A dynamic access control method and device applied to a B5G network, equipment and medium
Patent Information
- Application Number
- CN202511427924.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-09-30
- Publication Date
- 2026-09-29
- Estimated Expiration
- 2045-09-30
AI Technical Summary
然而,这种基于静态证书的认证机制的有效期通常较长,授权更新较为滞后,无法及时撤销或更新已授权的网元,存在数据访问的安全性和网络的整体可靠性低的问题
[0021]本公开实施例的技术方案,应用于授权服务网元中,对于任一服务请求网元,接收服务请求网元所发送的数据访问请求,以在数据访问请求中的网元信息满足预设条件时,存储网元信息并将网元信息发送至区块链,以基于区块链确定与网元信息相对应的初始访问令牌后并反馈。然后,接收服务请求网元所发送至的签名信息和证书信息,并在签名信息与存储的网元信息相一致时,对证书信息进行验证,以在验证通过时确定目标网元所对应的地址信息。进一步的,根据状态转移树和服务请求网元当前所对应的协议状态,确定服务请求网元所对应的行为鉴别结果为第一结果时,提取目标网元所对应网元标识,并基于网元标识调取目标网元的目标地址,以及将网元信息发送至区块链,以从区块链基于网元信息获取服务请求网元的初始访问令牌。最后,将初始访问令牌以及目标地址发送至服务请求网元,以使服务请求网元基于接收到的目标地址和初始访问令牌访问目标网元,解决了现有技术中网元之间进行数据访问的安全设计主要依赖公钥密码体系进行认证和授权,通过对公钥证书的验证来确认网元身份,因静态证书的认证机制的有效期通常较长,授权更新较为滞后,无法及时撤销或更新已授权的网元,存在数据访问的安全性和网络的整体可靠性低的问题。本公开实施例实现了在B5G网络中,基于区块链确定与服务请求网元的访问令牌,根据状态转移树确定目标网元的目标地址后,服务请求网元基于访问令牌动态访问目标网元,实现了对服务请求网元的动态访问控制,确保服务请求网元能够安全、高效地访问目标网元,达到提升B5G网络整体的安全性和响应能力的效果。
Smart Images

Figure CN121218176B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the field of communication technology, and in particular to a dynamic access control method, apparatus, device, and medium applied to B5G networks. Background Technology
[0002] B5G networks have entered a period of intense technological development. In B5G networks, the network architecture is constantly evolving, significantly increasing complexity, and data access and interaction between network elements are frequent. Therefore, effectively ensuring the security of data access is a key issue that B5G networks need to consider.
[0003] Currently, B5G networks primarily rely on public-key cryptography for data access security, verifying network element identities through public key certificate authentication. However, this static certificate-based authentication mechanism typically has a long validity period and delayed authorization updates, making it difficult to revoke or update authorized network elements in a timely manner. This results in security issues for data access and low overall network reliability. Summary of the Invention
[0004] This disclosure provides a dynamic access control method, apparatus, device, and medium for B5G networks, which enables dynamic access control of service requesting network elements, thereby enhancing the security of access control for service requesting network elements and improving the overall security of the B5G network.
[0005] In a first aspect, embodiments of this disclosure provide a dynamic access control method applied to a B5G network, the method comprising:
[0006] For any service requesting network element, receive the data access request sent by the service requesting network element, and when the network element information in the data access request meets the preset conditions, store the network element information and send the network element information to the blockchain, and then determine the initial access token corresponding to the network element information based on the blockchain and provide feedback.
[0007] The system receives signature information and certificate information sent by the network element requesting the service, and verifies the certificate information when the signature information matches the stored network element information. If the verification is successful, the system determines the address information corresponding to the target network element, wherein the target network element is the network element to be accessed by the network element requesting the service.
[0008] Based on the state transition tree and the protocol state corresponding to the current service request network element, when the behavior identification result corresponding to the service request network element is determined to be the first result, the network element identifier corresponding to the target network element is extracted, and the target address of the target network element is retrieved based on the network element identifier, and the network element information is sent to the blockchain, so as to obtain the initial access token of the service request network element from the blockchain based on the network element information.
[0009] The initial access token and the target address are sent to the service requesting network element, so that the service requesting network element can access the target network element based on the received target address and initial access token.
[0010] Secondly, embodiments of the present invention also provide a dynamic access control device for B5G networks, the device comprising:
[0011] The initial access token determination module is used to receive a data access request sent by any service requesting network element, and when the network element information in the data access request meets a preset condition, store the network element information and send the network element information to the blockchain, and determine the initial access token corresponding to the network element information based on the blockchain and then provide feedback.
[0012] The address information determination module is used to receive the signature information and certificate information sent by the service request network element, and verify the certificate information when the signature information is consistent with the stored network element information, so as to determine the address information corresponding to the target network element when the verification is successful, wherein the target network element is the network element to be accessed by the service request network element;
[0013] The initial access token acquisition module is used to extract the network element identifier corresponding to the target network element when the behavior identification result corresponding to the service request network element is determined to be the first result based on the state transition tree and the protocol state corresponding to the current service request network element, and to retrieve the target address of the target network element based on the network element identifier, and to send the network element information to the blockchain, so as to obtain the initial access token of the service request network element from the blockchain based on the network element information.
[0014] The target network element access module is used to send the initial access token and the target address to the service request network element, so that the service request network element can access the target network element based on the received target address and initial access token.
[0015] Thirdly, embodiments of the present invention also provide an electronic device, the electronic device comprising:
[0016] One or more processors;
[0017] Storage device for storing one or more programs.
[0018] When the one or more programs are executed by the one or more processors, the one or more processors implement the dynamic access control method for B5G networks as described in any embodiment of the present invention.
[0019] Fourthly, embodiments of the present invention also provide a storage medium containing computer-executable instructions, which, when executed by a computer processor, are used to perform a dynamic access control method applied to a B5G network as described in any embodiment of the present invention.
[0020] Fifthly, embodiments of the present invention also provide a computer program product, including a computer program, characterized in that, when executed by a processor, the computer program implements the dynamic access control method applied to a B5G network as described in any embodiment of the present invention.
[0021] The technical solution of this disclosure embodiment is applied to an authorized service network element. For any service request network element, a data access request sent by the service request network element is received. When the network element information in the data access request meets preset conditions, the network element information is stored and sent to the blockchain. Based on the blockchain, an initial access token corresponding to the network element information is determined and fed back. Then, signature information and certificate information sent by the service request network element are received. When the signature information is consistent with the stored network element information, the certificate information is verified. When the verification is successful, the address information corresponding to the target network element is determined. Further, based on the state transition tree and the protocol state corresponding to the service request network element, when the behavior authentication result corresponding to the service request network element is determined as the first result, the network element identifier corresponding to the target network element is extracted, and the target address of the target network element is retrieved based on the network element identifier. The network element information is also sent to the blockchain to obtain the initial access token of the service request network element from the blockchain based on the network element information. Finally, the initial access token and the target address are sent to the requesting network element, enabling the requesting network element to access the target network element based on the received target address and initial access token. This addresses the problem in existing technologies where data access between network elements primarily relies on public-key cryptography for authentication and authorization. The verification of public key certificates confirms the network element's identity, but static certificates typically have long validity periods, leading to delayed authorization updates and the inability to promptly revoke or update authorized network elements, resulting in low data access security and overall network reliability. This embodiment of the present disclosure implements a B5G network approach where, based on blockchain, an access token for the requesting network element is determined. After determining the target address of the target network element according to the state transition tree, the requesting network element dynamically accesses the target network element based on the access token. This achieves dynamic access control for the requesting network element, ensuring secure and efficient access to the target network element, thereby improving the overall security and responsiveness of the B5G network. Attached Figure Description
[0022] To more clearly illustrate the technical solutions of exemplary embodiments of the present invention, the accompanying drawings used in describing the embodiments are briefly introduced below. Obviously, the accompanying drawings described are only a portion of the drawings of the embodiments to be described in this invention, and not all of the drawings. For those skilled in the art, other drawings can be obtained from these drawings without any creative effort.
[0023] Figure 1 This is a flowchart illustrating a dynamic access control method applied to a B5G network provided in an embodiment of this disclosure.
[0024] Figure 2 This is a flowchart illustrating a dynamic access control method applied to a B5G network provided in an embodiment of this disclosure.
[0025] Figure 3 A schematic diagram of the structure of a dynamic access control device applied to a B5G network provided in an embodiment of this disclosure;
[0026] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this disclosure. Detailed Implementation
[0027] The present invention will now be described in further detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are merely illustrative of the invention and not intended to limit it. Furthermore, it should be noted that, for ease of description, the accompanying drawings show only the parts relevant to the present invention, and not all of the structures.
[0028] Before introducing the technical solutions provided in the embodiments of this disclosure, the application scenarios can be illustrated first. The technical solutions provided in the embodiments of this disclosure can be applied to scenarios where network elements in a B5G network access each other for data. For example, in a smart city environment, various sensors, surveillance cameras, and other IoT devices frequently access and interact with each other in the B5G network. This can be applied to the above scenario to ensure dynamic access control between network elements, thereby improving the security and efficiency of urban infrastructure.
[0029] It's important to note that B5G networks refer to network architectures and technologies that evolve further from 5G technology, aiming to meet future demands for higher data transmission rates, lower latency, and massive connectivity. B5G networks can support a wider range of application scenarios, including but not limited to the Internet of Things (IoT), smart cities, autonomous driving, and virtual reality. In a B5G network, a "network element" is a fundamental component, typically referring to an independent functional unit such as a base station, router, or switch. Each network element is responsible for a specific network function and interconnects and communicates within the B5G network through standardized interfaces.
[0030] It should also be noted that the requesting network element is the network element that initiates the service request, typically a user device or application. The requesting network element sends a request to the B5G network, seeking access to a specific network element. The authorizing network element is responsible for verifying and authorizing the access of the requesting network element. The authorizing network element ensures that the requesting network element accessing the B5G network has the appropriate permissions; only verified requesting network elements can access specific network elements. The target network element is the provider of the specific resource or service requested by the service request; that is, the network element the requesting network element is trying to access. The target network element can be a data center, cloud computing platform, or other network functional components, responsible for responding to the request from the requesting network element. The target network element processes the request from the requesting network element and returns the result.
[0031] Based on the technical solution of this disclosure embodiment, in a B5G network, after determining the access token of the service requesting network element based on the blockchain and determining the target address of the target network element according to the state transition tree, the service requesting network element dynamically accesses the target network element based on the access token. This realizes dynamic access control of the service requesting network element, ensuring that the service requesting network element can access the target network element securely and efficiently, thereby improving the overall security and responsiveness of the B5G network.
[0032] Example 1
[0033] Figure 1 This is a flowchart illustrating a dynamic access control method for B5G networks provided in this disclosure embodiment. This disclosure embodiment is applicable to situations where data access occurs between network elements in a B5G network. The method can be executed by a dynamic access control device for B5G networks. This device can be implemented in the form of software and / or hardware. The hardware can be a mobile electronic device. This electronic device can execute the dynamic access control method for B5G networks provided in this technical solution.
[0034] like Figure 1 As shown, the method includes:
[0035] S110. For any service requesting network element, receive the data access request sent by the service requesting network element, and when the network element information in the data access request meets the preset conditions, store the network element information and send the network element information to the blockchain, and then determine the initial access token corresponding to the network element information based on the blockchain and provide feedback.
[0036] In this context, a service requesting network element is a network component or device that initiates a data access request. For example, a service requesting network element can be a user terminal. An authorizing service network element is a network component responsible for verifying and authorizing the service requesting network element to access specific resources or services. The authorizing service network element ensures that only authenticated requests can obtain the corresponding access permissions. A data access request is a request message sent by the service requesting network element to the authorizing service network element, aiming to obtain access permissions to specific data or resources. The data access request contains necessary information for the authorizing service network element to verify and process the service requesting network element. The data access request includes at least a first identifier of the service requesting network element based on the public key corresponding to the authorizing service network element, additional information related to the service requesting network element, a requested access address, and a data access request encrypted with a first timestamp. Network element information includes at least a first identifier, additional information related to the service requesting network element, and a requested access address. Blockchain is a distributed ledger technology that enables the storage and management of data in a decentralized environment. A blockchain consists of a series of blocks linked chronologically, each block containing a set of transaction records. The initial access token is a credential generated by the blockchain and returned to the authorizing service network element. Initial access tokens typically contain information about access permissions and other relevant details, and may be stored in encrypted form to ensure their security.
[0037] It should be noted that the first identifier refers to the unique identifier of the service requesting network element, used to distinguish different service requesting network elements. The first identifier is usually an ID associated with a device or user. Additional information related to the service requesting network element refers to Info. Info includes additional information related to the service requesting network element, such as the device type, user role, specific content of the request, or other relevant information. The request access address refers to the network address of the target network element that the service requesting network element wishes to access. The request access address can be an API endpoint, a database address, or other accessible resource location. The first timestamp is a timestamp recording the time when the data access request sent by the service requesting network element was initiated. The first timestamp is usually represented in a standard format to ensure the timeliness and order of data access requests.
[0038] It should also be noted that after the authorized service network element sends its network element information to the blockchain, the network element information of the service requesting network element is stored in a new block, ensuring the security, transparency, and immutability of the network element information. The smart contract on the blockchain executes logical processing based on the stored network element information to generate a corresponding initial access token. Subsequently, the generated initial access token is sent back to the authorized service network element.
[0039] Optionally, the data access request is decrypted based on the private key corresponding to the authorized service network element to obtain a first timestamp. When the time difference between the first timestamp and the current timestamp is less than a preset time threshold, the decrypted network element information is obtained. The network element information is stored in a preset format, and a portion of the data in the network element information is signed and sent to the blockchain along with the network element information. After the target data with the signed data is verified by the blockchain, the initial access token corresponding to the service request network element is determined.
[0040] In this context, the private and public keys corresponding to the authorized service network element are paired keys, typically used for encrypting and decrypting data. Anyone can access the public key of the authorized service network element to encrypt information. The current timestamp refers to the moment when the data access request decryption process is completed. The preset format refers to the specific structure followed when storing network element information. Part of the data in the network element information refers to the first identifier within the network element information. Signature processing refers to the authorized service network element using its private key to encrypt the first identifier in the network element information. After encrypting the first identifier in the network element information, the result is the target data.
[0041] It should be noted that the service requesting network element encrypts the data access request based on the public key corresponding to the authorized service network element, and sends the encrypted data access request to the authorized service network element. After receiving the encrypted service request from the service requesting network element, the authorized service network element decrypts the data access request based on the private key corresponding to the authorized service network element's public key, and obtains the first identifier of the service requesting network element, additional information related to the service requesting network element, the requested access address, and the first timestamp.
[0042] It should also be noted that for the first timestamp of the service request network element obtained after decryption, the time difference between the first timestamp and the current timestamp is calculated. If the time difference is less than a preset time threshold, the first identifier, Info, and request access address of the service request network element are obtained. For example, when the preset time threshold is 0.1 seconds and the time difference is 0.01 seconds, the authorized service network element obtains the network element information of the service request network element. By verifying the validity of the first timestamp, it is ensured that the data access request was recently initiated, preventing attackers from repeatedly sending old requests to achieve deception or interference, and ensuring the credibility of the data access request. The authorized service network element only processes legitimate requests within the time limit, avoiding invalid or expired requests.
[0043] In this embodiment, the first identifier is hashed based on the hash algorithm of the service request network element to obtain a stored hash value; and a stored value is obtained by concatenating the additional information in the network element information and the request access address; the first identifier is signed based on a preset signature algorithm to obtain target data, and the target data and the additional information in the network element information are sent to the blockchain, so that after the blockchain verifies the target data based on the signature verification algorithm, an initial access token is allocated to the service request network element, and the token identifier and corresponding permission information of the initial access token are stored.
[0044] Here, a hash algorithm is used to map data of arbitrary length to a hash value of fixed length. Storing the hash value refers to the result obtained after hashing the first identifier. Attachment information refers to Info. Storing the value refers to the result obtained by concatenating Info and the requested access address. The preset signature algorithm refers to the algorithm used when signing the first identifier based on the private key of the authorized service network element. The signature verification algorithm refers to the algorithm used when verifying the target data based on the private key of the authorized service network element. The token identifier is a unique string used to identify and verify the validity of the initial access token. Each token identifier is unique. The corresponding permission information describes the specific permissions and restrictions of the service requesting network element when using this token, including accessible resources, access level, and validity period.
[0045] It should be noted that after selecting a hash algorithm, the first identifier is passed as input to the hash algorithm. After hashing the first identifier, a storage hash value corresponding to the first identifier is obtained. This storage hash value is then stored in the authorized service network element. For example, the hash algorithm could be SHA-256. After extracting the Info and requested access address from the network element information, a specific delimiter can be used to concatenate the Info and requested access address together. For example, "|" or ":" can be used to concatenate the Info and requested access address from the network element information.
[0046] It should also be noted that the first identifier can be signed using the private key of the authorized service network element to generate a signature SID, which is the target data. For example, the preset signature algorithm can be RSA, DSA, or other encryption algorithms. The blockchain can verify the target data using the public key of the authorized service network element. During signature verification, the target data and the original data are extracted, and then the target data is decrypted using the public key of the authorized service network element. The decrypted result is compared with the original data. If the decrypted result is the same as the original data, it means that the signature is valid and the data has not been tampered with during transmission. The blockchain can confirm the validity of the signature, indicating that the integrity and origin of the data have been verified. Once the signature verification is successful, the blockchain can assign an initial access token to the service requesting network element.
[0047] Specifically, the requesting network element encrypts the data access request using the public key of the authorizing service network element, and then sends the encrypted data access request to the authorizing service network element. Upon receiving the data access request from the requesting network element, the authorizing service network element decrypts the data access request using its private key corresponding to its public key, obtaining the network element information of the requesting network element. When the first timestamp in the network element information is less than a preset time threshold, the decrypted network element information is retrieved. The first identifier, Info, and request access address from the network element information are stored in the authorizing service network element in a preset format. The signed first identifier and Info are then sent to the blockchain. After the blockchain verifies the signed first identifier, it assigns an initial access token to the requesting network element and stores the token identifier and corresponding permission information of the initial access token in the block.
[0048] S120. Receive the signature information and certificate information sent by the service requesting network element, and verify the certificate information when the signature information matches the stored network element information, so as to determine the address information corresponding to the target network element when the verification is successful.
[0049] The target network element is the network element that the service requesting network element wants to access. When the authorized service network element receives feedback information from the blockchain indicating that an initial access token has been generated, it sends the feedback information back to the service requesting network element. The moment when the service requesting network element receives the feedback information from the authorized service network element is defined as the second timestamp. The signature information refers to the information obtained by signing the first identifier and the second timestamp.
[0050] It should be noted that certificate information refers to the digital certificate associated with the requesting network element, typically issued by a trusted certificate authority. Digital certificates are used to verify the identity of an entity corresponding to the requesting network element and ensure the authenticity of its public key. Certificate information may include the public key of the requesting network element, the identity information of the certificate holder, the issuer information, the validity period, and a signature obtained by the certificate authority using its private key to sign the certificate content. Address information refers to the network address or resource location information associated with the target network element. For example, address information could be the IP address of the target network element, i.e., the unique identifier of the target network element in the network. Determining the address information corresponding to the target network element ensures that the requesting network element can find and access the target network element.
[0051] Optionally, in response to receiving feedback information indicating that an initial access token has been generated, the feedback information is sent to the service requesting network element, so that the service requesting network element sends the signature information obtained by signing the first identifier and the second timestamp based on the private key to the authorized service network element; the signature information and certificate information are received, and the signature information is verified based on the public key of the service requesting network element to determine the verification result; when the verification result is consistent with the preset result, the first identifier and the stored network element information are compared, so that the certificate information is verified when the comparison is successful.
[0052] Here, feedback information refers to the confirmation message sent by the blockchain to the authorized service network element after the initial access token is generated and stored. Signature verification result refers to the result obtained by comparing the first identifier corresponding to the signature information with the first identifier stored locally by the authorized service network element. Preset result means that the first identifier corresponding to the signature information matches the first identifier stored locally by the authorized service network element.
[0053] It should be noted that after receiving the feedback information from the authorizing service network element, the requesting network element combines the first identifier and the second timestamp into a string or data structure. For example, a specific delimiter can be used to concatenate the first identifier and the second timestamp. A hash calculation is then performed on the string or data structure to generate a hash value. Finally, an appropriate signature algorithm is selected, and the hash value is signed using the private key of the requesting network element to generate signature information. For example, RSA, DSA, or ECDSA signature algorithms can be selected.
[0054] It should be noted that after receiving the signature and certificate information, the authorized service element uses the public key of the service requesting element to decrypt the signature information, obtaining a decrypted hash value. This decrypted hash value is compared with the hash value generated during signature processing. If the decrypted hash value matches the hash value generated during signature processing, it indicates that the signature information is valid, the data has not been tampered with, and it was indeed generated by the entity holding the private key of the service requesting element. Verifying the signature information based on the public key of the service requesting element ensures data integrity and the authenticity of the identity, thereby effectively preventing forgery and tampering.
[0055] It should also be noted that when the signature verification result matches the preset result, it indicates that the decrypted hash value is the same as the hash value generated during signature processing, and also indicates that the first identifier corresponding to the signature information matches the first identifier stored locally by the authorized service network element. Furthermore, when the signature verification result matches the preset result, network element information is extracted from the service request network element based on the first identifier. When the network element information extracted by the service request network element at this time matches the network element information stored locally by the authorized service network element, the certificate information is verified. For example, when the signature verification result matches the preset result, information such as Info and the request access address are extracted from the service request network element based on the first identifier. When the Info and the request access address at this time match the Info and the request access address stored locally by the authorized service network element, the certificate information is verified. The process of verifying the certificate information includes steps such as checking the certificate's validity period, obtaining the issuer's public key, verifying the signature, and checking the holder information. Through these steps, the authenticity and validity of the certificate can be ensured, thereby providing security for subsequent communication.
[0056] Specifically, after generating the initial access token, the blockchain sends feedback information about the initial access token generation to the authorized service network element. Upon receiving this feedback, the authorized service network element sends it to the service requesting network element. The moment the service requesting network element receives the feedback from the authorized service network element is recorded and defined as the second timestamp. In response to the received feedback, the service requesting network element signs the first identifier and the second timestamp using its private key and sends the resulting signature to the authorized service network element. Upon receiving the signature and certificate information from the service requesting network element, the authorized service network element evaluates the signature and certificate information. First, it verifies the signature information using the service requesting network element's public key to determine the verification result. Then, if the verification result matches a preset result, it compares the network element information extracted by the service requesting network element with the stored network element information. Further, if the comparison passes, it verifies the certificate information. Finally, if the certificate information verification passes, it determines the address information corresponding to the target network element.
[0057] S130. Based on the state transition tree and the protocol state corresponding to the current service request network element, when the behavior identification result corresponding to the service request network element is determined to be the first result, extract the network element identifier corresponding to the target network element, retrieve the target address of the target network element based on the network element identifier, and send the network element information to the blockchain to obtain the initial access token of the service request network element from the blockchain based on the network element information.
[0058] It's important to note that a state transition tree is a tree structure used to describe the transition relationships between different protocol states. In a state transition tree, each node represents a protocol state, and edges represent the transition conditions between protocol states. For example, a state transition tree could be as follows: When the initial protocol state is idle, if the "Request to Access" protocol state is entered, the tree transitions to "Request Received," indicating that the access request has been received and processing has begun. If the "Verify" protocol state is entered, the tree transitions to "Access Authorization," indicating that the validity of the request is being verified, and access is authorized upon successful verification. If the "Reject" protocol state is entered, the tree transitions to "Access Denied," indicating that the request failed verification and access was denied.
[0059] It should be noted that the current protocol state corresponding to the service requesting network element refers to the state of the protocol at a specific point in time. Each protocol state reflects the current operating mode of the protocol. For example, the current protocol state corresponding to the service requesting network element can be normal or abnormal. The behavior authentication result refers to the judgment made by the authorized service network element on the legality and validity of the request based on the current protocol state when processing data access requests. For example, the behavior authentication result can be a legal request, an illegal request, or a request with an incorrect format. A first result means that the behavior authentication result is a legal request, which means the request is approved.
[0060] It should also be noted that the network element identifier refers to the identifier of the target network element, used to uniquely identify the target network element. The target address refers to the network address used to locate the target network element, usually referring to the IP address of the target network element.
[0061] Specifically, when a service requesting network element makes a data access request, it determines the current protocol state of the service requesting network element by querying the state storage or management system. Then, based on the current protocol state of the service requesting network element, it searches for the input conditions corresponding to that protocol state in the state transition tree. If the received data access request meets the state transition conditions, the behavior authentication result is determined to be "normal". Once the authorized service network element determines that the behavior authentication result is "normal", it extracts the identifier of the target network element. Based on the identifier of the target network element, it queries the target address of the target network element in the local storage of the authorized service network element. Furthermore, it sends the network element information of the service requesting network element to the blockchain and obtains the initial access token of the service requesting network element from the blockchain. At this point, the initial access token of the service requesting network element and the target address of the target network element are obtained.
[0062] S140. Send the initial access token and the target address to the service requesting network element so that the service requesting network element can access the target network element based on the received target address and initial access token.
[0063] Optionally, the control service requests the network element to access the target network element that matches the target address based on the received initial access token and authorization information.
[0064] Specifically, the initial access token serves as a credential to prove the legitimacy of the requesting network element when accessing the target network element. The target address points to the network address of the target network element, which the requesting network element will use to connect and exchange data with it. After packaging the initial access token and the target address into a message, the authorized service network element can send the message to the requesting network element via network protocols. Upon receiving the initial access token and the target address, the requesting network element first parses the message content. Then, when accessing the target network element, the requesting network element sends the initial access token as an authentication credential. After ensuring that the target network element can verify the legitimacy of the request, the service requesting network element establishes a connection with the target network element using the target address, thus achieving the purpose of accessing the target network element.
[0065] The technical solution of this disclosure embodiment is applied to an authorized service network element. For any service request network element, a data access request sent by the service request network element is received. When the network element information in the data access request meets preset conditions, the network element information is stored and sent to the blockchain. Based on the blockchain, an initial access token corresponding to the network element information is determined and fed back. Then, signature information and certificate information sent by the service request network element are received. When the signature information is consistent with the stored network element information, the certificate information is verified. When the verification is successful, the address information corresponding to the target network element is determined. Further, based on the state transition tree and the protocol state corresponding to the service request network element, when the behavior authentication result corresponding to the service request network element is determined as the first result, the network element identifier corresponding to the target network element is extracted, and the target address of the target network element is retrieved based on the network element identifier. The network element information is also sent to the blockchain to obtain the initial access token of the service request network element from the blockchain based on the network element information. Finally, the initial access token and the target address are sent to the requesting network element, enabling the requesting network element to access the target network element based on the received target address and initial access token. This addresses the problem in existing technologies where data access between network elements primarily relies on public-key cryptography for authentication and authorization. The verification of public key certificates confirms the network element's identity, but static certificates typically have long validity periods, leading to delayed authorization updates and the inability to promptly revoke or update authorized network elements, resulting in low data access security and overall network reliability. This embodiment of the present disclosure implements a B5G network approach where, based on blockchain, an access token for the requesting network element is determined. After determining the target address of the target network element according to the state transition tree, the requesting network element dynamically accesses the target network element based on the access token. This achieves dynamic access control for the requesting network element, ensuring secure and efficient access to the target network element, thereby improving the overall security and responsiveness of the B5G network.
[0066] Example 2
[0067] Figure 2 This is a flowchart illustrating the dynamic access control method applied to B5G networks provided in this embodiment of the invention. Based on the aforementioned embodiments, it provides a more detailed explanation of retrieving the target address of the target network element and obtaining the initial access token of the service requesting network element. For specific implementation details, please refer to the technical solution of this embodiment. Technical terms that are the same as or corresponding to those in the above embodiments will not be repeated here.
[0068] like Figure 2 As shown, the method specifically includes the following steps:
[0069] S210. For any service requesting network element, receive the data access request sent by the service requesting network element, and when the network element information in the data access request meets the preset conditions, store the network element information and send the network element information to the blockchain, and then determine the initial access token corresponding to the network element information based on the blockchain and provide feedback.
[0070] S220. Receive the signature information and certificate information sent by the service requesting network element, and verify the certificate information when the signature information matches the stored network element information, so as to determine the address information corresponding to the target network element when the verification is successful.
[0071] S230. When the certificate information verification result is successful, generate a state transition tree based on the data access request sent by the service requesting network element, and determine the current protocol state of the service requesting network element according to the progress information of the data access request.
[0072] It should be noted that for a data access request sent by a service requesting network element, the request must first be parsed. This request may contain detailed information about the required operation, such as the request type and target resource. Then, based on the content of the data access request, a set of possible protocol states is determined. For example, possible protocol states may include: request initiated, request being verified, access authorized, access denied, and data retrieved. Further, the input conditions leading to state transitions are determined. For example, input conditions may be: verification passed, verification failed, or data retrieved. Based on the set of protocol states and the input conditions, state transition relationships are constructed. For example, a state transition relationship may be from request initiated to request being verified; from request being verified to access authorized; or from request being verified to access denied. Finally, all protocol states and transition relationships are represented in a tree structure, forming a complete state transition tree.
[0073] It should also be noted that the progress information of a data access request refers to the information recorded by the authorized service network element regarding the current processing stage of the data access request. This progress information may include: the current status of the data access request, the processing time from initiation to the present, and the percentage of completion. After obtaining the progress information, the current protocol status of the service request network element is analyzed based on this information. For example, if the progress percentage is 100% and there are no errors, the current protocol status of the service request network element is normal.
[0074] Specifically, before processing a data access request, the certificate information provided by the service requesting network element is first verified. If the verification passes, subsequent operations are allowed. The data access request sent by the service requesting network element is analyzed to understand its content and intent. Based on the request logic and response, the transition conditions between states are defined, and the states and transition relationships are represented in a tree structure, forming a complete state transition tree. After obtaining progress information about the data access request, the authorized service network element can identify the current processing stage of the data access request based on this information. By tracking the progress information of the data access request and following the path of the state transition tree, the current protocol state of the service requesting network element is determined.
[0075] For example, after receiving a data access request, the authorizing service element can determine the current protocol state of the requesting element according to the protocol state transition equation. The authorizing service element generates a unique protocol state based on the data access request. The generated state transition quintuple is as follows: ,in, For the set of protocol states, It is a collection of input elements. It is a collection of output elements. This is the initial protocol state. It is a state transition function, used when the protocol is in a state. When inputting elements Determine the current protocol state of the network element requesting the service. .
[0076] S240. When the protocol status is normal, determine the behavior identification result corresponding to the service request network element as the first result, and extract the network element identifier of the target network element.
[0077] Specifically, when the protocol status is normal, meaning the data access request is processed without abnormalities and can be responded to normally, based on the normal protocol status of the current result of the service request network element, the authorized service network element judges the legality and validity of the request, and determines that the behavior authentication result corresponding to the service request network element is a legal result, i.e., the first result. Finally, the network element identifier of the target network element is extracted from the local storage of the authorized service network element.
[0078] S250. Determine the network element hash value corresponding to the network element identifier, and retrieve the address information of the target network element based on the network element hash value.
[0079] Specifically, a cryptographic hash function is used, and the network element identifier is input into the hash function to generate the corresponding hash value. Since the authorized service network element has local storage containing the network element hash value and its corresponding address information, the generated network element hash value is used as the query condition to search for the corresponding address information in the authorized service network element's local storage. After finding a matching network element hash value, its corresponding address information is extracted. The address information of the found target network element is then returned to the authorized service network element.
[0080] S260. Send the first identifier in the network element information to the blockchain so that the blockchain can retrieve the initial access token of the service requesting network element and the permission information corresponding to the initial access token based on the first identifier.
[0081] Specifically, the authorized service network element uses the API or SDK provided by the blockchain to interact with the blockchain and sends the first identifier from the network element information. By calling a smart contract function, after accepting the first identifier as an input parameter, the smart contract function queries the access token stored on the blockchain and returns the initial access token of the service requesting network element to the authorized service network element. Furthermore, the initial access token is usually associated with permission information. The smart contract function can then return the permission information corresponding to the initial access token to the authorized service network element.
[0082] S270. Send the initial access token and the target address to the service requesting network element so that the service requesting network element can access the target network element based on the received target address and initial access token.
[0083] Optionally, during the service request network element access process, access process data is recorded; in response to abnormal access process data events, the abnormal behavior detection results and the runtime environment information that generated the access process data are sent to the blockchain, so that the smart contract in the blockchain can determine the risk assessment value of the runtime environment information and abnormal behavior detection results; when the risk assessment value is not within the preset risk value range, the permission information corresponding to the service request network element is updated.
[0084] Access process data refers to all relevant information generated during the process of a service requesting network element accessing a target network element. Access process data can include request information, response information, user information, operation logs, and error logs. An abnormal access process data event refers to a situation detected during the access process that deviates from normal behavior; the occurrence of an abnormal access process data event can indicate a potential security risk. For example, an abnormal access process data event could be an abnormal access frequency. Abnormal behavior detection results refer to conclusions drawn from analyzing access process data during the access process, determining whether malicious behavior or risk exists. Operating environment information refers to the environmental state of the service requesting network element during the access process when an abnormal access process data event occurs. Operating environment information can include resource usage, runtime, and network status. A smart contract is a self-executing contract whose terms are stored on the blockchain in the form of computer code. Smart contracts can automatically execute when specific conditions are met, ensuring that the execution process is transparent and immutable. In this embodiment of the invention, the smart contract is used to handle the risk assessment of access requests. The risk assessment value is a quantitative indicator used to represent the degree of risk of the operating environment information and the abnormal behavior detection results. Risk assessment values are typically calculated based on multiple factors, including user behavior, access patterns, and environmental information.
[0085] Specifically, during the service request network element access process, the recorded access process data can be uploaded to the cloud capability center, which then detects the behavior of the service request network element. If an abnormal event is identified in the access process data, the authorized service is notified to transmit the abnormal behavior detection result of the service request network element and the runtime environment information that generated the access process data to the blockchain. Upon receiving the abnormal behavior detection result and the runtime environment information that generated the access process data, the blockchain, based on the running smart contract, uses a dynamic risk assessment algorithm to calculate the risk assessment value corresponding to the runtime environment information and abnormal behavior detection result of the service request network element. If the risk assessment value is not within the preset risk value range, it indicates that the behavior of the service request network element may pose a risk, and measures need to be taken to protect resource security. Therefore, at this time, the access permissions of the service request network element are adjusted according to the risk assessment value. For example, the initial access token of the service request network element may be suspended or revoked. When monitoring and managing the access process of service request network elements, by recording access process data and monitoring abnormal events, potential malicious behaviors or security threats can be detected in a timely manner, reducing the occurrence of security incidents such as data leakage and unauthorized access. Furthermore, upon detecting abnormal behavior, it responds swiftly by updating permission information to restrict or revoke access permissions for service request network elements, thereby reducing risks and improving responsiveness and user experience.
[0086] The technical solution of this embodiment, when the certificate information verification result is successful, generates a state transition tree based on the data access request sent by the service requesting network element, and determines the current protocol state of the service requesting network element according to the progress information of the data access request. Then, when the protocol state is normal, the behavior authentication result corresponding to the service requesting network element is determined as the first result, and the network element identifier of the target network element is extracted. Further, the network element hash value corresponding to the network element identifier is determined, and the address information of the target network element is retrieved based on the network element hash value. The first identifier in the network element information is sent to the blockchain, so that the blockchain can retrieve the initial access token of the service requesting network element and the permission information corresponding to the initial access token based on the first identifier. Finally, the initial access token and the target address are sent to the service requesting network element, so that the service requesting network element can access the target network element based on the received target address and initial access token. By retrieving the initial access token and its corresponding permission information, the access permissions of the service requesting network element can be dynamically controlled, and permissions can be flexibly adjusted according to the actual situation to ensure resource security. Using the network element hash value to retrieve the target network element's address information ensures that the correct target network element is accessed, preventing erroneous or malicious access attempts. Furthermore, sending the initial identifier to the blockchain ensures that all access requests and related information are recorded on the blockchain, providing high transparency and immutability, thus promoting the security and stability of the overall network environment.
[0087] Example 3
[0088] Figure 3 This is a schematic diagram of the structure of the dynamic access control device applied to a B5G network provided in this embodiment of the disclosure, as shown below. Figure 3 As shown, the device includes: an initial access token determination module 310, an address information determination module 320, an initial access token acquisition module 330, and a target network element access module 340.
[0089] The initial access token determination module is used to receive a data access request sent by any service requesting network element, and when the network element information in the data access request meets preset conditions, store the network element information and send it to the blockchain, and determine and feedback the initial access token corresponding to the network element information based on the blockchain. The address information determination module is used to receive signature information and certificate information sent by the service requesting network element, and when the signature information matches the stored network element information, verify the certificate information, and determine the address information corresponding to the target network element when the verification is successful, wherein the target network element is the network element to be accessed by the service requesting network element. The network element; the initial access token acquisition module is used to extract the network element identifier corresponding to the target network element when the behavior identification result corresponding to the service request network element is determined to be the first result according to the state transition tree and the protocol state currently corresponding to the service request network element, and retrieve the target address of the target network element based on the network element identifier, and send the network element information to the blockchain to obtain the initial access token of the service request network element from the blockchain based on the network element information; the target network element access module is used to send the initial access token and the target address to the service request network element so that the service request network element can access the target network element based on the received target address and initial access token.
[0090] The technical solution of this disclosure embodiment is applied to an authorized service network element. For any service request network element, a data access request sent by the service request network element is received. When the network element information in the data access request meets preset conditions, the network element information is stored and sent to the blockchain. Based on the blockchain, an initial access token corresponding to the network element information is determined and fed back. Then, signature information and certificate information sent by the service request network element are received. When the signature information is consistent with the stored network element information, the certificate information is verified. When the verification is successful, the address information corresponding to the target network element is determined. Further, based on the state transition tree and the protocol state corresponding to the service request network element, when the behavior authentication result corresponding to the service request network element is determined as the first result, the network element identifier corresponding to the target network element is extracted, and the target address of the target network element is retrieved based on the network element identifier. The network element information is also sent to the blockchain to obtain the initial access token of the service request network element from the blockchain based on the network element information. Finally, the initial access token and the target address are sent to the requesting network element, enabling the requesting network element to access the target network element based on the received target address and initial access token. This addresses the problem in existing technologies where data access between network elements primarily relies on public-key cryptography for authentication and authorization. The verification of public key certificates confirms the network element's identity, but static certificates typically have long validity periods, leading to delayed authorization updates and the inability to promptly revoke or update authorized network elements, resulting in low data access security and overall network reliability. This embodiment of the present disclosure implements a B5G network approach where, based on blockchain, an access token for the requesting network element is determined. After determining the target address of the target network element according to the state transition tree, the requesting network element dynamically accesses the target network element based on the access token. This achieves dynamic access control for the requesting network element, ensuring secure and efficient access to the target network element, thereby improving the overall security and responsiveness of the B5G network.
[0091] Based on the above technical solutions, the data access request includes at least a first identifier of the service requesting network element based on the public key corresponding to the authorized service network element, additional information related to the service requesting network element, a request access address, and a data access request encrypted with a first timestamp.
[0092] Based on the above technical solutions, the initial access token determination module 310 includes: a network element information decryption submodule and a blockchain signature verification submodule.
[0093] The network element information decryption submodule is used to decrypt the data access request based on the private key corresponding to the authorized service network element, obtain the first timestamp, and obtain the decrypted network element information when the time difference between the first timestamp and the current timestamp is less than a preset time threshold; wherein, the network element information includes at least a first identifier, additional information related to the service request network element, and the request access address;
[0094] The blockchain signature verification submodule is used to store the network element information in a preset format, and after signing a portion of the data in the network element information, send it along with the network element information to the blockchain. After the target data with the signature processing is verified by the blockchain, the initial access token corresponding to the service request network element is determined.
[0095] Based on the above technical solutions, the blockchain signature verification submodule includes: a hash processing unit and an initial access token allocation unit.
[0096] The hash processing unit is used to hash the first identifier based on the hash algorithm of the service request network element to obtain a stored hash value; and to obtain a stored value by concatenating the additional information in the network element information and the request access address.
[0097] The initial access token allocation unit is used to sign the first identifier based on a preset signature algorithm to obtain target data, and send the target data and additional information in the network element information to the blockchain, so that after the blockchain verifies the target data based on the signature verification algorithm, it allocates an initial access token to the service request network element, and stores the token identifier and corresponding permission information of the initial access token.
[0098] Based on the above technical solutions, the address information determination module 320 includes: a signature information sending submodule, a public key verification submodule, and an information comparison submodule.
[0099] The signature information sending submodule is used to send the feedback information to the service request network element in response to receiving feedback information that an initial access token has been generated, so that the service request network element sends the signature information obtained by signing the first identifier and the second timestamp based on the private key to the authorized service network element.
[0100] The public key verification submodule is used to receive the signature information and the certificate information, and to verify the signature information based on the public key of the service request network element to determine the signature verification result.
[0101] The information comparison submodule is used to compare the certificate information based on the first identifier and the stored network element information when the verification result is consistent with the preset result, so as to verify the certificate information when the comparison is successful.
[0102] Based on the above technical solutions, the initial access token acquisition module 330 includes: a protocol status determination submodule, a network element identifier extraction submodule, an address information retrieval submodule, and an authorization information retrieval submodule.
[0103] The protocol state determination submodule is used to generate a state transition tree based on the data access request sent by the service requesting network element when the certificate information verification result is successful, and to determine the current protocol state of the service requesting network element according to the progress information of the data access request.
[0104] The network element identifier extraction submodule is used to determine the behavior identification result corresponding to the service request network element as the first result when the protocol status is normal, and extract the network element identifier of the target network element;
[0105] The address information retrieval submodule is used to determine the network element hash value corresponding to the network element identifier, and retrieve the address information of the target network element based on the network element hash value;
[0106] The permission information retrieval submodule is used to send the first identifier in the network element information to the blockchain, so that the blockchain can retrieve the initial access token of the service request network element and the permission information corresponding to the initial access token based on the first identifier.
[0107] Based on the above technical solutions, the target network element access module 340 further includes: controlling the service requesting network element to access the target network element consistent with the target address based on the received initial access token and permission information.
[0108] Based on the above technical solutions, the device further includes: a permission information update module, used to record access process data during the access process of the service requesting network element; in response to an abnormal access process data event, sending the abnormal behavior detection result and the operating environment information that generated the access process data to the blockchain, so that the smart contract in the blockchain determines the risk assessment value of the operating environment information and the abnormal behavior detection result; when the risk assessment value is not within the preset risk value range, updating the permission information corresponding to the service requesting network element.
[0109] The dynamic access control device for B5G networks provided in this disclosure can execute the dynamic access control method for B5G networks provided in any embodiment of this disclosure, and has the corresponding functional modules and beneficial effects for executing the method.
[0110] It is worth noting that the various units and modules included in the above-mentioned device are only divided according to functional logic, but are not limited to the above division, as long as the corresponding functions can be realized; in addition, the specific names of each functional unit are only for easy differentiation and are not used to limit the protection scope of the embodiments of this disclosure.
[0111] Example 4
[0112] Figure 4 This is a schematic diagram of the structure of an electronic device provided in an embodiment of this disclosure. Refer to the following... Figure 4 It illustrates an electronic device suitable for implementing embodiments of the present disclosure (e.g., Figure 4 The diagram below shows the structure of the terminal device or server 500. The terminal device in this embodiment may include, but is not limited to, mobile terminals such as mobile phones, laptops, digital radio receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), and vehicle terminals (e.g., vehicle navigation terminals). Figure 4 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.
[0113] like Figure 4 As shown, electronic device 500 may include a processing unit (e.g., a central processing unit, a graphics processing unit, etc.) 501, which can perform various appropriate actions and processes according to a program stored in read-only memory (ROM) 502 or a program loaded from storage device 508 into random access memory (RAM) 503. The RAM 503 also stores various programs and data required for the operation of electronic device 500. The processing unit 501, ROM 502, and RAM 503 are interconnected via bus 504. An edit / output (I / O) interface 505 is also connected to bus 504.
[0114] Typically, the following devices can be connected to I / O interface 505: input devices 506 including, for example, touchscreens, touchpads, keyboards, mice, cameras, microphones, accelerometers, gyroscopes, etc.; output devices 507 including, for example, liquid crystal displays (LCDs), speakers, vibrators, etc.; storage devices 508 including, for example, magnetic tapes, hard disks, etc.; and communication devices 509. Communication device 509 allows electronic device 500 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 4 An electronic device 500 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively.
[0115] In particular, according to embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a non-transitory computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 509, or installed from a storage device 508, or installed from a ROM 502. When the computer program is executed by the processing device 501, it performs the functions defined in the methods of embodiments of this disclosure.
[0116] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.
[0117] The electronic device provided in this embodiment belongs to the same inventive concept as the dynamic access control method for B5G networks provided in the above embodiments. Technical details not described in detail in this embodiment can be found in the above embodiments, and this embodiment has the same beneficial effects as the above embodiments.
[0118] Example 5
[0119] This disclosure provides a computer storage medium storing a computer program that, when executed by a processor, implements the dynamic access control method for B5G networks provided in the above embodiments.
[0120] It should be noted that the computer-readable medium described in this disclosure can be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium can be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In this disclosure, a computer-readable storage medium can be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In this disclosure, a computer-readable signal medium can include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.
[0121] In some implementations, the server may communicate using any currently known or future-developed network protocol such as HTTP (Hypertext Transfer Protocol) and may interconnect with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks), as well as any currently known or future-developed networks.
[0122] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device.
[0123] The aforementioned computer-readable medium carries one or more programs that, when executed by the electronic device, cause the electronic device to:
[0124] For any service requesting network element, receive the data access request sent by the service requesting network element, and when the network element information in the data access request meets the preset conditions, store the network element information and send the network element information to the blockchain, and then determine the initial access token corresponding to the network element information based on the blockchain and provide feedback.
[0125] The system receives signature information and certificate information sent by the network element requesting the service, and verifies the certificate information when the signature information matches the stored network element information. If the verification is successful, the system determines the address information corresponding to the target network element, wherein the target network element is the network element to be accessed by the network element requesting the service.
[0126] Based on the state transition tree and the protocol state corresponding to the current service request network element, when the behavior identification result corresponding to the service request network element is determined to be the first result, the network element identifier corresponding to the target network element is extracted, and the target address of the target network element is retrieved based on the network element identifier, and the network element information is sent to the blockchain, so as to obtain the initial access token of the service request network element from the blockchain based on the network element information.
[0127] The initial access token and the target address are sent to the service requesting network element, so that the service requesting network element can access the target network element based on the received target address and initial access token.
[0128] Computer program code for performing the operations of this disclosure can be written in one or more programming languages or a combination thereof, including but not limited to object-oriented programming languages such as Java, Smalltalk, and C++, as well as conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).
[0129] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.
[0130] The units described in the embodiments of this disclosure can be implemented in software or hardware. The names of the units are not, in some cases, intended to limit the specific unit.
[0131] The functions described above in this document can be performed at least in part by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), system-on-a-chip (SoCs), complex programmable logic devices (CPLDs), and so on.
[0132] In the context of this disclosure, a machine-readable medium can be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can be, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of machine-readable storage media include electrical connections based on one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the foregoing.
[0133] The above description is merely a preferred embodiment of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described concept. For example, technical solutions formed by substituting the above features with (but not limited to) technical features with similar functions disclosed in this disclosure.
[0134] Furthermore, while the operations are described in a specific order, this should not be construed as requiring these operations to be performed in the specific order shown or in a sequential order. In certain environments, multitasking and parallel processing may be advantageous. Similarly, while several specific implementation details are included in the above discussion, these should not be construed as limiting the scope of this disclosure. Certain features described in the context of individual embodiments may also be implemented in combination in a single embodiment. Conversely, various features described in the context of a single embodiment may also be implemented individually or in any suitable sub-combination in multiple embodiments.
[0135] Although the subject matter has been described using language specific to structural features and / or methodological logic, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. Rather, the specific features and actions described above are merely illustrative examples of implementing the claims.
Claims
1. A dynamic access control method applied to B5G networks, characterized in that, Applied to authorized service network elements, the method includes: For any service requesting network element, receive the data access request sent by the service requesting network element, and when the network element information in the data access request meets the preset conditions, store the network element information and send the network element information to the blockchain, and then determine the initial access token corresponding to the network element information based on the blockchain and provide feedback. The system receives signature information and certificate information sent by the network element requesting the service, and verifies the certificate information when the signature information matches the stored network element information. If the verification is successful, the system determines the address information corresponding to the target network element, wherein the target network element is the network element to be accessed by the network element requesting the service. Based on the state transition tree and the protocol state corresponding to the current service request network element, when the behavior identification result corresponding to the service request network element is determined to be the first result, the network element identifier corresponding to the target network element is extracted, and the target address of the target network element is retrieved based on the network element identifier, and the network element information is sent to the blockchain, so as to obtain the initial access token of the service request network element from the blockchain based on the network element information. The initial access token and the target address are sent to the service requesting network element, so that the service requesting network element can access the target network element based on the received target address and initial access token.
2. The method according to claim 1, characterized in that, The data access request includes at least a first identifier of the service requesting network element based on the public key corresponding to the authorized service network element, additional information related to the service requesting network element, a request access address, and a data access request encrypted with a first timestamp. When the network element information in the data access request meets preset conditions, the network element information is stored and sent to the blockchain. After determining the initial access token corresponding to the network element information based on the blockchain and providing feedback, the process includes: The data access request is decrypted based on the private key corresponding to the authorized service network element to obtain the first timestamp. When the time difference between the first timestamp and the current timestamp is less than a preset time threshold, the decrypted network element information is obtained. The network element information includes at least a first identifier, additional information related to the service request network element, and the request access address. The network element information is stored in a preset format, and a portion of the data in the network element information is signed and then sent to the blockchain. After the target data with the signed data is verified by the blockchain, the initial access token corresponding to the service request network element is determined.
3. The method according to claim 2, characterized in that, The process of storing the network element information in a preset format, signing a portion of the data in the network element information, and sending the network element information to the blockchain, and then determining the initial access token corresponding to the service request network element after the target data with the signed data is verified by the blockchain, includes: The first identifier is hashed based on the hash algorithm of the service request network element to obtain a stored hash value; and a stored value is obtained by concatenating the additional information in the network element information and the request access address. The first identifier is signed based on a preset signature algorithm to obtain target data. The target data and additional information in the network element information are then sent to the blockchain. After the blockchain verifies the target data based on the signature verification algorithm, it allocates an initial access token to the service request network element and stores the token identifier and corresponding permission information of the initial access token.
4. The method according to claim 2, characterized in that, The step of receiving the signature information and certificate information sent by the service request network element, and verifying the certificate information when the signature information matches the stored network element information, to determine the address information corresponding to the target network element upon successful verification, includes: In response to receiving feedback information that an initial access token has been generated, the feedback information is sent to the service request network element, so that the service request network element sends the signature information obtained by signing the first identifier and the second timestamp based on the private key to the authorized service network element. Receive the signature information and the certificate information, and verify the signature information based on the public key of the service request network element to determine the signature verification result; When the verification result matches the preset result, a comparison is made based on the first identifier and the stored network element information, so that the certificate information is verified when the comparison passes.
5. The method according to claim 1, characterized in that, When determining the behavior identification result corresponding to the service requesting network element as the first result based on the state transition tree and the protocol state currently corresponding to the service requesting network element, the network element identifier corresponding to the target network element is extracted, including: When the certificate information verification result is successful, a state transition tree is generated based on the data access request sent by the service requesting network element, and the current protocol state of the service requesting network element is determined according to the progress information of the data access request. When the protocol status is normal, the behavior identification result corresponding to the service request network element is determined as the first result, and the network element identifier of the target network element is extracted.
6. The method according to claim 1, characterized in that, The step of retrieving the target address of the target network element based on the network element identifier and sending the network element information to the blockchain to obtain the initial access token of the service requesting network element from the blockchain based on the network element information includes: Determine the network element hash value corresponding to the network element identifier, and retrieve the address information of the target network element based on the network element hash value; The first identifier in the network element information is sent to the blockchain so that the blockchain can retrieve the initial access token of the service request network element and the permission information corresponding to the initial access token based on the first identifier.
7. The method according to claim 1, characterized in that, The service requesting network element accesses the target network element based on the received target address and initial access token, including: The control network element requesting the service accesses the target network element that matches the target address based on the received initial access token and permission information.
8. The method according to claim 1, characterized in that, The method further includes: During the service request network element access process, access process data is recorded; In response to an abnormal event in the access process data, the abnormal behavior detection result and the runtime environment information that generated the access process data are sent to the blockchain, so that the smart contract in the blockchain can determine the risk assessment value of the runtime environment information and the abnormal behavior detection result; When the risk assessment value is not within the preset risk value range, the permission information corresponding to the service request network element is updated.
9. A dynamic access control device for use in B5G networks, characterized in that, include: The initial access token determination module is used to receive a data access request sent by any service requesting network element, and when the network element information in the data access request meets a preset condition, store the network element information and send the network element information to the blockchain, and determine the initial access token corresponding to the network element information based on the blockchain and then provide feedback. The address information determination module is used to receive the signature information and certificate information sent by the service request network element, and verify the certificate information when the signature information is consistent with the stored network element information, so as to determine the address information corresponding to the target network element when the verification is successful, wherein the target network element is the network element to be accessed by the service request network element; The initial access token acquisition module is used to extract the network element identifier corresponding to the target network element when the behavior identification result corresponding to the service request network element is determined to be the first result based on the state transition tree and the protocol state corresponding to the current service request network element, and to retrieve the target address of the target network element based on the network element identifier, and to send the network element information to the blockchain, so as to obtain the initial access token of the service request network element from the blockchain based on the network element information. The target network element access module is used to send the initial access token and the target address to the service request network element, so that the service request network element can access the target network element based on the received target address and initial access token.
10. An electronic device, characterized in that, The electronic device includes: One or more processors; Storage device for storing one or more programs. When one or more programs are executed by one or more processors, the one or more processors implement the dynamic access control method for B5G networks as described in any one of claims 1-8.
11. A storage medium containing computer-executable instructions, characterized in that, The computer-executable instructions, when executed by a computer processor, are used to perform the dynamic access control method for B5G networks as described in any one of claims 1-8.
12. A computer program product, comprising a computer program, characterized in that, When the computer program is executed by the processor, it implements the dynamic access control method for B5G networks as described in any one of claims 1-8.
Citation Information
Patent Citations
IKE protocol fuzz testing method based on state guidance
CN119652801A
6G wireless network resource sharing method, system and device and storage medium
CN120050663A