A data mapping method, device and equipment and readable storage medium are provided

By extracting the security attributes of application data and determining routing mapping rules based on the URSP policy, the problem of mixed transmission of data with different security levels is solved, and end-to-end security quality assurance is achieved.

CN116600286BActive Publication Date: 2026-02-06CETC CYBERSPACE SECURITY TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310567404.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-19
Publication Date
2026-02-06
Estimated Expiration
2043-05-19

AI Technical Summary

Technical Problem

In existing 3GPP standards, application data of different security levels are transmitted together, increasing the risk of data leakage or tampering.

Method used

By extracting the security attributes of the target application data, the corresponding URSP policy is obtained, and the target routing mapping rules are determined according to the policy. The data is then mapped to the corresponding security level routes, and cryptographic algorithms are used to protect confidentiality and integrity.

Benefits of technology

Ensuring that application data of different security levels is transmitted on routes of corresponding security levels improves end-to-end security quality assurance.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116600286B_ABST
    Figure CN116600286B_ABST
Patent Text Reader

Abstract

The application discloses an application data mapping method applied to the technical field of communication, and comprises the following steps: when target application data is received, target security attributes of the target application data are extracted; a target URSP policy corresponding to the target application data is acquired from a URSP policy according to the target security attributes; and a target routing mapping rule corresponding to the target application data is determined according to the target URSP policy. The target security attributes of the target application data are extracted, the target URSP policy corresponding to the target security attributes is acquired, the target routing mapping rule corresponding to the target URSP policy is determined, the application data with different security attributes is corresponded to the routing mapping rule, the application data with different security attributes can be transmitted on the route with the corresponding security level, and the end-to-end security quality guarantee is ensured. In addition, the application also provides an application data mapping device, equipment and readable storage medium, which also have the above beneficial effects.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of communication, in particular to an application data mapping method and device, equipment and readable storage medium. BACKGROUND

[0002] The specific method of terminal data transmission according to URSP (UE Route Selection Policy) is that the core network obtains the URSP that the terminal needs to follow from the policy control entity and provides it to the terminal, and the terminal will route the data to be sent by the application according to one or more rules in the URSP, including routing to an already established data transmission unit or routing to a newly established PDU (Protocol Data Unit) session, to realize data transmission. However, although the existing 3GPP (3rd Generation Partnership Project) standard and network provide end-to-end logical channels for various industries, with the help of this logical channel and URSP policy, the terminal can realize service channel selection and PDU mapping to realize the transmission of service data and meet the different Qos (Quality of Service) requirements of various industries. However, if it is completely implemented according to the existing URSP standard, different security level application services will be arranged in the same slice due to network performance requirements, and data of different security levels will be mixed together, resulting in data being stolen, leaked or tampered with. SUMMARY

[0003] Therefore, the purpose of the present application is to provide an application data mapping method, device, equipment and readable storage medium, which solves the problem of secure transmission of mixed data of different security levels in the prior art.

[0004] To solve the above technical problems, the present application provides an application data mapping method, comprising:

[0005] When receiving target application data, extracting the target security attribute of the target application data;

[0006] According to the target security attribute, obtaining the target URSP policy corresponding to the target application data from the URSP policy;

[0007] According to the target URSP policy, determining the target routing mapping rule corresponding to the target application data.

[0008] Optionally, after determining the target routing mapping rule corresponding to the target application data according to the target URSP policy, the method further comprises:

[0009] mapping the target application data to a corresponding logical channel according to the target routing mapping rule.

[0010] Optionally, the application data mapping method further comprises:

[0011] When mapping the target application data to a transmission channel according to the target routing mapping rule, the transmission channel uses a cryptographic algorithm to perform confidentiality protection and integrity protection on the target application data.

[0012] Optionally, the process of generating the URSP policy comprises:

[0013] receiving a URSP policy generation instruction; wherein the URSP policy generation instruction comprises a security attribute of application data;

[0014] generating the URSP policy according to the security attribute of the application data; wherein the URSP policy comprises a service security level and a routing security level, and the service security level and the routing security level correspond to the security attribute of the application data;

[0015] Optionally, the generating the URSP policy according to the security attribute of the application data comprises:

[0016] extracting the security attribute of the application data according to the industry attribute and the data feature of the application data, so as to generate the URSP policy according to the security attribute of the application data.

[0017] Optionally, the generating the URSP policy according to the security attribute of the application data comprises:

[0018] generating the URSP policy according to the security category and the security level of the application data, so that application data with different security categories but the same security level are mapped to different transmission channels; wherein the security attribute of the application data comprises the security category and the security level.

[0019] Optionally, the application data mapping method further comprises:

[0020] when the target URSP policy is not stored locally, generating the target URSP policy according to the security attribute of the target application data obtained.

[0021] The application further provides an application data mapping device, comprising:

[0022] a target security attribute extraction module configured to extract a target security attribute of target application data when the target application data is received;

[0023] a target URSP policy acquisition module, configured to acquire a target URSP policy corresponding to the target application data from URSP policies according to the target security attribute;

[0024] a target routing mapping rule determination module, configured to determine a target routing mapping rule corresponding to the target application data according to the target URSP policy.

[0025] The application further provides an application data mapping device, comprising:

[0026] a memory, configured to store a computer program;

[0027] a processor, configured to implement the steps of the application data mapping method when the computer program is executed.

[0028] The application further provides a readable storage medium, wherein the readable storage medium stores a computer program, and the computer program is executed by a processor to implement the steps of the application data mapping method.

[0029] It can be seen that the application provides a data mapping method, which extracts a target security attribute of target application data when the target application data is received, acquires a target URSP policy corresponding to the target application data from URSP policies according to the target security attribute, and determines a target routing mapping rule corresponding to the target application data according to the target URSP policy. Compared with the prior art which does not extract the security attribute of the application data for data mapping, the application extracts the target security attribute of the target application data, acquires the target URSP policy corresponding to the target security attribute, and then determines the target routing mapping rule corresponding to the target URSP policy according to the URSP policy, so that the application data with different security attributes is mapped to the routing security level corresponding to the security attribute, and the application data can be transmitted on the routing with the security level corresponding to the security attribute, so as to ensure the end-to-end security quality guarantee.

[0030] In addition, the application provides an application data mapping device, equipment and readable storage medium, which also have the beneficial effects described above. BRIEF DESCRIPTION OF DRAWINGS

[0031] In order to more clearly illustrate the technical solutions in the embodiments of the application or the prior art, the following will briefly introduce the drawings needed to be used in the embodiments or the prior art description. Obviously, the drawings in the following description only constitute the embodiments of the application, and for those skilled in the art, other drawings can also be obtained without creative labor on the basis of the provided drawings.

[0032] Figure 1 A flowchart of an application data mapping method provided by the application for the embodiments of the application;

[0033] Figure 2 A URSP policy with security attributes is provided for the embodiment of the present application.

[0034] Figure 3 A flowchart of a URSP policy generation method is provided for the embodiment of the present application.

[0035] Figure 4 A flowchart of an application data mapping method is provided for the embodiment of the present application.

[0036] Figure 5 A structural schematic diagram of an application data mapping device is provided for the embodiment of the present application.

[0037] Figure 6 A structural schematic diagram of an application data mapping device is provided for the embodiment of the present application. DETAILED DESCRIPTION

[0038] In order to make the objectives, technical solutions and advantages of the embodiments of the present application clearer, the technical solutions in the embodiments of the present application will be described clearly and completely below with reference to the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, rather than all the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by a person of ordinary skill in the art without creative work fall within the protection scope of the present application.

[0039] For reference Figure 1 , Figure 1 A flowchart of an application data mapping method is provided for the embodiment of the present application. The method can include:

[0040] S100, when receiving target application data, extracting a target security attribute of the target application data.

[0041] The execution subject of the embodiment is a terminal.

[0042] The embodiment does not limit the type of target application data, as long as the target application data can be registered and transmitted on a network. For example, the target application data is military data, or the target application data is civilian data, or the target application data is aerospace data. The embodiment does not limit the content of the target security attribute. For example, the target security attribute can be civilian data with a security level of 0, or the security attribute can be military data with a security level of 5, or the security attribute can be material data with a security level of 3. The embodiment does not limit the specific method of extracting the target security attribute of the target application data. For example, the target security attribute can be determined according to the industry category of the target application data, or the target security attribute can be determined according to the importance of the target application data.

[0043] S101, obtaining a target URSP policy corresponding to target application data from the URSP policy according to a target security attribute.

[0044] The embodiment does not limit the number of URSP policies, and the number of URSP policies can be 10, 20, 30, etc. The URSP policy describes the correspondence between the application data and the network slice, and the terminal selects the network slice for the application data according to the URSP policy. The existing URSP policy includes service description and routing description, but the service description and the routing description do not include service security level and routing security level. The URSP policy in the embodiment is a policy that has been modified according to the security attribute of the application data, and is a URSP policy corresponding to the application attribute of the application data. For example, when the target application attribute of the target application data is 0 level, the service security level in the corresponding URSP policy is 0, the slice security level in the routing security level is 0, and the data packet security level is 0. Or when the target security attribute of the target application data is a security level of 5, the service security level in the corresponding URSP policy can be 5, the slice security level in the routing security level is 5, and the data packet security level is 5. The embodiment does not limit the specific correspondence between the URSP policy and the target application data, as long as the URSP policy of the target application data can be determined according to the different target security attributes of the target application data.

[0045] For the convenience of understanding, the application provides a URSP policy with a security attribute, as shown in Figure 2 The URSP policy with a security attribute can include:

[0046] The URSP policy can include a plurality of URSP policies, and the service description of each URSP policy includes a service security level, and the routing description of each URSP policy includes a slice security level and a data packet security level. For example, the URSP policy includes URSP policy 1, URSP policy 2, URSP policy 3, URSP policy 4, URSP policy 5, and URSP policy 6. In addition to including the service network ID, application service ID, service IP, access preference, etc. in the existing URSP policy, the URSP policy also includes the service security level, slice security level, and data packet security level. When it is determined that the target URSP policy of the application data with a target security attribute A is URSP rule 3, it is determined that the service security level used by the application data during mapping transmission is 3, the slice security level used is 3, and the data packet security level used is 3. At this time, it can be ensured that the service security level of the application data and the routing security level are corresponding to each other, and the application data with a certain security level can be transmitted on the corresponding security level route.

[0047] S102, determining a target routing mapping rule corresponding to the target application data according to the target URSP policy.

[0048] The target routing mapping rule in this embodiment refers to a rule of mapping to a transmission channel, a physical channel and a logical channel corresponding to the target application data contained in the URSP policy. This embodiment does not limit a specific target routing mapping rule, as long as the target routing mapping rule is determined according to the URSP policy, as long as the target service data can be mapped to a slice security level and a packet security level corresponding to the target application data according to the target routing mapping rule. For example, the target security attribute of the target application data is determined to be A, at this time, if the target routing mapping rule corresponding to the application data with the target security attribute A is H1, then H1 is used to map and transmit the application data at this time.

[0049] Based on the above embodiment, when the target application data is received, the target security attribute of the target application data is extracted, the target URSP policy corresponding to the target application data is obtained from the URSP policy according to the target security attribute, and the target routing mapping rule corresponding to the target application data is determined according to the target URSP policy. It can be seen that, compared with the application data mapping method in the prior art, the application data mapping method provided by the application determines the target URSP policy through the target security attribute of the target application data, and then determines that the target application data is mapped to the target routing mapping rule corresponding to the target security attribute, so that the application data with different security attributes can be transmitted on the routing with the corresponding security level, to ensure the end-to-end security quality guarantee.

[0050] Further, in order to ensure that the application data can be mapped according to the target routing mapping rule, after the target routing mapping rule corresponding to the target application data is determined according to the target URSP policy, the method can further include:

[0051] Mapping the target application data to a corresponding logical channel according to the target routing mapping rule.

[0052] This embodiment does not limit the logical channel required for the transmission of the target application data, as long as the logical channel is determined according to the target routing mapping rule. For example, the first routing mapping rule corresponds to the first logical channel, the second routing mapping rule corresponds to the second logical channel, and the third routing mapping rule corresponds to the third logical channel, at this time, if the target routing channel is determined to be the second routing mapping rule, the second logical channel is used when the target application data is mapped and transmitted.

[0053] Further, in order to ensure the security of the mapping, the application data mapping method can further include:

[0054] When the target application data is mapped to the transmission channel according to the target routing mapping rule, the transmission channel uses a cipher algorithm to perform confidentiality protection and integrity protection on the target application data.

[0055] The embodiment does not limit the specific type of the cipher algorithm for performing confidentiality protection and integrity protection on the target application data, as long as the cipher algorithm can perform confidentiality and integrity protection on the target application data. For example, the cipher algorithm can be a hash algorithm, or the cipher algorithm can be a symmetric cipher algorithm, or the cipher algorithm can be an asymmetric cipher algorithm.

[0056] Further, in order to ensure that the URSP policy can be used, the process of generating the URSP policy can include:

[0057] receiving a URSP policy generation instruction; wherein the URSP policy generation instruction includes the security attribute of the application data;

[0058] generating the URSP policy according to the security attribute of the application data; wherein the URSP policy includes a service security level and a routing security level, and the service security level and the routing security level correspond to the security attribute of the application data;

[0059] obtaining the URSP policy, and updating the original URSP policy according to the URSP policy.

[0060] The embodiment does not limit the specific process of generating the URSP policy, as long as the URSP policy can be generated. The embodiment does not limit the triggering form of the URSP policy generation instruction, for example, the URSP policy generation instruction can be automatically triggered by the terminal, or the URSP policy can be passively triggered by the terminal according to the corresponding instruction. The embodiment does not limit the specific number of the URSP policy, for example, the URSP policy can be 7, or the URSP policy can be 10, or the URSP policy can be 20. The embodiment does not limit the specific form of the URSP policy generation instruction, as long as the security attribute of the application data can be obtained through the URSP policy generation instruction. The URSP policy in the embodiment corresponds to the same security attribute of the application data, one security attribute corresponds to one URSP policy, so that the application data with the same security attribute can use the corresponding URSP policy for mapping transmission. The embodiment does not limit the subject of generating the URSP policy according to the security attribute of the application data, as long as the corresponding URSP policy can be generated according to the security attribute of the application data. For example, the subject of generating the URSP policy according to the security attribute of the application data is the network side, or the subject of generating the URSP policy according to the security attribute of the application data is the terminal.

[0061] In order to facilitate understanding, the application provides a flowchart example of a URSP policy generation method,Figure 3 An example flowchart of a URSP policy generation method provided in an embodiment of the present application is shown in FIG. 3. The URSP policy generation method can specifically include the following steps.

[0062] S300, application registration.

[0063] The type of the application in this embodiment can be Taobao, or the application is Jingdong, or the application data is Construction Bank. The application registration in this embodiment refers to the registration of the application on the application processor.

[0064] S301, extracting the security attribute of the application data.

[0065] The execution subject in this embodiment is the application processor in the terminal. The application processor extracts the application data included in the application registration, and obtains the security attribute of the application data.

[0066] S302, registration request.

[0067] After the application processor in the terminal extracts the security attribute of the application data, the application processor initiates a registration request to the network side, so that the network side generates a corresponding URSP policy according to the security attribute of the application data.

[0068] S303, generating a URSP policy.

[0069] The execution subject in this embodiment is the network side. When the network side receives the registration request, the network side adds the service security level and the routing security level in the service description in the corresponding original URSP according to the security attribute of the application data in the registration request, so that the application data with the security attribute can be transmitted on the corresponding slice.

[0070] S304, obtaining a URSP policy.

[0071] The execution subject of this embodiment is the terminal. After the terminal obtains the URSP policy, the terminal updates the corresponding URSP policy stored locally, so that the URSP policy can be directly obtained for data transmission in subsequent data transmission.

[0072] The specific generation process of the URSP policy in the embodiment can include that when the terminal application is registered on the terminal application processor, the terminal application processor extracts the security attribute of the application data, the terminal initiates a registration request to the network end, the network end adds the service security level in the service description of the existing URSP policy according to the security attribute of the application data in the registration request, and adds the slice security level and the packet security level in the routing description of the existing URSP policy according to the security attribute of the application data, to generate the URSP policy, wherein the existing URSP policy is the URSP policy without the security attribute of the application data. Then the terminal obtains and stores the routing data mapping table of the URSP policy. When the application data is transmitted next time, the security attribute of the application data can be extracted, the URSP policy required for transmitting the application data is obtained, so that the application data is mapped to the route corresponding to the security level of the application data, and the security and quality of data transmission are ensured.

[0073] Further, in order to ensure that the security attribute of the application data is more accurate, the network end generating the URSP policy according to the security attribute of the application data can include:

[0074] extracting the security attribute of the application data according to the industry attribute and the data feature of the application data, to generate the URSP policy according to the security attribute of the application data.

[0075] The embodiment does not limit the specific process of extracting the security attribute of the application data according to the industry attribute and the data feature, as long as the security attribute of the application data can be determined according to the industry attribute and the data feature of the application data, so that the application data with different security attributes has a corresponding URSP policy.

[0076] Further, in order to ensure that the data with different security categories uses different transmission channels, the network end generating the URSP policy according to the security attribute of the application data can include:

[0077] generating the URSP policy according to the security category and the security level of the application data, so that the application data with different security categories but the same security level is mapped to different transmission channels; wherein the security attribute of the application data includes the security category and the security level.

[0078] The embodiment is to make the transmission of application data of different security categories on different routes, and the security attribute includes a security level and a security category. For example, the security categories of application data are divided into sensitive data and non-sensitive data, URSP policies of data with different security categories are different, non-sensitive data and sensitive data are transmitted on different slices and are not multiplexed on the same transmission channel. However, data with the same security category can be transmitted on the same slice and multiplexed on the same transmission channel. Alternatively, for example, data A and data B both belong to sensitive data, at this time, if the security levels of A and B are the same, the security attributes of A and B are completely the same at this time, A and B share one URSP policy, or when the security category of A is sensitive data and the security category of B is non-sensitive data, even if the security levels of A and B are the same, the URSP policies corresponding to A and B are different.

[0079] Further, in order to ensure that the application data can be successfully transmitted out, the above-mentioned application data mapping method can further include:

[0080] When the target URSP policy is not stored locally, generating the target URSP policy according to the security attribute of the target application data.

[0081] The embodiment does not limit the specific type of the target URSP policy, as long as the target application data of the target application attribute is found to have no corresponding URSP policy when the data is mapped, at this time, the URSP policy needs to be generated, so that the target application data can be successfully transmitted out.

[0082] In order to make the application easier to understand, please refer to Figure 4 , Figure 4 A flowchart example of an application data mapping method provided by the embodiment of the application can specifically include:

[0083] When application data 1, application data 2 and application data 3 are received at the same time, the security attributes of application data 1, application data 2 and application data 3 are extracted respectively, when it is determined that the security categories and the security levels in the security attributes of application data 1 and application data 3 are the same, it is indicated that application data 1 and application data 3 can multiplex the same slice and the same transmission channel. When the security attribute 1 and the security attribute 3 are the same, it is indicated that application data 1 and application data 3 correspond to the same URSP1, and application data 2 corresponds to URSP2 alone, at this time, it is determined that application data 1 and application data 3 correspond to routing mapping rule 1, and application data 2 corresponds to routing mapping rule 2, thereby realizing the mapping of application data to a logical channel, to a transmission channel, and to a physical channel. When the application data is mapped on the transmission channel, the transmission channel will perform confidentiality and integrity protection on the application data.

[0084] Further, if the security attribute of the application data 1 is extracted when the application data 1 is received, it is determined that the application data corresponds to the security attribute 1, and when the terminal does not find the URSP policy corresponding to the security attribute in the terminal, the terminal sends a registration request to the network end, so that the network end can change the initial URSP policy according to the registration request, increase the service security level corresponding to the security attribute 1 in the service description, and increase the slice security level and the packet security level corresponding to the security attribute 1 in the routing description, so that the security attribute 1 has the corresponding URSP policy. When the security attribute 1 has the corresponding URSP policy, the terminal can determine the routing mapping rule 1 corresponding to the application data 1 by using the URSP policy, and then map the application data 1 to the logical channel corresponding to the security attribute, and realize the mapping of the logical channel to the transmission channel, and the transmission channel uses the cryptographic algorithm to protect the confidentiality and integrity of the target application data, and realizes the mapping of the target application data from the transmission channel to the physical channel, and then the physical channel transmits the target application data through the corresponding slice.

[0085] In summary, based on the above embodiments, the application data mapping method provided by the application determines the target URSP policy through the target security attribute of the target application data, and then determines the mapping of the target application data to the target routing mapping rule corresponding to the target security attribute, so that the application data with different security attributes can be transmitted on the route with corresponding security level, to ensure the end-to-end security quality guarantee. Further, in order to ensure the quality and security of transmission, the target application data is protected in terms of confidentiality and integrity when mapping in the transmission channel. Further, in order to ensure the successful mapping of the target application data, when it is found that the URSP policy corresponding to the target security attribute is not stored locally, the corresponding URSP policy is generated according to the target security attribute.

[0086] Next, an application data mapping device provided by an embodiment of the application is described. The application data mapping device described below can be referred to in correspondence with the application data mapping method described above.

[0087] For details, please refer to Figure 5 , Figure 5 The structure of an application data mapping device provided by an embodiment of the application is shown in the figure. The device can include:

[0088] A target security attribute extraction module 100 is configured to extract the target security attribute of the target application data when the target application data is received.

[0089] A target URSP policy acquisition module 200 is configured to acquire the target URSP policy corresponding to the target application data from the URSP policy according to the target security attribute.

[0090] The target route mapping rule determination module 300 is configured to determine a target route mapping rule corresponding to the target application data according to the target URSP policy.

[0091] Based on the above embodiments, the application data mapping device can further include:

[0092] The logical channel mapping module is configured to map the target application data to a corresponding logical channel according to the target route mapping rule.

[0093] Based on any of the above embodiments, the application data mapping device can further include:

[0094] The transport channel mapping module is configured to map the target application data to a transport channel according to the target route mapping rule, and the transport channel uses a cryptographic algorithm to perform confidentiality protection and integrity protection on the target application data.

[0095] Based on any of the above embodiments, the application data mapping method can further include:

[0096] The policy generation instruction receiving module is configured to receive a URSP policy generation instruction, wherein the URSP policy generation instruction includes a security attribute of application data.

[0097] The URSP policy generation module is configured to generate the URSP policy according to the security attribute of the application data, wherein the URSP policy includes a service security level and a route security level, and the service security level and the route security level correspond to the security attribute of the application data.

[0098] The updating module is configured to obtain the URSP policy and update an original URSP policy according to the URSP policy.

[0099] Based on any of the above embodiments, the URSP policy generation module can include:

[0100] The first URSP policy generation unit is configured to extract a security attribute of the application data according to an industry attribute and a data feature of the application data, and generate the URSP policy according to the security attribute of the application data.

[0101] Based on any of the above embodiments, the URSP policy generation module can include:

[0102] The second URSP policy generation unit is configured to generate the URSP policy according to a security category and a security level of the application data, so that application data with different security categories but the same security level are mapped to different transport channels, wherein the security attribute of the application data includes the security category and the security level.

[0103] Based on any of the above embodiments, the application data mapping device can further include:

[0104] a target URSP policy detection unit configured to generate the target URSP policy according to the security attribute of the target application data when the target URSP policy is not stored locally.

[0105] It should be noted that the order of the modules and units in the application data mapping device described above can be changed without affecting the logic.

[0106] In summary, the application data mapping device provided by the embodiments of the present application includes: a target security attribute extraction module 100 configured to extract a target security attribute of target application data when the target application data is received; a target URSP policy acquisition module 200 configured to acquire a target URSP policy corresponding to the target application data from a URSP policy according to the target security attribute; and a target routing mapping rule determination module 300 configured to determine a target routing mapping rule corresponding to the target application data according to the target URSP policy. It can be seen that, compared with the existing application data mapping device, the application data mapping device provided by the present application determines the target URSP policy through the target security attribute of the target application data, and then determines that the target application data is mapped to the target routing mapping rule corresponding to the target security attribute, so that application data with different security attributes can be transmitted on the corresponding security level route to ensure end-to-end security quality assurance.

[0107] Next, an application data mapping device provided by the embodiments of the present application will be described. The application data mapping device described below can be referred to the application data mapping method described above.

[0108] Please refer to Figure 6 , Figure 6 The structure diagram of the application data mapping device provided by the embodiments of the present application can include:

[0109] a memory 10 configured to store a computer program;

[0110] a processor 20 configured to execute the computer program to implement the steps of the application data mapping method described above.

[0111] The memory 10, the processor 20, the communication interface 31 and the communication bus 32. The memory 10, the processor 20, the communication interface 31 all complete the communication among each other through the communication bus 32.

[0112] In the embodiment of the present application, the memory 10 stores one or more programs, which can include program codes including computer operation instructions. In the embodiment of the present application, the memory 10 can store programs for implementing the following functions:

[0113] When the target application data is received, a target security attribute of the target application data is extracted;

[0114] According to the target security attribute, a target URSP policy corresponding to the target application data is obtained from the URSP policy;

[0115] According to the target URSP policy, a target routing mapping rule corresponding to the target application data is determined.

[0116] In a possible implementation, the memory 10 can include a program storage area and a data storage area. The program storage area can store an operating system and at least one application program required by a function, etc. The data storage area can store data created during use.

[0117] In addition, the memory 10 can include a read-only memory and a random access memory, and provide instructions and data for the processor. A part of the memory can also include an NVRAM. The memory stores an operating system and operation instructions, executable modules or data structures, or a subset of them, or an extended set of them, wherein the operation instructions can include various operation instructions for implementing various operations. The operating system can include various system programs for implementing various basic tasks and processing hardware-based tasks.

[0118] The processor 20 can be a central processing unit (CPU), an application-specific integrated circuit, a digital signal processor, a field programmable gate array or other programmable logic device. The processor 20 can be a microprocessor or any conventional processor, etc. The processor 20 can invoke programs stored in the memory 10.

[0119] The communication interface 31 can be an interface of a communication module, used for connecting with other devices or systems.

[0120] It should be noted that, Figure 6 The structures shown do not constitute a limitation on the application data mapping device in the embodiment of the present application. In actual applications, the application data mapping device can include more or fewer components than those shown, or combine some components. Figure 6

[0121] The readable storage medium provided by the embodiment of the present application is described below. The readable storage medium described below can be referred to the application data mapping method described above.​

[0122] The application further provides a readable storage medium, and the readable storage medium stores a computer program.

[0123] The readable storage medium can include a U disk, a mobile hard disk, a Read-Only Memory (ROM), a Random Access Memory (RAM), a magnetic disk or an optical disk, and various storage program codes.

[0124] The embodiments in the specification are described in a progressive manner, and each embodiment focuses on the difference from other embodiments, and the same or similar parts of each embodiment can be referred to each other. For the device disclosed by the embodiments, since it corresponds to the method disclosed by the embodiments, the description is relatively simple, and the related parts can be referred to the method part.

[0125] The skilled person can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be realized by electronic hardware, computer software or a combination of both. In order to clearly show the interchangeability of hardware and software, the composition and steps of each example have been described in the above description. Whether the functions are realized by hardware or software depends on the specific application and design constraints of the technical solution. The skilled person can use different methods to realize the described functions for each specific application, but such implementation should not be considered beyond the scope of the application.

[0126] Finally, it should be noted that in this paper, relationships such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between the entities or operations. Moreover, the terms "include", "contain" or any other variant are intended to cover non-exclusive inclusion, so that the process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed or inherent to such process, method, article or device.

[0127] The application data mapping method, device, equipment and readable storage medium provided by the application are described in detail above, the principle and implementation mode of the application are described by using specific examples in this paper, and the above example description is only used to help understand the method of the application and its core idea; meanwhile, for those skilled in the art, according to the idea of the application, the specific implementation mode and application range will be changed, and the above description should not be understood as the limitation of the application.

Claims

1. An application data mapping method, characterized by, Comprise: When receiving target application data, extract the target security attribute of the target application data; According to the target security attribute, the target URSP policy corresponding to the target application data is obtained from the URSP policy; The generation process of the URSP policy includes that when the terminal application registers on the terminal application processor, the terminal application processor extracts the security attribute of the application data, the terminal application initiates a registration request to the network side, and the network side adds the service security level in the service description of the existing URSP policy according to the security attribute of the application data in the registration request, and adds the slice security level and the packet security level in the routing description of the existing URSP policy according to the security attribute of the application data, so as to generate the URSP policy; According to the target URSP policy, the target routing mapping rule corresponding to the target application data is determined; The process of generating the URSP policy includes: Receive the URSP policy generation instruction; The security attribute of the application data is included in the URSP policy generation instruction; According to the security attribute of the application data, the URSP policy is generated; The URSP policy includes service security level and routing security level, and the service security level and the routing security level correspond to the security attribute of the application data; The URSP policy is obtained, and the original URSP policy is updated according to the URSP policy; According to the security attribute of the application data, the URSP policy is generated, including: According to the industry attribute and data characteristics of the application data, the security attribute of the application data is extracted, so as to generate the URSP policy according to the security attribute of the application data; According to the security category and security level of the application data, the URSP policy is generated, so that the application data with different security categories but the same security level is mapped to different transmission channels; The security attribute of the application data includes the security category and the security level.

2. The method of claim 1, wherein, After determining the target routing mapping rule corresponding to the target application data according to the target URSP policy, it further includes: According to the target routing mapping rule, the target application data is mapped to the corresponding logical channel.

3. The method of claim 1, wherein the application data mapping is performed by a network server. Further comprising: When the target application data is mapped to the transmission channel according to the target routing mapping rule, the transmission channel uses a cryptographic algorithm to protect the confidentiality and integrity of the target application data.

4. The method of claim 1, wherein the application data mapping is performed by a network server. Further comprising: When the target URSP policy is not stored locally, the target URSP policy is generated according to the security attribute of the target application data obtained.

5. An application data mapping apparatus, characterized by comprising: Comprise: A target security attribute extraction module is configured to extract the target security attribute of the target application data when receiving the target application data; The target URSP policy obtaining module is configured to obtain a target URSP policy corresponding to the target application data from the URSP policy according to the target security attribute; wherein, the generation process of the URSP policy comprises that when a terminal application is registered on a terminal application processor, the terminal application processor extracts the security attribute of the application data, the terminal application initiates a registration request to a network end, the network end adds a service security level in a service description of an existing URSP policy according to the security attribute of the application data in the registration request, and adds a slice security level and a data packet security level in a routing description of the existing URSP policy according to the security attribute of the application data, so as to generate the URSP policy; The target routing mapping rule determining module is configured to determine a target routing mapping rule corresponding to the target application data according to the target URSP policy; The policy generation instruction receiving module is configured to receive a URSP policy generation instruction; wherein, the URSP policy generation instruction comprises a security attribute of application data; The URSP policy generating module is configured to generate the URSP policy according to the security attribute of the application data; wherein, the URSP policy comprises a service security level and a routing security level, and the service security level and the routing security level correspond to the security attribute of the application data; The updating module is configured to obtain the URSP policy, and update an original URSP policy according to the URSP policy; The URSP policy generating module comprises: The first URSP policy generating unit is configured to extract the security attribute of the application data according to the industry attribute and the data feature of the application data, and generate the URSP policy according to the security attribute of the application data; The second URSP policy generating unit is configured to generate the URSP policy according to the security category and the security level of the application data, so that application data with different security categories but the same security level is mapped to different transmission channels; wherein, the security attribute of the application data comprises the security category and the security level.

6. An application data mapping device, characterized by The memory is configured to store a computer program; The processor is configured to implement the application data mapping method in any one of claims 1 to 4 when executing the computer program. The computer program is stored on the readable storage medium, and when executed by the processor, the computer program implements the steps of the application data mapping method in any one of claims 1 to 4.

7. A readable storage medium characterized by, ​

Citation Information

Patent Citations

  • Route selection policy acquisition method, device and equipment

    CN109286567A

  • User plane safety policy implementation method, device and system

    CN110831243A