Zero trust-based service system access control method and apparatus, device, and medium

By combining a zero-trust security model with biometric authentication, the security issues of 5G technology in the smart manufacturing industry are solved, enabling continuous verification and access control of user identities, preventing identity theft, and ensuring the security of business systems.

WO2026085928A1PCT designated stage Publication Date: 2026-04-30GUANGDONG VOCATIONAL COLLEGE OF POST & TELECOM

Patent Information

Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-11-07
Publication Date
2026-04-30

AI Technical Summary

Technical Problem

5G technology faces numerous security challenges in the smart manufacturing industry, such as the theft of business data, illegal control of legitimate equipment, and misuse of legitimate identities, which can easily lead to unpredictable consequences at specific times.

Method used

A zero-trust-based access control method for business systems is adopted. By monitoring the continuous access of user terminals on the network side, the zero-trust security model is invoked for periodic and event-based re-authentication. Combined with biometric authentication, continuous verification of user identity and access control are ensured.

Benefits of technology

It enables continuous authentication of user identities when accessing backend business systems, preventing identity theft and phishing attacks caused by lost user terminals, ensuring the security of business data and devices, and improving network security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024130431_30042026_PF_FP_ABST
    Figure CN2024130431_30042026_PF_FP_ABST
Patent Text Reader

Abstract

The present application relates to a zero trust-based service system access control method and apparatus, a device, and a medium. The method comprises: triggering, among core network functional network elements of a network, a session management function network element or an AAA server to send a user re-authentication request to a user terminal, so that the user terminal returns current user information to the AAA server; upon the AAA server verifying that current user identity information is consistent with user identity information corresponding to a target user, determining an identity authentication success result; on the basis of the identity authentication success result and the current user identity information, the AAA server initiating a biometric authentication request to the user terminal, so that the AAA server checks whether most recent biometric information of the target user returned by the user terminal matches pre-stored biometric information of the target user, and if so, returns a biometric authentication success result to the user terminal, so as to authorize the target user to continue accessing a target service system. The present application can prevent several security issues, such as unauthorized control over authorized devices.
Need to check novelty before this filing date? Find Prior Art

Description

Zero-trust-based access control methods, devices, equipment, and media for business systems Technical Field

[0001] This application relates to the field of network security, and in particular to a zero-trust-based business system access control method, corresponding apparatus, electronic device, and computer-readable storage medium. Background Technology

[0002] Zero Trust has become a hot research and practice area in cybersecurity in recent years, primarily due to the changing security threats brought about by the dramatic changes in IT (Information Technology) infrastructure. With the trends of borderless, cloud-based, and service-oriented IT infrastructure, traditional security measures have proven ineffective, and Zero Trust offers a key to addressing these threats. The main characteristics of Zero Trust are "never trust, continuous authentication," meaning trust is relative, effective only for a short period, and requires continuous authentication to ensure user identity security and network security. The Zero Trust model fundamentally overturns traditional cybersecurity concepts, abandoning trust in the internal network and treating every user and device as a potential security threat. It assumes attackers may exist both inside and outside the network, and all access requests must undergo strict authentication and access control to protect network resources, with continuous verification and authorization to ensure network security.

[0003] Zero Trust emphasizes automated dynamic authentication, permission changes, and policy enforcement, providing a centralized way to define and enforce access control policies across distributed, heterogeneous infrastructures. It emphasizes identity-centricity and dynamic policies for access control. Therefore, implementing Zero Trust is a long-term and continuously evolving project.

[0004] On the other hand, with the advancement of "Industry 4.0," intelligent manufacturing has emerged as a new production model. The Industrial Internet, which effectively combines intelligent manufacturing processes with the Internet of Things (IoT), enables dynamic monitoring of various production stages and serves as a crucial foundational network for intelligent manufacturing. 5G (5th generation mobile communication technology), characterized by high bandwidth, low latency, and wide connectivity, offers the possibility of improving production automation and efficiency, and provides new pathways for the digitalization, networking, and intelligent development of industries. Particularly in the manufacturing sector, 5G technology is gradually becoming a core technology for the entire industry's transformation and development, providing crucial support for industrial growth. However, the specific application of 5G technology in intelligent manufacturing often faces numerous security challenges, such as the theft of business data, illegal control of legitimate equipment, and misuse of legitimate identities. These security issues can easily lead to unpredictable consequences at specific times.

[0005] In summary, given the numerous security issues that 5G technology faces in the smart manufacturing industry, such as the theft of business data, illegal control of legitimate equipment, and misuse of legitimate identities, which could easily lead to unpredictable consequences at certain times, the applicant has made corresponding explorations to address these issues.

[0006] Summary of the Invention

[0007] The purpose of this application is to solve the above-mentioned problems by providing a zero-trust-based access control method for business systems, a corresponding device, electronic equipment, and a computer-readable storage medium.

[0008] To achieve the various objectives of this application, the following technical solution is adopted:

[0009] A zero-trust-based access control method for business systems, proposed to meet one of the purposes of this application, includes:

[0010] When the network side detects that a user terminal that has passed network access authentication and business system access authentication continues to access the target business system, it calls the preset zero-trust security model and triggers the session management function network element or AAA server in the network core network function network element to send a user re-authentication request to the user terminal according to the preset access control policy, so that the user terminal returns the current user information to the AAA server. The user terminal includes one or more target users.

[0011] When the AAA server verifies that the current user's identity information matches the user's identity information corresponding to the target user, it determines that the identity authentication result is successful.

[0012] Based on the successful identity authentication result and the current user identity information, the AAA server initiates a biometric authentication request to the user terminal, so that the AAA server can detect whether the latest biometric information of the target user returned by the user terminal matches the pre-stored biometric information of the target user. If they match, the AAA server returns a successful biometric authentication result to the user terminal to authorize the target user to continue accessing the target business system.

[0013] The above steps are executed repeatedly based on the access control policy until the target user finishes accessing the target business system, thus completing the access control of the business system based on zero trust.

[0014] Optionally, the network core network functional elements include 5G core network functional elements and 6G core network functional elements, wherein the 5G core network functional elements include access and mobility management functional elements, session management functional elements, user plane functional elements, multi-access edge computing functional elements, and AAA server;

[0015] The access control policy includes periodic continuous re-authentication, event-based continuous re-authentication, and periodic and event-based continuous re-authentication. The periodic continuous re-authentication includes time-based periodic continuous user authentication, the event-based continuous re-authentication includes terminal location-based continuous user authentication and network security situation awareness-based continuous user authentication, and the periodic and event-based continuous re-authentication includes terminal location and time-based continuous user authentication.

[0016] The user identity information includes user account, user password, token or certificate;

[0017] The biometric information includes user fingerprint features, user facial features, or user iris features;

[0018] The user re-authentication request includes an EAP request.

[0019] Optionally, the step of invoking a preset zero-trust security model and triggering a session management function network element or AAA server in the network core network functional elements to send a user re-authentication request to the user terminal according to a preset access control policy, so that the user terminal returns the current user information to the AAA server, includes:

[0020] The session management function network element or the AAA server initiates the time-based periodic user identity continuous authentication, and the timer module in the session management function network element or the AAA server continuously detects whether the system access time interval of the target user reaches the preset time interval.

[0021] If the system access time interval of the target user reaches a preset time interval, the session management function network element or the AAA server sends an EAP request to the user terminal so that the user terminal returns the current user identity information to the AAA server.

[0022] Optionally, the step of invoking a preset zero-trust security model and triggering a session management function network element or AAA server in the network core network functional elements to send a user re-authentication request to the user terminal according to a preset access control policy, so that the user terminal returns the current user information to the AAA server, includes:

[0023] The session management function network element initiates continuous authentication of user identity based on terminal location. The session management function network element obtains the wireless location accessed by the target user uploaded by the access and mobility management function network element. The wireless location includes a cell, base station, or tracking area.

[0024] When the session management function network element detects that the target user has entered the re-authentication location area that requires the target user to re-authenticate, the session management function network element sends an EAP request to the user terminal so that the user terminal returns the current user identity information to the AAA server.

[0025] Optionally, after the session management function network element detects that the target user has entered the re-authentication location area requiring re-authentication, the following steps are included:

[0026] The session management function network element initiates continuous user authentication based on terminal location and time. The timer module in the session management function network element continuously detects whether the system access time interval when the target user enters the re-authentication location area reaches a preset time interval.

[0027] If this is achieved, the process continues with the session management function network element sending an EAP request to the user terminal so that the user terminal returns the current user identity information to the AAA server.

[0028] Optionally, the step of invoking a preset zero-trust security model and triggering a session management function network element or AAA server in the network core network functional elements to send a user re-authentication request to the user terminal according to a preset access control policy, so that the user terminal returns the current user information to the AAA server, includes:

[0029] The session management function network element initiates continuous user authentication based on network security situation awareness. The multi-access edge computing function network element or the user plane function network element continuously senses the network security situation of the user terminal according to the preset security situation awareness strategy. The network security situation includes abnormal user behavior, which includes abnormal login address or time, abnormal data transmission characteristics, and access restricted areas. The security situation awareness strategy includes machine learning models or user behavior analysis.

[0030] The session management function network element sends an EAP request to the user terminal based on the network security situation, so that the user terminal returns the current user identity information to the AAA server.

[0031] Optionally, based on the successful identity authentication result and the current user identity information, the AAA server initiates a biometric authentication request to the user terminal, so that the AAA server detects whether the latest biometric information of the target user returned by the user terminal matches the pre-stored biometric information of the target user. If they match, the AAA server returns a successful biometric authentication result to the user terminal to authorize the target user to continue accessing the target business system. This step includes:

[0032] Based on the successful identity authentication result and the current user identity information, the AAA server initiates a biometric authentication request to the user terminal.

[0033] The terminal re-authentication module in the user terminal calls the biometric acquisition module to collect the latest biometric information of the target user, and the AAA re-authentication module in the AAA server calls the pre-stored biometric information of the target user in the biometric storage module.

[0034] The AAA server detects whether the latest biometric information of the target user returned by the user terminal matches the pre-stored biometric information of the target user. If they match, the server returns a biometric authentication success result to the user terminal to authorize the target user to continue accessing the target business system.

[0035] A zero-trust-based business system access control device provided for another purpose of this application includes:

[0036] The re-authentication trigger module is configured to, when the network side detects that a user terminal that has passed network access authentication and business system access authentication continues to access the target business system, call the preset zero-trust security model and trigger the session management function network element or AAA server in the network core network function network element to send a user re-authentication request to the user terminal according to the preset access control policy, so that the user terminal returns the current user information to the AAA server, wherein the user terminal includes one or more target users;

[0037] The user authentication module is configured to determine a successful authentication result when the AAA server verifies that the current user's identity information matches the user's identity information corresponding to the target user.

[0038] The biometric authentication module is configured such that, based on the successful identity authentication result and the current user identity information, the AAA server initiates a biometric authentication request to the user terminal, so that the AAA server detects whether the latest biometric information of the target user returned by the user terminal matches the pre-stored biometric information of the target user. If they match, the AAA server returns a successful biometric authentication result to the user terminal to authorize the target user to continue accessing the target business system.

[0039] The access control module is configured to repeatedly execute the above steps based on the access control policy until the target user finishes accessing the target business system, thereby completing access control for the zero-trust-based business system.

[0040] An electronic device provided for another purpose of this application includes a central processing unit and a memory, the central processing unit being configured to invoke and run a computer program stored in the memory to perform the steps of the zero-trust-based business system access control method described in this application.

[0041] A computer-readable storage medium is provided for another purpose of this application, which stores, in the form of computer-readable instructions, a computer program implemented according to the zero-trust-based business system access control method, which, when invoked by a computer, executes the steps included in the corresponding method.

[0042] Compared to existing technologies, this application addresses numerous security issues faced by 5G technology in the smart manufacturing industry, such as the theft of business data, unauthorized control of legitimate equipment, and misuse of legitimate identities, which can easily lead to unpredictable consequences at specific times. This application offers benefits including, but is not limited to, the following:

[0043] This application employs a 5G re-authentication process and a zero-trust security model to continuously verify the identity of users accessing the backend business system, ensuring the security of the backend business system. During continuous user authentication, corresponding identity verification is required based on access control policies. These access control policies include re-authentication processes that can be triggered periodically or event-driven. Periodic re-authentication durations are defined as a periodic time that meets security requirements. Event-driven re-authentication triggers include re-authentication based on user terminal location and re-authentication based on network security situational awareness. For location-based re-authentication, the location can be the wireless location of the terminal, such as a cell, base station, or tracking area. Since the wireless network knows the cell, base station, or tracking area where the terminal is located, the 5G base station / access and mobility management function (AMF) network element needs to notify the session management function (SMF) network element of the terminal's location so that the session management function (SMF) network element can initiate a location-based re-authentication process. In network security situation awareness-based re-authentication, the network security situation also includes abnormal user access. That is, during the user's business process, the user plane function (UPF) network element or multi-access edge computing (MEC) function network element continuously monitors abnormal user access and network security situation, and adopts continuous intelligent risk assessment, such as based on machine learning and behavioral analysis technology, to report to the SMF in real time to assess the risk level of the user and the network, and dynamically adjust the user's access control policies and permissions to cope with constantly changing threats and environments and prevent unauthorized access.

[0044] During user re-authentication, multi-factor authentication with biometric features is used. This involves using the latest acquired user biometric features, such as fingerprints, facial features, or iris scans, to ensure the authenticity of the user's identity when accessing the business system. To enable accurate tracing in the event of a security incident, the system also records security authentication logs for each user.

[0045] Furthermore, this application enables user terminals to run not only in a relatively secure corporate intranet environment, but also in any environment, such as a home, coffee shop, or hotel. This avoids security threats such as identity theft, phishing attacks, and watering hole attacks that could result from lost user terminals. It also prevents numerous security issues in the smart manufacturing industry, such as the theft of business data, illegal control of legitimate equipment, and identity theft. Attached Figure Description

[0046] The above and / or additional aspects and advantages of this application will become apparent and readily understood from the following description of the embodiments taken in conjunction with the accompanying drawings, wherein:

[0047] Figure 1 shows an exemplary network architecture used in the 5G standard re-authentication process in this application embodiment;

[0048] Figure 2 is a schematic diagram of the 5G terminal user authentication access service in an embodiment of this application;

[0049] Figure 3 is a flowchart illustrating the zero-trust-based business system access control method in an embodiment of this application.

[0050] Figure 4 is an exemplary principle block diagram of the user terminal in an embodiment of this application;

[0051] Figure 5 is an exemplary principle block diagram of the AAA server in an embodiment of this application;

[0052] Figure 6 is an exemplary principle block diagram of the session management function network element in the embodiments of this application;

[0053] Figure 7 is an exemplary principle block diagram of the user plane function network element or the multi-access edge computing function network element in the embodiments of this application;

[0054] Figure 8 shows an exemplary network architecture in which the session management function network element initiates time-based periodic continuous user identity authentication in an embodiment of this application;

[0055] Figure 9 shows an exemplary network architecture in which the AAA server initiates time-based periodic user identity continuous authentication in an embodiment of this application;

[0056] Figure 10 shows an exemplary network architecture for continuous user authentication based on terminal location initiated by the session management function network element in this application embodiment;

[0057] Figure 11 shows an exemplary network architecture for continuous user authentication based on terminal location and time initiated by the session management function network element in this application embodiment;

[0058] Figure 12 is an exemplary network architecture for continuous user identity authentication based on network security situation awareness initiated by multiple access edge computing function network elements or user plane function network elements in this application embodiment;

[0059] Figure 13 is an exemplary principle block diagram of a zero-trust-based business system access control device in an embodiment of this application.

[0060] Figure 14 is a schematic diagram of the structure of the computer device in the embodiment of this application. Detailed Implementation

[0061] The embodiments of this application are described in detail below. Examples of these embodiments are shown in the accompanying drawings, wherein the same or similar reference numerals denote the same or similar elements or elements having the same or similar functions throughout. The embodiments described below with reference to the accompanying drawings are exemplary and are only used to explain this application, and should not be construed as limiting this application.

[0062] Unless otherwise expressly stated, the various embodiments disclosed in this application can be combined in a cross-cutting manner to flexibly construct new embodiments, as long as such combination does not depart from the inventive spirit of this application and can meet the needs of the prior art or solve a certain deficiency in the prior art. Those skilled in the art should be aware of such modifications.

[0063] The authentication and authorization process for user terminals accessing the network in the 5G standard mainly includes three parts: 5G terminal primary authentication for accessing the 5G core network, 5G terminal secondary authentication, and 5G terminal user authentication re-authentication when accessing services (the standard defaults to only one re-authentication). For details, please refer to the 3GPP TS33.501 standard document, which together provide the network access admission and access control capabilities for 5G terminals. Specifically, primary authentication ensures that only legitimate terminals can access the 5G core network, secondary authentication ensures that only legitimate users of the terminal can access the service network, and re-authentication ensures that only legitimate users of the terminal can continuously engage in service interactions, preventing unauthorized users from using the terminal for service interactions.

[0064] Please refer to Figure 1, where UE (User Equipment) is a 5G terminal, gNB is a 5G base station, and 5G core network functional elements include Access and Mobility Management Function (AMF) elements, Session Management Function (SMF) elements, User Plane Function (UPF) elements, AAA (Authentication / Authorization / Accounting) server, Authentication Server Function (AUSF) elements, Multi-Access Edge Computing (MEC) elements, etc.

[0065] The 5G standard recertification process specifically includes:

[0066] Step 11: The UE and the 5G network complete the main authentication process;

[0067] Step 12: The UE (User Equipment) completes the secondary authentication process with the AAA (Authentication / Authorization / Accounting) server and establishes business interaction with the backend business system;

[0068] Step 13: The Session Management Function (SMF) network element determines which secondary re-authentication to initiate;

[0069] Step 13a: The AAA server determines to initiate a second-order re-authentication;

[0070] Step 13b: The AAA server forwards the second re-authentication request to the Session Management Function (SMF) network element through the User Plane Function (UPF) network element. The second re-authentication request includes the user's GPSI and IP / MAC address.

[0071] Since either the Session Management Function (SMF) network element or the AAA server can initiate secondary re-authentication, it is divided into step 3 and step 3a. If the re-authentication is initiated by the Session Management Function (SMF) network element, then steps 3a and 3b are skipped; if the re-authentication is initiated by the AAA server, then steps 3a and 3b should replace step 3.

[0072] Step 14: The Session Management Function (SMF) network element sends an EAP identity request (Request / Identity) message to the UE;

[0073] Step 15: The UE responds to the EAP Fast-Reauth Identity;

[0074] Step 16: The AAA server and the UE exchange necessary authentication information (user password) via EAP request / response messages;

[0075] Step 17: The AAA server sends the re-authentication success result to the Session Management Function (SMF) network element and the User Terminal (UE) via an EAP success message.

[0076] In some embodiments, the research article "Research on Security Protection Technology for 5G-Empowered Intelligent Manufacturing" in the fourth issue of *Communications Technology* in 2024 mentions a three-layer authentication system: 5G primary authentication for accessing the 5G core network, 5G secondary authentication for accessing the enterprise intranet, and multi-user authentication for accessing specific services in scenarios where multiple users share 5G terminals. Both 5G primary and secondary authentication utilize the standard 5G primary and secondary authentication processes. Regarding network topology, 5G networks include three private network modes: standalone (SA), hybrid, and virtual private network (VPN). The main difference between these three modes lies in the degree of sharing between the wireless network and the core network. This research primarily enhances the security protection technology for enterprise private networks under standalone (SA) architecture. In scenarios where multiple users share 5G terminals, and after deploying an identity authentication system, users must be authenticated before being allowed to access specific services.

[0077] After 5G terminals are authenticated and authorized for network access, in scenarios where multiple people share 5G terminals, it is still necessary to deploy an identity authentication system to authenticate the identity of users of the terminal before allowing them to access specific services.

[0078] Please refer to Figure 2 for the 5G terminal user authentication access service. The specific operation process includes:

[0079] Step 21: The user clicks the identity authentication app to initiate the authentication process;

[0080] Step 22: The identity authentication app initiates certificate authentication with the identity authentication system. After verifying the identity's legitimacy, the identity authentication system returns an identity token.

[0081] Step 23: The user clicks on the application App and initiates a single sign-on process through the application App. The application App requests the code corresponding to the application from the identity authentication App. The identity authentication App carries the obtained token information and requests the code from the identity authentication system.

[0082] Step 24: After the identity authentication system verifies the validity of the token, it generates an encoding and returns it to the identity authentication App. The identity authentication App returns the encoding to the application App for single sign-on. The application App then transmits the encoding to the application system.

[0083] Steps 25 to 26: The application system sends a code to the identity authentication system to request access to the ticket information. The latter verifies the legality of the ticket and then returns the user information.

[0084] Step 27: Single sign-on is successful, and you can access the backend business system.

[0085] Based on the above exemplary scenarios, please refer to Figure 3. In one embodiment of the zero-trust-based business system access control method of this application, the method includes:

[0086] Step S10: When the network side detects that a user terminal that has passed network access authentication and business system access authentication continues to access the target business system, it calls the preset zero-trust security model and triggers the session management function network element or AAA server in the network core network function network element to send a user re-authentication request to the user terminal according to the preset access control policy, so that the user terminal returns the current user information to the AAA server, wherein the user terminal includes one or more target users.

[0087] Specifically, a user terminal refers to an industrial terminal device used by a target user that requires zero-trust authentication. The target user can access a protected target business system through the user terminal. This target business system contains protected internal production resources, which typically refer to operational resources controlled and owned by the enterprise or factory, usually accessible only to internal personnel. For example, factory internal resources are only accessible to the factory's management and production staff. With the introduction of the zero-trust security concept, internal resources that were previously only accessible within the enterprise's intranet can now be accessed by internal personnel from any location. Therefore, user terminals no longer operate in a relatively secure enterprise intranet environment but can potentially operate in any environment, such as a home, a coffee shop, or a hotel. In these environments, the loss of user terminals greatly increases the security threats such as identity theft, phishing attacks, and watering hole attacks that target users may suffer. Therefore, when a target user initiates a service access request through a user terminal, if the network detects that the user terminal, which has passed 5G access authentication and business system access authentication, continues to access the target business system, it calls the preset zero-trust security model and, according to the preset access control policy, triggers the session management function network element or AAA server in the network core network function element to send a user re-authentication request to the user terminal, i.e., identity authentication.

[0088] In some embodiments, the network includes 5G networks, 6G networks, and future networks, etc., and the core network functional elements include 5G core network functional elements, 6G core network functional elements, etc. This application uses a 5G network as an example, which does not constitute a limitation on this application. The 5G core network functional elements include access and mobility management functional elements, session management functional elements, user plane functional elements, multi-access edge computing functional elements, and AAA servers; the access control policies include periodic continuous re-authentication, event-based continuous re-authentication, and periodic and event-based continuous re-authentication, wherein the periodic continuous re-authentication includes time-based periodic continuous user identity authentication, the event-based continuous re-authentication includes but is not limited to continuous user identity authentication based on terminal location and continuous user identity authentication based on network security situation awareness, and the periodic and event-based continuous re-authentication includes but is not limited to continuous user identity authentication based on terminal location and time; the user identity information includes but is not limited to user account, user password, token, or certificate; the biometric information includes but is not limited to user fingerprint features, user facial features, or user iris features; the user re-authentication request includes but is not limited to EAP requests.

[0089] The core characteristics of zero trust are "never trust, continuous authentication," meaning that trust is relative, valid only for a short period, and requires continuous authentication to ensure user identity security and network security. The zero trust model fundamentally overturns traditional network security concepts. It no longer trusts the internal network but treats every user and device as a potential security threat. It assumes attackers may exist both inside and outside the network, and all access requests must undergo strict authentication and access control to protect network resources, with continuous verification and authorization to guarantee network security.

[0090] As mentioned above, the target user has already accessed the 5G core network through primary authentication and can access the back-end business system through secondary authentication. In order to ensure the security of accessing the back-end business system and the legitimacy of the user's identity, it is necessary to use zero-trust technology to continuously verify the user's identity. By utilizing the 5G re-authentication process, the identity of the user accessing the back-end business system can be continuously verified, thereby maximizing the security of the back-end business system.

[0091] When continuously verifying user identity, authentication must be performed based on preset access control policies. These policies include periodic continuous re-authentication or event-based continuous re-authentication, where the duration of periodic continuous re-authentication is a periodic time that meets security requirements. A timer module can be configured in the Session Management Function (SMF) network element or AAA server. Specifically, timer parameters for business re-authentication are configured in the SMF or AAA server. When a user accesses the business system, the SMF or AAA server starts the timer. When the timer expires, the re-authentication process begins, and the timer is reset for the next re-authentication process. This cycle repeats until the access to the backend business system terminates, at which point the timer is released.

[0092] Event-driven continuous re-authentication triggering conditions include, but are not limited to, re-authentication based on user terminal location and re-authentication based on network security situation awareness. For re-authentication based on terminal location, the location can be the wireless location of the terminal, such as a cell, base station, or tracking area. Since the wireless network knows the cell, base station, or tracking area where the user terminal is located, the 5G base station or Access and Mobility Management Function (AMF) network element needs to cooperate in informing the Session Management Function (SMF) network element of the changed location of the user terminal so as to trigger the Session Management Function (SMF) network element to initiate a re-authentication process for the user terminal.

[0093] Furthermore, in continuous re-authentication based on user terminal location, security can be enhanced by combining it with time. That is, the first re-authentication is triggered when the user terminal enters the set wireless location. If the user terminal remains in the wireless location, a timer is started to enter the periodic continuous re-authentication process.

[0094] In network security situational awareness-based re-authentication, network security situational awareness also includes abnormal user access. This means that network elements continuously monitoring abnormal user access and network security situation during user transactions include, but are not limited to, User Plane Function (UPF) network elements or Multi-access Edge Computing (MEC) network elements. These UPF or MEC network elements can employ continuous user behavior analysis technology for risk assessment, or they can use machine learning-based artificial intelligence technology for continuous risk assessment. This allows for real-time evaluation of the risk level of users and the network, timely triggering of continuous re-authentication processes, and dynamic adjustment of user access control policies and permissions to address constantly changing threats and environments and prevent unauthorized access. UPF or MEC network elements need to have built-in network security situational awareness capabilities, be able to diagnose abnormal user access, and report this information in real-time to the Session Management Function (SMF) network element to trigger the user identity re-authentication process.

[0095] In the user re-authentication process, multi-factor authentication user identity information and the latest acquired biometric features, such as fingerprint, facial, or iris features, are used to ensure the authenticity of the user's identity for continuous access to the business system. In this application, the target user has already stored their biometric data on the AAA server. Therefore, configuring a biometric feature acquisition module in the user terminal can extract the target user's fingerprint, facial, or iris features, and interact with the re-authentication process through an interface to provide the latest acquired biometric features, preventing the user terminal and identity from being stolen.

[0096] In some embodiments, the access control policy includes, but is not limited to: time-based periodic continuous user authentication, terminal location-based continuous user authentication, terminal location and time-based continuous user authentication, and network security situation awareness-based continuous user authentication; the user identity information includes, but is not limited to, user account, user password, token, authentication credential or certificate; the biometric information includes, but is not limited to, user fingerprint features, user facial features or user iris features.

[0097] In some embodiments, please refer to Figure 4. The user terminal includes a biometric feature acquisition module and a terminal re-authentication module. The biometric feature acquisition module is used to collect the user's biometric feature information. The terminal re-authentication module is used to respond to the re-authentication request of the AAA server or the Session Management Function (SMF) network element, and interact with the biometric feature acquisition module to obtain biometric feature information for re-authentication. Specifically, the terminal re-authentication module has the function of supporting continuous re-authentication of the AAA server. It does not have an authentication function, but only the function of cooperating with the AAA server to complete the re-authentication.

[0098] Please refer to Figure 5. The AAA server includes a first authentication timer module, an AAA re-authentication module, a biometric storage module, and a first security authentication log module. The first authentication timer module is used to continuously detect whether the system access time interval of the target user reaches a preset time interval to initiate time-based re-authentication. The AAA re-authentication module is used to verify the user's identity and biometric features. The biometric storage module is used to store the user's biometric information. The first security authentication log module is used to record the security authentication log information of each user.

[0099] Please refer to Figure 6. The Session Management Function (SMF) network element includes a security policy module, a re-authentication location module, a second re-authentication timer module, and a second security authentication log module. The security policy module is used to initiate re-authentication based on network security status, time, and / or location. The re-authentication location module is used to detect whether the wireless location of the user terminal has changed to initiate location-based re-authentication. The second re-authentication timer module is used to continuously detect whether the system access duration interval of the target user has reached a preset time interval to initiate time-based re-authentication. The second security authentication log module is used to record the security authentication log information of each user.

[0100] Please refer to Figure 7. The User Plane Function (UPF) network element or Multi-access Edge Computing (MEC) function network element includes a security situation awareness module and a security situation notification module. The security situation awareness module is used to sense and detect the network security situation to determine the network situation detection result. The network security situation includes abnormal user behavior. The security situation notification module is used to notify the Session Management Function (SMF) network element of the network situation detection result for re-authentication.

[0101] Step S20: When the AAA server verifies that the current user's identity information matches the user's identity information corresponding to the target user, it determines that the identity authentication is successful.

[0102] According to the preset access control policy, the session management function network element or AAA server in the core network function network element sends a user re-authentication request to the user terminal. After the user terminal returns the current user information to the AAA server, the AAA server verifies that the current user identity information is consistent with the user identity information corresponding to the target user, and then determines the identity authentication success result and the current user identity information.

[0103] Step S30: Based on the successful identity authentication result and the current user identity information, the AAA server initiates a biometric authentication request to the user terminal, so that the AAA server detects whether the latest biometric information of the target user returned by the user terminal matches the pre-stored biometric information of the target user. If they match, the AAA server returns a successful biometric authentication result to the user terminal to authorize the target user to continue accessing the target business system.

[0104] When the AAA server verifies that the current user's identity information matches the user's identity information corresponding to the target user, after determining a successful authentication result, based on the successful authentication result and the current user's identity information, the AAA server initiates a multi-factor authentication biometric authentication request to the user terminal. This allows the AAA server to detect whether the latest biometric information of the target user returned by the user terminal matches the target user's pre-stored biometric information. If they match, the AAA server returns a successful biometric authentication result to the user terminal to authorize the target user to continue accessing the target business system.

[0105] Specifically, based on the successful identity authentication result and the current user identity information, the AAA server initiates a biometric authentication request to the user terminal. This allows the AAA server to detect whether the latest biometric information of the target user returned by the user terminal matches the target user's pre-stored biometric information. If a match is found, a successful biometric authentication result is returned to the user terminal to authorize the target user to continue accessing the target business system. The steps include:

[0106] Step S301: Based on the successful identity authentication result and the current user identity information, the AAA server initiates a biometric authentication request to the user terminal;

[0107] Step S302: The terminal re-authentication module in the user terminal calls the biometric acquisition module to collect the latest biometric information of the target user, and the AAA re-authentication module in the AAA server calls the pre-stored biometric information of the target user in the biometric storage module.

[0108] Step S303: The AAA server detects whether the latest biometric information of the target user returned by the user terminal matches the pre-stored biometric information of the target user. If they match, the server returns a biometric authentication success result to the user terminal to authorize the target user to continue accessing the target business system.

[0109] More specifically, based on the successful authentication result and the current user's identity information, the AAA server initiates a biometric authentication request, requesting the target user's biometric information. This biometric information can be the user's fingerprint, facial features, or iris features, determined by the Vendor-Type in the extended type. The Vendor-Type can be set according to the provided biometric features; for example, fingerprint features could be set to 261, facial features to 262, and iris features to 263. The terminal re-authentication module in the user terminal collects the corresponding biometric information by calling the biometric acquisition module and sends it to the AAA server for verification via the extended data packet format of the EAP response message. The AAA server, through the re-authentication module, calls the target user's pre-stored biometric information in the biometric storage module and compares it with the target user's latest biometric information. If a match is found, a successful biometric authentication result is returned, and a successful biometric authentication message is sent to the user terminal, allowing the user terminal to continue accessing the backend business system. If no match is found, a failure message is returned to the user terminal, and the Session Management Function (SMF) network element is notified to initiate the 5G standard PDN session release process.

[0110] In some embodiments, the camera in the user terminal can directly collect the target user's facial features or iris features to push the latest biometric information of the target user, such as facial features or iris features, to the AAA server for biometric authentication. The AAA server calls the target user's pre-stored biometric information in the biometric storage module through the re-authentication module and compares it with the target user's latest biometric information. If they match, a biometric authentication success result is returned, and a biometric authentication success message is sent to the user terminal, allowing the user terminal to continue accessing the backend business system. If they do not match, a failure message is returned to the user terminal, and the Session Management Function (SMF) network element is notified to initiate a 5G standard PDN session release process to terminate the target user's access to the target business system.

[0111] Step S40: Execute the above steps repeatedly based on the access control policy until the target user finishes accessing the target business system, thereby completing access control for the zero-trust business system.

[0112] To prevent user identity theft and potential security threats such as phishing and watering hole attacks from lost user terminals, access control policies such as time-based periodic user identity authentication, terminal location-based user identity authentication, network security situation awareness-based user identity authentication, and terminal location and time-based user identity authentication are repeatedly executed when a user terminal that has passed 5G access authentication and business system access authentication continues to access the target business system, until the target user's access to the target business system ends, thus completing access control of the business system based on zero trust.

[0113] Based on any of the above embodiments, the step of invoking a preset zero-trust security model and triggering a session management function network element or AAA server in the network core network functional elements to send a user re-authentication request to the user terminal according to a preset access control policy, so that the user terminal returns the current user information to the AAA server, includes:

[0114] Step S101: The session management function network element or the AAA server initiates the time-based periodic user identity continuous authentication. The timer module in the session management function network element or the AAA server continuously detects whether the system access time interval of the target user reaches the preset time interval.

[0115] Step S102: If the system access time interval of the target user reaches a preset time interval, the session management function network element or the AAA server sends an EAP request to the user terminal so that the user terminal returns the current user identity information to the AAA server.

[0116] Specifically, please refer to Figure 8. The Session Management Function (SMF) network element initiates time-based periodic continuous authentication of user identity, and its specific process includes:

[0117] Step 31: When the second authentication timer module built into the Session Management Function (SMF) network element reaches the preset time interval when the target user continuously accesses the backend business system, the re-authentication process of the target user is initiated.

[0118] Step 32: The Session Management Function (SMF) network element sends an EAP request to the User Terminal (UE) to request user identity, so that the user terminal returns the current user identity information;

[0119] Step 33: The terminal re-authentication module in the user terminal responds with the fast re-authentication identity (current user identity information) to the AAA server. When the AAA server verifies that the current user identity information is consistent with the user identity information corresponding to the target user, it determines that the identity authentication result is successful.

[0120] Step 34: Based on the successful identity authentication result and the current user identity information, the AAA server initiates a biometric authentication request, that is, requests the biometric information of the target user. The biometric information may be the user's fingerprint features, user's facial features, or user's iris features, etc., which is determined by the Vendor-Type in the extended type.

[0121] Step 35: The terminal re-authentication module in the user terminal collects the corresponding biometric information by calling the biometric collection module, and sends the corresponding biometric information to the AAA server for verification by carrying the corresponding biometric information in the extended data packet format of the EAP response message.

[0122] In some embodiments, the terminal re-authentication module in the user terminal collects the corresponding biometric information by calling the biometric collection module, and sends the corresponding biometric information, as well as the current user information such as user account, user password, token or certificate, to the AAA server for verification through the extended data packet format of the EAP response message, so as to perform multi-factor authentication.

[0123] Step 36: The AAA re-authentication module in the AAA server calls the pre-stored biometric information of the target user in the biometric storage module and compares it with the latest biometric information of the target user. If they are the same, the authentication is successful and a biometric authentication success message is sent to the terminal, and the user terminal can continue to access the backend business system. If they are different, a failure message is returned to the user terminal and the Session Management Function (SMF) network element is notified to initiate the 5G standard PDN session release process.

[0124] Step 37: The AAA server continuously initiates periodic re-authentication when the timer expires, based on the built-in timer parameters, repeating steps 32 to 36.

[0125] In some embodiments, as shown in Figure 9, the AAA server initiates time-based periodic continuous user authentication, the specific process of which includes:

[0126] Step 41: When the re-authentication timer set by the first-level authentication timer module built into the AAA server expires during continuous access to the backend business system by the 5G target user, the user's re-authentication process is initiated.

[0127] Step 42: The AAA server sends an EAP request to the user terminal (UE) to request the current user identity information, so that the user terminal returns the current user identity information;

[0128] Step 43: The terminal re-authentication module in the user terminal responds with the fast re-authentication identity (current user identity information) to the AAA server. When the AAA server verifies that the current user identity information is consistent with the user identity information corresponding to the target user, it determines that the identity authentication result is successful.

[0129] Step 44: Based on the successful identity authentication result and the current user identity information, the AAA server initiates a biometric authentication request, that is, requests the biometric information of the target user. The biometric information may be the user's fingerprint features, user's facial features, or user's iris features, etc., which is determined by the Vendor-Type in the extended type.

[0130] Step 45: The terminal re-authentication module in the user terminal collects the corresponding biometric information by calling the biometric collection module, and sends the corresponding biometric information to the AAA server for verification by carrying the corresponding biometric information in the extended data packet format of the EAP response message.

[0131] Step 46: The AAA re-authentication module in the AAA server calls the pre-stored biometric information of the target user in the biometric storage module and compares it with the latest biometric information of the target user. If they are the same, the authentication is successful and a biometric authentication success message is sent to the terminal, and the user terminal can continue to access the backend business system. If they are different, a failure message is returned to the user terminal and the Session Management Function (SMF) network element is notified to initiate the 5G standard PDN session release process.

[0132] Step 47: The AAA server continuously initiates periodic re-authentication when the timer expires, based on the built-in timer parameters, repeating steps 42 to 46.

[0133] Based on any of the above embodiments, the step of invoking a preset zero-trust security model and triggering a session management function network element or AAA server in the network core network functional elements to send a user re-authentication request to the user terminal according to a preset access control policy, so that the user terminal returns the current user information to the AAA server, includes:

[0134] Step S1001: The session management function network element initiates continuous authentication of user identity based on terminal location. The session management function network element obtains the wireless location of the target user accessed by the access and mobility management function network element. The wireless location includes a cell, base station or tracking area.

[0135] Step S1002: When the session management function network element detects that the target user has entered the re-authentication location area that requires the target user to re-authenticate, the session management function network element sends an EAP request to the user terminal so that the user terminal returns the current user identity information to the AAA server.

[0136] Specifically, please refer to Figure 10. The session management function network element initiates continuous user authentication based on terminal location, and its specific process includes:

[0137] Step 50: If location re-authentication is cell-based, the 5G base station (gNB) needs to report it to the Access and Mobility Management Function (AMF) network element.

[0138] Step 51: The Access and Mobility Management Function (AMF) network element can report location information to the Session Management Function (SMF) network element. That is, when the cell, base station, or Tracking Area (TA) accessed by the user changes, it needs to be reported to the Session Management Function (SMF) network element.

[0139] Step 52: When the re-authentication location module built into the Session Management Function (SMF) network element detects that the target user has entered the location area that requires re-authentication while the target user is continuously accessing the backend business system, it initiates the user's re-authentication process.

[0140] Step 53: The Session Management Function (SMF) network element sends an EAP request to the User Terminal (UE) to request the current user identity information. The subsequent message flow is the same as steps 32 to 36 in the above embodiment, and will not be described in detail here.

[0141] Step 54: The re-authentication location module built into the Session Management Function (SMF) network element continuously monitors the location of the user terminal and detects whether it has entered a new re-authentication location area so as to continue triggering the re-authentication process.

[0142] Based on any of the above embodiments, after the session management function network element detects that the target user has entered the re-authentication location area requiring re-authentication, the steps include:

[0143] Step S10021: The session management function network element initiates continuous user identity authentication based on terminal location and time. The timer module in the session management function network element continuously detects whether the system access time interval when the target user enters the re-authentication location area reaches a preset time interval.

[0144] Step S10022: If the condition is met, continue executing the steps following the process where the session management function network element sends an EAP request to the user terminal so that the user terminal returns the current user identity information to the AAA server.

[0145] Specifically, please refer to Figure 11. The session management function network element initiates continuous user authentication based on terminal location and time. The specific process includes:

[0146] Step 60: If location re-authentication is cell-based, the 5G base station (gNB) needs to report the Access and Mobility Management Function (AMF) network element.

[0147] Step 61: The Access and Mobility Management Function (AMF) network element is configured to report location information to the Session Management Function (SMF) network element. That is, when the cell, base station, or Tracking Area (TA) accessed by the user changes, it needs to be reported to the Session Management Function (SMF) network element.

[0148] Step 62: When the re-authentication location module built into the Session Management Function (SMF) network element detects that the target user has entered the location area that requires re-authentication while the target user is continuously accessing the backend business system, it initiates the re-authentication process for the target user.

[0149] Step 63: The Session Management Function (SMF) network element requests identity from the User Terminal (UE) through the EAP request message. The subsequent message flow is the same as the re-authentication process in steps 32 to 36 of the above embodiment.

[0150] Step 64: When a user stays in a location area where a re-authentication process has already been initiated for an extended period of time, in order to enhance user security, as mentioned above, the Session Management Function (SMF) network element is also configured with a second authentication timer module. Therefore, when a user enters the location-based re-authentication process, the second authentication timer module is activated. Once the second authentication timer module reaches the preset time interval, the Session Management Function (SMF) network element triggers the re-authentication process.

[0151] Step 65: The subsequent process is to continuously repeat the re-authentication process of steps 32 to 36 in the above embodiments; in addition, when the user enters a new re-authentication location area, the re-authentication process of steps 51 to 54 in the above embodiments will be triggered again.

[0152] Based on any of the above embodiments, the step of invoking a preset zero-trust security model and triggering a session management function network element or AAA server in the network core network functional elements to send a user re-authentication request to the user terminal according to a preset access control policy, so that the user terminal returns the current user information to the AAA server, includes:

[0153] Step S100: The session management function network element initiates continuous user authentication based on network security situation awareness. The multi-access edge computing function network element or the user plane function network element continuously senses the network security situation of the user terminal according to a preset security situation awareness strategy. The network security situation includes abnormal user behavior, which includes abnormal login address or time, abnormal data transmission characteristics, and access-restricted areas. The security situation awareness strategy includes machine learning models or user behavior analysis.

[0154] Step S200: The session management function network element sends an EAP request to the user terminal based on the network security situation, so that the user terminal returns the current user identity information to the AAA server.

[0155] In some embodiments, please refer to Figure 12. The multi-access edge computing (MEC) functional network element continuously authenticates the user's identity based on abnormal user behavior or network security situation awareness. The specific process includes:

[0156] Step 71: When the Multi-Access Edge Computing (MEC) functional network element has a built-in security situation awareness module, the Multi-Access Edge Computing (MEC) functional network element continuously senses the network security situation. It can use machine learning models or user behavior analysis and other technologies. The network security situation includes abnormal user behavior, which includes abnormal login address or time, abnormal data transmission characteristics, and access restricted areas.

[0157] Step 72: If the Multi-access Edge Computing (MEC) function network element continuously senses the network security situation, the Multi-access Edge Computing (MEC) function network element notifies the Session Management Function (SMF) network element in real time to inform it of the network security situation.

[0158] Step 73: The security policy module of the Session Management Function (SMF) network element presets the access control policy and network security status, and initiates the user re-authentication process in a timely manner.

[0159] Step 74: Adopt the re-authentication process of steps 32 to 36 in the above embodiment; and continue the re-authentication process of steps 71 to 73 in this embodiment.

[0160] In some embodiments, the User Plane Function (UPF) network element performs continuous user authentication based on network security situation awareness. The specific process includes:

[0161] Step 71a: When the User Plane Function (UPF) network element has a built-in security situation awareness module, the User Plane Function (UPF) network element continuously senses the network security situation. It can use machine learning models or user behavior analysis and other technologies. The network security situation includes abnormal user behavior, which includes abnormal login location or time, abnormal data transmission volume or frequency, and access restricted areas.

[0162] Step 72a: If the User Plane Function (UPF) network element continuously senses the network security situation, the User Plane Function (UPF) network element notifies the Session Management Function (SMF) network element in real time to inform it of the network security situation.

[0163] Step 73a: The security policy module of the Session Management Function (SMF) network element initiates the user re-authentication process in a timely manner based on the preset access control policy and network security situation.

[0164] Step 74a: Adopt the re-authentication process of steps 32 to 36 in the above embodiment, and continue to perform the process of steps 71a to 73a in this embodiment.

[0165] In the above embodiments, both the SMF and AAA servers will activate the security authentication log module to record re-authentication logs, so as to accurately trace the security problem when a security incident occurs.

[0166] As can be seen from the above embodiments, compared with the prior art, this application addresses the numerous security problems faced by 5G technology in the smart manufacturing industry, such as the theft of business data, illegal control of legitimate equipment, and misuse of legitimate identities, which can easily lead to unpredictable consequences at specific times. This application includes, but is not limited to, the following beneficial effects:

[0167] This application employs a 5G re-authentication process and a zero-trust security model to continuously verify the identity of users accessing the backend business system, ensuring the security of the backend business system. During continuous user authentication, corresponding identity verification is required based on access control policies. These access control policies include re-authentication processes that can be triggered periodically or event-driven. Periodic re-authentication durations are defined as a periodic time that meets security requirements. Event-driven re-authentication triggers include re-authentication based on user terminal location and re-authentication based on network security situational awareness. For location-based re-authentication, the location can be the wireless environment area where the terminal is located, such as a cell, base station, or tracking area. Since the wireless network knows the cell, base station, or tracking area where the terminal is located, the 5G base station / access and mobility management function (AMF) network element needs to notify the session management function (SMF) network element of the terminal's location so that the session management function (SMF) network element can initiate a location-based re-authentication process. In network security situation awareness-based re-authentication, the network security situation also includes abnormal user access. That is, during the user's business process, the user plane function (UPF) network element or multi-access edge computing (MEC) function network element continuously monitors abnormal user access and network security situation, and adopts continuous intelligent risk assessment, such as based on machine learning and behavioral analysis technology, to report to the SMF in real time to assess the risk level of the user and the network, and dynamically adjust the user's access control policies and permissions to cope with constantly changing threats and environments and prevent unauthorized access.

[0168] During user re-authentication, biometric authentication is used, employing the latest acquired user biometric features such as fingerprints, facial features, or iris scans to ensure the authenticity of the user's identity when accessing the business system. To enable accurate tracing in the event of a security incident, the system also records security authentication logs for each user.

[0169] Furthermore, this application enables user terminals to run not only in a relatively secure corporate intranet environment, but also in any environment, such as a home, coffee shop, or hotel. This avoids security threats such as identity theft, phishing attacks, and watering hole attacks that could result from lost user terminals. It also prevents numerous security issues in the smart manufacturing industry, such as the theft of business data, illegal control of legitimate equipment, and identity theft.

[0170] In some embodiments, referring to Figure 13, a zero-trust-based business system access control device provided for one of the purposes of this application includes a re-authentication triggering module 1100, a user authentication module 1200, a biometric authentication module 1300, and an access control module 1400. The re-authentication triggering module 1100 is configured to, when the network side detects that a user terminal that has passed network access authentication and business system access authentication continues to access the target business system, invoke a preset zero-trust security model and, according to a preset access control policy, trigger a session management function network element or an AAA server in the network core network functional element to send a user re-authentication request to the user terminal, so that the user terminal returns the current user information to the AAA server, wherein the user terminal includes one or more target users; the user authentication module 1200 is configured to, when the AAA server verifies that the current user identity information matches the user identity information corresponding to the target user, determine a successful authentication result; the biometric authentication module 1300... The biometric authentication module 1300 is configured to, based on the successful identity authentication result and the current user identity information, initiate a biometric authentication request to the user terminal, so that the AAA server detects whether the latest biometric information of the target user returned by the user terminal matches the pre-stored biometric information of the target user. If they match, the AAA server returns a successful biometric authentication result to the user terminal to authorize the target user to continue accessing the target business system. The access control module 1400 is configured to execute the above steps in a loop based on the access control policy until the target user's access to the target business system ends, so as to complete the access control of the zero-trust business system.

[0171] In some embodiments, based on any embodiment of this application and referring to FIG14, another embodiment of this application also provides an electronic device, which can be implemented by a computer device. FIG14 shows a schematic diagram of the internal structure of the computer device. The computer device includes a processor, a computer-readable storage medium, a memory, and a network interface connected via a system bus. The computer-readable storage medium of the computer device stores an operating system, a database, and computer-readable instructions. The database may store a sequence of control information. When the computer-readable instructions are executed by the processor, the processor can implement a zero-trust-based business system access control method. The processor of the computer device provides computing and control capabilities to support the operation of the entire computer device. The memory of the computer device may store computer-readable instructions. When the computer-readable instructions are executed by the processor, the processor can execute the zero-trust-based business system access control method of this application. The network interface of the computer device is used for communication with a terminal. Those skilled in the art will understand that the structure shown in FIG14 is merely a block diagram of a portion of the structure related to the solution of this application and does not constitute a limitation on the computer device to which the solution of this application is applied. A specific computer device may include more or fewer components than shown in the figure, or combine certain components, or have different component arrangements.

[0172] In some embodiments, the processor in this embodiment is used to execute the specific functions of each module in FIG13, and the memory stores the program code and various types of data required to execute the above modules. The network interface is used for data transmission between the user terminal or the server. In this embodiment, the memory stores the program code and data required to execute all modules in the zero-trust-based business system access control device of this application, and the server can call the server's program code and data to execute the functions of all sub-modules.

[0173] In some embodiments, this application also provides a storage medium storing computer-readable instructions, which, when executed by one or more processors, cause the one or more processors to perform the steps of the zero-trust-based business system access control method described in any embodiment of this application.

[0174] In some embodiments, this application also provides a computer program product, including a computer program / instructions that, when executed by one or more processors, implement the steps of the zero-trust-based business system access control method described in any embodiment of this application.

[0175] Those skilled in the art will understand that all or part of the processes in the methods of the above embodiments of this application can be implemented by a computer program instructing related hardware. This computer program can be stored in a computer-readable storage medium, and when executed, it can include the processes of the embodiments of the methods described above. The aforementioned storage medium can be a magnetic disk, optical disk, read-only memory (ROM), or random access memory (RAM), etc.

[0176] The above description is only a partial embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.

[0177] In summary, this application enables user terminals to run not only in a relatively secure corporate intranet environment, but also potentially in any environment, such as a home, coffee shop, or hotel. This avoids security threats such as identity theft, phishing attacks, and watering hole attacks that could result from lost user terminals. It also prevents numerous security issues in the smart manufacturing industry, such as the theft of business data, illegal control of legitimate equipment, and identity theft.

Claims

1. A zero-trust-based access control method for business systems, characterized in that, include: When the network side detects that a user terminal that has passed network access authentication and business system access authentication continues to access the target business system, it calls the preset zero-trust security model and triggers the session management function network element or AAA server in the network core network function network element to send a user re-authentication request to the user terminal according to the preset access control policy, so that the user terminal returns the current user information to the AAA server. The user terminal includes one or more target users. When the AAA server verifies that the current user's identity information matches the user's identity information corresponding to the target user, it determines that the identity authentication result is successful. Based on the successful identity authentication result and the current user identity information, the AAA server initiates a biometric authentication request to the user terminal, so that the AAA server can detect whether the latest biometric information of the target user returned by the user terminal matches the pre-stored biometric information of the target user. If they match, the AAA server returns a successful biometric authentication result to the user terminal to authorize the target user to continue accessing the target business system. The above steps are executed repeatedly based on the access control policy until the target user finishes accessing the target business system, thus completing the access control of the business system based on zero trust.

2. The zero-trust-based business system access control method according to claim 1, characterized in that, The network core network functional elements include 5G core network functional elements and 6G core network functional elements. The 5G core network functional elements include access and mobility management functional elements, session management functional elements, user plane functional elements, multi-access edge computing functional elements, and AAA server. The access control policy includes periodic continuous re-authentication, event-based continuous re-authentication, and periodic and event-based continuous re-authentication. The periodic continuous re-authentication includes time-based periodic continuous user authentication, the event-based continuous re-authentication includes terminal location-based continuous user authentication and network security situation awareness-based continuous user authentication, and the periodic and event-based continuous re-authentication includes terminal location and time-based continuous user authentication. The user identity information includes user account, user password, token or certificate; The biometric information includes user fingerprint features, user facial features, or user iris features; The user re-authentication request includes an EAP request.

3. The zero-trust-based business system access control method according to claim 2, characterized in that, The steps of invoking a preset zero-trust security model and triggering a session management function element or AAA server in the network core network functional elements to send a user re-authentication request to the user terminal according to a preset access control policy, so that the user terminal returns the current user information to the AAA server, include: The session management function network element or the AAA server initiates the time-based periodic user identity continuous authentication, and the timer module in the session management function network element or the AAA server continuously detects whether the system access time interval of the target user reaches the preset time interval. If the system access duration interval of the target user reaches the preset time interval, the session management function... The network element or the AAA server sends an EAP request to the user terminal so that the user terminal returns the current user identity information to the AAA server.

4. The zero-trust-based business system access control method according to claim 2, characterized in that, The steps of invoking a preset zero-trust security model and triggering a session management function element or AAA server in the network core network functional elements to send a user re-authentication request to the user terminal according to a preset access control policy, so that the user terminal returns the current user information to the AAA server, include: The session management function network element initiates continuous authentication of user identity based on terminal location. The session management function network element obtains the wireless location accessed by the target user uploaded by the access and mobility management function network element. The wireless location includes a cell, base station, or tracking area. When the session management function network element detects that the target user has entered the re-authentication location area that requires the target user to re-authenticate, the session management function network element sends an EAP request to the user terminal so that the user terminal returns the current user identity information to the AAA server.

5. The zero-trust-based business system access control method according to claim 4, characterized in that, After the session management function network element detects that the target user has entered the re-authentication location area requiring re-authentication, the steps include: The session management function network element initiates continuous user authentication based on terminal location and time. The timer module in the session management function network element continuously detects whether the system access time interval when the target user enters the re-authentication location area reaches a preset time interval. If this is achieved, the process continues with the session management function network element sending an EAP request to the user terminal so that the user terminal returns the current user identity information to the AAA server.

6. The zero-trust-based business system access control method according to claim 2, characterized in that, The steps of invoking a preset zero-trust security model and triggering a session management function element or AAA server in the network core network functional elements to send a user re-authentication request to the user terminal according to a preset access control policy, so that the user terminal returns the current user information to the AAA server, include: The session management function network element initiates continuous user authentication based on network security situation awareness. The multi-access edge computing function network element or the user plane function network element continuously senses the network security situation of the user terminal according to the preset security situation awareness strategy. The network security situation includes abnormal user behavior, which includes abnormal login address or time, abnormal data transmission characteristics, and access restricted areas. The security situation awareness strategy includes machine learning models or user behavior analysis. The session management function network element sends an EAP request to the user terminal based on the network security situation, so that the user terminal returns the current user identity information to the AAA server.

7. The zero-trust-based access control method for business systems according to any one of claims 1 to 6, characterized in that, Based on the successful identity authentication result and the current user identity information, the AAA server initiates a biometric authentication request to the user terminal. This allows the AAA server to detect whether the latest biometric information of the target user returned by the user terminal matches the target user's pre-stored biometric information. If a match is found, a successful biometric authentication result is returned to the user terminal to authorize the target user to continue accessing the target business system. The steps include: Based on the successful identity authentication result and the current user identity information, the AAA server initiates a biometric authentication request to the user terminal. The terminal re-authentication module in the user terminal calls the biometric acquisition module to collect the latest biometric information of the target user, and the AAA re-authentication module in the AAA server calls the pre-stored biometric information of the target user in the biometric storage module. The AAA server detects whether the latest biometric information of the target user returned by the user terminal matches the pre-stored biometric information of the target user. If they match, the server returns a biometric authentication success result to the user terminal to authorize the target user to continue accessing the target business system.

8. A zero-trust-based access control device for business systems, characterized in that, include: The re-authentication trigger module is configured to, when the network side detects that a user terminal that has passed network access authentication and business system access authentication continues to access the target business system, call the preset zero-trust security model and trigger the session management function network element or AAA server in the network core network function network element to send a user re-authentication request to the user terminal according to the preset access control policy, so that the user terminal returns the current user information to the AAA server, wherein the user terminal includes one or more target users; The user authentication module is configured to determine a successful authentication result when the AAA server verifies that the current user's identity information matches the user's identity information corresponding to the target user. The biometric authentication module is configured such that, based on the successful identity authentication result and the current user identity information, the AAA server initiates a biometric authentication request to the user terminal, so that the AAA server detects whether the latest biometric information of the target user returned by the user terminal matches the pre-stored biometric information of the target user. If they match, the AAA server returns a successful biometric authentication result to the user terminal to authorize the target user to continue accessing the target business system. The access control module is configured to repeatedly execute the above steps based on the access control policy until the target user finishes accessing the target business system, thereby completing access control for the zero-trust-based business system.

9. An electronic device comprising a central processing unit and a memory, characterized in that, The central processing unit is used to invoke and run a computer program stored in the memory to perform the steps of the method as described in any one of claims 1 to 7.

10. A computer-readable storage medium, characterized in that, It stores, in the form of computer-readable instructions, a computer program implemented according to any one of claims 1 to 7, which, when invoked by a computer, executes the steps included in the corresponding method.

Citation Information

Patent Citations

  • Business access control system and control method based on zero trust

    CN115001770A

  • Zero-trust system access control method and device and zero-trust system

    CN116319024A

  • Network security architecture, network security implementation method and system, and medium

    CN117155605A

  • Initiation of seconday authentication for a subscriber entity

    WO2024067955A1

Cited By

  • Mobile terminal adaptive security protection method based on behavior portrait and environment perception

    CN122205423A