Method, apparatus, electronic device and storage medium for multi-subject cross-network trust transfer

Through the multi-subject cross-network trust transmission method, identity tokens and cross-network algorithm signatures are used to solve the isolation problem between multi-subject networks, information sharing and business collaboration are realized, cross-network trust mechanism is established, and data exchange security and legality are ensured.

CN119135366BActive Publication Date: 2025-07-25INFORMATION CENT OF THE LOGISTICS SUPPORT DEPT OF THE CENT MILITARY COMMISSION
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202410955254.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-07-17
Publication Date
2025-07-25
Estimated Expiration
2044-07-17

AI Technical Summary

Technical Problem

Multi-subject networks are isolated and independent of each other, and cannot effectively connect, resulting in difficulties in information sharing and business collaboration, and secure links are not allowed, data cannot be pushed online, software and hardware domesticization rate is low, and interconnected entities are difficult to authenticate and secure confidential.

Method used

Through the multi-subject cross-network trust transmission method, identity tokens and cross-network algorithm signatures are used to establish a cross-network isolation exchange center to realize cross-network data exchange and identity authentication, including identity authentication, cross-network signature authentication and permission verification, ensuring the legality and security of data exchange.

Benefits of technology

It realizes information sharing and service collaboration between isolated multi-subject networks, establishes a cross-network trust mechanism, provides unified entity identity identification and secure traceability, and ensures the credibility and legality of data exchange.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119135366B_ABST
    Figure CN119135366B_ABST
Patent Text Reader

Abstract

The present invention relates to a method, device, electronic device and storage medium for multi-agent cross-network trust transfer. The multi-agent cross-network trust transfer method includes the steps of: a first network user initiating network data exchange, initiating identity authentication, and obtaining an identity token with an identity identifier; entering the isolation exchange area of the first network, performing cross-network identity authentication, verifying the identity token, and performing cross-network algorithm signature; forming a cross-network isolation exchange center by the isolation exchange area of the first network and the isolation exchange area of the second network, and sending network data and cross-network signature from the isolation exchange area of the first network to the isolation exchange area of the second network; in the isolation exchange area of the second network, using a cross-network identity authentication system to authenticate the cross-network signature; after the cross-network identity authentication is passed, sending network data and the first network signature to the data center area of the second network, performing first network signature authentication identity verification, and if the verification is passed, the content identity of the cross-network data exchange request is legal.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of data sharing and exchange, and in particular to a method, device, electronic device and storage medium for multi-subject cross-network trust transmission. Background Art

[0002] The collaborative interconnection of multiple entities faces problems such as network connectivity, insufficient information sharing, difficulties in business collaboration, poor demand matching, and lack of system specifications. It is difficult to adapt to users from all parties, horizontally cover elements in various fields, and vertically run through the business integration service needs of departments at the strategic, management, and executive levels, which seriously restricts the comprehensive development of the business integration of multiple entities.

[0003] The main problems currently exist are: First, the multi-subject network is not connected. Multiple subjects are isolated and independent from each other, and related elements are carried on different networks, which cannot be effectively connected, making it difficult to support information sharing and business collaboration, restricting the deep integration and development of business. Second, the problem of security links not being allowed. The information network security and confidentiality systems of multiple subjects are different, and data can only be exchanged offline and dare not be pushed online; the localization rate of software and hardware is low, and they dare not be used online; information carriers such as chips are incompatible with each other, and interconnected entities are difficult to authenticate each other, and security and confidentiality are afraid of blind spots.

[0004] Therefore, there is an urgent need for a method of multi-subject cross-network trust transmission that can connect multi-subject networks to achieve information sharing, multi-subject business collaboration, integration and comprehensive development. Summary of the invention

[0005] The technical problem to be solved by the present invention is how to achieve intercommunication between mutually isolated and independent multi-agent networks, and realize information sharing, multi-agent business collaboration and integration.

[0006] To solve the above technical problems, according to one aspect of the present invention, a method for multi-subject cross-network trust transmission is provided, wherein the multi-subject network includes a first network and a second network that are independent of each other, and when trust transmission is required between the first network and the second network, it is achieved through the multi-subject cross-network trust transmission method, the first network and the second network respectively include a data center area and an isolation exchange area, and the isolation exchange area is used to isolate the data center area and access exchange data, and the multi-subject cross-network trust transmission method includes the following steps: Step 1: In the data center of the first network, a first network user initiates network data exchange, and the first network service system initiates identity authentication to the first network identity authentication system to obtain an identity token with an identity identifier, wherein the identity token can be a password or an identity ID; Step 2: In the data center of the first network, a first network user initiates network data exchange, and the first network service system initiates identity authentication to the first network identity authentication system to obtain an identity token with an identity identifier, wherein the identity token can be a password or an identity ID; Step 3: In the data center of the first network, a first network user initiates network data exchange, and the first network service system initiates identity authentication to the first network identity authentication system to obtain an identity token with an identity identifier, wherein the identity token can be a password or an identity ID; Step 4: In the data center of the first network, a first network user initiates network data exchange, and the first network service system initiates identity authentication to the first network identity authentication system to obtain an identity token with an identity identifier, wherein the identity token can be a password or an identity ID; Step 5: In the data center of the first network, a first network user initiates network data exchange, and the first network service system initiates identity authentication to the first network identity authentication system to obtain an identity token with an identity identifier, wherein the identity token can be a password or an identity ID; Step 6: In the data center of the first network, a first network user initiates network data exchange, and the first network service system initiates identity authentication to the first network identity authentication system to obtain an identity token with an identity identifier, wherein the identity token can be a password Step 2: Enter the isolated exchange area of the first network, perform cross-network identity authentication, verify the identity token, and perform cross-network algorithm signature; Step 3: The isolated exchange area of the first network and the isolated exchange area of the second network form a cross-network isolation exchange center, which is used for cross-network exchange between the first network and the second network, and the network data and cross-network signature are sent from the isolated exchange area of the first network to the isolated exchange area of the second network; Step 4: In the isolated exchange area of the second network, a cross-network identity authentication system is used to authenticate the cross-network signature; Step 5: After the cross-network identity authentication is passed, the network data and the first network signature are sent to the data center area of the second network, which are received by the second network system and the first network signature authentication and identity verification are performed. After the verification is passed, the identity of the content of the cross-network data exchange request is legal.

[0007] According to an embodiment of the present invention, step one may include the following steps: S1. A first network user logs in to the first network application system and initiates a cross-network data exchange process; S2. The first network application system initiates identity authentication to the first network identity authentication system and obtains its own identity token; S3. The first network application system queries the first network resource information management service system for the entity identity of the second network application system; S4. The first network application system initiates a cross-network data exchange request to the first network isolation exchange service, and the request content includes the first network application system entity identity, the second network application system entity identity and cross-network data, and carries the first network application system's identity token and the first network application system's signature on the cross-network data exchange request content.

[0008] According to an embodiment of the present invention, step two may include the following steps: S5. The first network isolation and exchange service authenticates the validity of the identity token of the first network application system to the first network identity authentication, and verifies the legality of the cross-network data exchange request content according to the identity token; S6. The first network isolation and exchange service authenticates through the first network authorization management service that the first network application system has the permission to perform cross-network data exchange with the second network application system; S7. The first network isolation and exchange service initiates a cross-network identity conversion request to the first network cross-network identity authentication system. The cross-network identity conversion request content includes the entity identity identifier of the first network application system, the entity identity identifier of the second network application system, and cross-network data, and carries the identity token of the first network isolation and exchange service and the signature of the first network isolation and exchange service on the cross-network identity conversion request content; S8. After receiving the cross-network identity conversion request, the first network cross-network identity authentication system first authenticates the legality of the identity token of the first network isolation and exchange service, and then verifies the legality of the signature of the cross-network identity request content through the identity token to ensure that the requested identity and data are trustworthy. Then, it signs the request through its own cross-network device certificate and cross-network service cryptography machine, and finally returns the converted result to the first network isolation and exchange service; S9. The first network isolation and exchange service imports the cross-network data exchange request content protected by cross-network signature into the first network cross-network data transmission cryptography machine.

[0009] According to an embodiment of the present invention, step three may include the following steps: S10. The first network cross-network data transmission cryptography machine unidirectionally imports the cross-network data exchange request content into the cross-network data transmission cryptography machine of the second network through laser.

[0010] According to an embodiment of the present invention, step four may include the following steps: S11. After receiving the data content, the second network cross-network data transmission cryptography machine sends the cross-network data exchange request content protected by cross-network signature to the second network isolation and exchange service; S12. The second network isolation and exchange service initiates a cross-network data exchange verification request to the second network cross-network identity authentication system; S13. After receiving the cross-network data verification request content, the second network cross-network identity authentication system first verifies the legality of the cross-network data request content according to the cross-network identity authentication system mutual trust strategy to ensure that the cross-network identity and data are trustworthy; then it signs the request through its own second network device certificate and second network cryptography machine; and then returns the converted data to the second network isolation and exchange service.

[0011] According to an embodiment of the present invention, step five may include the following steps: S14. After receiving the converted cross-network data, the second network isolation and exchange service verifies the legality of the cross-network data through the second network certificate and the second network cryptographic machine; then verifies that the government network application system has the permission to exchange data across the network with the second network application system through the second network authorization management service system; S15. After the second network isolation and exchange service signs the request using its own second network device certificate and the second network cryptographic machine, on the premise of verifying the legal identity of the second network application system, it sends the cross-network data exchange request content, its own second network identity token, and its signature on the request content to the second network application system; S16. After receiving the cross-network data exchange request, the second network application system verifies the legality of the identity and signature of the second network isolation and exchange service in the request content through the second network cryptographic machine, and verifies the legality of the identity identifier of the first network application system entity through the second network resource information management service system; after all the legality verifications are completed, it proves that the cross-network data exchange request content has a legal identity and the data is trustworthy.

[0012] According to a second aspect of the present invention, there is provided a multi-subject cross-network trust transfer device. The multi-subject network includes an independent first network and a second network. When trust transfer is required between the first network and the second network, it is realized through the multi-subject cross-network trust transfer device. The first network and the second network each include a data center area and an isolation and exchange area. The isolation and exchange area is used to isolate the data center area and access and exchange data. The multi-subject cross-network trust transfer device includes: a first network service system module, in the data center of the first network, used for a first network user to initiate network data exchange, and the first network service system initiates an identity authentication to the first network identity authentication system to obtain an identity token with an identity identifier; a first network isolation and exchange service module, used to enter the isolation and exchange area of the first network, perform cross-network identity authentication, verify the identity token, and perform cross-network algorithm signature; a cross-network isolation and exchange module, used to form a cross-network isolation and exchange center by the isolation and exchange area of the first network and the isolation and exchange area of the second network, used for cross-network exchange between the first network and the second network, and send network data and cross-network signature from the isolation and exchange area of the first network to the isolation and exchange area of the second network; a second network isolation and exchange service module, used to authenticate the cross-network signature in the isolation and exchange area of the second network using the cross-network identity authentication system; a second network verification module, used to send network data and the first network signature to the data center area of the second network after the cross-network identity authentication is passed, received by the second network system, and perform identity verification of the first network signature authentication. After the verification is passed, the cross-network data exchange request content has a legal identity.

[0013] According to an embodiment of the present invention, the multi - entity cross - network trust transfer device can perform the following steps: A first - network user logs in to a first - network application system through a first - network data center module and initiates a cross - network data exchange process; the first - network application system initiates an identity authentication to a first - network identity authentication system to obtain its own identity token; the first - network application system queries the entity identity identifier of a second - network application system from a first - network resource information management service system; the first - network application system initiates a cross - network data exchange request to a first - network isolation and exchange service, and the request content includes the entity identity identifier of the first - network application system, the entity identity identifier of the second - network application system, and cross - network data, and carries the identity token of the first - network application system and the signature of the first - network application system on the cross - network data exchange request content; the first - network isolation and exchange service module authenticates the validity of the identity token of the first - network application system to the first - network identity authentication and verifies the legality of the cross - network data exchange request content according to the identity token; the first - network isolation and exchange service module authenticates through a first - network authorization management service that the first - network application system has the permission to perform cross - network data exchange with the second - network application system; the first - network isolation and exchange service module initiates a cross - network identity conversion request to a first - network cross - network identity authentication system, and the cross - network identity conversion request content includes the entity identity identifier of the first - network application system, the entity identity identifier of the second - network application system, and cross - network data, and carries the identity token of the first - network isolation and exchange service and the signature of the first - network isolation and exchange service module on the cross - network identity conversion request content; after receiving the cross - network identity conversion request, the first - network cross - network identity authentication system first authenticates the legality of the identity token of the first - network isolation and exchange service, then verifies the legality of the signature of the cross - network identity request content through the identity token to ensure that the requested identity and data are trustworthy, then signs the request through its own cross - network device certificate and cross - network service cryptographic machine, and finally returns the converted result to the first - network isolation and exchange service module; the first - network isolation and exchange service module imports the cross - network data exchange request content protected by cross - network signature into a first - network cross - network data transmission cryptographic machine; the cross - network isolation and exchange module unidirectionally imports the cross - network data exchange request content into the cross - network data transmission cryptographic machine of the second network through a laser unidirectionally via the first - network cross - network data transmission cryptographic machine; after receiving the data content, the second - network cross - network data transmission cryptographic machine sends the cross - network data exchange request content protected by cross - network signature to a second - network isolation and exchange service module; the second - network isolation and exchange service module initiates a cross - network data exchange verification request to a second - network cross - network identity authentication system; after receiving the cross - network data verification request content, the second - network cross - network identity authentication system first verifies the legality of the cross - network data request content according to the cross - network identity authentication system mutual trust strategy to ensure that the cross - network identity and data are trustworthy; then signs the request through its own second - network device certificate and second - network cryptographic machine; and then returns the converted data to the second - network isolation and exchange service module;After the second network isolation and exchange service receiving module receives the converted cross-network data, it verifies the legality of the cross-network data through the second network certificate and the second network cryptographic machine; then the second network verification module verifies through the second network authorization management service system that the first network application system has the permission to exchange data across the network with the second network application system; after the second network isolation and exchange service module signs the request using its own second network device certificate and the second network cryptographic machine, on the premise that the second network verification module verifies that the identity of the second network application system is legal, it sends the cross-network data exchange request content, its own second network identity token, and its signature on the request content to the second network application system; after receiving the cross-network data exchange request, the second network application system verifies the legality of the identity and signature of the second network isolation and exchange service in the request content through the second network cryptographic machine, and verifies the legality of the entity identity identifier of the first network application system through the second network resource information management service system; after all the legality verifications are completed, it proves that the identity of the cross-network data exchange request content is legal and the data is trustworthy.

[0014] According to the third aspect of the present invention, there is provided an electronic device, including: a memory, a processor, and a multi-agent cross-network trust transfer program stored on the memory and executable on the processor. When the multi-agent cross-network trust transfer program is executed by the processor, the steps of the above-mentioned multi-agent cross-network trust transfer method are implemented.

[0015] According to the fourth aspect of the present invention, there is provided a computer storage medium, wherein a multi-agent cross-network trust transfer program is stored on the computer storage medium. When the multi-agent cross-network trust transfer program is executed by the processor, the steps of the above-mentioned multi-agent cross-network trust transfer method are implemented.

[0016] Compared with the prior art, the technical solutions provided by the embodiments of the present invention can at least achieve the following beneficial effects:

[0017] Based on the cryptographic mechanism, the present invention realizes the cross-network trusted transfer of cryptographic operations such as identity and integrity, establishes a cross-network trust mechanism, and provides a unified entity identity identifier, resource information management service, authorization management service, cross-network identity authentication, resource access control gateway, and security traceability and behavior traceability for mutual trust and mutual access between network nodes; enables the interconnection between multiple mutually isolated and independent multi-agent networks, realizes information sharing, multi-agent business collaboration and integration.

[0018] According to the multi-agent cross-network trust transfer method of the present invention, identity identification can be realized, and entity identification management, entity identification storage, entity identification mapping service, and log auditing can be carried out.

[0019] According to the multi-agent cross-network trust transfer method of the present invention, a resource information management service including organizational structure management, user resource management, and application resource management can be realized.

[0020] The method for multi - entity cross - network trust transfer according to the present invention can implement authorization management services including direct authorization, authorization management based on identity models, and authorization management based on role models.

[0021] The method for multi - entity cross - network trust transfer according to the present invention can implement cross - network identity authentication including identity authentication, single sign - on and unified portal, as well as cross - network identity verification, cross - network identity conversion, cross - network trust transfer, cross - network signature conversion, and cross - network trust policy management.

[0022] The method for multi - entity cross - network trust transfer according to the present invention can implement a resource access control gateway including end - user authentication, security proxy, and access control design.

[0023] The method for multi - entity cross - network trust transfer according to the present invention can implement security auditing and behavior traceability, establish a coordinated log collection method and dump method, form audit reports at different levels and that can be refined layer by layer, and process audit data in a timely and effective manner. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings of the embodiments will be briefly introduced below. Obviously, the drawings described below only relate to some embodiments of the present invention and do not limit the present invention.

[0025] Figure 1 is a flowchart showing the multi - entity cross - network trust transfer method according to an embodiment of the present invention;

[0026] Figure 2 is a schematic diagram showing the multi - entity cross - network identity authentication mechanism according to an embodiment of the present invention. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0027] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings of the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the described embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.

[0028] Unless otherwise defined, the technical terms or scientific terms used herein shall have the ordinary meanings as understood by those of ordinary skill in the art to which this invention pertains. The terms "first", "second" and similar terms used in the description and claims of this patent application do not denote any order, quantity or importance, but are only used to distinguish different components. Similarly, terms such as "a" or "an" do not denote a quantity limitation, but mean that there is at least one.

[0029] "Network A", "Network B", "the first network", "the second network" do not refer to a specific network, nor are they limited to a one-way trust transfer. They are only used to distinguish different network entities that are isolated from each other and independent.

[0030] The multi-agent network includes the mutually independent first network and second network. When trust transfer is required between the first network and the second network, it is achieved through the method of multi-agent cross-network trust transfer. The first network and the second network respectively include a data center area and an isolation exchange area, and the isolation exchange area is used to isolate the data center area and access and exchange data.

[0031] Figure 1 is a flowchart showing the multi-agent cross-network trust transfer method according to an embodiment of the present invention; Figure 2 is a schematic diagram showing the multi-agent cross-network identity authentication mechanism according to an embodiment of the present invention.

[0032] As Figure 1 and Figure 2 shown, the method of subject cross-network trust transfer includes the following steps:

[0033] Step 1: In the data center of the first network, a first network user initiates network data exchange. The first network service system initiates an identity authentication to the first network identity authentication system to obtain an identity token with an identity identifier. Among them, the identity token can be a password or an identity ID.

[0034] Step 2: Enter the isolation exchange area of the first network, perform cross-network identity authentication, verify the identity token, and perform cross-network algorithm signature.

[0035] Step 3: The isolation exchange area of the first network and the isolation exchange area of the second network form a cross-network isolation exchange center for cross-network exchange between the first network and the second network. The isolation exchange area of the first network sends network data and cross-network signature to the isolation exchange area of the second network.

[0036] Step 4: In the isolation exchange area of the second network, use the cross-network identity authentication system to authenticate the cross-network signature.

[0037] Step 5: After the cross-network identity authentication is passed, send network data and the first network signature to the data center area of the second network, which is received by the second network system for the first network signature authentication identity verification. If the verification is passed, the content identity of the cross-network data exchange request is legal.

[0038] According to one or some embodiments of the present invention, step one includes the following steps:

[0039] S1. The first network user logs in to the first network application system and initiates a cross-network data exchange process;

[0040] S2. The first network application system initiates an identity authentication to the first network identity authentication system to obtain its own identity token;

[0041] S3. The first network application system queries the entity identity identifier of the second network application system from the first network resource information management service system;

[0042] S4. The first network application system initiates a cross-network data exchange request to the first network isolation and exchange service. The request content includes the entity identity identifier of the first network application system, the entity identity identifier of the second network application system, and cross-network data, and carries the identity token of the first network application system and the signature of the first network application system on the cross-network data exchange request content.

[0043] According to one or some embodiments of the present invention, step two includes the following steps:

[0044] S5. The first network isolation and exchange service authenticates the validity of the identity token of the first network application system to the first network identity authentication and verifies the legality of the cross-network data exchange request content according to the identity token;

[0045] S6. The first network isolation and exchange service authenticates through the first network authorization management service that the first network application system has the permission to perform cross-network data exchange with the second network application system;

[0046] S7. The first network isolation and exchange service initiates a cross-network identity conversion request to the first network cross-network identity authentication system. The cross-network identity conversion request content includes the entity identity identifier of the first network application system, the entity identity identifier of the second network application system, and cross-network data, and carries the identity token of the first network isolation and exchange service and the signature of the first network isolation and exchange service on the cross-network identity conversion request content;

[0047] S8. After receiving the cross-network identity conversion request, the first network cross-network identity authentication system first identifies the legitimacy of the identity token of the first network isolation exchange service, and then verifies the legitimacy of the signature of the cross-network identity request content through the identity token to ensure that the request identity and data are credible, and then signs the request through its own cross-network device certificate and cross-network service cryptographic machine, and finally returns the converted result to the first network isolation exchange service;

[0048] S9. The first network isolation exchange service imports the cross-network data exchange request content after cross-network signature protection into the first network cross-network data transmission cipher machine.

[0049] According to one or some embodiments of the present invention, step three includes the following steps:

[0050] S10. The inter-network data transmission cipher machine of the first network unidirectionally imports the inter-network data exchange request content into the inter-network data transmission cipher machine of the second network through a laser.

[0051] According to one or some embodiments of the present invention, step 4 includes the following steps:

[0052] S11. After receiving the data content, the second network inter-network data transmission cipher sends the inter-network data exchange request content after the inter-network signature protection to the second network isolation exchange service;

[0053] S12, the second network isolation exchange service initiates a cross-network data exchange verification request to the second network cross-network identity authentication system;

[0054] S13. After receiving the cross-network data verification request content, the second network cross-network identity authentication system first verifies the legitimacy of the cross-network data request content according to the cross-network identity authentication system mutual trust strategy to ensure that the cross-network identity and data are credible; then signs the request with its own second network device certificate and second network cryptographic machine; and then returns the converted data to the second network isolation exchange service.

[0055] According to one or some embodiments of the present invention, step five includes the following steps:

[0056] S14. After receiving the converted cross-network data, the second network isolation exchange service verifies the legitimacy of the cross-network data through the second network certificate and the second network cipher machine; then verifies through the second network authorization management service system that the government network application system has the authority to exchange data with the second network application system across networks;

[0057] S15. After the second network isolation and exchange service signs the request using its own second network device certificate and second network cryptographic machine, on the premise of verifying the legal identity of the second network application system, it sends the cross-network data exchange request content, its own second network identity token, and its signature of the request content to the second network application system;

[0058] S16. After receiving the cross-network data exchange request, the second network application system verifies the legality of the identity and signature of the second network isolation and exchange service in the request content through the second network cryptographic machine, and verifies the legality of the entity identity identifier of the first network application system through the second network resource information management service system; after all the legality verifications are completed, it proves that the cross-network data exchange request content has a legal identity and the data is trustworthy.

[0059] Based on the cryptographic mechanism, the present invention realizes the cross-network trusted transmission of cryptographic operations such as identity and integrity, establishes a cross-network trust mechanism, and provides a unified entity identity identifier, resource information management service, authorization management service, cross-network identity authentication, resource access control gateway, and security traceability and behavior traceability for the mutual trust and mutual access between network nodes; enables the interconnection between multiple mutually isolated and independent multi-agent networks, and realizes information sharing, multi-agent business collaboration and integration.

[0060] According to the second aspect of the present invention, a multi-agent cross-network trust transmission device is provided, including: a first network service system module, a first network isolation and exchange service module, a cross-network isolation and exchange module, a second network isolation and exchange service module, and a second network verification module.

[0061] The first network service system module is in the data center of the first network and is used for the first network user to initiate network data exchange. The first network service system initiates an identity authentication to the first network identity authentication system to obtain an identity token with an identity identifier. Among them, the identity token can be a password or an identity ID.

[0062] The first network isolation and exchange service module is used to enter the isolation and exchange area of the first network, perform cross-network identity authentication, verify the identity token, and perform cross-network algorithm signature.

[0063] The cross-network isolation and exchange module is used to form a cross-network isolation and exchange center from the isolation and exchange area of the first network and the isolation and exchange area of the second network, and is used for the cross-network exchange between the first network and the second network. It sends network data and cross-network signatures from the isolation and exchange area of the first network to the isolation and exchange area of the second network.

[0064] The second network isolation and exchange service module is used to authenticate the cross-network signature in the isolation and exchange area of the second network using the cross-network identity authentication system.

[0065] After the cross-network identity authentication is passed by the second network verification module, it sends network data and the first network signature to the data center area of the second network, which is received by the second network system for the first network signature authentication identity verification. If the verification is passed, the content identity of the cross-network data exchange request is legal.

[0066] According to one or some embodiments of the present invention, the device for multi-subject cross-network trust transfer is implemented through the following steps:

[0067] The first network user logs in to the first network application system through the first network data center module and initiates a cross-network data exchange process; the first network application system initiates an identity authentication to the first network identity authentication system to obtain its own identity token; the first network application system queries the entity identity identifier of the second network application system from the first network resource information management service system; the first network application system sends a cross-network data exchange request to the first network isolation exchange service, and the request content includes the entity identity identifier of the first network application system, the entity identity identifier of the second network application system, and cross-network data, and carries the identity token of the first network application system and the signature of the first network application system for the cross-network data exchange request content.

[0068] The first network isolation exchange service module authenticates the validity of the identity token of the first network application system to the first network identity authentication, and verifies the legality of the cross-network data exchange request content according to the identity token; the first network isolation exchange service module authenticates the first network application system's permission to perform cross-network data exchange with the second network application system through the first network authorization management service; the first network isolation exchange service module sends a cross-network identity conversion request to the first network cross-network identity authentication system, and the cross-network identity conversion request content includes the entity identity identifier of the first network application system, the entity identity identifier of the second network application system, and cross-network data, and carries the identity token of the first network isolation exchange service and the signature of the first network isolation exchange service module for the cross-network identity conversion request content; after receiving the cross-network identity conversion request, the first network cross-network identity authentication system first authenticates the legality of the identity token of the first network isolation exchange service, and then verifies the legality of the signature of the cross-network identity request content through the identity token to ensure the credibility of the request identity and data credibility, and then signs the request through its own cross-network device certificate and cross-network service cipher machine, and finally returns the converted result to the first network isolation exchange service module; the first network isolation exchange service module imports the cross-network data exchange request content after cross-network signature protection into the first network cross-network data transmission cipher machine.

[0069] The cross-network isolation exchange module unidirectionally imports the cross-network data exchange request content into the cross-network data transmission cipher machine of the second network through the first network cross-network data transmission cipher machine by laser unidirectionally.

[0070] After receiving the data content, the second network cross-network data transmission cipher machine sends the cross-network data exchange request content after cross-network signature protection to the second network isolation exchange service module; the second network isolation exchange service module initiates a cross-network data exchange verification request to the second network cross-network identity authentication system; after receiving the cross-network data verification request content, the second network cross-network identity authentication system first verifies the legality of the cross-network data request content according to the cross-network identity authentication system mutual trust policy to ensure cross-network identity trust and data trust; then signs the request through its own second network device certificate and second network cipher machine; and then returns the converted data to the second network isolation exchange service module.

[0071] After receiving the converted cross-network data, the second network isolation exchange service receiving module verifies the legality of the cross-network data through the second network certificate and the second network cipher machine; then the second network verification module verifies through the second network authorization management service system that the first network application system has the permission to exchange data across the network with the second network application system; after the second network isolation exchange service module signs the request using its own second network device certificate and second network cipher machine, on the premise that the second network verification module verifies the legal identity of the second network application system, it sends the cross-network data exchange request content, its own second network identity token, and its signature on the request content to the second network application system; after receiving the cross-network data exchange request, the second network application system verifies the legality of the identity and signature of the second network isolation exchange service in the request content through the second network cipher machine, and verifies the legality of the entity identity identifier of the first network application system through the second network resource information management service system; after all the legality verifications are completed, it proves that the cross-network data exchange request content has a legal identity and reliable data.

[0072] According to the multi-subject cross-network trust transfer method of the present invention, identity identification can be realized, and entity identification management, entity identification storage, entity identification mapping service, and log auditing can be carried out.

[0073] According to the multi-subject cross-network trust transfer method of the present invention, resource information management services including organizational structure management, user resource management, and application resource management can be realized.

[0074] According to the multi-subject cross-network trust transfer method of the present invention, authorization management services including direct authorization, identity model-based authorization management, and role model-based authorization management can be realized.

[0075] According to the multi-subject cross-network trust transfer method of the present invention, cross-network identity authentication including identity authentication, single sign-on and unified portal, as well as cross-network identity verification, cross-network identity conversion, cross-network trust transfer, cross-network signature conversion, and cross-network trust policy management can be realized.

[0076] The method for multi - entity cross - network trust transfer according to the present invention can implement a resource access control gateway including end - user authentication, security proxy, and access control design.

[0077] The method for multi - entity cross - network trust transfer according to the present invention can implement security auditing and behavior traceability, establish a coordinated log collection method and dump method, form audit reports at different levels and which can be refined layer by layer, and process audit data timely and effectively.

[0078] According to another aspect of the present invention, there is provided a device for multi - entity cross - network trust transfer, including: a memory, a processor, and a multi - entity cross - network trust transfer program stored on the memory and executable on the processor. When the multi - entity cross - network trust transfer program is executed by the processor, the steps of the above - mentioned multi - entity cross - network trust transfer method are implemented.

[0079] The present invention also provides a computer storage medium.

[0080] The computer storage medium stores a multi - entity cross - network trust transfer program. When the multi - entity cross - network trust transfer program is executed by the processor, the steps of the above - mentioned multi - entity cross - network trust transfer method are implemented.

[0081] Among them, the method implemented when the multi - entity cross - network trust transfer program running on the processor is executed can refer to each embodiment of the multi - entity cross - network trust transfer method of the present invention, and will not be elaborated here.

[0082] The present invention also provides a computer program product.

[0083] The computer program product of the present invention includes a multi - entity cross - network trust transfer program. When the multi - entity cross - network trust transfer program is executed by the processor, the steps of the multi - entity cross - network trust transfer method as described above are implemented.

[0084] Among them, the method implemented when the multi - entity cross - network trust transfer program running on the processor is executed can refer to each embodiment of the multi - entity cross - network trust transfer method of the present invention, and will not be elaborated here.

[0085] Through the description of the above embodiments, those skilled in the art can clearly understand that the above-described example methods can be implemented by means of software plus a necessary general hardware platform. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art can be embodied in the form of a software product. This computer software product is stored in a storage medium as described above (such as ROM / RAM, magnetic disk, optical disk), and includes several instructions to enable a terminal device (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in various embodiments of the present invention.

[0086] The above description is only a demonstration implementation of the present invention and is not used to limit the protection scope of the present invention. The protection scope of the present invention is determined by the appended claims.

Claims

1. A method for multi-subject cross-network trust transfer, wherein the multi-subject network includes a first network and a second network that are independent of each other, and when trust transfer is required between the first network and the second network, the method for multi-subject cross-network trust transfer is used to achieve it, wherein the first network and the second network include a data center area and an isolation exchange area, respectively, and the isolation exchange area is used to isolate the data center area and access exchange data, The method for multi-subject cross-network trust transfer comprises the following steps: Step 1: In the data center of the first network, the first network user initiates network data exchange, and the first network service system initiates identity authentication to the first network identity authentication system to obtain an identity token with an identity identifier; Step 2: Enter the isolated exchange area of the first network, perform cross-network identity authentication, verify the identity token, and perform cross-network algorithm signature; Step 3: The isolated exchange area of the first network and the isolated exchange area of the second network form a cross-network isolated exchange center for performing cross-network exchange between the first network and the second network, and the isolated exchange area of the first network sends network data and cross-network signatures to the isolated exchange area of the second network; Step 4: In the isolated exchange area of the second network, a cross-network identity authentication system is used to authenticate the cross-network signature; Step 5: After the cross-network identity authentication is passed, the network data and the second network signature are sent to the data center area of the second network, which is received by the second network system and the first network signature authentication and identity verification are performed. After the verification is passed, the cross-network data exchange request content identity is legal. Wherein, step 2 includes the following steps: S7. The first network isolation exchange service initiates a cross-network identity conversion request to the first network cross-network identity authentication system. The cross-network identity conversion request includes the first network application system entity identity, the second network application system entity identity and cross-network data, and carries the identity token of the first network isolation exchange service and the signature of the first network isolation exchange service on the cross-network identity conversion request content; S8. After receiving the cross-network identity conversion request, the first network cross-network identity authentication system first identifies the legitimacy of the identity token of the first network isolation exchange service, and then verifies the legitimacy of the signature of the cross-network identity request content through the identity token to ensure that the request identity and data are credible, and then signs the request through its own cross-network device certificate and cross-network service cryptographic machine, and finally returns the converted result to the first network isolation exchange service.

2. The method for multi-agent cross-network trust transfer according to claim 1, wherein, Step 1 includes the following steps: S1. A first network user logs in to a first network application system and initiates a cross-network data exchange process; S2, the first network application system initiates identity authentication to the first network identity authentication system and obtains its own identity token; S3, the first network application system queries the first network resource information management service system for the entity identity of the second network application system; S4. The first network application system initiates a cross-network data exchange request to the first network isolation exchange service. The request content includes the entity identity of the first network application system, the entity identity of the second network application system and the cross-network data, and carries the identity token of the first network application system and the signature of the first network application system on the cross-network data exchange request content.

3. The method for multi-agent cross-network trust transfer as described in claim 1, wherein Step 2 further includes the following steps: S5. The first network isolation and exchange service authenticates the validity of the identity token of the first network application system to the first network identity authentication, and verifies the legality of the cross-network data exchange request content according to the identity token; S6. The first network isolation and exchange service authenticates that the first network application system has the permission to perform cross-network data exchange with the second network application system through the first network authorization management service; S9. The first network isolation and exchange service imports the cross-network data exchange request content after cross-network signature protection into the first network cross-network data transmission cryptograph.

4. The method for multi - entity cross - network trust transfer as described in claim 1, wherein, Step 3 includes the following steps: S10. The first network cross-network data transmission cryptograph unidirectionally imports the cross-network data exchange request content into the cross-network data transmission cryptograph of the second network through laser unidirectionality.

5. The method for multi - subject cross - network trust transfer according to claim 1, wherein, Step 4 includes the following steps: S11. After receiving the data content, the second network cross-network data transmission cryptograph sends the cross-network data exchange request content after cross-network signature protection to the second network isolation and exchange service; S12. The second network isolation and exchange service initiates a cross-network data exchange verification request to the second network cross-network identity authentication system; S13. After receiving the cross-network data verification request content, the second network cross-network identity authentication system first verifies the legality of the cross-network data request content according to the mutual trust strategy of the cross-network identity authentication system to ensure cross-network identity trust and data trust; Then, it signs the request through its own second network device certificate and the second network cryptograph; and then returns the converted data to the second network isolation and exchange service.

6. The method for multi - entity cross - network trust transfer as claimed in claim 1, wherein, Step 5 includes the following steps: S14. After receiving the converted cross-network data, the second network isolation and exchange service verifies the legality of the cross-network data through the second network certificate and the second network cryptograph; and then verifies that the government network application system has the permission to perform cross-network data exchange with the second network application system through the second network authorization management service system; S15. After signing the request with its own second network device certificate and the second network cryptograph, the second network isolation and exchange service sends the cross-network data exchange request content, its own second network identity token, and its signature on the request content to the second network application system on the premise of verifying the legal identity of the second network application system; S16. After receiving the cross-network data exchange request, the second network application system verifies the legality of the identity and signature of the second network isolation and exchange service in the request content through the second network cryptograph, and verifies the legality of the entity identity identifier of the first network application system through the second network resource information management service system; after all the legality verifications are completed, it proves that the cross-network data exchange request content has a legal identity and reliable data.

7. A multi-subject cross-network trust transfer device, the multi-subject network includes an independent first network and a second network, when trust transfer is required between the first network and the second network, it is realized through the multi-subject cross-network trust transfer device, the first network and the second network respectively include a data center area and an isolation and exchange area, and the isolation and exchange area is used to isolate the data center area and access and exchange data, The multi-subject cross-network trust transfer device includes: The first network service system module, in the data center of the first network, is used for first network users to initiate network data exchange. The first network service system initiates an identity authentication to the first network identity authentication system to obtain an identity token with an identity identifier. The first network isolation and exchange service module is used to enter the isolation and exchange area of the first network, perform cross-network identity authentication, verify the identity token, and perform cross-network algorithm signature. Among them, the first network isolation and exchange service initiates a cross-network identity conversion request to the first network cross-network identity authentication system. The content of the cross-network identity conversion request includes the entity identity identifier of the first network application system, the entity identity identifier of the second network application system, and cross-network data, and carries the identity token of the first network isolation and exchange service and the signature of the first network isolation and exchange service for the content of the cross-network identity conversion request. After receiving the cross-network identity conversion request, the first network cross-network identity authentication system first authenticates the legality of the identity token of the first network isolation and exchange service, then verifies the legality of the signature of the cross-network identity request content through the identity token to ensure the credibility of the requested identity and data, then signs the request through its own cross-network device certificate and cross-network service cryptographic machine, and finally returns the converted result to the first network isolation and exchange service. The cross-network isolation and exchange module is used to form a cross-network isolation and exchange center by the isolation and exchange area of the first network and the isolation and exchange area of the second network, for cross-network exchange between the first network and the second network, and send network data and cross-network signature from the isolation and exchange area of the first network to the isolation and exchange area of the second network. The second network isolation and exchange service module is used to authenticate the cross-network signature in the isolation and exchange area of the second network using the cross-network identity authentication system. The second network verification module is used to send network data and the second network signature to the data center area of the second network after the cross-network identity authentication is passed. The second network system receives it and performs the identity verification of the first network signature authentication. After the verification is passed, the identity of the cross-network data exchange request content is legal.

8. The apparatus for multi - entity cross - network trust transfer according to claim 7, wherein, The device for multi-subject cross-network trust transfer performs the following steps: The first network user logs in to the first network application system through the first network data center module and initiates a cross-network data exchange process. The first network application system initiates an identity authentication to the first network identity authentication system to obtain its own identity token. The first network application system queries the entity identity identifier of the second network application system from the first network resource information management service system. The first network application system initiates a cross-network data exchange request to the first network isolation and exchange service. The request content includes the entity identity identifier of the first network application system, the entity identity identifier of the second network application system, and cross-network data, and carries the identity token of the first network application system and the signature of the first network application system for the content of the cross-network data exchange request. The first network isolation and exchange service module authenticates the validity of the identity token of the first network application system to the first network identity authentication, and verifies the legality of the cross-network data exchange request content according to the identity token; the first network isolation and exchange service module authenticates through the first network authorization management service that the first network application system has the permission to perform cross-network data exchange with the second network application system; the first network isolation and exchange service module initiates a cross-network identity conversion request to the first network cross-network identity authentication system. The content of the cross-network identity conversion request includes the entity identity identifier of the first network application system, the entity identity identifier of the second network application system, and cross-network data, and carries the identity token of the first network isolation and exchange service and the signature of the first network isolation and exchange service module on the cross-network identity conversion request content; after receiving the cross-network identity conversion request, the first network cross-network identity authentication system first authenticates the legality of the identity token of the first network isolation and exchange service, and then verifies the legality of the signature of the cross-network identity request content through the identity token to ensure the credibility of the requested identity and data. Then, it signs the request through its own cross-network device certificate and cross-network service cryptographic machine, and finally returns the converted result to the first network isolation and exchange service module; The first network isolation and exchange service module imports the cross-network data exchange request content after cross-network signature protection into the first network cross-network data transmission cryptographic machine; The cross-network isolation and exchange module unidirectionally imports the cross-network data exchange request content into the cross-network data transmission cryptographic machine of the second network through the first network cross-network data transmission cryptographic machine by laser; After receiving the data content, the second network cross-network data transmission cryptographic machine sends the cross-network data exchange request content after cross-network signature protection to the second network isolation and exchange service module; the second network isolation and exchange service module initiates a cross-network data exchange verification request to the second network cross-network identity authentication system; after receiving the cross-network data verification request content, the second network cross-network identity authentication system first verifies the legality of the cross-network data request content according to the cross-network identity authentication system mutual trust strategy to ensure the credibility of the cross-network identity and data; Then it signs the request through its own second network device certificate and second network cryptographic machine; Then it returns the converted data to the second network isolation and exchange service module; After receiving the converted cross-network data, the second network isolation and exchange service receiving module verifies the legality of the cross-network data through the second network certificate and the second network cryptographic machine; then the second network verification module verifies through the second network authorization management service system that the first network application system has the permission to perform cross-network data exchange with the second network application system; after the second network isolation and exchange service module signs the request using its own second network device certificate and second network cryptographic machine, on the premise that the second network verification module verifies the legal identity of the second network application system, it sends the cross-network data exchange request content, its own second network identity token, and its own signature on the request content to the second network application system; After receiving a cross-network data exchange request, the second network application system verifies the legality of the identity and signature of the second network isolation exchange service in the request content through the second network cipher machine, and verifies the legality of the entity identity identifier of the first network application system through the second network resource information management service system; after all the legality verifications are completed, it proves that the identity of the cross-network data exchange request content is legal and the data is trustworthy.

9. An electronic device, comprising: A memory, a processor, and a multi-agent cross-network trust transfer program stored on the memory and executable on the processor, the multi-agent cross-network trust transfer program implementing the steps of the multi-agent cross-network trust transfer method according to any one of claims 1 to 6 when executed by the processor.

10. A computer storage medium, wherein, A multi-agent cross-network trust transfer program is stored on the computer storage medium, and the multi-agent cross-network trust transfer program implements the steps of the multi-agent cross-network trust transfer method according to any one of claims 1 to 6 when executed by a processor.

Citation Information

Patent Citations

  • Service data cross-network switching system in double-wiring network physical isolation environment

    CN117201110A