Cloud native network identification system and access authentication method thereof
By designing an access authentication method for the cloud-native network identification system, the need for unified identification in the cloud-native network architecture is solved, trusted access and secure management of terminals are achieved, and network security and service reliability are improved.
Patent Information
- Application Number
- CN202510752173.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-06
- Publication Date
- 2025-09-05
AI Technical Summary
How to design a unified identification system suitable for cloud-native network architecture to provide theoretical basis and technical support for the construction of next-generation information networks, intelligent edge services, and security and confidentiality mechanisms, especially to achieve secure interconnection in transparent connections between heterogeneous networks and services.
An access authentication method based on the cloud-native network identification system is designed, which includes the network twin service on the edge cloud device receiving terminal requests, allocating access attribute identification, and mapping and authenticating through global identification ID and dynamic attribute identification, evaluating the connection status and trust level of the terminal, and realizing trusted access and security management of the terminal.
It realizes trusted authentication and security management of terminals, reduces the risk of network attacks, enhances network defense capabilities, and ensures the safe use of network resources and the reliability of services.
Smart Images

Figure CN120602148A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of cloud native network technology, and in particular to a cloud native network identification system and an access authentication method thereof. Background Art
[0002] Demand for personalized, converged communications services for end entities—humans, machines, and objects—is surging. Network elements encompass diverse, numerous, and dispersed components, including systems, equipment, supplies, and personnel. Technologies like the Internet of Things, 5G, and Starlink are accelerating ubiquitous connectivity across all domains and promoting the maximization of network expansion. Future multi-dimensional scenarios encompassing land, sea, air, space, and electricity will inevitably require a robust network cloud infrastructure, supported by the Internet of Everything, intelligent perception, and human-machine interaction. Future heterogeneous networks will require transparent connectivity for massive numbers of humans, machines, and objects, as well as secure interconnection between heterogeneous networks and services. Furthermore, support will be needed to converge and interconnect various virtual resources (such as computing, storage, and services) within cloud-native networks.
[0003] From this, it can be concluded that how to design a unified identification system suitable for cloud-native network architecture from the perspective of cloud-native network system design to provide theoretical basis and technical support for the construction of next-generation information networks, intelligent edge services, and security and confidentiality mechanisms has become one of the existing technical problems that need to be solved urgently. Summary of the Invention
[0004] The present invention provides a cloud-native network identification system and its access authentication method, which are used to design a unified identification system suitable for cloud-native network architecture from the perspective of cloud-native network system design, and provide a theoretical basis and technical support for the construction of next-generation information networks and intelligent edge services and security and confidentiality mechanisms.
[0005] In a first aspect, an access authentication method based on a cloud native network identification system is provided, characterized by comprising:
[0006] The network twin service configured on the edge cloud device receives the network access request sent by the terminal carrying the terminal attributes, and assigns the terminal the corresponding access attribute identifier;
[0007] The network twin service maps the service attribute identifier of the terminal in the cloud native network space based on the terminal attribute identifier and the cloud native network identification system, and determines whether the terminal device has network access permission based on the pre-configured authorization management policy. The cloud native network identification system includes: a global identification ID and a dynamic attribute identifier. The dynamic attribute identifier includes: a terminal attribute identifier, an access attribute identifier, a service attribute identifier, a channel or path attribute identifier, a connection attribute identifier, and a business attribute identifier; wherein the global ID is dynamically mapped to the six types of dynamic attributes; the terminal attribute identifier and the access attribute identifier are in a parsing mapping relationship; the terminal attribute identifier and the service attribute identifier are in an authentication and authorization relationship;
[0008] If the terminal has network access permission, the access agent will periodically refresh the authentication of the terminal in the network connection state, and the network twin service will detect and evaluate the terminal's connection status based on the refresh authentication result;
[0009] If the terminal's connection status is normal use of network resources, the trust evaluation process will not be activated. If the network twin service detects abnormal time in the network, it will recalculate the terminal's trust level based on the onboard trust evaluation model and store it in the log database. When the trust level drops below the threshold, the network twin service will notify the access agent to cut off the terminal's network connection and reject the terminal's subsequent network access requests.
[0010] When the terminal logs off the network, it actively executes the network logout protocol, releases the terminal attribute identifier, access attribute identifier and session parameters of the local connection, reports to the network twin service, and returns a confirmation message to the access agent to complete the terminal logout.
[0011] In one embodiment, if the terminal has network access permission, the access agent periodically refreshes the authentication of the terminal in the network connection state, and the network twin service detects and evaluates the connection status of the terminal, specifically including:
[0012] If the terminal has network access permission, the access agent will start the soft life cycle and hard life cycle timers at the same time after the terminal passes the network access authentication. When the soft life cycle timer ends, the access agent will send a refresh authentication request to the network twin service again. The network twin service will respond with the access attribute identifier and session parameters saved during the initial network access authentication process. If the verification is correct, the hard timer will be restarted and the connection between the terminal and the network will continue to be maintained. If the verification is incorrect or no response message is received from the network twin service before the hard timer ends, the terminal's data communication session will be interrupted.
[0013] In one embodiment, the global ID is formed by uniquely encoding the network cloud nodes, network cloud devices of each public platform and the node elements of the control seat, user personnel, and user platform of each overall command agency;
[0014] The terminal attribute identification includes personnel, equipment and material elements, and is the identification of the human-machine-object entity in the physical space;
[0015] The access attribute identifier is a location identifier assigned when the human-machine-Internet of Things enters the cloud and a location identifier of the network twin service, which is used for the human-machine-thing to connect to the cloud native network based on the mapping relationship between the terminal attribute identifier and the access attribute identifier;
[0016] The service attribute identifier is the basis for querying and accessing upper-layer services on the cloud native network; the terminal attribute identifier of a person and the terminal attribute identifier of a machine are dynamically mapped one-to-one with the service attribute identifier of the person in the network; objects with Internet access capabilities are dynamically mapped one-to-one with the service attribute identifier of objects in the network; the service attribute identifiers of machines and objects are mapped many-to-one with the service attribute identifier of a person, and the service attribute identifier of an object is mapped with the service attribute identifier of the person to whom it belongs;
[0017] The channel or path attribute identifier is a link identifier composed of several physical transmission channels during the service transmission process;
[0018] The connection attribute identifier is a logical channel identifier established by the application and service on the physical transmission channel during the service transmission process;
[0019] The service attribute identifier is an identifier of the data service transmitted on the logical channel during the service transmission process, wherein different services have different service type identifiers and service sub-identifiers for service diversion and slicing.
[0020] In one embodiment, the global ID supports mapping cloud-native network space based on unique coding, and realizes user identity resolution and authentication in conjunction with the security and trust system; the coding capacity of the global ID is 128 bits, and a globally uniformly allocated 64-bit prefix includes: type, production date, manufacturer and serial number, and each system independently allocates a 64-bit suffix, including the unit code.
[0021] In one embodiment, in the terminal attribute identification, a person relies on a machine to access the cloud native network and then connect to the cloud. The person's unique terminal attribute identification includes: iris, fingerprint and ID card; the machine and the object themselves have the function of accessing the cloud native network and then connecting to the cloud. The unique terminal attribute identification of the machine and the object includes: the MAC address, terminal model and product serial number.
[0022] In one embodiment, the access attribute identifier is the address of the network node; the location identifier is represented by an IP address and a geographic location; and the location identifier of the network twin service is represented by a domain name or a service name.
[0023] In one embodiment, in the service attribute identification, the service attribute identification of a person includes the terminal attribute identification of the person, the terminal attribute identification of the machine, and the identification of human-machine data; the service attribute identification of an object includes the terminal attribute identification of the object, the terminal attribute identification of the owner, and the data identification of the person.
[0024] In one embodiment, the channel or path attribute identifier is used to represent a user connected to a single-hop network such as a cloud; for a user connected to a multi-hop network to a cloud, the channel or path attribute identifier is used in combination to represent the user.
[0025] In one embodiment, the connection attribute identifier includes a TCP connection identifier or a QUIC connection ID identifier, wherein a connection is uniquely identified in a TCP network by a five-tuple: source IP, source port, destination IP, destination port, and protocol identifier; QUIC uses a globally unique randomly generated connection ID to identify a connection.
[0026] In one embodiment, the service attribute identifier is used to match different application layer protocols and to be used in conjunction with a domain name system; the service is dynamically mapped to multiple connection attribute identifiers, channel or path attribute identifiers.
[0027] An embodiment of the present invention provides a cloud-native network identification system and an access authentication method thereof, comprising: a network twin service configured on an edge cloud device receives a network access request carrying terminal attributes sent by a terminal, and allocates a corresponding access attribute identifier to the terminal; the network twin service maps the service attribute identifier of the terminal in the cloud-native network space based on the terminal attribute identifier and the cloud-native network identification system, and judges whether the terminal device has network access authority based on a pre-configured authorization management policy. The cloud-native network identification system comprises: a global identification ID and a dynamic attribute identifier, and the dynamic attribute identifier comprises: a terminal attribute identifier, an access attribute identifier, a service attribute identifier, a channel or path attribute identifier, a connection attribute identifier, and a business attribute identifier; wherein, the global ID is dynamically mapped to six types of dynamic attributes; the terminal attribute identifier and the access attribute identifier are in a parsed mapping relationship; the terminal attribute identifier and the service attribute identifier are in an authentication and authorization relationship; if the terminal has network access authority, the access agent is timed Refresh authentication is performed on terminals in a network connection state, and the network twin service detects and evaluates the connection status of the terminal based on the refresh authentication result; if the connection status of the terminal is normal use of network resources, the trust evaluation process is not activated. If the network twin service detects abnormal time in the network, the terminal trust level is recalculated according to the onboard trust evaluation model and stored in the log database. When the trust level drops below the threshold, the network twin service will notify the access agent to cut off the terminal's network connection and reject the terminal's subsequent network access request; when the terminal logs off the network, it actively executes the network logout cancellation protocol, releases the terminal attribute identifier, access attribute identifier and session parameters of the local connection, reports to the network twin service, and returns a confirmation message to the access agent to complete the terminal logout. Through the above method, from the perspective of cloud native network system design, a unified identification system suitable for cloud native network architecture is designed, and a theoretical basis and technical support are provided for the construction of next-generation information networks, intelligent edge services, and security and confidentiality mechanisms.
[0028] Other features and advantages of the present invention will be described in the following description, and in part will become apparent from the description, or will be understood by practicing the present invention. The purposes and other advantages of the present invention can be realized and obtained by the structures particularly pointed out in the written description, claims, and drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] The drawings described herein are used to provide a further understanding of the present invention and constitute a part of the present invention. The exemplary embodiments of the present invention and their descriptions are used to explain the present invention and do not constitute an improper limitation of the present invention. In the drawings:
[0030] Figure 1 Schematic diagram of the access authentication method based on the cloud native network identification system according to an embodiment of the present invention;
[0031] Figure 2 Schematic diagram of a cloud-native network identification system according to an embodiment of the present invention;
[0032] Figure 3 A mapping diagram of a cloud-native network identification system according to an embodiment of the present invention;
[0033] Figure 4 Schematic diagram of the QUIC protocol model according to an embodiment of the present invention. DETAILED DESCRIPTION
[0034] From the perspective of cloud-native network system design, this paper designs a unified identification system suitable for cloud-native network architecture, providing a theoretical basis and technical support for the construction of next-generation information networks, intelligent edge services, and security and confidentiality mechanisms. A cloud-native network identification system and its access authentication method are provided.
[0035] The preferred embodiments of the present invention are described below in conjunction with the accompanying drawings. It should be understood that the preferred embodiments described herein are only used to illustrate and explain the present invention and are not used to limit the present invention.
[0036] like Figure 1 As shown, the embodiment provides an access authentication method based on a cloud native network identification system, including:
[0037] The network twin service adopts the process of "network access authentication-refresh authentication-trust assessment-network logout" to standardize the network access authentication process, timely and effectively detect abnormal behaviors of people, machines and objects, reduce potential security risks, and enhance network defense capabilities. When the access subnet has changes in access capacity or access methods, the use of different deployment modes will not affect the network access habits of users and terminals, and can fundamentally solve the problems of trusted authentication of terminal identities, trusted authentication of terminal users, and trusted authentication at the terminal security level. The specific process is described as follows:
[0038] S11. The network twin service configured on the edge cloud device receives the network access request carrying terminal attributes sent by the terminal, and assigns the corresponding access attribute identifier to the terminal.
[0039] Based on the authorization management policy pre-configured in the network twin service, the network twin service perceives the specific network access request initiated by the terminal and forwards it to the network twin service. The network twin service configured on the edge cloud device assigns the terminal the corresponding access attribute identifier.
[0040] S12. The network twin service maps the service attribute identification of the terminal in the cloud native network space according to the terminal attribute identification and based on the cloud native network identification system, and determines whether the terminal device has network access permission based on the pre-configured authorization management policy.
[0041] The authentication agent of the network twin service determines whether the terminal has network access authority by querying the terminal attribute identifier, and the terminal is a human-machine-object.
[0042] The specific implementation process is the network authentication process:
[0043] It is necessary to configure the authorization management policy in the network twin service in advance to determine whether the human-machine-object (terminal) has the right to access the network. When the terminal initiates a specific network access request, the network twin service perceives the terminal's network access requirement and forwards it to the network twin service. The authentication agent of the network twin service first queries the trust level of the terminal identification attribute of the terminal. If the trust level is lower than the threshold, the terminal's network access request is rejected; if the terminal's trust level is higher than the threshold, network access is approved. When the access agent of the network twin service receives the judgment result of approving the terminal's network access, it generates the session parameters for this connection and returns the result of the network access authentication to the access agent of the network twin service. The access agent saves the access attribute identifier for subsequent refresh authentication process. At this point, specific business data communication can be carried out between the terminal and the network.
[0044] like Figure 2 As shown, the embodiment provides a cloud-native network identification system, including: a global identification ID and dynamic attributes, the dynamic attributes including: a terminal attribute identifier, an access attribute identifier, a service attribute identifier, a channel or path attribute identifier, a connection attribute identifier and a business attribute identifier; wherein, the global ID and the six types of dynamic attributes are in a dynamic mapping relationship; the terminal attribute identifier and the access attribute identifier are in a parsing mapping relationship; the terminal attribute identifier and the service attribute identifier are in an authentication and authorization relationship.
[0045] To meet the secure, interoperable, and intelligent connectivity requirements of cloud-native networks, the proposed cloud-native network identification code primarily consists of a global ID and six dynamic attributes. These six dynamic attributes include: terminal attribute identifier, access attribute identifier, service attribute identifier, channel / path attribute identifier, connection attribute identifier, and business attribute identifier.
[0046] The one global ID is a globally unique identifier. The cloud-native network identification system covers networks, equipment, supplies, personnel, etc. It uniquely encodes the network cloud nodes, network cloud devices of each public platform, and the command seats, users, and use platforms of each overall command agency to form a global ID. The coding capacity is 128 bits. It supports mapping cloud-native network space based on unique coding, and can be linked with the security and trust system to realize user identity resolution and authentication. A 64-bit "prefix" is uniformly assigned globally: including type, factory (birth) date, manufacturer (compilation) manufacturer, serial number, etc. Each system independently assigns a 64-bit "suffix": including the unit code, etc.
[0047] 6 types of dynamic attribute identification. The attributes added to the cloud nodes, cloud devices, and command and control seats, users, and platforms of each public platform after being connected to the cloud will continue to change during the life cycle of the human-machine-object (end).
[0048] (1) Terminal attribute identification
[0049] In cloud-native networks, terminals include elements such as personnel, equipment, and supplies, forming the identification of human-machine-object (terminal) entities in the physical space.
[0050] People are attached to machines, connected to cloud-native networks, and then connected to the cloud. The unique attributes of people, such as irises, fingerprints, and ID cards, are combined to form an identification that serves as the person's unique terminal attribute identification.
[0051] Machines and objects inherently have the ability to connect to cloud-native networks and thus connect to the cloud. The MAC address, terminal model, and product serial number associated with each machine and object are combined to form an identifier that serves as their unique terminal attribute identifier.
[0052] (2) Access attribute identification
[0053] The location identifier (address) assigned to the human-machine-IoT cloud (core cloud or edge cloud) and the location identifier (address) of the network twin service. Through the access attribute identifier (i.e., the address of the network node), humans, machines, and objects are connected to the cloud native network. The location identifier assigned to the human-machine-IoT cloud is generally represented by an IP address or geographic location, while the location identifier of the network twin service is generally represented by a domain name (service name).
[0054] People, machines, and objects can be uniformly connected to the cloud-native network based on the mapping relationship between terminal attribute identifiers and access attribute identifiers.
[0055] (3) Service attribute identification
[0056] The service attribute identifier (name) of a physical human-machine-object (end) in the cloud-native network space serves as the basis for querying and accessing upper-layer services on the cloud-native network. In cloud-native networks, a network twin service for human-machine-object can be built in the cloud based on microservices. The network twin service in the cloud-native network space authenticates the physical human-machine-object (end), and the service attribute identifier remains unique within the cloud-native network space.
[0057] For humans and machines, humans are attached to machines with internet access, connected to the network and cloud. The human's terminal attribute identifier (person ID) and the machine's terminal attribute identifier (machine ID) are dynamically mapped one-to-one with the human's service attribute identifier in the network. The human's service attribute identifier includes multiple attributes, including the human's terminal attribute identifier, the machine's terminal attribute identifier, and the identifier of the human-machine data.
[0058] For objects, Internet-enabled objects form a one-to-one dynamic mapping with the service attribute identifiers of objects on the network. The service attribute identifiers of objects include multi-dimensional attributes such as the terminal attribute identifier of the object, the terminal attribute identifier of the owner, and the data identifier of the person.
[0059] The service attribute identifiers of machines and objects form a many-to-one mapping with the service attribute identifiers of people. In other words, the terminal attribute identifiers of people and machines form a one-to-one mapping with the service attribute identifiers of people, and the terminal attribute identifiers of objects form a one-to-one mapping with the service attribute identifiers of objects. At the same time, the service attribute identifiers of objects form a mapping with the service attribute identifiers of their respective people.
[0060] like Figure 3 As shown, when humans, machines, and objects in the network need to access the network, they find their corresponding service attribute identifiers through the mapping service between their terminal attribute identifiers and service attribute identifiers. The network twin service of humans, machines, and objects first performs security authentication on heterogeneous terminals such as humans, machines, and objects. After the authentication is completed, a network service request is initiated for the corresponding human-machine-object terminal, accessing the cloud native network to complete the requested cloud service function.
[0061] The network twin service is the mobile agent, transmission agent, and security agent for people, machines, and things in the cloud-native network. As the only entrance for people, machines, and things to access the cloud-native network, the network twin service realizes the authentication and authorization functions for heterogeneous terminals.
[0062] The terminal attribute identifier of human-machine-thing and the service attribute identifier of its network twin service are mapped. Machines and things have their own people. Human-machine-thing can be uniformly connected to the cloud native network based on the mapping relationship between terminal attribute identifier and access identifier.
[0063] The network twin service performs authentication and authorization for its human-machine-object (HMI) terminals. When a heterogeneous terminal such as HMI needs to access the cloud-native network, the HMI network twin service first performs security authentication for the HMI terminal through a mapping service between its terminal attribute identifier and service attribute identifier. Once authentication is complete, a network request is initiated for the HMI terminal, allowing it to access the cloud-native network and complete the request for the cloud-native network service function.
[0064] (4) Channel / path attribute identification
[0065] During service transmission, a link identifier consisting of several physical transmission channels.
[0066] For users who access the cloud through a single hop, a channel ID can be used to identify them. For example, for users who access the network through fiber or wired networks, the channel ID can be mapped using the channel type (optical ring network), optical port ID, and subnet ID.
[0067] For users accessing the cloud through multiple hops, they can be represented by combining channel IDs, such as [channel ID 1, channel ID 2, ..., channel ID n].
[0068] (5) Connection attribute identifier
[0069] During service transmission, the logical channel identifier established with the service is applied on the physical transmission channel, such as the TCP connection ID or the QUIC connection ID.
[0070] In traditional TCP / IP networks, a five-tuple (source IP, source port, destination IP, destination port, and protocol identifier) is used to uniquely identify a connection. This connection attribute identification method is retained in the cloud-native identification system.
[0071] New network protocols such as QUIC protocol model Figure 4 As shown. It uses the UDP (User Datagram Protocol) socket provided by the operating system downward, and provides a reliable and secure transmission channel for application layer protocols (such as HTTP / 2) upward. Although QUIC is based on the transport layer protocol UDP in its implementation, its protocol design does not rely on the characteristics of UDP, that is, it does not use UDP ports to identify a transport layer connection. The purpose of QUIC using UDP is only to maintain compatibility with existing networks, because some firewalls on the Internet currently block transport layer protocols other than TCP and UDP. Therefore, although QUIC works on the transport layer protocol UDP, researchers still generally classify it as a transport layer protocol.
[0072] To support mobility, QUIC abandons the use of a five-tuple to uniquely identify a connection in TCP / IP networks and instead uses a globally unique, randomly generated ID (the connection ID) to identify a connection. This allows QUIC connections established on the original network to seamlessly migrate to the new network when the physical network of one communicating party changes, such as switching from a cellular network to a Wi-Fi network, ensuring that network services are not interrupted during the user's network switch.
[0073] (6) Business attribute identification
[0074] During service transmission, the identifier of the data service is transmitted on the logical channel. Specifically, different services have different service type identifiers and service sub-identifiers for service slicing.
[0075] The service attribute identifier can be matched with different application layer protocols (e.g., sip), or can be used in conjunction with the Domain Name System. The service attribute identifier can be dynamically mapped with multiple connection attribute identifiers and channel / path attribute identifiers, so as to support the reliable transmission of multi-link and multi-connection for personalized services.
[0076] S13. If the terminal has the network access permission, the access agent periodically performs a refresh authentication on the terminal in the network connection state, and the network twin service detects and evaluates the connection state of the terminal.
[0077] Specifically in implementation, for the refresh authentication and authorization process:
[0078] The refresh authentication and authorization process centrally reflects the dynamic evaluation idea during runtime in the cloud-native network, that is, after the terminal accesses the network, its connection state is monitored and evaluated to make a trusted security evaluation during runtime. Therefore, in order to ensure the persistent credibility of the terminal identity, the access agent periodically performs a refresh authentication on the terminal in the network connection state. The refresh authentication process is an authentication performed again after the terminal passes the initial network access authentication request.
[0079] After the terminal passes the network access authentication and authorization, the access agent simultaneously starts the soft lifetime Ts and the hard lifetime Th timers (Ts < Th). When the soft lifetime timer expires, a refresh authentication request will be sent again to the network twin service, and the network twin service responds with the access attribute identifier and session parameters saved in the initial network access authentication and authorization process. If the verification is correct, the hard timer is restarted, and the connection between the terminal and the network is continued. If the verification is incorrect or no response message from the network twin service is received before the hard timer expires, the data communication session of the terminal is interrupted.
[0080] S14. If the connection state of the terminal is to use network resources normally, the trust evaluation process is not activated. If the network twin service detects an abnormal event in the network, the terminal trust level is recalculated and stored in the log database. When the trust level drops below the threshold, the network twin service will notify the access agent to cut off the network connection of the terminal and reject the subsequent network access requests of this terminal.
[0081] Specifically in implementation, for the trust evaluation process:
[0082] When the terminal is using network resources normally, the trust evaluation process is not activated. This process is only triggered by abnormal user behavior. When the network twin service detects an abnormal event in the network, such as a user using a forged digital certificate, accessing files beyond their level, or implanting a virus, the network twin service will recalculate its trust level and store it in the log database. Malicious users will continue to exhibit abnormal behavior during continuous attacks, and the trust level will drop sharply with the number and type of abnormal events. When the trust level drops below the threshold, the network twin service will notify the access agent to cut off the terminal's network connection and reject subsequent network access requests from the terminal. In this way, the behavior of people, machines, and objects using network resources can be supervised in a timely and effective manner, reducing the harm caused to the system by malicious network attackers and enhancing the security of the system.
[0083] S15. When the terminal logs off the network, it actively executes the network logout cancellation protocol, releases the terminal attribute identifier, access attribute identifier and session parameters of the local connection, reports to the network twin service, and returns a confirmation message to the access agent to complete the terminal logout.
[0084] When it is implemented, it is the process of logging off the network:
[0085] If a terminal on the network creates a false logout message, and the access agent does not verify this message and directly cuts off the connection between the terminal and the network, the victim will be unable to continue to access the Internet. Therefore, when designing the logout and cancellation protocol, the user is required to include the parameters of the most recent refresh authentication when requesting logout from the terminal to prevent this from happening. When the terminal logs out of the network, it can actively execute the logout and cancellation protocol, release the terminal attribute identifier, access attribute identifier, and session parameters of the local connection, report to the network twin service, and return a confirmation message to the access agent, thus completing the user logout process.
[0086] The embodiment provides a cloud-native network identification system and its access authentication method. The network twin service is based on the security verification of man-machine-object. Through device binding, identity authentication, security domain control and other means, it fundamentally guarantees the credibility of the access network terminal and controls the access rights of the trusted terminal, providing strong protection for the security of man-machine-object access to the cloud and reducing security risks from within the access subnet.
[0087] The Network Twin service provides role-based access control capabilities, assigning different security access control domains to different roles. Users who fail network security checks are isolated from special access control domains. Regular users' access to network resources is subject to certain restrictions, such as network bandwidth or transmission latency, to prevent potential risks to network security and transmission capabilities. Authorized users' access to network resources is better protected, with targeted network access policies and policy lifecycles configured for authorized users. Users' network access behavior events are also visible, controllable, and recordable.
[0088] Although the preferred embodiments of the present invention have been described, those skilled in the art may make additional changes and modifications to these embodiments once they have learned the basic creative concept. Therefore, the appended claims are intended to be interpreted as including the preferred embodiments and all changes and modifications that fall within the scope of the present invention.
[0089] Obviously, those skilled in the art may make various changes and modifications to the present invention without departing from the spirit and scope of the present invention. Thus, if such changes and modifications fall within the scope of the claims and their equivalents, the present invention is intended to include such changes and modifications.
Claims
1. An access authentication method based on a cloud native network identification system, characterized in that: include: The network twin service configured on the edge cloud device receives the network access request sent by the terminal carrying the terminal attributes and assigns the terminal the corresponding access attribute identifier; The network twin service maps the service attribute identifier of the terminal in the cloud native network space based on the terminal attribute identifier and the cloud native network identification system, and determines whether the terminal device has network access permission based on the pre-configured authorization management policy. The cloud native network identification system includes: a global identification ID and a dynamic attribute identifier. The dynamic attribute identifier includes: a terminal attribute identifier, an access attribute identifier, a service attribute identifier, a channel or path attribute identifier, a connection attribute identifier, and a business attribute identifier; wherein the global ID is dynamically mapped to the six types of dynamic attributes; the terminal attribute identifier and the access attribute identifier are in a parsing mapping relationship; the terminal attribute identifier and the service attribute identifier are in an authentication and authorization relationship; If the terminal has network access permission, the access agent will periodically refresh the authentication of the terminal in the network connection state, and the network twin service will detect and evaluate the terminal's connection status based on the refresh authentication result; If the terminal's connection status is normal use of network resources, the trust evaluation process will not be activated. If the network twin service detects abnormal time in the network, it will recalculate the terminal's trust level based on the onboard trust evaluation model and store it in the log database. When the trust level drops below the threshold, the network twin service will notify the access agent to cut off the terminal's network connection and reject the terminal's subsequent network access requests. When the terminal logs off the network, it actively executes the network logout protocol, releases the terminal attribute identifier, access attribute identifier and session parameters of the local connection, reports to the network twin service, and returns a confirmation message to the access agent to complete the terminal logout.
2. The method according to claim 1, characterized in that If the terminal has network access permission, the access agent periodically refreshes and authenticates the terminal in the network connection state. The network twin service detects and evaluates the terminal's connection status based on the refresh authentication result, specifically including: If the terminal has network access permission, the access agent will start the soft life cycle and hard life cycle timers at the same time after the terminal passes the network access authentication. When the soft life cycle timer ends, the access agent will send a refresh authentication request to the network twin service again. The network twin service will respond with the access attribute identifier and session parameters saved during the initial network access authentication process. If the verification is correct, the hard timer will be restarted and the connection between the terminal and the network will continue to be maintained. If the verification is incorrect or no response message is received from the network twin service before the hard timer ends, the terminal's data communication session will be interrupted.
3. The method according to claim 2, characterized in that The global ID is formed by uniquely encoding the network cloud nodes, network cloud devices of each public platform and the node elements of the command seat, user personnel and user platform of each overall command agency; The terminal attribute identification includes personnel, equipment and material elements, and is the identification of the human-machine-object entity in the physical space; The access attribute identifier is a location identifier assigned when the human-machine-Internet of Things enters the cloud and a location identifier of the network twin service, which is used for the human-machine-thing to connect to the cloud native network based on the mapping relationship between the terminal attribute identifier and the access attribute identifier; The service attribute identifier is the basis for querying and accessing upper-layer services on the cloud native network; the terminal attribute identifier of a person and the terminal attribute identifier of a machine are dynamically mapped one-to-one with the service attribute identifier of the person in the network; objects with Internet access capabilities are dynamically mapped one-to-one with the service attribute identifier of objects in the network; the service attribute identifiers of machines and objects are mapped many-to-one with the service attribute identifier of a person, and the service attribute identifier of an object is mapped with the service attribute identifier of the person to whom it belongs; The channel or path attribute identifier is a link identifier composed of several physical transmission channels during the service transmission process; The connection attribute identifier is a logical channel identifier established by the application and service on the physical transmission channel during the service transmission process; The service attribute identifier is an identifier of the data service transmitted on the logical channel during the service transmission process, wherein different services have different service type identifiers and service sub-identifiers for service diversion and slicing.
4. The method according to claim 3, characterized in that The global ID supports mapping cloud-native network space based on unique coding, and works in conjunction with security and trust systems to implement user identity resolution and authentication. The encoding capacity of the global ID is 128 bits. A 64-bit prefix is uniformly allocated globally, including: type, production date, manufacturer and serial number. Each system independently allocates a 64-bit suffix, including the unit code.
5. The method according to claim 4, characterized in that In the terminal attribute identification, people rely on machines to access the cloud native network and then connect to the cloud. The unique terminal attribute identification of people includes: iris, fingerprint and ID card; machines and objects themselves have the function of accessing the cloud native network and then connecting to the cloud. The unique terminal attribute identification of machines and objects includes: MAC address, terminal model and product serial number.
6. The method according to claim 5, characterized in that The access attribute identifier is the address of the network node; the location identifier is represented by the IP address and geographic location; the location identifier of the network twin service is represented by a domain name or service name.
7. The method according to claim 6, characterized in that In the service attribute identification, the service attribute identification of a person includes the terminal attribute identification of the person, the terminal attribute identification of the machine, and the identification of the human-machine data; the service attribute identification of an object includes the terminal attribute identification of the object, the terminal attribute identification of the owner, and the data identification of the person.
8. The method according to claim 7, characterized in that The channel or path attribute identifier is used to represent a user connected to a single-hop network such as a cloud; for a user connected to a multi-hop network such as a cloud, the channel or path attribute identifier is used in combination to represent the user.
9. The method according to claim 8, characterized in that The connection attribute identifier includes a TCP connection identifier or a QUIC connection ID identifier, wherein a connection is uniquely identified in a TCP network through a five-tuple: source IP, source port, destination IP, destination port and protocol identifier; QUIC uses a globally unique randomly generated connection ID to identify a connection.
10. The method according to claim 9, characterized in that The service attribute identifier is used to match different application layer protocols and to be used in conjunction with a domain name system; the service is dynamically mapped to a plurality of connection attribute identifiers, channel or path attribute identifiers.
Citation Information
Patent Citations
Internet of Things equipment management method and system
CN110505089A
Power network security protection method based on zero trust
CN115189927A
Unified access method, device and equipment based on network twinning and storage medium
CN116684195A
Access authentication method adaptive to network twinning scene
CN117915328A
System for providing zero trust model based seruity management service
KR102655993B1