Franchised chain supermarket-oriented zero trust architecture information system security operation method

CN122845196APending Publication Date: 2026-09-29BEIJING HUILIN BAIJIA TECHNOLOGY CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202610930247.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2026-06-26
Publication Date
2026-09-29

AI Technical Summary

Technical Problem

然而,现有零信任技术在加盟连锁零售行业的落地存在明显不足:现有信任度评估方法普遍采用静态加权平均算法,无法动态适应加盟连锁超市多主体、高流动性、业务场景复杂多变的特点;缺乏对主体行为时序特征和跨主体关联风险的有效挖掘;未考虑加盟模式特有的业务风险因素对信任度的影响;也没有建立与信任度深度绑定的动态权限调整和安全运营闭环机制

Benefits of technology

[0076](1)本申请提出了基于时序注意力图神经网络的动态信任度评估模型,将图卷积网络和时序注意力机制融合应用于加盟连锁超市的零信任信任度评估;从而能够同时捕捉主体的静态属性特征、时序行为特征和跨主体关联特征,显著提高了信任度评估的准确性和动态性,提高异常检测率,降低误报率。

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122845196A_ABST
    Figure CN122845196A_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of information security, and discloses a kind of franchise chain supermarket-oriented zero trust architecture information system security operation method, including collecting full subject multidimensional data, generating subject attribute feature matrix and subject correlation graph;Dynamic trust degree evaluation model based on time sequence attention graph neural network is constructed, and real-time dynamic trust degree score matrix is output;Establish a pre-audit mechanism for franchised businesses before access, generate network access credentials and initial security policy;Deploy cloud edge end collaborative zero trust execution architecture, verify network access credentials and load initial security policy, generate and execute dynamic access control policy;Build a cross-subject correlation risk propagation model to generate hierarchical early warning and linked disposal instructions;Establish a cross-store model collaborative training framework based on federated learning to generate an updated global trust model;Build a hybrid security operation system to complete the security event closed-loop disposal and full-link audit traceability.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention belongs to the field of information security technology, and in particular relates to a method for secure operation of a zero-trust architecture information system for franchised supermarkets. Background Technology

[0002] With the rapid development of the digital economy, the franchise model has become the mainstream in the retail industry due to its advantages of light assets and rapid expansion, but it has also brought serious information security challenges. Franchise supermarkets have unique problems such as complex trust relationships among multiple parties, decentralized and heterogeneous IT environments, and security vulnerabilities in hybrid operation models, making traditional perimeter-based security architectures completely ineffective.

[0003] Zero-trust architecture, based on the core principles of never trusting, continuous verification, and least privilege, offers a new approach to solving the aforementioned problems. However, existing zero-trust technologies have significant shortcomings in their application in the franchise retail industry: current trust assessment methods generally employ static weighted average algorithms, which cannot dynamically adapt to the characteristics of franchise supermarkets—multiple entities, high mobility, and complex and ever-changing business scenarios; they lack effective mining of the temporal characteristics of entity behavior and cross-entity associated risks; they do not consider the impact of business risk factors unique to the franchise model on trust levels; and they have not established a dynamic permission adjustment and secure operation closed-loop mechanism deeply tied to trust levels.

[0004] Therefore, there is an urgent need for a dynamic trust assessment and security operation method based on advanced machine learning algorithms, specifically tailored to the characteristics of the franchise supermarket business model, to solve the problems of inaccurate trust assessment, insufficient dynamism, and weak risk perception capabilities in existing technologies, and to provide reliable security for the digital transformation of franchise supermarkets. Summary of the Invention

[0005] This application addresses the problems existing in the prior art by proposing a zero-trust architecture information system security operation method for franchised supermarkets. By introducing a temporal attention graph neural network algorithm, a multi-dimensional, dynamic, and interconnected trust evaluation system is constructed, and a complete zero-trust security operation closed loop is established based on this system to achieve accurate, efficient, and adaptive security protection for the franchised supermarket information system.

[0006] To achieve the above objectives, this application provides the following technical solution:

[0007] A method for secure operation of a zero-trust architecture information system for franchised supermarkets includes the following steps: S1. Collect multi-dimensional raw data of all entities in the franchised supermarket, perform standardized preprocessing and relational modeling, and generate an entity attribute feature matrix and entity association graph; S2. Construct a dynamic trust evaluation model based on a temporal attention graph neural network, taking the entity attribute feature matrix and entity association graph as input, and outputting a real-time dynamic trust score matrix for all entities; S3. Establish a pre-entry security audit mechanism for franchisees, conduct an initial trust evaluation of new franchisees based on the dynamic trust evaluation model, and generate network access credentials and initial security policies; S4. Deploy a cloud-edge-device collaborative zero-trust execution architecture to verify network access. S5. Based on the changes in trust scores in the subject association graph and the real-time dynamic trust score matrix, a cross-subject association risk propagation model is constructed, generating tiered early warning and linkage response instructions. S6. A cross-store model collaborative training framework based on federated learning is established, and the dynamic trust assessment model is iteratively optimized using local security data from each store to generate an updated global trust model. S7. A hybrid security operation system for headquarters and franchisees is constructed, and based on the updated global trust model, dynamic access control policies, tiered early warning and linkage response instructions, closed-loop handling of security incidents and full-link audit traceability are completed.

[0008] Optionally, step S1 includes:

[0009] S11. Identify all entities in the franchised supermarket chain globally and classify them into entity types;

[0010] S12. Collect basic attribute data, device attribute data, network attribute data, behavioral attribute data, and business attribute data for each entity;

[0011] S13. Perform standardized preprocessing on the collected raw data, including data cleaning, outlier handling, normalization of numerical data, and coding of categorical data.

[0012] S14. Concatenate all the preprocessed main attribute data into a main attribute feature matrix;

[0013] S15. Construct the main association graph, define nodes, edges and edge weights, and dynamically decay edge weights according to the association time.

[0014] Optionally, step S2 includes:

[0015] S21. Construct a temporal attention graph neural network model, which includes an input layer, a graph convolutional layer, a temporal attention layer, a gated feature fusion layer, and an output layer in sequence.

[0016] S22. Input the main attribute feature matrix and the temporal behavior sequence matrix into the model;

[0017] S23. Mining cross-subject association features through graph convolutional layers;

[0018] S24. Capture the temporal dependencies and importance differences of behaviors through the temporal attention layer to generate temporal feature vectors;

[0019] S25. Adaptively fuse related features and temporal features through a gated feature fusion layer to generate a comprehensive feature vector;

[0020] S26. The comprehensive feature vector is mapped to a trust score through the output layer to generate a real-time dynamic trust score matrix for all subjects.

[0021] S27. The model is trained using supervised learning and then deployed to the headquarters' zero-trust security platform.

[0022] Optionally, step S24 includes:

[0023] S241. Perform sine and cosine position encoding on the temporal behavior sequence matrix and add time position information;

[0024] S242. Input the position-encoded sequence into the multi-head self-attention layer and calculate the attention output matrix;

[0025] S243. Perform global max pooling and global average pooling on the attention output matrix, and concatenate the results to obtain the temporal feature vector.

[0026] Optionally, step S3 includes:

[0027] S31. Receive the application materials submitted by franchisees and conduct a preliminary review;

[0028] S32. Send a safety assessment toolkit to approved franchisees and guide them in conducting automated safety assessments;

[0029] S33. Receive and review safety assessment reports, and issue rectification notices to franchisees with potential safety hazards;

[0030] S34. Conduct a second safety assessment on franchisees who have completed rectification;

[0031] S35. After the second evaluation is passed, the initial trust score of all entities of the new franchisee is calculated using the dynamic trust assessment model.

[0032] S36. Generate an initial security policy based on the initial trust score;

[0033] S37. Assign identity identifiers and zero-trust identity credentials to franchise stores;

[0034] S38. Pre-configure edge security gateway and terminal zero-trust proxy parameters to generate encrypted network access credentials;

[0035] S39. Verify the network access credentials submitted by the franchisee, issue the initial security policy, and complete the formal onboarding.

[0036] Optionally, step S4 includes:

[0037] S41. Deploy the headquarters zero-trust security platform, franchise store edge security gateways and terminal zero-trust agents to build a cloud-edge-device collaborative architecture.

[0038] S42. Verify the network access certificate and the identity certificate submitted by the terminal device;

[0039] S43. Load the initial security policy generated in step S3;

[0040] S44. Receive the real-time trust rating matrix output in step S2;

[0041] S45. For each access request, generate a dynamic access control policy based on the subject's real-time trust score and the security level of the requested resource.

[0042] S46. Distribute the dynamic access control policy to the edge security gateway and the terminal zero-trust agent for execution;

[0043] S47. When a subject's trust score crosses the trust level threshold, update its access permissions in real time.

[0044] Optionally, step S45 includes:

[0045] S451. Obtain the current trust score of the requesting subject and the security level of the requested resource;

[0046] S452. Determine whether to allow access based on the subject's trust score and the resource's security level;

[0047] S453. Determine the corresponding authentication strength based on the subject's trust score;

[0048] S454. Determine the corresponding access frequency limit based on the subject's trust score;

[0049] S455, Generate access control decisions and corresponding security policies.

[0050] Optionally, step S5 includes:

[0051] S51. When a security incident is detected in a subject, immediately reduce the subject's trust score to 0.

[0052] S52. Based on the subject association graph generated in step S1, a breadth-first search algorithm is used to calculate risk propagation.

[0053] S53. Calculate the risk impact value for all relevant entities and adjust their trust scores accordingly;

[0054] S54. Generate early warning information of corresponding levels based on the magnitude of the risk impact value;

[0055] S55. Send the early warning information to relevant entities and managers;

[0056] S56. Automatically execute corresponding joint response measures based on the warning level;

[0057] S57. After the security incident is handled, the trust score and access permissions of the relevant entities shall be gradually restored based on the rectification situation.

[0058] Optionally, step S6 includes:

[0059] S61. Construct a client-server architecture federated learning framework, with the headquarters acting as the central server and each franchise store acting as the client.

[0060] S62. The central server initializes the global trust model parameters and distributes them to all clients;

[0061] S63. In each round of training, a portion of clients are randomly selected to participate in the training, and the current global model parameters are sent to the selected clients.

[0062] S64. Each selected client trains a local model using the local dataset;

[0063] S65. Each client updates and encrypts the local model parameters before uploading them to the central server.

[0064] S66. The central server uses a federated averaging algorithm to aggregate local model updates from all clients and generate a new global model.

[0065] S67. The central server sends the updated global model parameters to all clients.

[0066] S68. Repeat steps S63-S67 until the global model converges.

[0067] Optionally, step S7 includes:

[0068] S71. Clearly define the safety responsibilities of the headquarters safety operations team and franchise owners;

[0069] S72. Establish a graded handling mechanism for safety incidents, classifying safety incidents into general incidents, important incidents, and major incidents, and implementing graded handling accordingly.

[0070] S73. Establish a safety operation assessment mechanism, incorporate safety operation performance into the franchisee assessment system, and link it to franchisee rebates and contract renewals;

[0071] S74. Record all operations of all entities throughout the entire process and generate an audit log;

[0072] S75. Audit logs are stored using a two-tier storage architecture of local and cloud, with critical audit logs stored using consortium blockchain technology.

[0073] S76. Establish a security incident tracing and analysis system to reconstruct the occurrence process of security incidents through correlation analysis of audit logs;

[0074] S77. Regularly generate security audit reports and security operation analysis reports.

[0075] The beneficial effects of this application are as follows:

[0076] (1) This application proposes a dynamic trust evaluation model based on temporal attention graph neural network, which integrates graph convolutional network and temporal attention mechanism for zero-trust trust evaluation of franchise chain supermarkets; thereby, it can simultaneously capture the static attribute features, temporal behavior features and cross-subject association features of the subject, significantly improve the accuracy and dynamism of trust evaluation, increase the anomaly detection rate and reduce the false alarm rate.

[0077] (2) This application establishes a dynamic permission adaptive adjustment mechanism based on trust level, realizing deep binding and real-time linkage between permissions and trust level. According to the real-time trust level score of the subject, the access permission scope, authentication strength and access frequency limit are automatically adjusted, realizing the zero-trust core principle of never trusting, continuous verification and least privilege; it can respond to changes in the subject's trust level in a timely manner and minimize security risks.

[0078] (3) This application proposes a cross-subject related risk propagation and linkage early warning mechanism, which solves the problem of lack of cross-subject related risk perception capability in the prior art; by simulating the risk propagation process through subject association diagram, it can quickly identify and warn of the potential risks of related subjects when a security incident occurs in a certain subject, realize the early prevention and linkage of risks, and effectively prevent the spread and escalation of security incidents.

[0079] (4) This application constructs a cross-store model collaborative training framework based on federated learning, which realizes continuous optimization and updating of the global trust model under the premise of protecting the data privacy and business secrets of each franchise store; it is applicable to the mixed business format of franchise chain supermarkets with unified management by the headquarters and independent operation by the stores, which not only improves the generalization ability of the model, but also solves the contradiction between data silos and privacy protection. Attached Figure Description

[0080] Figure 1 This is a schematic diagram illustrating the application scenarios of the traditional boundary security architecture commonly used in existing franchised supermarket chains.

[0081] Figure 2 This is a schematic diagram of a zero-trust architecture information system security operation method for franchised supermarkets, as described in Embodiment 1 of this application. Detailed Implementation

[0082] To make the objectives, technical solutions, and advantages of this application clearer, the following detailed description of this application is provided in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely one preferred embodiment of this application and are only used to explain this application. They do not limit the scope of protection of this application. All other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this application.

[0083] like Figure 1 The diagram illustrates a common application scenario for the traditional perimeter security architecture widely used in existing franchised supermarket chains. The headquarters data center deploys core business systems such as ERP, membership management, and financial management, connected to franchised stores scattered across the country via VPN or dedicated lines. The franchised stores contain heterogeneous devices including multiple POS terminals, cash register computers, and employee-owned mobile phones, all accessing the headquarters network through a unified perimeter. This architecture employs a static trust mechanism of one-time authentication and permanent trust, which has fundamental security flaws: once the perimeter firewall is breached, attackers can laterally penetrate the headquarters' core systems; furthermore, the varying security levels of franchised store devices allow risks to propagate bidirectionally between headquarters and stores, easily leading to large-scale data breaches and business disruptions.

[0084] Example 1:

[0085] like Figure 2 As shown, a method for secure operation of a zero-trust architecture information system for franchised supermarkets includes the following steps:

[0086] S1. Collect multi-dimensional raw data of all entities in the franchise chain supermarket, perform standardized preprocessing and relationship modeling, and generate entity attribute feature matrix and entity relationship diagram;

[0087] S2. Construct a dynamic trust evaluation model based on a temporal attention graph neural network, taking the subject attribute feature matrix and subject association graph as input, and outputting the real-time dynamic trust score matrix of all subjects.

[0088] S3. Establish a pre-entry security audit mechanism for franchisees, conduct an initial trust assessment of new franchisees based on a dynamic trust assessment model, and generate network access credentials and initial security policies.

[0089] S4. Deploy a cloud-edge-device collaborative zero-trust execution architecture to verify network access credentials and load the initial security policy. At the same time, receive the real-time dynamic trust score matrix and generate and execute dynamic access control policies.

[0090] S5. Based on the changes in trust scores using the subject association diagram and the real-time dynamic trust score matrix, construct a cross-subject association risk propagation model and generate tiered early warning and joint response instructions.

[0091] S6. Establish a cross-store model collaborative training framework based on federated learning, and use local security data from each store to iteratively optimize the dynamic trust evaluation model to generate an updated global trust model.

[0092] S7. Construct a hybrid security operation system for headquarters and franchisees, based on the updated global trust model, dynamic access control policies, hierarchical early warning and linkage response instructions, to complete the closed-loop handling of security incidents and full-link audit traceability.

[0093] In step S1, this application transforms dispersed heterogeneous data into structured data recognizable by the model through standardization processing and relational modeling, laying a solid foundation for subsequent trust assessment and risk analysis. Specifically, step S1 includes:

[0094] S11. Implement a globally unique identity identifier for all entities within the franchised supermarket chain, categorizing them into entity types; assign a 128-bit global identity ID to each entity; entity types are divided into three categories: personnel entities, equipment entities, and system entities. Personnel entities include headquarters management personnel, financial personnel, IT operations and maintenance personnel, security operations personnel, directly operated store managers, directly operated store employees, franchise store owners, franchise store employees, supplier liaisons, and logistics liaisons; equipment entities include POS terminals, cash register computers, inventory management terminals, self-checkout machines, employee mobile phones, supplier terminals, edge security gateways, headquarters servers, and cloud servers; system entities include the headquarters ERP system, membership management system, supply chain management system, financial management system, store inventory management system, and payment system.

[0095] S12. Collect basic attribute data, device attribute data, network attribute data, behavioral attribute data, and business attribute data for each entity. Basic attribute data includes entity name, type, department / store, role, responsibilities, onboarding / cooperation time, contact information, and qualification certificate number. Device attribute data includes device model, serial number, operating system version, CPU model, memory size, hard disk capacity, security patch installation time, virus database version, endpoint security software status, and device health. Network attribute data includes IP address, MAC address, network access method, geographical location, network bandwidth, network latency, packet loss rate, historical access time, and access duration. Behavioral attribute data includes login time, logout time, accessed resource ID, operation type, operation duration, data upload volume, data download volume, number of login failures, and number of abnormal operations. Business attribute data includes store operating area, monthly transaction amount, monthly order volume, number of members, supplier level, years of cooperation, number of historical violations, and number of historical security incidents.

[0096] S13. Standardize and preprocess the collected raw data, including data cleaning, outlier handling, numerical data normalization, and categorical data coding. Data cleaning includes deleting duplicate records, correcting erroneous data, and filling missing values. For numerical missing values, the mean of the same type of data is used for filling; for categorical missing values, the mode is used for filling. This maximizes the preservation of data integrity and accuracy. Outlier handling uses a 3-step process. Outliers are identified in principle. For data exceeding three standard deviations from the normal range, a truncation method is used to limit them to the normal range, effectively avoiding interference from outliers in subsequent model training and evaluation. Numerical data normalization uses the min-max standardization method to map all numerical data to the [0,1] interval. The calculation formula is as follows:

[0097]

[0098] in, x represents the standardized data; x represents the original data. This is the minimum value of the feature; This represents the maximum value of the feature. Normalization can eliminate the influence of dimensions between different features, improving the convergence speed and accuracy of the model.

[0099] Categorical data encoding uses one-hot encoding to convert categorical data into numerical vectors. For example, for device type features, a POS terminal is encoded as [1,0,0,0], and a cash register computer is encoded as [0,1,0,0]. One-hot encoding can convert discrete categorical features into numerical features that the model can process, while avoiding the influence of the order relationship between categories on the model.

[0100] S14. Concatenate all preprocessed main attribute data into a structure with dimension [missing information]. The main attribute feature matrix X is given by N, where N is the total number of subjects and D is the total feature dimension.

[0101] S15. Construct the main association graph, defining nodes, edges, and edge weights. Edge weights dynamically decay based on association time. The specific calculation formula is shown below:

[0102]

[0103] Where V is the set of nodes, each node representing a subject and corresponding to a row in the subject attribute feature matrix X; E is the set of edges, each edge representing a relationship between two subjects; and W is the edge weight matrix. This indicates the strength of the association between subject i and subject j.

[0104] In step S2, using the subject attribute feature matrix X and the subject association graph G as input, a real-time dynamic trust score matrix T for all subjects is output by fusing a graph convolutional network and a temporal attention mechanism. This approach simultaneously captures the static attribute features, temporal behavioral features, and cross-subject association features of subjects, making it more accurate and dynamic than the traditional static weighted average model. Specifically, step S2 includes:

[0105] S21. Construct a temporal attention graph neural network model, which includes an input layer, a graph convolutional layer, a temporal attention layer, a gated feature fusion layer, and an output layer in sequence.

[0106] S22, The main attribute feature matrix and temporal behavior sequence matrix Input model;

[0107] S23. Cross-subject association features are mined through graph convolutional layers; the graph convolutional layers, based on the subject association graph G, mine cross-subject association features. This application employs a two-layer graph convolutional network: the first layer extracts first-order neighborhood features, and the second layer extracts second-order neighborhood features. This multi-layer graph convolutional structure effectively captures indirect relationships between subjects, thereby providing a more comprehensive assessment of subject trust levels. The calculation formula for the first layer graph convolution is:

[0108]

[0109] in, This is the output feature matrix of the first layer graph convolution, with dimensions of N rows and 64 columns, where N is the total number of subjects; The adjacency matrix with self-loops added; A is the original adjacency matrix; I is the identity matrix; for The degree matrix has elements on its diagonal that represent the degree of the corresponding node. This is the weight matrix for the first layer of graph convolution; For bias terms; It is the ReLU activation function. .

[0110] The formula for calculating the convolution of the second layer graph is:

[0111]

[0112] in, This is the output feature matrix of the second layer graph convolution, which is the correlation feature matrix of all subjects; This is the weight matrix for the second layer graph convolution; This is the bias term. For a single subject i, its associated feature vector is the i-th row of the associated feature matrix, with a dimension of 64.

[0113] S24. A temporal attention layer captures the temporal dependencies and importance differences of actions, generating a temporal feature vector. This layer employs a multi-head self-attention mechanism to encode the subject's temporal action sequence, capturing the temporal dependencies and importance differences at different time steps. The multi-head self-attention mechanism can learn temporal features from multiple different subspaces in parallel, offering stronger expressive power than a single attention mechanism. Specifically, this includes the following steps:

[0114] S241. Perform sine and cosine position encoding on the time sequence matrix B, adding time position information:

[0115]

[0116] in, For the temporal behavior sequence matrix after adding position encoding; For the position coding matrix, the sine-cosine position coding method is used:

[0117]

[0118]

[0119] Where t is the time step index, ranging from 0 to T-1; and k is the feature dimension index, ranging from 0 to 15. Positional encoding enables the model to perceive the temporal order of actions, which is crucial for capturing temporal dependencies.

[0120] S242. Input the position-encoded sequence into the multi-head self-attention layer to calculate the attention output matrix. The multi-head self-attention mechanism maps the query, key, and value matrices to h different subspaces, calculates the attention in each subspace, and finally concatenates the results of all subspaces. The formula for calculating the m-th attention head is:

[0121]

[0122] in, , , These are the query, key, and value weight matrices for the m-th attention head, respectively.

[0123] The attention function uses scaled dot product attention:

[0124]

[0125] in, Dimensions for each attention head.

[0126] By concatenating the outputs of all attention heads, we obtain the output of the multi-head self-attention layer:

[0127]

[0128] in, This is the output matrix of the multi-head self-attention layer; This is the output weight matrix.

[0129] S243. Perform global max pooling and global average pooling on the attention output matrix, and concatenate the results to obtain the temporal feature vector. To obtain a fixed-dimensional temporal feature vector, perform global max pooling and global average pooling on Ha, and concatenate the results:

[0130]

[0131] in, The temporal feature vector of subject i; The temporal attention output matrix for subject i; MaxPool is the global max pooling; AvgPool is the global average pooling; This is a vector concatenation operation. Max pooling can capture the most significant behavioral features, while average pooling can capture the overall behavioral trend. Combining the two can more comprehensively express temporal features.

[0132] S25. Adaptively fuse related features and temporal features through a gated feature fusion layer to generate a comprehensive feature vector; specifically, step S25 includes the following steps:

[0133] S251. Concatenate the associated feature vector output by the graph convolutional layer and the temporal feature vector output by the temporal attention layer.

[0134] S252. Calculate the gating vector using the Sigmoid activation function to automatically learn the importance weights of associated features and temporal features;

[0135] S253. Based on the gating vector, the associated features and temporal features are weighted and fused to obtain the comprehensive feature vector.

[0136] The gated feature fusion layer adaptively fuses the association features output from the graph convolutional layer and the temporal features output from the temporal attention layer, automatically learning the importance weights of the two features. Compared to simple concatenation or weighted averaging, gated fusion can dynamically adjust the fusion ratio according to different subjects and scenarios, thus obtaining more accurate comprehensive features. Calculate the gate vector:

[0137]

[0138] in, This is the gate vector; This is the gate weight matrix; For bias terms; This is the Sigmoid activation function.

[0139] Then, the associated features and temporal features are weighted and fused based on the gating vector:

[0140]

[0141] in, is the comprehensive feature vector of subject i; ⊙ represents element-wise multiplication.

[0142] Each element of the gating vector controls the fusion ratio of associated features and temporal features in the corresponding dimension. When an element of the gating vector is close to 1, that dimension is mainly contributed by associated features; when it is close to 0, it is mainly contributed by temporal features. This adaptive fusion mechanism can fully leverage the advantages of both types of features and improve the accuracy of trust assessment.

[0143] S26. The output layer maps the comprehensive feature vector to trust scores, generating a real-time dynamic trust score matrix for all subjects; the output layer maps the comprehensive feature vector to trust scores between 0 and 1 through a fully connected layer and a sigmoid activation function.

[0144]

[0145] in, Trust score for subject i; To output the weight matrix; For bias terms; This is the Sigmoid activation function.

[0146] S27. The model is trained using supervised learning and deployed to the headquarters' zero-trust security platform. The supervised learning model is initially trained using a dataset that includes historical security incident data and normal behavior data from the franchised supermarket chain. Subjects involved in security incidents are labeled 0; normal subjects are labeled 1. The loss function used is the binary cross-entropy loss function.

[0147] in, The true label for subject i; The model's output is assigned a trust score. The binary cross-entropy loss function is well-suited for binary classification problems, effectively measuring the difference between the model's output and the true label. The Adam optimizer is used for model training. After training, the model is deployed in the trust assessment module of the headquarters' zero-trust security platform, running hourly. In one step, the trust score matrix T of all entities is updated. For newly added entities, the average characteristics of entities of the same type are used as initial input to calculate the initial trust score. This real-time update mechanism can reflect changes in entity trust in a timely manner, providing an accurate basis for dynamic permission adjustments.

[0148] In step S3, based on the trust assessment model from step S2, security auditing is moved to the franchisee signing and onboarding stage, controlling security risks at the source and outputting onboarding credentials and initial security strategies. This design completely changes the passive situation of traditional franchise models where onboarding precedes security, intercepting security risks before onboarding. Specifically, it includes the following steps:

[0149] S31. Receive the application materials submitted by franchisees and conduct a preliminary review. Among them, franchisees submit basic store information, business license, legal representative's identity certificate, list of hardware and software equipment, network environment description, etc. The headquarters security operations team will review the authenticity, completeness and compliance of the submitted materials within 1 working day.

[0150] S32. Send a security assessment toolkit to approved franchisees and guide them in conducting automated security assessments. The security assessment toolkit automatically scans terminal devices to detect security risks such as operating system vulnerabilities, weak passwords, unauthorized services, malware, and open network ports, and generates a security assessment report.

[0151] S33. Receive and review safety assessment reports, and issue rectification notices to franchisees with potential safety hazards;

[0152] S34. Conduct a second safety assessment for franchisees who have completed rectification; the safety assessment tool will rescan and generate a post-rectification assessment report;

[0153] S35. After the second evaluation is passed, the initial trust score of all entities of the new franchisee is calculated using the dynamic trust assessment model; all entity information, equipment information and network information of the franchisee are input into the dynamic trust assessment model to calculate the initial trust score of all entities of the new franchisee.

[0154] S36. Generate an initial security policy based on the initial trust score; based on the initial trust score, assign initial access permissions, authentication strength, and access frequency limits to each subject, and generate an initial security policy;

[0155] S37. Assign identity identifiers and zero-trust identity credentials to franchise stores; assign globally unique store IDs to franchise stores, and assign a global identity ID (GID) and zero-trust identity credentials (digital certificates) to each entity;

[0156] S38. Pre-configure edge security gateway and terminal zero-trust proxy parameters to generate encrypted network access credentials;

[0157] S39. Verify the network access credentials submitted by the franchisee, issue the initial security policy, and complete the formal onboarding. Under the guidance of technical personnel, the franchisee installs and activates the edge security gateway and terminal zero-trust agent, and connects to the headquarters zero-trust security platform with the network access credentials. The system automatically issues the initial security policy and completes the formal onboarding.

[0158] In step S4, based on the network access credentials and initial security policy, and simultaneously receiving the output real-time trust score matrix T, a zero-trust execution architecture co-located at the cloud, edge, and endpoint layers is deployed. Dynamic access control policies are generated and executed to achieve the core principles of zero trust: never trust, continuous verification, and least privilege. Specifically, this includes the following steps:

[0159] S41. Deploy a headquarters zero-trust security platform, franchise store edge security gateways, and terminal zero-trust proxies to build a cloud-edge-device collaborative architecture. The headquarters zero-trust security platform is deployed in the cloud and includes: an identity authentication module that verifies the network access credentials and entity identity credentials submitted by terminal devices; only verified devices and entities can access the headquarters network; a policy engine module that loads the initial security policy and receives the real-time trust score matrix T output by the trust assessment module, combining it with the context information of the access request (resource type, access time, access location) to generate dynamic access control policies; a micro-segmentation module that, based on the trust level and business needs of the entity, implements network micro-segmentation between different business systems, different stores, and different entities to prevent lateral movement; an encrypted transmission module that encrypts all data transmitted across the network using AES-256 to ensure data transmission security; and a policy distribution module that distributes the generated dynamic access control policies to the edge security gateways and terminal zero-trust proxies for execution.

[0160] The edge security gateway for franchise stores is deployed locally in each franchise store. It includes: receiving initial and dynamic security policies issued by headquarters and caching them locally; authenticating and verifying the identity and permissions of access requests from local terminal devices; performing deep packet inspection (DPI) on local traffic and filtering malicious traffic; collecting security status data and behavior data of local terminal devices, preprocessing them, and uploading them to headquarters; and independently executing the cached security policies in the event of a network outage to ensure the normal operation of store business.

[0161] The zero-trust proxy for endpoints is deployed on all endpoint devices. It includes: identifying and checking the health of endpoint devices and collecting real-time security status data; intercepting all access requests and sending authentication and authorization requests to the headquarters policy engine; establishing an encrypted tunnel with the headquarters, through which all access traffic is transmitted; executing the initial and dynamic security policies issued by the headquarters to control the access behavior of endpoints; and detecting abnormal endpoint behavior and reporting it to the headquarters security platform in a timely manner.

[0162] S42. Verify the network access certificate and the identity certificate submitted by the terminal device;

[0163] S43. Load the initial security policy generated in step S3;

[0164] S44. Receive the real-time trust rating matrix output in step S2;

[0165] S45. For each access request, a dynamic access control policy is generated based on the subject's real-time trust score and the security level of the requested resource. The dynamic access control policy generation logic is as follows:

[0166] For any access request Where u is the requesting body, r is the requested resource, t is the access time, and l is the access location. Specifically, it includes the following steps:

[0167] S451. Obtain the current trust score of the requesting subject u. and the security level of the requested resource r Security levels are divided into four levels: Open (1), Secret (2), Confidential (3), and Top Secret (4);

[0168] S452. Determine whether to allow access based on the subject's trust score and the resource's security level;

[0169] S453. Determine the corresponding authentication strength based on the subject's trust score;

[0170] S454. Determine the corresponding access frequency limit based on the subject's trust score;

[0171] S455, Generate access control decisions and corresponding security policies.

[0172] S46. Distribute the dynamic access control policy to the edge security gateway and the terminal zero-trust agent for execution;

[0173] S47. When a subject's trust score crosses the trust level threshold, update its access permissions in real time.

[0174] When a subject's trust score changes and crosses a trust level threshold, the policy engine immediately recalculates all of the subject's access permissions, generates a new security policy, and issues it for execution, achieving real-time dynamic adjustment of permissions. This dynamic adjustment mechanism ensures that a subject's permissions always match its current trust level, minimizing security risks.

[0175] In step S5, using the subject association graph G and changes in trust scores as input, a cross-subject risk propagation model is constructed. When a security incident occurs in a subject, the model automatically identifies and warns of potential risks to related subjects, generating tiered warnings and coordinated response instructions. This mechanism effectively addresses the limitations of traditional security systems' single-point alarm and single-point response, achieving global risk awareness and coordinated response. Specifically, it includes the following steps:

[0176] S51. When a security incident is detected in a subject, immediately reduce the subject's trust score to 0 and prohibit it from accessing all business systems and data resources.

[0177] S52. Based on the subject association graph generated in step S1, a breadth-first search algorithm is used to calculate risk propagation; the calculation formula for risk propagation is:

[0178]

[0179] in, The initial risk value for node i In the event of a security incident; Let the weight of the edge between node i and node j be denoted as ; Rate the current trust level of node j; Let be the risk impact value of node j, with a value range of [0,1].

[0180] S53. Calculate the risk impact value for all relevant entities and adjust their trust scores accordingly; for each node j affected by the risk, the formula for adjusting its trust score is as follows:

[0181]

[0182] in, This is the risk impact coefficient; This is the adjusted trust score.

[0183] S54. Based on the magnitude of the risk impact, generate corresponding warning information. The warning information includes the affected entity ID, entity name, risk level, risk source, scope of impact, and handling recommendations. The warnings are divided into three levels based on the magnitude of the risk impact: Level 1 Warning (Red): ≥0.5 indicates high risk; Level II warning (orange): 0.3≤ <0.5 indicates medium risk; Level 3 warning (yellow): 0.1≤ A value less than 0.3 indicates low risk.

[0184] S55. Send the early warning information to relevant entities and managers;

[0185] S56. Automatically execute corresponding joint response measures based on the warning level;

[0186] S57. After a security incident is resolved, trust scores and access permissions for the relevant entities will be gradually restored based on the rectification progress. This includes:

[0187] S571. Receive rectification completion applications and automatically verify device security status, behavioral compliance, and security knowledge assessment results. Specifically, when a rectification completion application is submitted through a terminal zero-trust agent, the system automatically triggers multi-dimensional verification: device security status verification, scanning terminal operating system patch versions, virus database versions, malware detection results, port open status, and other security indicators; behavioral compliance verification, continuously monitoring the subject's operational behavior for 24 hours to verify for any abnormal operations, unauthorized access, or other risky behaviors; and knowledge assessment verification, conducting online security knowledge assessments on the subject, with a minimum score of 80 points.

[0188] S572. Calculate the rectification completion score by weighting the verification items;

[0189] S573. Based on the rectification completion score, restore the trust score in a step-by-step manner, with each restoration not exceeding 30% of the lost value; for example: rectification completion score ≥ 90 points: restore 30% of the current lost trust score; rectification completion score 75-89 points: restore 20% of the current lost trust score; rectification completion score 60-74 points: restore 10% of the current lost trust score; rectification completion score < 60 points: no restoration, and a second rectification notice will be issued.

[0190] S574. During the observation period, the trust level is restored incrementally until the preset restoration ratio is reached. If there are no abnormalities at the end of the observation period, the trust level is restored to 90% of the level before the incident. If there are no security incidents for 30 consecutive days, the original trust level score and corresponding access permissions are fully restored.

[0191] S575. If abnormal behavior is detected during the recovery process, the recovery will be terminated immediately and the trust level will be rolled back.

[0192] In step S6, using the local security data of each franchise store as input, a cross-store model collaborative training framework based on the federated averaging algorithm is constructed. Without sharing the original data of each store, the dynamic trust evaluation model is iteratively optimized to generate an updated global trust model. This resolves the contradiction between data privacy protection and model generalization ability in franchised supermarket chains. Specifically, it includes the following steps:

[0193] S61. Construct a client-server architecture federated learning framework, with the headquarters acting as the central server and each franchise store acting as the client. The central server is deployed on the headquarters' zero-trust security platform and is responsible for the initialization, distribution, aggregation, and updating of the global model. The client is deployed on the edge security gateway of each franchise store and is responsible for training the local model using local data and uploading the updated model parameters to the central server.

[0194] S62. The central server initializes the global trust model parameters and distributes them to all clients;

[0195] S63. In each round of training, a portion of clients are randomly selected to participate in the training, and the current global model parameters are sent to the selected clients.

[0196] S64. Each selected client trains a local model using the local dataset;

[0197] S65. Each client updates and encrypts the local model parameters before uploading them to the central server.

[0198] S66. The central server uses a federated averaging algorithm to aggregate local model updates from all clients and generate a new global model.

[0199] S67. The central server sends the updated global model parameters to all clients.

[0200] S68. Repeat steps S63-S67 until the global model converges.

[0201] Step S65 includes:

[0202] S651. The client calculates the difference between the local model parameters and the global model parameters to obtain the local model parameter update.

[0203] S652. Add Gaussian noise to the local model parameter update to achieve differential privacy protection;

[0204] S653. Use a homomorphic encryption algorithm to encrypt the model parameter updates after adding noise;

[0205] S654. Upload the encrypted model parameters to the central server.

[0206] Specifically, step S7 includes the following steps:

[0207] S71. Clearly define the safety responsibilities of the headquarters' safety operations team and franchise owners; the hybrid safety operations system fully leverages the headquarters' professional advantages and the franchisees' initiative to achieve lightweight and efficient safety operations. This operating model is particularly suitable for franchised supermarket chains, solving the problem of franchise stores lacking professional safety personnel while improving the efficiency and response speed of safety operations.

[0208] The responsibilities of the headquarters security operations team include the daily maintenance, upgrades, and troubleshooting of the zero-trust security platform; the formulation, adjustment, and optimization of the overall security strategy; real-time monitoring and analysis of the overall security situation; handling and investigating important and major security incidents; providing security training and technical guidance to franchisees; and regularly generating security operations reports and submitting them to the headquarters management.

[0209] The responsibilities of franchise owners include the daily security maintenance of the store's terminal equipment, including installing security patches, updating virus definitions, and scanning for and removing malware; training and managing the security awareness of the store's employees; managing the security of the store's WiFi network and prohibiting unauthorized devices from accessing it; handling general security incidents independently and submitting handling reports; cooperating with the headquarters' security operations team in security inspections and incident investigations; and regularly participating in security training organized by the headquarters.

[0210] S72. Establish a graded handling mechanism for security incidents, classifying security incidents into general incidents, important incidents, and major incidents, and implementing graded handling accordingly; specifically, step S72 includes the following steps:

[0211] S721. For general incidents, the franchisee shall handle them independently and submit a handling report after completion. The headquarters shall review the report. General incidents include terminal virus infection, weak passwords, and single login failures. The franchisee shall handle them independently and submit a handling report through the security operations self-service platform within 24 hours after completion. The headquarters security operations team shall review the report within one business day.

[0212] S722. For critical incidents, the headquarters security operations team will remotely guide franchisees in handling the situation, with the entire process monitored. Critical incidents include multiple failed login attempts, access to unauthorized resources outside of working hours, and abnormal data downloads. The headquarters security operations team will remotely guide franchisees in handling these incidents, with the entire process monitored. A handling report will be generated and archived upon completion.

[0213] S723. For major incidents, the headquarters security operations team shall immediately activate the emergency response plan, rush to the scene to handle the situation, and coordinate external support as necessary. Major incidents include ransomware attacks, system crashes, data breaches, and hacker intrusions. The headquarters security operations team shall immediately activate the emergency response plan, rush to the scene as soon as possible to handle the situation, and coordinate external security experts and public security authorities for support as necessary.

[0214] S73. Establish a safety operation assessment mechanism, incorporating safety operation performance into the franchisee assessment system and linking it to franchisee rebates and contract renewals. Assessment indicators include average store trust ratings, number of safety incidents, safety inspection completion rate, and safety rectification completion rate. The assessment results are directly linked to franchisees' quarterly rebates and annual contract renewals, ensuring safety responsibility is implemented by each franchisee, significantly improving their safety awareness and enthusiasm, and forming a safety operation framework jointly participated in by headquarters and franchisees. For example, priority in assessment results in an additional 5% quarterly rebate; passing the assessment results in the normal quarterly rebate; failing the assessment results in a 10% deduction from the quarterly rebate and a deadline for rectification; if two consecutive quarters of assessment fail, headquarters has the right to terminate the franchise contract.

[0215] S74. Record all operations of all subjects in their entirety and generate audit logs; the audit logs include identity authentication logs, access control logs, system operation logs, security event logs, and trust level change logs.

[0216] S75. A two-tier storage architecture, local and cloud, is used to store audit logs. Critical audit logs are stored using consortium blockchain technology. Critical audit logs, such as logs of major security incidents, are stored using consortium blockchain technology. The headquarters and each franchise store act as blockchain nodes to jointly maintain the audit log ledger. Each audit log record is digitally signed and a hash value is generated to ensure that the audit logs are tamper-proof and traceable.

[0217] S76. Establish a security incident tracing and analysis system to reconstruct the occurrence process of security incidents through correlation analysis of audit logs;

[0218] S77. Regularly generate security audit reports and security operation analysis reports.

[0219] The above-described specific embodiments are preferred embodiments of a zero-trust architecture information system security operation method for franchised supermarkets, and are not intended to limit the specific scope of this application. The scope of this application includes but is not limited to these specific embodiments. All equivalent changes made in accordance with the shape and structure of this application are within the protection scope of this application.

Claims

1. A method for secure operation of a zero-trust architecture information system for franchised supermarkets, characterized in that, Includes the following steps: S1. Collect multi-dimensional raw data of all entities in the franchise chain supermarket, perform standardized preprocessing and relationship modeling, and generate entity attribute feature matrix and entity relationship diagram; S2. Construct a dynamic trust evaluation model based on a temporal attention graph neural network, taking the subject attribute feature matrix and subject association graph as input, and outputting the real-time dynamic trust score matrix of all subjects. S3. Establish a pre-entry security audit mechanism for franchisees, conduct an initial trust assessment of new franchisees based on the dynamic trust assessment model, and generate network access credentials and initial security policies. S4. Deploy a cloud-edge-device collaborative zero-trust execution architecture, verify the network access credentials and load the initial security policy, and simultaneously receive the real-time dynamic trust score matrix to generate and execute dynamic access control policies. S5. Based on the changes in trust scores of the subject association diagram and the real-time dynamic trust score matrix, construct a cross-subject association risk propagation model and generate hierarchical early warning and linkage response instructions. S6. Establish a cross-store model collaborative training framework based on federated learning, and use local security data from each store to iteratively optimize the dynamic trust evaluation model to generate an updated global trust model. S7. Construct a hybrid security operation system for headquarters and franchisees, based on the updated global trust model, dynamic access control policies, hierarchical early warning and linkage response instructions, to complete the closed-loop handling of security incidents and full-link audit traceability.

2. The method for secure operation of a zero-trust architecture information system for franchised supermarkets according to claim 1, characterized in that, Step S1 includes: S11. Identify all entities in the franchised supermarket chain globally and classify them into entity types; S12. Collect basic attribute data, device attribute data, network attribute data, behavioral attribute data, and business attribute data for each entity; S13. Perform standardized preprocessing on the collected raw data, including data cleaning, outlier handling, normalization of numerical data, and coding of categorical data. S14. Concatenate all the preprocessed main attribute data into a main attribute feature matrix; S15. Construct the main association graph, define nodes, edges and edge weights, and dynamically decay edge weights according to the association time.

3. The method for secure operation of a zero-trust architecture information system for franchised supermarkets according to claim 1, characterized in that, Step S2 includes: S21. Construct a temporal attention graph neural network model, which includes an input layer, a graph convolutional layer, a temporal attention layer, a gated feature fusion layer, and an output layer in sequence. S22. Input the main attribute feature matrix and the temporal behavior sequence matrix into the model; S23. Mining cross-subject association features through graph convolutional layers; S24. Capture the temporal dependencies and importance differences of behaviors through the temporal attention layer to generate temporal feature vectors; S25. Adaptively fuse related features and temporal features through a gated feature fusion layer to generate a comprehensive feature vector; S26. The comprehensive feature vector is mapped to a trust score through the output layer to generate a real-time dynamic trust score matrix for all subjects. S27. The model is trained using supervised learning and then deployed to the headquarters' zero-trust security platform.

4. The method for secure operation of a zero-trust architecture information system for franchised supermarkets according to claim 3, characterized in that, Step S24 includes: S241. Perform sine and cosine position encoding on the temporal behavior sequence matrix and add time position information; S242. Input the position-encoded sequence into the multi-head self-attention layer and calculate the attention output matrix; S243. Perform global max pooling and global average pooling on the attention output matrix, and concatenate the results to obtain the temporal feature vector.

5. The method for secure operation of a zero-trust architecture information system for franchised supermarkets according to claim 1, characterized in that, Step S3 includes: S31. Receive the application materials submitted by franchisees and conduct a preliminary review; S32. Send a safety assessment toolkit to approved franchisees and guide them in conducting automated safety assessments; S33. Receive and review safety assessment reports, and issue rectification notices to franchisees with potential safety hazards; S34. Conduct a second safety assessment on franchisees who have completed rectification; S35. After the second evaluation is passed, the initial trust score of all entities of the new franchisee is calculated using the dynamic trust assessment model. S36. Generate an initial security policy based on the initial trust score; S37. Assign identity identifiers and zero-trust identity credentials to franchise stores; S38. Pre-configure edge security gateway and terminal zero-trust proxy parameters to generate encrypted network access credentials; S39. Verify the network access credentials submitted by the franchisee, issue the initial security policy, and complete the formal onboarding.

6. The method for secure operation of a zero-trust architecture information system for franchised supermarkets according to claim 1, characterized in that, Step S4 includes: S41. Deploy the headquarters zero-trust security platform, franchise store edge security gateways and terminal zero-trust agents to build a cloud-edge-device collaborative architecture. S42. Verify the network access certificate and the identity certificate submitted by the terminal device; S43. Load the initial security policy generated in step S3; S44. Receive the real-time trust rating matrix output in step S2; S45. For each access request, generate a dynamic access control policy based on the subject's real-time trust score and the security level of the requested resource. S46. Distribute the dynamic access control policy to the edge security gateway and the terminal zero-trust agent for execution; S47. When a subject's trust score crosses the trust level threshold, update its access permissions in real time.

7. The method for secure operation of a zero-trust architecture information system for franchised supermarkets according to claim 6, characterized in that, Step S45 includes: S451. Obtain the current trust score of the requesting subject and the security level of the requested resource; S452. Determine whether to allow access based on the subject's trust score and the resource's security level; S453. Determine the corresponding authentication strength based on the subject's trust score; S454. Determine the corresponding access frequency limit based on the subject's trust score; S455, Generate access control decisions and corresponding security policies.

8. The method for secure operation of a zero-trust architecture information system for franchised supermarkets according to claim 1, characterized in that, Step S5 includes: S51. When a security incident is detected in a subject, immediately reduce the subject's trust score to 0. S52. Based on the subject association graph generated in step S1, a breadth-first search algorithm is used to calculate risk propagation. S53. Calculate the risk impact value for all relevant entities and adjust their trust scores accordingly; S54. Generate early warning information of corresponding levels based on the magnitude of the risk impact value; S55. Send the early warning information to relevant entities and managers; S56. Automatically execute corresponding joint response measures based on the warning level; S57. After the security incident is handled, the trust score and access permissions of the relevant entities shall be gradually restored based on the rectification situation.

9. The method for secure operation of a zero-trust architecture information system for franchised supermarkets according to claim 1, characterized in that, Step S6 includes: S61. Construct a client-server architecture federated learning framework, with the headquarters acting as the central server and each franchise store acting as the client. S62. The central server initializes the global trust model parameters and distributes them to all clients; S63. In each round of training, a portion of clients are randomly selected to participate in the training, and the current global model parameters are sent to the selected clients. S64. Each selected client trains a local model using the local dataset; S65. Each client updates and encrypts the local model parameters before uploading them to the central server. S66. The central server uses a federated averaging algorithm to aggregate local model updates from all clients and generate a new global model. S67. The central server sends the updated global model parameters to all clients. S68. Repeat steps S63-S67 until the global model converges.

10. The method for secure operation of a zero-trust architecture information system for franchised supermarkets according to claim 1, characterized in that, Step S7 includes: S71. Clearly define the safety responsibilities of the headquarters safety operations team and franchise owners; S72. Establish a graded handling mechanism for safety incidents, classifying safety incidents into general incidents, important incidents, and major incidents, and implementing graded handling accordingly. S73. Establish a safety operation assessment mechanism, incorporate safety operation performance into the franchisee assessment system, and link it to franchisee rebates and contract renewals; S74. Record all operations of all entities throughout the entire process and generate an audit log; S75. Audit logs are stored using a two-tier storage architecture of local and cloud, with critical audit logs stored using consortium blockchain technology. S76. Establish a security incident tracing and analysis system to reconstruct the occurrence process of security incidents through correlation analysis of audit logs; S77. Regularly generate security audit reports and security operation analysis reports.