Information processing method, gateway and communication system
By establishing a TCP connection between the gateway and the user terminal and using an independent security server for identity authentication, the problem that the existing technology cannot provide security services to third-party mail clients is solved, and the security authentication and identity binding of third-party mail clients is realized, which improves the security of information processing.
Patent Information
- Application Number
- CN202210118526.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-02-08
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2042-02-08
AI Technical Summary
The prior art cannot provide security services to mail clients provided by third parties, resulting in insufficient security of identity authentication.
By establishing a TCP connection between the gateway and the user terminal, an independent security server is used to perform security authentication of identity information and terminal characteristics, ensuring the binding of identity information to the user terminal, and thus providing security services.
It realizes the provision of security authentication services for third-party email clients, improves the security of information processing, and avoids the risk of account passwords being stolen.
Smart Images

Figure CN114500066B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of information processing, and in particular to an information processing method, a gateway and a communication system. Background Art
[0002] At present, the most commonly used identity authentication method for emails is to use the email account and password for identity authentication. In order to prevent the account and password from being illegally stolen, email providers use a more secure authentication method such as MFA (Multi Factor Authentication) to perform identity authentication to improve information security. Summary of the invention
[0003] The inventors have noticed that since email providers bind authentication methods with higher security levels to their own platforms, they are unable to provide security services for email clients provided by third parties.
[0004] Accordingly, the present disclosure provides an information processing solution that can provide security services for email clients provided by third parties.
[0005] According to a first aspect of an embodiment of the present disclosure, there is provided an information processing method, which is executed by a gateway, and includes: after receiving a connection establishment request sent by a user terminal, establishing a TCP connection between the gateway and the user terminal; sending the connection establishment request to a service server so that the service server authenticates the identity information included in the connection establishment request; if an authentication success message sent by the service server is received, sending a first verification request to a security server so that the security server verifies whether the identity information included in the first verification request and the terminal characteristics of the user terminal are bound to the user terminal; if a binding success message sent by the security server is received, sending the authentication success message to the user terminal so that the user terminal interacts with the service server through the gateway.
[0006] In some embodiments, if a binding failure message sent by the security server is received, the TCP connection is closed.
[0007] In some embodiments, after receiving a binding success message sent by the security server, a timer is started, and the timer has a preset timing duration; after the timer times out, the first verification request is sent to the security server.
[0008] In some embodiments, after receiving a connection establishment request sent by the user terminal, a second verification request is sent to the security server so that the security server can determine whether there is a security risk based on the identity information and the terminal characteristics included in the second verification request; if a no security risk indication message is received from the security server, the TCP connection is established between the gateway and the user terminal.
[0009] In some embodiments, if a security risk indication message sent by the security server is received, the connection establishment request is rejected.
[0010] In some embodiments, establishing a TCP connection between the gateway and the user terminal includes: selecting a TCP connection information not used by other users from a connection pool, so as to establish a TCP connection between the gateway and the user terminal.
[0011] In some embodiments, the terminal characteristics of the user terminal include at least one of an IP address, a unique device identifier, and a user agent of the user terminal.
[0012] According to a second aspect of an embodiment of the present disclosure, a gateway is provided, comprising: a first processing module, configured to establish a TCP connection between the gateway and the user terminal after receiving a connection establishment request sent by a user terminal; a second processing module, configured to send the connection establishment request to a business server, so that the business server authenticates the identity information included in the connection establishment request; a third processing module, configured to send a first verification request to a security server if an authentication success message sent by the business server is received, so that the security server verifies whether the identity information and the terminal characteristics included in the first verification request are bound to the user terminal; a fourth processing module, configured to send the authentication success message to the user terminal if a binding success message sent by the security server is received, so that the user terminal interacts with the business server through the gateway.
[0013] According to a third aspect of an embodiment of the present disclosure, a gateway is provided, comprising: a memory configured to store instructions; a processor coupled to the memory, the processor being configured to execute a method as described in any of the above embodiments based on the instructions stored in the memory.
[0014] According to a fourth aspect of an embodiment of the present disclosure, a communication system is provided, comprising: a gateway as described in any of the above embodiments; a service server, configured to, after receiving a connection establishment request sent by the gateway, authenticate the identity information included in the connection establishment request, and send an authentication success message to the gateway after successful authentication; a security server, configured to, after receiving a first verification request sent by the gateway, verify whether the identity information and terminal characteristics of the user terminal included in the first verification request are bound to the user terminal, and if the identity information and the terminal characteristics are successfully bound to the user terminal, send a binding success message to the gateway.
[0015] In some embodiments, if the identity information and the terminal characteristics are not successfully bound to the user terminal, the security server is configured to send a binding failure message to the gateway, perform security authentication on the user terminal, bind the identity information and the terminal characteristics to the user terminal after the security authentication is passed, and send a connection indication to the user terminal so that the user terminal re-sends a connection establishment request to the gateway.
[0016] In some embodiments, the security authentication is a multi-factor authentication.
[0017] In some embodiments, after receiving a second verification request sent by the gateway, the security server is configured to determine whether there is a security risk based on the identity information and the terminal characteristics included in the second verification request; if the identity information and the terminal characteristics do not pose a security risk, a no security risk indication message is sent to the gateway.
[0018] In some embodiments, the security server is configured to send a security risk indication message to the gateway if the identity information or the terminal feature has a security risk.
[0019] According to a fifth aspect of an embodiment of the present disclosure, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores computer instructions, and when the instructions are executed by a processor, the method involved in any of the above embodiments is implemented.
[0020] Other features and advantages of the present disclosure will become apparent from the following detailed description of exemplary embodiments of the present disclosure with reference to the accompanying drawings. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] In order to more clearly illustrate the embodiments of the present disclosure or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present disclosure. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.
[0022] Figure 1 A flowchart of an information processing method according to an embodiment of the present disclosure;
[0023] Figure 2 A schematic diagram of the structure of a gateway according to an embodiment of the present disclosure;
[0024] Figure 3 A schematic diagram of the structure of a gateway according to another embodiment of the present disclosure;
[0025] Figure 4 The present invention is a schematic diagram of the structure of a communication system according to an embodiment of the present invention. DETAILED DESCRIPTION
[0026] The following will be combined with the drawings in the embodiments of the present disclosure to clearly and completely describe the technical solutions in the embodiments of the present disclosure. Obviously, the described embodiments are only part of the embodiments of the present disclosure, rather than all of the embodiments. The following description of at least one exemplary embodiment is actually only illustrative and is by no means intended to limit the present disclosure and its application or use. Based on the embodiments in the present disclosure, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present disclosure.
[0027] Unless specifically stated otherwise, the relative arrangement of components and steps, the numerical expressions and numerical values set forth in these embodiments do not limit the scope of the present disclosure.
[0028] At the same time, it should be understood that for the convenience of description, the sizes of the various parts shown in the drawings are not drawn according to the actual proportional relationship.
[0029] Technologies, methods, and apparatus known to ordinary technicians in the relevant field may not be discussed in detail, but where appropriate, such technologies, methods, and apparatus should be considered part of the authorization specification.
[0030] In all examples shown and discussed herein, any specific values should be interpreted as merely exemplary and not as limiting. Therefore, other examples of the exemplary embodiments may have different values.
[0031] It should be noted that like reference numerals and letters refer to similar items in the following figures, and therefore, once an item is defined in one figure, it need not be further discussed in subsequent figures.
[0032] Figure 1 The following is a flow chart of an information processing method according to an embodiment of the present disclosure. In some embodiments, the following information processing method is executed by a gateway.
[0033] In step 101, after receiving a connection establishment request sent by a user terminal, a TCP (Transmission Control Protocol) connection is established between the gateway and the user terminal.
[0034] In some embodiments, after receiving the connection establishment request sent by the user terminal, the gateway sends the second verification request to the security server so that the security server can determine whether there is a security risk based on the identity information and terminal features included in the second verification request. In this way, illegal requests such as brute force cracking, database collision, and malicious IP can be filtered out. If a no security risk indication message sent by the security server is received, a TCP connection is established between the gateway and the user terminal.
[0035] In some embodiments, the terminal characteristics of the user terminal include at least one of an IP address, a unique device identifier, and a user agent of the user terminal.
[0036] In some embodiments, the gateway selects a TCP connection information that is not used by other users from the connection pool to establish a TCP connection between the gateway and the user terminal, thereby effectively avoiding information leakage caused by different users using the same TCP connection.
[0037] In some embodiments, if a security risk indication message sent by a security server is received, the connection establishment request is rejected, so as to effectively reject the request with security risk.
[0038] In some embodiments, the gateway is a mail gateway. After receiving the connection establishment request, the mail gateway performs protocol analysis on the connection establishment request to determine the mail protocol used and extract relevant identity information, such as account information.
[0039] In step 102, a connection establishment request is sent to a service server so that the service server authenticates the identity information included in the connection establishment request.
[0040] In some embodiments, after receiving the connection establishment request sent by the gateway, the service server authenticates the identity information included in the connection establishment request, and sends an authentication success message to the gateway after the authentication succeeds.
[0041] In some embodiments, the business server is a mail server.
[0042] In step 103, if the authentication success message sent by the service server is received, the first verification request is sent to the security server so that the security server verifies whether the identity information and the terminal characteristics of the user terminal included in the first verification request are bound to the user terminal.
[0043] It should be noted here that, since the security server is set up separately from the business server, the security server can provide security services for the mail client provided by the third party.
[0044] In step 104, if a binding success message is received from the security server, an authentication success message is sent to the user terminal so that the user terminal interacts with the service server through the gateway.
[0045] In some embodiments, if the gateway receives a binding failure message sent by the security server, the TCP connection is closed.
[0046] It should be noted that, when the identity information and terminal features are not successfully bound to the user terminal, the security server sends a binding failure message to the gateway so that the gateway closes the established TCP connection. In addition, the security server performs security authentication on the user terminal, binds the identity information and terminal features to the user terminal after the security authentication is passed, and sends a connection indication to the user terminal so that the user terminal resends a connection establishment request to the gateway.
[0047] In the information processing method provided by the above embodiment of the present disclosure, by using a security server that is separately provided from the business server to perform security authentication, it is possible to provide security services for the mail client provided by a third party.
[0048] In some embodiments, after receiving the binding success message sent by the security server, the gateway starts a timer with a preset timing duration. After the timer times out, the gateway sends the first verification request to the security server.
[0049] That is to say, in order to ensure security, the gateway will send relevant identity information and user terminal characteristics to the security server for re-security testing every once in a while (for example, half an hour), thereby effectively preventing security issues such as password leakage and account fraud.
[0050] Figure 2 FIG. 1 is a schematic diagram of the structure of a gateway according to an embodiment of the present disclosure. Figure 2 As shown, the gateway includes a first processing module 21 , a second processing module 22 , a third processing module 23 and a fourth processing module 24 .
[0051] The first processing module 21 is configured to establish a TCP connection between the gateway and the user terminal after receiving a connection establishment request sent by the user terminal.
[0052] In some embodiments, after receiving the connection establishment request sent by the user terminal, the first processing module 21 sends the second verification request to the security server so that the security server can determine whether there is a security risk based on the identity information and terminal features included in the second verification request. In this way, illegal requests such as brute force cracking, database collision, and malicious IP can be filtered out. If a no security risk indication message sent by the security server is received, a TCP connection is established between the gateway and the user terminal.
[0053] In some embodiments, the terminal characteristics of the user terminal include at least one of an IP address, a unique device identifier, and a user agent of the user terminal.
[0054] In some embodiments, the first processing module 21 selects a TCP connection information not used by other users from the connection pool to establish a TCP connection between the gateway and the user terminal, thereby effectively avoiding information leakage caused by different users using the same TCP connection.
[0055] In some embodiments, if the first processing module 21 receives a security risk indication message sent by the security server, the connection establishment request is rejected, so as to effectively reject the request with security risk.
[0056] In some embodiments, the gateway is a mail gateway. After receiving the connection establishment request, the first processing module 21 performs protocol analysis on the connection establishment request to determine the mail protocol used and extract relevant identity information, such as account information.
[0057] The second processing module 22 is configured to send the connection establishment request to the service server so that the service server authenticates the identity information included in the connection establishment request.
[0058] In some embodiments, after receiving the connection establishment request sent by the gateway, the service server authenticates the identity information included in the connection establishment request, and sends an authentication success message to the second processing module 22 after the authentication succeeds.
[0059] In some embodiments, the business server is a mail server.
[0060] The third processing module 23 is configured to send the first verification request to the security server if receiving the authentication success message sent by the service server, so that the security server verifies whether the identity information and terminal features included in the first verification request are bound to the user terminal.
[0061] It should be noted here that, since the security server is set up separately from the business server, the security server can provide security services for the mail client provided by the third party.
[0062] The fourth processing module 24 is configured to send an authentication success message to the user terminal if a binding success message sent by the security server is received, so that the user terminal interacts with the service server through the gateway.
[0063] In some embodiments, if the fourth processing module 24 receives a binding failure message sent by the security server, the TCP connection is closed.
[0064] It should be noted that, when the identity information and terminal features are not successfully bound to the user terminal, the security server sends a binding failure message to the gateway so that the gateway closes the established TCP connection. In addition, the security server performs security authentication on the user terminal, binds the identity information and terminal features to the user terminal after the security authentication is passed, and sends a connection indication to the user terminal so that the user terminal resends a connection establishment request to the gateway.
[0065] Figure 3 FIG. 1 is a schematic diagram of the structure of a gateway according to another embodiment of the present disclosure. Figure 3 As shown, the gateway includes a memory 31 and a processor 32 .
[0066] The memory 31 is used to store instructions. The processor 32 is coupled to the memory 31. The processor 32 is configured to execute the instructions stored in the memory to implement the following steps: Figure 1 The method of any one of the embodiments.
[0067] like Figure 3 As shown, the gateway also includes a communication interface 33 for information exchange with other devices. At the same time, the gateway also includes a bus 34, through which the processor 32, the communication interface 33, and the memory 31 communicate with each other.
[0068] The memory 31 may include a high-speed RAM memory, and may also include a non-volatile memory, such as at least one disk memory. The memory 31 may also be a memory array. The memory 31 may also be divided into blocks, and the blocks may be combined into virtual volumes according to certain rules.
[0069] In addition, the processor 32 may be a central processing unit (CPU), or may be an application specific integrated circuit (ASIC), or may be configured to implement one or more integrated circuits of the embodiments of the present disclosure.
[0070] The present disclosure also relates to a computer-readable storage medium, wherein the computer-readable storage medium stores computer instructions, which are executed by a processor to implement the following Figure 1 The method of any one of the embodiments.
[0071] Figure 4 FIG. 1 is a schematic diagram of the structure of a communication system according to an embodiment of the present disclosure. Figure 4 As shown, the communication system includes a gateway 41, a service server 42, a security server 43 and a user terminal 44. The gateway 41 is Figure 2 or Figure 3 The gateway involved in any one of the embodiments.
[0072] For example, the gateway 41 is a mail gateway, and the service server 42 is a mail server.
[0073] The service server 42 is configured to authenticate the identity information included in the connection establishment request after receiving the connection establishment request sent by the gateway 41 , and send an authentication success message to the gateway 41 after the authentication is successful.
[0074] The security server 43 is configured to verify whether the identity information and terminal characteristics of the user terminal included in the first verification request are bound to the user terminal after receiving the first verification request sent by the gateway 41. If the identity information and terminal characteristics are successfully bound to the user terminal, a binding success message is sent to the gateway 41.
[0075] In some embodiments, the terminal characteristics of the user terminal include at least one of an IP address, a unique device identifier, and a user agent of the user terminal.
[0076] In some embodiments, if the identity information and terminal characteristics are not successfully bound to the user terminal, the security server 43 is configured to send a binding failure message to the gateway 41, perform security authentication on the user terminal 44, for example, the security authentication is MFA authentication, bind the identity information and terminal characteristics to the user terminal after the security authentication is passed, and send a connection indication to the user terminal 41 so that the user terminal 44 re-sends a connection establishment request to the gateway 41.
[0077] In some embodiments, after receiving the second verification request sent by the gateway 41, the security server 43 is configured to determine whether there is a security risk based on the identity information and terminal characteristics included in the second verification request; if the identity information and terminal characteristics do not pose a security risk, a no security risk indication message is sent to the gateway.
[0078] In some embodiments, the security server 43 is configured to send a security risk indication message to the gateway 41 if the identity information or terminal characteristics have security risks.
[0079] The present disclosure is described below by using a specific example. Figure 4 As shown:
[0080] 1. The user terminal 44 sends a connection establishment request to the gateway 41.
[0081] 2. After receiving the connection establishment request, the gateway 41 sends a risk verification request to the security server 43.
[0082] 3. The security server 43 determines whether there is a security risk based on the identity information and the terminal characteristics of the user terminal included in the risk verification request. If there is no security risk based on the identity information and the terminal characteristics of the user terminal, a no security risk indication message is sent to the gateway 41.
[0083] 4. After receiving the no security risk indication message, the gateway 41 establishes a TCP connection between the gateway 41 and the user terminal 44.
[0084] 5. The gateway 41 sends a connection establishment request to the service server 42.
[0085] 6. The service server 42 authenticates the identity information included in the connection establishment request, and sends an authentication success message to the gateway 41 after the authentication succeeds.
[0086] 7. After receiving the authentication success message, the gateway 41 sends a binding detection request to the security server 43.
[0087] 8. The security server 43 verifies whether the identity information and the terminal characteristics of the user terminal included in the first verification request are bound to the user terminal.
[0088] If the identity information and the terminal characteristics of the user terminal are bound to the user terminal, execute step 9; otherwise, execute step 11.
[0089] 9. The security server 43 sends a binding success message to the gateway 41.
[0090] 10. After receiving the binding success message, the gateway 41 sends an authentication success message to the user terminal 44 so that the user terminal 44 interacts with the service server 42 through the gateway 41.
[0091] It should be noted that the gateway 41 establishes a TCP connection with the business server 42 in advance, thereby implementing email sending and receiving between the user terminal 44 and the business server 42 by utilizing the TCP connection between the gateway 41 and the user terminal 44 and the TCP connection between the gateway 41 and the business server 42.
[0092] 11. The security server 43 sends a binding failure message to the gateway 41 so that the gateway 41 closes the TCP connection between the gateway 41 and the user terminal 44.
[0093] 12. The security server 43 performs security authentication on the user terminal, binds the identity information and terminal features with the user terminal after the security authentication is passed, and sends a connection indication to the user terminal 44 so that the user terminal 44 resends a connection establishment request to the gateway 41.
[0094] By implementing the present disclosure, the following beneficial effects can be obtained:
[0095] 1) There is no need to modify the email client or server, or change the protocol, so that security testing and authentication can be seamlessly accessed;
[0096] 2) Realize multi-protocol identification and be extensible;
[0097] 3) Security detection and authentication are processed in real time, not asynchronously or by-pass, so risks are not missed;
[0098] 4) Do not process the email content to effectively protect data privacy.
[0099] In some embodiments, the functional unit module described above can be implemented as a general-purpose processor, a programmable logic controller (PLC), a digital signal processor (DSP), an application-specific integrated circuit (ASIC), a field-programmable gate array (FPGA) or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components or any appropriate combination thereof for performing the functions described in the present disclosure.
[0100] A person skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware or by instructing related hardware through a program, and the program may be stored in a computer-readable storage medium, and the above-mentioned storage medium may be a read-only memory, a disk or an optical disk, etc.
[0101] The description of the present disclosure is given for the purpose of illustration and description, and is not intended to be exhaustive or to limit the present disclosure to the disclosed form. Many modifications and variations will be apparent to those of ordinary skill in the art. The embodiments are selected and described in order to better illustrate the principles and practical applications of the present disclosure, and to enable those of ordinary skill in the art to understand the present disclosure and thereby design various embodiments with various modifications suitable for specific uses.
Claims
1. An information processing method, executed by a gateway, comprising: After receiving a connection establishment request sent by a user terminal, establishing a TCP connection between the gateway and the user terminal; Sending the connection establishment request to a service server so that the service server authenticates the identity information included in the connection establishment request; If an authentication success message sent by the service server is received, sending a first verification request to a security server so that the security server verifies whether the identity information and the terminal features of the user terminal included in the first verification request are bound to the user terminal; If a binding success message sent by the security server is received, the authentication success message is sent to the user terminal, so that the user terminal interacts with the service server through the gateway.
2. The method according to claim 1, further comprising: If a binding failure message sent by the security server is received, the TCP connection is closed.
3. The method according to claim 1, further comprising: After receiving the binding success message sent by the security server, starting a timer, the timer has a preset timing duration; After the timer times out, the first verification request is sent to the security server.
4. The method according to any one of claims 1 to 3, further comprising: After receiving the connection establishment request sent by the user terminal, sending a second verification request to the security server, so that the security server determines whether there is a security risk according to the identity information and the terminal characteristics included in the second verification request; If a no security risk indication message sent by the security server is received, the TCP connection is established between the gateway and the user terminal.
5. The method according to claim 4, further comprising: If a security risk indication message sent by the security server is received, the connection establishment request is rejected.
6. The method according to claim 4, wherein: Establishing a TCP connection between the gateway and the user terminal includes: A TCP connection information not used by other users is selected from the connection pool to establish a TCP connection between the gateway and the user terminal.
7. The method according to claim 4, wherein: The terminal characteristics of the user terminal include at least one of the IP address, device unique identifier and user agent of the user terminal.
8. A gateway, comprising: A first processing module is configured to establish a TCP connection between the gateway and the user terminal after receiving a connection establishment request sent by the user terminal; A second processing module is configured to send the connection establishment request to a service server so that the service server authenticates the identity information included in the connection establishment request; a third processing module configured to, upon receiving an authentication success message sent by the business server, send a first verification request to a security server so that the security server verifies whether the identity information and the terminal features of the user terminal included in the first verification request are bound to the user terminal; The fourth processing module is configured to send the authentication success message to the user terminal if a binding success message sent by the security server is received, so that the user terminal interacts with the service server through the gateway.
9. A gateway, comprising: a memory configured to store instructions; A processor is coupled to the memory, and the processor is configured to execute the method according to any one of claims 1 to 7 based on instructions stored in the memory.
10. A communication system comprising: The gateway as claimed in claim 8 or 9; The service server is configured to authenticate the identity information included in the connection establishment request after receiving the connection establishment request sent by the gateway, and send an authentication success message to the gateway after the authentication is successful; The security server is configured to verify whether the identity information and terminal characteristics of the user terminal included in the first verification request are bound to the user terminal after receiving the first verification request sent by the gateway, and if the identity information and the terminal characteristics are successfully bound to the user terminal, send a binding success message to the gateway.
11. The system according to claim 10, wherein: The security server is configured to send a binding failure message to the gateway if the identity information and the terminal characteristics are not successfully bound to the user terminal, perform security authentication on the user terminal, bind the identity information and the terminal characteristics to the user terminal after the security authentication is passed, and send a connection indication to the user terminal so that the user terminal can re-send a connection establishment request to the gateway.
12. The system according to claim 11, wherein: The security authentication is a multi-factor authentication.
13. The system according to any one of claims 10 to 12, wherein: The security server is configured to, after receiving the second verification request sent by the gateway, determine whether there is a security risk based on the identity information and the terminal characteristics included in the second verification request; if the identity information and the terminal characteristics do not pose a security risk, send a no security risk indication message to the gateway.
14. The system according to claim 13, wherein: The security server is configured to send a security risk indication message to the gateway if the identity information or the terminal feature has a security risk.
15. A non-transitory computer-readable storage medium, wherein: The computer-readable storage medium stores computer instructions, and when the instructions are executed by a processor, the method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
System and method for internet user authentication
CN102882853A
Method for terminal user safety access soft handoff network
CN1841998A