Cross-Domain Service Access Control With Stateless Traffic Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional single-point protection methods based on network boundaries are ineffective in cross-trust domain access, leading to delayed protection effects and increased service processing latency, as they rely on passive defense approaches and cannot be applied across domains.
Innovation Solution
A service access control method involving user, intermediate, and server nodes that perform collaborative key derivation and verification, enabling stateless filtering and active, near-source protection across multiple trust domains.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If passive defense approaches such as attack detection-analysis and tracing-traffic scrubbing are adopted, then attack sources can be analyzed and localized mitigation can be achieved, but protection effects are delayed and additional dedicated equipment is required which increases service processing latency
Solution Approach 1:
The patent implements preliminary action by performing access verification at intermediate nodes before malicious traffic reaches the target server. The verification process checks credentials and generates verification information in advance, blocking potential threats at the source rather than reacting after attacks are detected. This proactive approach eliminates the need for post-attack analysis and traffic scrubbing equipment, thereby reducing service processing latency while maintaining protection effectiveness.
Solution Approach 2:
The patent introduces intermediate nodes as mediators between user nodes and server nodes. These intermediate nodes perform access verification by checking credentials and generating verification information, acting as a security barrier that prevents malicious traffic from reaching targets. This intermediary mechanism enables early blocking of threats without requiring additional dedicated equipment at the server side, thus reducing both latency and equipment requirements while improving protection effectiveness.
2Adaptability or versatility
If traditional single-point protection methods based on network boundaries are used, then protection can be implemented at network boundaries, but these methods are ineffective in cross-trust domain access scenarios
Solution Approach 1:
The patent implements universality by designing an access verification mechanism that operates consistently across different trust domains. The intermediate nodes perform the same verification operations (checking credentials, generating verification information) regardless of which trust domain the traffic originates from or which domain the target server belongs to. This universal approach enables the system to handle cross-trust domain access scenarios effectively while maintaining protection effectiveness, overcoming the limitations of traditional boundary-based methods.
Solution Approach 2:
The patent transitions from traditional single-point protection at network boundaries to multi-point protection distributed across intermediate nodes in the network path. This dimensional change from boundary-based to path-based verification allows the system to protect against threats in cross-trust domain scenarios by verifying access requests at multiple intermediate points, thereby improving both cross-domain applicability and protection effectiveness.
3Reliability
If near-source protection is implemented within controllable internal networks, then early blocking of malicious traffic can be achieved, but such protection cannot be applied across domains
Solution Approach 1:
The patent uses intermediate nodes as mediators that enable near-source protection to function across trust domain boundaries. These intermediate nodes perform access verification by checking credentials and generating verification information, effectively acting as mobile security checkpoints that can operate in any trust domain. This intermediary mechanism allows early blocking of malicious traffic in cross-domain scenarios, simultaneously improving protection effectiveness and cross-domain applicability.
Solution Approach 2:
The patent implements universality by designing a verification mechanism that operates identically across different trust domains. The intermediate nodes execute the same verification logic (credential checking, verification information generation) regardless of domain boundaries, enabling near-source protection to be applied universally across domains. This universal approach maintains protection effectiveness while achieving cross-domain applicability.
Data Source
Figure 1
Figure 2
Figure 3
AI summary
Disclosed in the present application are a service access control method, an electronic device and a storage medium. The method comprises: a user node sending a first access request message to a server node (S101), wherein the first access request message carries IP address information, the first access request message passes at least one intermediate node and then reaches the server node, the at least one intermediate node comprises an access node, and the first access request message represents that the user node makes an access request for the first time; the user node receiving a first response message returned by the server node (S102), wherein the first response message carries access credential information and identification information; and the user node sending a second access request message to the server node (S103).