Data circulation method and system based on slice network and trusted data space
By deploying private network devices and SRV6 VPN networks in trusted data spaces, combined with the dual authentication mechanism of the network controller, the data leakage problem during user access is solved, and the user data is securely isolated and trusted interaction is achieved.
Patent Information
- Application Number
- CN202510813042.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-18
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-06-18
AI Technical Summary
The existing trusted data space network is prone to data privacy leakage when users access, and is even crawled by network models and trained into an agent, threatening the security of user data.
The data circulation method based on slice network and trusted data space is adopted. By deploying private network equipment one by one with the user, including a first router, core router and connector for communication connection, the SRV6 VPN network is used for user access, and combined with the dual authentication mechanism of the network controller, it ensures that the user's trusted credentials and network attribute tags are checked only after the data interaction is allowed.
It enhances the isolation and security of user data transmission, prevents data from being exposed on the public network, improves data privacy protection capabilities, and ensures the security and credibility of data interactions.
Smart Images

Figure CN120358078A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data circulation, and particularly to a data circulation method and system based on a slice network and a trusted data space. Background Art
[0002] Data circulation refers to the process of data flowing between different entities, including data opening, sharing, trading, exchanging, etc. In the era of big data, effective data circulation is of great practical significance for improving production efficiency, reducing production costs, promoting production innovation, and assisting production decision-making.
[0003] In the process of data circulation, a trusted data space, which is born out of the urgent need for cross-organization collaboration and data sharing in the data-driven era, can build a trusted and controllable data circulation environment through technologies such as blockchain, privacy computing, and federated learning. Specifically, the trusted data space uses blockchain to guarantee data ownership and transaction traceability, combines privacy-enhancing means such as multi-party secure computing and homomorphic encryption to achieve "data available but invisible", and at the same time regulates data usage rights and collaboration rules through mechanisms such as distributed identity authentication and smart contracts, aiming to break data islands and meet privacy protection and compliance requirements, and support the trusted sharing and value mining of cross-domain data.
[0004] However, when the trusted data space is promoted and applied, since the existing trusted data space network adopts the internet method, it is easy to cause the leakage of user data privacy after users access the trusted data space network, and even be crawled by network large models and trained into intelligent agents to threaten user data security. Summary of the Invention
[0005] The purpose of the present invention is to provide a data circulation method and system based on a slice network and a trusted data space to solve the technical problem that data leakage is likely to occur and data security is threatened when data interaction is carried out based on the trusted data space.
[0006] To achieve the above object, the present invention proposes the following technical solutions: In the first aspect, the present technical solution provides a data circulation method based on a slice network and a trusted data space, including: A private network device deployed corresponding to each user one by one, each private network device including a first router and a core router connected by communication; wherein, a connector is connected to each core router, and each core router is communicatively connected to the trusted data space via a second router; The method includes the following steps: The connector obtains the feedback generated by the private network to allow the user to access the connector through the corresponding slice private network based on the pre-configured static route; Obtain the user's trusted credentials and authentication messages forwarded after being addressed by the first router; wherein, the authentication message includes a header generated based on a network attribute label; wherein, the header is generated by the first router based on a sliced private network, and the network attribute label corresponds to the sliced private network one by one; Verify the user's trusted credentials, parse the authentication message, and forward the obtained network attribute label to the network controller; When the verification of the user's trusted credentials passes and it is determined that the network controller passes the verification of the network attribute label, allow the user to enter the trusted data space through the second router for data interaction.
[0007] Further, the sliced private network is an SRV6 VPN network; before the connector obtains the private network generation feedback to allow the user to use the pre-configured static route as the basis and access the connector through the corresponding sliced private network, it includes: The network controller obtains the service SLA requirements of each user to generate corresponding sliced network generation instructions; Based on the sliced network generation instructions, configure the second router, as well as the first router and core router corresponding to each user, to generate customized sliced private networks of corresponding levels; Among them, the SLA metrics corresponding to the service SLA requirements include: bandwidth parameters, delay parameters, and jitter parameters; the levels of the sliced private networks corresponding to the service SLA requirements from low to high include: soft isolation level, soft slicing level, deterministic slicing level, hard slicing level, and dedicated slicing level.
[0008] Further, it includes various dedicated network media, and both ends of any dedicated network media are respectively communicatively connected to the corresponding user and the first router; wherein, the dedicated network media includes a CPE access terminal for ensuring that the authentication message from the user is preferentially forwarded to the first router.
[0009] Further, it includes: When the connector fails to pass the verification of the user's trusted credentials, send the verification result to the user to re-obtain and verify the user's trusted credentials; When it is determined that the number of times the verification of the user's trusted credentials fails reaches the preset number threshold within the preset duration, send a random verification code to other clients bound to the user; Obtain the random verification code input by the user, and when its verification fails, send a first abnormal access feedback to the connector to disconnect the data connection between the user and the connector and reject the login.
[0010] Further, it includes: When the connector determines that the network controller fails to pass the verification of the network attribute label, it sends a second abnormal access feedback to the connector to disconnect the data connection between the user and the connector and reject the login.
[0011] In a second aspect, the present technical solution provides a data circulation system based on a sliced network and a trusted data space, including: A private network device deployed corresponding to each user one by one. Each private network device includes a first router and a core router connected by communication. Among them, a connector is connected to each core router, and each core router is communicatively connected to the trusted data space through a second router; It includes the following functional modules: A first acquisition module, configured to enable the connector to obtain a feedback generated by the private network to allow the user to access the connector based on a pre-configured static route and through the corresponding sliced private network; A second acquisition module, configured to acquire the user's trusted credentials and authentication packets forwarded after being addressed by the first router; among them, the authentication packet includes a header generated based on the network attribute label; among them, the header is generated by the first router based on the sliced private network, and the network attribute label corresponds to the sliced private network one by one; A verification and forwarding module, configured to verify the user's trusted credentials, parse the authentication packet, and forward the obtained network attribute label to the network controller; A data circulation module, configured to allow the user to enter the trusted data space through the second router for data interaction when the verification of the user's trusted credentials passes and it is determined that the network controller passes the verification of the network attribute label.
[0012] Further, it includes: A third acquisition module, configured to enable the network controller to acquire the service SLA requirements of each user to generate corresponding sliced network generation instructions; A private network generation module, configured to issue configurations to the second router, as well as the first router and core router corresponding to each user, based on the sliced network generation instructions to generate customized sliced private networks of corresponding levels; Among them, the SLA indicators corresponding to the service SLA requirements include: bandwidth parameters, delay parameters, and jitter parameters; the levels of the sliced private networks corresponding to the service SLA requirements from low to high include: soft isolation level, soft sliced level, deterministic sliced level, hard sliced level, and dedicated sliced level.
[0013] Further, it includes: An abnormal feedback module, configured to send a second abnormal access feedback to the connector to disconnect the data connection between the user and the connector and reject the login when the connector determines that the network controller fails to pass the verification of the network attribute label.
[0014] In a third aspect, the present technical solution provides an electronic device, including at least one processor, the processor being coupled to a memory, and a computer program being stored in the memory, the computer program being configured to execute the above method when being run by the processor.
[0015] In a fourth aspect, the present technical solution provides a computer-readable storage medium, on which a computer program is stored, the computer program being used to be executed by a processor to implement the above method.
[0016] Beneficial effects: As can be seen from the above technical solutions, the technical solution of the present invention provides a data circulation method based on a slice network and a trusted data space to improve the technical defect that data privacy leakage is likely to occur when data interaction and circulation are performed through the trusted data space.
[0017] The present technical solution deploys dedicated network devices corresponding to each user one by one. In each dedicated network device, there are a first router and a core router connected communicatively. Among them, a connector is connected to each core router, and each core router is communicatively connected to the trusted data space via a second router. Based on the above dedicated network devices, the following data flow process is included: First, the connector obtains a feedback generated by the dedicated network to allow the user to access the connector through the corresponding slice dedicated network based on a pre-configured static route. Second, obtain the user trusted credential and the authentication message forwarded after being addressed by the first router; wherein, the authentication message includes a header generated based on a network attribute label. Among them, the header is generated by the first router based on the slice dedicated network, and the network attribute label corresponds to the slice dedicated network one by one. Then, verify the user trusted credential, and after parsing the authentication message, forward the obtained network attribute label to the network controller. Finally, when the verification of the user trusted credential passes and it is determined that the network controller passes the verification of the network attribute label, allow the user to enter the trusted data space via the second router for data interaction.
[0018] At this time, based on this technical solution, first, a corresponding slice private network is set up for each user, realizing the dual coordination between the slice network and the trusted data space, enhancing the isolation of user data transmission, and further ensuring the data privacy and security of the data provider. Secondly, considering that data security is related to both the human factors of logged-in users and the objective factors of the network, a dual authentication mechanism of the network controller and the trusted data circulation space is adopted, that is, the user's trusted credentials are verified through the connector, and the network attributes are verified through the network controller, thus strengthening the protection against abnormal intruders. Furthermore, by adopting the access method of the virtual private network router, the access mode from the user-side IP is converted to the slice private network virtual private network routing addressing mode for connector access, realizing network identity authentication while preventing user data from being exposed on the public network and enhancing user data security.
[0019] It should be understood that all combinations of the foregoing concepts and additional concepts described in more detail below can be regarded as part of the inventive subject matter of the present disclosure as long as such concepts do not contradict each other.
[0020] The foregoing and other aspects, embodiments, and features of the teachings of the present invention can be more fully understood from the following description in conjunction with the accompanying drawings. Other additional aspects of the present invention, such as the features and / or beneficial effects of exemplary embodiments, will be apparent from the following description or will be learned through practice of the specific embodiments according to the teachings of the present invention. Brief Description of the Drawings
[0021] The drawings are not intended to be drawn to scale. In the drawings, each identical or nearly identical component shown in various figures may be represented by the same reference numeral. For clarity, not every component is labeled in each figure. Now, embodiments of various aspects of the present invention will be described by way of example and with reference to the drawings, wherein: Figure 1 is the hardware deployment topology diagram corresponding to the data circulation method based on the slice network and the trusted data space described in this embodiment; Figure 2 is the flowchart of the data circulation method based on the slice network and the trusted data space described in this embodiment; Figure 3 is the flowchart for generating a customized slice private network; Figure 4 is the processing flowchart when the user's trusted credential verification fails; Figure 5 is the processing flowchart when the network attribute label verification fails; Figure 6 is the structural block diagram of the data circulation system based on the slice network and the trusted data space described in this embodiment; Figure 7 It is a structural block diagram of the electronic device described in this embodiment. Detailed implementation manners
[0022] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the described embodiments of the present invention without creative efforts shall fall within the scope of protection of the present invention. Unless otherwise defined, the technical terms or scientific terms used herein shall have the ordinary meanings as understood by those of ordinary skill in the art to which the present invention pertains.
[0023] The terms "first", "second", and similar terms used in the specification and claims of this application do not denote any order, quantity, or importance, but are only used to distinguish different components. Similarly, unless clearly specified otherwise in the context, the singular forms "a", "an", or "the" and similar terms do not denote a limitation of quantity, but rather indicate the presence of at least one. The terms "include" or "comprise" and similar terms mean that the elements or items appearing before "include" or "comprise" cover the features, wholes, steps, operations, elements, and / or components listed after "include" or "comprise", and do not exclude the existence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations. The terms "upper", "lower", "left", "right", etc. are only used to represent relative positional relationships, and when the absolute position of the object being described changes, the relative positional relationship may also change accordingly.
[0024] In the big data era, effective data circulation has important practical significance, and the data circulation method based on the trusted data space has been gradually promoted and applied. However, since the existing trusted data space network adopts the internet method, it is easy to cause the leakage of user data privacy after the user accesses the trusted data space network, and even be crawled by the network large model and trained into an intelligent agent to threaten the security of user data. Based on this, this embodiment aims to provide a data circulation method based on the slice network and the trusted data space to solve the above technical problems related to data security.
[0025] The following will specifically introduce the data circulation method based on the slice network and the trusted data space described in this embodiment with reference to the accompanying drawings.
[0026] Combined with Figure 1As shown in the figure, in order to facilitate the implementation of subsequent data circulation methods, dedicated network devices are deployed corresponding to each user one by one. Each dedicated network device includes a first router and a core router that are communicatively connected. Among them, a connector is connected to each core router, and each core router is communicatively connected to the trusted data space via a second router. At the same time, it also includes a network controller that is communicatively connected to each first router, each core router, and the second router via a third router.
[0027] Among them, the first router, the second router, and the third router are mainly used for network access of users and application systems (such as network controllers, trusted data spaces, etc.). Their main functions include but are not limited to maintaining user / application system routing tables and providing the first-hop routing for user / application systems to access other user / application systems. The main uses of the core router include but are not limited to routing exchange and transmission relay during the data transmission process, and are responsible for accessing each user connector in this embodiment.
[0028] At this time, two network levels will be correspondingly generated: the access network and the sliced dedicated network. The access network refers to: the connection between users and each connector is realized through the first router, and it is composed in a direct fiber connection manner. The sliced dedicated network refers to: through network slicing technology, the first router, the core router, the trusted data space, each user connector, and the network controller are connected to form a sliced dedicated network. Among them, the first router can be locally deployed according to the actual situation of the customer, or co-located with the core router in the same computer room.
[0029] Furthermore, in combination with Figure 2 As shown in the figure, the method is carried out through the following steps: Step S202, the connector obtains the dedicated network generation feedback to allow the user to access the connector through the corresponding sliced dedicated network based on the pre-configured static route.
[0030] Specifically, between steps S202, corresponding sliced network software has been installed on all connectors to be used for parsing the network attribute tags carried by the sliced dedicated network and supporting the IPV4\V6 dual-stack protocol. Based on this, the sliced network technology used in the sliced dedicated network of this embodiment can select MPLS VPN network, VxLAN network, SRV6 VPN network, and then through means such as in-flow inspection, segment routing, resource reservation, time-frequency synchronization, periodic mapping, gated queue scheduling, traffic filtering and shaping, path planning, SDN network situation awareness, etc., to achieve path protection to the greatest extent and avoid service interruption caused by network node and line failures.
[0031] In the specific implementation, taking the SRV6 VPN network as an example, the slice private network generated for user N is SRV6 VPN N. At this time, the trusted data flow slice private network exclusive to user N is designated as SRV6 VPN N; and a static route to the address segment of connector N is configured on the corresponding first router N, so that only user N can access connector N through SRV6 VPN N.
[0032] Further, when the slice private network is an SRV6 VPN network, combined with Figure 3 As shown, before step S202, the following steps are also included to generate dedicated slice networks of different levels: Step S20102: The network controller obtains the service SLA requirements of each user to generate corresponding slice generation instructions.
[0033] In specific implementation, the SLA indicators corresponding to the service SLA requirements include: bandwidth parameters, delay parameters, jitter parameters, etc.
[0034] Step S20104: Based on the slice generation instruction, configuration is sent to the first router, core router and second router corresponding to each user to generate a customized slice private network of the corresponding level.
[0035] At this time, multi-level private network service levels can be achieved, and the customizable network service performance is better. In specific implementation, the slice private network levels corresponding to the business SLA requirements include: soft isolation level, soft slice level, deterministic slice level, hard slice level and dedicated slice level.
[0036] Among them, "L1-soft isolation" mainly adopts the general Qos technology to map different priority queues according to the source / destination IP, source / destination MAC, protocol type, etc. of data packets, and realizes differentiated service levels through the scheduling of priority queues. "L2-soft slicing" adds key technologies such as SR-TE, SRv6, controllable active / standby paths, and TI-LFA fast rerouting on the basis of L1, which can achieve 1-3ms jitter determinacy, service protection switching within 100ms, and upper-bound controllable latency, support large-granularity and small-granularity bandwidth granularities, and is applicable to basic deterministic services of primary latency-sensitive classes. "L3-deterministic slicing" expands the support for hardware characteristics on the basis of L2. By transforming the hardware, it realizes deterministic IP (DIP), hybrid queue mechanism, cycle / slot scheduling, and time-frequency synchronization technology, reducing the latency jitter index during the service transmission process to 20μs, which can effectively guarantee the service quality of jitter-sensitive services. "L4-hard slicing" focuses on the OTN optical transmission path on the basis of L3 layer, and focuses on improving the service quality in the optical transmission stage. By integrating the IP and optical transmission systems, applying the FlexE technology (which is an interface technology for the bearer network to achieve service isolation and network slicing. By breaking the one-to-one mapping relationship between the MAC layer and the PHY layer, FlexE realizes flexible and refined management of interface resources, meeting the needs of some services for hard pipe isolation and bandwidth allocation on demand) and 1+1 routing and wavelength protection technology, the jitter index and service switching time are further reduced. "L5-dedicated slicing" further reduces indicators such as latency, jitter, and packet loss caused by physical devices and lines by using dedicated equipment networking on the basis of L4 hard slicing. Dedicated transmission and optical fibers can reduce latency and jitter indicators and flexibly customize bandwidth; dedicated equipment and controllers can customize dedicated service indicators and better adapt to services.
[0037] Step S204, obtain the user's trusted credentials and authentication packets forwarded after being addressed by the first router.
[0038] In this embodiment, the authentication packet includes a header generated based on the network attribute label. Among them, the header is generated by the first router based on the sliced private network, and the network attribute label corresponds to the sliced private network one by one.
[0039] In specific implementation, taking the SRV6 VPN network as an example, user N addresses to connector N on the first router N, and verifies the user identity by entering the username and password on the connector N page. During this process, the user sends the generated authentication packet to the first router N of the sliced private network through the access network. The first router N will encapsulate and carry the data header with the VPN attribute label VRF SID=N through the SRV6 SID label to realize the identification of different VPN packets.
[0040] Among them, the SID in SRV6 is used to implement source - routed traffic engineering in the IPv6 network. The SRV6 SID can embed a VPN identifier: a VRF (Virtual Routing and Forwarding) SID. Each VRF corresponds to a unique SRV6 SID, which is used to isolate the routing tables of different VPNs. Based on this, in this embodiment, the SRV6 SID embeds the VRF SID to identify different VPNs to which users belong.
[0041] In specific applications, in order to ensure that the authentication packets from the user host to the connector are first sent to the first router, dedicated network media are also set up. Among them, the dedicated network media include CPE access terminals, ordinary routers, etc. In terms of connection, each dedicated network media is connected to each user one - to - one. Thus, ensuring that the authentication packets from the user are preferentially forwarded to the first router.
[0042] Step S206: Verify the user's trusted credentials, and after parsing the authentication packet, forward the obtained network attribute label to the network controller.
[0043] In specific implementation, taking the SRV6 VPN network as an example, the connector N verifies the user name and password input on the page. At the same time, after parsing the authentication packet, the corresponding network attribute label (VPN ID) is obtained; at this time, the routing method from the connector N to the network controller is not restricted, as long as the routing is reachable.
[0044] Step S208: When the verification of the user's trusted credentials passes and it is determined that the network controller passes the verification of the network attribute label, allow the user to enter the trusted data space through the second router for data interaction.
[0045] Specifically, the network controller verifies whether the VPN ID returned by the connector N is N, and returns the verification result to the connector N. After both the verification of the user's trusted credentials and the verification of the VPN ID pass, the connector N allows the user N to enter the trusted data space.
[0046] As a specific implementation manner, as shown in Figure 4 the following further regulations are made for the verification process of the user's trusted credentials: Step S20802: When the connector fails to verify the user's trusted credentials, send the verification result to the user to re - obtain and verify the user's trusted credentials.
[0047] Step S20804: Judge that when the number of times of failing to verify the user's trusted credentials reaches the preset number threshold within the preset time period, send a random verification code to other clients bound to the user.
[0048] Step S20806: Obtain the random verification code input by the user, and when the verification fails, send a first abnormal access feedback to the connector to disconnect the data connection between the user and the connector and refuse login.
[0049] Based on steps S20802 to S20806, this embodiment avoids access anomalies under verification anomalies caused by subjective reasons of legitimate users by combining multiple verifications with random verifications. If the above two verifications fail, it is considered that the user's trusted credentials are at risk of illegal theft. At this time, the user's access rights are terminated to protect the data security of all users in the trusted data space.
[0050] As another specific implementation, Figure 5 As shown, the authentication message verification process is further specified as follows: Step S20822: When the connector determines that the network controller fails to verify the network attribute tag, a second abnormal access feedback is sent to the connector to disconnect the data connection between the user and the connector and refuse login.
[0051] At this time, since the authentication message is automatically generated by the user host and the network attribute tag is automatically added by the first router, the entire process is not affected by user factors. Therefore, the abnormality of the network attribute tag proves that there is a problem with the network itself. At this time, directly disconnecting the corresponding communication can protect data security to the greatest extent.
[0052] In summary, in the data circulation method described in this embodiment, the slice network and the trusted data space technology work together to ensure more reliable realization of user data privacy and security, wherein the slice network realizes user data network isolation, and the trusted data space realizes data circulation privacy protection. Furthermore, the dual authentication mechanism of the network controller and the trusted data circulation space ensures data security by improving data access rights. Specifically, one is the connector login key verification, which is used to authenticate the user to access the connector; the other is the network attribute verification. After the user passes the first router, the data message carries the network attribute tag (VPN ID). After the connector parses the message, the VPN ID tag is sent to the network controller, and the network controller performs a secondary verification. Only after both verifications are qualified can the user access the trusted data space. At the same time, the access method of the SRV6 VPN router is adopted to realize the conversion from the user-side IP access method to the slice private network VPN routing addressing method to access the connector. While realizing network identity authentication, user data will not be exposed on the public network, which also greatly improves the security of user data.
[0053] The above program can run in a processor or can also be stored in a memory (or referred to as a computer-readable storage medium). A computer-readable medium includes permanent and non-permanent, removable and non-removable media and can implement information storage by any method or technology. The information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassette tapes, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device. As defined herein, a computer-readable medium does not include transitory computer-readable media such as modulated data signals and carrier waves.
[0054] These computer programs can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate computer-implemented processing. Thus, the instructions executed on the computer or other programmable device provide for implementing the steps for the functions specified in Figure 1 one process or multiple processes and / or Figure 1 boxes or multiple boxes. Corresponding different steps can be implemented by different modules.
[0055] This embodiment also provides a data circulation system based on a slice network and a trusted data space. The system includes: private network devices deployed corresponding to each user one by one. Each private network device includes a first router and a core router connected communicatively; wherein, a connector is connected to each core router, and each core router is communicatively connected to the trusted data space via a second router. Combining Figure 6 as shown, the system further includes the following functional modules: A first acquisition module, configured to enable the connector to acquire feedback generated by the private network to allow a user to access the connector through a corresponding slice private network based on a pre-configured static route.
[0056] A second acquisition module, configured to enable the connector to acquire the user's trusted credentials and authentication packets forwarded after being addressed by the first router; wherein, the authentication packet includes a header generated based on a network attribute label; wherein, the header is generated by the first router based on the slice private network, and the network attribute label corresponds to the slice private network one by one.
[0057] A verification and forwarding module, which is used to enable the connector to verify the user's trusted credentials, parse the authentication message, and forward the obtained network attribute label to the network controller.
[0058] A data circulation module, which is used to allow the user to enter the trusted data space through the second router for data interaction when the connector passes the verification of the user's trusted credentials and determines that the network controller passes the verification of the network attribute label.
[0059] Since the system is built based on the method, what has been described above will not be elaborated here.
[0060] For example, the system further includes: A third acquisition module, which is used to enable the network controller to acquire the service SLA requirements of each user to generate corresponding slice generation instructions.
[0061] A private network generation module, which is used to send configurations to the second router, as well as the first router and core router corresponding to each user based on the slice generation instructions to generate customized slice private networks of corresponding levels.
[0062] Among them, the SLA indicators corresponding to the service SLA requirements include: bandwidth parameters, delay parameters, and jitter parameters; the slice private network levels corresponding to the service SLA requirements include, from low to high in sequence: soft isolation level, soft slice level, deterministic slice level, hard slice level, and dedicated slice level.
[0063] For another example, the system further includes: An exception feedback module, which is used to send a second exception access feedback to the connector to disconnect the data connection between the user and the connector and reject the login when the connector determines that the network controller fails to pass the verification of the network attribute label.
[0064] Combined Figure 7 As shown, this embodiment also provides an electronic device. It includes at least one processor, the processor is coupled with a memory, and a computer program is stored in the memory. The computer program is configured to execute the method when being run by the processor.
[0065] At the same time, this embodiment also provides a computer-readable storage medium, on which a computer program is stored, and the computer program is used to be executed by a processor to implement the method.
[0066] Since the system, the electronic device, and the storage medium are all used to implement the method, they also have the following technical advantages in practical applications: (1) Through the per-user and per-slice private network technology, while ensuring the trusted circulation of user data, the isolation of user data transmission is enhanced, further protecting the data privacy and security of data providers. (2) Through the dual cooperation of the network controller and the trusted data circulation space, the security of user access to the trusted data space is enhanced, and the protection against intruders is strengthened by means of both network attribute verification and connector login password verification. (3) As a key component of the trusted data space, the connector adopts the VPN routing addressing method and will not be exposed on the user-side network, greatly improving data security.
[0067] Although the present invention has been disclosed above in its preferred embodiments, it is not intended to limit the present invention. Those with ordinary knowledge in the technical field to which the present invention pertains may make various modifications and refinements without departing from the spirit and scope of the present invention. Therefore, the protection scope of the present invention shall be subject to what is defined by the claims.
Claims
1. A data circulation method based on a slicing network and a trusted data space, characterized in that Including: Private network devices deployed corresponding to each user one by one. Each private network device includes a first router and a core router that are communicatively connected. Among them, a connector is connected to each core router, and each core router is communicatively connected to the trusted data space via a second router; Including the following steps: The connector obtains the private network generation feedback to allow the user to use the pre-configured static route as the basis and access the connector through the corresponding sliced private network; Obtain the user's trusted credentials and authentication message forwarded after being addressed by the first router. Among them, the authentication message includes a header generated based on the network attribute label. Among them, the header is generated by the first router based on the sliced private network, and the network attribute label corresponds to the sliced private network one by one; Verify the user's trusted credentials, parse the authentication message, and forward the obtained network attribute label to the network controller; When the verification of the user's trusted credentials passes and it is determined that the network controller passes the verification of the network attribute label, allow the user to enter the trusted data space via the second router for data interaction.
2. The data circulation method based on a slicing network and a trusted data space according to claim 1, wherein The sliced private network is an SRV6 VPN network; before the connector obtains the private network generation feedback to allow the user to use the pre-configured static route as the basis and access the connector through the corresponding sliced private network; including: The network controller obtains the service SLA requirements of each user to generate corresponding sliced generation instructions; Based on the sliced generation instructions, send configurations to the second router, as well as the first router and core router corresponding to each user, to generate customized sliced private networks of corresponding levels; Among them, the SLA indicators corresponding to the service SLA requirements include: bandwidth parameters, delay parameters, and jitter parameters. The levels of the sliced private networks corresponding to the service SLA requirements from low to high include: soft isolation level, soft slice level, deterministic slice level, hard slice level, and dedicated slice level.
3. The data circulation method based on a slice network and a trusted data space according to claim 1, wherein Including various private network media. Both ends of any private network media are communicatively connected to the corresponding user and the first router respectively. Among them, the private network media includes a CPE access terminal, which is used to ensure that the authentication message from the user is preferentially forwarded to the first router.
4. The data circulation method based on a slicing network and a trusted data space according to claim 1, wherein Including: When the connector fails to pass the verification of the user's trusted credentials, send the verification result to the user to re-obtain and verify the user's trusted credentials; Judge that when the number of times of failed verification of the user's trusted credentials reaches the preset number threshold within the preset time period, send a random verification code to other clients bound to the user; Obtain the random verification code input by the user, and when its verification fails, send a first abnormal access feedback to the connector to disconnect the data connection between the user and the connector and reject the login.
5. The data circulation method based on a slicing network and a trusted data space according to claim 1, characterized in that, Including: When the connector determines that the network controller fails to pass the verification of the network attribute label, send a second abnormal access feedback to the connector to disconnect the data connection between the user and the connector and reject the login.
6. A data circulation system based on a slicing network and a trusted data space, characterized in that, Including: Private network devices are deployed corresponding to each user one by one. Each private network device includes a first router and a core router that are communicatively connected; wherein, a connector is connected to each core router, and each core router is communicatively connected to the trusted data space via a second router; It includes the following functional modules: The first acquisition module is used to enable the connector to obtain the feedback generated by the private network to allow the user to use the pre-configured static route as the basis and access the connector through the corresponding sliced private network; The second acquisition module is used to acquire the user's trusted credentials and authentication messages forwarded after being addressed by the first router; wherein, the authentication message includes a header generated based on the network attribute label; wherein, the header is generated by the first router based on the sliced private network, and the network attribute label corresponds to the sliced private network one by one; The verification and forwarding module is used to verify the user's trusted credentials, parse the authentication message, and forward the obtained network attribute label to the network controller; The data circulation module is used to allow the user to enter the trusted data space through the second router for data interaction when the verification of the user's trusted credentials passes and it is determined that the network controller passes the verification of the network attribute label.
7. The data circulation system based on the slicing network and the trusted data space according to claim 6, characterized in that, It includes: The third acquisition module is used to enable the network controller to acquire the service SLA requirements of each user to generate corresponding slice generation instructions; The private network generation module is used to issue configurations to the second router, as well as the first router and core router corresponding to each user, based on the slice generation instructions to generate customized sliced private networks of corresponding levels; Among them, the SLA indicators corresponding to the service SLA requirements include: bandwidth parameters, latency parameters, and jitter parameters; the levels of the sliced private networks corresponding to the service SLA requirements from low to high are successively: soft isolation level, soft slice level, deterministic slice level, hard slice level, and dedicated slice level.
8. The data circulation system based on the slicing network and the trusted data space according to claim 6, wherein It includes: The abnormal feedback module is used to send a second abnormal access feedback to the connector to disconnect the data connection between the user and the connector and reject the login when the connector determines that the network controller fails to pass the verification of the network attribute label.
9. An electronic device, characterized in that, It includes at least one processor, the processor is coupled to the memory, and the memory stores a computer program, and the computer program is configured to execute the method according to any one of claims 1-5 when being run by the processor.
10. A computer-readable storage medium, characterized in that, A computer program is stored thereon, and the computer program is used to be executed by a processor to implement the method according to any one of claims 1-5.
Citation Information
Patent Citations
Method for safely accessing network slice based on application attribute and related equipment
CN114828010A
Communication method and device, computer readable storage medium and communication system
CN117812590A
Cross-network identity authentication system and method
CN118102298A
APN6 network-based application credibility verification method and system
CN119210736A
Privacy of relay selection in cellular sliced networks
WO2022038292A1
Cited By
Hyperlink cross-domain trusted data space implementation method, electronic equipment and storage medium
CN120915579A
An ultra-connection cross-domain trusted data space implementation method, electronic equipment and storage medium
CN120915579B
Cross-architecture communication method and system based on SRv6 deterministic network
CN121664726A