Methods, systems, and apparatus, contexture

By working collaboratively with the private network cloud management platform and the authorization center, the identity identifiers of private network devices and applications are obtained and parsed, solving the problem of insufficient authorization and management efficiency caused by the increase in the number of private network devices, and improving the security and stability of private network devices and applications.

CN116545658BActive Publication Date: 2026-01-13ALIBABA (CHINA) CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310396768.4
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-11-09
Publication Date
2026-01-13
Estimated Expiration
2042-11-09

AI Technical Summary

Technical Problem

In existing technologies, the increased number of private network devices in private network scenarios leads to insufficient efficiency in offline authorization and control, making it difficult to guarantee the security and stability of private network devices, applications on private network devices, and the entire private network scenario.

Method used

The private network cloud management platform obtains the identity identifier of the private network device and the application identifier of the target application, generates a query request and sends it to the authorization center, receives and parses the query results fed back by the authorization center, thereby determining the private network device's permissions to the target application and realizing centralized management and control of the private network device's permissions.

Benefits of technology

It enhances the security and stability of private network equipment and applications, improves the efficiency of authorization and control, avoids the shortcomings of offline authorization confirmation, and ensures the effectiveness of control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116545658B_ABST
    Figure CN116545658B_ABST
Patent Text Reader

Abstract

The embodiment of the present specification provides a right confirmation method, system and device, wherein the right confirmation method is applied to a private network cloud management and control platform, and includes: receiving a right update request input by a user on a front end, forwarding the right update request to an authorization center, so that the authorization center updates a right of a private network device to a target application according to the right update request, wherein the private network device is any network device in a private network scene, receiving a right update message fed back by the authorization center, and determining an updated right of the private network device to the target application according to the right update message. The right confirmation method applied to the private network cloud management and control platform realizes centralized management and control of the right of the private network device to the target application, guarantees the effectiveness of the management and control, and improves the security and stability of the private network device, an application on the private network device, and the entire private network scene. The right update of the private network device is realized through the private network cloud management and control platform, the timeliness and effectiveness of the management and control are guaranteed, and the stability of the private network scene is further improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The embodiments in this specification relate to the field of authorization verification technology, and in particular to a method for confirming authorization. Background Technology

[0002] With the development of communication technology, more and more dedicated network scenarios are needed, such as dedicated networks for companies, departments, factories, and schools. For reasons of data security, stability, and management effectiveness, these dedicated network scenarios are independent of public network scenarios, deploying dedicated network equipment to achieve internal data transmission and processing. For dedicated network equipment in these scenarios, corresponding functions are achieved by installing applications on them. Accordingly, access control for these applications is a crucial function. By controlling the functions, specifications, and other permissions of applications on dedicated network equipment, unauthorized use and misuse of applications are prevented, ensuring the security and stability of the dedicated network equipment, its applications, and the entire dedicated network scenario.

[0003] Currently, due to the limited number of private network devices in dedicated network scenarios, the permissions granted to these devices for applications are primarily generated by the application providers and managed through offline consoles. The corresponding authorization process also needs to be executed through an offline console.

[0004] However, due to the multiple applications mounted on private network devices, and this number increasing with growing usage demands, coupled with the continuous growth in the number of private network devices themselves due to advancements in communication technology, the current offline authorization and control method suffers from insufficient efficiency and struggles to maintain effective control. This results in inadequate security and stability for private network devices, applications on them, and the entire private network scenario. Therefore, a new authorization method is urgently needed to improve control efficiency and enhance the security and stability of private network devices, applications on them, and the entire private network scenario. Summary of the Invention

[0005] In view of this, embodiments of this specification provide a method for confirming ownership. One or more embodiments of this specification simultaneously relate to a method for confirming ownership of a smart application, a private network system, an ownership confirmation device, a computing device, a computer-readable storage medium, and a computer program, to address the technical deficiencies existing in the prior art.

[0006] According to a first aspect of the embodiments of this specification, a method for confirming rights is provided, applied to a private network cloud management and control platform, including:

[0007] Obtain the identity identifier of the private network device and the application identifier of the target application, wherein the private network device is any network device in the private network scenario;

[0008] Generate a query request based on the identity identifier and application identifier;

[0009] The query request is sent to the authorization center, which then determines the private network device's permissions for the target application based on the identity identifier and application identifier, and generates the query results.

[0010] Receive query results from the authorization center;

[0011] Based on the query results, determine the permissions of the private network equipment for the target application.

[0012] According to a second aspect of the embodiments of this specification, a method for determining rights is provided, applied to an application server, comprising:

[0013] Receive permission verification requests for the target application sent by private network devices, where the private network device is any network device in the private network scenario, and the permission verification request carries the device information of the private network device;

[0014] Generate the identity identifier for the private network device based on the device information;

[0015] Send the identity identifier to the private cloud management platform;

[0016] Receive query results from the private network cloud management platform. The query results are obtained by the private network cloud management platform from the authorization center based on the identity identifier and the application identifier of the target application. The query results represent the permissions of the private network device for the target application.

[0017] Based on the query results, determine the permissions of the private network equipment for the target application.

[0018] According to a third aspect of the embodiments of this specification, a method for determining the rights of a smart application is provided, applied to a private network cloud management and control platform in a smart park, including:

[0019] Obtain the identity identifier of smart park equipment and the application identifier of smart applications, where smart park equipment refers to any smart terminal device in the smart park;

[0020] Generate a query request based on the identity identifier and application identifier;

[0021] The query request is sent to the authorization center of the smart application, so that the authorization center can determine the smart park device's permissions for the smart application based on the identity identifier and application identifier, and generate query results;

[0022] Receive query results from the authorization center;

[0023] Based on the query results, determine the permissions of smart park devices for smart applications.

[0024] According to a fourth aspect of the embodiments of this specification, a private network system is provided, comprising:

[0025] The private network cloud management platform is configured to obtain the identity identifier of the private network device and the application identifier of the target application, where the private network device can be any network device; based on the identity identifier and application identifier, it generates a query request and sends the query request to the authorization center;

[0026] The authorization center is configured to receive query requests, determine the permissions of private network devices for the target application based on the identity identifier and application identifier, generate query results, and feed the query results back to the private network cloud management and control platform;

[0027] The private network cloud management platform is also configured to receive query results from the authorization center and determine the permissions of private network devices for target applications based on the query results.

[0028] According to a fifth aspect of the embodiments of this specification, a rights confirmation device is provided, applied to a private network cloud management and control platform, comprising:

[0029] The first acquisition module is configured to acquire the identity identifier of the private network device and the application identifier of the target application, wherein the private network device is any network device in the private network scenario;

[0030] The first generation module is configured to generate query requests based on identity identifier and application identifier;

[0031] The first sending module is configured to send a query request to the authorization center, so that the authorization center can determine the private network device's permissions for the target application based on the identity identifier and application identifier, and generate query results;

[0032] The first receiving module is configured to receive the query results fed back by the authorization center;

[0033] The first determination module is configured to determine the permissions of the private network device for the target application based on the query results.

[0034] According to a sixth aspect of the embodiments of this specification, a rights confirmation device is provided, applied to an application server, comprising:

[0035] The second receiving module is configured to receive permission verification requests for the target application sent by the private network device, wherein the private network device is any network device in the private network scenario, and the permission verification request carries the device information of the private network device.

[0036] The second generation module is configured to generate the identity identifier of the private network device based on the device information;

[0037] The second sending module is configured to send the identity identifier to the private network cloud management platform;

[0038] The third receiving module is configured to receive the query results fed back by the private network cloud management platform. The query results are obtained by the private network cloud management platform from the authorization center based on the identity identifier and the application identifier of the target application. The query results represent the permissions of the private network device for the target application.

[0039] The second determination module is configured to determine the permissions of the private network device for the target application based on the query results.

[0040] According to a seventh aspect of the embodiments of this specification, a computing device is provided, comprising:

[0041] Memory and processor;

[0042] The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions. When the computer-executable instructions are executed by the processor, they implement the steps of the above-mentioned rights confirmation method or the rights confirmation method of the above-mentioned smart application.

[0043] According to an eighth aspect of the embodiments of this specification, a computer-readable storage medium is provided that stores computer-executable instructions, which, when executed by a processor, implement the steps of the above-described rights confirmation method or the rights confirmation method of the above-described smart application.

[0044] According to a ninth aspect of the embodiments of this specification, a computer program is provided, wherein when the computer program is executed in a computer, it causes the computer to perform the steps of the above-described rights confirmation method or the rights confirmation method of the above-described smart application.

[0045] In one or more embodiments of this specification, the identity identifier of the private network device and the application identifier of the target application are obtained. The private network device can be any network device in the private network scenario. Based on the identity identifier and application identifier, a query request is generated and sent to the authorization center. The authorization center determines the private network device's permissions to the target application based on the identity identifier and application identifier, generates query results, receives the query results from the authorization center, and determines the private network device's permissions to the target application based on the query results. This authorization method applied to a cloud management platform achieves centralized control over the permissions of private network devices to target applications, ensuring the effectiveness of control and improving the security and stability of the private network device, the applications on the private network device, and the entire private network scenario. By using the identity identifier and application identifier of the private network device to generate a query request and send it to the authorization center to obtain query results, offline authorization is avoided, improving the efficiency of authorization. Attached Figure Description

[0046] Figure 1 This is a structural topology diagram of a private network scenario provided in one embodiment of this specification;

[0047] Figure 2This is a flowchart illustrating an authorization method for a private network cloud management platform, provided in one embodiment of this specification.

[0048] Figure 3 This is a flowchart illustrating an application server authorization method provided in one embodiment of this specification;

[0049] Figure 4 This is a flowchart illustrating an authorization method for a smart application applied to a private network cloud management platform, provided in one embodiment of this specification.

[0050] Figure 5 This is a flowchart illustrating the processing procedure of an authorization method applied to a 5G private network cloud management platform, provided in one embodiment of this specification.

[0051] Figure 6 This is a system block diagram of a private network system provided in one embodiment of this specification;

[0052] Figure 7 This is a data processing flow diagram for a private network scenario provided by one embodiment of this specification;

[0053] Figure 8 This is a data processing flow diagram in an application server for a private network scenario, provided by one embodiment of this specification.

[0054] Figure 9A This is a schematic diagram of the structure of a private network system provided in one embodiment of this specification;

[0055] Figure 9B This is a schematic diagram of another private network system provided in one embodiment of this specification;

[0056] Figure 10 This is a schematic diagram of the structure of an authorization device applied to a private network cloud management and control platform, provided in one embodiment of this specification.

[0057] Figure 11 This is a schematic diagram of a device for determining the rights of an application server, provided in one embodiment of this specification.

[0058] Figure 12 This is a structural block diagram of a computing device provided in one embodiment of this specification. Detailed Implementation

[0059] Many specific details are set forth in the following description to provide a full understanding of this specification. However, this specification can be implemented in many other ways than those described herein, and those skilled in the art can make similar extensions without departing from the spirit of this specification. Therefore, this specification is not limited to the specific implementations disclosed below.

[0060] The terminology used in one or more embodiments of this specification is for the purpose of describing particular embodiments only and is not intended to be limiting of the one or more embodiments of this specification. The singular forms “a,” “described,” and “the” as used in one or more embodiments of this specification and the appended claims are also intended to include the plural forms unless the context clearly indicates otherwise. It should also be understood that the term “and / or” as used in one or more embodiments of this specification refers to and includes any or all possible combinations of one or more associated listed items.

[0061] It should be understood that although the terms first, second, etc., may be used to describe various information in one or more embodiments of this specification, such information should not be limited to these terms. These terms are only used to distinguish information of the same type from one another. For example, first may also be referred to as second without departing from the scope of one or more embodiments of this specification, and similarly, second may also be referred to as first. Depending on the context, the word "if" as used herein may be interpreted as "when," "when," or "in response to a determination."

[0062] First, the terms and concepts used in one or more embodiments of this specification will be explained.

[0063] 5G (5th Generation Mobile Communication Technology): A broadband mobile communication technology characterized by high speed, low latency, and massive connectivity. 5G Private Network: A dedicated network scenario utilizing 5G communication technology, deploying private network equipment in designated areas. Core Network: In 5G communication technology, it provides user connectivity, user management, and service delivery, serving as the interface to external networks.

[0064] Mobile Edge Computing (MEC): A method of deploying industrial applications close to dedicated network equipment such as base stations and UPFs, enabling low-latency computing. User Plane Function (UPF): Dedicated network equipment for the data plane of the core network. Typically deployed in designated areas to handle routing and forwarding of user plane data packets within the 5G core network.

[0065] Radio Access Network (RAN): In 5G communication technology, it is a system composed of a series of transmission devices between the service node (switch) interface and the relevant user network interface, including base stations, radio frequency units and other equipment.

[0066] Access and Mobility Management Function (AMF): Implements registration, connection, reachability, and mobility management. It provides a session management message transmission channel for the UE (User Equipment) and SMF (Session Management Function), offering authentication and authorization functions for user access. It serves as the core network control plane access point for the terminal and radio. Session Management Function: Implements channel maintenance, IP address allocation and management, UP function selection, policy enforcement, and control in QoS (Quality of Service) routing, as well as billing data collection and roaming. Authentication Server Function (AUSF): Implements 3GPP and non-3GPP access authentication. Policy Control Function (PCF): Implements policy rules for control plane functions based on a unified policy framework. Unified Data Management Function (UDM): Implements 3GPP / PAKA authentication, user identification, access authorization, registration, mobility, subscription, and SMS management.

[0067] Centralized Unit (CU): Primarily includes non-real-time high-layer wireless protocol stack functions, while also supporting the deployment of some core network functions and edge application services. Distributed Unit (DU): Primarily handles physical layer functions and functions requiring real-time performance. Remote Radio Unit (RRU): Corresponding to the Radio Server (RS), it divides the base station into a near-end unit (RF Server) and a remote unit (Remote Radio Unit), connected by fiber optic cable for stable connection to network equipment. The RS can be installed in a suitable equipment room location, while the RRU is installed at the antenna end.

[0068] Cloud management service: A network management service deployed on a private network cloud management platform to centrally, automatically, and intelligently manage offline private network equipment (base stations, core networks, etc.).

[0069] This specification provides a method for confirming ownership, and also relates to a private network system, an ownership confirmation device, a computing device, a computer-readable storage medium, and a computer program, which will be described in detail in the following embodiments.

[0070] See Figure 1 , Figure 1This specification illustrates a structural topology diagram of a private network scenario provided by one embodiment.

[0071] like Figure 1 As shown, the private network scenario includes a private network cloud management platform and locally deployed private network equipment. The private network equipment includes user plane functions, wireless access networks, and mobile edge computing. Each private network device has a universal docking station, which enables data transmission via remote radio frequency units. The private network equipment also has a local cloud connection, connecting to the private network cloud management platform via a public Ethernet network for local / cloud connectivity. The cloud, i.e., the private network cloud management platform, enables cloud network management, primarily through access and mobility management functions, session management functions, unified data management functions, authentication server functions, and policy control functions. This is achieved through logical units such as centralized units, distributed units, and user plane functions. Furthermore, the private network equipment is deployed using mobile edge computing to achieve low-latency computing.

[0072] See Figure 2 , Figure 2 This specification illustrates a flowchart of an authorization method for a private network cloud management platform, based on an embodiment of this specification, which specifically includes the following steps:

[0073] Step 202: Obtain the identity identifier of the private network device and the application identifier of the target application, wherein the private network device is any network device in the private network scenario.

[0074] The private network cloud management platform is a cloud-based device management platform for private network scenarios. It has a transmission interface with the authorization center for data transmission. The platform manages private network devices, achieving centralized control over their permissions to target applications. A private network device is any network device within a private network scenario. Specifically, it includes hardware and / or logical devices, such as base stations, terminals, routers, and switches, and logical devices such as user plane functions, core networks, gateways, and virtual machines. The identity identifier is a unique identifier for the private network device across the entire network. For example, if the private network device is the first core network, its identity identifier is "CoreNetwork_1". The identity identifier is generated based on the device information. The target application is the application to be authorized and installed on the private network device, possessing at least one function. The private network device has a certain number of usable permissions for the target application. For example, if the target application has five functions, the private network device can use three of these five functions, with a usable size of three. The application identifier of the target application is a universal identifier for the target application across the entire network. For example, if the target application is ABC, its application identifier will be "ABC", "abc", etc. The application identifier is generated based on the application information of the target application.

[0075] To obtain the identity identifier of a private network device, specifically, one can receive the identity identifier of the private network device. Furthermore, one can receive the identity identifier of the private network device sent by the target application server, or one can receive the identity identifier of the private network device sent by the private network device itself.

[0076] For example, the private network device receives the private network device's identity identifier "Base_1 (base station number 1)" and the target application's application identifier "PowerCtrl (power regulation application)" sent by the private network device.

[0077] By obtaining the identity identifier of the private network device and the application identifier of the target application, a data foundation is laid for generating subsequent query requests.

[0078] Step 204: Generate a query request based on the identity identifier and application identifier.

[0079] The query request is a permission query request for the target application generated by the private network cloud management platform for the private network device, carrying the identity identifier of the private network device and the identity identifier of the target application.

[0080] A query request is generated based on the identity identifier and application identifier. Specifically, a pre-defined request generator is used to generate the query request based on the identity identifier and application identifier. This pre-defined request generator is a request generation function module pre-packaged on the private network cloud management platform, which can generate relevant function requests based on the identity identifier and application identifier. Examples include a string generation module.

[0081] For example, based on the identity identifier "Base_1 (Base Station No. 1)" and the application identifier "PowerCtrl (Power Ctrl Application)", a query request Request_1{Device: Base_1; Application: PowerCtrl} is generated using the preset request generator RequestBuilder.

[0082] Based on the identity identifier and application identifier, a query request is generated, which generates the transmission data between the private network cloud management platform and the authorization center. This provides a query index for the authorization center to determine the permissions of private network devices for the target application.

[0083] Step 206: Send the query request to the authorization center so that the authorization center can determine the private network device's permissions for the target application based on the identity identifier and application identifier, and generate query results.

[0084] The authorization center serves as the permission management server for the target application. It stores the permissions of each private network device for the target application within the private network scenario. The authorization center determines the permissions of each private network device for the target application based on the device's identity. The permissions of a private network device for the target application include the device's usage rights and / or the device's size / specification for the target application. The usage rights of a private network device indicate whether it has the necessary permissions, including whether it has permission or not. If it has permission, the authorization center generates query results including license / authorization information; if it does not have permission, it generates query results excluding license / authorization information. The size / specification of a private network device for the target application refers to the usable size / specification of the target application.

[0085] The query request is sent to the authorization center. Specifically, based on the application identifier of the target application, the corresponding authorization center for the target application is determined, and the query request is sent to the authorization center of the target application. Furthermore, the query request is sent to the authorization center using the transmission interface between the private network cloud management platform and the authorization center.

[0086] For example, based on the application identifier "PowerCtrl (Power Regulation Application)" of the target application, the corresponding power regulation application authorization center of the target application is determined, and the query request Request_1{Device: Base_1; Application: PowerCtrl} is sent to the power regulation application authorization center using the transmission interface between the private network cloud management platform and the authorization center.

[0087] The query request is sent to the authorization center, which then determines the private network device's permissions for the target application based on the identity identifier and application identifier, and generates query results. This avoids offline authorization confirmation and improves the efficiency of authorization confirmation.

[0088] Step 208: Receive the query results from the authorization center.

[0089] The query results are the permission query results of the private network devices for the target application generated by the authorization center. Specifically, the query results are received from the authorization center through the transmission interface between the private network cloud management platform and the authorization center.

[0090] For example, through the transmission interface between the private network cloud management platform and the authorization center, the query result ResulttoRequest_1{Permission(authorization information); Range(size): Function_1:Authorized(Function 1: Authorized); Function_2:Authorized(Function 2: Authorized); Function3:Unauthorized(Function 3: Unauthorized)} is received from the authorization center.

[0091] By receiving the query results from the authorization center, the foundation was laid for subsequently determining the permissions of private network devices for target applications.

[0092] Step 210: Based on the query results, determine the permissions of the private network device for the target application.

[0093] Based on the query results, the permissions of the private network devices for the target application are determined. Specifically, the query results are parsed to determine the permissions of the private network devices for the target application. Furthermore, a pre-defined parsing method is used to analyze the query results and determine the permissions of the private network devices for the target application. The parsing method is an information parsing module pre-packaged on the private network cloud management platform, which can parse the query results and extract the permissions. Examples include decryption modules and string analysis modules; the string analysis module includes regular expressions.

[0094] For example, using a preset parsing method, the query result ResulttoRequest_1{Permission(authorization information); Range(size): Function_1:Authorized(Function 1: Authorized); Function_2:Authorized(Function 2: Authorized); Function3:Unauthorized(Function 3: Unauthorized)} is parsed to determine that the private network device has the following permissions for the target application: "has permission, size: Function 1: has permission; Function 2: has permission; Function 3: unauthorized".

[0095] In the embodiments described in this specification, the identity identifier of the private network device and the application identifier of the target application are obtained. The private network device can be any network device in the private network scenario. Based on the identity identifier and application identifier, a query request is generated and sent to the authorization center. The authorization center determines the private network device's permissions to the target application based on the identity identifier and application identifier, generates query results, receives the query results from the authorization center, and determines the private network device's permissions to the target application based on the query results. This authorization method applied to the private network cloud management platform achieves centralized management of the private network device's permissions to the target application, ensuring the effectiveness of management and improving the security and stability of the private network device, the application on the private network device, and the entire private network scenario. By using the identity identifier and application identifier of the private network device to generate a query request and send it to the authorization center to obtain the query results, offline authorization is avoided, improving the efficiency of authorization.

[0096] Optionally, the private network scenario is a mobile communication private network scenario, and the private network equipment is a mobile communication network equipment.

[0097] A mobile communication private network scenario refers to a dedicated network scenario that utilizes mobile communication technology for communication between network devices. Mobile communication technologies include 4G (4th Generation Mobile Communication Technology), 5G, 6G, 7G, etc., and mobile communication network devices are hardware or logical devices that utilize mobile communication technology for communication. Hardware devices include base stations, terminals, routers, switches, etc. Logical devices include user plane functions, core network, gateways, virtual machines, etc.

[0098] Optionally, the private network scenario is a 5G private network scenario, and the private network equipment is a 5G network equipment.

[0099] A 5G private network scenario refers to a dedicated network environment that utilizes 5G communication technology for communication between network devices. 5G network devices are either 5G hardware devices or 5G logical devices that use 5G communication technology for communication. 5G hardware devices include 5G base stations, 5G terminals, 5G routers, and 5G switches. 5G logical devices include 5G user plane functions, 5G core network, 5G gateways, and 5G virtual machines.

[0100] In 5G private network scenarios, the number of network devices is rapidly increasing to enable extensive IoT data transmission, and the number of applications on these devices is also growing rapidly to achieve more functions. Utilizing the methods described in the embodiments above, centralized control over the permissions of 5G network devices to target applications is achieved more effectively, ensuring the effectiveness of control and improving the security and stability of 5G network devices, applications on 5G network devices, and the entire 5G private network scenario.

[0101] Optionally, step 202 includes the following specific steps:

[0102] Receive the identity identifier of the private network device sent by the target application server;

[0103] Determine the application identifier of the target application corresponding to the target application server;

[0104] Correspondingly, after step 210, the following specific steps are also included:

[0105] If the query results include license and authorization information, the query results will be sent to the target application server so that the target application server can grant the private network device permissions to the target application based on the license and authorization information.

[0106] The target application server serves as the management server for the target application in a private network scenario. The target application server communicates with the private network devices via an Application Programming Interface (API) for application management. Multiple management processes run on the target application server to manage the target application, including permission agent processes and configuration agent processes.

[0107] The license information pertains to the target application's usage license for authorized private network devices. This license information is pre-stored in the authorization center.

[0108] The system receives the identity identifier of the private network device sent by the target application server. Specifically, it receives the identity identifier of the private network device sent by the target application server through a permission agent process. The permission agent process is a process on the target application server that queries the private network device's permissions for the target application. The permission agent process is generated by the target application server after receiving a permission query request from the private network device. The permission agent process then sends the identity identifier of the private network device to the private network cloud management platform via an application programming interface (API).

[0109] The application identifier of the target application corresponding to the target application server is determined by determining the application identifier of the target application corresponding to the target application server based on the application programming interface.

[0110] For example, the application server receiving power regulation uses the identity identifier "Base_1 (Base Station No. 1)" of the private network device sent by the permission Agent process to determine the application identifier "PowerCtrl (Power Regulation Application)" of the power regulation application server corresponding to the power regulation application server according to the application programming interface. The query result is ResulttoRequest_1{Permission (authorization information); Range (size): Function_1:Authorized (Function 1: Authorized); Function_2:Authorized (Function 2: Authorized); Function3:Unauthorized (Function 3: Unauthorized)}, which includes permission information. The query result ResulttoRequest_1 is sent to the application server receiving power regulation so that the application server receiving power regulation can grant Base Station No. 1 permission for Function 1 and Function 2 in the power regulation application according to the permission information.

[0111] The system receives the identity identifier of the private network device from the target application server and determines the application identifier of the target application corresponding to the target application server. This lays the data foundation for subsequent query requests. Obtaining the identity identifier through the target application server further ensures the effectiveness of control and improves the security, stability, and control efficiency of the private network device, its applications, and the entire private network scenario. If the query result includes license and authorization information, the query result is sent to the target application server so that the target application server can grant the private network device permissions to the target application based on the license and authorization information. The feedback of the query result through the target application server further ensures the effectiveness of control and improves the security, stability, and control efficiency of the private network device, its applications, and the entire private network scenario.

[0112] Optionally, before sending the query results to the target application server, the following specific steps are also included:

[0113] The query results are encrypted using an identity identifier.

[0114] In private network scenarios, the cloud management platform needs to transmit data during interaction with other terminals, making it difficult to guarantee the security of query results. Once the query results are obtained by other users, unauthorized use or misuse of the application can occur, resulting in insufficient security in private network scenarios. Therefore, it is necessary to encrypt the query results.

[0115] The query results are encrypted using an identity identifier. Specifically, a preset encryption algorithm is used to encrypt the query results using the identity identifier. The preset encryption algorithm can be a symmetric encryption algorithm, such as parity checking, block cipher, or blockchain encryption, or an asymmetric encryption algorithm (public / key generation algorithm). For example, a key is generated based on the identity identifier, a public key is generated based on the query results, and the public key is subsequently used to decrypt the query results. No limitation is imposed here.

[0116] For example, a private key is generated based on the identity identifier "Base_1 (Base Station No. 1)", and a public key is generated based on the query result ResulttoRequest_1{Permission (authorization information); Range (size): Function_1:Authorized (Function 1: Authorized); Function_2:Authorized (Function 2: Authorized); Function3:Unauthorized (Function 3: Unauthorized)}, and the query result is encrypted.

[0117] By using identity identifiers to encrypt query results, the unauthorized resale and unauthorized use of applications are further prevented, thus improving the security of dedicated network scenarios.

[0118] Optionally, after step 210, the following specific steps are also included:

[0119] The authorization information of each private network device is displayed on the front end. The authorization information includes the permissions of the private network device for different applications.

[0120] The front-end is used to monitor private network devices in a private network scenario. A transmission interface is established between the front-end and the private network management platform for data transmission. The front-end includes a visualization front-end device. This visualization front-end device is a display device on the front-end that shows information about each private network device and its authorization information.

[0121] By monitoring the authorization information of each private network device through front-end display, centralized management of application permissions for each device is ensured. Specifically, the authorization information of each private network device is displayed on a visual front-end device.

[0122] For example, on the visualization front-end display device of the cloud management and control platform, the authorization information of each private network device (Base Station 1, Base Station 2, Terminal 1, Terminal 2, Core Network, Gateway 1, Gateway 2) is displayed on the front end: {Base Station 1 (Application 1: Authorized; Application 2: Authorized; Application 3: Not Authorized); Base Station 2 (Application 1: Authorized; Application 2: Not Authorized; Application 3: Authorized); Terminal 1 (Application 4: Not Authorized; Application 5: Authorized; Application 6: Not Authorized), Terminal 2 (Application 4: Not Authorized; Application 5: Authorized; Application 6: Not Authorized), Core Network (Application 7: Authorized; Application 8: Authorized), Gateway 1 (Application 9: Authorized; Application 10: Authorized; Application 11: Authorized), Gateway 2 (Application 9: Authorized; Application 10: Authorized; Application 11: Authorized)}.

[0123] The authorization information of each private network device, including its permissions for different applications, is displayed on the front end. This centralized management of permissions for each private network device enables the visual display of authorization information, ensuring the effectiveness of the management system.

[0124] Optionally, after displaying the authorization information of each private network device on the front end, the following specific steps are also included:

[0125] Receive permission update requests entered by the user on the front end;

[0126] The permission update request is forwarded to the authorization center so that the authorization center can update the permissions of the private network device for the target application according to the permission update request;

[0127] Receive permission update messages from the authorization center; determine the private network device's update permissions for the target application based on the permission update messages.

[0128] A permission update request is a request to update the permissions of a target application on a private network device, as input by the user through the front end. It includes: the identity identifier of the private network device, the application identifier of the target application, the renewal authorization period of the license, and the update permissions granted to the private network device for the target application. A permission update message is a message that updates the permissions of a target application on a private network device. It includes: the identity identifier of the private network device, the application identifier of the target application, the renewal authorization period of the license, and the update permissions granted to the private network device for the target application.

[0129] The permission update request is forwarded to the authorization center. Specifically, the permission update request is forwarded to the authorization center through the transmission interface.

[0130] The permission update message received from the authorization center is generated by the authorization center after receiving the permission update request from the front end forwarded by the control center.

[0131] The system receives permission update messages from the authorization center via a transmission interface. Based on these messages, it determines the private network device's update permissions for the target application. This is achieved by parsing the permission update messages. Furthermore, a pre-defined parsing method is used to analyze the permission update messages and determine the updated permissions for the target application. This parsing method is a pre-packaged information parsing module on the private network cloud management platform, capable of parsing permission update messages and extracting the update permissions. Examples include a string analysis module, which includes regular expressions.

[0132] For example, the private network device is Terminal 2, the target application is a message publishing application, and the authorization information displayed on the front end is the authorization information of Terminal 2: {Terminal 2 (Type 1 message publishing application: has permission; Type 2 message publishing application: has permission; Type 3 message publishing application: does not have permission)}. It receives the permission update request (Update_Request) input by the user on the front end, forwards it to the authorization center via the transmission interface, updates the private network device's permissions for the message publishing application based on the Update_Request, receives the permission update message (Update_Inform) from the authorization center, parses the UpdateInform message using regular expressions, and determines the private network device's update permissions for the target application: Terminal 2 (Type 1 message publishing application: has permission; Type 2 message publishing application: has permission; Type 3 message publishing application: has permission).

[0133] The system receives permission update requests input by the user on the front end, forwards these requests to the authorization center, and enables the authorization center to update the permissions of the private network device for the target application based on the request. It also receives permission update messages from the authorization center and determines the updated permissions of the private network device for the target application based on these messages. This ensures the timeliness and effectiveness of control and further improves the stability of the private network scenario.

[0134] Optionally, the query results may include the license duration.

[0135] Correspondingly, after step 210, the following specific steps are also included:

[0136] If the preset overdue conditions are determined based on the authorization period, a warning message will be generated.

[0137] A warning message is sent to the target user terminal to notify it to request the authorization center to update the private network device's permissions for the target application.

[0138] Currently, the management of license expiration dates is achieved through offline consoles or by directly managing the expiration dates of private network devices. This has led to situations where licenses expire and the target users are not notified in a timely manner.

[0139] For the license authorization period, for example, for private network equipment: the license authorization of Terminal 2 for Application 4 is valid from December 1, 2020 to December 1, 2022.

[0140] The preset expiration condition is a pre-set condition for determining expiration. For example, the preset expiration condition is 7 days remaining until the license authorization period expires. For an authorization period from December 1, 2020 to December 1, 2022, and the current time is November 25, 2022, the preset expiration condition is met, meaning there are 7 days left until the license authorization period expires. The warning message is an expiration warning message for the target user corresponding to the private network device. It includes the identity identifier of the private network device, the application identifier of the target application, the license authorization period, and a notification message confirming that the authorization period has reached the preset expiration condition. It can be a text message, a voice call, or a notification message from the target application management software installed on the target user's terminal, etc., and is not limited here. The target user terminal is the terminal device of the target user corresponding to the private network device. The authorization center provides a corresponding interface, allowing users to perform permission update operations through the target user terminal. The warning message can be sent once or multiple times. For repeated transmissions, this includes stopping repeated transmissions after confirming that the target user has been notified, retransmitting without confirming that the target user has been notified, retransmitting at a preset transmission frequency, and stopping repeated transmissions after receiving feedback from the target user's terminal. No further limitations are specified here.

[0141] If the preset overdue conditions are determined based on the authorization period, a warning message is generated. Specifically, if the preset overdue conditions are determined based on the authorization period, a warning message is generated based on the identity of the private network device, the application identifier of the target application, and the authorization period of the license.

[0142] For example, the preset expiration condition is 10 days remaining before the license authorization period expires. The current time is November 30, 2020. If the preset expiration condition is determined to be met within the authorization period (December 1, 2020 to December 1, 2022), a telephone voice message is generated based on the private network device's identity identifier "Terminal_2 (Second Terminal)", the target application's application identifier "MessageRelease (Message Publishing Application)", and the license authorization period (December 1, 2020 to December 1, 2022): "Hello, your Message Publishing Application license on Terminal 2 will expire on December 1, 2022. Please request the authorization center of the Message Publishing Application to update the permissions of Terminal 2 for the Message Publishing Application in a timely manner."

[0143] If the preset expiration conditions are met based on the authorization period, a warning message is generated and sent to the target user's terminal. This notifies the target user's terminal to request the authorization center to update the private network device's permissions for the target application. This timely reminder to the target user to update the license avoids the need for offline verification of license expiration, improving management efficiency and enhancing the user experience.

[0144] Optionally, the method further includes the following specific steps:

[0145] Receive permission update messages from the authorization center;

[0146] Based on the permission update message, determine the private network device's update permissions for the target application.

[0147] Permission update messages are messages that update the permissions of private network devices for target applications. They include: the identity identifier of the private network device, the application identifier of the target application, the updated license period, and the updated permissions granted to the private network device for the target application.

[0148] The permission update message received from the authorization center is generated by the authorization center after receiving the permission update request from the target user terminal. The permission update request can be generated and sent to the authorization center by the target user terminal after the warning message is sent to the target user terminal, or it can be actively generated and sent to the authorization center by the target user terminal.

[0149] Based on the permission update message, the update permissions of the private network device for the target application are determined. Specifically, the permission update message is parsed to determine the update permissions of the private network device for the target application. Furthermore, a preset parsing method is used to parse the permission update message to determine the update permissions of the private network device for the target application. The parsing method is an information parsing module pre-encapsulated in the private network cloud management platform, which can parse the permission update message and extract the update permissions. For example, a string analysis module, including regular expressions, can be used.

[0150] For example, the private network device is a second terminal, the target application is a message publishing application, receives the permission update message from the authorization center, uses regular expressions to parse the permission update message UpdateInform, and determines the private network device's update permission for the target application: it has the permission.

[0151] The system receives permission update messages from the authorization center and determines the update permissions of the private network devices for the target application based on these messages. This ensures the timeliness and effectiveness of control and further enhances the stability of the private network scenario.

[0152] See Figure 3 , Figure 3 This specification illustrates a flowchart of an authorization method for an application server according to an embodiment, which specifically includes the following steps:

[0153] Step 302: Receive the permission verification request for the target application sent by the private network device, wherein the private network device is any network device in the private network scenario, and the permission verification request carries the device information of the private network device.

[0154] The application server serves as the management server for any of the different applications on the private network device within a private network scenario. The application server and the private network device communicate via an Application Programming Interface (API) for application management. Multiple management processes run on the application server to manage the applications, including permission agent processes and configuration agent processes.

[0155] The permission verification request is a permission query request for the target application generated by the private network device. This request is sent by the private network device after invoking the licensing SDK (Software Development Kit). The device information of the private network device is its fingerprint information, i.e., unchangeable information set by the device manufacturer, such as the MAC address (Media Access Control Address), Permanent Equipment Identifier (PEI), Subscription Permanent Identifier (SUPI), Subscriber Identity Module (SIM), etc., which are not limited here.

[0156] The system receives permission verification requests for the target application sent by the private network device. Specifically, it receives these requests by invoking the licensed software development kit (SDK). Furthermore, it receives these permission verification requests via an application programming interface (API).

[0157] For example, the private network device is a user plane function, the target application is a mobile edge computing application, and it receives the permission verification request Request_1-1{Device:UOF;Application:MEC} sent by the user plane function by calling the licensed software development kit for the mobile edge computing application.

[0158] By receiving permission verification requests for target applications sent by private network devices, which carry device information of the private network devices, an information foundation is laid for the subsequent generation of the private network device's identity.

[0159] Step 304: Generate the identity identifier of the private network device based on the device information.

[0160] Based on device information, an identity identifier for the private network device is generated. Specifically, a preset identifier generation algorithm is used to generate the identifier for the private network device based on the device information. The preset identifier generation algorithm is an identifier generation function module pre-packaged on the application server, which can generate a unique identifier based on the device information. Examples include encryption modules and string generation modules. For instance, if the permanent device identifier for the user plane function is "XXXX", the preset identifier generation algorithm will generate the identity identifier "U-113 (User Plane Function)" for the private network device based on the permanent device identifier "XXXX".

[0161] Based on the device information, an identity identifier for the private network device is generated, which improves the accuracy and efficiency of the rights confirmation process.

[0162] Step 306: Send the identity identifier to the private network cloud management platform.

[0163] The identity identifier is sent to the private network cloud management platform. Specifically, this is done through the authorization agent process. For example, the identity identifier "U-113 (User Plane Function)" is sent to the private network cloud management platform through the authorization agent process.

[0164] Sending the identity identifier to the private network cloud management platform provides a data foundation for receiving query results from the platform later.

[0165] Step 308: Receive the query results from the private network cloud management platform. The query results are obtained by the private network cloud management platform from the authorization center based on the identity identifier and the application identifier of the target application. The query results represent the permissions of the private network device for the target application.

[0166] Step 310: Based on the query results, determine the permissions of the private network device for the target application.

[0167] Based on the query results, the permissions of the private network device for the target application are determined. Specifically, the query results are parsed to determine the permissions of the private network device for the target application. Furthermore, a preset parsing method is used to parse the query results and determine the permissions of the private network device for the target application. The parsing method is an information parsing module pre-packaged on the application server, which can parse the query results and extract the permissions. Examples include decryption modules and string analysis modules; the string analysis module includes regular expressions.

[0168] For example, using a preset parsing method, the query result ResulttoRequest_1-1{Permission(authorization information); Range(size): Function_7:Authorized(Function 7: No permission); Function_8:Authorized(Function 8: Permission)} is parsed to determine that the private network device has permission for the target application, with the size being: Function 7: No permission; Function 8: Permission.

[0169] In the embodiments of this specification, a permission verification request for a target application is received from a private network device. The private network device can be any network device in the private network scenario. The permission verification request carries the device information of the private network device. Based on the device information, an identity identifier of the private network device is generated and sent to the private network cloud management platform. The platform then receives the query results from the private network cloud management platform. These query results are obtained from the authorization center by the platform based on the identity identifier and the application identifier of the target application. The query results represent the permissions of the private network device for the target application. Based on the query results, the permissions of the private network device for the target application are determined. This permission confirmation method applied to application servers enables the private network cloud management platform to obtain the identity identifier of the private network device and the application identifier of the target application, achieving centralized management of the permissions of the private network device for the target application. This ensures the effectiveness of management and improves the security and stability of the private network device, the application on the private network device, and the entire private network scenario. By using the identity identifier and application identifier of the private network device, the platform can obtain the query results and perform permission confirmation upon receiving them, avoiding offline permission confirmation and improving the efficiency of permission confirmation.

[0170] Optionally, step 310 includes the following specific steps: using the identity identifier to decrypt the query results to obtain authorization information; and granting the private network device permissions to the target application based on the authorization information.

[0171] In private network scenarios, data transmission is required during the interaction between application servers and other terminals, making it difficult to guarantee the security of query results. Once the query results are obtained by other users, unauthorized use or misuse of the application can occur, resulting in insufficient security in private network scenarios. Therefore, it is necessary to encrypt the query results on the private network cloud management platform and decrypt them on the application server.

[0172] The license information pertains to the target application's usage license for authorized private network devices. This license information is pre-stored in the authorization center.

[0173] The query results are decrypted using an identity identifier. Specifically, a preset decryption algorithm is used to decrypt the query results using the identity identifier. The preset decryption algorithm can be a symmetric algorithm, such as parity checking, block cipher, or blockchain encryption, or an asymmetric algorithm (public-key / private-key decryption algorithm), such as decrypting the public key generated from the query results using a key generated from the identity identifier. No limitation is imposed here.

[0174] For example, the PrivateKey generated based on the identity identifier "U-113 (User Plane Function)" is used to decrypt the encrypted query result using the public key PublicKey generated based on the query result ResulttoRequest_1-1{Permission(Authorization Information); Range(Size): Function_7:Authorized(Function 7: No Permission); Function_8:Authorized(Function 8: Permission)}. This results in the authorization information {Authorization Information; Size: Function 7: No Permission; Function 8: Permission}. Based on this authorization information, the User Plane Function is granted permission for Function 8 in the mobile edge computing application.

[0175] Upon receiving the encrypted query results, the system decrypts the results using the identity identifier to obtain authorization information. Based on this authorization information, it grants the private network device permissions to the target application. This further prevents unauthorized repurposing and unauthorized use of applications, thus enhancing the security of private network scenarios.

[0176] Optionally, the method further includes the following specific steps: if the query result does not contain license authorization information, then the permission verification is determined to have failed; or, if the license authorization information obtained through decryption does not match the permission verification request, then the permission verification is determined to have failed.

[0177] The permission verification request also includes the target function information of the application requesting verification, and the license authorization information includes the authorization information for the target function. After decryption, the target function information in the permission verification request needs to be matched with the authorization information for the target function in the license authorization information to determine whether the user has the necessary permissions for the target function.

[0178] For example, the permission verification request also includes the target function information "Function 7" of the target application to be verified. The target function information "Function 7" in the permission verification request is matched with the authorization information "Function 7: No permission" of the target function in the license authorization information. If they do not match, the permission verification is determined to have failed.

[0179] If the query results do not contain license / authorization information, the permission verification is deemed to have failed. Alternatively, if the license / authorization information obtained through decryption does not match the permission verification request, the permission verification is deemed to have failed. This allows for timely confirmation of permissions, improving management efficiency and feedback effectiveness, and enhancing the user experience.

[0180] Optionally, after determining that the permission verification failed, the following specific steps are also included: sending a permission verification failure message to the target user terminal. The specific method for sending the permission verification failure message to the target user terminal can be SMS, telephone voice, or a notification message from the target application management software installed on the target user terminal, etc., and is not limited here.

[0181] See Figure 4 , Figure 4 This specification illustrates a flowchart of an authorization method for a smart application applied to a private network cloud management platform, according to an embodiment of this specification. The method specifically includes the following steps:

[0182] Step 402: Obtain the identity identifier of the smart park device and the application identifier of the smart application, wherein the smart park device is any smart terminal device in the smart park;

[0183] Step 404: Generate a query request based on the identity identifier and application identifier;

[0184] Step 406: Send the query request to the authorization center of the smart application so that the authorization center can determine the smart park device's permissions for the smart application based on the identity identifier and application identifier, and generate query results;

[0185] Step 408: Receive the query results from the authorization center;

[0186] Step 410: Based on the query results, determine the permissions of smart park devices for smart applications.

[0187] A smart park is a specific area where an Internet of Things (IoT) system is deployed. A smart park device is any IoT device within the smart park; specifically, it refers to hardware devices such as autonomous vehicles, smart home devices, and smart infrastructure equipment. A smart application is an application installed on a smart park device and awaiting authorization; the smart application possesses at least one IoT function. The smart park device has the appropriate size and permissions to use the smart application.

[0188] The specific implementation methods of steps 402-410 are the same as those of steps 202-210, and will not be repeated here.

[0189] The authorization method for the private network cloud management and control platform applied to smart parks in the embodiments of this specification realizes centralized management and control of the permissions of smart park devices to smart applications, ensuring the effectiveness of management and control, and improving the security and stability of smart park devices, smart applications on smart park devices, and the entire smart park. By using the identity identifier and application identifier of smart park devices, a query request is generated and sent to the authorization center to obtain the query result, avoiding offline authorization and improving the efficiency of authorization.

[0190] The following is in conjunction with the appendix Figure 5 Taking the application of the rights confirmation method provided in this specification in a 5G smart park private network cloud management platform as an example, the rights confirmation method will be further explained. Figure 5 This specification illustrates a flowchart of a rights confirmation method for a 5G private network cloud management platform, provided by an embodiment of this specification, which specifically includes the following steps.

[0191] Step 502: Receive the identity identifier of the 5G smart park device sent by the smart application server through the permission agent process;

[0192] The embodiments in this manual are applied to a 5G smart park private network cloud management and control platform;

[0193] Step 504: Determine the application identifier of the smart application corresponding to the smart application server based on the application programming interface;

[0194] Step 506: Generate a query request based on the identity identifier and application identifier;

[0195] Step 508: Send the query request to the authorization center through the data interface;

[0196] The data interface is a pre-set data transmission interface between the 5G smart park private network cloud management and control platform and the authorization center. The authorization center determines the permissions of the private network devices for smart applications based on the identity identifier and application identifier, and generates query results.

[0197] Step 510: Receive the query results from the authorization center via the data interface;

[0198] Step 512: Based on the query results, determine the permissions of the private network equipment for smart applications;

[0199] Step 514: If the query results include license and authorization information, display the authorization information of each 5G smart park device on the front end;

[0200] The smart application server grants 5G smart park devices access to smart applications based on the license authorization information.

[0201] Step 516: If the preset overdue conditions are determined according to the authorization period, a warning message is generated and sent to the target user terminal;

[0202] The search results include the license duration.

[0203] Step 518: Receive the permission update message from the authorization center, and determine the update permissions of the 5G smart park equipment for smart applications based on the permission update message;

[0204] Step 520: Encrypt the query results using a preset encryption algorithm and identity identifier;

[0205] Step 522: Send the encrypted query results to the smart application server.

[0206] The authorization method described in this specification, applied to the 5G smart park private network cloud management platform, achieves centralized control over the permissions of 5G smart park devices for smart applications. This ensures the effectiveness of control and improves the security and stability of 5G smart park devices, applications on those devices, and the entire 5G smart park private network scenario. By using the identity identifier and application identifier of the 5G smart park device to generate a query request and send it to the authorization center to obtain the query results, offline authorization is avoided, improving efficiency. Combined with encryption of the identity identifier, unauthorized misuse and unauthorized use of smart applications are further prevented, enhancing the security of the 5G smart park private network scenario. Timely reminders to target users to update their licenses eliminate the need for offline confirmation of expired licenses, improving management efficiency and user experience.

[0207] Figure 6A system block diagram of a private network system according to one embodiment of this specification is shown. Figure 6 As shown, the private network system includes a private network cloud management platform, an authorization center, and network equipment. The network equipment includes private network devices, user plane functions, core network, base stations, etc. Any one of these network devices is considered a private network device. The private network device carries the target application, and permission verification for the target application is achieved through a permission agent process. The private network cloud management platform is equipped with a permission management service module, a short message notification module, and front-end devices. The permission management service module receives the sent identity identifier and application identifier, generates a query request, and sends it to the authorization center. It receives the query results from the authorization center, obtains the authorization information and the authorization period based on the query results, and sends it to the permission agent process. The authorization information is encrypted. The module also obtains the functionality and specifications based on the query results and sends them to the target application on the private network device, again with encrypted functionality and specifications. The permission management module sends the authorization information to the front-end devices for display. When the authorization period reaches a preset limit, the short message notification module sends a short message to the target user terminal. The target user terminal then sends a permission update message to the authorization center to update its permissions. The short message notification module stops sending short messages after confirming that the target user terminal has sent a permission update message.

[0208] Figure 7 This specification illustrates a data processing flow diagram for a private network scenario based on one embodiment. For example... Figure 7 As shown, in a private network scenario, the Permission Agent process receives a permission verification request, then generates an identity identifier based on the device information in the permission verification request, and then sends the identity identifier and application identifier to the private network cloud management platform. Finally, it receives the authorization information fed back by the private network cloud management platform.

[0209] Figure 8 This specification illustrates a data processing flow diagram in an application server within a private network scenario, based on one embodiment of this specification. For example... Figure 8 As shown, in the application server of the private network scenario, for application 1 and / or application 2 on the private network device, the software development kit is used to send an authorization verification request to the authorization agent process. After determining the permissions of the private network device for application 1 and / or application 2, the authorization agent process sends feedback to the software development kit to authorize application 1 and application 2 on the private network device.

[0210] Corresponding to the above method embodiments, this specification also provides embodiments of a private network system. Figure 9A A schematic diagram of a private network system according to one embodiment of this specification is shown. Figure 9A As shown:

[0211] The private network cloud management platform 902 is configured to obtain the identity identifier of the private network device and the application identifier of the target application, wherein the private network device can be any network device; based on the identity identifier and application identifier, it generates a query request and sends the query request to the authorization center;

[0212] Authorization Center 904 is configured to receive query requests, determine the permissions of private network devices for the target application based on the identity identifier and application identifier, generate query results, and feed the query results back to the private network cloud management platform;

[0213] The private network cloud management platform 902 is also configured to receive query results from the authorization center and determine the permissions of private network devices for target applications based on the query results.

[0214] In the embodiments described in this specification, the identity identifier of the private network device and the application identifier of the target application are obtained. The private network device can be any network device in the private network scenario. Based on the identity identifier and application identifier, a query request is generated and sent to the authorization center. The authorization center determines the private network device's permissions to the target application based on the identity identifier and application identifier, generates query results, receives the query results from the authorization center, and determines the private network device's permissions to the target application based on the query results. This authorization method applied to the cloud management platform achieves centralized control over the permissions of private network devices to target applications, ensuring the effectiveness of control and improving the security and stability of the private network device, the applications on the private network device, and the entire private network scenario. By using the identity identifier and application identifier of the private network device to generate a query request and send it to the authorization center to obtain query results, offline authorization is avoided, improving the efficiency of authorization.

[0215] Figure 9B A schematic diagram of another private network system provided in one embodiment of this specification is shown. For example... Figure 9B As shown: Optionally, the private network system also includes an application server 906;

[0216] Application server 906 is configured to receive permission verification requests for target applications sent by private network devices, wherein the permission verification requests carry device information of the private network devices; generate an identity identifier for the private network devices based on the device information; and send the identity identifier to the private network cloud management platform.

[0217] The private network cloud management platform 902 is also configured to send the query results back to the application server;

[0218] Application server 906 is also configured to receive query results from the private network cloud management platform and determine the permissions of the private network devices for the target application based on the query results.

[0219] In the embodiments of this specification, a permission verification request for a target application is received from a private network device. The private network device can be any network device in the private network scenario. The permission verification request carries the device information of the private network device. Based on the device information, an identity identifier of the private network device is generated and sent to the private network cloud management platform. The platform then receives the query results from the private network cloud management platform. These query results are obtained from the authorization center by the platform based on the identity identifier and the application identifier of the target application. The query results represent the permissions of the private network device for the target application. Based on the query results, the permissions of the private network device for the target application are determined. This permission confirmation method applied to application servers enables the private network cloud management platform to obtain the identity identifier of the private network device and the application identifier of the target application, achieving centralized management of the permissions of the private network device for the target application. This ensures the effectiveness of management and improves the security and stability of the private network device, the application on the private network device, and the entire private network scenario. By using the identity identifier and application identifier of the private network device, the platform can obtain the query results and perform permission confirmation upon receiving them, avoiding offline permission confirmation and improving the efficiency of permission confirmation.

[0220] The above is an illustrative scheme of a private network system according to this embodiment. It should be noted that the technical solution of this private network system and the technical solution of the above-described rights confirmation method belong to the same concept. For details not described in detail in the technical solution of the private network system, please refer to the description of the technical solution of the above-described rights confirmation method.

[0221] Corresponding to the above method embodiments, this specification also provides embodiments of the rights confirmation device. Figure 10 This specification illustrates a schematic diagram of an authorization device applied to a private network cloud management platform, according to one embodiment of this specification. Figure 10 As shown, the device includes:

[0222] The first acquisition module 1002 is configured to acquire the identity identifier of the private network device and the application identifier of the target application, wherein the private network device is any network device in the private network scenario;

[0223] The first generation module 1004 is configured to generate a query request based on the identity identifier and the application identifier;

[0224] The first sending module 1006 is configured to send a query request to the authorization center, so that the authorization center can determine the private network device's permissions for the target application based on the identity identifier and application identifier, and generate query results;

[0225] The first receiving module 1008 is configured to receive the query results fed back by the authorization center;

[0226] The first determination module 1010 is configured to determine the permissions of the private network device for the target application based on the query results.

[0227] Optionally, the private network scenario is a mobile communication private network scenario, and the private network equipment is a mobile communication network equipment.

[0228] Optionally, the first acquisition module 1002 is further configured to: receive the identity identifier of the private network device sent by the target application server; determine the application identifier of the target application corresponding to the target application server; correspondingly, the device further includes: a third sending module, configured to send the query result to the target application server when the query result includes license authorization information, so that the target application server authorizes the private network device to access the target application according to the license authorization information.

[0229] Optionally, the device further includes a display module configured to display the authorization information of each private network device on the front end, wherein the authorization information includes the permissions of the private network device for different applications.

[0230] Optionally, the device further includes: a first update module, configured to receive a permission update request input by a user at the front end; forward the permission update request to an authorization center so that the authorization center updates the permissions of the private network device for the target application according to the permission update request; receive a permission update message from the authorization center; and determine the update permissions of the private network device for the target application according to the permission update message.

[0231] Optionally, the query results include the license authorization period; correspondingly, the device further includes: a warning module, configured to generate a warning message when a preset overdue condition is determined based on the authorization period; and send the warning message to the target user terminal to notify the target user terminal to request the authorization center to update the private network device's permissions for the target application.

[0232] Optionally, the device further includes: a second update module configured to receive permission update messages from the authorization center; and to determine the private network device's update permissions for the target application based on the permission update messages.

[0233] In the embodiments described in this specification, the identity identifier of the private network device and the application identifier of the target application are obtained. The private network device can be any network device in the private network scenario. Based on the identity identifier and application identifier, a query request is generated and sent to the authorization center. The authorization center determines the private network device's permissions to the target application based on the identity identifier and application identifier, generates query results, receives the query results from the authorization center, and determines the private network device's permissions to the target application based on the query results. This authorization method applied to the private network cloud management platform achieves centralized management of the private network device's permissions to the target application, ensuring the effectiveness of management and improving the security and stability of the private network device, the application on the private network device, and the entire private network scenario. By using the identity identifier and application identifier of the private network device to generate a query request and send it to the authorization center to obtain the query results, offline authorization is avoided, improving the efficiency of authorization.

[0234] The above is a schematic scheme of a rights confirmation device according to this embodiment. It should be noted that the technical solution of this rights confirmation device and the technical solution of the rights confirmation method described above belong to the same concept. For details not described in detail in the technical solution of the rights confirmation device, please refer to the description of the technical solution of the rights confirmation method described above.

[0235] Corresponding to the above method embodiments, this specification also provides embodiments of the rights confirmation device. Figure 11 This specification illustrates a schematic diagram of a device for determining the authority of an application server, according to one embodiment of this specification. Figure 11 As shown, the device includes:

[0236] The second receiving module 1102 is configured to receive an authorization verification request for a target application sent by a private network device, wherein the private network device is any network device in the private network scenario, and the authorization verification request carries the device information of the private network device.

[0237] The second generation module 1104 is configured to generate the identity identifier of the private network device based on the device information;

[0238] The second sending module 1106 is configured to send the identity identifier to the private network cloud management platform;

[0239] The third receiving module 1108 is configured to receive the query results fed back by the private network cloud management platform. The query results are obtained by the private network cloud management platform from the authorization center based on the identity identifier and the application identifier of the target application. The query results represent the permissions of the private network device to the target application.

[0240] The second determination module 1110 is configured to determine the permissions of the private network device for the target application based on the query results.

[0241] Optionally, the second determining module 1110 is further configured to: use the identity identifier to decrypt the query results to obtain permission authorization information; and grant the private network device permission to the target application based on the permission authorization information.

[0242] Optionally, the device further includes a third determining module, configured to determine that the permission verification failed if the query result does not contain permission information; or, determine that the permission verification failed if the decrypted permission information does not match the permission verification request.

[0243] In the embodiments of this specification, a permission verification request for a target application is received from a private network device. The private network device can be any network device in the private network scenario. The permission verification request carries the device information of the private network device. Based on the device information, an identity identifier of the private network device is generated and sent to the private network cloud management platform. The platform then receives the query results from the private network cloud management platform. These query results are obtained from the authorization center by the platform based on the identity identifier and the application identifier of the target application. The query results represent the permissions of the private network device for the target application. Based on the query results, the permissions of the private network device for the target application are determined. This permission confirmation method applied to application servers enables the private network cloud management platform to obtain the identity identifier of the private network device and the application identifier of the target application, achieving centralized management of the permissions of the private network device for the target application. This ensures the effectiveness of management and improves the security and stability of the private network device, the application on the private network device, and the entire private network scenario. By using the identity identifier and application identifier of the private network device, the platform can obtain the query results and perform permission confirmation upon receiving them, avoiding offline permission confirmation and improving the efficiency of permission confirmation.

[0244] The above is a schematic scheme of a rights confirmation device according to this embodiment. It should be noted that the technical solution of this rights confirmation device and the technical solution of the rights confirmation method described above belong to the same concept. For details not described in detail in the technical solution of the rights confirmation device, please refer to the description of the technical solution of the rights confirmation method described above.

[0245] Figure 12A structural block diagram of a computing device 1200 according to one embodiment of this specification is shown. Components of the computing device 1200 include, but are not limited to, a memory 1210 and a processor 1220. The processor 1220 is connected to the memory 1210 via a bus 1230, and a database 1250 is used to store data. The computing device 1200 also includes an access device 1240, which enables the computing device 1200 to communicate via one or more networks 1260. Examples of these networks include a Public Switched Telephone Network (PSTN), a Local Area Network (LAN), a Wide Area Network (WAN), a Personal Area Network (PAN), or a combination of communication networks such as the Internet. Access device 1240 may include one or more of any type of wired or wireless network interface (e.g., a network interface card (NIC)), such as an IEEE 802.12 Wireless Local Area Networks (WLAN) interface, a Wi-MAX (World Interoperability for Microwave Access) interface, an Ethernet interface, a Universal Serial Bus (USB) interface, a cellular network interface, a Bluetooth interface, a Near Field Communication (NFC) interface, and so on.

[0246] In one embodiment of this specification, the aforementioned components of the computing device 1200 and Figure 12 Other components, not shown, can also be connected to each other, for example, via a bus. It should be understood that... Figure 12The illustrated block diagram of the computing device is for illustrative purposes only and is not intended to limit the scope of this specification. Those skilled in the art can add or replace other components as needed. The computing device 1200 can be any type of stationary or mobile computing device, including mobile computers or mobile computing devices (e.g., tablet computers, personal digital assistants, laptop computers, notebook computers, netbooks, etc.), mobile phones (e.g., smartphones), wearable computing devices (e.g., smartwatches, smart glasses, etc.) or other types of mobile devices, or stationary computing devices such as desktop computers or PCs (Personal Computers). The computing device 1200 can also be a mobile or stationary server. The processor 1220 is configured to execute computer-executable instructions that, when executed by the processor, implement the steps of the aforementioned rights confirmation method or the rights confirmation method of the smart application.

[0247] The above is an illustrative scheme of a computing device according to this embodiment. It should be noted that the technical solution of this computing device belongs to the same concept as the technical solutions of the above-mentioned rights confirmation method and the rights confirmation method of smart applications. For details not described in detail in the technical solution of the computing device, please refer to the description of the technical solutions of the above-mentioned rights confirmation method or the rights confirmation method of smart applications.

[0248] An embodiment of this specification also provides a computer-readable storage medium storing computer-executable instructions that, when executed by a processor, implement the steps of the above-described rights confirmation method or the rights confirmation method of a smart application.

[0249] The above is an illustrative scheme of a computer-readable storage medium according to this embodiment. It should be noted that the technical solution of this storage medium belongs to the same concept as the technical solutions of the above-described rights confirmation method and the rights confirmation method of smart applications. For details not described in detail in the technical solution of the storage medium, please refer to the description of the technical solutions of the above-described rights confirmation method or the rights confirmation method of smart applications.

[0250] An embodiment of this specification also provides a computer program, wherein when the computer program is executed in a computer, it causes the computer to perform the steps of the above-described rights confirmation method or the rights confirmation method of a smart application.

[0251] The above is an illustrative scheme of a computer program according to this embodiment. It should be noted that the technical solution of this computer program belongs to the same concept as the technical solutions of the above-described rights confirmation method and the rights confirmation method of smart applications. For details not described in detail in the technical solution of the computer program, please refer to the description of the technical solutions of the above-described rights confirmation method or the rights confirmation method of smart applications.

[0252] The foregoing has described specific embodiments of this specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recited in the claims may be performed in a different order than that shown in the embodiments and may still achieve the desired result. Furthermore, the processes depicted in the drawings do not necessarily require the specific or sequential order shown to achieve the desired result. In some embodiments, multitasking and parallel processing are possible or may be advantageous.

[0253] The computer instructions include computer program code, which may be in the form of source code, object code, executable file, or some intermediate form. The computer-readable medium may include any entity or device capable of carrying the computer program code, recording media, USB flash drive, portable hard drive, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signals, telecommunication signals, and software distribution media, etc. It should be noted that, for the foregoing method embodiments, for the sake of simplicity, they are all described as a series of actions. However, those skilled in the art should understand that the embodiments in this specification are not limited to the described order of actions, because according to the embodiments in this specification, some steps may be performed in other orders or simultaneously. Furthermore, those skilled in the art should also understand that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the embodiments in this specification. In the above embodiments, the descriptions of each embodiment have different focuses; parts not described in detail in a certain embodiment can be referred to the relevant descriptions of other embodiments.

[0254] The preferred embodiments disclosed above are merely illustrative of this specification. The optional embodiments do not exhaustively describe all details, nor do they limit the invention to the specific implementations described. Clearly, many modifications and variations can be made based on the embodiments described herein. These embodiments are selected and specifically described in this specification to better explain the principles and practical applications of the embodiments, thereby enabling those skilled in the art to better understand and utilize this specification. This specification is limited only by the claims and their full scope and equivalents.

Claims

1. A method for confirming ownership, applied to a private network cloud management and control platform, the method comprising: Receive permission update requests entered by the user on the front end; The permission update request is forwarded to the authorization center so that the authorization center can update the permissions of the private network device for the target application according to the permission update request, wherein the private network device is any network device in the private network scenario; Receive permission update messages from the authorization center; Based on the permission update message, the update permission of the private network device for the target application is determined, wherein the private network cloud management platform manages the private network device to achieve centralized management of the private network device's permission for the target application.

2. The method according to claim 1, wherein the private network scenario is a mobile communication private network scenario, and the private network equipment is a mobile communication network equipment.

3. The method according to claim 1, further comprising: Receive the identity identifier of the private network device sent by the target application server; Determine the application identifier of the target application corresponding to the target application server; A query request is generated based on the identity identifier and the application identifier; The query request is sent to the authorization center, so that the authorization center can determine the private network device's permissions for the target application based on the identity identifier and the application identifier, and generate query results; If the query result includes license and authorization information, the query result is sent to the target application server so that the target application server can grant the private network device permissions to the target application based on the license and authorization information.

4. The method according to claim 1, further comprising: The authorization information of each private network device is displayed on the front end, wherein the authorization information includes the permissions of the private network device for different applications.

5. The method according to claim 1, further comprising: If the preset overdue conditions are determined based on the authorization period, a warning message will be generated. The warning message is sent to the target user terminal to notify the target user terminal to request the authorization center to update the permissions of the private network device for the target application.

6. The method according to claim 5, further comprising: Receive permission update messages from the authorization center; Based on the permission update message, the private network device's update permission for the target application is determined.

7. A method for determining rights in a smart application, applied to a private network cloud management and control platform in a smart park, the method comprising: Receive permission update requests entered by the user on the front end; The permission update request is forwarded to the authorization center so that the authorization center can update the permissions of the smart park device to the smart application according to the permission update request, wherein the smart park device is any smart terminal device in the smart park; Receive permission update messages from the authorization center; Based on the permission update message, the update permission of the smart park device for the smart application is determined. The private network cloud management platform manages the smart park device to achieve centralized management of the smart park device's permission for the smart application.

8. A private network system, the private network system comprising a private network cloud management and control platform, multiple network devices, and an authorization center; The private network cloud management platform is configured to receive permission update requests entered by users on the front end. Forward the permission update request to the authorization center; The authorization center is configured to receive permission update requests sent by the private network cloud management platform, update the permissions of the private network device to the target application according to the permission update requests, and send the permission update message to the private network cloud management platform. The private network device can be any network device in the private network scenario. The private network cloud management platform is also configured to receive permission update messages from the authorization center, and determine the update permissions of the private network device for the target application based on the permission update messages. The private network cloud management platform manages the private network device to achieve centralized management of the permissions of the private network device for the target application.

9. The system according to claim 8, wherein the private network system further includes an application server; The application server is configured to send the identity identifier of the private network device to the private network cloud management platform; The private network cloud management platform is also configured to receive the identity identifier of the private network device sent by the application server, determine the application identifier of the target application corresponding to the application server, generate a query request based on the identity identifier and the application identifier, and send the query request to the authorization center. The authorization center is also configured to receive query requests sent by the private network cloud management platform, determine the permissions of the private network device for the target application based on the identity identifier and the application identifier, generate query results, and send the query results to the private network cloud management platform. The private network cloud management platform is also configured to receive the query results sent by the private network cloud management platform, and, if the query results include license and authorization information, to send the query results back to the application server. The application server is also configured to receive the query results fed back by the private network cloud management platform, and determine the permissions of the private network device for the target application based on the query results.

10. A computing device, comprising: Memory and processor; The memory is used to store computer-executable instructions, and the processor is used to execute the computer-executable instructions, which, when executed by the processor, implement the steps of the method according to any one of claims 1 to 7.

11. A computer-readable storage medium storing computer-executable instructions that, when executed by a processor, implement the steps of the method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Method and system for managing terminal open platform power information

    CN101005699A

  • Access control method and device, equipment and storage medium

    CN114297708A