Unified access method, device and equipment based on network twinning and storage medium

By obtaining the terminal identifier of heterogeneous terminals and confirming the network twin identifier, the problem of non-fixed IP addresses in traditional network access methods is solved, realizing intelligent interconnection and business continuity between people, machines, and things in cloud-native networks.

CN116684195BActive Publication Date: 2026-04-10PENG CHENG LAB
View PDF 1 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-05
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

Traditional network access methods, which identify users by IP addresses, cannot guarantee the continuity of mobile services because IP addresses are not fixed.

Method used

By obtaining the terminal identifier of heterogeneous terminals, it is determined whether there is a corresponding network twin identifier in the target mapping table. After confirmation, security authentication is completed, and a network request is initiated to access the cloud-native network, thus establishing a unified access method based on network twins.

Benefits of technology

It enables intelligent interconnection of heterogeneous terminals such as people, machines, and things in cloud-native networks, ensuring the continuity of mobile services and providing more efficient, flexible, and secure network access through a network twin identification system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116684195B_ABST
    Figure CN116684195B_ABST
Patent Text Reader

Abstract

The application belongs to the technical field of computer networks, and discloses a unified access method and device based on network twinning, equipment and a storage medium. The method comprises the following steps: when an access instruction of a heterogeneous terminal is received, the terminal identifier of the heterogeneous terminal is acquired; it is judged whether the network twin identifier corresponding to the terminal identifier exists in a target mapping table, wherein the target mapping table comprises a one-to-one mapping relationship between the terminal identifier and the network twin identifier; when it is judged that the network twin identifier corresponding to the terminal identifier exists in the target mapping table, the security authentication of the heterogeneous terminal is completed; after the security authentication of the heterogeneous terminal is completed, a network request is initiated for the heterogeneous terminal, so that the heterogeneous terminal accesses a cloud native network. Through the above method, not only the continuity of mobile services can be ensured, but also the safe access of man-machine objects to the network can be ensured.
Need to check novelty before this filing date? Find Prior Art

Description

TECHNICAL FIELD

[0001] The present application relates to the technical field of computer networks, and particularly relates to a unified access method and device based on network twinning, equipment and a storage medium. BACKGROUND

[0002] With the continuous development of future network terminal types and access methods, the demand for human-machine-object-oriented Internet of Everything is increasing, and it is urgent to transparently connect people, machines and objects in the network to provide more diversified, personalized, efficient and customized services. The traditional network access method identifies the identity of the user at the network layer with an IP address, which can change with time, location and access method, making it impossible to guarantee the continuity of mobile services. SUMMARY

[0003] The main purpose of the present application is to provide a unified access method, device, equipment and storage medium based on network twinning, which aims to solve the technical problem that the continuity of services cannot be guaranteed when the identity is identified by IP in the traditional network access method due to the non-fixed IP address.

[0004] To achieve the above purpose, the present application provides a unified access method based on network twinning, which comprises the following steps:

[0005] When receiving the access instruction of the heterogeneous terminal, the terminal identifier of the heterogeneous terminal is obtained;

[0006] It is judged whether the network twin identifier corresponding to the terminal identifier exists in the target mapping table, wherein the target mapping table comprises a one-to-one mapping relationship between the terminal identifier and the network twin identifier;

[0007] When it is determined that the network twin identifier corresponding to the terminal identifier exists in the target mapping table, the security authentication of the heterogeneous terminal is completed;

[0008] After completing the security authentication of the heterogeneous terminal, a network request is initiated for the heterogeneous terminal to access the cloud native network.

[0009] Optionally, the heterogeneous terminal comprises a first heterogeneous terminal, and the network twin identifier comprises a first network twin identifier; wherein,

[0010] Before judging whether the network twin identifier corresponding to the terminal identifier exists in the target mapping table, it further comprises:

[0011] The iris, fingerprint and identity card information of the target personnel are obtained;

[0012] Bind the iris, the fingerprint and the identity card information to form a first identifier as the first identity identifier of the target personnel;

[0013] Generate the target mapping table based on the first identity identifier and the first network twin identifier;

[0014] The terminal identifier of the heterogeneous terminal is acquired when the access instruction of the heterogeneous terminal is received, including:

[0015] The target personnel corresponding to the first heterogeneous terminal is acquired when the access instruction of the first heterogeneous terminal is received;

[0016] The first identity identifier of the target personnel is taken as the terminal identifier of the first heterogeneous terminal;

[0017] The network twin identifier corresponding to the terminal identifier is determined in the target mapping table, including:

[0018] It is determined whether the first network twin identifier corresponding to the terminal identifier exists in the target mapping table.

[0019] Optionally, the heterogeneous terminal includes a second heterogeneous terminal, and the network twin identifier includes a first network twin identifier; wherein,

[0020] Before the network twin identifier corresponding to the terminal identifier is determined in the target mapping table, further including:

[0021] The terminal type, the manufacturer, the product serial number and the MAC address of the target machine are acquired;

[0022] The second identifier formed by binding the terminal type, the manufacturer, the product serial number and the MAC address is taken as the second identity identifier of the target machine;

[0023] The target mapping table is generated based on the second identity identifier and the first network twin identifier.

[0024] Optionally, the terminal identifier of the heterogeneous terminal is acquired when the access instruction of the heterogeneous terminal is received, including:

[0025] The target machine corresponding to the second heterogeneous terminal is acquired when the access instruction of the second heterogeneous terminal is received;

[0026] The second identity identifier of the target machine is taken as the terminal identifier of the second heterogeneous terminal;

[0027] The network twin identifier corresponding to the terminal identifier is determined in the target mapping table, including:

[0028] determining whether the terminal identifier corresponds to a first network twin identifier in the target mapping table.

[0029] Optionally, the heterogeneous terminal includes a third heterogeneous terminal, and the network twin identifier includes a second network twin identifier; wherein,

[0030] Before the determining whether the terminal identifier corresponds to a network twin identifier in the target mapping table, the method further includes:

[0031] obtaining a terminal type, a manufacturer, a product serial number, and a MAC address of a target object;

[0032] binding the terminal type, the manufacturer, the product serial number, and the MAC address to form a third identifier as a third identity identifier of the target object;

[0033] generating the target mapping table based on the third identity identifier and the second network twin identifier.

[0034] Optionally, the obtaining the terminal identifier of the heterogeneous terminal when receiving an access instruction of the heterogeneous terminal includes:

[0035] obtaining a target object corresponding to the third heterogeneous terminal when receiving an access instruction of the third heterogeneous terminal;

[0036] binding the third identity identifier of the target object as the terminal identifier of the heterogeneous terminal;

[0037] The determining whether the terminal identifier corresponds to a network twin identifier in the target mapping table includes:

[0038] determining whether the terminal identifier corresponds to a second network twin identifier in the target mapping table.

[0039] Optionally, the target mapping table further includes a many-to-one mapping relationship between the second network twin identifier and the first network twin identifier; wherein,

[0040] Before the determining whether the terminal identifier corresponds to a network twin identifier in the target mapping table, the method further includes:

[0041] obtaining a terminal type, a manufacturer, a product serial number, and a MAC address of a target object;

[0042] binding the terminal type, the manufacturer, the product serial number, and the MAC address to form a third identifier as a third identity identifier of the target object;

[0043] generating the target mapping table based on the third identity identifier, the second network twin identifier, and the first network twin identifier.

[0044] The terminal identifier of the heterogeneous terminal is acquired when the access instruction of the heterogeneous terminal is received.

[0045] The target object corresponding to the third heterogeneous terminal is acquired when the access instruction of the third heterogeneous terminal is received.

[0046] The third identity of the target object is taken as the terminal identifier of the third heterogeneous terminal.

[0047] The network twin identifier corresponding to the terminal identifier in the target mapping table is determined.

[0048] The first network twin identifier corresponding to the terminal identifier in the target mapping table is determined.

[0049] The security authentication of the heterogeneous terminal is completed when the network twin identifier corresponding to the terminal identifier in the target mapping table is determined.

[0050] The security authentication of the heterogeneous terminal is completed when the first network twin identifier corresponding to the second network twin identifier in the target mapping table is determined.

[0051] In addition, in order to achieve the above-mentioned purpose, the application further provides a unified access device based on network twin, which comprises:

[0052] The acquisition module is used for acquiring the terminal identifier of the heterogeneous terminal when the access instruction of the heterogeneous terminal is received.

[0053] The judgment module is used for determining whether the network twin identifier corresponding to the terminal identifier exists in the target mapping table, wherein the target mapping table comprises a one-to-one mapping relationship between the terminal identifier and the network twin identifier.

[0054] The completion module is used for completing the security authentication of the heterogeneous terminal when the network twin identifier corresponding to the terminal identifier in the target mapping table is determined.

[0055] The initiation module is used for initiating the network request for the heterogeneous terminal after the security authentication of the heterogeneous terminal is completed, so that the heterogeneous terminal accesses the cloud native network.

[0056] In addition, to achieve the above object, the application further provides a unified access device based on network twinning, comprising a memory, a processor and a unified access program based on network twinning stored on the memory and executable on the processor, the unified access program based on network twinning being configured to implement the steps of the unified access method based on network twinning as described above.

[0057] In addition, to achieve the above object, the application further provides a storage medium having a unified access program based on network twinning stored thereon, the unified access program based on network twinning implementing the steps of the unified access method based on network twinning as described above when executed by a processor.

[0058] The unified access method, device, equipment and storage medium based on network twinning provided by the application can provide support technology for intelligent interconnection of man-machine-thing in cloud native network architecture, provide core foundation for intelligent interconnection, resource intercommunication, sharing and cooperation of man-machine-thing in cloud native network, and establish a network twinning identification system based on network twinning, so that man-machine-thing can access the cloud native network after determining the network twinning identification through the terminal identification, and the network twinning identification corresponding to the heterogeneous terminal will not change with time, place and access mode, thereby ensuring the continuity of mobile services. BRIEF DESCRIPTION OF DRAWINGS

[0059] Figure 1 FIG. 1 is a structural schematic diagram of a unified access device based on network twinning of a hardware running environment involved in the embodiment of the application;

[0060] Figure 2 FIG. 2 is a flowchart of the first embodiment of the unified access method based on network twinning of the application;

[0061] Figure 3 FIG. 3 is a dynamic mapping relationship diagram between man-machine-thing heterogeneous terminals and network twinning in the first embodiment of the unified access method based on network twinning of the application;

[0062] Figure 4The unified access network based on network twinning identification in the first embodiment of the unified access method based on network twinning of the application is shown in the schematic diagram.

[0063] Figure 5 The flowchart of the second embodiment of the unified access method based on network twinning of the application is shown in the schematic diagram.

[0064] Figure 6 The structure block diagram of the first embodiment of the unified access device based on network twinning of the application is shown in the schematic diagram.

[0065] The implementation, functional features and advantages of the application will be further described with reference to the embodiments and the accompanying drawings. DETAILED DESCRIPTION

[0066] It should be understood that the specific embodiments described herein are intended to explain the application and are not intended to limit the application.

[0067] Reference Figure 1 , Figure 1 The unified access device based on network twinning of the hardware running environment involved in the embodiment scheme of the application is shown in the structure schematic diagram.

[0068] As Figure 1 shown, the unified access device based on network twinning can include a processor 1001, such as a central processing unit (CPU), a communication bus 1002, a user interface 1003, a network interface 1004, and a memory 1005. The communication bus 1002 is used to realize the connection and communication between the components. The user interface 1003 can include a display screen, an input unit such as a keyboard, and an optional user interface 1003 can also include a standard wired interface, a wireless interface. The network interface 1004 can optionally include a standard wired interface, a wireless interface (such as a wireless fidelity (Wi-Fi) interface). The memory 1005 can be a high-speed random access memory (RAM) memory, or a stable non-volatile memory (NVM), such as a magnetic disk memory. The memory 1005 can also be an independent storage device from the aforementioned processor 1001.

[0069] Those skilled in the art can understand that Figure 1 the structure shown in the foregoing embodiments does not constitute a limitation on the unified access device based on network twinning, and can include more or fewer components than the illustrated components, or combine certain components, or different component arrangements.

[0070] As Figure 1As shown, the memory 1005 as a storage medium can include an operating system, a network communication module, a user interface module, and a unified access program based on network twin.

[0071] In Figure 1 In the unified access device based on network twin shown, the network interface 1004 is mainly used for data communication with a network server; the user interface 1003 is mainly used for data interaction with a user; the processor 1001 and the memory 1005 in the unified access device based on network twin can be arranged in the unified access device based on network twin, and the unified access program based on network twin stored in the memory 1005 is called by the processor 1001, and the unified access method based on network twin provided by the embodiment of the application is executed.

[0072] Based on the above hardware structure, the embodiment of the unified access method based on network twin is proposed.

[0073] Referring to Figure 2 , Figure 2 The flowchart of the first embodiment of the unified access method based on network twin of the application is shown.

[0074] In this embodiment, the unified access method based on network twin includes the following steps:

[0075] Step S10: When receiving the access instruction of the heterogeneous terminal, the terminal identifier of the heterogeneous terminal is obtained.

[0076] It should be noted that the execution subject of the embodiment can be a computing service device with data processing, network communication and program running functions, such as mobile phones, tablet computers, personal computers, etc., or an electronic device or a unified access device based on network twin capable of realizing the above functions. The embodiment and the following embodiments will be described below with the unified access device based on network twin as an example.

[0077] It can be understood that the access instruction refers to the instruction that the heterogeneous terminal needs to access the cloud native network.

[0078] It should be noted that the heterogeneous terminal includes heterogeneous terminals such as man-machine-objects, and the terminal identifier refers to an identifier that can be used to refer to the heterogeneous terminal. Specifically, for a man heterogeneous terminal, the iris, fingerprint and identity card information possessed by the man can be used as the terminal identifier of the man heterogeneous terminal.

[0079] Step S20: Determine whether the network twin identifier corresponding to the terminal identifier exists in the target mapping table, wherein the target mapping table includes a one-to-one mapping relationship between the terminal identifier and the network twin identifier.

[0080] It should be noted that the network twin is a mobile agent, a transmission agent and a security agent of a person, a machine and a thing in a cloud native network, is a basic cloud service in the cloud native network, and is a unique entrance for accessing the cloud native network, which is not bound to an IP address. The IP address is only used as a location identifier of the network twin agent. The heterogeneous terminal of a person, a machine and a thing only needs to complete the function of the mobile agent through the network twin agent in the process of movement, maintains the access identifier unchanged, and guarantees the mobility of the user and the continuity of the service. The network twin can be used to establish a network twin identification system to realize the characteristics of supporting network endogenous security, flexible expansion, ubiquitous mobility and flexible flexibility, so that the network is more efficient, more flexible, more intelligent and more secure. The network twin identification in the network twin identification system is a service identifier and a unique access identifier in the cloud native network.

[0081] Step S30: When it is determined that the network twin identifier corresponding to the terminal identifier exists in the target mapping table, the security authentication of the heterogeneous terminal is completed.

[0082] It can be understood that when it is determined that the network twin identifier corresponding to the terminal identifier exists in the target mapping table, the security authentication of the heterogeneous terminal is completed.

[0083] In a specific implementation, as shown in Figure 3 The identity of a person, the identity of a machine and the identity of a thing can be used as an element for accessing the cloud native network, and the real-name system accesses the network.

[0084] In an embodiment, the heterogeneous terminal includes a first heterogeneous terminal, and the network twin identifier includes a first network twin identifier; and

[0085] Before the step of determining whether the network twin identifier corresponding to the terminal identifier exists in the target mapping table, the method further includes:

[0086] Obtaining the iris, the fingerprint and the ID card information of the target person;

[0087] Binding the iris, the fingerprint and the ID card information to form a first identifier as the first identity of the target person;

[0088] Generating the target mapping table based on the first identity and the first network twin identifier;

[0089] The step of obtaining the terminal identifier of the heterogeneous terminal when the access instruction of the heterogeneous terminal is received includes:

[0090] Obtaining the target person corresponding to the first heterogeneous terminal when the access instruction of the first heterogeneous terminal is received;

[0091] The first identity of the target person is taken as the terminal identity of the first heterogeneous terminal.

[0092] The judgment whether the network twin identity corresponding to the terminal identity exists in the target mapping table comprises:

[0093] The judgment whether the first network twin identity corresponding to the terminal identity exists in the target mapping table.

[0094] It should be noted that the target person can be a natural person or a legal person; for a natural person, the first identity formed by binding the iris, fingerprint and ID information of the natural person can be taken as the first identity of the target person; for a legal person, the representation identity information capable of representing the legal person can be taken as the first identity of the target person.

[0095] It should be noted that the first network twin identity refers to the network twin identity of a person, and the network twin identity of a person contains multiple attributes such as the identity of the person, the identity of the machine, and the identity of the person-machine data.

[0096] It should be noted that the first identity refers to the identity of a person, and the first heterogeneous terminal refers to a person heterogeneous terminal.

[0097] It can be understood that the judgment whether the first network twin identity corresponding to the terminal identity exists in the target mapping table is to judge whether the first network twin identity corresponding to the first identity exists in the target mapping table.

[0098] In the embodiment, the personal identity is supported by authentication means such as multi-factor authentication, and the potential security threat and attack of the existing network are solved by the real-name network access mode.

[0099] In an embodiment, the heterogeneous terminal comprises a second heterogeneous terminal, and the network twin identity comprises a first network twin identity; wherein,

[0100] Before the judgment whether the network twin identity corresponding to the terminal identity exists in the target mapping table, the method further comprises:

[0101] The terminal type, the manufacturer, the product serial number and the MAC address of the target machine are obtained.

[0102] The second identity formed by binding the terminal type, the manufacturer, the product serial number and the MAC address is taken as the second identity of the target machine.

[0103] The target mapping table is generated based on the second identity and the first network twin identity.

[0104] It should be noted that the first network twin identifier refers to the network twin identifier of a person, and the network twin identifier of the person includes the identity identifier of the person, the identity identifier of the machine, and the identity identifier of the person-machine data, and the like multi-dimensional attributes.

[0105] It should be noted that the second identity identifier refers to the identity identifier of the machine, and the second heterogeneous terminal refers to the machine heterogeneous terminal.

[0106] It should be noted that the person accesses the network to realize the function of surfing the Internet by attaching to the machine with the function of surfing the Internet, and the identity identifier of the person (person ID) and the identity identifier of the machine (machine ID) are dynamically mapped one-to-one with the network twin identifier (network twin (Cybertwin) ID) of the person. Among them, the network twin (Cybertwin) identifier of the person includes the identity identifier of the person, the identity identifier of the machine, and the identity identifier of the person-machine data, and the like multi-dimensional attributes.

[0107] It should be noted that the machine and the object have their affiliated legal persons, and the person-machine-object can be uniformly accessed in the cloud native network based on the mapping relationship between the identity identifier and the access identifier.

[0108] In an embodiment, when the access instruction of the heterogeneous terminal is received, the terminal identifier of the heterogeneous terminal is obtained, comprising:

[0109] When the access instruction of the second heterogeneous terminal is received, the target machine corresponding to the second heterogeneous terminal is obtained;

[0110] The second identity identifier of the target machine is taken as the terminal identifier of the second heterogeneous terminal;

[0111] The judgment whether the network twin identifier corresponding to the terminal identifier exists in the target mapping table, comprising:

[0112] Judging whether the first network twin identifier corresponding to the terminal identifier exists in the target mapping table.

[0113] It can be understood that judging whether the first network twin identifier corresponding to the terminal identifier exists in the target mapping table is to judge whether the first network twin identifier corresponding to the second identity identifier exists in the target mapping table.

[0114] In an embodiment, the heterogeneous terminal includes a third heterogeneous terminal, and the network twin identifier includes a second network twin identifier; wherein,

[0115] Before the judgment whether the network twin identifier corresponding to the terminal identifier exists in the target mapping table, further comprising:

[0116] Obtaining the terminal type, the manufacturer, the product serial number, and the MAC address of the target object;

[0117] binding the terminal type, the manufacturer, the product serial number, and the MAC address to form a third identity as a third identity of the target object;

[0118] Based on the third identity and the second network twin identity, the target mapping table is generated.

[0119] It should be noted that the second network twin identity refers to the network twin identity of the object, and the network twin of the object (Cybertwin) includes the identity of the object, the identity of the owner, and the data identity of the person, and the like.

[0120] It should be noted that the third identity refers to the identity of the object, and the third heterogeneous terminal refers to the heterogeneous terminal of the object.

[0121] In an embodiment, when the access instruction of the heterogeneous terminal is received, the terminal identity of the heterogeneous terminal is obtained, including:

[0122] When the access instruction of the third heterogeneous terminal is received, the target object corresponding to the third heterogeneous terminal is obtained.

[0123] The third identity of the target object is taken as the terminal identity of the heterogeneous terminal of the object.

[0124] The judgment whether the network twin identity corresponding to the terminal identity exists in the target mapping table includes:

[0125] It is judged whether the second network twin identity corresponding to the terminal identity exists in the target mapping table.

[0126] It can be understood that the judgment whether the second network twin identity corresponding to the terminal identity exists in the target mapping table is the judgment whether the second network twin identity corresponding to the third identity exists in the target mapping table.

[0127] Step S40: after completing the security authentication of the heterogeneous terminal, a network request is initiated for the heterogeneous terminal, so that the heterogeneous terminal accesses the cloud native network.

[0128] In specific implementation, as shown in Figure 4 When the heterogeneous terminal such as human-machine-object needs to access the cloud native network, the terminal identity of the heterogeneous terminal such as human-machine-object is determined first, and then the network twin identity corresponding to the terminal identity is determined according to the mapping relationship table (i.e. the security authentication of the heterogeneous terminal such as human-machine-object is needed), after the authentication is completed, the network request is initiated for the heterogeneous terminal to access the cloud native network.

[0129] The embodiment obtains the terminal identifier of the heterogeneous terminal when receiving the access instruction of the heterogeneous terminal, judges whether the network twin identifier corresponding to the terminal identifier exists in the target mapping table, wherein the target mapping table comprises a one-to-one mapping relationship between the terminal identifier and the network twin identifier, completes the security authentication of the heterogeneous terminal when judging that the network twin identifier corresponding to the terminal identifier exists in the target mapping table, initiates the network request for the heterogeneous terminal after completing the security authentication of the heterogeneous terminal, and enables the heterogeneous terminal to access the cloud native network. Through the above manner, the support technology of man-machine-object intelligent interconnection in the cloud native network architecture can be provided, the core foundation of the intelligent interconnection, resource intercommunication, sharing and cooperation of man-machine-object in the cloud native network can be provided, the network twin identifier system is innovatively established based on the network twin, the heterogeneous terminal such as man-machine-object can access the cloud native network after determining the network twin identifier through the terminal identifier, and the network twin identifier corresponding to the heterogeneous terminal will not change with the change of time, place and access mode, thereby the continuity of mobile service can be ensured.

[0130] Reference Figure 5 , Figure 5 The flowchart of the second embodiment of the unified access method based on the network twin is shown.

[0131] Based on the first embodiment, the target mapping table further comprises a many-to-one mapping relationship between the second network twin identifier and the first network twin identifier; wherein, the unified access method based on the network twin further comprises the following steps before the step S30 in the embodiment:

[0132] Step S301: obtaining the terminal type, manufacturer, product serial number and MAC address of the target object.

[0133] Step S302: binding the terminal type, the manufacturer, the product serial number and the MAC address to form a third identifier as the third identity identifier of the target object.

[0134] Step S303: generating the target mapping table based on the third identity identifier, the second network twin identifier and the first network twin identifier.

[0135] It should be noted that the first network twin identifier refers to the network twin identifier of a person, the second network twin identifier refers to the network twin identifier of an object, the third identity identifier refers to the identity identifier of the object, the identity identifier of the object and the network twin identifier of the object form a one-to-one mapping relationship, the network twin identifier of the object and the network twin identifier of the person to which it belongs form a mapping relationship, the network twin identifier of the object and the network twin identifier of the person form a many-to-one mapping relationship, and the person can be a natural person or a legal person.

[0136] Step S304: upon receiving the access instruction of the third heterogeneous terminal, obtaining a target object corresponding to the third heterogeneous terminal.

[0137] Step S305: taking a third identity of the target object as a terminal identity of the third heterogeneous terminal.

[0138] Step S306: judging whether the target mapping table has a first network twin identity corresponding to the terminal identity.

[0139] It can be understood that the identity of the object can be determined through the one-to-one mapping relationship between the identity of the object and the network twin identity of the object in the target mapping table, and then the network twin identity of the person is determined through the many-to-one mapping relationship between the network twin identity of the object and the network twin identity of the person in the target mapping table.

[0140] Step S307: upon determining that the target mapping table has the first network twin identity corresponding to the second network twin identity, completing the security authentication of the heterogeneous terminal.

[0141] The embodiment obtains the terminal type, the manufacturer, the product serial number and the MAC address of the target object; takes a third identity formed by binding the terminal type, the manufacturer, the product serial number and the MAC address as the third identity of the target object; generates the target mapping table based on the third identity, the second network twin identity and the first network twin identity; takes the third identity of the target object as the terminal identity of the third heterogeneous terminal; judges whether the target mapping table has the second network twin identity corresponding to the terminal identity; upon determining that the target mapping table has the first network twin identity corresponding to the second network twin identity, completes the security authentication of the heterogeneous terminal. Through the above manner, the mapping relationship among the identity of the object, the network twin identity of the object and the network twin identity of the person is defined to perform the security authentication of the heterogeneous terminal of the object, so as to prevent the network security threat and the network security attack problem in the process of accessing the cloud native network.

[0142] Optionally, the target mapping table is generated based on the third identity and the second network twin identity; the third identity of the target object is taken as the terminal identity of the third heterogeneous terminal, it is judged that the target mapping table has the second network twin identity corresponding to the terminal identity, and the security authentication of the heterogeneous terminal is completed.

[0143] In addition, the embodiment of the present application also provides a storage medium, and the storage medium stores a network twin-based unified access program. The network twin-based unified access program is executed by a processor to implement the steps of the network twin-based unified access method.

[0144] Referring to Figure 6 , Figure 6 FIG. 1 is a structural block diagram of a first embodiment of a network twin-based unified access device according to the present application.

[0145] As Figure 6 shown in the figure, the network twin-based unified access device provided by the embodiment of the present application comprises:

[0146] An acquisition module 10 is configured to acquire a terminal identifier of a heterogeneous terminal when receiving an access instruction of the heterogeneous terminal.

[0147] A judgment module 20 is configured to judge whether a network twin identifier corresponding to the terminal identifier exists in a target mapping table, wherein the target mapping table comprises a one-to-one mapping relationship between the terminal identifier and the network twin identifier.

[0148] A completion module 30 is configured to complete security authentication of the heterogeneous terminal when judging that the network twin identifier corresponding to the terminal identifier exists in the target mapping table.

[0149] An initiation module 40 is configured to initiate a network request for the heterogeneous terminal after completing the security authentication of the heterogeneous terminal, so that the heterogeneous terminal accesses a cloud-native network.

[0150] It should be understood that the above is only for illustration, and does not constitute any limitation on the technical solutions of the present application. In specific applications, those skilled in the art can set it according to the needs, and the present application does not limit it.

[0151] The embodiment can provide support technology for intelligent interconnection of man-machine-thing in cloud native network architecture, provide core foundation for intelligent interconnection, resource intercommunication, sharing and cooperation of man-machine-thing in cloud native network, and establish a network twin identification system based on network twin, so that man-machine-thing and other heterogeneous terminals can access the cloud native network after determining the network twin identification through the terminal identification, and the network twin identification corresponding to the heterogeneous terminal will not change with time, place and access mode, thereby ensuring the continuity of mobile services.

[0152] In an embodiment, the heterogeneous terminal includes a first heterogeneous terminal, and the network twin identification includes a first network twin identification.

[0153] The judging module 20 is further configured to:

[0154] Obtain iris, fingerprint and ID information of a target person;

[0155] Bind the iris, the fingerprint and the ID information to form a first identification as a first identity of the target person;

[0156] Generate the target mapping table based on the first identity and the first network twin identification.

[0157] The terminal identification of the heterogeneous terminal is obtained when an access instruction of the heterogeneous terminal is received, and includes:

[0158] Obtain a target person corresponding to the first heterogeneous terminal when an access instruction of the first heterogeneous terminal is received.

[0159] Take the first identity of the target person as the terminal identification of the first heterogeneous terminal.

[0160] The judging module 20 is further configured to:

[0161] Judge whether the first network twin identification corresponding to the terminal identification exists in the target mapping table.

[0162] In an embodiment, the heterogeneous terminal comprises a second heterogeneous terminal, and the network twin identifier comprises a first network twin identifier; wherein

[0163] The judging module 20 is further configured to:

[0164] obtain a terminal type, a manufacturer, a product serial number, and a MAC address of the target machine;

[0165] bind the terminal type, the manufacturer, the product serial number, and the MAC address to form a second identifier as a second identity of the target machine;

[0166] generate the target mapping table based on the second identity and the first network twin identifier.

[0167] In an embodiment, the obtaining module 10 is further configured to:

[0168] obtain a target machine corresponding to the second heterogeneous terminal when an access instruction of the second heterogeneous terminal is received;

[0169] use the second identity of the target machine as a terminal identifier of the second heterogeneous terminal;

[0170] The judging module 20 is further configured to:

[0171] judge whether the terminal identifier corresponds to a first network twin identifier in the target mapping table.

[0172] In an embodiment, the heterogeneous terminal comprises a third heterogeneous terminal, and the network twin identifier comprises a second network twin identifier; wherein

[0173] The judging module 20 is further configured to:

[0174] obtain a terminal type, a manufacturer, a product serial number, and a MAC address of a target object;

[0175] bind the terminal type, the manufacturer, the product serial number, and the MAC address to form a third identifier as a third identity of the target object;

[0176] generate the target mapping table based on the third identity and the second network twin identifier.

[0177] In an embodiment, the obtaining module 10 is further configured to:

[0178] obtain a target object corresponding to the third heterogeneous terminal when an access instruction of the third heterogeneous terminal is received;

[0179] The third identity of the target object is taken as the terminal identity of the heterogeneous terminal;

[0180] The judging module 20 is further configured to:

[0181] determine whether the second network twin identity corresponding to the terminal identity exists in the target mapping table.

[0182] In an embodiment, the target mapping table further comprises a many-to-one mapping relationship between the second network twin identity and the first network twin identity; wherein,

[0183] The judging module 20 is further configured to:

[0184] obtain the terminal type, the manufacturer, the product serial number and the MAC address of the target object;

[0185] bind the terminal type, the manufacturer, the product serial number and the MAC address to form a third identity as the third identity of the target object;

[0186] generate the target mapping table based on the third identity, the second network twin identity and the first network twin identity;

[0187] The obtaining module 20 is further configured to:

[0188] when the access instruction of the third heterogeneous terminal is received, obtain the target object corresponding to the third heterogeneous terminal;

[0189] The third identity of the target object is taken as the terminal identity of the third heterogeneous terminal;

[0190] The judging module 20 is further configured to:

[0191] determine whether the first network twin identity corresponding to the terminal identity exists in the target mapping table.

[0192] When it is determined that the network twin identity corresponding to the terminal identity exists in the target mapping table, the security authentication of the heterogeneous terminal is completed, comprising:

[0193] When it is determined that the first network twin identity corresponding to the second network twin identity exists in the target mapping table, the security authentication of the heterogeneous terminal is completed.

[0194] It should be noted that the above-described workflow is only illustrative and does not limit the protection scope of the present application. In actual application, a person skilled in the art can select part or all of them to achieve the purpose of the embodiment according to actual needs, which is not limited herein.

[0195] In addition, technical details not described in detail in the present embodiment can be found in the unified access method based on network twinning provided by any embodiment of the present application, which will not be described here.

[0196] Furthermore, it is to be understood that the terms "including", "comprising", "consisting of", or variations thereof herein are intended to be broad and encompass the terms "consisting essentially of" and "consisting of". It is not intended that any of the foregoing terms be limited to the inclusion of only an amount or a percentage of an element or to the exclusion of other elements.

[0197] The above-mentioned serial numbers of the embodiments of the present application are only for description, and do not represent the advantages and disadvantages of the embodiments.

[0198] From the above description of the embodiments, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be realized by means of software and the necessary general hardware platform, of course, they can also be realized by hardware, but in many cases the former is a better embodiment. Based on such understanding, the technical solutions of the present application can be embodied in the form of a software product, which is stored in a storage medium (such as a read-only memory (ROM) / RAM, a magnetic disk, or an optical disk) and includes a number of instructions for making a terminal device (which can be a mobile phone, a computer, a server, or a network device, etc.) execute the methods described in the various embodiments of the present application.

[0199] The above is only the preferred embodiment of the present application, and does not limit the patent scope of the present application, and any equivalent structure or equivalent process transformation, or direct or indirect application in other related technical fields, which is made by using the content of the present application specification and drawings, is also included in the patent protection scope of the present application.

Claims

1. A unified access method based on network twinning, characterized in that, The unified access method based on network twinning comprises: Upon receiving an access instruction of a heterogeneous terminal, obtaining a terminal identifier of the heterogeneous terminal; determining whether a network twin identifier corresponding to the terminal identifier exists in a target mapping table, wherein the target mapping table comprises a one-to-one mapping relationship between terminal identifiers and network twin identifiers, the network twin identifier is a unique and unchangeable access identifier of the heterogeneous terminal in a cloud native network, and has no binding relationship with an IP address; Upon determining that the network twin identifier corresponding to the terminal identifier exists in the target mapping table, completing security authentication of the heterogeneous terminal; After completing the security authentication of the heterogeneous terminal, initiating a network request for the heterogeneous terminal based on the network twin identifier, so that the heterogeneous terminal accesses the cloud native network.

2. The method of claim 1, wherein, The heterogeneous terminal comprises a first heterogeneous terminal, and the network twin identifier comprises a first network twin identifier; wherein Before the determining whether the network twin identifier corresponding to the terminal identifier exists in the target mapping table, the method further comprises: obtaining iris, fingerprint and ID information of a target person; binding the iris, the fingerprint and the ID information to form a first identifier as a first identity identifier of the target person; generating the target mapping table based on the first identity identifier and the first network twin identifier; Upon receiving the access instruction of the first heterogeneous terminal, obtaining a target person corresponding to the first heterogeneous terminal; taking the first identity identifier of the target person as a terminal identifier of the first heterogeneous terminal; determining whether the first network twin identifier corresponding to the terminal identifier exists in the target mapping table. The heterogeneous terminal comprises a second heterogeneous terminal, and the network twin identifier comprises a first network twin identifier; wherein Before the determining whether the network twin identifier corresponding to the terminal identifier exists in the target mapping table, the method further comprises:

3. The method of claim 1, wherein, obtaining a terminal type, a manufacturer, a product serial number and a MAC address of a target machine; binding the terminal type, the manufacturer, the product serial number and the MAC address to form a second identifier as a second identity identifier of the target machine; generating the target mapping table based on the second identity identifier and the first network twin identifier. Upon receiving the access instruction of the second heterogeneous terminal, obtaining a target machine corresponding to the second heterogeneous terminal; taking the second identity identifier of the target machine as a terminal identifier of the second heterogeneous terminal; 4. The method of claim 3, wherein, determining whether the first network twin identifier corresponding to the terminal identifier exists in the target mapping table. The heterogeneous terminal comprises a third heterogeneous terminal, and the network twin identifier comprises a second network twin identifier; wherein ​ ​ ​ 5. The method of claim 1, wherein, ​ Before the judging whether the network twin identifier corresponding to the terminal identifier exists in the target mapping table, the method further comprises: obtaining a terminal type, a manufacturer, a product serial number and a MAC address of the target object; binding the terminal type, the manufacturer, the product serial number and the MAC address to form a third identifier as a third identity of the target object; generating the target mapping table based on the third identity and the second network twin identifier.

6. The method of claim 5, wherein, When the access instruction of the heterogeneous terminal is received, the terminal identifier of the heterogeneous terminal is obtained, comprising: When the access instruction of the third heterogeneous terminal is received, the target object corresponding to the third heterogeneous terminal is obtained; the third identity of the target object is taken as the terminal identifier of the third heterogeneous terminal; The judging whether the network twin identifier corresponding to the terminal identifier exists in the target mapping table comprises: judging whether the second network twin identifier corresponding to the terminal identifier exists in the target mapping table.

7. The method of claim 5, wherein, The target mapping table further comprises a one-to-many mapping relationship between the second network twin identifier and the first network twin identifier; wherein Before the judging whether the network twin identifier corresponding to the terminal identifier exists in the target mapping table, the method further comprises: obtaining a terminal type, a manufacturer, a product serial number and a MAC address of the target object; binding the terminal type, the manufacturer, the product serial number and the MAC address to form a third identifier as a third identity of the target object; generating the target mapping table based on the third identity, the second network twin identifier and the first network twin identifier; When the access instruction of the heterogeneous terminal is received, the terminal identifier of the heterogeneous terminal is obtained, comprising: When the access instruction of the third heterogeneous terminal is received, the target object corresponding to the third heterogeneous terminal is obtained; the third identity of the target object is taken as the terminal identifier of the third heterogeneous terminal; The judging whether the network twin identifier corresponding to the terminal identifier exists in the target mapping table comprises: judging whether the first network twin identifier corresponding to the terminal identifier exists in the target mapping table; When it is judged that the network twin identifier corresponding to the terminal identifier exists in the target mapping table, the security authentication of the heterogeneous terminal is completed, comprising: When it is judged that the first network twin identifier corresponding to the second network twin identifier exists in the target mapping table, the security authentication of the heterogeneous terminal is completed.

8. A unified access device based on network twinning, comprising: The unified access device based on network twin comprises: an obtaining module, configured to obtain the terminal identifier of the heterogeneous terminal when the access instruction of the heterogeneous terminal is received; a judging module, configured to judge whether the network twin identifier corresponding to the terminal identifier exists in the target mapping table, wherein the target mapping table comprises a one-to-one mapping relationship between the terminal identifier and the network twin identifier, and the network twin identifier is the unique and invariable access identifier of the heterogeneous terminal in the cloud native network, and has no binding relationship with the IP address; A completion module configured to complete the security authentication of the heterogeneous terminal when it is determined that the network twin identifier corresponding to the terminal identifier exists in the target mapping table; An initiation module configured to initiate a network request for the heterogeneous terminal based on the network twin identifier after the security authentication of the heterogeneous terminal is completed, so that the heterogeneous terminal accesses a cloud-native network.

9. A network-twinning based unified access device, characterized in that, The device comprises a memory, a processor, and a network twin-based unified access program stored on the memory and executable on the processor, and the network twin-based unified access program is configured to implement the steps of the network twin-based unified access method according to any one of claims 1 to 7.

10. A storage medium, characterized by The storage medium has a network twin-based unified access program stored thereon, and the network twin-based unified access program, when executed by a processor, implements the steps of the network twin-based unified access method according to any one of claims 1 to 7.

Citation Information

Patent Citations

  • Virtual-real fusion space authentication method for 4G network

    CN115567936A