A hierarchical and domain-based authentication and authorization system and method based on trust transfer.
By using a hierarchical and domain-based authentication and authorization system, which separates the authentication and authorization center and regional agents into different layers and domains, the system solves the problems of complex identity management and difficult privacy protection under the centralized authentication model, and achieves the effects of simplified management and privacy protection.
Patent Information
- Application Number
- CN202411000244.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-24
- Publication Date
- 2026-01-30
- Estimated Expiration
- 2044-07-24
AI Technical Summary
Existing centralized authentication and authorization models lead to complex identity and permission management, high consumption of network computing and storage resources, and difficulty in protecting user privacy when managing massive numbers of users and terminals.
A layered and domained authentication and authorization system based on trust transmission is adopted, which divides the authentication and authorization center and regional agents into layers and domains. Through identity authentication and permission allocation within the trust domain, identity management is simplified, network resource consumption is reduced, and privacy information is protected.
It simplifies authentication and authorization management, reduces network resource consumption, improves organizational privacy, and ensures that private information within the trusted domain is not leaked.
Smart Images

Figure CN119071015B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of information security, and more particularly to a layered and domain authentication and authorization system and method based on trust transmission. BACKGROUND
[0002] In current information systems, access permissions to networks and information systems are implemented through a central centralized authentication and authorization model. All users and terminals need to apply for authentication in advance to the authentication and authorization center for access to information system resources (including network resources, application resources, and data resources, etc.). After authentication, the authentication and authorization center authorizes the access users and terminals, and issues authorization control information to the relevant network / resource access control gateway. Only after the users and terminals obtain the corresponding access permissions can they normally access the information system resources, as shown in the following figure. Figure 1
[0003] However, with the continuous development of zero-trust architecture and unified trust, and the demand for future ubiquitous interconnection of man-machine-objects, it is necessary to manage and authenticate and authorize a large number of users, computer terminals, and Internet of Things terminals in the future. The identity and permission information to be managed is extremely large, which will lead to extremely complex identity and permission management of the existing centralized authentication and authorization model, and will also bring great network bandwidth and computing storage overhead. In addition, under the centralized authentication and authorization model, all terminals and users (including terminals and users within some hierarchical organizational structures) need to be registered and registered in the authentication and authorization center, which increases the difficulty of user privacy protection, especially for some special teams in hierarchical organizational structures. The users and terminals within the organizational structure are sensitive privacy information and need to be protected. Therefore, a simple and efficient man-machine-object mutual authentication and authorization method with certain privacy protection capability is needed for future zero-trust architecture and ubiquitous interconnection of massive user terminals. SUMMARY
[0004] The present application aims to overcome the shortcomings of the prior art and provides a layered and domain authentication and authorization system and method based on trust transmission, which simplifies the authentication and authorization management work, reduces the network resource occupation, and improves the privacy of the organization.
[0005] The purpose of the present application is achieved by the following scheme:
[0006] A hierarchical, domain-based authentication and authorization system based on trust transmission includes: an authentication and authorization center, a primary-level regional authentication and authorization agent, a secondary-level regional authentication and authorization agent, a user agent, and a network access control gateway for the accessed network and a resource access control gateway for the accessed information resources. The authentication and authorization center is used to authenticate the identities and assign permissions to all terminals / users within the primary-level trust domain and to subordinate primary-level regional authentication and authorization agents, and to issue access control policies to network access control gateways and resource access control gateways at all levels based on the permission assignment. The primary-level regional authentication and authorization agents are used to authenticate the identities and assign permissions to all terminals / users within the secondary-level trust domain and to subordinate secondary-level regional authentication and authorization agents. The regional authentication and authorization agent performs identity verification and, within the scope of permissions granted by the superior authentication and authorization center to this trust domain, performs secondary permission allocation for terminals / users, and issues access control policies to network access control gateways and resource access control gateways at all levels based on the permission allocation. The user agent is used to identify the terminal / user and, when necessary, initiate identity authentication requests on behalf of the terminal / user to confirm the terminal / user's identity. Network access control gateways and resource access control gateways at all levels receive access control policies issued by the authentication and authorization center and regional authentication and authorization agents at all levels to implement access control for the network and resources.
[0007] Furthermore, it also includes: multi-level regional certification and authorization agents, that is, multiple third-level regional certification and authorization agents can be set up under a second-level regional certification and authorization agent, and so on.
[0008] A hierarchical, domain-based authentication and authorization method based on trust transitivity includes the following steps:
[0009] Step 1: Divide the entire information system's trust domain into a primary trust domain and a secondary trust domain. Then, divide the secondary trust domain into different tertiary trust domains, and so on down to multiple levels of trust domains.
[0010] Step two: The authentication and authorization center is responsible for building the trust relationships between all terminals / users in the first-level trust domain and all second-level trust domains; the authentication and authorization agent in the first-level region is responsible for building the trust relationships between all terminals / users in the second-level trust domain and all third-level trust domains; and so on to the multi-level trust domains.
[0011] A layered, domain-based authentication and authorization method based on trust transitivity, based on the layered, domain-based authentication and authorization system based on trust transitivity as described in any of the preceding claims, includes an identity registration process:
[0012] Step S1: Level 1 regional authentication and authorization agent A11 registers its group identity with authentication and authorization center A0 and obtains the group identity identifier C1. Authentication and authorization center A0 assigns group permissions PC1{p1, p2, p3, ..., pn} to Level 1 regional authentication and authorization agent A11.
[0013] Step S2: User agent 1 registers the user identity with the first-level regional authentication and authorization agent A11 and obtains the user identity identifier U1. The first-level regional authentication and authorization agent A11 assigns user permissions PU1{p1, p3, ...} to the user within the scope of permissions PC1.
[0014] Step S3: User agent 2 within the same trusted area registers the user identity with the first-level area authentication and authorization agent A11 and obtains the user identity identifier U2. The first-level area authentication and authorization agent A11 assigns user permissions PU2{p1, p2, ...} to the user within the scope of permissions PC1, and so on, to complete the identity registration and permission assignment of all users within the same trusted area.
[0015] Step S4: Register identities and assign permissions to the Level 1 regional authentication and authorization agent A12 and all users in another trusted region.
[0016] A layered and domain-based authentication and authorization method based on trust transitivity, based on the layered and domain-based authentication and authorization system based on trust transitivity as described in any of the preceding claims, includes a resource access process:
[0017] Step SS1: When the system is activated or external resource access is required, the regional authentication and authorization agent A11 initiates a group identity authentication application to the authentication and authorization center A0 as group user C1. The authentication and authorization center A0 authenticates the identity of user C1 and issues a trust credential TC1. At the same time, based on user C1's access permissions PC1, it issues access control policies to the corresponding network / resource access control gateway, allowing or denying the user holding the trust credential TC1 to access the corresponding resources.
[0018] Step SS2: Regional authentication and authorization agents and authentication and authorization centers perform identity preservation according to the established identity preservation scheme;
[0019] Step SS3: When user 1 needs to access resources, user agent 1, in the identity of user U1, initiates an individual-based identity authentication request to the regional authentication and authorization agent A11 in the region. The regional authentication and authorization agent A11 authenticates user U1's identity and issues a trust credential TU11. At the same time, based on user U1's access permissions PU1, it issues access control policies to the corresponding network / resource access control gateway, allowing the user holding the trust credential TU11 to access the corresponding resources.
[0020] Step SS4: During the resource access process, User 1 performs identity preservation according to the established identity preservation scheme.
[0021] Step SS5: User 1 uses trust credential TU11 to initiate access to the accessed resource. When the access packet arrives at the network access control gateway, the network access control gateway checks whether the trust credential TU11 is allowed. If it is allowed, the trust credential TU11 is replaced with TC1 to forward the access packet; otherwise, the access packet is discarded.
[0022] Step SS6: When the access control message arrives at the resource access control gateway, the resource access control gateway verifies whether the TC1 trust credential is allowed. If it is allowed, access is allowed; otherwise, access is denied.
[0023] Furthermore, the identity registration process is applied to ubiquitous interconnected, zero-trust information system environments.
[0024] Furthermore, the resource access process is applied to ubiquitous interconnected, zero-trust information system environments.
[0025] The beneficial effects of this invention include:
[0026] (1) Compared with the traditional centralized authentication and authorization architecture, the present invention simplifies the identity management, permission management and authentication and authorization of a large number of individual users to the identity management, permission management and authentication and authorization of different user groups and different individual users by classifying and processing identity management, permission management and authentication and authorization in different regions. This simplifies the work of the authentication and authorization center in managing the identity, permission management and authentication and authorization of a large number of users, and at the same time greatly reduces the storage resources occupied by the authentication and authorization center in storing identity information, the computing resources required for identity authentication and the network resources occupied in the identity authentication process.
[0027] (2) The present invention implements hierarchical and domain-based processing of identity management, permission management and authentication authorization, so that regional authentication authorization agents and authentication authorization centers that are not in the same trust domain cannot know the privacy information such as organizational structure, user information and network topology within other trust domains and lower-level trust domains. This ensures that the privacy information such as organizational structure, users and networks within the trust domain are not exposed outside the organization, thereby improving the organization's privacy. Attached Figure Description
[0028] To more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the drawings used in the description of the embodiments or the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without creative effort.
[0029] Figure 1 This is a schematic diagram of a centralized authentication and authorization model;
[0030] Figure 2 This invention presents the architecture and composition of a layered and domain-based authentication model based on trust transfer, as described in an embodiment of the present invention.
[0031] Figure 3 This is a schematic diagram of the application process of a layered and domain-based authentication system based on trust transfer, according to an embodiment of the present invention.
[0032] It should be noted that the colors in the figure are necessary colors to facilitate identification and understanding of the technical solution of the present invention. Detailed Implementation
[0033] All features disclosed in all embodiments of this specification, or steps in all methods or processes implied in the disclosure, may be combined and / or extended or replaced in any way, except for mutually exclusive features and / or steps.
[0034] In view of the problems mentioned in the background, this invention is mainly aimed at the future ubiquitous interconnected and zero-trust information system environment. It adopts a layered and domain-based collaborative authentication and authorization architecture based on trust transmission to achieve authentication and authorization for massive numbers of users and terminals in a ubiquitous interconnected environment. This aims to solve the privacy and security problems of centralized authentication and authorization architectures, such as high network computing and storage resource consumption, complex identity management, and exposure of internal organizational structures. Specifically, this invention, for information systems with a layered and hierarchical architecture, discloses a layered and domain-based authentication and authorization architecture based on trust transmission and its application process method in the embodiments. It is particularly suitable for user identity authentication and authorized access under a layered and hierarchical organizational structure. The detailed implementation process is as follows:
[0035] 1. Regarding the architecture and composition of this invention
[0036] The hierarchical and domain-based authentication and authorization model based on trust transfer in this invention is as follows: Figure 2 As shown, based on the network architecture and the organizational structure of the terminals / users, the entire information system's trust domain is divided into a primary trust domain and a secondary trust domain. If necessary, the secondary trust domain can be further divided into different tertiary trust domains, and so on down to multiple levels of trust domains. The trust relationship between all terminals / users within the primary trust domain and all secondary trust domains is established by the authentication and authorization center; the trust relationship between all terminals / users within the secondary trust domain and all tertiary trust domains is established by the primary regional authentication and authorization agent; and so on down to multiple levels of trust domains.
[0037] The entire system consists of an authentication and authorization center, a first-level regional authentication and authorization agent, a second-level regional authentication and authorization agent (multiple levels of regional authentication and authorization agents can exist if needed, i.e., multiple third-level regional authentication and authorization agents can be set under a second-level regional authentication and authorization agent, and so on), a user agent, as well as a network access control gateway for the accessed network and a resource access control gateway for the accessed information resources.
[0038] The authentication and authorization center performs identity authentication and permission allocation (authentication and authorization) for all terminals / users within the primary trust domain and subordinate primary regional authentication and authorization agents (representing trust in the entire secondary trust domain), and issues access control policies to network access control gateways and resource access control gateways at all levels based on the permission allocation. The primary regional authentication and authorization agent performs identity authentication for all terminals / users within the secondary trust domain and subordinate secondary regional authentication and authorization agents (representing trust in the entire tertiary trust domain), and performs secondary permission allocation for terminals / users within the scope of permissions granted to the trust domain by the superior authentication and authorization center, and issues access control policies to network access control gateways and resource access control gateways at all levels based on the permission allocation; and so on.
[0039] User agents are used to identify terminals / users and, when necessary, to initiate authentication requests on behalf of terminals / users to verify their identities.
[0040] Network access control gateways and resource access control gateways at all levels accept access control policies issued by certification and authorization centers and regional certification and authorization agents at all levels, and implement access control for networks and resources.
[0041] 2. Application process of the present invention
[0042] The following example uses an environment with two levels of trust domains (such as...). Figure 3 Taking the example shown, this section describes the specific system application processes such as identity registration and resource access (including identity authentication, authorization, and business interaction). The processes for multi-level trust domains follow the same logic.
[0043] (1) Identity registration process:
[0044] ① The Level 1 Regional Authentication Authorization Agent A11 registers its group identity with the Authentication Authorization Center A0 and obtains the group identity identifier C1. The Authentication Authorization Center A0 assigns group permissions PC1{p1, p2, p3, ... pn} to the Level 1 Regional Authentication Authorization Agent A11.
[0045] ② User agent 1 registers the user identity with the first-level regional authentication and authorization agent A11 and obtains the user identity identifier U1. The first-level regional authentication and authorization agent A11 assigns user permissions PU1{p1, p3, ...} to the user within the scope of permissions PC1;
[0046] ③ Similarly, user agent 2 within the same trusted area registers the user identity with the first-level area authentication and authorization agent A11 and obtains the user identity identifier U2. The first-level area authentication and authorization agent A11 assigns user permissions PU2{p1, p2, ...} to the user within the scope of permissions PC1, and so on, to complete the identity registration and permission assignment of all users within the same trusted area.
[0047] ④ Similarly, perform identity registration and permission assignment for Level 1 regional authentication and authorization agent A12 and all users in another trusted region.
[0048] (2) Resource access process:
[0049] ① When the system is activated or external resource access is required, the regional authentication and authorization agent A11 initiates a group identity authentication application to the authentication and authorization center A0 as group user C1. The authentication and authorization center A0 authenticates the identity of user C1 and issues a trust credential TC1. At the same time, based on user C1's access permissions PC1, it issues access control policies to the corresponding network / resource access control gateway, allowing or denying the user holding the trust credential TC1 to access the corresponding resources.
[0050] ②Regional authentication and authorization agents and authentication and authorization centers shall perform identity preservation in accordance with the established identity preservation scheme;
[0051] ③ When user 1 needs to access resources, user agent 1, in the identity of user U1, initiates an individual-based identity authentication application to the regional authentication and authorization agent A11 in the region. The regional authentication and authorization agent A11 authenticates user U1's identity and issues a trust credential TU11. At the same time, based on user U1's access permissions PU1, it issues access control policies to the corresponding network / resource access control gateway, allowing the user holding the trust credential TU11 to access the corresponding resources.
[0052] ④ During the resource access process, User 1's identity is kept alive according to the established identity keep-alive scheme;
[0053] ⑤ User 1 uses trust credential TU11 to initiate access to the accessed resource. When the access message arrives at the network access control gateway, the network access control gateway checks whether the trust credential TU11 is allowed. If it is allowed, the trust credential TU11 is replaced with TC1 to forward the access message; otherwise, the access message is discarded.
[0054] ⑥ When an access control message arrives at the resource access control gateway, the resource access control gateway checks whether the TC1 trust credential is allowed. If it is allowed, access is permitted; otherwise, access is denied.
[0055] It should be noted that the technical solution of this invention does not limit specific authentication and authorization methods and algorithms, but only constrains the system layered architecture, control flow, and resource access flow. Any modifications to the flow, algorithm, or function made by those skilled in the art based on these architectures and flows are included within the scope of protection of this invention. Furthermore, the system composition in the technical solution of this invention refers to functional composition, and does not constrain the specific deployment or fine-grained nature of the functional composition. Any morphological integration and decomposition of these functional components based on the architecture and flow of the technical solution of this invention are included within the scope of protection of this invention.
[0056] It should be noted that, within the scope of protection defined in the claims of this invention, the following embodiments can be combined and / or extended or replaced in any logical manner from the above specific embodiments, such as the disclosed technical principles, disclosed technical features or implicitly disclosed technical features.
[0057] Example 1
[0058] A hierarchical, domain-based authentication and authorization system based on trust transfer includes:
[0059] Certification and authorization center, first-level regional certification and authorization agent, second-level regional certification and authorization agent, user agent, as well as network access control gateway of the accessed network and resource access control gateway of the accessed information resources;
[0060] The authentication and authorization center is used to authenticate the identities and assign permissions to all terminals / users within the first-level trust domain and the authentication and authorization agents of subordinate first-level regions, and to issue access control policies to network access control gateways and resource access control gateways at all levels according to the permission assignment.
[0061] The first-level regional authentication and authorization agent is used to authenticate the identities of all terminals / users and subordinate second-level regional authentication and authorization agents within the second-level trust domain. At the same time, it performs secondary permission allocation for terminals / users within the scope of the permissions granted to this trust domain by the superior authentication and authorization center, and issues access control policies to network access control gateways and resource access control gateways at all levels according to the permission allocation.
[0062] The user agent is used to identify the terminal / user and, when necessary, initiate an identity authentication request on behalf of the terminal / user to confirm the identity of the terminal / user.
[0063] Network access control gateways and resource access control gateways at all levels accept access control policies issued by certification and authorization centers and regional certification and authorization agents at all levels to implement access control for networks and resources.
[0064] Example 2
[0065] Based on Example 1, it also includes: multi-level regional authentication and authorization agents, that is, multiple third-level regional authentication and authorization agents can be set under the second-level regional authentication and authorization agent, and so on.
[0066] Example 3
[0067] A hierarchical, domain-based authentication and authorization method based on trust transitivity includes the following steps:
[0068] Step 1: Divide the entire information system's trust domain into a primary trust domain and a secondary trust domain. Then, divide the secondary trust domain into different tertiary trust domains, and so on down to multiple levels of trust domains.
[0069] Step two: The authentication and authorization center is responsible for building the trust relationships between all terminals / users in the first-level trust domain and all second-level trust domains; the authentication and authorization agent in the first-level region is responsible for building the trust relationships between all terminals / users in the second-level trust domain and all third-level trust domains; and so on to the multi-level trust domains.
[0070] Example 4
[0071] A hierarchical and domain-based authentication and authorization method based on trust transfer, based on the hierarchical and domain-based authentication and authorization system based on trust transfer as described in either Embodiment 1 or Embodiment 2, includes an identity registration process:
[0072] Step S1: Level 1 regional authentication and authorization agent A11 registers its group identity with authentication and authorization center A0 and obtains the group identity identifier C1. Authentication and authorization center A0 assigns group permissions PC1{p1, p2, p3, ..., pn} to Level 1 regional authentication and authorization agent A11.
[0073] Step S2: User agent 1 registers the user identity with the first-level regional authentication and authorization agent A11 and obtains the user identity identifier U1. The first-level regional authentication and authorization agent A11 assigns user permissions PU1{p1, p3, ...} to the user within the scope of permissions PC1.
[0074] Step S3: User agent 2 within the same trusted area registers the user identity with the first-level area authentication and authorization agent A11 and obtains the user identity identifier U2. The first-level area authentication and authorization agent A11 assigns user permissions PU2{p1, p2, ...} to the user within the scope of permissions PC1, and so on, to complete the identity registration and permission assignment of all users within the same trusted area.
[0075] Step S4: Register identities and assign permissions to the Level 1 regional authentication and authorization agent A12 and all users in another trusted region.
[0076] Example 5
[0077] A hierarchical and domain-based authentication and authorization method based on trust transit, based on the hierarchical and domain-based authentication and authorization system based on trust transit as described in either Embodiment 1 or Embodiment 2, includes a resource access process:
[0078] Step SS1: When the system is activated or external resource access is required, the regional authentication and authorization agent A11 initiates a group identity authentication application to the authentication and authorization center A0 as group user C1. The authentication and authorization center A0 authenticates the identity of user C1 and issues a trust credential TC1. At the same time, based on user C1's access permissions PC1, it issues access control policies to the corresponding network / resource access control gateway, allowing or denying the user holding the trust credential TC1 to access the corresponding resources.
[0079] Step SS2: Regional authentication and authorization agents and authentication and authorization centers perform identity preservation according to the established identity preservation scheme;
[0080] Step SS3: When user 1 needs to access resources, user agent 1, in the identity of user U1, initiates an individual-based identity authentication request to the regional authentication and authorization agent A11 in the region. The regional authentication and authorization agent A11 authenticates user U1's identity and issues a trust credential TU11. At the same time, based on user U1's access permissions PU1, it issues access control policies to the corresponding network / resource access control gateway, allowing the user holding the trust credential TU11 to access the corresponding resources.
[0081] Step SS4: During the resource access process, User 1 performs identity preservation according to the established identity preservation scheme.
[0082] Step SS5: User 1 uses trust credential TU11 to initiate access to the accessed resource. When the access packet arrives at the network access control gateway, the network access control gateway checks whether the trust credential TU11 is allowed. If it is allowed, the trust credential TU11 is replaced with TC1 to forward the access packet; otherwise, the access packet is discarded.
[0083] Step SS6: When the access control message arrives at the resource access control gateway, the resource access control gateway verifies whether the TC1 trust credential is allowed. If it is allowed, access is allowed; otherwise, access is denied.
[0084] Example 6
[0085] Based on Example 4, the identity registration process is applied to a ubiquitous interconnected, zero-trust information system environment.
[0086] Example 7
[0087] Based on Example 5, the resource access process is applied to a ubiquitous interconnected, zero-trust information system environment.
[0088] The units described in the embodiments of the present invention can be implemented in software or hardware, and the described units can also be located in a processor. The names of these units do not necessarily limit the specific unit itself.
[0089] According to one aspect of the present invention, a computer program product or computer program is provided, the computer program product or computer program including computer instructions stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and executes the computer instructions, causing the computer device to perform the methods provided in the various optional implementations described above.
[0090] In another aspect, embodiments of the present invention also provide a computer-readable medium, which may be included in the electronic device described in the above embodiments; or it may exist independently and not assembled into the electronic device. The computer-readable medium carries one or more programs, which, when executed by the electronic device, cause the electronic device to perform the methods described in the above embodiments.
Claims
1. A hierarchical sub-domain authentication and authorization system based on trust transfer, characterized in that, Comprise: authentication and authorization center, first-level regional authentication and authorization agent, second-level regional authentication and authorization agent, user agent, and network access control gateway of visited network, resource access control gateway of visited information resource; The authentication and authorization center is used for realizing identity identification and permission distribution of all terminals / users and subordinate first-level regional authentication and authorization agents in the first-level trust domain, and issuing access control policies to network access control gateways and resource access control gateways of all levels according to the permission distribution; The first-level regional authentication and authorization agent is used for realizing identity identification of all terminals / users and subordinate second-level regional authentication and authorization agents in the second-level trust domain, and performing secondary permission distribution of terminals / users within the permission scope granted by the superior authentication and authorization center to the trust domain, and issuing access control policies to network access control gateways and resource access control gateways of all levels according to the permission distribution; The user agent is used for realizing identity identification of terminals / users, and proxying terminals / users to initiate identity authentication request when necessary, and realizing identity confirmation of terminals / users; The network access control gateways and resource access control gateways of all levels accept access control policies issued by the authentication and authorization center and regional authentication and authorization agents of all levels, and are used for implementing access control of network and resource.
2. The hierarchical sub-domain authentication and authorization system based on trust transfer according to claim 1, characterized in that, Further comprise: Multi-level regional authentication and authorization agent, i.e. multiple third-level regional authentication and authorization agents can be set under the second-level regional authentication and authorization agent.
3. A hierarchical sub-domain authentication and authorization method based on trust transfer, characterized in that, The layered and domain authentication and authorization system based on trust transmission according to any one of claims 1 or 2 comprises an identity registration process: Step S1, the first-level regional authentication and authorization agent A11 registers group identity to the authentication and authorization center A0, obtains group identity identification C1, and the authentication and authorization center A0 distributes group permission PC1 {p1, p2, p3, …pn} to the first-level regional authentication and authorization agent A11; Step S2, the user agent 1 registers user identity to the first-level regional authentication and authorization agent A11, obtains user identity identification U1, and the first-level regional authentication and authorization agent A11 distributes user permission PU1 {p1, p3, …} to the user within the permission scope of the permission PC1; Step S3, the user agent 2 in the same trust region registers user identity to the first-level regional authentication and authorization agent A11, obtains user identity identification U2, and the first-level regional authentication and authorization agent A11 distributes user permission PU2 {p1, p2, …} to the user within the permission scope of the permission PC1, and completes identity registration and permission distribution of all users in the same trust region; Step S4, identity registration and permission distribution are performed on the first-level regional authentication and authorization agent and all users in another trust region.
4. A hierarchical sub-domain authentication and authorization method based on trust transfer, characterized in that, The layered and domain authentication and authorization system based on trust transmission according to any one of claims 1 or 2 comprises a resource access process: Step SS1, when the system is opened or needs to access external resources, the regional authentication and authorization agent initiates a group identity authentication application based on the group user C1 to the authentication and authorization center A0, the authentication and authorization center A0 authenticates the identity of C1 and issues a trust credential TC1, and according to the access right PC1 of C1, issues an access control strategy to the corresponding network / resource access control gateway, allowing or refusing the user holding the trust credential TC1 to access the corresponding resource; Step SS2, the regional authentication and authorization agent and the authentication and authorization center perform identity keep-alive according to the established identity keep-alive scheme; Step SS3, when the user needs to access the resource, the user agent 1 initiates an individual identity authentication application based on the user identity U1 to the regional authentication and authorization agent in the region, and the regional authentication and authorization agent authenticates the identity of U1 and issues a trust credential TU11, and according to the access right PU1 of U1, issues an access control strategy to the corresponding network / resource access control gateway, allowing the user holding the trust credential TU11 to access the corresponding resource; Step SS4, during the resource access process of the user, identity keep-alive is performed according to the established identity keep-alive scheme; Step SS5, the user uses the trust credential TU11 to initiate access to the visited resource, when the access message reaches the network access control gateway, the network access control gateway checks whether the trust credential TU11 is allowed, if allowed, the trust credential TU11 is replaced with TC1 to forward the access message, otherwise the access message is discarded; Step SS6, when the access control message reaches the resource access control gateway, the resource access control gateway checks whether the trust credential TC1 is allowed, if allowed, the access is allowed, otherwise the access is refused.
5. The hierarchical sub-domain authentication and authorization method based on trust transfer according to claim 3, characterized in that, The identity registration process is applied to the ubiquitous interconnection and zero-trust information system environment.
6. The hierarchical subfield authentication and authorization method based on trust transfer according to claim 4, characterized in that, The resource access process is applied to the ubiquitous interconnection and zero-trust information system environment.
Citation Information
Patent Citations
Digital copyright identifier identification method and system
CN111130761A