A site access management method and device and related products
Patent Information
- Application Number
- CN202210565547.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-05-23
- Publication Date
- 2026-08-28
- Estimated Expiration
- 2042-05-23
AI Technical Summary
[0005]本申请实施例提供了一种站点访问管控方法、装置及相关产品,以灵活地满足企业的站点访问管控的需求,并解决站点访问管控时安全性和访问性能无法兼顾的问题
Smart Images

Figure CN117155870B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network access technology, and in particular to a method, apparatus and related products for website access control. Background Technology
[0002] With the development of internet technology, people can access specific websites, such as news sites, social media platforms, and databases, to obtain relevant resources. For reasons of resource and site security, some enterprises often use site access control technologies to control and manage device access to these sites.
[0003] To address security concerns, enterprises often delegate website traffic management and logging to backend systems. This inevitably leads to lengthy backend processing times and low efficiency. During this process, the latency in traffic handling is significant, resulting in substantial network overhead and impacting access performance. Furthermore, existing website access control technologies typically lack flexibility.
[0004] Ensuring the security of site resource access while flexibly meeting the site access control needs of enterprises and improving access performance has become an urgent technical problem to be solved in the field. Summary of the Invention
[0005] This application provides a site access control method, device, and related products to flexibly meet the site access control needs of enterprises and solve the problem of not being able to balance security and access performance during site access control.
[0006] A first aspect of this application provides a site access control method, the method comprising:
[0007] Receive site access control policies issued by the server;
[0008] Based on the site access control policy and the access control elements of the terminal device, multiple site access control structures of the terminal device are generated; wherein, each site access control structure includes at least priority, hit conditions, handling method and audit switch opening / closing information;
[0009] When a site access traffic is initiated through the terminal device, the site access control structure that the site access traffic hits first is determined as the target control structure in descending order of priority among the multiple site access control structures.
[0010] The site access traffic is controlled based on the handling methods and the on / off information of the audit switch in the target control structure.
[0011] A second aspect of this application provides a site access control device, the device comprising:
[0012] The access control policy receiving unit is used to receive site access control policies issued by the server.
[0013] The control structure generation unit is used to generate multiple site access control structures for the terminal device based on the site access control policy and the access control elements of the terminal device; wherein each site access control structure includes at least priority, hit conditions, handling method and audit switch opening / closing information;
[0014] The target control structure determination unit is used to determine, when the terminal device initiates site access traffic, the site access control structure that the site access traffic hits first in order of priority from high to low among the multiple site access control structures as the target control structure.
[0015] The access control unit is used to control the site access traffic according to the handling method and the opening / closing information of the audit switch in the target control structure.
[0016] A third aspect of this application provides a site access control device, the interactive device comprising a processor and a memory:
[0017] The memory is used to store program code and transmit the program code to the processor;
[0018] The processor is used to execute the steps of the site access control method provided in the first aspect according to the instructions in the program code.
[0019] In a fourth aspect, this application provides a computer-readable storage medium for storing program code for performing the steps of the site access control method provided in the first aspect.
[0020] A fifth aspect of this application provides a computer program product, including a computer program or instructions that, when executed by an interactive device, implement the steps of the site access control method provided in the first aspect.
[0021] As can be seen from the above technical solutions, the embodiments of this application have the following advantages:
[0022] The site access control method provided in this application is applied to a terminal device. The terminal device first receives a site access control policy from the server; then, based on the site access control policy and the access control elements of the terminal device, it generates multiple site access control structures. Since each site access control structure includes at least priority, hit conditions, handling methods, and audit switch on / off information, when site access traffic is initiated through the terminal device, the site access control structure that the traffic hits first can be determined as the target control structure in descending order of priority. When controlling the aforementioned site access traffic, the control is specifically based on the handling methods and audit switch on / off information in the target control structure. In this application, the site access traffic control process is moved forward to the terminal device, and the terminal device takes corresponding control measures based on the specific target control structure hit, reducing the processing burden on the backend, lowering the latency and network loss of Internet traffic link processing, thereby improving access performance. Furthermore, the site access control structure generated by integrating site access control policies and terminal device access control elements is diverse and prioritized, enabling it to more flexibly meet the site access control needs of enterprises. In addition, the multiple site access control structures provide layered control over site access traffic, and the generation method has strict requirements; therefore, the site access control method provided in this application can also improve the security and effectiveness of site resource access control. Attached Figure Description
[0023] Figure 1 A network architecture diagram of a site access control method provided in this application embodiment;
[0024] Figure 2 A flowchart illustrating a site access control method provided in this application embodiment;
[0025] Figure 3 A schematic diagram of a configuration page for a site access control policy provided in an embodiment of this application;
[0026] Figure 4 A schematic diagram of an Internet resource configuration page provided in an embodiment of this application;
[0027] Figure 5 A flowchart illustrating another site access control method provided in this application embodiment;
[0028] Figure 6 This is a schematic diagram of the structure of a site access control device provided in an embodiment of this application;
[0029] Figure 7 This is a schematic diagram of the server structure in an embodiment of this application;
[0030] Figure 8 This is a schematic diagram of the structure of a terminal device in an embodiment of this application. Detailed Implementation
[0031] In a zero-trust architecture, workplace access to internal network services is restricted to forwarding through an internal network smart gateway, constantly verifying network access security. However, internet traffic is far more extensive, with access volume per unit time significantly exceeding that of internal network resources. A common approach is to directly allow direct connections to the terminal for this type of traffic without any related auditing or statistics. This approach is simple to implement, but lacks auditing of access via a uniform resource locator (URL), resulting in weaker security in the workplace. Another approach is to aggregate internet traffic to an external network gateway and implement URL auditing while controlling access at the gateway level. This method completes the auditing function for external website access, but under fine-grained access control rules, the practice of filtering first, then auditing and processing, increases the processing chain and access latency for external websites, increases the data storage and processing pressure on the gateway, makes it difficult to guarantee access performance, and results in low traffic processing efficiency, negatively impacting the end-user experience.
[0032] In addition to the methods mentioned above, IT administrators can manage website access traffic by establishing blacklists and whitelists that comply with corporate security and management policies. This approach primarily focuses on auditing browsing history for mainstream desktop browsers, lacking comprehensive traffic control capabilities. It relies on reporting and auditing application and web browsing history, lacking multi-dimensional control measures for external website access and offering insufficient security. Furthermore, it struggles to implement flexible access control for different target systems, different applications initiating access, and different terminal devices.
[0033] To address the aforementioned issues, this application proposes a site access control method, apparatus, and related products. These aim to meet enterprises' flexible site access control needs, ensure the security of target system resources during site access control, improve access performance, and enhance the user experience.
[0034] First, we will explain several terms that may be involved in the embodiments of this application below.
[0035] Trusted Applications: Applications authorized by the management end that can be accessed by terminals within the internal business system, including application name, application MD5, signature information, etc.
[0036] Reachable Area: End users can access a list of internal sites set up by the enterprise through a zero-trust network.
[0037] Network request credentials: Authorization information issued by the iOA server for a single network request, used to identify the authorization status of the network request.
[0038] Zero-trust access control policies consist of information about user-accessible processes (trusted applications) and accessible business sites (reachable areas). With authorized permissions, a user can access any reachable area through any trusted application. The granularity of zero-trust access control policies is based on logged-in users, allowing for different zero-trust policies to be formulated for different logged-in users.
[0039] Zero Trust Gateway: Deployed at the entry point of enterprise applications and data resources, it is responsible for verifying and forwarding every session request that accesses enterprise resources.
[0040] Access Proxy: An endpoint access proxy is an endpoint agent deployed on a controlled device to initiate secure access. It is responsible for initiating requests for trusted authentication of the access subject. Once the identity is verified, an encrypted access connection can be established with the access gateway. It is also the point of enforcement of access control policies.
[0041] Direct access: In a zero-trust network access architecture, when an application initiates a network access request to a site, the full traffic proxy intercepts the traffic and then initiates a network access to the target site through the full traffic proxy, that is, it initiates a direct connection access. The full traffic proxy then sends the network response from the target site to the application. This access mode is called direct access.
[0042] Proxy access: In a zero-trust network access architecture, when an application initiates a network access request to a site, the full traffic proxy intercepts the traffic and then forwards it to the smart gateway. The smart gateway then proxies the access to the target business site. After the access is completed, the smart gateway sends the network response of the target site to the full traffic proxy, which then forwards the network response of the target site to the application. This access mode is called proxy access.
[0043] Access subject: In the network, the party that initiates the access, the person / device / application that accesses internal network business resources, is a digital entity composed of or combined with factors such as people, devices, and applications.
[0044] Accessed object: In the network, the party being accessed, namely the enterprise's intranet business resources, including applications, systems (development and testing environments, operation and maintenance environments, production environments, etc.), data, interfaces, functions, etc.
[0045] Policy: A set of rules issued by the administrator on the management terminal for enterprise endpoint management. This includes patch fixing, zero-trust network control, and security hardening policies. Policies may contain sensitive information such as tickets, expiration dates, and the number of valid entries.
[0046] To facilitate understanding of the technical solutions provided in the embodiments of this application, the following is combined with... Figure 1 The network architecture for the site access control method is explained. Figure 1 A network architecture diagram of a site access control method provided in this application embodiment. For example... Figure 1 The architecture diagram illustrates the design of the iOA system, which involves terminal devices and a server. The server acts as the backend, running the iOA server software and configured with a traffic gateway. The terminal devices run the iOA client software and are configured with access proxies. Each terminal device initiates site access traffic, and access control is managed on the terminal side (i.e., the terminal itself) through the iOA client and access proxy. Combined with site access control policies issued by the server, the terminal device can ultimately manage and handle site access traffic on the terminal side, such as allowing direct connections, forwarding to the traffic gateway, or blocking access. Auditing of specific site access traffic can be delegated to… Figure 1 The server shown is in operation. Figure 1 In the server shown, the iOA server and the traffic gateway can also communicate and interact. Figure 1 The dashed lines in the diagram indicate that the two entities can communicate with each other.
[0047] The following is an explanation of these core modules.
[0048] 1. iOA Client: A security agent installed on employees' work devices, responsible for verifying the trusted identity of users on the device, verifying whether the device and application are trustworthy; and requesting the server to send unknown processes for inspection.
[0049] 2. Access Proxy: It hijacks device traffic through the TUN / TAP virtual network card, and after authentication by the iOA client, it is responsible for forwarding the request to the smart gateway. If the authentication fails, it will either connect directly or disconnect.
[0050] 3. Traffic Gateway: Deployed at the entry point of enterprise applications and data resources, it is responsible for verifying, authorizing, and forwarding every session request that accesses enterprise resources.
[0051] 4. iOA Server: Through a policy control engine, it securely schedules business traffic, authorizing at the person-device-software-application granularity. Specifically, the identity verification module verifies user identity, the device trust module verifies device hardware information and security status, and the application detection module checks application processes for security, such as vulnerabilities and viruses / Trojans. The server periodically submits files to the Threat Intelligence Cloud Service Security Advisor or TAV for inspection; if malicious processes are identified, the client is notified to perform asynchronous blocking operations.
[0052] The execution entity of the site access control method provided in this application embodiment can be Figure 1 The terminal devices in the illustrated architecture can include, but are not limited to, mobile phones, computers, intelligent voice interaction devices, smart home appliances, in-vehicle terminals, and aircraft. This invention can be applied to various scenarios, including but not limited to cloud technology, artificial intelligence, smart transportation, and assisted driving.
[0053] Figure 1 The server shown can be a standalone physical server, a server cluster consisting of multiple physical servers, or a distributed system. Additionally, the server can also be a cloud server providing basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communication, middleware services, domain name services, security services, CDN, and big data and artificial intelligence platforms.
[0054] Cloud security refers to the collective term for security software, hardware, users, organizations, and security cloud platforms based on cloud computing business models. Cloud security integrates emerging technologies and concepts such as parallel processing, grid computing, and the identification of unknown virus behavior. Through a large network of clients, it monitors abnormal software behavior on the network, obtains the latest information on Trojans and malware on the internet, sends it to the server for automatic analysis and processing, and then distributes solutions for viruses and Trojans to each client.
[0055] The main research directions in cloud security include: 1. Cloud computing security, which mainly studies how to ensure the security of the cloud itself and various applications on the cloud, including cloud computer system security, secure storage and isolation of user data, user access authentication, information transmission security, network attack protection, and compliance auditing; 2. Cloudification of security infrastructure, which mainly studies how to use cloud computing to build and integrate security infrastructure resources and optimize security protection mechanisms, including building a large-scale security event and information collection and processing platform through cloud computing technology to achieve the collection and correlation analysis of massive amounts of information and improve the ability to control network-wide security events and risks; 3. Cloud security services, which mainly studies various security services provided to users based on cloud computing platforms, such as antivirus services.
[0056] Figure 2 This is a flowchart illustrating a site access control method provided in an embodiment of this application. The specific implementation of this method is described below, using a terminal device as the execution subject. Figure 2 The site access control methods shown include:
[0057] S201, Receive site access control policies issued by the server.
[0058] The server includes pre-defined site access control policies. These policies can be formulated in the name of the enterprise or server-side users. As an example, the server-side user could be the administrator responsible for the enterprise's site access control.
[0059] Figure 3 This is a diagram illustrating the configuration page for site access control policies. (Combined with...) Figure 3 As illustrated, server-side users can configure policy names, user information for blocked access to specific resources, and resource information. It also specifies that when a terminal device meets certain conditions, access to resources in the resource information list on the page will be blocked. These conditions can include a specified network location and access time. Server-side users can configure the specified network location in the conditions to be any network location or a specified network location; they can also configure the access time in the conditions to be unlimited or restricted to a specified time.
[0060] Figure 4 This is a schematic diagram of a configuration page for an internet resource provided in an embodiment of this application. (In conjunction with...) Figure 4 As shown in the illustration, users on the server can... Figure 4 The page shown configures the name, resource category (e.g., domain name, IP address, or IP range), port (e.g., all ports or a specified port), resource group (e.g., test resources, entertainment resources, etc.), and protocol type (e.g., TCP) of the internet resources.
[0061] Combination Figure 3 It's easy to see that the established site access control policies are associated with internet resources. In other words, site access control policies are policies regarding access control rules for resources. Before the terminal device implements control measures, the server sends the configured site access control policies to the terminal device. Thus, the terminal device can receive the site access control policies and, in subsequent steps, implement the actual control based on the received policies.
[0062] S202, Based on the site access control policy and the access control elements of the terminal device, generate a multi-site access control structure for the terminal device.
[0063] In this embodiment, for a terminal device to perform control, it first needs to generate its own corresponding multi-site access control structure. Different terminal devices may have different access control elements; therefore, even if they receive the same site access control policy, the multi-site access control structures generated by different terminal devices may differ. Furthermore, the access control elements of a terminal device can change dynamically in real time. This means that even for the same terminal device, the generated multi-site access control structures can differ when the access control elements change.
[0064] Access control elements for a terminal device refer to the control-related factors that the terminal device itself needs to consider when it is necessary to control site access traffic initiated by the terminal device. For example, access control elements for a terminal device may include its current security attributes and network location. Specifically, when the terminal device's network location changes, it affects the generated site access control structure. Alternatively, when the terminal device's current security attributes change, for example from security level one to security level two, it will also affect the generated site access control structure.
[0065] In this step, the terminal device can first determine its current security attributes and network location; then, based on the security attributes, the network location, and the site access control policy received in step S201, it can generate a multi-site access control structure for the terminal device.
[0066] Table 1 below shows an example of a multi-site access control structure generated by the terminal device. As shown in Table 1, different rows represent different site access control structures. Each site access control structure includes at least priority, hit conditions, handling methods, and audit switch on / off information. In the multi-site access control structures shown in Table 1, the highest priority is P0, and the lowest priority is P... n Where n is a general positive integer. In other words, there are n+1 site access control structures in Table 1.
[0067] In this embodiment, the terminal device handles site access traffic by allowing direct connection, blocking access, or forwarding it to a target traffic gateway. Here, the target traffic gateway refers to the traffic gateway specified in the access control structure to which site access traffic needs to be forwarded. For example, traffic gateway A and traffic gateway B are two different traffic gateways. In a site access control structure with priority P2, the handling method is to forward the traffic to traffic gateway A, in which case traffic gateway A acts as the target traffic gateway; while in a site access control structure with priority P... n In a site access control structure, the handling method is to forward the request to traffic gateway B, where traffic gateway B acts as the target traffic gateway.
[0068] The audit switch has two on / off settings: "on," indicating that traffic auditing is enabled, and "off," indicating that traffic is not audited. In other words, the site access control structure already specifies whether traffic hitting this structure needs to be audited through the audit switch's on / off information. As an optional implementation, for site access structures that allow direct connections, the audit switch is set to "off"; for site access structures that forward traffic to the target gateway or block access, the audit switch is set to "on." In practical applications, the audit switch's on / off information can be configured during the configuration phase according to actual control requirements.
[0069] The hit criteria directly determine whether site access traffic hits a specific site access control structure. Hit criteria include one or a combination of the following information: the source address, destination address, URL information of the site access traffic, information of the application initiating the site access traffic, information of the terminal device, or information of the user initiating the site access traffic. Here, terminal device information can refer to the unique identifier of the terminal device. User information can be the user's account name, account identity identifier, or user nickname, etc. Application information can be the application's name. In other words, application information, terminal device information, and user information are used to identify the application, the terminal device, and the user, respectively. Table 1 only briefly illustrates the types of information involved in hit criteria. In actual applications, the hit criteria in multiple site access control structures will be more detailed, such as specifying the information of the authenticated user, specifying the specific access time, etc.
[0070] It is understood that in the specific embodiments of this application, data related to user information, application information, and terminal device information are involved. When the above embodiments of this application are applied to specific products or technologies, user permission or consent is required, and the collection, use, and processing of related data must comply with the relevant laws, regulations, and standards of the relevant countries and regions. For example, before initiating site access traffic in response to a user's operation, a pop-up window is displayed on the interface of the terminal device or the interface of the application running on the terminal device, prompting relevant information that may be applied to site access control scenarios, and providing options to agree or refuse. Site access control is only performed after the user triggers the consent option and confirms.
[0071] Table 1. Example of a multi-site access control structure generated by a terminal device.
[0072] <![CDATA[P0]]> Block access open Blackening equipment <![CDATA[P1]]> Block access open Some certified users <![CDATA[P2]]> Switch to traffic gateway A open Combined URL and access time … … … … <![CDATA[P n-2 ]]> Block access open url <![CDATA[P n-1 ]]> Allow direct connection close Access time <![CDATA[P n ]]> Switch to traffic gateway B open Traffic gateway performs access control
[0073] S203, when site access traffic is initiated through the terminal device, the site access control structure that the site access traffic hits first is determined as the target control structure in descending order of priority among the multiple site access control structures.
[0074] When site access traffic is initiated through a terminal device, the source address, destination address, URL information, application information initiating the site access traffic, terminal device information, or user information initiating the site access traffic can be used to match the traffic against the hit conditions in various site access control structures, from highest to lowest priority. If a match is successful, it means the current condition has been met, and other lower priority conditions will not be matched. If a match is unsuccessful, it means the current condition has not been met, and the matching will continue down the list to match lower priority conditions. It should be noted that if no match is found even up to the second lowest priority condition, the lowest priority condition will be used, for example, priority P in Table 1. n The item with the lowest priority is the site access control structure. If the site access traffic is between priority P0 and P... n-1 If neither of these hits the site access control structure, then the priority will be P. n As one of the structures it hits, a site access control structure is prioritized as P. n One of the site access control structures is used as the target control structure for the site access traffic. The target control structure is the site access control structure adopted when controlling the traffic in the future. Conversely, if one of the multiple site access control structures generated in the previous step S202 is matched due to the matching condition, then the matched one is used as the target control structure.
[0075] S204. Based on the handling method and the opening / closing information of the audit switch in the target control structure, the site access traffic is controlled.
[0076] For example, if the handling method in the target control structure is to allow direct connection, the terminal device will directly send the site access traffic to the target system; if the handling method in the target control structure is to block traffic, the terminal device will block the access traffic to the target system according to the handling method in the target control structure; if the handling method in the target control structure is to forward to the target gateway, the terminal device can forward the access traffic to the target gateway in this step, and then the target gateway will perform further processing on the traffic.
[0077] Regarding the on / off information of the audit switch in the target control structure, if it is on, the terminal device can send this information along with the basic information of the traffic (such as information about the application initiating the site access traffic and information about the target system that the site access traffic needs to access) to the server before, during, or after processing a traffic flow. The server's server-side or gateway then performs the audit operation. Site access traffic initiated by different terminal devices can be audited by the server or different server nodes in a server cluster, which facilitates a more comprehensive audit of traffic by the server or server cluster, thereby facilitating the identification of relevant information about abnormal traffic and enabling timely and effective monitoring of abnormal traffic. In other implementations, the audit operation can also be performed by the terminal device based on the on / off information of the audit switch in the target control structure. After performing the audit, the terminal device can provide feedback to the server based on the audit results.
[0078] In this application, the control of website access traffic is moved forward to the terminal device. The terminal device then takes corresponding control measures based on the specific target control structure, reducing the processing burden on the backend, lowering latency and network overhead in internet traffic processing, and thus improving access performance. In other words, the control process is moved forward, no longer relying solely on the backend server; the terminal device itself has the ability to control website access traffic. Furthermore, the website access control structure generated by integrating website access control strategies and terminal device access control elements is diverse and prioritized, allowing for greater flexibility in meeting the website access control needs of enterprises. Enterprises can configure policies according to their needs, enabling flexible control by the terminal device, resulting in more secure and tailored control. Moreover, the multiple website access control structures provide layered control over website access traffic, and the generation method has strict requirements. Therefore, the website access control method provided in this application can also improve the security and effectiveness of website resource access control.
[0079] The process of generating multiple site access control structures for the terminal device was described in S202 of the preceding embodiment. It should be noted that the site access control structures in this embodiment are not static after generation, but can be dynamically updated and changed according to specific circumstances. Specifically, the site access control method provided in this embodiment further includes the following steps:
[0080] Get the number of times each of the multiple site access control structures is hit within a preset time period;
[0081] Site access control structures that hit more than the first threshold number are retained as high-frequency structures in the multiple site access control structures of the terminal device, while site access control structures that hit less than the second threshold number are removed as low-frequency structures from the multiple site access control structures of the terminal device.
[0082] The first threshold is used to define high-frequency structures, and the second threshold is used to define low-frequency structures. Both thresholds can be set according to actual needs. In practice, the second threshold is less than or equal to the first threshold. By retaining high-frequency structures and eliminating low-frequency structures, the target systems in the site access control structure are the websites that users of the current terminal device frequently access, improving the effectiveness of control and increasing the hit rate of the control structure.
[0083] In practical applications, each site access control structure can also include target system rules. These target system rules are access rules for a target system, specifying the supported domain names and / or the ports for those domain names. Table 2 shows another example of a multi-site access control structure generated by the terminal device. As can be seen from Table 2, compared to Table 1, a new column named "Target System Rules" has been added. In optional implementations, wildcards are supported for the target system rules. The target system rules shown in Table 2 are merely examples, and their specific content is not limited here.
[0084] Clearly, the target system rules in the target control structure only have binding significance when the handling method allows direct connection or forwarding to the target traffic gateway. Therefore, when the target control structure includes a handling method that allows direct connection or forwarding to the target traffic gateway, S204 in the aforementioned embodiment controls the site access traffic according to the handling method in the target control structure and the on / off information of the audit switch. Specifically, this includes controlling the site access traffic according to the handling method in the target control structure, the on / off information of the audit switch, and the target system rules.
[0085] In other words, when the target control structure includes a handling method that allows direct connection or forwarding to the target traffic gateway, it can also be combined with target system rules in the target control structure for control. For domains not mentioned in the target system rules, access is not supported. Of course, this embodiment only illustrates the case where the target system rules represent domains and / or ports of supported domains. In other possible implementations, the target system rules can also represent domains and / or ports of unsupported domains, thus restricting and controlling site access traffic in another way.
[0086] Table 2 shows another example of a multi-site access control structure generated by the terminal device.
[0087]
[0088] In one alternative implementation, a highly secure authentication mechanism can be established between the terminal device and the server through the client, access proxy, server, and traffic gateway. This ensures that site access meets enterprise requirements, reduces security threats, and improves the effectiveness of management and control.
[0089] Figure 5 Another site access control method provided in this application embodiment. Combined with... Figure 5 It can be seen that the method includes:
[0090] S501 receives site access control policies issued by the server.
[0091] S502, Based on the site access control policy and the access control elements of the terminal device, generate a multi-site access control structure for the terminal device.
[0092] S503, when site access traffic is initiated through the terminal device, the site access control structure that the site access traffic hits first is determined as the target control structure in descending order of priority among the multiple site access control structures.
[0093] The implementation methods of S501-S503 are basically the same as those of S201-S203 in the previous embodiments. For relevant details, please refer to the description in the previous embodiments. They will not be repeated here.
[0094] S504, authenticate the site access traffic; if the authentication is successful, proceed to S505; if the authentication fails, proceed to S514.
[0095] Terminal devices can authenticate traffic as follows: S501-S503 are completed by the terminal device's access proxy. In S504, the access proxy requests authentication of the site access traffic from the client. The client then sends the authentication result back to the access proxy. The main purpose of authentication is to determine whether the application initiating the site access traffic is a trusted application. Therefore, S505 and S514, as two different branches, describe the subsequent operations that the terminal device needs to perform, corresponding to the trusted and untrusted application scenarios, respectively.
[0096] S505, when the application that initiated the site access traffic is determined to be a trusted application through authentication, the site access traffic is sent to the server so that the server can detect the site access traffic.
[0097] The purpose of sending site access traffic to the server is to further inspect the site access traffic by the server. If the inspection of the site access traffic passes, it will send an access ticket corresponding to the traffic and the maximum reuse time limit of the access ticket. This access ticket will serve as a credential for the access proxy to send the traffic to the gateway, also known as an authentication factor. Blocking access does not require an access ticket; only forwarding traffic to the gateway requires a ticket. Table 3 is another example table of multiple site access control structures generated by the terminal device. Compared with Tables 1 and 2, the site access control structure shown in Table 3 has an additional column for authentication factors, which includes: none or access ticket. Combining Table 3, it is not difficult to find that the access control structure specifies whether an access ticket needs to be obtained from the server and then the traffic is processed based on the obtained ticket. Therefore, the implementation methods of obtaining and updating tickets described in detail in the following steps can be executed when the authentication factor in the determined target control structure includes an access ticket.
[0098] Table 3 shows another example of a multi-site access control structure generated by the terminal device.
[0099]
[0100]
[0101] S506, Receive from the server the access ticket corresponding to the site access traffic and the maximum reuse time limit of the access ticket.
[0102] As mentioned earlier, the access ticket and its maximum reuse duration limit are values issued by the server to the terminal device after the server detects and approves the site access traffic. If the server determines that the site access traffic detection fails, it will not issue the access ticket and its maximum reuse duration limit to the terminal device's access proxy. The maximum reuse duration limit is used to constrain the reusable time of the access ticket both locally on the terminal and at the gateway; its specific usage will be described in S508.
[0103] S507, associate the basic information of the site access traffic with the access ticket.
[0104] Upon receiving the ticket, the access agent can associate the basic information of the traffic with the access ticket, thereby binding the access ticket to the traffic. The basic information of the site access traffic includes at least: information about the application initiating the site access traffic and information about the target system that the site access traffic needs to access.
[0105] S508, based on the maximum reuse duration limit of the access ticket, set a first cache duration limit of the access ticket locally on the terminal device, wherein the first cache duration limit is shorter than the maximum reuse duration limit.
[0106] In practical implementation, a first coefficient can be assigned to the maximum reuse duration limit. This first coefficient is greater than 0 and less than 1 to obtain the first cache duration limit. As an example, the first coefficient is 0.8, so the first cache duration limit = 0.8 * maximum reuse duration limit.
[0107] The embodiments of this application do not limit the execution order of S507 and S508. For example, S507 can be executed first and then S508 can be executed simultaneously, or S508 can be executed first and then S507 can be executed. Figure 5 The method is demonstrated using only one execution order as an example.
[0108] S509, determine whether the time the access ticket has been cached locally on the terminal device has reached the first cache duration limit. If it has not reached the limit, proceed to S510; if it has reached the limit, proceed to S511.
[0109] If the access ticket is cached locally on the terminal device for less than the first cache duration limit, it can be reused at the access proxy; otherwise, it cannot be reused. It should be noted that when the access ticket is cached locally on the terminal device for less than the first cache duration limit, if the basic information of another site access traffic initiated through the terminal device is the same as the basic information of the site access traffic, the access ticket is reused, and authentication of the other site access traffic is no longer performed, nor is a new access ticket requested from the server for that other site access traffic. Thus, by setting the first cache duration limit and the access ticket reuse mechanism, the efficiency of managing different access traffic with the same basic information is improved, shortening the overall processing chain and access latency.
[0110] S510, the access ticket and the site access traffic are encapsulated and sent to the target traffic gateway, so that the target traffic gateway requests ticket verification from the server based on the access ticket and saves the access ticket in the cache of the target traffic gateway when the access ticket verification is successful.
[0111] The target traffic gateway is configured with a second local caching duration limit for the access ticket, which is shorter than the maximum reuse duration limit.
[0112] In practical implementation, a second coefficient can be assigned to the maximum reuse duration limit. This first coefficient is greater than 0 and less than 1 to obtain the second cache duration limit. As an example, the second coefficient is 0.6, so the second cache duration limit = 0.6 * maximum reuse duration limit.
[0113] After receiving the access ticket, the target traffic gateway sends it to the server for verification. If the server verification passes, the target traffic gateway saves the access ticket associated with the basic information of the site access traffic in its local cache. At this point, a second cache duration limit restricts the reusability of the access ticket on the target traffic gateway. Once the ticket has been cached on the target traffic gateway for the second cache duration limit, it is no longer reusable on the target traffic gateway.
[0114] The success or failure of a ticket hit within the gateway determines whether a ticket verification request needs to be sent to the server. If an access ticket sent to the target traffic gateway successfully hits the target traffic gateway's cache, it indicates a server-verified ticket has been hit. In this case, the target traffic gateway does not need to request ticket verification from the server based on the received access ticket. That is, by setting a second cache duration limit and a ticket reuse mechanism, unnecessary interactions between the traffic gateway and the server are reduced, shortening the overall processing chain and access latency. However, if an access ticket sent to the target traffic gateway fails to hit the target traffic gateway's cache, the target traffic gateway needs to request ticket verification from the server based on the received access ticket. This method ensures the security and reliability of tickets and improves the security of accessed resources.
[0115] It should be noted that the first and second cache duration limits can be implemented by setting timers. For example, the first cache duration limit can be used as the set time for the first timer. Starting from the timer's initial cache of the ticket on the terminal device, if the first timer issues a notification, it indicates that the ticket's local cache time on the terminal device has reached the first cache duration limit. Similarly, the second cache duration limit can be used as the set time for the second timer. Starting from the timer's initial cache of the ticket on the gateway, if the second timer issues a notification, it indicates that the ticket's local cache time on the traffic gateway has reached the second cache duration limit.
[0116] In this embodiment of the application, if the ticket times out on the terminal, that is, if the judgment result of S509 is whether the time for accessing the ticket in the local cache of the terminal device has reached the first cache duration limit, then in order to improve the processing efficiency, the operations of S511-S513 can be further executed.
[0117] S511, based on the basic information associated with the access ticket, initiate a request to the target traffic gateway to process the virtual access traffic.
[0118] As mentioned earlier, access tickets are already associated with basic information about site access traffic. Therefore, it is relatively easy to construct virtual access traffic using this information. This virtual access traffic is not actually initiated traffic.
[0119] S512, receive a first notification or a second notification from the target traffic gateway.
[0120] If the target traffic gateway determines, based on the virtual access traffic, that its handling method is still to forward to the target traffic gateway, then it sends a first notification to the terminal device. If the target traffic gateway determines, based on the virtual access traffic, that its handling method is to allow direct connection or block access, then it sends a second notification to the terminal device.
[0121] Through the first or second notification, the terminal device can know whether its handling method needs to be changed if traffic with the same basic information as the virtual access traffic is initiated. S513 specifically describes the operations that the terminal device should perform after receiving the first or second notification.
[0122] S513, according to the received first notification, clear the locally cached access ticket and apply for a new ticket to replace the access ticket; or, according to the received second notification, cache the handling method for the virtual access traffic determined by the target traffic gateway to the local terminal device to deal with other traffic with the same basic information as the basic information of the virtual access traffic, and clear the locally cached access ticket.
[0123] Sending virtual traffic to the gateway ensures ticket replacement in advance, eliminating the need to request unexpired tickets after traffic to the same site is initiated. This saves processing time. Furthermore, sending virtual traffic facilitates timely updates to the handling method on the terminal device when the handling method for traffic to the same site changes, improving the accuracy of traffic control.
[0124] S514, when authentication determines that the application initiating the site access traffic is an untrusted application, the site access traffic is intercepted.
[0125] It is understandable that the trust status of an application may change; for example, an application might be trustworthy one day and untrustworthy two days later. In this embodiment, when it is determined that the application initiating the site access traffic poses a security risk, the locally cached access tickets related to the application are deleted, and the site access traffic initiated by the application is intercepted. This ensures that site resources can be accessed and obtained more securely.
[0126] In this embodiment, the client authenticates the site access traffic provided by the access proxy, and the server issues access tickets and a maximum reuse time limit to the client, ensuring that only authenticated traffic can be bound to the access ticket. Access tickets can be cached at both the terminal device and the gateway, enabling multi-party reuse of access tickets, reducing unnecessary repetitive interactions, and further improving access performance.
[0127] Based on the site access control method described in the foregoing embodiments, this application also provides a corresponding site access control device. This device can be implemented using a terminal device. Figure 6 This is a schematic diagram of a site access control device provided in an embodiment of this application. Figure 6 The site access control device shown includes:
[0128] The access control policy receiving unit 601 is used to receive site access control policies issued by the server.
[0129] The control structure generation unit 602 is used to generate multiple site access control structures for the terminal device based on the site access control policy and the access control elements of the terminal device; wherein each site access control structure includes at least priority, hit conditions, handling method and audit switch opening and closing information;
[0130] The target control structure determination unit 603 is used to determine, in descending order of priority, the first site access control structure hit by the site access traffic as the target control structure when the terminal device initiates site access traffic.
[0131] The access control unit 604 is used to control the site access traffic according to the handling method and the opening / closing information of the audit switch in the target control structure.
[0132] In this application, the control of website access traffic is moved to the terminal device, which then takes corresponding control measures based on the specific target control structure. This reduces the processing burden on the backend, lowers latency and network overhead in internet traffic processing, and thus improves access performance. Furthermore, the website access control structure generated by integrating website access control strategies and terminal device access control elements is diverse and prioritized, enabling greater flexibility in meeting the website access control needs of enterprises. Moreover, the multiple website access control structures provide layered control over website access traffic, and the generation method has strict requirements; therefore, the website access control method provided in this application also enhances the security and effectiveness of website resource access control.
[0133] Optionally, the control structure generation unit 602 is specifically used for:
[0134] Determine the current security attributes and network location of the terminal device;
[0135] The terminal device generates multiple site access control structures based on the security attributes, network location, and site access control policies.
[0136] Optionally, the site access control device also includes:
[0137] The hit count acquisition unit is used to acquire the number of times each of the multiple site access control structures is hit within a preset time.
[0138] The structure change unit is used to retain site access control structures that have been hit more than the first threshold as high-frequency structures in the multiple site access control structures of the terminal device, and to remove site access control structures that have been hit less than the second threshold as low-frequency structures from the multiple site access control structures of the terminal device.
[0139] Optionally, each site access control structure may include one of the following actions: allow direct connection, block access, or forward to the target traffic gateway.
[0140] Optionally, each site access control structure also includes target system rules, which include supported domain names and / or ports of supported domain names; when the handling method included in the target control structure is to allow direct connection or forward to the target traffic gateway, the access control unit 604 is specifically used for:
[0141] The site access traffic is controlled based on the handling methods, audit switch activation / deactivation information, and target system rules in the target control structure.
[0142] Optionally, the hit condition includes one or a combination of the following information:
[0143] The source address, destination address, URL information, application information initiating the site access traffic, terminal device information, or user information initiating the site access traffic are all included in the site access traffic.
[0144] Optionally, the site access control device also includes:
[0145] A traffic authentication unit is used to authenticate the site access traffic;
[0146] The traffic sending unit is used to send the site access traffic to the server when the application that initiates the site access traffic is determined to be a trusted application through authentication, so that the server can detect the site access traffic.
[0147] The ticket receiving unit is used to receive from the server the access ticket corresponding to the site access traffic and the maximum reuse time limit of the access ticket; the access ticket and the maximum reuse time limit of the access ticket are sent to the terminal device by the server after the site access traffic is detected and approved.
[0148] A traffic ticket association unit is used to associate the basic information of the site access traffic with the access ticket; the basic information includes at least: information of the application that initiated the site access traffic and information of the target system that the site access traffic needs to access.
[0149] A cache duration limit setting unit is used to set a first cache duration limit for the access ticket on the local terminal device based on the maximum reuse duration limit of the access ticket, wherein the first cache duration limit is shorter than the maximum reuse duration limit;
[0150] The ticket reuse unit is used to reuse the access ticket when the access ticket is cached locally on the terminal device for less than the first cache duration limit. If the basic information of another site access traffic initiated through the terminal device is the same as the basic information of the site access traffic, the access ticket is reused and no further authentication is performed on the other site access traffic.
[0151] Optionally, when the processing method in the target control structure is forwarding to the target traffic gateway, the access control unit 604 is specifically used for:
[0152] The access ticket and the site access traffic are encapsulated and sent to the target traffic gateway, so that the target traffic gateway requests ticket verification from the server based on the access ticket and saves the access ticket in the cache of the target traffic gateway when the access ticket verification is successful; the target traffic gateway sets a second local cache duration limit for the access ticket, which is shorter than the maximum reuse duration limit.
[0153] Optionally, if the access ticket sent to the target traffic gateway successfully hits the cache of the target traffic gateway, the target traffic gateway does not need to request ticket verification from the server based on the received access ticket; if the access ticket sent to the target traffic gateway fails to hit the cache of the target traffic gateway, the target traffic gateway needs to request ticket verification from the server based on the received access ticket.
[0154] Optionally, when the processing method in the target control structure is forwarding to the target traffic gateway, the site access control device further includes:
[0155] The virtual traffic sending unit is used to initiate a request for processing virtual access traffic to the target traffic gateway based on the basic information associated with the access ticket when the time the access ticket is cached locally on the terminal device reaches the first cache duration limit.
[0156] The notification receiving unit is configured to receive a first notification or a second notification from the target traffic gateway; the first notification is sent to the terminal device by the target traffic gateway when the handling method based on the virtual access traffic is still to forward to the target traffic gateway; the second notification is sent to the terminal device by the target traffic gateway when the handling method based on the virtual access traffic is to allow direct connection or block access.
[0157] The first ticket clearing unit is configured to clear the access ticket in the local cache according to the received first notification;
[0158] A ticket replacement unit is configured to request, based on the first notification, a new ticket to replace the access ticket;
[0159] The processing method caching unit is used to cache the processing method for the virtual access traffic determined by the target traffic gateway to the local terminal device according to the received second notification in order to deal with other traffic with the same basic information as the basic information of the virtual access traffic;
[0160] The second ticket clearing unit is used to clear the access ticket in the local cache according to the second notification.
[0161] Optionally, the site access control device also includes:
[0162] The ticket deletion unit is used to delete locally cached access tickets related to the application when it is determined that the application that initiated the access traffic to the site has been detected as having a security risk.
[0163] The interception unit is used to intercept and process the site access traffic initiated by the application when it is determined that the application initiating the site access traffic poses a security risk.
[0164] In the embodiments described above, the implementation of the site access control method and apparatus was presented from the perspective of the terminal device. As described earlier, the server also plays a crucial role. For example, the server-side application installed on the server can further inspect the site access traffic of trusted applications and, upon successful inspection, send an access ticket and its maximum reuse time limit on the terminal device to the client installed on the terminal device. The client then forwards the received access ticket and its maximum reuse time limit to the access proxy so that the access proxy can successfully obtain the ticket. Furthermore, the server can also verify the access ticket provided by the traffic gateway and grant authorization.
[0165] In this embodiment, the server can be installed on the same server as the traffic gateway, or it can be located on a different server. When the traffic gateway acts as the target traffic gateway for handling site access traffic, it needs to receive site access traffic and access tickets provided by the terminal access proxy. If the access ticket is not found in the local cache, it sends the access ticket to the server to request ticket verification. For tickets not found in the local cache, if the server verification passes, the traffic gateway needs to cache them locally for later reuse.
[0166] Furthermore, the server can also perform auditing operations on traffic access control for specific sites. Whether or not auditing is performed depends on the on / off information of the audit switch in the target control structure of the site access traffic provided by the terminal device.
[0167] It should be noted that, in the implementation scenario of this application, the number and type of traffic gateways can be configured according to actual needs. For example, in the configured site access control policy, access requests for entertainment sites are handled by the first traffic gateway, and access requests for news sites are handled by the second traffic gateway; access requests for sites in city A are handled by the third traffic gateway, and access requests for sites in city B are handled by the fourth traffic gateway.
[0168] The structure of site access control equipment will be described below for both server-based and terminal-based configurations.
[0169] Figure 7This is a schematic diagram of a server structure provided in an embodiment of this application. The server 900 can vary significantly due to different configurations or performance. It may include one or more central processing units (CPUs) 922 (e.g., one or more processors) and memory 932, and one or more storage media 930 (e.g., one or more mass storage devices) for storing application programs 942 or data 944. The memory 932 and storage media 930 can be temporary or persistent storage. The program stored in the storage media 930 may include one or more modules (not shown in the diagram), each module may include a series of instruction operations on the server. Furthermore, the CPU 922 may be configured to communicate with the storage media 930 and execute the series of instruction operations in the storage media 930 on the server 900.
[0170] Server 900 may also include one or more power supplies 926, one or more wired or wireless network interfaces 950, one or more input / output interfaces 958, and / or one or more operating systems 941, such as Windows Server. TM Mac OS X TM Unix TM Linux TM FreeBSD TM etc.
[0171] The steps performed by the server in the above embodiments can be based on this Figure 7 The server structure shown.
[0172] CPU 922 is used to perform the following steps:
[0173] Further inspection of site access traffic for trusted applications, and upon successful inspection, sending an access ticket and its maximum reuse time limit on the terminal device to the client installed on the terminal device;
[0174] Verify the access ticket provided by the traffic gateway and provide the verification result of the ticket to the traffic gateway;
[0175] And / or,
[0176] Receive site access traffic and access tickets provided by the terminal access agent, and send the access ticket to the server to request the server to perform ticket verification when the access ticket is not found in the local cache;
[0177] Receive the verification result from the server;
[0178] For tickets that are not cached locally, if the server-side verification passes, the traffic gateway needs to cache them locally for later reuse.
[0179] This application also provides another site access control device, such as... Figure 8 As shown, for ease of explanation, only the parts related to the embodiments of this application are shown. For specific technical details not disclosed, please refer to the method section of the embodiments of this application. The terminal can be any terminal device including mobile phones, tablets, personal digital assistants (PDAs), point-of-sale (POS) terminals, in-vehicle computers, etc. Taking a mobile phone as an example:
[0180] Figure 8 This is a block diagram illustrating a portion of the structure of a mobile phone related to the terminal provided in the embodiments of this application. (Reference) Figure 8 The mobile phone includes: a radio frequency (RF) circuit 1010, a memory 1020, an input unit 1030, a display unit 1040, a sensor 1050, an audio circuit 1060, a wireless fidelity (WiFi) module 1070, a processor 1080, and a power supply 1090, etc. Those skilled in the art will understand that... Figure 8 The mobile phone structure shown does not constitute a limitation on the mobile phone and may include more or fewer components than shown, or combine certain components, or have different component arrangements.
[0181] The following is combined with Figure 8 A detailed introduction to each component of a mobile phone:
[0182] The RF circuit 1010 can be used for receiving and transmitting signals during information transmission or calls. Specifically, it receives downlink information from the base station and processes it with the processor 1080; additionally, it transmits uplink data to the base station. Typically, the RF circuit 1010 includes, but is not limited to, an antenna, at least one amplifier, a transceiver, a coupler, a low-noise amplifier (LNA), a duplexer, etc. Furthermore, the RF circuit 1010 can also communicate wirelessly with networks and other devices. The aforementioned wireless communications may use any communication standard or protocol, including but not limited to Global System for Mobile Communications (GSM), General Packet Radio Service (GPRS), Code Division Multiple Access (CDMA), Wideband Code Division Multiple Access (WCDMA), Long Term Evolution (LTE), email, and Short Messaging Service (SMS).
[0183] The memory 1020 can be used to store software programs and modules. The processor 1080 executes various mobile phone functions and data processing by running the software programs and modules stored in the memory 1020. The memory 1020 may mainly include a program storage area and a data storage area. The program storage area may store the operating system, applications required for at least one function (such as sound playback function, image playback function, etc.), etc.; the data storage area may store data created according to the use of the mobile phone (such as audio data, phonebook, etc.). In addition, the memory 1020 may include high-speed random access memory, and may also include non-volatile memory, such as at least one disk storage device, flash memory device, or other volatile solid-state storage device.
[0184] The input unit 1030 can be used to receive input numerical or character information, and to generate key signal inputs related to user settings and function control of the mobile phone. Specifically, the input unit 1030 may include a touch panel 1031 and other input devices 1032. The touch panel 1031, also known as a touch screen, can collect touch operations performed by the user on or near it (such as operations performed by the user using a finger, stylus, or any suitable object or accessory on or near the touch panel 1031), and drive the corresponding connection devices according to a pre-set program. Optionally, the touch panel 1031 may include two parts: a touch detection device and a touch controller. The touch detection device detects the user's touch position and the signal generated by the touch operation, and transmits the signal to the touch controller; the touch controller receives touch information from the touch detection device, converts it into touch point coordinates, and sends it to the processor 1080, and can also receive and execute commands sent by the processor 1080. In addition, the touch panel 1031 can be implemented using various types such as resistive, capacitive, infrared, and surface acoustic wave. In addition to the touch panel 1031, the input unit 1030 may also include other input devices 1032. Specifically, other input devices 1032 may include, but are not limited to, one or more of the following: physical keyboard, function keys (such as volume control buttons, power buttons, etc.), trackball, mouse, joystick, etc.
[0185] The display unit 1040 can be used to display information input by the user or information provided to the user, as well as various menus of the mobile phone. The display unit 1040 may include a display panel 1041, which may optionally be configured as a Liquid Crystal Display (LCD), Organic Light-Emitting Diode (OLED), or similar display panel 1041. Further, a touch panel 1031 may cover the display panel 1041. When the touch panel 1031 detects a touch operation on or near it, it transmits the information to the processor 1080 to determine the type of touch event. Subsequently, the processor 1080 provides corresponding visual output on the display panel 1041 according to the type of touch event. Although in Figure 8 In this embodiment, the touch panel 1031 and the display panel 1041 are two separate components to realize the input and output functions of the mobile phone. However, in some embodiments, the touch panel 1031 and the display panel 1041 can be integrated to realize the input and output functions of the mobile phone.
[0186] The mobile phone may also include at least one sensor 1050, such as a light sensor, a motion sensor, and other sensors. Specifically, the light sensor may include an ambient light sensor and a proximity sensor. The ambient light sensor can adjust the brightness of the display panel 1041 according to the ambient light level, and the proximity sensor can turn off the display panel 1041 and / or the backlight when the phone is moved to the ear. As a type of motion sensor, an accelerometer sensor can detect the magnitude of acceleration in various directions (generally three axes). When stationary, it can detect the magnitude and direction of gravity and can be used for applications that recognize the phone's posture (such as landscape / portrait switching, related games, magnetometer posture calibration), vibration recognition-related functions (such as pedometer, taps), etc. Other sensors that may be configured in the mobile phone, such as gyroscopes, barometers, hygrometers, thermometers, and infrared sensors, will not be described in detail here.
[0187] The audio circuit 1060, speaker 1061, and microphone 1062 provide an audio interface between the user and the mobile phone. The audio circuit 1060 converts the received audio data into electrical signals and transmits them to the speaker 1061, where the speaker 1061 converts them into sound signals for output. On the other hand, the microphone 1062 converts the collected sound signals into electrical signals, which are then received by the audio circuit 1060, converted into audio data, and then processed by the processor 1080 before being transmitted via the RF circuit 1010 to, for example, another mobile phone, or the audio data can be output to the memory 1020 for further processing.
[0188] WiFi is a short-range wireless transmission technology. Through the WiFi module 1070, mobile phones can help users send and receive emails, browse web pages, and access streaming media, providing users with wireless broadband internet access. Although Figure 8 The WiFi module 1070 is shown, but it is understood that it is not an essential component of a mobile phone and can be omitted as needed without changing the essence of the invention.
[0189] The processor 1080 is the control center of the mobile phone, connecting various parts of the phone through various interfaces and lines. It executes software programs and / or modules stored in the memory 1020 and calls data stored in the memory 1020 to perform various functions and process data, thereby collecting overall data and information from the phone. Optionally, the processor 1080 may include one or more processing units; preferably, the processor 1080 may integrate an application processor and a modem processor, wherein the application processor mainly handles the operating system, user interface, and applications, and the modem processor mainly handles wireless communication. It is understood that the modem processor may not be integrated into the processor 1080.
[0190] The mobile phone also includes a power supply 1090 (such as a battery) that supplies power to various components. Preferably, the power supply can be logically connected to the processor 1080 through a power management system, thereby enabling functions such as charging, discharging, and power consumption management through the power management system.
[0191] Although not shown, mobile phones may also include a camera, Bluetooth module, etc., which will not be described in detail here.
[0192] In this embodiment of the application, the processor 1080 included in the terminal also has the following functions:
[0193] Receive site access control policies issued by the server;
[0194] Based on the site access control policy and the access control elements of the terminal device, multiple site access control structures of the terminal device are generated; wherein, each site access control structure includes at least priority, hit conditions, handling method and audit switch opening / closing information;
[0195] When a site access traffic is initiated through the terminal device, the site access control structure that the site access traffic hits first is determined as the target control structure in descending order of priority among the multiple site access control structures.
[0196] The site access traffic is controlled based on the handling methods and the on / off information of the audit switch in the target control structure.
[0197] This application also provides a computer-readable storage medium for storing program code that executes any one of the implementation methods of the site access control method described in the foregoing embodiments.
[0198] This application also provides a computer program product including instructions that, when run on a computer, cause the computer to execute any one of the implementation methods of a site access control method described in the foregoing embodiments.
[0199] Those skilled in the art will understand that, for the sake of convenience and brevity, the specific working process of the system and equipment described above can be referred to the corresponding process in the foregoing method embodiments, and will not be repeated here.
[0200] In the several embodiments provided in this application, it should be understood that the disclosed systems and methods can be implemented in other ways. For example, the system embodiments described above are merely illustrative. For instance, the division of the system is only a logical functional division, and in actual implementation, there may be other division methods. For example, multiple systems may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the coupling or direct coupling or communication connection shown or discussed may be an indirect coupling or communication connection through some interfaces, devices, or units, and may be electrical, mechanical, or other forms.
[0201] The system described as separate components may or may not be physically separate. Components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple network units. Some or all of the units can be selected to achieve the purpose of this embodiment, depending on actual needs.
[0202] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0203] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes: USB flash drives, portable hard drives, read-only memory (ROM), random access memory (RAM), magnetic disks, optical disks, and other media capable of storing program code.
[0204] The above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the spirit and scope of the technical solutions of the embodiments of this application.
Claims
1. A site access control method, characterized in that, Applied to a terminal device, the method includes: Receive site access control policies issued by the server; Based on the site access control policy and the access control elements of the terminal device, multiple site access control structures of the terminal device are generated; wherein, each site access control structure includes at least priority, hit conditions, handling method and audit switch opening / closing information; When a site access traffic is initiated through the terminal device, the site access control structure that the site access traffic hits first is determined as the target control structure in descending order of priority among the multiple site access control structures. Based on the handling methods and the on / off information of the audit switch in the target control structure, the site access traffic is controlled; Authentication is performed on the access traffic to the aforementioned site; When the application that initiated the site access traffic is determined to be a trusted application through authentication, the site access traffic is sent to the server so that the server can detect the site access traffic; The server receives the access ticket corresponding to the site access traffic and the maximum reuse time limit of the access ticket; the access ticket and the maximum reuse time limit of the access ticket are sent to the terminal device by the server after the site access traffic is detected and approved. Associate the basic information of the site access traffic with the access ticket; the basic information includes at least: information about the application that initiated the site access traffic and information about the target system that the site access traffic needs to access. Based on the maximum reuse duration limit of the access ticket, a first cache duration limit of the access ticket is set locally on the terminal device, and the first cache duration limit is shorter than the maximum reuse duration limit; If the access ticket is cached locally on the terminal device for less than the first cache duration limit, and the basic information of another site access traffic initiated through the terminal device is the same as the basic information of the site access traffic, then the access ticket is reused and the other site access traffic is no longer authenticated.
2. The method according to claim 1, characterized in that, The method of generating a multi-site access control structure for the terminal device based on the site access control policy and the access control elements of the terminal device includes: Determine the current security attributes and network location of the terminal device; The terminal device generates multiple site access control structures based on the security attributes, network location, and site access control policies.
3. The method according to claim 1, characterized in that, Also includes: Get the number of times each of the multiple site access control structures is hit within a preset time period; Site access control structures that hit more than the first threshold number are retained as high-frequency structures in the multiple site access control structures of the terminal device, while site access control structures that hit less than the second threshold number are removed as low-frequency structures from the multiple site access control structures of the terminal device.
4. The method according to claim 1, characterized in that, Each site access control structure includes one of the following handling methods: Allow direct connection, block access, or forward traffic to the target traffic gateway.
5. The method according to claim 4, characterized in that, Each site access control structure also includes target system rules, which include the domain names that support access and / or the ports of the domain names that support access; When the target control structure includes a handling method that allows direct connection or forwarding to the target traffic gateway, the control of the site access traffic based on the handling method and the on / off information of the audit switch in the target control structure specifically includes: The site access traffic is controlled based on the handling methods, audit switch activation / deactivation information, and target system rules in the target control structure.
6. The method according to claim 1, characterized in that, The hit conditions include one or a combination of the following information: The source address, destination address, URL information, application information initiating the site access traffic, terminal device information, or user information initiating the site access traffic are all included in the site access traffic.
7. The method according to claim 1, characterized in that, When the processing method in the target control structure is forwarding to the target traffic gateway, the control of the site access traffic specifically includes: The access ticket and the site access traffic are encapsulated and sent to the target traffic gateway, so that the target traffic gateway requests ticket verification from the server based on the access ticket and saves the access ticket in the cache of the target traffic gateway when the access ticket verification is successful; the target traffic gateway sets a second local cache duration limit for the access ticket, which is shorter than the maximum reuse duration limit.
8. The method according to claim 7, characterized in that, Also includes: If the access ticket sent to the target traffic gateway successfully hits the target traffic gateway's cache, the target traffic gateway does not need to request ticket verification from the server based on the received access ticket. If the access ticket sent to the target traffic gateway fails to hit the target traffic gateway's cache, the target traffic gateway needs to request ticket verification from the server based on the received access ticket.
9. The method according to claim 1, characterized in that, When the handling method in the target control structure is forwarding to the target traffic gateway, the method further includes: When the access ticket is cached locally on the terminal device for the first cache duration limit, a request to process the virtual access traffic is initiated to the target traffic gateway based on the basic information associated with the access ticket. Receive a first notification or a second notification from the target traffic gateway; the first notification is sent to the terminal device by the target traffic gateway when the handling method based on the virtual access traffic is still to forward to the target traffic gateway; the second notification is sent to the terminal device by the target traffic gateway when the handling method based on the virtual access traffic is to allow direct connection or block access. According to the first notification received, the locally cached access ticket is cleared, and a new ticket to replace the access ticket is requested; or, according to the second notification received, the handling method for the virtual access traffic determined by the target traffic gateway is cached locally on the terminal device to deal with other traffic with the same basic information as the virtual access traffic, and the locally cached access ticket is cleared.
10. The method according to claim 1, characterized in that, Also includes: When it is determined that the application initiating the site access traffic poses a security risk, the locally cached access tickets related to the application are deleted, and the site access traffic initiated by the application is intercepted and processed.
11. A site access control device, characterized in that, include: The access control policy receiving unit is used to receive site access control policies issued by the server. The control structure generation unit is used to generate multiple site access control structures for the terminal device based on the site access control policy and the access control elements of the terminal device; wherein each site access control structure includes at least priority, hit conditions, handling method and audit switch opening and closing information; The target control structure determination unit is used to determine, when the terminal device initiates site access traffic, the site access control structure that the site access traffic hits first in order of priority from high to low among the multiple site access control structures as the target control structure. The access control unit is used to control the site access traffic according to the handling method and the opening / closing information of the audit switch in the target control structure; The site access control device also includes: A traffic authentication unit is used to authenticate the site access traffic; The traffic sending unit is used to send the site access traffic to the server when the application that initiates the site access traffic is determined to be a trusted application through authentication, so that the server can detect the site access traffic. The ticket receiving unit is used to receive from the server the access ticket corresponding to the site access traffic and the maximum reuse time limit of the access ticket; the access ticket and the maximum reuse time limit of the access ticket are sent to the terminal device by the server after the site access traffic is detected and approved. A traffic ticket association unit is used to associate the basic information of the site access traffic with the access ticket; the basic information includes at least: information of the application that initiated the site access traffic and information of the target system that the site access traffic needs to access. A cache duration limit setting unit is used to set a first cache duration limit for the access ticket on the local terminal device based on the maximum reuse duration limit of the access ticket, wherein the first cache duration limit is shorter than the maximum reuse duration limit; The ticket reuse unit is used to reuse the access ticket when the access ticket is cached locally on the terminal device for less than the first cache duration limit. If the basic information of another site access traffic initiated through the terminal device is the same as the basic information of the site access traffic, the access ticket is reused and no further authentication is performed on the other site access traffic.
12. The apparatus according to claim 11, characterized in that, The control structure generation unit is specifically used for: Determine the current security attributes and network location of the terminal device; The terminal device generates multiple site access control structures based on the security attributes, network location, and site access control policies.
13. The apparatus according to claim 11, characterized in that, The site access control device also includes: The hit count acquisition unit is used to acquire the number of times each of the multiple site access control structures is hit within a preset time. The structure change unit is used to retain site access control structures that have been hit more than the first threshold as high-frequency structures in the multiple site access control structures of the terminal device, and to remove site access control structures that have been hit less than the second threshold as low-frequency structures from the multiple site access control structures of the terminal device.
14. The apparatus according to claim 11, characterized in that, Each site access control structure includes one of the following handling methods: allow direct connection, block access, or forward to the target traffic gateway.
15. The apparatus according to claim 14, characterized in that, Each site access control structure also includes target system rules, which include supported domain names and / or ports for the supported domain names; when the handling method included in the target control structure is to allow direct connection or forward to the target traffic gateway, the access control unit is specifically used for: The site access traffic is controlled based on the handling methods, audit switch activation / deactivation information, and target system rules in the target control structure.
16. A site access control device, characterized in that, The site access control device includes a processor and a memory: The memory is used to store program code and transmit the program code to the processor; The processor is configured to execute the steps of the site access control method according to any one of claims 1 to 10, based on the instructions in the program code.
17. A computer-readable storage medium, characterized in that, The computer-readable storage medium is used to store program code for performing the steps of the site access control method according to any one of claims 1 to 10.
18. A computer program product, characterized in that, Includes a computer program or instructions that, when executed by an interactive device, implement the steps of the site access control method according to any one of claims 1 to 10.
Citation Information
Patent Citations
Method and device for controlling user URL (uniform resource locator) access
CN102724189A
Terminal permission setting method and device, electronic equipment and storage medium
CN112149159A