Network access risk assessment method and device, processor and electronic equipment

By combining quantum key distribution links and multi-factor authentication with AI behavioral analysis, security factors are generated for network access risk assessment, which solves the problem of insufficient accuracy in existing technologies and enables real-time, accurate assessment and rapid response to network access risks.

CN121814360APending Publication Date: 2026-04-07CHINA TELECOM CORP LTD
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-12-05
Publication Date
2026-04-07

AI Technical Summary

Technical Problem

Existing access risk assessment methods based on multi-factor authentication and zero-trust strategies are insufficient in terms of accuracy and response speed, making it difficult to accurately identify and defend against potential cyberattacks, especially in the face of quantum computing and dynamic network environments.

Method used

The first security factor is generated by establishing a quantum key distribution link for encryption. The confidence values ​​of multiple user identity features are obtained and weighted and fused to generate a second security factor to indicate the access permission status. This is combined with an AI-driven real-time behavior analysis model to assess network access risks.

Benefits of technology

It improves the accuracy and response speed of network access risk assessment, and can dynamically adjust security policies within milliseconds, effectively resisting quantum computing threats and complex network attacks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121814360A_ABST
    Figure CN121814360A_ABST
Patent Text Reader

Abstract

The invention discloses a network access risk assessment method and device, a processor and electronic equipment. The method relates to the field of computers and comprises the steps that a first security factor of a network is generated based on a quantum key distribution link established on the network, and the first security factor is used for encrypting transmission information of the network; a plurality of user identity features associated with a network are obtained, a confidence value of each user identity feature in the plurality of user identity features is obtained, the confidence value is used for indicating a matching degree between the user identity feature and an expected user identity feature, the confidence value of each user identity feature is subjected to weighted fusion, and a fusion result is obtained. Obtaining a comprehensive confidence value of the plurality of user identity features; under the condition that the comprehensive confidence value is greater than a preset authentication threshold value, generating a second security factor of the network, the second security factor being used for indicating an access permission state of the network; and generating an access risk score of the network based on the second security factor.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computers, and more specifically, to a method, apparatus, processor, and electronic device for assessing network access risks. Background Technology

[0002] Faced with increasingly complex and diverse cyber threats, especially the impact of quantum computing on traditional encryption technologies and the frequent changes in user behavior patterns in dynamic network environments, existing multi-factor authentication and zero-trust strategy access risk assessment methods are insufficient in terms of accuracy and response speed, making it difficult to accurately identify and defend against potential cyberattacks.

[0003] Therefore, there is a technical problem in the related technologies where the accuracy of network access risk assessment is relatively low. Summary of the Invention

[0004] The main objective of this application is to provide a method, apparatus, processor, and electronic device for assessing network access risks, in order to solve the problem of low accuracy in network access risk assessment in related technologies.

[0005] To achieve the above objectives, according to one aspect of this application, a method for assessing network access risk is provided. The method includes: generating a first security factor for the network based on a quantum key distribution link established on the network, wherein the first security factor is used to encrypt transmitted information on the network; obtaining multiple user identity features associated with the network, and obtaining a confidence value for each of the multiple user identity features, wherein the confidence value indicates the degree of matching between the user identity feature and expected user identity features, and the transmitted information includes multiple user identity features; weightedly fusing the confidence values ​​of each user identity feature to obtain a comprehensive confidence value for the multiple user identity features; generating a second security factor for the network if the comprehensive confidence value is greater than a preset authentication threshold, wherein the second security factor indicates the access permission status of the network; and generating a network access risk score based on the second security factor.

[0006] To achieve the above objectives, according to another aspect of this application, a network access risk assessment apparatus is provided. The apparatus includes: a first generation unit, configured to generate a first security factor for the network based on a quantum key distribution link established on the network, wherein the first security factor is used to encrypt transmitted information on the network; an acquisition unit, configured to acquire multiple user identity features associated with the network, and acquire a confidence value for each of the multiple user identity features, wherein the confidence value is used to indicate the degree of matching between the user identity feature and the expected user identity feature, and the transmitted information includes multiple user identity features; a fusion unit, configured to perform weighted fusion of the confidence values ​​of each user identity feature to obtain a comprehensive confidence value for the multiple user identity features; a second generation unit, configured to generate a second security factor for the network when the comprehensive confidence value is greater than a preset authentication threshold, wherein the second security factor is used to indicate the access permission status of the network; and a scoring unit, configured to generate an access risk score for the network based on the second security factor.

[0007] This application employs the following steps: Based on a quantum key distribution link established on the network, a first security factor is generated for the network, wherein the first security factor is used to encrypt the transmitted information of the network; multiple user identity features associated with the network are obtained, and a confidence value for each of the multiple user identity features is obtained, wherein the confidence value indicates the degree of matching between the user identity feature and the expected user identity feature, and the transmitted information includes the multiple user identity features; the confidence values ​​of each user identity feature are weighted and fused to obtain a comprehensive confidence value for the multiple user identity features; if the comprehensive confidence value is greater than a preset authentication threshold, a second security factor is generated for the network, wherein the second security factor indicates the access permission status of the network; based on the second security factor, an access risk score for the network is generated. The first security factor of quantum key distribution provides a guarantee for the encryption of transmitted information on the network, not only increasing the difficulty for attackers to break through the network link encryption, but also providing a security foundation for the subsequent multi-factor authentication process, ensuring the integrity and confidentiality of information during the authentication process. This dynamic adjustment mechanism can capture real-time changes in the effectiveness and risk level of user authentication elements, reduce assessment bias caused by individual authentication elements, and significantly improve the accuracy of risk assessment. This achieves the technical effect of improving the accuracy of network access risk assessment and solves the technical problem of low accuracy in network access risk assessment in related technologies. Attached Figure Description

[0008] The accompanying drawings, which form part of this application, are used to provide a further understanding of this application. The illustrative embodiments and descriptions of this application are used to explain this application and do not constitute an undue limitation of this application. In the drawings:

[0009] Figure 1 This is a hardware structure block diagram of a network access risk assessment method according to an embodiment of this application;

[0010] Figure 2 This is a flowchart of a network access risk assessment method provided according to an embodiment of this application;

[0011] Figure 3 This is a schematic diagram of a network access risk assessment device provided according to an embodiment of this application;

[0012] Figure 4 This is a schematic diagram of an electronic device for assessing network access risks according to an embodiment of this application. Detailed Implementation

[0013] It should be noted that, unless otherwise specified, the embodiments and features described in this application can be combined with each other. This application will now be described in detail with reference to the accompanying drawings and embodiments.

[0014] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.

[0015] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate for the embodiments of this application described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.

[0016] It should be noted that all information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for display, data used for analysis, etc.) involved in this disclosure are information and data authorized by the user or fully authorized by all parties. For example, this system has an interface with the relevant user or organization. Before obtaining relevant information, it is necessary to send an acquisition request to the aforementioned user or organization through the interface, and obtain the relevant information after receiving consent from the aforementioned user or organization.

[0017] The methods and embodiments provided in this application can be executed on a computer terminal or similar computing device. Taking running on a computer terminal as an example, Figure 1 This is a hardware structure block diagram of a computer terminal for a network access risk assessment method according to an embodiment of this application. Figure 1 As shown, a computer terminal may include one or more ( Figure 1 Only one is shown in the diagram. A processor 102 (which may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.) and a memory 104 for storing data are also shown. The computer terminal may further include a transmission device 106 for communication functions and an input / output device 108. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the computer terminal described above. For example, the computer terminal may also include components that are more complex than those described above. Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.

[0018] The memory 104 can be used to store computer programs, such as application software programs and modules, like the computer program corresponding to the network access risk assessment method in this embodiment. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, thus implementing the above-described method. The memory 104 may include high-speed random access memory and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor 102, and these remote memories can be connected to a computer terminal via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.

[0019] The transmission device 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by a communication provider for the computer terminal. In one example, the transmission device 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission device 106 may be a Radio Frequency (RF) module used for wireless communication with the Internet.

[0020] The present invention will now be described in conjunction with preferred implementation steps. Figure 2 This is a flowchart of a network access risk assessment method provided according to an embodiment of this application, such as... Figure 2 As shown, the method includes the following steps:

[0021] S201, based on the quantum key distribution link established on the network, generates the first security factor of the network, wherein the first security factor is used to encrypt the transmitted information of the network;

[0022] S202, obtain multiple user identity features associated with the network, and obtain the confidence value of each user identity feature among the multiple user identity features, wherein the confidence value is used to indicate the degree of matching between the user identity feature and the expected user identity feature, and the transmitted information includes multiple user identity features;

[0023] S203, weighted fusion of the confidence values ​​of each user identity feature to obtain a comprehensive confidence value of multiple user identity features;

[0024] S304, If the overall confidence value is greater than the preset authentication threshold, generate a second security factor for the network, wherein the second security factor is used to indicate the access permission status of the network;

[0025] S205, based on the second security factor, generates a network access risk score.

[0026] Optionally, in this embodiment, quantum key distribution (QKD) is a key generation and distribution technology based on the principles of quantum physics. It establishes a secure key between two communicating parties by transmitting quantum state particles (such as photons). This key is unbreakable by third parties because any observation of the quantum state will inevitably change its state. This characteristic guarantees the absolute security of the key.

[0027] Optionally, in this embodiment, the first security factor is a symmetric key generated through a quantum key distribution link. This key is used to encrypt information transmitted over the network, ensuring the security of data at the link layer and resisting various attacks, including quantum computing.

[0028] Optionally, in this embodiment, Multi-Factor Authentication (MFA) is an authentication mechanism that requires users to provide two or more authentication information. This information may include what the user knows (such as a password), what the user owns (such as a hardware token), and the user's own attributes (such as biometrics). User identity features are various information elements used for authentication in MFA, including but not limited to dynamic passwords (OTP), biometrics (fingerprints, irises, etc.), behavioral features (such as keystroke rhythm, mouse movement patterns), and device information (device fingerprints, hardware IDs).

[0029] Optionally, in this embodiment, the confidence score measures the degree to which user identity features match expected features, and is used to quantify the credibility of the authentication process. The overall confidence score is calculated by weighted fusion algorithm from the confidence scores of each user identity feature, and represents the credibility of the overall authentication process. It is used to determine whether to generate a second security factor, i.e., whether to grant access permissions.

[0030] Optionally, in this embodiment, the second security factor refers to an authentication token or flag generated after the user passes multi-factor authentication, used to indicate the status of network access permissions. It is used in conjunction with the first security factor to jointly determine the risk assessment result of network access. The access risk score is an indicator used to quantify the potential risk level of network access, derived by analyzing the status of the second security factor and other real-time risk factors (such as user behavior patterns and geographical location information), and guides the dynamic adjustment of the zero-trust policy.

[0031] Optionally, in this embodiment, a quantum key distribution link is established between the client and the server. A shared random symmetric key (i.e., the first security factor) is generated through the transmission of quantum photons encoded by polarization state or phase. The generation of the key follows strict quantum mechanical principles, ensuring that even in a quantum computing environment, the key cannot be eavesdropped on or copied by a third party. This provides the first layer of quantum security protection for subsequent multi-factor authentication and data transmission.

[0032] User identity features associated with the network are collected through multiple channels, including dynamic passwords, biometrics, and behavioral characteristics. Each feature is independently verified, and its confidence score is calculated. The confidence score reflects the degree of match between the user-submitted features and the features expected by the system, and is an important basis for assessing the credibility of user identities.

[0033] Based on the confidence scores obtained above, a weighted fusion algorithm is used to calculate the overall confidence score. The weights are trained using historical data and reflect the relative importance of different authentication elements in the overall authentication process. The calculation of the overall confidence score aims to integrate the credibility of multiple authentication elements to provide a comprehensive reference for subsequent decision-making.

[0034] If the overall confidence score exceeds a preset authentication threshold, the system will generate a second security factor to indicate the user's network access permission status. The generation of the second security factor signifies that the user has passed multi-factor authentication and has been granted temporary permission to access network resources.

[0035] Based on the status of the second security factor, further analysis of user behavior patterns, access history, geographical location, and other information is conducted. This data, combined with an AI-driven real-time behavior analysis model, generates an access risk score. A higher access risk score indicates a greater potential risk from the user's access behavior, suggesting the need for stricter access control measures.

[0036] Understandably, this embodiment achieves accurate assessment and dynamic control of network access risks through a combination of quantum key distribution (QKD) and multi-factor authentication, along with AI-based real-time behavioral analysis. First, the first security factor generated by QKD provides theoretically unbreakable encryption, laying a quantum-secure foundation for network communication. Second, the second security factor generated through the multi-factor authentication process, combined with a comprehensive confidence value, provides multi-dimensional authentication for network access, ensuring that only authenticated users can gain access. Finally, the AI ​​model based on real-time behavioral analysis dynamically adjusts the risk score for network access, ensuring that the zero-trust policy can respond rapidly to real-time changes in user behavior, refining access control granularity to the packet or API call level, thereby achieving policy updates within milliseconds and effectively resisting internal threats and session hijacking.

[0037] The embodiments provided in this application effectively address the limitations of traditional security models in the context of quantum computing threats by using a quantum key-driven multi-factor authentication and fine-grained zero-trust policy dynamic adjustment mechanism. This enables real-time, accurate assessment and millisecond-level response to network access risks, significantly improving the overall security and flexibility of the network.

[0038] As an optional approach, based on the second security factor, the network access risk score includes:

[0039] The generation state of the second security factor and the network session information of the network are input into the risk assessment model to obtain the access risk score output by the risk assessment model. The risk assessment model evaluates the user behavior attributes of the network based on the generation state and network session information, and determines the access risk score based on the difference between the user behavior attributes and the expected user behavior attributes. The risk assessment model is a neural network model obtained by training the network based on graph neural network and temporal convolutional network.

[0040] Optionally, in this embodiment, network session information refers to the data interaction process between a user device and a network service. Session information includes all interaction data during the session, such as packet sending and receiving times, packet size, API call sequences requested by the user, request frequency, geographical location information, and historical access records. This information forms the basis for evaluating user behavior.

[0041] Optionally, in this embodiment, user behavior attributes refer to the characteristics of a user's activities on the network obtained by the risk assessment model, including but not limited to access patterns, request frequency, access paths, and data packet interaction characteristics, used to determine whether user behavior deviates from the normal baseline. Expected user behavior attributes are normal behavior patterns defined by the system based on historical data and user roles. These patterns are typically used as comparison benchmarks to determine whether the user's current behavior is abnormal or high-risk.

[0042] Optionally, in this embodiment, the risk assessment model is a neural network model employing a graph neural network (GNN) and a temporal convolutional network (TCN) to analyze user behavior in real time and calculate access risk scores. GNN can capture dependencies in API call sequences, while TCN can model dynamic patterns in data packet time series.

[0043] Optionally, in this embodiment, after a user passes the multi-factor authentication process and the overall confidence value exceeds a preset authentication threshold, the system generates a second security factor. The generation status of the second security factor (i.e., whether the authentication is successful or not, and the corresponding overall confidence value) is sent to the risk assessment model as one of the inputs to assess the potential risks of the user's behavior.

[0044] Real-time collection of ongoing network session information, including but not limited to packet header fields (five-tuples), API call sequences, request frequencies, geographical locations, time periods, etc., is organized and preprocessed to form a feature set suitable for machine learning models.

[0045] The risk assessment model is based on a deep learning framework using GNN and TCN. The first module constructs a graph structure for API call relationships, capturing non-linear dependencies and abnormal paths in user behavior to identify potential anomalous operation patterns. The second module models the time series of data packet interactions, analyzing temporal features such as packet intervals and request frequencies to identify dynamic behaviors that do not conform to conventional patterns, especially attack attempts to bypass security mechanisms.

[0046] During the model training phase, historical login data, normal user behavior patterns, and known attack cases are used to adjust the parameters in the GNN and TCN modules through supervised learning, thereby optimizing the model's ability to identify user behavior attributes and learning the distinguishing features between normal and abnormal behaviors.

[0047] The generation status of the second security factor, along with the preprocessed network session information, is input into the pre-trained risk assessment model. The model calculates an access risk score R based on a comparison of the user's real-time behavior with a baseline of normal behavior. The higher the R value, the more the user's current behavior deviates from the normal range, and the greater the potential risk.

[0048] During the scoring process, the model not only considers the static attributes of user behavior (such as access frequency, packet size, etc.), but more importantly, it also captures the dynamic features in the time series, such as the changing trend of packet intervals and abnormal API call sequences, in order to more comprehensively evaluate the changing trends and risk patterns in user behavior attributes.

[0049] By combining static attributes and dynamic features of user behavior through the embodiments provided in this application, the risk assessment model of this embodiment can more comprehensively understand subtle changes in user network activity and identify potential threats hidden beneath normal behavior. This deep learning-based dynamic risk assessment method offers higher accuracy and real-time performance compared to traditional static rule-driven assessment methods.

[0050] As an alternative approach, before inputting the generation status of the second security factor and the network session information into the risk assessment model, the method further includes:

[0051] Obtain network layer session information associated with the network, including packet header information, packet length distribution information, and packet interval information of the data packets associated with the network.

[0052] Obtain network-associated application layer session information, which includes network-associated interface call sequence information, parameter pattern information, and request frequency information;

[0053] Obtain the context session information associated with the network, which includes the geographical location information, access time period information, and access path information associated with the network.

[0054] Network layer session information, application layer session information, and context session information are identified as network session information.

[0055] Optionally, in this embodiment, network layer session information refers to low-level session information generated during network communication, mainly including packet header information (such as source IP, destination IP, transport layer protocol, source port number, and destination port number), packet length distribution information (i.e., statistical distribution characteristics of packet size), and packet interval information (i.e., the time interval between packet transmissions during communication). This information forms the basis for evaluating network link-level behavior patterns.

[0056] Optionally, in this embodiment, application layer session information refers to information generated during higher-level protocol sessions, including interface call sequence information (the sequence of service interfaces requested by the user), parameter pattern information (the type and format of parameters provided by the user when requesting the interface), and request frequency information (the number of interface calls per unit time). This information can reveal the user's behavioral habits and potential anomalies at the specific application level.

[0057] Optionally, in this embodiment, the contextual session information encompasses external environmental information related to network access, including geographic location information (the user's location when accessing the network), access time period information (the specific time interval during which the user is active), and access path information (the order in which the user accesses different network resources or services). This information helps the system understand the user's access context and its rationality, providing contextual basis for risk scoring.

[0058] Optionally, in this embodiment, a sniffer is deployed at the network ingress or SDN / SRC network technology is used to capture data packets transmitted on the network in real time, extracting packet header information, packet length distribution, and packet interval information. This information reflects the data flow pattern at the link layer and is crucial for identifying potential network-level anomalies (such as DDoS attacks and packet replay attacks).

[0059] The collection of application-layer session information involves parsing user requests to extract features such as API call sequences, parameter patterns, and request frequencies. These features help assess whether a user's request patterns match their typical behavior or whether there are signs of an attempt to abuse system privileges. For example, an unusually high request frequency may indicate an automated attack attempt, while an unusual API call sequence may suggest improper operation by an insider.

[0060] The collection of contextual session information covers the user's geographical location, access time, and access path. This step is achieved through location services, timestamp recording, and access log analysis, with the aim of better understanding and assessing the rationality and predictability of user behavior. For example, if a user accesses sensitive resources from a geographically remote location outside of working hours, it may be considered a potentially high-risk behavior.

[0061] The collected network layer session information, application layer session information, and context session information are then merged into a complete set of network session information. This step ensures that the risk assessment model receives comprehensive data on user behavior, enabling a more complete assessment of potential risks.

[0062] After integrating the network session information, we will input this information, along with the generation status of the second security factor, into the risk assessment model to prepare for the next step of calculating the access risk score.

[0063] The embodiments provided in this application effectively improve the accuracy and comprehensiveness of risk assessment, avoiding biases caused by insufficient information. By comprehensively collecting session information at all levels of network communication, the system can construct a more comprehensive user behavior profile, thereby enabling timely and accurate identification of potential threats in the face of complex and ever-changing network attack methods, and providing a higher level of security for the network environment.

[0064] As an alternative approach, after generating a network access risk score based on the second security factor, the method further includes:

[0065] If the access risk score is greater than the first score threshold, the network will be subject to a first access restriction operation and a first interface call restriction operation. The first access restriction operation is used to indicate that the network access granularity is refined to the packet header field matching, and the first interface call restriction operation is used to indicate that the network's interface calls are only allowed to respond to whitelisted requests.

[0066] Optionally, in this embodiment, the access risk score is a numerical value calculated through a risk assessment model, representing a quantitative indicator of the potential risk in a network access request. A higher score indicates a greater degree of abnormality or potential threat in the access request. The first scoring threshold is a preset numerical standard used to determine the level of the access risk score. When the access risk score exceeds this threshold, the system will automatically trigger a series of security response measures to reduce the risk of network attacks.

[0067] Optionally, in this embodiment, to address network sessions with high-risk scores, the first access restriction operation refines access control granularity down to packet header field matching (five-tuple filtering). This means that the system will perform detailed checks on the source IP, destination IP, source port number, destination port number, and transport layer protocol of each packet to filter out potentially malicious or abnormal packets, reducing the possibility of attackers breaching defenses through unauthorized data flows.

[0068] Optionally, in this embodiment, the first interface call restriction operation is another security response measure, restricting interface calls in the network to only respond to requests on a whitelist. The whitelist contains a predefined list of service interfaces considered secure; any interface call not on the whitelist will be blocked, thereby preventing attackers from using unknown or unauthorized interfaces for penetration or data theft.

[0069] Optionally, in this embodiment, after the risk assessment model calculates the risk score of network access, the system compares this score with a preset first score threshold. If the score exceeds the threshold, it means that the current network session has a high potential security risk, and immediate action is required to reduce the risk.

[0070] The first access restriction operation is initiated, further refining access control granularity from session or application level to packet header field matching (five-tuple filtering). This operation involves rapidly updating firewall rules on network devices to ensure all packets undergo rigorous source and destination addresses, ports, and protocol checks. Only packets matching the preset five-tuple filtering rules are allowed to pass; the rest are blocked or dropped.

[0071] Simultaneously, the first API call restriction operation is initiated, allowing responses only to API calls defined on the whitelist. This restriction involves adjusting the policies of the API gateway or other application-layer security components to ensure that only API requests deemed safe are processed. For API calls not on the whitelist, the system automatically rejects the request to prevent potential API abuse attacks.

[0072] The aforementioned restrictions are implemented through a high-speed policy distribution channel, ensuring the immediacy and effectiveness of policy adjustments. Policy updates and distribution can be completed within ≤5ms, meaning a rapid response can be initiated upon detecting abnormal behavior or potential threats, significantly improving the real-time nature and flexibility of network defense.

[0073] The embodiments provided in this application, through dynamic access restriction operations, combine fine-grained network monitoring with strict control over service interfaces to form a multi-layered, fine-grained protection system. Within milliseconds, the system can automatically adjust access policies based on changes in risk scores, enhancing the adaptability and protective effectiveness of the zero-trust security architecture.

[0074] As an alternative approach, after generating a network access risk score based on the second security factor, the method further includes:

[0075] If the access risk score is greater than the second score threshold, a second access restriction operation and a second interface call restriction operation are performed on the network. The second access restriction operation is used to indicate that access events on the network are prohibited, and the second interface call restriction operation is used to indicate that interface calls on the network are only allowed to respond to requests that have been authenticated and are on the whitelist. The second score threshold is greater than the first score threshold.

[0076] Optionally, in this embodiment, the second scoring threshold is a risk scoring boundary value set above the first scoring threshold, used to identify network access behaviors with extremely high risk. Compared to the first scoring threshold, the second scoring threshold represents a higher probability of abnormal behavior or a higher level of potential threat.

[0077] Optionally, in this embodiment, the second access restriction operation is a more stringent security measure that the system will implement when the access risk score reaches or exceeds a second score threshold, directly prohibiting suspicious network access events. This typically involves immediately freezing or suspending the user session to prevent potential attacks from continuing and to protect network resources from damage.

[0078] Optionally, in this embodiment, the second interface call restriction operation is a more stringent security restriction compared to the first interface call restriction operation. It not only requires interface calls to respond to requests defined in the whitelist, but also further ensures that all interface calls must undergo real-time authentication. This means that even if the interface is originally in the whitelist, the call will not receive a response unless the visitor verifies their identity again through the MFA authentication process.

[0079] Optionally, in this embodiment, the network access risk score output by the risk assessment model is continuously monitored. When the score suddenly rises and exceeds a preset second score threshold, it indicates that the current network session may involve very high-risk behavior or a potential serious threat, requiring immediate and more stringent protective measures.

[0080] The system automatically triggers a second access restriction operation, immediately prohibiting network access events. This includes, but is not limited to, freezing user sessions, denying further packet transmission, and immediately terminating all network connections associated with abnormal behavior. This immediate response mechanism ensures that, in the face of extreme threats, the source of risk can be quickly cut off, minimizing the exposure of network resources.

[0081] Meanwhile, to further strengthen network security, the system has implemented a second layer of interface call restrictions. In addition to maintaining basic restrictions on calls to whitelisted interfaces, the system requires secondary authentication for all attempts to call whitelisted interfaces. This means that even if a user's previous access behavior appears normal, once their risk score reaches the second threshold, any interface call request will be subject to additional scrutiny until the user passes the real-time authentication process.

[0082] These emergency security measures are implemented through a highly optimized policy linkage mechanism, ensuring that the entire process, from detecting that the risk score exceeds the second score threshold to executing the second access restriction operation and the second interface call restriction operation, is completed within milliseconds, demonstrating extremely high response speed and flexibility.

[0083] The embodiments provided in this application, under the second scoring threshold, further enhance network security by instantly freezing access events and performing secondary verification of whitelisted interface calls, especially when facing extremely high-risk network attacks, providing a faster and more effective protection response. This technical solution effectively balances the relationship between network security and user experience by dynamically adjusting the strictness of security policies, making it suitable for critical applications with extremely high security requirements.

[0084] As an optional approach, obtaining multiple user identity features associated with the network, and obtaining the confidence value of each user identity feature among the multiple user identity features, includes:

[0085] Obtain network-related dynamic password features, user body posture features, user behavior features, and device features, among which multiple user identity features include dynamic password features, user body posture features, user behavior features, and device features;

[0086] The similarity is calculated for each user identity feature to obtain the confidence value of each user identity feature.

[0087] Optionally, in this embodiment, the dynamic password feature is a one-time-use password generated synchronously based on time or events, such as a time-based verification code or an event-counted verification code. Dynamic passwords increase the unpredictability of the authentication process and effectively resist replay attacks.

[0088] Optionally, in this embodiment, user physical characteristics refer to the user's own physiological characteristics, typically including biometric information such as fingerprints, iris scans, and facial recognition. These characteristics are unique and difficult to change, providing a reliable identity verification dimension for multi-factor authentication.

[0089] Optionally, in this embodiment, user behavior characteristics encompass personalized behavioral patterns formed by users when operating devices or interacting with the network, such as keystroke rhythm, mouse movement trajectory, touch screen pressure distribution, and frequently used operation commands. Analysis of behavioral characteristics helps identify subtle differences between legitimate users and imposters, enhancing authentication security and user experience.

[0090] Optionally, in this embodiment, device features refer to the hardware and software attributes of the user device, including device model, operating system version, browser fingerprint, device ID, etc. This information can help the system determine whether the device is a registered or authorized device, further improving the reliability of authentication.

[0091] Optionally, in this embodiment, the similarity calculation is performed by comparing each user identity feature with a pre-stored template or historical data, and using a specific algorithm (such as cosine similarity, Hamming distance, etc.) to calculate the difference between the two, which is then converted into a confidence value to evaluate the degree of matching between the current feature and the legitimate user feature.

[0092] Optionally, in this embodiment, multi-dimensional identity authentication information, such as dynamic passwords, user posture, user behavior, and device characteristics, is extracted from the network session. This process may involve the client's biometric sensors (for fingerprint and iris reading), behavior tracking scripts (monitoring keystroke rhythm and mouse behavior), and device fingerprint generation tools (collecting hardware and software attribute information).

[0093] For dynamic password features (such as TOTP and HOTP), the system compares them with pre-stored dynamic password generation mechanisms to calculate the matching degree between the currently submitted password and the expected dynamic password, and obtains the confidence value of the dynamic password feature.

[0094] The system compares the physiological features submitted by users (such as fingerprint images and iris scan results) with the legitimate user templates stored in the database. It then calculates the similarity (cosine similarity, Hamming distance, etc.) to assess the confidence value of the user's physical features, ensuring their consistency with the features of legitimate users.

[0095] Record user behavior patterns during sessions, such as keystroke intervals and mouse movement paths, and then compare them with the user's historical behavior data. Calculate the confidence value of the behavioral features using behavioral analysis algorithms (such as time-series-based statistical models) to quantify the normality of the user's behavior patterns.

[0096] The system checks the device's hardware and software attributes and compares them with the list of authorized devices to verify the device's legitimacy. By analyzing the similarity of device fingerprints, the system can calculate the confidence value of device characteristics, ensuring the trustworthiness of accessed devices.

[0097] After obtaining the confidence scores for all the aforementioned user identity features, the system aggregates these confidence scores using a weighted fusion algorithm to obtain a comprehensive confidence score. The weights can be trained based on historical data and reflect the importance of different features in the overall authentication process.

[0098] Through the embodiments provided in this application, by collecting and analyzing dynamic passwords, user body language, user behavior, and device characteristics, the system can construct a multi-factor authentication security framework, significantly improving the difficulty and security of identity verification and reducing the risk of single-factor attacks. The confidence score is calculated as a similarity calculation for each user's identity features, transforming the abstract degree of matching into a concrete numerical indicator. This facilitates the system's quantitative evaluation of user identities, enabling more accurate access control decisions.

[0099] As an alternative approach, after generating a network access risk score based on the second security factor, the method further includes:

[0100] If the access risk score is detected to be greater than the third score threshold for a period of time exceeding a preset duration, the first security factor is updated based on the quantum key distribution link.

[0101] Optionally, in this embodiment, the third scoring threshold is a predefined numerical standard used to identify network sessions that have been in a high-risk state for an extended period. Compared to the first and second scoring thresholds, the third scoring threshold reflects a special concern about prolonged abnormal behavior, suggesting that further security measures should be taken.

[0102] Optionally, in this embodiment, the preset duration is a time window set by the system to determine whether the state of the access risk score continuously exceeding the third score threshold continues. The selection of this duration needs to consider the real-time and security requirements of the network, and is usually ranging from a few seconds to a few minutes.

[0103] Optionally, in this embodiment, the system continuously monitors the network access risk score calculated by the risk assessment model, paying particular attention to whether the score remains at a high level for a long time, i.e., records that continuously exceed the third score threshold.

[0104] If the access risk score is detected to be higher than the third score threshold for a period of time exceeding the preset duration, it indicates that there is persistent abnormal behavior or potential persistent attack in the network session, and the existing security mechanism needs to be upgraded or adjusted.

[0105] The system then activates the quantum key distribution (QKD) mechanism, regenerates a new quantum key, and updates the first security factor (i.e., the new quantum key) to the client and server via a secure quantum channel. This update process ensures the timeliness and security of the link-layer encryption key, thereby enhancing the overall network protection capability.

[0106] The embodiments provided in this application demonstrate the real-time monitoring capability of network session security and showcase the function of strengthening link-layer encryption protection by dynamically updating quantum keys when continuous high-risk behavior is detected. Compared with static encryption key management methods, the dynamic quantum key update technology of this embodiment can better cope with constantly changing network attack strategies, providing a more flexible and robust security barrier for the network environment.

[0107] As an alternative approach, the aforementioned network access risk assessment methods can be applied to multi-factor authentication scenarios involving quantum key distribution and AI-driven zero-trust strategies with dynamic adjustment. In this scenario, with the development of quantum computing, traditional public-key cryptography systems based on mathematical problems (such as RSA and ECC) may be rapidly cracked in the future. Quantum key distribution (QKD) provides a theoretically uneavesdroppable key exchange mechanism and is considered a core security technology in the post-quantum era. However, existing QKD technologies mainly focus on link-layer key distribution, with limited integration for identity authentication. This means that even with secure link encryption, attacks can still occur if the authentication process is compromised.

[0108] On the other hand, zero-trust architecture is gradually replacing the traditional "perimeter defense" model, achieving secure access control through mechanisms such as continuous verification, least privilege, and micro-segmentation. However, existing zero-trust strategies are mostly static or rule-driven, making it difficult to respond promptly to complex network environments and changes in user behavior, and there are still technical gaps in fine-grained control at the packet or API call level.

[0109] In existing technologies, quantum key distribution (QKD) systems are mainly used for secure key exchange at the communication link layer. This involves generating random keys between communicating parties by transmitting quantum photons (such as polarization states or phase-coded states), and then performing bit error rate detection, information harmonization, and privacy amplification on a classical channel to obtain data encryption keys that can be used for symmetric encryption. However, such schemes are typically limited to ensuring data transmission security at the link layer and are not deeply integrated with the authentication process. Multi-factor authentication (MFA) systems are mostly based on traditional encryption technologies, using dynamic passwords (OTP), biometrics (such as fingerprints and irises), device fingerprints, or behavioral characteristics as additional verification elements. These are verified by a central authentication server, and access is granted if all verification elements pass. Zero-trust architectures in existing applications often rely on static rule sets or predefined policies, using users, devices, and locations as trust evaluation factors to continuously verify access requests and assign the least privilege. However, policy adjustments are typically made on a minute or even hourly basis, lacking real-time response capabilities and making it difficult to refine access control granularity to the data packet or API call level. Overall, existing technologies often operate QKD, MFA, and zero trust independently, lacking a unified security framework that integrates the link-layer security factor generated by QKD with the MFA authentication process, and combines AI real-time behavior analysis to drive fine-grained dynamic adjustment of zero trust policies. Therefore, when facing quantum computing threats and dynamic network attacks, there are still shortcomings such as the separation of link and application layer protection, policy response delays, and coarse-grained access control.

[0110] While existing technologies have made some progress in link encryption, multi-factor authentication, and zero-trust access control, the following technical problems still exist: First, quantum key distribution (QKD) is only used for link-layer key exchange and is not deeply integrated with identity authentication, which means that even if the link encryption is secure, attackers may still break through the authentication process by exploiting weak authentication strategies. Second, multi-factor authentication (MFA) relies on traditional encryption algorithms and static verification logic, making it difficult to resist the threat of cracking in a quantum computing environment. At the same time, it lacks real-time perception of user behavior patterns and cannot dynamically adjust the authentication strength. Third, most existing implementations of zero-trust architecture use static or low-frequency policy updates, which cannot respond to rapid changes in user session behavior at the millisecond level. Moreover, the granularity of access control usually remains at the session level or application level, making it difficult to be precise to the data packet or API call level. Fourth, QKD, MFA, and zero-trust lack a unified coordination mechanism, resulting in a disconnect between link-layer and application-layer protection, creating security gaps where the attack surface is not covered.

[0111] To address the aforementioned issues, this embodiment proposes a method to organically integrate QKD link-layer security factors with MFA multi-factor authentication, and dynamically adjust the zero-trust strategy through AI-driven real-time behavior analysis, thereby achieving an integrated, fine-grained, and millisecond-level security protection system that combines the link layer and application layer. First, a quantum key distribution (QKD) link is established between the client and server. Random symmetric keys are generated through quantum photon transmission, and bit error rate detection, information reconciliation, and privacy amplification are performed to form the first security factor. Next, various authentication elements of the user are collected, including active passwords (OTP), biometrics, and behavioral characteristics, to generate the second security factor. A comprehensive confidence calculation is performed at the authentication gateway to complete multi-factor authentication. Then, an AI behavior analysis model based on graph neural networks (GNN) and temporal convolutional networks (TCN) is deployed to model and assess the user's session patterns, access paths, and data packet interaction characteristics in real time. When the model detects an increase in the user's risk level, the policy control module refines the zero-trust access control granularity to the data packet or API call level and updates and distributes the policy within milliseconds. Finally, end-to-end security is achieved through a closed-loop combination of link-layer encryption protection and application-layer dynamic access control. The main inventive point of this invention is to deeply integrate the link-layer security factor generated by QKD with the MFA multi-factor authentication process, and to drive the zero-trust policy to make fine-grained dynamic adjustments at the millisecond level with AI real-time behavior analysis, so as to achieve unified protection of the link layer and the application layer.

[0112] This embodiment deeply integrates the link-layer security factor generated by quantum key distribution (QKD) with the multi-factor authentication (MFA) process, and introduces an artificial intelligence (AI) model based on real-time behavior analysis to drive a dynamic adjustment mechanism for the zero-trust policy. This effectively solves the problems in existing technologies such as the disconnect between link encryption and identity authentication, the vulnerability of the authentication process to quantum computing, the lack of real-time adaptive capability in multi-factor authentication, the delay in zero-trust policy updates, and insufficient granularity of access control. By fine-grainedly adjusting the access policy at the millisecond level (accurate to data packets or API calls), this invention not only significantly improves the system's protection capabilities against quantum computing threats and dynamic network attacks, but also achieves integrated security protection at the link layer and application layer, ultimately reducing the risk of authentication breaches, narrowing the attack surface, improving response speed, and enhancing overall network security.

[0113] Optionally, in this embodiment, the client and server establish a QKD channel on a physical link (optical fiber or free-space optical link), employing polarization-state or phase-encoded quantum photon transmission. The receiving end performs random basis measurements on the photons, and both parties exchange measurement basis information on a classical channel. Bit error rate detection (QBER detection, threshold <3%) is performed; if the threshold is exceeded, the key is discarded and regenerated. Information reconciliation (Cascade algorithm) and privacy amplification (based on a universal hash function) are performed to remove potential information leakage. A 256-bit symmetric key K_q is generated, ensuring its information-theoretic security, and serves as the first security factor.

[0114] Optionally, in this embodiment, K_q is passed to the authentication gateway. K_q is used to encrypt the dynamic challenge value and session control signaling in the subsequent multi-factor authentication process (AES-256-GCM mode). This ensures that the interaction data during the authentication process cannot be eavesdropped on, tampered with, or replayed at the link layer.

[0115] Optionally, in this embodiment, in addition to K_q, the system collects additional authentication elements: dynamic passwords (OTP / TOTP / HOTP); biometrics (fingerprint, iris, etc.); behavioral characteristics (keystroke rhythm, mouse trajectory, etc.). Each authentication element is independently verified at the authentication gateway. A weighted confidence fusion algorithm is used to calculate the overall authentication confidence. When C_total ≥ threshold θ_auth, a second security factor K_m is generated; otherwise, a secondary verification process is triggered or access is denied.

[0116] Optionally, in this embodiment, the authentication gateway sends the session information of authenticated users to the AI ​​behavior analysis server in real time. The AI ​​model is composed of a graph neural network (GNN) and a temporal convolutional network (TCN). The GNN model analyzes the API call relationship graph and access path structure; the TCN model analyzes and models the data packet interaction time series and request frequency change patterns. The AI ​​model calculates a real-time risk score R to assess the degree of deviation of the current user behavior from the normal baseline.

[0117] Optionally, in this embodiment, when R ≥ θ_risk (risk threshold), the policy engine receives the risk event and performs dynamic tightening operations: refining the access control granularity to packet header field matching (five-tuple filtering); applying API call whitelist restrictions (allowing only secure calls). Policy issuance is completed within ≤5ms via the high-speed southbound interface. If R ≥ θ_high (high-risk threshold), it immediately switches to high-security mode: adding secondary verification (such as real-time face recognition) to sensitive API calls; freezing high-risk sessions or resource access permissions.

[0118] Optionally, in this embodiment, the link layer uses a QKD key K_q to encrypt data transmission throughout the process, defending against passive eavesdropping and man-in-the-middle attacks. The application layer continuously verifies identity and behavior through an AI-driven zero-trust strategy, defending against internal threats and session hijacking. When the application layer risk score consistently exceeds a threshold, the QKD module is triggered to update K_q in advance; when the link layer detects abnormal interference or attacks, the application layer MFA verification strength is increased.

[0119] To further illustrate, the following example uses a QKD and AI-driven zero-trust multi-factor authentication system to explain the network access risk assessment method described above.

[0120] 1. System Deployment Architecture

[0121] This system consists of a client (UserAgent), a quantum key distribution module (QKDNode), an authentication gateway (AuthGateway), an AI behavior analysis server (AIBehaviorServer), and a zero-trust policy controller (ZeroTrustPolicyController).

[0122] The client runs a security agent program, supporting MFA factor collection and QKD link access. QKDNodes are deployed at both ends of the physical link between the client and the authentication gateway, using polarized quantum signal transmission. The authentication gateway is responsible for multi-factor authentication logic and confidence calculation, and communicates with the zero-trust controller. The AI ​​behavior analysis server runs graph neural network (GNN) and temporal convolutional network (TCN) models to perform real-time analysis of user session data. The zero-trust policy controller distributes access policies to data plane devices (such as switches and API gateways) via a high-speed southbound interface.

[0123] 2. Technical Process

[0124] Step S1: Establish QKD link and generate the first security factor

[0125] The client and authentication gateway establish a QKD channel via fiber optic or free-space optical communication, transmitting quantum photons using the BB84 protocol or an improved polarization coding protocol. The quantum signal receiver performs random basis measurements on the photon polarization state. After classical channel switching, the measurement result undergoes bit error rate (QBER) detection (QBER < 3%). If the rate exceeds this limit, the key is discarded and regenerated. Information reconciliation (using the Cascade algorithm) and privacy amplification (based on a universal hash function) are performed to generate a 256-bit symmetric key K_q, which serves as the first security factor. K_q is used to encrypt the challenge value and control signaling in the subsequent MFA authentication process (AES-256-GCM mode).

[0126] Step S2: Multi-factor authentication and generation of the second security factor

[0127] The system collects the following authentication elements:

[0128] Dynamic password (OTP): based on time synchronization (TOTP, updated every 30 seconds) or event synchronization (HOTP).

[0129] Biometric features: fingerprint (fingerprint image compressed into a 512-bit feature vector after Minutiae feature extraction), iris (Iris Code extracted using the Daugman algorithm).

[0130] Behavioral characteristics: keystroke rhythm (millisecond-level key interval), mouse trajectory (coordinate sequence), touch pressure curve.

[0131] Device fingerprints include hardware serial numbers, operating system versions, and browser fingerprints.

[0132] Calculate the similarity (e.g., cosine similarity, Hamming distance) for each element to obtain a confidence value C_i. Authentication is successful when C_total ≥ threshold θ_auth, and a second security factor K_m is generated; otherwise, access is denied or a secondary verification process is initiated.

[0133] Step S3: Real-time AI Behavior Analysis

[0134] The system inputs real-time session data streams into the AI ​​model, including:

[0135] Network layer characteristics: packet header (source IP, destination IP, port, protocol number), packet length distribution, packet interval time.

[0136] Application layer characteristics: API call sequence, parameter pattern, request frequency.

[0137] Contextual features: geographical location, time period, and historical access path.

[0138] Model structure:

[0139] GNN module: Constructs a call relationship graph for API call sequences, capturing non-linear dependencies and abnormal call paths.

[0140] TCN module: Performs time series pattern modeling on time series data (packet interval, request frequency).

[0141] Policy adjustment is triggered when R ≥ θ_risk.

[0142] Step S4: Dynamically Adjust the Zero Trust Strategy

[0143] Policy controllers refine access control granularity to:

[0144] Packet level: Match header fields (5-tuples) to block or allow specific flows.

[0145] API call level: Restrict sensitive APIs (such as DELETE, POST, and finance / ) The call to ) or the addition of additional validation.

[0146] Policy delivery latency is controlled to ≤5ms to ensure immediate response.

[0147] In high-risk situations (R≥θ_high): Force temporary session freeze; activate additional MFA verification factors (such as real-time face recognition).

[0148] Step S5: Closed-loop protection at the link layer and application layer

[0149] Link layer: K_q generated by QKD ensures that the data cannot be eavesdropped on or tampered with.

[0150] Application layer: Defend against session hijacking and insider threats through MFA and AI-driven zero-trust strategies.

[0151] Closed-loop mechanism: AI risk assessment results can be used to adjust MFA weight allocation and QKD session update cycle to achieve global optimization of security policy.

[0152] On the simulation platform, with QKD link rate of 1Mbps, user request frequency of 100req / s, and AI model inference latency of 3ms as test conditions: authentication breach rate: decreased from 0.43% to 0.01%; policy response latency: decreased from 1.2s to 4.7ms; link encryption cracking rate: remained at 0% under the quantum attack model.

[0153] Understandably, for cross-domain access scenarios (such as users accessing a unified cloud service platform from different geographical locations and different carrier networks), traditional QKD and MFA authentication schemes can only work within a single link and lack cross-domain collaborative protection capabilities. This extended solution introduces a "multi-domain quantum key collaboration network" and a "policy linkage central control module" to achieve cross-domain zero-trust integrated security protection.

[0154] Optionally, a cross-domain quantum key pool can be established between multiple operators or data centers through quantum relay nodes and quantum entanglement exchange to achieve key resource sharing and dynamic scheduling between different domains.

[0155] Authentication gateways in different domains share MFA verification results and confidence data through encrypted channels, enabling users to quickly reuse authentication results in other collaborative domains after being authenticated in a trusted domain, reducing delays caused by repeated verification.

[0156] The system collects AI behavior analysis results from all domains and generates a global risk profile R_global. When any domain detects a high-risk event, all domains simultaneously tighten their access policies to achieve second-level network-wide protection.

[0157] To further illustrate, when a user accesses a domain, they first complete QKD key generation (K_q) and MFA two-factor authentication (K_m) using the main solution of this invention. The authentication result and confidence level are sent to the global policy control module via a cross-domain MFA sharing protocol. The global policy control module integrates the risk scores from the AI ​​behavior analysis servers of each domain to calculate the global risk value R_global. When R_global ≥ the threshold θ_risk_global, it triggers a synchronous adjustment of the zero-trust policy across all domains. For example, it may restrict the API call permissions of high-risk accounts across all domains; initiate a network-wide mandatory two-factor authentication mode; or instruct the QKD network at the link layer to update the global quantum key pool in advance. When the cross-domain access requirement ends, the control module revokes the relevant policies and releases the key resources to prevent long-term occupation and abuse.

[0158] Understandably, even if an attacker launches an attack from a non-primary access domain, it will still trigger network-wide synchronous defense. After users have completed MFA verification in a trusted domain, they can quickly access other domains without needing to repeat full verification, reducing latency by 30% to 50%. Through a key pool sharing mechanism, key resource utilization is improved, and the overhead of redundant distribution is reduced.

[0159] The embodiments provided in this application generate an information-theoretically secure symmetric key K_q using polarization-state or phase-encoded quantum signals during the client-server session initialization phase. Error rate detection, information reconciliation, and privacy amplification are then performed at the link layer to achieve key consistency verification and error correction. This key, once generated, serves as the first security factor, used to encrypt multi-factor authentication (MFA) challenge values ​​and session control signaling. Compared to traditional key negotiation methods based on mathematical problems, this method can resist quantum computing attacks, ensuring that data during the link layer authentication process cannot be eavesdropped on, tampered with, or replayed, significantly improving link security and resistance to quantum attacks.

[0160] Based on the first security factor generated by QKD, multiple identity elements such as OTP, biometrics, and behavioral characteristics are collected and independently verified at the authentication gateway. A weighted confidence fusion algorithm is used to calculate the comprehensive authentication confidence C_total. When C_total reaches a threshold, a second security factor K_m is generated. Compared to existing single-factor or fixed-weight MFA mechanisms, the dynamic weighted fusion method of this invention can adjust the weight allocation based on historical verification accuracy and real-time risk situation, thereby improving authentication accuracy while reducing false rejection rate, enhancing user experience and security.

[0161] After users complete two-factor authentication, real-time session data is input into an analysis model composed of a graph neural network (GNN) and a temporal convolutional network (TCN). This model combines multi-dimensional information such as session patterns, access paths, and packet interaction characteristics to perform high-dimensional modeling and calculate a real-time risk score R. Compared to traditional intrusion detection systems that rely on fixed rules or single-dimensional features, this approach can identify complex and covert attack behaviors (such as API abuse and internal privilege abuse) within millisecond response times, significantly improving the accuracy and timeliness of anomaly detection.

[0162] When the risk score R assessed by the AI ​​model exceeds the threshold, the policy engine can refine access control granularity to the level of packet header field matching and API call whitelisting, and complete rule issuance and revocation within ≤5ms through a high-speed policy distribution channel. In high-risk situations, it can also instantly switch to a high-security mode, adding additional authentication factors or freezing access. Compared to existing zero-trust control methods that are granular at the session or user level, this technology can achieve security protection at a finer granularity, reduce the impact on normal business operations, and achieve millisecond-level policy switching, improving the system's real-time defense capabilities.

[0163] The closed-loop feedback mechanism enables coordinated response between the link layer and the application layer. When the application layer risk score continues to rise, the QKD module can be instructed to update the key in advance; when the link layer detects abnormal interference, the application layer authentication strength can be dynamically increased. Compared with existing technologies that protect the link layer and application layer independently, this dual-layer closed-loop design can achieve cross-layer linkage in the early stages of an attack, improving the overall defense flexibility and resistance to persistent attacks.

[0164] It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases the steps shown or described may be executed in a different order than that shown here.

[0165] This application also provides a network access risk assessment device. It should be noted that the network access risk assessment device of this application can be used to execute the network access risk assessment method provided in this application. The network access risk assessment device provided in this application is described below.

[0166] Figure 3 This is a schematic diagram of a network access risk assessment device according to an embodiment of this application. Figure 3 As shown, the device includes:

[0167] The first generation unit 301 is used to generate a first security factor for the network based on the quantum key distribution link established on the network, wherein the first security factor is used to encrypt the transmitted information of the network.

[0168] The acquisition unit 302 is used to acquire multiple user identity features associated with the network, and to acquire the confidence value of each user identity feature among the multiple user identity features, wherein the confidence value is used to indicate the degree of matching between the user identity feature and the expected user identity feature, and the transmitted information includes multiple user identity features.

[0169] The fusion unit 303 is used to perform weighted fusion of the confidence values ​​of each user identity feature to obtain a comprehensive confidence value of multiple user identity features;

[0170] The second generation unit 304 is used to generate a second security factor for the network when the overall confidence value is greater than a preset authentication threshold. The second security factor is used to indicate the access permission status of the network.

[0171] Scoring unit 305 is used to generate a network access risk score based on the second security factor.

[0172] As an optional approach, scoring unit 305 includes:

[0173] The scoring module is used to input the generation status of the second security factor and the network session information of the network into the risk assessment model to obtain the access risk score output by the risk assessment model. The risk assessment model evaluates the user behavior attributes of the network based on the generation status and network session information, and determines the access risk score based on the difference between the user behavior attributes and the expected user behavior attributes. The risk assessment model is a neural network model obtained by training the network based on graph neural network and temporal convolutional network.

[0174] As an optional solution, the device also includes:

[0175] The first acquisition module is used to acquire network layer session information associated with the network before inputting the generation status of the second security factor and the network session information of the network into the risk assessment model. The network layer session information includes the packet header information, packet length distribution information and packet interval time information of the data packets associated with the network.

[0176] The second acquisition module is used to acquire network-related application layer session information before inputting the generation status of the second security factor and the network session information of the network into the risk assessment model. The application layer session information includes network-related interface call sequence information, parameter mode information, and request frequency information.

[0177] The third acquisition module is used to acquire the contextual session information associated with the network before inputting the generation status of the second security factor and the network session information of the network into the risk assessment model. The contextual session information includes the geographical location information, access time period information, and access path information associated with the network.

[0178] The determination module is used to determine network layer session information, application layer session information, and context session information as network session information before inputting the generation status of the second security factor and the network session information of the network into the risk assessment model.

[0179] As an optional solution, the device also includes:

[0180] The first control module is used to generate a network access risk score based on a second security factor, and then, if the access risk score is greater than a first score threshold, to perform a first access restriction operation and a first interface call restriction operation on the network. The first access restriction operation is used to indicate that the network access granularity is refined to packet header field matching, and the first interface call restriction operation is used to indicate that the network's interface calls are only allowed to respond to whitelisted requests.

[0181] As an optional solution, the device also includes:

[0182] The second control module is used to generate a network access risk score based on a second security factor, and then, if the access risk score is greater than a second score threshold, to perform a second access restriction operation and a second interface call restriction operation on the network. The second access restriction operation is used to indicate that network access events are prohibited, and the second interface call restriction operation is used to indicate that network interface calls are only allowed to respond to requests that have passed the authentication whitelist. The second score threshold is greater than the first score threshold.

[0183] As an optional solution, the acquisition unit 302 includes:

[0184] The fourth acquisition module is used to acquire network-related dynamic password features, user body features, user behavior features, and device features. Among these, multiple user identity features include dynamic password features, user body features, user behavior features, and device features.

[0185] The calculation module is used to calculate the similarity of each user's identity feature and obtain the confidence value of each user's identity feature.

[0186] As an optional solution, the device also includes:

[0187] The update module is used to update the first security factor based on the quantum key distribution link when the access risk score is detected to be continuously greater than the third score threshold for a period of time exceeding a preset duration.

[0188] The network access risk assessment device includes a processor and a memory. The first generation unit, acquisition unit, fusion unit, second generation unit, scoring unit, etc. are all stored in the memory as program units. The processor executes the program units stored in the memory to realize the corresponding functions.

[0189] A processor contains a kernel, which retrieves the corresponding program units from memory. One or more kernels can be configured.

[0190] The memory may include non-permanent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM, and the memory includes at least one memory chip.

[0191] This invention provides a computer-readable storage medium storing a program that, when executed by a processor, implements the aforementioned network access risk assessment method.

[0192] This invention provides a processor for running a program, wherein the program executes the network access risk assessment method during runtime.

[0193] like Figure 4 As shown, an embodiment of the present invention provides an electronic device, which includes a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, it implements the above-mentioned network access risk assessment method.

[0194] The devices mentioned in this article can be servers, PCs, tablets, mobile phones, etc.

[0195] This application also provides a computer program product that, when executed on a data processing device, is suitable for executing a program that initializes the access risk assessment method for the aforementioned network.

[0196] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0197] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0198] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.

[0199] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.

[0200] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0201] Memory may include non-persistent memory in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.

[0202] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.

[0203] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article, or apparatus. Unless otherwise specified, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes that element.

[0204] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0205] The above are merely embodiments of this application and are not intended to limit the scope of this application. Various modifications and variations can be made to this application by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this application should be included within the scope of the claims of this application.

Claims

1. A method for assessing network access risks, characterized in that, include: Based on the quantum key distribution link established on the network, a first security factor is generated for the network, wherein the first security factor is used to encrypt the transmitted information of the network; The system acquires multiple user identity features associated with the network, and acquires a confidence value for each of the multiple user identity features, wherein the confidence value is used to indicate the degree of matching between the user identity feature and the expected user identity feature, and the transmitted information includes the multiple user identity features. The confidence values ​​of each user identity feature are weighted and fused to obtain a comprehensive confidence value for the multiple user identity features; If the overall confidence value is greater than a preset authentication threshold, a second security factor is generated for the network, wherein the second security factor is used to indicate the access permission status of the network; Based on the second security factor, an access risk score for the network is generated.

2. The method according to claim 1, characterized in that, The process of generating an access risk score for the network based on the second security factor includes: The generation state of the second security factor and the network session information of the network are input into the risk assessment model to obtain the access risk score output by the risk assessment model. The risk assessment model evaluates the user behavior attributes of the network based on the generation state and the network session information, and determines the access risk score based on the difference between the user behavior attributes and the expected user behavior attributes. The risk assessment model is a neural network model obtained by training a graph neural network and a temporal convolutional network.

3. The method according to claim 2, characterized in that, Before inputting the generation status of the second security factor and the network session information of the network into the risk assessment model, the method further includes: Obtain the network layer session information associated with the network, wherein the network layer session information includes the packet header information, packet length distribution information and packet interval time information of the data packets associated with the network; Obtain the application layer session information associated with the network, wherein the application layer session information includes the interface call sequence information, parameter mode information, and request frequency information associated with the network; Obtain the context session information associated with the network, wherein the context session information includes the geographical location information, access time period information, and access path information associated with the network; The network layer session information, the application layer session information, and the context session information are identified as the network session information.

4. The method according to claim 1, characterized in that, After generating the network access risk score based on the second security factor, the method further includes: If the access risk score is greater than the first score threshold, the network is subjected to a first access restriction operation and a first interface call restriction operation. The first access restriction operation is used to indicate that the access granularity of the network is refined to packet header field matching, and the first interface call restriction operation is used to indicate that the network's interface calls are only allowed to respond to whitelisted requests.

5. The method according to claim 4, characterized in that, After generating the network access risk score based on the second security factor, the method further includes: If the access risk score is greater than the second score threshold, a second access restriction operation and a second interface call restriction operation are performed on the network. The second access restriction operation is used to indicate that access events of the network are prohibited, and the second interface call restriction operation is used to indicate that interface calls of the network are only allowed to respond to requests that have been authenticated and are on a whitelist. The second score threshold is greater than the first score threshold.

6. The method according to any one of claims 1 to 5, characterized in that, The step of obtaining multiple user identity features associated with the network, and obtaining the confidence value of each of the multiple user identity features, includes: The network-associated dynamic password features, user body posture features, user behavior features, and device features are obtained, wherein the multiple user identity features include the dynamic password features, the user body posture features, the user behavior features, and the device features; A similarity calculation is performed on each of the user identity features to obtain the confidence value of each user identity feature.

7. The method according to any one of claims 1 to 5, characterized in that, After generating the network access risk score based on the second security factor, the method further includes: If the access risk score is detected to be continuously greater than the third score threshold for a period of time exceeding a preset duration, the first security factor is updated based on the quantum key distribution link.

8. A network access risk assessment device, characterized in that, include: The first generation unit is used to generate a first security factor for the network based on the quantum key distribution link established on the network, wherein the first security factor is used to encrypt the transmitted information of the network. The acquisition unit is used to acquire multiple user identity features associated with the network, and to acquire the confidence value of each user identity feature among the multiple user identity features, wherein the confidence value is used to indicate the degree of matching between the user identity feature and the expected user identity feature, and the transmitted information includes multiple user identity features; The fusion unit is used to perform weighted fusion of the confidence values ​​of each user identity feature to obtain a comprehensive confidence value of multiple user identity features; The second generation unit is used to generate a second security factor for the network when the overall confidence value is greater than a preset authentication threshold. The second security factor is used to indicate the access permission status of the network. The scoring unit is used to generate a network access risk score based on the second security factor.

9. A processor, characterized in that, The processor is used to run a program, wherein the program executes the method according to any one of claims 1 to 7 when it runs.

10. An electronic device, characterized in that, The method includes one or more processors and a memory for storing one or more programs, wherein when the one or more programs are executed by the one or more processors, the one or more processors cause the one or more processors to implement the method of any one of claims 1 to 7.