Blockchain SDP Controller for Multi-Access Terminal Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing Software Defined Perimeter (SDP) technology limits access to multiple services or access points simultaneously, as it operates in a one-to-one manner, preventing users or enterprises from accessing all services or different services at the same time.
Innovation Solution
A data processing method and apparatus that utilize a blockchain network to determine target access points for application access requests, perform SDP authentication, and establish data channels with a preset validity period, allowing terminals to access multiple access points concurrently while preventing centralization and Distributed Denial of Service (DDoS) attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional one-to-one SDP access manner is used, then security authentication is simplified, but the terminal can only access one access point at a time, limiting service accessibility
Solution Approach 1:
The patent segments the traditional one-to-one access control into one-to-many relationships by introducing a blockchain-based permission verification mechanism. Each access point maintains independent permission records on the blockchain, allowing a terminal to simultaneously access multiple access points without creating a centralized complex control system. The segmentation is achieved by distributing permission verification across multiple blockchain nodes rather than using a single centralized controller.
Solution Approach 2:
The patent introduces a blockchain network as an intermediary between terminals and access points. Instead of direct one-to-one authentication, the blockchain serves as a distributed intermediary that stores and verifies permission information. This intermediary enables multiple access points to recognize and authenticate the same terminal simultaneously, resolving the contradiction between simplified authentication and enhanced service accessibility.
2Adaptability or versatility
If multiple access points are deployed to provide diverse services, then service variety is improved, but the terminal cannot access all services simultaneously due to one-to-one access limitation
Solution Approach 1:
The patent implements universality by enabling a single terminal to perform multiple access functions simultaneously through different access points. The blockchain-based permission system allows the terminal to maintain multiple active connections to different access points, each providing different services. This multi-functional access capability directly addresses the limitation where terminals could only access one service at a time despite multiple services being available.
3Reliability
If centralized SDP controller is used for managing access points, then access control is simplified, but the system becomes vulnerable to centralization failure and DDoS attacks
Solution Approach 1:
The patent extracts the centralized SDP controller function and distributes it across multiple blockchain nodes. Instead of having a single centralized controller that manages all access points, the permission verification function is extracted and replicated across the decentralized blockchain network. This extraction eliminates the single point of failure and reduces vulnerability to DDoS attacks while maintaining simplified access control through the blockchain's inherent distributed verification mechanism.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The present disclosure relates to a data processing method and apparatus, a terminal and an access point computer, which can achieve an effect that the terminal accesses multiple access points at the same time. The method includes: receiving an application access request; determining a target access point corresponding to the application access request according to a mapping relationship between the access point and an application server obtained from a blockchain network; sending a software defined perimeter SDP authentication request to the target access point; and after the SDP authentication succeeds, performing interaction of application data through a data channel established with the target access point, wherein the data channel has a period of validity of a preset time length.