IPv6 address management method and computer equipment

By generating encrypted network and address identifiers and combining them with device attributes and operating status information, the security management and control issues of financial-grade IoT devices are resolved, highly secure and reliable IPv6 address management is achieved, and the device identity traceability capability and fault response efficiency are improved.

CN120768657APending Publication Date: 2025-10-10AGRICULTURAL BANK OF CHINA
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202511067090.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-07-31
Publication Date
2025-10-10

AI Technical Summary

Technical Problem

The existing IPv6 address allocation scheme is difficult to meet the high security, high reliability and high efficiency management and control requirements in financial-grade IoT devices, and the pain points of device identity traceability and security management have not been effectively resolved.

Method used

By obtaining the device attribute information and operating status information of the IoT device, an encrypted network identifier and address identifier are generated, and the IPv6 address of the device is generated by combining the IPv6 address prefix. The encrypted identifier is dynamically updated to improve security, and operation and maintenance operations are driven by health scores.

Benefits of technology

It enhances the credibility of device identity, improves attack defense capabilities, ensures the non-tamperability of device identity and the reliability of addresses, meets the high-security and high-reliability management and control requirements of financial-grade IoT scenarios, and achieves efficient fault response.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120768657A_ABST
    Figure CN120768657A_ABST
Patent Text Reader

Abstract

The invention provides an IPv6 address management method and computer equipment, and the method comprises the steps: obtaining equipment information of first Internet of Things equipment requesting to access a target network, namely, current equipment operation state information and equipment attribute information; encrypting and generating a network identifier for the first Internet of Things equipment based on the equipment attribute information; based on the network identifier, the equipment operation state information and a first equipment identifier of the first Internet of Things equipment, encrypting to generate an address identifier of the first Internet of Things equipment; and on the basis of the address identifier and the IPv6 address prefix, generating the IPv6 address of the first Internet of Things equipment accessing the target network, thereby solving the problems of untrusted equipment identity, difficulty in tracing address abuse and the like in a traditional scheme, and providing high-security and high-reliability management and control requirements for a financial-level Internet of Things scene.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of communication technology, and in particular to an IPv6 address management method and computer equipment. Background Art

[0002] As the digital transformation of banking business accelerates, the scale of IoT terminals such as ATMs, smart counters, and vault security equipment continues to expand. The IPv6 (Internet Protocol Version 6) protocol has gradually replaced the traditional IPv4 (Internet of Things Protocol Version 4) protocol to become the mainstream protocol for bank-first IoT device communications. The IPv6 protocol utilizes the huge address space to provide unique network identification for massive devices to meet the communication needs of financial-level scenarios.

[0003] However, the first publicly available IPv6 address allocation solutions for IoT devices, such as SLAAC (Stateless Address Autoconfiguration) or DHCPv6 (Dynamic Host Configuration Protocol for IPv6), although they alleviate the problem of IPv4 address resource exhaustion, do not solve the pain points of device identity traceability and security management, and are unable to reliably meet the high-security, high-reliability, and high-efficiency management and control requirements in financial scenarios. Summary of the Invention

[0004] In view of the above problems, this application provides the following technical solutions:

[0005] A first aspect of the present application provides an IPv6 address management method, the method comprising:

[0006] Obtaining device information of a first IoT device requesting access to a target network; the device information includes current device operating status information and device attribute information;

[0007] Encrypt and generate a network identifier for the first IoT device based on the device attribute information;

[0008] Encrypting and generating an address identifier of the first Internet of Things device based on the network identifier, the device operating status information, and the first device identification of the first Internet of Things device; the encrypted identifier can be dynamically updated and stored;

[0009] Based on the address identifier and the IPv6 address prefix, an IPv6 address for the first Internet of Things device to access the target network is generated.

[0010] A second aspect of the present application provides an IPv6 address management system, the system comprising: a target network management device, a service authentication device, a source address verification device, and an IPv6 address management device, wherein:

[0011] The target network management device is configured to connect to the service authentication device and the source address verification device, respectively, respond to a target network access request from an IoT device, verify the IoT device is legitimate via the service authentication device, determine device information of the IoT device and store it, and transmit the device information to the IPv6 address management device via the source address verification device; the device information includes current device operating status information and device attribute information;

[0012] The IPv6 address management device is used to connect to the source address verification device, execute multiple computer instructions, and implement the various steps of an IPv6 address management method provided in the first aspect of this application.

[0013] It can be seen that the present application proposes an IPv6 address management method and computer device, which obtains the device information of the first Internet of Things device requesting access to the target network, namely the current device operating status information and device attribute information; based on the device attribute information, encrypts and generates a network identifier for the first Internet of Things device; based on the network identifier, the device operating status information and the first device identification of the first Internet of Things device, encrypts and generates an address identifier for the first Internet of Things device; based on the address identifier and the IPv6 address prefix, generates an IPv6 address for the first Internet of Things device to access the target network, thereby solving the problems of untrustworthy device identity and difficult to trace address abuse in traditional solutions, and providing high-security and high-reliability management and control requirements for financial-grade Internet of Things scenarios. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] The above and other features, advantages, and aspects of the various embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and that the originals and elements are not necessarily drawn to scale.

[0015] Figure 1 A flowchart of an IPv6 address management method provided in Example 1 of the present application;

[0016] Figure 2 A flowchart of an IPv6 address management method provided in Example 2 of the present application;

[0017] Figure 3 An example of generating a NID in an IPv6 address management method provided in an embodiment of the present application;

[0018] Figure 4 A flowchart of an IPv6 address management method provided in Example 3 of the present application;

[0019] Figure 5 An AID generation instance in an IPv6 address management method provided in an embodiment of the present application;

[0020] Figure 6 A flowchart of an IPv6 address management method provided in Example 4 of the present application;

[0021] Figure 7 A flowchart of an IPv6 address management method provided in Example 5 of the present application;

[0022] Figure 8 An example of address tracing in an IPv6 address management method provided in an embodiment of the present application;

[0023] Figure 9 A schematic diagram of the structure of an IPv6 address management device provided in an embodiment of the present application;

[0024] Figure 10 A schematic diagram of the structure of an optional embodiment of the IPv6 address management system proposed in the embodiment of the present application;

[0025] Figure 11 A schematic diagram of the address generation process in the IPv6 address management method proposed in an embodiment of the present application;

[0026] Figure 12 A schematic diagram of the address tracing process in the IPv6 address management method proposed in the embodiment of the present application. DETAILED DESCRIPTION

[0027] The embodiments of the present application are described below in conjunction with the drawings in the embodiments of the present application. The terms used in the implementation section of this application are only used to explain the specific embodiments of the present application and are not intended to limit this application. The embodiments of the present application are described below in conjunction with the drawings. It is known to those skilled in the art that with the development of technology and the emergence of new scenarios, the technical solutions provided in the embodiments of the present application are also applicable to similar technical problems.

[0028] The terms "first", "second" etc. in the context of the present application and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a specific order or sequential order. It should be understood that the terms used in this way can be interchangeable under appropriate circumstances, and this is merely a way of distinguishing the objects of the same attributes when describing them in the embodiments of the present application. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, so that the process, method, system, product or equipment comprising a series of units need not be limited to those units, but may include other units that are not clearly listed or inherent to these processes, methods, products or equipment.

[0029] It is understandable that before using the technical solutions disclosed in the embodiments of this application, the data involved in the implementation of the technical solutions proposed in this application (including but not limited to the data itself, the acquisition and use of the data) must comply with the requirements of relevant laws, regulations and relevant provisions.

[0030] Regarding the description in the background technology section, the current process of allocating IPv6 (Internet Protocol Version 6) addresses to first IoT devices in financial scenarios only binds the device's logical ID (such as the user ID) to the IP address. This lacks a deep association with device attributes (such as the MAC address (Media Access Control Address), geographic location, software configuration, etc.), resulting in weak device identity binding. This makes it easy for attackers to forge MAC addresses to attack first IoT devices, leading to serious consequences such as user privacy leaks and network service interruptions, and hindering device identity tracing. Furthermore, current IPv6 address allocation does not take into account the operating status of IoT devices, such as timestamps, heartbeat cycles, or hardware health scores. This results in the generated IPv6 addresses being out of sync with the actual device status and failing to meet the response speed requirements of relevant regulations.

[0031] In order to solve the above problems, the embodiment of the present application provides an IPv6 address management method. The IPv6 address management method of the embodiment of the present application will be described in detail below with reference to the accompanying drawings.

[0032] Reference Figure 1 , is a flow chart of an IPv6 address management method provided in Example 1 of the present application. This embodiment can be applied to computer devices, such as one or more physical servers, or cloud servers that support cloud computing, such as Figure 1 As shown, the IPv6 address management method provided in this embodiment may include but is not limited to the following steps:

[0033] Step S11: obtaining device information of a first IoT device requesting access to a target network; the device information includes current device operating status information and device attribute information;

[0034] In the embodiment of the present application, the target network can be a 5G private 5G network (abbreviated as 5G private network), which is a local area network technology that will use 5G technology to create a private network with unified connectivity, optimized services, and secure communication within a specific area. The 5G private network provides enterprises with the freedom to customize their networks and can provide dedicated communication connections for people or things in a specific enterprise. It is independently operated and used exclusively. This application does not elaborate on the network structure and working principle of the 5G private network.

[0035] It should be understood that when any IoT device in a financial scenario (such as an ATM, smart counter or other IoT device, which can be recorded as the first IoT device) requests access to the 5G private network (target network) to implement corresponding services, after completing the network registration, an IPv6 address needs to be allocated to the first IoT device. In this process, this application proposes to deeply integrate device attribute information and current device operation status information to improve the ability to resist continuous penetration attacks and meet the high security management and control requirements in banking scenarios.

[0036] Therefore, this application can first obtain device attribute information (i.e., multiple device hardware feature codes) and device operating status information during the IPv6 address generation process. The device operating status information can represent the health status of the corresponding IoT device, etc. This application does not limit the content of the device information and its acquisition method.

[0037] Step S12: Encrypt and generate a network identifier for the first IoT device based on the device attribute information;

[0038] The device attribute information in this application may include multi-dimensional device attributes, such as MAC address, geographic location (physical address), software configuration, etc., to represent the device identity of the IoT device by using the uniqueness of the device attributes in each dimension. Afterwards, these device attributes are deeply associated with the generated IPV6 address to divide the IPv6 address generation process into the NID (Network Identifier) ​​and AID (Address Identifier, i.e., the interface identifier part of the last 64 bits in the IPv6 address) generation process, that is, the NID is generated first and then the AID is generated.

[0039] Thus, during the NID generation process, this application proposes associating multi-dimensional device attribute information so that the resulting IPv6 address can be globally associated with the device hardware information, generating an IPv6 address that is a trusted device identity. This application does not limit the detailed implementation of how to cryptographically generate the network identifier (NID) of an IoT device based on its device attribute information.

[0040] Step S13: Encrypt and generate an address identifier of the first IoT device based on the network identifier, the device operation status information, and the first device identifier of the first IoT device; the encrypted identifier can be dynamically updated and stored;

[0041] In the process of generating the AID of the first IoT device by combining NID, after achieving deep integration with the device attribute information through the NID generation method, the encrypted identifier can be dynamically updated at short time intervals, thereby improving the attack resistance of the generated IPv6 address. For example, by updating the encrypted identifier every hour, the attack window period is shortened from 24 hours in the traditional solution to 1 hour, and the reverse engineering cost of the encrypted identifier is increased to 2 128 The success rate of resisting MAC cloning attacks (that is, attackers disguise MAC addresses to attack) has been greatly improved, which has improved security.

[0042] Moreover, in the process of generating the AID, this application will also combine the current device operating status information and determine the real-time health status of the first IoT device, such as the health score, through real-time state perception, so that in the case of a low health score, corresponding operation and maintenance measures can be taken in a timely manner to ensure the reliability of network communication. This application does not limit the implementation method of device operating status information obtained periodically or in real time, and different appropriate methods can be used for different status contents.

[0043] To further improve security, in the above-mentioned NID and AID generation process, after determining the required input data for each, a suitable encryption algorithm can be used to ensure that the corresponding generated network identifier NID and address identifier AID are both ciphertext. This application does not limit the type of encryption algorithm and how to implement the NID and AID respectively, which can be determined as appropriate.

[0044] Step S14: Based on the address identifier and the IPv6 address prefix, generate an IPv6 address for the first IoT device to access the target network.

[0045] Following the above analysis, after determining the address identifier AID of the current first IoT device, the generated AID, which is the last 64 bits of the IPv6 address, can be concatenated with the IPv6 address prefix in accordance with the network communication protocol requirements of the target network, to ensure that the generated global IPv6 address can meet the secure and reliable access requirements of the first IoT device to the target network and fulfill the communication needs of banking services. For example, if the target network is a 5G private network, the generated AID is concatenated with the standardized network prefix 2001:250:4000:4500:: / 64 to generate a global IPv6 address that complies with RFC 4291. It should be understood that for other target networks, such as 6G private networks, step S14 can be implemented in accordance with the corresponding network access specifications, and this application does not impose any restrictions on this.

[0046] In summary, in the scenario where any IoT device requests to access the target network, in the process of allocating the IPv6 address required for network access, this application deeply binds the device attribute information of the IoT device and encrypts and generates a unique network identifier NID. The device attribute information and the network identity are tamper-proof and bound, so that the attacker needs to forge each identifier contained in the device attribute information at the same time, which significantly increases the complexity of the device identity cloning attack and improves the credibility of the device identity. Moreover, after combining the dynamic encryption identifier management and the device operation status, the suffix of the IPv6 address, namely AID, is generated through collaborative encryption, so that the attack defense of the IPv6 address generated by splicing it with the IPv6 prefix is ​​strengthened, which can meet the high security and high reliability management and control requirements in financial scenarios.

[0047] Reference Figure 2 , is a flow chart of an IPv6 address management method provided in Example 2 of this application. This embodiment can provide a detailed description of the encryption generation process of the NID, such as Figure 2 As shown, when the obtained device attribute information of the first IoT device includes: a hardware identifier (such as a MAC address), a geographic location (such as geographic coordinates or geographic bits obtained by encoding), a software configuration (such as a firmware version or firmware bits obtained by encoding), and a device type identifier (such as a pre-configured or encoded flag indicating the device type of the first IoT device), the cryptographic NID generation method provided in this embodiment may include but is not limited to the following steps:

[0048] Step S21, performing a national secret hash calculation on the hardware identifier of the first IoT device to determine the device bit for the first IoT device;

[0049] In the embodiment of the present application, the hardware identifier is a MAC address as an example for explanation. The MAC address of the first IoT device can be one-way encrypted based on the national secret SM3 hash algorithm to generate a 32-bit collision-resistant hash value, such as Figure 3In the NID generation example shown, if the MAC address is 00:23:D4:A8:B1:C2, a national secret hash calculation is performed on it to obtain a 32-bit collision-resistant hash value, such as EAB5735EE362090DF8609E67955FDF95FC6AD7C05256D2F1C4F45D2D9F6276FB. The hash value of the first 18 bits or the converted binary number is intercepted and determined as the device bit of the first IoT device to ensure the uniqueness of the device bit.

[0050] The National Security SM3 hash algorithm uses a cryptographic hash function standard, primarily used for signature and verification, message authentication code generation and verification, and random number generation. Its security and efficiency are comparable to the SHA-256 algorithm. This application does not detail the operational principles of this encryption algorithm. It should be understood that this application may also use other encryption algorithms to implement step S21, and is not limited to this National Security Hash Algorithm.

[0051] Afterwards, the present application can fuse the geographic location, software configuration, device type identifier, and the device bit of the first IoT device to obtain a network identifier (NID) for the first IoT device, thereby achieving close integration with multi-dimensional device attributes and increasing the difficulty of device cloning. The present application does not limit the implementation method of this fusion, including but not limited to the optional implementation method described in the following steps.

[0052] Step S22: Determine a firmware bit obtained by encoding the firmware version information of the first IoT device, a geographic bit obtained by encoding the geographic coordinates of the first IoT device, and a flag bit configured corresponding to the device type of the first IoT device;

[0053] In an embodiment of the present application, a structured coding method can be used, such as at least one of binary coding suitable for high-performance transmission and storage, hash coding with fixed-length output, and network protocol coding that meets the structural requirements of the target network communication protocol, to encode each dimension of information in the device attribute information to obtain corresponding bits of a preset length, which may include but are not limited to: a 4-bit flag bit representing the device type (such as 0101 corresponding to an ATM machine); a firmware bit (4 bits) identifying the software version (such as V3.0.1 encoded as 0110), compressing the longitude and latitude of the geographic coordinates to geographic bits (8 bits) with cabinet-level accuracy, and using an 8-bit geographic coding algorithm such as GeoHash to compress the longitude and latitude of the device into a reversible string (such as ws8gv92), with a positioning accuracy of 3 meters, such as 01100111 01111011 corresponding to a 3-meter error grid coordinate), etc.

[0054] Step S23, based on the cyclic redundancy check rule, performing conflict detection on the flag bit, firmware bit, geographic bit and device bit to obtain corresponding detection results;

[0055] Step S24: Perform offset processing on the repeated bits indicated by the detection result through a secondary detection method to obtain a network identifier of the first length for the first IoT device.

[0056] Following the above analysis, the present application can splice and fuse the flag bit, firmware bit, geographic bit, and device bit of the first IoT device to generate the network identifier NID of the first IoT device. In order to improve the reliability of the NID, a cyclic redundancy check (CRC-8) mechanism can be used to detect conflicts. If duplicate identifiers occur (i.e., duplicate bits exist), the offset sequence (1², 2², …, k²) can be dynamically adjusted using a secondary detection method to ultimately synthesize a network identifier of the first length, such as a 40-bit NID (e.g., a 4-bit device type code + a 37-bit hash truncation), which is encoded as shown in the attached figure. Figure 3 56677eef15 shown, etc. This ensures that the device attribute information is uniquely bound to the network identity, improving the credibility of the network device.

[0057] Reference Figure 4 , is a flow chart of an IPv6 address management method provided in Example 3 of the present application. This embodiment can provide a detailed description of the encryption generation process of the AID, such as Figure 4 As shown, based on the NID encryption generation method described above, the following steps can be performed but are not limited to:

[0058] Step S41, determining a currently generated encrypted identifier for the first IoT device; the encrypted identifier conforms to a globally unique temporary identifier structure of the target network;

[0059] In this embodiment of the present application, a globally unique temporary identifier (GUTI) can serve as a key mechanism for protecting user privacy in target networks (such as 5G private networks). It can replace permanent identification and reduce the exposure of sensitive information within the network. When a first IoT device requests access to a target device, a GUTI is dynamically generated as an encrypted identifier for the first IoT device, using methods such as hashing, encryption, or random generation, based on the GUTI structure required by the target network. The GUTI is then periodically updated to improve security.

[0060] In some embodiments, during the GUTI generation process, information such as a timestamp or serial number can also be combined to improve the anti-replay attack capability of the GUTI and the IPv6 address generated in combination with the GUTI. Cross-network compatibility can also be achieved by processing the byte order when processing network mapping. Optionally, this application can update the GUTI when the target AMF is switched, or activate the GUTI update process in NAS encryption or security mode to generate a new GUTI and update the associated stored IPv6 address. This application does not limit the GUTI update implementation method.

[0061] Preferably, this application can implement blockchain-based associated storage of encrypted identifiers and timestamps. Specifically, this application can use a mapping table to record the encrypted identifier and timestamp (i.e., the timestamp when the encrypted identifier was generated) and store this mapping table on the blockchain for evidence storage, thereby enabling tamper-proof auditing and resisting reverse engineering attacks. However, this recording method is not limited to this. Furthermore, since the encrypted identifier can be dynamically updated at a first time interval (e.g., one hour), and this first time interval is less than a first time threshold to better resist attacks, this application does not impose a limit on the first time threshold, which can be determined based on business scenario requirements. Each time the encrypted identifier is updated, it can be synchronously updated to the blockchain for storage, allowing subsequent access and address tracing.

[0062] Step S42: Encrypt and generate a ciphertext address identifier for the first IoT device based on the network identifier, the device operating status information, the encryption identifier, and the device number;

[0063] Among them, the device operation status information includes at least the current timestamp and heartbeat signal (heartbeat cycle, which can be based on the count of the heartbeat counter) and other contents. Based on the pre-configured encryption algorithm, the above-mentioned generated network identifier NID, the dynamically generated encryption identifier GUTI, the device number (unique) and the current timestamp, heartbeat signal and other device operation status information can be fused and encrypted to generate an encrypted ciphertext block, namely the address identifier ciphertext for the first Internet of Things device (also called the pre-encrypted address identifier preAID). This application does not limit the encryption generation method of step S42.

[0064] It should be noted that the device operating status information used in the encryption generation process of step S42 can be simply the current timestamp (e.g., the accumulated seconds since the IoT device was started) or a heartbeat signal (in this case, the timestamp can be represented by a heartbeat counter, such as the accumulated heartbeat count with 15-second increments; this can also be used to determine the health status of the first IoT device. The implementation process can refer to the description of the corresponding section of the embodiment below). If needed, a health score generated based on the device operating status information (indicating the health status of the first IoT device) can also be introduced to embed the real-time health status of the IoT device in the generated IPv6 address, thereby improving attack resistance. This application does not restrict the content of the device operating status information used to generate the address identifier ciphertext.

[0065] In some embodiments, in the process of generating the address identifier ciphertext, at least one of the device operation status information such as the timestamp and the heartbeat signal can be used for implementation. This application only uses the optional implementation method of generating the address identifier ciphertext preAID by combining the device operation status information such as the timestamp as an example. Figure 5 The AID generation example shown in the figure can use a timestamp (which can be a hexadecimal compressed value, such as 11c92, etc., or a binary compressed value, etc., and this application does not limit the representation of the timestamp), a network identifier (NID, such as Figure 3 The generated 56677eef15 in the example) and the device number (which can be determined by a suitable encoding method based on actual encoding requirements, such as 0000 / 0000x, to ensure that each IoT device has a unique device number) are used to generate the third-length intermediate code through bit-aligned padding, such as Figure 5 The 20-byte intermediate code 56677eef151511c920 in the middle can be used for subsequent hashing or encryption processing.

[0066] Optionally, the filling rules of the bit-aligned filling method of the present application can be length alignment, that is, when the length of each input is less than 20 bytes, it is padded to 20 bytes according to specific rules; or it can be based on data integrity filling, that is, the filled encoding needs to retain the uniqueness of the original information and avoid introducing conflicts. The implementation method is not described in detail in this application.

[0067] Afterwards, the intermediate code and the encrypted identifier can be symmetrically encrypted to obtain the address identifier ciphertext for the first IoT device. Figure 5As shown, the application can encrypt the above generated intermediate code (such as "56677eef151511c920") by using the dynamically generated encryption identifier (such as 4a363479e84797efd1f6a541398d5bac, which can be generated based on an hourly rotation strategy) as an encryption key (i.e. an IDEA key) through the IDEA (International Data Encryption Algorithm) symmetric encryption algorithm, to generate an encrypted ciphertext block, i.e. an address identifier ciphertext preAID, such as 7A428282A7D28502. However, it is not limited to the symmetric encryption method described in the application, and the IDEA algorithm with higher attack resistance is preferred.

[0068] In step S43, the device running state information is subjected to a hash operation, and a time confusion hash value of a second length is extracted from the obtained hash value.

[0069] In step S44, the address identifier ciphertext and the time confusion hash value are subjected to an XOR operation to obtain the address identifier of the first Internet of Things device.

[0070] In order to improve the anti-reverse cracking capability, the application proposes to obtain a time confusion hash value TimeHash through a hash algorithm with cryptographic properties such as collision resistance, irreversibility, and avalanche effect. Optionally, as shown, the timestamp in the device running state information can be subjected to a hash operation based on the SHA3 (Secure Hash Algorithm 3)-256 hash algorithm, and the first 16 bits of the obtained hash value are extracted to generate the time confusion hash value TimeHash, such as ff61c612015437731b in Figure 5 Figure 5

[0071] Then, the confusion value (such as e499964b470f68e4 in Figure 5 ) obtained through the XOR operation (preAID ⊕ TimeHash) can be used as the address identifier AID of the first Internet of Things device. In the bank scenario of the target network of the 5G private network, it can be concatenated with the standardized network prefix asPrefix: 2001:250:4000:4500:: / 64 (which can be updated according to the changes of network communication protocols, and the application only takes this as an example for description) to generate a global IPv6 address 2001:250:4000:4500:e499:964b:470f:68e4 that meets the RFC 4291 specification, which meets the needs of the first Internet of Things device to access the 5G private network for bank business processing.

[0072] As can be seen, the application can generate the address identifier AID of the first Internet of Things device in the target network of the 5G private network according to the following formula: Figure 5 ​​The AID is generated in the illustrated manner, and then spliced with the IPv6 address prefix to generate the IPv6 address, which can be periodically updated as the encryption identifier is updated, improving security. And because the timestamp or the heartbeat signal of the heartbeat counter or the double timestamp composed of the two kinds of information is introduced in the generation process, the old hash value is invalidated, and the purpose of resisting replay attacks is achieved. For example, the time confusion hash value generation method makes the same input data generate different hashes at different times, which can prevent behavior analysis, prevent data association, and avoid tracking Internet of Things devices or their users through hash values by updating at regular intervals, achieving privacy protection

[0073] Reference Figure 6 For the flowchart of the IPv6 address management method provided in Embodiment Four of the present application, on the basis of the IPv6 address management method described in the above embodiments, the present application can also drive the operation and maintenance module with the health degree, monitor the health status of the Internet of Things device (which can be represented by the health degree score), and automatically trigger appropriate operation and maintenance operations for the Internet of Things device with a low health degree score, thereby improving the fault response efficiency. Based on this, as shown in the figure, Figure 6 The IPv6 address management method provided by the present application can include but is not limited to the following steps:

[0074] Step S61, input the device running state information into the health degree evaluation model, determine at least one state index and the index abnormal threshold value, and obtain the health degree score of the first Internet of Things device;

[0075] Step S62, in response to the health degree score meeting the operation and maintenance condition, performing the corresponding operation and maintenance operation;

[0076] Step S63, in response to the health degree score meeting the network optimization condition, adjusting the priority of the corresponding network slice; wherein the core transaction business occupies one network slice, and multiple non-core transaction businesses share one network slice.

[0077] In the present application, the health degree evaluation model can be pre-trained for bank Internet of Things devices to predict and fuse dynamic threshold values and multi-dimensional data (i.e., multiple device running state information), realize real-time quantitative evaluation and automatic operation and maintenance response of device running state, and the present application does not limit the construction and training method of the health degree evaluation model. Optionally, the health degree evaluation model can be based on the index abnormal threshold value (or the predicted normal interval of the state index) predicted by at least one of the heartbeat delay rate, the port abnormal frequency, and the traffic fluctuation rate, determine the health degree score of the current first Internet of Things device to represent the current health status of the first Internet of Things device, and subsequently determine whether the operation and maintenance condition is met, such as the health degree score being less than a certain threshold value, which will automatically trigger the execution of the corresponding operation and maintenance operation.

[0078] In one possible implementation, the prediction process of the above-mentioned indicator abnormality threshold (or status indicator normal range) can be based on a pre-trained LSTM (Long Short-Term Memory) model to process the device operation status information collected in real time, predict the normal range of the corresponding status indicator, and thus obtain the indicator abnormality threshold of the corresponding status indicator. When the currently calculated status indicator exceeds the corresponding indicator abnormality threshold, it indicates that the first IoT device is operating abnormally, that is, unhealthy. Corresponding operation and maintenance operations can be performed to promptly resolve the abnormality and ensure the normal execution of banking business.

[0079] Based on the above analysis, this application can send the device operation status information collected in real time to the blockchain for recording, read the device operation status information input (each device operation status information can be processed into a model input format before input) health assessment model, and determine the three status indicators of the current first IoT device: heartbeat delay rate (such as sliding window mean / standard deviation, etc.), port abnormality frequency (such as the ratio of the number of abnormal ports per hour to the total number of ports), and traffic fluctuation rate (such as the traffic difference between the current traffic and the baseline traffic, and determine the ratio of the traffic difference to the baseline traffic). It can be seen that the device operation status information collected in real time by this application may include but is not limited to heartbeat signals, port operation status, traffic monitoring data, etc.

[0080] In one possible implementation, the health score of the first IoT device can be determined by using the heartbeat delay rate, port abnormality frequency, traffic fluctuation rate, and the weights of each indicator through a health assessment model according to the health scoring rules of the corresponding status indicators. Optionally, based on the health scoring rules, after calculating the health indicator score using the corresponding status indicators, the weighted sum of each health indicator score and indicator weight is performed, and the total score is determined as the health score of the first IoT device. For example, the health score can be calculated according to the rule of health score = 0.6×(1-heartbeat delay / threshold)+0.3×(1-port abnormality frequency)+0.1×(1-traffic fluctuation rate).

[0081] This health score can then be compared to the predicted device anomaly threshold (which can be multiple segmented thresholds). If the health score is less than a certain device anomaly threshold, an operational maintenance operation specific to that device anomaly threshold can be executed. Different operational maintenance operations can be configured for different device anomaly thresholds. The lower the device anomaly threshold, the more difficult the corresponding operational maintenance operation will be, indicating a higher number of IoT device failures. This application does not restrict the content of each operational maintenance operation. Optionally, this application can also update the address allocation log and encryption identifier recorded in the blockchain accordingly to improve security.

[0082] For example, if the health score is less than 0.4, the device IP address of the IoT device can be automatically isolated. If needed, a maintenance work order with a positioning accuracy of ≤3 meters (this can be determined based on geolocation encoding, but is not limited to this accuracy. This application only uses 8-bit GeoHash coordinates (with an accuracy of 3 meters) to implement health assessment as an example) can be generated. This work order can then be assigned to the appropriate operations and maintenance personnel, who will be notified to promptly resolve the corresponding IoT device fault, shortening the fault response time. If the health score is greater than 0.7, redundant monitoring resources can be dynamically released.

[0083] In one possible implementation, the present application may also execute a pre-configured corresponding operation and maintenance operation in response to at least one of the following status indicators: heartbeat delay rate, port abnormality frequency, and traffic fluctuation rate reaching a corresponding predicted indicator abnormality threshold. For example, if the ATM heartbeat delay baseline value is 150-220ms (a normal range for status indicators), and based on the heartbeat signal collected in real time from the ATM, it is determined that the ATM's current heartbeat delay rate exceeds the baseline but the deviation does not reach a threshold (e.g., ≤270ms), the ATM's health score is calculated using the linear formula (i.e., the health scoring rule for the heartbeat delay rate status indicator) 0.6 × (1-heartbeat delay / threshold). Based on a comparison of this health score with the device abnormality threshold, the corresponding operation and maintenance operation is executed.

[0084] Similarly, if a port abnormality is detected according to the above method (i.e., the port abnormality frequency reaches the corresponding indicator abnormality threshold, such as the packet loss rate within 30 minutes is greater than 15%) or a traffic mutation (i.e., the traffic fluctuation rate reaches the corresponding indicator abnormality threshold, such as the standard deviation is greater than 20%), a single zero-point penalty operation can be directly triggered. However, it is not limited to the operation and maintenance operation methods described in this embodiment, and the operation and maintenance operation methods can be dynamically configured or adjusted according to actual needs.

[0085] In some embodiments, in order to further improve operation and maintenance efficiency, the present application can also achieve end-to-end (IoT device) encrypted communication through the SRv6 tunnel of the 5G private network based on network slicing. During this communication process, the priority of the network slice can be adjusted by configuring the core transaction business (which can be determined based on the business needs of the banking scenario) to exclusively occupy a network slice, and multiple non-core transaction businesses to share a network slice. This process can also be combined with the health score of the IoT device (such as a health score greater than 0.8) to trigger the adjustment of the network slice priority, so as to optimize the 5G network architecture, reduce the communication delay of the core transaction business, that is, reduce the delay of the encrypted communication channel constructed by the core transaction business exclusively occupying the network slice (such as less than 10ms), and improve the UPF (User Plane Function) carrying efficiency.

[0086] As can be seen, this application divides target networks, such as 5G private networks, into network slices, enabling independent encrypted channels for core transaction services, such as SRv6 tunnels, and is compatible with MPLS evolution. It also records IPv6 address allocation logs and updates them to the blockchain via lightweight smart contracts, along with dynamically generated encrypted identifiers, significantly reducing the risk of tampering.

[0087] Reference Figure 7 , which is a flow chart of an IPv6 address management method provided in Example 5 of this application. Based on the IPv6 address generation method proposed in the above embodiment, this embodiment can describe the IPv6 address tracing process, such as Figure 7 As shown, the IPv6 address management method proposed in this embodiment may further include:

[0088] Step S71, in response to a request for tracing the address of the second IoT device, determining a source IPv6 address of the second IoT device and an encrypted identifier stored synchronously during the generation of the source IPv6 address;

[0089] In an embodiment of the present application, when the health score of any IoT device (which can be recorded as the second IoT device, which can be the above-mentioned first physical network device or other IoT devices) is low, or a security incident is detected in the target network, an alarm needs to be triggered, and the source IPv6 address is sent to the address tracing module to parse the device information corresponding to the address, thereby triggering corresponding operation and maintenance operations based on the device information. It can be seen that the response to the address tracing request for the second IoT device in the present application can include: responding to a security incident occurring in the target network for the second IoT device, and / or responding to the address tracing request of the second IoT device, etc.

[0090] It should be noted that in order to achieve address traceability, during the IPv6 address generation process of the corresponding second IoT device, the corresponding address generation module can synchronously store the dynamically updated encrypted identifier in the address tracing module, so that the address tracing module can perform address tracing according to the method proposed in this embodiment. This application does not elaborate on the interactive implementation process between the address generation module and the address tracing module in the IPv6 address management device.

[0091] In a possible implementation, in the IPv6 address generation process, the generated IPv6 address can be stored in association with the dynamically updated encrypted identifier GUTI, the health score and the like information in the source address verification module (such as the SAVA router B), and the health score can be dynamically updated according to the method described above, so that when the health score is less than the address tracing threshold, it means that the address tracing condition is met, and the address tracing request for the corresponding second Internet of Things device can be generated, that is, in response to the health score of the second Internet of Things device meeting the address tracing condition, the stored IPv6 address is read as the source IPv6 address and the encrypted identifier GUTI to perform subsequent tracing operations.

[0092] In step S72, the pre-encryption address identifier corresponding to the address identifier contained in the source IPv6 address is read;

[0093] In step S73, the source network identifier is decrypted based on the pre-encryption address identifier, the encrypted identifier and the current time confusion hash value.

[0094] In step S74, the second Internet of Things device is traced based on the source network identifier and the second device identifier of the second Internet of Things device.

[0095] In the embodiments of the present application, the unique NID of the second Internet of Things device can be decrypted based on the encrypted identifier and the pre-encryption address identifier stored in the database according to the reverse process of the IPv6 address generation described above, so that the address tracing of the second Internet of Things device can be accurately realized, and the geographic location and hardware identifier of the second Internet of Things device can be determined, that is, which Internet of Things device is faulty can be determined, so as to inform the operation and maintenance personnel to timely perform operation and maintenance processing.

[0096] For example, the address tracing process is illustrated by taking the NID generation example and the AID generation example shown in the drawings as examples, as follows: Figure 8In the address tracing example shown, after determining that the source IPv6 address of the second IoT device that requires address tracing is 2001:250:4000:4504:e499:964b:470f:68e4, the IPv6 address prefix (which can be allocated by the network slice) 2001:250:4000:4504:: / 64 and the address identifier (AID) e499964b470f68e4 can be extracted from it, and the pre-encrypted identifier preAID 7A428282A7D28502 can be obtained through hash database retrieval. Combined with the timestamp hash value TimeHashff61c2015437731b (obtained by truncating the address generation time parameter through a SHA3-256 operation, the implementation process can be described in the corresponding part of the address generation example above, which is not detailed in this embodiment) and the dynamically rotated IDEA encrypted identifier 4a363479e84797efd1f6a541398d5bac (as analyzed above, the encrypted identifier library is synchronized in real time), the decryption operation IDEA_Decrypt(7A428282A7D28502, Key) is performed to generate the intermediate code 56677eef151511c920. The first 8 hexadecimal digits are truncated to obtain the unique network identifier (i.e., source network identifier) ​​of the second IoT device, NID56677eef15. Subsequently, combined with the second device identifier of the second IoT device, such as the device number, Figure 8 Still taking the device number 0000 of the first IoT device as an example, the device attribute information indicating the second IoT device is read from the database, which includes but is not limited to Figure 8 The MAC address and geographic latitude and longitude (geographic coordinates) are shown.

[0097] Optionally, if the address tracing request is triggered by a security event, the health score of the second IoT device can be queried from the database. Specifically, the hardware identifier, geographic location, and health score of the second IoT device can be queried. Based on the health score and the device attribute information obtained through tracing (such as the unique hardware identifier and geographic location), corresponding operation and maintenance operations can be performed on the second IoT device. This implementation process can be combined with the description of the corresponding parts of the above embodiment and will not be repeated in this embodiment.

[0098] Reference Figure 9 , is a structural diagram of an IPv6 address management device provided in an embodiment of the present application, such as Figure 9 As shown, the IPv6 address management device may include:

[0099] The device information obtaining module 91 is configured to obtain device information of a first IoT device requesting access to a target network; the device information includes current device operation status information and device attribute information;

[0100] A network identifier generation module 92 is configured to generate, based on the device attribute information, a network identifier for the first IoT device through encryption;

[0101] An address identifier generation module 93 is configured to generate an address identifier of the first IoT device by encryption based on the network identifier, the device operation status information, and the first device identification of the first IoT device; the encrypted identifier can be dynamically updated and stored;

[0102] The IPv6 address generation module 94 is configured to generate an IPv6 address for the first IoT device to access the target network based on the address identifier and the IPv6 address prefix.

[0103] In some embodiments, the device attribute information may include: hardware identification, geographic location, software configuration, and device type identification; based on this, the network identifier generation module 92 may include:

[0104] a device bit determination unit, configured to perform a national secret hash calculation on the hardware identifier to determine a device bit for the first IoT device;

[0105] A network identifier obtaining unit is configured to fuse the geographic location, the software configuration, the device type identifier, and the device bit to obtain a network identifier for the first IoT device.

[0106] In some embodiments, the software configuration may include a firmware bit obtained by encoding the firmware version information of the first IoT device, the geographic location may be a geographic bit obtained by encoding the geographic coordinates of the first IoT device, and the device type identifier may be a flag bit configured corresponding to the device type to which the first IoT device belongs. Based on this, the network identifier obtaining unit may include:

[0107] a conflict detection unit, configured to perform conflict detection on the flag bit, the firmware bit, the geographic bit, and the device bit based on a cyclic redundancy check rule, and obtain a corresponding detection result;

[0108] An offset processing unit is used to perform offset processing on the repeated bits indicated by the detection result through a secondary detection method to obtain a network identifier of a first length for the first Internet of Things device.

[0109] Optionally, the address identifier generating module 93 may include:

[0110] an encryption identifier determination unit, configured to determine a currently generated encryption identifier for the first IoT device; the encryption identifier conforming to a globally unique temporary identifier structure of the target network;

[0111] An address identifier ciphertext generating unit, configured to encrypt and generate an address identifier ciphertext for the first IoT device based on the network identifier, the device operating status information, the encryption identifier, and the device number;

[0112] a time obfuscated hash value extraction unit, configured to perform a hash operation on the device operation status information and extract a time obfuscated hash value of a second length from the obtained hash value;

[0113] The address identifier obtaining unit is configured to perform an XOR operation on the address identifier ciphertext and the time obfuscated hash value to obtain the address identifier of the first Internet of Things device.

[0114] Optionally, the device operation status information may include at least a timestamp and a heartbeat signal; the heartbeat signal may be used to determine the health status of the first IoT device, and the encrypted identifier and the timestamp may be associated and stored based on a blockchain;

[0115] Based on this, the address identifier generation module 93 may include:

[0116] an intermediate code generating unit, configured to generate an intermediate code of a third length by using at least one of the timestamp and the heartbeat signal, the network identifier and the device number, in a bit alignment and padding manner;

[0117] A symmetric encryption processing unit is used to perform symmetric encryption processing on the intermediate code and the encryption identifier to obtain an address identifier ciphertext for the first Internet of Things device; the encryption identifier is dynamically updated according to a first time interval, and the first time interval is less than a first time threshold.

[0118] In some embodiments, the above apparatus may further include:

[0119] a health score obtaining module, configured to input the device operating status information into a health assessment model, and obtain a health score of the first IoT device by determining at least one status indicator and an indicator abnormality threshold;

[0120] A first operation and maintenance module, configured to execute corresponding operation and maintenance operations in response to the health score satisfying the operation and maintenance conditions;

[0121] an adjustment module, configured to adjust the priority of the corresponding network slice in response to the health score satisfying the network optimization condition;

[0122] Among them, the core transaction business exclusively occupies one network slice, and multiple non-core transaction businesses share one network slice.

[0123] Optionally, the health score obtaining module may include:

[0124] A first determining unit is configured to input the device operating status information into a health assessment model to determine a current heartbeat delay rate, a port abnormality frequency, and a traffic fluctuation rate of the first IoT device;

[0125] A second determining unit is configured to determine a health score of the first IoT device by using the heartbeat delay rate, the port abnormality frequency, the traffic fluctuation rate, and the weights of the respective indicators through the health assessment model and according to a health scoring rule for the corresponding status indicator;

[0126] Based on this, the above device may further include:

[0127] The second operation and maintenance module is used to execute a pre-configured corresponding operation and maintenance operation in response to at least one status indicator among the heartbeat delay rate, the port abnormal frequency and the traffic fluctuation rate reaching a corresponding predicted indicator abnormality threshold.

[0128] In some embodiments, the above apparatus may further include:

[0129] A first determination module is configured to determine, in response to an address tracing request for a second IoT device, a source IPv6 address of the second IoT device and an encrypted identifier synchronously stored during the generation of the source IPv6 address;

[0130] A first reading module is configured to read a corresponding pre-encrypted address identifier based on the address identifier included in the source IPv6 address;

[0131] a decryption module, configured to decrypt and obtain a source network identifier based on the pre-encrypted address identifier, the encrypted identifier, and a current time obfuscated hash value;

[0132] A tracing module is used to perform address tracing on the second Internet of Things device based on the source network identifier and the second device identification of the second Internet of Things device.

[0133] Those skilled in the art will understand that the functions and technical effects of each module in the above-mentioned device embodiment, as well as the units for implementing the functions, are equivalent to the corresponding steps described in the above-mentioned method embodiment. For specific implementation details, please refer to the description of the method part, and the device embodiment does not elaborate on them one by one.

[0134] An embodiment of the present application also provides a computer program product including computer-readable instructions. When the computer-readable instructions are executed on an electronic device, the electronic device implements any one of the IPv6 address management methods provided in the embodiments of the present application.

[0135] A computer-readable storage medium is also provided in an embodiment of the present application. The storage medium carries one or more computer programs. When the one or more computer programs are executed by an electronic device, the electronic device can implement any IPv6 address management method provided in the embodiment of the present application.

[0136] Reference Figure 10 , is a structural diagram of the IPv6 address management system proposed in Example 1 of this application, such as Figure 10 As shown, the IPv6 address management system may include: a target network management device 1010, a service authentication device 1020, a source address verification device 1030 and an IPv6 address management device 1040. These devices may be one or more servers, or terminals as needed, such as routers and other network terminal devices.

[0137] The target network management device 1010 can be used to connect to the service authentication device 1020 and the source address verification device 1030 (i.e., the source address verification module mentioned above) respectively. In response to a target network access request from an IoT device, the service authentication device 1020 verifies the IoT device's legitimacy, determines and stores the device information of the IoT device, and transmits the device information to the IPv6 address management device 1040 via the source address verification device 1030. The device information includes the current device operating status information and device attribute information.

[0138] The IPv6 address management device 1040 can be used to connect to the source address verification device 1030, execute multiple computer instructions, and implement the IPv6 address management method proposed in the embodiment of the present application. The implementation process can refer to the description of the corresponding part of the method embodiment above, and this embodiment will not be repeated here.

[0139] In the embodiment of this application, Figure 11 The scenario diagram of the IPv6 address generation process shown in the figure shows that the target network management device 1010 may include a target network communication component, an access device and an AAA server, etc. For any physical network device in the bank campus (such as an ATM device, a smart counter or other IoT devices, etc.), a 5G private network (target network) access service application is initiated, that is, the IoT device initiates an access request to the target network, and the UPF network element responsible for the routing and forwarding related functions of the user plane data packet in the 5G core network (this application may refer to the 3GPP5G core network) sends the access request to the access device, and the access device forwards the access request or the request information it contains (which may include corresponding device information, etc.) to the AAA server for recording.

[0140] Afterwards, the AAA server can communicate with the bank system's authentication device, namely the service authentication device 1020 (eg Figure 11The address generation module can generate the IPv6 address of the IoT device according to the IPv6 address generation method and system of the present application. The address generation module can be connected to the service authentication device 1020 (such as the in-line authentication system in the figure) to verify the legitimacy of the IoT device requesting network access, such as verifying whether the IoT device is on the list of allowed access, whether the device attribute information is compliant (such as verifying firmware version compliance, etc.), which can be determined according to pre-configured legitimate verification rules. The service authentication device 1020 can feed back the legitimacy verification result of the IoT device to the AAA server, and if the verification is legitimate, the AAA server can transmit the device information of the physical network device to the IPv6 address management device 1040 through the source address verification device 1030. The address generation module in the IPv6 address management device 1040 performs the IPv6 address generation steps described in the above embodiment to generate the IPv6 address of the IoT device requesting network access.

[0141] In order to facilitate device address tracing, the present application can associate the IPv6 address generated by the IoT device with the corresponding encrypted identifier GUTI and the corresponding determined health score (such as <GUTI, IPv6 address, health score> form, but not limited to this) and store it to the source address verification device 1030, such as the SAVA router B shown in the figure. In addition, the encrypted identifier in the address generation module can be stored to the address tracing module synchronously except for the encrypted identifier updated at the transaction peak stage, so that the address tracing module can realize address tracing in combination with the stored encrypted identifier. Figure 11

[0142] The address tracing implementation process can refer to the address tracing example shown in Figure 8 Figure 12 When the health of the IoT device triggers an alarm or a security event occurs in the private network, the address corresponding to the device information is sent to the address tracing module through the source IPv6 address for analysis, and the device information is triggered according to the device information to trigger IP isolation, maintenance work order distribution, and the implementation process can refer to the description of the corresponding part of the above method embodiment, which will not be described here.

[0143] In addition, in combination with the above analysis, the IPv6 address management method and system proposed by the present application covers four dimensions of device identity binding, dynamic encryption, network architecture optimization and security audit, which can refer to Figure 11 and Figure 12 ​​The 5G private network converged architecture shown in the figure implements closed-loop management of the IPv6 address lifecycle and improves resource utilization efficiency. It covers the entire process of network access authentication (5G PDU frame secondary authentication), dynamic address generation, and network withdrawal and recovery. It triggers automated operation and maintenance (IP isolation, work order distribution) based on the health scoring model (heartbeat delay, port anomaly, traffic fluctuation), reducing the retention rate of "zombie addresses". It is also compatible with the 5G private network slicing architecture and supports financial-level high security requirements. It implements closed-loop management of the entire lifecycle of device network access authentication, status perception, fault location, and network withdrawal and recovery, and supports the access of 650 million devices in a single instance. At the same time, the blockchain stores address allocation logs and encrypted identifier update records, making the tampering risk ≤10 -18 , thereby meeting the management and control requirements of "equipment trustworthiness, status visibility, and controllable operation and maintenance" in banking scenarios.

[0144] It should be understood that Figure 10-12 The IPv6 address management system structure shown does not constitute a limitation on the IPv6 address management system in the embodiments of the present application. In actual applications, the IPv6 address management system may include more devices than those shown in the drawings. This application does not provide detailed examples one by one.

[0145] It should also be noted that the device embodiments described above are merely illustrative, wherein the units described as separate components may or may not be physically separate, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed across multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the present embodiment. In addition, in the drawings of the device embodiments provided in this application, the connection relationship between the modules indicates that there is a communication connection between them, which can be specifically implemented as one or more communication buses or signal lines.

[0146] Through the description of the above embodiments, those skilled in the art can clearly understand that the present application can be implemented by means of software plus necessary general-purpose hardware, and of course can also be implemented by means of dedicated hardware including dedicated integrated circuits, dedicated CPUs, dedicated memories, dedicated components, etc. In other words, the above embodiments can be implemented in whole or in part by means of software, hardware, firmware, or any combination thereof.

Claims

1. A method for managing IPv6 addresses, characterized in that: The method comprises: Obtaining device information of a first IoT device requesting access to a target network; the device information includes current device operating status information and device attribute information; Encrypt and generate a network identifier for the first IoT device based on the device attribute information; Encrypt and generate an address identifier for the first Internet of Things device based on the network identifier, the device operating status information, and the first device identifier of the first Internet of Things device; Based on the address identifier and the IPv6 address prefix, an IPv6 address for the first Internet of Things device to access the target network is generated.

2. The method according to claim 1, characterized in that The device attribute information includes: hardware identification, geographic location, software configuration and device type identification; The step of encrypting and generating a network identifier for the first IoT device based on the device attribute information includes: Performing a national secret hash calculation on the hardware identifier to determine a device bit for the first IoT device; The geographic location, the software configuration, the device type identifier, and the device bit are integrated to obtain a network identifier for the first Internet of Things device.

3. The method according to claim 2, characterized in that The software configuration includes a firmware bit obtained by encoding the firmware version information of the first IoT device, the geographic location is a geographic bit obtained by encoding the geographic coordinates of the first IoT device, and the device type identifier is a flag bit configured corresponding to the device type to which the first IoT device belongs; The fusing the geographic location, the software configuration, the device type identifier, and the device bit to obtain a network identifier for the first IoT device includes: Based on a cyclic redundancy check rule, performing conflict detection on the flag bit, the firmware bit, the geographic bit, and the device bit to obtain a corresponding detection result; Through the secondary detection method, the repeated bits indicated by the detection result are offset to obtain a network identifier of the first length for the first Internet of Things device.

4. The method according to claim 2, characterized in that The step of encrypting and generating an address identifier of the first Internet of Things device based on the network identifier, the device operation status information, and the first device identification of the first Internet of Things device includes: Determining a currently generated encrypted identifier for the first IoT device; the encrypted identifier conforms to a globally unique temporary identifier structure of the target network and can be dynamically updated and stored; Encrypt and generate a ciphertext address identifier for the first Internet of Things device based on the network identifier, the device operating status information, the encryption identifier, and the first device identification of the first Internet of Things device; Performing a hash operation on the device operation status information, and extracting a time-obfuscated hash value of a second length from the obtained hash value; An exclusive OR operation is performed on the address identifier ciphertext and the time obfuscated hash value to obtain an address identifier of the first Internet of Things device.

5. The method according to claim 4, characterized in that The device operation status information includes at least a timestamp and a heartbeat signal; the heartbeat signal can be used to determine the health status of the first IoT device, and the encrypted identifier and the timestamp are associated and stored based on a blockchain; The step of encrypting and generating an address identifier ciphertext for the first Internet of Things device based on the network identifier, the device operating status information, the encryption identifier, and the first device identification of the first Internet of Things device includes: Generate an intermediate code of a third length by using at least one of the timestamp and the heartbeat signal, the network identifier, and the first device identifier of the first Internet of Things device through bit alignment and padding; Symmetric encryption is performed on the intermediate code and the encryption identifier to obtain an address identifier ciphertext for the first Internet of Things device; the encryption identifier is dynamically updated according to a first time interval, and the first time interval is less than a first time threshold.

6. The method according to any one of claims 1 to 5, characterized in that The method further comprises: Inputting the device operating status information into a health assessment model, and obtaining a health score of the first IoT device by determining at least one status indicator and an indicator abnormality threshold; In response to the health score satisfying the operation and maintenance conditions, performing corresponding operation and maintenance operations; In response to the health score satisfying the network optimization condition, adjusting the priority of the corresponding network slice; Among them, the core transaction business exclusively occupies one network slice, and multiple non-core transaction businesses share one network slice.

7. The method according to claim 6, characterized in that Inputting the device operating status information into a health assessment model and obtaining a health score of the first IoT device by determining at least one status indicator and an indicator abnormality threshold includes: Inputting the device operation status information into a health assessment model to determine the current heartbeat delay rate, port abnormality frequency, and traffic fluctuation rate of the first IoT device; Determine the health score of the first IoT device by using the health evaluation model, the heartbeat delay rate, the port abnormality frequency, the traffic fluctuation rate, and the weights of the indicators, according to the health scoring rules of the corresponding status indicators; The method further comprises: In response to at least one status indicator among the heartbeat delay rate, the port abnormal frequency and the traffic fluctuation rate reaching a corresponding predicted indicator abnormality threshold, a pre-configured corresponding operation and maintenance operation is performed.

8. The method according to claim 6, characterized in that The method further comprises: In response to a request for tracing the address of a second IoT device, determine a source IPv6 address of the second IoT device and an encrypted identifier stored synchronously during the generation of the source IPv6 address; Based on the address identifier included in the source IPv6 address, read the corresponding pre-encrypted address identifier; Decrypting the pre-encrypted address identifier, the encrypted identifier, and the current time-obfuscated hash value to obtain a source network identifier; Based on the source network identifier and the second device identification of the second Internet of Things device, address tracing is performed on the second Internet of Things device.

9. The method according to claim 8, characterized in that The response to the address tracing request for the second IoT device includes at least one of the following: In response to the health score of the second IoT device satisfying the address tracing condition; In response to a security event occurring on the target network targeting a second IoT device; The address tracing of the second IoT device includes: Query the hardware identification, geographic location, and health score of the second IoT device.

10. An IPv6 address management system, characterized in that: The system includes: a target network management device, a service authentication device, a source address verification device, and an IPv6 address management device, wherein: The target network management device is configured to connect to the service authentication device and the source address verification device, respectively, respond to a target network access request from an IoT device, verify the IoT device is legitimate via the service authentication device, determine device information of the IoT device and store it, and transmit the device information to the IPv6 address management device via the source address verification device; the device information includes current device operating status information and device attribute information; The IPv6 address management device is used to connect to the source address verification device, execute multiple computer instructions, and implement the IPv6 address management method according to any one of claims 1 to 9.