A data circulation method and system based on slicing network and trusted data space

Through the combination of sliced ​​network and trusted data space, the use of dedicated network equipment and dual-factor authentication mechanisms solves the problem of data privacy leakage in trusted data space networks, and realizes the secure isolation and protection of user data.

CN120358078BActive Publication Date: 2025-08-22NANJING FUTURE NETWORK CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510813042.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-06-18
Publication Date
2025-08-22
Estimated Expiration
2045-06-18

AI Technical Summary

Technical Problem

The existing trusted data space network is prone to data privacy leakage when users access, and is even crawled by network models and trained into an agent, threatening the security of user data.

Method used

The combination of sliced ​​network and trusted data space is adopted, and through dedicated network equipment and dual-factor authentication mechanisms, including connectors and network controllers, the verification of user trusted credentials and network attribute tags is realized to ensure that user data is isolated and authenticated before accessing the trusted data space.

Benefits of technology

Enhanced the isolation and security of user data transmission, prevent data leakage, and improve data privacy protection and security through the coordinated cooperation between the sliced ​​network and the trusted data space.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358078B_ABST
    Figure CN120358078B_ABST
Patent Text Reader

Abstract

The present invention belongs to the field of data circulation technology, and discloses a data circulation method and system based on a slice network and a trusted data space. It includes: the connector obtains feedback generated by the private network to allow the user to access the connector through the corresponding slice private network based on the pre-configured static route; obtains the user's trusted credentials and authentication message forwarded after being addressed by the first router; verifies the user's trusted credentials, and forwards the obtained network attribute tag to the network controller after parsing the authentication message; when the user's trusted credentials are verified and it is determined that the network controller has passed the verification of the network attribute tag, the user is allowed to enter the trusted data space through the second router for data interaction. The present invention effectively improves the security of data circulation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of data circulation technology, and in particular to a data circulation method and system based on a slice network and a trusted data space. Background Art

[0002] Data circulation refers to the flow of data between different entities, including data openness, sharing, transaction, and exchange. In the era of big data, effective data circulation is of great practical significance for improving production efficiency, reducing production costs, promoting production innovation, and assisting production decision-making.

[0003] In the data flow process, a trusted data space, born out of the urgent need for cross-organizational collaboration and data sharing in the data-driven era, can be used to build a trusted and controllable data flow environment through technologies such as blockchain, privacy-preserving computing, and federated learning. Specifically, this trusted data space uses blockchain to safeguard data ownership and transaction traceability, and combines privacy-enhancing methods such as multi-party secure computing and homomorphic encryption to achieve "data availability without visibility." At the same time, distributed identity authentication, smart contracts, and other mechanisms regulate data usage permissions and collaboration rules. This aims to break down data silos, meet privacy protection and compliance requirements, and support the trusted sharing and value mining of cross-domain data.

[0004] However, when promoting the application of trusted data space, since the existing trusted data space network adopts the Internet, it is easy for users to leak their data privacy after accessing the trusted data space network, and even be crawled by large network models and trained into intelligent agents to threaten user data security. Summary of the Invention

[0005] The purpose of the present invention is to provide a data circulation method and system based on a slice network and a trusted data space, so as to solve the technical problem that data leakage is easily caused and data security is threatened when data interaction is based on a trusted data space.

[0006] To achieve the above objectives, the present invention proposes the following technical solutions:

[0007] In the first aspect, this technical solution provides a data circulation method based on a slice network and a trusted data space, including:

[0008] Private network devices are deployed one-to-one with each user, each private network device includes a first router and a core router that are communicatively connected; wherein each core router is connected to a connector, and each core router is communicatively connected to the trusted data space via a second router;

[0009] The steps include:

[0010] The connector obtains feedback generated by the private network to allow users to adopt pre-configured static routes as the basis and access the connector through the corresponding slice private network;

[0011] Obtaining a user trusted credential and an authentication message forwarded after being addressed by the first router; wherein the authentication message includes a header generated based on a network attribute tag; wherein the header is generated by the first router based on the slice private network, and the network attribute tag corresponds one-to-one to the slice private network;

[0012] Verify the user's trusted credentials, parse the authentication message, and forward the obtained network attribute tag to the network controller;

[0013] When the user's trusted credentials are verified and it is determined that the network controller has verified the network attribute tag, the user is allowed to enter the trusted data space through the second router to perform data interaction.

[0014] Furthermore, the slice private network is an SRV6 VPN network; the connector obtains feedback generated by the private network to allow the user to adopt a pre-configured static route as a basis, and accesses the connector through the corresponding slice private network; including:

[0015] The network controller obtains the service SLA requirements of each user to generate corresponding slice generation instructions;

[0016] Based on the slice generation instruction, the configuration is issued to the second router, and the first router and core router corresponding to each user to generate a customized slice private network of the corresponding level;

[0017] Among them, the SLA indicators corresponding to the business SLA requirements include: bandwidth parameters, latency parameters, and jitter parameters; the slice private network levels corresponding to the business SLA requirements include, from low to high,: soft isolation level, soft slicing level, deterministic slicing level, hard slicing level, and dedicated slicing level.

[0018] Furthermore, it includes dedicated network media, and the two ends of any dedicated network medium are respectively connected to the corresponding user and the first router; wherein the dedicated network medium includes a CPE access terminal, which is used to ensure that the authentication message from the user is forwarded to the first router first.

[0019] Further, including:

[0020] When the connector fails to verify the user's trusted credentials, the connector sends the verification result to the user so that the user's trusted credentials can be obtained and verified again;

[0021] When it is determined that the number of times the user's trusted credentials have failed to be verified within a preset time period reaches a preset threshold, a random verification code is sent to other clients bound to the user;

[0022] Obtain the random verification code input by the user, and when the verification fails, send a first abnormal access feedback to the connector to disconnect the data connection between the user and the connector and refuse login.

[0023] Further, including:

[0024] When the connector determines that the network controller fails to verify the network attribute tag, it sends a second abnormal access feedback to the connector to disconnect the data connection between the user and the connector and refuse login.

[0025] Secondly, this technical solution provides a data circulation system based on a slice network and a trusted data space, including:

[0026] Private network devices are deployed one-to-one with each user, each private network device includes a first router and a core router that are communicatively connected; wherein each core router is connected to a connector, and each core router is communicatively connected to the trusted data space via a second router;

[0027] Includes the following functional modules:

[0028] The first acquisition module is used to enable the connector to obtain feedback generated by the private network to allow the user to use the pre-configured static route as a basis and access the connector through the corresponding slice private network;

[0029] a second acquisition module, configured to acquire a user trusted credential and an authentication message forwarded after being addressed by the first router; wherein the authentication message includes a header generated based on a network attribute tag; wherein the header is generated by the first router based on the slice private network, and the network attribute tag corresponds one-to-one to the slice private network;

[0030] A verification and forwarding module, configured to verify the user's trusted credentials, parse the authentication message, and forward the obtained network attribute tag to the network controller;

[0031] The data circulation module is used to allow the user to enter the trusted data space through the second router for data interaction when the user's trusted credentials are verified and the network attribute tag is determined to be verified by the network controller.

[0032] Further, including:

[0033] The third acquisition module is used to enable the network controller to obtain the service SLA requirements of each user to generate corresponding slice generation instructions;

[0034] A private network generation module is configured to issue a configuration to the second router, and the first router and core router corresponding to each user based on the slice generation instruction to generate a customized slice private network of the corresponding level;

[0035] Among them, the SLA indicators corresponding to the business SLA requirements include: bandwidth parameters, latency parameters, and jitter parameters; the slice private network levels corresponding to the business SLA requirements include, from low to high,: soft isolation level, soft slicing level, deterministic slicing level, hard slicing level, and dedicated slicing level.

[0036] Further, including:

[0037] The abnormal feedback module is used for sending a second abnormal access feedback to the connector to disconnect the data connection between the user and the connector and refuse login when the connector determines that the network controller fails to verify the network attribute tag.

[0038] In a third aspect, the present technical solution provides an electronic device comprising at least one processor, wherein the processor is coupled to a memory, wherein a computer program is stored in the memory, and wherein the computer program is configured to execute the method described when executed by the processor.

[0039] In a fourth aspect, the present technical solution provides a computer-readable storage medium on which a computer program is stored, and the computer program is used to be executed by a processor to implement the described method.

[0040] Beneficial effects:

[0041] It can be seen from the above technical solutions that the technical solution of the present invention provides a data circulation method based on a slice network and a trusted data space to improve the current technical defects that easily cause data privacy leakage when data is interactively circulated through a trusted data space.

[0042] This technical solution deploys private network devices corresponding to each user. Each private network device includes a first router and a core router for communication. Each core router is connected to a connector, and each core router is communicatively connected to the trusted data space via a second router. Based on these private network devices, the following data flow process is involved: First, the connector obtains feedback generated by the private network to allow the user to access the connector through the corresponding slice private network based on a preconfigured static route. Second, the user's trusted credentials and authentication message, which are forwarded after being addressed by the first router, are obtained; the authentication message includes a header generated based on a network attribute tag. The header is generated by the first router based on the slice private network, and the network attribute tag corresponds to the slice private network. Then, the user's trusted credentials are verified, and after parsing the authentication message, the obtained network attribute tag is forwarded to the network controller. Finally, if the user's trusted credentials are verified and the network controller determines that the network attribute tag has been verified, the user is allowed to access the trusted data space via the second router for data exchange.

[0043] At this time, based on this technical solution, first of all, a corresponding slice private network is set up for each user, realizing the dual coordination of the slice network and the trusted data space, enhancing the isolation of user data transmission, and further protecting the data privacy security of the data provider. Secondly, considering that data security is related to both the human factors of the logged-in user and the objective factors of the network, a dual authentication mechanism of the network controller and the trusted data circulation space is adopted, that is, the user's trusted credentials are verified through the connector, and the network attributes are verified through the network controller, thereby strengthening the protection against abnormal intruders. Furthermore, the access method of the virtual private network router is adopted to realize the conversion from the user-side IP access method to the slice private network virtual private network routing addressing method for connector access, which avoids the exposure of user data on the public network while realizing network identity authentication, thereby improving the security of user data.

[0044] It should be appreciated that all combinations of the foregoing concepts, as well as additional concepts described in greater detail below, to the extent such concepts are not mutually inconsistent, can be considered to be part of the inventive subject matter of this disclosure.

[0045] The foregoing and other aspects, embodiments, and features of the present invention will be more fully understood from the following description in conjunction with the accompanying drawings. Other additional aspects of the present invention, such as features and / or beneficial effects of the exemplary embodiments, will become apparent from the following description or through practice of specific embodiments according to the present invention. BRIEF DESCRIPTION OF THE DRAWINGS

[0046] The accompanying drawings are not intended to be drawn to scale. In the drawings, each identical or nearly identical component shown in various figures may be represented by the same reference numeral. For the sake of clarity, not every component is labeled in every figure. Embodiments of various aspects of the present invention will now be described by way of example and with reference to the accompanying drawings, in which:

[0047] Figure 1 This is a hardware deployment topology diagram corresponding to the data flow method based on the slice network and trusted data space described in this embodiment;

[0048] Figure 2 This is a flow chart of the data circulation method based on the slice network and trusted data space described in this embodiment;

[0049] Figure 3 A flowchart generated for customized slicing private networks;

[0050] Figure 4 This is a flowchart for handling the failure of user trusted credential verification;

[0051] Figure 5 Flowchart for processing when network attribute label verification fails;

[0052] Figure 6 This is a structural block diagram of the data circulation system based on the slice network and trusted data space described in this embodiment;

[0053] Figure 7 This is a structural block diagram of the electronic device described in this embodiment. DETAILED DESCRIPTION

[0054] In order to make the purpose, technical solutions and advantages of the embodiments of the present invention clearer, the technical solutions of the embodiments of the present invention will be clearly and completely described below in conjunction with the drawings of the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the described embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention. Unless otherwise defined, the technical terms or scientific terms used herein should be the common meanings understood by people with ordinary skills in the field to which the present invention belongs.

[0055] The terms "first", "second" and similar words used in the specification and claims of this application do not indicate any order, quantity or importance, but are only used to distinguish different components. Similarly, unless the context clearly indicates otherwise, the singular forms of "a", "an" or "the" and similar words do not indicate a quantitative limitation, but rather indicate the presence of at least one. Words such as "include" or "comprise" mean that the elements or objects preceding "include" or "comprises" cover the features, wholes, steps, operations, elements and / or components listed after "include" or "comprises", and do not exclude the existence or addition of one or more other features, wholes, steps, operations, elements, components and / or their collections. "Up", "down", "left", "right" and the like are only used to indicate relative positional relationships. When the absolute position of the described object changes, the relative positional relationship may also change accordingly.

[0056] In the era of big data, effective data circulation is of great practical significance, and data circulation methods based on trusted data spaces are gradually being promoted and applied. However, because existing trusted data space networks use the internet, user data privacy leaks after users access the trusted data space network, and even data can be crawled and trained into intelligent agents by large network models, threatening user data security. Therefore, this embodiment aims to provide a data circulation method based on slice networks and trusted data spaces to address the above-mentioned technical issues related to data security.

[0057] The following is a detailed introduction to the data circulation method based on the slice network and trusted data space described in this embodiment with reference to the accompanying drawings.

[0058] Combine Figure 1 As shown, to facilitate the subsequent implementation of the data flow method, dedicated network equipment is deployed one-to-one with each user. Each dedicated network device includes a first router and a core router that are communicatively connected. Each core router is connected to a connector and is communicatively connected to the trusted data space via a second router. Furthermore, a network controller is also included, which is communicatively connected to each first router, each core router, and the second router via a third router.

[0059] The first, second, and third routers are primarily used for network access for users and application systems (e.g., network controllers and trusted data spaces). Their primary functions include, but are not limited to, maintaining user / application routing tables and providing first-hop routing for users / application systems to access other users / application systems. The core router's primary uses include, but are not limited to, routing switching and transmission relay during data transmission. In this embodiment, it is responsible for accessing each user connector.

[0060] At this point, two network layers are generated: the access network and the sliced ​​private network. The access network connects users to each connector through the first router, using direct fiber connections. The sliced ​​private network uses network slicing technology to connect the first router and core router with the trusted data space, user connectors, and network controllers, forming a sliced ​​private network. The first router can be deployed locally or in the same data center as the core router, depending on the customer's specific needs.

[0061] Combined with Figure 2 As shown, the method is carried out by the following steps:

[0062] Step S202: The connector obtains feedback generated by the private network to allow the user to access the connector through the corresponding slice private network based on the pre-configured static route.

[0063] Specifically, prior to step S202, the corresponding slicing network software has been installed on all connectors to parse the network attribute tags carried by the sliced ​​private network and support the IPV4 / V6 dual-stack protocol. Based on this, the slicing network technology used in this embodiment can be selected from MPLS VPN networks, VxLAN networks, and SRV6 VPN networks. Furthermore, through flow inspection, segment routing, resource reservation, time-frequency synchronization, cycle mapping, gated queue scheduling, traffic filtering and shaping, path planning, and SDN network situational awareness, path protection is achieved to the greatest extent possible, avoiding service interruptions caused by network node and line failures.

[0064] In the specific implementation, taking the SRV6 VPN network as an example, the slice private network generated for user N is SRV6 VPN N. At this time, the trusted data flow slice private network exclusive to user N is designated as SRV6 VPN N; and a static route to the address segment of connector N is configured on the corresponding first router N, so that only user N can access connector N through SRV6 VPN N.

[0065] Furthermore, when the slice private network is an SRV6 VPN network, combined with Figure 3 As shown, before step S202, the following steps are also included to generate dedicated slice networks at different levels:

[0066] Step S20102: The network controller obtains the service SLA requirements of each user to generate corresponding slice generation instructions.

[0067] In specific implementation, the SLA indicators corresponding to the service SLA requirements include: bandwidth parameters, delay parameters, jitter parameters, etc.

[0068] Step S20104: Based on the slice generation instruction, the configuration is issued to the first router, core router and second router corresponding to each user to generate a customized slice private network of the corresponding level.

[0069] This allows for multi-tiered private network service levels, resulting in even better customizable network service performance. In practice, the slicing private network levels corresponding to service SLA requirements are ranked from low to high: soft isolation, soft slicing, deterministic slicing, hard slicing, and dedicated slicing.

[0070] Among them, "L1-soft isolation" primarily utilizes common QoS technologies to map data packets to different priority queues based on their source / destination IP addresses, source / destination MAC addresses, and protocol types. This allows for differentiated service levels through scheduling of these priority queues. "L2-soft slicing" builds on L1 by adding key technologies such as SR-TE, SRv6, controllable primary / backup paths, and TI-LFA fast rerouting. This enables deterministic jitter of 1-3ms, service protection switching within 100ms, and controllable upper latency. It supports both large and small bandwidth granularity, making it suitable for basic, latency-sensitive services. "L3-deterministic slicing" expands on L2 by adding hardware feature support. Through hardware modifications, it implements deterministic IP (DIP), a hybrid queuing mechanism, cycle / time slot scheduling, and time-frequency synchronization. This reduces latency jitter to as low as 20μs during service transmission, effectively ensuring the quality of service for jitter-sensitive services. "L4-hard slicing" builds on L3 by focusing on the OTN optical transmission path, specifically improving the quality of service at the optical transmission stage. By integrating IP and optical transmission systems, applying FlexE technology (an interface technology for service isolation and network slicing in the bearer network. By breaking the rigid one-to-one mapping between the MAC layer and the PHY layer, FlexE enables flexible and refined management of interface resources, meeting the needs of some services for hard pipe isolation and on-demand bandwidth allocation) and 1+1 routing and wavelength protection technologies, jitter and service switching time are further reduced. "L5-dedicated slicing" builds on L4 hard slicing by using dedicated equipment networking to further reduce latency, jitter, and packet loss caused by physical equipment and lines. Dedicated transmission and optical fiber reduce latency and jitter, allowing for flexible bandwidth customization. Dedicated equipment and controllers enable customized service metrics for better service adaptation.

[0071] Step S204: Acquire the user's trusted credentials and authentication message forwarded after being addressed by the first router.

[0072] In this embodiment, the authentication message includes a header generated based on a network attribute tag, wherein the header is generated by the first router based on the slice private network, and the network attribute tag corresponds to the slice private network in a one-to-one manner.

[0073] In a specific implementation, taking an SRV6 VPN network as an example, user N addresses connector N on router N and performs user identity verification by entering the username and password on connector N's ​​page. During this process, the user sends the generated authentication message via the access network to router N on the slice private network. Router N then encapsulates the datagram header carrying the VPN attribute tag VRF SID=N using the SRV6 SID tag, thus identifying different VPN messages.

[0074] SRV6 SIDs are used to implement source-routing traffic engineering in IPv6 networks. SRV6 SIDs can embed VPN identifiers: VRF (Virtual Routing and Forwarding) SIDs. Each VRF corresponds to a unique SRV6 SID, which is used to isolate the routing tables of different VPNs. Therefore, this embodiment uses SRV6 SIDs embedded in VRF SIDs to identify the different VPNs to which a user belongs.

[0075] In specific applications, to ensure that authentication messages from user hosts accessing the connector are first sent to the first router, dedicated network media are also provided. These dedicated network media include CPE access terminals, common routers, and the like. Each dedicated network media is connected to each user on a one-to-one basis. This ensures that authentication messages from users are preferentially forwarded to the first router.

[0076] Step S206: Verify the user's trusted credentials, parse the authentication message, and forward the obtained network attribute tag to the network controller.

[0077] In a specific implementation, using an SRV6 VPN network as an example, Connector N verifies the username and password entered on the page. It also parses the authentication message to obtain the corresponding network attribute tag (VPN ID). At this point, the routing method from Connector N to the network controller is not restricted, as long as the route is reachable.

[0078] Step S208: When the user's trusted credentials are verified and it is determined that the network controller has verified the network attribute tag, the user is allowed to enter the trusted data space through the second router to perform data interaction.

[0079] Specifically, the network controller verifies whether the VPN ID returned by the connector N is N, and returns the verification result to the connector N. After the verification with the user's trusted credentials is passed, the connector N allows the user N to enter the trusted data space.

[0080] As a specific implementation method, Figure 4 As shown, the user trusted credential verification process is further specified as follows:

[0081] Step S20802: When the connector fails to verify the user's trusted credentials, the connector sends the verification result to the user so that the user's trusted credentials can be obtained and verified again.

[0082] Step S20804: When it is determined that the number of times that the user's trusted credentials have failed to be verified within the preset time period reaches a preset threshold, a random verification code is sent to other clients bound to the user.

[0083] Step S20806: Obtain the random verification code input by the user, and when the verification fails, send a first abnormal access feedback to the connector to disconnect the data connection between the user and the connector and refuse login.

[0084] Based on steps S20802 to S20806, this embodiment avoids access anomalies caused by verification anomalies due to subjective reasons of legitimate users by combining multiple verifications with random verifications. If both of the above verifications fail, it is considered that the user's trusted credentials are at risk of illegal theft, and the access rights are terminated at this time to protect the data security of all users in the trusted data space.

[0085] As another specific implementation method, Figure 5 As shown, the authentication message verification process is further specified as follows:

[0086] Step S20822: When the connector determines that the network controller fails to verify the network attribute tag, it sends a second abnormal access feedback to the connector to disconnect the data connection between the user and the connector and refuse login.

[0087] At this time, since the authentication message is automatically generated by the user host and the network attribute tag is automatically added by the first router, the entire process is not affected by user human factors. Therefore, an abnormality in the network attribute tag proves that there is a problem with the network itself. At this time, directly disconnecting the corresponding communication can maximize data security.

[0088] In summary, the data flow method described in this embodiment utilizes slicing networks and trusted data space technologies to more reliably ensure user data privacy and security. The slicing network implements user data network isolation, while the trusted data space protects data flow privacy. Furthermore, the dual authentication mechanism between the network controller and the trusted data flow space ensures data security by enhancing data access rights. Specifically, the first is connector login key verification, used to authenticate user access to the connector; the second is network attribute verification. After the user passes the first router, the data packet carries a network attribute tag (VPN ID). After the connector parses the packet, the VPN ID tag is sent to the network controller for secondary verification. Only after passing both verifications can the user access the trusted data space. Furthermore, access to the connector is achieved through an SRV6 VPN router, switching from user-side IP access to slice-specific VPN routing addressing. This ensures network identity authentication while preventing user data from being exposed to the public internet, significantly enhancing user data security.

[0089] The above program can be executed in a processor or stored in a memory (also known as a computer-readable storage medium). Computer-readable media include both permanent and non-permanent, removable and non-removable media, and can be implemented using any method or technology to store information. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include temporary computer-readable media such as modulated data signals and carrier waves.

[0090] These computer programs can also be loaded onto a computer or other programmable data processing device so that a series of operational steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable device to implement the process. Figure 1 a process or multiple processes and / or boxes Figure 1 The steps of the functions specified in one or more blocks can be implemented by different modules corresponding to different steps.

[0091] This embodiment also provides a data flow system based on a slice network and a trusted data space. The system includes: a private network device deployed one-to-one with each user, each private network device includes a first router and a core router connected in communication; wherein each core router is connected to a connector, and each core router is connected to the trusted data space in communication via a second router. Figure 6 As shown, the system also includes the following functional modules:

[0092] The first acquisition module is used to enable the connector to obtain feedback generated by the private network to allow the user to access the connector through the corresponding slice private network based on the pre-configured static route.

[0093] The second acquisition module is used to enable the connector to obtain the user's trusted credentials and authentication message forwarded after being addressed by the first router; wherein, the authentication message includes a header generated based on a network attribute tag; wherein, the header is generated by the first router based on the slice private network, and the network attribute tag corresponds one-to-one to the slice private network.

[0094] The verification and forwarding module is used to enable the connector to verify the user's trusted credentials, parse the authentication message, and forward the obtained network attribute tag to the network controller.

[0095] The data circulation module is used to allow the user to enter the trusted data space through the second router for data interaction when the connector verifies the user's trusted credentials and the network controller verifies the network attribute tag.

[0096] Since the system is built based on the method, what has been explained above will not be repeated here.

[0097] For example, the system further includes:

[0098] The third acquisition module is used to enable the network controller to obtain the service SLA requirements of each user to generate corresponding slice generation instructions.

[0099] The private network generation module is used to send configurations to the second router, as well as the first router and core router corresponding to each user based on the slice generation instruction to generate a customized slice private network of the corresponding level.

[0100] Among them, the SLA indicators corresponding to the business SLA requirements include: bandwidth parameters, latency parameters, and jitter parameters; the slice private network levels corresponding to the business SLA requirements include, from low to high,: soft isolation level, soft slicing level, deterministic slicing level, hard slicing level, and dedicated slicing level.

[0101] For another example, the system further includes:

[0102] The abnormal feedback module is used to send a second abnormal access feedback to the connector to disconnect the data connection between the user and the connector and refuse login when the connector determines that the network controller fails to verify the network attribute tag.

[0103] Combine Figure 7 As shown, this embodiment further provides an electronic device, comprising at least one processor coupled to a memory, wherein a computer program is stored in the memory, and the computer program is configured to execute the method when executed by the processor.

[0104] At the same time, this embodiment also provides a computer-readable storage medium on which a computer program is stored. The computer program is used to be executed by a processor to implement the method described.

[0105] Since the system, the electronic device, and the storage medium are all used to implement the method, they also have the following technical advantages in practical application: (1) Through the dedicated network technology for each user and each slice, the isolation of user data transmission is enhanced while ensuring the trusted circulation of user data, further ensuring the data privacy security of the data provider. (2) Through the dual cooperation of the network controller and the trusted data circulation space, the security of user access to the trusted data space is enhanced, and the protection against intruders is strengthened by the dual means of network attribute verification + connector login password verification. (3) As a key component of the trusted data space, the connector adopts VPN routing addressing and will not be exposed on the user side network, greatly improving data security.

[0106] While the present invention has been disclosed above with reference to preferred embodiments, this is not intended to limit the present invention. Persons skilled in the art will readily appreciate that various modifications and variations can be made without departing from the spirit and scope of the present invention. Therefore, the scope of protection of the present invention shall be determined by the claims.

Claims

1. A data circulation method based on a slice network and a trusted data space, characterized in that: include: Private network devices are deployed one-to-one with each user, each private network device includes a first router and a core router that are communicatively connected; wherein each core router is connected to a connector, and each core router is communicatively connected to the trusted data space via a second router; The steps include: The connector obtains feedback generated by the private network to allow users to adopt pre-configured static routes as the basis and access the connector through the corresponding slice private network; Obtaining a user trusted credential and an authentication message forwarded after being addressed by the first router; wherein the authentication message includes a header generated based on a network attribute tag; wherein the header is generated by the first router based on the slice private network, and the network attribute tag corresponds one-to-one to the slice private network; Verify the user's trusted credentials, parse the authentication message, and forward the obtained network attribute tag to the network controller; When the user's trusted credentials are verified and it is determined that the network controller has verified the network attribute tag, the user is allowed to enter the trusted data space through the second router to perform data interaction.

2. The data circulation method based on slice network and trusted data space according to claim 1 is characterized in that: The slice private network is an SRV6 VPN network; the connector obtains feedback generated by the private network to allow the user to adopt a pre-configured static route as a basis, and accesses the connector through the corresponding slice private network; including: The network controller obtains the service SLA requirements of each user to generate corresponding slice generation instructions; Based on the slice generation instruction, the configuration is issued to the second router, and the first router and core router corresponding to each user to generate a customized slice private network of the corresponding level; Among them, the SLA indicators corresponding to the business SLA requirements include: bandwidth parameters, latency parameters, and jitter parameters; the slice private network levels corresponding to the business SLA requirements include, from low to high,: soft isolation level, soft slicing level, deterministic slicing level, hard slicing level, and dedicated slicing level.

3. The data circulation method based on slice network and trusted data space according to claim 1 is characterized in that: It includes dedicated network media, and both ends of any dedicated network medium are respectively connected to the corresponding user and the first router; wherein the dedicated network medium includes a CPE access terminal, which is used to ensure that the authentication message from the user is forwarded to the first router first.

4. The data circulation method based on slice network and trusted data space according to claim 1 is characterized in that: include: When the connector fails to verify the user's trusted credentials, the connector sends the verification result to the user so that the user's trusted credentials can be obtained and verified again; When it is determined that the number of times the user's trusted credentials have failed to be verified within a preset time period reaches a preset threshold, a random verification code is sent to other clients bound to the user; Obtain the random verification code input by the user, and when the verification fails, send a first abnormal access feedback to the connector to disconnect the data connection between the user and the connector and refuse login.

5. The data circulation method based on slice network and trusted data space according to claim 1 is characterized in that: include: When the connector determines that the network controller fails to verify the network attribute tag, it sends a second abnormal access feedback to the connector to disconnect the data connection between the user and the connector and refuse login.

6. A data circulation system based on a slice network and a trusted data space, characterized in that: include: Private network devices are deployed one-to-one with each user, each private network device includes a first router and a core router that are communicatively connected; wherein each core router is connected to a connector, and each core router is communicatively connected to the trusted data space via a second router; Includes the following functional modules: The first acquisition module is used to enable the connector to obtain feedback generated by the private network to allow the user to use the pre-configured static route as a basis and access the connector through the corresponding slice private network; a second acquisition module, configured to acquire a user trusted credential and an authentication message forwarded after being addressed by the first router; wherein the authentication message includes a header generated based on a network attribute tag; wherein the header is generated by the first router based on the slice private network, and the network attribute tag corresponds one-to-one to the slice private network; A verification and forwarding module, configured to verify the user's trusted credentials, parse the authentication message, and forward the obtained network attribute tag to the network controller; The data circulation module is used to allow the user to enter the trusted data space through the second router for data interaction when the user's trusted credentials are verified and the network attribute tag is determined to be verified by the network controller.

7. The data circulation system based on slice network and trusted data space according to claim 6 is characterized in that: include: The third acquisition module is used to enable the network controller to obtain the service SLA requirements of each user to generate corresponding slice generation instructions; A private network generation module is configured to issue a configuration to the second router, and the first router and core router corresponding to each user based on the slice generation instruction to generate a customized slice private network of the corresponding level; Among them, the SLA indicators corresponding to the business SLA requirements include: bandwidth parameters, latency parameters, and jitter parameters; the slice private network levels corresponding to the business SLA requirements include, from low to high,: soft isolation level, soft slicing level, deterministic slicing level, hard slicing level, and dedicated slicing level.

8. The data circulation system based on slice network and trusted data space according to claim 6 is characterized in that: include: The abnormal feedback module is used for sending a second abnormal access feedback to the connector to disconnect the data connection between the user and the connector and refuse login when the connector determines that the network controller fails to verify the network attribute tag.

9. An electronic device, characterized in that: The method comprises at least one processor coupled to a memory, wherein a computer program is stored in the memory, and the computer program is configured to execute the method according to any one of claims 1 to 5 when executed by the processor.

10. A computer-readable storage medium, characterized in that A computer program is stored thereon, and the computer program is used to be executed by a processor to implement the method according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Method for safely accessing network slice based on application attribute and related equipment

    CN114828010A

  • Privacy of relay selection in cellular sliced networks

    WO2022038292A1