Distributed network architecture and authentication method
By introducing a first network element in the 6G distributed network for subnet identity authentication and security protection, the problem of excessively high efficiency and performance requirements for border gateways in traditional authentication methods is solved, and secure communication and privacy protection are achieved.
Patent Information
- Application Number
- CN202510591087.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-08
- Publication Date
- 2025-12-12
AI Technical Summary
In 6G distributed networks, how can secure communication of network resources between different enterprises, operators, individuals or third parties be achieved, especially in addressing the problem of excessively high efficiency and performance requirements for border gateways imposed by traditional authentication methods?
The first network element in the distributed network architecture is introduced. The identity of the subnet is represented by authenticating the first network element, and a secure channel is established. Security protection functions such as topology hiding, signaling monitoring and filtering, and encrypted data transmission are provided, simplifying the authentication process between subnets.
It reduces the efficiency and performance requirements of border gateways, ensures secure communication between different network resources, prevents forged signaling attacks, and ensures secure communication of data privacy information.
Smart Images

Figure CN121126340A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of network information security, and particularly relates to a distributed network architecture and an authentication method. BACKGROUND
[0002] In order to meet the business requirements of diversified scenarios, networks in the era of 6th generation wireless systems (6G) will cover space, air, land and sea, more non-mobile communication systems will access 6G networks and interwork with 6G networks to realize the fusion and coexistence of heterogeneous networks. In the 6G distributed network, a large number of diversified nodes (such as macro base stations, small base stations, terminals, etc.) are highly autonomous, and have differentiated communication characteristics, cache capabilities, computing capabilities and load conditions, etc., so that different nodes need to be coordinated to realize distributed network resource complementation and on-demand networking. However, since the distributed network resources may belong to different enterprises, operators, individuals or third parties, etc., how to realize secure communication between these networks is a problem to be solved at present. SUMMARY
[0003] Embodiments of the present application provide a distributed network architecture and an authentication method, which solve the problem that the security of communication between distributed network resources belonging to different enterprises / operators / individuals / third parties cannot be guaranteed.
[0004] In a first aspect, to achieve the above object, the embodiments of the present application provide a distributed network architecture, comprising a plurality of subnets; wherein each of the subnets is deployed with a first network element;
[0005] In the distributed network authentication, the first network element is used to represent the identity of the subnet where the first network element is located.
[0006] And / or,
[0007] The first network element has a security protection function.
[0008] The authentication mode of the subnet is to authenticate the first network element representing the identity of the subnet.
[0009] The first network elements of different subnets communicate with each other.
[0010] The first network elements of different subnets establish a secure channel.
[0011] The security protection function includes one or more of the following: topology hiding function, signaling monitoring and filtering function, and transmission data encryption function.
[0012] The first network element is a first logical function entity, or the first network element is an extended function of a first device; the first device includes at least one of a network element device, a network device, a security edge protection proxy (SEPP), and a security gateway (SEG).
[0013] In a second aspect, to achieve the above object, an embodiment of the present application provides an authentication method of a distributed network, applied to a first network element in a subnet of the distributed network architecture as described in the first aspect, and the method comprises:
[0014] sending a first authentication request to the first node, the first authentication request being used to request authentication of the subnet where the first network element is located;
[0015] receiving a first authentication response sent by the first node, the first authentication response carrying a first token of the subnet where the first network element is located, the first token being used for identity authentication with other subnets.
[0016] When the authentication of the distributed network is a center-based public key infrastructure (PKI) authentication, the first node is a center node, and the first authentication request carries a public key certificate of the first network element.
[0017] When the authentication of the distributed network is a distributed public key infrastructure (DPKI) authentication based on a block chain, the first node is a distributed ledger node based on a certificate management system, and the first authentication request carries a public key certificate of the first network element or a certificate identifier of the first network element.
[0018] When the first node is a distributed ledger node based on a certificate management system, before sending the first authentication request to the first node, the method further comprises:
[0019] sending a certificate registration message to the first node.
[0020] After receiving the first authentication response sent by the first node, the method further comprises:
[0021] receiving request information sent by a second device; the request information includes a second authentication request used to request a token of the second device, and / or a first token verification request used to verify a token of a third device; the second device and the first network element are deployed in the same subnet, and the second device and the third device are deployed in different subnets;
[0022] In response to the request information, sending response information to the second device.
[0023] When the request information includes the second authentication request, the response information carries the token of the second device.
[0024] Or, when the request information includes the first token verification request, the request information carries the token of the third device.
[0025] When the request information includes the first token verification request, before sending the response information to the second device, the method further includes:
[0026] When the first node is a distributed ledger node based on a certificate management system, according to the request information, a second token verification request is sent to the first node, and the second token verification request carries the token of the third device.
[0027] Receiving the token verification response sent by the first node;
[0028] Sending the response information to the second device, including:
[0029] Based on the token verification response, the response information is sent to the second device.
[0030] In a third aspect, to achieve the above object, an embodiment of the present application provides an authentication method of a distributed network, applied to a second device, and the method includes:
[0031] Sending request information to a first network element, the request information including at least one of the following: a second authentication request for requesting a token of the second device; and a first token verification request for verifying a token of a third device; wherein the second device and the first network element are deployed in the same subnet, and the second device and the third device are deployed in different subnets.
[0032] Receiving response information sent by the first network element.
[0033] When the request information includes the second authentication request, the response information carries the token of the second device.
[0034] And / or, when the request information includes the first token verification request, the request information carries the token of the third device.
[0035] When the request information includes the second authentication request, after receiving the response information sent by the first network element, the method further includes:
[0036] Sending a first service request to a fourth device, the first service request carrying the token of the second device, and the second device and the fourth device being deployed in different subnets.
[0037] Receiving a first service response sent by the fourth device.
[0038] wherein, in a case where the request information comprises the first token verification request:
[0039] Before sending the request information to the first network element, the method further comprises:
[0040] receiving a second service request sent by a third device, the second service request carrying a token of the third device;
[0041] After receiving the response information sent by the first network element, the method further comprises:
[0042] According to the response information, sending a second service response to the third device.
[0043] wherein, in a case where the request information is the second authentication request, sending the request information to the first network element comprises:
[0044] In a case where it is determined according to the subnet information and / or authentication level requirement that inter-subnet device authentication is needed, sending the request information to the first network element, wherein the subnet information comprises a number of subnets and / or a type of subnet.
[0045] The beneficial effects of the above technical solutions of the present application are as follows:
[0046] The distributed network architecture of the embodiments of the present application comprises a plurality of subnets; wherein, a first network element is deployed in each of the subnets; wherein, in distributed network authentication, the first network element is used to represent the identity of the subnet where the first network element is located, and / or the first network element has a security protection function. In this way, the authentication of the first network element can realize the authentication of the subnet where the first network element is located, and / or the first network element can perform security protection on the subnet where it is located, so as to guarantee the secure communication between different network resources. BRIEF DESCRIPTION OF DRAWINGS
[0047] Figure 1 It is a schematic diagram of an existing 6G distributed network architecture;
[0048] Figure 2 It is a structural schematic diagram of the distributed network architecture of the embodiments of the present application;
[0049] Figure 3 It is one of the flow schematic diagrams of the authentication method of the distributed network of the embodiments of the present application;
[0050] Figure 4 It is the second flow schematic diagram of the authentication method of the distributed network of the embodiments of the present application;
[0051] Figure 5 It is the third flow schematic diagram of the authentication method of the distributed network of the embodiments of the present application;
[0052] Figure 6 Figure 4 is a flowchart illustrating a method for authenticating a distributed network according to an embodiment of the present application;
[0053] Figure 7 Figure 5 is a flowchart illustrating a method for authenticating a distributed network according to an embodiment of the present application;
[0054] Figure 8 Figure 6 is a flowchart illustrating a method for authenticating a distributed network according to an embodiment of the present application. DETAILED DESCRIPTION
[0055] In order to make the technical problems to be solved, technical solutions and advantages of the present application clearer, specific embodiments will be described in detail below with reference to the accompanying drawings.
[0056] It should be understood that the term "one embodiment" or "an embodiment" mentioned throughout the specification means that the specific features, structures or characteristics related to the embodiment are included in at least one embodiment of the present application. Therefore, "in one embodiment" or "in an embodiment" appearing throughout the specification does not necessarily refer to the same embodiment. In addition, these specific features, structures or characteristics can be combined in any suitable manner in one or more embodiments.
[0057] In various embodiments of the present application, it should be understood that the size of the serial number of each process does not mean the order of execution, and the execution order of each process should be determined according to its function and inherent logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0058] In addition, the terms "system" and "network" are often used interchangeably in this document.
[0059] In the embodiments provided in the present application, it should be understood that "B corresponding to A" means that B is associated with A, and B can be determined according to A. However, it should also be understood that the determination of B according to A does not mean that B is determined only according to A, but B can also be determined according to A and / or other information.
[0060] Next, the technologies related to the scheme of the present application will be described.
[0061] As described above, the distributed network resources may belong to different enterprises, operators, individuals or third parties, etc., and therefore a decentralized network security trusted collaboration mechanism needs to be established, and an important problem is to solve the device identity authentication between different distributed subnets.
[0062] Network device identity authentication is an important mechanism to protect the security of a mobile communication network. By authenticating all devices accessing the internal network of a mobile operator, it is ensured that only legitimate network devices are allowed to access the network resources, such as establishing a network connection.
[0063] The identity authentication of devices in a mobile communication network has been using the mechanism of Network Domain Security (NDS) defined by the relevant protocols since 2G. For different network elements in the same operator network, the identity authentication of network devices can use the mechanism defined by NDS / Application Function (AF), or use the Internet Security Protocol (IPSec) or Transport Layer Security (TLS) in the Internet Engineering Task Force (IETF) standard for mutual identity authentication between devices. However, since different network elements in a unified operator network are in the same security domain, in practice, the identity of devices in the same operator network is not usually mutually authenticated, because the identity of these devices is considered to be inherently trusted. However, in different security domains, such as between different operators, the security mechanism of NDS / AF defined by the relevant protocols is used to mutually authenticate the security gateways (SEGs) at the boundary of the network domain. In the 5G stage, the Security Edge Protection Proxies (SEPP) are introduced to authenticate the interconnection of devices between operators.
[0064] However, as shown in Figure 1 The network data volume and computing volume will increase significantly in the 6G era, and the existing centralized and integrated network architecture cannot meet the growing network needs of users. Distributed autonomous networking architecture has become a trend, which improves the drawbacks of centralized processing and centralized storage in the original network, can effectively realize the distributed computing and storage of data, has the characteristics of collaboration, fusion, scalability, etc., and will become the mainstream development direction of 6G networks. Distributed autonomous networking brings new requirements for network device identity authentication. For example, considering the large number of autonomous networks and the authentication between devices in different autonomous networks, the traditional NDS / AF brings complexity challenges to the boundary gateway of the security domain, such as a boundary gateway needs to mutually authenticate the identity of the boundary gateway of N-1 autonomous networks. When the number of N is very large, there is a great challenge to the efficiency and performance of the boundary gateway, so it is necessary to consider designing a device identity authentication mechanism that meets the distributed networking architecture.
[0065] Based on this, embodiments of this application provide a distributed network architecture, such as... Figure 2 As shown, the distributed network architecture includes multiple subnets; wherein a first network element is deployed in each subnet; wherein, in distributed network authentication, the first network element is used to characterize the identity of the subnet in which the first network element is located; and / or, the first network element has security protection functions.
[0066] by Figure 2 For example, the distributed network architecture includes subnet 1, subnet 2 and subnet 3. Each subnet deploys a first network element (e.g., first network element_subnet 1, first network element_subnet 1, first network element_subnet 1, etc.) and multiple devices (e.g., device 1_subnet 1, device 2_subnet 1, device 3_subnet 1, etc.).
[0067] In this distributed network architecture, one of the multiple subnets can be called the central network, while the others can be called distributed subnets. There is no hierarchical relationship between the central network and the distributed subnets; they have similar roles / functions within the distributed network architecture, and the aforementioned first network element is deployed in both the central network and each distributed subnet.
[0068] Here, the first network element can also be called: agent function network element, or distributed security agent function (DSAF) network element; wherein, the first network element itself is virtualized, cloudified, and atomic, and its logical functions can also be flexibly expanded according to the scenario of distributed subnet.
[0069] In the embodiments of this application, the distributed network architecture includes multiple subnets; each subnet is equipped with a first network element; and in the distributed network authentication, the first network element is used to characterize the identity of the subnet to which the first network element resides. Thus, firstly, authentication of the first network element enables authentication of the subnet to which it resides. Mutual authentication between subnets ensures secure communication between them to a certain extent. Furthermore, this authentication method addresses the problem in the aforementioned NDS / AF-based network device authentication method, where a border gateway needs to perform mutual authentication with the border gateways of N-1 other autonomous networks, posing a significant challenge to the efficiency and performance of the security domain's border gateways. Secondly, the security protection function of the first network element also provides security protection for the subnet to which it resides, preventing the subnet from receiving forged signaling or being attacked by signaling, thereby ensuring secure communication between the subnet to which the first network element resides and other subnets.
[0070] As an optional implementation, the authentication method for the subnet is as follows: authenticating the first network element that represents the identity of the subnet. That is, authentication of the subnet to which the first network element resides is achieved through the authentication of the first network element. In other words, the authentication of the first network element is successful through authentication of the subnet (each device within the subnet) to which the first network element resides. Thus, it is unnecessary for the border gateway within a subnet to perform separate authentication with the border gateways of each other subnet, reducing the efficiency and performance requirements on the border gateways.
[0071] As an optional implementation, different subnets communicate through the first network element; wherein, for example... Figure 2 As shown, a secure channel is established between the first network elements of different subnets.
[0072] In the above optional implementation, the secure channel is established between the first network elements deployed in different subnets. Figure 2 In this context, Za represents a secure channel, ensuring that all communication traffic between distributed subnets passes through the first network element. Thus, the first network element acts as a gateway for the subnet in which it resides. Figure 2 As shown, within a subnet, a secure channel is also established between the first network element and other devices in its subnet (such as network element devices, network devices, etc.). Figure 2 Zb in the text represents the secure channel.
[0073] Furthermore, as an optional implementation, the security protection function includes one or more of the following: topology hiding function, signaling monitoring and filtering function, and data transmission encryption function.
[0074] The data encryption function refers to the ability to encrypt data transmission during the transmission process.
[0075] The security protection functions in the above optional implementation methods can effectively protect against risks such as topology exposure, signaling attacks, and data leakage, and achieve secure communication between subnets.
[0076] As an optional implementation, the first network element is a first logical functional entity, or the first network element is an extended function of the first device; wherein the first device includes at least one of network element device, network device, Security Edge Protection Agent (SEPP), and Security Gateway (SEG).
[0077] In other words, the first network element itself is virtualized, cloud-based, and atomic, and its logical functions can be flexibly extended according to the distributed subnet scenario. In implementation, the first network element can be a functional extension of an existing SEG or SEPP, or other network elements or network devices, or it can be a new logical functional entity. If it is an extension of SEG or SEPP, security protection functions such as topology hiding, signaling monitoring and filtering can be added to the SEG or SEPP.
[0078] In the distributed network architecture of this application embodiment, by introducing a first network element, which represents the identity of its subnet in the distributed network authentication process, security authentication is performed. Firstly, this satisfies the need for cross-domain authentication in distributed networks, reducing the complexity of device authentication interactions between different subnets. Secondly, it lowers the efficiency and performance requirements of the security domain's boundary gateway. Thirdly, it ensures the security of privacy information such as user data, interaction data, and management data generated during the authentication process, extending authentication information from different network architectures to other networks and ensuring the credibility of authentication results in the distributed architecture. Ultimately, it guarantees secure communication between different subnets in the distributed network.
[0079] Embodiments of this application provide an authentication method for a distributed network. This method is applied to a first network element in a subnet of the aforementioned distributed network architecture, such as... Figure 3 As shown, the method includes:
[0080] Step 301: Send a first authentication request to the first node. The first authentication request is used to request authentication of the subnet where the first network element is located.
[0081] Step 302: Receive the first authentication response sent by the first node. The first authentication response carries the first token of the subnet where the first network element is located. The first token is used for identity authentication with other subnets.
[0082] In the above embodiments, a first network element sends a first authentication request to a first node to request authentication of the subnet in which the first network element resides, and receives a first authentication response from the first node. Thus, the first network element performs security authentication on behalf of its entire distributed subnet. Once the first network element is successfully authenticated by the first node, it indicates that devices within the subnet in which the first network element resides are also trustworthy. Based on this, the first network element can authenticate with first network elements in other subnets using the first token in the first authentication response, thereby achieving identity authentication between different subnets. When identity authentication between two subnets is successful, it indicates that the two subnets (including the devices within them) trust each other.
[0083] Based on this, after step 302, the method further includes: a first network element sending a third authentication request to a first network element in the target subnet, the third authentication request being used to request the target subnet to authenticate the subnet where the first network element resides, the third authentication request carrying the first token; and the first network element receiving an authentication response corresponding to the third authentication request from the first network element in the target subnet. Thus, authentication between subnets is achieved through mutual authentication between first network elements in different subnets, replacing the authentication of individual devices within the subnet with overall subnet authentication, thereby reducing the complexity of authentication.
[0084] In addition, one way for the first network element in the target subnet to authenticate the first network element that sends the third authentication request is to verify the authenticity of the first token carried in the third authentication request, such as verifying whether the first token is the token sent by the first node.
[0085] Corresponding to steps 301 and 302 above, embodiments of this application also provide an authentication method for a distributed network, applied to a first node, the method comprising:
[0086] Receive a first authentication request sent by a first network element, wherein the first authentication request is used to request authentication of the subnet where the first network element is located;
[0087] Based on the first authentication request, the subnet where the first network element is located is authenticated to obtain the first token of the subnet where the first network element is located.
[0088] A first authentication response is sent to the first network element. The first authentication response carries the first token, which is used for identity authentication with other subnets.
[0089] As an optional implementation, when the authentication of the distributed network is based on centralized public key infrastructure (PKI), the first node is the central node; the first authentication request carries the public-key certificate of the first network element.
[0090] It should be noted that the central node is referred to as centralnode, specifically as Bridge CA (Certificate Authority).
[0091] As another optional implementation, when the authentication of the distributed network is based on Distributed Public Key Infrastructure (DPKI) authentication, the first node is a Distributed Ledger Technology (DLT) node; where DLT stands for Distributed Ledger Technology; the first authentication request carries the public-key certificate or the certificate identifier of the first network element. The certificate identifier is a unique identifier of the public-key certificate of the first network element, such as an index value of the public-key certificate.
[0092] Furthermore, when the first node is a distributed ledger node based on a certificate management system, before sending the first authentication request to the first node, the method further includes:
[0093] Send a certificate registration message to the first node. This step involves uploading relevant information about the first network element (such as its certificate and authentication credentials) to the blockchain. In other words, the certificate registration message includes at least one of the first network element's public key certificate, certificate identifier, and authentication credentials, but is not limited to these.
[0094] It should be noted that, since the first network element represents the identity of its subnet during the security authentication process, the authentication of the subnet can be achieved by authenticating the first network element. Therefore, in the above implementation, only the relevant information of the first network element needs to be uploaded to the blockchain, without needing to upload the relevant information of all devices in the subnet to which the first network element belongs. This saves storage resources while ensuring that subsequent authentication of the first network element is based on the uploaded information to achieve authentication of the subnet to which the first network element belongs.
[0095] Furthermore, as an optional implementation, after step 302, the method further includes:
[0096] The system receives a request from a second device. This request includes: a second authentication request for a token from the second device; and / or a first token verification request for verifying a token from a third device. The second device and the first network element are deployed in the same subnet, while the second device and the third device are deployed in different subnets. Here, when the request is a first token verification request, the second device authenticates the third device; that is, the third device is the device that requires inter-subnet device authentication from the second device.
[0097] In response to the request information, a response information is sent to the second device.
[0098] Here, when the request information is the second authentication request, the above-mentioned optional implementation method is that the first network element provides a token to the second device, so that the second device can request devices in other subnets to authenticate the second device based on the token provided by the first network element; when the request information is the first token verification request, the above-mentioned optional implementation method is that the first network element assists the second device in authenticating a third device in another subnet. In this way, mutual authentication between devices in different subnets can be achieved.
[0099] Based on this, by way of example, when the request information includes the second authentication request, the response information carries the token of the second device;
[0100] Alternatively, when the request information includes the first token verification request, the request information carries the token of the third device. In this case, the response information carries the token verification result.
[0101] It should also be noted that the authentication between devices in different subnets in the above optional implementation method needs to be performed after the subnet authentication is successful. That is, the optional implementation method is executed only after the first token verification between the two subnets is successful. In other words, the authentication level between devices in different subnets is higher than the authentication level between subnets.
[0102] Furthermore, as an optional implementation, before sending response information to the second device when the request information includes the first token verification request, the method further includes:
[0103] When the first node is a distributed ledger node based on a certificate management system, a second token verification request is sent to the first node according to the request information, and the second token verification request carries the token of the third device;
[0104] Receive the token verification response sent by the first node;
[0105] Sending response information to the second device, including:
[0106] Based on the token verification response, the response information is sent to the second device.
[0107] In other words, when the authentication in the distributed network is based on blockchain-based DPKI authentication, the first network element needs to transmit (e.g., pass through) the token verification request to the DLT-based management system, so that the DLT-based management system can verify the token carried in the token verification request and feed back the token verification response (carrying the token verification result) to the first network element, thereby enabling the first network element to feed back the token verification response to the second device that sent the token verification request.
[0108] Corresponding to the above-mentioned optional implementation methods, embodiments of this application also provide an authentication method for a distributed network applied to a DLT-based management system, the method comprising:
[0109] The DLT-based management system receives a second token verification request sent by a first network element, the second token verification request carrying a token from a third device.
[0110] In response to the received first token verification request, the token of the third device is verified;
[0111] A token verification response is sent to the first network element, the token verification response carrying the verification result of the token of the third device.
[0112] Embodiments of this application also provide an authentication method for a distributed network, applied to a second device, such as... Figure 4 As shown, the method includes:
[0113] Step 401: Send request information to the first network element. The request information includes at least one of the following: a second authentication request for requesting a token from the second device; a first token verification request for verifying a token from the third device; wherein the second device and the first network element are deployed in the same subnet, and the second device and the third device are deployed in different subnets.
[0114] Here, when the request information is a first token verification request, the second device is used to authenticate the third device. That is, the third device is the device that needs the second device to perform inter-subnet device authentication.
[0115] Step 402: Receive the response information sent by the first network element.
[0116] It should be noted that when the request information is the second authentication request, the above-mentioned optional implementation method is that the first network element provides a token to the second device, so that the second device can request devices in other subnets to authenticate the second device based on the token provided by the first network element; when the request information is the first token verification request, the above-mentioned optional implementation method is that the first network element assists the second device in authenticating a third device in another subnet. In this way, mutual authentication between devices in different subnets can be achieved.
[0117] Based on this, by way of example, when the request information includes the second authentication request, the response information carries the token of the second device;
[0118] Alternatively, when the request information includes the first token verification request, the request information carries the token of the third device. In this case, the response information carries the token verification result.
[0119] It should also be noted that the authentication between devices in different subnets needs to be performed after the subnet authentication is successful. In other words, the authentication level between devices in different subnets is higher than the authentication level between subnets.
[0120] In the distributed network authentication method of this application, firstly, a second device sends request information to a first network element. The request information includes at least one of the following: a second authentication request for authenticating the second device; and a first token verification request for verifying the token of a third device. The second device and the first network element are deployed in the same subnet, while the second device and the third device are deployed in different subnets. Secondly, the second device receives response information sent by the first network element. Thus, through the interaction between the second device and the first network element, the second device's token can be obtained, facilitating subsequent device authentication requests from devices in other subnets based on this token. And / or, through the interaction between the second device and the first network element, the token of a third device deployed in another subnet can be verified, enabling mutual authentication between devices deployed in different subnets.
[0121] Furthermore, as an optional implementation, if the request information includes the second authentication request, after step 402, the method further includes:
[0122] A first service request is sent to a fourth device, the first service request carrying the token of the second device, the second device and the fourth device being deployed in different subnets; here, the fourth device is the device that performs inter-subnet device authentication for the second device.
[0123] The system receives a first service response from the fourth device. This first service response carries a token verification result. If the token verification result indicates successful token verification, it means the fourth device has successfully authenticated the second device; otherwise, it means the fourth device has failed to authenticate the second device.
[0124] Based on the above-mentioned optional implementation methods, embodiments of this application also provide an authentication method applied to a distributed network of a fourth device, the method comprising:
[0125] The fourth device receives a first service request sent by the second device, the first service request carrying the token of the second device;
[0126] In response to the first service request, the fourth device sends a token verification request to the first network element in the subnet where the fourth device is located. The token verification request carries the token of the second device. The first network element in the subnet where the fourth device is located is used to verify the token of the second device.
[0127] The fourth device receives a token verification response sent by the first network element in the subnet where the fourth device is located, and the token verification response carries the token verification result;
[0128] The fourth device sends a first service response to the second device, and the first service response carries the token verification result.
[0129] As an optional implementation, if the request information includes the first token verification request:
[0130] Before step 401, the method further includes:
[0131] The system receives a second service request sent by a third device, the second service request carrying the token of the third device; here, the third device is a device that requires the second device to perform inter-subnet device authentication.
[0132] After step 402, the method further includes:
[0133] Based on the response information, a second service response is sent to the third device; wherein the second service response carries the verification result of the token of the third device by the second device.
[0134] Based on the above-mentioned optional implementation methods, embodiments of this application also provide an authentication method applied to a distributed network of a third device, the method comprising:
[0135] The third device sends a second service request to the second device, the second service request carrying the token of the third device;
[0136] Receive a second service response from the second device, the second service response carrying the verification result of the token of the third device.
[0137] As an optional implementation, if the request information is the second authentication request, the request information is sent to the first network element, including:
[0138] If it is determined that inter-subnet device authentication is required based on subnet information and / or authentication level requirements, the request information is sent to the first network element, wherein the subnet information includes the number of subnets and / or the subnet type.
[0139] In other words, in the embodiments of this application, generally, successful subnet authentication means that all devices within the subnet have been authenticated. However, authentication between devices in different subnets is conditional. For example, depending on the number and type of distributed subnets and the authentication level requirements, the method of subnet authentication or network element authentication can be selected, thus providing flexibility for distributed subnet network element authentication.
[0140] The following describes various specific embodiments of the distributed network architecture described above in this application, with reference to the accompanying drawings.
[0141] like Figure 5 As shown, the distributed network architecture includes network_a, network_b, and network_c. The PKI-based authentication process of this distributed network includes:
[0142] First, the first network element in network _a ( Figure 5 In network _a (DSAF) and the first network element in network _b ( Figure 5 In network _b (DSAF) and the first network element in network _c ( Figure 5 The network _c(DSAF) in the middle sends to the first node ( Figure 5 The central node (bridge CA) in the network sends an authentication request, which carries the public key certificate of the sending entity (DSAF in each network).
[0143] Secondly, the first node sends an authentication response to the entity that sent the authentication request, wherein the authentication response carries a first token for network _a. This first token is then used by the first network element to perform inter-subnet authentication with other subnets.
[0144] like Figure 6 As shown, the distributed network architecture includes network_a, network_b, and network_c. The DPKI authentication process based on blockchain in this distributed network includes:
[0145] First, the first network element in network _a ( Figure 6In network _a (DSAF) and the first network element in network _b ( Figure 6 In network _b (DSAF) and the first network element in network _c ( Figure 6 The network _c(DSAF) in the middle sends to the first node ( Figure 6 The certificate registration is sent by a DLT-based certificate management system, wherein the certificate registration carries information such as the certificate and / or authentication credentials of the sending subject.
[0146] Secondly, the first network element in each network sends an authentication request to the first node; the authentication request carries the public key certificate or certificate identifier of the sending entity.
[0147] Next, the first node sends an authentication response to the entity that sent the authentication request. This authentication response carries the first token for network _a. The first network element then uses this first token to perform inter-subnet authentication with other subnets.
[0148] like Figure 7 As shown, the distributed network architecture includes two security domains (security domain _a and security domain _b), where each security domain represents a subnet within the distributed network architecture; N1_a represents devices deployed in network _a (such as network element devices), and N1_b represents devices deployed in network _b; after network authentication in the above architecture is successful, the device authentication process between subnets in PKI-based authentication includes:
[0149] First, devices deployed in the subnet (such as...) Figure 7 N1_a) in the network is directed to the first network element in the network (e.g., Figure 7 The network _a(DSAF) sends an authentication request;
[0150] Secondly, the first network element sends an authentication response back to the entity that sent the authentication request, wherein the authentication response carries the token of the sending entity;
[0151] Secondly, the entity sending the authentication request addresses a device in another subnet (such as...). Figure 7 In N1_b), a service request is sent, wherein the service request carries the token of the sending subject;
[0152] Then, devices in another subnet (such as...) Figure 7 N1_b) in the network is directed to the first network element of its subnet (e.g., Figure 7 The network _b(DSAF) sends a token verification request, which carries the token received by the device (the token of the sending body of the service request);
[0153] Then, devices in another subnet (such as...) Figure 7N1_b) sends a service response back to the entity that sent the service request; the service response carries the token verification result.
[0154] like Figure 8 As shown, the distributed network architecture includes two security domains (security domain_a and security domain_b), where each security domain represents a subnet within the distributed network architecture; N1_a represents devices deployed in network_a (such as network element devices), and N1_b represents devices deployed in network_b; after network authentication in the above architecture is successful, the device authentication process between subnets in the blockchain-based DPKI authentication includes:
[0155] First, devices deployed in the subnet (such as...) Figure 8 N1_a) in the network is directed to the first network element in the network (e.g., Figure 8 The network _a(DSAF) sends an authentication request;
[0156] Secondly, the first network element sends an authentication response back to the entity that sent the authentication request, wherein the authentication response carries the token of the sending entity;
[0157] Secondly, the entity sending the authentication request addresses a device in another subnet (such as...). Figure 8 In N1_b), a service request is sent, wherein the service request carries the token of the sending subject;
[0158] Then, devices in another subnet (such as...) Figure 8 N1_b) in the network is directed to the first network element of its subnet (e.g., Figure 8 The network _b(DSAF) sends a token verification request, which carries the token received by the device (the token of the sending body of the service request);
[0159] Then, the first network element of another subnet (such as...) Figure 8 The network _b(DSAF) in the DLT-based management system forwards the token authentication request to the DLT-based management system and receives the token verification response from the DLT-based management system, wherein the token verification response carries the token verification result;
[0160] Then, the first element of another subnet (such as...) Figure 8 In the network_b(DSAF)) to the devices in its network element (such as Figure 8 The N1_b) forwards the token verification response.
[0161] Finally, devices in another subnet (such as...) Figure 8 In N1_b), a service response is sent back to the entity that sent the service request, where the service response carries the token verification result.
[0162] Embodiments of this application also provide an authentication device for a distributed network, applied to a first network element in a subnet of the distributed network architecture described above, the device comprising:
[0163] The first sending module is used to send a first authentication request to the first node, wherein the first authentication request is used to request authentication of the subnet where the first network element is located;
[0164] The first receiving module is used to receive the first authentication response sent by the first node. The first authentication response carries the first token of the subnet where the first network element is located. The first token is used for identity authentication with other subnets.
[0165] In the case where the authentication in the distributed network is based on a centralized public key infrastructure (PKI), the first node is the central node, and the first authentication request carries the public key certificate of the first network element.
[0166] In the case of authentication in the distributed network being based on the Distributed Public Key Infrastructure (DPKI) blockchain, the first node is a distributed ledger node based on a certificate management system, and the first authentication request carries the public key certificate of the first network element or the certificate identifier of the first network element.
[0167] The device further includes:
[0168] The second sending module is used to send a certificate registration message to the first node before the first sending module sends the first authentication request to the first node.
[0169] The device further includes:
[0170] The second receiving module is configured to receive request information sent by the second device after the first receiving module receives the first authentication response sent by the first node; the request information includes: a second authentication request for requesting a token from the second device; and / or a first token verification request for verifying a token from the third device; wherein the second device and the first network element are deployed in the same subnet, and the second device and the third device are deployed in different subnets;
[0171] The third sending module is used to send response information to the second device in response to the request information.
[0172] Wherein, when the request information includes the second authentication request, the response information carries the token of the second device;
[0173] Alternatively, when the request information includes the first token verification request, the request information carries the token of the third device.
[0174] The device further includes:
[0175] The fourth sending module is configured to send a second token verification request to the first node according to the request information before the third sending module sends the response information to the second device when the first node is a distributed ledger node based on a certificate management system, when the request information includes the first token verification request; the second token verification request carries the token of the third device.
[0176] The third receiving module is used to receive the token verification response sent by the first node;
[0177] Specifically, the third sending module is used to: send the response information to the second device based on the token verification response.
[0178] Embodiments of this application also provide an authentication device for a distributed network, applied to a second device, the device comprising:
[0179] A first sending module is configured to send request information to a first network element, the request information including at least one of the following: a second authentication request, used to request authentication of the second device; a first token verification request, used to verify the token of the third device; wherein the second device and the first network element are deployed in the same subnet, and the second device and the third device are deployed in different subnets;
[0180] The first receiving module is used to receive the response information sent by the first network element.
[0181] When the request information includes the second authentication request, the response information carries the token of the second device;
[0182] And / or, when the request information includes the first token verification request, the request information carries the token of the third device.
[0183] The device further includes:
[0184] The second sending module is configured to, when the request information includes the second authentication request, after the first receiving module receives the response information sent by the first network element, send a first service request to the fourth device, wherein the first service request carries the token of the second device, and the second device and the fourth device are deployed in different subnets;
[0185] The second receiving module is used to receive the first service response sent by the fourth device.
[0186] The device further includes:
[0187] The third receiving module is configured to, when the request information includes the first token verification request, receive a second service request sent by the third device before the first sending module sends the request information to the first network element, wherein the second service request carries the token of the third device.
[0188] The third sending module is configured to, when the request information includes the first token verification request: after the first receiving module receives the response information sent by the first network element, send a second service response to the third device based on the response information.
[0189] Specifically, the first sending module is used to send the request information to the first network element when the request information is the second authentication request and when it is determined that inter-subnet device authentication is required based on subnet information and / or authentication level requirements. The subnet information includes the number of subnets and / or the subnet type.
[0190] An embodiment of this application also provides a network element, which is the first network element in a subnet of the distributed network architecture as described above. The network element includes a transceiver, a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, it implements the authentication method of the distributed network applied to the first network element as described above, and achieves the same effect. To avoid repetition, it will not be described again here.
[0191] An embodiment of this application also provides a communication device, which is the second device as described above. The device includes a transceiver, a processor, a memory, and a program stored in the memory and executable on the processor. When the processor executes the program, it implements the authentication method for the distributed network applied to the second device as described above, and achieves the same effect. To avoid repetition, it will not be described again here.
[0192] Embodiments of this application also provide a readable storage medium storing a program or instructions thereon. When the program or instructions are executed by a processor, they implement the authentication method described above for a distributed network applied to a first network element or a second device, and can achieve the same technical effect. To avoid repetition, it will not be described again here.
[0193] The processor is the processor in the first network element or the second device described in the above embodiments. The readable storage medium includes computer-readable storage media, such as computer read-only memory (ROM), random access memory (RAM), magnetic disk, or optical disk.
[0194] Through the above description of the embodiments, those skilled in the art can clearly understand that the methods of the above embodiments can be implemented by means of software plus necessary general-purpose hardware platforms. Of course, they can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, disk, optical disk) and includes several instructions for executing the methods described in the various embodiments of this application.
[0195] Therefore, embodiments of this application also provide a computer program product, including computer instructions, which, when executed by a processor, implement the authentication method for a distributed network applied to a first network element or a second device as described above, and can achieve the same technical effect. To avoid repetition, it will not be described again here.
[0196] In this embodiment, the module can be implemented in software so that it can be executed by various types of processors. For example, an identified executable code module may include one or more physical or logical blocks of computer instructions, which may be constructed as objects, procedures, or functions. Nevertheless, the executable code of the identified module does not need to be physically located together, but may include different instructions stored in different bits, which, when logically combined, constitute the module and achieve the module's intended purpose.
[0197] In practice, an executable code module can be a single instruction or many instructions, and can even be distributed across multiple different code segments, different programs, and across multiple memory devices. Similarly, operational data can be identified within the module and can be implemented in any suitable form and organized within any suitable type of data structure. This operational data can be collected as a single dataset or distributed across different locations (including different storage devices), and can exist, at least in part, solely as electronic signals within the system or network.
[0198] When a module can be implemented using software, considering the current level of hardware technology, modules that can be implemented in software can be implemented using hardware circuits by those skilled in the art to achieve the corresponding functions, without considering cost. These hardware circuits include conventional very-large-scale integrated circuits (VLSI) or gate arrays, as well as existing semiconductors such as logic chips and transistors, or other discrete components. Modules can also be implemented using programmable hardware devices, such as field-programmable gate arrays, programmable array logic, and programmable logic devices.
[0199] The exemplary embodiments described above are with reference to the accompanying drawings. Many different forms and embodiments are feasible without departing from the spirit and teachings of this application. Therefore, this application should not be construed as limiting the exemplary embodiments set forth herein. Rather, these exemplary embodiments are provided to make this application complete and convey the scope of this application to those skilled in the art. In these drawings, component dimensions and relative dimensions may be exaggerated for clarity. The terminology used herein is for the purpose of describing particular exemplary embodiments only and is not intended to be limiting. As used herein, unless clearly indicated otherwise, the singular forms “a,” “an,” and “the” are intended to include all such forms. It will be further understood that the terms “comprising” and / or “including”, when used in this specification, indicate the presence of the stated features, integers, steps, operations, components, and / or elements, but do not exclude the presence or addition of one or more other features, integers, steps, operations, components, and / or groups thereof. Unless otherwise indicated, when stated, a range of values includes the upper and lower limits of the range and any subranges in between.
[0200] The above description is the preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principles described in this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. A distributed network architecture, characterized in that, It includes multiple subnets; wherein a first network element is deployed in each of the subnets; In distributed network authentication, the first network element is used to represent the identity of the subnet to which the first network element is located; And / or, The first network element has security protection functions.
2. The distributed network architecture according to claim 1, characterized in that, The authentication method for the subnet is as follows: authenticating the first network element that represents the identity of the subnet.
3. The distributed network architecture according to claim 1, characterized in that, Different subnets communicate with each other through the first network element; A secure channel is established between the first network elements of different subnets.
4. The distributed network architecture according to claim 1 or 3, characterized in that, The security protection functions include one or more of the following: topology hiding function, signaling monitoring and filtering function, and data transmission encryption function.
5. The distributed network architecture according to any one of claims 1 to 4, characterized in that, The first network element is a first logical functional entity, or the first network element is an extended function of the first device; wherein the first device includes at least one of network element device, network device, Security Edge Protection Agent (SEPP), and Security Gateway (SEG).
6. An authentication method for a distributed network, characterized in that, The method, applied to a first network element in a subnet of a distributed network architecture as described in any one of claims 1 to 5, comprises: Send a first authentication request to the first node. The first authentication request is used to request authentication of the subnet where the first network element is located. The system receives a first authentication response sent by the first node. The first authentication response carries a first token of the subnet where the first network element is located. The first token is used for identity authentication with other subnets.
7. The method according to claim 6, characterized in that, When authentication in a distributed network is based on a centralized public key infrastructure (PKI), the first node is the central node, and the first authentication request carries the public key certificate of the first network element.
8. The method according to claim 6, characterized in that, When the authentication in the distributed network is based on the distributed public key infrastructure (DPKI) blockchain, the first node is a distributed ledger node based on a certificate management system; the first authentication request carries the public key certificate of the first network element or the certificate identifier of the first network element.
9. The method according to claim 8, characterized in that, When the first node is a distributed ledger node based on a certificate management system, before sending the first authentication request to the first node, the method further includes: Send a certificate registration message to the first node.
10. The method according to claim 6, characterized in that, After receiving the first authentication response sent by the first node, the method further includes: Receive request information sent by the second device; the request information includes: a second authentication request for requesting a token from the second device; and / or a first token verification request for verifying a token from the third device; wherein the second device and the first network element are deployed in the same subnet, and the second device and the third device are deployed in different subnets; In response to the request information, a response information is sent to the second device.
11. The method according to claim 10, characterized in that, When the request information includes the second authentication request, the response information carries the token of the second device; Alternatively, when the request information includes the first token verification request, the request information carries the token of the third device.
12. The method according to claim 10, characterized in that, Before sending response information to the second device when the request information includes the first token verification request, the method further includes: When the first node is a distributed ledger node based on a certificate management system, a second token verification request is sent to the first node according to the request information, and the second token verification request carries the token of the third device; Receive the token verification response sent by the first node; Sending response information to the second device, including: Based on the token verification response, the response information is sent to the second device.
13. An authentication method for a distributed network, characterized in that, Applied to a second device, the method includes: Sending request information to a first network element, the request information including at least one of the following: a second authentication request for requesting authentication of the second device; a first token verification request for verifying the token of the third device; wherein the second device and the first network element are deployed in the same subnet, and the second device and the third device are deployed in different subnets; Receive the response information sent by the first network element.
14. The method according to claim 13, characterized in that, When the request information includes the second authentication request, the response information carries the token of the second device; And / or, when the request information includes the first token verification request, the request information carries the token of the third device.
15. The method according to claim 14, characterized in that, If the request information includes the second authentication request, after receiving the response information sent by the first network element, the method further includes: A first service request is sent to a fourth device, the first service request carrying the token of the second device, the second device and the fourth device being deployed in different subnets; Receive the first service response sent by the fourth device.
16. The method according to claim 13, characterized in that, If the request information includes the first token verification request: Before sending the request information to the first network element, the method further includes: Receive a second service request sent by a third device, the second service request carrying the token of the third device; After receiving the response information sent by the first network element, the method further includes: Based on the response information, a second service response is sent to the third device.
17. The method according to claim 13, characterized in that, If the request information is the second authentication request, send the request information to the first network element, including: If it is determined that inter-subnet device authentication is required based on subnet information and / or authentication level requirements, the request information is sent to the first network element, wherein the subnet information includes the number of subnets and / or the subnet type.