Automated and hierarchical trusted cloud level management unit system and method
By constructing an automated and hierarchical trusted cloud level management unit system, the problems of insufficient unit robustness, lagging level assessment, and policy execution deviation in trusted cloud management are solved. It realizes full-process automated governance, improves the real-time and accuracy of security management, adapts to new threats, and improves configuration efficiency.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- WUHAN TRUSTED CLOUD TECH CO LTD
- Filing Date
- 2026-02-02
- Publication Date
- 2026-04-21
AI Technical Summary
The existing trusted cloud management system suffers from insufficient unit robustness, lagging level assessment, policy execution deviation, low verification efficiency, and weak adaptability to new threats, resulting in insufficient automation, precision, and trustworthiness in security management.
The system adopts an automated and hierarchical trusted cloud level management unit system, including an autonomous configuration module, an automated operation module, an adaptive decision-making module, and a hierarchical governance module. By building robust autonomous units, real-time monitoring, dynamic level recalculation, product portfolio optimization, and policy verification optimization, it achieves fully automated governance throughout the entire process.
It has achieved fully automated management and control of the trusted cloud unit, improved the real-time and accuracy of security level management, enhanced the adaptability to new threats, reduced security vulnerabilities caused by policy conflicts, and improved configuration efficiency.
Smart Images

Figure CN121616244B_ABST
Abstract
Description
Technical Field
[0001] This invention belongs to the field of trusted cloud technology, specifically an automated and hierarchical trusted cloud level management unit system and method. Background Technology
[0002] With the deep application of cloud computing in sensitive fields such as finance and government, the security level management of trusted clouds has become a core requirement for ensuring data security and service compliance. However, the current trusted cloud management system has many pain points that urgently need to be addressed. In the trusted unit configuration stage, traditional methods rely heavily on manual setting of resources and policies, often resulting in issues such as units depending on uncertain external resources and conflicting security policy logic, leading to insufficient robustness of trusted units and creating hidden dangers for subsequent security management. Regarding level assessment, mainstream solutions adopt a static level classification model, which cannot monitor key indicators such as software integrity and trust chain status of trusted units in real time. When faced with sudden security events such as component intrusion and unauthorized configuration changes, level updates are lagging, making it difficult to accurately reflect the real-time security status of units. At the governance level, cross-level policy execution is prone to a "hot at the top, cold at the bottom" phenomenon, making it difficult for global policies to effectively penetrate to the underlying units, and lacking a sound execution status feedback and fault compensation mechanism, resulting in significant policy execution deviations. Furthermore, the policy verification stage often adopts a full-scale verification model, failing to distinguish the conflict risk differences of trusted units of different related types, leading to low verification efficiency and serious resource waste. At the same time, the system's adaptability to new threats such as post-quantum cryptography is weak, making it difficult to meet diverse security needs. These issues collectively constrain the level of automation, precision, and trustworthiness in trusted cloud management.
[0003] To this end, the present invention provides an automated and hierarchical trusted cloud level management unit system and method. Summary of the Invention
[0004] In order to overcome the shortcomings of the prior art, at least one technical problem raised in the background art is solved.
[0005] The technical solution adopted by this invention to solve its technical problem is: an automated and hierarchical trusted cloud level management unit system, comprising the following modules:
[0006] Autonomous Configuration Module: Used to activate the three principles of autonomy configuration by receiving instructions from the administrator to the TCDMU, build a robust autonomous unit TCDUN, and wait for the automated operation module to take over;
[0007] The automated operation module is used to continuously monitor the robust autonomous units (TCDUNs) under its control, determine whether to trigger the dynamic level recalculation of TCDUNs based on the monitoring results, and execute the dynamic level recalculation when triggered. It is also used to generate trusted status reports in response to remote proof requests.
[0008] Adaptive decision module: It is used to extract security dimension requirements based on input, map the level requirements of the three dimensions, find product combinations that meet the requirements based on the mapping results, and also to adaptively optimize the weights of products with quantum cryptography resistance.
[0009] Hierarchical governance module: used to realize a complete automated governance cycle based on the global policies issued by the upper-level TCDMU, the policies received by the lower-level TCDMU and penetrated to the TCDSU, and the execution status reporting and compensation mechanism.
[0010] As a further technical solution of the present invention, the Trusted Cloud Level Management Unit System also includes:
[0011] Configuration verification analysis module: acquires historical verification data of configuration policies, and through conflict frequency analysis of each historical configuration verification event, identifies non-mandatory verification TCDUN association types and mandatory verification TCDUN association types of configuration policies, and performs verification filtering on configuration policies;
[0012] Configuration verification priority analysis module: After the configuration policy performs verification filtering, based on the required verification TCDUN association type of the configuration policy, it constructs a table of required verification configuration policies under each TCDUN association type, and sorts the configuration policies in the table of required verification configuration policies for each TCDUN association type.
[0013] Configuration verification module: Based on the association type between TCDUNs constructed by the autonomous configuration module, when performing configuration policy verification, the configuration policy is verified according to the sorted list of mandatory verification configuration policies corresponding to the TCDUN association type.
[0014] As a further technical solution of the present invention, the process of constructing the robust autonomous unit TCDUN includes:
[0015] The administrator issues a command to the TCDMU, which activates the autonomous configuration module inside the TCDUN to perform the three principles of autonomy configuration. These include: configuring strict logical isolation boundaries for the TCDUN, allocating all the hardware and software resources required for the TCDUN to run, and performing formal verification before the final application configuration to ensure that the internal logic of the policy is consistent and conflict-free. Only then will the final configuration be submitted, outputting a successfully constructed, robust autonomous unit TCDUN that satisfies the three principles of autonomy.
[0016] A further technical solution of the present invention is as follows: The process of determining whether TCDUN dynamic level recalculation is triggered and performing dynamic level recalculation when triggered is as follows:
[0017] The Integrity Continuous Monitoring Unit in the Automated Operations Module continuously collects internal status data from the TCDUN.
[0018] If the monitoring unit detects a negative security event that disrupts the trust chain, it triggers a dynamic recalculation of the TCDUN security level. The negative security event is reported to the dynamic level calculation unit in the automated operation module, and the real-time security level of the TCDUN is recalculated based on the security model preset in the dynamic level calculation unit.
[0019] As a further technical solution of the present invention, the process of generating a trusted state report in response to a remote proof request is as follows:
[0020] When a remote verification request is received from an external audit system or user, the automated operations module obtains the latest real-time security level derived by the dynamic level calculation unit and generates a trusted report. The report includes at least: the current macro security level of the TCDUN, the micro security levels of all TCDSUs within it, the key metrics that led to the current level, and a digital signature of the report using the TCDMU's private key.
[0021] As a further technical solution of the present invention, the process of finding a product combination that meets the needs is as follows:
[0022] The adaptive decision-making module performs natural language parsing or data formatting on the input, extracts key security dimension requirements, maps these key security dimension requirements to level requirements for the three dimensions, and then finds the product combination with the highest comprehensive score and best meeting the requirements in the 3D security matrix.
[0023] As a further technical solution of the present invention, the process of identifying the non-mandatory verification TCDUN association type and the mandatory verification TCDUN association type of the configuration strategy is as follows:
[0024] Based on any type of configuration strategy;
[0025] Extract historical configuration verification events for configuration policies under different TCDUN association types;
[0026] If the historical verification result of a historical configuration verification event under the TCDUN association type is a conflict, then the historical configuration verification event will be marked as a conflict verification event.
[0027] The frequency of occurrence of statistical conflict verification events in historical configuration verification events is used to obtain the conflict performance value of the TCDUN association type;
[0028] If the conflict performance value is greater than or equal to the conflict performance threshold, the TCDUN association type is marked as a mandatory TCDUN association type for the configuration policy; otherwise, the TCDUN association type is marked as a non-mandatory TCDUN association type for the configuration policy.
[0029] A further technical solution of the present invention is as follows: the process of verifying and screening the configuration strategy is as follows:
[0030] If the configuration policy does not have any TCDUN association type that must be verified, the configuration policy will be filtered out and no configuration policy verification will be performed.
[0031] If at least one of the configuration policies requires verification of the TCDUN association type, then the configuration policy will be filtered and retained for verification.
[0032] As a further technical solution of the present invention, the process of constructing the mandatory verification configuration strategy table under each TCDUN association type is as follows:
[0033] Based on any TCDUN association type;
[0034] If the TCDUN association type is "Configuration policy must verify TCDUN association type", then mark the configuration policy as "Configuration policy must be verified".
[0035] Iterate through all the verification filtering configuration policies, summarize all the mandatory verification configuration policies, and obtain the mandatory verification configuration policy table under the TCDUN related type.
[0036] The configuration policies in the configuration policy table that must be verified are sorted in descending order of conflict performance value.
[0037] An automated and hierarchical approach to trusted cloud level management includes the following methods:
[0038] Step 1: Activate the three principles of autonomy configuration by receiving instructions from the administrator to the TCDMU, build a robust autonomous unit TCDUN, and wait for the automated operation module to take over;
[0039] This involves acquiring historical verification data for configuration policies, analyzing the conflict frequency of each historical configuration verification event to identify non-mandatory and mandatory TCDUN association types for configuration policies, and then filtering the configuration policies for verification.
[0040] After the configuration policy is verified and filtered, a table of mandatory verification configuration policies is constructed for each TCDUN association type based on the mandatory verification TCDUN association type of the configuration policy, and the configuration policies in the table of mandatory verification configuration policies for each TCDUN association type are sorted.
[0041] Based on the association type between TCDUNs constructed by the autonomous configuration module, when performing configuration policy verification, the configuration policy is verified according to the sorted table of mandatory verification configuration policies corresponding to the TCDUN association type.
[0042] Step 2: Continuously monitor the robust autonomous unit TCDUN under its control, and determine whether to trigger the TCDUN dynamic level recalculation based on the monitoring results. If triggered, perform the dynamic level recalculation and generate a trusted status report in response to the remote proof request.
[0043] Step 3: Extract security dimension requirements based on the input, map the level requirements of the three dimensions, find product combinations that meet the requirements based on the mapping results, and adaptively optimize the weights of products with quantum cryptography resistance.
[0044] Step 4: Based on the global policy issued by the superior TCDMU, the policy received by the subordinate TCDMU and penetrated to the TCDSU, and the execution status reporting and compensation mechanism, a complete automated governance cycle is achieved.
[0045] The beneficial effects of this invention are as follows:
[0046] 1. The Autonomous Configuration Module constructs the TCDUN based on three principles: isolation, resource configuration, and policy verification to ensure unit robustness and lay the foundation for graded management. The Automated Operations Module monitors and dynamically recalculates security levels in real time, addressing the shortcomings of static assessments, and the trusted reports from digital signatures ensure the authority of remote proof. The Adaptive Decision-Making Module matches requirements and products using a three-dimensional security matrix and combines quantum-resistant cryptographic weight optimization to improve threat adaptability. The Hierarchical Governance Module forms a closed loop for policy distribution, execution, and reporting, solving cross-level management issues. Ultimately, it achieves fully automated control of the Trusted Cloud Unit, providing security support for sensitive data processing and compliance scenarios.
[0047] 2. By employing data-driven verification optimization logic, the security and efficiency of the trusted unit configuration phase are improved. This solution leverages historical verification data of configuration strategies to analyze the conflict frequency of different TCDUN association types, accurately distinguishing between mandatory and non-mandatory verification types, filtering out low-risk strategies to avoid invalid verification and reduce system resource consumption. Simultaneously, high-risk strategies are sorted according to their conflict performance values, prioritizing verification for critical strategies with high conflict probabilities and reducing security vulnerabilities caused by strategy conflicts. This optimization retains the rigor of the formal policy verification in Example 1 while resolving the process redundancy issue of full-scale verification, ensuring that TCDUN configuration meets security requirements while improving configuration efficiency, providing more efficient support for large-scale, multi-type trusted cloud unit deployment scenarios. Attached Figure Description
[0048] The invention will now be further described with reference to the accompanying drawings.
[0049] Figure 1 This is a flowchart of the automated and hierarchical trusted cloud level management unit system described in the embodiments of the present invention;
[0050] Figure 2This is a flowchart illustrating the steps of the automated and hierarchical trusted cloud level management method described in this embodiment of the invention.
[0051] Figure 3 This is a flowchart illustrating the steps of configuring resource verification in the construction of the Autonomous Unit TCDUN in the automated and hierarchical trusted cloud level management method described in this embodiment of the invention. Detailed Implementation
[0052] To make the technical means, creative features, objectives and effects of this invention easier to understand, the invention will be further described below in conjunction with specific embodiments.
[0053] Example 1: Please refer to Figure 1 As shown in the embodiment of the present invention, the automated and hierarchical trusted cloud level management unit system includes the following modules:
[0054] Autonomous Configuration Module: Used to activate the three principles of autonomy configuration by receiving instructions from the administrator to the TCDMU, build a robust autonomous unit TCDUN, and wait for the automated operation module to take over;
[0055] In the autonomous configuration module, the process of building a robust autonomous unit (TCDUN) includes:
[0056] A1, Receive management instructions:
[0057] Input: The administrator issues a command to the TCDMU, such as: "Create a Trusted Cloud Unit (TCDUN) with a security level of 4 on server A";
[0058] Trigger: The command will activate the autonomous configuration module inside TCDMU to execute the three principles of autonomy configuration;
[0059] A2, Configuration based on the three principles of autonomy:
[0060] A21, configure isolation policies to ensure "independence";
[0061] Action: Configure strict logical isolation boundaries for TCDUN.
[0062] The specific process involves: allocating independent VLANs, configuring dedicated firewall rules, and setting up virtualization-level resource isolation (such as cgroups and namespaces) to ensure that TCDUN does not interfere with the host machine and other tenant units during operation, forming an independent logical entity.
[0063] A22, Configure all necessary resources to ensure "self-containment";
[0064] Action: Allocate all the hardware and software resources required for TCDUN to run.
[0065] The specific process involves allocating dedicated CPU cores, memory blocks, and storage space. Simultaneously, a complete, digitally signed, verified base operating system image, necessary security toolkits, and initial policy files are loaded to ensure the unit can operate independently without relying on uncertain external resources.
[0066] A23, validate all strategies to ensure "self-consistency";
[0067] Action: Before final application configuration, perform formal verification to ensure that the internal logic of the strategy is consistent and conflict-free.
[0068] The specific process involves invoking the built-in TCDT (Trusted Cloud Level Theory) theoretical verification engine. This engine, based on the axioms and theorems of Trusted Cloud Level Theory (TCDT) (such as the isolation axiom A5), performs automated logical reasoning and consistency verification on all configurations to be deployed (such as firewall rules and access control lists) to ensure that they are compatible with each other and conform to the security model.
[0069] A3. After completing A1-A2, the configuration will be finally committed, outputting a robust autonomous unit TCDUN that has been successfully built and meets the three principles of autonomy. Its initial state is set to the security level required by the instruction (such as level 4), and it enters the ready state, waiting to be taken over by the automated operation engine.
[0070] The automated operation module is used to continuously monitor the robust autonomous units (TCDUNs) under its control, determine whether to trigger the dynamic level recalculation of TCDUNs based on the monitoring results, and execute the dynamic level recalculation when triggered. It is also used to generate trusted status reports in response to remote proof requests.
[0071] In the automated operations module, the process of continuously monitoring the robust autonomous unit TCDUN that has been taken over is as follows:
[0072] The Integrity Continuous Monitoring Unit in the Automated Operations Module continuously collects internal status data from TCDUN. The monitoring content includes, but is not limited to: software integrity (such as whether the kernel and executable files of critical applications have been tampered with), trust chain status (such as whether the metric value from the root trust TCDR to the kernel TCDKN has changed), resource usage, security event logs, etc.
[0073] In the automated operations module, the process of determining whether to trigger a TCDUN dynamic level recalculation is as follows:
[0074] If the monitoring unit detects a negative security event that breaks the chain of trust (e.g., loading an unsigned application, detecting unauthorized configuration changes, or intrusion into a core component), it will trigger a dynamic recalculation of the TCDUN level.
[0075] If the monitoring unit detects a negative security event that breaks the chain of trust (e.g., loading an unsigned application, detecting unauthorized configuration changes, or intrusion into core components), it will continue to monitor continuously.
[0076] In the automated operations module, the process of performing dynamic level recalculation is as follows:
[0077] Negative security events will be reported to the dynamic level calculation unit in the automated operation module, and the real-time security level of TCDUN will be recalculated according to the security model (such as SBEC model or min model) preset in the dynamic level calculation unit. For example, if the root of trust (TCDR) and kernel (TCDKN) are degraded to level 1 due to contamination, then no matter how high the level of other components is, the overall level will be recalculated to level 1.
[0078] In the automated operations module, the process of generating a trusted status report in response to a remote proof request is as follows:
[0079] Upon receiving a remote verification request from an external audit system or user, the automated operations module obtains the latest real-time security level (rather than the static configuration level) derived by the dynamic level calculation unit and generates a trust report, which includes at least:
[0080] Current macro-level security level of TCDUN;
[0081] The micro-level safety of all TCDSUs within it;
[0082] Key metrics that lead to the current level (such as PCR value);
[0083] The report is digitally signed using the TCDMU's private key.
[0084] Adaptive decision module: It is used to extract security dimension requirements based on input, map the level requirements of the three dimensions, find product combinations that meet the requirements based on the mapping results, and also to adaptively optimize the weights of products with quantum cryptography resistance.
[0085] In the adaptive decision-making module, the input refers to the service requirements submitted by the user (such as "an environment that needs to process sensitive financial keys and complies with GDPR") or the real-time threat intelligence received by the system (such as "a new type of post-quantum cryptographic attack has been discovered").
[0086] In the adaptive decision-making module, the process of finding a product combination that meets the requirements is as follows:
[0087] The adaptive decision-making module performs natural language parsing or data formatting on the input, extracts key security dimension requirements, maps these requirements to level requirements for the three dimensions, and then searches for the product combination with the highest comprehensive score and best meeting the requirements in the 3D security matrix (for example, recommending "TCDIS4 (TEE confidential computing) + TCDR5 (Hardware Security Module HSM)").
[0088] The 3D security matrix has already provided quantitative scores for various security products and services across three dimensions:
[0089] Security dimensions typically refer to integrity, availability, and tamper resistance.
[0090] Confidentiality dimension: refers to data confidentiality, such as whether TEE (Trusted Execution Environment) is supported;
[0091] Privacy dimension: refers to data compliance and anonymization capabilities;
[0092] In the adaptive decision-making module, the weight adaptive optimization process for products with quantum cryptography resistance is as follows:
[0093] Upon receiving intelligence about "post-quantum cryptography threats," the adaptive decision-making module automatically increases the weight of products or configurations in the matrix that possess quantum cryptography resistance properties. This ensures that in the next matching process, these products, which are better suited to the current threat environment, will receive a higher recommendation priority, thereby achieving adaptive optimization of the model.
[0094] Hierarchical governance module: used to realize a complete automated governance cycle based on the global policies issued by the upper-level TCDMU, the policies received by the lower-level TCDMU and penetrated to the TCDSU, and the execution status reporting and compensation mechanism;
[0095] In the hierarchical governance module, the specific process of the upper-level TCDMU issuing global policies is as follows:
[0096] Triggering condition: A global security policy is formulated or received by the top-level (e.g., facility-level) TCDMU;
[0097] For example, "all units carrying DSL4 (extremely confidential) data must have an internal isolation level of 4 (i.e., they must run in a TEE)";
[0098] Specific process: The superior TCDMU issues policy instructions to all subordinate TCDMUs under its jurisdiction through a secure and verifiable management channel;
[0099] In the hierarchical governance module, the process by which the lower-level TCDMU receives and penetrates to the TCDSU policy is as follows:
[0100] Reception and parsing: The lower-level (local) TCDMU receives instructions, and its hierarchical governance engine parses the global policy.
[0101] Strategy penetration:
[0102] The engine queries its list of assets under its jurisdiction to identify all TCDUNs and their internal TCDSUs affected by the policy.
[0103] The specific process involves translating abstract global policies into executable instructions specific to a particular TCDSU. For example, "promote to TEE level" is transformed into a concrete command to "migrate the virtual machine [TCDSU-ID] to a physical node that supports Intel TDX in real time."
[0104] In the hierarchical governance module, the process of execution status reporting and compensation mechanism is as follows:
[0105] Successful execution: The subordinate TCDMU successfully executes the instruction (such as completing the migration) by calling its automated operations engine, and reports the "execution successful" status to the superior through the management channel.
[0106] Execution failure and compensation:
[0107] Failure scenario: The lower-level TCDMU discovers that the local hardware does not support TEE and cannot execute the migration command.
[0108] Specific process:
[0109] It immediately reports "execution failed" to its superiors, along with detailed reasons (such as "insufficient hardware capabilities").
[0110] Upon receiving a failure report, the governance engine of the parent TCDMU automatically triggers a preset compensation strategy, such as:
[0111] Strategy A: Migrate the TCDSU to another downstream node with TEE capability.
[0112] Strategy B: If migration is not possible, temporarily raise the external isolation level of the TCDSU to the highest level and notify the security administrator for manual decision-making and handling.
[0113] In this implementation plan, the significance of this embodiment lies in the following: By constructing a TCDMU system that includes autonomous configuration, automated operation, adaptive decision-making, and hierarchical governance modules, the core significance is to break through the bottlenecks of rigid configuration, static level assessment, and lagging governance response in traditional trusted cloud management. The autonomous configuration module, based on the three principles of autonomy, ensures that units possess independent, self-contained, and logically consistent robust characteristics through isolation, resource configuration, and policy verification, laying a reliable foundation for trusted level management and avoiding security risks caused by unit dependence on external resources or policy conflicts. The automated operation module, through continuous monitoring and dynamic level recalculation, achieves real-time updates of security levels, solving the problem that traditional static level assessment cannot respond to sudden security incidents. The system addresses the issue of the entire event, while the trusted state reporting and digital signature mechanisms ensure the authenticity and authority of remote proofs. The adaptive decision-making module achieves precise matching of requirements and product combinations based on a three-dimensional security matrix, and enhances the system's adaptability to diverse security needs and new threats by combining the weight optimization of anti-quantum cryptography products. The hierarchical governance module constructs a closed loop of fully automated governance through policy distribution, penetrating execution, and state reporting compensation mechanisms, ensuring the efficient implementation of global security policies and effectively solving the problems of policy execution deviation and passive fault handling in cross-level management. Ultimately, it realizes fully automated and trusted control of the trusted cloud unit from creation and operation to governance, providing solid security support for scenarios such as sensitive data processing and compliance requirements.
[0114] Example 2: Please refer to Figure 1 As shown, the automated and hierarchical trusted cloud level management unit system described in this embodiment of the invention mainly addresses the issue of formal verification performed before final application configuration in the self-configuration module of Embodiment 1 to ensure the consistency and lack of conflict of the internal logic of the policy. This embodiment of the invention also includes the following modules:
[0115] Configuration verification analysis module: acquires historical verification data of configuration policies, and through conflict frequency analysis of each historical configuration verification event, identifies non-mandatory verification TCDUN association types and mandatory verification TCDUN association types of configuration policies, and performs verification filtering on configuration policies;
[0116] And reverse the division of the mandatory verification configuration policies under the TCDUN association type;
[0117] In the configuration verification analysis module, the historical verification data of the configuration strategy includes the historical verification results of different types of configuration strategies under different TCDUN association types. The historical verification results include conflicting and non-conflicting results, and each verification is a historical configuration verification event.
[0118] In this implementation plan, it should be noted that the types of configuration policies include, but are not limited to:
[0119] Resource isolation strategies: Compute isolation: CPU core binding, memory NUMA partitioning, container runtime isolation; Storage isolation: dedicated storage volumes, encrypted storage partitions, data sandbox boundaries; Network isolation: VLAN segmentation, Virtual Private Cloud (VPC), Network Policy.
[0120] Security control policies: Identity and Access Management (IAM): Role-Based Access Control (RBAC), service accounts, multi-factor authentication; Key Management: Key rotation policy, HSM access rules, key lifecycle; Security Group Rules: Inbound / outbound traffic filtering, port open range, protocol restrictions;
[0121] Integrity verification strategies: Trusted boot strategy: UEFI secure boot configuration, image signature verification rules; Runtime integrity: application whitelist, system call filtering, file integrity monitoring (FIM) rules; Measurement strategy: PCR extended strategy, integrity measurement event definition;
[0122] Compliance strategies: Data protection strategy: data classification standards, encryption strength requirements, data residency rules; Audit strategy: log retention period, scope of audit events, report generation frequency; Privacy strategy: personal information processing rules, data anonymization standards, GDPR / HIPAA compliance requirements;
[0123] Service Quality Strategy: Performance SLA: minimum / maximum resource guarantees, performance baseline thresholds; Availability Strategy: fault domain distribution, redundancy deployment rules, backup strategies; Elasticity Strategy: automatic scaling rules, load balancing strategies;
[0124] It should also be noted that TCDUN association types include, but are not limited to:
[0125] Hierarchical relationships: Parent-child containment relationship: vertical management chain of TCDMU → TCDUN → TCDSU; Sibling parallel relationship: multiple sibling TCDUNs managed by the same parent TCDMU; Cross-generational inheritance relationship: inheritance and overriding relationship of strategies between levels;
[0126] Functional dependency relationships: Service call chain: Service dependencies in a microservice architecture (e.g., TCDUN-A's API service depends on TCDUN-B's database service); Data flow dependencies: Data production-consumption relationships, data pipeline dependencies; Resource sharing: Shared storage volumes, shared network gateways, shared security services;
[0127] Trust domain association: Same trust domain: A set of TCDUNs that share the same trust root and authentication system; Cross trust domain: Interaction between TCDUNs belonging to different organizations and different security domains; Trust level transfer: Service authorization from a high-trust-level TCDUN to a low-trust-level TCDUN.
[0128] Physical topology relationships: Same rack / same host: tight coupling relationship of shared physical infrastructure; Same data center: network proximity relationship within the same physical facility; Cross region / multi-cloud: relationship between TCDUNs distributed in different geographical regions and different cloud providers;
[0129] In the configuration verification analysis module, the process of identifying the non-mandatory and mandatory TCDUN association types for configuration policies is as follows:
[0130] Based on any type of configuration strategy;
[0131] Based on historical verification data, extract historical configuration verification events for configuration strategies under different TCDUN association types;
[0132] Based on any TCDUN association type;
[0133] If the historical verification result of a historical configuration verification event under the TCDUN association type is a conflict, then the historical configuration verification event will be marked as a conflict verification event.
[0134] If the historical verification result of a historical configuration verification event under the TCDUN association type is non-conflicting, then the historical configuration verification event will be marked as a non-conflicting verification event.
[0135] The frequency of occurrence of statistical conflict verification events in historical configuration verification events is used to obtain the conflict performance value of the TCDUN association type;
[0136] In this implementation, the conflict performance value of the TCDUN association type is compared with the conflict performance threshold;
[0137] If the conflict performance value is greater than or equal to the conflict performance threshold, then the TCDUN association type is marked as a TCDUN association type that must be verified in the configuration policy.
[0138] If the conflict performance value is less than the conflict performance threshold, the TCDUN association type will be marked as a non-mandatory verification TCDUN association type in the configuration policy.
[0139] In the configuration verification and analysis module, the process of verifying and filtering configuration policies is as follows:
[0140] Based on any configuration strategy;
[0141] If the configuration policy does not have any TCDUN association type that must be verified, the configuration policy will be filtered out and no configuration policy verification will be performed.
[0142] If at least one of the configuration policies requires verification of the TCDUN association type, then the configuration policies will be filtered and retained for verification.
[0143] Configuration verification priority analysis module: After the configuration policy performs verification filtering, based on the required verification TCDUN association type of the configuration policy, it constructs a table of required verification configuration policies under each TCDUN association type, and sorts the configuration policies in the table of required verification configuration policies for each TCDUN association type.
[0144] In the configuration verification priority analysis module, the process of constructing the mandatory verification configuration strategy table for each TCDUN association type is as follows:
[0145] Based on any TCDUN association type;
[0146] If the TCDUN association type is "Configuration policy must verify TCDUN association type", then mark the configuration policy as "Configuration policy must be verified".
[0147] If the TCDUN association type is not configured to require verification of the TCDUN association type, no action will be taken.
[0148] Iterate through all the verification filtering configuration policies, summarize all the mandatory verification configuration policies, and obtain the mandatory verification configuration policy table under the TCDUN related type.
[0149] In the configuration verification priority analysis module, the process of sorting the configuration policies in the mandatory verification configuration policy table for each TCDUN associated type is as follows:
[0150] The configuration policies in the configuration policy table that must be verified are sorted in descending order of conflict performance value;
[0151] Understandably, the conflict performance value reflects the frequency of conflict verification events of the configuration strategy under the TCDUN association type. The higher the frequency, the higher the probability risk of the configuration strategy being prone to conflict under the TCDUN association type. Therefore, sorting the configuration strategies in the configuration strategy table that must be verified according to the conflict performance value is conducive to the rational arrangement of subsequent configuration strategy verification.
[0152] Configuration verification module: Based on the association type between TCDUNs constructed by the autonomous configuration module, when performing configuration policy verification, the configuration policy is verified according to the sorted list of mandatory verification configuration policies corresponding to the TCDUN association type.
[0153] In the configuration verification module, the process of verifying configuration policies according to the sorted list of mandatory verification configuration policies corresponding to the TCDUN association type is as follows:
[0154] When performing configuration policy verification, extract the required configuration policy table corresponding to the association type between the TCDUN constructed by the autonomous configuration module, and perform configuration policy verification.
[0155] In this implementation scheme, the significance of this embodiment lies in the following: By adding configuration verification analysis, configuration verification priority analysis, and configuration verification modules, its core function is to address the problem of overly broad configuration policy verification coverage and low efficiency in Embodiment 1. It constructs a precise and orderly policy verification mechanism, significantly improving the security and verification efficiency of Trusted Cloud Unit configuration. By mining conflict patterns in historical configuration policy verification data, it distinguishes between mandatory and non-mandatory TCDUN association types, enabling targeted screening of configuration policies. This avoids invalid verification of policies with extremely low conflict risk, reducing system resource consumption. Simultaneously, it constructs a mandatory verification configuration policy table based on conflict performance values. The prioritization allows the verification process to focus on policies with high conflict risk, significantly reducing security vulnerabilities caused by conflicts in key policies. This data-driven verification optimization logic retains the rigor of the formal policy verification in Example 1 while solving the problem of lengthy processes caused by traditional full verification. It ensures that TCDUN can guarantee policy consistency through accurate verification during the configuration phase and improve configuration efficiency by optimizing the verification order. This provides more efficient support for building robust TCDUNs for autonomous configuration modules and further enhances the practicality and security of the entire TCDMU system in the configuration phase. It is especially suitable for complex trusted cloud scenarios with large-scale, multi-type TCDUN deployments.
[0156] Example 3: Please refer to Figures 2-3 As shown in the embodiment of the present invention, the automated and hierarchical trusted cloud level management method includes the following steps:
[0157] Step 1: Activate the three principles of autonomy configuration by receiving instructions from the administrator to the TCDMU, build a robust autonomous unit TCDUN, and wait for the automated operation module to take over;
[0158] This involves acquiring historical verification data for configuration policies, analyzing the conflict frequency of each historical configuration verification event to identify non-mandatory and mandatory TCDUN association types for configuration policies, and then filtering the configuration policies for verification.
[0159] After the configuration policy is verified and filtered, a table of mandatory verification configuration policies is constructed for each TCDUN association type based on the mandatory verification TCDUN association type of the configuration policy, and the configuration policies in the table of mandatory verification configuration policies for each TCDUN association type are sorted.
[0160] Based on the association type between TCDUNs constructed by the autonomous configuration module, when performing configuration policy verification, the configuration policy is verified according to the sorted table of mandatory verification configuration policies corresponding to the TCDUN association type.
[0161] Step 2: Continuously monitor the robust autonomous unit TCDUN under its control, and determine whether to trigger the TCDUN dynamic level recalculation based on the monitoring results. If triggered, perform the dynamic level recalculation and generate a trusted status report in response to the remote proof request.
[0162] Step 3: Extract security dimension requirements based on the input, map the level requirements of the three dimensions, find product combinations that meet the requirements based on the mapping results, and adaptively optimize the weights of products with quantum cryptography resistance.
[0163] Step 4: Based on the global policy issued by the superior TCDMU, the policy received by the subordinate TCDMU and penetrated to the TCDSU, and the execution status reporting and compensation mechanism, a complete automated governance cycle is achieved.
[0164] The foregoing has shown and described the basic principles, main features, and advantages of the present invention. Those skilled in the art should understand that the present invention is not limited to the above embodiments. The embodiments and descriptions in the specification are merely illustrative of the principles of the invention. Various changes and modifications can be made to the invention without departing from its spirit and scope, and all such changes and modifications fall within the scope of the present invention as claimed. The scope of protection of the present invention is defined by the appended claims and their equivalents.
Claims
1. An automated and hierarchical trusted cloud level management unit system, characterized by: Includes the following modules: Autonomous Configuration Module: Used to activate the three principles of autonomy configuration by receiving instructions from the administrator to the Trusted Cloud Level Management Unit (TCDMU), build a robust Autonomous Unit (TCDUN), and wait for the Automated Operations Module to take over; The three principles of autonomy include configuring isolation strategies to ensure independence, configuring all necessary resources to ensure self-containment, and verifying all strategies to ensure self-consistency; The automated operation module is used to continuously monitor the robust autonomous units (TCDUNs) under its control, determine whether to trigger the dynamic level recalculation of TCDUNs based on the monitoring results, and execute the dynamic level recalculation when triggered. It is also used to generate trusted status reports in response to remote proof requests. Adaptive decision module: It is used to extract security dimension requirements based on input, map the level requirements of the three dimensions, find product combinations that meet the requirements based on the mapping results, and also to adaptively optimize the weights of products with quantum cryptography resistance. The three dimensions include security, confidentiality, and privacy. The process of adaptive weight optimization is as follows: When receiving post-quantum cryptography threat intelligence, the adaptive decision module will automatically increase the weight of products or configurations with anti-quantum cryptography characteristics in the matrix, so that in the next matching, products that are more adapted to the current threat environment will receive higher recommendation priority, thereby achieving adaptive optimization of the model. Hierarchical governance module: used to realize a complete automated governance cycle based on the global policies issued by the upper-level TCDMU, the policies received by the lower-level TCDMU and penetrated to the robust autonomous subunit TCDSU, and the execution status reporting and compensation mechanism.
2. The automated and hierarchical trusted cloud level management unit system according to claim 1, wherein: The Trusted Cloud Level Management Unit system also includes: Configuration verification analysis module: acquires historical verification data of configuration policies, and through conflict frequency analysis of each historical configuration verification event, identifies non-mandatory verification TCDUN association types and mandatory verification TCDUN association types of configuration policies, and performs verification filtering on configuration policies; Configuration verification priority analysis module: After the configuration policy performs verification filtering, based on the required verification TCDUN association type of the configuration policy, it constructs a table of required verification configuration policies under each TCDUN association type, and sorts the configuration policies in the table of required verification configuration policies for each TCDUN association type. Configuration verification module: Based on the association type between TCDUNs constructed by the autonomous configuration module, when performing configuration policy verification, the configuration policy is verified according to the sorted list of mandatory verification configuration policies corresponding to the TCDUN association type.
3. The automated and hierarchical trusted cloud level management unit system according to claim 1, characterized in that: The process of building a robust autonomous unit (TCDUN) includes: The administrator issues a command to the TCDMU, which activates the autonomous configuration module inside the TCDUN to perform the three principles of autonomy configuration. These include: configuring strict logical isolation boundaries for the TCDUN, allocating all the hardware and software resources required for the TCDUN to run, and performing formal verification before the final application configuration to ensure that the internal logic of the policy is consistent and conflict-free. Only then will the final configuration be submitted, outputting a successfully constructed, robust autonomous unit TCDUN that satisfies the three principles of autonomy.
4. The automated and hierarchical trusted cloud level management unit system according to claim 2, characterized in that: The process of determining whether TCDUN dynamic level recalculation has been triggered and performing dynamic level recalculation when triggered is as follows: The Integrity Continuous Monitoring Unit in the Automated Operations Module continuously collects internal status data from the TCDUN. If the monitoring unit detects a negative security event that disrupts the trust chain, it triggers a dynamic recalculation of the TCDUN security level. The negative security event is reported to the dynamic level calculation unit in the automated operation module, and the real-time security level of the TCDUN is recalculated based on the security model preset in the dynamic level calculation unit.
5. The automated and hierarchical trusted cloud level management unit system according to claim 1, characterized in that: The process of generating a trusted state report in response to a remote proof request is as follows: When a remote verification request is received from an external audit system or user, the automated operations module obtains the latest real-time security level derived by the dynamic grading unit and generates a trusted report. The report includes at least: the current macro security level of the TCDUN, the micro security levels of all robust autonomous subunits (TCDSUs) within it, the key metrics that led to the current level, and a digital signature of the report using the TCDMU's private key.
6. The automated and hierarchical trusted cloud level management unit system according to claim 1, characterized in that: The process of finding a product mix that meets the needs is as follows: The adaptive decision-making module performs natural language parsing or data formatting on the input, extracts key security dimension requirements, maps them to three-dimensional level requirements, and then finds the product combination with the highest comprehensive score and best meeting the requirements in the 3D security matrix. The three dimensions include security, confidentiality, and privacy.
7. The automated and hierarchical trusted cloud level management unit system according to claim 2, characterized in that: The process for identifying the non-mandatory and mandatory TCDUN association types for configuration policies is as follows: Based on any type of configuration strategy; Extract historical configuration verification events for configuration policies under different TCDUN association types; If the historical verification result of a historical configuration verification event under the TCDUN association type is a conflict, then the historical configuration verification event will be marked as a conflict verification event. The frequency of occurrence of statistical conflict verification events in historical configuration verification events is used to obtain the conflict performance value of the TCDUN association type; If the conflict performance value is greater than or equal to the conflict performance threshold, the TCDUN association type is marked as a mandatory TCDUN association type for the configuration policy; otherwise, the TCDUN association type is marked as a non-mandatory TCDUN association type for the configuration policy.
8. The automated and hierarchical trusted cloud level management unit system according to claim 7, characterized in that: The process of validating and filtering configuration strategies is as follows: If the configuration policy does not have any TCDUN association type that must be verified, the configuration policy will be filtered out and no configuration policy verification will be performed. If at least one of the configuration policies requires verification of the TCDUN association type, then the configuration policy will be filtered and retained for verification.
9. The automated and hierarchical trusted cloud level management unit system according to claim 8, characterized in that: The process of constructing the mandatory verification configuration policy table for each TCDUN association type is as follows: Based on any TCDUN association type; If the TCDUN association type is "Configuration policy must verify TCDUN association type", then mark the configuration policy as "Configuration policy must be verified". Iterate through all the verification filtering configuration policies, summarize all the mandatory verification configuration policies, and obtain the mandatory verification configuration policy table under the TCDUN related type. The configuration policies in the configuration policy table that must be verified are sorted in descending order of conflict performance value.
10. An automated and hierarchical trust cloud level management method, characterized in that: Including the following methods: Step 1: Activate the three principles of autonomy configuration by receiving instructions from the administrator to the Trusted Cloud Level Management Unit (TCDMU), build a robust autonomous unit (TCDUN), and wait for the automated operations module to take over; This involves acquiring historical verification data for configuration policies, analyzing the conflict frequency of each historical configuration verification event to identify non-mandatory and mandatory TCDUN association types for configuration policies, and then filtering the configuration policies for verification. After the configuration policy is verified and filtered, a table of mandatory verification configuration policies is constructed for each TCDUN association type based on the mandatory verification TCDUN association type of the configuration policy, and the configuration policies in the table of mandatory verification configuration policies for each TCDUN association type are sorted. Based on the association type between TCDUNs constructed by the autonomous configuration module, when performing configuration policy verification, the configuration policy is verified according to the sorted table of mandatory verification configuration policies corresponding to the TCDUN association type. The three principles of autonomy include configuring isolation strategies to ensure independence, configuring all necessary resources to ensure self-containment, and verifying all strategies to ensure self-consistency; Step 2: Continuously monitor the robust autonomous unit TCDUN under its control, and determine whether to trigger the TCDUN dynamic level recalculation based on the monitoring results. If triggered, perform the dynamic level recalculation and generate a trusted status report in response to the remote proof request. Step 3: Extract security dimension requirements based on the input, map the level requirements of the three dimensions, find product combinations that meet the requirements based on the mapping results, and adaptively optimize the weights of products with quantum cryptography resistance. The three dimensions include security, confidentiality, and privacy. The process of adaptive weight optimization is as follows: When receiving post-quantum cryptography threat intelligence, the adaptive decision module will automatically increase the weight of products or configurations with anti-quantum cryptography characteristics in the matrix, so that in the next matching, products that are more adapted to the current threat environment will receive higher recommendation priority, thereby achieving adaptive optimization of the model. Step 4: Based on the global policy issued by the superior TCDMU, the policy received by the subordinate TCDMU and penetrated to the robust autonomous subunit TCDSU, and the execution status reporting and compensation mechanism, a complete automated governance cycle is achieved.
Citation Information
Patent Citations
Trusted cloud security confidential privacy level product service system and method
CN120342734A
Trusted cloud security confidential privacy three-dimensional grade product service system and method
CN120528631A