Access control method and device, network equipment and user equipment
By adopting DID and VC mechanisms in 6G networks and using blockchain network devices for user equipment authentication and authorization, the problem of sub-network authentication and authorization in future 6G networks is solved, reducing the pressure on the central network and communication latency.
Patent Information
- Application Number
- CN202410562139.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-05-08
- Publication Date
- 2025-11-11
AI Technical Summary
The existing roaming authentication mechanism cannot effectively authenticate and authorize user identities in the future 6G network, leading to increased pressure on the central network and communication delays.
By adopting decentralized identity (DID) and verifiable claims (VC) mechanisms, user devices are authenticated and authorized through blockchain network devices, realizing authentication and authorization between distributed subnets and reducing the involvement of the central network.
It enables authentication and authorization of user equipment through distributed subnets, reducing the burden on the central network and lowering communication latency for user equipment.
Smart Images

Figure CN120935564A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of communication technology, and in particular to an access control method, apparatus, network device, and user equipment. Background Technology
[0002] Existing roaming authentication mechanisms mainly rely on the user's Subscriber Identity Module (SIM) card and authentication information in the home network. The authentication and authorization of users can only be performed by the home network, and the home network and the visited network need to be based on a pre-signed roaming agreement to complete the identity authentication of users when roaming to different visited networks.
[0003] Future 6G networks will introduce a distributed architecture consisting of a central network and distributed subnets. The central network will meet wide-area coverage and general service requirements, while the distributed subnets will primarily address specific needs in various scenarios. In a 6G distributed network, if user subscription data is stored in the central node network, using a mechanism similar to roaming authentication, each user device connecting to the distributed subnets will need to be authenticated and authorized in the central network and maintain a real-time connection. This will put pressure on the central network, and some user devices may require multiple routing hops to connect, causing communication delays. Therefore, existing roaming authentication mechanisms are not suitable for the authentication and authorization requirements of future 6G networks. Furthermore, there are currently no solutions for how to implement user authentication and authorization in each subnet and how authentication will occur between subnets in future 6G networks. Summary of the Invention
[0004] This application provides an access control method, apparatus, network device, and user equipment, which solves the problem that there is currently no solution for how to achieve user authentication and authorization in each subnetwork and how to authenticate between subnetworks in future 6G networks.
[0005] Embodiments of this application provide an access control method applied to a first network device in a first subnet, the method comprising:
[0006] The first network device receives the first information or the second information;
[0007] The first network device performs authentication of the user equipment based on the first information, or performs authentication and authorization of the user equipment based on the first information, or performs authentication of the second subnet based on the second information;
[0008] The first information includes one of the following:
[0009] The first decentralized identity (DID) identifier corresponding to the user equipment and the information related to the authentication of the user equipment;
[0010] The first DID identifier corresponding to the user equipment, the authentication-related information of the user equipment, and the authorization-related information of the user equipment;
[0011] The second information includes the second DID identifier corresponding to the second subnet and information related to the authentication of the second subnet.
[0012] Optionally, the first DID identifier is configured by the central network to which the first subnet belongs, and / or the second DID identifier is configured by the central network to which the second subnet belongs.
[0013] Optionally, the information related to the authentication of the user equipment includes at least one of the following:
[0014] First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier;
[0015] The request message in plaintext and a second encrypted message encrypted using the user equipment's private key;
[0016] or,
[0017] The information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature;
[0018] or,
[0019] The information related to the authentication of the second subnet includes at least one of the following:
[0020] The third encrypted information is obtained by encrypting the second DID identifier using the private key of the second subnet's identity.
[0021] The request message is in plaintext and a fourth encrypted message is generated by encrypting the request message using the private key of the identity of the second subnet.
[0022] Optionally, the first network device performs authentication of the user equipment based on the first information, including:
[0023] The first network device queries the blockchain network device for the identity public key of the user device based on the first DID identifier;
[0024] The first network device decrypts the first encrypted information to obtain first decrypted information based on the identity public key of the user equipment, and / or decrypts the second encrypted information to obtain second decrypted information;
[0025] The first network device determines the authentication result of the user equipment based on the decryption information and the plaintext information; wherein the decryption information and the plaintext information include at least one combination of the following:
[0026] The first decryption information and the first DID identifier;
[0027] The second decryption information and the request information in plaintext.
[0028] Optionally, the first network device determines the authentication result of the user equipment based on the decrypted information and the plaintext information, including:
[0029] If the decrypted information and the plaintext information are consistent, the first network device determines that the authentication result indicates that the user equipment's identity is legitimate.
[0030] And / or,
[0031] If the decrypted information and the plaintext information do not meet the consistency requirement, the first network device determines that the authentication result indicates that the user equipment's identity is illegitimate.
[0032] Optionally, the first network device performs authorization of the user equipment based on the first information, including:
[0033] The first network device determines the first identity public key based on the third DID identifier carried in the verifiable claim plaintext;
[0034] The first network device decrypts the verifiable declaration digital signature based on the first identity public key to obtain the third decryption information;
[0035] The first network device determines the authorization result of the user equipment based on the third decryption information and the verifiable declaration plaintext.
[0036] Optionally, the first network device determines the identity public key based on the third DID identifier carried in the plaintext of the verifiable claim, including at least one of the following:
[0037] If the third DID identifier is the DID identifier corresponding to the first subnet, then the first identity public key is determined to be the identity public key of the first subnet;
[0038] If the third DID identifier is the DID identifier corresponding to the central network to which the first subnet belongs, the first network device queries the blockchain network device for the identity public key of the central network based on the third DID identifier, and determines that the first identity public key is the identity public key of the central network.
[0039] If the third DID identifier is the DID identifier corresponding to the third subnet associated with the first subnet, the first network device queries the blockchain network device for the identity public key of the third subnet based on the third DID identifier, and determines that the first identity public key is the identity public key of the third subnet.
[0040] Optionally, the first network device determines the authorization result of the user equipment based on the third decryption information and the verifiable claim plaintext, including:
[0041] If the third decryption information and the plaintext of the verifiable declaration are consistent, then the first network device determines that the authorization result is authorized.
[0042] And / or,
[0043] If the third decryption information and the verifiable declaration plaintext do not meet the consistency requirement, the first network device determines that the authorization result is an authorization failure.
[0044] Optionally, the access control method further includes at least one of the following:
[0045] If the first network device determines that the user equipment's identity is legitimate, it sends a first message to the third network device of the central network to which the first subnet belongs; wherein, the first message is used to request a verifiable statement for the user equipment;
[0046] The first network device sends a second message to the third network device; wherein the second message is used to request authentication of the user equipment and to provide a verifiable claim for the user equipment;
[0047] The verifiable claim is used to access at least one subnet belonging to the central network.
[0048] Optionally, the access control method further includes:
[0049] The first network device sends a third message to a third network device in the central network to which the first subnet belongs; wherein the third message is used to request authentication of the user equipment;
[0050] The first network device receives a response message from the third network device to the third message; wherein the response message is used to indicate the authentication result of the user equipment;
[0051] The first network device sends a verifiable declaration to the user equipment based on the response message;
[0052] The verifiable statement is used to access the first subnet and / or to access the third subnet associated with the first subnet.
[0053] Optionally, the first network device performs authentication of the second subnet based on the second information, including:
[0054] The first network device queries the identity public key of the second subnet from the blockchain network device through the proxy server based on the second DID identifier;
[0055] The first network device decrypts the third encrypted information to obtain the third decrypted information based on the identity public key of the second subnet, and / or decrypts the fourth encrypted information to obtain the fourth decrypted information;
[0056] The first network device determines the authentication result of the second subnet based on the decryption information and the plaintext information; wherein the decryption information and the plaintext information include at least one combination of the following:
[0057] The third decryption information and the second DID identifier;
[0058] The fourth decryption information and request information are in plaintext.
[0059] Optionally, the first network device determines the authentication result of the second subnet based on the decrypted information and the plaintext information, including:
[0060] If the decrypted information and the plaintext information are consistent, the first network device determines that the authentication result is valid for the identity of the second subnet.
[0061] And / or,
[0062] If the decrypted information and the plaintext information do not meet the consistency requirement, the first network device determines that the authentication result indicates that the identity of the second subnet is illegitimate.
[0063] Optionally, the access control method further includes:
[0064] The first network device receives the DID identifier corresponding to the first subnet from the third network device of the central network to which the first subnet belongs.
[0065] This application provides an access control method, including:
[0066] The user equipment sends first information to the first network device in the first subnet; wherein the first information includes one of the following:
[0067] The first DID identifier corresponding to the user equipment and the authentication-related information of the user equipment;
[0068] The user equipment includes a first DID identifier, authentication information related to the user equipment, and authorization information related to the user equipment.
[0069] Optionally, before the user equipment sends the first information to the first network device of the first subnet, it further includes:
[0070] The user equipment receives the first DID identifier sent by the third network device of the central network to which the first subnet belongs.
[0071] Optionally, the information related to the authentication of the user equipment includes at least one of the following:
[0072] First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier;
[0073] The request message in plaintext and a second encrypted message encrypted using the user equipment's private key;
[0074] or,
[0075] The information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature. Optionally, the access control method further includes at least one of the following:
[0076] The user equipment receives a verifiable statement plaintext sent by the first network device;
[0077] The user equipment receives a verifiable statement plaintext sent by a third network device of the central network to which the first subnet belongs;
[0078] The verifiable declaration states that a plaintext user accesses at least one subnet belonging to the central network.
[0079] This application provides an access control method applied to a third network device in a central network. The method includes:
[0080] The third network device sends the first DID identifier corresponding to the user equipment to the user equipment, and / or sends the second DID identifier corresponding to the second subnet to the second network device of the second subnet;
[0081] The second subnet belongs to the central network.
[0082] Optionally, the information related to the authentication of the user equipment includes at least one of the following:
[0083] First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier;
[0084] The request message in plaintext and a second encrypted message encrypted using the user equipment's private key;
[0085] or,
[0086] The information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature;
[0087] or,
[0088] The information related to the authentication of the second subnet includes at least one of the following:
[0089] The third encrypted information is obtained by encrypting the second DID identifier using the private key of the second subnet's identity.
[0090] The request message is in plaintext and a fourth encrypted message is generated by encrypting the request message using the private key of the identity of the second subnet.
[0091] Optionally, the access control method further includes:
[0092] The third network device receives a first message sent by the first network device of the first subnet; wherein the first message is used to request a verifiable claim for the user equipment;
[0093] The third network device sends a verifiable declaration to the user equipment based on the user equipment's subscription information;
[0094] The first subnet belongs to the central network, and the verifiable declaration is used to access at least one subnet belonging to the central network.
[0095] Optionally, the access control method further includes:
[0096] The third network device receives a second message sent by the first network device of the first subnet; wherein the second message is used to request authentication of the user equipment and to provide a verifiable claim for the user equipment;
[0097] The third network device authenticates the user equipment based on the second message and determines the authentication result;
[0098] If the authentication result confirms that the user equipment's identity is legitimate, the third network device sends a verifiable declaration to the user equipment based on the user equipment's subscription information.
[0099] The first subnet belongs to the central network, and the verifiable declaration is used to access at least one subnet belonging to the central network.
[0100] Optionally, the access control method further includes:
[0101] The third network device receives a third message sent by the first network device in the first subnet; wherein the third message is used to request authentication of the user equipment; wherein the first subnet belongs to the central network;
[0102] The third network device authenticates the user equipment based on the third message and determines the authentication result;
[0103] The third network device sends a response message to the first network device for the third message; wherein the response message is used to indicate the authentication result of the user equipment.
[0104] Optionally, the authentication result is used to indicate whether the identity of the user equipment is legitimate, and / or, the authentication result is used to indicate whether the verifiable claim is allowed to be provided to the user equipment.
[0105] Optionally, the access control method further includes:
[0106] The third network device sends the DID identifier corresponding to the first subnet to the first network device of the first subnet; wherein, the first subnet belongs to the central network.
[0107] This application provides an access control device applied to a first subnet, including a memory, a transceiver, and a processor;
[0108] The memory stores computer programs; the transceiver, under the control of the processor, sends and receives data; the processor reads the computer programs from the memory and performs the following operations:
[0109] Receive the first message or the second message;
[0110] Authentication of the user equipment is performed based on the first information, or authentication and authorization of the user equipment are performed based on the first information, or authentication of the second subnet is performed based on the second information;
[0111] The first information includes one of the following:
[0112] The first DID identifier corresponding to the user equipment and the authentication-related information of the user equipment;
[0113] The first DID identifier corresponding to the user equipment, the authentication-related information of the user equipment, and the authorization-related information of the user equipment;
[0114] The second information includes the second DID identifier corresponding to the second subnet and information related to the authentication of the second subnet.
[0115] Optionally, the information related to the authentication of the user equipment includes at least one of the following:
[0116] First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier;
[0117] The request message in plaintext and a second encrypted message encrypted using the user equipment's private key;
[0118] or,
[0119] The information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature;
[0120] or,
[0121] The information related to the authentication of the second subnet includes at least one of the following:
[0122] The third encrypted information is obtained by encrypting the second DID identifier using the private key of the second subnet's identity.
[0123] The request message is in plaintext and a fourth encrypted message is generated by encrypting the request message using the private key of the identity of the second subnet.
[0124] Optionally, the processor is configured to read the computer program in the memory and perform the following operations:
[0125] Based on the first DID identifier, query the blockchain network device for the identity public key of the user device;
[0126] Based on the user equipment's identity public key, the first encrypted information is decrypted to obtain the first decrypted information, and / or the second encrypted information is decrypted to obtain the second decrypted information;
[0127] The authentication result of the user equipment is determined based on the decrypted information and the plaintext information; wherein the decrypted information and the plaintext information include at least one combination of the following:
[0128] The first decryption information and the first DID identifier;
[0129] The second decryption information and the request information in plaintext.
[0130] Optionally, the processor is configured to read the computer program in the memory and perform the following operations:
[0131] The first identity public key is determined based on the third DID identifier carried in the plaintext of the verifiable claim;
[0132] Based on the first identity public key, the verifiable declaration digital signature is decrypted to obtain the third decryption information;
[0133] The authorization result of the user equipment is determined based on the third decryption information and the verifiable statement plaintext.
[0134] Optionally, the processor is configured to read the computer program in the memory and perform the following operations:
[0135] Based on the second DID identifier, query the identity public key of the second subnet from the blockchain network device through the proxy server;
[0136] Based on the identity public key of the second subnet, the third encrypted information is decrypted to obtain the third decrypted information, and / or the fourth encrypted information is decrypted to obtain the fourth decrypted information;
[0137] The authentication result of the second subnet is determined based on the decrypted information and the plaintext information; wherein the decrypted information and the plaintext information include at least one combination of the following:
[0138] The third decryption information and the second DID identifier;
[0139] The fourth decryption information and request information are in plaintext.
[0140] This application provides a network device applied to a first subnet, comprising:
[0141] The first receiving unit is used to receive first information or second information;
[0142] The processing unit is configured to perform authentication of the user equipment based on the first information, or to perform authentication and authorization of the user equipment based on the first information, or to perform authentication of the second subnet based on the second information;
[0143] The first information includes one of the following:
[0144] The first DID identifier corresponding to the user equipment and the authentication-related information of the user equipment;
[0145] The first DID identifier corresponding to the user equipment, the authentication-related information of the user equipment, and the authorization-related information of the user equipment;
[0146] The second information includes the second DID identifier corresponding to the second subnet and information related to the authentication of the second subnet.
[0147] This application provides an access control device, including a memory, a transceiver, and a processor;
[0148] The memory stores computer programs; the transceiver, under the control of the processor, sends and receives data; the processor reads the computer programs from the memory and performs the following operations:
[0149] Send first information to a first network device in a first subnet; wherein the first information includes one of the following:
[0150] The first DID identifier corresponding to the user equipment and the authentication-related information of the user equipment;
[0151] The user equipment's first DID identifier, authentication-related information, and authorization-related information.
[0152] This application provides a user equipment, including:
[0153] The sending unit is configured to send first information to a first network device in a first subnet; wherein the first information includes one of the following:
[0154] The first DID identifier corresponding to the user equipment and the authentication-related information of the user equipment;
[0155] The user equipment includes a first DID identifier, authentication information related to the user equipment, and authorization information related to the user equipment.
[0156] This application provides an access control device for use in a central network, including a memory, a transceiver, and a processor;
[0157] The memory stores computer programs; the transceiver, under the control of the processor, sends and receives data; the processor reads the computer programs from the memory and performs the following operations:
[0158] Send the first DID identifier corresponding to the user equipment to the user equipment, and / or send the second DID identifier corresponding to the second subnet to the second network device of the second subnet;
[0159] The second subnet belongs to the central network.
[0160] This application provides a network device applied to a central network, including:
[0161] The first sending unit is configured to send a first DID identifier corresponding to the user equipment to the user equipment, and / or send a second DID identifier corresponding to the second subnet to the second network device of the second subnet;
[0162] The second subnet belongs to the central network.
[0163] This application provides a processor-readable storage medium storing a computer program for causing the processor to perform the steps of the access control method described above.
[0164] This application provides a computer program product, including computer instructions, which, when executed by a processor, implement the steps of the access control method described above.
[0165] The beneficial effects of the above-mentioned technical solution of this application are:
[0166] In this embodiment, the first network device in the first subnet can support authenticating the user equipment (UE) or authenticating and authorizing the UE based on the first information. Alternatively, the first network device can support authenticating the second subnet based on the second information. This achieves UE authentication and authorization by distributed subnets within the 6G network, enables authentication between different distributed subnets in the 6G network, avoids network pressure caused by authentication and authorization by the central network in the 6G network, and reduces communication latency for UEs. Attached Figure Description
[0167] Figure 1 A schematic diagram illustrating the 6G system architecture of an embodiment of this application;
[0168] Figure 2 This is a schematic diagram illustrating the structure of the DID identifier in an embodiment of this application.
[0169] Figure 3 This is a schematic diagram illustrating the structure of the DID document in an embodiment of this application.
[0170] Figure 4 This is a schematic diagram showing the structure of the VC in an embodiment of this application;
[0171] Figure 5 A flowchart illustrating the access control method on the first network device side according to an embodiment of this application;
[0172] Figure 6 A flowchart illustrating the access control method on the user equipment side according to an embodiment of this application;
[0173] Figure 7 A flowchart illustrating the access control method on the third network device side according to an embodiment of this application;
[0174] Figure 8 A block diagram illustrating the authentication and authorization process of a user device according to an embodiment of this application;
[0175] Figure 9A flowchart illustrating the user equipment authentication process according to an embodiment of this application;
[0176] Figure 10 A flowchart illustrating the VC authentication process of a user equipment according to an embodiment of this application;
[0177] Figure 11 A schematic diagram illustrating the interaction flow of the access control method according to an embodiment of this application;
[0178] Figure 12 A block diagram illustrating the authentication process between distributed subnets in an embodiment of this application;
[0179] Figure 13 A flowchart illustrating the authentication process between distributed subnets in an embodiment of this application;
[0180] Figure 14 A block diagram illustrating the access control device on the first network device side according to an embodiment of this application;
[0181] Figure 15 A block diagram illustrating the first network device according to an embodiment of this application;
[0182] Figure 16 A block diagram illustrating the access control device on the user equipment side according to an embodiment of this application;
[0183] Figure 17 A block diagram illustrating a user equipment according to an embodiment of this application;
[0184] Figure 18 A block diagram illustrating the access control device on the network device side of the embodiments of this application;
[0185] Figure 19 This is a block diagram illustrating the third network device in an embodiment of this application. Detailed Implementation
[0186] To make the technical problems, technical solutions, and advantages of this application clearer, a detailed description will be provided below in conjunction with the accompanying drawings and specific embodiments. In the following description, specific details such as particular configurations and components are provided merely to aid in a comprehensive understanding of the embodiments of this application. Therefore, those skilled in the art should understand that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this application. Furthermore, for clarity and brevity, descriptions of known functions and structures have been omitted.
[0187] It should be understood that the phrase "one embodiment" or "an embodiment" throughout the specification means that a specific feature, structure, or characteristic related to the embodiment is included in at least one embodiment of this application. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification does not necessarily refer to the same embodiment. Furthermore, these specific features, structures, or characteristics can be combined in any suitable manner in one or more embodiments.
[0188] In the various embodiments of this application, it should be understood that the sequence number of each process described below does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this application.
[0189] In addition, the terms "system" and "network" are often used interchangeably in this article.
[0190] The technical solutions provided in this application can be applied to various systems, especially 6G systems. For example, applicable systems include Global System for Mobile Communication (GSM), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA) General Packet Radio Service (GPRS), Long Term Evolution (LTE), LTE Frequency Division Duplex (FDD), LTE Time Division Duplex (TDD), Long Term Evolution Advanced (LTE-A), Universal Mobile Telecommunication System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX), 5G New Radio (NR), and 6G systems. All of these systems include terminal equipment (or user equipment) and network equipment. The system may also include a core network component, such as an evolved packet system (EPS), a 5G system (5GS), or a 6G system.
[0191] Network devices and terminal devices can each use one or more antennas for multiple-input multiple-output (MIMO) transmission. MIMO transmission can be single-user MIMO (SU-MIMO) or multiple-user MIMO (MU-MIMO). Depending on the configuration and number of antenna combinations, MIMO transmission can be 2D-MIMO, 3D-MIMO, FD-MIMO, or massive-MIMO, and can also be diversity transmission, precoding transmission, or beamforming transmission, etc.
[0192] In the embodiments of this application, the term "and / or" describes the relationship between associated objects, indicating that three relationships can exist. For example, A and / or B can represent three cases: A alone, A and B simultaneously, and B alone. The character " / " generally indicates that the preceding and following associated objects have an "or" relationship.
[0193] In the embodiments of this application, the term "multiple" refers to two or more, and other quantifiers are similar.
[0194] The technical solutions of the embodiments of this application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only a part of the embodiments of this application, and not all of the embodiments. Based on the embodiments of this application, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this application.
[0195] The following describes the relevant technologies involved in this application:
[0196] 1. Distributed 6G network architecture
[0197] Future 6G networks will introduce a distributed architecture consisting of a central network and distributed subnets, such as... Figure 1As shown, the terms "central" and "distributed" refer to network operation and management, not strictly a difference in physical location. The central network (or central node, central network node, etc.) is used to meet wide-area coverage needs and universal new service requirements such as intelligence and sensing. Distributed subnets (or distributed nodes, distributed subnet nodes, etc.) are mainly used to meet specific needs for connectivity, intelligence, and sensing in various scenarios, such as localized access and customized subnets for enterprises (ToB), satellite network access, and personalized subnets for personal services. The 6G network architecture follows the principles of flexible, on-demand, and intelligent network design, enabling diverse connections and network configurations between various networks. The central network has relatively complete functions, while the distributed subnet functions are tailored and organized as needed, following a principle of minimalist design. Through collaboration between wireless access and the core network, interconnection between the central network and distributed subnets, high- and low-frequency collaborative access, and air-space-ground integrated access networking, 6G networks will evolve from two-dimensional to full-space three-dimensional coverage, meeting the needs of various ubiquitous connectivity scenarios and providing network infrastructure for green and sustainable ubiquitous access and co-construction and sharing that is compatible with various industry ecosystems.
[0198] 2. Decentralized Identity
[0199] DID is a new type of identifier designed to identify any entity (such as an individual, organization, abstract entity, virtual entity, etc.).
[0200] Currently, mainstream internet identities are defined by each platform. A user may need to record identity information from multiple websites, which can easily lead to various problems. Identity information is not shared between platforms, and identity data is held by each application. Once a website closes, the identity information is lost. In contrast, the DID identifier is platform-independent. A single DID identifier can log in to multiple different platforms. Even if one platform closes, it does not affect the ability to log in to other platforms (provided that the platform supports DID identifiers). In other words, the DID identifier does not belong to any platform and exists independently.
[0201] like Figure 2 As shown, a string with a specific format for a DID identifier is given, consisting of three parts: Scheme, DID Method, and DID Method-Specific Identifier, representing a digital identity for a person, machine, thing, or virtual person or thing.
[0202] A DID document is a detailed description of a DID, representing a one-to-one relationship. It can be viewed as consisting of two parts: DID metadata and the DID public key. Figure 3 As shown, the public key is crucial and is used for digital signatures or encryption operations.
[0203] Generally, DID identifiers are stored on the user's side, while DID documents are stored in a database such as a blockchain (using the DID identifier as the key index) to ensure the correctness of the DID documents. It's important to note that DID documents do not contain any information related to the user's actual personal information, such as real name, address, or phone number. Therefore, relying solely on the DID specification is insufficient to verify the legitimacy of an identity; verifiable claims (VCs) at the DID application layer are necessary.
[0204] 3. Verifiable Statement
[0205] A VC is a descriptive statement issued by one DID to endorse certain attributes of another DID, and it includes its own digital signature to prove the authenticity of those attributes. It can be considered a type of digital certificate. The format of a VC is as follows: Figure 4 As shown, it includes:
[0206] VC metadata mainly includes information such as issuer, issue date, and declaration type.
[0207] Claim(s): One or more statements about the subject, such as: identity-related documents issued by an authority to an individual as a VC. The claim may include information such as: name, gender, date of birth, ethnicity, address, etc.
[0208] Proof(s): This is usually the digital signature of the issuer, which ensures that the VC can be verified, prevents the VC content from being tampered with, and verifies the issuer of the VC.
[0209] Because the DID document corresponding to the DID identifier does not contain the user's real information, the network side requires the user to provide proof, i.e., a VC, when performing a certain operation. Considering that the VC does not contain the issuer's public key, otherwise the verifier would also need to verify the authenticity of the public key, how the verifier verifies the VC needs to be considered. Therefore, this embodiment considers the VC's ID to be a Uniform Resource Identifier (URI), and the issuer field in the VC is also a URI. The issuer may also use a DID identifier as its identity. The DID identifier can be obtained through the issuer field (URI address) in the VC, and its public key can be obtained through the corresponding DID document. The digital signature of the VC is verified through public key verification, thereby achieving VC verification.
[0210] 4. Blockchain
[0211] Blockchain networks are essentially a distributed ledger technology. Due to their consensus and cryptographic mechanisms, they can ensure that the data on the chain is not tampered with, thus providing a trust endorsement for the data.
[0212] Future 6G networks will see the coexistence of numerous subnetworks (e.g., edge networks, enterprise private networks, campus networks), operating independently or supporting interconnection. When mobile 6G network users need to connect to different distributed subnetworks to obtain 6G network services due to changes in time and location, there is currently no solution for how 6G networks can provide a unified mechanism to achieve (re)authentication and authorization of user identities across various subnetworks, and how authentication will occur between different subnetworks.
[0213] This application provides access control methods, apparatus, network devices, and user equipment to address the current lack of solutions for how to implement user authentication and authorization in each subnetwork and how to authenticate between subnetworks in future 6G networks. The methods and apparatus (or network devices or user equipment) are based on the same concept. Since the principles underlying the problems solved by the methods and apparatus (or network devices or user equipment) are similar, their implementations can be mutually referenced, and repeated details will not be elaborated further.
[0214] like Figure 5 As shown, an embodiment of this application provides an access control method applied to a first network device in a first subnet. Optionally, the first subnet may be a distributed subnet in a 6G network.
[0215] The method includes the following steps:
[0216] Step 51: The first network device receives the first information or the second information.
[0217] Optionally, the first network device receiving the first information may be the first network device receiving the first information of the user equipment, or the first network device receiving the first information of the first user equipment forwarded by the second user equipment, or the first network device receiving the first information of the user equipment forwarded by other network devices, etc. The embodiments of this application are not limited thereto.
[0218] Optionally, the first information includes one of the following:
[0219] The first DID identifier corresponding to the user equipment and the authentication information related to the user equipment;
[0220] The user equipment's first DID identifier, authentication-related information, and authorization-related information.
[0221] For example, if the first information includes a first DID identifier corresponding to the user equipment and authentication-related information for the user equipment, the first information can be used for authenticating the user equipment. As another example, if the first information includes a first DID identifier corresponding to the user equipment, authentication-related information for the user equipment, and authorization-related information for the user equipment, the first information can be used for both authentication and authorization of the user equipment.
[0222] Optionally, the first network device receiving the second information may be that the first network device receives the second information of the second subnet from a second network device in the second subnet, or the first network device receives the second information of the second subnet forwarded by a network device in another subnet, etc. The embodiments of this application are not limited thereto.
[0223] Optionally, the second subnet can be a distributed subnet in a 6G network, and the first and second subnets are different distributed subnets in the 6G network. The first and second subnets may belong to the same central network or different central networks, etc., and this embodiment is not limited thereto.
[0224] Optionally, the second information includes a second DID identifier corresponding to the second subnet and information related to the authentication of the second subnet. For example, the second information can be used to authenticate the second subnet.
[0225] Step 52: The first network device performs authentication of the user equipment based on the first information, or performs authentication and authorization of the user equipment based on the first information, or performs authentication of the second subnet based on the second information.
[0226] Optionally, if the first information includes a first DID identifier corresponding to the user equipment and information related to the authentication of the user equipment, the first network device may perform authentication of the user equipment based on the first information.
[0227] Optionally, if the first information includes a first DID identifier corresponding to the user equipment, authentication-related information of the user equipment, and authorization-related information of the user equipment, the first network device may perform authentication and authorization of the user equipment based on the first information.
[0228] Optionally, if the second information includes the second DID identifier corresponding to the second subnet and information related to the authentication of the second subnet, the first network device may perform authentication of the second subnet based on the second information.
[0229] It should be noted that the first network device can support authenticating user equipment or authenticating and authorizing user equipment based on the first information. And / or, the first network device can support authenticating the second subnet based on the second information.
[0230] It should also be noted that, in addition to supporting authentication of the second subnet based on the second information, the first network device can also support sending third information to the second network device of the second subnet for the second network device to authenticate the first subnet. For example, the third information includes the DID identifier of the first subnet and information related to the authentication of the first subnet, etc., but this embodiment is not limited thereto.
[0231] In the above scheme, the first network device in the first subnet can support authenticating user equipment (UE) or authenticating and authorizing UE based on the first information. Alternatively, the first network device can support authenticating the second subnet based on the second information. This achieves UE authentication and authorization by distributed subnets in the 6G network, enables authentication between different distributed subnets in the 6G network, avoids network pressure caused by the central network in the 6G network participating in authentication and authorization in real time, and reduces communication latency for UEs.
[0232] Optionally, the first DID identifier is configured by the central network to which the first subnet belongs, and / or the second DID identifier is configured by the central network to which the second subnet belongs.
[0233] For example, the central network can be the central network in a 6G network, and the first subnet and the second subnet are different distributed subnets in the 6G network. The first subnet and the second subnet can belong to the same central network or different central networks.
[0234] For example, see [link to previous article] Figure 1 As shown, a central network can have multiple distributed subnetworks, meaning multiple distributed subnetworks can belong to the central network. After each distributed subnetwork confirms the identity of the central network, the central network is trusted by each distributed subnetwork. Optionally, the central network can configure a corresponding DID identifier for each distributed subnetwork; that is, the second DID identifier for the second subnetwork can be configured by the central network to which the second subnetwork belongs.
[0235] For example, the central network generates DID identifiers and DID documents for each distributed sub-network. The central network also maintains the DID documents for each distributed sub-network, performing operations such as modifying, deleting, or adding DID documents. Optionally, only the central network may have permission to perform these operations; for example, a smart contract may be configured so that only the home network can write to the DID document of the user device. This embodiment is not limited to this.
[0236] The central network sends the DID identifiers and corresponding private keys of each distributed subnetwork to user devices for storage, and uploads the DID identifiers and DID documents (wherein the DID identifier contains the user device's public key) to the blockchain network. Distributed subnetworks belonging to the central network can query the blockchain network for the DID documents of other distributed subnetworks using their respective DID identifiers. Optionally, both the central network and the distributed subnetworks can act as nodes in the blockchain network, registered in the blockchain network through a proxy server. Alternatively, the central network and the distributed subnetworks can also be nodes independent of the blockchain network, such as clients connected to blockchain nodes, etc., and this embodiment is not limited thereto.
[0237] Optionally, the access control method further includes: the first network device receiving a DID identifier corresponding to the first subnet from a third network device of the central network to which the first subnet belongs. That is, the DID identifier corresponding to the first subnet can be configured by the central network of the first subnet.
[0238] For example, if a user equipment (UE) can subscribe to a central network, the central network can configure a corresponding DID identifier for the UE. For instance, if a first subnet belongs to the central network, the UE can access the first subnet based on the DID identifier configured by the central network. In other words, the UE's first DID identifier is configured by the central network to which the first subnet belongs.
[0239] For example, a user device (User Equipment) is subscribed to a central network, which generates a DID identifier and a DID document for the User Equipment. The DID identifier corresponds one-to-one with the user's identity. The central network maintains the DID document for the User Equipment, performing operations such as modification, deletion, and addition. Optionally, only the central network may have permission to perform these operations; for example, a smart contract can be configured to allow only the home network to write to the User Equipment's DID document. This embodiment is not limited to this.
[0240] The central network sends the user device's DID identifier and corresponding private key to the user device for storage, and uploads the DID identifier and DID document (wherein the DID identifier contains the user device's public key) to the blockchain network. Distributed sub-networks belonging to this central network can query the user device's DID document from the blockchain network using the user device's DID identifier. Optionally, both the central network and the distributed sub-networks can act as nodes in the blockchain network, registered through a proxy server. Alternatively, the central network and the distributed sub-networks can also be nodes independent of the blockchain network, such as clients connected to blockchain nodes; this embodiment is not limited to these limitations.
[0241] Optionally, the information related to the authentication of the user equipment includes at least one of the following:
[0242] First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier;
[0243] The request information consists of plaintext and a second encrypted information encrypted using the user equipment's private key. For example, the plaintext request information may be plaintext information related to the user equipment's access request and / or authentication request, or other request-related information. The second encrypted information corresponds to the plaintext request information. For instance, if the plaintext request information is plaintext information related to the user equipment's access request, then the second encrypted information may be encrypted information related to the user equipment's access request, etc. This embodiment is not limited to this.
[0244] For example, the first information may include a first DID identifier corresponding to the user equipment and the first encrypted information. Alternatively, the first information may include a first DID identifier corresponding to the user equipment, plaintext request information, and the second encrypted information.
[0245] Optionally, the information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature.
[0246] Optionally, the information related to the authentication of the second subnet includes at least one of the following:
[0247] The third encrypted information is obtained by encrypting the second DID identifier using the private key of the second subnet's identity.
[0248] The request information consists of plaintext and a fourth encrypted information, which is encrypted using the private key of the second subnet's identity. For example, the plaintext request information may be plaintext information related to service requests and / or authentication requests of the second subnet, or other request-related information. The fourth encrypted information corresponds to the plaintext request information. For instance, if the plaintext request information is plaintext information related to an authentication request of the second subnet, then the fourth encrypted information may be encrypted information related to the authentication request of the second subnet. This embodiment of the application is not limited to this.
[0249] For example, the second information may include the second DID identifier corresponding to the second subnet and the third encrypted information. Alternatively, the second information may include the second DID identifier corresponding to the second subnet, the plaintext request information, and the fourth encrypted information.
[0250] It should be noted that, for ease of distinction, the plaintext request information carried in the first information can also be called the first request information plaintext, and the plaintext request information carried in the second information can also be called the second request information plaintext.
[0251] Optionally, the first network device performs authentication of the user equipment based on the first information, including:
[0252] The first network device queries the blockchain network device for the identity public key of the user device based on the first DID identifier;
[0253] The first network device decrypts the first encrypted information to obtain first decrypted information based on the identity public key of the user equipment, and / or decrypts the second encrypted information to obtain second decrypted information;
[0254] The first network device determines the authentication result of the user equipment based on the decryption information and the plaintext information; wherein the decryption information and the plaintext information include at least one combination of the following:
[0255] The first decryption information and the first DID identifier;
[0256] The second decryption information and the request information in plaintext.
[0257] For example, taking a user equipment (UE) needing to access a first subnet as an example, the first information sent by the UE to the first network device of the first subnet includes: a first DID identifier corresponding to the UE and the first encrypted information. The first network device can query the UE's public key from the blockchain network device based on the first DID identifier in the first information. For example, the first network device can query the blockchain network device for the DID document corresponding to the first DID identifier, which carries the UE's public key. The first network device can then decrypt the first encrypted information using the UE's public key to obtain first decrypted information (i.e., the decrypted first DID identifier). Finally, the first network device determines the UE's authentication result based on the first decrypted information (i.e., the decrypted first DID identifier) and the first DID identifier.
[0258] For example, taking a user device's need to access a first subnet as an example, the first information sent by the user device to the first network device of the first subnet includes: a first DID identifier corresponding to the user device, plaintext request information, and second encrypted information. The first network device can query the user device's identity public key from the blockchain network device based on the first DID identifier in the first information. For example, the first network device can query the blockchain network device for the DID document corresponding to the first DID identifier, which carries the user device's identity public key. The first network device decrypts the second encrypted information using the user device's identity public key to obtain second decrypted information (i.e., the decrypted request information). The first network device determines the authentication result of the user device based on the second decrypted information (i.e., the decrypted request information) and the plaintext request information.
[0259] Optionally, the first network device determines the authentication result of the user equipment based on the decrypted information and the plaintext information, including:
[0260] If the decrypted information and the plaintext information are consistent, the first network device determines that the authentication result indicates that the user equipment's identity is legitimate.
[0261] And / or,
[0262] If the decrypted information and the plaintext information do not meet the consistency requirement, the first network device determines that the authentication result indicates that the user equipment's identity is illegitimate.
[0263] For example, the decryption information and the plaintext information include: the first decryption information and the first DID identifier. That is, when the decryption information is the first decryption information and the plaintext information is the first DID identifier, the first decryption information (i.e., the decrypted first DID identifier) and the first DID identifier are compared for consistency. If the first decryption information (i.e., the decrypted first DID identifier) and the first DID identifier are consistent, the first network device determines that the authentication result is that the user equipment's identity is legitimate; and / or, if the first decryption information (i.e., the decrypted first DID identifier) and the first DID identifier are not consistent, the first network device determines that the authentication result is that the user equipment's identity is illegitimate. That is, the first network device determines the authentication result of the user equipment based on the first decryption information (i.e., the decrypted first DID identifier) and the first DID identifier.
[0264] For example, the decrypted information and the plaintext information include: the second decrypted information and the plaintext request information. That is, when the decrypted information is the second decrypted information and the plaintext request information is the plaintext request information, the second decrypted information (i.e., the decrypted request information) and the plaintext request information are compared for consistency. If the second decrypted information (i.e., the decrypted request information) and the plaintext request information are consistent, the first network device determines that the authentication result indicates the user equipment's identity is legitimate; and / or, if the second decrypted information (i.e., the decrypted request information) and the plaintext request information are inconsistent, the first network device determines that the user equipment's identity is illegitimate. In other words, the first network device determines the user equipment's authentication result based on the second decrypted information (i.e., the decrypted request information) and the plaintext request information.
[0265] Optionally, the first network device performs authorization of the user equipment based on the first information, including:
[0266] The first network device determines the first identity public key based on the third DID identifier carried in the verifiable claim plaintext;
[0267] The first network device decrypts the verifiable declaration digital signature based on the first identity public key to obtain the third decryption information;
[0268] The first network device determines the authorization result of the user equipment based on the third decryption information and the verifiable declaration plaintext.
[0269] For example, when a user equipment (UE) accesses a first subnet, the verifiable claim information in the authorization-related information sent to the first network device can be issued by the first subnet, the central network, or a third subnet associated with the first subnet (e.g., if the first subnet is a subordinate subnet of the third subnet, the verifiable claim information issued by the third subnet to the UE can be used to access the first subnet). Optionally, the verifiable claim carries the issuer's DID identifier. Based on the issuer's DID identifier, the corresponding identity public key (i.e., the first identity public key) can be obtained, which is used to verify the digital signature of the verifiable claim.
[0270] The following explains the process of determining the primary identity public key in different situations:
[0271] Optionally, the first network device determines the identity public key based on the third DID identifier carried in the plaintext of the verifiable claim, including at least one of the following:
[0272] Case 1: If the third DID identifier is the DID identifier corresponding to the first subnet, then the first identity public key is determined to be the identity public key of the first subnet.
[0273] For example, when a user device receives a verifiable claim (including VC metadata, Claims, and proof) issued by a first subnet, it sends authorization-related information to the first network device when accessing the first subnet. This verifies the plaintext of the claim (including VC metadata and / or Claims) and the digital signature of the verifiable claim (i.e., proof). The first network device determines that the issuer of the verifiable claim is the first subnet based on the third DID identifier carried in the plaintext of the verifiable claim. If the first subnet knows its own identity public key (e.g., the central network has provided the corresponding identity public key when configuring the DID identifier for the first subnet), then the first subnet can directly determine that the identity public key used for signature verification (i.e., the first identity public key) is the identity public key of the first subnet. Alternatively, if the first subnet does not know its own identity public key (e.g., the central network did not provide the corresponding identity public key when configuring the DID identifier for the first subnet), then the first subnet can query its own identity public key from the blockchain network to verify the digital signature of the verifiable claim sent by the user device.
[0274] Scenario 2: If the third DID identifier is the DID identifier corresponding to the central network to which the first subnet belongs, the first network device queries the blockchain network device for the identity public key of the central network based on the third DID identifier, and determines that the first identity public key is the identity public key of the central network.
[0275] For example, when a user equipment (UE) receives a verifiable claim (including VC metadata, Claims, and proof) issued by a central network, and the UE accesses a first subnet, it sends authorization-related information to the first network device, which can verify the plaintext of the claim (including VC metadata and / or Claims) and the digital signature of the verifiable claim (i.e., proof). The first network device determines the issuer of the verifiable claim to be the central network to which the first subnet belongs based on the third DID identifier carried in the plaintext of the verifiable claim. It can then use this third DID identifier to query the blockchain network device for the identity public key of the central network (i.e., the first identity public key of the claim issuer) to verify the digital signature of the verifiable claim sent by the UE.
[0276] Scenario 3: If the third DID identifier is the DID identifier corresponding to the third subnet associated with the first subnet, the first network device queries the blockchain network device for the identity public key of the third subnet based on the third DID identifier, and determines that the first identity public key is the identity public key of the third subnet.
[0277] For example, a user device obtains a verifiable claim (e.g., including VC metadata, Claims, and proof) issued by a third subnet (e.g., when the first subnet is a subordinate subnet of the third subnet, the verifiable claim information issued by the third subnet to the user device can be used to access the first subnet). When the user device accesses the first subnet, it sends authorization-related information to the first network device, which can verify the plaintext of the claim (e.g., including VC metadata and / or Claims) and the digital signature of the verifiable claim (i.e., proof). The first network device determines that the issuer of the verifiable claim is the third subnet based on the third DID identifier carried in the plaintext of the verifiable claim. It can then use this third DID identifier to query the blockchain network device for the identity public key of the third subnet (i.e., the first identity public key of the claim issuer) to verify the digital signature of the verifiable claim sent by the user device.
[0278] Optionally, the first network device determines the authorization result of the user equipment based on the third decryption information and the verifiable claim plaintext, including:
[0279] If the third decryption information and the plaintext of the verifiable declaration are consistent, then the first network device determines that the authorization result is authorized.
[0280] And / or,
[0281] If the third decryption information and the verifiable declaration plaintext do not meet the consistency requirement, the first network device determines that the authorization result is an authorization failure.
[0282] Specifically, when the first identity public key is determined based on at least one of the above situations 1 to 3, the digital signature of the verifiable claim sent by the user equipment is decrypted based on the issuer's first identity public key to obtain third decrypted information (i.e., the decrypted verifiable claim), and the third decrypted information (i.e., the decrypted verifiable claim) is compared with the plaintext of the verifiable claim. If the third decrypted information (i.e., the decrypted verifiable claim) and the plaintext of the verifiable claim are consistent, the first network device determines that the authorization result is successful; and / or, if the third decrypted information (i.e., the decrypted verifiable claim) and the plaintext of the verifiable claim are not consistent, the first network device determines that the authorization result is unsuccessful.
[0283] The following describes the pre-defined process for verifiable claims (i.e., how user equipment obtains verifiable claims):
[0284] Optionally, the access control method further includes at least one of the following:
[0285] Method 1: When the first network device determines that the user equipment's identity is legitimate, it sends a first message to a third network device in the central network to which the first subnet belongs; wherein the first message is used to request a verifiable statement for the user equipment, and the verifiable statement is used to access at least one subnet belonging to the central network.
[0286] For example: A user equipment (UE) initially registers in a first subnet. The first subnet verifies the UE's identity in the central network (for the specific authentication process of the UE, please refer to the above embodiment). If the first subnet verifies the UE's identity as legitimate, it can forward the UE's verifiable statement acquisition request to the central network (i.e., send a first message to a third network device in the central network to which the first subnet belongs). The central network then issues a verifiable statement to the UE. For example, if the UE has a subscription to the central network, the central network can issue a verifiable statement to the UE for accessing one or more subnets based on the UE's subscription information.
[0287] Method 2: The first network device sends a second message to the third network device; wherein the second message is used to request authentication of the user equipment and to provide a verifiable claim for the user equipment, the verifiable claim being used to access at least one subnet belonging to the central network.
[0288] For example, when a user equipment (UE) initiates registration with a first subnet, the first subnet requests the central network to verify the UE's identity within that network and to forward a request for a verifiable statement from the UE to the central network. The central network then authenticates the UE (the specific authentication process can be found in the above embodiment). If the central network verifies the UE's legitimacy, it can issue a verifiable statement to the UE. For instance, if the UE has a subscription with the central network, the central network can issue a verifiable statement for accessing one or more subnets based on the UE's subscription information.
[0289] It should be noted that the verifiable claim issued by the central network to the user equipment can be used to access at least one subnet belonging to the central network. Here, one verifiable claim can be used to access one subnet or multiple subnets. The at least one subnet belonging to the central network may or may not include the first subnet. For example, the central network may issue a verifiable claim to the user equipment only for accessing the first subnet, or the central network may issue a verifiable claim to the user equipment for accessing the first subnet and verifiable claims for accessing other subnets, or the central network may issue one or more verifiable claims to the user equipment for accessing one or more subnets other than the first subnet, etc. The embodiments of this application are not limited to this.
[0290] Optionally, the access control method further includes:
[0291] The first network device sends a third message to a third network device in the central network to which the first subnet belongs; wherein the third message is used to request authentication of the user equipment;
[0292] The first network device receives a response message from the third network device to the third message; wherein the response message is used to indicate the authentication result of the user equipment;
[0293] The first network device sends a verifiable declaration to the user equipment based on the response message;
[0294] The verifiable statement is used to access the first subnet and / or to access the third subnet associated with the first subnet.
[0295] For example, when a user equipment (UE) requests a verifiable claim from a first subnet for accessing the first subnet and / or a third subnet associated with the first subnet, since the UE is subscribed to a central network, the first subnet can request the central network to authenticate the UE (i.e., the first network device sends a third message to a third network device in the central network to which the first subnet belongs). The central network then authenticates the UE, and can inform the first subnet of the authentication result (i.e., the first network device receives a response message from the third network device to the third message).
[0296] Optionally, the authentication result can be used to indicate whether the user equipment's identity is legitimate, and / or, the authentication result can be used to indicate whether the verifiable claim is allowed to be provided to the user equipment. For example, the central network can verify the legitimacy of the user equipment's identity (see the above embodiments for details), and / or, based on the user's subscription information, determine whether the user equipment can obtain authorization from the first subnet, thereby determining whether the first subnet is allowed to provide the verifiable claim to the user equipment. For example, the user equipment's subscription information in the central network includes support for providing service 1 and service 2. If the central network determines that the first subnet supports providing service 3, it can notify the first subnet that the verifiable claim is not allowed to be provided to the user equipment; or if the first subnet supports providing service 1, the central network can notify the first subnet that the verifiable claim is allowed to be provided to the user equipment, etc. Of course, the embodiments of this application are not limited thereto.
[0297] For example, if the authentication result indicates that the user equipment's identity is legitimate (e.g., there is no indication of whether the verifiable claim is allowed for the user equipment), then the first network device can determine, based on the response message, that it can send the verifiable claim to the user equipment. Alternatively, if the authentication result indicates that the verifiable claim is allowed for the user equipment (e.g., there is no explicit indication of whether the user equipment's identity is legitimate), then the first network device can determine, based on the response message, that the user equipment's identity is legitimate and that it can send the verifiable claim to the user equipment.
[0298] It should be noted that the verifiable claims issued by the central network or distributed sub-network (such as the first sub-network) to the user equipment may include VC metadata, Claims, proof, etc., that is, information such as issuer, issuance date, and type of claim; one or more descriptions about the subject; digital signature of the issuer, etc., but this application embodiment is not limited thereto.
[0299] Optionally, the first network device performs authentication of the second subnet based on the second information, including:
[0300] The first network device queries the identity public key of the second subnet from the blockchain network device through the proxy server based on the second DID identifier;
[0301] The first network device decrypts the third encrypted information to obtain the third decrypted information based on the identity public key of the second subnet, and / or decrypts the fourth encrypted information to obtain the fourth decrypted information;
[0302] The first network device determines the authentication result of the second subnet based on the decryption information and the plaintext information; wherein the decryption information and the plaintext information include at least one combination of the following:
[0303] The third decryption information and the second DID identifier;
[0304] The fourth decryption information and request information are in plaintext.
[0305] For example, taking cross-subnet services, such as a second subnet requesting a service from a first subnet, the second information sent by the second subnet to the first network device of the first subnet includes: a second DID identifier corresponding to the second subnet and the third encrypted information. The first network device can query the blockchain network device for the identity public key of the second subnet based on the second DID identifier in the second information. For example, the first network device can query the blockchain network device for the DID document corresponding to the second DID identifier, which carries the identity public key of the second subnet. The first network device decrypts the third encrypted information using the identity public key of the second subnet to obtain third decrypted information (i.e., the decrypted second DID identifier). The first network device determines the authentication result of the second subnet based on the third decrypted information (i.e., the decrypted second DID identifier) and the second DID identifier.
[0306] For example, taking cross-subnet services, such as a second subnet requesting a service from a first subnet, the second information sent by the second subnet to the first network device of the first subnet includes: a second DID identifier corresponding to the second subnet, plaintext request information, and the fourth encrypted information. The first network device can query the blockchain network device for the identity public key of the second subnet based on the second DID identifier in the second information. For example, the first network device can query the blockchain network device for the DID document corresponding to the second DID identifier, which carries the identity public key of the second subnet. The first network device decrypts the fourth encrypted information to obtain fourth decrypted information (i.e., the decrypted request information) based on the identity public key of the user device. The first network device determines the authentication result of the user device based on the fourth decrypted information (i.e., the decrypted request information) and the plaintext request information.
[0307] Optionally, the first network device determines the authentication result of the second subnet based on the decrypted information and the plaintext information, including:
[0308] If the decrypted information and the plaintext information are consistent, the first network device determines that the authentication result is valid for the identity of the second subnet.
[0309] And / or,
[0310] If the decrypted information and the plaintext information do not meet the consistency requirement, the first network device determines that the authentication result indicates that the identity of the second subnet is illegitimate.
[0311] For example, the decryption information and the plaintext information include: the third decryption information and the second DID identifier. That is, when the decryption information is the third decryption information and the plaintext information is the second DID identifier, the third decryption information (i.e., the decrypted second DID identifier) and the second DID identifier are compared for consistency. If the third decryption information (i.e., the decrypted second DID identifier) and the second DID identifier are consistent, the first network device determines that the authentication result is that the identity of the second subnet is legitimate; and / or, if the third decryption information (i.e., the decrypted second DID identifier) and the second DID identifier are not consistent, the first network device determines that the authentication result is that the identity of the second subnet is illegitimate. That is, the first network device determines the authentication result of the second subnet based on the third decryption information (i.e., the decrypted second DID identifier) and the second DID identifier.
[0312] For example, the decrypted information and the plaintext information include: the fourth decrypted information and the plaintext request information. That is, when the decrypted information is the fourth decrypted information and the plaintext request information is the plaintext request information, the fourth decrypted information (i.e., the decrypted request information) and the plaintext request information are compared for consistency. If the fourth decrypted information (i.e., the decrypted request information) and the plaintext request information are consistent, the first network device determines that the authentication result is that the identity of the second subnet is legitimate; and / or, if the fourth decrypted information (i.e., the decrypted request information) and the plaintext request information are inconsistent, the first network device determines that the authentication result is that the identity of the second subnet is illegitimate. That is, the first network device determines the authentication result of the user equipment based on the fourth decrypted information (i.e., the decrypted request information) and the plaintext request information.
[0313] It should be noted that the embodiments of this application can also support a first subnet requesting services from a second subnet. For example, the first subnet sends third information to the second subnet for the second network device to authenticate the first subnet. For example, the third information includes the DID identifier of the first subnet and information related to the authentication of the first subnet. Specifically, the authentication process of the second subnet to the first subnet is similar to the authentication process of the first subnet to the second subnet described above, and will not be repeated here to avoid repetition.
[0314] It should also be noted that, for ease of distinction, the decryption information involved in the above authentication embodiments for user equipment can be referred to as the first target decryption information, and the plaintext information involved can be referred to as the first target plaintext information; the decryption information involved in the above authentication embodiments for the second subnet can be referred to as the second target decryption information, and the plaintext information involved can be referred to as the second target plaintext information.
[0315] The first network device involved in this application embodiment can be a base station, which may include multiple cells providing services to terminals. Depending on the specific application, the base station may also be called an access point, or a device in the access network that communicates with the wireless terminal device through one or more sectors on the air interface, or other names. The network device can be used to exchange received air frames with Internet Protocol (IP) packets, acting as a router between the wireless terminal device and the rest of the access network, where the rest of the access network may include an Internet Protocol (IP) communication network. The network device can also coordinate the attribute management of the air interface. For example, the network equipment involved in the embodiments of this application can be a base transceiver station (BTS) in a Global System for Mobile communications (GSM) or Code Division Multiple Access (CDMA), a NodeB in a Wide-band Code Division Multiple Access (WCDMA) system, an evolved Node B (eNB or e-NodeB) in a long term evolution (LTE) system, a 5G base station (gNB) in a next generation system, a Home evolved Node B (HeNB), a relay node, a femto, a pico, etc., and is not limited in the embodiments of this application. In some network structures, the network equipment may include centralized unit (CU) nodes and distributed unit (DU) nodes, and the centralized unit and distributed unit may be geographically separated.
[0316] like Figure 6 As shown in the figure, this application provides an access control method, including the following steps:
[0317] Step 61: The user equipment sends first information to the first network device of the first subnet; wherein the first information includes one of the following:
[0318] The first decentralized identity (DID) identifier corresponding to the user equipment and the authentication-related information of the user equipment;
[0319] The user equipment includes a first DID identifier, authentication information related to the user equipment, and authorization information related to the user equipment.
[0320] Optionally, before the user equipment sends the first information to the first network device of the first subnet, it further includes:
[0321] The user equipment receives the first DID identifier sent by the third network device of the central network to which the first subnet belongs.
[0322] Optionally, the information related to the authentication of the user equipment includes at least one of the following:
[0323] First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier;
[0324] The request message in plaintext and a second encrypted message encrypted using the user equipment's private key;
[0325] or,
[0326] The information related to the authorization of the user equipment includes: the plaintext of the verifiable claim and the digital signature of the verifiable claim.
[0327] Optionally, the access control method further includes at least one of the following:
[0328] The user equipment receives a verifiable statement plaintext sent by the first network device;
[0329] The user equipment receives a verifiable statement plaintext sent by a third network device of the central network to which the first subnet belongs;
[0330] The verifiable declaration states that a plaintext user accesses at least one subnet belonging to the central network.
[0331] It should be noted that the access control method on the user equipment side in this application embodiment and the access control method on the first network device side described above are based on the same inventive concept. The two embodiments can refer to each other and can achieve the same technical effect. To avoid repetition, they will not be described again here.
[0332] The user equipment involved in the embodiments of this application includes, but is not limited to, terminal equipment, such as devices that provide voice and / or data connectivity to users, handheld devices with wireless connectivity, or other processing devices connected to a wireless modem. The name of the terminal equipment may differ in different systems; for example, in a 5G system, the terminal equipment may be called User Equipment (UE). Wireless terminal equipment can communicate with one or more core networks (CNs) via a Radio Access Network (RAN). Wireless terminal equipment can be mobile terminal equipment, such as mobile phones (or "cellular" phones) and computers with mobile terminal equipment, for example, portable, pocket-sized, handheld, computer-embedded, or vehicle-mounted mobile devices, which exchange voice and / or data with the RAN. Examples include Personal Communication Service (PCS) phones, cordless phones, Session Initiated Protocol (SIP) phones, Wireless Local Loop (WLL) stations, and Personal Digital Assistants (PDAs). Wireless terminal equipment can also be referred to as a system, subscriber unit, subscriber station, mobile station, mobile station, remote station, access point, remote terminal, access terminal, user terminal, user agent, or user device, but is not limited to these terms in the embodiments of this application.
[0333] like Figure 7 As shown, an embodiment of this application provides an access control method applied to a third network device in a central network. The method includes the following steps:
[0334] Step 71: The third network device sends the first DID identifier corresponding to the user equipment to the user equipment, and / or sends the second DID identifier corresponding to the second subnet to the second network device of the second subnet;
[0335] The second subnet belongs to the central network.
[0336] Optionally, the information related to the authentication of the user equipment includes at least one of the following:
[0337] First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier;
[0338] The request message in plaintext and a second encrypted message encrypted using the user equipment's private key;
[0339] or,
[0340] The information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature;
[0341] or,
[0342] The information related to the authentication of the second subnet includes at least one of the following:
[0343] The third encrypted information is obtained by encrypting the second DID identifier using the private key of the second subnet's identity.
[0344] The request message is in plaintext and a fourth encrypted message is generated by encrypting the request message using the private key of the identity of the second subnet.
[0345] Optionally, the access control method further includes:
[0346] The third network device receives a first message sent by the first network device of the first subnet; wherein the first message is used to request a verifiable claim for the user equipment;
[0347] The third network device sends a verifiable statement to the user equipment based on the user equipment's subscription information;
[0348] The first subnet belongs to the central network, and the verifiable declaration is used to access at least one subnet belonging to the central network.
[0349] Optionally, the access control method further includes:
[0350] The third network device receives a second message sent by the first network device of the first subnet; wherein the second message is used to request authentication of the user equipment and to provide a verifiable claim for the user equipment;
[0351] The third network device authenticates the user equipment based on the second message and determines the authentication result;
[0352] If the authentication result confirms that the user equipment's identity is legitimate, the third network device sends a verifiable declaration to the user equipment based on the user equipment's subscription information.
[0353] The first subnet belongs to the central network, and the verifiable declaration is used to access at least one subnet belonging to the central network.
[0354] Optionally, the access control method further includes:
[0355] The third network device receives a third message sent by the first network device in the first subnet; wherein the third message is used to request authentication of the user equipment; wherein the first subnet belongs to the central network;
[0356] The third network device authenticates the user equipment based on the third message and determines the authentication result;
[0357] The third network device sends a response message to the first network device for the third message; wherein the response message is used to indicate the authentication result of the user equipment.
[0358] Optionally, the authentication result is used to indicate whether the identity of the user equipment is legitimate, and / or, the authentication result is used to indicate whether the verifiable claim is allowed to be provided to the user equipment.
[0359] It should be noted that the access control method on the third network device side in this application embodiment is based on the same inventive concept as the access control method on the first network device side described above. The two embodiments can refer to each other and can achieve the same technical effect. To avoid repetition, they will not be described again here.
[0360] The third network device involved in this application embodiment can be a base station, which may include multiple cells providing services to terminals. Depending on the specific application, the base station may also be called an access point, or a device in the access network that communicates with the wireless terminal device through one or more sectors on the air interface, or other names. The network device can be used to exchange received air frames with Internet Protocol (IP) packets, acting as a router between the wireless terminal device and the rest of the access network, where the rest of the access network may include an Internet Protocol (IP) communication network. The network device can also coordinate the attribute management of the air interface. For example, the network equipment involved in the embodiments of this application can be a base transceiver station (BTS) in a Global System for Mobile communications (GSM) or Code Division Multiple Access (CDMA), a NodeB in a Wide-band Code Division Multiple Access (WCDMA) system, an evolved Node B (eNB or e-NodeB) in a long term evolution (LTE) system, a 5G base station (gNB) in a next generation system, a Home evolved Node B (HeNB), a relay node, a femto, a pico, etc., and is not limited in the embodiments of this application. In some network structures, the network equipment may include centralized unit (CU) nodes and distributed unit (DU) nodes, and the centralized unit and distributed unit may be geographically separated.
[0361] The access control method of this application will be described below with reference to specific embodiments:
[0362] Example 1: DID Identification Format
[0363] The format of the DID identifier is as follows:
[0364] did: <did-method>:<DID method-specific identifier>
[0365] Where did-method is a method used, such as DTmethod-1;
[0366] The DID method-specific identifier is <network information> + <user information ciphertext>, where network information in this embodiment refers to the name of the central network (in plaintext), and user information can be personal information such as user identity, obtained through hash calculation.
[0367] Example 2: User Equipment Authentication
[0368] like Figure 8 and Figure 9 As shown, the user equipment authentication process includes the following steps:
[0369] Step 91: When a user equipment needs to access distributed subnet 1, it can present the user equipment's DID identifier, the plaintext of the access request, and the access request encrypted with the user equipment's corresponding identity private key.
[0370] Step 92: Distributed subnet 1 uses the DID identifier of the user device as the key in the key-value pair to search for the DID document corresponding to the DID identifier of the user device in the blockchain network.
[0371] Step 93: The blockchain network returns the DID document corresponding to the DID identifier of the user device, which contains the public key of the user device's identity.
[0372] Step 94: Distributed subnet 1 obtains the user equipment's public key, decrypts the encrypted access request using the user equipment's public key, and verifies the consistency between the decrypted access request and the plaintext access request. If they match, the user equipment's authentication is successful; if they do not match, the user equipment's authentication is deemed invalid, and the user equipment's access request is rejected.
[0373] Step 95: Distributed subnet 1 returns the authentication result to the user equipment.
[0374] Example 3: VC Authentication for User Equipment
[0375] like Figure 8 and Figure 10 As shown, the VC authentication process for user equipment includes the following steps:
[0376] The user equipment obtains a VC from the central network, meaning that the issuer of the VC is the central network. The VC indicates that the central network authorizes the user equipment to provide services in distributed subnet 1, such as service A.
[0377] Step 101: When a user equipment needs to obtain service A from distributed subnet 1, it can present the VC and the digital signature of the central network on the VC to distributed subnet 1.
[0378] Step 102: Distributed subnet 1 searches for the corresponding DID document in the blockchain network based on the issuer DID identifier in VC (i.e., the DID identifier of the central network).
[0379] Step 103: The blockchain network returns the DID document of the central network, which contains the identity public key of the central network.
[0380] Step 104: Distributed subnet 1 obtains the identity public key of the central network, verifies the digital signature of the VC by the central network based on the identity public key, and determines whether the decrypted VC is consistent with the plaintext VC sent by the user equipment. If they are consistent, the authorization is successful; if they are inconsistent, the authorization is unsuccessful and the authorization request of the user equipment is rejected.
[0381] Step 105: Distributed subnet 1 returns the authorization result to the user equipment.
[0382] Example 4:
[0383] When a user device (User Equipment) accesses distributed subnet 2, and authorization from distributed subnet 1 is required, the User Equipment can access distributed subnet 2 through the VC (Virtual Control Provider) used to access distributed subnet 1. In real-world scenarios, such as when distributed subnet 1 belongs to a specific industry application network and distributed subnet 2 is a subordinate subnet, User Equipment needs authorization from distributed subnet 1 to access distributed subnet 2. Figure 11 As shown, the specific process includes:
[0384] Step 111: The user equipment requests a VC from distributed subnet 1.
[0385] Step 112: Distributed subnet 1 requests the central network to verify the identity of the user equipment and determine whether the corresponding VC can be issued to the user equipment.
[0386] For example, the central network can authenticate user equipment and, based on the user's subscription information, determine whether the user equipment can obtain authorization from the distributed subnet 1, and return the authentication result to the distributed subnet.
[0387] Step 113: If the user equipment is successfully authenticated and is allowed to provide a VC, then the distributed subnet 1 can issue the corresponding VC to the user equipment.
[0388] Step 114: When a user equipment needs to access distributed subnet 2, it can send the VC issued by distributed subnet 1 to distributed subnet 2.
[0389] Step 115: Distributed subnet 2 verifies the VC in the blockchain network (specifically, the VC authentication process in embodiment 3 above can be used, which will not be repeated here), and returns the authorization result.
[0390] Example 5: Addition of Distributed Subnets
[0391] 6G networks support a plug-and-play network architecture, thus allowing for the addition of distributed subnets. For example, when adding a distributed subnet, the node information of the subnet also needs to be updated in the blockchain network. This involves the generation of the distributed subnet's DID identifier and the on-chain process of the DID document, specifically including:
[0392] The central network generates DID identifiers and DID documents for the distributed subnets it manages. The distributed subnets store the DID identifiers and the corresponding private keys. Optionally, the private keys corresponding to the DID identifiers of the distributed subnets can be stored in the first network element of the distributed subnet. For example, the first network element can be a network element belonging to the core network that is involved in authentication functions, or it can be other network elements, etc. This application embodiment does not make specific limitations.
[0393] The central network uploads the DID identifier and DID document (including identity public key) of the distributed subnet to the blockchain network and maintains the DID document of the distributed subnet node (such as modification, deletion, addition, etc.). Only the central network to which the distributed subnet belongs has the right to perform the above operations (for example, a smart contract can be set so that only the central network to which it belongs can perform write operations on the DID document of the distributed subnet).
[0394] Optionally, both the central network and the distributed subnets can serve as nodes in the blockchain network, or the central network and the distributed subnets can also be clients that can obtain services from the blockchain network and register in the blockchain network through a proxy server. This application embodiment is not limited to this.
[0395] Example 6: Authentication between distributed subnets
[0396] Distributed subnets are registered on the blockchain network. Unlike user devices, which can upload DID identifiers and DID documents to the blockchain network through the central network, distributed subnets can connect to the blockchain network through a proxy server. Distributed subnets can directly publish messages or download data on the blockchain network through the proxy server.
[0397] For example, cross-subnet services for user equipment require authentication between multiple distributed subnets to provide the corresponding services. Taking authentication between distributed subnet 1 and distributed subnet 2 as an example, distributed subnet 1 sends a DID identifier to distributed subnet 2, and distributed subnet 2 sends a DID identifier to distributed subnet 1. After both parties obtain each other's DID identifiers, they can download the corresponding DID document from the blockchain and authenticate each other's identities (specifically, the authentication process described in Example 2 above can be used). The central networks to which distributed subnet 1 and distributed subnet 2 belong can be the same or different.
[0398] like Figure 12 and Figure 13 As shown, the specific authentication process between distributed subnets includes the following steps:
[0399] Step 131: Distributed subnet 1 sends an authentication request to distributed subnet 2, which carries the DID identifier of distributed subnet 1 and a digital signature.
[0400] Step 132: Distributed subnet 2 requests the proxy server 2 to return the public key of the identity of distributed subnet 1 based on the DID identifier of distributed subnet 1.
[0401] Step 133: Proxy server 2 queries the blockchain network for the identity public key of distributed subnet 1, and the blockchain network returns the identity public key of distributed subnet 1.
[0402] For example, distributed subnet 2 queries the blockchain network through proxy server 2 for the DID document corresponding to the DID identifier of distributed subnet 1 based on the DID identifier of distributed subnet 1. This DID document carries the identity public key of distributed subnet 1.
[0403] Step 134: Proxy server 2 returns the identity public key of distributed subnet 1.
[0404] Step 135: Distributed subnet 2 uses the public key of distributed subnet 1 to decrypt the digital signature of distributed subnet 1 and authenticate the identity of distributed subnet 1.
[0405] Optionally, distributed subnet 2 can also send an authentication request to distributed subnet 1, which carries the DID identifier and digital signature of distributed subnet 2. The specific authentication process is similar to steps 132-135 above, and will not be repeated here.
[0406] In this way, distributed subnet 1 authenticates distributed subnet 2, and / or distributed subnet 2 authenticates distributed subnet 1, and if the authentication is successful, a trusted relationship is established between distributed subnet 1 and distributed subnet 2.
[0407] In this embodiment, distributed subnets do not need to pre-sign authorization; instead, they can establish trusted relationships through DID authentication. Compared to traditional mechanisms where different networks need to pre-sign authorization to support cross-network services, this approach offers greater flexibility.
[0408] In this embodiment of the application, under a distributed network architecture, user device authentication and authorization, as well as authentication between various distributed subnets, can be achieved based on the DID mechanism without relying on pre-established trust relationships. Furthermore, a blockchain technology based on distributed characteristics ensures the security of trust credentials through an authentication and service authorization mechanism. This scheme, based on the DID-based user authentication and service authorization mechanism and authentication between various distributed subnets, does not require pre-established trust relationships between networks, and the trust credentials are stored on the user side. Compared to roaming authentication technology in 5G networks, it reduces the real-time involvement of the home network. Moreover, the use of blockchain technology and its distributed storage characteristics improve authentication efficiency, while the immutability of the blockchain endorses the on-chain trust credentials and ensures their secure storage.
[0409] The above embodiments describe the access control method of this application. The following embodiments will further describe the corresponding devices, network devices and user devices in conjunction with the accompanying drawings.
[0410] like Figure 14 As shown, this embodiment provides an access control device applied to a first subnet, including a memory 141, a transceiver 142, and a processor 143; wherein, the memory 141 is used to store computer programs; the transceiver 142 is used to send and receive data under the control of the processor 143; for example, the transceiver 142 is used to receive and send data under the control of the processor 143; the processor 143 is used to read the computer program in the memory 141 and perform the following operations:
[0411] Receive the first message or the second message;
[0412] Authentication of the user equipment is performed based on the first information, or authentication and authorization of the user equipment are performed based on the first information, or authentication of the second subnet is performed based on the second information;
[0413] The first information includes one of the following:
[0414] The first decentralized identity (DID) identifier corresponding to the user equipment and the authentication-related information of the user equipment;
[0415] The first DID identifier corresponding to the user equipment, the authentication-related information of the user equipment, and the authorization-related information of the user equipment;
[0416] The second information includes the second DID identifier corresponding to the second subnet and information related to the authentication of the second subnet.
[0417] Optionally, the first DID identifier is configured by the central network to which the first subnet belongs, and / or the second DID identifier is configured by the central network to which the second subnet belongs.
[0418] Optionally, the information related to the authentication of the user equipment includes at least one of the following:
[0419] First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier;
[0420] The request message in plaintext and a second encrypted message encrypted using the user equipment's private key;
[0421] or,
[0422] The information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature;
[0423] or,
[0424] The information related to the authentication of the second subnet includes at least one of the following:
[0425] The third encrypted information is obtained by encrypting the second DID identifier using the private key of the second subnet's identity.
[0426] The request message is in plaintext and a fourth encrypted message is generated by encrypting the request message using the private key of the identity of the second subnet.
[0427] Optionally, the processor 143 is configured to read the computer program in the memory 141 and perform the following operations:
[0428] Based on the first DID identifier, query the blockchain network device for the identity public key of the user device;
[0429] Based on the user equipment's identity public key, the first encrypted information is decrypted to obtain the first decrypted information, and / or the second encrypted information is decrypted to obtain the second decrypted information;
[0430] The authentication result of the user equipment is determined based on the decrypted information and the plaintext information; wherein the decrypted information and the plaintext information include at least one combination of the following:
[0431] The first decryption information and the first DID identifier;
[0432] The second decryption information and the request information in plaintext.
[0433] Optionally, the processor 143 is configured to read the computer program in the memory 141 and perform the following operations:
[0434] If the decrypted information and the plaintext information are consistent, then the authentication result is determined to be that the user equipment is legitimate.
[0435] And / or,
[0436] If the decrypted information and the plaintext information do not meet the consistency requirement, then the authentication result is determined to be that the user equipment's identity is illegitimate.
[0437] Optionally, the processor 143 is configured to read the computer program in the memory 141 and perform the following operations:
[0438] The first identity public key is determined based on the third DID identifier carried in the plaintext of the verifiable claim;
[0439] Based on the first identity public key, the verifiable declaration digital signature is decrypted to obtain the third decryption information;
[0440] The authorization result of the user equipment is determined based on the third decryption information and the verifiable statement plaintext.
[0441] Optionally, the processor 143 is configured to read the computer program in the memory 141 and perform at least one of the following operations:
[0442] If the third DID identifier is the DID identifier corresponding to the first subnet, then the first identity public key is determined to be the identity public key of the first subnet;
[0443] If the third DID identifier is the DID identifier corresponding to the central network to which the first subnet belongs, the blockchain network device is queried for the identity public key of the central network based on the third DID identifier, and the first identity public key is determined to be the identity public key of the central network.
[0444] If the third DID identifier is the DID identifier corresponding to the third subnet associated with the first subnet, the blockchain network device is queried based on the third DID identifier to determine the identity public key of the third subnet, and the first identity public key is determined to be the identity public key of the third subnet.
[0445] Optionally, the processor 143 is configured to read the computer program in the memory 141 and perform the following operations:
[0446] If the third decryption information and the plaintext of the verifiable declaration are consistent, then the authorization result is determined to be authorized.
[0447] And / or,
[0448] If the third decryption information and the verifiable declaration plaintext do not meet the consistency requirement, then the authorization result is determined to be authorization failure.
[0449] Optionally, the processor 143 is configured to read the computer program in the memory 141 and perform at least one of the following operations:
[0450] If the identity of the user equipment is confirmed to be legitimate, a first message is sent to a third network device in the central network to which the first subnet belongs; wherein, the first message is used to request a verifiable statement for the user equipment;
[0451] Send a second message to the third network device; wherein the second message is used to request authentication of the user equipment and to provide a verifiable claim for the user equipment;
[0452] The verifiable claim is used to access at least one subnet belonging to the central network.
[0453] Optionally, the processor 143, for reading the computer program in the memory 141, also performs the following operations:
[0454] A third message is sent to a third network device in the central network to which the first subnet belongs; wherein the third message is used to request authentication of the user equipment;
[0455] Receive a response message from the third network device to the third message; wherein the response message is used to indicate the authentication result of the user equipment;
[0456] Based on the response message, a verifiable declaration is sent to the user equipment;
[0457] The verifiable statement is used to access the first subnet and / or to access the third subnet associated with the first subnet.
[0458] Optionally, the processor 143 is configured to read the computer program in the memory 141 and perform the following operations:
[0459] Based on the second DID identifier, query the identity public key of the second subnet from the blockchain network device through the proxy server;
[0460] Based on the identity public key of the second subnet, the third encrypted information is decrypted to obtain the third decrypted information, and / or the fourth encrypted information is decrypted to obtain the fourth decrypted information;
[0461] The authentication result of the second subnet is determined based on the decrypted information and the plaintext information; wherein the decrypted information and the plaintext information include at least one combination of the following:
[0462] The third decryption information and the second DID identifier;
[0463] The fourth decryption information and request information are in plaintext.
[0464] Optionally, the processor 143 is configured to read the computer program in the memory 141 and perform the following operations:
[0465] If the decrypted information and the plaintext information are consistent, then the authentication result is determined to be the legitimate identity of the second subnet.
[0466] And / or,
[0467] If the decrypted information and the plaintext information do not meet the consistency requirement, then the authentication result is determined to be that the identity of the second subnet is illegitimate.
[0468] Optionally, the processor 143, for reading the computer program in the memory 141, also performs the following operations:
[0469] Receive the DID identifier corresponding to the first subnet from the third network device of the central network to which the first subnet belongs.
[0470] Among them, Figure 14 In this context, the bus architecture may include any number of interconnected buses and bridges, specifically linking various circuits together, represented by one or more processors (processor 143) and memory (memory 141). The bus architecture may also link together various other circuits, such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. The transceiver 142 may be multiple elements, including transmitters and receivers, providing units for communicating with various other devices over transmission media, including wireless channels, wired channels, optical fibers, etc. The processor 143 is responsible for managing the bus architecture and general processing, and the memory 141 may store data used by the processor 143 during operation.
[0471] Optionally, the processor 143 can be a CPU (Central Processing Unit), an ASIC (Application Specific Integrated Circuit), an FPGA (Field-Programmable Gate Array), or a CPLD (Complex Programmable Logic Device), and the processor can also adopt a multi-core architecture.
[0472] The processor executes any of the methods described in the embodiments of this application according to the obtained executable instructions by calling a computer program stored in memory. The processor and memory may also be physically separated.
[0473] It should be noted that the apparatus provided in this application embodiment can implement all the method steps implemented in the above-mentioned access control method embodiment on the first network device side, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0474] like Figure 15 As shown, this application embodiment provides a network device 1500, applied to a first subnet, including:
[0475] The first receiving unit 1510 is used to receive first information or second information;
[0476] Processing unit 1520 is configured to perform authentication of user equipment based on the first information, or to perform authentication and authorization of user equipment based on the first information, or to perform authentication of second subnet based on the second information;
[0477] The first information includes one of the following:
[0478] The first decentralized identity (DID) identifier corresponding to the user equipment and the authentication-related information of the user equipment;
[0479] The first DID identifier corresponding to the user equipment, the authentication-related information of the user equipment, and the authorization-related information of the user equipment;
[0480] The second information includes the second DID identifier corresponding to the second subnet and information related to the authentication of the second subnet.
[0481] Optionally, the first DID identifier is configured by the central network to which the first subnet belongs, and / or the second DID identifier is configured by the central network to which the second subnet belongs.
[0482] Optionally, the information related to the authentication of the user equipment includes at least one of the following:
[0483] First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier;
[0484] The request message in plaintext and a second encrypted message encrypted using the user equipment's private key;
[0485] or,
[0486] The information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature;
[0487] or,
[0488] The information related to the authentication of the second subnet includes at least one of the following:
[0489] The third encrypted information is obtained by encrypting the second DID identifier using the private key of the second subnet's identity.
[0490] The request message is in plaintext and a fourth encrypted message is generated by encrypting the request message using the private key of the identity of the second subnet.
[0491] Optionally, the processing unit 1520 is further configured to:
[0492] Based on the first DID identifier, query the blockchain network device for the identity public key of the user device;
[0493] Based on the user equipment's identity public key, the first encrypted information is decrypted to obtain the first decrypted information, and / or the second encrypted information is decrypted to obtain the second decrypted information;
[0494] The authentication result of the user equipment is determined based on the decrypted information and the plaintext information; wherein the decrypted information and the plaintext information include at least one combination of the following:
[0495] The first decryption information and the first DID identifier;
[0496] The second decryption information and the request information in plaintext.
[0497] Optionally, the processing unit 1520 is further configured to:
[0498] If the decrypted information and the plaintext information are consistent, then the authentication result is determined to be that the user equipment is legitimate.
[0499] And / or,
[0500] If the decrypted information and the plaintext information do not meet the consistency requirement, then the authentication result is determined to be that the user equipment's identity is illegitimate.
[0501] Optionally, the processing unit 1520 is further configured to:
[0502] The first identity public key is determined based on the third DID identifier carried in the plaintext of the verifiable claim;
[0503] Based on the first identity public key, the verifiable declaration digital signature is decrypted to obtain the third decryption information;
[0504] The authorization result of the user equipment is determined based on the third decryption information and the verifiable statement plaintext.
[0505] Optionally, the processing unit 1520 is further configured to perform at least one of the following:
[0506] If the third DID identifier is the DID identifier corresponding to the first subnet, then the first identity public key is determined to be the identity public key of the first subnet;
[0507] If the third DID identifier is the DID identifier corresponding to the central network to which the first subnet belongs, the blockchain network device is queried for the identity public key of the central network based on the third DID identifier, and the first identity public key is determined to be the identity public key of the central network.
[0508] If the third DID identifier is the DID identifier corresponding to the third subnet associated with the first subnet, the blockchain network device is queried based on the third DID identifier to determine the identity public key of the third subnet, and the first identity public key is determined to be the identity public key of the third subnet.
[0509] Optionally, the processing unit 1520 is further configured to:
[0510] If the third decryption information and the plaintext of the verifiable declaration are consistent, then the authorization result is determined to be authorized.
[0511] And / or,
[0512] If the third decryption information and the verifiable declaration plaintext do not meet the consistency requirement, then the authorization result is determined to be authorization failure.
[0513] Optionally, the network device 1500 further includes at least one of the following:
[0514] The first sending unit is configured to send a first message to a third network device in the central network to which the first subnet belongs, after determining that the identity of the user equipment is legitimate; wherein the first message is used to request a verifiable statement for the user equipment;
[0515] The second sending unit is used for the first network device to send a second message to the third network device; wherein the second message is used to request authentication of the user equipment and to provide a verifiable claim for the user equipment;
[0516] The verifiable claim is used to access at least one subnet belonging to the central network.
[0517] Optionally, the network device 1500 further includes:
[0518] The third sending unit is configured to send a third message to a third network device in the central network to which the first subnet belongs; wherein the third message is used to request authentication of the user equipment;
[0519] The second receiving unit is configured to receive a response message from the third network device to the third message; wherein the response message is used to indicate the authentication result of the user equipment;
[0520] The fourth sending unit is configured to send a verifiable declaration to the user equipment based on the response message;
[0521] The verifiable statement is used to access the first subnet and / or to access the third subnet associated with the first subnet.
[0522] Optionally, the processing unit 1520 is further configured to:
[0523] Based on the second DID identifier, query the identity public key of the second subnet from the blockchain network device through the proxy server;
[0524] Based on the identity public key of the second subnet, the third encrypted information is decrypted to obtain the third decrypted information, and / or the fourth encrypted information is decrypted to obtain the fourth decrypted information;
[0525] The authentication result of the second subnet is determined based on the decrypted information and the plaintext information; wherein the decrypted information and the plaintext information include at least one combination of the following:
[0526] The third decryption information and the second DID identifier;
[0527] The fourth decryption information and request information are in plaintext.
[0528] Optionally, the processing unit 1520 is further configured to:
[0529] If the decrypted information and the plaintext information are consistent, then the authentication result is determined to be the legitimate identity of the second subnet.
[0530] And / or,
[0531] If the decrypted information and the plaintext information do not meet the consistency requirement, then the authentication result is determined to be that the identity of the second subnet is illegitimate.
[0532] Optionally, the network device 1500 further includes:
[0533] The third receiving unit is used to receive the DID identifier corresponding to the first subnet sent by the third network device of the central network to which the first subnet belongs.
[0534] It should be noted that the network device provided in this application embodiment can implement all the method steps implemented in the access control method embodiment of the first network device side, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0535] like Figure 16 As shown, this application embodiment provides an access control device, including a memory 161, a transceiver 162, and a processor 163; wherein, the memory 161 is used to store a computer program; the transceiver 162 is used to send and receive data under the control of the processor 163; for example, the transceiver 162 is used to receive and send data under the control of the processor 163; the processor 163 is used to read the computer program in the memory 161 and perform the following operations:
[0536] Send first information to a first network device in a first subnet; wherein the first information includes one of the following:
[0537] The first decentralized identity (DID) identifier corresponding to the user equipment and the authentication-related information of the user equipment;
[0538] The user equipment includes a first DID identifier, authentication information related to the user equipment, and authorization information related to the user equipment.
[0539] Optionally, the processor 163 is configured to read the computer program in the memory 161 and perform the following operations:
[0540] The first DID identifier is received from the third network device of the central network to which the first subnet belongs.
[0541] Optionally, the information related to the authentication of the user equipment includes at least one of the following:
[0542] First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier;
[0543] The request message in plaintext and a second encrypted message encrypted using the user equipment's private key;
[0544] or,
[0545] The information related to the authorization of the user equipment includes: the plaintext of the verifiable claim and the digital signature of the verifiable claim.
[0546] Optionally, the processor 163 is configured to read the computer program in the memory 161 and perform at least one of the following operations:
[0547] Receive the plaintext verifiable declaration sent by the first network device;
[0548] Receive a verifiable declaration plaintext sent by a third network device in the central network to which the first subnet belongs;
[0549] The verifiable declaration states that a plaintext user accesses at least one subnet belonging to the central network.
[0550] Among them, Figure 16 In this context, the bus architecture can include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors represented by processor 163 and memory represented by memory 161 together. The bus architecture can also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. Transceiver 162 can be multiple elements, including transmitters and receivers, providing a unit for communicating with various other devices over a transmission medium, including wireless channels, wired channels, optical fibers, etc. For different user equipment, user interface 144 can also be an interface capable of connecting external or internal devices, including but not limited to keypads, displays, speakers, microphones, joysticks, etc.
[0551] Processor 163 is responsible for managing the bus architecture and general processing, while memory 161 can store the data used by processor 163 when performing operations.
[0552] The processor 163 can be a central processing unit (CPU), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a complex programmable logic device (CPLD). The processor can also adopt a multi-core architecture.
[0553] It should be noted that the apparatus provided in this application embodiment can implement all the method steps implemented in the above-mentioned user equipment side access control method embodiment, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0554] like Figure 17 As shown, this application embodiment provides a user equipment 1700, including:
[0555] The sending unit 1710 is configured to send first information to a first network device in a first subnet; wherein the first information includes one of the following:
[0556] The first decentralized identity (DID) identifier corresponding to the user equipment and the authentication-related information of the user equipment;
[0557] The user equipment includes a first DID identifier, authentication information related to the user equipment, and authorization information related to the user equipment.
[0558] Optionally, the user equipment 1700 further includes:
[0559] The first receiving unit is configured to receive the first DID identifier sent by the third network device of the central network to which the first subnet belongs.
[0560] Optionally, the information related to the authentication of the user equipment includes at least one of the following:
[0561] First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier;
[0562] The request message in plaintext and a second encrypted message encrypted using the user equipment's private key;
[0563] or,
[0564] The information related to the authorization of the user equipment includes: the plaintext of the verifiable claim and the digital signature of the verifiable claim.
[0565] Optionally, the user equipment 1700 further includes at least one of the following:
[0566] The second receiving unit is used to receive the verifiable declaration plaintext sent by the first network device;
[0567] The third receiving unit is used to receive a verifiable declaration plaintext sent by the third network device of the central network to which the first subnet belongs;
[0568] The verifiable declaration states that a plaintext user accesses at least one subnet belonging to the central network.
[0569] It should be noted that the user equipment provided in this application embodiment can implement all the method steps implemented in the above-mentioned user equipment-side access control method embodiment, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0570] like Figure 18 As shown, this embodiment provides an access control device applied to a central network, including a memory 181, a transceiver 182, and a processor 183; wherein, the memory 181 is used to store computer programs; the transceiver 182 is used to send and receive data under the control of the processor 183; for example, the transceiver 182 is used to receive and send data under the control of the processor 183; the processor 183 is used to read the computer program in the memory 181 and perform the following operations:
[0571] Send the first decentralized identity (DID) identifier corresponding to the user equipment to the user equipment, and / or send the second DID identifier corresponding to the second subnet to the second network device of the second subnet;
[0572] The second subnet belongs to the central network.
[0573] Optionally, the information related to the authentication of the user equipment includes at least one of the following:
[0574] First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier;
[0575] The request message in plaintext and a second encrypted message encrypted using the user equipment's private key;
[0576] or,
[0577] The information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature;
[0578] or,
[0579] The information related to the authentication of the second subnet includes at least one of the following:
[0580] The third encrypted information is obtained by encrypting the second DID identifier using the private key of the second subnet's identity.
[0581] The request message is in plaintext and a fourth encrypted message is generated by encrypting the request message using the private key of the identity of the second subnet.
[0582] Optionally, the processor 183, for reading the computer program in the memory 181, also performs the following operations:
[0583] Receive a first message sent by a first network device in a first subnet; wherein the first message is used to request a verifiable claim to the user equipment;
[0584] Based on the user equipment's subscription information, a verifiable statement is sent to the user equipment;
[0585] The first subnet belongs to the central network, and the verifiable declaration is used to access at least one subnet belonging to the central network.
[0586] Optionally, the processor 183, for reading the computer program in the memory 181, also performs the following operations:
[0587] The system receives a second message from a first network device in a first subnet; wherein the second message is used to request authentication of the user equipment and to provide a verifiable claim for the user equipment.
[0588] Based on the second message, the user equipment is authenticated, and the authentication result is determined;
[0589] If the authentication result confirms that the user equipment's identity is legitimate, a verifiable declaration is sent to the user equipment based on the user equipment's subscription information.
[0590] The first subnet belongs to the central network, and the verifiable declaration is used to access at least one subnet belonging to the central network.
[0591] Optionally, the processor 183, for reading the computer program in the memory 181, also performs the following operations:
[0592] The system receives a third message from a first network device in a first subnet; wherein the third message is used to request authentication of the user equipment; and wherein the first subnet belongs to the central network.
[0593] Based on the third message, the user equipment is authenticated, and the authentication result is determined;
[0594] A response message to the third message is sent to the first network device; wherein the response message is used to indicate the authentication result of the user equipment.
[0595] Optionally, the authentication result is used to indicate whether the identity of the user equipment is legitimate, and / or, the authentication result is used to indicate whether a verifiable claim is allowed for the user equipment.
[0596] Among them, Figure 18 In this context, the bus architecture may include any number of interconnected buses and bridges, specifically linking various circuits together, represented by one or more processors (processor 183) and memory (memory 181). The bus architecture may also link together various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. The transceiver 182 may be multiple elements, including transmitters and receivers, providing units for communicating with various other devices over transmission media, including wireless channels, wired channels, optical fibers, etc. The processor 183 is responsible for managing the bus architecture and general processing, and the memory 181 may store data used by the processor 183 during operation.
[0597] Optionally, the processor 183 can be a CPU (Central Processing Unit), an ASIC (Application Specific Integrated Circuit), an FPGA (Field-Programmable Gate Array), or a CPLD (Complete Programmable Logic Device), and the processor can also adopt a multi-core architecture.
[0598] The processor executes any of the methods described in the embodiments of this application according to the obtained executable instructions by calling a computer program stored in memory. The processor and memory may also be physically separated.
[0599] It should be noted that the apparatus provided in this application embodiment can implement all the method steps implemented in the access control method embodiment on the third network device side, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0600] like Figure 19 As shown, this application embodiment provides a network device 1900, applied to a central network, including:
[0601] The first sending unit 1910 is used to send the first decentralized identity (DID) identifier corresponding to the user equipment to the user equipment, and / or send the second DID identifier corresponding to the second subnet to the second network device of the second subnet;
[0602] The second subnet belongs to the central network.
[0603] Optionally, the information related to the authentication of the user equipment includes at least one of the following:
[0604] First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier;
[0605] The request message in plaintext and a second encrypted message encrypted using the user equipment's private key;
[0606] or,
[0607] The information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature;
[0608] or,
[0609] The information related to the authentication of the second subnet includes at least one of the following:
[0610] The third encrypted information is obtained by encrypting the second DID identifier using the private key of the second subnet's identity.
[0611] The request message is in plaintext and a fourth encrypted message is generated by encrypting the request message using the private key of the identity of the second subnet.
[0612] Optionally, the network device 1900 further includes:
[0613] The first receiving unit is configured to receive a first message sent by a first network device in a first subnet; wherein the first message is configured to request a verifiable claim to the user equipment.
[0614] The second sending unit is used to send a verifiable declaration to the user equipment based on the user equipment's subscription information;
[0615] The first subnet belongs to the central network, and the verifiable declaration is used to access at least one subnet belonging to the central network.
[0616] Optionally, the network device 1900 further includes:
[0617] The second receiving unit is configured to receive a second message sent by a first network device in the first subnet; wherein the second message is used to request authentication of the user equipment and to provide a verifiable claim for the user equipment;
[0618] An authentication unit is configured to authenticate the user equipment based on the second message and determine the authentication result;
[0619] The third sending unit is used to send a verifiable declaration to the user equipment based on the user equipment's subscription information, provided that the authentication result indicates that the user equipment's identity is legitimate.
[0620] The first subnet belongs to the central network, and the verifiable declaration is used to access at least one subnet belonging to the central network.
[0621] Optionally, the network device 1900 further includes:
[0622] The third receiving unit is configured to receive a third message sent by a first network device in the first subnet; wherein the third message is used to request authentication of the user equipment; wherein the first subnet belongs to the central network;
[0623] An authentication unit is used to authenticate the user equipment based on the third message and determine the authentication result;
[0624] The fourth sending unit is configured to send a response message of the third message to the first network device; wherein the response message is used to indicate the authentication result of the user equipment.
[0625] Optionally, the authentication result is used to indicate whether the identity of the user equipment is legitimate, and / or, the authentication result is used to indicate whether a verifiable claim is allowed for the user equipment.
[0626] It should be noted that the network device provided in this application embodiment can implement all the method steps implemented in the access control method embodiment of the third network device side, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0627] It should be noted that the division of units in the embodiments of this application is illustrative and only represents one logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated units described above can be implemented in hardware or as software functional units.
[0628] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a processor-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0629] This application embodiment also provides a processor-readable storage medium storing a computer program. The computer program is used to cause the processor to execute the steps of the access control method on the first network device side, or the computer program is used to cause the processor to execute the steps of the access control method on the user equipment side, or the computer program is used to cause the processor to execute the steps of the access control method on the third network device side, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0630] This application also provides a computer program product, including computer instructions. When executed by a processor, the computer instructions implement the steps of the access control method on the first network device side, or when executed by a processor, the computer instructions implement the steps of the access control method on the user equipment side, or when executed by a processor, the computer instructions implement the steps of the access control method on the third network device side, and can achieve the same technical effect. To avoid repetition, it will not be described again here.
[0631] The processor-readable storage medium can be any available medium or data storage device that the processor can access, including but not limited to magnetic memory (e.g., floppy disk, hard disk, magnetic tape, magneto-optical disk (MO)), optical memory (e.g., CD, DVD, BD, HVD), and semiconductor memory (e.g., ROM, EPROM, EEPROM, non-volatile memory (NAND FLASH), solid-state drive (SSD)).
[0632] Those skilled in the art will understand that embodiments of this application can be provided as methods, systems, or computer program products. Therefore, this application can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this application can take the form of a computer program product implemented on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.
[0633] This application is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this application. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-executable instructions. These computer-executable instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, generate instructions for implementing the flowchart... Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0634] These processor-executable instructions may also be stored in a processor-readable memory that can direct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the processor-readable memory produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0635] These processors can execute instructions that can also be loaded onto a computer or other programmable data processing device, causing a series of operational steps to be performed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable device for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0636] Furthermore, it should be noted that in the apparatus and method of this application, it is obvious that the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered equivalent solutions of this application. Moreover, the steps performing the above series of processes can naturally be executed in the order described, but are not necessarily required to be executed in chronological order; some steps can be executed in parallel or independently of each other. Those skilled in the art will understand that all or any step or component of the method and apparatus of this application can be implemented in any computing device (including processors, storage media, etc.) or network of computing devices, in hardware, firmware, software, or a combination thereof. This is something that those skilled in the art can achieve by using their basic programming skills after reading the description of this application.
[0637] Obviously, those skilled in the art can make various modifications and variations to this application without departing from the spirit and scope of this application. Therefore, if such modifications and variations fall within the scope of the claims of this application and their equivalents, this application also intends to include such modifications and variations.
Claims
1. An access control method, characterized in that, The method, applied to a first network device in a first subnet, includes: The first network device receives the first information or the second information; The first network device performs authentication of the user equipment based on the first information, or performs authentication and authorization of the user equipment based on the first information, or performs authentication of the second subnet based on the second information; The first information includes one of the following: The first decentralized identity (DID) identifier corresponding to the user equipment and the authentication-related information of the user equipment; The first DID identifier corresponding to the user equipment, the authentication-related information of the user equipment, and the authorization-related information of the user equipment; The second information includes the second DID identifier corresponding to the second subnet and information related to the authentication of the second subnet.
2. The access control method according to claim 1, characterized in that, The first DID identifier is configured by the central network to which the first subnet belongs, and / or the second DID identifier is configured by the central network to which the second subnet belongs.
3. The access control method according to claim 1, characterized in that, The information related to the authentication of the user equipment includes at least one of the following: First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier; The request message in plaintext and a second encrypted message encrypted using the user equipment's private key; or, The information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature; or, The information related to the authentication of the second subnet includes at least one of the following: The third encrypted information is obtained by encrypting the second DID identifier using the private key of the second subnet's identity. The request message is in plaintext and a fourth encrypted message is generated by encrypting the request message using the private key of the identity of the second subnet.
4. The access control method according to claim 3, characterized in that, The first network device performs authentication of the user equipment based on the first information, including: The first network device queries the blockchain network device for the identity public key of the user device based on the first DID identifier; The first network device decrypts the first encrypted information to obtain first decrypted information based on the identity public key of the user equipment, and / or decrypts the second encrypted information to obtain second decrypted information; The first network device determines the authentication result of the user equipment based on the decryption information and the plaintext information; wherein the decryption information and the plaintext information include at least one combination of the following: The first decryption information and the first DID identifier; The second decryption information and the request information in plaintext.
5. The access control method according to claim 4, characterized in that, The first network device determines the authentication result of the user equipment based on the decrypted information and the plaintext information, including: If the decrypted information and the plaintext information are consistent, the first network device determines that the authentication result indicates that the user equipment's identity is legitimate. And / or, If the decrypted information and the plaintext information do not meet the consistency requirement, the first network device determines that the authentication result indicates that the user equipment's identity is illegitimate.
6. The access control method according to claim 3, characterized in that, The first network device performs authorization of the user equipment based on the first information, including: The first network device determines the first identity public key based on the third DID identifier carried in the verifiable claim plaintext; The first network device decrypts the verifiable declaration digital signature based on the first identity public key to obtain the third decryption information; The first network device determines the authorization result of the user equipment based on the third decryption information and the verifiable declaration plaintext.
7. The access control method according to claim 6, characterized in that, The first network device determines the identity public key based on the third DID identifier carried in the verifiable claim plaintext, including at least one of the following: If the third DID identifier is the DID identifier corresponding to the first subnet, then the first identity public key is determined to be the identity public key of the first subnet; If the third DID identifier is the DID identifier corresponding to the central network to which the first subnet belongs, the first network device queries the blockchain network device for the identity public key of the central network based on the third DID identifier, and determines that the first identity public key is the identity public key of the central network. If the third DID identifier is the DID identifier corresponding to the third subnet associated with the first subnet, the first network device queries the blockchain network device for the identity public key of the third subnet based on the third DID identifier, and determines that the first identity public key is the identity public key of the third subnet.
8. The access control method according to claim 6, characterized in that, The first network device determines the authorization result of the user equipment based on the third decryption information and the verifiable declaration plaintext, including: If the third decryption information and the plaintext of the verifiable declaration are consistent, then the first network device determines that the authorization result is authorized. And / or, If the third decryption information and the verifiable declaration plaintext do not meet the consistency requirement, the first network device determines that the authorization result is an authorization failure.
9. The access control method according to any one of claims 1 to 8, characterized in that, It also includes at least one of the following: If the first network device determines that the user equipment's identity is legitimate, it sends a first message to the third network device of the central network to which the first subnet belongs; wherein, the first message is used to request a verifiable statement for the user equipment; The first network device sends a second message to the third network device; wherein the second message is used to request authentication of the user equipment and to provide a verifiable claim for the user equipment; The verifiable claim is used to access at least one subnet belonging to the central network.
10. The access control method according to any one of claims 1 to 8, characterized in that, Also includes: The first network device sends a third message to a third network device in the central network to which the first subnet belongs; wherein the third message is used to request authentication of the user equipment; The first network device receives a response message from the third network device to the third message; wherein the response message is used to indicate the authentication result of the user equipment; The first network device sends a verifiable declaration to the user equipment based on the response message; The verifiable statement is used to access the first subnet and / or to access the third subnet associated with the first subnet.
11. The access control method according to claim 3, characterized in that, The first network device performs authentication of the second subnet based on the second information, including: The first network device queries the identity public key of the second subnet from the blockchain network device through the proxy server based on the second DID identifier; The first network device decrypts the third encrypted information to obtain the third decrypted information based on the identity public key of the second subnet, and / or decrypts the fourth encrypted information to obtain the fourth decrypted information; The first network device determines the authentication result of the second subnet based on the decryption information and the plaintext information; wherein the decryption information and the plaintext information include at least one combination of the following: The third decryption information and the second DID identifier; The fourth decryption information and request information are in plaintext.
12. The access control method according to claim 11, characterized in that, The first network device determines the authentication result of the second subnet based on the decrypted information and the plaintext information, including: If the decrypted information and the plaintext information are consistent, the first network device determines that the authentication result is valid for the identity of the second subnet. And / or, If the decrypted information and the plaintext information do not meet the consistency requirement, the first network device determines that the authentication result indicates that the identity of the second subnet is illegitimate.
13. The access control method according to claim 11, characterized in that, Also includes: The first network device receives the DID identifier corresponding to the first subnet from the third network device of the central network to which the first subnet belongs.
14. An access control method, characterized in that, include: The user equipment sends first information to the first network device in the first subnet; wherein the first information includes one of the following: The first decentralized identity (DID) identifier corresponding to the user equipment and the authentication-related information of the user equipment; The user equipment includes a first DID identifier, authentication information related to the user equipment, and authorization information related to the user equipment.
15. The access control method according to claim 14, characterized in that, Before the user equipment sends the first information to the first network device of the first subnet, it also includes: The user equipment receives the first DID identifier sent by the third network device of the central network to which the first subnet belongs.
16. The access control method according to claim 14, characterized in that, The information related to the authentication of the user equipment includes at least one of the following: First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier; The request message in plaintext and a second encrypted message encrypted using the user equipment's private key; or, The information related to the authorization of the user equipment includes: the plaintext of the verifiable claim and the digital signature of the verifiable claim.
17. The access control method according to any one of claims 14 to 16, characterized in that, It also includes at least one of the following: The user equipment receives a verifiable statement plaintext sent by the first network device; The user equipment receives a verifiable statement plaintext sent by a third network device of the central network to which the first subnet belongs; The verifiable declaration states that a plaintext user accesses at least one subnet belonging to the central network.
18. An access control method, characterized in that, A third network device applied to a central network, the method comprising: The third network device sends the first decentralized identity (DID) identifier corresponding to the user equipment to the user equipment, and / or sends the second DID identifier corresponding to the second subnet to the second network device of the second subnet; The second subnet belongs to the central network.
19. The access control method according to claim 18, characterized in that, The information related to the authentication of the user equipment includes at least one of the following: First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier; The request message in plaintext and a second encrypted message encrypted using the user equipment's private key; or, The information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature; or, The information related to the authentication of the second subnet includes at least one of the following: The third encrypted information is obtained by encrypting the second DID identifier using the private key of the second subnet's identity. The request message is in plaintext and a fourth encrypted message is generated by encrypting the request message using the private key of the identity of the second subnet.
20. The access control method according to claim 18, characterized in that, Also includes: The third network device receives a first message sent by the first network device of the first subnet; wherein the first message is used to request a verifiable claim for the user equipment; The third network device sends a verifiable declaration to the user equipment based on the user equipment's subscription information; The first subnet belongs to the central network, and the verifiable declaration is used to access at least one subnet belonging to the central network.
21. The access control method according to claim 18, characterized in that, Also includes: The third network device receives a second message sent by the first network device of the first subnet; wherein the second message is used to request authentication of the user equipment and to provide a verifiable claim for the user equipment; The third network device authenticates the user equipment based on the second message and determines the authentication result; If the authentication result confirms that the user equipment's identity is legitimate, the third network device sends a verifiable declaration to the user equipment based on the user equipment's subscription information. The first subnet belongs to the central network, and the verifiable declaration is used to access at least one subnet belonging to the central network.
22. The access control method according to claim 18, characterized in that, Also includes: The third network device receives a third message sent by the first network device in the first subnet; wherein the third message is used to request authentication of the user equipment; wherein the first subnet belongs to the central network; The third network device authenticates the user equipment based on the third message and determines the authentication result; The third network device sends a response message to the first network device for the third message; wherein the response message is used to indicate the authentication result of the user equipment.
23. The access control method according to claim 21 or 22, characterized in that, The authentication result is used to indicate whether the identity of the user equipment is legitimate, and / or, the authentication result is used to indicate whether a verifiable claim is allowed for the user equipment.
24. An access control device, characterized in that, It is applied to the first subnet, including memory, transceiver, and processor; The memory stores computer programs; the transceiver, under the control of the processor, sends and receives data; the processor reads the computer programs from the memory and performs the following operations: Receive the first message or the second message; Authentication of the user equipment is performed based on the first information, or authentication and authorization of the user equipment are performed based on the first information, or authentication of the second subnet is performed based on the second information; The first information includes one of the following: The first decentralized identity (DID) identifier corresponding to the user equipment and the authentication-related information of the user equipment; The first DID identifier corresponding to the user equipment, the authentication-related information of the user equipment, and the authorization-related information of the user equipment; The second information includes the second DID identifier corresponding to the second subnet and information related to the authentication of the second subnet.
25. The access control device according to claim 24, characterized in that, The information related to the authentication of the user equipment includes at least one of the following: First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier; The request message in plaintext and a second encrypted message encrypted using the user equipment's private key; or, The information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature; or, The information related to the authentication of the second subnet includes at least one of the following: The third encrypted information is obtained by encrypting the second DID identifier using the private key of the second subnet's identity. The request message is in plaintext and a fourth encrypted message is generated by encrypting the request message using the private key of the identity of the second subnet.
26. The access control device according to claim 25, characterized in that, The processor is used to read the computer program in the memory and perform the following operations: Based on the first DID identifier, query the blockchain network device for the identity public key of the user device; Based on the user equipment's identity public key, the first encrypted information is decrypted to obtain the first decrypted information, and / or the second encrypted information is decrypted to obtain the second decrypted information; The authentication result of the user equipment is determined based on the decrypted information and the plaintext information; wherein the decrypted information and the plaintext information include at least one combination of the following: The first decryption information and the first DID identifier; The second decryption information and the request information in plaintext.
27. The access control device according to claim 25, characterized in that, The processor is used to read the computer program in the memory and perform the following operations: The first identity public key is determined based on the third DID identifier carried in the plaintext of the verifiable claim; Based on the first identity public key, the verifiable declaration digital signature is decrypted to obtain the third decryption information; The authorization result of the user equipment is determined based on the third decryption information and the verifiable statement plaintext.
28. The access control device according to claim 25, characterized in that, The processor is used to read the computer program in the memory and perform the following operations: Based on the second DID identifier, query the identity public key of the second subnet from the blockchain network device through the proxy server; Based on the identity public key of the second subnet, the third encrypted information is decrypted to obtain the third decrypted information, and / or the fourth encrypted information is decrypted to obtain the fourth decrypted information; The authentication result of the second subnet is determined based on the decrypted information and the plaintext information; wherein the decrypted information and the plaintext information include at least one combination of the following: The third decryption information and the second DID identifier; The fourth decryption information and request information are in plaintext.
29. A network device, characterized in that, Applied to the first subnet, including: The first receiving unit is used to receive first information or second information; The processing unit is configured to perform authentication of the user equipment based on the first information, or to perform authentication and authorization of the user equipment based on the first information, or to perform authentication of the second subnet based on the second information; The first information includes one of the following: The first decentralized identity (DID) identifier corresponding to the user equipment and the authentication-related information of the user equipment; The first DID identifier corresponding to the user equipment, the authentication-related information of the user equipment, and the authorization-related information of the user equipment; The second information includes the second DID identifier corresponding to the second subnet and information related to the authentication of the second subnet.
30. An access control device, characterized in that, Includes memory, transceiver, and processor; The memory stores computer programs; the transceiver, under the control of the processor, sends and receives data; the processor reads the computer programs from the memory and performs the following operations: Send first information to a first network device in a first subnet; wherein the first information includes one of the following: The first decentralized identity (DID) identifier corresponding to the user equipment and the authentication information related to the user equipment; The user equipment's first DID identifier, authentication-related information, and authorization-related information.
31. A user equipment, characterized in that, include: The sending unit is configured to send first information to a first network device in a first subnet; wherein the first information includes one of the following: The first decentralized identity (DID) identifier corresponding to the user equipment and the authentication-related information of the user equipment; The user equipment includes a first DID identifier, authentication information related to the user equipment, and authorization information related to the user equipment.
32. An access control device, characterized in that, It is used in central networks, including memory, transceivers, and processors; The memory stores computer programs; the transceiver, under the control of the processor, sends and receives data; the processor reads the computer programs from the memory and performs the following operations: Send the first decentralized identity (DID) identifier corresponding to the user equipment to the user equipment, and / or send the second DID identifier corresponding to the second subnet to the second network device of the second subnet; The second subnet belongs to the central network.
33. A network device, characterized in that, Applied to the central network, including: The first sending unit is configured to send a first decentralized identity (DID) identifier corresponding to the user equipment to the user equipment, and / or send a second DID identifier corresponding to the second subnet to the second network device of the second subnet; The second subnet belongs to the central network.
34. A processor-readable storage medium, characterized in that, The processor-readable storage medium stores a computer program for causing the processor to perform the steps of the access control method according to any one of claims 1 to 23.
35. A computer program product, characterized in that, It includes computer instructions that, when executed by a processor, implement the steps of the access control method as described in any one of claims 1 to 23.