Network access method and device, computer equipment and storage medium

By receiving the access domain name entered by the user, calling the load balancer of the target network environment, using the DNS server to resolve to a virtual IP address, filtering the target server, and processing access requests based on the authentication and access control policies, the problem that traditional security means cannot meet the security of the open system in the internal and external networks is solved, and higher network access security and availability are achieved.

CN120498752APending Publication Date: 2025-08-15HUNAN DATA IND GRP CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510620817.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-14
Publication Date
2025-08-15

AI Technical Summary

Technical Problem

Traditional network isolation or simple security protection methods are difficult to meet the security needs of comprehensive internal and external network open systems, resulting in low security of network access.

Method used

By receiving the access domain name entered by the user, calling the load balancer of the target network environment, resolving it to a virtual IP address using the DNS server, filtering the target server, and processing access requests based on authentication and access control policies.

Benefits of technology

It improves the security and availability of network access and ensures the stable operation of the system in the open environment of the internal and external networks.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120498752A_ABST
    Figure CN120498752A_ABST
Patent Text Reader

Abstract

The invention belongs to the technical field of computers, and relates to a network access method and device, computer equipment and a storage medium, and the method comprises the steps: receiving an access domain name input by a user in a target network environment; calling a target load balancer corresponding to the target network environment; analyzing the access domain name into a virtual I P address of the target load balancer based on a preset DNS server, and returning the virtual I P address to the user; receiving an access request sent by a user to the virtual IP address; based on the target load balancer, screening out a target server from a plurality of servers corresponding to the target network environment, and distributing the access request to the target server; based on the target server, performing identity verification on the user by using a preset identity verification strategy; and if the user passes the identity verification, performing corresponding response processing on the access request based on a preset access control strategy. According to the network access processing method provided by the invention, the security and availability of network access can be effectively improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology and can be applied to fields such as financial technology and digital medicine, and in particular to network access methods, devices, computer equipment and storage media. Background Art

[0002] In today's digital age, enterprise data security is paramount. To safeguard core data, many companies implement network isolation measures, dividing their networks into an extranet and an intranet. Physical isolation blocks direct connections between the extranet and the intranet, preventing external network attacks, data leaks, and other security threats from directly invading core intranet systems. This ensures the confidentiality, integrity, and availability of critical data and business systems.

[0003] However, with the diversification of enterprise businesses and the growing demand for digital collaborative office work, some business systems need to fully open up their intranets and extranets to support efficient data exchange and business collaboration between intranet employees and extranet partners and customers. However, fully open intranet and extranet systems break the security barriers provided by traditional network isolation, exposing systems to more complex and severe security challenges, such as significantly increased risks of external malicious attacks, unauthorized data access, and sensitive information leakage.

[0004] In this context, traditional single-network isolation or simple security protection methods are no longer able to meet the security requirements of fully open systems with both internal and external networks, resulting in low network access security. Therefore, a more secure and efficient deployment solution is urgently needed. While ensuring full system openness within both internal and external networks, it can also effectively defend against various security threats, ensure the security and confidentiality of enterprise data in an open environment, and promote the stable and sustainable development of enterprise business in a secure environment. Summary of the Invention

[0005] The purpose of the embodiments of the present application is to propose a network access method, apparatus, computer equipment and storage medium to solve the technical problem that the existing traditional single network isolation or simple security protection means are difficult to meet the security requirements of the fully open internal and external network systems, resulting in low security of network access of the fully open internal and external network systems.

[0006] In a first aspect, a network access method is provided, comprising:

[0007] Receiving an access domain name entered by a user in a target network environment; wherein the target network environment includes an intranet environment or an extranet environment;

[0008] Invoking a target load balancer corresponding to the target network environment;

[0009] Resolving the access domain name into the virtual IP address of the target load balancer based on a preset DNS server, and returning the virtual IP address to the user;

[0010] receiving an access request sent by the user to the virtual IP address;

[0011] Based on the target load balancer, a target server is selected from a plurality of servers corresponding to the target network environment, and the access request is distributed to the target server;

[0012] authenticating the user using a preset authentication policy based on the target server;

[0013] If the user passes the identity authentication, the access request is responded to accordingly based on the preset access control policy.

[0014] In a second aspect, a network access device is provided, comprising:

[0015] A first receiving module is configured to receive an access domain name input by a user in a target network environment; wherein the target network environment includes an intranet environment or an extranet environment;

[0016] A first calling module, configured to call a target load balancer corresponding to the target network environment;

[0017] A return module, configured to resolve the access domain name into a virtual IP address of the target load balancer based on a preset DNS server, and return the virtual IP address to the user;

[0018] A second receiving module is used to receive an access request sent by the user to the virtual IP address;

[0019] a processing module, configured to screen out a target server from a plurality of servers corresponding to the target network environment based on the target load balancer, and distribute the access request to the target server;

[0020] A verification module, configured to authenticate the user based on the target server using a preset authentication strategy;

[0021] The response module is used to perform corresponding response processing on the access request based on a preset access control policy if the user passes the identity authentication.

[0022] In a third aspect, a computer device is provided, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above-mentioned network access method when executing the computer program.

[0023] In a fourth aspect, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the above-mentioned network access method are implemented.

[0024] In the scheme implemented by the above-mentioned network access method, device, computer equipment and storage medium, the access domain name entered by the user in the target network environment is first received; wherein the target network environment includes an intranet environment or an extranet environment; then the target load balancer corresponding to the target network environment is called; thereafter, based on the preset DNS server, the access domain name is resolved into the virtual IP address of the target load balancer, and the virtual IP address is returned to the user; subsequently, an access request sent by the user to the virtual IP address is received; further based on the target load balancer, the target server is screened out from multiple servers corresponding to the target network environment, and the access request is assigned to the target server; and based on the target server, the user is authenticated using a preset authentication policy; if the user passes the authentication, the access request is responded to accordingly based on the preset access control policy. When this application receives the access domain name entered by the user in the target network environment, it will resolve the access domain name into the virtual IP address of the called target load balancer based on the use of the DNS server, and return the virtual IP address to the user, and then receive the access request sent by the user to the virtual IP address. After that, based on the use of the target load balancer, the target server is screened out from multiple servers corresponding to the target network environment, and the access request is assigned to the target server. Then, based on the target server, the user is authenticated using the preset authentication policy, and when it is detected that the user has passed the authentication, the access request is responded to accordingly based on the use of the access control policy. Through the above comprehensive network access processing process, combined with the use of technical means such as dynamic DNS resolution, load balancing, authentication and access control, the security and availability of network access can be effectively improved, and the stable operation of the system in an open environment of internal and external networks can be guaranteed. BRIEF DESCRIPTION OF THE DRAWINGS

[0025] In order to more clearly illustrate the solutions in this application, a brief introduction will be given below to the drawings required for use in the description of the embodiments of this application. Obviously, the drawings described below are some embodiments of this application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.

[0026] Figure 1 is an exemplary system architecture diagram to which the present application may be applied;

[0027] Figure 2is a flow chart of an embodiment of a network access method according to the present application;

[0028] Figure 3 is a structural diagram of an embodiment of a network access device according to the present application;

[0029] Figure 4 It is a structural diagram of an embodiment of a computer device according to the present application. DETAILED DESCRIPTION

[0030] Unless otherwise defined, all technical and scientific terms used herein have the same meanings as commonly understood by those skilled in the art to which this application belongs. The terms used in the specification of the application are for the purpose of describing specific embodiments only and are not intended to limit this application. The terms "including" and "having" and any variations thereof in the specification and claims of this application and the above-mentioned drawings are intended to cover non-exclusive inclusions. The terms "first", "second", etc. in the specification and claims of this application or the above-mentioned drawings are used to distinguish different objects, not to describe a specific order.

[0031] References herein to "embodiments" mean that a particular feature, structure, or characteristic described in connection with the embodiments may be included in at least one embodiment of the present application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it constitute an independent or alternative embodiment that is mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described herein may be combined with other embodiments.

[0032] In order to enable those skilled in the art to better understand the solution of the present application, the technical solution in the embodiments of the present application will be clearly and completely described below in conjunction with the accompanying drawings.

[0033] like Figure 1 As shown, system architecture 100 may include a terminal device 101, a network 102, and a server 103. Terminal device 101 may be a laptop computer 1011, a tablet computer 1012, or a mobile phone 1013. Network 102 is a medium for providing a communication link between terminal device 101 and server 103. Network 102 may include various connection types, such as wired or wireless communication links or fiber optic cables.

[0034] The user can use the terminal device 101 to interact with the server 103 via the network 102 to receive or send messages, etc. Various communication client applications can be installed on the terminal device 101, such as web browser applications, shopping applications, search applications, instant messaging tools, email clients, social platform software, etc.

[0035] The terminal device 101 can be various electronic devices with a display screen and supporting web browsing. In addition to the laptop computer 1011, tablet computer 1012 or mobile phone 1013, the terminal device 101 can also be an e-book reader, an MP3 player (Moving Picture Experts Group Audio Layer III), an MP4 (Moving Picture Experts Group Audio Layer IV) player, a laptop computer and a desktop computer, etc.

[0036] The server 103 may be a server that provides various services, such as a background server that provides support for web pages displayed on the terminal device 101 .

[0037] It should be noted that the network access method provided in the embodiment of the present application is generally executed by a server / terminal device, and accordingly, the network access device is generally set in the server / terminal device.

[0038] It should be understood that Figure 1 The number of terminal devices, networks and servers in the embodiment is merely illustrative. Any number of terminal devices, networks and servers may be provided as required.

[0039] Continue to refer Figure 2 , shows a flowchart of an embodiment of the network access method according to the present application. Depending on different requirements, the order of the steps in the flowchart can be changed, and some steps can be omitted. The network access method provided in the embodiment of the present application can be applied to any scenario requiring network access. The network access method includes the following steps:

[0040] Step S201: receiving an access domain name input by a user in a target network environment; wherein the target network environment includes an intranet environment or an extranet environment.

[0041] In this embodiment, the network access method is executed on the electronic device (eg Figure 1The server / terminal device shown in the figure) can obtain the access domain name entered by the user in the target network environment through a wired connection or a wireless connection. It should be pointed out that the above-mentioned wireless connection method may include but is not limited to 3G / 4G / 5G connection, WiFi connection, Bluetooth connection, WiMAX connection, Zigbee connection, UWB (Ultra Wi-Fi) connection, and other wireless connection methods currently known or to be developed in the future. The executive subject of this application is specifically a network access system, which can be referred to as the system for short. The above-mentioned target network environment includes an intranet environment or an extranet environment. If the target network environment is an intranet environment, the user is an intranet user, and if the target network environment is an extranet environment, the user is an extranet user. The above-mentioned access domain name is the domain name entered by the user on the user device according to the actual access needs, for example, it can be the procurement system domain name.

[0042] Step S202: calling a target load balancer corresponding to the target network environment.

[0043] In this embodiment, for an intranet environment, an intranet load balancer corresponding to the intranet environment will be pre-built. Similarly, for an extranet environment, an extranet load balancer corresponding to the extranet environment will be pre-built.

[0044] Step S203: Resolve the access domain name into the virtual IP address of the target load balancer based on a preset DNS server, and return the virtual IP address to the user.

[0045] In this embodiment, dynamic DNS servers are configured in both the intranet and extranet environments. For the intranet, the access domain name is dynamically bound to the virtual IP address of the intranet load balancer in advance; for the extranet, the access domain name is also dynamically bound to the public virtual IP address of the extranet load balancer. The DNS server is the target DNS server corresponding to the target network environment. Upon receiving the access domain name entered by the user in the target network environment, the DNS server resolves the access domain name into the virtual IP address of the corresponding target load balancer and returns the virtual IP address to the user's device.

[0046] Step S204: receiving an access request sent by the user to the virtual IP address.

[0047] In this embodiment, the user can use the user device to send the required access request to the virtual IP address according to actual business needs. The above access request is a request carrying address information input by the user on the user device according to actual access needs.

[0048] Step S205 : Based on the target load balancer, a target server is selected from multiple servers corresponding to the target network environment, and the access request is distributed to the target server.

[0049] In this embodiment, the above-mentioned specific implementation process of screening out the target server from multiple servers corresponding to the target network environment based on the target load balancer will be further described in detail in subsequent specific embodiments of this application and will not be elaborated on here.

[0050] Step S206: authenticating the user using a preset authentication policy based on the target server.

[0051] In this embodiment, the specific implementation process of authenticating the user based on the target server using a preset authentication strategy will be described in further detail in subsequent specific embodiments of this application and will not be elaborated on here.

[0052] Step S207: If the user passes the identity authentication, the access request is responded to accordingly based on the preset access control policy.

[0053] In this embodiment, the specific implementation process of performing corresponding response processing on the access request based on the preset access control policy will be further described in detail in subsequent specific embodiments of this application and will not be elaborated on here.

[0054] This application first receives an access domain name entered by a user in a target network environment; wherein the target network environment includes an intranet environment or an extranet environment; then calls a target load balancer corresponding to the target network environment; then resolves the access domain name into a virtual IP address of the target load balancer based on a preset DNS server, and returns the virtual IP address to the user; subsequently receives an access request sent by the user to the virtual IP address; further based on the target load balancer, filters out a target server from multiple servers corresponding to the target network environment, and distributes the access request to the target server; and based on the target server, authenticates the user using a preset authentication policy; if the user passes the authentication, performs corresponding response processing on the access request based on a preset access control policy. When this application receives the access domain name entered by the user in the target network environment, it will resolve the access domain name into the virtual IP address of the called target load balancer based on the use of the DNS server, and return the virtual IP address to the user, and then receive the access request sent by the user to the virtual IP address. After that, based on the use of the target load balancer, the target server is screened out from multiple servers corresponding to the target network environment, and the access request is assigned to the target server. Then, based on the target server, the user is authenticated using the preset authentication policy, and when it is detected that the user has passed the authentication, the access request is responded to accordingly based on the use of the access control policy. Through the above comprehensive network access processing process, combined with the use of technical means such as dynamic DNS resolution, load balancing, authentication and access control, the security and availability of network access can be effectively improved, and the stable operation of the system in an open environment of internal and external networks can be guaranteed.

[0055] In some optional implementations, step S205 includes the following steps:

[0056] Call the preset monitoring tool.

[0057] In this embodiment, there is no specific limitation on the selection of the above-mentioned monitoring tools, which can be determined according to actual business needs. For example, tools such as Zabbix and Nagi os can be used.

[0058] The monitoring tool is used to collect status information of multiple servers corresponding to the target network environment.

[0059] In this embodiment, the above-mentioned monitoring tool can be used to collect status information of multiple servers corresponding to the above-mentioned target network environment in real time. The status information includes but is not limited to: CPU usage: reflecting the computing resource usage of the server, memory usage: reflecting the memory resource usage of the server, network bandwidth: reflecting the network resource usage of the server, current number of connections: reflecting the number of requests being processed by the server, response time: reflecting the speed at which the server processes requests, and whether the server is operating normally: reflecting the availability of the server.

[0060] Get the preset load balancing algorithm.

[0061] In this embodiment, the selection of the aforementioned load balancing algorithm is not specifically limited and can be determined based on actual business needs. For example, any of round-robin, weighted round-robin, least connections, IP hash, and response time can be used. Round-robin: The load balancer sequentially distributes requests to the backend nginx servers, moving on to the next server after each request. This is suitable for scenarios with similar server performance and relatively balanced loads. Weighted round-robin: Each server is assigned a weight based on its processing power (such as CPU, memory, and bandwidth). The load balancer distributes requests to the backend nginx servers in order based on the weights. This is suitable for scenarios with uneven server performance, where servers with higher performance receive more requests. Least Connections: The load balancer monitors the current number of connections to each server in real time and distributes new requests to the server with the fewest current connections. This is suitable for scenarios with large variations in request processing times, effectively preventing overloading of certain servers. IP Hash: A hash is calculated based on the IP address of the user device, assigning requests from the same IP address to the same server. This is suitable for scenarios requiring session persistence, ensuring that user requests are always handled by the same server. Response Time: The load balancer monitors the response time of each server in real time and assigns new requests to the server with the fastest response time. This is suitable for scenarios requiring high response speed, ensuring rapid response to user requests.

[0062] Based on the target load balancer, the load balancing algorithm is used to analyze the status information of the multiple servers to filter out a designated server that meets the requirements from the multiple servers.

[0063] In this embodiment, according to the algorithm processing logic of the selected load balancing algorithm, the target load balancer may use the collected status information to filter out the optimal server from all servers, ie, the designated server.

[0064] The designated server is used as the target server.

[0065] In this embodiment, the target load balancer can also dynamically adjust request distribution strategies based on the real-time status of servers and algorithm feedback to ensure overall system performance and availability. For example, when a server is overloaded or fails, the load balancer automatically distributes requests to other healthy, less-loaded servers. Alternatively, when server performance changes, the load balancer can recalculate weights or adjust algorithm parameters to optimize request distribution.

[0066] This application calls a preset monitoring tool; and based on the monitoring tool, collects the status information of multiple servers corresponding to the target network environment; then obtains a preset load balancing algorithm; and then, based on the target load balancer, uses the load balancing algorithm to analyze the status information of the multiple servers to filter out the designated server that meets the requirements from the multiple servers; and subsequently uses the designated server as the target server. This application collects the status information of multiple servers corresponding to the target network environment based on the use of a monitoring tool; and then, based on the target load balancer, uses the load balancing algorithm to analyze the status information of multiple servers, thereby efficiently and accurately filtering out the optimal server from multiple servers and using it as the required target server, thereby effectively allocating user requests to the optimal server, which is beneficial to improving the performance and availability of the system, as well as improving user experience.

[0067] In some optional implementations of this embodiment, step S206 includes the following steps:

[0068] Password verification is performed on the user.

[0069] In this embodiment, after the access request is assigned to the target server, the system first performs password verification on the user, requiring the user to enter a username and password. The system then verifies the received username and password. If the username and password are correct for the user, the user is deemed to have passed password verification. Otherwise, the user is deemed to have failed password verification. If the user fails password verification, the user is directly deemed to have failed identity verification.

[0070] If the user passes the password verification, the user is subjected to verification code verification.

[0071] In this embodiment, after detecting that the user has passed the password verification, the user will be further subject to verification code verification. That is, after the user enters the correct username and password, the system will then send a text message verification code to the registered mobile phone number. If the user enters the correct text message verification code, the user is deemed to have passed the verification code verification; otherwise, the user is deemed to have failed the verification code verification. If the user fails the verification code verification, the user is directly deemed to have failed identity verification.

[0072] If the user passes the verification code verification, the user's biometric information verification is performed.

[0073] In this embodiment, after detecting that the user has passed the password verification and the verification code verification, the user will be further subjected to biometric information verification. Specifically, biometric information verification includes: the system calls a biometric identification device (such as a fingerprint reader, a facial recognition camera), and requires the user to perform fingerprint recognition or facial recognition verification. If it is detected that the user has passed the fingerprint recognition or facial recognition verification, it is determined that the user has passed the biometric information verification, otherwise it is determined that the user has not passed the biometric information verification. Among them, if the user has not passed the biometric information verification, it is directly determined that the user has not passed the identity authentication. In addition, by adding the authentication method of biometric information verification, the security of identity authentication is further enhanced, and the risk of account theft is reduced. Even if the attacker obtains the user's username and password, it is difficult to pass the multi-factor identity authentication.

[0074] If the user passes the biometric information verification, it is determined that the user has passed the identity authentication; otherwise, it is determined that the user has not passed the identity authentication.

[0075] In this embodiment, only when the user passes the password verification, the verification code verification and the biometric information verification at the same time, will the user be determined to have passed the identity authentication; otherwise, the user will be determined to have failed the identity authentication.

[0076] This application verifies the user's password; if the user passes the password verification, the user is then subjected to verification code verification; if the user passes the verification code verification, the user is then subjected to biometric verification; if the user passes the biometric verification, the user is determined to have passed identity authentication; otherwise, the user is determined to have failed identity authentication. This application utilizes a multi-factor authentication strategy that combines password verification, verification code verification, and biometric verification to process user identity authentication, effectively enhancing the security of identity authentication and improving the accuracy of the generated user identity authentication results.

[0077] In some optional implementations, step S207 includes the following steps:

[0078] If the target network environment is an intranet environment, identity information corresponding to the user is obtained.

[0079] In this embodiment, in an intranet environment, the user is an intranet user, and the system automatically obtains the user's identity information, including the user name or user ID.

[0080] Access permission information corresponding to the identity information is retrieved from a preset database.

[0081] In this embodiment, the database is a pre-built permissions database that stores mappings between all user identity information and access rights. Based on a user's identity information, the database can be used to retrieve the corresponding access rights. Access rights are associated with the user's role, position, and business needs. For example, roles such as system administrator and procurement specialist have different permissions.

[0082] Based on the access permission information, it is determined whether the first data corresponding to the access request is within the permission range of the user.

[0083] In this embodiment, the system filters and processes access requests from users based on the retrieved user access rights information. The system checks whether the first data (including functional modules and data) requested for access falls within its scope of authority. If the functional modules and data requested for access fall within the scope of authority, the system allows access and processes the access request. Otherwise, the system denies access and returns a corresponding error message.

[0084] If the first data is within the scope of the user's authority, the access request is responded to and processed.

[0085] In this embodiment, if it is detected that the first data is within the user's permission range, it indicates that the user has the access permission to the first data, and the access request will be responded to and processed.

[0086] If the first data is not within the scope of the user's authority, the access request is rejected and an error message is returned to the user.

[0087] In this embodiment, if it is detected that the first data is not within the user's permission range, it indicates that the user does not have the permission to access the first data, and the access request will be rejected and a corresponding error message will be returned to the user, wherein the error message may be a 403 Forbidden error.

[0088] If the present application detects that the target network environment is an intranet environment, the identity information corresponding to the user is obtained; then the access permission information corresponding to the identity information is queried from a preset database; subsequently, based on the access permission information, whether the first data corresponding to the access request is within the user's permission range is determined; if the first data is within the user's permission range, the access request is responded to and processed; and if the first data is not within the user's permission range, the access request is refused to be responded to, and an error message is returned to the user. When the present application detects that the target network environment is an intranet environment, the identity information corresponding to the user is obtained, and the access permission information corresponding to the identity information is queried from a preset database, and then, based on the access permission information, whether the first data corresponding to the access request is within the user's permission range is determined, and the access request is responded to and processed accordingly based on the obtained judgment result. Through the above processing of access requests, the present application can effectively distinguish the access permissions of intranet users, ensure that intranet users can access all functions and data required for their business, thereby helping to improve the security and controllability of the system.

[0089] In some optional implementations, step S207 includes the following steps:

[0090] If the target network environment is an external network environment, address information corresponding to the access request is obtained.

[0091] In this embodiment, in an extranet environment, the user is an extranet user, and the system extracts the URL address of the access request sent by the user to obtain corresponding address information.

[0092] Determine whether the address information is a sensitive function address.

[0093] In this embodiment, a list of URL addresses for management and sensitive functions is predefined based on actual business needs, such as / admin / and / system / config / . The address information is matched against the URL address list. If the match is successful, i.e., the address information matches a URL in the URL address list, the address information is determined to be a sensitive function address. If the match fails, i.e., the address information fails to match a URL in the URL address list, the address information is determined not to be a sensitive function address.

[0094] If the address information is a sensitive function address, the access request is rejected and an error message is returned to the user.

[0095] In this embodiment, if the address information is detected to be a sensitive function address, the system will directly return an error message (such as 403 Forbidden) and reject the user's access request.

[0096] If the address information is not a sensitive function address, it is determined whether the second data corresponding to the access request is within the scope of the user's authority.

[0097] In this embodiment, the above-mentioned processing process of determining whether the second data corresponding to the access request is within the scope of the user's authority can refer to the above-mentioned specific processing process of determining whether the first data corresponding to the access request is within the scope of the user's authority based on the access permission information, and will not be elaborated on here.

[0098] If the second data is within the scope of the user's authority, the access request is responded to and processed.

[0099] In this embodiment, if it is detected that the second data is within the user's permission range, it indicates that the user has the access permission to the second data, and the access request will be responded to and processed.

[0100] If the second data is not within the scope of the user's authority, the access request is rejected and an error message is returned to the user.

[0101] In this embodiment, if it is detected that the second data is not within the user's permission range, it indicates that the user does not have the permission to access the second data, and the access request will be rejected and a corresponding error message will be returned to the user, wherein the error message may be a 403 Forbidden error.

[0102] If the present application detects that the target network environment is an extranet environment, the address information corresponding to the access request is obtained; then it is determined whether the address information is a sensitive function address; if the address information is a sensitive function address, the access request is refused to be responded to, and an error message is returned to the user; and if the address information is not a sensitive function address, it is determined whether the second data corresponding to the access request is within the scope of authority of the user; if the second data is within the scope of authority of the user, the access request is responded to and processed; and if the second data is not within the scope of authority of the user, the access request is refused to be responded to, and an error message is returned to the user. When the present application detects that the target network environment is an extranet environment, the address information corresponding to the access request is obtained, and when the address information is detected to be a sensitive function address, the access request is directly refused to be responded to, and an error message is returned to the user. In addition, when it is detected that the address information is not a sensitive function address, it will further determine whether the second data corresponding to the access request is within the user's authority range. If it is detected that the second data is within the user's authority range, the access request will be responded to and processed. If it is detected that the second data is not within the user's authority range, the access request will be rejected and an error message will be returned to the user. Through the above processing of access requests, the present application can effectively distinguish the access rights of external network users. External network users can only access permitted non-sensitive functions and data, thereby helping to improve the security and controllability of the system.

[0103] In some optional implementations of this embodiment, after step S207, the electronic device may further perform the following steps:

[0104] Call the preset behavior analysis tool.

[0105] In this embodiment, a user behavior analysis tool is pre-built and deployed, which has the ability to monitor and analyze user behavior in real time. The behavior analysis data is configured to collect and analyze user login time, login location, operation and other data.

[0106] The user's operation behavior is collected based on the behavior analysis tool.

[0107] In this embodiment, the behavior analysis tool captures user login and operation behaviors in real time through logging, network traffic analysis, or other monitoring methods. The collected operation behaviors include, but are not limited to, login timestamps, IP addresses, geographic locations, function modules accessed, and operation frequency.

[0108] Determine whether the operation behavior deviates from a preset behavior baseline.

[0109] In this embodiment, based on the use of the aforementioned behavioral analysis tools, all collected user behavior data is statistically analyzed in advance to establish a behavioral baseline for each user. Specifically, the behavioral baseline typically includes: Login time range: recording the user's usual working hours, such as 9:00-18:00. Frequently used login locations: recording the user's frequently used IP address segments or geographic locations. Regular operation behavior patterns: recording the functional modules accessed by the user, operation frequency, etc.

[0110] The system can compare the current user's operation behavior with a pre-established behavior baseline in real time, and determine whether the operation behavior deviates from the pre-established behavior baseline based on the comparison results. For example, if a user attempts to log in during non-working hours (such as 2:00 a.m.); attempts to log in from an unusual geographical location (such as a foreign IP address); or attempts to access an infrequently accessed function module or perform an unusual operation, the operation behavior will be determined to have deviated from the behavior baseline.

[0111] If so, temporarily restrict the user's permissions.

[0112] In this embodiment, the temporary restriction includes prohibiting users from performing sensitive operations, such as modifying system configurations and deleting important data, and restricting users from accessing certain functional modules or data. The temporary restriction persists until the administrator further verifies and confirms the user's behavior.

[0113] This application calls a preset behavior analysis tool; then collects the user's operating behavior based on the behavior analysis tool; subsequently determines whether the operating behavior deviates from the preset behavior baseline; if so, temporarily restricts the user's permissions. This application collects the user's operating behavior based on the use of a behavior analysis tool, and when it detects that the operating behavior deviates from the preset behavior baseline, it automatically and intelligently temporarily restricts the user's permissions, thereby achieving the ability to effectively identify and respond to abnormal user behavior, thereby helping to enhance the security and stability of the system.

[0114] In some optional implementations of this embodiment, after the step of temporarily restricting the user's rights, the electronic device may further perform the following steps:

[0115] Generate corresponding warning information based on the operation behavior.

[0116] In this embodiment, the warning information at least includes a detailed description of the operation behavior, such as user ID, time, location, operation, and other information of the abnormal behavior.

[0117] Get the communication information of the preset administrator.

[0118] In this embodiment, the management personnel are system administrators. The communication information may include email addresses, mobile phone numbers, etc.

[0119] Call the preset communication tool.

[0120] In this embodiment, the communication tool refers to a tool corresponding to the communication information, and may include, for example, email, text messages or other instant messaging tools.

[0121] Based on the communication information, the early warning information is sent to the management personnel using the communication tool.

[0122] In this embodiment, warning information can be sent to administrators using communication tools based on their communication information. After receiving the warning information, the administrator can further verify the user's behavior. This verification can be performed by reviewing user behavior logs, communicating with the user, and other methods. If the user's behavior is confirmed to be legitimate, the administrator can manually restore the user's permissions. If the user's behavior is confirmed to be malicious, the administrator can take further security measures, such as permanently restricting permissions or banning the account.

[0123] This application generates corresponding warning information based on the operational behavior; then obtains the preset communication information of the administrator; then calls a preset communication tool; and subsequently uses the communication tool to send the warning information to the administrator based on the communication information. When this application detects that the user's operational behavior deviates from the preset behavioral baseline, it automatically generates corresponding warning information based on the operational behavior, thereby improving the efficiency of generating warning information. Subsequently, based on the obtained communication information, the warning information will be sent to the administrator using the communication tool, so that abnormal user behavior can be effectively responded to, thereby enhancing the security and stability of the system.

[0124] In some optional implementations, the user information obtained is obtained with the user's consent and complies with relevant laws and policies.

[0125] In addition, any software tools or components not provided by our company that appear in the embodiments of this application are merely examples and do not represent actual use.

[0126] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present invention.

[0127] Those skilled in the art will appreciate that all or part of the processes in the above-described method embodiments can be implemented by instructing related hardware via computer-readable instructions. The computer-readable instructions can be stored in a computer-readable storage medium, and when the program is executed, it can include the processes in the above-described method embodiments. The aforementioned storage medium can be a non-volatile storage medium such as a magnetic disk, an optical disk, a read-only memory (ROM), or a random access memory (RAM).

[0128] It should be understood that although the steps in the flowcharts of the accompanying drawings are shown in sequence as indicated by the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise specified herein, there is no strict order restriction on the execution of these steps, and they can be executed in other orders. Moreover, at least some of the steps in the flowcharts of the accompanying drawings may include multiple sub-steps or multiple stages, and these sub-steps or stages are not necessarily executed at the same time, but can be executed at different times, and their execution order is not necessarily sequential, but can be executed in turn or alternately with other steps or at least a portion of the sub-steps or stages of other steps.

[0129] Further references Figure 3 , as a response to the above Figure 2 The present application provides an embodiment of a network access device, which is similar to the embodiment of the network access device. Figure 2 Corresponding to the method embodiment shown, the device can be specifically applied to various electronic devices.

[0130] like Figure 3 As shown, the network access device 300 of this embodiment includes: a first receiving module 301, a first calling module 302, a returning module 303, a second receiving module 304, a processing module 305, a verification module 306 and a response module 307.

[0131] The first receiving module 301 is configured to receive an access domain name input by a user in a target network environment; wherein the target network environment includes an intranet environment or an extranet environment;

[0132] A first calling module 302 is configured to call a target load balancer corresponding to the target network environment;

[0133] The return module 303 is configured to resolve the access domain name into the virtual IP address of the target load balancer based on a preset DNS server, and return the virtual IP address to the user;

[0134] A second receiving module 304 is configured to receive an access request sent by the user to the virtual IP address;

[0135] The processing module 305 is configured to select a target server from multiple servers corresponding to the target network environment based on the target load balancer, and distribute the access request to the target server;

[0136] The verification module 306 is configured to authenticate the user based on the target server using a preset authentication policy;

[0137] The response module 307 is configured to perform corresponding response processing on the access request based on a preset access control policy if the user passes the identity authentication.

[0138] In this embodiment, the operations performed by the above modules or units correspond one-to-one to the steps of the network access method in the aforementioned embodiment, and are not described in detail here.

[0139] In some optional implementations of this embodiment, the processing module 305 includes:

[0140] Call submodule, used to call the preset monitoring tool;

[0141] a collection submodule, configured to collect status information of a plurality of servers corresponding to the target network environment based on the monitoring tool;

[0142] A first acquisition submodule is used to obtain a preset load balancing algorithm;

[0143] an analysis submodule, configured to analyze the status information of the plurality of servers using the load balancing algorithm based on the target load balancer, so as to select a designated server that meets the requirements from the plurality of servers;

[0144] The determination submodule is configured to use the designated server as the target server.

[0145] In this embodiment, the operations performed by the above modules or units correspond one-to-one to the steps of the network access method in the aforementioned embodiment, and are not described in detail here.

[0146] In some optional implementations of this embodiment, the verification module 306 includes:

[0147] A first verification submodule, configured to perform password verification on the user;

[0148] A second verification submodule is configured to perform verification code verification on the user if the user passes the password verification;

[0149] A third verification submodule is configured to perform biometric verification on the user if the user passes the verification code verification;

[0150] The determination submodule is configured to determine that the user has passed the identity authentication if the user has passed the biometric information verification, and otherwise determine that the user has failed the identity authentication.

[0151] In this embodiment, the operations performed by the above modules or units correspond one-to-one to the steps of the network access method in the aforementioned embodiment, and are not described in detail here.

[0152] In some optional implementations of this embodiment, the response module 307 includes:

[0153] A second acquisition submodule is configured to acquire identity information corresponding to the user if the target network environment is an intranet environment;

[0154] A query submodule, configured to query the access permission information corresponding to the identity information from a preset database;

[0155] a first judgment submodule, configured to judge, based on the access permission information, whether the first data corresponding to the access request is within the permission scope of the user;

[0156] a first processing submodule, configured to respond to the access request if the first data is within the scope of the user's authority;

[0157] The second processing submodule is configured to refuse to respond to the access request and return an error message to the user if the first data is not within the scope of the user's authority.

[0158] In this embodiment, the operations performed by the above modules or units correspond one-to-one to the steps of the network access method in the aforementioned embodiment, and are not described in detail here.

[0159] In some optional implementations of this embodiment, the response module 307 includes:

[0160] A third acquisition submodule is configured to acquire address information corresponding to the access request if the target network environment is an external network environment;

[0161] A second judgment submodule is used to judge whether the address information is a sensitive function address;

[0162] a third processing submodule, configured to refuse to respond to the access request and return an error message to the user if the address information is a sensitive function address;

[0163] a third judgment submodule, configured to, if the address information is not a sensitive function address, determine whether the second data corresponding to the access request is within the scope of the user's authority;

[0164] a fourth processing submodule, configured to respond to the access request if the second data is within the scope of the user's authority;

[0165] The fifth processing submodule is configured to refuse to respond to the access request and return an error message to the user if the second data is not within the scope of the user's authority.

[0166] In this embodiment, the operations performed by the above modules or units correspond one-to-one to the steps of the network access method in the aforementioned embodiment, and are not described in detail here.

[0167] In some optional implementations of this embodiment, the network access device further includes:

[0168] The second calling module is used to call the preset behavior analysis tool;

[0169] A collection module, configured to collect the user's operation behavior based on the behavior analysis tool;

[0170] A judgment module, used to judge whether the operation behavior deviates from a preset behavior baseline;

[0171] The restriction processing module is used to temporarily restrict the user's authority if so.

[0172] In this embodiment, the operations performed by the above modules or units correspond one-to-one to the steps of the network access method in the aforementioned embodiment, and are not described in detail here.

[0173] In some optional implementations of this embodiment, the network access device further includes:

[0174] A generation module, configured to generate corresponding warning information based on the operation behavior;

[0175] The acquisition module is used to obtain the communication information of the preset management personnel;

[0176] The third calling module is used to call the preset communication tool;

[0177] A sending module is used to send the warning information to the management personnel using the communication tool based on the communication information.

[0178] In this embodiment, the operations performed by the above modules or units correspond one-to-one to the steps of the network access method in the aforementioned embodiment, and are not described in detail here.

[0179] To solve the above technical problems, the present application also provides a computer device. Figure 4 , Figure 4 This is a basic structural block diagram of the computer device in this embodiment.

[0180] The computer device 4 includes a memory 41, a processor 42, and a network interface 43 that are interconnected through a system bus. It should be noted that the figure only shows a computer device 4 having components 41-43, but it should be understood that it is not required to implement all the components shown, and more or fewer components can be implemented instead. Among them, those skilled in the art can understand that the computer device here is a device that can automatically perform numerical calculations and / or information processing according to pre-set or stored instructions, and its hardware includes but is not limited to microprocessors, application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), digital signal processors (DSPs), embedded devices, etc.

[0181] The computer device may be a desktop computer, notebook computer, PDA, cloud server, etc. The computer device may interact with the user via a keyboard, mouse, remote control, touchpad, or voice control device.

[0182] The memory 41 includes at least one type of readable storage medium, including flash memory, hard disk, multimedia card, card-type memory (e.g., SD or DX memory), random access memory (RAM), static random access memory (SRAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), programmable read-only memory (PROM), magnetic storage, magnetic disk, optical disk, etc. In some embodiments, the memory 41 can be an internal storage unit of the computer device 4, such as the hard disk or memory of the computer device 4. In other embodiments, the memory 41 can also be an external storage device of the computer device 4, such as a plug-in hard disk equipped on the computer device 4, a smart memory card (SMC), a secure digital (SD) card, a flash memory card, etc. Of course, the memory 41 can also include both the internal storage unit of the computer device 4 and its external storage device. In this embodiment, the memory 41 is generally used to store the operating system and various application software installed on the computer device 4, such as computer-readable instructions for network access methods. In addition, the memory 41 can also be used to temporarily store various types of data that have been output or are to be output.

[0183] In some embodiments, the processor 42 may be a central processing unit (CPU), a controller, a microcontroller, a microprocessor, or other data processing chip. The processor 42 is generally used to control the overall operation of the computer device 4. In this embodiment, the processor 42 is used to execute computer-readable instructions stored in the memory 41 or process data, such as computer-readable instructions for executing the network access method.

[0184] The network interface 43 may include a wireless network interface or a wired network interface. The network interface 43 is generally used to establish a communication connection between the computer device 4 and other electronic devices.

[0185] Compared with the prior art, the embodiments of the present application have the following beneficial effects:

[0186] In an embodiment of the present application, an access domain name entered by a user in a target network environment is first received; wherein the target network environment includes an intranet environment or an extranet environment; then a target load balancer corresponding to the target network environment is called; thereafter, based on a preset DNS server, the access domain name is resolved into a virtual IP address of the target load balancer, and the virtual IP address is returned to the user; subsequently, an access request sent by the user to the virtual IP address is received; further based on the target load balancer, a target server is screened out from multiple servers corresponding to the target network environment, and the access request is assigned to the target server; and based on the target server, the user is authenticated using a preset authentication policy; if the user passes the authentication, the access request is responded to accordingly based on the preset access control policy. When this application receives the access domain name entered by the user in the target network environment, it will resolve the access domain name into the virtual IP address of the called target load balancer based on the use of the DNS server, and return the virtual IP address to the user, and then receive the access request sent by the user to the virtual IP address. After that, based on the use of the target load balancer, the target server is screened out from multiple servers corresponding to the target network environment, and the access request is assigned to the target server. Then, based on the target server, the user is authenticated using the preset authentication policy, and when it is detected that the user has passed the authentication, the access request is responded to accordingly based on the use of the access control policy. Through the above comprehensive network access processing process, combined with the use of technical means such as dynamic DNS resolution, load balancing, authentication and access control, the security and availability of network access can be effectively improved, and the stable operation of the system in an open environment of internal and external networks can be guaranteed.

[0187] The present application also provides another embodiment, namely, providing a computer-readable storage medium, wherein the computer-readable storage medium stores computer-readable instructions, and the computer-readable instructions can be executed by at least one processor to enable the at least one processor to perform the steps of the network access method as described above.

[0188] Compared with the prior art, the embodiments of the present application have the following beneficial effects:

[0189] In an embodiment of the present application, an access domain name entered by a user in a target network environment is first received; wherein the target network environment includes an intranet environment or an extranet environment; then a target load balancer corresponding to the target network environment is called; thereafter, based on a preset DNS server, the access domain name is resolved into a virtual IP address of the target load balancer, and the virtual IP address is returned to the user; subsequently, an access request sent by the user to the virtual IP address is received; further based on the target load balancer, a target server is screened out from multiple servers corresponding to the target network environment, and the access request is assigned to the target server; and based on the target server, the user is authenticated using a preset authentication policy; if the user passes the authentication, the access request is responded to accordingly based on the preset access control policy. When this application receives the access domain name entered by the user in the target network environment, it will resolve the access domain name into the virtual IP address of the called target load balancer based on the use of the DNS server, and return the virtual IP address to the user, and then receive the access request sent by the user to the virtual IP address. After that, based on the use of the target load balancer, the target server is screened out from multiple servers corresponding to the target network environment, and the access request is assigned to the target server. Then, based on the target server, the user is authenticated using the preset authentication policy, and when it is detected that the user has passed the authentication, the access request is responded to accordingly based on the use of the access control policy. Through the above comprehensive network access processing process, combined with the use of technical means such as dynamic DNS resolution, load balancing, authentication and access control, the security and availability of network access can be effectively improved, and the stable operation of the system in an open environment of internal and external networks can be guaranteed.

[0190] Through the description of the above implementation methods, those skilled in the art can clearly understand that the above-mentioned embodiment methods can be implemented by means of software plus the necessary general hardware platform, and of course can also be implemented by hardware, but in many cases the former is a better implementation method. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, can be embodied in the form of a software product, which is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk), and includes a number of instructions for enabling a terminal device (which can be a mobile phone, computer, server, air conditioner, or network device, etc.) to execute the methods described in each embodiment of the present application.

[0191] Obviously, the embodiments described above are only some of the embodiments of the present application, rather than all of the embodiments. The preferred embodiments of the present application are given in the accompanying drawings, but they do not limit the patent scope of the present application. The present application can be implemented in many different forms. On the contrary, the purpose of providing these embodiments is to make the understanding of the disclosure of the present application more thorough and comprehensive. Although the present application has been described in detail with reference to the aforementioned embodiments, for those skilled in the art, it is still possible to modify the technical solutions described in the aforementioned specific embodiments, or to make equivalent replacements for some of the technical features therein. Any equivalent structure made using the contents of the present application specification and the accompanying drawings, directly or indirectly used in other related technical fields, is also within the scope of patent protection of the present application.

Claims

1. A network access method, characterized in that: The steps include: Receiving an access domain name entered by a user in a target network environment; wherein the target network environment includes an intranet environment or an extranet environment; Invoking a target load balancer corresponding to the target network environment; Resolving the access domain name into the virtual IP address of the target load balancer based on a preset DNS server, and returning the virtual IP address to the user; receiving an access request sent by the user to the virtual IP address; Based on the target load balancer, a target server is selected from a plurality of servers corresponding to the target network environment, and the access request is distributed to the target server; authenticating the user using a preset authentication policy based on the target server; If the user passes the identity authentication, the access request is responded to accordingly based on the preset access control policy.

2. The network access method according to claim 1, wherein: The step of selecting a target server from a plurality of servers corresponding to the target network environment based on the target load balancer specifically includes: Call the preset monitoring tool; collecting status information of a plurality of servers corresponding to the target network environment based on the monitoring tool; Get the preset load balancing algorithm; Based on the target load balancer, using the load balancing algorithm to analyze the status information of the multiple servers to filter out a designated server that meets the requirements from the multiple servers; The designated server is used as the target server.

3. The network access method according to claim 1, wherein: The step of authenticating the user based on the target server using a preset authentication policy specifically includes: Performing password verification on the user; If the user passes the password verification, the user is subject to verification code verification; If the user passes the verification code, biometric information verification is performed on the user; If the user passes the biometric information verification, it is determined that the user has passed the identity authentication; otherwise, it is determined that the user has not passed the identity authentication.

4. The network access method according to claim 1, wherein: The step of performing corresponding response processing on the access request based on the preset access control policy specifically includes: If the target network environment is an intranet environment, obtaining identity information corresponding to the user; Querying access permission information corresponding to the identity information from a preset database; Based on the access permission information, determining whether the first data corresponding to the access request is within the scope of the user's permission; If the first data is within the scope of the user's authority, responding to the access request; If the first data is not within the scope of the user's authority, the access request is rejected and an error message is returned to the user.

5. The network access method according to claim 1, wherein: The step of performing corresponding response processing on the access request based on the preset access control policy specifically includes: If the target network environment is an external network environment, obtaining address information corresponding to the access request; Determining whether the address information is a sensitive function address; If the address information is a sensitive function address, refusing to respond to the access request and returning an error message to the user; If the address information is not a sensitive function address, determining whether the second data corresponding to the access request is within the scope of the user's authority; If the second data is within the scope of the user's authority, responding to the access request; If the second data is not within the scope of the user's authority, the access request is rejected and an error message is returned to the user.

6. The network access method according to claim 1, wherein: After the step of performing corresponding response processing on the access request based on the preset access control policy, the method further includes: Call the preset behavior analysis tool; Collecting the user's operating behavior based on the behavior analysis tool; Determine whether the operation behavior deviates from the preset behavior baseline; If so, temporarily restrict the user's permissions.

7. The network access method according to claim 6, characterized in that: After the step of temporarily restricting the user's rights, the method further includes: Generate corresponding warning information based on the operation behavior; Get the communication information of the preset managers; Call the preset communication tool; Based on the communication information, the early warning information is sent to the management personnel using the communication tool.

8. A network access device, characterized in that: include: A first receiving module is configured to receive an access domain name input by a user in a target network environment; wherein the target network environment includes an intranet environment or an extranet environment; A first calling module, configured to call a target load balancer corresponding to the target network environment; A return module, configured to resolve the access domain name into a virtual IP address of the target load balancer based on a preset DNS server, and return the virtual IP address to the user; A second receiving module is used to receive an access request sent by the user to the virtual IP address; a processing module, configured to screen out a target server from a plurality of servers corresponding to the target network environment based on the target load balancer, and distribute the access request to the target server; A verification module, configured to authenticate the user based on the target server using a preset authentication strategy; The response module is used to perform corresponding response processing on the access request based on a preset access control policy if the user passes the identity authentication.

9. A computer device, characterized in that: The method comprises a memory and a processor, wherein the memory stores computer-readable instructions, and the processor implements the steps of the network access method according to any one of claims 1 to 7 when executing the computer-readable instructions.

10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer-readable instructions, which, when executed by a processor, implement the steps of the network access method according to any one of claims 1 to 7.

Citation Information

Cited By

  • Information processing system, method and equipment and computer readable storage medium

    CN116389119A

  • Processing method and system for data governance

    CN120934916A