Access control method, device, system and communication equipment for edge resource pool

By setting up switches and proxy nodes in the edge resource pool and utilizing the interaction between control nodes and proxy nodes to determine and send access control information, the problem of low MEC security is solved, unified management and control of switches and micro-isolation protection are achieved, and network security is improved.

CN116896747BActive Publication Date: 2025-10-03CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202310950722.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-07-31
Publication Date
2025-10-03
Estimated Expiration
2043-07-31

AI Technical Summary

Technical Problem

In the existing technology, the security protection mechanism of MEC has the problem of low security and may become the starting point of hacker attacks.

Method used

By setting up switches and proxy nodes in the edge resource pool and utilizing the interaction between the control node and the proxy node, access control information is determined and sent to achieve unified management and control of the switch and micro-isolation protection.

Benefits of technology

It improves the security of edge resource pool access control, realizes unified management and control and micro-isolation protection between switches, and enhances network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116896747B_ABST
    Figure CN116896747B_ABST
Patent Text Reader

Abstract

The present application relates to an access control method, apparatus, system, and communication device for an edge resource pool. The method comprises: determining first access control information for a switch in the edge resource pool in response to an access control request for the edge resource pool; using the first access control information to control access between the switches; and sending the first access control information to the proxy node corresponding to the switch in the edge resource pool, so that the proxy node performs access control on the switch based on the received first access control information. This method can improve the security of edge resource pool access control.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security technology, and in particular to an access control method, apparatus, system and communication equipment for an edge resource pool. Background Art

[0002] With the development of wireless communication technology, MEC (Multi-access Edge Computing) technology has emerged, which is cloud computing at the edge of the network. This technology deploys computing power closer to users, providing computing power and applications nearby, thereby improving the user service experience.

[0003] In existing technologies, the security protection mechanism for MEC continues the VPC (Virtual Private Cloud), security domain, network isolation and other means in traditional cloud computing, sinking security control from the network center to the edge. This method results in MEC being able to determine security protection measures only based on its own node information, which may lead to security vulnerabilities and become the starting point for hacker attacks.

[0004] Therefore, the current access control technology for edge resource pools has the problem of low security. Summary of the Invention

[0005] Based on this, it is necessary to provide an access control method, device, system, communication equipment, computer-readable storage medium and computer program product for an edge resource pool that can improve security in response to the above technical problems.

[0006] In a first aspect, the present application provides an access control method for an edge resource pool, which is applied to a control node, the control node being connected to an edge resource pool, the edge resource pool being provided with a switch and a proxy node corresponding to the switch; the method comprising:

[0007] In response to an access control request for the edge resource pool, determining first access control information of the switches in the edge resource pool, wherein the first access control information is used to control access between the switches;

[0008] The first access control information is sent to the proxy node corresponding to the switch in the edge resource pool, so that the proxy node performs access control on the switch according to the received first access control information.

[0009] In one embodiment, before determining the first access control information of the switch in the edge resource pool in response to the access control request for the edge resource pool, the method further includes:

[0010] Upon receiving a registration request for an edge resource from the edge resource pool, or upon detecting the edge resource of the edge resource pool, acquiring resource information of the edge resource;

[0011] The resource information is registered to obtain registered resource information of the edge resource pool; the registered resource information is used to determine the first access control information.

[0012] In one embodiment, after sending the first access control information to the proxy node corresponding to the switch in the edge resource pool, the method further includes:

[0013] Upon receiving an identity authentication request from a target user, performing identity authentication on the target user;

[0014] If the identity authentication is successful, determining second access control information of the switch; the second access control information is used to control access between the target user and the switch;

[0015] The second access control information is sent to the proxy node corresponding to the switch, so that the proxy node performs access control on the switch according to the received second access control information.

[0016] In one embodiment, after sending the second access control information to the proxy node corresponding to the switch, the method further includes:

[0017] Acquire user traffic of the target user and resource pool traffic of the edge resource pool corresponding to the second access control information;

[0018] In a case where the user traffic does not match the resource pool traffic, an alarm signal for the second access control information is generated.

[0019] In a second aspect, the present application further provides an access control method for an edge resource pool, which is applied to a proxy node, wherein the proxy node is set in the edge resource pool and corresponds to a switch in the edge resource pool, and the edge resource pool is connected to a control node; the method includes:

[0020] receiving first access control information sent by the control node; the first access control information is information for controlling access between the switches in the edge resource pool, determined by the control node in response to an access control request for the edge resource pool;

[0021] Access control is performed on the switch corresponding to the proxy node according to the received first access control information.

[0022] In one embodiment, performing access control on the switch corresponding to the proxy node according to the received first access control information includes:

[0023] Upon receiving the first access control information, performing access permission verification on the switch corresponding to the proxy node;

[0024] When the access authority verification is passed, access control is performed on the switch.

[0025] In a third aspect, the present application further provides an access control device for an edge resource pool, which is applied to a control node, the control node being connected to the edge resource pool, the edge resource pool being provided with a switch and a proxy node corresponding to the switch; the device comprising:

[0026] a determination module, configured to determine first access control information of the switches in the edge resource pool in response to an access control request for the edge resource pool; the first access control information is used to control access between the switches;

[0027] The sending module is configured to send the first access control information to the proxy node corresponding to the switch in the edge resource pool, so that the proxy node performs access control on the switch according to the received first access control information.

[0028] In a fourth aspect, the present application further provides an access control device for an edge resource pool, which is applied to a proxy node, wherein the proxy node is arranged in the edge resource pool and corresponds to a switch in the edge resource pool, and the edge resource pool is connected to a control node; the device includes:

[0029] a receiving module, configured to receive first access control information sent by the control node; the first access control information is information for controlling access between the switches in the edge resource pool, determined by the control node in response to an access control request for the edge resource pool;

[0030] A control module is configured to perform access control on the switch corresponding to the proxy node according to the received first access control information.

[0031] In a fifth aspect, the present application further provides an access control system for an edge resource pool, the system comprising a control node and an agent node, the control node being connected to the edge resource pool, the edge resource pool being provided with a switch and the agent node corresponding to the switch;

[0032] The control node is configured to determine, in response to an access control request for the edge resource pool, first access control information of the switch in the edge resource pool, and send the first access control information to the proxy node in the edge resource pool; the first access control information is used to control access between the switches;

[0033] The proxy node is configured to perform access control on the switch corresponding to the proxy node according to the received first access control information.

[0034] In a sixth aspect, the present application further provides a communication device. The communication device includes a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, the following steps are implemented:

[0035] In response to an access control request for the edge resource pool, determining first access control information of the switches in the edge resource pool, wherein the first access control information is used to control access between the switches;

[0036] The first access control information is sent to the proxy node corresponding to the switch in the edge resource pool, so that the proxy node performs access control on the switch according to the received first access control information.

[0037] In a seventh aspect, the present application further provides a computer-readable storage medium having a computer program stored thereon, which, when executed by a processor, implements the following steps:

[0038] In response to an access control request for the edge resource pool, determining first access control information of the switches in the edge resource pool, wherein the first access control information is used to control access between the switches;

[0039] The first access control information is sent to the proxy node corresponding to the switch in the edge resource pool, so that the proxy node performs access control on the switch according to the received first access control information.

[0040] In an eighth aspect, the present application further provides a computer program product. The computer program product includes a computer program that, when executed by a processor, implements the following steps:

[0041] In response to an access control request for the edge resource pool, determining first access control information of the switches in the edge resource pool, wherein the first access control information is used to control access between the switches;

[0042] The first access control information is sent to the proxy node corresponding to the switch in the edge resource pool, so that the proxy node performs access control on the switch according to the received first access control information.

[0043] The access control method, apparatus, system, communication equipment, storage medium and computer program product of the above-mentioned edge resource pool determine the first access control information for controlling access between switches in the edge resource pool in response to an access control request for the edge resource pool, and send the first access control information to the proxy node corresponding to the switch in the edge resource pool; by setting a corresponding proxy node for each switch in the edge resource pool and enabling the control node to interact with the proxy node, while achieving unified control of each switch in the edge resource pool, micro-isolation protection function is provided between each switch, thereby improving the security of access control of the edge resource pool. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] Figure 1 FIG. 1 is an application environment diagram of an edge resource pool access control method according to an embodiment;

[0045] Figure 2 1 is a flow chart of an edge resource pool access control method according to an embodiment;

[0046] Figure 3 1 is a flow chart of an access control method for an edge resource pool in another embodiment;

[0047] Figure 4 This is a structural block diagram of a public unified micro-isolation management and control system implemented on MEC in one embodiment;

[0048] Figure 5 This is a flowchart of a method for implementing a common unified micro-isolation control method on MEC in one embodiment;

[0049] Figure 6 1 is a flow chart of an access control method for an edge resource pool in another embodiment;

[0050] Figure 7 is a structural block diagram of an access control device for an edge resource pool in one embodiment;

[0051] Figure 8 is a structural block diagram of an access control device for an edge resource pool in another embodiment;

[0052] Figure 9 is a structural block diagram of an access control system for an edge resource pool in one embodiment;

[0053] Figure 10 FIG. 4 is a diagram showing the internal structure of a communication device in one embodiment. DETAILED DESCRIPTION

[0054] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.

[0055] The access control method for the edge resource pool provided in the embodiment of the present application can be applied to Figure 1 In the application environment shown. The control node 102 can be a terminal or a server, deployed in a management-level cloud resource pool, for example, a provincial / municipal cloud resource pool; the edge resource pool 104 can be a MEC (Multi-access Edge Computing) cloud resource pool, in which a physical switch and OVS (Open vSwitch, virtual switch), physical switch and OVS all correspond to the agent node 106. For example, agent software can be installed on the physical switch or OVS, and the physical switch or OVS installed with the agent software is used as the agent node 106; the control node 102 is connected to the edge resource pool 104 through each agent node 106, and the user terminal is connected to the 5GC (core network) through the RAN (access network). The 5GC is equipped with network elements such as AMF (access and mobility management function), SMF (session management function), NEF (network open function), etc. The UPF (user plane function) network element is set in the edge resource pool 104. The user terminal is also connected to the UPF network element in the edge resource pool 104 through the RAN. In addition to the physical switch, OVS and UPF, the edge resource pool 104 is also equipped with MEP (Message Exchange Pattern), cloud hardware and cloud operating system.

[0056] In one embodiment, Figure 2 As shown, a method for access control of an edge resource pool is provided, which is applied to Figure 1 Taking the control node 102 in FIG. 1 as an example, the method includes the following steps:

[0057] Step S210 : In response to an access control request for an edge resource pool, determining first access control information of switches in the edge resource pool; the first access control information is used to control access between switches.

[0058] The access control request may be a signal requesting access control to the edge resource pool.

[0059] The first access control information may be access control information between switches.

[0060] In a specific implementation, resource information of each switch in the edge resource pool can be obtained in advance and stored in the control node. The user terminal sends an access control request for the edge resource pool to the control node. The control node responds to the received access control request and generates first access control information of the switch based on the pre-stored resource information of each switch in the edge resource pool to control access between switches.

[0061] In actual applications, agent software can be installed on the physical switches and OVS of the MEC cloud resource pool to enable micro-isolation protection functions between each switch. Control nodes can also be deployed on the management-level cloud resource pool to uniformly manage and control each switch in the MEC cloud resource pool. For example, the resource information of each switch in the MEC cloud resource pool can be pre-registered in the control node in the management-level cloud resource pool. In response to the micro-isolation management and control requirements sent by the user terminal, the control node can uniformly generate east-west micro-isolation access control policies between each switch in the MEC cloud resource pool based on the registered resource information.

[0062] Step S220: Send the first access control information to the proxy node corresponding to the switch in the edge resource pool, so that the proxy node performs access control on the switch according to the received first access control information.

[0063] In a specific implementation, after generating the first access control information of the switch, the control node can determine the proxy node corresponding to the switch and send the first access control information to the proxy node. The proxy node verifies the access rights of the switch based on the first access control information. If the verification passes, the switch is accessed; otherwise, if the verification fails, the switch is not accessed.

[0064] In actual applications, after generating the east-west micro-isolation access control policy, the control node can send the east-west micro-isolation access control policy to each physical switch or OVS installed with agent software. The physical switch or OVS executes the east-west micro-isolation access control through the agent software. For example, the agent software can verify the access rights of the physical switch or OVS. If the verification is successful, the physical switch or OVS will be given east-west micro-isolation access. Otherwise, if the verification fails, the physical switch or OVS will not be given east-west micro-isolation access.

[0065] The access control method of the above-mentioned edge resource pool determines the first access control information for controlling access between switches in the edge resource pool in response to an access control request for the edge resource pool, and sends the first access control information to the proxy node corresponding to the switch in the edge resource pool; by setting a corresponding proxy node for each switch in the edge resource pool and enabling the control node to interact with the proxy node, while achieving unified control of each switch in the edge resource pool, micro-isolation protection function is provided between each switch, thereby improving the security of access control of the edge resource pool.

[0066] In one embodiment, before the above step S210, it may further specifically include: when a registration request for edge resources from an edge resource pool is received, or when edge resources of an edge resource pool are detected, obtaining resource information of the edge resources; registering the resource information to obtain registered resource information of the edge resource pool; and using the registered resource information to determine the first access control information.

[0067] The registration request may be a signal requesting to register resource information of the edge resource.

[0068] The edge resource may be a storage resource in an edge resource pool.

[0069] In a specific implementation, when a new edge resource is present in the edge resource pool, the edge resource pool may send a registration request to the control node for the new edge resource. Upon receiving the registration request, the control node may register the resource information of the new edge resource on the control node, thereby forming the registered resource information of the edge resource on the control node. Alternatively, the control node may detect whether there is a new edge resource in the edge resource pool according to a preset period. If a new edge resource is detected in the edge resource pool, the resource information of the new edge resource may be registered on the control node, thereby forming the registered resource information of the edge resource on the control node. Upon receiving an access control request, the control node may determine first access control information based on the registered resource information of the edge resource in response to the access control request.

[0070] In actual applications, when the MEC cloud resource pool releases a new virtual machine or a new container, the MEC cloud resource pool can register the new virtual machine or new container on the control node of the management-level cloud resource pool. The control node of the management-level cloud resource pool can also register the new virtual machine or new container through a self-discovery program, so that in response to the micro-isolation control requirements sent by the user terminal, the control node can uniformly manage the virtual machines and containers in the MEC cloud resource pool based on the registration information of the virtual machines and containers.

[0071] In this embodiment, when a registration request for edge resources is received from the edge resource pool, or when edge resources of the edge resource pool are detected, resource information of the edge resources is obtained; the resource information is registered to obtain the registered resource information of the edge resource pool, so that the control node can obtain the resource information of all edge resources in the edge resource pool, uniformly manage all edge resources, meet the micro-isolation management and control requirements of edge resources, and thereby ensure the security of access control of the edge resource pool.

[0072] In one embodiment, after step S220, the following steps may further include: upon receiving an identity authentication request sent by the target user, performing identity authentication on the target user; if the identity authentication passes, determining second access control information of the switch; the second access control information is used to control access between the target user and the switch; and sending the second access control information to a proxy node corresponding to the switch, so that the proxy node performs access control on the switch based on the received second access control information.

[0073] The target user may be a user of the edge resource pool.

[0074] The identity authentication request may be a signal requesting identity authentication.

[0075] The second access control information may be access control information between the switch and the user.

[0076] In a specific implementation, the target user can send an identity authentication request to the control node. When the control node receives the identity authentication request, it performs identity authentication on the target user. If the authentication fails, there is no need to determine the second access control information between the target user and the target switch. Otherwise, if the authentication passes, the second access control information is determined and sent to the target proxy node corresponding to the target switch. The target proxy node performs access control on the target switch according to the received second access control information. Specifically, the target proxy node can verify the access permission of the target switch according to the second access control information. If the verification passes, the target switch is accessed. Otherwise, if the verification fails, the target switch is not accessed.

[0077] The target switch may be a switch corresponding to the target user in the north-south access control policy, and the target proxy node may be a proxy node corresponding to the target switch.

[0078] In actual applications, after the user accesses the mobile network through 5GC authentication, a PDN (Packet Data Network) connection to the UPF is established. When the user accesses the MEC cloud resource pool through the security gateway (physical switch), the user can initiate identity authentication to the control node through the security gateway. If the authentication is successful, the control node can open the north-south access permission policy of a specific VLAN (Virtual Local Area Network) and send it to the security gateway. Otherwise, if the authentication fails, the control node will not open the north-south access permission policy.

[0079] In this embodiment, upon receiving an identity authentication request sent by the target user, the target user is authenticated; if the identity authentication is passed, the second access control information of the switch is determined; the second access control information is used to control the access between the target user and the switch; the second access control information is sent to the proxy node corresponding to the switch, so that the north-south access of the edge resource pool can be uniformly micro-isolated and controlled, further improving the security of the access control of the edge resource pool.

[0080] In one embodiment, after the above-mentioned step of sending the second access control information to the proxy node corresponding to the switch, the method may further include: obtaining the user traffic of the target user and the resource pool traffic of the edge resource pool corresponding to the second access control information; and generating an alarm signal for the second access control information when the user traffic does not match the resource pool traffic.

[0081] The user traffic can be the target user's transmission traffic per unit time, and the resource pool traffic can be the edge resource pool's transmission traffic per unit time.

[0082] In a specific implementation, after sending the second access control information to the target proxy node, the target proxy node controls the access between the target user and the target switch based on the received second access control information. Afterwards, the control node can obtain the user traffic of the target user and the resource pool traffic of the edge resource pool, and compare the user traffic with the resource pool traffic. If the user traffic is compatible with the resource pool traffic, no processing is required. Otherwise, if the user traffic is not compatible with the resource pool traffic, an alarm signal can be generated for the second access control information.

[0083] In practical applications, control nodes can collaborate with proxy nodes to monitor edge resource pools and user traffic in real time. If abnormal network behavior is detected, dynamic access control policies are generated to block it. For example, proxy nodes can report resource pool traffic to the control node in real time, and user terminals can also report transmission logs containing user traffic to the control node in real time. The control node generates dynamic access control policies based on resource pool and user traffic and sends them to the switch. Specifically, if user traffic is significantly greater than resource pool traffic, the resource pool traffic can be appropriately increased. If user traffic is significantly less than resource pool traffic, the resource pool traffic can be appropriately reduced. If user traffic is consistent with resource pool traffic, there is no need to adjust the access control policy.

[0084] In this embodiment, by obtaining the user traffic of the target user and the resource pool traffic of the edge resource pool corresponding to the second access control information; when the user traffic does not match the resource pool traffic, an alarm signal for the second access control information is generated, so that abnormal situations of the second access control information can be discovered in time, and corresponding strategies can be taken in time to ensure the reliability of access control.

[0085] In one embodiment, the control node is deployed in a resource pool that is a level above the edge resource pool.

[0086] Among them, the upper-level resource pool of the edge resource pool can be a management-level cloud resource pool, for example, a provincial / municipal cloud resource pool.

[0087] In a specific implementation, the control node can be deployed in the upper-level management-level cloud resource pool of the edge resource pool.

[0088] In this embodiment, by deploying the control node in the upper-level resource pool of the edge resource pool, the edge cloud resource pool can be uniformly micro-isolated and managed, thereby improving the security of edge resource pool access control.

[0089] In one embodiment, Figure 3 As shown, a method for access control of an edge resource pool is provided, which is applied to Figure 1 Taking the proxy node 106 in FIG. 1 as an example, the method includes the following steps:

[0090] Step S310: receiving first access control information sent by a control node; the first access control information is information for controlling access between switches in an edge resource pool, determined by the control node in response to an access control request for the edge resource pool;

[0091] Step S320: Perform access control on the switch corresponding to the proxy node according to the received first access control information.

[0092] In a specific implementation, the control node can pre-acquire resource information of each switch in the edge resource pool and store it. The user terminal sends an access control request for the edge resource pool to the control node. In response to the received access control request, the control node generates first access control information of the switch based on the pre-stored resource information of each switch in the edge resource pool, and sends the first access control information to the proxy node. The proxy node verifies the access permission of the corresponding switch based on the first access control information. If the verification is successful, the switch is accessed. Otherwise, if the verification fails, the switch is not accessed.

[0093] In this embodiment, by receiving the first access control information sent by the control node, access control is performed on the switch corresponding to the proxy node based on the received first access control information. Corresponding proxy nodes can be set for each switch in the edge resource pool, and the control node and the proxy node can be interacted with each other. This allows for unified management and control of each switch in the edge resource pool while providing micro-isolation protection functions between each switch, thereby improving the security of access control of the edge resource pool.

[0094] In one embodiment, the above step S320 may specifically include: upon receiving the first access control information, performing access permission verification on the switch corresponding to the proxy node; and upon passing the access permission verification, performing access control on the switch.

[0095] In a specific implementation, when the proxy node receives the first access control information, it can determine the switch corresponding to the first access control information and perform access permission verification on the switch. If the verification passes, the proxy node accesses the switch; otherwise, if the verification fails, the proxy node does not access the switch.

[0096] In this embodiment, by verifying the access rights of the switch corresponding to the proxy node when the first access control information is received; and performing access control on the switch when the access rights verification passes, micro-isolation management and control between the switches in the edge resource pool can be achieved, thereby improving the security of the access control of the edge resource pool.

[0097] In order to facilitate those skilled in the art to have a deeper understanding of the embodiments of the present application, a specific example will be used for illustration below.

[0098] Figure 4 Provides a structural diagram of a public unified micro-isolation control system on MEC. Figure 4In order to achieve public and unified micro-isolation management and control capabilities on MEC, agents can be installed on the OVS and physical switches of the MEC cloud resource pool to enable the OVS and physical switches to have micro-isolation protection functions. Deploy a policy decision point (control node 102) in the provincial / municipal cloud resource pool (management-level cloud resource pool) to uniformly manage the MEC cloud resource pool OVS and physical switches. The virtual machines / container resources in the MEC cloud resource pool are isolated from each other by default. Users need to submit MEC resource micro-isolation access requirements to the operator. Based on user needs, the operator generates a micro-isolation policy based on VLAN QinQ (a technology that encapsulates the user's private network VLAN label in the public network VLAN label, allowing the message to pass through the operator's backbone network with two layers of VLAN labels) through the policy decision point and sends it to the corresponding OVS or physical switch to provide MEC resource micro-isolation protection services.

[0099] For user identity-based access control, users can access the mobile network through 5GC authentication and establish a PDN connection to the UPF. When users access MEC resources through the security gateway (physical switch), they need to initiate identity authentication to the policy decision point through the security gateway. After the authentication is passed, the policy decision point opens the specific VLAN access permission policy and sends it to the security gateway.

[0100] In order to improve the security processing rate of the MEC resource pool, the policy decision point can also be linked with the agent to monitor the resource pool traffic in real time, generate dynamic access control policies when abnormal network behavior is found, and block abnormal traffic.

[0101] Figure 5 Provides a flow chart of the method for implementing a common and unified micro-isolation control method on MEC. Figure 5 , implement a public unified micro-isolation control method on MEC. The specific process is as follows:

[0102] Step 1: Install agents on the MEC resource pool OVS and physical switches to enable micro-isolation protection.

[0103] Step 2: Deploy policy decision points in provincial / municipal resource pools to implement unified micro-isolation management and control of MEC cloud resource pool OVS and physical switches.

[0104] Step 3: After a new VM / container is released in the MEC resource pool, it is managed uniformly by the policy decision point through registration or self-discovery. The user submits the VM / container resource micro-isolation control requirements to the operator.

[0105] Step 4: The operator analyzes enterprise customer needs, uses policy decision points to uniformly generate micro-segmentation access control policies, and distributes them to physical switches or OVS agents. The physical switches or OVS agents then execute micro-segmentation access control.

[0106] Step 5: After the user accesses the mobile network through 5GC authentication, a PDN connection to the UPF is established. When the user accesses MEC resources through the security gateway (physical switch), the security gateway must initiate identity authentication to the policy decision point. After the authentication is passed, the policy decision point opens the specific VLAN access permission policy and sends it to the security gateway.

[0107] In step 6, the policy decision point monitors the resource pool and user traffic in real time by coordinating with the agent. If abnormal network behavior is found, a dynamic access control policy is generated to block abnormal traffic.

[0108] In one embodiment, Figure 6 As shown, a method for access control of an edge resource pool is provided, which is applied to Figure 1 Taking the control node 102 in FIG. 1 as an example, the method includes the following steps:

[0109] Step S601: upon receiving a registration request for an edge resource from an edge resource pool, or upon detecting an edge resource in an edge resource pool, obtaining resource information of the edge resource;

[0110] Step S602: Register resource information to obtain registered resource information of the edge resource pool; the registered resource information is used to determine the first access control information;

[0111] Step S603: In response to the access control request for the edge resource pool, determining first access control information of the switches in the edge resource pool; the first access control information is used to control access between switches;

[0112] Step S604: Send the first access control information to the proxy node corresponding to the switch in the edge resource pool, so that the proxy node performs access control on the switch according to the received first access control information;

[0113] Step S605: upon receiving the identity authentication request sent by the target user, perform identity authentication on the target user;

[0114] Step S606: If the identity authentication is successful, determine the second access control information of the switch; the second access control information is used to control access between the target user and the switch;

[0115] Step S607: Send the second access control information to the proxy node corresponding to the switch, so that the proxy node performs access control on the switch according to the received second access control information;

[0116] Step S608: acquiring the user traffic of the target user and the resource pool traffic of the edge resource pool corresponding to the second access control information;

[0117] Step S609: When the user traffic does not match the resource pool traffic, an alarm signal for the second access control information is generated.

[0118] In a specific implementation, the edge resource pool can send a registration request for edge resources to the control node. The control node registers the edge resources upon receiving the registration request. Alternatively, the control node can register the edge resources upon detecting edge resources in the edge resource pool and obtain the registered resource information of the edge resource pool after registration. Based on the user's access control request, the control node can generate first access control information for east-west micro-isolation and send the first access control information to the proxy node. The proxy node then performs access control on the corresponding switch. The target user can also send an identity authentication request to the control node through the switch. Upon receiving the identity authentication request, the control node authenticates the target user. If the authentication fails, no processing is required. Otherwise, if the authentication passes, the control node determines the access control information between the target user and the target switch, generates second access control information for north-south micro-isolation, and sends the second access control information to the target proxy node corresponding to the target switch. The target proxy node then performs access control on the target switch. The control node can also obtain user traffic and resource pool traffic in real time. If the user traffic and resource pool traffic match, no processing is required. Otherwise, if the user traffic and resource pool traffic do not match, an alarm signal can be generated to adjust the second access control information.

[0119] It should be understood that, although the various steps in the flowcharts involved in the various embodiments described above are displayed in sequence according to the instructions of the arrows, these steps are not necessarily executed in sequence in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and these steps can be executed in other orders. Moreover, at least a portion of the steps in the flowcharts involved in the various embodiments described above can include multiple steps or multiple stages, and these steps or stages are not necessarily executed and completed at the same time, but can be executed at different times, and the execution order of these steps or stages is not necessarily to be carried out in sequence, but can be executed in turn or alternately with other steps or at least a portion of steps or stages in other steps.

[0120] Based on the same inventive concept, the embodiments of the present application also provide an access control device and system for an edge resource pool for implementing the access control method for the edge resource pool involved above. The implementation solution provided by the device and system to solve the problem is similar to the implementation solution described in the above method. Therefore, the specific limitations in the embodiments of the access control device and system for one or more edge resource pools provided below can be found in the limitations of the access control method for the edge resource pool above, and will not be repeated here.

[0121] In one embodiment, Figure 7 As shown, an access control device 700 for an edge resource pool is provided, which is applied to a control node, the control node being connected to an edge resource pool, wherein a switch and a proxy node corresponding to the switch are provided in the edge resource pool; the device includes: a determination module 710 and a sending module 720, wherein:

[0122] A determination module 710 is configured to determine first access control information of the switches in the edge resource pool in response to an access control request for the edge resource pool; the first access control information is used to control access between the switches;

[0123] The sending module 720 is configured to send the first access control information to the proxy node corresponding to the switch in the edge resource pool, so that the proxy node performs access control on the switch according to the received first access control information.

[0124] In one embodiment, the access control device 700 of the edge resource pool further includes:

[0125] a resource acquisition module, configured to, upon receiving a registration request for an edge resource from the edge resource pool, or upon detecting the edge resource in the edge resource pool, acquire resource information of the edge resource;

[0126] A resource registration module is used to register the resource information to obtain the registered resource information of the edge resource pool; the registered resource information is used to determine the first access control information.

[0127] In one embodiment, the access control device 700 of the edge resource pool further includes:

[0128] An identity authentication module is used to authenticate the target user upon receiving an identity authentication request from the target user;

[0129] A control information module, configured to determine second access control information of the switch when identity authentication is successful; the second access control information is used to control access between the target user and the switch;

[0130] The access control module is configured to send the second access control information to the proxy node corresponding to the switch, so that the proxy node performs access control on the switch according to the received second access control information.

[0131] In one embodiment, the access control device 700 of the edge resource pool further includes:

[0132] a traffic acquisition module, configured to acquire the user traffic of the target user and the resource pool traffic of the edge resource pool corresponding to the second access control information;

[0133] An alarm signal module is used to generate an alarm signal for the second access control information when the user traffic does not match the resource pool traffic.

[0134] In one embodiment, the control node is deployed in a resource pool at an upper level of the edge resource pool.

[0135] In one embodiment, Figure 8 As shown, an access control device 800 for an edge resource pool is provided, which is applied to a proxy node. The proxy node is set in the edge resource pool and corresponds to a switch in the edge resource pool. The edge resource pool is connected to a control node. The device includes: a receiving module 810 and a control module 820, wherein:

[0136] A receiving module 810 is configured to receive first access control information sent by the control node; the first access control information is information for controlling access between the switches in the edge resource pool, determined by the control node in response to an access control request for the edge resource pool;

[0137] The control module 820 is configured to perform access control on the switch corresponding to the proxy node according to the received first access control information.

[0138] In one embodiment, the control module 820 is further configured to perform access permission verification on the switch corresponding to the proxy node upon receiving the first access control information; and perform access control on the switch if the access permission verification passes.

[0139] In one embodiment, Figure 9As shown, an access control system 900 for an edge resource pool is provided. The system includes: a control node 910 and an agent node 920. The control node is connected to the edge resource pool. The edge resource pool is provided with a switch and the agent node corresponding to the switch, wherein:

[0140] The control node 910 is configured to determine, in response to an access control request for the edge resource pool, first access control information of the switch in the edge resource pool, and send the first access control information to the proxy node in the edge resource pool; the first access control information is used to control access between the switches;

[0141] The proxy node 920 is configured to perform access control on the switch corresponding to the proxy node according to the received first access control information.

[0142] Each module in the aforementioned edge resource pool access control device and system can be implemented in whole or in part through software, hardware, or a combination thereof. Each module can be embedded in or independent of a processor in a communication device in hardware form, or can be stored in a memory in the communication device in software form, so that the processor can call and execute the corresponding operations of each module.

[0143] In one embodiment, a communication device is provided. The communication device may be a server, and its internal structure diagram may be as follows: Figure 10 As shown. The communication device includes a processor, a memory, an input / output interface (Input / Output, abbreviated as I / O) and a communication interface. The processor, memory and input / output interface are connected through a system bus, and the communication interface is connected to the system bus through the input / output interface. The processor of the communication device is used to provide computing and control capabilities. The memory of the communication device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The database of the communication device is used to store access control data of the edge resource pool. The input / output interface of the communication device is used to exchange information between the processor and an external device. The communication interface of the communication device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, an access control method for the edge resource pool is implemented.

[0144] Those skilled in the art will understand that Figure 10The structure shown in the figure is only a block diagram of a part of the structure related to the scheme of the present application, and does not constitute a limitation on the communication device to which the scheme of the present application is applied. The specific communication device may include more or fewer components than shown in the figure, or combine certain components, or have a different component arrangement.

[0145] In one embodiment, a communication device is further provided, including a memory and a processor. The memory stores a computer program, and the processor implements the steps in the above method embodiments when executing the computer program.

[0146] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps in the above-mentioned method embodiments are implemented.

[0147] In one embodiment, a computer program product is provided, including a computer program, which implements the steps in the above method embodiments when executed by a processor.

[0148] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions.

[0149] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, database or other media used in the embodiments provided in this application may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory, optical memory, high-density embedded non-volatile memory, resistive random access memory (ReRAM), magnetic random access memory (MRAM), ferroelectric random access memory (FRAM), phase change memory (PCM), graphene memory, etc. Volatile memory may include random access memory (RAM) or external cache memory, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM). The database involved in the various embodiments provided herein may include at least one of a relational database and a non-relational database. Non-relational databases may include, but are not limited to, distributed databases based on blockchains. The processor involved in the various embodiments provided herein may be, but are not limited to, a general-purpose processor, a central processing unit, a graphics processing unit, a digital signal processor, a programmable logic unit, a data processing logic unit based on quantum computing, and the like.

[0150] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0151] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person of ordinary skill in the art may make various modifications and improvements without departing from the spirit of the present application, and these modifications and improvements fall within the scope of protection of the present application. Therefore, the scope of protection of the present application shall be determined by the appended claims.

Claims

1. A method for controlling access to an edge resource pool, characterized in that: Applied to a control node, the control node is connected to an edge resource pool, the edge resource pool is provided with a switch and a proxy node corresponding to the switch; the method includes: In response to an access control request for the edge resource pool, determining first access control information of the switches in the edge resource pool, wherein the first access control information is used to control access between the switches; Sending the first access control information to the proxy node corresponding to the switch in the edge resource pool, so that the proxy node performs access control on the switch according to the received first access control information; Upon receiving an identity authentication request from a target user, performing identity authentication on the target user; If the identity authentication is successful, determining second access control information of the switch; the second access control information is used to control access between the target user and the switch; The second access control information is sent to the proxy node corresponding to the switch, so that the proxy node performs access control on the switch according to the received second access control information.

2. The method according to claim 1, characterized in that Before determining the first access control information of the switch in the edge resource pool in response to the access control request for the edge resource pool, the method further includes: Upon receiving a registration request for an edge resource from the edge resource pool, or upon detecting the edge resource of the edge resource pool, acquiring resource information of the edge resource; The resource information is registered to obtain registered resource information of the edge resource pool; the registered resource information is used to determine the first access control information.

3. The method according to claim 1, characterized in that After sending the second access control information to the proxy node corresponding to the switch, the method further includes: Acquire user traffic of the target user and resource pool traffic of the edge resource pool corresponding to the second access control information; In a case where the user traffic does not match the resource pool traffic, an alarm signal for the second access control information is generated.

4. The method according to claim 1, wherein The control node is deployed in a resource pool at an upper level of the edge resource pool.

5. A method for controlling access to an edge resource pool, characterized in that: Applied to a proxy node, the proxy node is set in an edge resource pool and corresponds to a switch in the edge resource pool, and the edge resource pool is connected to a control node; the method includes: receiving first access control information sent by the control node; the first access control information is information for controlling access between the switches in the edge resource pool, determined by the control node in response to an access control request for the edge resource pool; performing access control on the switch corresponding to the proxy node according to the received first access control information; receiving second access control information sent by the control node; the second access control information is information for controlling access between the target user and the switch determined by the control node when the target user passes the identity authentication request of the target user; Access control is performed on the switch corresponding to the proxy node according to the received second access control information.

6. The method according to claim 5, characterized in that The performing access control on the switch corresponding to the proxy node according to the received first access control information includes: Upon receiving the first access control information, performing access permission verification on the switch corresponding to the proxy node; When the access authority verification is passed, access control is performed on the switch.

7. The method according to claim 5, characterized in that The method further comprises: Reporting resource pool traffic to the control node in real time; the control node generating a dynamic access control policy based on the resource pool traffic and user traffic.

8. An access control device for an edge resource pool, characterized in that: Applied to a control node, the control node is connected to an edge resource pool, the edge resource pool is provided with a switch and a proxy node corresponding to the switch; the device includes: a determination module, configured to determine first access control information of the switches in the edge resource pool in response to an access control request for the edge resource pool; the first access control information is used to control access between the switches; a sending module, configured to send the first access control information to the proxy node corresponding to the switch in the edge resource pool, so that the proxy node performs access control on the switch according to the received first access control information; An identity authentication module is used to authenticate the target user upon receiving an identity authentication request from the target user; A control information module, configured to determine second access control information of the switch when identity authentication is successful; the second access control information is used to control access between the target user and the switch; The access control module is configured to send the second access control information to the proxy node corresponding to the switch, so that the proxy node performs access control on the switch according to the received second access control information.

9. An access control device for an edge resource pool, characterized in that: Applied to a proxy node, the proxy node is set in an edge resource pool and corresponds to a switch in the edge resource pool, and the edge resource pool is connected to a control node; the device includes: a receiving module, configured to receive first access control information sent by the control node; the first access control information is information for controlling access between the switches in the edge resource pool, determined by the control node in response to an access control request for the edge resource pool; a control module, configured to perform access control on the switch corresponding to the proxy node according to the received first access control information; The receiving module is further configured to receive second access control information sent by the control node; the second access control information is information for controlling access between the target user and the switch, determined by the control node when the target user passes identity authentication of the target user according to an identity authentication request of the target user; The control module is further configured to perform access control on the switch corresponding to the proxy node according to the received second access control information.

10. An access control system for an edge resource pool, characterized in that: The system includes a control node and an agent node, wherein the control node is connected to an edge resource pool, and the edge resource pool is provided with a switch and the agent node corresponding to the switch; The control node is configured to determine, in response to an access control request for the edge resource pool, first access control information of the switch in the edge resource pool, and send the first access control information to the proxy node in the edge resource pool; the first access control information is used to control access between the switches; The proxy node is configured to perform access control on the switch corresponding to the proxy node according to the received first access control information; The control node is further configured to, upon receiving an identity authentication request sent by a target user, perform identity authentication on the target user, and if the identity authentication passes, determine second access control information of the switch, and send the second access control information to the proxy node corresponding to the switch; the second access control information is used to control access between the target user and the switch; The proxy node is further configured to perform access control on the switch corresponding to the proxy node according to the received second access control information.

11. A communication device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.

12. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

13. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.

Citation Information

Patent Citations

  • Data interaction method between internal containers of electric power edge Internet-of-things agent

    CN111556136A

  • Access control method and device of cloud native application, electronic equipment and storage medium

    CN115913676A