt different access control strategies based on the number of times the current network resource access request has been initiated. If it is the first access, the subjective weighting method will be used to calculate the trust score directly. If it is not the first access, the subjective weighting method and the objective weighting method will be used for access control. This takes into account both the importance of the business and the actual data distribution of different factors, making the trust assessment results more accurate and thus improving the accuracy of network access control.
[0125] Accordingly, this application also discloses a network access control device, applied to an access control system, see [link to relevant documentation]. Figure 3 As shown, the device includes:
[0126] Request receiving module 11 is used to receive network resource access requests sent by the target client;
[0127] The first determining module 12 is used to determine the trust assessment factors used to assess the trust level of the target client, and the current trust score corresponding to each trust assessment factor;
[0128] The second determining module 13 is used to determine the target number of accesses corresponding to the current network resource access request;
[0129] The first estimation module 14 is used to estimate the coefficient of variation of each of the trust evaluation factors based on the target number of visits and the current trust score;
[0130] The second estimation module 15 is used to estimate the conflict coefficient of each of the trust evaluation factors based on the target number of visits and the current trust score.
[0131] The third determining module 16 is used to determine the objective weight corresponding to a single trust evaluation factor based on the conflict coefficient and the variation coefficient.
[0132] The first calculation module 17 is used to obtain the subjective weight corresponding to a single trust assessment factor, and to fuse the subjective weight with the corresponding objective weight to obtain the comprehensive weight of the single trust assessment factor; the subjective weight is the weight assigned to different trust assessment factors using the subjective weight method.
[0133] The second calculation module 18 is used to calculate the sum of the products of all the comprehensive weights and the corresponding current trust scores to obtain the total trust score;
[0134] Access control module 19 is configured to allow the target client to access the target network resources if the total trust score exceeds a preset threshold, and to prohibit the target client from accessing the target network resources if the total trust score does not exceed the preset threshold.
[0135] The specific workflow of each of the above modules can be found in the relevant content disclosed in the foregoing embodiments, and will not be repeated here.
[0136] As can be seen, in this embodiment, the trust assessment factors and corresponding trust scores for evaluating the current client are first determined. Then, the coefficient of variation and conflict coefficient of each trust assessment factor are calculated in combination with the number of accesses of the current client to obtain the subjective weight of a single factor. Then, the subjective weight and the objective weight are fused to obtain the comprehensive weight of a single factor. That is, the weight of a single factor combines both subjective and objective weights, and the objective weight is dynamically generated in real time based on the coefficient of variation and the conflict coefficient. In this way, the importance of the business is taken into account, while the objective distribution of the actual data of different assessment factors is also taken into account. This enables accurate trust assessment of the access subject (i.e., the target client), making the trust assessment results more accurate, thereby achieving precise network access control.
[0137] Furthermore, embodiments of this application also disclose an electronic device, Figure 4 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content of the diagram should not be construed as limiting the scope of this application.
[0138] Figure 4This is a schematic diagram of the structure of an electronic device 20 provided in an embodiment of this application. Specifically, the electronic device 20 may include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 stores a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the network access control method disclosed in any of the foregoing embodiments. Furthermore, the electronic device 20 in this embodiment may specifically be an electronic computer.
[0139] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and external devices, and the communication protocol it follows can be any communication protocol applicable to the technical solution of this application, and is not specifically limited here; the input / output interface 25 is used to acquire external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs, and is not specifically limited here.
[0140] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or optical disk, etc. The resources stored thereon can include operating system 221, computer program 222, etc., and the storage method can be temporary storage or permanent storage.
[0141] The operating system 221 is used to manage and control the various hardware devices on the electronic device 20 and the computer program 222, which may be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program capable of performing the network access control method executed by the electronic device 20 as disclosed in any of the foregoing embodiments, the computer program 222 may further include a computer program capable of performing other specific tasks.
[0142] Furthermore, this application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, it implements the aforementioned network access control method. Specific steps of this method can be found in the corresponding content disclosed in the foregoing embodiments, and will not be repeated here.
[0143] Furthermore, embodiments of this application also disclose a computer program product, including a computer program / instructions, which, when executed by a processor, implement the steps of the network access control method disclosed above.
[0144] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from other embodiments. Similar or identical parts between embodiments can be referred to interchangeably. For the apparatus disclosed in the embodiments, since it corresponds to the method disclosed in the embodiments, the description is relatively simple; relevant parts can be referred to in the method section.
[0145] Those skilled in the art will further recognize that the units and algorithm steps of the various examples described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the components and steps of the various examples have been generally described in terms of functionality in the foregoing description. Whether these functions are implemented in hardware or software depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0146] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein can be implemented directly by hardware, a software module executed by a processor, or a combination of both. The software module can be located in random access memory (RAM), main memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium known in the art.
[0147] Finally, it should be noted that in this document, relational terms such as "first" and "second" are used only to distinguish one entity or operation from another, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Furthermore, the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitations, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0148] The foregoing has provided a detailed description of a network access control method, apparatus, device, and storage medium provided in this application. Specific examples have been used to illustrate the principles and implementation methods of this application. The descriptions of the above embodiments are only for the purpose of helping to understand the method and core ideas of this application. At the same time, for those skilled in the art, there will be changes in the specific implementation methods and application scope based on the ideas of this application. Therefore, the content of this specification should not be construed as a limitation of this application.
Claims
1. A network access control method, characterized in that, Applied to access control systems, including: Receive network resource access requests sent by the target client, and determine the trust assessment factors used to assess the trust level of the target client, as well as the current trust score corresponding to each trust assessment factor; Determine the target number of accesses corresponding to the current network resource access request, and estimate the coefficient of variation of each of the trust evaluation factors based on the target number of accesses and the current trust score; The conflict coefficients of each trust evaluation factor are estimated based on the target number of visits and the current trust score, and the objective weights corresponding to each trust evaluation factor are determined based on the conflict coefficients and the coefficient of variation. Obtain the subjective weight corresponding to each trust assessment factor, and merge the subjective weight with the corresponding objective weight to obtain the comprehensive weight of each trust assessment factor; the subjective weight is the weight assigned to different trust assessment factors using the subjective weighting method. The total trust score is obtained by summing the products of all the comprehensive weights and the corresponding current trust scores. If the total trust score exceeds a preset threshold, the target client is allowed to access the target network resources. If the total trust score does not exceed the preset threshold, the target client is prohibited from accessing the target network resources.
2. The network access control method according to claim 1, characterized in that, The step of determining the trust assessment factors used to assess the trust level of the target client, and the current trust score corresponding to each trust assessment factor, includes: The access information carried in the network resource access request is matched with a preset database to obtain a matching result; the preset database is used to record the mapping relationship between different access information and corresponding trust evaluation factors and trust scores. Based on the matching results, trust assessment factors are determined for assessing the trust level of the target client, and the current trust score corresponding to each trust assessment factor is determined.
3. The network access control method according to claim 1, characterized in that, The estimation of the coefficient of variation of each of the trust assessment factors based on the target number of visits and the current trust score includes: The historical average value corresponding to the last resource access request is updated using the target access count and the current trust score to obtain the updated average value; The historical variance corresponding to the previous resource access request is updated using the target access count, the current trust score, the historical mean, and the updated mean to obtain the updated variance; The coefficient of variation of each of the trust assessment factors is estimated based on the updated variance and the updated mean.
4. The network access control method according to claim 3, characterized in that, The step of estimating the conflict coefficients of each of the trust assessment factors based on the target number of visits and the current trust score includes: The sum of historical trust scores corresponding to the last resource access request is updated using the current trust score corresponding to each of the trust evaluation factors to obtain the updated sum of trust scores. The current trust score corresponding to each of the trust evaluation factors is used to update the sum of squared historical trust scores corresponding to the previous resource access request, so as to obtain the updated sum of squared trust scores. The current trust score corresponding to any two of the trust evaluation factors is used to update the product sum of the historical trust scores corresponding to the previous resource access request, so as to obtain the updated product sum of trust scores. The correlation coefficient between the two trust evaluation factors is calculated based on the sum of the updated trust scores, the sum of squares of the updated trust scores, the sum of products of the updated trust scores, and the target number of visits for any two of the trust evaluation factors. The conflict coefficient of the corresponding trust assessment factor is calculated based on all the correlation coefficients corresponding to a single trust assessment factor.
5. The network access control method according to claim 4, characterized in that, The determination of the objective weight corresponding to a single trust assessment factor based on the conflict coefficient and the coefficient of variation includes: Calculate the product of the conflict coefficient and the coefficient of variation corresponding to a single trust assessment factor to obtain the coefficient product result; The objective weight of each trust assessment factor is calculated based on the product of the coefficients corresponding to all the trust assessment factors. The formula for calculating the objective weight is: ; In the formula, This represents the objective weight. This represents the product of the coefficients corresponding to any current trust assessment factor. This represents the product of the coefficients corresponding to the other trust assessment factors.
6. The network access control method according to claim 5, characterized in that, The formula for calculating the overall weight of each trust assessment factor is as follows: ; In the formula, This represents the comprehensive weight corresponding to any current trust assessment factor. This represents the objective weight corresponding to any current trust assessment factor. This represents the subjective weight corresponding to any current trust assessment factor. These are preset parameters; Accordingly, the formula for calculating the total trust score is: ; In the formula, This represents the total trust score. This represents the current trust score corresponding to any current trust assessment factor.
7. The network access control method according to any one of claims 1 to 6, characterized in that, After determining the target number of accesses corresponding to the current network resource access request, the method further includes: Determine whether the target access count is 1; If the target access count is greater than 1, then the step of estimating the coefficient of variation of each of the trust evaluation factors based on the target access count and the current trust score is triggered; If the target number of visits is 1, then obtain the subjective weights corresponding to each of the trust evaluation factors, calculate the sum of the products of all the subjective weights and the corresponding current trust scores to obtain the target trust score, and determine whether the target trust score exceeds a preset threshold. If the target trust score exceeds the preset threshold, the target client is allowed to access the target network resources; If the target trust score does not exceed the preset threshold, the target client is prohibited from accessing the target network resources.
8. A network access control device, characterized in that, Applied to access control systems, including: The request receiving module is used to receive network resource access requests sent by the target client; The first determining module is used to determine the trust assessment factors used to assess the trust level of the target client, and the current trust score corresponding to each trust assessment factor. The second determining module is used to determine the target number of accesses corresponding to the current network resource access request; The first estimation module is used to estimate the coefficient of variation of each of the trust evaluation factors based on the target number of visits and the current trust score; The second estimation module is used to estimate the conflict coefficient of each of the trust evaluation factors based on the target number of visits and the current trust score. The third determining module is used to determine the objective weight corresponding to a single trust evaluation factor based on the conflict coefficient and the variation coefficient; The first calculation module is used to obtain the subjective weight corresponding to a single trust assessment factor, and to fuse the subjective weight with the corresponding objective weight to obtain the comprehensive weight of the single trust assessment factor; the subjective weight is the weight assigned to different trust assessment factors using the subjective weight method. The second calculation module is used to calculate the sum of the products of all the comprehensive weights and the corresponding current trust scores to obtain the total trust score; An access control module is configured to allow the target client to access the target network resources if the total trust score exceeds a preset threshold, and to prohibit the target client from accessing the target network resources if the total trust score does not exceed the preset threshold.
9. An electronic device, characterized in that, It includes a processor and a memory; wherein, when the processor executes a computer program stored in the memory, it implements the network access control method as described in any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that, Used to store computer programs; wherein, when the computer programs are executed by a processor, they implement the network access control method as described in any one of claims 1 to 7.
Citation Information
Patent Citations
Network access control method and device, equipment and storage medium
CN121193538A