Security service implementation method and apparatus, security service system, device, and medium

By building end-to-end security information through the MEC platform, security service requirements are transformed into MEC host parameters, and security services are configured. This solves the problem that security policies in 5G networks cannot balance performance and quality, and achieves unified security services.

CN115665741BActive Publication Date: 2025-11-07CETC CYBERSPACE SECURITY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211329071.7
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-27
Publication Date
2025-11-07
Estimated Expiration
2042-10-27

AI Technical Summary

Technical Problem

In existing technologies, the security strategies of 5G networks cannot simultaneously meet the requirements of network security performance and network quality, resulting in the sacrifice of network performance when improving security performance.

Method used

By building end-to-end security information through the MEC platform, security service requirement instructions and security policies are transformed into security service parameters available to MEC hosts, and MEC hosts are configured to provide matching security services. By combining edge computing to optimize resource configuration, unified security services can be achieved.

Benefits of technology

While ensuring layered security levels, it also meets network quality requirements, solving the problem of the disconnect between security and network, and enabling security services suitable for 5G networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115665741B_ABST
    Figure CN115665741B_ABST
Patent Text Reader

Abstract

The present disclosure relates to a security service implementation method and device, a security service system, an electronic device and a readable storage medium, and is applied to the technical field of mobile communication. The method comprises the following steps: a MEC server converts a received security service demand instruction and a corresponding security policy from a core network into a security service parameter suitable for a MEC platform, and sends the security service parameter. A MEC host pre-constructs an end-to-end security information for storing the correspondence among authorized user terminals, authorized business applications and security policies; after the MEC host is configured based on the security service parameter, the MEC host provides a matching security service for an authorized initiator based on an end-to-end security list. The present disclosure can realize a security service suitable for a 5G network while taking into account the network security performance and network quality requirements.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of mobile communication, in particular to a security service implementation method and device, a security service system, an electronic device and a readable storage medium. BACKGROUND

[0002] With the rapid development of Internet technology and its wide application in daily work and life, users' network performance requirements are also getting higher and higher. As a new generation of broadband mobile communication technology with high speed, low latency and large connection characteristics, 5G (5th Generation Mobile Communication Technology) has been widely used in various industries, and the 5G era of linking everything has come.

[0003] It can be understood that for a network, security is an important performance parameter that cannot be ignored. In related technologies, a network will build a security facility based on transmission based on its data transmission security needs; application vendors and security vendors will also add a layer of application security facility based on applications, thereby effectively improving the security performance of the network. This method does not consider the network properties and sacrifices network performance to improve security performance, which is suitable for application scenarios with low demand for network quality such as network latency and network jitter. For 5G, which provides performance guarantees and on-demand customization, its network performance requirements are higher, and the security strategy used in related technologies is not suitable for 5G networks.

[0004] Therefore, how to determine a security strategy suitable for 5G networks to improve network security performance while meeting network quality requirements is a technical problem that needs to be solved by those skilled in the art. SUMMARY

[0005] The purpose of the present disclosure is to provide a security service implementation method, device, system, electronic device and readable storage medium, which is suitable for 5G networks while taking into account network security performance and network quality requirements.

[0006] To achieve the above-mentioned purpose, the present disclosure provides the following technical solutions:

[0007] The first aspect of the present disclosure provides a security service implementation method applied to a MEC server of a MEC platform, the MEC platform further comprising a plurality of MEC hosts, each MEC host pre-constructing end-to-end security information for storing the correspondence between authorized user terminals, authorized business applications and security policies; comprising:

[0008] Converting the received security service requirement instruction and the corresponding security policy from the target network into a security service parameter suitable for the target MEC host;

[0009] sending the security service parameters to configure the target MEC host based on the security service parameters, and using the target MEC host to provide matched security service for the authorized initiator based on the end-to-end security information;

[0010] The target MEC host is a MEC host used to perform security service corresponding to the security service requirement instruction.

[0011] Optionally, the conversion of the received security service requirement instruction and the security policy from the target network corresponding thereto into the security service parameters applicable to the target MEC host comprises:

[0012] When receiving a target security attribute service initiated by a third-party service application through the MEC platform, the target security attribute service is translated into service attribute information applicable to the MEC platform;

[0013] According to the service attribute information and the service scheduling information, network requirement signaling is generated, and the network requirement signaling is sent to the target network;

[0014] The security policy is acquired, which is generated by the target network based on the network requirement signaling and network environment information;

[0015] The security policy is translated into the security service parameters.

[0016] Optionally, the conversion of the received security service requirement instruction and the security policy from the target network corresponding thereto into the security service parameters applicable to the target MEC host comprises:

[0017] When receiving a network security requirement message sent by a target user terminal through the target network, the network security requirement information is translated into security service parameters;

[0018] The network security requirement message comprises security service requirement and security policy of the user terminal.

[0019] Optionally, the conversion of the received security service requirement instruction and the security policy from the target network corresponding thereto into the security service parameters applicable to the target MEC host comprises:

[0020] When receiving a network security requirement message sent by a target network element, the network security requirement information is translated into security service parameters;

[0021] The network security requirement message comprises security service requirement and security policy of the network element.

[0022] Optionally, before the receiving of the security service demand instruction and the security policy from the target network corresponding to the security service demand instruction, the method further comprises:

[0023] When the security service demand instruction is received, a security service ID is automatically generated for the security service corresponding to the security service demand instruction.

[0024] The security service ID is used to replace the ID of the initiator of the security service demand instruction.

[0025] The second aspect of the present disclosure provides a security service implementation method applied to a MEC host of a MEC platform, wherein the MEC platform further comprises a MEC server, and the method comprises:

[0026] An end-to-end security information for storing the correspondence among authorized user terminals, authorized business applications and security policies is pre-constructed.

[0027] When it is detected that the security service parameters have been configured, it is judged whether the initiator corresponding to the security service demand instruction has been authorized based on the end-to-end security information.

[0028] If the initiator has been authorized, the initiator is provided with a matching security service based on the end-to-end security information.

[0029] The security service parameters are converted and generated by the MEC server according to the received security service demand instruction and the security policy from the target network corresponding to the security service demand instruction.

[0030] Optionally, after the judging whether the initiator corresponding to the security service demand instruction has been authorized based on the end-to-end security information, the method further comprises:

[0031] If the initiator has not been authorized, an authentication task is generated, and after the identity authentication passes, the authentication task is sent.

[0032] Authentication parameter information is obtained; the authentication parameter information is obtained and transmitted by the MEC server after the MEC platform allocates corresponding resources for the initiator based on business configuration information and notifies the controller of the MEC platform; the business configuration information is resource information configured by the target network for the initiator according to the authentication task and network environment information.

[0033] The end-to-end security information is updated based on the authentication parameter information, and authentication pass information is sent to the initiator.

[0034] Optionally, the constructing of the end-to-end security information for storing the correspondence among authorized user terminals, authorized business applications and security policies comprises:

[0035] Acquire various security service data;

[0036] Classify the various security service data to obtain multiple groups of security service data belonging to different industries;

[0037] According to the industry security attribute, each group of security service data is respectively security-enabled to serve as the security policy of the corresponding security service data;

[0038] According to the security-enabled security service data and the data access information of each group of security service data, an end-to-end security list is constructed.

[0039] Optionally, the end-to-end security information for storing the correspondence between the authorized user terminal, the authorized service application and the security policy comprises:

[0040] Based on the security level, the authorized user terminals in the end-to-end security information are classified to obtain multiple terminal groups; the authorized terminals in the same terminal group are of the same security level;

[0041] Based on the security level, the authorized service applications in the end-to-end security information are classified to obtain multiple service groups; the authorized service applications in the same service group are of the same security level;

[0042] Among the same service group, each authorized service application has the right to access the remaining authorized service applications and each authorized terminal in the same authorized terminal group in the service security life cycle; each authorized terminal in the same terminal group has the right to access each authorized terminal and each authorized service application in the same authorized service group in the service security life cycle.

[0043] Optionally, the judgment of whether the initiator of the security service demand instruction has been authorized based on the end-to-end security information comprises:

[0044] Determine the initiator and the accessed party of the security service demand instruction;

[0045] If the initiator and the accessed party are located in the same service group, the initiator has been authorized;

[0046] If the initiator and the accessed party are located in the same terminal group, the initiator has been authorized;

[0047] If there is a user terminal in the service group to which the initiator belongs and which has the right to access the terminal group to which the accessed party belongs, the initiator has been authorized;

[0048] If there is a service application in the terminal group to which the initiator belongs and which has the right to access the service group to which the accessed party belongs, the initiator has been authorized.

[0049] The third aspect of the present disclosure provides a security service implementation apparatus, applied to a MEC server of a MEC platform, the MEC platform further comprising a plurality of MEC hosts, each MEC host pre-constructing end-to-end security information for storing a correspondence among authorized user terminals, authorized service applications and security policies; comprising:

[0050] a conversion module, configured to convert the received security service demand instruction and the security policy from the target network corresponding thereto into security service parameters applicable to a target MEC host; wherein the target MEC host is a MEC host for executing a security service corresponding to the security service demand instruction;

[0051] a sending module, configured to send the security service parameters, to configure the target MEC host based on the security service parameters, and to provide a matching security service for an authorized initiator based on the end-to-end security information by using the target MEC host.

[0052] The fourth aspect of the present disclosure provides a security service implementation apparatus, applied to a MEC host of a MEC platform, the MEC platform further comprising a MEC server; comprising:

[0053] a relationship construction module, configured to pre-construct end-to-end security information for storing a correspondence among authorized user terminals, authorized service applications and security policies;

[0054] a security service providing module, configured to, when detecting that a security service parameter has been configured, if it is determined based on the end-to-end security information that an initiator corresponding to a security service demand instruction has been authorized, provide a matching security service for the initiator based on the end-to-end security information; wherein the security service parameter is generated by conversion by the MEC server according to a received security service demand instruction and a security policy from a target network corresponding thereto.

[0055] The fifth aspect of the present disclosure further provides a security service system, embedded in a MEC platform, comprising a security service scheduling layer, a plurality of identical security service business layers and a MEC host management module;

[0056] the security service scheduling layer is deployed in a MEC server, each security service business layer is deployed in a corresponding MEC host; each security service business layer comprises a plurality of security service interfaces for being called by third-party service applications;

[0057] The security service scheduling layer is configured to implement the security service implementation method according to any one of the preceding embodiments when executing the computer program; each security service service layer is configured to implement the security service implementation method according to any one of the preceding embodiments when executing the computer program; and the MEC host management module is configured to map the security service parameters generated by the security service scheduling layer to the target security service interface of the corresponding MEC host.

[0058] The sixth aspect of the present disclosure further provides an electronic device, comprising:

[0059] a memory having a computer program stored thereon;

[0060] a processor configured to implement the steps of the security service implementation method according to any one of the preceding embodiments when executing the computer program stored in the memory.

[0061] The present disclosure further provides a readable storage medium having a computer program stored thereon, wherein the computer program is configured to implement the steps of the security service implementation method according to any one of the preceding embodiments when executed by a processor.

[0062] According to the above technical solution, the MEC platform converts the security service requirement into information understood by the platform, and obtains the resource allocation of the core network based on the current network environment for the security service requirement. The MEC host performs security service based on the security service requirement, security resource and network resource configuration. Since the security policy is determined by the target network based on the current network environment, the resource is allocated and the process is optimized based on the quality of network requirement as the basic input condition. The network quality requirement can be met while the hierarchical security level is guaranteed. When the network quality requirement changes, the MEC platform can be reconstructed according to the network requirement, and the corresponding security service is customized as needed. The MEC host pre-associates the user terminal, security policy and business application as the basis for business security processing, and responds to the security service requirement based on the associated information, so as to provide unified security service to the user terminal, network element and business application. The process of data access and business development through the network is implemented by using the MEC platform. As a service, security can be jointly arranged with the network, and the phenomenon that security guarantee is disconnected from the network can be solved. Without sacrificing network performance, the security service suitable for the 5G network can be realized based on the consideration of network security performance and network quality requirement.

[0063] Other features and advantages of the present disclosure will be described in detail in the following detailed description.

[0064] In addition, the embodiment of the present application also provides the corresponding implementation device, the security service system, the electronic equipment and the readable storage medium for the security service implementation method, so that the method is more practical, and the device, the security service system, the electronic equipment and the readable storage medium have corresponding advantages.

[0065] It should be understood that the above general description and the following detailed description are only exemplary and do not limit the present disclosure. BRIEF DESCRIPTION OF DRAWINGS

[0066] The accompanying drawings are used to provide further understanding of the present disclosure, and constitute a part of the specification, and are used to explain the present disclosure together with the following specific embodiments, but do not constitute a limitation of the present disclosure. In the drawings:

[0067] Figure 1 A flowchart of a security service implementation method provided by the present disclosure;

[0068] Figure 2 A flowchart of a security service management scheduling method provided by the present disclosure;

[0069] Figure 3 A flowchart of another security service implementation method provided by the present disclosure;

[0070] Figure 4 An interaction flowchart of a third-party business application initiating a security service provided by the present disclosure;

[0071] Figure 5 An end-to-end security list provided by the present disclosure;

[0072] Figure 6 A specific embodiment structure diagram of a security service implementation device provided by the present disclosure;

[0073] Figure 7 Another specific embodiment structure diagram of a security service implementation device provided by the present disclosure;

[0074] Figure 8 Still another specific embodiment structure diagram of a security service implementation device provided by the present disclosure;

[0075] Figure 9 Still another specific embodiment structure diagram of a security service implementation device provided by the present disclosure;

[0076] Figure 10 A specific embodiment structure diagram of an electronic equipment provided by the present disclosure;

[0077] Figure 11 Another specific embodiment structure diagram of an electronic equipment provided by the present disclosure.

[0078] Figure 12 A specific implementation structure diagram of a security service system provided for the present disclosure;

[0079] Figure 13 A MEC platform framework schematic diagram of an example application scenario provided for the present disclosure. DETAILED DESCRIPTION

[0080] The detailed description of the specific implementation of the present disclosure is described below in combination with the drawings. It should be understood that the specific implementation described herein is only used to illustrate and explain the present disclosure, and is not used to limit the present disclosure.

[0081] The terms "include" and "have" and any variations thereof in the specification and claims of the present disclosure and the above drawings are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device including a series of steps or units is not limited to the listed steps or units, but can include steps or units not listed.

[0082] The inventors of the present disclosure have found through research that MEC (Multi-Access Edge Computing) can combine IT (Internet Technology) service environment and cloud computing technology at the network edge, adopt a distributed architecture to improve the computing and storage capabilities of the edge network, reduce the time delay of network operation and service delivery, and improve user experience. In the 5G network, edge computing is introduced, a large number of businesses can be terminated at the edge of the 5G network, key businesses and part of the core network elements are sunk to the edge network, forming an industry application private network, which can be used as a general application scenario for the 5G industry and become a new type of infrastructure designed by operators for users in the 5G era. In order to combine the future network with edge computing organically, the 3rd generation partnership project (3GPP) and the European Telecommunication Standards Institute (ETSI) have formulated many protocols for the interaction between 5G network and MEC network, so that the 5G network can change the user plane routing information according to the business demand and business server address and other information, so that the user plane data passes through the base station and is processed by the UPF (User Plane Function) on the edge MEC server to perform the edge unloading function of data.

[0083] Based on this, in order to solve the problem that the security service and the network deployment are independent of each other and the network security is improved at the expense of network performance, the present disclosure can comprehensively consider the network architecture and the security, solve the security and timeliness of the 5G network by referring to the edge computing, and meet the network quality demand while improving the security performance. The edge computing server is limited by the application architecture, deployment, volume and other characteristics, and the same concept as the future network service architecture is adopted to establish a security service system based on the MEC platform architecture and the end-to-end closed loop, and the MEC platform provides unified security services for each network element, terminal and application of the edge network. The various non-limiting embodiments of the present disclosure are described in detail below.

[0084] First, see Figure 1 , Figure 1 The flowchart of a security service implementation method provided by the embodiment of the present disclosure, the embodiment of the present disclosure is applied to the MEC server of the MEC platform, that is, the subject of the execution of the following method is the MEC server of the MEC platform, and the MEC platform includes the MEC server and a plurality of MEC hosts, which can include the following contents:

[0085] In step S101, the received security service demand instruction and the security policy from the target network corresponding thereto are converted into security service parameters suitable for the target MEC host.

[0086] In this step, the security service demand instruction can be sent to the MEC platform by the user terminal through the network, can be sent to the MEC platform by the network element, and can also be initiated by the third-party business application to the MEC platform. The security service demand instruction is used to indicate the security service demand of the initiator such as the user terminal or the network element or the third-party business application. The security service demand can be to carry out a certain security service such as sensitive scheduling data service, user identity protection service, user privacy protection service, application authentication protection, etc. It can also be a data access service between the user terminal and the third-party business application. The target network is the core network, that is, the network supporting the security service demand, such as the 5G network. The security policy is the network resource guarantee policy and the security resource guarantee policy generated by the core network based on the demand information such as the security service demand from the MEC platform, the user terminal demand, the core network element demand, the network load and the service quality demand, etc. The MEC platform is arranged by the entire network end-to-end security level policy, and the unified network security policy is translated into the security service provided by the MEC to support the security of the edge data application system. The resource is allocated and the process is optimized based on the basic input condition of the network demand quality guarantee, so that the network quality demand can be met while the hierarchical security level is guaranteed. Since the security policy is determined based on the network environment of the target network, when the network quality demand changes, the MEC platform can be reconstructed according to the network demand to customize the corresponding security service on demand.

[0087] In this embodiment, different security services are carried by different MEC hosts of the MEC platform. In order not to cause ambiguity, the MEC host used to execute the security service corresponding to the security service demand instruction is referred to as a target MEC host in this step. Each MEC host uses different security service parameters to complete services of different security levels, that is, the security service parameters of different MEC hosts are different. In order to configure the security service parameters of the MEC host, the security service demand instruction and the corresponding security policy need to be translated. For example, the security service demand instruction initiator ID and the security policy can be translated into the target MEC host ID, the security policy of the MEC platform, storage security, computing resources, and the like.

[0088] In step S102, the security service parameters are sent to configure the target MEC host based on the security service parameters, and the target MEC host is used to provide the authorized initiator with a matching security service based on the end-to-end security information.

[0089] In this step, after the MEC server translates the security service demand instruction and the security policy into security service parameters suitable for the MEC host or the MEC platform, the MEC server sends the security service parameters to the MEC host management module. The MEC host management module maps the security service parameters to the security service parameter interface of the target MEC host, and the target MEC host issues instantiation of security resource requirements to the infrastructure layer for supporting the development of security services. In order to improve security performance, the MEC platform supports security service requirements of authorized user terminals or authorized business applications. Therefore, each business application and user terminal needs to be registered in the MEC platform in advance and complete the identity protection or authentication task to become an authorized user terminal or an authorized business application of the MEC platform. The authorized initiator of this embodiment refers to an initiator that has been authorized by the MEC platform to initiate a security service, or the initiator of the security service demand instruction is authorized. The authorized initiator can be an authorized user terminal or an authorized business application or an authorized network element. The security service refers to the service required to be developed by the authorized initiator. For each MEC host of the MEC platform, each MEC host will pre-build end-to-end security information for storing the correspondence between the authorized user terminal, the authorized business application, and the security policy, so as to associate the user terminal, the business application, and the security policy. The end-to-end security information may, for example, be an end-to-end security list, and of course, the correspondence between the user terminal, the business application, and the security policy can also be represented in other forms. After the security service parameters are configured in the MEC host, the MEC host learns the related information of the initiator and the corresponding security policy, and based on the end-to-end security information, the security service can be uniquely determined, and then the security service is executed.

[0090] In the technical scheme provided in the embodiments of the present application, the MEC platform converts the security service requirement into information understood by the platform, and obtains the resource allocation of the core network based on the security service requirement under the current network environment, and the MEC host that executes the security service based on the security service requirement, the security resource and the network resource configuration. Since the security policy is determined by the target network based on the current network environment, the resource is allocated and the process is optimized based on the basic input condition of network quality requirement guarantee, the network quality requirement can be met while guaranteeing the hierarchical security level; and when the network quality requirement changes, the MEC platform can be reconstructed according to the network requirement, and the corresponding security service is customized as needed. The MEC host pre-associates the user terminal, the security policy and the service application as the basis for security processing, and responds to the security service requirement based on the associated information, so as to realize the unified security service provided to the user terminal, the network element and the service application. The process of data access and service through the network is realized by using the MEC platform. As a service, security can be jointly arranged with the network, and the phenomenon that the security guarantee is disconnected from the network can be solved. Without sacrificing the network performance, the security service suitable for the 5G network can be realized on the basis of considering the network security performance and the network quality requirement.

[0091] It can be understood that the security service requirement instruction can be a network security requirement message sent by the user terminal or the network element through the target network, or a target security attribute service initiated by the third-party service application through the MEC platform. Based on this, the present disclosure gives the implementation process of step S101 in the above-mentioned embodiments, i.e., "converting the received security service requirement instruction and the security policy from the target network corresponding thereto into security service parameters suitable for the target MEC host". The implementation process can include the following contents:

[0092] As an optional implementation, the MEC platform provides an application access interface to the outside, and the third-party service application can access the platform through the interface. The third-party service application is an application that accesses the MEC platform, and the MEC platform is an intermediate body that carries the access application and the access terminal. The third-party service application initiates a target security attribute service to the MEC platform, the MEC server receives the target security attribute service, translates the target security attribute service into service attribute information suitable for the MEC platform; generates network requirement signaling according to the service attribute information and the service scheduling information, and sends the network requirement signaling to the target network; obtains the security policy sent by the target network; and translates the security policy into security service parameters.

[0093] In the embodiment, the target security attribute service is a security service demand initiated by a third-party service application, and the service attribute information is a security information language that can be understood by the MEC platform, which includes service information and security information. For example, the service attribute information can include service attributes such as a high-reliability low-latency service, a third-party service application ID, a security algorithm, a secure storage space, and the like. The service scheduling information is service scheduling information of the MEC platform obtained from an orchestration scheduler of the MEC platform, and the network demand signaling is used to inform the target network of the security capability and service capability demand of the MEC platform where the target security attribute service is located. After receiving the network demand signaling, the target network generates a corresponding security policy for the target security attribute service according to the network demand signaling and network environment information. The network environment information is MEC platform demand information, user terminal demand information, core network element demand information, current load condition of the network, and network service quality demand received by the core network. The security policy can include network resource data and security resource data allocated by the network such as a 5G network for the target security attribute service. In order for the MEC platform to obtain the security policy of the network, the MEC server needs to translate the received security policy to obtain parameters that can be used by the MEC platform, such as a MEC host ID, a MEC platform security policy, storage security, and computing resources.

[0094] In order to make those skilled in the art more clearly understand how the present disclosure implements the security management and scheduling of the third-party service application, the present disclosure combines Figure 2 An optional embodiment is given. In the embodiment, a functional module in the MEC server that implements the computer program corresponding to the method of implementing the security management and scheduling of the third-party service application is referred to as a security service scheduling layer, the target network is a 5G core network, and the MEC platform further includes an orchestration scheduler, for example, a MEAO (Multiaccess-Edge Application Orchestration). The orchestration scheduler is used to globally orchestrate edge computing services of the entire MEC platform, and to overall plan edge services of the platform, so as to realize scheduling of the edge services of the MEC platform. A functional module in the MEC host that is used to provide a security service is referred to as a security service service layer. Based on this, the embodiment can include the following content:

[0095] In step S201, the third-party service application initiates a service with a certain security attribute, such as a sensitive data access service, through the MEC platform.

[0096] In step S202, the security service scheduling layer of the MEC server obtains the service information and security information contained in the security attribute service, and translates them into the security information language of the MEC platform, which is referred to as service attribute information in this embodiment. For example, the service attribute is a high-reliability low-latency service, the service ID of the security attribute service, a security algorithm, a security storage space level, etc.

[0097] In step S203, the service attribute information is fused with the service scheduling information in the MEC arrangement scheduler to generate the security capability and service capability requirements of the MEC platform.

[0098] In step S204, the service capability and security capability are fed back to the 5G core network, that is, the service type, service security requirement and basic capability of the MEC platform that the MEC platform needs to carry out are reported to the core network. Steps S201-S204 complete the requirement of the security service initiated by the third-party service application of the edge network, which is sent to the core network through the edge network of the MEC platform. The whole process is completed by the arrangement scheduler of the MEC platform and the security service scheduling layer in the MEC server. The 5G core network aggregates the MEC platform requirements, user terminal requirements, core network element requirements, network load, Qos (Quality of Service) requirements, etc., and comprehensively forms the end-to-end network resource guarantee strategy and security resource guarantee strategy of the third-party service application to complete the security strategy of the security attribute service. That is, the 5G core network deploys the resources and security levels used by a certain end-to-end slice service according to the data information collected by each party. Further, the 5G core network sends the security strategy to each network element, user terminal and MEC platform to inform each network element, user terminal and MEC platform to prepare resources to carry the upcoming service, thereby establishing a service resource allocation context. The 5G core network can send the security strategy to the MEC platform through the session management layer, so that the MEC platform analyzes the security strategy and uses the uniformly coordinated service resources to carry out the service. Of course, the service resources include security resources.

[0099] In step S205, the MEC platform receives the resource parameters allocated by the 5G core network for the security attribute service, and the security scheduling layer obtains the security requirements such as service ID, security strategy and security service attribute from the arrangement scheduler, and translates them into parameters that can be used by the security service business layer of the MEC platform, that is, security service parameters, such as MEC host ID corresponding to the MEC platform, MEC platform security strategy, storage security, computing resources, etc.

[0100] In step S206, the translated parameters, that is, the security service parameters, are mapped to the security parameter management interface of the MEC host responsible for carrying out the security attribute service by the security management module in the MEC host management module.

[0101] In step S207, the MEC host infrastructure layer issues instantiation of security resource requirements to further carry out security services according to the resources required by the instantiation of the security services.

[0102] In step S208, the security service parameters are configured to the security service business layer.

[0103] As another optional implementation, for the security service requirements sent by the user terminal to the MEC platform through the target network such as the 5G core network, or the network security requirements sent directly by the network element to the MEC platform, the MEC server translates the network security requirement information into security service parameters when receiving the network security requirement message sent by the target user terminal through the target network. The MEC server translates the network security requirement information into security service parameters when receiving the network security requirement message sent by the target network element. The MEC server generates messages that can be understood by the MEC platform by parsing and translating the network security requirement message from the network security requirement message. And hand over these messages to the arrangement scheduler such as MEAO, the arrangement scheduler unifies the arrangement and planning of the traditional resources and the security resources, and combines them into the message of the MEC system layer controlling the MEC platform, and sends them to the business bearing management platform of the MEC and the MEC host carrying out the corresponding edge business. Further, the arrangement scheduler starts the corresponding security support virtualization resources according to the security service scheduling message of the MEC server. Whether the network security requirement is sent by the user terminal or the network element, since it is directly sent to the MEC platform through the target network, the target network will first converge the MEC requirements, the user terminal requirements, the core network element requirements, the network load, the Qos requirements (Quality of Service, service quality), etc. to generate a security policy containing network resource guarantee strategy and security resource guarantee strategy, that is, the network security requirement message already includes the security service requirements and the security policy of the user terminal or the network element.

[0104] From the above, the MEC server receives network security requirement information, also receives security requirement information from third-party service applications accessing the MEC platform from outside, performs scheduling processing on the security requirement information, and forms a security service closed loop. In the security service scheduling process, security is combined with the network, and security is an endogenous factor for network resource allocation. In different application scenarios, the embodiment takes it as an influencing factor for network resource arrangement. The MEC server deeply analyzes network commands, assists the network to complete the construction of security services, translates different network requirements of the network into different security guarantee services, uniformly arranges security policies under the condition of unified network quality guarantee, and jointly completes the differentiated requirements of different industries on the network, completes the security customization of the business platform security slice on demand, and realizes the load balancing and cross-regional sharing of security.

[0105] In order to further improve the security performance of the service, based on the above embodiment, before the step of "receiving the security service requirement instruction and the security policy corresponding thereto from the target network", the following steps can also be included:

[0106] When the security service requirement instruction is received, a security service ID is automatically generated for the security service corresponding to the security service requirement instruction.

[0107] In the embodiment, the user terminal or the third-party service application capable of carrying out the security service is pre-registered and authenticated on the MEC platform, that is, the MEC platform provides the security service within the scope of the pre-constructed end-to-end security information. That is, for the MEC platform carrying the security service, after authentication, the ID of the third-party service user and the ID of the user terminal are not transmitted in the business process, the security service ID is redistributed according to the security policy defined in the mapping relationship contained in the end-to-end security information, and the security service ID is used to replace the ID of the initiator of the security service requirement instruction, so that the privacy of the third-party service application and the user terminal can be protected on the open MEC platform, and the security service performance is further improved.

[0108] From the above, the embodiment establishes a secure link for end-to-end services, arranges a security service ID, and achieves privacy protection while completing the security service, which is also beneficial to improve the efficiency of the security service.

[0109] It can be understood that the present disclosure provides unified security services for network elements, user terminals and third-party service applications of the edge network through the MEC platform, and relies on the standard MEC architecture. The MEC server and the MEC host jointly support the security service. The above embodiments take the MEC server as the execution subject and describe the implementation process of the security service of the MEC platform. The following method embodiments take the MEC host as the execution subject and describe the implementation process of the security service of the MEC platform. The following embodiments can be applied to any MEC host in the MEC platform and can include the following contents:

[0110] In S301, end-to-end security information for storing the correspondence between authorized user terminals, authorized service applications and security policies is constructed in advance.

[0111] This step is consistent with the description of the related content described in S102 of the above embodiments, and will not be repeated here.

[0112] In S302, when it is detected that the security service parameter has been configured, it is judged whether the initiator corresponding to the security service demand instruction has been authorized based on the end-to-end security information.

[0113] This step is consistent with the description of the related content described in S102 of the above embodiments, and will not be repeated here.

[0114] In step S303, if the initiator has been authorized, the initiator is provided with the matching security service based on the end-to-end security information.

[0115] This step is consistent with the description of the related content described in S102 of the above embodiments, and will not be repeated here. The security service parameter is converted and generated by the MEC server according to the received security service demand instruction and the security policy from the target network corresponding thereto. The generation process of the security service parameter is consistent with the description of the related content described in S101 of the above embodiments, and will not be repeated here.

[0116] As can be seen from the above, the embodiments of the present application can realize the security service suitable for the 5G network on the basis of considering the network security performance and network quality requirements.

[0117] Based on the above embodiments, in the edge computing service scenario, the user has already registered in the network, but is not registered in the service, and the service security attribute and the network signaling security attribute can be different. Therefore, before the MEC platform service is performed, the user terminal needs to be registered in the edge network of the MEC platform. Similarly, the third-party service application on the MEC platform needs to be initiated, and permission still needs to be obtained. The network needs to identify the legitimacy of the user terminal and the legitimacy of the service application, and then edit the legitimate terminal and the legitimate application to the edge network end-to-end slice resource corresponding to the security level, so as to guarantee the end-to-end security. That is to say, for the user terminal and the third-party service application supporting the safe service on the MEC platform, registration and authentication operation need to be performed on the MEC platform. The above embodiments do not limit how to perform the authentication operation of the user terminal and the third-party service application. The present embodiment further provides an optional implementation manner. Similarly, for the implementation process of the authorization of the un-authorized initiator after the step of "judging whether the initiator corresponding to the safe service demand instruction is authorized based on the end-to-end security information", the implementation manner provided in the following embodiments can also be adopted, which can include the following contents:

[0118] When it is detected that there is a registration request or an authorization request of the user terminal or the third-party service application, the MEC host generates an authentication task and sends the authentication task after identity authentication is passed. The authentication parameter information is acquired. The end-to-end security information is updated based on the authentication parameter information, and the authentication passing information is sent to the initiator.

[0119] In the present embodiment, the authentication task carries the related data information of the initiator that needs to be authenticated, that is, the service parameter. After the MEC host initiates the service authentication and passes the service authentication, the corresponding service parameter is transmitted to the MEC server. The MEC server combines the service parameter corresponding to the service with the MEC arrangement scheduler to send the service demand information to the target network. The target network configures the resource information for the initiator according to the service demand information corresponding to the authentication task and the network environment information, so as to serve as the service configuration information of the initiator, and feeds back the service configuration information to the MEC platform. The MEC platform allocates the corresponding resource for the initiator based on the service configuration information, and notifies the controller of the MEC platform to develop the service for the initiator. After the resource allocation is completed, the MEC server acquires the authentication parameter information of the authentication task in the current MEC platform, and feeds back the authentication parameter information to the MEC host that initiates the authentication task, to complete the authentication operation or authorization operation of the initiator of the authentication task.

[0120] In the embodiment, for the third-party service application of the MEC platform to initiate the establishment request, first trigger the application identity authentication mechanism of the MEC host, and only after the identity authentication passes, the request command can be sent to the orchestration scheduler MECO of the MEC, and further sent to the network, indicating that an edge platform needs to initiate a certain service, including the basic security requirements of the service, the end point of the service, etc. Further, the target user terminal paged by the new service application also needs to be registered in the service, and the target user terminal will initiate the service registration task of the MEC platform, and the MEC platform can determine whether the terminal can access according to the service ID carried by the target user terminal.

[0121] In order to make the skilled in the art more clearly understand how the present disclosure implements the authentication operation, the present disclosure combines the accompanying drawings Figure 4 An optional implementation of how to initiate a secure service on the MEC platform is given, in which the functional module in the MEC server for implementing the computer program corresponding to the secure service initiation process processing method is called a secure service scheduling layer, and the target network can be a 5G core network, for example, and the functional module in the MEC host for providing a secure service is called a secure service business layer. Based on this, the embodiment can include the following content:

[0122] In step S401, a third-party new service application registration task is initiated on the MEC platform.

[0123] In step S402, the MEC platform locates the new service application registration to the secure service business layer and starts the service authentication.

[0124] In step S403, the secure service business layer passes the authentication, and transmits the corresponding service parameters to the secure service scheduling layer.

[0125] In step S404, the secure service scheduling layer notifies the MEC orchestration scheduler of the information of the secure service corresponding to the new service application to be carried out.

[0126] In step S405, the orchestration scheduler combines other service information of the MEC platform to generate a service demand message, and sends it to the core network.

[0127] In step S406, the core network configures the end-to-end service information by comprehensively considering the current end-to-end service data, network resource information, and load and other network environment information, that is, generates the service configuration information of the new service application, and sends the service configuration information to the orchestration scheduler of the MEC platform.

[0128] In step S407, after the orchestration scheduler receives the secure service configuration information of the network, the resources required by the new service application are instantiated and allocated, and the corresponding controller of the MEC platform is notified to start the service.

[0129] In step S408, the security service scheduling layer obtains the security service related parameters, i.e., the authentication parameter information.

[0130] In step S409, the security service scheduling layer transmits the authentication parameter information to the security service business layer.

[0131] In step S410, the security service business layer establishes an end-to-end security service chain for a new service application and updates the end-to-end security information.

[0132] In step S411, the security service business layer notifies the third-party business layer that the authentication is passed and the business can be carried out.

[0133] As can be seen from the above, the MEC platform can realize user identity protection, user privacy protection, MEC platform application authentication protection, MEC platform security, and MEC end-to-end secure transmission in the edge computing application scenario, thereby establishing the communication possibility of the edge business of the MEC platform and the user terminal. After the identity authentication of each user terminal and business application, the communication between the third-party business applications on the MEC platform and between the user terminals can be realized through the MEC platform. The edge platform provides security services, the terminal business joins the authentication, the third-party application business carries out the authentication, and the network together establishes the end-to-end security service access guarantee on the MEC platform, which is conducive to the stable, reliable, and secure business development of the MEC platform and is also a guarantee for the stable operation of the big data industry.

[0134] Based on the above embodiment, after the MEC platform identifies the identity of the user terminal or the third-party business application, it can allocate a security level and a security role to each business application and user terminal. Combined with the network security policy feedback of the scheduling editor, it can complete the storage of the corresponding relationship between the end-to-end security policy and parameters of a certain business, i.e., build the end-to-end security information, to serve as a reference for security business resource allocation and business migration. The above embodiment does not limit how to build the end-to-end security information, and the present embodiment further provides an optional building method of the end-to-end security information, which can include:

[0135] Obtain various types of security business data; classify and process the various types of security business data to obtain multiple groups of security business data belonging to different industries. For each group of security business data, perform security empowerment according to the industry security attribute to serve as the security policy of the corresponding security business data. According to the security empowered security business data and the data access information of each group of security business data, build an end-to-end security list.

[0136] In this embodiment, security business data refers to various types of security data obtained from the security infrastructure layer of the MEC host, such as authentication data and encryption data. After obtaining the security data, it can be classified first. For example, all authentication data can be clustered into one group, or classified based on whether the data needs to be reported to higher-level processing, or whether the data needs to be subjected to secondary analysis. Then, it can be classified according to different industries. Secondly, a pre-built end-to-end security list can be extracted based on the data attributes, such as... Figure 5 As shown, the end-to-end security list is a chain of end-to-end secure communication lists and policy lists. It links terminal security, security policies, and secure edge applications into a chain, forming the basic basis for the security classification and processing of MEC platform resources, data, and storage. Utilizing the industry security data integration module and based on big data analytics capabilities, industry security attributes are extracted to empower end-to-end security in edge application scenarios.

[0137] Furthermore, the security service layer of the MEC host maintains an end-to-end security list. This list associates terminals, security policies, and services, serving as the basis for secure processing of service slicing on the edge platform. After service management, a new security service ID is assigned, eliminating the need for multiple transmissions of user terminal IDs and third-party application IDs on the MEC platform, thus protecting privacy. To further improve the efficiency of security service implementation and enhance user experience, this embodiment can also group user terminals and service applications in the end-to-end security list according to security levels. Optionally, authorized user terminals in the end-to-end security information can be classified based on security levels to obtain multiple terminal groups; authorized terminals within the same terminal group belong to the same security level. Authorized service applications in the end-to-end security information can also be classified based on security levels to obtain multiple service groups. Authorized service applications within the same service group belong to the same security level. In this way, third-party edge applications within the same business group or secure terminals within the same security group can access each other throughout the business security lifecycle. That is, each authorized business application within the same business group has the right to access all other authorized business applications and each authorized terminal within the same authorized terminal group during the business security lifecycle; conversely, each authorized terminal within the same terminal group has the right to access each authorized terminal and each authorized business application within the same authorized business group during the business security lifecycle. For example, such as... Figure 5 As shown, edge service ID1 corresponds to third-party service ID2. All terminals in terminal group 1 can access third-party service ID2 without re-authentication.

[0138] The embodiment further optimizes the mapping relationship between the user terminal and the service application in the end-to-end security information, and can effectively save air interface resources and improve user experience for a massive terminal and massive service application scenario.

[0139] Based on the embodiment, the optional implementation of the step "judging whether the initiator of the security service demand instruction is authorized based on the end-to-end security information" in the above embodiment can include:

[0140] Determining the initiator and the accessed party of the security service demand instruction; if the initiator and the accessed party are located in the same service group, the initiator is authorized; if the initiator and the accessed party are located in the same terminal group, the initiator is authorized; if there is a user terminal that has the right to access the terminal group where the accessed party is located in the service group to which the initiator belongs, the initiator is authorized; and if there is a service application that has the right to access the service group where the accessed party is located in the terminal group to which the initiator belongs, the initiator is authorized.

[0141] That is, if the initiator or the accessed party is not authorized, or there is no authorized service or user terminal in the service group or the terminal group accessed by the initiator, re-authentication is required, and the implementation process of the authentication can refer to the method described in the above authentication embodiment.

[0142] In the embodiment, for a massive user terminal and massive application service, the user terminal and the third-party application are grouped according to the security level, and in the edge computing scenario, the user terminal accesses the user terminal, and the third-party service application on the MEC platform accesses the third-party service application, which can effectively reduce the authentication process, the terminals in the same group and the applications in the same group can access each other, and a feasible simplified process is provided for complex network services, and the implementation efficiency of the security service is effectively improved.

[0143] It should be noted that there is no strict execution order between the steps in the present disclosure, as long as the logical order is met, the steps can be executed simultaneously, or executed in a certain preset order, and the method flowchart is only a schematic mode and does not represent only this execution order.

[0144] The embodiment of the present application also provides a corresponding device for the security service implementation method, which further makes the method more practical. The device can be explained from the perspective of functional modules and hardware. The security service implementation device provided by the embodiment of the present application is introduced below, and the security service implementation device described below can be mutually referred to the security service implementation method described above.

[0145] Based on the perspective of functional modules, please refer to Figure 6 , Figure 6The structure diagram of the security service implementation device provided by the embodiment of the present application in an implementation manner, the device is applied to a MEC server of a MEC platform, the MEC platform further includes a plurality of MEC hosts, each MEC host is preconfigured with end-to-end security information for storing the correspondence among authorized user terminals, authorized service applications and security policies; the device can include:

[0146] The conversion module 601 is configured to convert the received security service requirement instruction and the security policy from the target network corresponding to the security service requirement instruction into security service parameters applicable to the target MEC host; the target MEC host is a MEC host used for executing the security service corresponding to the security service requirement instruction.

[0147] The sending module 602 is configured to send the security service parameters, configure the target MEC host based on the security service parameters, and provide the authorized initiator with the matching security service based on the end-to-end security information by using the target MEC host.

[0148] Optionally, as an optional implementation manner of the above-mentioned embodiment, the conversion module 601 can be further configured to: when receiving a target security attribute service initiated by a third-party service application through the MEC platform, translate the target security attribute service into service attribute information applicable to the MEC platform; generate network requirement signaling according to the service attribute information and service scheduling information, and send the network requirement signaling to the target network; obtain the security policy sent by the target network; the security policy is generated by the target network based on the network requirement signaling and network environment information; and translate the security policy into security service parameters.

[0149] As an optional implementation manner parallel to the above-mentioned embodiment, the conversion module 601 can be further configured to: when receiving a network security requirement message sent by a target user terminal through a target network, translate the network security requirement information into security service parameters; the network security requirement message includes the security service requirement and the security policy of the user terminal.

[0150] As another optional implementation manner parallel to the above-mentioned embodiment, the conversion module 601 can be further configured to: when receiving a network security requirement message sent by a target network element, translate the network security requirement information into security service parameters; the network security requirement message includes the security service requirement and the security policy of the network element.

[0151] Optionally, as another optional implementation manner of the above-mentioned embodiment, refer to Figure 7 The device can further include a service ID allocation module 603 configured to automatically generate a security service ID for the security service corresponding to the security service requirement instruction when receiving the security service requirement instruction; the security service ID is used to replace the ID of the initiator of the security service requirement instruction.

[0152] The above device embodiment is based on the functional modules in the MEC server of the MEC platform. The device is also described based on the functional modules in the MEC host of the MEC platform. Please refer to Figure 8 , Figure 8 The structure diagram of the security service implementation device provided by the embodiment of the application in another implementation manner is shown. The device is applied to the MEC host of the MEC platform, and the MEC platform further includes a MEC server. The device can include:

[0153] The relationship construction module 801 is configured to pre-construct end-to-end security information for storing the corresponding relationship among the authorized user terminal, the authorized business application, and the security policy.

[0154] The security service providing module 802 is configured to, when it is detected that the security service parameter has been configured, if it is determined based on the end-to-end security information that the initiator corresponding to the security service demand instruction has been authorized, provide the initiator with the matching security service based on the end-to-end security information. The security service parameter is converted and generated by the MEC server according to the received security service demand instruction and the security policy from the target network corresponding thereto.

[0155] Optionally, as an optional implementation manner of the above embodiment, please refer to Figure 9 The device can further include an authentication module 803 configured to, if the initiator is not authorized, generate an authentication task and send the authentication task after identity authentication is passed, obtain authentication parameter information, and update the end-to-end security information based on the authentication parameter information and send the authentication passing information to the initiator. The authentication parameter information is obtained and transmitted by the MEC server after the MEC platform allocates corresponding resources for the initiator based on the business configuration information and notifies the controller of the MEC platform. The business configuration information is the resource information configured for the initiator by the target network according to the authentication task and the network environment information.

[0156] Optionally, as another optional implementation manner of the above embodiment, the relationship construction module 801 can be further configured to: obtain various types of security business data; perform classification processing on the various types of security business data to obtain multiple groups of security business data belonging to different industries; perform security empowerment on each group of security business data according to the industry security attribute to serve as the security policy of the corresponding security business data; and construct the end-to-end security list according to the security business data after security empowerment and the data access information of each group of security business data.

[0157] As an optional implementation of the above embodiments, the relationship construction module 801 may further be used to: classify each authorized user terminal in the end-to-end security information based on the security level to obtain multiple terminal groups; authorized terminals within the same terminal group have the same security level; classify each authorized business application in the end-to-end security information based on the security level to obtain multiple business groups; authorized business applications within the same business group have the same security level; wherein, each authorized business application within the same business group has the right to access all other authorized business applications and each authorized terminal within the same authorized terminal group during the business security lifecycle; each authorized terminal within the same terminal group has the right to access each authorized terminal and each authorized business application within the same authorized business group during the business security lifecycle.

[0158] As another optional implementation of the above embodiments, the security service providing module 802 may further be used to: determine the initiator and the accessed party of the security service request instruction; if the initiator and the accessed party are located in the same business group, the initiator has been authorized; if the initiator and the accessed party are located in the same terminal group, the initiator has been authorized; if there is a user terminal in the business group to which the initiator belongs that has the right to access the terminal group to which the accessed party is located, the initiator has been authorized; if there is a business application in the terminal group to which the initiator belongs that has the right to access the business group to which the accessed party is located, the initiator has been authorized.

[0159] The functions of each functional module of the security service implementation device in this embodiment of the invention can be specifically implemented according to the methods in the above method embodiments. The specific implementation process can be referred to the relevant descriptions in the above method embodiments, which will not be repeated here.

[0160] As can be seen from the above, the embodiments of the present invention can realize security services suitable for 5G networks while taking into account both network security performance and network quality requirements.

[0161] The security service implementation device mentioned above is described from the perspective of functional modules. Figure 10 This is a block diagram illustrating an electronic device 1000 according to an exemplary embodiment. For example... Figure 10 As shown, the electronic device 1000 may include: a processor 1001 and a memory 1002. The electronic device 1000 may also include one or more of a multimedia component 1003, an input / output (I / O) interface 1004, and a communication component 1005.

[0162] The processor 1001 is configured to control overall operations of the electronic device 1000 to complete all or part of the steps of the above-mentioned security service implementation method. The memory 1002 is configured to store various types of data to support operations of the electronic device 1000, which can include, for example, instructions for operating any application or method on the electronic device 1000, and application-related data, such as contact data, transmitted and received messages, pictures, audio, video, and the like. The memory 1002 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as a static random access memory (SRAM), an electrically erasable programmable read-only memory (EEPROM), an erasable programmable read-only memory (EPROM), a programmable read-only memory (PROM), a read-only memory (ROM), a magnetic storage, a flash memory, a magnetic disk, or an optical disk. The multimedia component 1003 can include a screen and an audio component. The screen can be, for example, a touch screen, and the audio component is configured to output and / or input audio signals. For example, the audio component can include a microphone configured to receive external audio signals. The received audio signals can be further stored in the memory 1002 or transmitted through the communication component 1005. The audio component also includes at least one speaker configured to output audio signals. The I / O interface 1004 provides an interface between the processor 1001 and other interface modules, which can be a keyboard, a mouse, a button, and the like. The buttons can be virtual buttons or physical buttons. The communication component 1005 is configured to perform wired or wireless communication between the electronic device 1000 and other devices. The wireless communication, such as Wi-Fi, Bluetooth, near field communication (NFC), 2G, 3G, or 4G, or a combination of one or more of them, so the corresponding communication component 1005 can include a Wi-Fi module, a Bluetooth module, and an NFC module.

[0163] In an exemplary embodiment, the electronic device 1000 can be implemented by one or more Application Specific Integrated Circuits (ASICs), Digital Signal Processors (DSPs), Digital Signal Processing Devices (DSPDs), Programmable Logic Devices (PLDs), Field Programmable Gate Arrays (FPGAs), controllers, micro-controllers, microprocessors, or other electronic elements for performing the above-mentioned security service implementation method.

[0164] In another exemplary embodiment, a computer-readable storage medium including program instructions that, when executed by a processor, implement the steps of the above-mentioned security service implementation method is also provided. For example, the computer-readable storage medium can be the above-mentioned memory 1002 including program instructions that are executable by the processor 1001 of the electronic device 1000 to complete the above-mentioned security service implementation method.

[0165] Figure 11 is a block diagram of an electronic device 1100 according to an exemplary embodiment. For example, the electronic device 1100 can be provided as a server. Referring to Figure 11 , the electronic device 1100 can include a processor 1122, the number of which can be one or more, and a memory 1132 for storing a computer program executable by the processor 1122. The computer program stored in the memory 1132 can include one or more modules each corresponding to a set of instructions. In addition, the processor 1122 can be configured to execute the computer program to perform the above-mentioned security service implementation method.

[0166] In addition, the electronic device 1100 can further include a power supply component 1126 that can be configured to perform power management of the electronic device 1100, and a communication component 1150 that can be configured to implement communication of the electronic device 1100, for example, wired or wireless communication. In addition, the electronic device 1100 can further include an input / output (I / O) interface 1158. The electronic device 1100 can operate based on an operating system stored in the memory 1132, for example, Windows ServerTM, Mac OS XTM, UnixTM, LinuxTM, etc.

[0167] In another example embodiment, a computer readable storage medium including program instructions that, when executed by a processor, implement the steps of the above-described security service implementation method is also provided. For example, the computer readable storage medium can be the above-described memory 1132 including program instructions that are executable by the processor 1122 of the electronic device 1100 to complete the above-described security service implementation method.

[0168] Finally, the embodiment of the present application also provides a security service implementation system which can be embedded in a MEC platform, please refer to Figure 12 , which can include:

[0169] The security service system 120 can include a security service scheduling layer 121, a plurality of identical security service business layers 122, and a MEC host management module 123. The security service scheduling layer 121 is deployed in a MEC server, and each security service business layer 122 is deployed in a corresponding MEC host. Each security service business layer 122 includes a plurality of security service interfaces for being invoked by third-party business applications. The security service scheduling layer 121 is configured to implement the method steps in any one of the above-described security service implementation method embodiments when executing a computer program. Each security service business layer is configured to implement the method steps in any one of the above-described security service implementation method embodiments when executing a computer program. In terms of data processing, the security service business layer 122 of the MEC host can provide the MEC platform with third-party application authentication capability, terminal authentication capability, privacy protection capability, encrypted data protection capability, and various built-in security capabilities of security APPs developed according to application requirements, such as Figure 12 The MEC host management module 123 can be configured to manage a plurality of MEC hosts and to map the security service parameters generated by the security service scheduling layer 121 to target security service interfaces of the corresponding MEC hosts.

[0170] The functions of the functional modules of the security service system of the embodiment of the present application can be implemented according to the methods in the above-described method embodiments, and the specific implementation process can be referred to the related descriptions of the above-described method embodiments, which will not be described here in detail.

[0171] In order to make the skilled in the art more clearly understand the technical solutions of the present embodiment, the present embodiment also combines Figure 13 to give an illustrative example, which can include the following content:

[0172] In the present embodiment, the MEC platform includes a security service scheduling layer 121 embedded in a MEC edge server system layer, a security management module embedded in a MEC host management module 123, and a security service business layer 122 embedded in a MEC host of the MEC platform.

[0173] The security service scheduling layer 121 assists the MEC orchestration scheduler to complete the security scheduling work in edge computing. Optionally, the security service scheduling layer 121 can be used to analyze network security parameters and translate them into security inputs required by the security service platform of the MEC; and is also used to translate the security requirements of the MEC platform into network parameters and submit them to the 5G network. The security management module completes the mapping work of the security scheduling parameters and a certain MEC host, so as to realize the configuration of the security service parameters of the MEC host. The security service business layer 122 provides security services for the MEC host, such as third-party application authentication, access terminal authentication, end-to-end same security level service, privacy protection, etc. In addition, the security service business layer 122 can further derive a security service APP 124, and each security service APP provides different security service interfaces for the MEC platform, which are called by third-party business applications, and provide security services such as authentication services of applications and encryption services of application data.

[0174] Based on the MEC platform of the above embodiment, one of the application scenarios of the present disclosure can be implemented by a user terminal accessing a third-party business application. The user terminal initiates a security access service for accessing third-party business application data to the MEC platform through the 5G network, and the security access service carries the user terminal ID, the security policy generated by the 5G network for the security access service, and the accessed third-party business application ID. The security service scheduling layer of the MEC platform receives the security access service, translates the security access service into security service parameters understood by the MEC platform, and allocates an edge service ID for the security access service. The MEC host management module maps the security service parameters to the interface of the security service parameters of the MEC host that develops the security access service, the MEC host issues an instantiation security resource requirement, and configures the security service parameters to the security service business layer. The security service business layer calls an end-to-end security list, and if the user terminal ID and the third-party business application ID are not authorized to access each other in the end-to-end security list, authentication is required. If the third business application ID is not in the end-to-end security list, a registration reminder instruction can be generated. If the user terminal ID and the third-party business application ID are authorized to access each other in the end-to-end security list, the user terminal is allowed to access the third-party business application, and at this time, the user terminal can access the coherent data of the third-party business application.

[0175] It should be noted that the above application scenario is only shown for the purpose of facilitating the understanding of the ideas and principles of the present disclosure, and the embodiments of the present disclosure are not limited in this respect. On the contrary, the embodiments of the present disclosure can be applied to any applicable scenario.

[0176] As can be seen from the above, the embodiments of the present application can realize the security service applicable to the 5G network on the basis of considering the network security performance and network quality requirements.

[0177] The optional embodiments of the present disclosure are described in detail above in combination with the drawings, but the present disclosure is not limited to the specific details in the above-described embodiments. Within the technical concept range of the present disclosure, various simple modifications can be made to the technical solutions of the present disclosure, and these simple modifications all belong to the protection range of the present disclosure. For example, the 5G network can be changed to a 4G network. In addition, it should be noted that various specific technical features described in the above specific embodiments can be combined in any appropriate manner without contradiction. In order to avoid unnecessary repetition, various possible combination manners are not described again in the present disclosure.

[0178] In addition, any combination of various different embodiments of the present disclosure can also be made, as long as it does not deviate from the idea of the present disclosure, and it should also be considered as disclosed by the present disclosure.

Claims

1. A method of implementing a security service, characterized by, A MEC server applied to a MEC platform, the MEC platform further comprising a plurality of MEC hosts, each MEC host pre-constructing end-to-end security information for storing a correspondence between authorized user terminals, authorized service applications and security policies; The method comprises: Converting the received security service requirement instruction and the security policy from the target network corresponding thereto into security service parameters applicable to the target MEC host; Sending the security service parameters to configure the target MEC host based on the security service parameters, and using the target MEC host to provide the authorized initiator with a matching security service based on the end-to-end security information; Wherein, the target MEC host is a MEC host for executing the security service corresponding to the security service requirement instruction; Wherein, before the received security service requirement instruction and the security policy from the target network corresponding thereto, further comprising: When receiving a security service requirement instruction, automatically generating a security service ID for the security service corresponding to the security service requirement instruction; Wherein, the security service ID is used to replace the ID of the initiator of the security service requirement instruction.

2. The security service implementation method according to claim 1, characterized by, The conversion of the received security service requirement instruction and the security policy from the target network corresponding thereto into security service parameters applicable to the target MEC host comprises: When receiving a target security attribute service initiated by a third-party service application through the MEC platform, translating the target security attribute service into service attribute information applicable to the MEC platform; According to the service attribute information and the service scheduling information, generating network demand signaling and sending the network demand signaling to the target network; Obtaining the security policy sent by the target network; the security policy is generated by the target network based on the network demand signaling and network environment information; Translate the security policy into the security service parameters.

3. The security service implementation method of claim 1, wherein, The conversion of the received security service requirement instruction and the security policy from the target network corresponding thereto into security service parameters applicable to the target MEC host comprises: When receiving a network security requirement message sent by a target user terminal through the target network, translating the network security requirement information into security service parameters; Wherein, the network security requirement message comprises the security service requirement and the security policy of the user terminal.

4. The security service implementation method of claim 1, wherein, The conversion of the received security service requirement instruction and the security policy from the target network corresponding thereto into security service parameters applicable to the target MEC host comprises: When receiving a network security requirement message sent by a target network element, translating the network security requirement information into security service parameters; Wherein, the network security requirement message comprises the security service requirement and the security policy of the network element.

5. A security service implementation method characterized by, A MEC host applied to a MEC platform, the MEC platform further comprising a MEC server; the method comprises: Pre-constructing end-to-end security information for storing a correspondence between authorized user terminals, authorized service applications and security policies; When it is detected that the security service parameter has been completed configuration, it is judged whether the initiator corresponding to the security service demand instruction has been authorized based on the end-to-end security information; If the initiator has been authorized, the matching security service is provided for the initiator based on the end-to-end security information; Wherein, the security service parameter is converted and generated by the MEC server according to the received security service demand instruction and the security policy from the target network corresponding thereto; Wherein, the MEC server automatically generates a security service ID for the security service corresponding to the security service demand instruction when receiving the security service demand instruction; the security service ID is used to replace the ID of the initiator of the security service demand instruction.

6. The security service implementation method according to claim 5, characterized by, After judging whether the initiator corresponding to the security service demand instruction has been authorized based on the end-to-end security information, it further includes: If the initiator has not been authorized, an authentication task is generated, and after the identity authentication passes, the authentication task is sent; Obtain authentication parameter information; the authentication parameter information is obtained and transmitted by the MEC server after the MEC platform allocates corresponding resources for the initiator based on the service configuration information and notifies the controller of the MEC platform; the service configuration information is the resource information configured by the target network for the initiator according to the authentication task and network environment information; Update the end-to-end security information based on the authentication parameter information, and send the authentication pass information to the initiator.

7. The security service implementation method according to claim 5, characterized by, The end-to-end security information for storing the corresponding relationship among authorized user terminals, authorized business applications and security policies is constructed, including: Obtain various types of security business data; Classify and process various types of security business data to obtain multiple groups of security business data belonging to different industries; Respectively, for each group of security business data, security enablement is performed according to the industry security attribute to serve as the security policy of the corresponding security business data; According to the security business data after security enablement and the data access information of each group of security business data, an end-to-end security list is constructed.

8. The security service implementation method according to any one of claims 5 to 7, characterized by, The end-to-end security information for storing the corresponding relationship among authorized user terminals, authorized business applications and security policies is constructed, including: Classify each authorized user terminal in the end-to-end security information based on the security level to obtain multiple terminal groups; the authorized terminals in the same terminal group are of the same security level; Classify each authorized business application in the end-to-end security information based on the security level to obtain multiple business groups; the authorized business applications in the same business group are of the same security level; Wherein, each authorized business application in the same business group has the right to access the remaining authorized business applications and each authorized terminal in the same authorized terminal group within the business security life cycle; each authorized terminal in the same terminal group has the right to access each authorized terminal and each authorized business application in the same authorized business group within the business security life cycle.

9. The security service implementation method according to claim 8, characterized by, The judgment of whether the initiator corresponding to the security service demand instruction has been authorized based on the end-to-end security information includes: Determine the initiator and the accessed party of the security service demand instruction; If the initiator and the visited party are in the same service group, the initiator has been authorized; If the initiator and the visited party are in the same terminal group, the initiator has been authorized; If there is a user terminal in the service group to which the initiator belongs and which has the right to access the terminal group to which the visited party belongs, the initiator has been authorized; If there is a service application in the terminal group to which the initiator belongs and which has the right to access the service group to which the visited party belongs, the initiator has been authorized.

10. A security service implementation apparatus characterized by comprising: The MEC server applied to the MEC platform further comprises a plurality of MEC hosts, and each MEC host is preconfigured to build end-to-end security information for storing the correspondence among authorized user terminals, authorized service applications and security policies; The device comprises: A conversion module is configured to convert the received security service demand instruction and the security policy from the target network corresponding thereto into security service parameters applicable to the target MEC host, wherein the target MEC host is a MEC host used to execute the security service corresponding to the security service demand instruction; A sending module is configured to send the security service parameters, configure the target MEC host based on the security service parameters, and provide the authorized initiator with the matching security service based on the end-to-end security information by using the target MEC host; The device further comprises: A service ID allocation module is configured to automatically generate a security service ID for the security service corresponding to the security service demand instruction when the security service demand instruction is received. The security service ID is used to replace the ID of the initiator of the security service demand instruction.

11. A security service implementation apparatus characterized by comprising: The MEC host applied to the MEC platform further comprises a MEC server; the device comprises: A relationship construction module is configured to pre-construct end-to-end security information for storing the correspondence among authorized user terminals, authorized service applications and security policies; A security service providing module is configured to, when it is detected that the security service parameters have been configured, provide the initiator with the matching security service based on the end-to-end security information if it is determined that the initiator of the security service demand instruction has been authorized based on the end-to-end security information, wherein the security service parameters are generated by the MEC server based on the received security service demand instruction and the security policy from the target network corresponding thereto; The MEC server automatically generates a security service ID for the security service corresponding to the security service demand instruction when the security service demand instruction is received; the security service ID is used to replace the ID of the initiator of the security service demand instruction.

12. A security service system characterized by comprising: The MEC platform comprises a security service scheduling layer, a plurality of identical security service business layers and a MEC host management module; The security service scheduling layer is deployed in the MEC server, and each security service business layer is deployed in a corresponding MEC host; each security service business layer comprises a plurality of security service interfaces for being called by third-party service applications; The security service scheduling layer is configured to implement the security service implementation method according to any one of claims 1 to 4 when executing the computer program; each security service service layer is configured to implement the security service implementation method according to any one of claims 5 to 9 when executing the computer program; and the MEC host management module is configured to map the security service parameters generated by the security service scheduling layer to target security service interfaces of corresponding MEC hosts.

13. An electronic device, comprising: The computer program is stored on the computer-readable storage medium and comprises computer program code configured to perform the steps of the security service implementation method according to any one of claims 1 to 4 and / or the security service implementation method according to any one of claims 5 to 9 when the computer program code is executed by the processor. The computer program is stored on the computer-readable storage medium and comprises computer program code configured to perform the steps of the security service implementation method according to any one of claims 1 to 4 and / or the security service implementation method according to any one of claims 5 to 9 when the computer program code is executed by the processor. The computer program is stored on the computer-readable storage medium and comprises computer program code configured to perform the steps of the security service implementation method according to any one of claims 1 to 4 and / or the security service implementation method according to any one of claims 5 to 9 when the computer program code is executed by the processor.

14. A readable storage medium, characterized by, ​

Citation Information

Patent Citations

  • 5G mobile communication method and system based on MEC (Mobile Edge Computing) and hierarchical SDN (software defined network)

    CN107404733A

  • Security protection method, device and system for edge computing APP

    CN114615000A