Edge endogenous security extension access method, system, device, medium and equipment
By dynamically selecting the quantitative difference between the intrinsic interface and the secondary interface, merging or separating the interface types, and using the policy control function network element or edge application server to select the authentication strategy, the intrinsic security issues of the 5G-A network platform under multi-level extended interfaces are solved, and the authentication flexibility and security are improved.
Patent Information
- Application Number
- CN202511022459.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-07-24
- Publication Date
- 2025-09-12
AI Technical Summary
With the support of diversified services and multi-level extension interfaces on the 5G-A network platform, the existing AKA authentication mechanism cannot effectively authenticate secondary and deeper extension interfaces, resulting in prominent inherent security issues, especially the lack of flexibility when accessing terminals and application services in scenarios such as the Internet of Vehicles and smart cities.
By dynamically selecting the quantitative relationship between the intrinsic interface and the secondary interface, merging or separating interface types, and using the policy control function network element or edge application server as the authentication identification network element, authentication strategy selection is performed, authentication vectors are generated and consistency comparison is performed, thereby improving authentication flexibility.
While ensuring the security of the inherent extension interface, it significantly improves the flexibility of extended access authentication, addresses the gaps in the existing authentication mechanism, and improves the multi-access security management and scheduling capabilities of the 5G-A platform.
Smart Images

Figure CN120639485A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of communication technology, and in particular to an edge intrinsic security extended access method, system, device, computer-readable storage medium, electronic device and computer program product. Background Art
[0002] At the 2019 Beijing Cybersecurity Conference, security vendors proposed the concept of "intrinsic security." This concept focuses on the cybersecurity attack and defense process, referring to security capabilities that continuously grow within information systems, improving with business growth and ensuring ongoing business security. Currently, 5G networks are gradually transitioning to 5G-A (5G Advanced) networks to accommodate the multi-terminal access requirements of the IoT environment. By introducing the Network Data Analytics Function (NWDAF) network element extension interface, external AI capabilities, super-subscription capabilities, and diversified billing capabilities are integrated into the current slicing network platform.
[0003] However, with the evolution of 5G to 5G-A, support for diversified services and multi-level extension interfaces has become increasingly stronger, and inherent security issues have become increasingly prominent. Specifically, after the 5G-A platform accesses the primary extension interface, it can further extend its functionality through secondary extension interfaces, forming a "multi-connection, multi-multi" inherent access model. However, the NWDAF network element extension structure in the 5G-A platform is unable to verify multiple inherent accesses. In other words, the existing AKA authentication mechanism for 5G and 5G-A only verifies the legitimacy of the primary extension interface and lacks effective authentication of secondary and deeper extension interfaces. This inherent security issue is particularly prominent in typical application scenarios such as the Internet of Vehicles and smart cities, because these scenarios often require the introduction of a large number of terminals and application services through extension interfaces. Summary of the Invention
[0004] The purpose of the embodiments of the present invention is to provide an edge intrinsic security extended access method, system, device, computer-readable storage medium, electronic device and computer program product, which dynamically selects authentication strategies based on the quantitative relationship between intrinsic interfaces and secondary interfaces, and can significantly improve the flexibility of extended access authentication while ensuring the security of intrinsic extended interfaces, and fill the gap in authentication of intrinsic extended interfaces under existing authentication mechanisms.
[0005] An embodiment of the present invention provides an edge intrinsic security extension access method, including:
[0006] When the difference between the endogenous interface to be accessed and the secondary interface is less than a first preset value, merging the primary interface and the secondary interface into an external verification interface, using the secondary interface as an edge authentication interface, and using the policy control function network element as an authentication and identification network element;
[0007] When the number of differences is not less than the first preset value, the primary interface is used as an external verification interface, the internal interface and the secondary interface are used as edge authentication interfaces, and the edge application server is used as an authentication and identification network element; wherein the external verification interface is used to assist the edge authentication interface in completing authentication-related cryptographic operations, so that the edge authentication interface generates an authentication vector;
[0008] The edge authentication interface is authenticated and identified through the authentication and identification network element.
[0009] Optionally, after the authentication and identification network element performs authentication and identification on the edge authentication interface, the method further includes:
[0010] When the authentication identification network element is the policy control function network element, the policy control function network element generates an authorization token for the edge authentication interface that has passed the authentication and sends it to the edge application server. The authorization token is synchronized to the network data analysis function network element through the edge application server, so that the authorization token is sent by the network data analysis function network element to the edge authentication interface that has passed the authentication.
[0011] Optionally, after the authentication and identification network element performs authentication and identification on the edge authentication interface, the method further includes:
[0012] When the authentication identification network element is the edge application server, the edge application server generates an authorization token for the edge authentication interface that has passed the authentication and synchronizes it to the network data analysis function network element, and the authorization token is sent to the edge authentication interface that has passed the authentication through the network data analysis function network element.
[0013] Optionally, when the difference between the endogenous interface and the secondary interface to be connected is less than a first preset value, the interface with the shortest message queue length is selected from the external verification interface corresponding to each edge authentication interface as the main communication interface, and the corresponding edge authentication interface is used as the reception interface; wherein each of the main communication interfaces is used to interact with the corresponding reception interface to perform the cryptographic operation to obtain the corresponding authentication vector.
[0014] Optionally, when the number of differences is not less than the first preset value, the interface with the longest sustainable sweet spot duration or the shortest message queue length under the current load is selected as the reception interface from the edge authentication interfaces corresponding to each external verification interface, and the corresponding external verification interface is used as the main communication interface.
[0015] Optionally, the authentication vector is obtained by the following steps:
[0016] Generate a public key and a master key through the external verification interface;
[0017] The edge authentication interface obtains an initial parameter group based on the collected parameters and sends the initial parameter group to the external verification interface; wherein the initial parameter group includes: a primary communication interface identifier and an optimal service time of the edge authentication interface;
[0018] The external verification interface encrypts the information received in the initial parameter group according to the local optimal service time and the master key, obtains the corresponding verification response parameter group, and sends the verification response parameter group to the edge authentication interface;
[0019] The received verification response parameter group is encrypted through the edge authentication interface to obtain the authentication vector.
[0020] Optionally, the performing authentication and identification on the edge authentication interface by the authentication and identification network element includes:
[0021] Requesting the interface identifiers of the communicating interfaces from the external verification interface and the edge authentication interface respectively through the authentication identification network element, and performing consistency comparison;
[0022] If the comparison results are consistent, it indicates that the edge authentication interface authentication has failed;
[0023] If the comparison results are inconsistent, verifying the authentication vector of the edge authentication interface through the authentication identification network element;
[0024] If the verification fails, it indicates that the edge authentication interface authentication has failed;
[0025] If the verification is successful, it indicates that the edge authentication interface authentication is passed.
[0026] An embodiment of the present invention provides an edge intrinsic security extension access system, including:
[0027] A request access interface, configured to extract a capability requirement from a received access capability extension request and forward the capability requirement to a network data analysis function network element;
[0028] The network data analysis function network element is configured to initiate an interface access registration request to the network storage function network element according to the tracking area list and the received capability requirement;
[0029] The network storage function network element is configured to respond to the received interface access registration request, activate the protocol data unit session of the subscriber, and feed back the user subscription information to the policy control function network element;
[0030] The policy control function network element is configured to, after receiving the user contract information, initiate a service quality analysis subscription request to the network data analysis function network element; wherein the service quality analysis subscription request is used to instruct the policy control function network element and the edge application server to collaboratively analyze the quantitative relationship between the intrinsic interface and the secondary interface under the capacity demand;
[0031] an edge application server, configured to collaborate with the policy control function network element to analyze the quantity relationship;
[0032] The policy control function network element is further configured to serve as an authentication and identification network element when the quantity relationship is that the difference between the intrinsic interface and the secondary interface is less than a first preset value;
[0033] The edge application server is further configured to serve as an authentication and identification network element when the difference amount is not less than the first preset value.
[0034] An embodiment of the present invention provides an edge intrinsic security extension access device, including:
[0035] A first interface definition module is configured to, when the difference between the endogenous interface to be accessed and the secondary interface is less than a first preset value, merge the endogenous interface and the secondary interface into an external verification interface, use the secondary interface as an edge authentication interface, and use the policy control function network element as an authentication and identification network element;
[0036] a second interface definition module configured to, when the number of differences is not less than the first preset value, use the primary interface as an external verification interface, use the intrinsic interface and the secondary interface as edge authentication interfaces, and use the edge application server as an authentication identification network element; wherein the external verification interface is configured to assist the edge authentication interface in completing authentication-related cryptographic operations, so that the edge authentication interface generates an authentication vector;
[0037] The authentication and identification module is used to authenticate and identify the edge authentication interface through the authentication and identification network element.
[0038] An embodiment of the present invention provides a computer-readable storage medium, which includes a stored computer program; wherein, when the computer program is running, it controls the device where the computer-readable storage medium is located to execute the edge intrinsic security extension access method described in any of the above embodiments.
[0039] An embodiment of the present invention provides a computer program product, including a computer program, which, when executed by a processor, implements the edge intrinsic security extended access method described in any of the above embodiments.
[0040] An embodiment of the present invention provides an electronic device, including a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, it implements the edge intrinsic security extended access method as described in any of the above embodiments.
[0041] Compared with the existing technology, the embodiments of the present invention provide an edge intrinsic security extended access method, system, device, computer-readable storage medium, electronic device and computer program product. The method determines the parallel relationship between interfaces based on the difference between the intrinsic interface and the secondary interface, thereby dynamically selecting the access security authentication strategy, significantly improving the flexibility of extended access authentication while ensuring the security of the intrinsic extended interface, and filling the gap in authentication of the intrinsic extended interface under the existing authentication mechanism. BRIEF DESCRIPTION OF THE DRAWINGS
[0042] Figure 1 This is a structural diagram of an embodiment of the edge intrinsic security extended access system provided by the present invention;
[0043] Figure 2 This is a flow chart of an embodiment of the edge intrinsic security extension access system management intrinsic extension interface provided by the present invention;
[0044] Figure 3 This is a flow chart of an embodiment of the edge intrinsic security extension access method provided by the present invention;
[0045] Figure 4 This is a flowchart of an embodiment of obtaining and identifying authentication vectors provided by the present invention;
[0046] Figure 5 This is a flowchart of an embodiment of generating and sending an authorization token provided by the present invention;
[0047] Figure 6 This is a structural diagram of an embodiment of the edge intrinsic security extension access device provided by the present invention;
[0048] Figure 7It is a structural diagram of an embodiment of an electronic device provided by the present invention. DETAILED DESCRIPTION
[0049] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. All other embodiments obtained by ordinary technicians in this technical field based on the embodiments of the present invention without making any creative efforts shall fall within the scope of protection of the present invention.
[0050] In order to clearly describe the technical solutions in the embodiments of the present invention, see Table 1, which briefly explains some terminology concepts involved in the embodiments of the present invention.
[0051] Table 1. Explanation of terminology
[0052] Chinese expression Complete English statement English abbreviations Network data analysis function Network Data Analytics Function NWDAF Protocol Data Unit Protocol Data Unit PDU Network repository functionality Network Repository Function NRF Policy control function Policy Control Function PCF Edge application server Edge Application Server EAS Tracking Area Tracking Area TA Tracking area identifier Tracking Area Identity TAI
[0053] See also Figure 1 , is a structural diagram of an embodiment of the edge intrinsic security extended access system provided by the present invention.
[0054] A first embodiment of the present invention provides an edge intrinsic security extension access system, including:
[0055] The request access interface 11 is used to extract the capability requirement from the received access capability extension request and forward the capability requirement to the network data analysis function network element 12;
[0056] The network data analysis function network element 12 is configured to initiate an interface access registration request to the network storage function network element 13 according to the tracking area list and the received capability requirement;
[0057] The network repository function network element 13 is configured to respond to the received interface access registration request, activate the protocol data unit session of the subscriber, and feed back the subscriber subscription information to the policy control function network element 14;
[0058] The policy control function network element 14 is configured to, after receiving the user contract information, initiate a service quality analysis subscription request to the network data analysis function network element 12; wherein the service quality analysis subscription request is used to instruct the policy control function network element 14 and the edge application server 15 to collaboratively analyze the quantitative relationship between the intrinsic interface and the secondary interface under the capacity demand;
[0059] The edge application server 15 is configured to collaborate with the policy control function network element 14 to analyze the quantity relationship;
[0060] The policy control function network element 14 is further configured to serve as an authentication and identification network element when the quantity relationship is that the difference between the intrinsic interface and the secondary interface is less than a first preset value;
[0061] The edge application server 15 is further configured to serve as an authentication and identification network element when the difference amount is not less than the first preset value.
[0062] For example, Figure 2 FIG. 1 is a flow chart of an embodiment of an edge intrinsic security extension access system management intrinsic extension interface provided by the present invention. The specific steps are as follows:
[0063] Step 1.1: The demander (user) initiates an access capability expansion request Q-PDU to the 5G-A intelligent platform and submits it through the platform's PDU interface. The Q-PDU request carries information including the required capability quantity NV (used to describe the required quantity of interface capability).
[0064] Step 1.2: After the Q-PDU request response is passed, the PDU interface extracts the capability requirement NV from the Q-PDU request and forwards it to the NWDAF interface.
[0065] Step 1.3: The NWDAF network element initiates an interface access registration request to the NRF network element. The information carried in the interface access registration request includes: a list of TAs supported and guaranteed by the NWDAF network element in the region (including a list of 4G TAs in the corresponding region); and NWDAF network elements in the province can collect the wireless cell loads of the entire province.
[0066] Step 1.4 and Step 1.5: After the interface access registration request response is passed, the NWDAF network element triggers the NRF network element's "Subscriber PDU Session Activation" process. After completion, the user subscription information is fed back to the PCF network element through the NRF network element.
[0067] Step 1.6 and Step 1.7: After the PCF network element receives the user's contract information, it locates the NWDAF interface according to the TAI at the time of the user's initial activation and initiates a service quality analysis (QoS_ANALYSIS) subscription request to the NWDAF interface; wherein, the QoS_ANALYSIS subscription request is used to indicate the quantitative relationship between the intrinsic interfaces and secondary interfaces involved in the collaborative analysis capability requirement NV of the PCF network element and EAS, so as to determine the authentication process for extended interface access based on the quantitative relationship.
[0068] Step 1.8: After the QoS_ANALYSIS subscription request response is passed, the PCF network element and EAS jointly analyze the quantitative relationship between the intrinsic interfaces and secondary interfaces involved in the capability demand NV.
[0069] Specifically, the PCF network element port and EAS jointly decompose the capacity requirement NV according to the "primary-endogenous-secondary" relationship, determine the parallel relationship between the interfaces, and the number of primary interfaces, endogenous interfaces, and secondary interfaces. For example, when the number of primary interfaces is equal to the average of the current maximum carrying capacity of the PCF network element and EAS, the difference between the endogenous interfaces and the secondary interfaces under the primary interface is estimated. If the difference between the number of secondary interfaces and the number of endogenous interfaces is less than 3× the number of primary interfaces, the endogenous interfaces and the primary interfaces are authenticated for access according to the same dimensional standard (i.e., access situation one), and the PCF network element is used as the authentication and identification network element. Otherwise, the endogenous interfaces and secondary interfaces are combined for access authentication according to the same dimensional standard (i.e., access situation two), and the EAS is used as the authentication and identification network element.
[0070] It is worth noting that the edge intrinsic security extension access system relies on the collaborative interaction of interfaces such as NWDAF, PDU, PCF and EAS under the core network 5G-A intelligent platform, and can complete the management and scheduling of intrinsic extension interfaces such as intrinsic interfaces and secondary interfaces.
[0071] The edge intrinsic security extended access system in the embodiment of the present invention can implement all processes of the edge intrinsic security extended access method described in any embodiment of the second aspect. The functions of each module, interface, and network element in the system and the technical effects achieved are respectively the same as the functions and technical effects achieved by the edge intrinsic security extended access method described in any embodiment of the second aspect, and will not be repeated here.
[0072] See also Figure 3 , is a flow chart of an embodiment of the edge intrinsic security extended access method provided by the present invention.
[0073] The second embodiment of the present invention provides an edge intrinsic security extension access method, including steps S1 to S3, as follows:
[0074] Step S1: When the difference between the primary interface and the secondary interface to be connected is less than a first preset value, the primary interface and the secondary interface are merged into an external verification interface, the secondary interface is used as an edge authentication interface, and the policy control function network element 14 is used as an authentication and identification network element;
[0075] Step S2: If the number of differences is not less than the first preset value, the primary interface is used as an external verification interface, the internal interface and the secondary interface are used as edge authentication interfaces, and the edge application server 15 is used as an authentication and identification network element; wherein the external verification interface is used to assist the edge authentication interface in completing authentication-related cryptographic operations, so that the edge authentication interface generates an authentication vector;
[0076] Step S3: Authentication and identification are performed on the edge authentication interface through the authentication and identification network element.
[0077] It should be noted that "situation one to be accessed" corresponds to "the situation where the difference between the intrinsic interface to be accessed and the secondary interface is less than the first preset value"; "situation two to be accessed" corresponds to "the situation where the difference is not less than the first preset value".
[0078] In an embodiment of the present invention, dynamic policy selection is performed based on the difference in the number of endogenous interfaces and secondary interfaces, that is, intelligent selection of authentication methods is achieved. When the difference number is less than a first preset value (such as the difference between the number of secondary interfaces and the number of endogenous interfaces <3×the number of primary interfaces), the primary interface and the secondary interface are merged in the same dimension as an external verification interface (generation interface), the secondary interface is directly used as the edge authentication interface, and the policy control function network element 14 is enabled as the authentication and identification network element. When the difference number is not less than a first preset value (such as the difference between the number of secondary interfaces and the number of endogenous interfaces ≥3×the number of primary interfaces), the secondary interface is directly used as an external verification interface, the endogenous interface and the secondary interface are merged in the same dimension as the edge authentication interface, and the edge application server 15 is enabled as the authentication and identification network element.
[0079] The embodiment of the present invention adopts a dual-mechanism authentication process, that is, by analyzing the number and relationship of the intrinsic ports and secondary ports under the capacity demand NV, the parallel relationship between the interfaces is determined, thereby dynamically selecting the access security authentication strategy, while ensuring the security of the intrinsic extension interface and significantly improving the flexibility of the extended access authentication. It solves the problem that the AKA authentication mechanism of 5G and 5G-A cannot provide iterative authentication services and authentication capabilities, fills the gaps in the above-mentioned security policies and signaling authentication, and improves the security management and scheduling capabilities of the 5G-A platform's diversified access.
[0080] In an optional embodiment, when the difference between the endogenous interface and the secondary interface to be connected is less than a first preset value, the interface with the shortest message queue length is selected from the external verification interface corresponding to each edge authentication interface as the main communication interface, and the corresponding edge authentication interface is used as the reception interface; wherein each of the main communication interfaces is used to interact with the corresponding reception interface to perform the cryptographic operation to obtain the corresponding authentication vector.
[0081] It should be noted that, in the case of waiting for access, the edge authentication interface has only one interface type (i.e., secondary interface). For any edge authentication interface, its upper interface chain has two interface types (i.e., primary interface and endogenous interface) for the external verification interface. The interface with the shortest message queue in its upper interface chain is selected as the main communication interface, that is, the main communication interface is dynamically selected. While ensuring the fastest response, it can also improve the flexibility and security of authentication and avoid single point failure.
[0082] In an optional embodiment, when the number of differences is not less than the first preset value, the interface with the longest sustainable sweet spot duration or the shortest message queue length under the current load is selected from the edge authentication interfaces corresponding to each external verification interface as the reception interface, and the corresponding external verification interface is used as the main communication interface.
[0083] It should be noted that, in the second access situation, the external verification interface has only one interface type (i.e., primary interface), and for any external verification interface, its lower interface chain has two interface types (i.e., endogenous interface and secondary interface) for the edge authentication interface. In its lower interface chain, the reception interface can be flexibly selected according to actual needs; for example, when the total number of endogenous interfaces and secondary interfaces is greater than 3×n1 times the number of primary interfaces, the interface with the longest sustainable sweet spot under the current load is used as the reception interface, otherwise the interface with the shortest message queue length is selected as the reception interface; wherein, n1≥1. The embodiment of the present invention can not only realize the intelligent scheduling and resource optimization of authentication computing power, but also improve the flexibility and security of authentication and avoid single point failure.
[0084] In an optional embodiment, the authentication vector is obtained by the following steps:
[0085] Generate a public key and a master key through the external verification interface;
[0086] The edge authentication interface obtains an initial parameter group based on the collected parameters and sends the initial parameter group to the external verification interface; wherein the initial parameter group includes: a primary communication interface identifier and an optimal service time of the edge authentication interface;
[0087] The external verification interface encrypts the information received in the initial parameter group according to the local optimal service time and the master key, obtains the corresponding verification response parameter group, and sends the verification response parameter group to the edge authentication interface;
[0088] The received verification response parameter group is encrypted through the edge authentication interface to obtain the authentication vector.
[0089] Furthermore, the authentication and identification of the edge authentication interface by the authentication and identification network element includes:
[0090] Requesting the interface identifiers of the communicating interfaces from the external verification interface and the edge authentication interface respectively through the authentication identification network element, and performing consistency comparison;
[0091] If the comparison results are consistent, it indicates that the edge authentication interface authentication has failed;
[0092] If the comparison results are inconsistent, verifying the authentication vector of the edge authentication interface through the authentication identification network element;
[0093] If the verification fails, it indicates that the edge authentication interface authentication has failed;
[0094] If the verification is successful, it indicates that the edge authentication interface authentication is passed.
[0095] For example, Figure 4 FIG. 1 is a flow chart of an embodiment of obtaining and identifying an authentication vector provided by the present invention. Figure 4 External verification interface B in j and edge authentication interface Y i It is a set of corresponding interactive interfaces. By performing authentication-related cryptographic operations, the corresponding authentication vector is obtained. The specific steps are as follows:
[0096] Step 2.1: External verification interface B j First, select two arbitrarily large prime numbers A and L (satisfying A≡L≡3(mod4)), and calculate the private key M=(A,L) and the public key P pub =A×L, and by selecting a random number S j As external verification interface B j The master key.
[0097] Step 2.2: Edge Authentication Interface Y i Enter the main communication interface ID currently collected (recorded as I i ), take over the password R i and edge authentication interface Y i The number of sweet spots on the server b i , and arbitrarily select a random number α, and calculate the intermediate parameters W and P through the one-way hash function h(·); then the generated W and P are calculated as follows:
[0098] Among them, || represents data splicing.
[0099] It is worth noting that the sweet spot refers to the area where the server achieves the best balance in terms of performance, cost and efficiency; the more sweet spots there are, the stronger the interface capabilities under the server are, and the more reliable the certification results are.
[0100] In the case of waiting for access, since the primary interface and the endogenous interface have been merged in the same dimension and used as the external verification interface, the main communication interface ID may be the primary interface ID or the endogenous interface ID. iThe interface with the shortest message queue length among the corresponding external verification interfaces is used as the main communication interface. Obviously, in the second access situation, since the external verification interface has only one interface type (i.e., the nascent interface), the edge authentication interface Y is directly used. i The corresponding nascent interface serves as the main communication interface.
[0101] Step 2.3: Edge Authentication Interface Y i Will I i and the best service time t2 are sent to the external verification interface B j , that is, edge authentication interface Y i The initial parameter group {I i ,W,P,t2} is transmitted to the external verification interface B j .
[0102] Step 2.4: External Verification Interface B j Received the initial parameter set {I i ,W,P,t2}, use the master key S j And the symmetric encryption algorithm calculates the ciphertext vector u j , and generate the verification dual interface standard comparison time T1 and T2 at the same time; the specific calculation formula is as follows:
[0103] in, For S j Symmetric encryption algorithm under the action of.
[0104] At the same time, according to the personalized service time periods (t1, t2) of different interfaces, T1 and T2 are calculated:
[0105] Among them, h k (x) means iterative hashing of data x k times.
[0106] It is worth noting that t1 and t2 in the service time period represent the edge authentication interface Y i and external verification interface B j The standardized service time (optimal service time) corresponds to the service sweet spot, which can improve its processing speed without affecting the overall processing capacity of the system due to secure access.
[0107] Step 2.5: External Verification Interface B j Verify the response parameter group {P pub ,u j ,t1,t2,T1,T2} is sent to the edge authentication interface Y i .
[0108] Step 2.6: Edge Authentication Interface Y i Received verification response parameter group {Ppub ,u j ,t1,t2,T1,T2}, and then calculate the authentication vector F and key exchange parameter γ through the one-way hash function and XOR function respectively. j , the calculation formula is as follows:
[0109] in, Indicates the amount of splicing of time data.
[0110] Step 2.7: Edge Authentication Interface Y i Set the authentication credentials parameter group { j ,P pub ,t1,t2,T1,T2} are stored in their own server, and {α,F} is sent to the authentication and identification network element (i.e., PCF network element and EAS).
[0111] Step 2.8: When the authentication and identification network element (PCF interface, EAS interface) receives {α, F}, the authentication and identification network element obtains the takeover password R through reverse hash analysis. i .
[0112] It is worth noting that the authentication and identification network element in the first access situation is the PCF network element; the authentication and identification network element in the second access situation is the EAS.
[0113] Step 2.9: Authentication and identification network element to the external verification interface B j and edge authentication interface Y i Synchronously request the ID of the interface being communicated and perform consistency comparison, such as authentication interface Y from the edge i Request the main communication interface ID and verify the interface B j Ask for the reception interface ID; if the comparison result is inconsistent, it indicates that the edge authentication interface Y i If the authentication fails, the access process needs to be terminated; if the comparison results are consistent, execute step 2.10, that is, according to the ID information after the comparison, the edge authentication interface Y i The authentication vector F is used for authentication and identification.
[0114] Step 2.10: Edge Authentication Interface Y i Send the locally stored authentication credential parameter group {γ j ,P pub ,t1,t2,T1,T2}, the authentication and identification network element also checks whether the parameters in the following equation are valid based on the information obtained in step 2.9:
[0115]
[0116] If not, it is considered that the edge authentication interface Yi and external verification interface B j There is a risk in any interface, edge authentication interface Y i Authentication failed, need to terminate external verification interface B j If the following process is established, it means that the edge authentication interface Y i If the authentication is successful, the subsequent authorization Token generation and sending will continue.
[0117] In an optional embodiment, after the authentication and identification network element authenticates and identifies the edge authentication interface, the method further includes:
[0118] When the authentication identification network element is the policy control function network element 14, the policy control function network element 14 generates an authorization token for the edge authentication interface that has passed the authentication and sends it to the edge application server 15. The authorization token is synchronized to the network data analysis function network element 12 through the edge application server 15, so that the authorization token is sent by the network data analysis function network element 12 to the edge authentication interface that has passed the authentication.
[0119] Furthermore, after the edge authentication interface is authenticated and identified by the authentication and identification network element, the method further includes:
[0120] When the authentication identification network element is the edge application server 15, the edge application server 15 generates an authorization token for the edge authentication interface that has passed the authentication and synchronizes it to the network data analysis function network element 12, and the authorization token is sent to the edge authentication interface that has passed the authentication through the network data analysis function network element 12.
[0121] It should be noted that if Figure 5 The figure is a flow chart of an embodiment of generating and sending authorization tokens provided by the present invention. Steps 3.1.1 to 3.5.1 correspond to the access situation 1, where the PCF network element generates the authorization token Q1-k. j , and then authorize Token Q1-k through the PCF interface j Send to the EAS interface, and synchronized to the NWDAF interface by the EAS interface; then, the NWDAF interface will authorize the Token Q1-k j Feedback is sent to the edge authentication interface so that it can use the authorization token to perform capability authorization expansion.
[0122] Steps 3.1.2 to 3.4.2 correspond to the second access scenario, where EAS generates the authorization token Q1-k. j , and then synchronized to the NWDAF interface by the EAS interface; then, the NWDAF interface will authorize the Token Q1-k jFeedback is sent to the edge authentication interface so that it can use the authorization token to perform capability authorization expansion.
[0123] It is worth noting that the authorization token Q1-k j Calculated by the following formula:
[0124]
[0125] Among them, t is the time of T1-T2, and a random number e and an integer z are randomly generated at the same time, and k is calculated through a one-way hash function. j :
[0126] Where n is the modulus.
[0127] The edge authentication interface that passes the authentication can use the authorization Token Q1-k generated above j Access the 5G-A intelligent platform.
[0128] See also Figure 6 , is a structural diagram of an embodiment of the edge intrinsic security extension access device provided by the present invention.
[0129] A third embodiment of the present invention provides an edge intrinsic security extension access device, including:
[0130] The first interface definition module 21 is configured to, when the difference between the endogenous interface to be accessed and the secondary interface is less than a first preset value, merge the endogenous interface and the secondary interface into an external verification interface, use the secondary interface as an edge authentication interface, and use the policy control function network element 14 as an authentication and identification network element;
[0131] A second interface definition module 22 is configured to, when the number of differences is not less than the first preset value, use the primary interface as an external verification interface, use the internal interface and the secondary interface as edge authentication interfaces, and use the edge application server 15 as an authentication and identification network element; wherein the external verification interface is configured to assist the edge authentication interface in completing authentication-related cryptographic operations, so that the edge authentication interface generates an authentication vector;
[0132] The authentication and identification module 23 is used to authenticate and identify the edge authentication interface through the authentication and identification network element.
[0133] It should be noted that the edge intrinsic security extended access device provided in the embodiment of the third aspect of the present invention can implement all the processes of the edge intrinsic security extended access method described in any embodiment of the second aspect above. The functions of each module and unit in the device and the technical effects achieved are respectively the same as the functions and technical effects achieved by the edge intrinsic security extended access method described in any embodiment of the second aspect above, and will not be repeated here.
[0134] An embodiment of the fourth aspect of the present invention provides a computer-readable storage medium, which includes a stored computer program; wherein, when the computer program is running, it controls the device where the computer-readable storage medium is located to execute the edge intrinsic security extended access method described in any embodiment of the second aspect above.
[0135] An embodiment of the fifth aspect of the present invention provides a computer program product, including a computer program, which, when executed by a processor, implements the edge intrinsic security extended access method described in any embodiment of the second aspect above.
[0136] See also Figure 7 , is a structural diagram of an embodiment of an electronic device provided by the present invention.
[0137] An embodiment of the sixth aspect of the present invention provides an electronic device, including a processor 31, a memory 32, and a computer program stored in the memory 32 and configured to be executed by the processor 31, wherein the processor 22 implements the edge intrinsic security extended access method described in any embodiment of the second aspect when executing the computer program.
[0138] The processor 31 can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. A general-purpose processor can be a microprocessor, or the processor 31 can be any conventional processor. The processor 31 is the control center of the electronic device, and uses various interfaces and lines to connect various parts of the electronic device.
[0139] The memory 32 mainly includes a program storage area and a data storage area. The program storage area can store an operating system, at least one application required for a function, and the data storage area can store related data. In addition, the memory 32 can be a high-speed random access memory or a non-volatile memory such as a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, or a flash card. Alternatively, the memory 32 can be other volatile solid-state memory devices.
[0140] It should be noted that the above electronic device may include, but is not limited to, a processor and a memory. Those skilled in the art will understand that Figure 7 The structural diagram shown is only an example of the structure of the above-mentioned electronic device and does not constitute a structural limitation of the above-mentioned electronic device. The above-mentioned electronic device may include more or fewer components than shown in the figure, or combine certain components, or different components.
[0141] The above is only a preferred embodiment of the present invention. It should be pointed out that for ordinary technicians in this technical field, several improvements and modifications can be made without departing from the technical principles of the present invention. These improvements and modifications should also be regarded as the scope of protection of the present invention.
Claims
1. A method for edge intrinsic security extension access, characterized in that: include: When the difference between the endogenous interface to be accessed and the secondary interface is less than a first preset value, merging the primary interface and the secondary interface into an external verification interface, using the secondary interface as an edge authentication interface, and using the policy control function network element as an authentication and identification network element; When the number of differences is not less than the first preset value, the primary interface is used as an external verification interface, the internal interface and the secondary interface are used as edge authentication interfaces, and the edge application server is used as an authentication and identification network element; wherein the external verification interface is used to assist the edge authentication interface in completing authentication-related cryptographic operations, so that the edge authentication interface generates an authentication vector; The edge authentication interface is authenticated and identified through the authentication and identification network element.
2. The edge endogenous security extension access method according to claim 1, characterized in that: After the edge authentication interface is authenticated and identified by the authentication and identification network element, the method further includes: When the authentication identification network element is the policy control function network element, the policy control function network element generates an authorization token for the edge authentication interface that has passed the authentication and sends it to the edge application server. The authorization token is synchronized to the network data analysis function network element through the edge application server, so that the authorization token is sent by the network data analysis function network element to the edge authentication interface that has passed the authentication.
3. The edge endogenous security extension access method according to claim 1, characterized in that: After the edge authentication interface is authenticated and identified by the authentication and identification network element, the method further includes: When the authentication identification network element is the edge application server, the edge application server generates an authorization token for the edge authentication interface that has passed the authentication and synchronizes it to the network data analysis function network element, and the authorization token is sent to the edge authentication interface that has passed the authentication through the network data analysis function network element.
4. The edge endogenous security extension access method according to claim 1, characterized in that: When the difference between the endogenous interface and the secondary interface to be connected is less than a first preset value, the interface with the shortest message queue length is selected from the external verification interface corresponding to each edge authentication interface as the main communication interface, and the corresponding edge authentication interface is used as the reception interface; wherein each of the main communication interfaces is used to interact with the corresponding reception interface to perform the cryptographic operation to obtain the corresponding authentication vector.
5. The edge endogenous security extension access method according to claim 1, characterized in that: When the number of differences is not less than the first preset value, from the edge authentication interfaces corresponding to each external verification interface, the interface with the longest sustainable sweet spot duration or the shortest message queue length under the current load is selected as the reception interface, and the corresponding external verification interface is used as the main communication interface.
6. The edge endogenous security extension access method according to claim 1, characterized in that: The authentication vector is obtained by the following steps: Generate a public key and a master key through the external verification interface; The edge authentication interface obtains an initial parameter group based on the collected parameters and sends the initial parameter group to the external verification interface; wherein the initial parameter group includes: a primary communication interface identifier and an optimal service time of the edge authentication interface; The external verification interface encrypts the information received in the initial parameter group according to the local optimal service time and the master key, obtains the corresponding verification response parameter group, and sends the verification response parameter group to the edge authentication interface; The received verification response parameter group is encrypted through the edge authentication interface to obtain the authentication vector.
7. The edge endogenous security extension access method according to claim 1, characterized in that: The authentication and identification of the edge authentication interface by the authentication and identification network element includes: Requesting the interface identifiers of the communicating interfaces from the external verification interface and the edge authentication interface respectively through the authentication identification network element, and performing consistency comparison; If the comparison results are consistent, it indicates that the edge authentication interface authentication has failed; If the comparison results are inconsistent, verifying the authentication vector of the edge authentication interface through the authentication identification network element; If the verification fails, it indicates that the edge authentication interface authentication has failed; If the verification is successful, it indicates that the edge authentication interface authentication is passed.
8. An edge endogenous security extension access system, characterized in that: include: A request access interface, configured to extract a capability requirement from a received access capability extension request and forward the capability requirement to a network data analysis function network element; The network data analysis function network element is configured to initiate an interface access registration request to the network storage function network element according to the tracking area list and the received capability requirement; The network storage function network element is configured to respond to the received interface access registration request, activate the protocol data unit session of the subscriber, and feed back the user subscription information to the policy control function network element; The policy control function network element is configured to, after receiving the user contract information, initiate a service quality analysis subscription request to the network data analysis function network element; wherein the service quality analysis subscription request is used to instruct the policy control function network element and the edge application server to collaboratively analyze the quantitative relationship between the intrinsic interface and the secondary interface under the capacity demand; an edge application server, configured to collaborate with the policy control function network element to analyze the quantity relationship; The policy control function network element is further configured to serve as an authentication and identification network element when the quantity relationship is that the difference between the intrinsic interface and the secondary interface is less than a first preset value; The edge application server is further configured to serve as an authentication and identification network element when the difference amount is not less than the first preset value.
9. An edge endogenous security extension access device, characterized in that: include: A first interface definition module is configured to, when the difference between the endogenous interface to be accessed and the secondary interface is less than a first preset value, merge the endogenous interface and the secondary interface into an external verification interface, use the secondary interface as an edge authentication interface, and use the policy control function network element as an authentication and identification network element; a second interface definition module configured to, when the number of differences is not less than the first preset value, use the primary interface as an external verification interface, use the internal interface and the secondary interface as edge authentication interfaces, and use the edge application server as an authentication and identification network element; wherein the external verification interface is configured to assist the edge authentication interface in completing authentication-related cryptographic operations, so that the edge authentication interface generates an authentication vector; The authentication and identification module is used to authenticate and identify the edge authentication interface through the authentication and identification network element.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium includes a stored computer program; wherein, when the computer program is run, it controls the device where the computer-readable storage medium is located to execute the edge intrinsic security extended access method according to any one of claims 1 to 7.
11. A computer program product, characterized in that The method comprises a computer program, which, when executed by a processor, implements the edge intrinsic security extended access method according to any one of claims 1 to 7.
12. An electronic device, characterized in that: The system comprises a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor implements the edge intrinsic security extended access method according to any one of claims 1 to 7 when executing the computer program.