An identity authentication method and device, and an electronic device

By introducing distributed authentication nodes and a trust identifier mechanism into the SASE network, the problems of excessive load and over-authorization on the centralized management and control platform are solved, realizing a secure and scalable identity authentication solution and reducing the impact of single point of failure on business.

CN117081819BActive Publication Date: 2026-07-21CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER +1
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
CHINA TELECOM CORP LTD TECHNOLOGY INNOVATION CENTER
Filing Date
2023-08-29
Publication Date
2026-07-21

AI Technical Summary

Technical Problem

In a SASE network, a centralized management and control platform can experience excessive load when handling identity authentication, leading to a single point of failure that affects all services. Furthermore, distributed identity authentication schemes may result in over-authorization issues for cross-domain user access.

Method used

By introducing distributed authentication nodes into the SASE network, initial nodes are selected based on trust levels and trust identifiers are generated. After the first authentication, user devices can directly authenticate with nodes that match the trust level, reducing dependence on the management platform, lowering its load pressure, and achieving elastic expansion of authentication nodes through the horizontal expansion of trust identifiers.

Benefits of technology

While ensuring network access security, it reduces the load pressure on the management platform, reduces over-authorization caused by cross-domain access, improves the security and scalability of authentication, and reduces authentication latency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117081819B_ABST
    Figure CN117081819B_ABST
Patent Text Reader

Abstract

The application discloses an identity authentication method and device and electronic equipment, and the method comprises the following steps: after receiving an authentication request sent by a user equipment, based on object information corresponding to the authentication request, authenticating the object, determining an initial node for connecting with the object from each network node after the object is authenticated; determining an authentication node from each network node, wherein the node is a node corresponding to a trust level not lower than the trust level corresponding to the initial node; sending the authentication result and the node information of the authentication node to the user equipment, so that the user equipment needs to perform identity authentication through the authentication node corresponding to the node information when re-authentication is needed; and sending the trust identifier corresponding to the object to the authentication node, so that the authentication node performs identity authentication after receiving the authentication request of the object corresponding to the trust identifier. Thus, the problem that the existing management and control platform has too large load pressure in centralized processing of identity authentication is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This invention relates to the field of security authentication technology, and in particular to an identity authentication method and device, and an electronic device. Background Technology

[0002] In the current Security Access Service Edge (SASE) architecture, users must authenticate their identities and obtain network access authorization through a centralized management platform when accessing the SASE network. A large number of user authentication requests may put pressure on the management platform, and a single point of failure in the management platform will also affect all SASE network-related services. The distributed identity authentication scheme based on shared tokens allows the terminal to access network resources behind all nodes after authentication at one node, which may lead to over-authorization issues at the network layer in terms of cross-domain user access. Summary of the Invention

[0003] The purpose of this application is to provide an identity authentication method, device, and electronic device to address the problem of excessive load on existing centralized identity authentication platforms.

[0004] In a first aspect, embodiments of this application provide an identity authentication method applied to a management and control platform, the method comprising:

[0005] After receiving an authentication request from a user equipment, the system authenticates the object based on the object information corresponding to the authentication request, and then determines an initial node for connecting to the object from among the network nodes included in the Secure Access Service Edge (SASE) network.

[0006] An authentication node is determined from the network nodes, wherein the authentication node is a node whose corresponding trust level is not lower than the trust level corresponding to the initial node;

[0007] The authentication result and the node information of the authentication node are sent to the user equipment so that the user equipment can perform identity authentication through the authentication node corresponding to the node information when it needs to authenticate again; and the trust identifier corresponding to the object is sent to the authentication node so that the authentication node can perform identity authentication after receiving the authentication request of the object corresponding to the trust identifier.

[0008] In some possible embodiments, the trust identifier corresponding to the object is determined in the following ways:

[0009] The object information is encrypted based on a preset platform key and node key to obtain a trust identifier corresponding to the object.

[0010] In some possible implementations, the trust level of each network node is determined in the following ways:

[0011] For any given network node, determine the set of trust parameters corresponding to that network node, wherein each trust parameter in the set of trust parameters is used to characterize the trustworthiness of the corresponding network node;

[0012] Based on the set of trust parameters corresponding to any given network node, determine the current trust level of that network node.

[0013] In some possible embodiments, determining the current trust level of any network node based on the trust parameter currently corresponding to that network node includes:

[0014] For any given network node, the trust score of the given network node is determined based on the weights corresponding to each preset trust parameter and each trust parameter in the set of trust parameters corresponding to the given network node.

[0015] Based on the preset correspondence between trust levels and trust score ranges, the trust level corresponding to the trust score range to which the trust score of any network node belongs is determined, and the determined trust level is used as the current trust level of any network node.

[0016] Secondly, embodiments of this application provide an identity authentication method applied to a user equipment, the method comprising:

[0017] In response to an authentication request, a target node for authentication is selected from the authentication nodes based on the node information corresponding to the authentication node. The node information corresponding to the authentication node is sent by the management platform after determining the authentication node corresponding to the user equipment from the nodes included in the SASE network. The authentication node is a node whose corresponding trust level is not lower than the trust level of the initial node. The initial node is the access node selected by the management platform for the user equipment based on the authentication request sent by the user equipment.

[0018] An authentication request is sent to the target node based on the node information corresponding to the target node, and the authentication result is received from the target node.

[0019] In some possible embodiments, after receiving the authentication result from the target node, the method further includes:

[0020] If the authentication result received from the target node is an authentication failure message, and the reason for the failure is that the trust identifier has timed out or the trust identifier sent by the management platform does not include a trust identifier used to identify the object information corresponding to the authentication request, then an authentication request is sent to the management platform; or

[0021] If the authentication result received from the target node is an authentication failure message, and the reason for the failure is that the node information has changed, then based on the node information corresponding to the authentication node, another target node other than the failed node is reselected from the authentication nodes, and an authentication request is sent to the reselected target node.

[0022] Thirdly, embodiments of this application provide an authentication method applied to network nodes located in a SASE network, the method comprising:

[0023] Receive authentication requests sent by user equipment; wherein the authentication request is sent by the user equipment after selecting the target node for authentication from the authentication nodes based on the node information corresponding to the authentication node;

[0024] If the node information remains unchanged after receiving the trust identifier sent by the management and control platform, then the object corresponding to the authentication request is authenticated based on the object information; wherein the trust identifier is sent by the management and control platform to the authentication node after determining the authentication node corresponding to the user equipment from the nodes included in the SASE network.

[0025] The authentication result is then fed back to the user equipment.

[0026] In some possible embodiments, the step of authenticating the object corresponding to the authentication request based on the object information includes:

[0027] Based on the object information, determine whether the trust identifier sent by the management and control platform includes a trust identifier used to identify the object information corresponding to the authentication request;

[0028] The step of feeding back the authentication result to the user equipment includes:

[0029] If the trust identifier does not include a trust identifier used to identify the object information corresponding to the authentication request, then the authentication failure result will be fed back to the user equipment.

[0030] In some possible embodiments, after receiving the authentication request sent by the user equipment, the method further includes:

[0031] If the node information changes after receiving the trust identifier sent by the management platform, the authentication failure result will be fed back to the user equipment.

[0032] In some possible embodiments, the step of feeding back the authentication result to the user equipment includes:

[0033] If the received trust identifier takes longer than a preset time, the authentication failure result will be fed back to the user equipment.

[0034] Fourthly, embodiments of this application provide an identity authentication device, the device comprising:

[0035] The management platform authentication module is used to, after receiving an authentication request sent by a user device, authenticate the object based on the object information corresponding to the authentication request, and determine the initial node for connecting to the object from the network nodes included in the SASE network after the object is successfully authenticated.

[0036] The authentication node determination module is used to determine the authentication node from the network nodes, wherein the authentication node is a node whose corresponding trust level is not lower than the trust level corresponding to the initial node;

[0037] The sending module is used to send the authentication result and the node information of the authentication node to the user equipment, so that the user equipment can perform identity authentication through the authentication node corresponding to the node information when it needs to authenticate again; and to send the trust identifier corresponding to the object to the authentication node, so that the authentication node can perform identity authentication after receiving the authentication request of the object corresponding to the trust identifier.

[0038] Fifthly, embodiments of this application provide an identity authentication device, the device comprising:

[0039] The target node determination module is used to respond to identity authentication requests and select a target node for authentication from the authentication nodes based on the node information corresponding to the authentication node. The node information corresponding to the authentication node is sent by the management and control platform after determining the authentication node corresponding to the user equipment from the nodes included in the SASE network. The authentication node is a node whose corresponding trust level is not lower than the trust level of the initial node. The initial node is the access node selected by the management and control platform for the user equipment based on the authentication request sent by the user equipment.

[0040] The authentication result receiving module is used to send an authentication request to the target node based on the node information corresponding to the target node, and to receive the authentication result returned by the target node.

[0041] Sixthly, embodiments of this application provide an identity authentication device, the device comprising:

[0042] The authentication request receiving module is used to receive authentication requests sent by the user equipment; wherein the authentication request is sent by the user equipment after selecting the target node for authentication from the authentication nodes based on the node information corresponding to the authentication node;

[0043] The identity authentication module is used to perform identity authentication on the object corresponding to the authentication request based on the object information if its own node information has not changed after receiving the trust identifier sent by the management and control platform; wherein the trust identifier is sent by the management and control platform to the authentication node after determining the authentication node corresponding to the user equipment from the nodes included in the SASE network.

[0044] The authentication result feedback module is used to send the authentication result back to the user equipment.

[0045] In a seventh aspect, embodiments of this application provide an electronic device, including at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform the authentication method provided in the first aspect, or the authentication method provided in the second aspect, or the authentication method provided in the third aspect.

[0046] Eighthly, embodiments of this application provide a computer storage medium storing a computer program, the computer program being used to cause a computer to execute the authentication method provided in the first aspect, or to execute the authentication method provided in the second aspect, or to execute the authentication method provided in the third aspect.

[0047] In order to solve the problem of excessive load on the centralized identity authentication of existing management and control platforms, this embodiment of the application sinks the centralized authentication method of the management and control platform to distributed network nodes. While ensuring network access security, the distributed authentication nodes reduce the load on the management and control platform. User devices cannot connect to the network layer before authentication, reducing the potential over-authorization caused by cross-domain access and enhancing authentication security.

[0048] Other features and advantages of this application will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the application. The objectives and other advantages of this application may be realized and obtained by means of the structures particularly pointed out in the written description, claims, and drawings. Attached Figure Description

[0049] To more clearly illustrate the technical solutions of the embodiments of this application, the drawings used in the embodiments of this application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of this application. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.

[0050] Figure 1 This is a schematic diagram of an application environment according to an embodiment of this application;

[0051] Figure 2 This is a schematic diagram illustrating the transmission of a trust identifier according to an embodiment of this application;

[0052] Figure 3 This is a schematic diagram illustrating the process of applying an identity authentication method according to an embodiment of this application to a management and control platform;

[0053] Figure 4 This is a schematic diagram illustrating the process of applying an identity authentication method according to an embodiment of this application to a user equipment;

[0054] Figure 5 This is a schematic diagram illustrating the process of applying an authentication method according to an embodiment of this application to a network node located in a SASE network;

[0055] Figure 6 This is a schematic diagram of the overall process of an identity authentication method according to an embodiment of this application;

[0056] Figure 7 This is a schematic diagram of an identity authentication device according to an embodiment of this application;

[0057] Figure 8 This is a schematic diagram of an identity authentication device according to an embodiment of this application;

[0058] Figure 9 This is a schematic diagram of an identity authentication device according to an embodiment of this application;

[0059] Figure 10 This is a schematic diagram of an electronic device structure according to an embodiment of this application. Detailed Implementation

[0060] The technical solutions in the embodiments of this application will be clearly and thoroughly described below with reference to the accompanying drawings. In the description of the embodiments of this application, unless otherwise stated, " / " means "or", for example, A / B can mean A or B; "and / or" in the text is merely a description of the relationship between related objects, indicating that there can be three relationships, for example, A and / or B can mean: A exists alone, A and B exist simultaneously, and B exists alone. In addition, in the description of the embodiments of this application, "multiple" means two or more.

[0061] In the description of the embodiments of this application, unless otherwise stated, the term "multiple" refers to two or more, and other quantifiers are similarly understood. The preferred embodiments described herein are for illustration and explanation only and are not intended to limit this application. Furthermore, the embodiments and features in the embodiments of this application can be combined with each other without conflict.

[0062] To further illustrate the technical solutions provided in the embodiments of this application, a detailed description is provided below in conjunction with the accompanying drawings and specific implementation methods. Although the embodiments of this application provide method operation steps as shown in the following embodiments or drawings, more or fewer operation steps may be included in the method based on conventional or non-inventive effort. For steps that do not logically have a necessary causal relationship, the execution order of these steps is not limited to the execution order provided in the embodiments of this application. In actual processing or when the control device executes the method, it may be executed sequentially or in parallel according to the method shown in the embodiments or drawings.

[0063] In view of the problem that centralized identity authentication on the management platform in related technologies results in excessive load, this application proposes an identity authentication method, device, and electronic device. This method can reduce the load on the management platform by utilizing distributed authentication nodes while ensuring network access security. It also reduces the impact on services due to management platform failures, reduces latency during the authentication process through proximity of authentication nodes, and allows trust identifiers to be horizontally extended to other authentication nodes based on trust levels. This facilitates authentication expansion after elastic scaling of authentication nodes. User devices cannot establish network-level connectivity before authentication, reducing potential over-authorization caused by cross-domain access and enhancing authentication security.

[0064] Other features and advantages of this application will be set forth in the description which follows, and will be apparent in part from the description, or may be learned by practicing the application. The objectives and other advantages of this application may be realized and obtained by means of the structures particularly pointed out in the written description, claims, and drawings.

[0065] The identity authentication method in the embodiments of this application will be described in detail below with reference to the accompanying drawings.

[0066] See Figure 1 A schematic diagram of an identity authentication system provided in one embodiment of this application is shown. The system includes user equipment, a management platform, and network nodes located in the SASE network.

[0067] Upon receiving an authentication request from a user device, the management platform authenticates the object based on the object information corresponding to the authentication request, and then determines the initial node for connecting to the object from among the network nodes included in the Secure Access Service Edge (SASE) network.

[0068] An authentication node is determined from the network nodes, wherein the authentication node is a node whose corresponding trust level is not lower than the trust level corresponding to the initial node;

[0069] The authentication result and the node information of the authentication node are sent to the user equipment so that the user equipment can perform identity authentication through the authentication node corresponding to the node information when it needs to authenticate again; and the trust identifier corresponding to the object is sent to the authentication node so that the authentication node can perform identity authentication after receiving the authentication request of the object corresponding to the trust identifier.

[0070] The user equipment is used to respond to identity authentication requests and select a target node for authentication from the authentication nodes based on the node information corresponding to the authentication node. The node information corresponding to the authentication node is sent by the management and control platform after determining the authentication node corresponding to the user equipment from the nodes included in the SASE network. The authentication node is a node whose corresponding trust level is not lower than the trust level of the initial node. The initial node is the access node selected by the management and control platform based on the authentication request sent by the user equipment.

[0071] An authentication request is sent to the target node based on the node information corresponding to the target node, and the authentication result is received from the target node.

[0072] The network node is used to receive authentication requests sent by the user equipment; wherein the authentication request is sent by the user equipment after selecting the target node for authentication from the authentication nodes based on the node information corresponding to the authentication node;

[0073] If the node information remains unchanged after receiving the trust identifier sent by the management and control platform, then the object corresponding to the authentication request is authenticated based on the object information; wherein the trust identifier is sent by the management and control platform to the authentication node after determining the authentication node corresponding to the user equipment from the nodes included in the SASE network.

[0074] The authentication result is then fed back to the user equipment.

[0075] Specifically, the identity authentication system of this application involves three interactive entities: user equipment, management platform, and various network nodes within the Secure Access Service Edge (SASE) network. Currently, user equipment must undergo identity authentication and obtain network access authorization through a centralized management platform when accessing the SASE network. In this application, when a user equipment makes its first identity authentication request, it sends an authentication request to the management platform. The management platform's database pre-stores a list of object information corresponding to different user equipment. It should be noted that the object in this application can be a user and / or a device. If the object is a user, the object information includes, but is not limited to, username and password. If the object is a device, the object information includes, but is not limited to, terminal device information and terminal device IP. In summary, the specific object information included in the object in this application is determined according to the relevant policies of the management platform and is not limited here. After the user equipment sends a request packet for authentication to the management platform, the management platform determines that the user equipment is making its first request based on the object information corresponding to the authentication request, and authenticates the object. After successful authentication, it determines the initial node for connection to the object. The initial node is used to complete the initial authentication of the user equipment, and the user equipment connects to subsequent resources through this initial node.

[0076] The trust level is determined based on the trust parameters of each network node in the SASE network. In subsequent authentication requests from user devices, authentication through the management platform is no longer required; direct authentication can be performed through all network nodes that meet the trust level criteria, ensuring network access security. As an optional implementation, the trust level of each network node is determined as follows: For any given network node, a set of trust parameters corresponding to that network node is determined, where each trust parameter in the set represents the trustworthiness of the corresponding network node; based on the set of trust parameters corresponding to that network node, the current trust level of that network node is determined.

[0077] As an optional implementation, the trust parameter set includes some or all of the following trust parameters: security baseline, network fluctuation amplitude, frequency of interaction with the management and control platform, and object frequency. That is, only when a network node meets the security baseline (complies with system, service, process, etc. security requirements) can it serve as a candidate node for user devices to directly initiate identity authentication with the network node. Network fluctuation amplitude, frequency of interaction with the management and control platform, frequency of direct authentication with user devices, and historical trust assessment results are used as relevant factors affecting trust to calculate scores and classify different trust levels, such as T1 / T2 / T3… The authentication node periodically obtains the trust level assessment results of other network nodes from the management and control platform or network-reachable network nodes. Trust identifiers can only flow to assessed nodes of the same or higher level. See [link to relevant documentation]. Figure 2If there are four network nodes 1, 2, 3, and 4, and the initial node is node 1, if the trust level of nodes 2 and 3 is not lower than that of node 1, and the trust level of node 4 is lower than that of node 1, then node 1 will pass the trust identifier to nodes 2 and 3.

[0078] As an optional implementation, the management platform is specifically used to determine the trust score of any network node based on the weights corresponding to each preset trust parameter and each trust parameter in the trust parameter set corresponding to the network node.

[0079] Based on the preset correspondence between trust levels and trust score ranges, the trust level corresponding to the trust score range to which the trust score of any network node belongs is determined, and the determined trust level is used as the current trust level of any network node.

[0080] Among these factors, the security baseline serves as a prerequisite for trust level assessment. Network nodes, while ensuring the security of cloud infrastructure, detect security vulnerabilities or malicious programs in systems, services, and processes through scanning and antivirus software. Network fluctuations are primarily assessed based on bandwidth, latency, and jitter from the network node itself to user devices, the management platform, and application resources; a more stable network results in a higher trust score. The frequency of interaction and synchronization with the management platform mainly affects the validity period of the trust identifier; a longer validity period results in a higher trust score. The frequency of direct authentication with terminals is mainly determined by the number of users directly authenticating with the node using the trust identifier within a certain period; the more users directly authenticate, the more trustworthy the node, and the higher the trust score. Historical trust assessment results also influence the current trust level assessment result; the shorter the time since the current assessment, the higher the reference value, and the higher the historical trust level, the higher the trust score. By comprehensively considering all these factors and setting the weight of each factor according to actual needs, a preset trust score range corresponds to each trust level. In other words, the trust level is formed by the security environment and state of each network node itself. The trust level is determined based on the trust score's range. It should be noted that since the parameter values ​​corresponding to each trust parameter of each node change in real time, in this application, after a user completes identity authentication for the first time through the management platform, the current trust level of each network node determined by the management platform is temporarily set as an authentication node that meets the identity authentication conditions, and these authentication nodes are sent to the user device. After sending the authentication nodes to the user device, the node trust level will not be updated to the user until the user authenticates with the platform again.

[0081] As an optional implementation, the management platform determines the trust identifier corresponding to the object by encrypting the object information based on a preset platform key and node key to obtain the trust identifier corresponding to the object.

[0082] The platform key and node key, in the form of a public-private key pair, are used to manage mutual authentication between the platform and network nodes, as well as the synchronization and distribution of object information among network nodes. Trust tokens can be transferred between evaluated network nodes at the same or higher trust level.

[0083] After the user equipment completes its initial identity authentication through the management and control platform, the pre-authentication keys of the management and control platform and each network node, as well as the object information of the user equipment, contained in the trust identifier generated by the management and control platform, serve as the SPA knock packet in the zero-trust SDP architecture in subsequent identity authentication based on network nodes, and perform access control before connecting to network nodes; when the trust identifier changes, the management and control platform will redistribute and synchronize the newly generated trust identifier to the authentication nodes, and the newly generated trust identifier will flow to other authentication nodes.

[0084] After the user equipment completes its initial authentication and receives the authentication node from the management platform, when the user equipment initiates another authentication request, it selects a target node for authentication from the authentication nodes based on the node information corresponding to the authentication node. It should be noted that the method for selecting a target node can be set by the user equipment itself according to the actual scenario; this is not limited here. The user can directly connect to the authentication node subsequently. The selected target node uses a trust identifier for authentication, without going through the management platform. Once the user equipment determines the target node, it sends an authentication request to the target node based on the node information corresponding to the target node. The network node acting as the target node receives the authentication request from the user equipment. First, the target node needs to determine whether its own node information has changed, i.e., whether its own information has been updated. If the target node determines that its node information has not changed, it can begin authenticating the user equipment and finally feed back the authentication result to the user equipment. Authentication failure results from the target node include, but are not limited to, three reasons:

[0085] Reason 1: The object information corresponding to the user device has been updated.

[0086] As an optional implementation, the target node determines, based on the object information, whether the trust identifier sent by the management platform includes a trust identifier used to identify the object information corresponding to the authentication request; if the trust identifier does not include a trust identifier used to identify the object information corresponding to the authentication request, the authentication failure result is fed back to the user equipment.

[0087] Specifically, since the trust identifier includes object information of the user device itself, and the management platform also has a database that stores object information of authenticated user devices, if the trust identifier does not include the trust identifier used to identify the object information corresponding to the authentication request, it proves that the object information corresponding to the user device has been updated. The object information in the trust identifier previously generated by the management platform has changed, and the target node needs to send an authentication failure message back to the user device. It should be noted that the data packet in the feedback process includes the reason for the authentication failure: the object information of the user device has been updated.

[0088] Reason 2: The node information corresponding to the target node has been updated.

[0089] As an optional implementation, after the target node receives the authentication request sent by the user equipment, if its node information changes after receiving the trust identifier sent by the management platform, it will send the authentication failure result back to the user equipment.

[0090] Specifically, during the process of the target node authenticating the object information of the user device, that is, after receiving the trust identifier sent by the management platform, the target node needs to send back the authentication failure result to the user device. It should be noted that the data packet in the feedback process includes the reason for the authentication failure, which is that the node information has been updated.

[0091] Reason 3: Trust token timed out.

[0092] As an optional implementation, if the target node receives the trust identifier for a period of time exceeding a preset duration, it will send the authentication failure result back to the user equipment.

[0093] Specifically, each trust identifier generated by the management platform has a pre-set duration. This duration begins when the target node receives the trust identifier and expires after that time. Therefore, if the target node receives a trust identifier beyond the pre-set duration, regardless of whether the target node has started authentication or has already started authenticating the user device, the target node will send an authentication failure message to the user device. It should be noted that the data packet in the feedback process includes the reason for the authentication failure: the trust identifier has expired.

[0094] After the target node sends the authentication result back to the user equipment, the user equipment receives the authentication result from the target node, parses the data packet, and adopts different response strategies for different authentication results.

[0095] Strategy 1: This applies to cases where the trust identifier times out or the trust identifier sent by the control platform does not include a trust identifier used to identify the object information corresponding to the authentication request (i.e., Reason 1 and Reason 3 mentioned above).

[0096] If the authentication result received from the target node is an authentication failure message, and the reason for the failure is that the trust identifier has timed out or the trust identifier sent by the management platform does not include a trust identifier used to identify the object information corresponding to the authentication request, then an authentication request is sent to the management platform.

[0097] Specifically, if the authentication failure received by the user equipment is due to a trust identifier timeout or object information update, it proves that the authentication failure is caused by a problem on the user equipment side and is unrelated to the authentication node. This means that the user equipment can no longer send authentication information to the target node. In this case, if the user equipment initiates an authentication request again, it needs to send it to the management platform, which is equivalent to the user equipment re-performing the initial authentication. The management platform regenerates the trust identifier based on the user equipment's object information, node key, and platform key.

[0098] Strategy 2: Targeting changes in node information (i.e., reason 2 mentioned above).

[0099] If the authentication result received from the target node is an authentication failure message, and the reason for the failure is that the node information has changed, then based on the node information corresponding to the authentication node, another target node other than the failed node is reselected from the authentication nodes, and an authentication request is sent to the reselected target node.

[0100] Specifically, if the authentication failure received by the user equipment is due to a change in node information, it proves that the authentication failure was caused by a problem with the target node. In this case, if the user equipment initiates an authentication request again, it can still interact directly with the network node, but it needs to select another target node other than the failed node and send the authentication request to the newly selected target node.

[0101] This application decentralizes the centralized authentication method of the management platform to distributed network nodes. During the initial authentication of a user device (UGC), a trust identifier is formed through information exchange between the management platform and network nodes. In subsequent access authentication processes, the UAC can choose to connect to any target node that meets the trust level based on the trust identifier of the authentication node, eliminating the need for centralized authentication from the management platform. This ensures network access security while reducing the load on the management platform through distributed authentication nodes, minimizing service disruptions due to management platform failures. The proximity of authentication nodes also reduces latency during the authentication process. Furthermore, the trust identifier can be horizontally expanded to other authentication nodes based on the trust level, facilitating authentication expansion after elastic scaling of authentication nodes. The trust identifier, containing the pre-authentication keys of the management platform and each network node, as well as the UAC object information, can be used as a SPA (Single-Instance Persistent Access Point) in a zero-trust SDP architecture for access control before connecting to target nodes. UACs cannot establish network-level connectivity before authentication, reducing potential over-authorization due to cross-domain access and enhancing authentication security.

[0102] See Figure 3 This is a flowchart of an identity authentication method according to this application, applied to a management and control platform.

[0103] Step 301: After receiving the authentication request sent by the user equipment, based on the object information corresponding to the authentication request, after the object is successfully authenticated, the initial node for connecting to the object is determined from the network nodes included in the Secure Access Service Edge (SASE) network.

[0104] Step 302: Determine the authentication node from among the network nodes, wherein the authentication node is the node whose corresponding trust level is not lower than the trust level of the initial node.

[0105] Step 303: Send the authentication result and the node information of the authentication node to the user device so that the user device can perform identity authentication through the authentication node corresponding to the node information when it needs to authenticate again; and send the trust identifier corresponding to the object to the authentication node so that the authentication node can perform identity authentication after receiving the authentication request of the object corresponding to the trust identifier.

[0106] As an optional implementation, the trust identifier corresponding to the object is determined in the following way:

[0107] The object information is encrypted based on the preset platform key and node key to obtain the trust identifier corresponding to the object.

[0108] As an optional implementation, the trust level of each network node is determined in the following way:

[0109] For any given network node, determine the set of trust parameters corresponding to that network node, where each trust parameter in the set of trust parameters is used to characterize the trustworthiness of the corresponding network node.

[0110] Based on the set of trust parameters corresponding to any network node, determine the current trust level of any network node.

[0111] As an optional implementation, the current trust level of any network node is determined based on the trust parameters currently corresponding to that network node, including:

[0112] For any network node, the trust score of any network node is determined based on the weights corresponding to each preset trust parameter and each trust parameter in the set of trust parameters corresponding to any network node.

[0113] Based on the preset correspondence between trust levels and trust score ranges, the trust level corresponding to the trust score range to which the trust score of any network node belongs is determined, and the determined trust level is used as the current trust level of any network node.

[0114] See Figure 4 This is a flowchart of an authentication method according to this application, applied to a user equipment.

[0115] Step 401: Respond to the identity authentication request and select the target node for authentication from the authentication nodes based on the node information corresponding to the authentication node. The node information corresponding to the authentication node is sent by the management platform after determining the authentication node corresponding to the user equipment from the nodes included in the SASE network. The authentication node is a node whose trust level is not lower than the trust level of the initial node. The initial node is the access node selected by the management platform for the user equipment based on the authentication request sent by the user equipment.

[0116] Specifically, after a user device is successfully authenticated by the management platform for the first time, the management platform combines the user device's object information to form a trust node and synchronously distributes it to authentication nodes that meet the trust level. Subsequently, the user device can directly rely on the trust identifier to perform authentication on the selected target node without going through the management platform. The authentication nodes are expanded through the flow of trust identifiers between authentication nodes, thus sinking the centralized authentication of the management platform to distributed authentication nodes.

[0117] Step 402: Send an authentication request to the target node based on the node information corresponding to the target node, and receive the authentication result returned by the target node.

[0118] As an optional implementation, after receiving the authentication result from the target node, the method further includes:

[0119] If the authentication result received from the target node is an authentication failure message, and the reason for the failure is that the trust identifier has timed out or the trust identifier sent by the management platform does not include the trust identifier used to identify the object information corresponding to the authentication request, then an authentication request is sent to the management platform; or

[0120] If the target node sends an authentication failure message, and the reason for the failure is that the node information has changed, then based on the node information corresponding to the authentication node, a new target node other than the failed node is selected from the authentication nodes, and an authentication request is sent to the newly selected target node.

[0121] join Figure 5 This is a flowchart of an authentication method according to this application, applied to a network node located in a SASE network.

[0122] Step 501: Receive the authentication request sent by the user equipment; wherein the authentication request is sent by the user equipment after selecting the target node for authentication from the authentication nodes based on the node information corresponding to the authentication node.

[0123] Specifically, network nodes that do not meet the trust level cannot authenticate user devices and will not respond to authentication requests; authentication nodes that meet the trust level cannot establish a network connection to the network node before the user device verifies and authenticates the node's trust identifier with object information, thus reducing the problem of over-authorization at the network layer.

[0124] Step 502: If the node information itself has not changed after receiving the trust identifier sent by the management and control platform, then the identity authentication of the object corresponding to the authentication request is performed based on the object information; wherein the trust identifier is sent by the management and control platform to the authentication node after determining the authentication node corresponding to the user device from the nodes included in the SASE network.

[0125] Step 503: Feed back the authentication result to the user device.

[0126] As an optional implementation, identity authentication is performed on the object corresponding to the authentication request based on object information, including:

[0127] Based on the object information, determine whether the trust identifier sent by the management and control platform includes a trust identifier used to identify the object information corresponding to the authentication request;

[0128] The authentication results are fed back to the user's device, including:

[0129] If the trust identifier does not include a trust identifier used to identify the object information corresponding to the authentication request, the authentication failure result will be fed back to the user device.

[0130] As an optional implementation, after receiving the authentication request sent by the user equipment, the method further includes:

[0131] If the node information changes after receiving the trust identifier from the management platform, the node will send the authentication failure result back to the user device.

[0132] As an optional implementation, the authentication result is fed back to the user equipment, including:

[0133] If the received trust identifier takes longer than a preset time, the authentication failure result will be sent back to the user device.

[0134] See Figure 6 This is a flowchart illustrating the overall authentication process for this application.

[0135] Step 601: Responding to the authentication request. After determining that it has not received the authentication node sent by the management and control platform, the user equipment initiates an authentication request to the management and control platform.

[0136] Step 602: After receiving the authentication request sent by the user equipment, the management and control platform authenticates the object based on the object information corresponding to the authentication request. After the object is successfully authenticated, the platform determines the initial node for connecting to the object from each network node. The platform encrypts the object information based on the preset platform key and node key to obtain the trust identifier corresponding to the object.

[0137] Step 603: For any given network node, the management platform determines the set of trust parameters currently corresponding to that network node.

[0138] Step 604: For any given network node, the management platform determines the trust score based on the weights of each preset trust parameter and the trust parameters in the set of trust parameters corresponding to any given network node.

[0139] Step 605: Based on the preset correspondence between trust levels and trust score ranges, the management platform determines the trust level corresponding to the trust score range to which the trust score of any network node belongs, and uses the determined trust level as the current trust level of any network node.

[0140] Step 606: The management platform determines the authentication nodes from each network node whose trust level is not lower than that of the initial node.

[0141] Step 607: The management platform sends the authentication result and the node information of the authentication node to the user device.

[0142] Step 608: The user equipment responds to the authentication request and selects the target node for authentication from the authentication nodes based on the node information corresponding to the authentication node.

[0143] Step 609: The user equipment sends an authentication request to the target node based on the node information corresponding to the target node.

[0144] Step 610: The target node receives the authentication request sent by the user equipment.

[0145] Step 611: The target node determines whether its own node information has changed. If yes, proceed to step 612; otherwise, proceed to step 614.

[0146] Step 612: The target node will send the authentication result of the authentication failure due to the update of node information back to the user device.

[0147] Step 613: The user equipment selects another target node from the authentication nodes (excluding the failed node) based on the node information corresponding to the authentication node, and sends an authentication request to the newly selected target node, then returns to step 609.

[0148] Step 614: Based on the object information, the target node determines whether the trust identifier sent by the management platform includes a trust identifier used to identify the object information corresponding to the authentication request. If yes, proceed to step 615; otherwise, proceed to step 617.

[0149] That is, the target node determines whether the object information has been updated based on the object information.

[0150] Step 615: Determine whether the time of the received trust identifier exceeds the preset duration. If yes, proceed to step 619; otherwise, proceed to step 616.

[0151] Step 616: The target node continues to authenticate the user device.

[0152] Step 617: The target node will send the authentication result of the authentication failure due to object information update back to the user device.

[0153] Step 618: The user equipment sends an authentication request to the management and control platform.

[0154] Step 619: The target node sends the authentication result of the authentication failure due to the trust identifier timeout back to the user device, and returns to step 618.

[0155] Example 2

[0156] Based on the same inventive concept, this application also provides an identity authentication device, such as... Figure 7 As shown, the device includes:

[0157] The management platform authentication module 701 is used to, after receiving an authentication request sent by a user device, authenticate the object based on the object information corresponding to the authentication request, and determine the initial node for connecting to the object from the network nodes included in the Secure Access Service Edge (SASE) network after the object is successfully authenticated.

[0158] The authentication node determination module 702 is used to determine the authentication node from each network node, wherein the authentication node is a node whose corresponding trust level is not lower than the trust level of the initial node;

[0159] The sending module 703 is used to send the authentication result and the node information of the authentication node to the user equipment, so that the user equipment can perform identity authentication through the authentication node corresponding to the node information when it needs to authenticate again; and to send the trust identifier corresponding to the object to the authentication node, so that the authentication node can perform identity authentication after receiving the authentication request of the object corresponding to the trust identifier.

[0160] Optionally, the sending module 703 is specifically used to determine the trust identifier corresponding to the object by encrypting the object information based on the preset platform key and node key to obtain the trust identifier corresponding to the object.

[0161] Optionally, the authentication node module 702 is specifically used to determine the trust level of each network node in the following ways:

[0162] For any given network node, determine the set of trust parameters corresponding to that network node, where each trust parameter in the set of trust parameters is used to characterize the trustworthiness of the corresponding network node.

[0163] Based on the set of trust parameters corresponding to any network node, determine the current trust level of any network node.

[0164] Optionally, the authentication node module 702 is specifically used for:

[0165] For any network node, the trust score of any network node is determined based on the weights corresponding to each preset trust parameter and each trust parameter in the set of trust parameters corresponding to any network node.

[0166] Based on the preset correspondence between trust levels and trust score ranges, the trust level corresponding to the trust score range to which the trust score of any network node belongs is determined, and the determined trust level is used as the current trust level of any network node.

[0167] Based on the same inventive concept, this application also provides an identity authentication device, such as... Figure 8 As shown, the device includes:

[0168] The target node determination module 801 is used to respond to identity authentication requests and select the target node for authentication from the authentication nodes based on the node information corresponding to the authentication node. The node information corresponding to the authentication node is sent by the management and control platform after determining the authentication node corresponding to the user equipment from the nodes included in the SASE network. The authentication node is a node whose corresponding trust level is not lower than the trust level of the initial node. The initial node is the access node selected by the management and control platform for the user equipment based on the authentication request sent by the user equipment.

[0169] The authentication result receiving module 802 is used to send an authentication request to the target node based on the node information corresponding to the target node, and to receive the authentication result returned by the target node.

[0170] Optionally, the authentication result receiving module 802 is also used for:

[0171] If the authentication result received from the target node is an authentication failure message, and the reason for the failure is that the trust identifier has timed out or the trust identifier sent by the management platform does not include the trust identifier used to identify the object information corresponding to the authentication request, then an authentication request is sent to the management platform; or

[0172] If the authentication result received from the target node is an authentication failure message, and the reason for the failure is that the node information has changed, then based on the node information corresponding to the authentication node, another target node other than the failed node is selected from the authentication nodes, and an authentication request is sent to the newly selected target node.

[0173] Based on the same inventive concept, this application also provides an identity authentication device, such as... Figure 9 As shown, the device includes:

[0174] The authentication request receiving module 901 is used to receive authentication requests sent by the user equipment; wherein the authentication request is sent by the user equipment after selecting the target node for authentication from the authentication nodes based on the node information corresponding to the authentication node;

[0175] The identity authentication module 902 is used to authenticate the object corresponding to the authentication request based on the object information if its own node information has not changed after receiving the trust identifier sent by the management and control platform; wherein the trust identifier is sent by the management and control platform to the authentication node after determining the authentication node corresponding to the user device from the nodes included in the SASE network.

[0176] The authentication result feedback module 903 allows users to send the authentication results back to their devices.

[0177] Optionally, the identity authentication module 902 is used to: determine, based on the object information, whether the trust identifier sent by the management platform includes a trust identifier used to identify the object information corresponding to the authentication request;

[0178] The authentication results are fed back to the user's device, including:

[0179] If the trust identifier does not include a trust identifier used to identify the object information corresponding to the authentication request, the authentication failure result will be fed back to the user device.

[0180] Optionally, the authentication request receiving module 901 is further configured to: if its own node information changes after receiving the trust identifier sent by the management platform, then send the authentication failure result back to the user device.

[0181] Optionally, the authentication result feedback module 903 is specifically used to: if the time for receiving the trust identifier exceeds a preset duration, then send the authentication failure result back to the user device.

[0182] Having introduced the identity authentication method and apparatus according to exemplary embodiments of this application, we will now introduce an electronic device according to another exemplary embodiment of this application.

[0183] Those skilled in the art will understand that various aspects of this application can be implemented as a system, method, or program product. Therefore, various aspects of this application can be specifically implemented in the following forms: a completely hardware implementation, a completely software implementation (including firmware, microcode, etc.), or a combination of hardware and software implementations, collectively referred to herein as a "circuit," "module," or "system."

[0184] In some possible implementations, the electronic device according to this application may include at least one processor and at least one memory. The memory stores program code that, when executed by the processor, causes the processor to perform the steps of applying the authentication method according to the various exemplary embodiments of this application described above to a management platform, or to perform the steps of applying the authentication method according to the various exemplary embodiments of this application described above to a user device, or to perform the steps of applying the authentication method according to the various exemplary embodiments of this application described above to a network node located in a SASE network.

[0185] The following reference Figure 10 To describe the electronic device 130 according to this embodiment of the present application, namely the aforementioned identity authentication device. Figure 10 The electronic device 130 shown is merely an example and should not impose any limitations on the functionality and scope of use of the embodiments of this application.

[0186] like Figure 10As shown, the electronic device 130 is presented in the form of a general-purpose electronic device. The components of the electronic device 130 may include, but are not limited to: at least one processor 131, at least one memory 132, and a bus 133 connecting different system components (including memory 132 and processor 131).

[0187] Bus 133 represents one or more of several bus structures, including a memory bus or memory controller, peripheral bus, processor, or local bus using any of the various bus structures.

[0188] The memory 132 may include a readable medium in the form of volatile memory, such as random access memory (RAM) 1321 and / or cache memory 1322, and may further include read-only memory (ROM) 1323.

[0189] The memory 132 may also include a program / utility 1325 having a set (at least one) of program modules 1324, including but not limited to: an operating system, one or more application programs, other program modules, and program data, each or some combination of these examples may include an implementation of a network environment.

[0190] Electronic device 130 can also communicate with one or more external devices 134 (e.g., keyboard, pointing device, etc.), and with one or more devices that enable a user to interact with electronic device 130, and / or with any device that enables electronic device 130 to communicate with one or more other electronic devices (e.g., router, modem, etc.). This communication can be performed via input / output (I / O) interface 135. Furthermore, electronic device 130 can also communicate with one or more networks (e.g., local area network (LAN), wide area network (WAN), and / or public networks, such as the Internet) via network adapter 136. As shown, network adapter 136 communicates with other modules used in electronic device 130 via bus 133. It should be understood that, although not shown in the figures, other hardware and / or software modules can be used in conjunction with electronic device 130, including but not limited to: microcode, device drivers, redundant processors, external disk drive arrays, RAID systems, tape drives, and data backup storage systems.

[0191] In some possible implementations, various aspects of the authentication method provided in this application can also be implemented as a program product, which includes program code. When the program product is run on a computer device, the program code is used to cause the computer device to perform the steps of applying the authentication method according to the various exemplary embodiments of this application to a management platform, or to perform the steps of applying the authentication method according to the various exemplary embodiments of this application to a user device, or to perform the steps of applying the authentication method according to the various exemplary embodiments of this application to a network node located in a SASE network.

[0192] The program product may employ any combination of one or more readable media. A readable medium may be a readable signal medium or a readable storage medium. A readable storage medium may be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples (a non-exhaustive list) of readable storage media include: electrical connections having one or more wires, portable disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof.

[0193] The monitoring program product of the embodiments of this application may employ a portable compact disc read-only memory (CD-ROM) and include program code, and may run on an electronic device. However, the program product of this application is not limited thereto. In this document, the readable storage medium may be any tangible medium that contains or stores a program that may be used by or in conjunction with an instruction execution system, apparatus, or device.

[0194] A readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying readable program code. This propagated data signal may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A readable signal medium may also be any readable medium other than a readable storage medium, capable of sending, propagating, or transmitting a program for use by or in conjunction with an instruction execution system, apparatus, or device.

[0195] The program code contained on the readable medium may be transmitted using any suitable medium, including but not limited to wireless, wired, optical fiber, RF, etc., or any suitable combination thereof.

[0196] Program code for performing the operations of this application can be written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java and C++, and conventional procedural programming languages ​​such as C or similar languages. The program code can execute entirely on the user's electronic device, partially on the user's device, as a standalone software package, partially on the user's electronic device and partially on a remote electronic device, or entirely on a remote electronic device or server. In cases involving remote electronic devices, the remote electronic device can be connected to the user's electronic device via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external electronic device (e.g., via the Internet using an Internet service provider).

[0197] It should be noted that although several units or sub-units of the device have been mentioned in the detailed description above, this division is merely exemplary and not mandatory. In fact, according to embodiments of this application, the features and functions of two or more units described above can be embodied in one unit. Conversely, the features and functions of one unit described above can be further divided and embodied by multiple units.

[0198] Furthermore, although the operations of the method of this application are described in a specific order in the accompanying drawings, this does not require or imply that these operations must be performed in that specific order, or that all the operations shown must be performed to achieve the desired result. Additionally or alternatively, certain steps may be omitted, multiple steps may be combined into one step, and / or one step may be broken down into multiple steps.

[0199] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product embodied on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.

[0200] This application is described with reference to flowchart illustrations and block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block and / or block in the flowchart illustrations and block diagrams, as well as combinations of blocks and processes in the flowchart illustrations and block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the process. Figure 1 One or more processes and boxes Figure 1 A device that provides the functions specified in one or more boxes.

[0201] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data processing device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and boxes Figure 1 The function specified in one or more boxes.

[0202] These computer program instructions may also be loaded onto a computer or other programmable data processing equipment to cause a series of operational steps to be performed on the computer or other programmable equipment to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable equipment for implementing the process. Figure 1 One or more processes and boxes Figure 1 The steps of the function specified in one or more boxes.

[0203] Although preferred embodiments of this application have been described, those skilled in the art, upon learning the basic inventive concept, can make other changes and modifications to these embodiments. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments as well as all changes and modifications falling within the scope of this application.

[0204] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.

Claims

1. An identity authentication method, characterized in that, Applied to a management and control platform, the method includes: After receiving an authentication request from a user equipment, the system authenticates the object based on the object information corresponding to the authentication request, and then determines an initial node for connecting to the object from among the network nodes included in the Secure Access Service Edge (SASE) network. An authentication node is determined from the network nodes, wherein the authentication node is a node whose corresponding trust level is not lower than the trust level corresponding to the initial node; The authentication result and the node information of the authentication node are sent to the user equipment so that the user equipment can perform identity authentication through the authentication node corresponding to the node information when it needs to authenticate again; and the trust identifier corresponding to the object is sent to the authentication node so that the authentication node can perform identity authentication after receiving the authentication request of the object corresponding to the trust identifier.

2. The method according to claim 1, characterized in that, The trust identifier corresponding to the object is determined in the following ways: The object information is encrypted based on a preset platform key and node key to obtain a trust identifier corresponding to the object.

3. The method according to claim 1, characterized in that, The trust level of each network node is determined in the following ways: For any given network node, determine the set of trust parameters corresponding to that network node, wherein each trust parameter in the set of trust parameters is used to characterize the trustworthiness of the corresponding network node; Based on the set of trust parameters corresponding to any given network node, determine the current trust level of that network node.

4. The method according to claim 3, characterized in that, Determining the current trust level of any network node based on its current trust parameters includes: For any given network node, the trust score of the given network node is determined based on the weights corresponding to each preset trust parameter and each trust parameter in the set of trust parameters corresponding to the given network node. Based on the preset correspondence between trust levels and trust score ranges, the trust level corresponding to the trust score range to which the trust score of any network node belongs is determined, and the determined trust level is used as the current trust level of any network node.

5. An identity authentication method, characterized in that, Applied to user equipment, the method includes: In response to an authentication request, a target node for authentication is selected from the authentication nodes based on the node information corresponding to the authentication node. The node information corresponding to the authentication node is sent by the management platform after determining the authentication node corresponding to the user equipment from the nodes included in the SASE network. The authentication node is a node whose corresponding trust level is not lower than the trust level of the initial node. The initial node is the access node selected by the management platform for the user equipment based on the authentication request sent by the user equipment. An authentication request is sent to the target node based on the node information corresponding to the target node, and the authentication result is received from the target node.

6. The method according to claim 5, characterized in that, After receiving the authentication result from the target node, the method further includes: If the authentication result received from the target node is an authentication failure message, and the reason for the failure is that the trust identifier has timed out or the trust identifier sent by the management platform does not include a trust identifier used to identify the object information corresponding to the authentication request, then an authentication request is sent to the management platform; or If the authentication result received from the target node is an authentication failure message, and the reason for the failure is that the node information has changed, then based on the node information corresponding to the authentication node, another target node other than the failed node is reselected from the authentication nodes, and an authentication request is sent to the reselected target node.

7. An identity authentication method, characterized in that, Applied to network nodes located in a SASE network, the method includes: The system receives an authentication request sent by a user equipment; wherein the authentication request is sent by the user equipment after selecting a target node for authentication from the authentication nodes based on the node information corresponding to the authentication node; and the authentication node is a node whose corresponding trust level is not lower than the trust level corresponding to the initial node. If the node information remains unchanged after receiving the trust identifier sent by the management and control platform, then the object corresponding to the authentication request is authenticated based on the object information; wherein the trust identifier is sent by the management and control platform to the authentication node after determining the authentication node corresponding to the user equipment from the nodes included in the SASE network. The authentication result is then fed back to the user equipment.

8. The method according to claim 7, characterized in that, The step of authenticating the object corresponding to the authentication request based on the object information includes: Based on the object information, determine whether the trust identifier sent by the management and control platform includes a trust identifier used to identify the object information corresponding to the authentication request; The step of feeding back the authentication result to the user equipment includes: If the trust identifier does not include a trust identifier used to identify the object information corresponding to the authentication request, then the authentication failure result will be fed back to the user equipment.

9. The method according to claim 7, characterized in that, After receiving the authentication request sent by the user equipment, the method further includes: If the node information changes after receiving the trust identifier sent by the management platform, the authentication failure result will be fed back to the user equipment.

10. The method according to claim 7, characterized in that, The step of feeding back the authentication result to the user equipment includes: If the received trust identifier takes longer than a preset time, the authentication failure result will be fed back to the user equipment.

11. An identity authentication device, characterized in that, The device includes: The management platform authentication module is used to, after receiving an authentication request sent by a user device, authenticate the object based on the object information corresponding to the authentication request, and determine the initial node for connecting to the object from the network nodes included in the SASE network after the object is successfully authenticated. The authentication node determination module is used to determine the authentication node from the network nodes, wherein the authentication node is a node whose corresponding trust level is not lower than the trust level corresponding to the initial node; The sending module is used to send the authentication result and the node information of the authentication node to the user equipment, so that the user equipment can perform identity authentication through the authentication node corresponding to the node information when it needs to authenticate again; and to send the trust identifier corresponding to the object to the authentication node, so that the authentication node can perform identity authentication after receiving the authentication request of the object corresponding to the trust identifier.

12. An identity authentication device, characterized in that, The device includes: The target node determination module is used to respond to identity authentication requests and select a target node for authentication from the authentication nodes based on the node information corresponding to the authentication node. The node information corresponding to the authentication node is sent by the management and control platform after determining the authentication node corresponding to the user equipment from the nodes included in the SASE network. The authentication node is a node whose corresponding trust level is not lower than the trust level of the initial node. The initial node is the access node selected by the management and control platform for the user equipment based on the authentication request sent by the user equipment. The authentication result receiving module is used to send an authentication request to the target node based on the node information corresponding to the target node, and to receive the authentication result returned by the target node.

13. An identity authentication device, characterized in that, The device includes: The authentication request receiving module is used to receive authentication requests sent by the user equipment; wherein the authentication request is sent by the user equipment after selecting a target node for authentication from the authentication nodes based on the node information corresponding to the authentication node; the authentication node is a node whose corresponding trust level is not lower than the trust level corresponding to the initial node. The identity authentication module is used to perform identity authentication on the object corresponding to the authentication request based on the object information if its own node information has not changed after receiving the trust identifier sent by the management and control platform; wherein the trust identifier is sent by the management and control platform to the authentication node after determining the authentication node corresponding to the user equipment from the nodes included in the SASE network. The authentication result feedback module is used to send the authentication result back to the user equipment.

14. An electronic device, characterized in that, The method includes at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, the instructions being executed by the at least one processor to enable the at least one processor to perform the method as claimed in any one of claims 1-4, or the method as claimed in claim 5 or 6, or the method as claimed in any one of claims 7-10.

15. A computer storage medium, characterized in that, The computer storage medium stores a computer program that causes the computer to perform the method as described in any one of claims 1-4, or the method as described in claim 5 or 6, or the method as described in any one of claims 7-10.