A network access method and system
The network request information is isolated from the network and sent to the server through client software, solving the problem of cumbersome VPN client authentication in the existing technology, achieving more efficient network access, and significantly improving the user experience.
Patent Information
- Application Number
- CN202211114437.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-14
- Publication Date
- 2025-05-02
- Estimated Expiration
- 2042-09-14
AI Technical Summary
The existing network access method requires users to perform VPN client authentication, which is cumbersome, reduces network access efficiency and affects user experience.
The network request information is isolated from the client software to send network request information to the server. The server obtains valid network configuration information based on the network request information, and determines the resources to be allocated according to the preset distribution rules conditions, sends them to the client, and the client performs the network connection opening operation.
There is no need for VPN client authentication, which reduces operational difficulty, improves network access efficiency, and enhances users' experience of remote services.
Smart Images

Figure CN115460004B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of network technology, and in particular to a network access method and system. Background Art
[0002] At present, with the operation of infrastructure, users are accustomed to expecting a cloud-like connection experience when accessing enterprise servers. With the existing network access method, when users need to connect to enterprise applications, they need to open the VPN client for authentication first, and then open the application after passing the authentication. This is inconvenient to use, requiring users to log in and out repeatedly, and the speed is very slow. It can be seen that the existing method requires VPN client authentication, which is cumbersome to operate, reduces network access efficiency, and thus affects the user's network access experience. Summary of the invention
[0003] The purpose of the embodiments of the present application is to provide a network access method and system, which can eliminate the need for users to perform VPN client authentication, thereby reducing operational difficulty, improving network access efficiency, and significantly enhancing the user's experience of remote services.
[0004] A first aspect of an embodiment of the present application provides a network access method, including:
[0005] The client sends network request information to the server through the software isolation network; wherein the network request information includes user identity information, IP address, OS information and software information;
[0006] The server receives the network request information, and obtains valid network configuration information according to the network request information;
[0007] The server determines the resources to be allocated according to the preset distribution rule conditions and the effective network configuration information, and sends the allocated resources to the client;
[0008] The client receives the allocated resources and performs a network connection opening operation according to the allocated resources.
[0009] In the above implementation process, the method can be applied to a network access system including both a client and a server. Specifically, the client can send network request information to the server through a software isolation network; wherein the network request information includes user identity information, IP address, OS information and software information; the server can receive the network request information and obtain valid network configuration information according to the network request information; and determine the resources to be allocated according to the preset distribution rule conditions and the valid network configuration information, and send the allocated resources to the client; then, the client receives the allocated resources and performs a network connection opening operation according to the allocated resources. It can be seen that the implementation of this implementation method can eliminate the need for users to perform VPN client authentication, thereby reducing the difficulty of operation, improving network access efficiency, and greatly enhancing the user's experience of remote services.
[0010] Furthermore, the method further comprises:
[0011] The client obtains network access data related to the network request information;
[0012] Among them, the relevant network access data includes the IP address, port, specific content of network access packet sending and receiving, and the user equipment terminal information corresponding to the client. The user equipment terminal information includes the device identification, device operating system, device operating system version, application on the device operating system, usage data of the application, and resource data accessed by the application.
[0013] Furthermore, the method further comprises:
[0014] The client receives network configuration information input by an administrator;
[0015] The client pushes the network configuration information to other clients under the cloud service management through the cloud service management for batch network configuration.
[0016] Furthermore, the client sends network request information to the server through the software isolation network, including:
[0017] The client receives a network access instruction input by a user;
[0018] The client generates network request information in a SPA packet format using the SPA protocol according to the network access instruction;
[0019] The client sends network request information to the server through the software isolation network.
[0020] A second aspect of an embodiment of the present application provides a network access system, the network access system comprising a client and a server, wherein:
[0021] The client is used to send network request information to the server through the software isolation network; wherein the network request information includes user identity information, IP address, OS information and software information;
[0022] The server is used to receive the network request information and obtain valid network configuration information according to the network request information; and determine the resources to be allocated according to the preset distribution rule conditions and the valid network configuration information, and send the allocated resources to the client;
[0023] The client is used to receive the allocated resources and perform a network connection opening operation according to the allocated resources.
[0024] In the above implementation process, the system can send network request information to the server through the software isolation network through the client; wherein the network request information includes user identity information, IP address, OS information and software information; receive the network request information through the server, and obtain valid network configuration information according to the network request information; and determine the resources to be allocated according to the preset distribution rule conditions and the valid network configuration information, and send the allocated resources to the client; receive the allocated resources through the client, and perform the network connection opening operation according to the allocated resources. It can be seen that the implementation of this implementation method can no longer require users to perform VPN client authentication, thereby reducing the difficulty of operation, improving network access efficiency, and greatly enhancing the user's experience of remote services.
[0025] Furthermore, the client is also used to obtain relevant network access data of the network request information; wherein the relevant network access data includes the IP address, port, specific content of network access packet sending and receiving, and user device terminal information corresponding to the client, and the user device terminal information includes device identification, device operating system, device operating system version, application on the device operating system, usage data of the application, and resource data accessed by the application.
[0026] Furthermore, the client is also used to receive network configuration information input by an administrator; and push the network configuration information to other clients under the cloud service management through cloud service management for batch network configuration.
[0027] Furthermore, the client is specifically used to receive a network access instruction input by a user; and according to the network access instruction, generate network request information in a SPA package format using the SPA protocol; and send the network request information to the server through a software isolated network.
[0028] A third aspect of an embodiment of the present application provides an electronic device, including a memory and a processor, wherein the memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the network access method described in any one of the first aspects of the embodiments of the present application.
[0029] A fourth aspect of an embodiment of the present application provides a computer-readable storage medium storing computer program instructions. When the computer program instructions are read and executed by a processor, the network access method described in any one of the first aspects of the embodiment of the present application is executed. BRIEF DESCRIPTION OF THE DRAWINGS
[0030] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the embodiments of the present application will be briefly introduced below. It should be understood that the following drawings only show certain embodiments of the present application and therefore should not be regarded as limiting the scope. For ordinary technicians in this field, other related drawings can be obtained based on these drawings without paying creative work.
[0031] Figure 1 A flowchart of a network access method provided in an embodiment of the present application;
[0032] Figure 2 A flowchart of another network access method provided in an embodiment of the present application;
[0033] Figure 3 A schematic diagram of the structure of a network access system provided in an embodiment of the present application;
[0034] Figure 4 A schematic diagram of the structure of a client provided in an embodiment of the present application;
[0035] Figure 5 A schematic diagram of the structure of a server provided in an embodiment of the present application. DETAILED DESCRIPTION
[0036] The technical solutions in the embodiments of the present application will be described below in conjunction with the drawings in the embodiments of the present application.
[0037] It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in subsequent drawings. At the same time, in the description of this application, the terms "first", "second", etc. are only used to distinguish the description and cannot be understood as indicating or implying relative importance.
[0038] Example 1
[0039] Please see Figure 1 , Figure 1A flowchart of a network access method is provided for an embodiment of the present application. The network access method includes:
[0040] S101. The client sends a network request message to the server through a software-isolated network.
[0041] In this embodiment, the network request information includes user identity information, IP address, OS information and software information.
[0042] S201. The server receives network request information and obtains valid network configuration information according to the network request information.
[0043] S202: The server determines the resources to be allocated according to the preset distribution rule conditions and the effective network configuration information, and sends the allocated resources to the client.
[0044] S102: The client receives the allocated resources and performs a network connection opening operation according to the allocated resources.
[0045] In this embodiment, the execution subject of the method may be a computing device such as a computer or a server, and no limitation is made in this embodiment.
[0046] In this embodiment, the execution subject of the method may also be a smart device such as a smart phone, a tablet computer, etc., which is not limited in this embodiment.
[0047] It can be seen that the implementation of the network access method described in this embodiment enables users to simply and securely access enterprise servers from the devices of their choice, without the need for a remote access process, and without the problem of being unable to log in due to VPN access interruptions; at the same time, the use of this method can make the user's remote connection authorization and authentication imperceptible, thereby greatly enhancing the user's experience of remote services. In addition, the method can separate applications and network access so that users are no longer on the enterprise network. At this time, a secure isolation environment is created around each private program, and only minimum privileged access is provided to specific users, so this greatly improves the protection performance of the intranet. Then, the method can adapt to various mobile devices, so that IT has a higher level of visibility and control over the network, users, and enterprise servers, which makes it easier for the security team to easily monitor, identify and diagnose any security threats to the enterprise. Finally, the method can also extend access rights to the branch offices of the enterprise without configuring site-to-site VPN and firewall rules, and at the same time, this method also allows users to verify user identities through personal devices.
[0048] Example 2
[0049] Please see Figure 2 , Figure 2A flowchart of a network access method is provided for an embodiment of the present application. The network access method includes:
[0050] S301: The client obtains network access data related to network request information.
[0051] In this embodiment, the relevant network access data includes the IP address, port, specific content of the network access packet sending and receiving, and the user device terminal information corresponding to the client. The user device terminal information includes the device identification, device operating system, device operating system version, application on the device operating system, application usage data, and resource data accessed by the application.
[0052] In this embodiment, the method can obtain more information from the user in real time. In addition to traditional network-related information, it can also obtain the mobile information of the user's device terminal, including device ID, device OS, device OS version, software running on the device OS, and whether there is any suspicious software, etc. This information can make authentication more stable and reliable, and make network access more secure. At the same time, the zero-trust network solution enables administrators to obtain comprehensive information about all activities between users and applications. Not only can each activity, the IP and port of each network request be tracked in real time, but also user identity, latency, location and other data can be captured. All user operations have log files, which greatly enhances the monitoring and management capabilities. Problems can be quickly traced to the source, preventing major incidents and reducing possible harm.
[0053] For example, this method can record the specific data of each network request through syslog, including IP address, port, specific content of packet sending and receiving, and specific data of each device, including deviceID, OS, etc. It can also record the usage data of application software, including which applications actively accessed a certain resource at a certain point in time.
[0054] S302: The client receives a network access instruction input by a user.
[0055] S303: The client generates network request information in SPA package format using SPA protocol according to the network access instruction.
[0056] In this embodiment, the network request information includes user identity information, IP address, OS information and software information.
[0057] For example, the client uses the SPA protocol to open a connection by sending a SPA packet to the server. After that, the server allocates reliable resources to the client based on the valid information provided by the client, including user identity, IP address, OS information, software information, etc. The server's operations include obtaining valid network configurations and distributing corresponding resources to the client based on rules and conditions.
[0058] S304: The client sends network request information to the server through the software isolation network.
[0059] S401. The server receives network request information, and obtains valid network configuration information input by an administrator according to the network request information.
[0060] S402: The client pushes network configuration information to other clients under the cloud service management through the cloud service management to perform batch network configuration.
[0061] In this embodiment, the method allows the administrator to only configure network information, without having to configure more complex network access rules, such as specific network requests, etc. This can greatly simplify the administrator's configuration work in a complex network deployment environment, making the configuration simpler and more reliable. Moreover, a network can be configured multiple times, which greatly enhances the scalability of network configuration and reduces the complexity of multiple configurations by the administrator.
[0062] For example, the administrator can configure the information of only one box and automatically push the same management configuration information to other boxes under the same cloud service management through cloud service management. The configuration data is transmitted through the communication between the box and the cloud service management center, which greatly enhances the scalability of the configuration.
[0063] S403: The server determines the resources to be allocated according to the preset distribution rule conditions and the effective network configuration information, and sends the allocated resources to the client.
[0064] S305: The client receives the allocated resources and performs a network connection opening operation according to the allocated resources.
[0065] In this embodiment, the method can use software-isolated networks to ensure that the user's access rights and scope are obtained once and for all within the application program, without the need for repeated applications. At the same time, the benefits of software-defined networks can greatly reduce operating costs and reduce hardware dependence. Users do not have to consider whether the remote service is located in a data center or in the cloud, and do not have to get bogged down by delays. Faster connections mean better user experience. At the same time, the user's access rights include not only the network addresses that the user can access, but also the specific program software that the user can use. Such a flexible and changeable combination solves the current complex and changeable user usage scenarios on desktop and mobile terminals, and meets the growing security and speed requirements of modern working methods.
[0066] In this embodiment, the execution subject of the method may be a computing device such as a computer or a server, and no limitation is made in this embodiment.
[0067] In this embodiment, the execution subject of the method may also be a smart device such as a smart phone, a tablet computer, etc., which is not limited in this embodiment.
[0068] It can be seen that the implementation of the network access method described in this embodiment enables users to simply and securely access enterprise servers from the devices of their choice, without the need for a remote access process, and without the problem of being unable to log in due to VPN access interruptions; at the same time, the use of this method can make the user's remote connection authorization and authentication imperceptible, thereby greatly enhancing the user's experience of remote services. In addition, the method can separate applications and network access so that users are no longer on the enterprise network. At this time, a secure isolation environment is created around each private program, and only minimum privileged access is provided to specific users, so this greatly improves the protection performance of the intranet. Then, the method can adapt to various mobile devices, so that IT has a higher level of visibility and control over the network, users, and enterprise servers, which makes it easier for the security team to easily monitor, identify and diagnose any security threats to the enterprise. Finally, the method can also extend access rights to the branch offices of the enterprise without configuring site-to-site VPN and firewall rules, and at the same time, this method also allows users to verify user identities through personal devices.
[0069] Example 3
[0070] Please see Figure 3 , Figure 3 A schematic diagram of the structure of a network access system provided in an embodiment of the present application. Figure 3 As shown, the network access system includes a client 500 and a server 600, wherein:
[0071] The client 500 is used to send network request information to the server 600 through the software isolation network; wherein the network request information includes user identity information, IP address, OS information and software information;
[0072] The server 600 is used to receive network request information and obtain valid network configuration information according to the network request information; and determine the resources to be allocated according to the preset distribution rule conditions and the valid network configuration information, and send the allocated resources to the client 500;
[0073] The client 500 is used to receive the allocated resources and perform a network connection opening operation according to the allocated resources.
[0074] As an optional implementation, the client 500 is also used to obtain relevant network access data of the network request information; wherein the relevant network access data includes the IP address, port, specific content of the network access packet sending and receiving, and the user device terminal information corresponding to the client 500, and the user device terminal information includes the device identification, device operating system, device operating system version, application on the device operating system, application usage data, and resource data accessed by the application.
[0075] As an optional implementation, the client 500 is also used to receive network configuration information input by an administrator; and to push the network configuration information to other clients 500 under the cloud service management through the cloud service management for batch network configuration.
[0076] As an optional implementation, the client 500 is specifically used to receive a network access instruction input by a user; and according to the network access instruction, generate network request information in a SPA package format using the SPA protocol; and send the network request information to the server 600 through a software isolation network.
[0077] In this embodiment, the explanation of the network access system can refer to the description in Embodiment 1 or Embodiment 2, and will not be further elaborated in this embodiment.
[0078] It can be seen that the implementation of the network access system described in this embodiment enables users to simply and securely access enterprise servers from the devices of their choice, without the need for a remote access process, and without the problem of being unable to log in due to VPN access interruptions; at the same time, the use of this method can make the authorization and authentication of the user's remote connection imperceptible, thereby greatly enhancing the user's experience of remote services. In addition, the method can separate applications and network access so that users are no longer on the enterprise network. At this time, a secure isolation environment is created around each private program, and only minimum privileged access is provided to specific users, so this greatly improves the protection performance of the intranet. Then, the method can adapt to various mobile devices, so that IT has a higher level of visibility and control over the network, users, and enterprise servers, which makes it easier for the security team to easily monitor, identify and diagnose any security threats to the enterprise. Finally, the method can also extend access rights to the branch offices of the enterprise without configuring site-to-site VPN and firewall rules, and at the same time, this method also allows users to verify user identities through personal devices.
[0079] Example 4
[0080] Please see Figure 4 , Figure 4 A schematic diagram of the structure of a network access system provided in an embodiment of the present application. Figure 4 As shown, the client 500 includes:
[0081] The sending unit 510 is used to send network request information to the server through the software isolation network; wherein the network request information includes user identity information, IP address, OS information and software information;
[0082] The receiving unit 520 is used to receive the allocated resources and perform a network connection opening operation according to the allocated resources.
[0083] As an optional implementation, the client 500 further includes:
[0084] An acquisition unit 530 is used to acquire network access data related to the network request information;
[0085] Among them, the relevant network access data includes the IP address, port, specific content of network access packets sent and received, and the user device terminal information corresponding to the client. The user device terminal information includes the device identification, device operating system, device operating system version, application on the device operating system, application usage data, and resource data accessed by the application.
[0086] As an optional implementation, the client 500 further includes:
[0087] The receiving unit 520 is further used to receive network configuration information input by an administrator;
[0088] The push unit 540 is used to push the network configuration information to other clients under the cloud service management through the cloud service management to perform batch network configuration.
[0089] As an optional implementation, the sending unit 510 is specifically used to receive a network access instruction input by a user; and generate network request information in a SPA package format using the SPA protocol according to the network access instruction; and send the network request information to the server through a software isolation network.
[0090] In this embodiment, the explanation of the network access system can refer to the description in Embodiment 1 or Embodiment 2, and will not be further elaborated in this embodiment.
[0091] It can be seen that the implementation of the network access system described in this embodiment enables users to simply and securely access enterprise servers from the devices of their choice, without the need for a remote access process, and without the problem of being unable to log in due to VPN access interruptions; at the same time, the use of this method can make the authorization and authentication of the user's remote connection imperceptible, thereby greatly enhancing the user's experience of remote services. In addition, the method can separate applications and network access so that users are no longer on the enterprise network. At this time, a secure isolation environment is created around each private program, and only minimum privileged access is provided to specific users, so this greatly improves the protection performance of the intranet. Then, the method can adapt to various mobile devices, so that IT has a higher level of visibility and control over the network, users, and enterprise servers, which makes it easier for the security team to easily monitor, identify and diagnose any security threats to the enterprise. Finally, the method can also extend access rights to the branch offices of the enterprise without configuring site-to-site VPN and firewall rules, and at the same time, this method also allows users to verify user identities through personal devices.
[0092] Example 5
[0093] Please see Figure 5 , Figure 5 A schematic diagram of the structure of a network access system provided in an embodiment of the present application. Figure 5 As shown, the server 600 includes:
[0094] The receiving unit 610 is used to receive the network request information and obtain the valid network configuration information according to the network request information;
[0095] The allocation unit 620 is used to determine the resources to be allocated according to the preset distribution rule conditions and the effective network configuration information, and send the allocated resources to the client.
[0096] In this embodiment, the explanation of the network access system can refer to the description in Embodiment 1 or Embodiment 2, and will not be further elaborated in this embodiment.
[0097] It can be seen that the implementation of the network access system described in this embodiment enables users to simply and securely access enterprise servers from the devices of their choice, without the need for a remote access process, and without the problem of being unable to log in due to VPN access interruptions; at the same time, the use of this method can make the authorization and authentication of the user's remote connection imperceptible, thereby greatly enhancing the user's experience of remote services. In addition, the method can separate applications and network access so that users are no longer on the enterprise network. At this time, a secure isolation environment is created around each private program, and only minimum privileged access is provided to specific users, so this greatly improves the protection performance of the intranet. Then, the method can adapt to various mobile devices, so that IT has a higher level of visibility and control over the network, users, and enterprise servers, which makes it easier for the security team to easily monitor, identify and diagnose any security threats to the enterprise. Finally, the method can also extend access rights to the branch offices of the enterprise without configuring site-to-site VPN and firewall rules, and at the same time, this method also allows users to verify user identities through personal devices.
[0098] An embodiment of the present application provides an electronic device, including a memory and a processor, wherein the memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the network access method in Embodiment 1 or Embodiment 2 of the present application.
[0099] An embodiment of the present application provides a computer-readable storage medium storing computer program instructions. When the computer program instructions are read and executed by a processor, the network access method in Embodiment 1 or Embodiment 2 of the present application is executed.
[0100] In several embodiments provided in the present application, it should be understood that the disclosed devices and methods can also be implemented in other ways. The device embodiments described above are merely schematic. For example, the flowcharts and block diagrams in the accompanying drawings show the possible architecture, functions and operations of the devices, methods and computer program products according to multiple embodiments of the present application. In this regard, each box in the flowchart or block diagram can represent a module, a program segment or a part of a code, and the module, a program segment or a part of a code contains one or more executable instructions for implementing the specified logical function. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a different order from the order marked in the accompanying drawings. For example, two consecutive boxes can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, and the combination of boxes in the block diagram and / or flowchart can be implemented with a dedicated hardware-based system that performs a specified function or action, or can be implemented with a combination of dedicated hardware and computer instructions.
[0101] In addition, the functional modules in the various embodiments of the present application may be integrated together to form an independent part, or each module may exist separately, or two or more modules may be integrated to form an independent part.
[0102] If the functions are implemented in the form of software function modules and sold or used as independent products, they can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application can be essentially or partly embodied in the form of a software product that contributes to the prior art. The computer software product is stored in a storage medium, including several instructions for a computer device (which can be a personal computer, a server, or a network device, etc.) to perform all or part of the steps of the methods described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0103] The above description is only an embodiment of the present application and is not intended to limit the scope of protection of the present application. For those skilled in the art, the present application may have various changes and variations. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application should be included in the scope of protection of the present application. It should be noted that similar reference numerals and letters represent similar items in the following drawings, so once an item is defined in one drawing, it does not need to be further defined and explained in the subsequent drawings.
[0104] The above is only a specific implementation of the present application, but the protection scope of the present application is not limited thereto. Any technician familiar with the technical field can easily think of changes or substitutions within the technical scope disclosed in the present application, which should be included in the protection scope of the present application. Therefore, the protection scope of the present application should be based on the protection scope of the claims.
[0105] It should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the existence of other identical elements in the process, method, article or device including the elements.
Claims
1. A network access method, characterized in that: include: The client obtains network access data related to the network request information; the related network access data includes the IP address, port, specific content of the network access packet sending and receiving, and the user device terminal information corresponding to the client, and the user device terminal information includes the device identification, device operating system, device operating system version, application on the device operating system, usage data of the application, and resource data accessed by the application; The client sends network request information to the server through the software isolation network; wherein the network request information includes user identity information, IP address, operating system information and software information; The server receives the network request information, and obtains valid network configuration information input by the administrator according to the network request information; pushes the valid network configuration information to other clients under the cloud service management through cloud service management for batch network configuration; The server determines the resources to be allocated according to the preset distribution rule conditions and the effective network configuration information, and sends the resources to be allocated to the client; The client receives the resources to be allocated, and performs a network connection opening operation according to the resources to be allocated; The client sends network request information to the server through the software isolation network, including: The client receives a network access instruction input by a user; The client generates network request information in a SPA packet format using the SPA protocol according to the network access instruction; The client sends network request information to the server through the software isolation network; Wherein, the network access method is to record the specific data of each network request through syslog.
2. A network access system, characterized in that: The network access system includes a client and a server, wherein: The client is used to obtain network access data related to the network request information; wherein the related network access data includes the IP address, port, specific content of the network access packet sending and receiving, and the user equipment terminal information corresponding to the client, and the user equipment terminal information includes the device identification, device operating system, device operating system version, application on the device operating system, usage data of the application, and resource data accessed by the application; The client is used to send network request information and the related network access data to the server through the software isolation network; wherein the network request information includes user identity information, IP address, operating system information and software information; The server is used to receive the network request information, and obtain valid network configuration information input by the administrator according to the network request information; push the valid network configuration information to other clients under the cloud service management through cloud service management to perform batch network configuration; and determine the resources to be allocated according to the preset distribution rule conditions and the valid network configuration information, and send the resources to be allocated to the client; The client is used to receive the resources to be allocated and perform a network connection opening operation according to the resources to be allocated; The client is specifically used to receive a network access instruction input by a user; and according to the network access instruction, generate network request information in a SPA package format using the SPA protocol; and send the network request information to the server through a software isolated network; Wherein, the network access system records the specific data of each network request through syslog.
3. An electronic device, characterized in that: The electronic device comprises a memory and a processor, the memory is used to store a computer program, and the processor runs the computer program to enable the electronic device to execute the network access method according to claim 1.
4. A readable storage medium, characterized in that: The readable storage medium stores computer program instructions, and when the computer program instructions are read and executed by a processor, the network access method according to claim 1 is executed.
Citation Information
Patent Citations
Large-scale Internet of Things service domain isolation communication method and device, electronic equipment and storage medium
CN114172930A