Access control method and apparatus, and network device and user equipment
By adopting decentralized identity identification and verifiable claim mechanisms in 6G networks, and utilizing blockchain networks for user device authentication and authorization, the problem of sub-network authentication and authorization in future 6G networks is solved, achieving efficient authentication and authorization of distributed sub-networks and reducing the pressure on the central network and communication latency.
Patent Information
- Application Number
- PCT/CN2025/093060
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-05-08
- Filing Date
- 2025-05-07
- Publication Date
- 2025-11-13
AI Technical Summary
The existing roaming authentication mechanism cannot effectively authenticate and authorize user identities in the future 6G network, leading to increased pressure on the central network and communication delays.
By adopting decentralized identity (DID) and verifiable claims (VC) mechanisms, user devices are authenticated and authorized through the blockchain network, realizing authentication and authorization between distributed subnets and reducing the burden on the central network.
It enables authentication and authorization of user equipment through distributed subnets, reducing the pressure on the central network and lowering communication latency, and supports authentication between different distributed subnets in 6G networks.
Smart Images

Figure CN2025093060_13112025_PF_FP_ABST
Abstract
Description
Access control methods, devices, network equipment and user equipment
[0001] This disclosure claims priority to Chinese Patent Application No. 202410562139.9, filed with the Chinese Patent Office on May 8, 2024, entitled "Access Control Method, Apparatus, Network Equipment and User Equipment", the entire contents of which are incorporated herein by reference. Technical Field
[0002] This disclosure relates to the field of communication technology, and in particular to an access control method, apparatus, network device, and user equipment. Background Technology
[0003] The roaming authentication mechanism of related technologies mainly relies on the user's Subscriber Identity Module (SIM) card and the authentication information in the home network. The authentication and authorization of the user can only be performed by the home network, and the home network and the visited network need to be based on a pre-signed roaming agreement to complete the identity authentication of the user when roaming to different visited networks.
[0004] The future 6th generation mobile communication technology (6G) network will introduce a distributed architecture consisting of a central network and distributed subnets. The central network is used to meet wide-area coverage and universal service requirements. Distributed subnets are primarily used to meet specific needs in various scenarios. In a 6G distributed network, if user subscription data is stored in the central node network, when using a mechanism similar to roaming authentication, each user device connected to the distributed subnet needs to be authenticated and authorized in the central network and maintain a real-time connection. This puts pressure on the central network, and some user devices may need to use multi-hop routing to connect, causing communication delays. Therefore, the roaming authentication mechanism of related technologies is not suitable for the authentication and authorization of future 6G networks. Furthermore, there are currently no solutions for how to implement user authentication and authorization in each subnet and how authentication will occur between subnets in future 6G networks. Summary of the Invention
[0005] This disclosure provides an access control method, apparatus, network device, and user equipment, which solves the problem that there is currently no solution for how to achieve user authentication and authorization in each subnetwork and how to authenticate between subnetworks in future 6G networks.
[0006] Embodiments of this disclosure provide an access control method applied to a first network device in a first subnet, the method comprising:
[0007] The first network device receives the first information or the second information;
[0008] The first network device performs authentication of the user equipment based on the first information, or performs authentication and authorization of the user equipment based on the first information, or performs authentication of the second subnet based on the second information;
[0009] The first information includes one of the following:
[0010] The first decentralized identity (DID) identifier corresponding to the user equipment and the information related to the authentication of the user equipment;
[0011] The first DID identifier corresponding to the user equipment, the authentication-related information of the user equipment, and the authorization-related information of the user equipment;
[0012] The second information includes the second DID identifier corresponding to the second subnet and information related to the authentication of the second subnet.
[0013] In some embodiments, the first DID identifier is configured by the central network to which the first subnet belongs, and / or the second DID identifier is configured by the central network to which the second subnet belongs.
[0014] In some embodiments, the information related to the authentication of the user equipment includes at least one of the following:
[0015] First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier;
[0016] The request message in plaintext and a second encrypted message encrypted using the user equipment's private key;
[0017] or,
[0018] The information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature;
[0019] or,
[0020] The information related to the authentication of the second subnet includes at least one of the following:
[0021] The third encrypted information is obtained by encrypting the second DID identifier using the private key of the second subnet's identity.
[0022] The request message is in plaintext and a fourth encrypted message is generated by encrypting the request message using the private key of the identity of the second subnet.
[0023] In some embodiments, the first network device performs authentication of the user equipment based on the first information, including:
[0024] The first network device queries the blockchain network device for the identity public key of the user device based on the first DID identifier;
[0025] The first network device decrypts the first encrypted information to obtain first decrypted information based on the identity public key of the user equipment, and / or decrypts the second encrypted information to obtain second decrypted information;
[0026] The first network device determines the authentication result of the user equipment based on the decryption information and the plaintext information; wherein the decryption information and the plaintext information include at least one combination of the following:
[0027] The first decryption information and the first DID identifier;
[0028] The second decryption information and the request information in plaintext.
[0029] In some embodiments, the first network device determines the authentication result of the user equipment based on decryption information and plaintext information, including:
[0030] If the decrypted information and the plaintext information are consistent, the first network device determines that the authentication result indicates that the user equipment's identity is legitimate.
[0031] And / or,
[0032] If the decrypted information and the plaintext information do not meet the consistency requirement, the first network device determines that the authentication result indicates that the user equipment's identity is illegitimate.
[0033] In some embodiments, the first network device performs authorization of the user equipment based on the first information, including:
[0034] The first network device determines the first identity public key based on the third DID identifier carried in the verifiable claim plaintext;
[0035] The first network device decrypts the verifiable declaration digital signature based on the first identity public key to obtain the third decryption information;
[0036] The first network device determines the authorization result of the user equipment based on the third decryption information and the verifiable declaration plaintext.
[0037] In some embodiments, the first network device determines the identity public key based on a third DID identifier carried in the plaintext of the verifiable claim, including at least one of the following:
[0038] If the third DID identifier is the DID identifier corresponding to the first subnet, then the first identity public key is determined to be the identity public key of the first subnet;
[0039] If the third DID identifier is the DID identifier corresponding to the central network to which the first subnet belongs, the first network device queries the blockchain network device for the identity public key of the central network based on the third DID identifier, and determines that the first identity public key is the identity public key of the central network.
[0040] If the third DID identifier is the DID identifier corresponding to the third subnet associated with the first subnet, the first network device queries the blockchain network device for the identity public key of the third subnet based on the third DID identifier, and determines that the first identity public key is the identity public key of the third subnet.
[0041] In some embodiments, the first network device determines the authorization result of the user equipment based on the third decryption information and the verifiable claim plaintext, including:
[0042] If the third decryption information and the plaintext of the verifiable declaration are consistent, then the first network device determines that the authorization result is authorized.
[0043] And / or,
[0044] If the third decryption information and the verifiable declaration plaintext do not meet the consistency requirement, the first network device determines that the authorization result is an authorization failure.
[0045] In some embodiments, the access control method further includes at least one of the following:
[0046] If the first network device determines that the user equipment's identity is legitimate, it sends a first message to the third network device of the central network to which the first subnet belongs; wherein, the first message is used to request a verifiable statement for the user equipment;
[0047] The first network device sends a second message to the third network device; wherein the second message is used to request authentication of the user equipment and to provide a verifiable claim for the user equipment;
[0048] The verifiable claim is used to access at least one subnet belonging to the central network.
[0049] In some embodiments, the access control method further includes:
[0050] The first network device sends a third message to a third network device in the central network to which the first subnet belongs; wherein the third message is used to request authentication of the user equipment;
[0051] The first network device receives a response message from the third network device to the third message; wherein the response message is used to indicate the authentication result of the user equipment;
[0052] The first network device sends a verifiable declaration to the user equipment based on the response message;
[0053] The verifiable statement is used to access the first subnet and / or to access the third subnet associated with the first subnet.
[0054] In some embodiments, the first network device performs authentication of the second subnet based on the second information, including:
[0055] The first network device queries the identity public key of the second subnet from the blockchain network device through the proxy server based on the second DID identifier;
[0056] The first network device decrypts the third encrypted information to obtain the third decrypted information based on the identity public key of the second subnet, and / or decrypts the fourth encrypted information to obtain the fourth decrypted information;
[0057] The first network device determines the authentication result of the second subnet based on the decryption information and the plaintext information; wherein the decryption information and the plaintext information include at least one combination of the following:
[0058] The third decryption information and the second DID identifier;
[0059] The fourth decryption information and request information are in plaintext.
[0060] In some embodiments, the first network device determines the authentication result of the second subnet based on the decryption information and the plaintext information, including:
[0061] If the decrypted information and the plaintext information are consistent, the first network device determines that the authentication result is valid for the identity of the second subnet.
[0062] And / or,
[0063] If the decrypted information and the plaintext information do not meet the consistency requirement, the first network device determines that the authentication result indicates that the identity of the second subnet is illegitimate.
[0064] In some embodiments, the access control method further includes:
[0065] The first network device receives the DID identifier corresponding to the first subnet from the third network device of the central network to which the first subnet belongs.
[0066] This disclosure provides an access control method, including:
[0067] The user equipment sends first information to the first network device in the first subnet; wherein the first information includes one of the following:
[0068] The first DID identifier corresponding to the user equipment and the authentication-related information of the user equipment;
[0069] The user equipment includes a first DID identifier, authentication information related to the user equipment, and authorization information related to the user equipment.
[0070] In some embodiments, before the user equipment sends the first information to the first network device of the first subnet, the method further includes:
[0071] The user equipment receives the first DID identifier sent by the third network device of the central network to which the first subnet belongs.
[0072] In some embodiments, the information related to the authentication of the user equipment includes at least one of the following:
[0073] First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier;
[0074] The request message in plaintext and a second encrypted message encrypted using the user equipment's private key;
[0075] or,
[0076] The information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature. In some embodiments, the access control method further includes at least one of the following:
[0077] The user equipment receives a verifiable statement plaintext sent by the first network device;
[0078] The user equipment receives a verifiable statement plaintext sent by a third network device of the central network to which the first subnet belongs;
[0079] The verifiable declaration states that a plaintext user accesses at least one subnet belonging to the central network.
[0080] This disclosure provides an access control method applied to a third network device in a central network, the method comprising:
[0081] The third network device sends the first DID identifier corresponding to the user equipment to the user equipment, and / or sends the second DID identifier corresponding to the second subnet to the second network device of the second subnet;
[0082] The second subnet belongs to the central network.
[0083] In some embodiments, the information related to the authentication of the user equipment includes at least one of the following:
[0084] First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier;
[0085] The request message in plaintext and a second encrypted message encrypted using the user equipment's private key;
[0086] or,
[0087] The information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature;
[0088] or,
[0089] The information related to the authentication of the second subnet includes at least one of the following:
[0090] The third encrypted information is obtained by encrypting the second DID identifier using the private key of the second subnet's identity.
[0091] The request message is in plaintext and a fourth encrypted message is generated by encrypting the request message using the private key of the identity of the second subnet.
[0092] In some embodiments, the access control method further includes:
[0093] The third network device receives a first message sent by the first network device of the first subnet; wherein the first message is used to request a verifiable claim for the user equipment;
[0094] The third network device sends a verifiable declaration to the user equipment based on the user equipment's subscription information;
[0095] The first subnet belongs to the central network, and the verifiable declaration is used to access at least one subnet belonging to the central network.
[0096] In some embodiments, the access control method further includes:
[0097] The third network device receives a second message sent by the first network device of the first subnet; wherein the second message is used to request authentication of the user equipment and to provide a verifiable claim for the user equipment;
[0098] The third network device authenticates the user equipment based on the second message and determines the authentication result;
[0099] If the authentication result confirms that the user equipment's identity is legitimate, the third network device sends a verifiable declaration to the user equipment based on the user equipment's subscription information.
[0100] The first subnet belongs to the central network, and the verifiable declaration is used to access at least one subnet belonging to the central network.
[0101] In some embodiments, the access control method further includes:
[0102] The third network device receives a third message sent by the first network device in the first subnet; wherein the third message is used to request authentication of the user equipment; wherein the first subnet belongs to the central network;
[0103] The third network device authenticates the user equipment based on the third message and determines the authentication result;
[0104] The third network device sends a response message to the first network device for the third message; wherein the response message is used to indicate the authentication result of the user equipment.
[0105] In some embodiments, the authentication result is used to indicate whether the identity of the user equipment is legitimate, and / or, the authentication result is used to indicate whether the verifiable claim is allowed to be provided to the user equipment.
[0106] In some embodiments, the access control method further includes:
[0107] The third network device sends the DID identifier corresponding to the first subnet to the first network device of the first subnet; wherein, the first subnet belongs to the central network.
[0108] This disclosure provides an access control device applied to a first subnet, including a memory, a transceiver, and a processor;
[0109] The memory stores computer programs; the transceiver, under the control of the processor, sends and receives data; the processor reads the computer programs from the memory and performs the following operations:
[0110] Receive the first message or the second message;
[0111] Authentication of the user equipment is performed based on the first information, or authentication and authorization of the user equipment are performed based on the first information, or authentication of the second subnet is performed based on the second information;
[0112] The first information includes one of the following:
[0113] The first DID identifier corresponding to the user equipment and the authentication-related information of the user equipment;
[0114] The first DID identifier corresponding to the user equipment, the authentication-related information of the user equipment, and the authorization-related information of the user equipment;
[0115] The second information includes the second DID identifier corresponding to the second subnet and information related to the authentication of the second subnet.
[0116] In some embodiments, the information related to the authentication of the user equipment includes at least one of the following:
[0117] First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier;
[0118] The request message in plaintext and a second encrypted message encrypted using the user equipment's private key;
[0119] or,
[0120] The information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature;
[0121] or,
[0122] The information related to the authentication of the second subnet includes at least one of the following:
[0123] The third encrypted information is obtained by encrypting the second DID identifier using the private key of the second subnet's identity.
[0124] The request message is in plaintext and a fourth encrypted message is generated by encrypting the request message using the private key of the identity of the second subnet.
[0125] In some embodiments, the processor is configured to read a computer program from the memory and perform the following operations:
[0126] Based on the first DID identifier, query the blockchain network device for the identity public key of the user device;
[0127] Based on the user equipment's identity public key, the first encrypted information is decrypted to obtain the first decrypted information, and / or the second encrypted information is decrypted to obtain the second decrypted information;
[0128] The authentication result of the user equipment is determined based on the decrypted information and the plaintext information; wherein the decrypted information and the plaintext information include at least one combination of the following:
[0129] The first decryption information and the first DID identifier;
[0130] The second decryption information and the request information in plaintext.
[0131] In some embodiments, the processor is configured to read a computer program from the memory and perform the following operations:
[0132] The first identity public key is determined based on the third DID identifier carried in the plaintext of the verifiable claim;
[0133] Based on the first identity public key, the verifiable declaration digital signature is decrypted to obtain the third decryption information;
[0134] The authorization result of the user equipment is determined based on the third decryption information and the verifiable statement plaintext.
[0135] In some embodiments, the processor is configured to read a computer program from the memory and perform the following operations:
[0136] Based on the second DID identifier, query the identity public key of the second subnet from the blockchain network device through the proxy server;
[0137] Based on the identity public key of the second subnet, the third encrypted information is decrypted to obtain the third decrypted information, and / or the fourth encrypted information is decrypted to obtain the fourth decrypted information;
[0138] The authentication result of the second subnet is determined based on the decrypted information and the plaintext information; wherein the decrypted information and the plaintext information include at least one combination of the following:
[0139] The third decryption information and the second DID identifier;
[0140] The fourth decryption information and request information are in plaintext.
[0141] This disclosure provides a network device applied to a first subnet, comprising:
[0142] The first receiving unit is used to receive first information or second information;
[0143] The processing unit is configured to perform authentication of the user equipment based on the first information, or to perform authentication and authorization of the user equipment based on the first information, or to perform authentication of the second subnet based on the second information;
[0144] The first information includes one of the following:
[0145] The first DID identifier corresponding to the user equipment and the authentication-related information of the user equipment;
[0146] The first DID identifier corresponding to the user equipment, the authentication-related information of the user equipment, and the authorization-related information of the user equipment;
[0147] The second information includes the second DID identifier corresponding to the second subnet and information related to the authentication of the second subnet.
[0148] This disclosure provides an access control device, including a memory, a transceiver, and a processor;
[0149] The memory stores computer programs; the transceiver, under the control of the processor, sends and receives data; the processor reads the computer programs from the memory and performs the following operations:
[0150] Send first information to a first network device in a first subnet; wherein the first information includes one of the following:
[0151] The first DID identifier corresponding to the user equipment and the authentication-related information of the user equipment;
[0152] The user equipment's first DID identifier, authentication-related information, and authorization-related information.
[0153] This disclosure provides a user equipment, including:
[0154] The sending unit is configured to send first information to a first network device in a first subnet; wherein the first information includes one of the following:
[0155] The first DID identifier corresponding to the user equipment and the authentication-related information of the user equipment;
[0156] The user equipment includes a first DID identifier, authentication information related to the user equipment, and authorization information related to the user equipment.
[0157] This disclosure provides an access control device for use in a central network, including a memory, a transceiver, and a processor;
[0158] The memory stores computer programs; the transceiver, under the control of the processor, sends and receives data; the processor reads the computer programs from the memory and performs the following operations:
[0159] Send the first DID identifier corresponding to the user equipment to the user equipment, and / or send the second DID identifier corresponding to the second subnet to the second network device of the second subnet;
[0160] The second subnet belongs to the central network.
[0161] This disclosure provides a network device applied to a central network, comprising:
[0162] The first sending unit is configured to send a first DID identifier corresponding to the user equipment to the user equipment, and / or send a second DID identifier corresponding to the second subnet to the second network device of the second subnet;
[0163] The second subnet belongs to the central network.
[0164] This disclosure provides a processor-readable storage medium storing a computer program for causing the processor to perform the steps of the access control method described above.
[0165] This disclosure provides a computer program product, including computer instructions that, when executed by a processor, implement the steps of the access control method described above.
[0166] The beneficial effects of the above-mentioned technical solution disclosed herein are:
[0167] In this embodiment of the disclosure, the first network device of the first subnet can support authenticating the user equipment (UE) or authenticating and authorizing the UE based on the first information. Alternatively, the first network device can support authenticating the second subnet based on the second information. This achieves authenticating and authorizing the UE through distributed subnets in the 6G network, enabling authentication between different distributed subnets within the 6G network, avoiding network pressure caused by authentication and authorization by the central network in the 6G network, and reducing communication latency for the UE. Attached Figure Description
[0168] Figure 1 shows a schematic diagram of the 6G system architecture according to an embodiment of the present disclosure;
[0169] Figure 2 shows a schematic diagram of the structure of the DID identifier according to an embodiment of this disclosure;
[0170] Figure 3 shows a schematic diagram of the structure of the DID document according to an embodiment of this disclosure;
[0171] Figure 4 shows a schematic diagram of the structure of the VC according to an embodiment of this disclosure;
[0172] Figure 5 shows a flowchart of the access control method on the first network device side according to an embodiment of this disclosure;
[0173] Figure 6 is a flowchart of an access control method on the user equipment side according to an embodiment of this disclosure;
[0174] Figure 7 is a flowchart of the access control method on the third network device side according to an embodiment of this disclosure;
[0175] Figure 8 is a block diagram illustrating the authentication and authorization process of a user device according to an embodiment of this disclosure;
[0176] Figure 9 shows a flowchart of the user equipment authentication process according to an embodiment of this disclosure;
[0177] Figure 10 shows a flowchart of the VC authentication process of a user equipment according to an embodiment of this disclosure;
[0178] Figure 11 shows a schematic diagram of the interaction flow of the access control method according to an embodiment of the present disclosure;
[0179] Figure 12 is a block diagram illustrating the authentication process between distributed subnets according to an embodiment of this disclosure;
[0180] Figure 13 is a flowchart illustrating the authentication process between distributed subnets according to an embodiment of this disclosure;
[0181] Figure 14 is a block diagram of the access control device on the first network device side according to an embodiment of the present disclosure;
[0182] Figure 15 shows a block diagram of a first network device according to an embodiment of the present disclosure;
[0183] Figure 16 is a block diagram of an access control device on the user equipment side according to an embodiment of the present disclosure;
[0184] Figure 17 shows a block diagram of a user equipment according to an embodiment of the present disclosure;
[0185] Figure 18 shows a block diagram of the access control device on the third network device side according to an embodiment of this disclosure;
[0186] Figure 19 shows a block diagram of a third network device according to an embodiment of this disclosure. Detailed Implementation
[0187] To make the technical problems, solutions, and advantages of this disclosure clearer, a detailed description will be provided below in conjunction with the accompanying drawings and specific embodiments. In the following description, specific details such as particular configurations and components are provided merely to aid in a comprehensive understanding of the embodiments of this disclosure. Therefore, those skilled in the art should understand that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of this disclosure. Furthermore, for clarity and brevity, descriptions of known functions and structures have been omitted.
[0188] It should be understood that the phrase "an embodiment" or "one embodiment" throughout the specification means that a particular feature, structure, or characteristic relating to an embodiment is included in at least one embodiment of this disclosure. Therefore, "in one embodiment" or "one embodiment" appearing throughout the specification does not necessarily refer to the same embodiment. Furthermore, these particular features, structures, or characteristics may be combined in any suitable manner in one or more embodiments.
[0189] In the various embodiments of this disclosure, it should be understood that the sequence number of each process described below does not imply the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of this disclosure.
[0190] In addition, the terms "system" and "network" are often used interchangeably in this article.
[0191] The technical solutions provided in this disclosure are applicable to a variety of systems, especially 6G systems. For example, applicable systems include Global System for Mobile Communication (GSM), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA) General Packet Radio Service (GPRS), Long Term Evolution (LTE), LTE Frequency Division Duplex (FDD), LTE Time Division Duplex (TDD), Long Term Evolution Advanced (LTE-A), Universal Mobile Telecommunications System (UMTS), Worldwide Interoperability for Microwave Access (WiMAX), 5th Generation Mobile Communication Technology (5G) New Radio (NR), and 6G systems. All of these systems include terminal equipment (or user equipment) and network equipment. The system may also include a core network component, such as an evolved packet system (EPS), a 5G system (5GS), or a 6G system.
[0192] Network devices and terminal devices can each use one or more antennas for Multiple Input Multiple Output (MIMO) transmission. MIMO transmission can be Single User MIMO (SU-MIMO) or Multiple User MIMO (MU-MIMO). Depending on the configuration and number of antenna combinations, MIMO transmission can be 2D MIMO, 3D MIMO, Full Dimension MIMO (FD-MIMO), or Massive MIMO, or it can be diversity transmission, pre-coded transmission, or beamforming transmission, etc.
[0193] In this disclosure, the term "and / or" describes the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent three cases: A alone, A and B simultaneously, and B alone. The character " / " generally indicates that the preceding and following related objects have an "or" relationship.
[0194] In this disclosure, the term "multiple" refers to two or more, and other quantifiers are similar.
[0195] The technical solutions of the embodiments of this disclosure will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of this disclosure, and not all embodiments. Based on the embodiments of this disclosure, all other embodiments obtained by those of ordinary skill in the art without creative effort are within the scope of protection of this disclosure.
[0196] The following describes the relevant technologies involved in this disclosure:
[0197] 1. Distributed 6G network architecture
[0198] Future 6G networks will introduce a distributed architecture consisting of a central network and distributed subnets, as shown in Figure 1. Here, "central" and "distributed" refer to network operation and management, not strictly a difference in physical location. The central network (or central node, central network node, etc.) is used to meet wide-area coverage needs and universal new service requirements such as intelligence and sensing. Distributed subnets (or distributed nodes, distributed subnet nodes, etc.) are mainly used to meet specific needs for connectivity, intelligence, and sensing in various scenarios, such as localized access and customized subnets for enterprises (ToB), satellite network access, and personalized subnets for personal services. The 6G network architecture follows the principles of flexible, on-demand, and intelligent network design, enabling diverse connections and network configurations between various networks. The central network has relatively complete functions, while the distributed subnet functions are tailored and organized as needed, following a principle of minimalist design. Through collaboration between wireless access and the core network, interconnection between the central network and distributed subnets, high- and low-frequency collaborative access, and air-space-ground integrated access networking, 6G networks will evolve from two-dimensional to full-space three-dimensional coverage, meeting the needs of various ubiquitous connectivity scenarios and providing network infrastructure for green and sustainable ubiquitous access and co-construction and sharing that is compatible with various industry ecosystems.
[0199] 2. Decentralized Identity
[0200] DID is a new type of identifier designed to identify any entity (such as an individual, organization, abstract entity, virtual entity, etc.).
[0201] Currently, mainstream internet identities are defined by each platform. A user may need to record identity information from multiple websites, which can easily lead to various problems. Identity information is not shared between platforms, and identity data is held by each application. Once a website closes, the identity information is lost. In contrast, the DID identifier is platform-independent. A single DID identifier can log in to multiple different platforms. Even if one platform closes, it does not affect the ability to log in to other platforms (provided that the platform supports DID identifiers). In other words, the DID identifier does not belong to any platform and exists independently.
[0202] As shown in Figure 2, a string with a specific format for a DID identifier is given, which consists of three parts: Scheme, DID Method, and DID Method-Specific Identifier, representing a digital identity for a person, machine, thing, or virtual person or thing.
[0203] A DID document is a detailed description of a DID, representing a one-to-one relationship. It can be viewed as consisting of two parts: DID metadata and the DID public key, as shown in Figure 3. The public key is crucial and is used for digital signatures or encryption operations.
[0204] Generally, DID identifiers are stored on the user's side, while DID documents are stored in a database such as a blockchain (using the DID identifier as the key index) to ensure the correctness of the DID documents. It's important to note that DID documents do not contain any information related to the user's actual personal information, such as real name, address, or phone number. Therefore, relying solely on the DID specification is insufficient to verify the legitimacy of an identity; verifiable claims (VCs) at the DID application layer are necessary.
[0205] 3. Verifiable Statement
[0206] A VC is a descriptive statement issued by one DID to endorse certain attributes of another DID, and includes its own digital signature to prove the authenticity of these attributes. It can be considered a type of digital certificate. The format of a VC is shown in Figure 4, including:
[0207] VC metadata: mainly includes information such as issuer, issue date, and type of declaration;
[0208] Claim(s): One or more statements about the subject, such as: identity-related documents issued by an authority to an individual as a VC. The claim may include information such as: name, gender, date of birth, ethnicity, address, etc.
[0209] Proof(s): This is usually the digital signature of the issuer, which ensures that the VC can be verified, prevents the VC content from being tampered with, and verifies the issuer of the VC.
[0210] Because the DID document corresponding to the DID identifier does not contain the user's real information, when the user performs an operation, the network side requires the user to provide proof, i.e., to present the VC. Considering that the VC does not contain the issuer's public key, otherwise the verifier would also need to verify the authenticity of the public key, how the verifier verifies the VC needs to be considered. Therefore, this embodiment considers the VC's ID to be a Uniform Resource Identifier (URI), and the issuer field in the VC is also a URI. The issuer may also use the DID identifier as its identity identifier. The DID identifier can be obtained through the issuer field: URI address in the VC, and its public key can be obtained through the corresponding DID document. The digital signature of the VC is verified through public key verification, thereby achieving VC verification.
[0211] 4. Blockchain
[0212] Blockchain networks are essentially a distributed ledger technology. Due to their consensus and cryptographic mechanisms, they can ensure that the data on the chain is not tampered with, thus providing a trust endorsement for the data.
[0213] Future 6G networks will see the coexistence of numerous subnetworks (e.g., edge networks, enterprise private networks, campus networks), operating independently or supporting interconnection. When mobile 6G network users need to connect to different distributed subnetworks to obtain 6G network services due to changes in time and location, there is currently no solution for how 6G networks can provide a unified mechanism to achieve (re)authentication and authorization of user identities across various subnetworks, and how authentication will occur between different subnetworks.
[0214] This disclosure provides access control methods, apparatus, network devices, and user equipment to address the current lack of solutions for how to authenticate and authorize user identities in each subnetwork and how to authenticate between subnetworks in future 6G networks. The methods and apparatus (or network devices or user equipment) are based on the same concept. Since the principles underlying the problems solved by the methods and apparatus (or network devices or user equipment) are similar, their implementations can be mutually referenced, and repeated details will not be elaborated further.
[0215] As shown in Figure 5, embodiments of this disclosure provide an access control method applied to a first network device in a first subnet. In some embodiments, the first subnet may be a distributed subnet in a 6G network.
[0216] The method includes the following steps:
[0217] Step 51: The first network device receives the first information or the second information.
[0218] In some embodiments, the first network device receiving the first information may be the first network device receiving the first information of the user equipment, or the first network device receiving the first information of the first user equipment forwarded by the second user equipment, or the first network device receiving the first information of the user equipment forwarded by other network devices, etc., and the embodiments disclosed herein are not limited thereto.
[0219] In some embodiments, the first information includes one of the following:
[0220] The first DID identifier corresponding to the user equipment and the authentication information related to the user equipment;
[0221] The user equipment's first DID identifier, authentication-related information, and authorization-related information.
[0222] For example, if the first information includes a first DID identifier corresponding to the user equipment and authentication-related information for the user equipment, the first information can be used for authenticating the user equipment. As another example, if the first information includes a first DID identifier corresponding to the user equipment, authentication-related information for the user equipment, and authorization-related information for the user equipment, the first information can be used for both authentication and authorization of the user equipment.
[0223] In some embodiments, the first network device receiving the second information may be that the first network device receives the second information of the second subnet from a second network device in the second subnet, or the first network device receives the second information of the second subnet forwarded by a network device in another subnet, etc., and the embodiments disclosed herein are not limited thereto.
[0224] In some embodiments, the second subnet can be a distributed subnet in a 6G network, and the first subnet and the second subnet are different distributed subnets in the 6G network. The first subnet and the second subnet may belong to the same central network or different central networks, etc., and this disclosure is not limited thereto.
[0225] In some embodiments, the second information includes a second DID identifier corresponding to the second subnet and information related to the authentication of the second subnet. For example, the second information can be used for the authentication of the second subnet.
[0226] Step 52: The first network device performs authentication of the user equipment based on the first information, or performs authentication and authorization of the user equipment based on the first information, or performs authentication of the second subnet based on the second information.
[0227] In some embodiments, where the first information includes a first DID identifier corresponding to the user equipment and information related to the authentication of the user equipment, the first network device may perform authentication of the user equipment based on the first information.
[0228] In some embodiments, when the first information includes a first DID identifier corresponding to the user equipment, authentication-related information of the user equipment, and authorization-related information of the user equipment, the first network device may perform authentication and authorization of the user equipment based on the first information.
[0229] In some embodiments, where the second information includes a second DID identifier corresponding to the second subnet and information related to the authentication of the second subnet, the first network device may perform authentication of the second subnet based on the second information.
[0230] It should be noted that the first network device can support authenticating user equipment or authenticating and authorizing user equipment based on the first information. And / or, the first network device can support authenticating the second subnet based on the second information.
[0231] It should also be noted that, in addition to supporting authentication of the second subnet based on the second information, the first network device can also support sending third information to the second network device of the second subnet for authentication of the first subnet by the second network device. For example, the third information includes the DID identifier of the first subnet and information related to the authentication of the first subnet, etc., and this embodiment is not limited thereto.
[0232] In the above scheme, the first network device in the first subnet can support authenticating user equipment (UE) or authenticating and authorizing UE based on the first information. Alternatively, the first network device can support authenticating the second subnet based on the second information. This achieves UE authentication and authorization by distributed subnets in the 6G network, enables authentication between different distributed subnets in the 6G network, avoids network pressure caused by the central network in the 6G network participating in authentication and authorization in real time, and reduces communication latency for UEs.
[0233] In some embodiments, the first DID identifier is configured by the central network to which the first subnet belongs, and / or the second DID identifier is configured by the central network to which the second subnet belongs.
[0234] For example, the central network can be the central network in a 6G network, and the first subnet and the second subnet are different distributed subnets in the 6G network. The first subnet and the second subnet can belong to the same central network or different central networks.
[0235] For example, continuing to refer to Figure 1, a central network can have multiple distributed sub-networks, meaning multiple distributed sub-networks can belong to the central network. After each distributed sub-network confirms the identity of the central network, the central network is trusted by each distributed sub-network. In some embodiments, the central network can configure a corresponding DID identifier for each distributed sub-network; that is, the second DID identifier corresponding to the second sub-network can be configured by the central network to which the second sub-network belongs.
[0236] For example, the central network generates DID identifiers and DID documents for each distributed sub-network. The central network also maintains the DID documents for each distributed sub-network, performing operations such as modification, deletion, and addition of DID documents. In some embodiments, only the central network has permission to perform these operations; for example, a smart contract can be configured to allow only the home network to write to the DID document of the user device. This disclosure is not limited to these embodiments.
[0237] The central network sends the DID identifiers and corresponding private keys of each distributed subnetwork to user devices for storage, and uploads the DID identifiers and DID documents (wherein the DID identifier contains the user device's public key) to the blockchain network. Distributed subnetworks belonging to the central network can query the blockchain network for the DID documents of other distributed subnetworks using their respective DID identifiers. In some embodiments, both the central network and the distributed subnetworks can act as nodes in the blockchain network, registered in the blockchain network through a proxy server. Alternatively, the central network and the distributed subnetworks can also be nodes independent of the blockchain network, such as clients connected to blockchain nodes, etc., and this disclosure is not limited to these embodiments.
[0238] In some embodiments, the access control method further includes: the first network device receiving a DID identifier corresponding to the first subnet from a third network device of the central network to which the first subnet belongs. That is, the DID identifier corresponding to the first subnet can be configured by the central network of the first subnet.
[0239] For example, if a user equipment (UE) can subscribe to a central network, the central network can configure a corresponding DID identifier for the UE. For instance, if a first subnet belongs to the central network, the UE can access the first subnet based on the DID identifier configured by the central network. In other words, the UE's first DID identifier is configured by the central network to which the first subnet belongs.
[0240] For example, a user equipment (UE) subscribes to a central network, which generates a DID identifier and a DID document for the UE. The DID identifier corresponds one-to-one with the user's identity. The central network maintains the UE's DID document, performing operations such as modification, deletion, and addition. In some embodiments, only the central network has permission to perform these operations; for example, a smart contract can be configured to allow only the home network to write to the UE's DID document. This disclosure is not limited to these limitations.
[0241] The central network sends the user device's DID identifier and corresponding private key to the user device for storage, and uploads the DID identifier and DID document (wherein the DID identifier contains the user device's public key) to the blockchain network. Distributed sub-networks belonging to this central network can query the user device's DID document from the blockchain network using the user device's DID identifier. In some embodiments, both the central network and the distributed sub-networks can act as nodes in the blockchain network, registered in the blockchain network through a proxy server. Alternatively, the central network and the distributed sub-networks can also be nodes independent of the blockchain network, such as clients connected to blockchain nodes; this disclosure is not limited to these embodiments.
[0242] In some embodiments, the information related to the authentication of the user equipment includes at least one of the following:
[0243] First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier;
[0244] The request information consists of plaintext and a second encrypted information encrypted using the user equipment's private key. For example, the plaintext request information may be plaintext information related to the user equipment's access request and / or authentication request, or other request-related information. The second encrypted information corresponds to the plaintext request information. For instance, if the plaintext request information is plaintext information related to the user equipment's access request, then the second encrypted information may be encrypted information related to the user equipment's access request, etc. This embodiment is not limited to this.
[0245] For example, the first information may include a first DID identifier corresponding to the user equipment and the first encrypted information. Alternatively, the first information may include a first DID identifier corresponding to the user equipment, plaintext request information, and the second encrypted information.
[0246] In some embodiments, the information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature.
[0247] In some embodiments, the information related to the authentication of the second subnet includes at least one of the following:
[0248] The third encrypted information is obtained by encrypting the second DID identifier using the private key of the second subnet's identity.
[0249] The request information consists of plaintext and a fourth encrypted information, which is encrypted using the private key of the second subnet's identity. For example, the plaintext request information may be plaintext information related to service requests and / or authentication requests of the second subnet, or other request-related information. The fourth encrypted information corresponds to the plaintext request information. For instance, if the plaintext request information is plaintext information related to an authentication request of the second subnet, then the fourth encrypted information may be encrypted information related to the authentication request of the second subnet. This embodiment is not limited to this.
[0250] For example, the second information may include the second DID identifier corresponding to the second subnet and the third encrypted information. Alternatively, the second information may include the second DID identifier corresponding to the second subnet, the plaintext request information, and the fourth encrypted information.
[0251] It should be noted that, for ease of distinction, the plaintext request information carried in the first information can also be called the first request information plaintext, and the plaintext request information carried in the second information can also be called the second request information plaintext.
[0252] In some embodiments, the first network device performs authentication of the user equipment based on the first information, including:
[0253] The first network device queries the blockchain network device for the identity public key of the user device based on the first DID identifier;
[0254] The first network device decrypts the first encrypted information to obtain first decrypted information based on the identity public key of the user equipment, and / or decrypts the second encrypted information to obtain second decrypted information;
[0255] The first network device determines the authentication result of the user equipment based on the decryption information and the plaintext information; wherein the decryption information and the plaintext information include at least one combination of the following:
[0256] The first decryption information and the first DID identifier;
[0257] The second decryption information and the request information in plaintext.
[0258] For example, taking a user equipment (UE) needing to access a first subnet as an example, the first information sent by the UE to the first network device of the first subnet includes: a first DID identifier corresponding to the UE and the first encrypted information. The first network device can query the UE's public key from the blockchain network device based on the first DID identifier in the first information. For example, the first network device can query the blockchain network device for the DID document corresponding to the first DID identifier, which carries the UE's public key. The first network device can then decrypt the first encrypted information using the UE's public key to obtain first decrypted information (i.e., the decrypted first DID identifier). Finally, the first network device determines the UE's authentication result based on the first decrypted information (i.e., the decrypted first DID identifier) and the first DID identifier.
[0259] For example, taking a user device's need to access a first subnet as an example, the first information sent by the user device to the first network device of the first subnet includes: a first DID identifier corresponding to the user device, plaintext request information, and second encrypted information. The first network device can query the user device's identity public key from the blockchain network device based on the first DID identifier in the first information. For example, the first network device can query the blockchain network device for the DID document corresponding to the first DID identifier, which carries the user device's identity public key. The first network device decrypts the second encrypted information using the user device's identity public key to obtain second decrypted information (i.e., the decrypted request information). The first network device determines the authentication result of the user device based on the second decrypted information (i.e., the decrypted request information) and the plaintext request information.
[0260] In some embodiments, the first network device determines the authentication result of the user equipment based on decryption information and plaintext information, including:
[0261] If the decrypted information and the plaintext information are consistent, the first network device determines that the authentication result indicates that the user equipment's identity is legitimate.
[0262] And / or,
[0263] If the decrypted information and the plaintext information do not meet the consistency requirement, the first network device determines that the authentication result indicates that the user equipment's identity is illegitimate.
[0264] For example, the decryption information and the plaintext information include: the first decryption information and the first DID identifier. That is, when the decryption information is the first decryption information and the plaintext information is the first DID identifier, the first decryption information (i.e., the decrypted first DID identifier) and the first DID identifier are compared for consistency. If the first decryption information (i.e., the decrypted first DID identifier) and the first DID identifier are consistent, the first network device determines that the authentication result is that the user equipment's identity is legitimate; and / or, if the first decryption information (i.e., the decrypted first DID identifier) and the first DID identifier are not consistent, the first network device determines that the authentication result is that the user equipment's identity is illegitimate. That is, the first network device determines the authentication result of the user equipment based on the first decryption information (i.e., the decrypted first DID identifier) and the first DID identifier.
[0265] For example, the decrypted information and the plaintext information include: the second decrypted information and the plaintext request information. That is, when the decrypted information is the second decrypted information and the plaintext request information is the plaintext request information, the second decrypted information (i.e., the decrypted request information) and the plaintext request information are compared for consistency. If the second decrypted information (i.e., the decrypted request information) and the plaintext request information are consistent, the first network device determines that the authentication result indicates the user equipment's identity is legitimate; and / or, if the second decrypted information (i.e., the decrypted request information) and the plaintext request information are inconsistent, the first network device determines that the user equipment's identity is illegitimate. In other words, the first network device determines the user equipment's authentication result based on the second decrypted information (i.e., the decrypted request information) and the plaintext request information.
[0266] In some embodiments, the first network device performs authorization of the user equipment based on the first information, including:
[0267] The first network device determines the first identity public key based on the third DID identifier carried in the verifiable claim plaintext;
[0268] The first network device decrypts the verifiable declaration digital signature based on the first identity public key to obtain the third decryption information;
[0269] The first network device determines the authorization result of the user equipment based on the third decryption information and the verifiable declaration plaintext.
[0270] For example, when a user equipment (UE) accesses a first subnet, the verifiable claim information in the authorization-related information sent to the first network device can be issued by the first subnet, the central network, or a third subnet associated with the first subnet (e.g., if the first subnet is a subordinate subnet of the third subnet, the verifiable claim information issued by the third subnet to the UE can be used to access the first subnet). In some embodiments, the verifiable claim carries the issuer's DID identifier. Based on the issuer's DID identifier, the corresponding identity public key (i.e., the first identity public key) can be obtained, which is used to verify the digital signature of the verifiable claim.
[0271] The following explains the process of determining the primary identity public key in different situations:
[0272] In some embodiments, the first network device determines the identity public key based on a third DID identifier carried in the plaintext of the verifiable claim, including at least one of the following:
[0273] Case 1: If the third DID identifier is the DID identifier corresponding to the first subnet, then the first identity public key is determined to be the identity public key of the first subnet.
[0274] For example, when a user device (UGC) receives a verifiable claim (including VC metadata, Claims, and proof) issued by a first subnet, it sends authorization-related information to the first network device when accessing the first subnet. This verifies the plaintext of the claim (including VC metadata and / or Claims) and the digital signature of the verifiable claim (i.e., the proof). The first network device determines that the issuer of the verifiable claim is the first subnet based on the third DID identifier carried in the plaintext of the verifiable claim. If the first subnet knows its own identity public key (e.g., the central network has provided the corresponding identity public key when configuring the DID identifier for the first subnet), then the first subnet can directly determine that the identity public key used for signature verification (i.e., the first identity public key) is the identity public key of the first subnet. Alternatively, if the first subnet does not know its own identity public key (e.g., the central network did not provide the corresponding identity public key when configuring the DID identifier for the first subnet), then the first subnet can query its own identity public key from the blockchain network to verify the digital signature of the verifiable claim sent by the user device.
[0275] Scenario 2: If the third DID identifier is the DID identifier corresponding to the central network to which the first subnet belongs, the first network device queries the blockchain network device for the identity public key of the central network based on the third DID identifier, and determines that the first identity public key is the identity public key of the central network.
[0276] For example, when a user equipment (UE) receives a verifiable claim (including VC metadata, Claims, and proof) issued by a central network, and the UE accesses a first subnet, it sends authorization-related information to the first network device, which can verify the plaintext of the claim (including VC metadata and / or Claims) and the digital signature of the verifiable claim (i.e., proof). The first network device determines the issuer of the verifiable claim to be the central network to which the first subnet belongs based on the third DID identifier carried in the plaintext of the verifiable claim. It can then use this third DID identifier to query the blockchain network device for the identity public key of the central network (i.e., the first identity public key of the claim issuer) to verify the digital signature of the verifiable claim sent by the UE.
[0277] Scenario 3: If the third DID identifier is the DID identifier corresponding to the third subnet associated with the first subnet, the first network device queries the blockchain network device for the identity public key of the third subnet based on the third DID identifier, and determines that the first identity public key is the identity public key of the third subnet.
[0278] For example, a user device obtains a verifiable claim (e.g., including VC metadata, Claims, and proof) issued by a third subnet (e.g., when the first subnet is a subordinate subnet of the third subnet, the verifiable claim information issued by the third subnet to the user device can be used to access the first subnet). When the user device accesses the first subnet, it sends authorization-related information to the first network device, which can verify the plaintext of the claim (e.g., including VC metadata and / or Claims) and the digital signature of the verifiable claim (i.e., proof). The first network device determines that the issuer of the verifiable claim is the third subnet based on the third DID identifier carried in the plaintext of the verifiable claim. It can then use this third DID identifier to query the blockchain network device for the identity public key of the third subnet (i.e., the first identity public key of the claim issuer) to verify the digital signature of the verifiable claim sent by the user device.
[0279] In some embodiments, the first network device determines the authorization result of the user equipment based on the third decryption information and the verifiable claim plaintext, including:
[0280] If the third decryption information and the plaintext of the verifiable declaration are consistent, then the first network device determines that the authorization result is authorized.
[0281] And / or,
[0282] If the third decryption information and the verifiable declaration plaintext do not meet the consistency requirement, the first network device determines that the authorization result is an authorization failure.
[0283] Specifically, when the first identity public key is determined based on at least one of the above situations 1 to 3, the digital signature of the verifiable claim sent by the user equipment is decrypted based on the issuer's first identity public key to obtain third decrypted information (i.e., the decrypted verifiable claim), and the third decrypted information (i.e., the decrypted verifiable claim) is compared with the plaintext of the verifiable claim. If the third decrypted information (i.e., the decrypted verifiable claim) and the plaintext of the verifiable claim are consistent, the first network device determines that the authorization result is successful; and / or, if the third decrypted information (i.e., the decrypted verifiable claim) and the plaintext of the verifiable claim are not consistent, the first network device determines that the authorization result is unsuccessful.
[0284] The following describes the pre-defined process for verifiable claims (i.e., how user equipment obtains verifiable claims):
[0285] In some embodiments, the access control method further includes at least one of the following:
[0286] Method 1: When the first network device determines that the user equipment's identity is legitimate, it sends a first message to a third network device in the central network to which the first subnet belongs; wherein the first message is used to request a verifiable statement for the user equipment, and the verifiable statement is used to access at least one subnet belonging to the central network.
[0287] For example: A user equipment (UE) initially registers in a first subnet. The first subnet verifies the UE's identity in the central network (for the specific authentication process of the UE, please refer to the above embodiment). If the first subnet verifies the UE's identity as legitimate, it can forward the UE's verifiable statement acquisition request to the central network (i.e., send a first message to a third network device in the central network to which the first subnet belongs). The central network then issues a verifiable statement to the UE. For example, if the UE has a subscription to the central network, the central network can issue a verifiable statement to the UE for accessing one or more subnets based on the UE's subscription information.
[0288] Method 2: The first network device sends a second message to the third network device; wherein the second message is used to request authentication of the user equipment and to provide a verifiable claim for the user equipment, the verifiable claim being used to access at least one subnet belonging to the central network.
[0289] For example, when a user equipment (UE) initiates registration with a first subnet, the first subnet requests the central network to verify the UE's identity within that network and to forward a request for a verifiable statement from the UE to the central network. The central network then authenticates the UE (the specific authentication process can be found in the above embodiment). If the central network verifies the UE's legitimacy, it can issue a verifiable statement to the UE. For instance, if the UE has a subscription with the central network, the central network can issue a verifiable statement for accessing one or more subnets based on the UE's subscription information.
[0290] It should be noted that the verifiable claim issued by the central network to the user equipment can be used to access at least one subnet belonging to the central network. Here, one verifiable claim can be used to access one subnet or multiple subnets. The at least one subnet belonging to the central network may or may not include the first subnet. For example, the central network may issue a verifiable claim to the user equipment only for accessing the first subnet, or the central network may issue a verifiable claim to the user equipment for accessing the first subnet and verifiable claims for accessing other subnets, or the central network may issue one or more verifiable claims to the user equipment for accessing one or more subnets other than the first subnet, etc. This disclosure embodiment is not limited to these.
[0291] In some embodiments, the access control method further includes:
[0292] The first network device sends a third message to a third network device in the central network to which the first subnet belongs; wherein the third message is used to request authentication of the user equipment;
[0293] The first network device receives a response message from the third network device to the third message; wherein the response message is used to indicate the authentication result of the user equipment;
[0294] The first network device sends a verifiable declaration to the user equipment based on the response message;
[0295] The verifiable statement is used to access the first subnet and / or to access the third subnet associated with the first subnet.
[0296] For example, when a user equipment (UE) requests a verifiable claim from a first subnet for accessing the first subnet and / or a third subnet associated with the first subnet, since the UE is subscribed to a central network, the first subnet can request the central network to authenticate the UE (i.e., the first network device sends a third message to a third network device in the central network to which the first subnet belongs). The central network then authenticates the UE, and can inform the first subnet of the authentication result (i.e., the first network device receives a response message from the third network device to the third message).
[0297] In some embodiments, the authentication result can be used to indicate whether the identity of the user equipment is legitimate, and / or, the authentication result can be used to indicate whether the verifiable claim is allowed to be provided to the user equipment. For example, the central network can verify the legitimacy of the user equipment's identity (see the above embodiments for details), and / or, based on the user's subscription information, determine whether the user equipment can obtain authorization from the first subnet, thereby determining whether the first subnet is allowed to provide the verifiable claim to the user equipment. For example, the user equipment's subscription information in the central network includes support for providing service 1 and service 2. If the central network determines that the first subnet supports providing service 3, it can notify the first subnet that the verifiable claim is not allowed to be provided to the user equipment; or if the first subnet supports providing service 1, the central network can notify the first subnet that the verifiable claim is allowed to be provided to the user equipment, etc. Of course, the embodiments disclosed herein are not limited thereto.
[0298] For example, if the authentication result indicates that the user equipment's identity is legitimate (e.g., there is no indication of whether the verifiable claim is allowed for the user equipment), then the first network device can determine, based on the response message, that it can send the verifiable claim to the user equipment. Alternatively, if the authentication result indicates that the verifiable claim is allowed for the user equipment (e.g., there is no explicit indication of whether the user equipment's identity is legitimate), then the first network device can determine, based on the response message, that the user equipment's identity is legitimate and that it can send the verifiable claim to the user equipment.
[0299] It should be noted that the verifiable claims issued by the central network or distributed sub-network (such as the first sub-network) to the user equipment may include VC metadata, Claims, proof, etc., that is, information such as issuer, issuance date, and type of claim; one or more descriptions about the subject; digital signature of the issuer, etc., and this disclosure is not limited thereto.
[0300] In some embodiments, the first network device performs authentication of the second subnet based on the second information, including:
[0301] The first network device queries the identity public key of the second subnet from the blockchain network device through the proxy server based on the second DID identifier;
[0302] The first network device decrypts the third encrypted information to obtain the third decrypted information based on the identity public key of the second subnet, and / or decrypts the fourth encrypted information to obtain the fourth decrypted information;
[0303] The first network device determines the authentication result of the second subnet based on the decryption information and the plaintext information; wherein the decryption information and the plaintext information include at least one combination of the following:
[0304] The third decryption information and the second DID identifier;
[0305] The fourth decryption information and request information are in plaintext.
[0306] For example, taking cross-subnet services, such as a second subnet requesting a service from a first subnet, the second information sent by the second subnet to the first network device of the first subnet includes: a second DID identifier corresponding to the second subnet and the third encrypted information. The first network device can query the blockchain network device for the identity public key of the second subnet based on the second DID identifier in the second information. For example, the first network device can query the blockchain network device for the DID document corresponding to the second DID identifier, which carries the identity public key of the second subnet. The first network device decrypts the third encrypted information using the identity public key of the second subnet to obtain third decrypted information (i.e., the decrypted second DID identifier). The first network device determines the authentication result of the second subnet based on the third decrypted information (i.e., the decrypted second DID identifier) and the second DID identifier.
[0307] For example, taking cross-subnet services, such as a second subnet requesting a service from a first subnet, the second information sent by the second subnet to the first network device of the first subnet includes: a second DID identifier corresponding to the second subnet, plaintext request information, and the fourth encrypted information. The first network device can query the blockchain network device for the identity public key of the second subnet based on the second DID identifier in the second information. For example, the first network device can query the blockchain network device for the DID document corresponding to the second DID identifier, which carries the identity public key of the second subnet. The first network device decrypts the fourth encrypted information to obtain fourth decrypted information (i.e., the decrypted request information) based on the identity public key of the user device. The first network device determines the authentication result of the user device based on the fourth decrypted information (i.e., the decrypted request information) and the plaintext request information.
[0308] In some embodiments, the first network device determines the authentication result of the second subnet based on the decryption information and the plaintext information, including:
[0309] If the decrypted information and the plaintext information are consistent, the first network device determines that the authentication result is valid for the identity of the second subnet.
[0310] And / or,
[0311] If the decrypted information and the plaintext information do not meet the consistency requirement, the first network device determines that the authentication result indicates that the identity of the second subnet is illegitimate.
[0312] For example, the decryption information and the plaintext information include: the third decryption information and the second DID identifier. That is, when the decryption information is the third decryption information and the plaintext information is the second DID identifier, the third decryption information (i.e., the decrypted second DID identifier) and the second DID identifier are compared for consistency. If the third decryption information (i.e., the decrypted second DID identifier) and the second DID identifier are consistent, the first network device determines that the authentication result is that the identity of the second subnet is legitimate; and / or, if the third decryption information (i.e., the decrypted second DID identifier) and the second DID identifier are not consistent, the first network device determines that the authentication result is that the identity of the second subnet is illegitimate. That is, the first network device determines the authentication result of the second subnet based on the third decryption information (i.e., the decrypted second DID identifier) and the second DID identifier.
[0313] For example, the decrypted information and the plaintext information include: the fourth decrypted information and the plaintext request information. That is, when the decrypted information is the fourth decrypted information and the plaintext request information is the plaintext request information, the fourth decrypted information (i.e., the decrypted request information) and the plaintext request information are compared for consistency. If the fourth decrypted information (i.e., the decrypted request information) and the plaintext request information are consistent, the first network device determines that the authentication result is that the identity of the second subnet is legitimate; and / or, if the fourth decrypted information (i.e., the decrypted request information) and the plaintext request information are inconsistent, the first network device determines that the authentication result is that the identity of the second subnet is illegitimate. That is, the first network device determines the authentication result of the user equipment based on the fourth decrypted information (i.e., the decrypted request information) and the plaintext request information.
[0314] It should be noted that the embodiments of this disclosure can also support a first subnet requesting services from a second subnet. For example, the first subnet may send third information to the second subnet for authentication of the first subnet by the second network device. For instance, the third information may include the DID identifier of the first subnet and information related to the authentication of the first subnet. Specifically, the authentication process of the second subnet to the first subnet is similar to the authentication process of the first subnet to the second subnet described above, and will not be repeated here to avoid repetition.
[0315] It should also be noted that, for ease of distinction, the decryption information involved in the above authentication embodiments for user equipment can be referred to as the first target decryption information, and the plaintext information involved can be referred to as the first target plaintext information; the decryption information involved in the above authentication embodiments for the second subnet can be referred to as the second target decryption information, and the plaintext information involved can be referred to as the second target plaintext information.
[0316] The first network device involved in this disclosure can be a base station, which may include multiple cells providing services to terminals. Depending on the specific application, the base station may also be called an access point, or a device in the access network that communicates with the wireless terminal device through one or more sectors on the air interface, or other names. The network device can be used to exchange received air frames with Internet Protocol (IP) packets, acting as a router between the wireless terminal device and the rest of the access network, where the rest of the access network may include an Internet Protocol (IP) communication network. The network device can also coordinate the attribute management of the air interface. For example, the network equipment involved in this disclosure can be a base transceiver station (BTS) in a Global System for Mobile communications (GSM) or Code Division Multiple Access (CDMA) system, a NodeB in a wide-band Code Division Multiple Access (WCDMA) system, an evolved Node B (eNB or e-NodeB) in a long term evolution (LTE) system, a 5G base station (gNB) in a next generation system, a Home evolved Node B (HeNB), a relay node, a femto, a pico, etc., and is not limited in this disclosure. In some network structures, the network equipment may include centralized unit (CU) nodes and distributed unit (DU) nodes, and the centralized unit and distributed unit may be geographically separated.
[0317] As shown in Figure 6, this embodiment of the present disclosure provides an access control method, including the following steps:
[0318] Step 61: The user equipment sends first information to the first network device of the first subnet; wherein the first information includes one of the following:
[0319] The first decentralized identity (DID) identifier corresponding to the user equipment and the authentication-related information of the user equipment;
[0320] The user equipment includes a first DID identifier, authentication information related to the user equipment, and authorization information related to the user equipment.
[0321] In some embodiments, before the user equipment sends the first information to the first network device of the first subnet, the method further includes:
[0322] The user equipment receives the first DID identifier sent by the third network device of the central network to which the first subnet belongs.
[0323] In some embodiments, the information related to the authentication of the user equipment includes at least one of the following:
[0324] First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier;
[0325] The request message in plaintext and a second encrypted message encrypted using the user equipment's private key;
[0326] or,
[0327] The information related to the authorization of the user equipment includes: the plaintext of the verifiable claim and the digital signature of the verifiable claim.
[0328] In some embodiments, the access control method further includes at least one of the following:
[0329] The user equipment receives a verifiable statement plaintext sent by the first network device;
[0330] The user equipment receives a verifiable statement plaintext sent by a third network device of the central network to which the first subnet belongs;
[0331] The verifiable declaration states that a plaintext user accesses at least one subnet belonging to the central network.
[0332] It should be noted that the access control method on the user equipment side in this disclosure embodiment and the access control method on the first network device side described above are based on the same inventive concept. The two embodiments can refer to each other and can achieve the same technical effect. To avoid repetition, they will not be described again here.
[0333] The user equipment involved in the embodiments of this disclosure includes, but is not limited to, terminal equipment, such as devices that provide voice and / or data connectivity to users, handheld devices with wireless connectivity, or other processing devices connected to a wireless modem. The name of the terminal equipment may differ in different systems; for example, in a 5G system, the terminal equipment may be called User Equipment (UE). Wireless terminal equipment can communicate with one or more core networks (CNs) via a Radio Access Network (RAN). Wireless terminal equipment can be mobile terminal devices, such as mobile phones (or "cellular" phones) and computers with mobile terminal devices, for example, portable, pocket-sized, handheld, computer-embedded, or vehicle-mounted mobile devices that exchange voice and / or data with the RAN. Examples include Personal Communication Service (PCS) phones, cordless phones, Session Initiated Protocol (SIP) phones, Wireless Local Loop (WLL) stations, and Personal Digital Assistants (PDAs). Wireless terminal equipment can also be referred to as a system, subscriber unit, subscriber station, mobile station, mobile station, remote station, access point, remote terminal, access terminal, user terminal, user agent, or user device, but is not limited to these terms in the embodiments disclosed herein.
[0334] As shown in Figure 7, an embodiment of this disclosure provides an access control method applied to a third network device in a central network. The method includes the following steps:
[0335] Step 71: The third network device sends the first DID identifier corresponding to the user equipment to the user equipment, and / or sends the second DID identifier corresponding to the second subnet to the second network device of the second subnet;
[0336] The second subnet belongs to the central network.
[0337] In some embodiments, the information related to the authentication of the user equipment includes at least one of the following:
[0338] First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier;
[0339] The request message in plaintext and a second encrypted message encrypted using the user equipment's private key;
[0340] or,
[0341] The information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature;
[0342] or,
[0343] The information related to the authentication of the second subnet includes at least one of the following:
[0344] The third encrypted information is obtained by encrypting the second DID identifier using the private key of the second subnet's identity.
[0345] The request message is in plaintext and a fourth encrypted message is generated by encrypting the request message using the private key of the identity of the second subnet.
[0346] In some embodiments, the access control method further includes:
[0347] The third network device receives a first message sent by the first network device of the first subnet; wherein the first message is used to request a verifiable claim for the user equipment;
[0348] The third network device sends a verifiable declaration to the user equipment based on the user equipment's subscription information;
[0349] The first subnet belongs to the central network, and the verifiable declaration is used to access at least one subnet belonging to the central network.
[0350] In some embodiments, the access control method further includes:
[0351] The third network device receives a second message sent by the first network device of the first subnet; wherein the second message is used to request authentication of the user equipment and to provide a verifiable claim for the user equipment;
[0352] The third network device authenticates the user equipment based on the second message and determines the authentication result;
[0353] If the authentication result confirms that the user equipment's identity is legitimate, the third network device sends a verifiable declaration to the user equipment based on the user equipment's subscription information.
[0354] The first subnet belongs to the central network, and the verifiable declaration is used to access at least one subnet belonging to the central network.
[0355] In some embodiments, the access control method further includes:
[0356] The third network device receives a third message sent by the first network device in the first subnet; wherein the third message is used to request authentication of the user equipment; wherein the first subnet belongs to the central network;
[0357] The third network device authenticates the user equipment based on the third message and determines the authentication result;
[0358] The third network device sends a response message to the first network device for the third message; wherein the response message is used to indicate the authentication result of the user equipment.
[0359] In some embodiments, the authentication result is used to indicate whether the identity of the user equipment is legitimate, and / or, the authentication result is used to indicate whether the verifiable claim is allowed to be provided to the user equipment.
[0360] It should be noted that the access control method on the third network device side in this disclosure embodiment is based on the same inventive concept as the access control method on the first network device side described above. The two embodiments can refer to each other and can achieve the same technical effect. To avoid repetition, they will not be described again here.
[0361] The third network device involved in this disclosure can be a base station, which may include multiple cells providing services to terminals. Depending on the specific application, the base station may also be called an access point, or a device in the access network that communicates with the wireless terminal device through one or more sectors on the air interface, or other names. The network device can be used to exchange received air frames with Internet Protocol (IP) packets, acting as a router between the wireless terminal device and the rest of the access network, where the rest of the access network may include an Internet Protocol (IP) communication network. The network device can also coordinate the attribute management of the air interface. For example, the network equipment involved in this disclosure can be a base transceiver station (BTS) in a Global System for Mobile communications (GSM) or Code Division Multiple Access (CDMA) system, a NodeB in a wide-band Code Division Multiple Access (WCDMA) system, an evolved Node B (eNB or e-NodeB) in a long term evolution (LTE) system, a 5G base station (gNB) in a next generation system, a Home evolved Node B (HeNB), a relay node, a femto, a pico, etc., and is not limited in this disclosure. In some network structures, the network equipment may include centralized unit (CU) nodes and distributed unit (DU) nodes, and the centralized unit and distributed unit may be geographically separated.
[0362] The access control method of this disclosure will be described below with reference to specific embodiments:
[0363] Example 1: DID Identification Format
[0364] The format of the DID identifier is as follows:
[0365] did: <did-method>:<DID method-specific identifier>
[0366] Where did-method is a method used, such as DTmethod-1;
[0367] The DID method-specific identifier is <network information> + <user information ciphertext>, where network information refers to the name of the central network (in plaintext) in this embodiment of the disclosure, and user information can be personal information such as user identity, obtained through hash calculation.
[0368] Example 2: User Equipment Authentication
[0369] As shown in Figures 8 and 9, the user equipment authentication process includes the following steps:
[0370] Step 91: When a user equipment needs to access distributed subnet 1, it can present the user equipment's DID identifier, the plaintext of the access request, and the access request encrypted with the user equipment's corresponding identity private key.
[0371] Step 92: Distributed subnet 1 uses the DID identifier of the user device as the key in the key-value pair to search for the DID document corresponding to the DID identifier of the user device in the blockchain network.
[0372] Step 93: The blockchain network returns the DID document corresponding to the DID identifier of the user device, which contains the public key of the user device's identity.
[0373] Step 94: Distributed subnet 1 obtains the user equipment's public key, decrypts the encrypted access request using the user equipment's public key, and verifies the consistency between the decrypted access request and the plaintext access request. If they match, the user equipment's authentication is successful; if they do not match, the user equipment's authentication is deemed invalid, and the user equipment's access request is rejected.
[0374] Step 95: Distributed subnet 1 returns the authentication result to the user equipment.
[0375] Example 3: VC Authentication for User Equipment
[0376] As shown in Figures 8 and 10, the VC authentication process for user equipment includes the following steps:
[0377] The user equipment obtains a VC from the central network, meaning that the issuer of the VC is the central network. The VC indicates that the central network authorizes the user equipment to provide services in distributed subnet 1, such as service A.
[0378] Step 101: When a user equipment needs to obtain service A from distributed subnet 1, it can present the VC and the digital signature of the central network on the VC to distributed subnet 1.
[0379] Step 102: Distributed subnet 1 searches for the corresponding DID document in the blockchain network based on the issuer DID identifier in VC (i.e., the central network's DID identifier).
[0380] Step 103: The blockchain network returns the DID document of the central network, which contains the identity public key of the central network.
[0381] Step 104: Distributed subnet 1 obtains the identity public key of the central network, verifies the digital signature of the VC by the central network based on the identity public key, and determines whether the decrypted VC is consistent with the plaintext VC sent by the user equipment. If they are consistent, the authorization is successful; if they are inconsistent, the authorization is unsuccessful and the authorization request of the user equipment is rejected.
[0382] Step 105: Distributed subnet 1 returns the authorization result to the user equipment.
[0383] Example 4:
[0384] When a user device accesses distributed subnet 2, and authorization from distributed subnet 1 is required, the user device can access distributed subnet 2 through the VC used to access distributed subnet 1. In practical scenarios, for example, distributed subnet 1 belongs to a certain industry application network, and distributed subnet 2 is a subordinate subnet of it. When a user device accesses distributed subnet 2, it needs to obtain authorization from distributed subnet 1. As shown in Figure 11, the specific process includes:
[0385] Step 111: The user equipment requests a VC from distributed subnet 1.
[0386] Step 112: Distributed subnet 1 requests the central network to verify the identity of the user equipment and determine whether the corresponding VC can be issued to the user equipment.
[0387] For example, the central network can authenticate user equipment and, based on the user's subscription information, determine whether the user equipment can obtain authorization from the distributed subnet 1, and return the authentication result to the distributed subnet.
[0388] Step 113: If the user equipment is successfully authenticated and is allowed to provide a VC, then the distributed subnet 1 can issue the corresponding VC to the user equipment.
[0389] Step 114: When a user equipment needs to access distributed subnet 2, it can send the VC issued by distributed subnet 1 to distributed subnet 2.
[0390] Step 115: Distributed subnet 2 verifies the VC in the blockchain network (specifically, the VC authentication process in embodiment 3 above can be used, which will not be repeated here), and returns the authorization result.
[0391] Example 5: Addition of Distributed Subnets
[0392] 6G networks support a plug-and-play network architecture, thus allowing for the addition of distributed subnets. For example, when adding a distributed subnet, the node information of the subnet also needs to be updated in the blockchain network. This involves the generation of the distributed subnet's DID identifier and the on-chain process of the DID document, specifically including:
[0393] The central network generates DID identifiers and DID documents for the distributed subnets it manages. The distributed subnets store the DID identifiers and the corresponding identity private keys. In some embodiments, the identity private key corresponding to the DID identifier of a distributed subnet can be stored in a first network element of the distributed subnet. For example, the first network element can be a network element belonging to the core network in the distributed subnet that is involved in authentication functions, or it can be other network elements, etc. This disclosure does not make specific limitations.
[0394] The central network uploads the DID identifier and DID document (including identity public key) of the distributed subnet to the blockchain network and maintains the DID document of the distributed subnet node (such as modification, deletion, addition, etc.). Only the central network to which the distributed subnet belongs has the right to perform the above operations (for example, a smart contract can be set so that only the central network to which it belongs can perform write operations on the DID document of the distributed subnet).
[0395] In some embodiments, the central network and the distributed subnets can both serve as nodes in the blockchain network, or the central network and the distributed subnets can also be clients that can obtain services from the blockchain network and register in the blockchain network through a proxy server. This disclosure is not limited to these embodiments.
[0396] Example 6: Authentication between distributed subnets
[0397] Distributed subnets are registered on the blockchain network. Unlike user devices, which can upload DID identifiers and DID documents to the blockchain network through the central network, distributed subnets can connect to the blockchain network through a proxy server. Distributed subnets can directly publish messages or download data on the blockchain network through the proxy server.
[0398] For example, cross-subnet services for user equipment require authentication between multiple distributed subnets to provide the corresponding services. Taking authentication between distributed subnet 1 and distributed subnet 2 as an example, distributed subnet 1 sends a DID identifier to distributed subnet 2, and distributed subnet 2 sends a DID identifier to distributed subnet 1. After both parties obtain each other's DID identifiers, they can download the corresponding DID document from the blockchain and authenticate each other's identities (specifically, the authentication process described in Example 2 above can be used). The central networks to which distributed subnet 1 and distributed subnet 2 belong can be the same or different.
[0399] As shown in Figures 12 and 13, the specific authentication process between distributed subnets includes the following steps:
[0400] Step 131: Distributed subnet 1 sends an authentication request to distributed subnet 2, which carries the DID identifier of distributed subnet 1 and a digital signature.
[0401] Step 132: Distributed subnet 2 requests the proxy server 2 to return the public key of the identity of distributed subnet 1 based on the DID identifier of distributed subnet 1.
[0402] Step 133: Proxy server 2 queries the blockchain network for the identity public key of distributed subnet 1, and the blockchain network returns the identity public key of distributed subnet 1.
[0403] For example, distributed subnet 2 queries the blockchain network through proxy server 2 for the DID document corresponding to the DID identifier of distributed subnet 1 based on the DID identifier of distributed subnet 1. This DID document carries the identity public key of distributed subnet 1.
[0404] Step 134: Proxy server 2 returns the identity public key of distributed subnet 1.
[0405] Step 135: Distributed subnet 2 uses the public key of distributed subnet 1 to decrypt the digital signature of distributed subnet 1 and authenticate the identity of distributed subnet 1.
[0406] In some embodiments, distributed subnet 2 can also send an authentication request to distributed subnet 1, which carries the DID identifier and digital signature of distributed subnet 2. The specific authentication process is similar to steps 132 to 135 above, and will not be repeated here.
[0407] In this way, distributed subnet 1 authenticates distributed subnet 2, and / or distributed subnet 2 authenticates distributed subnet 1, and if the authentication is successful, a trusted relationship is established between distributed subnet 1 and distributed subnet 2.
[0408] In this embodiment, distributed subnets do not need to pre-sign authorization; instead, they can establish trusted relationships through DID authentication. Compared to traditional mechanisms where different networks need to pre-sign authorization to support cross-network services, this approach offers greater flexibility.
[0409] This disclosure, in a distributed network architecture, enables user device authentication and authorization, as well as authentication between various distributed subnets, based on a DID mechanism without relying on pre-established trust relationships. It also utilizes blockchain technology, based on distributed characteristics, to ensure the security of trust credentials through an authentication and service authorization mechanism. This scheme, based on DID-based user authentication and service authorization mechanisms, and authentication between various distributed subnets, does not require pre-established trust relationships between networks. Furthermore, trust credentials are stored on the user side, reducing the real-time involvement of the home network compared to 5G network roaming authentication technology. The use of blockchain technology and its distributed storage characteristics improve authentication efficiency, while the immutability of the blockchain endorses the on-chain trust credentials and ensures their secure storage.
[0410] The above embodiments describe the access control method of this disclosure. The following embodiments will further describe the corresponding devices, network devices and user devices in conjunction with the accompanying drawings.
[0411] As shown in Figure 14, this embodiment provides an access control device applied to a first subnet, including a memory 141, a transceiver 142, and a processor 143; wherein, the memory 141 is used to store computer programs; the transceiver 142 is used to send and receive data under the control of the processor 143; for example, the transceiver 142 is used to receive and send data under the control of the processor 143; the processor 143 is used to read the computer program in the memory 141 and perform the following operations:
[0412] Receive the first message or the second message;
[0413] Authentication of the user equipment is performed based on the first information, or authentication and authorization of the user equipment are performed based on the first information, or authentication of the second subnet is performed based on the second information;
[0414] The first information includes one of the following:
[0415] The first decentralized identity (DID) identifier corresponding to the user equipment and the authentication-related information of the user equipment;
[0416] The first DID identifier corresponding to the user equipment, the authentication-related information of the user equipment, and the authorization-related information of the user equipment;
[0417] The second information includes the second DID identifier corresponding to the second subnet and information related to the authentication of the second subnet.
[0418] In some embodiments, the first DID identifier is configured by the central network to which the first subnet belongs, and / or the second DID identifier is configured by the central network to which the second subnet belongs.
[0419] In some embodiments, the information related to the authentication of the user equipment includes at least one of the following:
[0420] First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier;
[0421] The request message in plaintext and a second encrypted message encrypted using the user equipment's private key;
[0422] or,
[0423] The information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature;
[0424] or,
[0425] The information related to the authentication of the second subnet includes at least one of the following:
[0426] The third encrypted information is obtained by encrypting the second DID identifier using the private key of the second subnet's identity.
[0427] The request message is in plaintext and a fourth encrypted message is generated by encrypting the request message using the private key of the identity of the second subnet.
[0428] In some embodiments, the processor 143 is configured to read the computer program in the memory 141 and perform the following operations:
[0429] Based on the first DID identifier, query the blockchain network device for the identity public key of the user device;
[0430] Based on the user equipment's identity public key, the first encrypted information is decrypted to obtain the first decrypted information, and / or the second encrypted information is decrypted to obtain the second decrypted information;
[0431] The authentication result of the user equipment is determined based on the decrypted information and the plaintext information; wherein the decrypted information and the plaintext information include at least one combination of the following:
[0432] The first decryption information and the first DID identifier;
[0433] The second decryption information and the request information in plaintext.
[0434] In some embodiments, the processor 143 is configured to read the computer program in the memory 141 and perform the following operations:
[0435] If the decrypted information and the plaintext information are consistent, then the authentication result is determined to be that the user equipment is legitimate.
[0436] And / or,
[0437] If the decrypted information and the plaintext information do not meet the consistency requirement, then the authentication result is determined to be that the user equipment's identity is illegitimate.
[0438] In some embodiments, the processor 143 is configured to read the computer program in the memory 141 and perform the following operations:
[0439] The first identity public key is determined based on the third DID identifier carried in the plaintext of the verifiable claim;
[0440] Based on the first identity public key, the verifiable declaration digital signature is decrypted to obtain the third decryption information;
[0441] The authorization result of the user equipment is determined based on the third decryption information and the verifiable statement plaintext.
[0442] In some embodiments, the processor 143 is configured to read a computer program from the memory 141 and perform at least one of the following operations:
[0443] If the third DID identifier is the DID identifier corresponding to the first subnet, then the first identity public key is determined to be the identity public key of the first subnet;
[0444] If the third DID identifier is the DID identifier corresponding to the central network to which the first subnet belongs, the blockchain network device is queried for the identity public key of the central network based on the third DID identifier, and the first identity public key is determined to be the identity public key of the central network.
[0445] If the third DID identifier is the DID identifier corresponding to the third subnet associated with the first subnet, the blockchain network device is queried based on the third DID identifier to determine the identity public key of the third subnet, and the first identity public key is determined to be the identity public key of the third subnet.
[0446] In some embodiments, the processor 143 is configured to read the computer program in the memory 141 and perform the following operations:
[0447] If the third decryption information and the plaintext of the verifiable declaration are consistent, then the authorization result is determined to be authorized.
[0448] And / or,
[0449] If the third decryption information and the verifiable declaration plaintext do not meet the consistency requirement, then the authorization result is determined to be authorization failure.
[0450] In some embodiments, the processor 143 is configured to read a computer program from the memory 141 and perform at least one of the following operations:
[0451] If the identity of the user equipment is confirmed to be legitimate, a first message is sent to a third network device in the central network to which the first subnet belongs; wherein, the first message is used to request a verifiable statement for the user equipment;
[0452] Send a second message to the third network device; wherein the second message is used to request authentication of the user equipment and to provide a verifiable claim for the user equipment;
[0453] The verifiable claim is used to access at least one subnet belonging to the central network.
[0454] In some embodiments, the processor 143, for reading the computer program in the memory 141, also performs the following operations:
[0455] A third message is sent to a third network device in the central network to which the first subnet belongs; wherein the third message is used to request authentication of the user equipment;
[0456] Receive a response message from the third network device to the third message; wherein the response message is used to indicate the authentication result of the user equipment;
[0457] Based on the response message, a verifiable declaration is sent to the user equipment;
[0458] The verifiable statement is used to access the first subnet and / or to access the third subnet associated with the first subnet.
[0459] In some embodiments, the processor 143 is configured to read the computer program in the memory 141 and perform the following operations:
[0460] Based on the second DID identifier, query the identity public key of the second subnet from the blockchain network device through the proxy server;
[0461] Based on the identity public key of the second subnet, the third encrypted information is decrypted to obtain the third decrypted information, and / or the fourth encrypted information is decrypted to obtain the fourth decrypted information;
[0462] The authentication result of the second subnet is determined based on the decrypted information and the plaintext information; wherein the decrypted information and the plaintext information include at least one combination of the following:
[0463] The third decryption information and the second DID identifier;
[0464] The fourth decryption information and request information are in plaintext.
[0465] In some embodiments, the processor 143 is configured to read the computer program in the memory 141 and perform the following operations:
[0466] If the decrypted information and the plaintext information are consistent, then the authentication result is determined to be the legitimate identity of the second subnet.
[0467] And / or,
[0468] If the decrypted information and the plaintext information do not meet the consistency requirement, then the authentication result is determined to be that the identity of the second subnet is illegitimate.
[0469] In some embodiments, the processor 143, for reading the computer program in the memory 141, also performs the following operations:
[0470] Receive the DID identifier corresponding to the first subnet from the third network device of the central network to which the first subnet belongs.
[0471] In Figure 14, the bus architecture may include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors represented by processor 143 and memory represented by memory 141. The bus architecture may also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. Transceiver 142 may be multiple elements, including transmitters and receivers, providing units for communicating with various other devices over transmission media, including wireless channels, wired channels, optical fibers, etc. Processor 143 is responsible for managing the bus architecture and general processing, and memory 141 may store data used by processor 143 during operation.
[0472] In some embodiments, the processor 143 may be a central processing unit (CPU), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a complex programmable logic device (CPLD), and the processor may also adopt a multi-core architecture.
[0473] The processor executes any of the methods described in the embodiments of this disclosure by invoking a computer program stored in memory, according to the obtained executable instructions. The processor and memory may also be physically separated.
[0474] It should be noted that the apparatus provided in this embodiment can implement all the method steps implemented in the first network device side access control method embodiment and can achieve the same technical effect. Therefore, the parts and beneficial effects that are the same as those in the method embodiment will not be described in detail here.
[0475] As shown in Figure 15, this embodiment of the disclosure provides a network device 1500, applied to a first subnet, comprising:
[0476] The first receiving unit 1510 is used to receive first information or second information;
[0477] Processing unit 1520 is configured to perform authentication of user equipment based on the first information, or to perform authentication and authorization of user equipment based on the first information, or to perform authentication of second subnet based on the second information;
[0478] The first information includes one of the following:
[0479] The first decentralized identity (DID) identifier corresponding to the user equipment and the authentication-related information of the user equipment;
[0480] The first DID identifier corresponding to the user equipment, the authentication-related information of the user equipment, and the authorization-related information of the user equipment;
[0481] The second information includes the second DID identifier corresponding to the second subnet and information related to the authentication of the second subnet.
[0482] In some embodiments, the first DID identifier is configured by the central network to which the first subnet belongs, and / or the second DID identifier is configured by the central network to which the second subnet belongs.
[0483] In some embodiments, the information related to the authentication of the user equipment includes at least one of the following:
[0484] First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier;
[0485] The request message in plaintext and a second encrypted message encrypted using the user equipment's private key;
[0486] or,
[0487] The information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature;
[0488] or,
[0489] The information related to the authentication of the second subnet includes at least one of the following:
[0490] The third encrypted information is obtained by encrypting the second DID identifier using the private key of the second subnet's identity.
[0491] The request message is in plaintext and a fourth encrypted message is generated by encrypting the request message using the private key of the identity of the second subnet.
[0492] In some embodiments, the processing unit 1520 is further configured to:
[0493] Based on the first DID identifier, query the blockchain network device for the identity public key of the user device;
[0494] Based on the user equipment's identity public key, the first encrypted information is decrypted to obtain the first decrypted information, and / or the second encrypted information is decrypted to obtain the second decrypted information;
[0495] The authentication result of the user equipment is determined based on the decrypted information and the plaintext information; wherein the decrypted information and the plaintext information include at least one combination of the following:
[0496] The first decryption information and the first DID identifier;
[0497] The second decryption information and the request information in plaintext.
[0498] In some embodiments, the processing unit 1520 is further configured to:
[0499] If the decrypted information and the plaintext information are consistent, then the authentication result is determined to be that the user equipment is legitimate.
[0500] And / or,
[0501] If the decrypted information and the plaintext information do not meet the consistency requirement, then the authentication result is determined to be that the user equipment's identity is illegitimate.
[0502] In some embodiments, the processing unit 1520 is further configured to:
[0503] The first identity public key is determined based on the third DID identifier carried in the plaintext of the verifiable claim;
[0504] Based on the first identity public key, the verifiable declaration digital signature is decrypted to obtain the third decryption information;
[0505] The authorization result of the user equipment is determined based on the third decryption information and the verifiable statement plaintext.
[0506] In some embodiments, the processing unit 1520 is further configured to perform at least one of the following:
[0507] If the third DID identifier is the DID identifier corresponding to the first subnet, then the first identity public key is determined to be the identity public key of the first subnet;
[0508] If the third DID identifier is the DID identifier corresponding to the central network to which the first subnet belongs, the blockchain network device is queried for the identity public key of the central network based on the third DID identifier, and the first identity public key is determined to be the identity public key of the central network.
[0509] If the third DID identifier is the DID identifier corresponding to the third subnet associated with the first subnet, the blockchain network device is queried based on the third DID identifier to determine the identity public key of the third subnet, and the first identity public key is determined to be the identity public key of the third subnet.
[0510] In some embodiments, the processing unit 1520 is further configured to:
[0511] If the third decryption information and the plaintext of the verifiable declaration are consistent, then the authorization result is determined to be authorized.
[0512] And / or,
[0513] If the third decryption information and the verifiable declaration plaintext do not meet the consistency requirement, then the authorization result is determined to be authorization failure.
[0514] In some embodiments, the network device 1500 further includes at least one of the following:
[0515] The first sending unit is configured to send a first message to a third network device in the central network to which the first subnet belongs, after determining that the identity of the user equipment is legitimate; wherein the first message is used to request a verifiable statement for the user equipment;
[0516] The second sending unit is used for the first network device to send a second message to the third network device; wherein the second message is used to request authentication of the user equipment and to provide a verifiable claim for the user equipment;
[0517] The verifiable claim is used to access at least one subnet belonging to the central network.
[0518] In some embodiments, the network device 1500 further includes:
[0519] The third sending unit is configured to send a third message to a third network device in the central network to which the first subnet belongs; wherein the third message is used to request authentication of the user equipment;
[0520] The second receiving unit is configured to receive a response message from the third network device to the third message; wherein the response message is used to indicate the authentication result of the user equipment;
[0521] The fourth sending unit is configured to send a verifiable declaration to the user equipment based on the response message;
[0522] The verifiable statement is used to access the first subnet and / or to access the third subnet associated with the first subnet.
[0523] In some embodiments, the processing unit 1520 is further configured to:
[0524] Based on the second DID identifier, query the identity public key of the second subnet from the blockchain network device through the proxy server;
[0525] Based on the identity public key of the second subnet, the third encrypted information is decrypted to obtain the third decrypted information, and / or the fourth encrypted information is decrypted to obtain the fourth decrypted information;
[0526] The authentication result of the second subnet is determined based on the decrypted information and the plaintext information; wherein the decrypted information and the plaintext information include at least one combination of the following:
[0527] The third decryption information and the second DID identifier;
[0528] The fourth decryption information and request information are in plaintext.
[0529] In some embodiments, the processing unit 1520 is further configured to:
[0530] If the decrypted information and the plaintext information are consistent, then the authentication result is determined to be the legitimate identity of the second subnet.
[0531] And / or,
[0532] If the decrypted information and the plaintext information do not meet the consistency requirement, then the authentication result is determined to be that the identity of the second subnet is illegitimate.
[0533] In some embodiments, the network device 1500 further includes:
[0534] The third receiving unit is used to receive the DID identifier corresponding to the first subnet from the third network device of the central network to which the first subnet belongs.
[0535] It should be noted that the network device provided in this embodiment can implement all the method steps implemented in the access control method embodiment of the first network device side, and can achieve the same technical effect. Therefore, the parts and beneficial effects that are the same as those in the method embodiment will not be described in detail here.
[0536] As shown in Figure 16, this embodiment of the present disclosure provides an access control device, including a memory 161, a transceiver 162, and a processor 163; wherein, the memory 161 is used to store a computer program; the transceiver 162 is used to send and receive data under the control of the processor 163; for example, the transceiver 162 is used to receive and send data under the control of the processor 163; the processor 163 is used to read the computer program in the memory 161 and perform the following operations:
[0537] Send first information to a first network device in a first subnet; wherein the first information includes one of the following:
[0538] The first decentralized identity (DID) identifier corresponding to the user equipment and the authentication-related information of the user equipment;
[0539] The user equipment includes a first DID identifier, authentication information related to the user equipment, and authorization information related to the user equipment.
[0540] In some embodiments, the processor 163 is configured to read a computer program from the memory 161 and perform the following operations:
[0541] The first DID identifier is received from the third network device of the central network to which the first subnet belongs.
[0542] In some embodiments, the information related to the authentication of the user equipment includes at least one of the following:
[0543] First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier;
[0544] The request message in plaintext and a second encrypted message encrypted using the user equipment's private key;
[0545] or,
[0546] The information related to the authorization of the user equipment includes: the plaintext of the verifiable claim and the digital signature of the verifiable claim.
[0547] In some embodiments, the processor 163 is configured to read a computer program from the memory 161 and perform at least one of the following operations:
[0548] Receive the plaintext verifiable declaration sent by the first network device;
[0549] Receive a verifiable declaration plaintext sent by a third network device in the central network to which the first subnet belongs;
[0550] The verifiable declaration states that a plaintext user accesses at least one subnet belonging to the central network.
[0551] In Figure 16, the bus architecture may include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors represented by processor 163 and memory represented by memory 161. The bus architecture may also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. Transceiver 162 may be multiple elements, including transmitters and receivers, providing a unit for communicating with various other devices over a transmission medium, including wireless channels, wired channels, optical fibers, etc. For different user equipment, user interface 164 may also be an interface capable of connecting external or internal devices, including but not limited to keypads, displays, speakers, microphones, joysticks, etc.
[0552] Processor 163 is responsible for managing the bus architecture and general processing, while memory 161 can store the data used by processor 163 when performing operations.
[0553] The processor 163 can be a central processing unit (CPU), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or a complex programmable logic device (CPLD). The processor can also adopt a multi-core architecture.
[0554] It should be noted that the apparatus provided in this embodiment can implement all the method steps implemented in the above-mentioned user equipment-side access control method embodiment, and can achieve the same technical effect. Therefore, the parts and beneficial effects that are the same as those in the method embodiment will not be described in detail here.
[0555] As shown in Figure 17, this embodiment of the disclosure provides a user equipment 1700, including:
[0556] The sending unit 1710 is configured to send first information to a first network device in a first subnet; wherein the first information includes one of the following:
[0557] The first decentralized identity (DID) identifier corresponding to the user equipment and the authentication-related information of the user equipment;
[0558] The user equipment includes a first DID identifier, authentication information related to the user equipment, and authorization information related to the user equipment.
[0559] In some embodiments, the user equipment 1700 further includes:
[0560] The first receiving unit is configured to receive the first DID identifier sent by the third network device of the central network to which the first subnet belongs.
[0561] In some embodiments, the information related to the authentication of the user equipment includes at least one of the following:
[0562] First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier;
[0563] The request message in plaintext and a second encrypted message encrypted using the user equipment's private key;
[0564] or,
[0565] The information related to the authorization of the user equipment includes: the plaintext of the verifiable claim and the digital signature of the verifiable claim.
[0566] In some embodiments, the user equipment 1700 further includes at least one of the following:
[0567] The second receiving unit is used to receive the verifiable declaration plaintext sent by the first network device;
[0568] The third receiving unit is used to receive a verifiable declaration plaintext sent by the third network device of the central network to which the first subnet belongs;
[0569] The verifiable declaration states that a plaintext user accesses at least one subnet belonging to the central network.
[0570] It should be noted that the user equipment provided in this embodiment can implement all the method steps implemented in the above-mentioned user equipment-side access control method embodiment, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0571] As shown in Figure 18, this embodiment provides an access control device applied to a central network, including a memory 181, a transceiver 182, and a processor 183; wherein, the memory 181 is used to store computer programs; the transceiver 182 is used to send and receive data under the control of the processor 183; for example, the transceiver 182 is used to receive and send data under the control of the processor 183; the processor 183 is used to read the computer program in the memory 181 and perform the following operations:
[0572] Send the first decentralized identity (DID) identifier corresponding to the user equipment to the user equipment, and / or send the second DID identifier corresponding to the second subnet to the second network device of the second subnet;
[0573] The second subnet belongs to the central network.
[0574] In some embodiments, the information related to the authentication of the user equipment includes at least one of the following:
[0575] First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier;
[0576] The request message in plaintext and a second encrypted message encrypted using the user equipment's private key;
[0577] or,
[0578] The information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature;
[0579] or,
[0580] The information related to the authentication of the second subnet includes at least one of the following:
[0581] The third encrypted information is obtained by encrypting the second DID identifier using the private key of the second subnet's identity.
[0582] The request message is in plaintext and a fourth encrypted message is generated by encrypting the request message using the private key of the identity of the second subnet.
[0583] In some embodiments, the processor 183, for reading the computer program in the memory 181, also performs the following operations:
[0584] Receive a first message sent by a first network device in a first subnet; wherein the first message is used to request a verifiable claim to the user equipment;
[0585] Based on the user equipment's subscription information, a verifiable statement is sent to the user equipment;
[0586] The first subnet belongs to the central network, and the verifiable declaration is used to access at least one subnet belonging to the central network.
[0587] In some embodiments, the processor 183, for reading the computer program in the memory 181, also performs the following operations:
[0588] The system receives a second message from a first network device in a first subnet; wherein the second message is used to request authentication of the user equipment and to provide a verifiable claim for the user equipment.
[0589] Based on the second message, the user equipment is authenticated, and the authentication result is determined;
[0590] If the authentication result confirms that the user equipment's identity is legitimate, a verifiable declaration is sent to the user equipment based on the user equipment's subscription information.
[0591] The first subnet belongs to the central network, and the verifiable declaration is used to access at least one subnet belonging to the central network.
[0592] In some embodiments, the processor 183, for reading the computer program in the memory 181, also performs the following operations:
[0593] The system receives a third message from a first network device in a first subnet; wherein the third message is used to request authentication of the user equipment; and wherein the first subnet belongs to the central network.
[0594] Based on the third message, the user equipment is authenticated, and the authentication result is determined;
[0595] A response message to the third message is sent to the first network device; wherein the response message is used to indicate the authentication result of the user equipment.
[0596] In some embodiments, the authentication result is used to indicate whether the identity of the user equipment is legitimate, and / or, the authentication result is used to indicate whether a verifiable claim is permitted for the user equipment.
[0597] In Figure 18, the bus architecture may include any number of interconnected buses and bridges, specifically linking various circuits of one or more processors represented by processor 183 and memory represented by memory 181. The bus architecture may also link various other circuits such as peripheral devices, voltage regulators, and power management circuits, which are well known in the art and therefore will not be described further herein. The bus interface provides an interface. Transceiver 182 may be multiple elements, including transmitters and receivers, providing units for communicating with various other devices over transmission media, including wireless channels, wired channels, optical fibers, etc. Processor 183 is responsible for managing the bus architecture and general processing, and memory 181 may store data used by processor 183 during operation.
[0598] In some embodiments, the processor 183 may be a CPU, ASIC, FPGA or CPLD, and the processor may also adopt a multi-core architecture.
[0599] The processor executes any of the methods described in the embodiments of this disclosure by invoking a computer program stored in memory, according to the obtained executable instructions. The processor and memory may also be physically separated.
[0600] It should be noted that the apparatus provided in this embodiment can implement all the method steps implemented in the access control method embodiment on the third network device side, and can achieve the same technical effect. Therefore, the parts and beneficial effects that are the same as those in the method embodiment will not be described in detail here.
[0601] As shown in Figure 19, this embodiment of the disclosure provides a network device 1900, applied to a central network, including:
[0602] The first sending unit 1910 is used to send the first decentralized identity (DID) identifier corresponding to the user equipment to the user equipment, and / or send the second DID identifier corresponding to the second subnet to the second network device of the second subnet;
[0603] The second subnet belongs to the central network.
[0604] In some embodiments, the information related to the authentication of the user equipment includes at least one of the following:
[0605] First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier;
[0606] The request message in plaintext and a second encrypted message encrypted using the user equipment's private key;
[0607] or,
[0608] The information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature;
[0609] or,
[0610] The information related to the authentication of the second subnet includes at least one of the following:
[0611] The third encrypted information is obtained by encrypting the second DID identifier using the private key of the second subnet's identity.
[0612] The request message is in plaintext and a fourth encrypted message is generated by encrypting the request message using the private key of the identity of the second subnet.
[0613] In some embodiments, the network device 1900 further includes:
[0614] The first receiving unit is configured to receive a first message sent by a first network device in a first subnet; wherein the first message is configured to request a verifiable claim to the user equipment.
[0615] The second sending unit is used to send a verifiable declaration to the user equipment based on the user equipment's subscription information;
[0616] The first subnet belongs to the central network, and the verifiable declaration is used to access at least one subnet belonging to the central network.
[0617] In some embodiments, the network device 1900 further includes:
[0618] The second receiving unit is configured to receive a second message sent by a first network device in the first subnet; wherein the second message is used to request authentication of the user equipment and to provide a verifiable claim for the user equipment;
[0619] An authentication unit is configured to authenticate the user equipment based on the second message and determine the authentication result;
[0620] The third sending unit is used to send a verifiable declaration to the user equipment based on the user equipment's subscription information, provided that the authentication result indicates that the user equipment's identity is legitimate.
[0621] The first subnet belongs to the central network, and the verifiable declaration is used to access at least one subnet belonging to the central network.
[0622] In some embodiments, the network device 1900 further includes:
[0623] The third receiving unit is configured to receive a third message sent by a first network device in the first subnet; wherein the third message is used to request authentication of the user equipment; wherein the first subnet belongs to the central network;
[0624] An authentication unit is used to authenticate the user equipment based on the third message and determine the authentication result;
[0625] The fourth sending unit is configured to send a response message of the third message to the first network device; wherein the response message is used to indicate the authentication result of the user equipment.
[0626] In some embodiments, the authentication result is used to indicate whether the identity of the user equipment is legitimate, and / or, the authentication result is used to indicate whether a verifiable claim is permitted for the user equipment.
[0627] It should be noted that the network device provided in this embodiment can implement all the method steps implemented in the access control method embodiment on the third network device side, and can achieve the same technical effect. Therefore, the parts and beneficial effects that are the same as those in the method embodiment will not be described in detail here.
[0628] It should be noted that the division of units in the embodiments of this disclosure is illustrative and only represents one logical functional division. In actual implementation, other division methods may be used. Furthermore, the functional units in the various embodiments of this disclosure can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated units described above can be implemented in hardware or as software functional units.
[0629] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a processor-readable storage medium. Based on this understanding, the technical solution of this disclosure, in essence, or the part that contributes to related technologies, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) or processor to execute all or part of the steps of the methods described in the various embodiments of this disclosure. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, or optical disks.
[0630] This disclosure also provides a processor-readable storage medium storing a computer program. The computer program is used to cause the processor to execute the steps of the access control method on the first network device side, or the computer program is used to cause the processor to execute the steps of the access control method on the user equipment side, or the computer program is used to cause the processor to execute the steps of the access control method on the third network device side, and can achieve the same technical effect. Here, the parts that are the same as those in the method embodiment and the beneficial effects will not be described in detail.
[0631] This disclosure also provides a computer program product, including computer instructions, which, when executed by a processor, implement the steps of the access control method on the first network device side, or the steps of the access control method on the user equipment side, or the steps of the access control method on the third network device side, and can achieve the same technical effect. To avoid repetition, these steps will not be repeated here.
[0632] The processor-readable storage medium can be any available medium or data storage device that the processor can access, including but not limited to magnetic memory (e.g., floppy disk, hard disk, magnetic tape, magneto-optical disk (MO)), optical memory (e.g., compact disc (CD), digital video disc (DVD), Blu-ray disc (BD), high-definition versatile disc (HVD)), and semiconductor memory (e.g., ROM, erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), non-volatile memory (NAND (Non-volatile Memory Device) FLASH), solid state hard disk (SSD)).
[0633] Those skilled in the art will understand that embodiments of this disclosure can be provided as methods, systems, or computer program products. Therefore, this disclosure can take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this disclosure can take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage and optical storage) containing computer-usable program code.
[0634] This disclosure is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this disclosure. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-executable instructions. These computer-executable instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in one or more flowchart illustrations and / or one or more block diagrams.
[0635] These processor-executable instructions may also be stored in a processor-readable memory that can instruct a computer or other programmable data processing device to operate in a particular manner, such that the instructions stored in the processor-readable memory produce an article of manufacture including instruction means that implement the functions specified in one or more flowcharts and / or one or more block diagrams.
[0636] These processor-executable instructions can also be loaded onto a computer or other programmable data processing apparatus to cause a series of operational steps to be performed on the computer or other programmable apparatus to produce a computer-implemented process, such that the instructions, which execute on the computer or other programmable apparatus, provide steps for implementing the functions specified in one or more flowcharts and / or one or more block diagrams.
[0637] Furthermore, it should be noted that in the apparatus and method of this disclosure, it is obvious that the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered equivalent solutions of this disclosure. Moreover, the steps performing the above series of processes can naturally be executed in the order described, but are not necessarily required to be executed in chronological order; some steps can be executed in parallel or independently of each other. Those skilled in the art will understand that all or any step or component of the method and apparatus of this disclosure can be implemented in any computing device (including processors, storage media, etc.) or network of computing devices, in hardware, firmware, software, or a combination thereof, which can be achieved by those skilled in the art using their basic programming skills after reading the description of this disclosure.
[0638] Furthermore, it should be noted that in the apparatus and method of this disclosure, it is obvious that the components or steps can be decomposed and / or recombined. These decompositions and / or recombinations should be considered equivalent solutions of this disclosure. Moreover, the steps performing the above series of processes can naturally be executed in the order described, but are not necessarily required to be executed in chronological order; some steps can be executed in parallel or independently of each other. Those skilled in the art will understand that all or any step or component of the method and apparatus of this disclosure can be implemented in any computing device (including processors, storage media, etc.) or network of computing devices, in hardware, firmware, software, or a combination thereof, which can be achieved by those skilled in the art using their basic programming skills after reading the description of this disclosure.
[0639] It should be noted that the above division of modules is merely a logical functional division. In actual implementation, they can be fully or partially integrated into a single physical entity, or they can be physically separated. Furthermore, these modules can be implemented entirely in software via processing element calls; they can be fully implemented in hardware; or some modules can be implemented by processing element calls to software, while others are implemented in hardware. For example, a module can be a separate processing element, or it can be integrated into a chip in the aforementioned device. Alternatively, it can be stored as program code in the memory of the aforementioned device, and its function can be called and executed by a processing element of the device. The implementation of other modules is similar. Moreover, these modules can be fully or partially integrated together, or they can be implemented independently. The processing element mentioned here can be an integrated circuit with signal processing capabilities. In the implementation process, each step of the above method or each of the above modules can be completed through integrated logic circuits in the hardware of the processor element or through software instructions.
[0640] For example, each module, unit, subunit, or submodule can be one or more integrated circuits configured to implement the above methods, such as one or more application-specific integrated circuits (ASICs), one or more digital signal processors (DSPs), or one or more field-programmable gate arrays (FPGAs). As another example, when a module is implemented using processing element scheduler code, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processor capable of calling program code. Furthermore, these modules can be integrated together to implement a system-on-a-chip (SOC).
[0641] The terms "first," "second," etc., used in this disclosure and in the claims are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that embodiments of this disclosure described herein may be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus. Additionally, the use of "and / or" in the specification and claims indicates at least one of the connected objects, such as A and / or B and / or C, indicating seven possibilities: A alone, B alone, C alone, and both A and B, both B and C, both A and C, and A, B, and C. Similarly, the use of "at least one of A and B" in this specification and claims should be understood as "A alone, B alone, or both A and B."
[0642] Obviously, those skilled in the art can make various modifications and variations to this disclosure without departing from its spirit and scope. Therefore, if such modifications and variations fall within the scope of the claims of this disclosure and their equivalents, this disclosure is also intended to include such modifications and variations.
Claims
An access control method, applied to a first network device in a first subnet, the method comprising: The first network device receives the first information or the second information; The first network device performs authentication of the user equipment based on the first information, or performs authentication and authorization of the user equipment based on the first information, or performs authentication of the second subnet based on the second information; The first information includes one of the following: The first decentralized identity (DID) identifier corresponding to the user equipment and the authentication-related information of the user equipment; The first DID identifier corresponding to the user equipment, the authentication-related information of the user equipment, and the authorization-related information of the user equipment; The second information includes the second DID identifier corresponding to the second subnet and information related to the authentication of the second subnet. According to the access control method of claim 1, wherein, The first DID identifier is configured by the central network to which the first subnet belongs, and / or the second DID identifier is configured by the central network to which the second subnet belongs. According to the access control method of claim 1, wherein, The information related to the authentication of the user equipment includes at least one of the following: First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier; The request message in plaintext and a second encrypted message encrypted using the user equipment's private key; or, The information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature; or, The information related to the authentication of the second subnet includes at least one of the following: The third encrypted information is obtained by encrypting the second DID identifier using the private key of the second subnet's identity. The request message is in plaintext and a fourth encrypted message is generated by encrypting the request message using the private key of the identity of the second subnet. According to the access control method of claim 3, wherein, The first network device performs authentication of the user equipment based on the first information, including: The first network device queries the blockchain network device for the identity public key of the user device based on the first DID identifier; The first network device decrypts the first encrypted information to obtain first decrypted information based on the identity public key of the user equipment, and / or decrypts the second encrypted information to obtain second decrypted information; The first network device determines the authentication result of the user equipment based on the decryption information and the plaintext information; wherein the decryption information and the plaintext information include at least one combination of the following: The first decryption information and the first DID identifier; The second decryption information and the request information in plaintext. According to the access control method of claim 4, wherein, The first network device determines the authentication result of the user equipment based on the decrypted information and the plaintext information, including: If the decrypted information and the plaintext information are consistent, the first network device determines that the authentication result indicates that the user equipment's identity is legitimate. And / or, If the decrypted information and the plaintext information do not meet the consistency requirement, the first network device determines that the authentication result indicates that the user equipment's identity is illegitimate. According to the access control method of claim 3, wherein, The first network device performs authorization of the user equipment based on the first information, including: The first network device determines the first identity public key based on the third DID identifier carried in the verifiable claim plaintext; The first network device decrypts the verifiable declaration digital signature based on the first identity public key to obtain the third decryption information; The first network device determines the authorization result of the user equipment based on the third decryption information and the verifiable declaration plaintext. According to the access control method of claim 6, wherein, The first network device determines the identity public key based on the third DID identifier carried in the verifiable claim plaintext, including at least one of the following: If the third DID identifier is the DID identifier corresponding to the first subnet, then the first identity public key is determined to be the identity public key of the first subnet; If the third DID identifier is the DID identifier corresponding to the central network to which the first subnet belongs, the first network device queries the blockchain network device for the identity public key of the central network based on the third DID identifier, and determines that the first identity public key is the identity public key of the central network. If the third DID identifier is the DID identifier corresponding to the third subnet associated with the first subnet, the first network device queries the blockchain network device for the identity public key of the third subnet based on the third DID identifier, and determines that the first identity public key is the identity public key of the third subnet. According to the access control method of claim 6, wherein, The first network device determines the authorization result of the user equipment based on the third decryption information and the verifiable declaration plaintext, including: If the third decryption information and the plaintext of the verifiable declaration are consistent, then the first network device determines that the authorization result is authorized. And / or, If the third decryption information and the verifiable declaration plaintext do not meet the consistency requirement, the first network device determines that the authorization result is an authorization failure. The access control method according to any one of claims 1 to 8 further includes at least one of the following: Upon verifying the legitimacy of the user equipment, the first network device sends a first message to the third network device in the central network to which the first subnet belongs; wherein, The first message is used to request a verifiable claim for the user equipment; The first network device sends a second message to the third network device; wherein the second message is used to request authentication of the user equipment and to provide a verifiable claim for the user equipment; The verifiable claim is used to access at least one subnet belonging to the central network. The access control method according to any one of claims 1 to 8 further includes: The first network device sends a third message to a third network device in the central network to which the first subnet belongs; wherein the third message is used to request authentication of the user equipment; The first network device receives a response message from the third network device to the third message; wherein the response message is used to indicate the authentication result of the user equipment; The first network device sends a verifiable declaration to the user equipment based on the response message; The verifiable statement is used to access the first subnet and / or to access the third subnet associated with the first subnet. According to the access control method of claim 3, wherein, The first network device performs authentication of the second subnet based on the second information, including: The first network device queries the identity public key of the second subnet from the blockchain network device through the proxy server based on the second DID identifier; The first network device decrypts the third encrypted information to obtain the third decrypted information based on the identity public key of the second subnet, and / or decrypts the fourth encrypted information to obtain the fourth decrypted information; The first network device determines the authentication result of the second subnet based on the decryption information and the plaintext information; wherein the decryption information and the plaintext information include at least one combination of the following: The third decryption information and the second DID identifier; The fourth decryption information and request information are in plaintext. According to the access control method of claim 11, wherein, The first network device determines the authentication result of the second subnet based on the decrypted information and the plaintext information, including: If the decrypted information and the plaintext information are consistent, the first network device determines that the authentication result is valid for the identity of the second subnet. And / or, If the decrypted information and the plaintext information do not meet the consistency requirement, the first network device determines that the authentication result indicates that the identity of the second subnet is illegitimate. The access control method according to claim 11 further includes: The first network device receives the DID identifier corresponding to the first subnet from the third network device of the central network to which the first subnet belongs. An access control method, comprising: The user equipment sends first information to the first network device in the first subnet; wherein the first information includes one of the following: The first decentralized identity (DID) identifier corresponding to the user equipment and the authentication-related information of the user equipment; The user equipment includes a first DID identifier, authentication information related to the user equipment, and authorization information related to the user equipment. The access control method according to claim 14, wherein, Before the user equipment sends the first information to the first network device of the first subnet, it also includes: The user equipment receives the first DID identifier sent by the third network device of the central network to which the first subnet belongs. The access control method according to claim 14, wherein, The information related to the authentication of the user equipment includes at least one of the following: First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier; The request message in plaintext and a second encrypted message encrypted using the user equipment's private key; or, The information related to the authorization of the user equipment includes: the plaintext of the verifiable claim and the digital signature of the verifiable claim. The access control method according to any one of claims 14 to 16, wherein, It also includes at least one of the following: The user equipment receives a verifiable statement plaintext sent by the first network device; The user equipment receives a verifiable statement plaintext sent by a third network device of the central network to which the first subnet belongs; The verifiable declaration states that a plaintext user accesses at least one subnet belonging to the central network. An access control method, applied to a third network device in a central network, the method comprising: The third network device sends the first decentralized identity (DID) identifier corresponding to the user equipment to the user equipment, and / or sends the second DID identifier corresponding to the second subnet to the second network device of the second subnet; The second subnet belongs to the central network. The access control method according to claim 18, wherein, The information related to the authentication of the user equipment includes at least one of the following: First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier; The request message in plaintext and a second encrypted message encrypted using the user equipment's private key; or, The information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature; or, The information related to the authentication of the second subnet includes at least one of the following: The third encrypted information is obtained by encrypting the second DID identifier using the private key of the second subnet's identity. The request message is in plaintext and a fourth encrypted message is generated by encrypting the request message using the private key of the identity of the second subnet. The access control method according to claim 18 further includes: The third network device receives a first message sent by the first network device of the first subnet; wherein the first message is used to request a verifiable claim for the user equipment; The third network device sends a verifiable declaration to the user equipment based on the user equipment's subscription information; The first subnet belongs to the central network, and the verifiable declaration is used to access at least one subnet belonging to the central network. The access control method according to claim 18 further includes: The third network device receives a second message sent by the first network device of the first subnet; wherein the second message is used to request authentication of the user equipment and to provide a verifiable claim for the user equipment; The third network device authenticates the user equipment based on the second message and determines the authentication result; If the authentication result confirms that the user equipment's identity is legitimate, the third network device sends a verifiable declaration to the user equipment based on the user equipment's subscription information. The first subnet belongs to the central network, and the verifiable declaration is used to access at least one subnet belonging to the central network. The access control method according to claim 18 further includes: The third network device receives a third message sent by the first network device in the first subnet; wherein the third message is used to request authentication of the user equipment; wherein the first subnet belongs to the central network; The third network device authenticates the user equipment based on the third message and determines the authentication result; The third network device sends a response message to the first network device for the third message; wherein the response message is used to indicate the authentication result of the user equipment. The access control method according to claim 21 or 22, wherein, The authentication result is used to indicate whether the identity of the user equipment is legitimate, and / or, the authentication result is used to indicate whether a verifiable claim is allowed for the user equipment. An access control device for use in a first subnet, the device comprising a memory, a transceiver, and a processor; in, The memory is used to store computer programs; the transceiver is used to send and receive data under the control of the processor; the processor is used to read the computer programs from the memory and perform the following operations: Receive the first message or the second message; Authentication of the user equipment is performed based on the first information, or authentication and authorization of the user equipment are performed based on the first information, or authentication of the second subnet is performed based on the second information; The first information includes one of the following: The first decentralized identity (DID) identifier corresponding to the user equipment and the authentication-related information of the user equipment; The first DID identifier corresponding to the user equipment, the authentication-related information of the user equipment, and the authorization-related information of the user equipment; The second information includes the second DID identifier corresponding to the second subnet and information related to the authentication of the second subnet. The access control device according to claim 24, wherein, The information related to the authentication of the user equipment includes at least one of the following: First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier; The request message in plaintext and a second encrypted message encrypted using the user equipment's private key; or, The information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature; or, The information related to the authentication of the second subnet includes at least one of the following: The third encrypted information is obtained by encrypting the second DID identifier using the private key of the second subnet's identity. The request message is in plaintext and a fourth encrypted message is generated by encrypting the request message using the private key of the identity of the second subnet. The access control device according to claim 25, wherein, The processor is used to read the computer program in the memory and perform the following operations: Based on the first DID identifier, query the blockchain network device for the identity public key of the user device; Based on the user equipment's identity public key, the first encrypted information is decrypted to obtain the first decrypted information, and / or the second encrypted information is decrypted to obtain the second decrypted information; The authentication result of the user equipment is determined based on the decrypted information and the plaintext information; wherein the decrypted information and the plaintext information include at least one combination of the following: The first decryption information and the first DID identifier; The second decryption information and the request information in plaintext. The access control device according to claim 25, wherein, The processor is used to read the computer program in the memory and perform the following operations: The first identity public key is determined based on the third DID identifier carried in the plaintext of the verifiable claim; Based on the first identity public key, the verifiable declaration digital signature is decrypted to obtain the third decryption information; The authorization result of the user equipment is determined based on the third decryption information and the verifiable statement plaintext. The access control device according to claim 25, wherein, The processor is used to read the computer program in the memory and perform the following operations: Based on the second DID identifier, query the identity public key of the second subnet from the blockchain network device through the proxy server; Based on the identity public key of the second subnet, the third encrypted information is decrypted to obtain the third decrypted information, and / or the fourth encrypted information is decrypted to obtain the fourth decrypted information; The authentication result of the second subnet is determined based on the decrypted information and the plaintext information; wherein the decrypted information and the plaintext information include at least one combination of the following: The third decryption information and the second DID identifier; The fourth decryption information and request information are in plaintext. A network device, applied to a first subnet, the network device comprising: The first receiving unit is used to receive first information or second information; The processing unit is configured to perform authentication of the user equipment based on the first information, or to perform authentication and authorization of the user equipment based on the first information, or to perform authentication of the second subnet based on the second information; The first information includes one of the following: The first decentralized identity (DID) identifier corresponding to the user equipment and the authentication-related information of the user equipment; The first DID identifier corresponding to the user equipment, the authentication-related information of the user equipment, and the authorization-related information of the user equipment; The second information includes the second DID identifier corresponding to the second subnet and information related to the authentication of the second subnet. An access control device includes a memory, a transceiver, and a processor; in, The memory is used to store computer programs; the transceiver is used to send and receive data under the control of the processor; the processor is used to read the computer programs from the memory and perform the following operations: Send first information to a first network device in a first subnet; wherein the first information includes one of the following: The first decentralized identity (DID) identifier corresponding to the user equipment and the authentication information related to the user equipment; The user equipment's first DID identifier, authentication-related information, and authorization-related information. The access control device according to claim 30, wherein, The processor is used to read the computer program in the memory and perform the following operations: The first DID identifier is received from the third network device of the central network to which the first subnet belongs. The access control device according to claim 30, wherein, The information related to the authentication of the user equipment includes at least one of the following: First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier; The request message in plaintext and a second encrypted message encrypted using the user equipment's private key; or, The information related to the authorization of the user equipment includes: the plaintext of the verifiable claim and the digital signature of the verifiable claim. The access control device according to any one of claims 30 to 32, wherein, The processor is configured to read a computer program from the memory and perform at least one of the following operations: Receive the plaintext verifiable declaration sent by the first network device; Receive a verifiable declaration plaintext sent by a third network device in the central network to which the first subnet belongs; The verifiable declaration states that a plaintext user accesses at least one subnet belonging to the central network. A user equipment, comprising: The sending unit is configured to send first information to a first network device in a first subnet; wherein the first information includes one of the following: The first decentralized identity (DID) identifier corresponding to the user equipment and the authentication-related information of the user equipment; The user equipment includes a first DID identifier, authentication information related to the user equipment, and authorization information related to the user equipment. An access control device for use in a central network, the device comprising a memory, a transceiver, and a processor; in, The memory is used to store computer programs; the transceiver is used to send and receive data under the control of the processor; the processor is used to read the computer programs from the memory and perform the following operations: Send the first decentralized identity (DID) identifier corresponding to the user equipment to the user equipment, and / or send the second DID identifier corresponding to the second subnet to the second network device of the second subnet; The second subnet belongs to the central network. The access control device according to claim 35, wherein, The information related to the authentication of the user equipment includes at least one of the following: First encrypted information, which uses the user equipment's private key to encrypt the first DID identifier; The request message in plaintext and a second encrypted message encrypted using the user equipment's private key; or, The information related to the authorization of the user equipment includes: a verifiable claim plaintext and a verifiable claim digital signature; or, The information related to the authentication of the second subnet includes at least one of the following: The third encrypted information is obtained by encrypting the second DID identifier using the private key of the second subnet's identity. The request message is in plaintext and a fourth encrypted message is generated by encrypting the request message using the private key of the identity of the second subnet. According to the access control device of claim 35, the processor, when reading the computer program in the memory, further performs the following operations: Receive the first message sent by the first network device in the first subnet; wherein, The first message is used to request a verifiable claim for the user equipment; Based on the user equipment's subscription information, a verifiable statement is sent to the user equipment; The first subnet belongs to the central network, and the verifiable declaration is used to access at least one subnet belonging to the central network. According to the access control device of claim 35, the processor, when reading the computer program in the memory, further performs the following operations: Receive the second message sent by the first network device in the first subnet; wherein... The second message is used to request authentication of the user equipment and to provide a verifiable claim for the user equipment; Based on the second message, the user equipment is authenticated, and the authentication result is determined; If the authentication result confirms that the user equipment's identity is legitimate, a verifiable declaration is sent to the user equipment based on the user equipment's subscription information. The first subnet belongs to the central network, and the verifiable declaration is used to access at least one subnet belonging to the central network. According to the access control device of claim 35, the processor, when reading the computer program in the memory, further performs the following operations: Receive a third message sent by the first network device in the first subnet; wherein, The third message is used to request authentication of the user equipment; wherein, the first subnet belongs to the central network; Based on the third message, the user equipment is authenticated, and the authentication result is determined; A response message to the third message is sent to the first network device; wherein the response message is used to indicate the authentication result of the user equipment. The access control device according to claim 38 or 39, wherein, The authentication result is used to indicate whether the identity of the user equipment is legitimate, and / or, the authentication result is used to indicate whether a verifiable claim is allowed for the user equipment. A network device, applied to a central network, the network device comprising: The first sending unit is configured to send a first decentralized identity (DID) identifier corresponding to the user equipment to the user equipment, and / or send a second DID identifier corresponding to the second subnet to the second network device of the second subnet; The second subnet belongs to the central network. A processor-readable storage medium storing a computer program for causing the processor to perform the steps of the access control method according to any one of claims 1 to 23. A computer program product includes computer instructions that, when executed by a processor, implement the steps of the access control method as described in any one of claims 1 to 23.
Citation Information
Patent Citations
System and method for blockchain-based cross-entity authentication
CN111213147A
System and method for blockchain based cross entity certification
CN111316303A
Data authorization based on decentralized identifiers
CN111527489A
Decentralized authentication anchored by decentralized identifiers
CN115191103A
Identity authentication method and device in distributed network environment
CN117592023A