Endogenous security network trust architecture based on family genes

Through the endogenous security network trust architecture based on family genes, the family leader issues gene certificates for identity authentication and credibility measurements is solved, and the problem of lack of trust mechanism in the network architecture is achieved, and the security endogenous attributes and robustness of the network are prevented from illegal access and information leakage.

CN120358037APending Publication Date: 2025-07-22DATA COMM SCI & TECH RES INST +2
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410083317.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-19
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

The existing network architecture lacks an endogenous trust mechanism, which leads to frequent attacks such as identity spoofing, illegal access and information leakage. The traditional trust model has defects such as unclear information of the certificate subject, difficulty in distinguishing entities of the same name, poor scalability, and complex authentication process, which limits network applications.

Method used

Adopting an endogenous secure network trust architecture based on family genes, the family leader issues gene certificates to achieve a fine-grained trust mechanism of "authentication + authorization + trustworthiness" in the network. Family elders at all levels of network domains generate patriarch gene certificates and issue user gene certificates and application gene certificates to users and applications, perform identity authentication and trustworthiness measurements, and establish a trust chain for access between members.

Benefits of technology

Ensure the pure bloodline of network members, realize the security and endogenous attributes of the network, improve system robustness, prevent illegal intrusion, ensure the security and reliability of network resources, and avoid local attacks causing system paralysis.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358037A_ABST
    Figure CN120358037A_ABST
Patent Text Reader

Abstract

The invention relates to an endogenous security network trust architecture based on family genes, and belongs to the field of computer network security. Comprising the steps of managing a family leader of each level of network domain and a plurality of network subjects, wherein the family leader is used for generating a family leader gene certificate of the network domain and respectively issuing a user gene certificate and an application gene certificate to a user and an application in the network domain; each network subject performs identity authentication and trusted measurement on the application based on the family leader gene certificate of the corresponding network domain family leader; when the applications are accessed, identity authentication and access authorization are carried out on the applications of the opposite side based on the application gene certificate and the gender gene certificate of the applications of the opposite side; and when the application is accessed by the user, performing identity authentication and access authorization on the user based on the user gene certificate and the genealogy gene certificate of the network domain where the user is located. The endogenous security network trust architecture is based on an authentication + authorization + credibility integrated family gene certificate, and a fine-grained network trust architecture for establishing a trust relationship in a network is realized.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention belongs to the field of computer network security, and particularly relates to an endogeneous security network trust architecture based on family genes. Background Art

[0002] For decades, the information network centered around the TCP / IP protocol has developed rapidly, realizing the interconnection of most computer systems, fixed / mobile devices, playing a huge role in various aspects of social life, politics, military, etc., and becoming an indispensable information infrastructure in various fields. However, at the same time, due to the lack of an endogeneous trustworthy mechanism in the existing network architecture, a large number of attack events such as identity deception, illegal access, and information leakage have occurred, seriously disrupting the network order and bringing great harm to the security of the national economic, social, and military systems relying on the network operation.

[0003] The network trust model is used to provide an overall framework for establishing and managing grid trust relationships in an information system, giving the basic criteria and methods for mutual trust between users and trust institutions as well as between trust institutions, and providing services for establishing a trustworthy, controllable, and manageable network application environment to ensure the healthy development of business systems. Traditional trust models mostly adopt conventional systems such as PKI. The trust relationship between the third party (CA) and users in the model is artificially established by force. The trustworthiness of the CA is questionable, and there are defects such as unclear certificate subject information, difficulty in distinguishing homonymous entities in reality, poor scalability, and complex authentication processes. The defects of traditional trust models and the lack of network security protection measures have led to the emergence of network trust crises and restricted the application of the network to a certain extent. Establishing an endogeneous security trust mechanism from the network architecture to systematically solve the network security trust problem has become an important topic in the research of future network architecture (Future Internet Architecture). Summary of the Invention

[0004] In view of the above analysis, the present invention aims to provide an endogeneous security network trust architecture based on family genes, which issues gene certificates to members in the network by the family head, and realizes a fine-grained network trust mechanism of "authentication + authorization + trustworthiness" in the network based on the gene certificates.

[0005] An endogeneous security network trust architecture based on family genes of the present invention includes a family head for managing each level of network domain and multiple network entities, wherein:

[0006] The family head of each level of network domain is used to generate the family head gene certificate of the current network domain based on the family information allocated by the family head of the upper-level network, and issue user gene certificates and application gene certificates to users and applications within the current network domain respectively;

[0007] When each of the network entities loads and runs an application, it is used to authenticate the identity and perform trusted measurement of the application based on the patriarch gene certificate of the patriarch of the corresponding network domain family;

[0008] When applications loaded on each of the network entities access each other, they mutually authenticate the identity and perform access authorization on the other application based on the application gene certificate and the patriarch gene certificate of the other application;

[0009] When an application loaded on each of the network entities is accessed by a user, the user's identity is authenticated and access authorization is performed based on the user gene certificate and the patriarch gene certificate of the network domain where the user is located.

[0010] Further, the patriarchs of each level of network domain generate the patriarch gene certificate of this network domain based on the family information assigned by the patriarch of the upper-level network, including:

[0011] Patriarchs of each level of network domain family issue a family public key and a family private key for themselves;

[0012] Determine the family gene based on the family information and the family private key;

[0013] Generate the patriarch gene certificate of this network domain based on the patriarch name, family gene, and family public key of the patriarch of this network domain.

[0014] Further, the patriarchs of each level of network domain issue user gene certificates and application gene certificates to users and applications within their respective network domains, including:

[0015] The patriarch issues a user gene certificate to the user based on the patriarch name, user name, family gene, user permission gene, user public key, and family private key;

[0016] The patriarch issues an application gene certificate to the application based on the patriarch name, application name, family gene, application permission gene, application program gene, application public key, and the family private key of the application.

[0017] Further, the patriarch issues a user gene certificate to the user based on the patriarch name, user name, family gene, user permission gene, user public key, and family private key, including:

[0018] The patriarch constructs the user gene main body information based on the patriarch name, user name, family gene, and user permission gene;

[0019] The patriarch obtains the user gene signature based on the family private key, user public key, and user gene main body information;

[0020] The patriarch obtains the user gene certificate based on the user gene main body information and the user gene signature and issues it to the user.

[0021] Further, the family head issues an application gene certificate to the application based on the patriarch name, application name, family gene, application permission gene, application program gene, application public key, and family private key of the application, including:

[0022] The family head forms the application gene main body information based on the patriarch name, application name, family gene, application permission gene, and application program gene;

[0023] The family head obtains the application gene signature based on the family private key, application public key, and application gene main body information of the application;

[0024] The family head obtains the application gene certificate based on the application gene main body information, application public key, and application gene signature, and issues it to the application.

[0025] Further, when each of the network entities loads and runs the application, the identity authentication and trusted measurement of the application based on the patriarch gene certificate of the family head in the corresponding network domain includes:

[0026] Before loading the application, each of the network entities obtains the family gene and family public key based on the patriarch gene certificate of the family head in the corresponding network domain;

[0027] Each of the network entities verifies the signature of the application gene certificate based on the family public key. If the signature verification fails, the identity authentication fails; if the signature verification is successful, proceed to the next step;

[0028] Each of the network entities matches the family gene in the application gene certificate with the family gene in the patriarch gene certificate. If the matching fails, the identity authentication fails; if the matching is successful, the identity authentication is successful, and proceed to the next step;

[0029] When loading and running the application, each of the network entities performs trusted measurement on the application based on the application program gene and family public key in the application gene certificate.

[0030] Further, the application program gene includes static information, dynamic information, and integrity verification value;

[0031] When loading and running the application, each of the network entities performs trusted measurement on the application based on the program gene and family public key in the application gene certificate, including:

[0032] When loading the application, each of the network entities verifies whether the static trusted measurement is tampered with based on the integrity verification value of the static information using the family public key. If the verification passes, the static trusted authentication is successful; otherwise, the authentication fails;

[0033] Each of the network entities loads an application with successful static trusted authentication. During the operation of the application, the network entity compares the currently dynamic information of the application monitored in real time with the dynamic information. If they are consistent, the dynamic trusted authentication is successful; otherwise, the authentication fails.

[0034] Further, when the applications loaded on each of the network entities access each other, the mutual identity authentication and access authorization of each other's applications based on the application gene certificate and the patriarch gene certificate of the other application include:

[0035] When the applications loaded on each of the network entities access each other, they mutually obtain the family gene and family public key of the other party based on the patriarch gene certificate of the other party;

[0036] Authenticate the other party based on the family gene and family public key of the other party;

[0037] Obtain the permission gene in the application gene certificate of the other party that has passed the identity authentication;

[0038] Authorize access to the other party based on the patriarch gene certificate of the other party and the application permission gene of the other party.

[0039] Further, the authorizing access to the other party based on the patriarch gene certificate of the other party and the application permission gene of the other party includes:

[0040] Obtain the family public key of the other party based on the patriarch gene certificate of the other party;

[0041] Perform integrity verification on the resource access permission coding information in the application permission gene of the other party based on the family public key of the other party and the integrity signature value in the application permission gene of the other party;

[0042] Authorize access to the other party's application based on the resource access permission coding information that has passed the integrity verification.

[0043] Further, when the applications loaded on each of the network entities are accessed by a user, the identity authentication and access authorization of the user based on the user gene certificate and the patriarch gene certificate of the network domain where the user is located include:

[0044] When the applications loaded on each of the network entities are accessed by a user, the application obtains the family gene and family public key of the other party based on the patriarch gene certificate of the user;

[0045] Authenticate the user based on the family gene and family public key of the user;

[0046] Obtain the permission gene in the user gene certificate of the user who has passed the identity authentication;

[0047] Authorize access to the user based on the patriarch gene certificate and the user permission gene of the user.

[0048] The present invention can at least achieve one of the following beneficial effects:

[0049] By generating their own patriarch gene certificates by the patriarchs of each level of network domain families based on the family information distributed by the superior family, and issuing family gene certificates to the members of this network domain, including user gene certificates and application gene certificates, the pure bloodlines of the members in the network are ensured, the endogenous security attribute of the network is realized, and thus the endogenous security architecture of the entire network is realized.

[0050] By authenticating, authorizing, accessing controlling, and performing trusted measurement on members based on family genes, a network trust chain for member access is established, the legality of mutual access between members is guaranteed, so that intruders cannot penetrate or bypass the identity authentication mechanism to wantonly access network resources, and thus it is ensured that even if a local sub-network is attacked, the entire system will not crash, improving the robustness of the system.

[0051] Other features and advantages of the present invention will be described in the subsequent specification, and some advantages can be made obvious from the specification, or understood by implementing the present invention. The objectives and other advantages of the present invention can be achieved and obtained from the content specifically pointed out in the specification, claims, and drawings. Description of the Drawings

[0052] The drawings are only for the purpose of showing specific embodiments, and are not considered as limiting the present invention. Throughout the drawings, the same reference signs denote the same components;

[0053] Figure 1 It is a schematic diagram of the endogenous security network trust architecture of the present invention;

[0054] Figure 2 It is a structural diagram of the patriarch gene certificate of the present invention;

[0055] Figure 3 It is a structural diagram of the family gene of the present invention;

[0056] Figure 4 It is a schematic diagram of the structure of the user gene certificate of the present invention;

[0057] Figure 5 It is a structural diagram of the user / application permission gene of the present invention;

[0058] Figure 6 It is a schematic diagram of the structure of the application gene certificate of the present invention;

[0059] Figure 7 It is a structural diagram of the application program gene of the present invention. Detailed Embodiments

[0060] The preferred embodiments of the present invention will be specifically described below with reference to the accompanying drawings. The accompanying drawings form a part of this application and are used together with the embodiments of the present invention to explain the principles of the present invention, rather than to limit the scope of the present invention.

[0061] A specific embodiment of the present invention discloses an endogeneous security network trust architecture based on family genes, including a family head for managing network domains at all levels and a plurality of network entities, wherein:

[0062] The family head of each network domain at all levels is used to generate a family head gene certificate for this network domain based on the family information assigned by the family head of the superior network, and issue a user gene certificate and an application gene certificate to users and applications within the network domain respectively;

[0063] When each of the network entities loads and runs an application, it is used to authenticate the identity and perform a trusted measurement of the application based on the family head gene certificate of the corresponding network domain family head;

[0064] When applications loaded on each of the network entities access each other, they mutually authenticate the identity and authorize access to the other application based on the application gene certificate and the family head gene certificate of the other application;

[0065] When an application loaded on each of the network entities is accessed by a user, it authenticates the identity and authorizes access to the user based on the user gene certificate and the family head gene certificate of the network domain where the user is located.

[0066] In this embodiment, the family heads of network domains at all levels generate their own family head gene certificates based on the family information assigned by the superior family, and issue family gene certificates, including user gene certificates and application gene certificates, to members of this network domain, ensuring the pure lineage of members in the network and realizing the endogeneous security attribute of the network, thereby realizing the endogeneous security architecture of the entire network; by authenticating, authorizing, and performing trusted measurement on accesses in the network based on gene certificates, a network access trust chain is established, effectively resisting illegal network intrusions.

[0067] Specifically, the family heads of network domains at all levels manage the members of their own network domains. The family heads of network domains at all levels are security management servers for this network domain, realizing the security management functions of the security management center in the network. Each network domain includes a plurality of network entities, and the types of the network entities include hosts, backbone routers, and access routers in each network domain; the members include applications and users registered in each network domain.

[0068] Specifically, each network domain corresponds to the head of the family of each network domain, that is, a network domain in the network corresponds to a family, and there is an inheritance relationship between families. That is, the head of the family of the network domain generates the gene certificate of the head of the family of this network domain based on the family information allocated by the head of the family of the superior network domain. In the entire network, the head of the family of the highest-level network domain is called the ancestor head. Starting from the ancestor head, the family information is allocated to the head of the family of the next-level network domain step by step, forming a top-down family inheritance relationship to ensure that each network domain in the entire network architecture is securely managed by its own head of the family.

[0069] Furthermore, the head of the family of each network domain issues a family public key and a family private key for itself, and issues respective gene certificates and user public-private key pairs for the members in the family.

[0070] Specifically, the members in the family include the applications and users in this network domain. The head of the family issues a user gene certificate and a user public-private key pair to the users registered in this network domain, and issues an application gene certificate and an application public-private key pair for the application when publishing the application in this network domain.

[0071] Specifically, the family private key and the family public key are used to sign and verify the gene certificates of family members, and the user / application private key and the user / application public key are used to sign and verify the identities of family members during the network authentication process.

[0072] Specifically, the head of the family of each level of network domain determines the family gene based on the family information allocated by the head of the family of the superior network and the family private key; generates the gene certificate of the head of the family of this network domain based on the name of the head of the family, the family gene, and the family public key of the head of the family of this network domain, as Figure 2 shown. It should be noted that after the head of the family of each level of network domain generates the gene certificate of the head of the family, it is submitted to the head of the family of the superior network domain for backup storage. The head of the family of each level of network domain in the network provides the service of querying the gene certificate of the head of the family to family members, and family members can trace and query the gene certificates of the heads of the family of each network domain in the network through the head of the family of the network domain where they are located step by step.

[0073] Furthermore, as Figure 3 described, the family gene includes family information and an integrity signature value, where the family information includes the name of the head of the previous-level family, the domain address of the head of the previous-level family, the name of the network domain of the head of the family, and the prefix of the network domain address of the head of the family; the head of the family performs integrity encryption on the family information based on the family private key to obtain the integrity signature value. It should be noted that in the family gene of the ancestor head in the network, the name of the head of the previous-level family is the name of the ancestor head, and the domain address of the head of the previous-level family is the domain address of the ancestor head.

[0074] Specifically, when a user registers within a network domain, the head of the family of each level of network domain issues a user gene certificate to the user registering within the network domain where they are located, including:

[0075] The clan leader forms user gene subject information based on the clan leader name, user name, clan gene, and user authority gene; wherein the clan leader name is used to identify the certificate issuer, and the user name is used to identify the certificate owner;

[0076] The family head digitally signs the user's gene subject information and the user's public key based on the family's private key to obtain gene signature information, and forms the user's gene signature based on the user's gene signature information and the signature algorithm;

[0077] The family leader obtains the user gene certificate based on the user gene subject information, the user public key and the user gene signature and issues it to the user. The structure of the user gene certificate is as follows: Figure 4 It should be noted that when a user logs out, the corresponding network domain family leader revokes the corresponding user gene certificate.

[0078] Furthermore, the user permission gene includes resource access permission encoding information and integrity signature value; wherein the resource access permission exemplarily includes (such as Figure 5 As shown): user ID, cross-network access rights (yes / no), accessible file type (configuration file / executable file), file access rights (read / write / execute), socket type (domain socket / stream / datagram), socket port number (1 or more) and network service type (connection-oriented / connectionless); optionally, the resource access rights are encoded using a preset encoding rule to obtain resource access rights encoding information; when the family head issues a user gene certificate to the user, the resource access rights encoding information is encrypted based on the family private key to obtain an integrity signature value.

[0079] Specifically, when an application is released, the family leader of each network domain issues an application gene certificate to the application released in the network domain, including:

[0080] The family leader forms application gene subject information based on the family leader name, application name, family gene, application authority gene, and application program gene;

[0081] The family leader digitally signs the application gene main body information and the application public key based on the family private key of the application to obtain the application gene signature information, and forms the application gene signature based on the application gene signature information and the signature algorithm;

[0082] The family leader obtains the application gene certificate based on the application gene subject information, application public key and application gene signature and issues it to the application. The application gene certificate structure is as follows: Figure 6 It should be noted that when a user cancels his / her registration, the corresponding network domain family leader shall revoke the corresponding application gene certificate.

[0083] Furthermore, the application permission gene structure is the same as the user permission gene structure, e.g. Figure 5 shown.

[0084] Further, the application gene includes static information, dynamic information, and an integrity verification value (as Figure 7 shown). The static information includes the software version and the software size; the dynamic information includes the resource file list, the socket type, and the socket port number. When the family head issues an application gene certificate to an application, an integrity signature value is obtained based on the family private key of the application and the static information.

[0085] Specifically, when each of the network entities loads and runs an application, the identity authentication and trusted measurement of the application based on the family head gene certificate of the corresponding network domain family head include:

[0086] Before loading the application, each of the network entities obtains the family gene and the family public key based on the family head gene certificate of the corresponding network domain family head, and obtains the signature algorithm based on the application gene certificate;

[0087] Each of the network entities verifies the signature of the application gene certificate based on the family public key and the signature algorithm. If the signature verification fails, the identity authentication fails; if the signature verification succeeds, continue to the next step;

[0088] Each of the network entities matches the family gene in the application gene certificate with the family gene in the family head gene certificate. If the matching fails, the identity authentication fails; if the matching succeeds, the identity authentication succeeds, and continue to the next step;

[0089] When each of the network entities loads and runs the application, the trusted measurement of the application is performed based on the application program gene and the family public key in the application gene certificate; it should be noted that in the endogenous security network trust architecture of the present invention, each network entity has a corresponding trusted measurement service, and each network entity uses the trusted measurement service to perform the trusted measurement on the application.

[0090] Further, the trusted measurement includes static trusted authentication and dynamic trusted authentication:

[0091] When each of the network entities loads the application, based on the static information integrity verification value, the family public key is used to verify whether the static information is tampered with. If the verification passes, the static trusted authentication succeeds; otherwise, the authentication fails;

[0092] Each of the network entities loads the application with successful static trusted authentication. During the running process of the application, the network entity compares the current dynamic information of the application monitored in real time with the dynamic information. If they are consistent, the dynamic trusted authentication succeeds; otherwise, the authentication fails.

[0093] Further, during the operation of the application, when the dynamic trusted authentication fails, each network entity stops the operation of the application and performs trusted recovery, that is, the trusted measurement service performs static trusted authentication on the application. If the static trusted authentication is successful, the statically trusted authenticated application is reloaded.

[0094] Specifically, when the applications loaded on each of the network entities access each other, the mutual identity authentication and access authorization of the other application based on the application gene certificate and the patriarch gene certificate of the other application include:

[0095] When the applications loaded on each of the network entities access each other, they mutually obtain the family gene and family public key of the other party based on the patriarch gene certificate of the other party;

[0096] Perform identity authentication on the other party based on the family gene and family public key of the other party;

[0097] Obtain the permission gene in the application gene certificate of the other party that has passed the identity authentication;

[0098] Perform access authorization on the other party based on the patriarch gene certificate of the other party and the application permission gene of the other party.

[0099] Further, performing identity authentication on the other party based on the family gene and family public key of the other party includes:

[0100] Obtain the family gene and family public key of the other party based on the patriarch gene certificate of the other party, and obtain the signature algorithm of the other party based on the application gene certificate;

[0101] Verify the signature of the other party's application gene certificate based on the family public key and signature algorithm of the other party. If the signature verification fails, the identity authentication fails. If the signature verification is successful, continue to the next step;

[0102] Match the family gene in the other party's application gene certificate with the family gene in the other party's patriarch gene certificate. If the match is recognized, the identity authentication fails. If the match is successful, it means that the application gene certificate of the other party has not been tampered with, and continue to the next step;

[0103] Obtain the application public key and signature algorithm of the other party based on the other party's application gene certificate, and verify the signature of the random number signature sent by the other party's application. If the signature verification passes, the identity authentication is successful, otherwise the authentication fails.

[0104] It should be noted that during the process of mutual identity authentication between the two parties, the two parties respectively provide the application gene certificate, the random number for this authentication, and the random number signature obtained based on their own application private key and signature algorithm to the other party; the other party verifies the signature of the random number. Since the random number signature and signature verification process are common technical means in identity authentication negotiation in the prior art, the present invention will not elaborate further.

[0105] Further, performing access authorization on the other party based on the other party's patriarch gene certificate and the other party's application permission gene includes:

[0106] Obtaining the family public key of the other party based on the other party's patriarch gene certificate;

[0107] Performing integrity verification on the resource access permission coding information in the other party's application permission gene based on the family public key of the other party and the integrity signature value in the other party's application permission gene;

[0108] Performing access authorization on the other party's application based on the resource access permission coding information that passes the integrity verification.

[0109] Exemplarily, when the access between applications is cross-domain access, when application A on one side accesses application B on the other side across domains: Application A on one side needs to first access the access authentication service of the access router in its own network domain, that is, application A and the access authentication service of the access router in its own network domain authenticate and authorize each other's applications based on the application gene certificates and patriarch gene certificates of the other party's applications; Further, the routing application of the access router and the routing applications of the backbone routers (exemplarily including OSPF, IS-IS, RIP, BGP), the routing applications of the backbone routers and the routing applications of the access routers in another network domain, the access authentication service of the access router in another network domain, and application B in another network domain authenticate and authorize each other based on the gene certificates and patriarch gene certificates of the other party. Thus, a network trust chain for cross-domain access is established, that is, the trust chain of application A - multiple routing services - application B, realizing the security authentication of cross-domain access.

[0110] Specifically, when the applications loaded on each of the network entities are accessed by a user, performing identity authentication and access authorization on the user based on the user gene certificate and the patriarch gene certificate of the network domain where the user is located includes:

[0111] When the applications loaded on each of the network entities are accessed by a user, the application obtains the family gene and family public key of the other party based on the user's patriarch gene certificate;

[0112] Performing identity authentication on the user based on the user's family gene and family public key;

[0113] Obtaining the permission gene in the user gene certificate of the user who passes the identity authentication;

[0114] Performing access authorization on the user based on the patriarch gene certificate and the user's user permission gene.

[0115] Further, performing identity authentication on the user based on the user's family gene and family public key:

[0116] Obtain the family gene and the family public key based on the user's patriarch gene certificate, and obtain the signature algorithm based on the user gene certificate;

[0117] Verify the signature of the user gene certificate based on the family public key and the signature algorithm. If the signature verification fails, the identity authentication fails. If the signature verification succeeds, proceed to the next step;

[0118] Match the family gene in the user gene certificate with the family gene in the other party's patriarch gene certificate. If the match is recognized, the identity authentication fails. If the match is successful, it indicates that the user gene certificate has not been tampered with, and proceed to the next step;

[0119] Obtain the public key of the other user and the signature algorithm based on the user gene certificate, and verify the signature of the random number generated from the user's Ukey. If the signature verification passes, the identity authentication is successful; otherwise, the authentication fails.

[0120] It should be noted that during the process of authenticating the user by the application, the user provides the user gene certificate, the random number generated by the Ukey for this authentication, and the random number signature obtained based on the user's own private key and the signature algorithm to the application; the application verifies the signature of the random number. Since the random number signature and the signature verification process are common technical means for identity authentication negotiation in the prior art, the present invention will not elaborate further. Further, when the loaded application is accessed by the user, if the user and the application are not in the same network domain, i.e., for cross-domain access, each access router and backbone router's routing application that the user needs to pass through when accessing the application, as well as the application being accessed by the user, all authenticate the user based on the user gene certificate in sequence; and when the routing applications and the application being accessed by the user are connected to each other, they authenticate and authorize access to each other based on the application gene certificate of the other party being connected; finally, the application being accessed by the user authorizes access to the user based on the user gene certificate.

[0121] In this embodiment, an endogenetic security network trust architecture based on family genes is disclosed. Based on various network domain family gene certificates including the patriarch gene certificate, the user gene certificate, and the application gene certificate, it can realize the cross-domain network trust chain of user - application - routing service - application, realize mutual authentication and access authorization between applications in the same network domain or across domains, and realize identity authentication and access authorization of the application to users in the same domain or across domains. Under the endogenetic security network trust architecture based on family gene certificates, identity authentication and access control are integrated in the same certificate to enforce identity discrimination and access control on all network users using system resources, making it impossible for intruders to penetrate or bypass the identity authentication mechanism and wantonly access network resources, thus greatly improving the system security.

[0122] It should be noted that the above embodiments of the present invention are based on the same inventive concept, and for the parts not repeatedly described, they can be mutually referred to.

[0123] As described above, it is only the preferred specific implementation manner of the present invention, but the protection scope of the present invention is not limited thereto. Any changes or substitutions that can be easily thought of by those skilled in the art within the technical scope disclosed by the present invention should be covered within the protection scope of the present invention.

Claims

1. An endogenous security network trust architecture based on family genes, characterized in that, It includes the clan leaders of each level of network domain and multiple network entities, where: The clan leaders of each level of network domain are used to generate the clan leader gene certificate of this network domain based on the clan information allocated by the clan leader of the superior network, and issue user gene certificates and application gene certificates to users and applications within the network domain respectively; When each of the network entities loads and runs an application, it is used to authenticate the identity and perform trusted measurement of the application based on the clan leader gene certificate of the corresponding network domain clan leader; When the applications loaded on each of the network entities access each other, they authenticate the identity and authorize access to each other's applications based on the application gene certificate and clan leader gene certificate of the other party's application; When the applications loaded on each of the network entities are accessed by users, they authenticate the identity and authorize access to the users based on the user gene certificate and the clan leader gene certificate of the network domain where the users are located.

2. The endogenous security network trust architecture according to claim 1, wherein The clan leaders of each level of network domain generating the clan leader gene certificate of this network domain based on the clan information allocated by the clan leader of the superior network includes: The clan leaders of each level of network domain issue a clan public key and a clan private key for themselves; Determine the clan gene based on the clan information and the clan private key; Generate the clan leader gene certificate of this network domain based on the clan leader name, clan gene and clan public key of the clan leader of this network domain.

3. The endogenous security network trust architecture according to claim 2, characterized in that, The clan leaders of each level of network domain issuing user gene certificates and application gene certificates to users and applications within the network domain respectively includes: The clan leader issues a user gene certificate to the user based on the clan leader name, user name, clan gene, user permission gene, user public key and clan private key; The clan leader issues an application gene certificate to the application based on the clan leader name, application name, clan gene, application permission gene, application program gene, application public key and the clan private key of the application.

4. The endogenous security network trust architecture according to claim 3, characterized in that, The clan leader issuing a user gene certificate to the user based on the clan leader name, user name, clan gene, user permission gene, user public key and clan private key includes: The clan leader constructs user gene main body information based on the clan leader name, user name, clan gene and user permission gene; The clan leader obtains a user gene signature based on the clan private key, user public key and user gene main body information; The clan leader obtains a user gene certificate based on the user gene main body information, user public key and user gene signature and issues it to the user.

5. The endogenous security network trust architecture according to claim 4, characterized in that, The clan leader issuing an application gene certificate to the application based on the clan leader name, application name, clan gene, application permission gene, application program gene, application public key and the clan private key of the application includes: The clan leader constructs application gene main body information based on the clan leader name, application name, clan gene, application permission gene and application program gene; The clan leader obtains an application gene signature based on the clan private key of the application, application public key and application gene main body information; The clan leader obtains an application gene certificate based on the application gene main body information, application public key and application gene signature and issues it to the application.

6. The endogenous security network trust architecture according to claim 5, wherein When each of the network entities loads and runs an application, the authenticating the identity and performing trusted measurement of the application based on the clan leader gene certificate of the corresponding network domain clan leader includes: Before each of the network entities loads an application, it obtains the clan gene and clan public key based on the clan leader gene certificate of the corresponding network domain clan leader; Each of the network entities verifies the signature of the application gene certificate based on the family public key. If the signature verification fails, the identity authentication fails; if the signature verification succeeds, proceed to the next step. Each of the network entities matches the family gene in the application gene certificate with the family gene in the patriarch gene certificate. If the matching fails, the identity authentication fails; if the matching succeeds, the identity authentication succeeds, and proceed to the next step. When each of the network entities loads and runs an application, it performs a trusted measurement on the application based on the application program gene and the family public key in the application gene certificate.

7. The endogenous security network trust architecture according to claim 6, characterized in that, The application program gene includes static information, dynamic information, and an integrity check value. When each of the network entities loads and runs an application, the trusted measurement of the application based on the program gene and the family public key in the application gene certificate includes: When each of the network entities loads an application, based on the integrity check value of the static information, it uses the family public key to verify whether the static trusted measurement has been tampered with. If the verification passes, the static trusted authentication succeeds; otherwise, the authentication fails. Each of the network entities loads an application with successful static trusted authentication. During the running process of the application, the network entity compares the currently monitored dynamic information of the application with the dynamic information. If they are consistent, the dynamic trusted authentication succeeds; otherwise, the authentication fails.

8. The endogenous security network trust architecture according to claim 7, wherein, When the applications loaded on each of the network entities access each other, the mutual identity authentication and access authorization of each other's applications based on the application gene certificate and the patriarch gene certificate of the other application include: When the applications loaded on each of the network entities access each other, they obtain the family gene and family public key of the other party based on the patriarch gene certificate of the other party. Perform identity authentication on the other party based on the family gene and family public key of the other party. Obtain the permission gene in the application gene certificate of the other party that has passed the identity authentication. Perform access authorization on the other party based on the patriarch gene certificate of the other party and the application permission gene of the other party.

9. The endogenous security network trust architecture according to claim 8, characterized in that, The performing access authorization on the other party based on the patriarch gene certificate of the other party and the application permission gene of the other party includes: Obtain the family public key of the other party based on the patriarch gene certificate of the other party. Perform an integrity check on the resource access permission coding information in the application permission gene of the other party based on the family public key of the other party and the integrity signature value in the application permission gene of the other party. Perform access authorization on the other party's application based on the resource access permission coding information that has passed the integrity check.

10. The endogenous security network trust architecture according to claim 9, characterized in that, When the applications loaded on each of the network entities are accessed by a user, the identity authentication and access authorization of the user based on the user gene certificate and the patriarch gene certificate of the network domain where the user is located include: When the application loaded on each of the network entities is accessed by a user, the application obtains the family gene and family public key of the other party based on the patriarch gene certificate of the user. Perform identity authentication on the user based on the family gene and family public key of the user. Obtain the permission gene in the user gene certificate of the user who has passed the identity authentication. Perform access authorization on the user based on the patriarch gene certificate and the user permission gene of the user.