Inter-domain isolation system, method and equipment based on identification password
Through an inter-domain isolation system based on identification passwords, end-to-end normal isolation and fine-grained access control between different business network domains is realized, solving the problems of communication terminal identity authentication and data security transmission that cannot be achieved in the prior art, and improving network security and controllability.
Patent Information
- Application Number
- CN202311774568.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-21
- Publication Date
- 2025-06-24
AI Technical Summary
The prior art cannot achieve end-to-end normal isolation between different business network domains, and cannot meet the needs of identification of communication terminal identity and fine-grained access control between domains.
The inter-domain isolation system based on identification passwords is adopted, including identification of security terminal groups, identification of security domain isolation gateway groups, and unified security policy management platform. Through two-way authentication and key negotiation, secure data transmission and access control between domains are realized.
It realizes the secure data transmission between two identified security terminals within and between domains, ensures the authenticity of the identity of the communication terminal, and realizes the approval and security policy management of inter-domain access, improving network security and controllability.
Smart Images

Figure CN120200761A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of inter-domain isolation, and particularly to an inter-domain isolation system, method and device based on identity-based cryptography. Background Art
[0002] Although technologies such as traditional firewalls and network gates based on rule isolation, and virtual local area networks (VLANs) based on logical isolation, to a certain extent, meet the basic requirements of inter-domain isolation, they do not provide the function of secure data transmission, nor can they solve the problem of the expansion of risks brought about by the breakthrough within the network, and they cannot meet the requirements for authenticating the authenticity of communication terminal identities. The IPSec VPN technology based on public key infrastructure only realizes the authentication between the end and the VPN server. After the authentication is completed, all addresses in the private network can be accessed, which cannot meet the requirements of end-to-end fine-grained access control between domains.
[0003] Therefore, how to achieve end-to-end normal isolation between different service network domains and secure interconnection on demand has become an urgent problem to be solved in this field. Summary of the Invention
[0004] The purpose of the present invention is to provide an inter-domain isolation system, method and device based on identity-based cryptography to achieve secure data transmission between two identity-secure terminals within a domain; mutual authentication and key negotiation between two identity-secure domain isolation gateways; secure data transmission between two identity-secure terminals between domains; as well as functions such as secure distribution of identity keys, approval of inter-domain access applications, management and distribution of inter-domain security policies, management of identity-secure terminals, and user management.
[0005] To achieve the above purpose, the present invention provides the following solutions:
[0006] In a first aspect, the present invention provides an inter-domain isolation system based on identity-based cryptography, including:
[0007] An identity-secure terminal group, an identity-secure domain isolation gateway group, and a unified security policy management platform;
[0008] The identity-secure terminal group, the identity-secure domain isolation gateway group, and the unified security policy management platform are sequentially connected through an Ethernet network.
[0009] Optionally, the identity-secure terminal group includes: a first identity-secure terminal A1, a second identity-secure terminal A2, a first identity-secure terminal B1, and a second identity-secure terminal B2;
[0010] The identity-secure domain isolation gateway group includes: a first identity-secure domain isolation gateway GA and a second identity-secure domain isolation gateway GB;
[0011] Both the first identity security terminal A1 and the second identity security terminal A2 are connected to the first identity security domain isolation gateway GA via Ethernet, and the first identity security domain isolation gateway GA is connected to the unified security policy management platform via Ethernet;
[0012] Both the first identity security terminal B1 and the second identity security terminal B2 are connected to the second identity security domain isolation gateway GB via Ethernet, and the second identity security domain isolation gateway GB is connected to the unified security policy management platform via Ethernet;
[0013] The first identity security domain isolation gateway GA, the first identity security terminal A1, and the second identity security terminal A2 constitute production domain A;
[0014] The second identity security domain isolation gateway GB, the first identity security terminal B1, and the second identity security terminal B2 constitute production domain B.
[0015] In a second aspect, the present invention provides an inter-domain isolation method based on identity cryptography, including:
[0016] Secure data transmission between two identity security terminals within production domain A or within production domain B;
[0017] Secure data transmission between two identity security terminals between production domain A and production domain B.
[0018] Optionally, the secure data transmission between two identity security terminals within production domain A or within production domain B specifically includes the following steps:
[0019] The first identity security terminal A1 requests a connection to the second identity security terminal A2;
[0020] The second identity security terminal A2 generates a random number r1 as challenge information;
[0021] The second identity security terminal A2 returns the challenge information r1 to the first identity security terminal A1;
[0022] The first identity security terminal A1 calls its own identity composite private key to sign the challenge information r1 as a challenge response;
[0023] The first identity security terminal A1 generates a random number r2 as authentication challenge information;
[0024] The first identity security terminal A1 sends the signature data and the authentication challenge information r2 to the second identity security terminal A2;
[0025] The second identity security terminal A2 calculates the public key of the first identity security terminal A1 based on the identity of the first identity security terminal A1, and verifies the signature to complete the authenticity authentication of the first identity security terminal A1;
[0026] The second identity security terminal A2 signs the authentication challenge information r2 with its own identity composite private key as the response data;
[0027] The second identity security terminal A2 returns the signed response data to the first identity security terminal A1;
[0028] The first identity security terminal A1 calculates the public key of the second identity security terminal A2 based on the identity of the second identity security terminal A2 and verifies the signature to determine the authenticity of the second identity security terminal A2;
[0029] The first identity security terminal A1 and the second identity security terminal A2 encrypt and decrypt the transmitted data with r1^r2 as the session key of their virtual security channel.
[0030] Optionally, the secure data transmission between the two identity security terminals between the production domain A and the production domain B specifically includes the following steps:
[0031] The first identity security terminal A1 in the production domain A sends a connection request to the first identity security domain isolation gateway GA, requesting to connect to the first identity security terminal B1 in the production domain B;
[0032] The first identity security domain isolation gateway GA determines whether the connection request conforms to the security policy;
[0033] If the connection request conforms to the security policy, the first identity security domain isolation gateway GA submits a connection request to the unified security management platform;
[0034] The administrator of the unified security management platform reviews the connection request;
[0035] After the review is passed, the unified security management platform forwards the review result to the second identity security domain isolation gateway GB;
[0036] The second identity security domain isolation gateway GB returns a response to the unified security management platform;
[0037] The unified security management platform sends the domain public key of the first identity security domain isolation gateway GA to the second identity security domain isolation gateway GB in the production domain B through a security protocol; and sends the domain public key of the second identity security domain isolation gateway GB to the first identity security domain isolation gateway GA in the production domain A through a security protocol;
[0038] The unified security management platform simultaneously generates two temporary shared authentication keys for identifying security terminals and distributes them to the first identifying security terminal A1 in production domain A and the first identifying security terminal B1 in production domain B respectively;
[0039] The first identifying security terminal A1 sends a connection request to the first identifying security terminal B1 through the first identifying security domain isolation gateway GA;
[0040] The first identifying security terminal B1 generates a random number r1 as challenge information and returns it to the first identifying security terminal A1;
[0041] The first identifying security terminal A1 calculates the MAC for the challenge information r1 using the temporary shared authentication key distributed by the unified security management platform;
[0042] The first identifying security terminal A1 generates a random number r2 as challenge information and the response data MAC and sends them to the first identifying security terminal B1;
[0043] The first identifying security terminal B1 verifies the MAC code to determine the authenticity of the first identifying security terminal A1;
[0044] After two-way authentication, r1^r2 is used as the session key of the established virtual security channel to encrypt and decrypt the transmitted data.
[0045] Thirdly, the present invention provides an electronic device, including a memory and a processor. The memory is used for storing a computer program, and the processor runs the computer program to enable the electronic device to execute the above-mentioned domain isolation method based on identity cryptography.
[0046] Fourthly, the present invention provides a computer-readable storage medium, which is characterized in that it stores a computer program, and when the computer program is executed by a processor, it implements the above-mentioned domain isolation method based on identity cryptography.
[0047] According to the specific embodiments provided by the present invention, the following technical effects are disclosed:
[0048] The present invention adopts the interconnection rule full life cycle management technology of "normal isolation, interconnected as needed", and uses the unified security management platform to securely store the domain public keys of each domain; based on the pre-configured platform public key, it realizes the secure exchange of the domain public keys of both parties for secure interconnection; the unified security management platform controls the other-domain public keys of each domain gateway to ensure the secure use and secure destruction of the other-domain public keys, and realizes the life cycle management of the domain public keys.
[0049] Adopting cross-domain end-to-end authentication technology, the difficulty of cross-domain end-to-end authentication lies in realizing end-to-end interconnection through the domain gateway. The terminal uses the temporary shared authentication key distributed by the identity security domain isolation gateway to realize identity authentication and key negotiation between ends.
[0050] Adopt the hierarchical management technology of identity keys, and use a unified security management platform to uniformly manage the domain public keys of each layer of domain gateways; adopt the upper-layer domain gateway to hierarchically manage the domain public keys of the lower-layer domain gateways. Brief Description of the Drawings
[0051] In order to more clearly illustrate the technical solutions in the embodiments of the present invention or the prior art, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0052] Figure 1 Schematic diagram of the inter-domain isolation system based on identity cryptography provided by the present invention;
[0053] Figure 2 End-to-end identity authentication flowchart of the in-domain identity security terminal device provided by the present invention;
[0054] Figure 3 Identity authentication flowchart of the inter-domain identity security terminal provided by the present invention. Detailed Embodiments
[0055] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the drawings in the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, rather than all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0056] The purpose of the present invention is to provide an inter-domain isolation system, method and device based on identity cryptography to achieve secure data transmission between two identity security terminals within a domain; mutual authentication and key negotiation between two identity security domain isolation gateways; secure data transmission between two identity security terminals between domains; as well as functions such as secure distribution of identity keys, approval of inter-domain access applications, management and distribution of inter-domain security policies, management of identity security terminals, and user management.
[0057] To make the above objects, features and advantages of the present invention more obvious and understandable, the present invention will be further described in detail below with reference to the drawings and specific embodiments.
[0058] Embodiment 1
[0059] See Figure 1, the present invention provides an inter-domain isolation system based on identity-based cryptography, specifically including: an identity security terminal group, an identity security domain isolation gateway group, and a unified security policy management platform;
[0060] The identity security terminal group, the identity security domain isolation gateway group, and the unified security policy management platform are sequentially connected through Ethernet links.
[0061] The identity security terminal group includes: a first identity security terminal A1, a second identity security terminal A2, a first identity security terminal B1, and a second identity security terminal B2;
[0062] The identity security domain isolation gateway group includes: a first identity security domain isolation gateway GA and a second identity security domain isolation gateway GB;
[0063] Both the first identity security terminal A1 and the second identity security terminal A2 are connected to the first identity security domain isolation gateway GA through Ethernet, and the first identity security domain isolation gateway GA is connected to the unified security policy management platform through Ethernet;
[0064] Both the first identity security terminal B1 and the second identity security terminal B2 are connected to the second identity security domain isolation gateway GB through Ethernet, and the second identity security domain isolation gateway GB is connected to the unified security policy management platform through Ethernet;
[0065] The first identity security domain isolation gateway GA, the first identity security terminal A1, and the second identity security terminal A2 form a production domain A;
[0066] The second identity security domain isolation gateway GB, the first identity security terminal B1, and the second identity security terminal B2 form a production domain B.
[0067] This system realizes the secure data transmission between two identity security terminals within a domain; the mutual authentication and key negotiation between two identity security domain isolation gateways; the secure data transmission between two identity security terminals across domains; as well as functions such as identity key secure distribution, inter-domain access application approval, management and distribution of inter-domain security policies, identity security terminal management, and user management.
[0068] Although physically, the identity security domain isolation gateways of each domain are network reachable. However, this connectivity is only physical connectivity. The gateway of one domain does not know the domain public keys of other domains and cannot directly exchange domain public keys with the identity security domain isolation gateways of other domains. Therefore, by default, two domains are truly cryptographically isolated. That is, when the gateway of production domain A wants to actively connect to the gateway of production domain B, without the permission of the unified security management platform, production domain B cannot recognize production domain A, so a secure channel between production domain A and production domain B cannot be established. In other words, the devices within one domain are invisible to another domain, so a cross-domain secure connection cannot be established, let alone mutual authentication and secure communication. Therefore, one domain is naturally isolated from other domains, forming an independent closed environment.
[0069] When collaboration and communication are needed between domains, the barriers between domains can be broken through and cross-domain secure connections can be established through the authorization and control of the unified security management platform, realizing cross-domain secure interconnection. The specific implementation steps are as follows:
[0070] Each identity security domain isolation gateway pre-configures the public key of the unified security management platform;
[0071] Each gateway establishes a secure tunnel with the unified security management platform through this public key to realize the secure upload and download of domain public keys;
[0072] Each identity security domain isolation gateway independently generates a domain key pair, securely uploads the domain public key to the unified security management platform and stores it securely, forming a list of domain public keys for all domains;
[0073] The unified security management platform configures the secure interconnection rules for each domain, generates security policies according to the secure interconnection rules and securely distributes them to each identity security domain isolation gateway;
[0074] The unified security management platform securely distributes the public keys of the other domains required to establish connections between security domains according to the secure interconnection rules, and determines the full domain public key exchange and partial domain public key exchange according to the one-way and two-way attributes;
[0075] When device A1 in production domain A needs to conduct temporary cross-domain secure communication with device B2 in production domain B, gateway A first needs to send a request to the unified security management platform. The request content includes the identity of production domain A, the identity of device A1 within the domain, the identity of production domain B, the identity of device B2 within the domain, the reason for communication, and the communication duration, etc.
[0076] After the unified security management platform reviews the interconnection request, if it agrees for both parties to conduct secure communication, the security management center of the unified security management platform securely distributes the domain public keys and secure interconnection execution policies of both communication parties;
[0077] Before the gateway A and the gateway B start communicating between devices, a secure channel is established based on the domain public key, and a shared authentication key k is generated for the device A1 and the device B2 AB and securely distributed to the device A1 and the device B2;
[0078] Then, the device A1 and the device B2 will use the HMAC value based on k AB as the verification value to perform device authentication and establish a secure tunnel; in the above process, the communication in each link is authenticated and confidential, so as to realize cross-domain authentication and confidential communication.
[0079] When the confidential communication between the two parties ends, the gateway A and the gateway B delete the domain public keys of each other according to the security policy. After the deletion is completed, the production domain A and the production domain B return to the initial isolated state.
[0080] Embodiment 2
[0081] Based on the identity-based cryptography inter-domain isolation system in Embodiment 1, the present invention correspondingly provides an identity-based cryptography inter-domain isolation method, and the method includes:
[0082] Data secure transmission between two identity-secure terminals within the production domain A or within the production domain B;
[0083] Data secure transmission between two identity-secure terminals between the production domain A and the production domain B.
[0084] Among them, referring to Figure 2 , the data secure transmission between two identity-secure terminals within the production domain A or within the production domain B specifically includes the following steps:
[0085] The first identity-secure terminal A1 requests a connection to the second identity-secure terminal A2;
[0086] The second identity-secure terminal A2 generates a random number r1 as a challenge message;
[0087] The second identity-secure terminal A2 returns the challenge message r1 to the first identity-secure terminal A1;
[0088] The first identity-secure terminal A1 calls its own identity composite private key to sign the challenge message r1 as a challenge response;
[0089] The first identity-secure terminal A1 generates a random number r2 as an authentication challenge message;
[0090] The first identity-secure terminal A1 sends the signature data and the authentication challenge message r2 to the second identity-secure terminal A2;
[0091] The second identity security terminal A2 calculates the public key of the first identity security terminal A1 based on the identity of the first identity security terminal A1, and verifies the signature to complete the authenticity authentication of the first identity security terminal A1;
[0092] The second identity security terminal A2 signs the authentication challenge information r2 with its own identity composite private key as the response data;
[0093] The second identity security terminal A2 returns the signed response data to the first identity security terminal A1;
[0094] The first identity security terminal A1 calculates the public key of the second identity security terminal A2 based on the identity of the second identity security terminal A2 and verifies the signature to determine the authenticity of the second identity security terminal A2;
[0095] After the above process passes, the first identity security terminal A1 and the second identity security terminal A2 use r1^r2 as the session key of the virtual security channel between the two to encrypt and decrypt the transmitted data.
[0096] See Figure 3 , the secure data transmission between the two identity security terminals between the production domain A and the production domain B specifically includes the following steps:
[0097] The first identity security terminal A1 in the production domain A sends a connection request to the first identity security domain isolation gateway GA, requesting to connect to the first identity security terminal B1 in the production domain B;
[0098] The first identity security domain isolation gateway GA determines whether the connection request conforms to the security policy;
[0099] If the connection request conforms to the security policy, the first identity security domain isolation gateway GA submits the connection request to the unified security management platform;
[0100] The administrator of the unified security management platform reviews the connection request;
[0101] After the review passes, the unified security management platform forwards the review result to the second identity security domain isolation gateway GB;
[0102] The second identity security domain isolation gateway GB returns the response to the unified security management platform;
[0103] The unified security management platform sends the domain public key of the first identity security domain isolation gateway GA to the second identity security domain isolation gateway GB in the production domain B through the security protocol; and sends the domain public key of the second identity security domain isolation gateway GB to the first identity security domain isolation gateway GA in the production domain A through the security protocol;
[0104] The unified security management platform simultaneously generates two temporary shared authentication keys for identifying security terminals, and sends them to the first identified security terminal A1 in production domain A and the first identified security terminal B1 in production domain B respectively;
[0105] The first identified security terminal A1 sends a connection request to the first identified security terminal B1 through the first identified security domain isolation gateway GA;
[0106] The first identified security terminal B1 generates a random number r1 as a challenge message and returns it to the first identified security terminal A1;
[0107] The first identified security terminal A1 calculates the MAC of the challenge message r1 using the temporary shared authentication key distributed by the unified security management platform;
[0108] The first identified security terminal A1 generates a random number r2 as a challenge message and sends the response data MAC to the first identified security terminal B1;
[0109] The first identified security terminal B1 verifies the MAC code to determine the authenticity of the first identified security terminal A1;
[0110] After two-way authentication, r1^r2 is used as the session key of the established virtual security channel to encrypt and decrypt the transmitted data.
[0111] The end-to-end identification authentication technology includes the end-to-end identification authentication technology between identified security terminals within a domain, the end-to-end identification authentication technology between two identified security domain isolation gateways, and the end-to-end identification authentication technology between identified security terminals in different security domains.
[0112] Embodiment 3
[0113] Embodiment 3 of the present invention provides an electronic device, including a memory and a processor. The memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the domain isolation method based on identity cryptography provided in Embodiment 2.
[0114] Embodiment 4
[0115] Based on the description of Embodiment 3, Embodiment 4 of the present invention provides a storage medium, on which a computer program is stored. The computer program can be executed by a processor to implement the domain isolation method based on identity cryptography in Embodiment 2.
[0116] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the various embodiments can be referred to each other.
[0117] In this article, specific examples are used to illustrate the principles and implementation manners of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation on the present invention.
Claims
1. An inter-domain isolation system based on identity-based cryptography, characterized in that Including: An identity security terminal group, an identity security domain isolation gateway group, and a unified security policy management platform; The identity security terminal group, the identity security domain isolation gateway group, and the unified security policy management platform are sequentially connected via Ethernet.
2. The inter-domain isolation system based on identity-based cryptography according to claim 1, wherein, The identity security terminal group includes: a first identity security terminal A1, a second identity security terminal A2, a first identity security terminal B1, and a second identity security terminal B2; The identity security domain isolation gateway group includes: a first identity security domain isolation gateway GA and a second identity security domain isolation gateway GB; Both the first identity security terminal A1 and the second identity security terminal A2 are connected to the first identity security domain isolation gateway GA via Ethernet, and the first identity security domain isolation gateway GA is connected to the unified security policy management platform via Ethernet; Both the first identity security terminal B1 and the second identity security terminal B2 are connected to the second identity security domain isolation gateway GB via Ethernet, and the second identity security domain isolation gateway GB is connected to the unified security policy management platform via Ethernet; The first identity security domain isolation gateway GA, the first identity security terminal A1, and the second identity security terminal A2 constitute production domain A; The second identity security domain isolation gateway GB, the first identity security terminal B1, and the second identity security terminal B2 constitute production domain B.
3. An inter-domain isolation method based on identity-based cryptography, characterized in that Including: Secure data transmission between two identity security terminals within production domain A or within production domain B; Secure data transmission between two identity security terminals between production domain A and production domain B.
4. The method for inter-domain isolation based on identity-based cryptography according to claim 1, wherein The secure data transmission between two identity security terminals within production domain A or within production domain B specifically includes the following steps: The first identity security terminal A1 requests a connection to the second identity security terminal A2; The second identity security terminal A2 generates a random number r1 as challenge information; The second identity security terminal A2 returns the challenge information r1 to the first identity security terminal A1; The first identity security terminal A1 calls its own identity composite private key to sign the challenge information r1 as a challenge response; The first identity security terminal A1 generates a random number r2 as authentication challenge information; The first identity security terminal A1 sends the signature data and the authentication challenge information r2 to the second identity security terminal A2; The second identity security terminal A2 calculates the public key of the first identity security terminal A1 based on the identity of the first identity security terminal A1 and verifies the signature to complete the authenticity authentication of the first identity security terminal A1; The second identity security terminal A2 uses its own identity composite private key to sign the authentication challenge information r2 as response data; The second identity security terminal A2 returns the signature response data to the first identity security terminal A1; The first identity security terminal A1 calculates the public key of the second identity security terminal A2 based on the identity of the second identity security terminal A2 and verifies the signature to determine the authenticity of the second identity security terminal A2; The first identity security terminal A1 and the second identity security terminal A2 use r1^r2 as the session key for the virtual security channel between the two to encrypt and decrypt the transmitted data.
5. The method for inter-domain isolation based on identity-based cryptography according to claim 1, wherein The secure data transmission between two identity-secured terminals between the production domain A and the production domain B specifically includes the following steps: The first identity-secured terminal A1 within the production domain A sends a connection request to the first identity-secured domain isolation gateway GA, requesting to connect to the first identity-secured terminal B1 within the production domain B; The first identity-secured domain isolation gateway GA determines whether the connection request complies with the security policy; If the connection request complies with the security policy, the first identity-secured domain isolation gateway GA submits the connection request to the unified security management platform; The administrator of the unified security management platform reviews the connection request; After the review is passed, the unified security management platform forwards the review result to the second identity-secured domain isolation gateway GB; The second identity-secured domain isolation gateway GB sends a response back to the unified security management platform; The unified security management platform sends the domain public key of the first identity-secured domain isolation gateway GA to the second identity-secured domain isolation gateway GB within the production domain B through a security protocol; and sends the domain public key of the second identity-secured domain isolation gateway GB to the first identity-secured domain isolation gateway GA within the production domain A through a security protocol; The unified security management platform simultaneously generates a temporary shared authentication key between the two identity-secured terminals and sends it to the first identity-secured terminal A1 within the production domain A and the first identity-secured terminal B1 within the production domain B respectively; The first identity-secured terminal A1 sends a connection request to the first identity-secured terminal B1 through the first identity-secured domain isolation gateway GA; The first identity-secured terminal B1 generates a random number r1 as a challenge message and returns it to the first identity-secured terminal A1; The first identity-secured terminal A1 calculates the MAC of the challenge message r1 using the temporary shared authentication key assigned by the unified security management platform; The first identity-secured terminal A1 generates a random number r2 as a challenge message and sends it together with the response data MAC to the first identity-secured terminal B1; The first identity-secured terminal B1 verifies the MAC code to determine the authenticity of the first identity-secured terminal A1; After two-way authentication, use r1^r2 as the session key of the established virtual security channel to encrypt and decrypt the transmitted data.
6. An electronic device, characterized in that, It includes a memory and a processor. The memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the identity-based cryptography-based inter-domain isolation method according to any one of claims 3-5.
7. A computer-readable storage medium, characterized in that, It stores a computer program, and when the computer program is executed by the processor, it implements the identity-based cryptography-based inter-domain isolation method according to any one of claims 3-5.